Unisphere Central versions prior to 4.0 suffer from a large amount of security vulnerabilities and an update has been released that includes a fix for an unvalidated redirect issue along with various embedded component vulnerabilities.
Monthly Archives: January 2015
Asus RT-N10 Plus Cross Site Scripting
Asus RT-N10 Plus with firmware version 2.1.1.1.70 suffers from a cross site scripting vulnerability.
VMware Security Advisory 2015-0002
VMware Security Advisory 2015-0002 – VMware vSphere Data Protection product update addresses a certificate validation vulnerability.
HP Security Bulletin HPSBOV03226 2
HP Security Bulletin HPSBOV03226 2 – Potential security vulnerabilities have been identified with the TCP/IP Services for OpenVMS BIND 9 Resolver. These vulnerabilities could be remotely exploited to cause a Denial of Service (DoS) and other vulnerabilities. NOTE: These vulnerabilities impact OpenVMS TCP/IP BIND servers only. No update is required for BIND clients. Revision 2 of this advisory.
Debian Security Advisory 3144-1
Debian Linux Security Advisory 3144-1 – Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in the execution of arbitrary code, information disclosure or denial of service.
Debian Security Advisory 3145-1
Debian Linux Security Advisory 3145-1 – Multiple vulnerabilities were discovered in Privoxy, a privacy enhancing HTTP proxy, which might result in denial of service.
Debian Security Advisory 3147-1
Debian Linux Security Advisory 3147-1 – Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in the execution of arbitrary code, information disclosure or denial of service.
Debian Security Advisory 3146-1
Debian Linux Security Advisory 3146-1 – Jakub Wilk discovered that in requests, an HTTP library for the Python language, authentication information was improperly handled when a redirect occurred. This would allow remote servers to obtain two Proxy-Authorization header (CVE-2014-1830), or netrc passwords from the Authorization header (CVE-2014-1829).
Symantec Encryption Management Server Remote Command Injection
Symantec Encryption Management Server versions prior to 3.2.0 MP6 suffers from a remote command injection vulnerability.
NPDS CMS Revolution-13 SQL Injection
NPDS CMS Revolution-13 suffers from a remote SQL injection vulnerability.