Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 38 articles for you...
172

Ubuntu 26.04 Transmission Important Clickjacking Threat USN-8404-1

Transmission could allow unintended actions if a user visited a malicious website.. ========================================================================== Ubuntu Security Notice USN-8404-1 June 08, 2026 transmission vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Transmission could allow unintended actions if a user visited a malicious website. Software Description: - transmission: lightweight BitTorrent client Details: It was discovered that Transmission had a clickjacking weakness in the browser-facing WebUI and RPC response paths. An attacker could possibly use this issue to trick users into performing unintended actions. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS transmission 4.1.1+dfsg-1ubuntu1.1 transmission-daemon 4.1.1+dfsg-1ubuntu1.1 Ubuntu 25.10 transmission 4.1.0~beta2+dfsg-3ubuntu1.1 transmission-daemon 4.1.0~beta2+dfsg-3ubuntu1.1 Ubuntu 24.04 LTS transmission 4.0.5-1ubuntu0.1 transmission-daemon 4.0.5-1ubuntu0.1 Ubuntu 22.04 LTS transmission 3.00-2ubuntu2.2 transmission-daemon 3.00-2ubuntu2.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8404-1 CVE-2026-38978 Package Information: https://launchpad.net/ubuntu/+source/transmission/4.1.1+dfsg-1ubuntu1.1 https://launchpad.net/ubuntu/+source/transmission/4.1.0~beta2+dfsg-3ubuntu1.1 https://launchpad.net/ubuntu/+source/transmission/4.0.5-1ubuntu0.1 https://launchpad.net/ubuntu/+source/transmission/3.00-2ubuntu2.2 . Transmission has a clickjacking flaw; users could be tricked into unintended actions.. Ubuntu TransmissionClickjacking Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 08, 2026 Important Ubuntu
172

Ubuntu 26.04 Transmission Significant Clickjacking Vulnerability USN-8404-1

Transmission could allow unintended actions if a user visited a malicious website.. ========================================================================== Ubuntu Security Notice USN-8404-1 June 08, 2026 transmission vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Transmission could allow unintended actions if a user visited a malicious website. Software Description: - transmission: lightweight BitTorrent client Details: It was discovered that Transmission had a clickjacking weakness in the browser-facing WebUI and RPC response paths. An attacker could possibly use this issue to trick users into performing unintended actions. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS transmission 4.1.1+dfsg-1ubuntu1.1 transmission-daemon 4.1.1+dfsg-1ubuntu1.1 Ubuntu 25.10 transmission 4.1.0~beta2+dfsg-3ubuntu1.1 transmission-daemon 4.1.0~beta2+dfsg-3ubuntu1.1 Ubuntu 24.04 LTS transmission 4.0.5-1ubuntu0.1 transmission-daemon 4.0.5-1ubuntu0.1 Ubuntu 22.04 LTS transmission 3.00-2ubuntu2.2 transmission-daemon 3.00-2ubuntu2.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8404-1 CVE-2026-38978 Package Information: https://launchpad.net/ubuntu/+source/transmission/4.1.1+dfsg-1ubuntu1.1 https://launchpad.net/ubuntu/+source/transmission/4.1.0~beta2+dfsg-3ubuntu1.1 https://launchpad.net/ubuntu/+source/transmission/4.0.5-1ubuntu0.1 https://launchpad.net/ubuntu/+source/transmission/3.00-2ubuntu2.2 . Transmission in Ubuntu exposes users to clickjacking attacks; updates are essential for vulnerability mitigation..Ubuntu Transmission Clickjacking Attack Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 08, 2026 Important Ubuntu
89

Fedora 44 Transmission 4.1.2 Important Clickjacking Fix CVE-2026-38978

4.1.2, fix for CVE-2026-38978. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-c032fac814 2026-06-05 04:25:00.359120+00:00 -------------------------------------------------------------------------------- Name : transmission Product : Fedora 44 Version : 4.1.2 Release : 1.fc44 URL : http://www.transmissionbt.com Summary : A lightweight GTK+ BitTorrent client Description : Transmission is a free, lightweight BitTorrent client. It features a simple, intuitive interface on top on an efficient, cross-platform back-end. -------------------------------------------------------------------------------- Update Information: 4.1.2, fix for CVE-2026-38978 -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 3 2026 Gwyn Ciesla - 4.1.2-1 - 4.1.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2483871 - transmission-4.1.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2483871 [ 2 ] Bug #2484367 - CVE-2026-38978 transmission: Transmission: Clickjacking weakness in WebUI and RPC response paths [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2484367 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-c032fac814' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Transmission 4.1.2 update addresses important Clickjacking weakness in WebUI and RPC response. Immediate action recommended.. Transmission Clickjacking Update Fedora. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 05, 2026 Important Fedora
89

Fedora 43 Transmission 4.1.2 Clickjacking Fix CVE-2026-38978

4.1.2, fix for CVE-2026-38978. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-893c99f61c 2026-06-05 04:07:33.980067+00:00 -------------------------------------------------------------------------------- Name : transmission Product : Fedora 43 Version : 4.1.2 Release : 1.fc43 URL : http://www.transmissionbt.com Summary : A lightweight GTK+ BitTorrent client Description : Transmission is a free, lightweight BitTorrent client. It features a simple, intuitive interface on top on an efficient, cross-platform back-end. -------------------------------------------------------------------------------- Update Information: 4.1.2, fix for CVE-2026-38978 -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 3 2026 Gwyn Ciesla - 4.1.2-1 - 4.1.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2483871 - transmission-4.1.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2483871 [ 2 ] Bug #2484367 - CVE-2026-38978 transmission: Transmission: Clickjacking weakness in WebUI and RPC response paths [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2484367 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-893c99f61c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Transmission 4.1.2 for Fedora 43 addresses Clickjacking issues with CVE-2026-38978. Get installation instructions now!. Linux Update, BitTorrent Client, Fedora Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 05, 2026 Important Fedora
89

Fedora 44 Transmission Important Clickjacking Fix 2026-c032fac814

4.1.2, fix for CVE-2026-38978. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-c032fac814 2026-06-05 04:25:00.359120+00:00 -------------------------------------------------------------------------------- Name : transmission Product : Fedora 44 Version : 4.1.2 Release : 1.fc44 URL : http://www.transmissionbt.com Summary : A lightweight GTK+ BitTorrent client Description : Transmission is a free, lightweight BitTorrent client. It features a simple, intuitive interface on top on an efficient, cross-platform back-end. -------------------------------------------------------------------------------- Update Information: 4.1.2, fix for CVE-2026-38978 -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 3 2026 Gwyn Ciesla - 4.1.2-1 - 4.1.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2483871 - transmission-4.1.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2483871 [ 2 ] Bug #2484367 - CVE-2026-38978 transmission: Transmission: Clickjacking weakness in WebUI and RPC response paths [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2484367 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-c032fac814' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update transmission for Fedora 44 addresses important clickjacking issues for improved security.. Transmission clickjacking, Fedora 44 update, security advisory, BitTorrent client, software vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 05, 2026 Important Fedora
89

Fedora 43 Transmission Important Clickjacking Fix Advisory 2026-893c99f61c

4.1.2, fix for CVE-2026-38978. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-893c99f61c 2026-06-05 04:07:33.980067+00:00 -------------------------------------------------------------------------------- Name : transmission Product : Fedora 43 Version : 4.1.2 Release : 1.fc43 URL : http://www.transmissionbt.com Summary : A lightweight GTK+ BitTorrent client Description : Transmission is a free, lightweight BitTorrent client. It features a simple, intuitive interface on top on an efficient, cross-platform back-end. -------------------------------------------------------------------------------- Update Information: 4.1.2, fix for CVE-2026-38978 -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 3 2026 Gwyn Ciesla - 4.1.2-1 - 4.1.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2483871 - transmission-4.1.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2483871 [ 2 ] Bug #2484367 - CVE-2026-38978 transmission: Transmission: Clickjacking weakness in WebUI and RPC response paths [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2484367 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-893c99f61c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fixes important clickjacking issue in Transmission on Fedora 43, ensuring better usability and security.. Fedora security advisory, Transmission update, Clickjacking fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 05, 2026 Important Fedora
100

SUSE: 2025:01946-1 important: MozillaThunderbird security update

* bsc#1243353 Cross-References: * CVE-2025-5262 * CVE-2025-5263 . # Security update for MozillaThunderbird Announcement ID: SUSE-SU-2025:01946-1 Release Date: 2025-06-13T10:17:13Z Rating: important References: * bsc#1243353 Cross-References: * CVE-2025-5262 * CVE-2025-5263 * CVE-2025-5264 * CVE-2025-5265 * CVE-2025-5266 * CVE-2025-5267 * CVE-2025-5268 * CVE-2025-5269 CVSS scores: * CVE-2025-5262 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-5263 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2025-5263 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2025-5264 ( SUSE ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2025-5264 ( NVD ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2025-5265 ( SUSE ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2025-5265 ( NVD ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2025-5266 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-5266 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-5267 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-5267 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-5268 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-5268 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-5269 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-5269 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise WorkstationExtension 15 SP6 * SUSE Linux Enterprise Workstation Extension 15 SP7 * SUSE Package Hub 15 15-SP6 * SUSE Package Hub 15 15-SP7 An update that solves eight vulnerabilities can now be installed. ## Description: This update for MozillaThunderbird fixes the following issues: Update to Mozilla Thunderbird 128.11 (MFSA 2025-46, bsc#1243353): * CVE-2025-5262: Double-free in libvpx encoder (bmo#1962421) * CVE-2025-5263: Error handling for script execution was incorrectly isolated from web content (bmo#1960745) * CVE-2025-5264: Potential local code execution in "Copy as cURL" command (bmo#1950001) * CVE-2025-5265: Potential local code execution in "Copy as cURL" command (bmo#1962301) * CVE-2025-5266: Script element events leaked cross-origin resource status (bmo#1965628) * CVE-2025-5267: Clickjacking vulnerability could have led to leaking saved payment card details (bmo#1954137) * CVE-2025-5268: Memory safety bugs fixed in Firefox 139, Thunderbird 139, Firefox ESR 128.11, and Thunderbird 128.11 (bmo#1950136, bmo#1958121, bmo#1960499, bmo#1962634) * CVE-2025-5269: Memory safety bug fixed in Firefox ESR 128.11 and Thunderbird 128.11 (bmo#1924108) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-1946=1 * SUSE Linux Enterprise Workstation Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-WE-15-SP6-2025-1946=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2025-1946=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1946=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1946=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64les390x) * MozillaThunderbird-translations-common-128.11.0-150200.8.221.1 * MozillaThunderbird-translations-other-128.11.0-150200.8.221.1 * MozillaThunderbird-debugsource-128.11.0-150200.8.221.1 * MozillaThunderbird-128.11.0-150200.8.221.1 * MozillaThunderbird-debuginfo-128.11.0-150200.8.221.1 * SUSE Linux Enterprise Workstation Extension 15 SP6 (x86_64) * MozillaThunderbird-translations-common-128.11.0-150200.8.221.1 * MozillaThunderbird-translations-other-128.11.0-150200.8.221.1 * MozillaThunderbird-debugsource-128.11.0-150200.8.221.1 * MozillaThunderbird-128.11.0-150200.8.221.1 * MozillaThunderbird-debuginfo-128.11.0-150200.8.221.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * MozillaThunderbird-translations-common-128.11.0-150200.8.221.1 * MozillaThunderbird-translations-other-128.11.0-150200.8.221.1 * MozillaThunderbird-debugsource-128.11.0-150200.8.221.1 * MozillaThunderbird-128.11.0-150200.8.221.1 * MozillaThunderbird-debuginfo-128.11.0-150200.8.221.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * MozillaThunderbird-translations-common-128.11.0-150200.8.221.1 * MozillaThunderbird-translations-other-128.11.0-150200.8.221.1 * MozillaThunderbird-debugsource-128.11.0-150200.8.221.1 * MozillaThunderbird-128.11.0-150200.8.221.1 * MozillaThunderbird-debuginfo-128.11.0-150200.8.221.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x) * MozillaThunderbird-translations-common-128.11.0-150200.8.221.1 * MozillaThunderbird-translations-other-128.11.0-150200.8.221.1 * MozillaThunderbird-debugsource-128.11.0-150200.8.221.1 * MozillaThunderbird-128.11.0-150200.8.221.1 * MozillaThunderbird-debuginfo-128.11.0-150200.8.221.1 ## References: * https://www.suse.com/security/cve/CVE-2025-5262.html * https://www.suse.com/security/cve/CVE-2025-5263.html * https://www.suse.com/security/cve/CVE-2025-5264.html * https://www.suse.com/security/cve/CVE-2025-5265.html *https://www.suse.com/security/cve/CVE-2025-5266.html * https://www.suse.com/security/cve/CVE-2025-5267.html * https://www.suse.com/security/cve/CVE-2025-5268.html * https://www.suse.com/security/cve/CVE-2025-5269.html * https://bugzilla.suse.com/show_bug.cgi?id=1243353 . SUSE releases a crucial enhancement for MozillaThunderbird to tackle various security flaws and strengthen protection measures.. MozillaThunderbird security, SUSE updates, openSUSE vulnerabilities, important patching. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 13, 2025 Important SuSE
203

Mageia 9: 2024-0189 Critical: NSS & Firefox Security Issues

Arbitrary JavaScript execution in PDF.js. (CVE-2024-4367) IndexedDB files retained in private browsing mode. (CVE-2024-4767) Potential permissions request bypass via clickjacking. (CVE-2024-4768) Cross-origin responses could be distinguished between script and non-script content-types. (CVE-2024-4769) . MGASA-2024-0189 - Updated nss & firefox packages fix security vulnerabilities Publication date: 21 May 2024 URL: https://advisories.mageia.org/MGASA-2024-0189.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-4367, CVE-2024-4767, CVE-2024-4768, CVE-2024-4769, CVE-2024-4770, CVE-2024-4777 Arbitrary JavaScript execution in PDF.js. (CVE-2024-4367) IndexedDB files retained in private browsing mode. (CVE-2024-4767) Potential permissions request bypass via clickjacking. (CVE-2024-4768) Cross-origin responses could be distinguished between script and non-script content-types. (CVE-2024-4769) Use-after-free could occur when printing to PDF. (CVE-2024-4770) Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. (CVE-2024-4777) References: - https://bugs.mageia.org/show_bug.cgi?id=33211 - https://www.firefox.com/en-US/firefox/115.11.0/releasenotes/?redirect_source=mozilla-org - https://www.mozilla.org/en-US/security/advisories/mfsa2024-22/ - https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_100.html - https://www.cve.org/CVERecord?id=CVE-2024-4367 - https://www.cve.org/CVERecord?id=CVE-2024-4767 - https://www.cve.org/CVERecord?id=CVE-2024-4768 - https://www.cve.org/CVERecord?id=CVE-2024-4769 - https://www.cve.org/CVERecord?id=CVE-2024-4770 - https://www.cve.org/CVERecord?id=CVE-2024-4777 SRPMS: - 9/core/nss-3.100.0-1.mga9 - 9/core/firefox-115.11.0-1.mga9 - 9/core/firefox-l10n-115.11.0-1.mga9 . Mageia 2024-0190 addresses severe security flaws in openSSL & chrome. Safeguard against unauthorized access and phish attacks.. Mageia Security Advisory, NSS Updates, Firefox Updates, Security Patches, CSS Security Issues. . Severity:Critical. LinuxSecurity.com Team

Calendar%202 May 21, 2024 Critical Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200