The (1) order and (2) group methods in ZendDbSelect in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.
It was found that vncconnectionservermessage() and vnccolormapset() functions do not check for integer overflow properly, leading to a malicious server being able to overwrite parts of the client memory, possibly leading to remote code execution under privileges of user running the VNC client.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=778050
Upstream patch:
https://git.gnome.org/browse/gtk-vnc/commit/?id=c8583fd3783c5b811590
Last updated 25 August 2025
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.
A heap-buffer overflow vulnerability was discovered in cryptopp. This vulnerability can be used to remotely gain access to shell.
References:
http://seclists.org/oss-sec/2016/q4/760 https://pony7.fr/ctf:public:32c3:cryptmsg
Upstream bug:
https://github.com/dlitz/pycrypto/issues/176
Last updated 25 August 2025
Last updated 25 August 2025
Potential SQL injection in ORDER and GROUP statements of ZendDbSelect