Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4256, CVE-2016-4257, CVE-2016-4258, CVE-2016-4259, CVE-2016-4260, and CVE-2016-4261.
Monthly Archives: September 2016
CVE-2016-4263 (digital_editions)
Use-after-free vulnerability in Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code via unspecified vectors.
CVE-2016-6302 (openssl)
The tls_decrypt_ticket function in ssl/t1_lib.c in OpenSSL before 1.1.0 does not consider the HMAC size during validation of the ticket length, which allows remote attackers to cause a denial of service via a ticket that is too short.
CVE-2016-6303 (openssl)
Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors.
CVE-2016-6936 (air_sdk_&_compiler)
Adobe AIR SDK & Compiler before 23.0.0.257 on Windows does not support Android runtime-analytics transport security, which might allow remote attackers to obtain sensitive information by leveraging access to a network over which analytics data is sent.
CVE-2016-7420 (crypto++)
Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are unintended in production use, which might allow context-dependent attackers to obtain sensitive information by leveraging access to process memory after an assertion failure, as demonstrated by reading a core dump.
Bugtraq: Insecure transmission of data in Android applications developed with Adobe AIR [CVE-2016-6936]
Insecure transmission of data in Android applications developed with Adobe AIR [CVE-2016-6936]
Bugtraq: Cisco EPC 3925 Multiple Vulnerabilities
Cisco EPC 3925 Multiple Vulnerabilities
Bugtraq: ESA-2016-094: RSA BSAFE® Micro Edition Suite Multiple Vulnerabilities
ESA-2016-094: RSA BSAFE® Micro Edition Suite Multiple Vulnerabilities
RHEA-2016:1902-1: new packages: kmod-i40e, kmod-i40evf
Red Hat Enterprise Linux: New kmod-i40e and kmod-i40evf packages are now available for Red Hat Enterprise
Linux 7.