CuteNews version 1.3.1 is susceptible to a cross site scripting flaw.
7ed2bbb81e542045e1ee215883d3871bb25403d00ee7161199bfb071268e10bd
During the client-side Windows installation of Lotus Notes, a notes: URL handler is registered in the registry. An argument injection attack allows an intruder to pass command line arguments to notes.exe, which can lead to execution of arbitrary code.
7f1d5d7fa6e4854573d335dc29ba01617e06478c0fbeabab00dc2a8338959037
The Zone-H Security Team has discovered a SQL injection flaw in Infinity WEB that allows malicious attackers to bypass the authentication mechanism without having an account.
38f4ddea3d5eb05ff4217cd5f69e210542b334b36ba152257c34449d81ff759e
All versions of MPlayer, the movie player for Linux, are vulnerable to a buffer overflow attack that allows for privilege escalation. Local exploit included. Tested against Redhat Linux with Gnome, FreeBSD and latest cvsup plus ports with Gnome.
6850af71802ee705a1be21d2e279558327d7f8c14f4363ad429d736e33bfa329