Multiple vulnerabilities have been discovered in the JasPer library for
processing JPEG-2000 images, which may result in denial of service or
the execution of arbitrary code if a malformed image is processed.
Monthly Archives: April 2017
Vuln: HP Business Process Monitor CVE-2017-5801 Unspecified Unauthorized Access Vulnerability
HP Business Process Monitor CVE-2017-5801 Unspecified Unauthorized Access Vulnerability
Vuln: Google Android Qualcomm Kyro L2 Driver CVE-2017-6423 Privilege Escalation Vulnerability
Google Android Qualcomm Kyro L2 Driver CVE-2017-6423 Privilege Escalation Vulnerability
Vuln: Marel Food Processing Systems Security Bypass and Arbitrary File Upload Vulnerabilities
Marel Food Processing Systems Security Bypass and Arbitrary File Upload Vulnerabilities
Vuln: Linux Kernel 'digi_acceleport.c' Local Denial of Service Vulnerability
Linux Kernel ‘digi_acceleport.c’ Local Denial of Service Vulnerability
CVE-2016-1000307
Multiple Cross Site Scripting (XSS) Vulnerabilities in ClipBucket v2.8.1 and probably prior allow Remote Attackers to inject arbitrary web script or HTML via (1) profile_desc, about_me, schools, occupation, companies, hobbies, fav_movies, fav_music, fav_books parameters to ProfileSettings page; (2) note parameter to PersonalNotes Section; (3) closed_msg, description, allowed_types parameters to WebsiteConfigurations Section. NOTE: the collection_description vector is already covered by CVE-2015-4673.
CVE-2015-4673
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.7.0.5 allow remote authenticated users to inject arbitrary web script or HTML via (1) the collection_description parameter to upload/manage_collections.php in an add_new action or the (2) photo_description, (3) photo_tags, or (4) photo_title parameter to upload/actions/photo_uploader.php.
CVE-2017-7576
DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and password of wireless) meant to allow the vendor to access the devices. These credentials can be used in the web interface or by connecting to the device via TELNET. This is fixed in recent versions including 1.4.8.
CVE-2016-6809
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
CVE-2015-8965
Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that exists in the classpath, such as test code or administration code. The issue exists because the ilog.views.faces.IlvFacesController servlet in jviews-framework-all.jar does not require explicit configuration of servlets that can be called.