[RCESEC-2016-001] Postfix Admin v2.93 Generic POST Cross-Site Request Forgeries
Monthly Archives: May 2016
Bugtraq: [SECURITY] [DSA 3585-1] wireshark security update
[SECURITY] [DSA 3585-1] wireshark security update
Bugtraq: [RCESEC-2016-002] XenAPI v1.4.1 for XenForo Multiple Unauthenticated SQL Injections
[RCESEC-2016-002] XenAPI v1.4.1 for XenForo Multiple Unauthenticated SQL Injections
RHSA-2016:1096-1: Important: kernel security and bug fix update
Red Hat Enterprise Linux: An update for kernel is now available for Red Hat Enterprise Linux 6.4 Advanced
Update Support.
Red Hat Product Security has rated this update as having a security impact of
Important. A Common Vulnerability Scoring System (CVSS) base score, which gives
a detailed severity rating, is available for each vulnerability from the CVE
link(s) in the References section.
CVE-2015-5364, CVE-2015-5366
RHEA-2016:1097-1: Red Hat Enterprise Linux Atomic pod-infrastructure Container Image Update
An updated Red Hat Enterprise Linux Atomic pod-infrastructure container image is
now available for Red Hat Enterprise Linux Atomic Host.
Teenager charged over Mumsnet hack and DDoS attack
An 18-year-old man has been charged by British police in connection with an internet attack that saw Mumsnet hacked, users’ accounts breached, passwords stolen, and the site blasted offline.
The post Teenager charged over Mumsnet hack and DDoS attack appeared first on We Live Security.
![]()
CVE-2015-8558
The ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular isochronous transfer descriptor (iTD) list.
CVE-2016-2855
The Huawei Mobile Broadband HL Service 22.001.25.00.03 and earlier uses a weak ACL for the MobileBrServ program data directory, which allows local users to gain SYSTEM privileges by modifying VERSION.dll.
CVE-2016-3664
Trend Micro Mobile Security for iOS before 3.2.1188 does not verify the X.509 certificate of the mobile application login server, which allows man-in-the-middle attackers to spoof this server and obtain sensitive information via a crafted certificate.
CVE-2016-3958
Untrusted search path vulnerability in Go before 1.5.4 and 1.6.x before 1.6.1 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, related to use of the LoadLibrary function.