OpenEDX platform Ironwood version 2.5 suffers from a remote code execution vulnerability.
7a54e38627d6ca731048e6e1fe6e6741c718fa2f3cd5f6374e5ad4c2c7cf6dd0
PHP-Fusion version 9.03.50 has been found susceptible to additional methods of persistent cross site scripting. Initial findings in this version were discovered by SunCSR.
c6b9922795d11a23e3b4151c57c54613d48ea125dc0bc2b428d1acbb0c0f9f47
Composr CMS version 10.0.30 suffers from a persistent cross site scripting vulnerability.
bd0304dc55718b3129060de9dd8a6ac6f198948bfb00573ed86879db126f081e
Ubuntu Security Notice 4365-2 - USN-4365-1 fixed several vulnerabilities in Bind. This update provides the corresponding update for Ubuntu 12.04 ESM and 14.04 ESM. Lior Shafir, Yehuda Afek, and Anat Bremler-Barr discovered that Bind incorrectly limited certain fetches. A remote attacker could possibly use this issue to cause Bind to consume resources, leading to a denial of service, or possibly use Bind to perform a reflection attack. Various other issues were also addressed.
8cd4885ea870121ddb49aa2e9497c23e099b8e054c205f6250e8608d3a33b714
Red Hat Security Advisory 2020-2242-01 - The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Issues addressed include double free, null pointer, and use-after-free vulnerabilities.
2cb694524e3da29b25481569692ca7d659c95c88727071a36fd595125f080c3f
Red Hat Security Advisory 2020-2241-01 - IBM Java SE version 8 includes the IBM Java Runtime Environment and the IBM Java Software Development Kit. This update upgrades IBM Java SE 8 to version 8 SR6-FP10. Issues addressed include crlf injection, denial of service, and deserialization vulnerabilities.
f0a00e6c2897e3b34f4d76a502cf33a9b6b3a5bb92185c584430653540491778
CloudMe version 1.11.2 SEH / DEP / ASLR buffer overflow exploit. The original discovery of this vulnerability was by hyp3rlinx.
f9b36ce85715513e6297fe5545cc87bca3c5904d7f17206e43521ab4744650b8
Wireshark is a GTK+-based network protocol analyzer that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercial-quality analyzer for Unix and Win32 and to give Wireshark features that are missing from closed-source sniffers.
d17d461e849e2d0b033431c45f71d8ee8ec3c8faa232a6ad63069a47927db8aa
Red Hat Security Advisory 2020-2239-01 - IBM Java SE version 8 includes the IBM Java Runtime Environment and the IBM Java Software Development Kit. This update upgrades IBM Java SE 8 to version 8 SR6-FP10. Issues addressed include crlf injection, denial of service, and deserialization vulnerabilities.
b8f9324d92710ea91ef72655d4d78c1b86a5965071456524e5ff06267798ab5a
Red Hat Security Advisory 2020-2237-01 - IBM Java SE version 8 includes the IBM Java Runtime Environment and the IBM Java Software Development Kit. This update upgrades IBM Java SE 8 to version 8 SR6-FP10. Issues addressed include crlf injection, denial of service, and deserialization vulnerabilities.
ce74563b510055121357a0449cb19d6264fd6cd97bee55a37601d36a933b8be1
Red Hat Security Advisory 2020-2238-01 - IBM Java SE version 7 Release 1 includes the IBM Java Runtime Environment and the IBM Java Software Development Kit. This update upgrades IBM Java SE 7 to version 7R1 SR4-FP65. Issues addressed include crlf injection, denial of service, and deserialization vulnerabilities.
8ae670ed3e6ca90af274c345c8a84e83c905c215fa9d79e2541e1a64e5e98f64
Red Hat Security Advisory 2020-2236-01 - IBM Java SE version 7 Release 1 includes the IBM Java Runtime Environment and the IBM Java Software Development Kit. This update upgrades IBM Java SE 7 to version 7R1 SR4-FP65. Issues addressed include crlf injection, denial of service, and deserialization vulnerabilities.
213e907f08a54134a0d5d6adf53b9b6c58cdaaf6f0d8173b0184f2ba61722ac1
Ubuntu Security Notice 4367-1 - It was discovered that the btrfs implementation in the Linux kernel did not properly detect that a block was marked dirty in some situations. An attacker could use this to specially craft a file system image that, when unmounted, could cause a denial of service. It was discovered that the linux kernel did not properly validate certain mount options to the tmpfs virtual memory file system. A local attacker with the ability to specify mount options could use this to cause a denial of service. Various other issues were also addressed.
321685a1adbdcccf734ad851c77e79c05483bf554e2914c4f09a4d1df26c8252
Ubuntu Security Notice 4368-1 - Tristan Madani discovered that the file locking implementation in the Linux kernel contained a race condition. A local attacker could possibly use this to cause a denial of service or expose sensitive information. It was discovered that the Serial CAN interface driver in the Linux kernel did not properly initialize data. A local attacker could use this to expose sensitive information. Various other issues were also addressed.
e6d9dc36e87b107c541d9e200b7670120dd2a6f0e812c4b8530369abbb224c18
Craft CMS 3 with vCard plugin version 1.0.0 suffers from a remote code execution vulnerability.
ce154e4de28850d7115ccbe4c7a650e9f2d764ccee27790603139f700de8d483