IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain sensitive information from system memory via unspecified vectors.
Monthly Archives: October 2015
CVE-2015-5011
IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command.
CVE-2015-5014
IBM Cognos Disclosure Management (CDM) 10.1.x and 10.2.x before 10.2.4 IF10 allows man-in-the-middle attackers to obtain access by spoofing an executable file during a client upload operation.
CVE-2015-5448
HP Asset Manager 9.40 and 9.41 before 9.41.11103 P4-rev1 and 9.50 before 9.50.11925 P3 allows local users to obtain sensitive information via unspecified vectors.
Vuln: Mozilla Firefox CVE-2015-4495 Same Origin Policy Security Bypass Vulnerability
Mozilla Firefox CVE-2015-4495 Same Origin Policy Security Bypass Vulnerability
Vuln: IBM WebSphere Application Server CVE-2015-1885 Remote Privilege Escalation Vulnerability
IBM WebSphere Application Server CVE-2015-1885 Remote Privilege Escalation Vulnerability
HP Security Bulletin HPSBGN03429 1
HP Security Bulletin HPSBGN03429 1 – A potential security vulnerability has been identified with HP ArcSight Logger. The vulnerability could be exploited remotely to disclose information. Revision 1 of this advisory.
HP Security Bulletin HPSBGN03428 1
HP Security Bulletin HPSBGN03428 1 – A potential security vulnerability has been identified with HP Asset Manager. The vulnerability could be exploited to allow local disclosure of sensitive information. Revision 1 of this advisory.
CVE-2015-1001
Multiple stack-based buffer overflows in IniNet embeddedWebServer (aka eWebServer) before 2.02 allow remote attackers to execute arbitrary code via a long field in an HTTP request.
CVE-2015-1002
IniNet embeddedWebServer (aka eWebServer) before 2.02 mishandles URL encoding, which allows remote attackers to write to or delete files via a crafted string.