NTP CVE-2015-7979 Denial of Service Vulnerability
Monthly Archives: October 2016
Vuln: Open-Xchange AppSuite Multiple Content Spoofing Vulnerabilities
Open-Xchange AppSuite Multiple Content Spoofing Vulnerabilities
Vuln: Open-Xchange AppSuite CVE-2016-6848 Local Code Execution Vulnerability
Open-Xchange AppSuite CVE-2016-6848 Local Code Execution Vulnerability
Fitbit Connect Service Privilege Escalation
Fitbit Connect Service suffers from an unquoted service path privilege escalation vulnerability.
Foxit Cloud Update Service Privilege Escalation
Foxit Cloud Update Service suffers from an unquoted service path privilege escalation vulnerability.
Wacom Consumer Service Privilege Escalation
Wacom Consumer Service suffers from an unquoted service path privilege escalation vulnerability.
Yahoo Email Spying Scandal — Here's Everything that has Happened So Far
Today Yahoo! is all over the Internet, but in a way the company would never have expected.
It all started days ago when Reuters cited some anonymous sources and reported that Yahoo built a secret software to scan the emails of hundreds of millions of its users at the request of a U.S. intelligence service.
At this point, we were not much clear about the intelligence agency: the National
![]()
USN-3091-1: Oxide vulnerabilities
Ubuntu Security Notice USN-3091-1
7th October, 2016
oxide-qt vulnerabilities
A security issue affects these releases of Ubuntu and its
derivatives:
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary
Several security issues were fixed in Oxide.
Software description
- oxide-qt
– Web browser engine for Qt (QML plugin)
Details
A use-after-free was discovered in the V8 bindings in Blink. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via application
crash, or execute arbitrary code. (CVE-2016-5170)
A use-after-free was discovered in the V8 bindings in Blink. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via application
crash, or execute arbitrary code. (CVE-2016-5171)
An issue was discovered in V8. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
ontain sensitive information from arbitrary memory locations.
(CVE-2016-5172)
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial
of service via application crash, or execute arbitrary code.
(CVE-2016-5175, CVE-2016-5178)
A use-after-free was discovered in V8. If a user were tricked in to
opening a specially crafted website, an attacker could potentially
exploit this to cause a denial of service via application crash, or
execute arbitrary code. (CVE-2016-5177)
It was discovered that Chromium does not ensure the recipient of a certain
IPC message is a valid RenderFrame or RenderWidget. An attacker could
potentially exploit this to cause a denial of service via application
crash, or execute arbitary code. (CVE-2016-7549)
Update instructions
The problem can be corrected by updating your system to the following
package version:
- Ubuntu 16.04 LTS:
-
liboxideqtcore0
1.17.9-0ubuntu0.16.04.1
- Ubuntu 14.04 LTS:
-
liboxideqtcore0
1.17.9-0ubuntu0.14.04.1
To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.
In general, a standard system update will make all the necessary changes.
References
DSA-3689 php5 – security update
Several vulnerabilities were found in PHP, a general-purpose scripting
language commonly used for web application development.
www.httpd.apache.org
Hi, The version of your website and SEO-Algorithm is outdated and affecting your outcome on prominent search-engines. We can make the necessary changes to improve your rankings in the organic search result and drive more quality visitors to your website. Would you be open to seeing briefer info/quote for what I would like to accomplish, with no-obligation? Best regards, David | BRANCH MANAGER DOMINICS WEB NETWORK Pty Ltd Level 2, 265 Queen Street Melbourne—VIC. 3000 Australia NATION WIDE: Sydney | Perth | Brisbane | Adelaide | Hobart
