Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HTML by tricking an administrator into uploading an image file that has a crafted filename.
Monthly Archives: January 2017
CVE-2016-10010
sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to gain privileges via unspecified vectors, related to serverloop.c.
CVE-2016-10011
authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which might allow local users to obtain sensitive private-key information by leveraging access to a privilege-separated child process.
CVE-2016-10009
Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket.
CVE-2016-7169
Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authenticated users to access arbitrary files via a crafted urlholder parameter.
DSA-3753 libvncserver – security update
It was discovered that libvncserver, a collection of libraries used to
implement VNC/RFB clients and servers, incorrectly processed incoming
network packets. This resulted in several heap-based buffer overflows,
allowing a rogue server to either cause a DoS by crashing the client,
or potentially execute arbitrary code on the client side.
Vuln: Linux Kernel 'path_openat()' Function Use After Free Memory Corruption Vulnerability
Linux Kernel ‘path_openat()’ Function Use After Free Memory Corruption Vulnerability
Vuln: Linux Kernel CVE-2016-7042 Local Denial of Service Vulnerability
Linux Kernel CVE-2016-7042 Local Denial of Service Vulnerability
Vuln: Linux Kernel 'mm/memory.c' Local Code Execution Vulnerability
Linux Kernel ‘mm/memory.c’ Local Code Execution Vulnerability
Vuln: Objective Systems ASN1C CVE-2016-5080 Heap Based Buffer Overflow Vulnerability
Objective Systems ASN1C CVE-2016-5080 Heap Based Buffer Overflow Vulnerability