Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via an object with a revision number of -1 in a PDF document.
Monthly Archives: April 2016
CVE-2016-4064
Use-after-free vulnerability in the XFA forms handling functionality in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via a crafted remerge call.
CVE-2016-4065
The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 7.3.4 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted (1) JPEG, (2) GIF, or (3) BMP image.
OpenSCAP Libraries 1.2.9
The openscap project is a set of open source libraries that support the SCAP (Security Content Automation Protocol) set of standards from NIST. It supports CPE, CCE, CVE, CVSS, OVAL, and XCCDF.
Digitalstrom Konfigurator 1.10.0 CSRF / Cross Site Scripting
Digitalstrom Konfigurator version 1.10.0 suffers from cross site request forgery and cross site scripting vulnerabilities.
my devolo 1.2.8 Insecure Data Storage
my devolo version 1.2.8 suffers from an insecure data storage vulnerability.
HP Security Bulletin HPSBGN03580 1
HP Security Bulletin HPSBGN03580 1 – Potential security vulnerabilities have been identified in HP Data Protector that could allow the remote execution of code or the unauthorized disclosure of information. Revision 1 of this advisory.
HP Security Bulletin HPSBMU03573 1
HP Security Bulletin HPSBMU03573 1 – A potential security vulnerability has been identified with HPE System Management Homepage (SMH) on Windows and Linux. The vulnerability could be exploited remotely resulting in disclosure of information. Revision 1 of this advisory.
Debian Security Advisory 3554-1
Debian Linux Security Advisory 3554-1 – Multiple vulnerabilities have been discovered in the Xen hypervisor.
Debian Security Advisory 3553-1
Debian Linux Security Advisory 3553-1 – Regis Leroy from Makina Corpus discovered that varnish, a caching HTTP reverse proxy, is vulnerable to HTTP smuggling issues, potentially resulting in cache poisoning or bypassing of access control policies.