Various Ubiquiti Networks products suffers from an authenticated command injection vulnerability.
AXIS Cross Site Request Forgery / Cross Site Scripting
Various AXIS cameras suffer from cross site request forgery and cross site scripting vulnerabilities amongst other issues.
Windows DVD Maker 6.1.7 XXE Injection
Windows DVD Maker version 6.1.7 suffers from an XML external entity injection vulnerability.
Red Hat Security Advisory 2017-0557-01
Red Hat Security Advisory 2017-0557-01 – Red Hat JBoss BPM Suite is a business rules and processes management system for the management, storage, creation, modification, and deployment of JBoss rules and BPMN2-compliant business processes. This release of Red Hat JBoss BPM Suite 6.4.2 serves as a replacement for Red Hat JBoss BPM Suite 6.4.1, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Multiple security issues have been addressed.
Slackware Security Advisory – pidgin Updates
Slackware Security Advisory – New pidgin packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.
Ubuntu Security Notice USN-3235-1
Ubuntu Security Notice 3235-1 – It was discovered that libxml2 incorrectly handled format strings. If a user or automated system were tricked into opening a specially crafted document, an attacker could possibly cause libxml2 to crash, resulting in a denial of service. This issue only affected Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, and Ubuntu 16.04 LTS. It was discovered that libxml2 incorrectly handled certain malformed documents. If a user or automated system were tricked into opening a specially crafted document, an attacker could cause libxml2 to crash, resulting in a denial of service, or possibly execute arbitrary code. Various other issues were also addressed.
xen-4.7.2-2.fc25
Cirrus VGA Heap overflow via display refresh [XSA-211, CVE-2016-9603] (#1432041)
Qemu: usb: an infinite loop issue in ohci_service_ed_list [CVE-2017-6505] (#1429433)
Microsoft Windows "LoadUvsTable()" Buffer Overflow Vulnerability
Posted by Hossein Lotfi on Mar 16
Hello,
The details of this vulnerability can be found here if interested:
Microsoft initially tried to fixed the issue in MS16-147, but the fix was
incomplete and the issue remained unpatched til Microsoft March 2017 patch
release.
https://twitter.com/hosselot/status/809059287037251584
It appears MS17-013…
Windows DVD Maker XML External Entity File Disclosure
Posted by hyp3rlinx on Mar 16
[+] Credits: John Page AKA hyp3rlinx
[+] Website: hyp3rlinx.altervista.org
[+] Source:
http://hyp3rlinx.altervista.org/advisories/MICROSOFT-DVD-MAKER-XML-EXTERNAL-ENTITY-FILE-DISCLOSURE.txt
[+] ISR: ApparitionSec
Vendor:
=================
www.microsoft.com
Product:
=================
Windows DVD Maker
v6.1.7
Windows DVD Maker is a feature you can use to make DVDs that you can watch
on a computer or on a TV using a regular DVD player….
Axis Camera Multiple Vulnerabilities
Posted by David Wearing on Mar 16
Introduction
============
Vulnerabilities were identified in the camera software by Axis. These were
discovered during a black box assessment and therefore the vulnerability
list should not be considered exhaustive; observations suggest that it is
likely that further vulnerabilities exist.
Affected Software And Versions
==============================
Model P1204, software versions <= 5.50.4
Model P3225, software versions <= 6.30.1…