WordPress XSS vulnerability

  WordPress 4.2.2 is now available. This is a critical security release for all previous versions and we strongly encourage you to update your sites immediately. Version 4.2.2 addresses two security issues: The Genericons icon font package, which is used in a number of popular themes and plugins, contained an HTML file vulnerable to a cross-site scripting attack. All affected themes...
Read More

Xen Security Advisory CVE-2015-3340 / XSA-132 V2

ISSUE DESCRIPTION ================= The handler for XEN_DOMCTL_gettscinfo failed to initialize a padding field subsequently copied to guest memory. A similar leak existed in XEN_SYSCTL_getdomaininfolist, which is being addressed here regardless of that operation being declared unsafe for disaggregation by XSA-77. IMPACT ====== Malicious or buggy stub domain kernels or tool stacks ...
Read More

CVE-2015-0235 – GLIBC Ghost

Background Information GHOST is a 'buffer overflow' bug affecting the gethostbyname() and gethostbyname2() function calls in the glibc library. This vulnerability allows a remote attacker that is able to make an application call to either of these functions to execute arbitrary code with the permissions of the user running the application. Impact The gethostbyname() function calls are used for ...
Read More