Month: February 2026
CVE-2023-4535 Opensc: out-of-bounds read in myeid driver handling encryption using symmetric keys
CVE-2024-39936 An issue was discovered in HTTP2 in Qt before 5.15.18 6.x before 6.2.13 6.3.x through 6.5.x before 6.5.7 and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early because the encrypted() signal has not yet been emitted and processed..
CVE-2023-23914 A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.
CVE-2025-49630 Apache HTTP Server: mod_proxy_http2 denial of service
Information published. Continue reading CVE-2025-49630 Apache HTTP Server: mod_proxy_http2 denial of service
CVE-2024-42288 scsi: qla2xxx: Fix for possible memory corruption
Information published. Continue reading CVE-2024-42288 scsi: qla2xxx: Fix for possible memory corruption
