Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Bernhard Wiedemann

#17105of 53,633
15.6Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2022-10548
8.8
2022-03-09
Opensuse · Opensuse Build Service Login-Proxy-Scripts · CVE-2021-36777
**Name of the Vulnerable Software and Affected Versions** openSUSE Build service login-proxy-scripts versions prior to dc000cdfe9b9b715fb92195b1a57559362f689ef **Description** A Reliance on Untrusted Inputs in a Security Decision issue in the login proxy of the openSUSE Build service allows attackers to present users with an expected login form that sends clear text credentials to an attacker-specified server. **Recommendations** For openSUSE Build service login-proxy-scripts versions prior to dc000cdfe9b9b715fb92195b1a57559362f689ef, update to a version that includes the fix for this issue to prevent attackers from intercepting clear text credentials. As a temporary workaround, consider restricting access to the login proxy until a patch is available.
PT-2019-6808
6.8
2019-12-20
Apple · Cups · CVE-2012-6094
**Name of the Vulnerable Software and Affected Versions** cups (Common Unix Printing System) (affected versions not specified) **Description** The issue is related to the 'Listen localhost:631' option in cups not being honored correctly, potentially allowing unauthorized access to the system. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.