ESA-2016-061: EMC Isilon OneFS SMB Signing Vulnerability

2016-05-26 Thread Security Alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ESA-2016-061: EMC Isilon OneFS SMB Signing Vulnerability EMC Identifier: ESA-2016-061 CVE Identifier: CVE-2016-0907 Severity Rating: CVSSv3 Base Score: 5.9 (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N) Affected products: EMC IsilonSD Edge OneFS

[CVE-2016-4434] Apache Tika XML External Entity vulnerability

2016-05-26 Thread Tim Allison
CVE-2016-4434: Apache Tika XML External Entity vulnerability Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tika 0.10 to 1.12 Description: Apache Tika parses XML within numerous file formats. In some instances[1], the initialization ofthe XML parser o

[CVE-2016-2175] Apache PDFBox XML External Entity vulnerability

2016-05-26 Thread Andreas Lehmkuehler
CVE-2016-2175: Apache PDFBox XML External Entity vulnerability Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache PDFBox 1.8.0 to 1.8.11 Apache PDFBox 2.0.0 Earlier, unsupported Apache PDFBox versions may be affected as well Description: Apache PDFBox parses