Multiple cross-site scripting (XSS) vulnerabilities in (1) mainpage.jsp and (2) GetImageServlet.img in IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Monthly Archives: January 2015
CVE-2014-8894
Open redirect vulnerability in IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via the out parameter.
CVE-2014-8895
IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allows remote attackers to bypass intended access restrictions and read the image files of arbitrary users via a crafted URL.
Vulnerabilities in HP LaserJet
Posted by MustLive on Jan 29
Hello list!
There are Information Leakage and Insufficient Authorization vulnerabilities
in HP LaserJet. Vulnerabilities are in control panel of HP network MFP and
printers. Earlier I informed HP about it.
You can read articles in BBC
(http://seclists.org/fulldisclosure/2014/Dec/98) and Global Voices
(http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/2014-December/009067.html)
about my attacks on network printers of…
DSA-3144 openjdk-7 – security update
Several vulnerabilities have been discovered in OpenJDK, an
implementation of the Oracle Java platform, resulting in the execution
of arbitrary code, information disclosure or denial of service.
Vuln: Linux Kernel 'ISOFS' Deadlock Local Denial of Service Vulnerability
Linux Kernel ‘ISOFS’ Deadlock Local Denial of Service Vulnerability
Vuln: Linux Kernel 'ISOFS' Stack-Based Buffer Overflow Vulnerability
Linux Kernel ‘ISOFS’ Stack-Based Buffer Overflow Vulnerability
Vuln: Linux Kernel 'shmem.c' CVE-2014-4171 Local Denial of Service Vulnerability
Linux Kernel ‘shmem.c’ CVE-2014-4171 Local Denial of Service Vulnerability
Vuln: Linux Kernel 'SMB2_tcon' NULL Pointer Dereference Denial of Service Vulnerability
Linux Kernel ‘SMB2_tcon’ NULL Pointer Dereference Denial of Service Vulnerability
AST-2015-002: Mitigation for libcURL HTTP request injection vulnerability
Posted by Asterisk Security Team on Jan 28
Asterisk Project Security Advisory – AST-2015-002
Product Asterisk
Summary Mitigation for libcURL HTTP request injection
vulnerability
Nature of Advisory HTTP request injection
Susceptibility Remote Authenticated Sessions…