Posted by Shawn on Dec 08
Hi Agostino,
I don’t think this issue impact on Grsecurity/PaX, which
Hardened-Gentoo is using PaX.
Posted by Shawn on Dec 08
Hi Agostino,
I don’t think this issue impact on Grsecurity/PaX, which
Hardened-Gentoo is using PaX.
Posted by Jeffrey Walton on Dec 08
Now might be a good time to reflect on the past, and recall Sony has
had at least 22 breaches in the past.
Thanks to Security Curmudgeon for putting this list together:
http://attrition.org/security/rant/sony_aka_sownage.html.
Posted by stephen () averagesecurityguy info on Dec 08
Coinbase User Enumeration
=========================
The Coinbase web site allows user enumeration, which would normally not be a big deal, but in this case, we are able to
enumerate a users username, “real name”, and an MD5 hash of the user’s email address. Using a large list of email
addresses and a tool like hashcat it is possible to determine the email address for many of these users. Keep in mind
that the real name is user…
Adobe’s get3.adobe.com site suffered from a reflective cross site scripting vulnerability.
Flat Calendar version 1.1 suffers from an unauthenticated html injection vulnerability that allows for cross site scripting attacks.
PBBoard CMS suffers from a persistent cross site scripting vulnerability.
nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain privileges to conduct “virtual host confusion” attacks. (CVSS:4.3) (Last Update:2014-12-08)
Several vulnerabilities have been discovered in the Linux kernel that
may lead to a denial of service or privilege escalation:
It was discovered that BIND, a DNS server, is prone to a denial of
service vulnerability.
Mozilla Firefox/Thunderbird CVE-2014-1594 Security Vulnerability