Posted by Cláudio André on Nov 17
https://labs.integrity.pt/articles/google-aosp-email-app-html-injection-2/
1. Vulnerability Properties
*Title: *Google AOSP Email App HTML Injection
*CVE ID: PendingCVSSv3 Base Score: *6.3
(AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)
*Vendor: *Google
*Products:* AOSP Email App
*Advisory Release Date:* 16 November 2015
*Advisory URL:*https://labs.integrity.pt/advisories/google-aosp-email-app-html-injection/
*Credits: *Discovery by Cláudio André…
Adobe patched vulnerabilities in ColdFusion, LiveCycle Data Services and Premiere Clip for iOS.
Most applications, including Firefox, are not vulnerable to a pair of memory corruption vulnerabilities patched in the libpng PNG reference library.
Open-Xchange Guard version 2.0 suffers from a cross site scripting vulnerability.
Gentoo Linux Security Advisory 201511-2 – Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code. Versions less than 11.2.202.548 are affected.
Free WMA MP3 Converter version 1.8 suffers from a buffer overflow vulnerability.
Murgent CMS from 2015Q4 suffers from a remote SQL injection vulnerability.
LineNity WP premium theme suffers from a local file inclusion vulnerability.
Magento Bug Bounty #24 – Multiple CSRF Web Vulnerabilities
Murgent CMS – SQL Injection Vulnerability
Posts navigation
Software and Security Information