ALCASAR before 3.6.1 allows CSRF and remote code execution in activity.php.
A flaw was found in Hazelcast and Hazelcast Jet. This flaw may allow an attacker unauthenticated access to manipulate data in the cluster.
ALCASAR before 3.6.1 allows stillconnected.php remote code execution.
ALCASAR before 3.6.1 allows emailregistrationback.php remote code execution.
Icecast before 2.4.0 does not change the supplementary group privileges when <changeowner> is configured, which allows local users to gain privileges via unspecified vectors.
Icecast before 2.4.1 transmits the output of the on-connect script, which might allow remote attackers to obtain sensitive information, related to shared file descriptors.
End of life: 1/31/2025, End of support: 12/19/2022, Latest version: 5.4.1
End of life: 1/31/2025, End of support: 12/19/2022, Latest version: 5.4.1
End of life: 1/31/2024, End of support: 1/19/2022, Latest version: 4.2.4
End of life: 1/31/2024, End of support: 1/19/2022, Latest version: 4.2.4