Adobe RoboHelp version 2015.0.3 and earlier, RoboHelp 11 and earlier have an input validation issue that could be used in cross-site scripting attacks.
Monthly Archives: December 2016
CVE-2016-7892
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.
Yahoo Admits 1 Billion Accounts Compromised in Newly Discovered Data Breach
In what believe to be the largest data breach in history, Yahoo is reporting a massive data breach that disclosed personal details associated with more than 1 Billion user accounts in August 2013.
…And it’s separate from the one disclosed by Yahoo! in September, in which hackers compromised as many as 500 Million user accounts in late 2014.
What’s troubling is that the company has not been
![]()
CVE-2016-9566
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565. (CVSS:7.2) (Last Update:2016-12-16)
CVE-2016-9565
MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796. (CVSS:7.5) (Last Update:2016-12-16)
Vuln: MIT Kerberos KDC CVE-2016-3120 NULL Pointer Dereference Denial Of Service Vulnerability
MIT Kerberos KDC CVE-2016-3120 NULL Pointer Dereference Denial Of Service Vulnerability
Vuln: IBM Spectrum Scale and IBM GPFS Local Command Execution Vulnerability
IBM Spectrum Scale and IBM GPFS Local Command Execution Vulnerability
Vuln: GNU Wget CVE-2016-4971 Arbitrary File Overwrite Vulnerability
GNU Wget CVE-2016-4971 Arbitrary File Overwrite Vulnerability
Vuln: cURL/libcURL CVE-2016-5419 Remote Security Bypass Vulnerability
cURL/libcURL CVE-2016-5419 Remote Security Bypass Vulnerability
DSA-3735 game-music-emu – security update
Chris Evans discovered that incorrect emulation of the SPC700 audio
co-processor of the Super Nintendo Entertainment System allows the
execution of arbitrary code if a malformed SPC music file is opened.
Further information can be found at
http://scarybeastsecurity.blogspot.de/2016/12/redux-compromising-linux-using-snes.html
