Flexense DiskSorter versions 9.5.12 through 10.7 suffer from a cross site scripting vulnerability.
Arastta version 1.6.2 suffers from a cross site scripting vulnerability.
Trovebox versions 4.0.0-rc6 and below suffer from authentication bypass, server-side request forgery, unsafe token generation, nd remote SQL injection vulnerabilities.
If the /install/ directory was not removed, it is possible for an unauthenticated attacker to run the “install_4.php” script, which will create the configuration file for the installation. This allows…
GPON Routers – Authentication Bypass / Command Injection
http://coop.ocsc.go.th/vuln.htm notified by zakiloup
There is a use-after-free security vulnerability in WebKit. The vulnerability was confirmed on ASan build of revision 227958 on OSX.
Call of Duty Modern Warefare 2 – Buffer Overflow
LibreOffice/Open Office – ‘.odt’ Information Disclosure
Exim < 4.90.1 – base64d Remote Code Execution