A use-after-free vulnerability exists in the RTF parser of the LibreOffice office suite. The vulnerability is due to invalid parsing of stylesheets in RTF files. By enticing the user to open a specially crafted RTF file, an attacker could exploit this vulnerability to execute arbitrary code on the affected system.
Monthly Archives: July 2016
Tiki-Wiki CMS Calendar Remote Command Execution
A remote command injection vulnerability exists in Tiki-Wiki CMS’s calendar module. By exploiting this vulnerability, a remote attacker can execute arbitrary code on the affected server.
Liferay Portal User Account Stored Cross Site Scripting (CVE-2016-3670)
A persistent XSS vulnerability exists in the user account creation process in Liferay Portal. The vulnerability is due to insufficient input validation of the firstName, middleName and lastName parameters. Successful exploitation could allow the attacker to inject arbitrary script code into a user profile.
Squid Long String Header Processing Assertion Failure (CVE-2016-2569)
A denial-of-service vulnerability has been reported in Squid. The vulnerability is due to the way Squid uses a String object of a certain maximum length to store incoming headers, such as the Vary header, in HTTP responses. Long strings in headers can cause an assertion failure.
D-Link DCS-930L Authenticated Remote Command Execution
A command execution vulnerability exists in D-Link DCS-930L. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary commands on the affected system.
Criminals plant banking malware where victims least expect it – Ars Technica
Criminals plant banking malware where victims least expect it – Ars Technica
Nexthon Whois Website Value Calculator 1.5 SQL Injection
Nexthon Whois Website Value Calculator version 1.5 suffers from a remote blind SQL injection vulnerability.
VeraCrypt 1.17 DLL Hijacking
The installer for VeraCrypt version 1.17 suffers from a dll hijacking vulnerability.
Codebase Business Directory Pro 1.02 SQL Injection
Codebase Business Directory Pro version 1.02 suffers from a remote SQL injection vulnerability.
Vuln: Libarchive CVE-2016-4302 Local Heap Buffer Overflow Vulnerability
Libarchive CVE-2016-4302 Local Heap Buffer Overflow Vulnerability