Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 8.6.x and 9.x before 9.1.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Monthly Archives: June 2016
CVE-2016-0233
SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Armadito Arbitrary File Write / Man-In-The-Middle
Armadito suffers from a remote arbitrary file write due to a man-in-the-middle issue.
Craft CMS Server-Side Template Injection
Craft CMS versions prior to build 2791 suffer from a server-side template injection vulnerability.
Kagao 3.0 Cross Site Scripting / SQL Injection
Kagao version 3.0 suffers from cross site scripting and remote SQL injection vulnerabilities.
Windows NtCreateProcessEx NULL Pointer Dereference
PspInitializeFullProcessImageName does not correctly handle a NULL pointer being passed to it leading to a dereference at NULL for a file object which might be exploitable on 32 bit systems for elevation of privilege.
DSA-3607 linux – security update
Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.
Untangle NGFW 12.1.0 Beta execEvil() Command Injection
Untangle NGFW versions 12.1.0 Beta and below execEvil() authentication root command injection exploit.
Craft CMS affected by server side template injection
Posted by Securify B.V. on Jun 27
————————————————————————
Craft CMS affected by server side template injection
————————————————————————
Nelson Berg & Jurgen Kloosterman, June 2016
————————————————————————
Abstract
————————————————————————
It was discovered that Craft CMS is vulnerable…
Ubuntu Security Notice USN-3017-2
Ubuntu Security Notice 3017-2 – Jesse Hertz and Tim Newsham discovered that the Linux netfilter implementation did not correctly perform validation when handling 32 bit compatibility IPT_SO_SET_REPLACE events on 64 bit platforms. A local unprivileged attacker could use this to cause a denial of service (system crash) or execute arbitrary code with administrative privileges. Kangjie Lu discovered an information leak in the core USB implementation in the Linux kernel. A local attacker could use this to obtain potentially sensitive information from kernel memory. Various other issues were also addressed.