CVE-2014-6271 Shellshock: Bash command injection via function import from environment variables

CVE-2018-20483: wget leaks HTTP Basic-Auth credentials into user.xdg.origin.url xattr

CVE-2018-20483: Wget stores credentials in extended file attributes (information-leak)

CVE-2018-20483 - Information Leak via Extended File Attributes in wget

CVE-2023-43115: Ghostscript IJS device path-traversal/sandbox-escape via subprocess file delegation

CVE-2023-43115: Ghostscript IJS device bypasses -dSAFER (path-traversal + RCE)

CVE-2018-20483: wget --xattr leaks URL credentials into extended file attributes

CVE-2018-20483: wget --xattr leaks userinfo (user:password) into persistent extended attributes

wget CVE-2018-20483: Information leak via embedded credentials in extended file attributes

CVE-2018-20483: wget stores plaintext credentials in xattr file metadata (information-leak)

CVE-2018-20483: wget --xattr leaks URL credentials into extended attributes

CVE-2018-20483: wget --xattr leaks HTTP Basic-Auth credentials into user.xdg.origin.url

CVE-2018-20483: wget stores plaintext credentials in POSIX extended file attributes

CVE-2018-20483: wget --xattr leaks credentials via user.xdg.origin.url

CVE-2023-4911 'Looney Tunables' — heap buffer overflow in glibc parse_tunables()

criticalruntimecposted 3 months ago

glibc CVE-2023-4911 Looney Tunables Buffer Overflow

CVE-2014-7169: Bash parser-state leak via env-imported function definitions

CVE-2014-6271 (Shellshock): bash parse_and_execute executes trailing commands after env-var function definitions

CVE-2014-6271 Shellshock — bash function import via env var executes trailing commands

CVE-2014-6271 (Shellshock): Environment Variable Function Definition Injection in bash-4.3

posted 3 months ago