HP LaserJet Fax Preview DLL side loading vulnerability

Posted by Securify B.V. on Jan 23

————————————————————————
HP LaserJet Fax Preview DLL side loading vulnerability
————————————————————————
Yorick Koster, September 2015

————————————————————————
Abstract
————————————————————————
A DLL side loading vulnerability was found in the HP LaserJet…

HP ToComMsg DLL side loading vulnerability

Posted by Securify B.V. on Jan 23

————————————————————————
HP ToComMsg DLL side loading vulnerability
————————————————————————
Yorick Koster, September 2015

————————————————————————
Abstract
————————————————————————
A DLL side loading vulnerability was found in the HP ToComMsg DLL. This…

LEADTOOLS ActiveX control multiple DLL side loading vulnerabilities

Posted by Securify B.V. on Jan 23

————————————————————————
LEADTOOLS ActiveX control multiple DLL side loading vulnerabilities
————————————————————————
Yorick Koster, September 2015

————————————————————————
Abstract
————————————————————————
Multiple DLL side loading vulnerabilities were…

CVE-2015-6317

Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct request, aka Bug ID CSCuu45926.

CVE-2015-7417

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 7.0 before 7.0.0.41, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.9 allows remote authenticated users to inject arbitrary web script or HTML via crafted data from an OAuth provider.