Lynis is an auditing tool for Unix (specialists). It scans the system and available software to detect security issues. Beside security related information it will also scan for general system information, installed packages and configuration mistakes. This software aims in assisting automated auditing, software patch management, vulnerability and malware scanning of Unix based systems.
29b119f93755e76b24c292f58469247b7ed3c593f1fcdc6b314b9c6e6d715139
HP Security Bulletin HPSBPI02945 - A potential security vulnerability has been identified with HP Officejet Pro 8500 (A909) All-in-One Printer. The vulnerability could be exploited to allow cross-site scripting (XSS). Revision 1 of this advisory.
b35d3e26c887cc8ced416f5a609f91e7caa6519c7d6912a6951f58c370a236b8
HP Security Bulletin HPSBUX02944 - Potential security vulnerabilities have been identified in Java Runtime Environment (JRE) and Java Developer Kit (JDK) running on HP-UX. These vulnerabilities could allow remote unauthorized access, disclosure of information, and other exploits. Revision 1 of this advisory.
9e4e72fa0d68d78d12e2dca17b344d718317f33ab7e2a0548b43475b3fc95a2a
HP Security Bulletin HPSBUX02943 - Potential security vulnerabilities have been identified in the Java Runtime Environment (JRE) and the Java Developer Kit (JDK) running on HP-UX. These vulnerabilities could allow remote unauthorized access, disclosure of information, and other exploits. Revision 1 of this advisory.
0b06219b99634e2760b32a91db4192e4ffbc72b3b3d7c83e3979ed1cc7fe4be5
Red Hat Security Advisory 2013-1815-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A memory corruption flaw was found in the way the openssl_x509_parse() function of the PHP openssl extension parsed X.509 certificates. A remote attacker could use this flaw to provide a malicious self-signed certificate or a certificate signed by a trusted authority to a PHP application using the aforementioned function, causing the application to crash or, possibly, allow the attacker to execute arbitrary code with the privileges of the user running the PHP interpreter.
bcd0697b2635538663653e7ec4d16dcebac059d0efa3b56042b720b77fdd07d1
Red Hat Security Advisory 2013-1813-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A memory corruption flaw was found in the way the openssl_x509_parse() function of the PHP openssl extension parsed X.509 certificates. A remote attacker could use this flaw to provide a malicious self-signed certificate or a certificate signed by a trusted authority to a PHP application using the aforementioned function, causing the application to crash or, possibly, allow the attacker to execute arbitrary code with the privileges of the user running the PHP interpreter.
2ed3a5238acb93b671efe0450e767b6c5b0faacc0e027c813efd637c3d21c496
Red Hat Security Advisory 2013-1814-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A memory corruption flaw was found in the way the openssl_x509_parse() function of the PHP openssl extension parsed X.509 certificates. A remote attacker could use this flaw to provide a malicious self-signed certificate or a certificate signed by a trusted authority to a PHP application using the aforementioned function, causing the application to crash or, possibly, allow the attacker to execute arbitrary code with the privileges of the user running the PHP interpreter.
a4e1d08541902fd7fe4e90fbe8ae7921cd07ad583ab8f09120fdca658d4ada1c
Red Hat Security Advisory 2013-1812-01 - Mozilla Firefox is an open source web browser. XULRunner provides the XUL Runtime environment for Mozilla Firefox. Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to terminate unexpectedly or, potentially, execute arbitrary code with the privileges of the user running Firefox. A flaw was found in the way Firefox rendered web content with missing character encoding information. An attacker could use this flaw to possibly bypass same-origin inheritance and perform cross-site scripting attacks.
040943e2a4cdfeb053110f692259e15bb3c72d087ba11c91c00263aeb9430f21
Core Security Technologies Advisory - IcoFX is prone to a (client side) security vulnerability when processing .ICO files. This vulnerability could be exploited by a remote attacker to execute arbitrary code on the target machine, by enticing the user of IcoFX to open a specially crafted icon file. Version 2.5.0.0 for Windows is affected.
e6dff7d349a0e93cb8dcc794915fdfde76e566041ccccf904fc0244c16a59b12
This paper presents a newly discovered vulnerability in the Android Framework which breaks its sandbox environment. This vulnerability affects many Android applications including ones which are bundled with every Android device. The vulnerability has been patched in Android KitKat.
8f72a7311a831bdaa7811567902e82d2dd42a9aadddb39fc579d481b96535d75
Veno File Manager suffers from an arbitrary file download vulnerability. The vendor has contacted Packet Storm and has noted that this has been addressed starting in version 1.0.3.
80512b799f75ba354914c5888ab9ecd01e3b541be21758a5632997f5fbc2d7a1
This bulletin summary lists 11 released Microsoft security bulletins for December, 2013.
8bb3daca53ba46ceee67926f5131473ca900264a4bd75c1c15d7f9d78936fa18
This Metasploit module exploits a directory traversal vulnerability on the version 11.52 of HP LoadRunner. The vulnerability exists on the EmulationAdmin web service, specifically in the copyFileToServer method, allowing to upload arbitrary files. This Metasploit module has been tested successfully on HP LoadRunner 11.52 over Windows 2003 SP2.
3ecfa30b0524d6d84a7b8d523d5b32e43379309197e84b8213bd82d2450eebc7
Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication using the RDS component. Its password can by default or by misconfiguration be set to an empty value. This allows you to create a session via the RDS login that can be carried over to the admin web interface even though the passwords might be different. Therefore bypassing authentication on the admin web interface which then could lead to arbitrary code execution. Tested on Windows and Linux with ColdFusion 9.
09ebd63c7a46949c50bf462317ac70d7ecfe31f97bac6c746f870def7e83e007
Gentoo Linux Security Advisory 201312-8 - An integer overflow vulnerability in WebP could lead to arbitrary code execution or Denial of Service. Versions less than 0.2.1 are affected.
5abe7d3448f23f069fb61d4f3a28864383adf5dd8fdf11a357985cbdb1c408c6