Skip to content
Threat Feed

CPE

Cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

4 briefs RSS
high threat

UNC3569 Exploitation of Sogou Input Method to Deploy GRAYRABBIT Backdoor

UNC3569 exploited a command-line argument injection flaw in Sogou Input Method to trigger an insecure Chromium component and execute the GRAYRABBIT backdoor.

Sogou Input Method UNC3569 backdoor exploitation cve-2026-51990 grayrabbit
1r 4t 1c 6i
medium advisory

Expat XML Parsing Library Integer Overflow Vulnerabilities

The Expat XML parsing library is affected by integer overflow vulnerabilities (CVE-2022-25235, CVE-2022-25236) that can be exploited by a local attacker to achieve arbitrary code execution or denial of service.

expat
1t 2c
critical advisory

Vulnerabilities in Nokogiri Vendored libxml2 and libxslt Libraries

Nokogiri versions prior to 1.13.2 bundle vulnerable libxml2 2.9.12 and libxslt 1.1.34 libraries, exposing applications to denial of service, memory disclosure, and potential code execution.

Nokogiri +2 vulnerability memory-corruption libxslt
3c
high advisory

HAProxy CVE-2021-40346 Integer Overflow Leading to HTTP Request Smuggling and ACL Bypass

A critical integer overflow vulnerability, CVE-2021-40346, in HAProxy's `htx_add_header()` function allows unauthenticated attackers to bypass access control rules by crafting HTTP requests with specific header name lengths, leading to HTTP request smuggling and unauthorized access to backend paths, for which a public exploit is available.

HAProxy +4 integer-overflow http-smuggling acl-bypass webserver
2t 1c