Enalean Tuleap versions 7.4.99.5 and below suffer from a remote command execution vulnerability.
Monthly Archives: October 2014
Tuleap 7.2 XXE Injection
Enalean Tuleap versions 7.2 and below suffer from an external XML entity injection vulnerability.
Tuleap 7.4.99.5 Blind SQL Injection
Enalean Tuleap versions 7.4.99.5 and below suffer from a remote, authenticated blind SQL injection vulnerability.
AVAR Down Under – Security Researchers at Work
ESET will be well represented in papers presented at the AVAR conference in November, but that’s not the only interesting content on the agenda.
The post AVAR Down Under â Security Researchers at Work appeared first on We Live Security.
![]()
ESET 7.0 Kernel Memory Leak
ESET versions 5.0 through 7.0 suffer from a kernel memory leak vulnerability.
HP Security Bulletin HPSBST03160
HP Security Bulletin HPSBST03160 – A potential security vulnerability has been identified with HP XP Command View Advanced Edition running Apache Struts. Revision 1 of this advisory.
Ubuntu Security Notice USN-2390-1
Ubuntu Security Notice 2390-1 – Jacob Appelbaum and an anonymous person discovered that Pidgin incorrectly handled certificate validation. A remote attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. Yves Younan and Richard Johnson discovered that Pidgin incorrectly handled certain malformed MXit emoticons. A malicious remote server or a man in the middle could use this issue to cause Pidgin to crash, resulting in a denial of service. Various other issues were also addressed.
Mandriva Linux Security Advisory 2014-210
Mandriva Linux Security Advisory 2014-210 – Multiple vulnerabilities have been discovered and corrected in mariadb.
Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 (.wax) Buffer Overflow
Mini-stream RM-MP3 Converter version 3.1.2.1.2010.03.30 suffers from a buffer overflow vulnerability when handling .wax files.
ESTsoft ALUpdate 8.5.1.0.0 Privilege Escalation
ESTsoft ALUpdate version 8.5.1.0.0 suffers from a privilege escalation vulnerability.