Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 598
Alerts This Week
Warning Icon 1 598

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 18 articles for you...
172

Ubuntu 18.04 16.04 HtmlUnit Important Remote Code Exec USN-8220-1

HtmlUnit could be made to run programs as your login if it opened a malicious website.. ========================================================================== Ubuntu Security Notice USN-8220-1 May 05, 2026 htmlunit vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: HtmlUnit could be made to run programs as your login if it opened a malicious website. Software Description: - htmlunit: headless web browser written in Java Details: It was discovered that HtmlUnit was vulnerable to remote code execution via XSLT when browsing an attacker-controlled webpage. An attacker could possibly use this issue to execute arbitrary code in the context of the application using HtmlUnit. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS libhtmlunit-java 2.8-3ubuntu1+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libhtmlunit-java 2.8-1ubuntu2.1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8220-1 CVE-2023-49093 . HtmlUnit in Ubuntu could execute code as your login when accessing malicious sites. Immediate updates are required.. HtmlUnit Remote Code Execution Ubuntu Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 07, 2026 Important Ubuntu
172

Ubuntu 20.04, 18.04 LTS USN-5581-1: Firefox Denial Of Service Risk

Firefox could be made to crash or run programs as your login if it opened a malicious website.. =========================================================================Ubuntu Security Notice USN-5581-1 August 24, 2022 firefox vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Firefox could be made to crash or run programs as your login if it opened a malicious website. Software Description: - firefox: Mozilla Open Source web browser Details: Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, spoof the contents of the addressbar, bypass security restrictions, or execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: firefox 104.0+build3-0ubuntu0.20.04.1 Ubuntu 18.04 LTS: firefox 104.0+build3-0ubuntu0.18.04.1 After a standard system update you need to restart Firefox to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5581-1 CVE-2022-38472, CVE-2022-38473, CVE-2022-38475, CVE-2022-38477, CVE-2022-38478 Package Information: https://launchpad.net/ubuntu/+source/firefox/104.0+build3-0ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/firefox/104.0+build3-0ubuntu0.18.04.1 . Various Chrome vulnerabilities might result in operating system failure or allow rogue applications to run through harmful web pages.. Firefox vulnerabilities, Ubuntu security notice, Mozilla Firefox. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 24, 2022 Important Ubuntu
172

Ubuntu 21.10 USN-5411-1: Critical firefox crash vulnerabilities identified

Firefox could be made to crash or run programs as your login if it opened a malicious website.. =========================================================================Ubuntu Security Notice USN-5411-1 May 11, 2022 firefox vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Firefox could be made to crash or run programs as your login if it opened a malicious website. Software Description: - firefox: Mozilla Open Source web browser Details: Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, spoof the browser UI, bypass permission prompts, obtain sensitive information, bypass security restrictions, or execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: firefox 100.0+build2-0ubuntu0.21.10.1 Ubuntu 20.04 LTS: firefox 100.0+build2-0ubuntu0.20.04.1 Ubuntu 18.04 LTS: firefox 100.0+build2-0ubuntu0.18.04.1 After a standard system update you need to restart Firefox to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5411-1 CVE-2022-29909, CVE-2022-29911, CVE-2022-29912, CVE-2022-29914, CVE-2022-29915, CVE-2022-29916, CVE-2022-29917, CVE-2022-29918 Package Information: https://launchpad.net/ubuntu/+source/firefox/100.0+build2-0ubuntu0.21.10.1 https://launchpad.net/ubuntu/+source/firefox/100.0+build2-0ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/firefox/100.0+build2-0ubuntu0.18.04.1 . Ubuntu Security Notice USN-5411-1 addresses critical security flaws in Firefox that could lead to application crashes or the execution ofmalicious code.. firefox Security, Ubuntu Vulnerabilities, Firefox Crash, Malicious Websites. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 11, 2022 Critical Ubuntu
172

Ubuntu 21.10 USN-5370-1 Moderate: Firefox Crash From Malicious Site

Firefox could be made to crash or run programs as your login if it opened a malicious website.. =========================================================================Ubuntu Security Notice USN-5370-1 April 07, 2022 firefox vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Firefox could be made to crash or run programs as your login if it opened a malicious website. Software Description: - firefox: Mozilla Open Source web browser Details: Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, execute script unexpectedly, obtain sensitive information, conduct spoofing attacks, or execute arbitrary code. (CVE-2022-1097, CVE-2022-24713, CVE-2022-28281, CVE-2022-28282, CVE-2022-28284, CVE-2022-28285, CVE-2022-28286, CVE-2022-28288, CVE-2022-28289) A security issue was discovered with the sourceMapURL feature of devtools. An attacker could potentially exploit this to include local files that should have been inaccessible. (CVE-2022-28283) It was discovered that selecting text caused Firefox to crash in some circumstances. An attacker could potentially exploit this to cause a denial of service. (CVE-2022-28287) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: firefox 99.0+build2-0ubuntu0.21.10.2 Ubuntu 20.04 LTS: firefox 99.0+build2-0ubuntu0.20.04.2 Ubuntu 18.04 LTS: firefox 99.0+build2-0ubuntu0.18.04.2 After a standard system update you need to restart Firefox to make all the necessary changes. References: CVE-2022-1097, CVE-2022-24713, CVE-2022-28281, CVE-2022-28282, CVE-2022-28283, CVE-2022-28284, CVE-2022-28285, CVE-2022-28286, CVE-2022-28287, CVE-2022-28288, CVE-2022-28289 Package Information: https://launchpad.net/ubuntu/+source/firefox/99.0+build2-0ubuntu0.21.10.2 https://launchpad.net/ubuntu/+source/firefox/99.0+build2-0ubuntu0.20.04.2 https://launchpad.net/ubuntu/+source/firefox/99.0+build2-0ubuntu0.18.04.2 . Ubuntu's Mozilla Firefox could face risks of crashes and potential execution of harmful code through compromised webpages.. browser exploits, Ubuntu security advisories, Firefox security issues. . LinuxSecurity.com Team

Calendar%202 Apr 07, 2022 Ubuntu
87

Debian DSA-5114-1: Critical Fix For Chromium Code Execution Risk

Sergei Glazunov discovered a security issue in Chromium, which could result in the execution of arbitrary code if a malicious website is visited. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5114-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso April 07, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : chromium CVE ID : CVE-2022-1232 Sergei Glazunov discovered a security issue in Chromium, which could result in the execution of arbitrary code if a malicious website is visited. For the stable distribution (bullseye), this problem has been fixed in version 100.0.4896.75-1~deb11u1. We recommend that you upgrade your chromium packages. For the detailed security status of chromium please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/chromium Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Notice DSA-5114-1 announces a remedy for a major vulnerability in Chromium that could enable unauthorized code execution when users visit harmful websites.. Chromium Security Update, Debian Security Advisory, Code Execution Risk. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 07, 2022 Critical Debian
87

Debian DSA-5110-1 Moderate: Chromium Code Execution Threat

A security issue was discovered in Chromium, which could result in the execution of arbitrary code if a malicious website is visited. For the stable distribution (bullseye), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5110-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff March 28, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : chromium CVE ID : CVE-2022-1096 A security issue was discovered in Chromium, which could result in the execution of arbitrary code if a malicious website is visited. For the stable distribution (bullseye), this problem has been fixed in version 99.0.4844.84-1~deb11u1. We recommend that you upgrade your chromium packages. For the detailed security status of chromium please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/chromium Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Uncover a fresh security notice for Chromium on Debian that tackles a vital vulnerability allowing code execution from harmful web pages.. Debian Security Advisory, Chromium Security Update, Code Execution Threat. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 28, 2022 Important Debian
172

Ubuntu 21.10 USN-5284-1 Critical: Firefox Denial Of Service Threat

Firefox could be made to crash or run programs as your login if it opened a malicious website.. =========================================================================Ubuntu Security Notice USN-5284-1 February 14, 2022 firefox vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Firefox could be made to crash or run programs as your login if it opened a malicious website. Software Description: - firefox: Mozilla Open Source web browser Details: Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, bypass security restrictions, obtain sensitive information, or execute arbitrary code. (CVE-2022-0511, CVE-2022-22755, CVE-2022-22759, CVE-2022-22760, CVE-2022-22761, CVE-2022-22764) It was discovered that extensions of a particular type could auto-update themselves and bypass the prompt that requests permissions. If a user were tricked into installing a specially crafted extension, an attacker could potentially exploit this to bypass security restrictions. (CVE-2022-22754) It was discovered that dragging and dropping an image into a folder could result in it being marked as executable. If a user were tricked into dragging and dropping a specially crafted image, an attacker could potentially exploit this to execute arbitrary code. (CVE-2022-22756) It was discovered that Remote Agent, used in WebDriver, did not validate Host or Origin headers. If a user were tricked into opening a specially crafted website with WebDriver enabled, an attacker could potentially exploit this to connect back to the user's browser in order to control it. (CVE-2022-22757) Update instructions: The problem can be corrected by updating your system to the following packageversions: Ubuntu 21.10: firefox 97.0+build2-0ubuntu0.21.10.1 Ubuntu 20.04 LTS: firefox 97.0+build2-0ubuntu0.20.04.1 Ubuntu 18.04 LTS: firefox 97.0+build2-0ubuntu0.18.04.1 After a standard system update you need to restart Firefox to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5284-1 CVE-2022-0511, CVE-2022-22754, CVE-2022-22755, CVE-2022-22756, CVE-2022-22757, CVE-2022-22759, CVE-2022-22760, CVE-2022-22761, CVE-2022-22764 Package Information: https://launchpad.net/ubuntu/+source/firefox/97.0+build2-0ubuntu0.21.10.1 https://launchpad.net/ubuntu/+source/firefox/97.0+build2-0ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/firefox/97.0+build2-0ubuntu0.18.04.1 . Uncover the vital security vulnerabilities of Firefox on Ubuntu and find out how to defend against them through prompt updates.. Firefox Security Issues, Ubuntu 21.10 Update, Browser Vulnerabilities, Software Threats. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 14, 2022 Critical Ubuntu
172

Ubuntu 21.10: 5131-1 Critical: Firefox Denial of Service Exploits

Firefox could be made to crash or run programs as your login if it opened a malicious website.. =========================================================================Ubuntu Security Notice USN-5131-1 November 03, 2021 firefox vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 21.04 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Firefox could be made to crash or run programs as your login if it opened a malicious website. Software Description: - firefox: Mozilla Open Source web browser Details: Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, bypass security restrictions, spoof the browser UI, confuse the user, conduct phishing attacks, or execute arbitrary code. (CVE-2021-38503, CVE-2021-38504, CVE-2021-38506, CVE-2021-38507, CVE-2021-38508, CVE-2021-38509) It was discovered that the 'Copy Image Link' context menu action would copy the final image URL after redirects. If a user were tricked into copying and pasting a link for an embedded image that triggered authentication flows back to the page, an attacker could potentially exploit this to steal authentication tokens. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: firefox 94.0+build3-0ubuntu0.21.10.1 Ubuntu 21.04: firefox 94.0+build3-0ubuntu0.21.04.1 Ubuntu 20.04 LTS: firefox 94.0+build3-0ubuntu0.20.04.1 Ubuntu 18.04 LTS: firefox 94.0+build3-0ubuntu0.18.04.1 After a standard system update you need to restart Firefox to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5131-1 CVE-2021-38503,CVE-2021-38504, CVE-2021-38506, CVE-2021-38507, CVE-2021-38508, CVE-2021-38509 Package Information: https://launchpad.net/ubuntu/+source/firefox/94.0+build3-0ubuntu0.21.10.1 https://launchpad.net/ubuntu/+source/firefox/94.0+build3-0ubuntu0.21.04.1 https://launchpad.net/ubuntu/+source/firefox/94.0+build3-0ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/firefox/94.0+build3-0ubuntu0.18.04.1 . The latest Ubuntu Security Announcement USN-5131-1 highlights security flaws in Firefox which could be leveraged by malicious websites.. Firefox Exploit, Ubuntu Security, Mozilla Issue, Security Update, Denial of Service. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 03, 2021 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200