ASUS DSL-X11 ADSL router unauthenticated remote DNS changer exploit.
Monthly Archives: September 2016
Antisip libosip2 4.1.0 Heap Buffer Overflow / Denial Of Service
Antisip libosip2 version 4.1.0 suffers from heap buffer overflow vulnerabilities that can lead to a denial of service.
Red Hat Security Advisory 2016-1858-01
Red Hat Security Advisory 2016-1858-01 – Ruby on Rails is a model-view-controller framework for web application development. Action Pack implements the controller and the view components. Security Fix: It was discovered that Action View tag helpers did not escape quotes when using strings declared as HTML safe as attribute values. A remote attacker could use this flaw to conduct a cross-site scripting attack.
Red Hat Security Advisory 2016-1857-01
Red Hat Security Advisory 2016-1857-01 – Ruby on Rails is a model-view-controller framework for web application development. Action Pack implements the controller and the view components. Security Fix: It was discovered that Action View tag helpers did not escape quotes when using strings declared as HTML safe as attribute values. A remote attacker could use this flaw to conduct a cross-site scripting attack.
Red Hat Security Advisory 2016-1855-01
Red Hat Security Advisory 2016-1855-01 – Ruby on Rails is a model-view-controller framework for web application development. Action View implements the view component, and Active Record implements the model component. Security Fix in rubygem-actionview: It was discovered that Action View tag helpers did not escape quotes when using strings declared as HTML safe as attribute values. A remote attacker could use this flaw to conduct a cross-site scripting attack.
Red Hat Security Advisory 2016-1856-01
Red Hat Security Advisory 2016-1856-01 – Ruby on Rails is a model-view-controller framework for web application development. Action View implements the view component. Security Fix: It was discovered that Action View tag helpers did not escape quotes when using strings declared as HTML safe as attribute values. A remote attacker could use this flaw to conduct a cross-site scripting attack.