Red Hat Security Advisory 2016-1423-01 – The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update upgrades Flash Player to version 11.2.202.632. Security Fix: This update fixes multiple vulnerabilities in Adobe Flash Player. These vulnerabilities, detailed in the Adobe Security Bulletin listed in the References section, could allow an attacker to create a specially crafted SWF file that would cause flash-plugin to crash, execute arbitrary code, or disclose sensitive information when the victim loaded a page containing the malicious SWF content.
Monthly Archives: July 2016
WordPress WP No External Links 3.5.15 Cross Site Scripting
WordPress WP No External Links plugin version 3.5.15 suffers from a cross site scripting vulnerability.
Cisco Security Advisory 20160713-ncs6k
Cisco Security Advisory – A vulnerability in the management of system timer resources in Cisco IOS XR for Cisco Network Convergence System 6000 (NCS 6000) Series Routers could allow an unauthenticated, remote attacker to cause a leak of system timer resources, leading to a nonoperational state and an eventual reload of the Route Processor (RP) on the affected platform. The vulnerability is due to improper management of system timer resources. An attacker could exploit this vulnerability by sending a number of Secure Shell (SSH), Secure Copy Protocol (SCP), and Secure FTP (SFTP) management connections to an affected device. An exploit could allow the attacker to cause a leak of system timer resources, leading to a nonoperational state and an eventual reload of the RP on the affected platform. Cisco has released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.
Red Hat Security Advisory 2016-1424-01
Red Hat Security Advisory 2016-1424-01 – Red Hat JBoss Fuse, based on Apache ServiceMix, provides a small-footprint, flexible, open source enterprise service bus and integration platform. Red Hat JBoss A-MQ, based on Apache ActiveMQ, is a standards compliant messaging system that is tailored for use in mission critical applications. This patch is an update to Red Hat JBoss Fuse 6.2.1 and Red Hat JBoss A-MQ 6.2.1. It includes several bug fixes, which are documented in the readme.txt file included with the patch files. It was reported that the web based administration console does not set the X-Frame-Options header in HTTP responses. This allows the console to be embedded in a frame or iframe which could then be used to cause a user to perform an unintended action in the console. It was found that Apache Active MQ administration web console did not validate input correctly when creating a queue. An authenticated attacker could exploit this flaw via cross-site scripting and use it to access sensitive information or further attacks.
Open-Xchange App Suite 7.8.1 Cross Site Scripting
Open-Xchange App Suite version 7.8.1 suffers from a cross site scripting vulnerability.
WordPress Google Forms 0.84 Cross Site Scripting
WordPress Google Forms plugin version 0.84 suffers from a cross site scripting vulnerability.
Adobe Acrobat Reader DC 15.016.20045 Memory Corruption
Adobe Acrobat Reader DC version 15.016.20045 suffers from multiple memory corruption vulnerabilities while handling font (.ttf) files.
Drupal Patches Remote Code Execution Vulnerabilities in Three Modules
Developers with the open source content management framework Drupal patched a series of highly critical remote code execution bugs in three separate modules today. If exploited, the bugs could let an attacker take over any site running the modules.
Cross-Site Scripting vulnerability in WP No External Links WordPress Plugin
Posted by Summer of Pwnage on Jul 13
————————————————————————
Cross-Site Scripting vulnerability in WP No External Links WordPress
Plugin
————————————————————————
Yorick Koster, July 2016
————————————————————————
Abstract
————————————————————————
A Cross-Site Scripting vulnerability was found…
Cross-Site Scripting vulnerability in Google Forms WordPress Plugin
Posted by Summer of Pwnage on Jul 13
————————————————————————
Cross-Site Scripting vulnerability in Google Forms WordPress Plugin
————————————————————————
Yorick Koster, July 2016
————————————————————————
Abstract
————————————————————————
A Cross-Site Scripting vulnerability was found in the…