CVE-2016-0229

Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 8.6.x and 9.x before 9.1.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVE-2016-0233

SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

Craft CMS affected by server side template injection

Posted by Securify B.V. on Jun 27

————————————————————————
Craft CMS affected by server side template injection
————————————————————————
Nelson Berg & Jurgen Kloosterman, June 2016

————————————————————————
Abstract
————————————————————————
It was discovered that Craft CMS is vulnerable…

Ubuntu Security Notice USN-3017-2

Ubuntu Security Notice 3017-2 – Jesse Hertz and Tim Newsham discovered that the Linux netfilter implementation did not correctly perform validation when handling 32 bit compatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A local unprivileged attacker could use this to cause a denial of service (system crash) or execute arbitrary code with administrative privileges. Kangjie Lu discovered an information leak in the core USB implementation in the Linux kernel. A local attacker could use this to obtain potentially sensitive information from kernel memory. Various other issues were also addressed.