SQL injection vulnerability in the “the_search_function” function in cardoza_ajax_search.php in the AJAX Post Search (cardoza-ajax-search) plugin before 1.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the srch_txt parameter in a “the_search_text” action to wp-admin/admin-ajax.php.
Monthly Archives: January 2015
CVE-2012-6684
Cross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9 for Ruby and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI.
CVE-2014-9473
Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the cf_uploadfile2[] parameter, then accessing the file via a direct request to the file in the default upload directory.
DSA-3122 curl – security update
Andrey Labunets of Facebook discovered that cURL, an URL transfer
library, fails to properly handle URLs with embedded end-of-line
characters. An attacker able to make an application using libcurl to
access a specially crafted URL via an HTTP proxy could use this flaw to
do additional requests in a way that was not intended, or insert
additional request headers into the request.
DSA-3121 file – security update
Multiple security issues have been found in file, a tool/library to
determine a file type. Processing a malformed file could result in
denial of service. Most of the changes are related to parsing ELF
files.
Vuln: Schneider Electric ProClima CVE-2014-8511 Remote Buffer Overflow Vulnerability
Schneider Electric ProClima CVE-2014-8511 Remote Buffer Overflow Vulnerability
Vuln: Schneider Electric ProClima CVE-2014-9188 Remote Buffer Overflow Vulnerability
Schneider Electric ProClima CVE-2014-9188 Remote Buffer Overflow Vulnerability
Vuln: Schneider Electric ProClima CVE-2014-8512 Remote Buffer Overflow Vulnerability
Schneider Electric ProClima CVE-2014-8512 Remote Buffer Overflow Vulnerability
Vuln: Schneider Electric ProClima CVE-2014-8514 Remote Buffer Overflow Vulnerability
Schneider Electric ProClima CVE-2014-8514 Remote Buffer Overflow Vulnerability
Fedora 21 Security Update: xen-4.4.1-12.fc21
Resolved Bugs
1179221 – CVE-2015-0361 xen: kernel: xen crash due to use after free on hvm guest teardown (xsa116) [fedora-all]
1176097 – CVE-2015-0361 kernel: xen crash due to use after free on hvm guest teardown (xsa116)<br
xen crash due to use after free on hvm guest teardown [XSA-116,
CVE-2015-0361]