WordPress Portfolio plugin version 2.27 suffers from a cross site scripting vulnerability.
Monthly Archives: December 2015
WordPress PDF And Print 1.7.4 Cross Site Scripting
WordPress PDF and Print plugin version 1.7.4 suffers from a cross site scripting vulnerability.
WordPress Limit Attempts 1.0.3 Cross Site Scripting
WordPress Limit Attempts plugin version 1.0.3 suffers from a cross site scripting vulnerability.
WordPress Limit Attempts 1.0.3 Cross Site Request Forgery
WordPress Limit Attempts plugin version 1.0.3 suffers from a cross site request forgery vulnerability.
Ubuntu Security Notice USN-2843-1
Ubuntu Security Notice 2843-1 – Jan Beulich discovered that the KVM svm hypervisor implementation in the Linux kernel did not properly catch Debug exceptions on AMD processors. An attacker in a guest virtual machine could use this to cause a denial of service (system crash) in the host OS. It was discovered that the ppp implementation in the Linux kernel did not ensure that certain slot numbers are valid. A local attacker with the privilege to call ioctl() on /dev/ppp could cause a denial of service (system crash). Various other issues were also addressed.
Ubuntu Security Notice USN-2844-1
Ubuntu Security Notice 2844-1 – Jan Beulich discovered that the KVM svm hypervisor implementation in the Linux kernel did not properly catch Debug exceptions on AMD processors. An attacker in a guest virtual machine could use this to cause a denial of service (system crash) in the host OS. It was discovered that the ppp implementation in the Linux kernel did not ensure that certain slot numbers are valid. A local attacker with the privilege to call ioctl() on /dev/ppp could cause a denial of service (system crash). Various other issues were also addressed.
Debian Security Advisory 3425-1
Debian Linux Security Advisory 3425-1 – Cedric Krier discovered a vulnerability in the server-side of Tryton, an application framework written in Python. An authenticated malicious user can write arbitrary values in record fields due missed checks of access permissions when multiple records are written.
Ubuntu Security Notice USN-2842-2
Ubuntu Security Notice 2842-2 – Jan Beulich discovered that the KVM svm hypervisor implementation in the Linux kernel did not properly catch Debug exceptions on AMD processors. An attacker in a guest virtual machine could use this to cause a denial of service (system crash) in the host OS. It was discovered that the ppp implementation in the Linux kernel did not ensure that certain slot numbers are valid. A local attacker with the privilege to call ioctl() on /dev/ppp could cause a denial of service (system crash). Various other issues were also addressed.