[FD] CVE-2014-1785: MSIE 11 MSHTML CSpliceTreeEngine::RemoveSplice use-after-free

2016-12-20 Thread Berend-Jan Wever
Since November I have been releasing details on all vulnerabilities I found that I have not released before. This is the 36th entry in the series. This information is available in more detail on my blog at http://blog.skylined.nl/20161220001.html. There you can find a repro that triggered this

[FD] New BlackArch Linux ISOs (2016.12.20) released!

2016-12-20 Thread Black Arch
Dear list, We've released the new BlackArch Linux ISOs along with many improvements. They include more than 1600 tools now. The armv6h and armv7h repositories are filled with about 1400 tools. The x86_64 and i686 live ISOs now exceeds 6GB! A short ChangeLog of the Live-ISOs: - include

[FD] [ERPSCAN-16-035] SAP Solman - user accounts disclosure

2016-12-20 Thread ERPScan inc
Application: SAP Solman Versions Affected: SAP Solman 7.1-7.31 Vendor URL: http://SAP.com Bugs: Information Disclosure Sent: 12.07.2016 Reported: 13.07.2016 Vendor response: 13.07.2016 Date of Public Advisory: 13.09.2016 Reference: SAP Security Note 2344524 Author: Roman Bezhan (ERPScan)

[FD] NEW VMSA-2016-0023 VMware ESXi updates address a cross-site scripting issue

2016-12-20 Thread VMware Security Response Center
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- VMware Security Advisory Advisory ID: VMSA-2016-0023 Severity:Important Synopsis:VMware ESXi updates address a cross-site scripting issue Issue date: