Cross-site request forgery (CSRF) vulnerability in the com_templates component in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. (CVSS:6.8) (Last Update:2015-12-17)
Monthly Archives: December 2015
CVE-2015-8565
Directory traversal vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via unknown vectors. (CVSS:7.5) (Last Update:2015-12-17)
CVE-2015-8566
The Session package 1.x before 1.3.1 for Joomla! Framework allows remote attackers to execute arbitrary code via unspecified session values. (CVSS:7.5) (Last Update:2015-12-17)
CVE-2015-8564
Directory traversal vulnerability in Joomla! 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via directory traversal sequences in the XML install file in an extension package archive. (CVSS:7.5) (Last Update:2015-12-17)
DSA-3423 cacti – security update
Several SQL injection vulnerabilities have been discovered in Cacti, an
RRDTool frontend written in PHP. Specially crafted input can be used by
an attacker in the rra_id value of the graph.php script to execute
arbitrary SQL commands on the database.
DSA-3424 subversion – security update
Ivan Zhakov discovered an integer overflow in mod_dav_svn, which allows
an attacker with write access to the server to execute arbitrary code or
cause a denial of service.
DSA-3421 grub2 – security update
Hector Marco and Ismael Ripoll, from Cybersecurity UPV Research Group,
found an integer underflow vulnerability in Grub2, a popular bootloader.
A local attacker can bypass the Grub2 authentication by inserting a
crafted input as username or password.
Vuln: Multiple FireEye Products 'JAR Analysis' Remote Code Execution Vulnerability
Multiple FireEye Products ‘JAR Analysis’ Remote Code Execution Vulnerability
DSA-3422 iceweasel – security update
Multiple security issues have been found in Iceweasel, Debian’s version
of the Mozilla Firefox web browser: Multiple memory safety errors,
integer overflows, use-after-frees and other implementation errors
may lead to the execution of arbitrary code, bypass of the same-origin
policy or denial of service.
RHBA-2015:2639-1: initscripts bug fix update
Red Hat Enterprise Linux: Updated initscripts packages that fix one bug are now available for Red Hat
Enterprise Linux 6.