The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3) portmap executable files, which allows local users to gain privileges via a Trojan horse file.
Monthly Archives: March 2016
CVE-2016-1314
Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (CDM) 8.1(1) allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux80760.
CVE-2016-2344
Stack-based buffer overflow in manager.exe in Backburner Manager in Autodesk Backburner 2016 2016.0.0.2150 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted command. NOTE: this is only a vulnerability in environments in which the administrator has not followed documentation that outlines the security risks of operating Backburner on untrusted networks.
BMC Server Automation (BSA) RSCD Agent User Enumeration
A security vulnerability has been identified in BMC Server Automation (BSA) RSCD Agent on the Linux/Unix platforms. The vulnerability allows unauthorized remote user enumeration on a target server by using the Remote Procedure Call (RPC) API of the RSCD Agent. Windows agents are not affected. The flaw has been confirmed to exist in the following versions of BSA on Unix and Linux platforms: 8.2.x, 8.3.x, 8.5.x, 8.6.x and 8.7.x.
Zen Cart Plugs Dozens Of XSS Vulnerabilities
Terrorists Hardly Use The Dark Web
FBI-Apple Case: Investigators Break Into Dead San Bernardino Gunman's iPhone
Cogent Datahub 7.3.9 Privilege Escalation
Cogent Datahub versions 7.3.9 and below suffer from a gamma script elevation of privilege vulnerability.
TallSoft SNMP TFTP Server 1.0.0 Denial Of Service
TallSoft SNMP TFTP server version 1.0.0 suffers from a denial of service vulnerability.
Popular Shopping Cart App Plugs Dozens of XSS Vulnerabilities
Researchers found 50 cross site scripting vulnerabilities in the popular open source shopping cart application Zen Cart.