BisonWare FTP Server version 3.5 buffer overflow proof of concept exploit for Windows XP SP3.
Monthly Archives: May 2015
WordPress Contact Form To Email Plugin CSRF / XSS
WordPress Contact Form To Email Plugin suffers from cross site request forgery and cross site scripting vulnerabilities.
Webfactory N&P CMS Arbitrary File Upload
Webfactory N&P CMS suffers from an arbitrary file upload vulnerability. Note that this advisory has site-specific information.
Re: Concrete5 Security Advisory – Multiple XSS Vulnerabilities – CVE-2015-2250
Posted by Scott Arciszewski on May 14
I’m honestly surprised it took their team two months to fix this. I’ve
previously reported issues via HackerOne and they were on it within a day.
If anyone else is thinking about whitehatting up Concrete5, you might get a
faster response if you go through the HackerOne platform. Also, they’re
friendly and won’t pull a Daniel Kerr move on you if you tell them their
code is Swiss cheese. Speaking from experience here.
Bugtraq: Cisco Security Advisory: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco Security Advisory: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Bugtraq: [SECURITY] [DSA 3259-1] qemu security update
[SECURITY] [DSA 3259-1] qemu security update
Bugtraq: [CORE-2015-0009] – SAP LZC/LZH Compression Multiple Vulnerabilities
[CORE-2015-0009] – SAP LZC/LZH Compression Multiple Vulnerabilities
Bugtraq: [SECURITY] [DSA 3260-1] iceweasel security update
[SECURITY] [DSA 3260-1] iceweasel security update
Debian Security Advisory 3260-1
Debian Linux Security Advisory 3260-1 – Multiple security issues have been found in Iceweasel, Debian’s version buffer overflows and use-after-frees may lead to the execution of arbitrary code, privilege escalation or denial of service.
Ubuntu Security Notice USN-2602-1
Ubuntu Security Notice 2602-1 – Jesse Ruderman, Mats Palmgren, Byron Campen, Steve Fink, Gary Kwong, Andrew McCreight, Christian Holler, Jon Coppeard, and Milan Sreckovic discovered multiple memory safety issues in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. Atte Kettunen discovered a buffer overflow during the rendering of SVG content with certain CSS properties in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. Various other issues were also addressed.