Memory leak in queue-manager agents in IBM WebSphere MQ 8.x before 8.0.0.5 allows remote attackers to cause a denial of service (heap memory consumption) by triggering many errors.
Monthly Archives: June 2016
CVE-2016-0263
IBM Spectrum Scale 4.1 before 4.1.1.5 and 4.2 before 4.2.0.2 and General Parallel File System 3.5 before 3.5.0.30 allow local users to gain privileges or cause a denial of service via a crafted mmapplypolicy command.
CVE-2016-0267
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 allows remote authenticated users to obtain sensitive cleartext secure-property information via (1) the server UI or (2) a database request.
CVE-2016-0298
Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote authenticated users to read arbitrary files via a crafted URL.
CVE-2016-0304
The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, aka SPR KLYHA7MM3J. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-0920.
Symantec PowerPoint Misaligned Stream-Cache Buffer Overflow
Symantec suffers from a PowerPoint misaligned stream-cache remote stack buffer overflow vulnerability.
Symantec dec2zip ALPkOldFormatDecompressor::UnShrink Missing Bounds Check
Symantec suffers from a missing bounds checks in dec2zip ALPkOldFormatDecompressor::UnShrink.
Symantec TNEF Decoder Integer Overflow
Symantec suffers from an integer overflow in the TNEF decoder.
Symantec MIME Message Modification Heap Overflow
Symantec attempts to clean or remove components from archives or other multipart containers that they detect as malicious. The code that they use to remove components from MIME encoded messages in CMIMEParser::UpdateHeader() assumes that filenames cannot be longer than 77 characters. This assumption is obviously incorrect, names can be any length, resulting in a very clean heap overflow.
Symantec Antivirus MSPACK Unpacking Memory Corruption
Symantec Antivirus suffers from multiple remote memory corruption issues when unpacking MSPACK archives.