[SECURITY] CVE-2016-8748: Apache NiFi XSS vulnerability in connection details dialogue

2017-01-16 Thread Joe Witt
CVE-2016-8748: Apache NiFi XSS vulnerability in connection details dialogue Severity: Moderate Vendor: The Apache Software Foundation Versions Affected: Apache NiFi 1.0.0 Apache NiFi 1.1.0 Description: There is a cross-site scripting vulnerability in connection details dialog when accessed by

[SECURITY] [DSA 3743-2] python-bottle regression update

2017-01-16 Thread Sebastien Delafond
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-3743-2 secur...@debian.org https://www.debian.org/security/ Sebastien Delafond January 15, 2017

[SECURITY] [DSA 3765-1] icoutils security update

2017-01-16 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-3765-1 secur...@debian.org https://www.debian.org/security/ Salvatore Bonaccorso January 14, 2017

[security bulletin] HPSBGN03689 rev.1 - HPE Diagnostics, Remote Cross-Site Scripting and Click Jacking

2017-01-16 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Note: the current version of the following document is available here: https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05370100 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c05370100 Version: 1 HPSBGN03689 rev.1 - HPE

[security bulletin] HPSBST03671 rev.2 - HPE StoreEver MSL6480 Tape Library Management Interface, Multiple Remote Vulnerabilities

2017-01-16 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Note: the current version of the following document is available here: https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05333297 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c05333297 Version: 2 HPSBST03671 rev.2 - HPE

[SECURITY] [DSA 3764-1] pdns security update

2017-01-16 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-3764-1 secur...@debian.org https://www.debian.org/security/ Salvatore Bonaccorso January 13, 2017