[SECURITY] [DSA 3355-1] libvdpau security update

2015-09-10 Thread Alessandro Ghedini
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-3355-1 secur...@debian.org https://www.debian.org/security/ Alessandro Ghedini September 10, 2015

DataTables Security Advisory - XSS Vulnerability - CVE-2015-6584

2015-09-10 Thread Onur Yilmaz
Information Advisory by Netsparker. Name: XSS Vulnerability in DataTables Affected Software : DataTables Affected Versions : 1.10.8 and possibly below Vendor Homepage : https://github.com/DataTables/DataTables Vulnerability Type : Cross-site Scripting Severity : Important Statu

Re: Defense in depth -- the Microsoft way (part 33): arbitrary code execution (and UAC bypass) via RegEdit.exe

2015-09-10 Thread Stefan Kanthak
I wrote ... and forgot some mitigations: [...] > Proof of concept (for Windows 2000 to Windows 10; use your own "sentinel" > instead of mine for Windows NT4): > > 1. get (this is a >32-bit executable [*]; the 64-bit exec