VeryPhoto version 3.0 suffers from a command injection vulnerability.
Monthly Archives: January 2015
Sim Editor 6.6 Buffer Overflow
Sim Editor version 6.6 stack-based buffer overflow exploit.
Facebook Mobile Parameter Tampering Bypass
Facebook Mobile allowed for a name change prior to the 60 day limit.
CatBot 0.4.2 SQL Injection
CatBot version 0.4.2 suffers from a remote SQL injection vulnerability.
Pandora FMS 5.1 SP1 Cross Site Scripting
Pandora FMS version 5.1 SP1 suffers from a persistent cross site scripting vulnerability in the SNMP editor.
Debian Security Advisory 3129-1
Debian Linux Security Advisory 3129-1 – Two vulnerabilities have been discovered in the RPM package manager.
Mandriva Linux Security Advisory 2015-027
Mandriva Linux Security Advisory 2015-027 – Multiple vulnerabilities has been found and corrected in the Linux kernel. The SCTP implementation in the Linux kernel before 3.17.4 allows remote attackers to cause a denial of service by triggering a large number of chunks in an association’s output queue, as demonstrated by ASCONF probes, related to net/sctp/inqueue.c and net/sctp/sm_statefuns.c. Various other issues have also been addressed. The updated packages provides a solution for these security issues.
CVE-2014-9602
libavcodec/xface.h in FFmpeg before 2.5.2 establishes certain digits and words array dimensions that do not satisfy a required mathematical relationship, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted X-Face image data.
CVE-2014-9603
The vmd_decode function in libavcodec/vmdvideo.c in FFmpeg before 2.5.2 does not validate the relationship between a certain length value and the frame width, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Sierra VMD video data.
CVE-2014-9604
libavcodec/utvideodec.c in FFmpeg before 2.5.2 does not check for a zero value of a slice height, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Ut Video data, related to the (1) restore_median and (2) restore_median_il functions.