Re: EMC Documentum Content Server: arbitrary code execution (incomplete fix in CVE-2015-4532)
Monthly Archives: August 2015
Bugtraq: Privilege escalation through RPC commands in EMC Documentum Content Server (incomplete fix in CVE-2015-4532)
Privilege escalation through RPC commands in EMC Documentum Content Server (incomplete fix in CVE-2015-4532)
Bugtraq: CVE-2015-3269 Apache Flex BlazeDS Insecure Xml Entity Expansion Vulnerability
CVE-2015-3269 Apache Flex BlazeDS Insecure Xml Entity Expansion Vulnerability
Bugtraq: [security bulletin] HPSBUX03400 SSRT102211 rev.1 – HP-UX Running BIND, Remote Denial of Service (DoS)
[security bulletin] HPSBUX03400 SSRT102211 rev.1 – HP-UX Running BIND, Remote Denial of Service (DoS)
Inside the Unpatched OS X Vulnerabilities
Italian researcher Luca Todesco explains how exploiting two vulnerabilities in OS X gain enable root access for a hacker. He won’t, however, say why he went public with details and exploit code before Apple patched.
RHSA-2015:1643-1: Moderate: kernel security and bug fix update
Red Hat Enterprise Linux: Updated kernel packages that fix one security issue and two bugs are now
available for Red Hat Enterprise Linux 6.4 Advanced Update Support.
Red Hat Product Security has rated this update as having Moderate security
impact. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available from the CVE link in the
References section.
CVE-2015-3636
CVE-2015-1830
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors.
CVE-2015-4298
Cisco Unified Web and E-Mail Interaction Manager 9.0(2) and 11.0(1) improperly performs authorization, which allows remote authenticated users to read or write to stored data via unspecified vectors, aka Bug ID CSCuo89056.
CVE-2015-4299
Cisco Unified Web and E-Mail Interaction Manager 9.0(2) improperly performs authorization, which allows remote authenticated users to remove default messaging-queue system folders via unspecified vectors, aka Bug ID CSCuo89046.
CVE-2015-4301
Cisco NX-OS on Nexus 9000 devices 11.1(1c) allows remote authenticated users to cause a denial of service (device hang) via large files that are copied to a device’s filesystem, aka Bug ID CSCuu77225.