CVE-2014-8802

The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.

CVE-2014-9623

OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quote and cause a denial of service (disk consumption) by deleting an image in the saving state.

CVE-2014-9638

oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero.

CVE-2014-9639

Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.

CVE-2015-1176

Cross-site scripting (XSS) vulnerability in upload/scp/tickets.php in osTicket before 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the status parameter in a search action.

CVE-2015-1180

Cross-site scripting (XSS) vulnerability in the Web Reports in EventSentry 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the pageId parameter to networktile/bullet.

CVE-2015-1200

Race condition in pxz 4.999.99 Beta 3 uses weak file permissions for the output file when compressing a file before changing the permission to match the original file, which allows local users to bypass the intended access restrictions.

CVE-2015-1347

Cross-site scripting (XSS) vulnerability in client.inc.php in osTicket before 1.9.5.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

CESA-2015:0074 Important CentOS 7 jasper SecurityUpdate

CentOS Errata and Security Advisory 2015:0074 Important

Upstream details at : https://rhn.redhat.com/errata/RHSA-2015-0074.html

The following updated files have been uploaded and are currently 
syncing to the mirrors: ( sha256sum Filename ) 

x86_64:
5b88566c2ddeadebd75404b5c572a7025b4c89f322a43701bd1db8294685d916  jasper-1.900.1-26.el7_0.3.x86_64.rpm
cb9bc4503d074241ba6fe951f85903084422a23dd65407a7ddd76af60e2bb93b  jasper-devel-1.900.1-26.el7_0.3.i686.rpm
e63daafdff55024ce4f9452433e61eb43c86cbb56b563f20d70545a1bd54afcf  jasper-devel-1.900.1-26.el7_0.3.x86_64.rpm
4b81e3e4c62e0d3693e0967515125e0b2438874a235dfc6f902a49c2be4330df  jasper-libs-1.900.1-26.el7_0.3.i686.rpm
9c513640ff30310e1d970475380243698f0ecaa9471124113b88f6d29fddfa70  jasper-libs-1.900.1-26.el7_0.3.x86_64.rpm
b7e708b3c4e49933f43bcd7c32adfb03d50004c55cf326514d2f5b08daae3ae8  jasper-utils-1.900.1-26.el7_0.3.x86_64.rpm

Source:
ccdfae3a689ce539c3d93553f2818da2e91e66e2ad937620922c6dad2dd7b765  jasper-1.900.1-26.el7_0.3.src.rpm