The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.
Monthly Archives: January 2015
CVE-2014-9623
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quote and cause a denial of service (disk consumption) by deleting an image in the saving state.
CVE-2014-9638
oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero.
CVE-2014-9639
Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.
CVE-2014-9640
oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file.
CVE-2015-1176
Cross-site scripting (XSS) vulnerability in upload/scp/tickets.php in osTicket before 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the status parameter in a search action.
CVE-2015-1180
Cross-site scripting (XSS) vulnerability in the Web Reports in EventSentry 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the pageId parameter to networktile/bullet.
CVE-2015-1200
Race condition in pxz 4.999.99 Beta 3 uses weak file permissions for the output file when compressing a file before changing the permission to match the original file, which allows local users to bypass the intended access restrictions.
CVE-2015-1347
Cross-site scripting (XSS) vulnerability in client.inc.php in osTicket before 1.9.5.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
CESA-2015:0074 Important CentOS 7 jasper SecurityUpdate
CentOS Errata and Security Advisory 2015:0074 Important Upstream details at : https://rhn.redhat.com/errata/RHSA-2015-0074.html The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: 5b88566c2ddeadebd75404b5c572a7025b4c89f322a43701bd1db8294685d916 jasper-1.900.1-26.el7_0.3.x86_64.rpm cb9bc4503d074241ba6fe951f85903084422a23dd65407a7ddd76af60e2bb93b jasper-devel-1.900.1-26.el7_0.3.i686.rpm e63daafdff55024ce4f9452433e61eb43c86cbb56b563f20d70545a1bd54afcf jasper-devel-1.900.1-26.el7_0.3.x86_64.rpm 4b81e3e4c62e0d3693e0967515125e0b2438874a235dfc6f902a49c2be4330df jasper-libs-1.900.1-26.el7_0.3.i686.rpm 9c513640ff30310e1d970475380243698f0ecaa9471124113b88f6d29fddfa70 jasper-libs-1.900.1-26.el7_0.3.x86_64.rpm b7e708b3c4e49933f43bcd7c32adfb03d50004c55cf326514d2f5b08daae3ae8 jasper-utils-1.900.1-26.el7_0.3.x86_64.rpm Source: ccdfae3a689ce539c3d93553f2818da2e91e66e2ad937620922c6dad2dd7b765 jasper-1.900.1-26.el7_0.3.src.rpm