The decompose function in platform/transforms/TransformationMatrix.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not verify that a matrix inversion succeeded, which allows remote attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted web site.
Monthly Archives: September 2015
CVE-2015-6583
Google Chrome before 45.0.2454.85 does not display a location bar for a hosted app’s window after navigation away from the installation site, which might make it easier for remote attackers to spoof content via a crafted app, related to browser.cc and hosted_app_browser_controller.cc.
Cisco Security Advisory 20150902-cimcs
Cisco Security Advisory – Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director contain a remote file overwrite vulnerability that could allow an unauthenticated, remote attacker to overwrite arbitrary system files, resulting in system instability or a denial of service (DoS) condition. Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
Debian Security Advisory 3349-1
Debian Linux Security Advisory 3349-1 – Several vulnerabilities were discovered in qemu-kvm, a full virtualization solution on x86 hardware.
Debian Security Advisory 3348-1
Debian Linux Security Advisory 3348-1 – Several vulnerabilities were discovered in qemu, a fast processor emulator.
Ubuntu Security Notice USN-2728-1
Ubuntu Security Notice 2728-1 – Hanno Boeck discovered that Bind incorrectly handled certain malformed keys when configured to perform DNSSEC validation. A remote attacker could use this issue with specially crafted zone data to cause Bind to crash, resulting in a denial of service.
WatchGuard Technologies Recognized as a Visionary in Gartner's Magic Quadrant for the Unified Threat Management (UTM) Market
Bugtraq: Checkmarx CxQL Sandbox bypass (CVE-2014-8778)
Checkmarx CxQL Sandbox bypass (CVE-2014-8778)
Bugtraq: Zhone ADSL2+ 4P Bridge & Router (Broadcom) – Multiple Vulnerabilities
Zhone ADSL2+ 4P Bridge & Router (Broadcom) – Multiple Vulnerabilities
Bugtraq: ESA-2015-144: EMC Documentum Content Server Privilege Escalation Vulnerability
ESA-2015-144: EMC Documentum Content Server Privilege Escalation Vulnerability





