The EMC DPA Illuminator service (DPA_Illuminator.exe) listening on port 8090 (tcp/http) and 8453 (tcp/https) embeds JBOSS servlets (JMXInvokerServlet and EJBInvokerServlet). These JBOSS servlets are vulnerable to a remote code execution vulnerability that allows for execution with NT AUTHORITY\SYSTEM privileges.
9eb60d2f0166c8c5ad74885e575d95784550f7cfa020c432d1df57b5cc8a29c8
Revive Adserver versions 3.0.1 and below suffer from a remote SQL injection vulnerability. The XML-RPC delivery invocation script was failing to escape its input parameters in the same way the other delivery methods do, allowing attackers to inject arbitrary SQL code via the "what" parameter of the delivery XML-RPC methods. Also, the escaping technique used to handle such parameter in the delivery scripts was based on the addslashes PHP function and has now been upgraded to use the dedicated escaping functions for the database in use.
aae6d650022d7cd159dfd9c7aa3425dd04b9ca82313106207d0a48c48043025f
HP Operations Orchestration Central version 9.06 suffers from multiple cross site scripting vulnerabilities.
1cce985e37ff678546bdbfc58d9240c9e77f144952a275bef85b1bd85a23cb13
Apple Security Advisory 2013-12-19-1 - An integer overflow existed in the handling of .motn files which led to an out of bounds memory access. This issue was addressed through improved bounds checking.
83fb4a6f570da86bd1acecf2795a558c8f827f1a3a1eadb210d497faad840f22
RSA Archer GRC versions 5.4 P2 and 5.4 SP1 contain fixes for multiple cross site scripting vulnerabilities that could potentially be exploited by malicious users to compromise the affected system.
2ce8ca4e1e93acdd8a8433a7feff22bda50be99dc851f0979581da0574f407d2
du Mobile Broadband version 16.002.03.16.124 suffers from a local privilege escalation vulnerability due to improper permissions.
2c70f2ccec1017caae9ab7e58c850bf30dd22596312e63d647efc6b69e032bcc
The Apache Santuario XML Security for Java project is vulnerable to a Denial of Service (DoS) type attack leading to an OutOfMemoryError, which is caused by allowing Document Type Definitions (DTDs) when applying Transforms. From the 1.5.6 release onwards, DTDs will not be processed at all when the "secure validation" mode is enabled.
8718e8b28ba92f0c8d1021a89a00f91b0c89c346b43d6b5dba5031eb339cb16c
MBB CMS versions 004 and below suffer from local file inclusion and remote SQL injection vulnerabilities.
398c2a077d4abbc969a441b3fd784add2425de7c3d23257f5dcdd5847b8a0415
Codiad version 2.0.7 suffers from a persistent cross site scripting vulnerability.
6fd396ea8dd173caabd6c81d45224dd5d0b1746c6bb28918a6904caa9714cd8c
Core Security Technologies Advisory - RealPlayer is prone to a security vulnerability when processing RMP files. This vulnerability could be exploited by a remote attacker to execute arbitrary code on the target machine, by enticing RealPlayer users to open a specially crafted RMP file (client-side attack). Versions 16.0.2.32 and 16.0.3.51 are affected.
138c669ee28a20c01fad95f2ddae01490a953b8043d0631d15f8c2f418a3d9c1
HP Security Bulletin HPSBGN02950 - A potential security vulnerability has been identified in HP Autonomy Ultraseek. The vulnerability could be exploited as cross-site scripting (XSS). Revision 1 of this advisory.
e4fb0ebcfafaf42700c0a3aacf329b2205389329661f3cecad27218e4cb439bf
Drupal Ubercart third party module versions 6.x and 7.x suffer from a session fixation vulnerability.
9ec60eea550b5d680533fd41cd5b758f5099d04826925243e66b12879d6ec282
The InfoSec Southwest 2014 Call For Papers has been announced. The conference will be held April 4th through April 6th, 2014 in Austin, Texas.
339a930fc5b597160bf708c5dda8c237525d45a61ee405ab1c0dbb30e4ec22a5
Song Exporter version 2.1.1 RS suffers from a local file inclusion vulnerability.
ea65da253d616e40f5ffe502874617705b1161d1a0b2f8c0e9df02a8b9936669
WordPress Persuasion Theme suffers from an arbitrary file download and deletion vulnerability.
2a70725a6c45899c35c6c0202c7202b59dda01342cecd7705353378bc1f85037
phpMyRecipes version 1.x.x suffers from cross site request forgery, cross site scripting, and remote SQL injection vulnerabilities.
717dd33446428aed6b6a79a2fadd94fc507d0138e82b80c3ab389ab431f81f92