Debian Linux Security Advisory 2830-1 - Peter McLarnan discovered that the internationalization component of Ruby on Rails does not properly encode parameters in generated HTML code, resulting in a cross-site scripting vulnerability. This update corrects the underlying vulnerability in the i18n gem, as provided by the ruby-i18n package.
a6747869dc9268239f3564cf20ff354298c368b9de8167fa4c2a6aa329202c06
HP Security Bulletin HPSBMU02959 - Potential security vulnerabilities have been identified with HP Service Manager WebTier and Windows Client. The vulnerabilities could be remotely exploited including cross-site scripting (XSS) and execution of arbitrary code. Note: The HP Service Manager WebTier and Windows Client resolutions below include updated Oracle JRE7 that addresses security issues in that component. Revision 1 of this advisory.
58a30edc080b0e25adb01a93ba0056e311ea2ed59f2ef7f92be99429af407f3a
Adobe Flash versions 11.9.900.152 and 11.9.900.170 suffer from a denial of service vulnerability.
fe33acf39a4e11bf2cf251b2ce8509d7bda5c2a8a7c4dcc811d324d4df6d50e9