Pligg CMS 2.0.2 – Stored XSS
Monthly Archives: April 2015
Bugtraq: Avsarsoft Matbaa Script – Multiple Vulnerabilities
Avsarsoft Matbaa Script – Multiple Vulnerabilities
Bugtraq: 4k ULTRA HIGH DEFINITION Satellite Security Research – DVB-S2X Security Evaluation Draft Notes
4k ULTRA HIGH DEFINITION Satellite Security Research – DVB-S2X Security Evaluation Draft Notes
Ubuntu usb-creator 0.2.x Local Privilege Escalation
Ubuntu usb-creator version 0.2.x suffers from a local privilege escalation vulnerability.
Red Hat Security Advisory 2015-0884-01
Red Hat Security Advisory 2015-0884-01 – The novnc package provides a VNC client that uses HTML5 and includes encryption support. It was discovered that noVNC did not properly set the ‘secure’ flag when issuing cookies. An attacker could use this flaw to intercept cookies via a man-in-the-middle attack. All novnc users are advised to upgrade to this updated package, which corrects this issue.
MIMEDefang Email Scanner 2.78
MIMEDefang is a flexible MIME email scanner designed to protect Windows clients from viruses. Includes the ability to do many other kinds of mail processing, such as replacing parts of messages with URLs. It can alter or delete various parts of a MIME message according to a very flexible configuration file. It can also bounce messages with unacceptable attachments. MIMEDefang works with the Sendmail 8.11 and newer “Milter” API, which makes it more flexible and efficient than procmail-based approaches.
Ubuntu Security Notice USN-2577-1
Ubuntu Security Notice 2577-1 – It was discovered that wpa_supplicant incorrectly handled SSID information when creating or updating P2P peer entries. A remote attacker could use this issue to cause wpa_supplicant to crash, resulting in a denial of service, expose memory contents, or possibly execute arbitrary code.
Honeywell XLWEB SCADA Path Traversal
Honeywell XLWEB SCADA controller suffers from a remote path traversal vulnerability that allows for remote code execution.
RHEA-2015:0875-1: devtoolset-3-elfutils bug fix and enhancement update
Red Hat Enterprise Linux: Updated devtoolset-3-elfutils packages that fix several bugs and add various
enhancements are now available for Red Hat Developer Toolset 3.1.
RHEA-2015:0874-1: devtoolset-3-memstomp enhancement update
Red Hat Enterprise Linux: Updated devtoolset-3-memstomp packages that add one enhancement are now
available for Red Hat Developer Toolset 3.1.