A denial of service vulnerability exists in Apache Struts URLValidator. The vulnerability is due to insufficient validation of crafted URLs by the URLValidator. A remote, unauthenticated attacker could exploit this vulnerability by sending a crafted HTTP request to a Struts 2 application. Successful attack can result in a denial of service condition.
Monthly Archives: July 2016
Adobe Acrobat and Reader Memory Corruption (APSB16-14: CVE-2016-1076; CVE-2016-1076)
A memory corruption vulnerability exists in Adobe Reader and Acrobat. The vulnerability is due to out-of-bounds error while accessing unintended memory in a specially crafted JPG file. A remote attacker can exploit this vulnerability by enticing a target user to open a specially crafted JPG file in Adobe Acrobat and Reader.
Tiki Wiki ELFinder Unauthenticated File Upload
An unauthenticated file upload vulnerability exists in Tiki Wiki. By uploading a malicious file to Tiki Wiki, a remote attacker can exploit this vulnerability for execution of arbitrary code in the security context of the web server.
Adobe Flash Player Memory Corruption (APSB16-25: CVE-2016-4182; CVE-2016-4182)
A memory corruption vulnerability exists in Adobe Flash Player. The vulnerability is due to an error in Adobe Flash Player while parsing a specially crafted SWF file. A remote attacker can exploit this issue by enticing a victim to open a specially crafted SWF file.
Adobe Flash Player Use After Free Code Execution (APSB16-25: CVE-2016-4173; CVE-2016-4173)
A remote code execution vulnerability exists in Adobe Flash Player. The vulnerability is due to a use-after-free error in Adobe Flash Player while handling a specially crafted SWF file. A remote attacker can exploit this vulnerability by enticing a target user to open a specially crafted SWF file with an affected version of Flash Player.
Adobe Flash Player Use After Free Code Execution (APSB16-25: CVE-2016-4174; CVE-2016-4174)
A remote code execution vulnerability has been reported in Adobe Flash Player. The vulnerability is due to a use-after-free error in Adobe Flash Player while handling a specially crafted SWF file. A remote attacker can exploit this vulnerability by enticing a target user to open a specially crafted SWF file with an affected version of Flash Player.
WordPress Code Snippets 2.6.1 Cross Site Scripting
WordPress Code Snippets plugin version 2.6.1 suffers from a cross site scripting vulnerability.
WordPress Contact Form To Email 1.1.47 Cross Site Scripting
WordPress Contact Form to Email plugin version 1.1.47 suffers from a cross site scripting vulnerability.
Bellini/Supercook Wi-Fi Yumi SC200 Information Disclosure / Code Execution
Bellini/Supercook Wi-Fi Yumi SC200 suffers from code execution, weak default password, and information disclosure vulnerabilities.
Neoscreen 4.5 Cross Site Scripting
Neoscreen version 4.5 suffers from a cross site scripting vulnerability.