Big remote form function payloads can cause the Node process to crash. Doing this repeatedly can cause DoS.
### Am I affected You are affected if all of the following hold: - You run a `better-auth` version below 1.6.22, or a `1.7.0-beta` below `1.7.0-beta.10`. - You enable the magic-link plugin or the email-OTP plugin. - You also enable email and password sign-up with open registration. - An account can exist at an address before its owner first signs in with the passwordless flow. ### Summary An attacker can keep password access to a victim's account after the victim starts using it. The attack
### Am I affected? You are affected if all of these are true: - You use `@better-auth/stripe` from version 1.4.11 up to a patched version below. This covers the stable line through 1.6.20 and every 1.7.0 beta through 1.7.0-beta.9. - The Stripe plugin has subscriptions turned on (`subscription.enabled: true`). - Organization subscriptions are turned on (`organization.enabled: true`) and you have set an `authorizeReference` callback. - A user can join more than one org. So a user can be a member
### Am I affected? You are affected if your application registers the `@better-auth/scim` plugin and lets authenticated users generate SCIM tokens. The default `canGenerateToken` policy was affected, and custom policies were affected when they did not reject provider IDs already used by other account providers. The provider-ID collision issue additionally requires SSO, SAML, OIDC, generic OAuth, or social providers whose account rows use custom provider IDs, plus existing account rows under tho
Running an X11 import with a crafted window title can result in a heap buffer over-write.
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary connection records from the `wp_ea_connections` table, disrupting the plugin's core booking functionality.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services Website Template allows Reflected XSS. This issue affects Website Template: before v2.
An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.
A memory leak will occur in the ICON decoder when an allocation fails.
When an allocation fails in the VIFF encoder a memory leak will occus.
A memory leak will occur in the MIFF encoder when an allocation fails.
A memory leak will occur when a blob cannot be opened in the YUV decoder.
When an allocation fails in the TIFF encoder a small memory leak will occur.
When a blob can not be opened a memory leak will occur when encoding a JNG file.
When a specific operation fails in the hough lines operation a small memory leak will occur.
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
When a memory allocation fails inside the FormatMagickCaption method a dangling pointer still points to the freed memory.
When the freetype initialization fails the method does not exit and uses memory that was freed.