This Microsoft bulletin summary lists security advisories released or updated on January 9 and 10, 2018.
045553410bb987358a34fa14b7004d3551e152b4ba41d0d52e768bdacf1c5eb2
Gentoo Linux Security Advisory 201801-13 - Multiple vulnerabilities have been found in TigerVNC, the worst of which may lead to arbitrary code execution. Versions less than 1.8.0 are affected.
c2d4767acb8b67851054ab3f12d2a5d768e55e88325493134fe5e51c65c6693e
Gentoo Linux Security Advisory 201801-12 - Multiple vulnerabilities have been found in icoutils, the worst of which may lead to arbitrary code execution. Versions less than 0.32.0 are affected.
df95fe98e9bba0805f73448c40206703d1d5d3c62be7486348ec1726aed13366
Gentoo Linux Security Advisory 201801-11 - A vulnerability in PySAML2 might allow remote attackers to bypass authentication. Versions less than 4.5.0 are affected.
43c4437d78a00aff91fda3cd1bc4b2cd22f0017ccf180eb356f01fd5690fd8cf
Ubuntu Security Notice 3531-1 - It was discovered that microprocessors utilizing speculative execution and branch prediction may allow unauthorized memory reads via sidechannel attacks. This flaw is known as Spectre. A local attacker could use this to expose sensitive information, including kernel memory. This update provides the microcode updates required for the corresponding Linux kernel updates.
7c9b81a120a8434f1f7261103896025df431f67925c0c995b5477bac5165f14d
Ubuntu Security Notice 3530-1 - It was discovered that speculative execution performed by modern CPUs could leak information through a timing side-channel attack, and that this could be exploited in web browser JavaScript engines. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to obtain sensitive information from other domains, bypassing same-origin restrictions.
8f96dcbac2259c3601a1033069b3405baa33d4754a54380112435c94bd351a44
ALLMediaServer version 0.95 stack buffer overflow exploit with DEP bypass on Windows 7 x64.
b32e6037a31b7fad537466c0749084442cb4b6e30ae14d2312537291ebb2d01f