Debian Linux Security Advisory 3561-1 - Several vulnerabilities were discovered in Subversion, a version control system.
b23f16f854ad8a913fcb71a65f6118aa
GLPI version 0.90.2 suffers from a remote SQL injection vulnerability.
2c2bc727021894555545066d1c21025e
Mozilla continues to ship Firefox and Thunderbird for Windows with a vulnerable executable installer.
3a7773a1eef943e50f4d2710742d2ba2
WordPress Truemag theme from 2016 Q2 suffers from a cross site scripting vulnerability.
f1ca607fdfa4b0f1d2365da088941388
431 bytes small NULL free shellcode for windows that is a primitive keylogger that writes to a file.
95baa416c64784bf8f830e561a634ea6
HPE Security Bulletin HPSBUX03583 SSRT110084 1 - Potential security vulnerabilities have been identified in the HP-UX BIND service running named. These vulnerabilities could be exploited remotely to create a Denial of Service (DoS). Revision 1 of this advisory.
89b6347ee7f06f57801fb90fdaa71701
An integer wrap may occur in PHP 7.x before version 7.0.6 when reading zip files with the getFromIndex() and getFromName() methods of ZipArchive, resulting in a heap overflow. Full exploit included.
a681c55094ed13770f1f961d5c5dde1d
Red Hat Security Advisory 2016-0699-01 - In accordance with the Red Hat Enterprise Developer Toolset Life Cycle policy, the Red Hat Developer Toolset Version 3.x offering will be retired as of October 31, 2016, and support will no longer be provided. Accordingly, Red Hat will no longer provide updated packages, including Critical impact security patches or urgent priority bug fixes, for Developer Toolset Version 3.x after October 31, 2016.
c0d5eb7b5cbc315bbcea623b58371139
Debian Linux Security Advisory 3560-1 - Several vulnerabilities were found in PHP, a general-purpose scripting language commonly used for web application development.
41a933eee7d30ee30a8e376640625e3d
Apache Cordova iOS versions 3.9.1 and below suffer from an access bypass vulnerability.
d3e27114a3b585742111bbdb0e732900
Apache Cordova iOS versions 3.9.1 and below allow for arbitrary plugin execution.
ff85ca99ae191e3adac2d159263e6b8f
PacketFence is a network access control (NAC) system. It is actively maintained and has been deployed in numerous large-scale institutions. It can be used to effectively secure networks, from small to very large heterogeneous networks. PacketFence provides NAC-oriented features such as registration of new network devices, detection of abnormal network activities including from remote snort sensors, isolation of problematic devices, remediation through a captive portal, and registration-based and scheduled vulnerability scans.
a0198d0ae9df05ec91c004936be2884b
A Microsoft Windows kernel crash exists in the win32k.sys driver while processing a corrupted TTF font file.
03655c617bca96ec7e0f05501dd92609
If an application sends a one way binder transaction the service tries to send a reply which fails. This causes the service manager to exit its binder loop and the process dies causing the system to reboot. Tested on Android version 6.0.1 February patches.
99e18c7b5134fd0d4dcd4383654d1372
Ubuntu Security Notice 2936-1 - Christian Holler, Tyson Smith, Phil Ringalda, Gary Kwong, Jesse Ruderman, Mats Palmgren, Carsten Book, Boris Zbarsky, David Bolter, Randell Jesup, Andrew McCreight, and Steve Fink discovered multiple memory safety issues in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. Various other issues were also addressed.
9dda7e88d57a605520c6b4c443e20fac
Ubuntu Security Notice 2934-1 - Bob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, Daniel Holbert, Jesse Ruderman, and Randell Jesup discovered multiple memory safety issues in Thunderbird. If a user were tricked in to opening a specially crafted message, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Thunderbird. Various other issues were also addressed.
b201b017c2e8ff3aad7d9a0824d057b3
Ubuntu Security Notice 2955-1 - A use-after-free was discovered when responding synchronously to permission requests. An attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking the program. An out-of-bounds read was discovered in V8. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash. Various other issues were also addressed.
dc07d36baf6262e0f5d1e242b1ed2d1e
Debian Linux Security Advisory 3559-1 - Multiple security issues have been found in Iceweasel, Debian's version buffer overflows may lead to the execution of arbitrary code or denial of service.
a2f97b7e4e9a5ecd1eb8f0f2616d7fe1
Ubuntu Security Notice 2952-2 - USN-2952-1 fixed vulnerabilities in PHP. One of the backported patches caused a regression in the PHP Soap client. This update fixes the problem. It was discovered that the PHP Zip extension incorrectly handled directories when processing certain zip files. A remote attacker could possibly use this issue to create arbitrary directories. It was discovered that the PHP Soap client incorrectly validated data types. A remote attacker could use this issue to cause PHP to crash, resulting in a denial of service, or possibly execute arbitrary code. Various other issues were also addressed.
46573c2a67141cd49c531625378337dc
Ubuntu Security Notice 2950-2 - USN-2950-1 fixed vulnerabilities in Samba. The updated Samba packages introduced a compatibility issue with NTLM authentication in libsoup. This update fixes the problem. Jouni Knuutinen discovered that Samba contained multiple flaws in the DCE/RPC implementation. A remote attacker could use this issue to perform a denial of service, downgrade secure connections by performing a man in the middle attack, or possibly execute arbitrary code. Various other issues were also addressed.
4378a3e1b91e771dd7893d559ac783d4
This is a SUID, SIP, and binary entitlements universal OS X local privilege escalation exploit.
5e928a94c937ab6683178d70d0000c4e
EMC ViPR SRM versions prior to 3.7 suffer from a cross site request forgery vulnerability.
5c998f817d0bd863cd2844f5ca0014b5
AWS appears to suffer from a CAPTCHA bypass vulnerability.
c4514c132311303459541cc65e978f96
Voo branded Netgear CG3700b custom firmware version 2.02.03 suffers from cross site request forgery and insufficient authentication vulnerabilities.
f56165d9368729c1623e374b5e46c6e3
The CSRSS BaseSrv RPC call BaseSrvCheckVDM allows you to create a new process with the anonymous token, which results on a new process in session 0 which can be abused to elevate privileges.
b53f1c042d141766251ba3d2c5ce4315