The Vulnerability Laboratory Core Research Team discovered a local command inject vulnerability in the LAN Scan HD v1.20 iOS mobile application.
>> ARCHIVE: 2015-11
Heap-based out-of-bounds memory reads have been encountered in FreeType in the handling of the cmap (format 14) SFNT table.
ATutor versions 2.2 and below suffer from a remote unrestricted file upload vulnerability.
ATutor versions 2.2 and below suffer from a cross site scripting vulnerability.
ATutor versions 2.2 and below suffer from a remote php code injection vulnerability.
Piwik version 2.14.3 and below suffer from a local file inclusion vulnerability.
Piwik versions 2.14.3 and below suffer from a PHP object injection vulnerability that can lead to remote code execution.
vBulletin 5.1.x – PreAuth 0day Remote Code Execution Exploit
JSSE SKIP-TLS Exploit
OpenSSL Alternative Chains Certificate Forgery