WordPress Authentic theme suffers from an arbitrary file download vulnerability. Note that this finding houses site-specific data.
Category Archives: Security
Security
Mozilla 1024-Bit Cert Deprecation Leaves 107,000 Sites Untrusted
Data compiled from Rapid7’s Project Sonar scan found 107,000 websites running 1024-bit CA certificates that will soon be untrusted as Mozilla announces it will no longer support the shorter, weaker keys.
ProjectDox 8.1 XSS / User Enumeration / Ciphertext Reuse
ProjectDox version 8.1 suffers from cross site scripting, insecure direct object reference, ciphertext reuse, and user enumeration vulnerabilities.
HP Security Bulletin HPSBMU03083 2
HP Security Bulletin HPSBMU03083 2 – A potential security vulnerability has been identified with HP BladeSystem c-Class Virtual Connect Firmware running OpenSSL. This vulnerability could be exploited remotely resulting in unauthorized access or disclosure of information. Revision 2 of this advisory.
Gentoo Linux Security Advisory 201409-04
Gentoo Linux Security Advisory 201409-4 – Multiple vulnerabilities have been found in MySQL, worst of which allows local attackers to escalate their privileges. Versions less than 5.5.39 are affected.
Red Hat Security Advisory 2014-1147-01
Red Hat Security Advisory 2014-1147-01 – Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects. A flaw was found in the way Squid handled malformed HTTP Range headers. A remote attacker able to send HTTP requests to the Squid proxy could use this flaw to crash Squid.
Red Hat Security Advisory 2014-1145-01
Red Hat Security Advisory 2014-1145-01 – Mozilla Thunderbird is a standalone mail and newsgroup client. Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running Thunderbird.
Red Hat Security Advisory 2014-1146-01
Red Hat Security Advisory 2014-1146-01 – HttpClient is an HTTP/1.1 compliant HTTP agent implementation based on httpcomponents HttpCore. It was discovered that the HttpClient incorrectly extracted host name from an X.509 certificate subject’s Common Name field. A man-in-the-middle attacker could use this flaw to spoof an SSL server using a specially crafted X.509 certificate.
Red Hat Security Advisory 2014-1148-01
Red Hat Security Advisory 2014-1148-01 – Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects. A flaw was found in the way Squid handled malformed HTTP Range headers. A remote attacker able to send HTTP requests to the Squid proxy could use this flaw to crash Squid. A buffer overflow flaw was found in Squid’s DNS lookup module. A remote attacker able to send HTTP requests to the Squid proxy could use this flaw to crash Squid.
Red Hat Security Advisory 2014-1144-01
Red Hat Security Advisory 2014-1144-01 – Mozilla Firefox is an open source web browser. XULRunner provides the XUL Runtime environment for Mozilla Firefox. Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox.