<?xml version="1.0"?>
<rss version="2.0" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:yt="http://gdata.youtube.com/schemas/2007" xmlns:atom="http://www.w3.org/2005/Atom">
   <channel>
      <title>eci final</title>
      <description>Pipes Output</description>
      <link>http://pipes.yahoo.com/pipes/pipe.info?_id=8af12a586c435709cd393c4e91aa6a97</link>
      <atom:link rel="next" href="http://pipes.yahoo.com/pipes/pipe.run?_id=8af12a586c435709cd393c4e91aa6a97&amp;_render=rss&amp;page=2"/>
      <pubDate>Thu, 01 Oct 2015 23:12:52 +0000</pubDate>
      <generator>http://pipes.yahoo.com/pipes/</generator>
      <item>
         <title>VMware Releases Security Advisory</title>
         <link>http://www.us-cert.gov/ncas/current-activity/2015/10/01/VMware-Releases-Security-Advisory</link>
         <description>Original release date: October 01, 2015&lt;br /&gt;
	
		&lt;p&gt;VMware has released security updates to address security vulnerabilities in vCenter and ESXi. Exploitation of one of these vulnerabilities may allow a remote attacker to take control of an affected system.&lt;/p&gt;&lt;p&gt;Users and administrators are encouraged to review &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.vmware.com/security/advisories/VMSA-2015-0007.html&quot;&gt;VMware Security Advisory VMSA-2015-0007&lt;/a&gt; and apply the necessary updates.&lt;/p&gt;		
		&lt;hr /&gt;
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;		&lt;br /&gt;</description>
         <guid isPermaLink="false">6269 at http://www.us-cert.gov</guid>
         <pubDate>Thu, 01 Oct 2015 23:06:20 +0000</pubDate>
      </item>
      <item>
         <title>Apple Releases Security Updates for OS X El Capitan, Safari, and iOS</title>
         <link>http://www.us-cert.gov/ncas/current-activity/2015/09/30/Apple-Releases-Security-Updates-OS-X-El-Capitan-Safari-and-iOS</link>
         <description>Original release date: September 30, 2015&lt;br /&gt;
	
		&lt;p&gt;Apple has released security updates for OS X El Capitan, Safari, and iOS to address multiple vulnerabilities. Exploitation of some of these vulnerabilities may allow an attacker to run arbitrary code.&lt;/p&gt;&lt;p&gt;Available updates include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;OS X El Capitan 10.11 for Mac OS X v10.6.8 and later&lt;/li&gt;&lt;li&gt;Safari 9 for OS X Mavericks v10.9.5, OS X Yosemite v10.10.5, and OS X El Capitan v10.11&lt;/li&gt;&lt;li&gt;iOS 9.0.2 for iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;US-CERT encourages users and administrators to review Apple security updates for &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/en-us/HT205267&quot;&gt;OS X El Capitan&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/en-us/HT205265&quot;&gt;Safari&lt;/a&gt;, and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/en-us/HT205284&quot;&gt;iOS&lt;/a&gt; and apply the necessary updates.&lt;/p&gt;		
		&lt;hr /&gt;
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;		&lt;br /&gt;</description>
         <guid isPermaLink="false">6268 at http://www.us-cert.gov</guid>
         <pubDate>Thu, 01 Oct 2015 01:32:15 +0000</pubDate>
      </item>
      <item>
         <title>SB15-271: Vulnerability Summary for the Week of September 21, 2015</title>
         <link>http://www.us-cert.gov/ncas/bulletins/SB15-271</link>
         <description>Original release date: September 28, 2015		&lt;br /&gt;
		&lt;p&gt;The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.nist.gov&quot;&gt;National Institute of Standards and Technology&lt;/a&gt; (NIST) &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://nvd.nist.gov&quot;&gt;National Vulnerability Database&lt;/a&gt; (NVD) in the past week. The NVD is sponsored by the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.dhs.gov&quot;&gt;Department of Homeland Security&lt;/a&gt; (DHS) &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.us-cert.gov/nccic&quot;&gt;National Cybersecurity and Communications Integration Center&lt;/a&gt; (NCCIC) / &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.us-cert.gov&quot;&gt;United States Computer Emergency Readiness Team&lt;/a&gt; (US-CERT). For modified or updated entries, please visit the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://nvd.nist.gov&quot;&gt;NVD&lt;/a&gt;, which contains historical vulnerability information.&lt;/p&gt;&lt;p&gt;The vulnerabilities are based on the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://cve.mitre.org/&quot;&gt;CVE&lt;/a&gt; vulnerability naming standard and are organized according to severity, determined by the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://nvd.nist.gov/cvss.cfm&quot;&gt;Common Vulnerability Scoring System&lt;/a&gt; (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;strong&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;#high&quot;&gt;High&lt;/a&gt;&lt;/strong&gt; - Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 - 10.0&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;strong&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;#medium&quot;&gt;Medium&lt;/a&gt;&lt;/strong&gt; - Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 - 6.9&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;strong&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;#low&quot;&gt;Low&lt;/a&gt;&lt;/strong&gt; - Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 - 3.9&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis.&lt;/p&gt;
		&lt;p&gt;&lt;a rel=&quot;nofollow&quot; name=&quot;high&quot; id=&quot;high&quot;&gt;&lt;/a&gt;&lt;/p&gt;&lt;div id=&quot;high_v&quot;&gt;&lt;h2 id=&quot;high_v_title&quot;&gt;High Vulnerabilities&lt;/h2&gt;&lt;table align=&quot;center&quot; border=&quot;1&quot;&gt;&lt;thead&gt;&lt;tr&gt;&lt;th scope=&quot;col&quot; style=&quot;width:24%;&quot;&gt;Primary&lt;br /&gt;Vendor -- Product&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:44%;&quot;&gt;Description&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:8%;&quot;&gt;Published&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:4%;&quot;&gt;CVSS Score&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:10%;&quot;&gt;Source &amp;amp; Patch Info&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;3s-smart -- codesys_gateway_server&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Multiple heap-based buffer overflows in 3S-Smart CODESYS Gateway Server before 2.3.9.47 allow remote attackers to execute arbitrary code via opcode (1) 0x3ef or (2) 0x3f0.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6460&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6460&quot;&gt;CVE-2015-6460&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://ics-cert.us-cert.gov/advisories/ICSA-15-258-02&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://zerodayinitiative.com/advisories/ZDI-15-442/&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://zerodayinitiative.com/advisories/ZDI-15-441/&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5579.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5567&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5567&quot;&gt;CVE-2015-5567&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allow attackers to cause a denial of service (vector-length corruption) or possibly have unspecified other impact via unknown vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5568&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5568&quot;&gt;CVE-2015-5568&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5574, CVE-2015-5581, CVE-2015-5584, and CVE-2015-6682.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5570&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5570&quot;&gt;CVE-2015-5570&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allow attackers to execute arbitrary code by leveraging an unspecified &quot;type confusion.&quot;&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5573&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5573&quot;&gt;CVE-2015-5573&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5581, CVE-2015-5584, and CVE-2015-6682.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5574&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5574&quot;&gt;CVE-2015-5574&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5577, CVE-2015-5578, CVE-2015-5580, CVE-2015-5582, CVE-2015-5588, and CVE-2015-6677.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5575&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5575&quot;&gt;CVE-2015-5575&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5578, CVE-2015-5580, CVE-2015-5582, CVE-2015-5588, and CVE-2015-6677.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5577&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5577&quot;&gt;CVE-2015-5577&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5580, CVE-2015-5582, CVE-2015-5588, and CVE-2015-6677.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5578&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5578&quot;&gt;CVE-2015-5578&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5567.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5579&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5579&quot;&gt;CVE-2015-5579&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5578, CVE-2015-5582, CVE-2015-5588, and CVE-2015-6677.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5580&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5580&quot;&gt;CVE-2015-5580&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5574, CVE-2015-5584, and CVE-2015-6682.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5581&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5581&quot;&gt;CVE-2015-5581&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5578, CVE-2015-5580, CVE-2015-5588, and CVE-2015-6677.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5582&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5582&quot;&gt;CVE-2015-5582&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5574, CVE-2015-5581, and CVE-2015-6682.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5584&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5584&quot;&gt;CVE-2015-5584&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Stack-based buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5587&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5587&quot;&gt;CVE-2015-5587&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5578, CVE-2015-5580, CVE-2015-5582, and CVE-2015-6677.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5588&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5588&quot;&gt;CVE-2015-5588&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-6678.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6676&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6676&quot;&gt;CVE-2015-6676&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5578, CVE-2015-5580, CVE-2015-5582, and CVE-2015-5588.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6677&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6677&quot;&gt;CVE-2015-6677&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-6676.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6678&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6678&quot;&gt;CVE-2015-6678&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5574, CVE-2015-5581, and CVE-2015-5584.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6682&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6682&quot;&gt;CVE-2015-6682&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;apple -- mac_os_x_server&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Multiple unspecified vulnerabilities in Twisted in Wiki Server in Apple OS X Server before 5.0.3 allow attackers to have an unknown impact via an XML document.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5911&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5911&quot;&gt;CVE-2015-5911&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205219&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;avira -- management_console&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Use-after-free vulnerability in the Update Manager service in Avira Management Console allows remote attackers to execute arbitrary code via a large header.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-21&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7303&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7303&quot;&gt;CVE-2015-7303&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.zerodayinitiative.com/advisories/ZDI-15-445&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;boxoft -- boxoft_wav_to_mp3_converter&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted WAV file.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7243&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7243&quot;&gt;CVE-2015-7243&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.exploit-db.com/exploits/38035/&quot;&gt;EXPLOIT-DB&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133377/Boxoft-WAV-To-MP3-Converter-Buffer-Overflow.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;cisco -- prime_collaboration_assurance&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended access restrictions, and create administrative accounts or read data from arbitrary tenant domains, via a crafted URL, aka Bug IDs CSCus62671 and CSCus62652.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-19&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4304&amp;amp;vector=(AV:N/AC:L/Au:S/C:C/I:C/A:C)&quot;&gt;9.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4304&quot;&gt;CVE-2015-4304&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150916-pca&quot;&gt;CISCO&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;cisco -- prime_collaboration_assurance&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended login-session read restrictions, and impersonate administrators of arbitrary tenant domains, by discovering a session identifier and constructing a crafted URL, aka Bug IDs CSCus88343 and CSCus88334.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-19&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4306&amp;amp;vector=(AV:N/AC:M/Au:S/C:C/I:C/A:C)&quot;&gt;8.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4306&quot;&gt;CVE-2015-4306&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150916-pca&quot;&gt;CISCO&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;cisco -- prime_collaboration_provisioning&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The web framework in Cisco Prime Collaboration Provisioning before 11.0 allows remote authenticated users to bypass intended access restrictions and create administrative accounts via a crafted URL, aka Bug ID CSCut64111.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-19&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4307&amp;amp;vector=(AV:N/AC:L/Au:S/C:C/I:C/A:C)&quot;&gt;9.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4307&quot;&gt;CVE-2015-4307&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150916-pcp&quot;&gt;CISCO&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;cisco -- telepresence_server_software&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Buffer overflow in the Conference Control Protocol API implementation in Cisco TelePresence Server software before 4.1(2.33) on 7010, MSE 8710, Multiparty Media 310 and 320, and Virtual Machine devices allows remote attackers to cause a denial of service (device crash) via a crafted URL, aka Bug ID CSCuu28277.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6284&amp;amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)&quot;&gt;7.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6284&quot;&gt;CVE-2015-6284&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150916-tps&quot;&gt;CISCO&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;cisco -- prime_network_registrar&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cisco Prime Network Registrar (CPNR) 8.1(3.3), 8.2(3), and 8.3(2) has a default account, which allows local users to obtain root access by leveraging knowledge of the credentials, aka Bug ID CSCuw21825.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6296&amp;amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;7.2&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6296&quot;&gt;CVE-2015-6296&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/viewAlert.x?alertId=41041&quot;&gt;CISCO&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;ge -- mds_pulsenet&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 have hardcoded credentials for a support account, which allows remote attackers to obtain administrative access, and consequently execute arbitrary code, by leveraging knowledge of the password.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6456&amp;amp;vector=(AV:N/AC:L/Au:S/C:C/I:C/A:C)&quot;&gt;9.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6456&quot;&gt;CVE-2015-6456&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://ics-cert.us-cert.gov/advisories/ICSA-15-258-03&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://zerodayinitiative.com/advisories/ZDI-15-440/&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.gedigitalenergy.com/app/resources.aspx?prod=pulsenet&amp;amp;type=9&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;ge -- mds_pulsenet&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 allows remote attackers to read or delete arbitrary files via a full pathname.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6459&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6459&quot;&gt;CVE-2015-6459&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://ics-cert.us-cert.gov/advisories/ICSA-15-258-03&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://zerodayinitiative.com/advisories/ZDI-15-439/&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.gedigitalenergy.com/app/resources.aspx?prod=pulsenet&amp;amp;type=9&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4500&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4500&quot;&gt;CVE-2015-4500&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1202844&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1201793&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1186962&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1183153&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1181651&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1161063&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1152026&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1044077&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-96.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4501&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4501&quot;&gt;CVE-2015-4501&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1186657&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1165706&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-96.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Use-after-free vulnerability in the HTMLVideoElement interface in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to execute arbitrary code via crafted JavaScript code that modifies the URI table of a media element, aka ZDI-CAN-3176.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4509&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4509&quot;&gt;CVE-2015-4509&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1198435&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-106.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Mozilla Firefox before 41.0 allows remote attackers to bypass certain ECMAScript 5 (aka ES5) API protection mechanisms and modify immutable properties, and consequently execute arbitrary JavaScript code with chrome privileges, via a crafted web page that does not use ES5 APIs.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4516&amp;amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)&quot;&gt;9.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4516&quot;&gt;CVE-2015-4516&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=904886&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-109.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;NetworkUtils.cpp in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4517&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4517&quot;&gt;CVE-2015-4517&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1168959&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-112.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The ConvertDialogOptions function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4521&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4521&quot;&gt;CVE-2015-4521&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1170246&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-112.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The nsUnicodeToUTF8::GetMaxLength function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors, related to an &quot;overflow.&quot;&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4522&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4522&quot;&gt;CVE-2015-4522&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1170794&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-112.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The nsAttrAndChildArray::GrowBy function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors, related to an &quot;overflow.&quot;&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7174&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7174&quot;&gt;CVE-2015-7174&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1172055&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-112.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The XULContentSinkImpl::AddText function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors, related to an &quot;overflow.&quot;&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7175&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7175&quot;&gt;CVE-2015-7175&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1172189&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-112.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The AnimationThread function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 uses an incorrect argument to the sscanf function, which might allow remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via unknown vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7176&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7176&quot;&gt;CVE-2015-7176&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1174479&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-112.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The InitTextures function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7177&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7177&quot;&gt;CVE-2015-7177&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1186725&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-112.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The ProgramBinary::linkAttributes function in libGLES in ANGLE, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows, mishandles shader access, which allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted (1) OpenGL or (2) WebGL content.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7178&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7178&quot;&gt;CVE-2015-7178&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1189860&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-113.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The VertexBufferInterface::reserveVertexSpace function in libGLES in ANGLE, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows, incorrectly allocates memory for shader attribute arrays, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via crafted (1) OpenGL or (2) WebGL content.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7179&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7179&quot;&gt;CVE-2015-7179&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1190526&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-113.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The ReadbackResultWriterD3D11::Run function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 misinterprets the return value of a function call, which might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7180&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7180&quot;&gt;CVE-2015-7180&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1191463&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-112.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;philippine_long_distance_telephone -- kasda_kw58293_firmware&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Buffer overflow in form2ping.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to cause a denial of service (device outage) via a long ipaddr parameter.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-21&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5993&amp;amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)&quot;&gt;7.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5993&quot;&gt;CVE-2015-5993&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.kb.cert.org/vuls/id/525276&quot;&gt;CERT-VN&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;sap -- netweaver_j2ee_engine&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;SQL injection vulnerability in the BP_FIND_JOBS_WITH_PROGRAM function module in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7239&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7239&quot;&gt;CVE-2015-7239&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://erpscan.com/advisories/erpscan-15-021-sap-netweaver-7-4-bp_find_jobs_with_program-sql-injection/&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;securifi -- almond-2015_firmware&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M have a default password of admin for the admin account, which allows remote attackers to obtain web-management access by leveraging the ability to authenticate from the intranet.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-21&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-2915&amp;amp;vector=(AV:A/AC:L/Au:N/C:P/I:P/A:C)&quot;&gt;7.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-2915&quot;&gt;CVE-2015-2915&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.kb.cert.org/vuls/id/906576&quot;&gt;CERT-VN&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;sqlite -- sqlite&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and attack vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5895&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5895&quot;&gt;CVE-2015-5895&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;symantec -- web_gateway&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging a &quot;redirect.&quot;&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5690&amp;amp;vector=(AV:N/AC:M/Au:S/C:C/I:C/A:C)&quot;&gt;8.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5690&quot;&gt;CVE-2015-5690&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.zerodayinitiative.com/advisories/ZDI-15-444/&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;amp;pvid=security_advisory&amp;amp;year=&amp;amp;suid=20150916_00&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/bid/76725&quot;&gt;BID&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;symantec -- web_gateway&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;admin_messages.php in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary code by uploading a file with a safe extension and content type, and then leveraging an improper Sudo configuration to make this a setuid-root file.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5692&amp;amp;vector=(AV:N/AC:M/Au:M/C:C/I:C/A:C)&quot;&gt;7.9&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5692&quot;&gt;CVE-2015-5692&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.zerodayinitiative.com/advisories/ZDI-15-443/&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;amp;pvid=security_advisory&amp;amp;year=&amp;amp;suid=20150916_00&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/bid/76726&quot;&gt;BID&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;symantec -- web_gateway&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary commands via vectors related to &quot;traffic capture.&quot;&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5693&amp;amp;vector=(AV:N/AC:M/Au:M/C:C/I:C/A:C)&quot;&gt;7.9&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5693&quot;&gt;CVE-2015-5693&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.zerodayinitiative.com/advisories/ZDI-15-444/&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;amp;pvid=security_advisory&amp;amp;year=&amp;amp;suid=20150916_00&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/bid/76731&quot;&gt;BID&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;symantec -- web_gateway&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary commands at boot time via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6547&amp;amp;vector=(AV:N/AC:L/Au:M/C:C/I:C/A:C)&quot;&gt;8.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6547&quot;&gt;CVE-2015-6547&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;amp;pvid=security_advisory&amp;amp;year=&amp;amp;suid=20150916_00&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/bid/76730&quot;&gt;BID&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;vboxcomm -- satellite_express_protocol&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary physical memory locations and gain privileges via a 0x00000ffd ioctl call.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-21&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6923&amp;amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;7.2&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6923&quot;&gt;CVE-2015-6923&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.korelogic.com/Resources/Advisories/KL-001-2015-005.txt&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.exploit-db.com/exploits/38225/&quot;&gt;EXPLOIT-DB&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/archive/1/archive/1/536491/100/0/threaded&quot;&gt;BUGTRAQ&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/fulldisclosure/2015/Sep/72&quot;&gt;FULLDISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov#top&quot;&gt;Back to top&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;a rel=&quot;nofollow&quot; name=&quot;medium&quot; id=&quot;medium&quot;&gt;&lt;/a&gt;&lt;/p&gt;&lt;div id=&quot;medium_v&quot;&gt;&lt;h2 id=&quot;medium_v_title&quot;&gt;Medium Vulnerabilities&lt;/h2&gt;&lt;table align=&quot;center&quot; border=&quot;1&quot;&gt;&lt;thead&gt;&lt;tr&gt;&lt;th scope=&quot;col&quot; style=&quot;width:24%;&quot;&gt;Primary&lt;br /&gt;Vendor -- Product&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:44%;&quot;&gt;Description&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:8%;&quot;&gt;Published&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:4%;&quot;&gt;CVSS Score&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:10%;&quot;&gt;Source &amp;amp; Patch Info&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671 and CVE-2014-5333.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5571&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5571&quot;&gt;CVE-2015-5571&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5572&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5572&quot;&gt;CVE-2015-5572&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5576&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5576&quot;&gt;CVE-2015-5576&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;adobe -- air&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &amp;amp; Compiler before 19.0.0.190 allow attackers to bypass the Same Origin Policy and obtain sensitive information via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6679&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6679&quot;&gt;CVE-2015-6679&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The __sflush function in fflush.c in stdio in libc in FreeBSD 10.1 and the kernel in Apple iOS before 9 mishandles failures of the write system call, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a crafted application.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2014-8611&amp;amp;vector=(AV:L/AC:M/Au:N/C:C/I:C/A:C)&quot;&gt;6.9&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-8611&quot;&gt;CVE-2014-8611&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.freebsd.org/security/advisories/FreeBSD-SA-14:27.stdio.asc&quot;&gt;FREEBSD&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://svnweb.freebsd.org/base?view=revision&amp;amp;revision=275665&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The document.cookie API implementation in the CFNetwork Cookies subsystem in WebKit in Apple iOS before 9 allows remote attackers to bypass an intended single-cookie restriction via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-3801&amp;amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3801&quot;&gt;CVE-2015-3801&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- xcode&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows remote attackers to obtain potentially sensitive build information in opportunistic circumstances by leveraging incorrect notification delivery.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5909&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5909&quot;&gt;CVE-2015-5909&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00002.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205217&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The Software Update component in Apple iTunes before 12.3 does not properly handle redirection, which allows man-in-the-middle attackers to discover encrypted SMB credentials via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5920&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5920&quot;&gt;CVE-2015-5920&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;atlassian -- hipchat&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors, related to &quot;Velocity Template Injection Vulnerability.&quot;&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-21&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5603&amp;amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)&quot;&gt;6.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5603&quot;&gt;CVE-2015-5603&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://confluence.atlassian.com/jira/jira-and-hipchat-for-jira-plugin-security-advisory-2015-08-26-776650785.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/archive/1/archive/1/536374/100/0/threaded&quot;&gt;BUGTRAQ&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133401/Jira-HipChat-For-Jira-Java-Code-Execution.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;bolt -- bolt&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7309&amp;amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)&quot;&gt;6.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7309&quot;&gt;CVE-2015-7309&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bolt.cm/newsitem/bolt-2-2-5-released&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.exploit-db.com/exploits/38196/&quot;&gt;EXPLOIT-DB&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.rapid7.com/db/modules/exploit/multi/http/bolt_file_upload&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/fulldisclosure/2015/Aug/66&quot;&gt;FULLDISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133539/CMS-Bolt-2.2.4-File-Upload.html&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blog.curesec.com/article/blog/Bolt-224-Code-Execution-44.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;cisco -- prime_collaboration_assurance&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended system-database read restrictions, and discover credentials or SNMP communities for arbitrary tenant domains, via a crafted URL, aka Bug ID CSCus62656.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-19&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4305&amp;amp;vector=(AV:N/AC:L/Au:S/C:P/I:N/A:N)&quot;&gt;4.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4305&quot;&gt;CVE-2015-4305&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/viewAlert.x?alertId=40520&quot;&gt;CISCO&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150916-pca&quot;&gt;CISCO&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;cisco -- ios&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cisco IOS 15.2(3)E and earlier and IOS XE 3.6(2)E and earlier allow remote attackers to cause a denial of service (functionality loss) via crafted Cisco Discovery Protocol (CDP) packets, aka Bug ID CSCuu25770.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6294&amp;amp;vector=(AV:A/AC:L/Au:N/C:N/I:N/A:C)&quot;&gt;6.1&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6294&quot;&gt;CVE-2015-6294&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/viewAlert.x?alertId=41006&quot;&gt;CISCO&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;cisco -- nx-os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cisco NX-OS 6.1(2)I3(4) and 7.0(3)I1(1) on Nexus 9000 (N9K) devices allows remote attackers to cause a denial of service (CPU consumption or control-plane instability) or trigger unintended traffic forwarding via a Layer 2 packet with a reserved VLAN number, aka Bug ID CSCuw13560.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6295&amp;amp;vector=(AV:A/AC:L/Au:N/C:P/I:N/A:P)&quot;&gt;4.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6295&quot;&gt;CVE-2015-6295&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/viewAlert.x?alertId=40990&quot;&gt;CISCO&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;cisco -- ios_xr&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun36525.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6297&amp;amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6297&quot;&gt;CVE-2015-6297&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/viewAlert.x?alertId=41060&quot;&gt;CISCO&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;cisco -- unity_connection&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;SQL injection vulnerability in the web interface in Cisco Unity Connection 9.1(1.2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted POST request, aka Bug ID CSCuv63824.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6299&amp;amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)&quot;&gt;6.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6299&quot;&gt;CVE-2015-6299&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/viewAlert.x?alertId=41074&quot;&gt;CISCO&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;cisco -- secure_access_control_server&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cisco Secure Access Control Server (ACS) Solution Engine 5.7(0.15) allows remote authenticated users to cause a denial of service (SSH screen process crash) via crafted (1) CLI or (2) GUI commands, aka Bug ID CSCuw24694.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6300&amp;amp;vector=(AV:N/AC:L/Au:S/C:N/I:N/A:P)&quot;&gt;4.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6300&quot;&gt;CVE-2015-6300&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/viewAlert.x?alertId=41087&quot;&gt;CISCO&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;cisco -- asr_9001&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun72171.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6301&amp;amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6301&quot;&gt;CVE-2015-6301&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/viewAlert.x?alertId=41101&quot;&gt;CISCO&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;cisco -- spark&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The Cisco Spark application 2015-07-04 for mobile operating systems does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate, aka Bug IDs CSCut36742 and CSCut36844.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6303&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6303&quot;&gt;CVE-2015-6303&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/viewAlert.x?alertId=41127&quot;&gt;CISCO&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;cisco -- telepresence_server_software&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site request forgery (CSRF) vulnerability in Cisco TelePresence Server software 3.0(2.24) allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCut63718, CSCut63724, and CSCut63760.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6304&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6304&quot;&gt;CVE-2015-6304&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/viewAlert.x?alertId=41128&quot;&gt;CISCO&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;dena -- h20&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Directory traversal vulnerability in H2O before 1.4.5 and 1.5.x before 1.5.0-beta2, when the file.dir directive is enabled, allows remote attackers to read arbitrary files via a crafted URL.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5638&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5638&quot;&gt;CVE-2015-5638&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://h2o.examp1e.net/vulnerabilities.html#CVE-2015-5638&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvndb.jvn.jp/jvndb/JVNDB-2015-000136&quot;&gt;JVNDB&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvn.jp/en/jp/JVN65602714/index.html&quot;&gt;JVN&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;drupaldise -- cms_updater&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal does not properly check access permissions, which allows remote authenticated users to access and change settings by leveraging the &quot;access administration pages&quot; permission.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-21&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7306&amp;amp;vector=(AV:N/AC:M/Au:S/C:N/I:P/A:P)&quot;&gt;4.9&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7306&quot;&gt;CVE-2015-7306&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.drupal.org/node/2569599&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.drupal.org/node/2569111&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;drupaldise -- cms_updater&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site scripting (XSS) vulnerability in the CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the configuration page.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-21&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7307&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7307&quot;&gt;CVE-2015-7307&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.drupal.org/node/2569599&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.drupal.org/node/2569111&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;f5 -- big-ip_advanced_firewall_manager&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The FastL4 virtual server in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.3.0 through 11.5.2 and 11.6.0 through 11.6.0 HF4, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.2.1 through 11.3.0, and BIG-IP PSM 11.2.1 through 11.4.1 allows remote attackers to cause a denial of service (Traffic Management Microkernel restart) via a fragmented packet.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4638&amp;amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4638&quot;&gt;CVE-2015-4638&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.f5.com/kb/en-us/solutions/public/17000/100/sol17155.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securitytracker.com/id/1033578&quot;&gt;SECTRACK&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;ipython -- notebook&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: this was originally reported as a cross-site request forgery (CSRF) vulnerability, but this may be inaccurate.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-21&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6938&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6938&quot;&gt;CVE-2015-6938&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://github.com/jupyter/notebook/commit/dd9876381f0ef09873d8c5f6f2063269172331e3&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://github.com/jupyter/notebook/commit/35f32dd2da804d108a3a3585b69ec3295b2677ed&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://github.com/ipython/ipython/commit/3ab41641cf6fce3860c73d5cf4645aa12e1e5892&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.redhat.com/show_bug.cgi?id=1259405&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/oss-sec/2015/q3/544&quot;&gt;MLIST&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/oss-sec/2015/q3/474&quot;&gt;MLIST&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.fedoraproject.org/pipermail/package-announce/2015-September/166471.html&quot;&gt;FEDORA&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.fedoraproject.org/pipermail/package-announce/2015-September/166460.html&quot;&gt;FEDORA&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;joomla -- joomla!&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site scripting (XSS) vulnerability in the login module in Joomla! 3.4.x before 3.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6939&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6939&quot;&gt;CVE-2015-6939&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securitytracker.com/id/1033541&quot;&gt;SECTRACK&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://developer.joomla.org/security-centre/626-20150908-core-xss-vulnerability.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;mcafee -- mcafee_agent&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Directory traversal vulnerability in the remote log viewing functionality in McAfee Agent (MA) 5.x before 5.0.2 allows remote attackers to obtain sensitive information via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7237&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7237&quot;&gt;CVE-2015-7237&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://kc.mcafee.com/corporate/index?page=content&amp;amp;id=SB10130&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securitytracker.com/id/1033450&quot;&gt;SECTRACK&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;mcafee -- enterprise_security_manager&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) before 9.3.2MR18, 9.4.x before 9.4.2MR8, and 9.5.x before 9.5.0MR7 allow remote authenticated users to execute arbitrary OS commands via a crafted filename, which is not properly handled when downloading the file.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7310&amp;amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)&quot;&gt;6.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7310&quot;&gt;CVE-2015-7310&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://kc.mcafee.com/corporate/index?page=content&amp;amp;id=SB10133&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Mozilla Firefox before 41.0 on Android allows user-assisted remote attackers to spoof address-bar attributes by leveraging lack of navigation after a paste of a URL with a nonstandard scheme, as demonstrated by spoofing an SSL attribute.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4476&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4476&quot;&gt;CVE-2015-4476&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1162372&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-99.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;js/src/proxy/Proxy.cpp in Mozilla Firefox before 41.0 mishandles certain receiver arguments, which allows remote attackers to bypass intended window access restrictions via a crafted web site.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4502&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4502&quot;&gt;CVE-2015-4502&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://hg.mozilla.org/mozilla-central/rev/dc21224de25b&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1105045&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-108.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that were established with a navigator.mozTCPSocket.open method call and send method calls, which allows remote TCP servers to obtain sensitive information from process memory by reading packet data, as demonstrated by availability of this API in a Firefox OS application.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4503&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4503&quot;&gt;CVE-2015-4503&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=994337&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-97.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The lut_inverse_interp16 function in the QCMS library in Mozilla Firefox before 41.0 allows remote attackers to obtain sensitive information or cause a denial of service (buffer over-read and application crash) via crafted attributes in the ICC 4 profile of an image.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4504&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:P)&quot;&gt;6.4&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4504&quot;&gt;CVE-2015-4504&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1132467&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-98.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;updater.exe in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows allows local users to write to arbitrary files by conducting a junction attack and waiting for an update operation by the Mozilla Maintenance Service.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4505&amp;amp;vector=(AV:L/AC:L/Au:N/C:N/I:C/A:C)&quot;&gt;6.6&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4505&quot;&gt;CVE-2015-4505&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1177861&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-100.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Buffer overflow in the vp9_init_context_buffers function in libvpx, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3, allows remote attackers to execute arbitrary code via a crafted VP9 file.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4506&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4506&quot;&gt;CVE-2015-4506&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1192226&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-101.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41.0, when the Debugger API is enabled, allows remote attackers to cause a denial of service (getSlotRef assertion failure and application exit) or possibly execute arbitrary code via a crafted web site.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4507&amp;amp;vector=(AV:N/AC:H/Au:N/C:P/I:P/A:P)&quot;&gt;5.1&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4507&quot;&gt;CVE-2015-4507&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1192401&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-102.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Race condition in the WorkerPrivate::NotifyFeatures function in Mozilla Firefox before 41.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) by leveraging improper interaction between shared workers and the IndexedDB implementation.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4510&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4510&quot;&gt;CVE-2015-4510&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1200004&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-104.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to execute arbitrary code via a crafted header in a WebM video.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4511&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4511&quot;&gt;CVE-2015-4511&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1200148&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-105.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;gfx/2d/DataSurfaceHelpers.cpp in Mozilla Firefox before 41.0 on Linux improperly attempts to use the Cairo library with 32-bit color-depth surface creation followed by 16-bit color-depth surface display, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) by using a CANVAS element to trigger 2D rendering.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4512&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:P)&quot;&gt;6.4&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4512&quot;&gt;CVE-2015-4512&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1170390&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-107.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow user-assisted remote attackers to bypass intended access restrictions and discover a redirect's target URL via crafted JavaScript code that executes after a drag-and-drop action of an image into a TEXTBOX element.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4519&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4519&quot;&gt;CVE-2015-4519&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1189814&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-110.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to bypass CORS preflight protection mechanisms by leveraging (1) duplicate cache-key generation or (2) retrieval of a value from an incorrect HTTP Access-Control-* response header.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4520&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:N)&quot;&gt;6.4&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4520&quot;&gt;CVE-2015-4520&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1200869&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1200856&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-111.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Mozilla Firefox before 41.0 does not properly restrict the availability of High Resolution Time API times, which allows remote attackers to track last-level cache access, and consequently obtain sensitive information, via crafted JavaScript code that makes performance.now calls.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7327&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7327&quot;&gt;CVE-2015-7327&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1167489&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1153672&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-114.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://arxiv.org/abs/1502.07373&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;newphoria_corporation -- applican&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The runtime engine in the Newphoria applican framework before 1.12.3 for Android and before 1.12.2 for iOS allows attackers to bypass a whitelist.xml URL whitelist protection mechanism and obtain API access via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5632&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5632&quot;&gt;CVE-2015-5632&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvndb.jvn.jp/jvndb/JVNDB-2015-000130&quot;&gt;JVNDB&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvn.jp/en/jp/JVN73346595/index.html&quot;&gt;JVN&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvn.jp/en/jp/JVN73346595/995707/index.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;newphoria_corporation -- auction_camera&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The Newphoria Auction Camera application for iOS and before 1.2 for Android allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5633&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5633&quot;&gt;CVE-2015-5633&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvndb.jvn.jp/jvndb/JVNDB-2015-000131&quot;&gt;JVNDB&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvn.jp/en/jp/JVN71815309/index.html&quot;&gt;JVN&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvn.jp/en/jp/JVN71815309/995707/index.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;newphoria_corporation -- megaphone_music&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The Newphoria MEGAPHONE MUSIC application before 1.1 for Android and before 1.1 for iOS allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5634&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5634&quot;&gt;CVE-2015-5634&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvndb.jvn.jp/jvndb/JVNDB-2015-000132&quot;&gt;JVNDB&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvn.jp/en/jp/JVN83862346/index.html&quot;&gt;JVN&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvn.jp/en/jp/JVN83862346/995707/index.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;newphoria_corporation -- koritore&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The Newphoria Koritore application before 1.1 for Android and before 1.1 for iOS allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5635&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5635&quot;&gt;CVE-2015-5635&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvndb.jvn.jp/jvndb/JVNDB-2015-000133&quot;&gt;JVNDB&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvn.jp/en/jp/JVN24517322/index.html&quot;&gt;JVN&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvn.jp/en/jp/JVN24517322/995707/index.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;newphoria_corporation -- reversi&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The Newphoria Reversi application before 1.0.3 for Android and before 1.2 for iOS allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5636&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5636&quot;&gt;CVE-2015-5636&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvndb.jvn.jp/jvndb/JVNDB-2015-000134&quot;&gt;JVNDB&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvn.jp/en/jp/JVN67586379/index.html&quot;&gt;JVN&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvn.jp/en/jp/JVN67586379/995707/index.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;newphoria_corporation -- 1.1&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The Newphoria Photon application before 1.2 for Android allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5637&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5637&quot;&gt;CVE-2015-5637&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvndb.jvn.jp/jvndb/JVNDB-2015-000135&quot;&gt;JVNDB&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvn.jp/en/jp/JVN19948778/index.html&quot;&gt;JVN&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvn.jp/en/jp/JVN19948778/995707/index.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;ows -- scald&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The Scald module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to fields, which allows remote attackers to obtain sensitive atom property information via vectors involving a &quot;debug context.&quot;&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-21&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7305&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7305&quot;&gt;CVE-2015-7305&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.drupal.org/node/2569631&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.drupal.org/node/2569621&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;pentaho -- business_analytics&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The GetResource servlet in Pentaho Business Analytics (BA) Suite 4.5.x, 4.8.x, and 5.0.x through 5.2.x and Pentaho Data Integration (PDI) Suite 4.3.x, 4.4.x, and 5.0.x through 5.2.x does not restrict access to files in the pentaho-solutions/system folder, which allows remote attackers to obtain passwords and other sensitive information via a file name in the resource parameter.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-22&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6940&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6940&quot;&gt;CVE-2015-6940&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.pentaho.com/entries/78884125-Security-Vulnerability-Announcement-Feb-2015&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/archive/1/archive/1/536477/100/0/threaded&quot;&gt;BUGTRAQ&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133601/Pentaho-5.2.x-BA-Suite-PDI-Information-Disclosure.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;philippine_long_distance_telephone -- kasda_kw58293_firmware&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site request forgery (CSRF) vulnerability in form2WlanSetup.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to hijack the authentication of administrators for requests that perform setup operations, as demonstrated by modifying network settings.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-21&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5991&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5991&quot;&gt;CVE-2015-5991&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.kb.cert.org/vuls/id/525276&quot;&gt;CERT-VN&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;philippine_long_distance_telephone -- kasda_kw58293_firmware&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site scripting (XSS) vulnerability in form2WlanSetup.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to inject arbitrary web script or HTML via the ssid parameter.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-21&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5992&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5992&quot;&gt;CVE-2015-5992&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.kb.cert.org/vuls/id/525276&quot;&gt;CERT-VN&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;redhat -- openshift&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execute arbitrary commands via a crafted request to the Broker.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5274&amp;amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)&quot;&gt;6.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5274&quot;&gt;CVE-2015-5274&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://rhn.redhat.com/errata/RHSA-2015-1808.html&quot;&gt;REDHAT&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;retrospect -- retrospect&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Retrospect and Retrospect Client before 10.0.2.119 on Windows, before 12.0.2.116 on OS X, and before 10.0.2.104 on Linux improperly generate password hashes, which makes it easier for remote attackers to bypass authentication and obtain access to backup files by leveraging a collision.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-21&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-2864&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-2864&quot;&gt;CVE-2015-2864&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.kb.cert.org/vuls/id/101500&quot;&gt;CERT-VN&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.retrospect.com/support/kb/cve_2015_2864&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.youtube.com/watch?v=MB8AL5u7JCA&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;schneider_electric -- struxureware_building_expert_mpm&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Schneider Electric StruxureWare Building Expert MPM before 2.15 does not use encryption for the client-server data stream, which allows remote attackers to discover credentials by sniffing the network.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-3962&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3962&quot;&gt;CVE-2015-3962&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://ics-cert.us-cert.gov/advisories/ICSA-15-258-01&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2015-254-01&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;securifi -- almond-2015_firmware&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M use a fixed source-port number in outbound DNS queries performed on behalf of any device, which makes it easier for remote attackers to spoof responses by using this number for the destination port, a different vulnerability than CVE-2015-7296.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-21&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-2914&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-2914&quot;&gt;CVE-2015-2914&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.kb.cert.org/vuls/id/906576&quot;&gt;CERT-VN&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;securifi -- almond-2015_firmware&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site request forgery (CSRF) vulnerability on Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M allows remote attackers to hijack the authentication of arbitrary users.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-21&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-2916&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-2916&quot;&gt;CVE-2015-2916&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.kb.cert.org/vuls/id/906576&quot;&gt;CERT-VN&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;securifi -- almond-2015_firmware&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M unintentionally omit the X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site that contains a (1) FRAME, (2) IFRAME, or (3) OBJECT element.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-21&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-2917&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-2917&quot;&gt;CVE-2015-2917&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.kb.cert.org/vuls/id/906576&quot;&gt;CERT-VN&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;securifi -- almond-2015_firmware&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M use a linear algorithm for selecting the ID value in the header of a DNS query performed on behalf of the device itself, which makes it easier for remote attackers to spoof responses by including this ID value, as demonstrated by a response containing the address of the firmware update server, a different vulnerability than CVE-2015-2914.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-21&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7296&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7296&quot;&gt;CVE-2015-7296&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.kb.cert.org/vuls/id/906576&quot;&gt;CERT-VN&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;sumome -- google_analyticator&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Multiple cross-site scripting (XSS) vulnerabilities in the Google Analyticator plugin before 6.4.9.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) ga_adsense, (2) ga_admin_disable_DimentionIndex, (3) ga_downloads_prefix, (4) ga_downloads, or (5) ga_outbound_prefix parameter in the google-analyticator page to wp-admin/admin.php.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-21&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6238&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6238&quot;&gt;CVE-2015-6238&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://wordpress.org/plugins/google-analyticator/changelog/&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.netsparker.com/cve-2015-6238-multiple-xss-vulnerabilities-in-google-analyticator/&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://wpvulndb.com/vulnerabilities/8159&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;symantec -- endpoint_protection&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Multiple untrusted search path vulnerabilities in the Manager component in Symantec Endpoint Protection (SEP) before 12.1.6 allow local users to gain privileges via a Trojan horse DLL in an unspecified directory.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2014-9227&amp;amp;vector=(AV:L/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;4.4&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9227&quot;&gt;CVE-2014-9227&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;amp;pvid=security_advisory&amp;amp;year=&amp;amp;suid=20150617_00&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/bid/75203&quot;&gt;BID&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;symantec -- endpoint_protection&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;sysplant.sys in the Manager component in Symantec Endpoint Protection (SEP) before 12.1.6 allows local users to cause a denial of service (blocked system shutdown) by triggering an unspecified deadlock condition.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2014-9228&amp;amp;vector=(AV:L/AC:L/Au:N/C:N/I:N/A:C)&quot;&gt;4.9&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9228&quot;&gt;CVE-2014-9228&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;amp;pvid=security_advisory&amp;amp;year=&amp;amp;suid=20150617_00&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/bid/75202&quot;&gt;BID&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;symantec -- endpoint_protection&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Multiple SQL injection vulnerabilities in interface PHP scripts in the Manager component in Symantec Endpoint Protection (SEP) before 12.1.6 allow remote authenticated users to execute arbitrary SQL commands by leveraging the Limited Administrator role.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2014-9229&amp;amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)&quot;&gt;6.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9229&quot;&gt;CVE-2014-9229&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;amp;pvid=security_advisory&amp;amp;year=&amp;amp;suid=20150617_00&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/bid/75204&quot;&gt;BID&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;symantec -- deployment_solution&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;ghostexp.exe in Ghost Explorer Utility in Symantec Ghost Solutions Suite (GSS) before 3.0 HF2 12.0.0.8010 and Symantec Deployment Solution (DS) before 7.6 HF4 12.0.0.7045 performs improper sign-extend operations before array-element accesses, which allows remote attackers to execute arbitrary code, cause a denial of service (application crash), or possibly obtain sensitive information via a crafted Ghost image.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5689&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5689&quot;&gt;CVE-2015-5689&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://zerodayinitiative.com/advisories/ZDI-15-419/&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;amp;pvid=security_advisory&amp;amp;year=&amp;amp;suid=20150902_00&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/bid/76498&quot;&gt;BID&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;symantec -- web_gateway&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Multiple cross-site scripting (XSS) vulnerabilities in PHP scripts in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, as demonstrated an attack against admin_messages.php.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5691&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5691&quot;&gt;CVE-2015-5691&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.zerodayinitiative.com/advisories/ZDI-15-443/&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;amp;pvid=security_advisory&amp;amp;year=&amp;amp;suid=20150916_00&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/bid/76728&quot;&gt;BID&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;symantec -- web_gateway&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Multiple SQL injection vulnerabilities in a PHP script in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-20&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6548&amp;amp;vector=(AV:N/AC:L/Au:M/C:P/I:P/A:P)&quot;&gt;5.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6548&quot;&gt;CVE-2015-6548&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;amp;pvid=security_advisory&amp;amp;year=&amp;amp;suid=20150916_00&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/bid/76729&quot;&gt;BID&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;vmware -- vcenter_server&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6932&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:N)&quot;&gt;5.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6932&quot;&gt;CVE-2015-6932&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.vmware.com/security/advisories/VMSA-2015-0006.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;xiph -- vorbis-tools&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Buffer overflow in the aiff_open function in oggenc/audio.c in vorbis-tools 1.4.0 and earlier allows remote attackers to cause a denial of service (crash) via a crafted AIFF file.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-21&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6749&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6749&quot;&gt;CVE-2015-6749&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://trac.xiph.org/ticket/2212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://trac.xiph.org/attachment/ticket/2212/0001-oggenc-Fix-large-alloca-on-bad-AIFF-input.patch&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.redhat.com/show_bug.cgi?id=1258443&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.redhat.com/show_bug.cgi?id=1258424&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=797461&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/oss-sec/2015/q3/457&quot;&gt;MLIST&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/oss-sec/2015/q3/455&quot;&gt;MLIST&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.fedoraproject.org/pipermail/package-announce/2015-September/166424.html&quot;&gt;FEDORA&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165555.html&quot;&gt;FEDORA&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov#top&quot;&gt;Back to top&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;a rel=&quot;nofollow&quot; name=&quot;low&quot; id=&quot;low&quot;&gt;&lt;/a&gt;&lt;/p&gt;&lt;div id=&quot;low_v&quot;&gt;&lt;h2 id=&quot;low_v_title&quot;&gt;Low Vulnerabilities&lt;/h2&gt;&lt;table align=&quot;center&quot; border=&quot;1&quot;&gt;&lt;thead&gt;&lt;tr&gt;&lt;th scope=&quot;col&quot; style=&quot;width:24%;&quot;&gt;Primary&lt;br /&gt;Vendor -- Product&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:44%;&quot;&gt;Description&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:8%;&quot;&gt;Published&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:4%;&quot;&gt;CVSS Score&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:10%;&quot;&gt;Source &amp;amp; Patch Info&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;CFNetwork in Apple iOS before 9 relies on the hardware UID for its cache encryption key, which makes it easier for physically proximate attackers to obtain sensitive information by obtaining this UID.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5898&amp;amp;vector=(AV:L/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;2.1&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5898&quot;&gt;CVE-2015-5898&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- xcode&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;IDE Xcode Server in Apple Xcode before 7.0 does not ensure that server traffic is encrypted, which allows remote attackers to obtain sensitive information by sniffing the network.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5910&amp;amp;vector=(AV:A/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;3.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5910&quot;&gt;CVE-2015-5910&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00002.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205217&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;drupaljedi -- amocrm&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site scripting (XSS) vulnerability in the amoCRM module 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified HTTP POST data.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-21&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7304&amp;amp;vector=(AV:N/AC:H/Au:N/C:N/I:P/A:N)&quot;&gt;2.6&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7304&quot;&gt;CVE-2015-7304&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.drupal.org/node/2569587&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.drupal.org/node/2569243&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;mcafee -- threat_intelligence_exchange&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The Secondary server in Threat Intelligence Exchange (TIE) before 1.2.0 uses weak permissions for unspecified (1) configuration files and (2) installation logs, which allows local users to obtain sensitive information by reading the files.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7238&amp;amp;vector=(AV:L/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;2.1&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7238&quot;&gt;CVE-2015-7238&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://kc.mcafee.com/corporate/index?page=content&amp;amp;id=SB10132&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;mozilla -- firefox&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Mozilla Firefox before 41.0, when reader mode is enabled, allows remote attackers to spoof the relationship between address-bar URLs and web content via a crafted web site.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-24&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4508&amp;amp;vector=(AV:N/AC:H/Au:N/C:N/I:P/A:N)&quot;&gt;2.6&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4508&quot;&gt;CVE-2015-4508&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1195976&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2015/mfsa2015-103.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov#top&quot;&gt;Back to top&lt;/a&gt;&lt;/div&gt;	
		&lt;hr /&gt;
		
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;	&lt;br /&gt;</description>
         <guid isPermaLink="false">6266 at http://www.us-cert.gov</guid>
         <pubDate>Mon, 28 Sep 2015 10:46:16 +0000</pubDate>
      </item>
      <item>
         <title>Google Releases Security Update for Chrome</title>
         <link>http://www.us-cert.gov/ncas/current-activity/2015/09/25/Google-Release-Security-Update-Chrome-0</link>
         <description>Original release date: September 25, 2015&lt;br /&gt;
	
		&lt;p&gt;Google has released Chrome version 45.0.2454.101 to address multiple vulnerabilities for Windows, Mac, and Linux. Exploitation of one of these vulnerabilities may allow a remote attacker to obtain sensitive information from an affected system.&lt;/p&gt;&lt;p&gt;Users and administrators are encouraged to review the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://googlechromereleases.blogspot.com/2015/09/stable-channel-update_24.html&quot;&gt;Chrome Releases&lt;/a&gt; page and apply the necessary update.&lt;/p&gt;		
		&lt;hr /&gt;
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;		&lt;br /&gt;</description>
         <guid isPermaLink="false">6265 at http://www.us-cert.gov</guid>
         <pubDate>Sat, 26 Sep 2015 01:36:49 +0000</pubDate>
      </item>
      <item>
         <title>Cisco Semiannual Security Advisory Bundle</title>
         <link>http://www.us-cert.gov/ncas/current-activity/2015/09/24/Cisco-Semiannual-Security-Advisory-Bundle-0</link>
         <description>Original release date: September 24, 2015&lt;br /&gt;
	
		&lt;p&gt;Cisco has released its semiannual IOS and IOS XE Software Security Advisory bundle to address multiple vulnerabilities. Exploitation of these vulnerabilities could allow a remote attacker to bypass user authentication or cause a denial-of-service condition.&lt;/p&gt;&lt;p&gt;US-CERT encourages users and administrators to review the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_sep15.html&quot;&gt;Cisco Security Advisory&lt;/a&gt; and apply the necessary updates.&lt;/p&gt;		
		&lt;hr /&gt;
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;		&lt;br /&gt;</description>
         <guid isPermaLink="false">6262 at http://www.us-cert.gov</guid>
         <pubDate>Thu, 24 Sep 2015 19:33:04 +0000</pubDate>
      </item>
      <item>
         <title>Mozilla Releases Security Updates for Firefox</title>
         <link>http://www.us-cert.gov/ncas/current-activity/2015/09/22/Mozilla-Releases-Security-Updates-Firefox</link>
         <description>Original release date: September 22, 2015&lt;br /&gt;
	
		&lt;p&gt;The Mozilla Foundation has released security updates to address critical vulnerabilities in Firefox and Firefox ESR. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.&lt;/p&gt;&lt;p&gt;Available updates include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Firefox 41&lt;/li&gt;&lt;li&gt;Firefox ESR 38.3&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;US-CERT encourages users and administrators to review the Security Advisories for &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox/#firefox41&quot;&gt;Firefox&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/#firefoxesr38.3&quot;&gt;Firefox ESR&lt;/a&gt; and apply the necessary updates.&lt;/p&gt;		
		&lt;hr /&gt;
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;		&lt;br /&gt;</description>
         <guid isPermaLink="false">6260 at http://www.us-cert.gov</guid>
         <pubDate>Wed, 23 Sep 2015 00:05:26 +0000</pubDate>
      </item>
      <item>
         <title>Adobe Releases Security Updates for Flash Player</title>
         <link>http://www.us-cert.gov/ncas/current-activity/2015/09/21/Adobe-Releases-Security-Update-Flash-Player</link>
         <description>Original release date: September 21, 2015&lt;br /&gt;
	
		&lt;div&gt;&lt;div&gt;&lt;div&gt;&lt;div&gt;&lt;p&gt;Adobe has released security updates to address multiple vulnerabilities in Flash Player for Windows, Macintosh, ChromeOS, and Linux. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.&lt;/p&gt;&lt;p&gt;Users and administrators are encouraged to review &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://helpx.adobe.com/security/products/flash-player/apsb15-23.html&quot;&gt;Adobe Security Bulletin APSB15-23&lt;/a&gt; and apply the necessary updates. &lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;		
		&lt;hr /&gt;
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;		&lt;br /&gt;</description>
         <guid isPermaLink="false">6259 at http://www.us-cert.gov</guid>
         <pubDate>Mon, 21 Sep 2015 16:22:12 +0000</pubDate>
      </item>
      <item>
         <title>SB15-264: Vulnerability Summary for the Week of September 14, 2015</title>
         <link>http://www.us-cert.gov/ncas/bulletins/SB15-264</link>
         <description>Original release date: September 21, 2015		&lt;br /&gt;
		&lt;p&gt;The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.nist.gov&quot;&gt;National Institute of Standards and Technology&lt;/a&gt; (NIST) &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://nvd.nist.gov&quot;&gt;National Vulnerability Database&lt;/a&gt; (NVD) in the past week. The NVD is sponsored by the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.dhs.gov&quot;&gt;Department of Homeland Security&lt;/a&gt; (DHS) &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.us-cert.gov/nccic&quot;&gt;National Cybersecurity and Communications Integration Center&lt;/a&gt; (NCCIC) / &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.us-cert.gov&quot;&gt;United States Computer Emergency Readiness Team&lt;/a&gt; (US-CERT). For modified or updated entries, please visit the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://nvd.nist.gov&quot;&gt;NVD&lt;/a&gt;, which contains historical vulnerability information.&lt;/p&gt;&lt;p&gt;The vulnerabilities are based on the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://cve.mitre.org/&quot;&gt;CVE&lt;/a&gt; vulnerability naming standard and are organized according to severity, determined by the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://nvd.nist.gov/cvss.cfm&quot;&gt;Common Vulnerability Scoring System&lt;/a&gt; (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;strong&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;#high&quot;&gt;High&lt;/a&gt;&lt;/strong&gt; - Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 - 10.0&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;strong&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;#medium&quot;&gt;Medium&lt;/a&gt;&lt;/strong&gt; - Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 - 6.9&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;strong&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;#low&quot;&gt;Low&lt;/a&gt;&lt;/strong&gt; - Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 - 3.9&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis.&lt;/p&gt;
		&lt;p&gt;&lt;a rel=&quot;nofollow&quot; name=&quot;high&quot; id=&quot;high&quot;&gt;&lt;/a&gt;&lt;/p&gt;&lt;div id=&quot;high_v&quot;&gt;&lt;h2 id=&quot;high_v_title&quot;&gt;High Vulnerabilities&lt;/h2&gt;&lt;table align=&quot;center&quot; border=&quot;1&quot;&gt;&lt;thead&gt;&lt;tr&gt;&lt;th scope=&quot;col&quot; style=&quot;width:24%;&quot;&gt;Primary&lt;br /&gt;Vendor -- Product&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:44%;&quot;&gt;Description&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:8%;&quot;&gt;Published&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:4%;&quot;&gt;CVSS Score&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:10%;&quot;&gt;Source &amp;amp; Patch Info&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;advantech -- webaccess&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attackers to execute arbitrary code via unknown vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2014-9208&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9208&quot;&gt;CVE-2014-9208&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://ics-cert.us-cert.gov/advisories/ICSA-15-251-01&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;IOMobileFrameBuffer in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5843&amp;amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;7.2&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5843&quot;&gt;CVE-2015-5843&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;IOKit in the kernel in Apple iOS before 9 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-5845 and CVE-2015-5846.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5844&amp;amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)&quot;&gt;9.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5844&quot;&gt;CVE-2015-5844&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;IOKit in the kernel in Apple iOS before 9 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-5844 and CVE-2015-5846.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5845&amp;amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)&quot;&gt;9.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5845&quot;&gt;CVE-2015-5845&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;IOKit in the kernel in Apple iOS before 9 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-5844 and CVE-2015-5845.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5846&amp;amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)&quot;&gt;9.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5846&quot;&gt;CVE-2015-5846&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The Disk Images component in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5847&amp;amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;7.2&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5847&quot;&gt;CVE-2015-5847&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;IOAcceleratorFamily in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5848&amp;amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;7.2&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5848&quot;&gt;CVE-2015-5848&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;IOHIDFamily in Apple iOS before 9 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5867&amp;amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)&quot;&gt;9.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5867&quot;&gt;CVE-2015-5867&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5896 and CVE-2015-5903.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5868&amp;amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;7.2&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5868&quot;&gt;CVE-2015-5868&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;CoreText in Apple iOS before 9 and iTunes before 12.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5874&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5874&quot;&gt;CVE-2015-5874&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;dyld in Dev Tools in Apple iOS before 9 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5876&amp;amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)&quot;&gt;9.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5876&quot;&gt;CVE-2015-5876&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The processor_set_tasks API implementation in Apple iOS before 9 allows local users to bypass an entitlement protection mechanism and obtain access to the task ports of arbitrary processes by leveraging root privileges.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5882&amp;amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;7.2&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5882&quot;&gt;CVE-2015-5882&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5868 and CVE-2015-5903.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5896&amp;amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;7.2&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5896&quot;&gt;CVE-2015-5896&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;libpthread in the kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5899&amp;amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;7.2&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5899&quot;&gt;CVE-2015-5899&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5868 and CVE-2015-5896.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5903&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5903&quot;&gt;CVE-2015-5903&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;asus -- tm-1900&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Stack-based buffer overflow in the ASUS TM-AC1900 router allows remote attackers to execute arbitrary code via crafted HTTP header values.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-15&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6949&amp;amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)&quot;&gt;9.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6949&quot;&gt;CVE-2015-6949&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.zerodayinitiative.com/advisories/ZDI-15-409&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;borland -- accurev&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Multiple stack-based buffer overflows in the Reprise License Manager service in Borland AccuRev allow remote attackers to execute arbitrary code via the (1) akey or (2) actserver parameter to the the activate_doit function or (3) licfile parameter to the service_startup_doit functionality.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-15&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6946&amp;amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)&quot;&gt;9.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6946&quot;&gt;CVE-2015-6946&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.zerodayinitiative.com/advisories/ZDI-15-416&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.zerodayinitiative.com/advisories/ZDI-15-414/&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.zerodayinitiative.com/advisories/ZDI-15-412&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;checkmarx -- cxsast&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Checkmarx CxSAST (formerly CxSuite) before 7.1.8 allows remote authenticated users to bypass the CxQL sandbox protection mechanism and execute arbitrary C# code by asserting the (1) System.Security.Permissions.PermissionState.Unrestricted or (2) System.Security.Permissions.SecurityPermissionFlag.AllFlags permission.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-16&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2014-8778&amp;amp;vector=(AV:N/AC:L/Au:S/C:C/I:C/A:C)&quot;&gt;9.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-8778&quot;&gt;CVE-2014-8778&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/archive/1/archive/1/536387/100/0/threaded&quot;&gt;BUGTRAQ&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/fulldisclosure/2015/Sep/17&quot;&gt;FULLDISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133437/Checkmarx-CxQL-7.1.5-Sandbox-Bypass.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;ciphercoin -- wp_limit_login_attempts&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Multiple SQL injection vulnerabilities in the getip function in wp-limit-login-attempts.php in the WP Limit Login Attempts plugin before 2.0.1 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) X-Forwarded-For or (2) Client-IP HTTP header.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-16&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6829&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6829&quot;&gt;CVE-2015-6829&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://wpvulndb.com/vulnerabilities/8178&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://wordpress.org/support/topic/sql-injection-vulnerability-9&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://plugins.trac.wordpress.org/changeset/1239492/wp-limit-login-attempts&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.openwall.com/lists/oss-security/2015/09/06/3&quot;&gt;MLIST&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.openwall.com/lists/oss-security/2015/09/05/4&quot;&gt;MLIST&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;ibm -- websphere_portal&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-14&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-1943&amp;amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)&quot;&gt;7.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1943&quot;&gt;CVE-2015-1943&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www-01.ibm.com/support/docview.wss?uid=swg21962567&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www-01.ibm.com/support/docview.wss?uid=swg1PI39617&quot;&gt;AIXAPAR&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;ibm -- http_server&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, as used in WebSphere Application Server and other products, allows remote authenticated users to execute arbitrary code via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-15&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4947&amp;amp;vector=(AV:N/AC:L/Au:S/C:C/I:C/A:C)&quot;&gt;9.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4947&quot;&gt;CVE-2015-4947&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www-01.ibm.com/support/docview.wss?uid=swg21965419&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www-01.ibm.com/support/docview.wss?uid=swg1PI45596&quot;&gt;AIXAPAR&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www-01.ibm.com/support/docview.wss?uid=swg1PI44793&quot;&gt;AIXAPAR&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;ibs_mappro_project -- ibs_mappro&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Absolute path traversal vulnerability in lib/download.php in the IBS Mappro plugin before 1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-15&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5472&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:N/A:N)&quot;&gt;7.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5472&quot;&gt;CVE-2015-5472&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://wpvulndb.com/vulnerabilities/8091&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://wordpress.org/plugins/ibs-mappro/changelog/&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.vapid.dhs.org/advisory.php?v=137&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;impero -- impero_education_pro&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Impero Education Pro before 5105 uses a hardcoded CBC key and initialization vector derived from a hash of the Imp3ro string, which makes it easier for remote attackers to obtain plaintext data by sniffing the network for ciphertext data.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-14&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5997&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:N/A:N)&quot;&gt;7.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5997&quot;&gt;CVE-2015-5997&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.kb.cert.org/vuls/id/549807&quot;&gt;CERT-VN&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;impero -- impero_education_pro&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Impero Education Pro before 5105 relies on the -1|AUTHENTICATE&amp;#92;x02PASSWORD string for authentication, which allows remote attackers to execute arbitrary programs via an encrypted command.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-14&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5998&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5998&quot;&gt;CVE-2015-5998&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.kb.cert.org/vuls/id/549807&quot;&gt;CERT-VN&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;mindbite -- sitefactory_cms&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Absolute path traversal vulnerability in SiteFactory CMS 5.5.9 allows remote attackers to read arbitrary files via a full pathname in the file parameter to assets/download.aspx.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6914&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:N/A:N)&quot;&gt;7.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6914&quot;&gt;CVE-2015-6914&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133251/SiteFactory-CMS-5.5.9-Directory-Traversal.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;montala -- resourcespace&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;SQL injection vulnerability in Montala Limited ResourceSpace 7.3.7009 and earlier allows remote attackers to execute arbitrary SQL commands via the &quot;user&quot; cookie to plugins/feedback/pages/feedback.php.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6915&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6915&quot;&gt;CVE-2015-6915&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133297/ResourceSpace-CMS-7.3.7009-SQL-Injection.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;moxa -- eds-405a_firmware&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote authenticated users to bypass a read-only protection mechanism by using Firefox with a web-developer plugin.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6464&amp;amp;vector=(AV:N/AC:L/Au:S/C:N/I:C/A:C)&quot;&gt;8.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6464&quot;&gt;CVE-2015-6464&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://ics-cert.us-cert.gov/advisories/ICSA-15-246-03&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.moxa.com/support/download.aspx?type=support&amp;amp;id=328&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;mozilla -- bugzilla&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during account registration, which allows remote attackers to obtain the default privileges for an arbitrary domain name by placing that name in a substring of an address, as demonstrated by truncation of an @mozilla.com.example.com address to an @mozilla.com address.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-13&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4499&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4499&quot;&gt;CVE-2015-4499&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/bugtraq/2015/Sep/49&quot;&gt;BUGTRAQ&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/bugtraq/2015/Sep/48&quot;&gt;BUGTRAQ&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=1202447&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;sis -- windows_vga_display_manager&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Silicon Integrated Systems WindowsXP Display Manager (aka VGA Driver Manager and VGA Display Manager) 6.14.10.3930 allows local users to gain privileges via a crafted (1) 0x96002400 or (2) 0x96002404 IOCTL call.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-16&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5465&amp;amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;7.2&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5465&quot;&gt;CVE-2015-5465&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.korelogic.com/Resources/Advisories/KL-001-2015-003.txt&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.exploit-db.com/exploits/38054/&quot;&gt;EXPLOIT-DB&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/archive/1/archive/1/536370/100/0/threaded&quot;&gt;BUGTRAQ&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/fulldisclosure/2015/Sep/1&quot;&gt;FULLDISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133399/SiS-Windows-VGA-Display-Manager-Privilege-Escalation.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;sma_solar_technology_ag -- webbox_firmware&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;SMA Solar Sunny WebBox has hardcoded passwords, which makes it easier for remote attackers to obtain access via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-3964&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3964&quot;&gt;CVE-2015-3964&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://ics-cert.us-cert.gov/advisories/ICSA-15-181-02&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;synology -- video_station&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;SQL injection vulnerability in Synology Video Station before 1.5-0757 allows remote attackers to execute arbitrary SQL commands via the id parameter to audiotrack.cgi.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6910&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6910&quot;&gt;CVE-2015-6910&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.synology.com/en-global/support/security/Video_Station_1_5_0757&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.synology.com/en-global/releaseNote/VideoStation?model=DS715&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.securify.nl/advisory/SFY20150810/synology_video_station_command_injection_and_multiple_sql_injection_vulnerabilities.html&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/archive/1/archive/1/536427/100/0/threaded&quot;&gt;BUGTRAQ&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/fulldisclosure/2015/Sep/31&quot;&gt;FULLDISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133519/Synology-Video-Station-1.5-0757-Command-Injection-SQL-Injection.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;synology -- video_station&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;SQL injection vulnerability in Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary SQL commands via the id parameter to watchstatus.cgi.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6911&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6911&quot;&gt;CVE-2015-6911&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.synology.com/en-global/releaseNote/VideoStation?model=DS715&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.securify.nl/advisory/SFY20150810/synology_video_station_command_injection_and_multiple_sql_injection_vulnerabilities.html&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/archive/1/archive/1/536427/100/0/threaded&quot;&gt;BUGTRAQ&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/fulldisclosure/2015/Sep/31&quot;&gt;FULLDISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133519/Synology-Video-Station-1.5-0757-Command-Injection-SQL-Injection.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;synology -- video_station&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharacters in the subtitle_codepage parameter to subtitle.cgi.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6912&amp;amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)&quot;&gt;10.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6912&quot;&gt;CVE-2015-6912&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.synology.com/en-global/releaseNote/VideoStation?model=DS715&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.securify.nl/advisory/SFY20150810/synology_video_station_command_injection_and_multiple_sql_injection_vulnerabilities.html&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/archive/1/archive/1/536427/100/0/threaded&quot;&gt;BUGTRAQ&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/fulldisclosure/2015/Sep/31&quot;&gt;FULLDISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133519/Synology-Video-Station-1.5-0757-Command-Injection-SQL-Injection.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;teiko -- farol&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;SQL injection vulnerability in the web application in Farol allows remote attackers to execute arbitrary SQL commands via the email parameter to tkmonitor/estrutura/login/Login.actions.php.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-17&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6962&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6962&quot;&gt;CVE-2015-6962&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.exploit-db.com/exploits/38213/&quot;&gt;EXPLOIT-DB&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;unit4 -- teta_web&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 does not properly restrict access to the (1) Design Mode and (2) Debug Logger mode modules, which allows remote attackers to gain privileges via crafted &quot;received parameters.&quot;&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-16&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-1173&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;7.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1173&quot;&gt;CVE-2015-1173&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/fulldisclosure/2015/Aug/68&quot;&gt;FULLDISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133147/UNIT4TETA-TETA-WEB-22.62.3.4-Authorization-Bypass.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot;&gt;yahoo -- messenger&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the (1) shortcut or (2) title keys in an emoticons.xml file.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2014-7216&amp;amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)&quot;&gt;9.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-7216&quot;&gt;CVE-2014-7216&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.rcesecurity.com/2015/09/cve-2014-7216-a-journey-through-yahoos-bug-bounty-program/&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://hackerone.com/reports/10767&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/archive/1/archive/1/536390/100/0/threaded&quot;&gt;BUGTRAQ&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133443/Yahoo-Messenger-11.5.0.228-Buffer-Overflow.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov#top&quot;&gt;Back to top&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;a rel=&quot;nofollow&quot; name=&quot;medium&quot; id=&quot;medium&quot;&gt;&lt;/a&gt;&lt;/p&gt;&lt;div id=&quot;medium_v&quot;&gt;&lt;h2 id=&quot;medium_v_title&quot;&gt;Medium Vulnerabilities&lt;/h2&gt;&lt;table align=&quot;center&quot; border=&quot;1&quot;&gt;&lt;thead&gt;&lt;tr&gt;&lt;th scope=&quot;col&quot; style=&quot;width:24%;&quot;&gt;Primary&lt;br /&gt;Vendor -- Product&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:44%;&quot;&gt;Description&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:8%;&quot;&gt;Published&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:4%;&quot;&gt;CVSS Score&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:10%;&quot;&gt;Source &amp;amp; Patch Info&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;administration_views_project -- administration_views&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive information via vectors related to the access handler.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-17&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7226&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7226&quot;&gt;CVE-2015-7226&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.drupal.org/node/2529378&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.drupal.org/node/2529366&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://cgit.drupalcode.org/admin_views/commit/?id=44098bb&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5765 and CVE-2015-5767.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5764&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5764&quot;&gt;CVE-2015-5764&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5764 and CVE-2015-5767.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5765&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5765&quot;&gt;CVE-2015-5765&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5764 and CVE-2015-5765.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5767&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5767&quot;&gt;CVE-2015-5767&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The WebKit Canvas implementation in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain sensitive image information via vectors involving a CANVAS element.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5788&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5788&quot;&gt;CVE-2015-5788&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5789&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5789&quot;&gt;CVE-2015-5789&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5790&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5790&quot;&gt;CVE-2015-5790&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5791&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5791&quot;&gt;CVE-2015-5791&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5792&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5792&quot;&gt;CVE-2015-5792&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5793&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5793&quot;&gt;CVE-2015-5793&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5794&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5794&quot;&gt;CVE-2015-5794&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5795&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5795&quot;&gt;CVE-2015-5795&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5796&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5796&quot;&gt;CVE-2015-5796&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5797&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5797&quot;&gt;CVE-2015-5797&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iTunes before 12.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5798&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5798&quot;&gt;CVE-2015-5798&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5799&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5799&quot;&gt;CVE-2015-5799&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5800&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5800&quot;&gt;CVE-2015-5800&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5801&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5801&quot;&gt;CVE-2015-5801&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5802&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5802&quot;&gt;CVE-2015-5802&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5803&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5803&quot;&gt;CVE-2015-5803&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5804&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5804&quot;&gt;CVE-2015-5804&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5805&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5805&quot;&gt;CVE-2015-5805&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5806&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5806&quot;&gt;CVE-2015-5806&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5807&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5807&quot;&gt;CVE-2015-5807&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iTunes before 12.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5808&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5808&quot;&gt;CVE-2015-5808&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5809&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5809&quot;&gt;CVE-2015-5809&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5810&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5810&quot;&gt;CVE-2015-5810&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5811&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5811&quot;&gt;CVE-2015-5811&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5812&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5812&quot;&gt;CVE-2015-5812&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5813&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5813&quot;&gt;CVE-2015-5813&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5814&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5814&quot;&gt;CVE-2015-5814&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iTunes before 12.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5815&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5815&quot;&gt;CVE-2015-5815&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5816&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5816&quot;&gt;CVE-2015-5816&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5817&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5817&quot;&gt;CVE-2015-5817&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5818&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5818&quot;&gt;CVE-2015-5818&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5819&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5819&quot;&gt;CVE-2015-5819&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit in Apple iOS before 9 allows remote attackers to trigger a dialing action via a crafted (1) tel://, (2) facetime://, or (3) facetime-audio:// URL.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5820&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5820&quot;&gt;CVE-2015-5820&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5821&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5821&quot;&gt;CVE-2015-5821&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5822&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5822&quot;&gt;CVE-2015-5822&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- itunes&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5823&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5823&quot;&gt;CVE-2015-5823&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205221&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html&quot;&gt;APPLE&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The NSURL implementation in the CFNetwork SSL component in Apple iOS before 9 does not properly verify X.509 certificates from SSL servers after a certificate change, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5824&amp;amp;vector=(AV:A/AC:M/Au:N/C:P/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5824&quot;&gt;CVE-2015-5824&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit in Apple iOS before 9 does not properly restrict the availability of Performance API times, which allows remote attackers to obtain sensitive information about the browser history, mouse movement, or network traffic via crafted JavaScript code.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5825&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5825&quot;&gt;CVE-2015-5825&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit in Apple iOS before 9 does not properly select the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5826&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5826&quot;&gt;CVE-2015-5826&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain an object reference via vectors involving a (1) custom event, (2) message event, or (3) pop state event.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5827&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5827&quot;&gt;CVE-2015-5827&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Data Detectors Engine in Apple iOS before 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5829&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5829&quot;&gt;CVE-2015-5829&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;NetworkExtension in the kernel in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows attackers to obtain sensitive memory-layout information via a crafted app.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5831&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5831&quot;&gt;CVE-2015-5831&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;IOAcceleratorFamily in Apple iOS before 9 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5834&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5834&quot;&gt;CVE-2015-5834&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Apple iOS before 9 allows attackers to obtain sensitive information about inter-app communication via a crafted app that conducts an interception attack involving an unspecified URL scheme.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5835&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5835&quot;&gt;CVE-2015-5835&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;PluginKit in Apple iOS before 9 allows attackers to bypass an intended app-trust requirement and install arbitrary extensions via a crafted enterprise app.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5837&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5837&quot;&gt;CVE-2015-5837&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;SpringBoard in Apple iOS before 9 does not properly restrict access to privileged API calls, which allows attackers to spoof the dialog windows of an arbitrary app via a crafted app.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5838&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5838&quot;&gt;CVE-2015-5838&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;dyld in Apple iOS before 9 allows attackers to bypass a code-signing protection mechanism via an app that places a crafted signature in an executable file.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5839&amp;amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5839&quot;&gt;CVE-2015-5839&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The checkint division routines in removefile in Apple iOS before 9 allow attackers to cause a denial of service (overflow fault and app crash) via crafted data.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5840&amp;amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5840&quot;&gt;CVE-2015-5840&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The CFNetwork Proxies component in Apple iOS before 9 does not properly handle a Set-Cookie header within a response to an HTTP CONNECT request, which allows remote proxy servers to conduct cookie-injection attacks via a crafted response.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5841&amp;amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5841&quot;&gt;CVE-2015-5841&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Apple iOS before 9 allows attackers to discover the e-mail address of a player via a crafted Game Center app.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5855&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5855&quot;&gt;CVE-2015-5855&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The Application Store component in Apple iOS before 9 allows remote attackers to cause a denial of service to an enterprise-signed app via a crafted ITMS URL.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5856&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5856&quot;&gt;CVE-2015-5856&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Mail in Apple iOS before 9 allows remote attackers to use an address-book contact as a spoofed e-mail sender address via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5857&amp;amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5857&quot;&gt;CVE-2015-5857&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The CFNetwork HTTPProtocol component in Apple iOS before 9 allows remote attackers to bypass the HSTS protection mechanism, and consequently obtain sensitive information, via a crafted URL.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5858&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5858&quot;&gt;CVE-2015-5858&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The CFNetwork HTTPProtocol component in Apple iOS before 9 mishandles HSTS state, which allows remote attackers to bypass the Safari private-browsing protection mechanism and track users via a crafted web site.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5860&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5860&quot;&gt;CVE-2015-5860&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The Audio component in Apple iOS before 9 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted audio file.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5862&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5862&quot;&gt;CVE-2015-5862&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;XNU in the kernel in Apple iOS before 9 does not properly validate the headers of TCP packets, which allows remote attackers to bypass the sequence-number protection mechanism and cause a denial of service (TCP connection disruption) via a crafted header.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5879&amp;amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5879&quot;&gt;CVE-2015-5879&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;CoreAnimation in Apple iOS before 9 allows attackers to bypass intended IOSurface restrictions and obtain screen-framebuffer access via a crafted background app.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5880&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5880&quot;&gt;CVE-2015-5880&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The CFNetwork Cookies component in Apple iOS before 9 allows remote attackers to track users via vectors involving a cookie for a top-level domain.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5885&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5885&quot;&gt;CVE-2015-5885&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafted web site.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5904&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5904&quot;&gt;CVE-2015-5904&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafted window opener on a web site.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5905&amp;amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5905&quot;&gt;CVE-2015-5905&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The HTML form implementation in WebKit in Apple iOS before 9 does not prevent QuickType access to the final character of a password, which might make it easier for remote attackers to discover a password by leveraging a later prediction containing that character.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5906&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5906&quot;&gt;CVE-2015-5906&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The CFNetwork FTPProtocol component in Apple iOS before 9 allows remote FTP proxy servers to trigger TCP connection attempts to intranet hosts via crafted responses.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5912&amp;amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5912&quot;&gt;CVE-2015-5912&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The Apple Pay component in Apple iOS before 9 allows remote terminals to obtain sensitive recent-transaction information during payments by leveraging the transaction-log feature.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5916&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5916&quot;&gt;CVE-2015-5916&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit in Apple iOS before 9 mishandles &quot;Content-Disposition: attachment&quot; HTTP headers, which might allow man-in-the-middle attackers to obtain sensitive information via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5921&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5921&quot;&gt;CVE-2015-5921&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;auto-exchanger -- auto-exchanger&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote attackers to hijack the authentication of users for requests that change a password via a request to signup.php.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6827&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6827&quot;&gt;CVE-2015-6827&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.exploit-db.com/exploits/38119/&quot;&gt;EXPLOIT-DB&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;canon -- pixma_mg7500_series_inkjet_printer&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site request forgery (CSRF) vulnerability in the Remote UI on Canon PIXMA MG7500 printers allows remote attackers to hijack the authentication of administrators.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5631&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5631&quot;&gt;CVE-2015-5631&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.canon.com/support/pdf/inkjet-printer.pdf&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvndb.jvn.jp/jvndb/JVNDB-2015-000129&quot;&gt;JVNDB&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvn.jp/en/jp/JVN07427376/index.html&quot;&gt;JVN&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;cisco -- email_security_appliance&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Format string vulnerability in Cisco Email Security Appliance (ESA) 7.6.0 and 8.0.0 allows remote attackers to cause a denial of service (memory overwrite or service outage) via format string specifiers in an HTTP request, aka Bug ID CSCug21497.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-13&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6285&amp;amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:P)&quot;&gt;6.4&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6285&quot;&gt;CVE-2015-6285&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/viewAlert.x?alertId=40844&quot;&gt;CISCO&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;cisco -- application_visibility_and_control&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cisco Application Visibility and Control (AVC) 15.3(3)JA, when FlexConnect is enabled, allows remote attackers to cause a denial of service (access-point outage) via a crafted UDP packet, aka Bug ID CSCuu47016.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-13&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6286&amp;amp;vector=(AV:A/AC:M/Au:N/C:N/I:N/A:C)&quot;&gt;5.7&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6286&quot;&gt;CVE-2015-6286&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/viewAlert.x?alertId=40845&quot;&gt;CISCO&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;cisco -- web_security_virtual_appliance&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cisco Web Security Appliance (WSA) 8.0.6-078 and 8.0.6-115 allows remote attackers to cause a denial of service (service outage) via a flood of TCP traffic that leads to DNS resolution delays, aka Bug IDs CSCur32005 and CSCur07907.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-13&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6287&amp;amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6287&quot;&gt;CVE-2015-6287&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/viewAlert.x?alertId=40846&quot;&gt;CISCO&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;cisco -- content_security_management_appliance&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cisco Content Security Management Appliance (SMA) 7.8.0-000 does not properly validate credentials, which allows remote attackers to cause a denial of service (rapid log-file rollover and application fault) via crafted HTTP requests, aka Bug ID CSCuw09620.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-13&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6288&amp;amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6288&quot;&gt;CVE-2015-6288&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/viewAlert.x?alertId=40847&quot;&gt;CISCO&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;cisco -- web_security_virtual_appliance&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cisco Web Security Appliance (WSA) 8.0.7 allows remote HTTP servers to cause a denial of service (memory consumption from stale TCP connections) via crafted responses, aka Bug ID CSCuw10426.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-13&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6290&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6290&quot;&gt;CVE-2015-6290&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/viewAlert.x?alertId=40896&quot;&gt;CISCO&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;corel -- wordperfect&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Heap-based buffer overflow in the Microsoft Word document conversion feature in Corel WordPerfect allows remote attackers to execute arbitrary code via a crafted document.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-15&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6948&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6948&quot;&gt;CVE-2015-6948&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.zerodayinitiative.com/advisories/ZDI-15-410&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;creative-solutions -- contact_form_generator&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) create a field, (2) update a field, (3) delete a field, (4) create a form, (5) update a form, (6) delete a form, (7) create a template, (8) update a template, (9) delete a template, or (10) conduct cross-site scripting (XSS) attacks via a crafted request to the cfg_forms page in wp-admin/admin.php.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-16&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6965&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6965&quot;&gt;CVE-2015-6965&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.exploit-db.com/exploits/38086/&quot;&gt;EXPLOIT-DB&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://wpvulndb.com/vulnerabilities/8176&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133463/WordPress-Contact-Form-Generator-2.0.1-CSRF.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;freetype -- freetype&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a &quot;broken number-with-base&quot; in a Postscript stream, as demonstrated by 8#garbage.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-14&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2014-9745&amp;amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9745&quot;&gt;CVE-2014-9745&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://code.google.com/p/chromium/issues/detail?id=459050&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugs.launchpad.net/ubuntu/+source/freetype/+bug/1492124&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.ubuntu.com/usn/USN-2739-1&quot;&gt;UBUNTU&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://savannah.nongnu.org/bugs/index.php?41590&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=df14e6c0b9592cbb24d5381dfc6106b14f915e75&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;googlesearch_project -- googlesearch&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site scripting (XSS) vulnerability in the googleSearch (CSE) (com_googlesearch_cse) component 3.0.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the q parameter to index.php.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6919&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6919&quot;&gt;CVE-2015-6919&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133375/Joomla-GoogleSearch-CSE-3.0.2-Cross-Site-Scripting.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;hp -- arcsight_logger&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;HP ArcSight Logger before 6.0 P2 allows remote authenticated users to bypass the intended authorization policy via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-16&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-2136&amp;amp;vector=(AV:N/AC:L/Au:S/C:P/I:N/A:N)&quot;&gt;4.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-2136&quot;&gt;CVE-2015-2136&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04762372&quot;&gt;HP&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;hp -- loadrunner&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Unspecified vulnerability in HP LoadRunner Controller before 12.50 allows local users to gain privileges via unknown vectors, aka ZDI-CAN-2756.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-15&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5426&amp;amp;vector=(AV:L/AC:L/Au:N/C:P/I:P/A:P)&quot;&gt;4.6&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5426&quot;&gt;CVE-2015-5426&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04692147&quot;&gt;HP&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;hp -- universal_configuration_management_database&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;HP UCMDB 10.00 and 10.01 before 10.01CUP12, 10.10 and 10.11 before 10.11CUP6, and 10.2x before 10.21 allows local users to obtain sensitive information via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-16&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5440&amp;amp;vector=(AV:L/AC:L/Au:N/C:C/I:N/A:N)&quot;&gt;4.9&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5440&quot;&gt;CVE-2015-5440&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04790231&quot;&gt;HP&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;ibm -- websphere_mq&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;IBM WebSphere MQ 7.0.1 before 7.0.1.13 allows remote attackers to cause a denial of service (channel-agent abend and process outage) via a crafted selection string in an MQI call.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-13&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-2013&amp;amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-2013&quot;&gt;CVE-2015-2013&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www-01.ibm.com/support/docview.wss?uid=swg21962479&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www-01.ibm.com/support/docview.wss?uid=swg1IV73860&quot;&gt;AIXAPAR&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;ibm -- websphere_commerce&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Unspecified vulnerability in IBM WebSphere Commerce 7.0.0.6 through 7.0.0.9 allows remote authenticated users to obtain sensitive personal information via unknown vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-14&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-4980&amp;amp;vector=(AV:N/AC:L/Au:S/C:P/I:N/A:N)&quot;&gt;4.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4980&quot;&gt;CVE-2015-4980&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www-01.ibm.com/support/docview.wss?uid=swg21965013&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www-01.ibm.com/support/docview.wss?uid=swg1JR54107&quot;&gt;AIXAPAR&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;igniterealtime -- openfire&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to inject arbitrary web script or HTML via the (1) groupchatName parameter to plugins/clientcontrol/create-bookmark.jsp; the (2) urlName parameter to plugins/clientcontrol/create-bookmark.jsp; the (3) hostname parameter to server-session-details.jsp; or the (4) search parameter to group-summary.jsp.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-16&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6972&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6972&quot;&gt;CVE-2015-6972&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.exploit-db.com/exploits/38191/&quot;&gt;EXPLOIT-DB&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133558/Openfire-3.10.2-Cross-Site-Scripting.html&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://hyp3rlinx.altervista.org/advisories/AS-OPENFIRE-XSS.txt&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;igniterealtime -- openfire&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) change a password via a crafted request to user-password.jsp, (2) add users via a crafted request to user-create.jsp, (3) edit server setting or (4) disable SSL on the server via a crafted request to server-props.jsp, or (5) add clients via a crafted request to plugins/clientcontrol/permitted-clients.jsp.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-16&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6973&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6973&quot;&gt;CVE-2015-6973&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.exploit-db.com/exploits/38192/&quot;&gt;EXPLOIT-DB&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/archive/1/archive/1/536470/100/0/threaded&quot;&gt;BUGTRAQ&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://hyp3rlinx.altervista.org/advisories/AS-OPENFIRE-CSRF.txt&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;jsp/mysql_administrador_web_project -- jsp/mysql_administrador_web&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site request forgery (CSRF) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to hijack the authentication of users for requests that execute arbitrary SQL commands via the cmd parameter to sys/sys/listaBD2.jsp.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-15&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6944&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6944&quot;&gt;CVE-2015-6944&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/archive/1/archive/1/536406/100/0/threaded&quot;&gt;BUGTRAQ&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133466/JSPMySQL-Administrador-1-Cross-Site-Request-Forgery-Cross-Site-Scripting.html&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://hyp3rlinx.altervista.org/advisories/AS-JSPMYSQLADMINISTRADOR-0904.txt&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;jsp/mysql_administrador_web_project -- jsp/mysql_administrador_web&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site scripting (XSS) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to inject arbitrary web script or HTML via the bd parameter to sys/sys/listaBD2.jsp.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-15&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6945&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6945&quot;&gt;CVE-2015-6945&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/archive/1/archive/1/536406/100/0/threaded&quot;&gt;BUGTRAQ&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133466/JSPMySQL-Administrador-1-Cross-Site-Request-Forgery-Cross-Site-Scripting.html&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://hyp3rlinx.altervista.org/advisories/AS-JSPMYSQLADMINISTRADOR-0904.txt&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;moxa -- eds-405a_firmware&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The GoAhead web server on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote authenticated users to cause a denial of service (reboot) via a crafted URL.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6465&amp;amp;vector=(AV:N/AC:L/Au:S/C:N/I:N/A:C)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6465&quot;&gt;CVE-2015-6465&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://ics-cert.us-cert.gov/advisories/ICSA-15-246-03&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.moxa.com/support/download.aspx?type=support&amp;amp;id=328&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;moxa -- eds-405a_firmware&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site scripting (XSS) vulnerability in the Diagnosis Ping feature in the administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote attackers to inject arbitrary web script or HTML via an unspecified field.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6466&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6466&quot;&gt;CVE-2015-6466&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://ics-cert.us-cert.gov/advisories/ICSA-15-246-03&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.moxa.com/support/download.aspx?type=support&amp;amp;id=328&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;nibbleblog -- nibbleblog&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Multiple cross-site request forgery (CSRF) vulnerabilities in Nibbleblog before 4.0.5 allow remote attackers to hijack the authentication of administrators for requests that (1) create a post via a new_simple action to admin.php or (2) conduct cross-site scripting (XSS) attacks via the content parameter in a new_simple action to admin.php.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-16&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6966&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6966&quot;&gt;CVE-2015-6966&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blog.nibbleblog.com/post/nibbleblog-v4-0-5/&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/fulldisclosure/2015/Sep/4&quot;&gt;FULLDISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blog.curesec.com/article/blog/NibbleBlog-403-CSRF-46.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;nibbleblog -- nibbleblog&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in content/private/plugins/my_image/image.php.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-16&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6967&amp;amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)&quot;&gt;6.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6967&quot;&gt;CVE-2015-6967&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/fulldisclosure/2015/Sep/5&quot;&gt;FULLDISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133425/NibbleBlog-4.0.3-Shell-Upload.html&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blog.nibbleblog.com/post/nibbleblog-v4-0-5/&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blog.curesec.com/article/blog/NibbleBlog-403-Code-Execution-47.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;nokia -- @vantage_commander&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Multiple cross-site scripting (XSS) vulnerabilities in Nokia Networks (formerly Nokia Solutions and Networks and Nokia Siemens Networks) @vantage Commander allow remote attackers to inject arbitrary web script or HTML via the (1) idFilter or (2) nameFilter parameter to cftraces/filter/fl_copy.jsp; the (3) flName parameter to cftraces/filter/fl_crea1.jsp; the (4) serchStatus, (5) refreshTime, or (6) serchNode parameter to cftraces/process/pr_show_process.jsp; the (7) MaxActivationTime, (8) NumberOfBytes, (9) NumberOfTracefiles, (10) SessionName, or (11) serchSessionkind parameter to cftraces/session/se_crea.jsp; the (12) serchSessionDescription parameter to cftraces/session/se_show.jsp; the (13) serchApplication or (14) serchApplicationkind parameter to cftraces/session/tr_crea_filter.jsp; the (15) columKeyUnique, (16) columParameter, (17) componentName, (18) criteria1, (19) criteria2, (20) criteria3, (21) description, (22) filter, (23) id, (24) pathName, (25) tableName, or (26) component parameter to cftraces/session/tr_create_tagg_para.jsp; or the (27) userid parameter to home/certificate_association.jsp.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-16&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6929&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6929&quot;&gt;CVE-2015-6929&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://drive.google.com/open?id=0B-LWHbwdK3P9eTNKRkdDWGpkN2M&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/fulldisclosure/2015/Sep/42&quot;&gt;FULLDISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133538/Nokia-Solutions-And-Networks-Cross-Site-Scripting.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;ntt-bp -- japan_connected-free_wi-fi&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.6.0 and earlier for Android and 1.0.2 and earlier for iOS allows attackers to bypass a URL whitelist protection mechanism via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5629&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5629&quot;&gt;CVE-2015-5629&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://play.google.com/store/apps/details?id=com.nttbp.jfw&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://itunes.apple.com/en/app/japan-connected-free-wi-fi/id810838196?mt=8&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvndb.jvn.jp/jvndb/JVNDB-2015-000115&quot;&gt;JVNDB&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvn.jp/en/jp/JVN04644117/index.html&quot;&gt;JVN&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;ntt-bp -- japan_connected-free_wi-fi&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site scripting (XSS) vulnerability in the NTT Broadband Platform Japan Connected-free Wi-Fi application 1.6.0 and earlier for Android and 1.0.2 and earlier for iOS allows remote attackers to inject arbitrary web script or HTML via a crafted SSID.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5630&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5630&quot;&gt;CVE-2015-5630&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://play.google.com/store/apps/details?id=com.nttbp.jfw&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://itunes.apple.com/en/app/japan-connected-free-wi-fi/id810838196?mt=8&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvndb.jvn.jp/jvndb/JVNDB-2015-000116&quot;&gt;JVNDB&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://jvn.jp/en/jp/JVN41048401/index.html&quot;&gt;JVN&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;openldap -- openldap&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6908&amp;amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6908&quot;&gt;CVE-2015-6908&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.openldap.org/its/index.cgi/Software%20Bugs?id=8240&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.openldap.org/devel/gitweb.cgi?p=openldap.git;a=commit;h=6fe51a9ab04fd28bbc171da3cf12f1c1040d6629&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;phpmyadmin -- phpmyadmin&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass a multiple-reCaptcha protection mechanism against brute-force credential guessing by providing a correct response to a single reCaptcha.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-13&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6830&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;5.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6830&quot;&gt;CVE-2015-6830&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.phpmyadmin.net/security/PMASA-2015-4/&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://github.com/phpmyadmin/phpmyadmin/commit/785f4e2711848eb8945894199d5870253a88584e&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;qlik -- qlikview&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server-side request forgery (SSRF) attacks and read arbitrary files via crafted XML data in a request to AccessPoint.aspx.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-16&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-3623&amp;amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:N)&quot;&gt;6.4&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3623&quot;&gt;CVE-2015-3623&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.exploit-db.com/exploits/38118/&quot;&gt;EXPLOIT-DB&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/archive/1/archive/1/536411/100/0/threaded&quot;&gt;BUGTRAQ&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133499/Qlikview-11.20-SR4-Blind-XXE-Injection.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;s9y -- serendipity&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;SQL injection vulnerability in the serendipity_checkCommentToken function in include/functions_comments.inc.php in Serendipity before 2.0.2, when &quot;Use Tokens for Comment Moderation&quot; enabled, allows remote administrators to execute arbitrary SQL commands via the serendipity[id] parameter to serendipity_admin.php.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-15&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6943&amp;amp;vector=(AV:N/AC:M/Au:S/C:P/I:P/A:P)&quot;&gt;6.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6943&quot;&gt;CVE-2015-6943&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://github.com/s9y/Serendipity/releases/tag/2.0.2&quot;&gt;NVD&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blog.s9y.org/archives/265-Serendipity-2.0.2-Security-Fix-Release.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/fulldisclosure/2015/Sep/10&quot;&gt;FULLDISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133428/Serendipity-2.0.1-Blind-SQL-Injection.html&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blog.curesec.com/article/blog/Serendipity-201-Blind-SQL-Injection-52.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;s9y -- serendipity&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Multiple incomplete blacklist vulnerabilities in the serendipity_isActiveFile function in include/functions_images.inc.php in Serendipity before 2.0.2 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) .pht or (2) .phtml extension.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-16&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6968&amp;amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)&quot;&gt;6.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6968&quot;&gt;CVE-2015-6968&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/fulldisclosure/2015/Sep/6&quot;&gt;FULLDISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blog.s9y.org/archives/265-Serendipity-2.0.2-Security-Fix-Release.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133426/Serendipity-2.0.1-Shell-Upload.html&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blog.curesec.com/article/blog/Serendipity-201-Code-Execution-48.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;s9y -- serendipity&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site scripting (XSS) vulnerability in js/2k11.min.js in the 2k11 theme in Serendipity before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via a user name in a comment, which is not properly handled in a Reply link.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-16&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6969&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6969&quot;&gt;CVE-2015-6969&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/fulldisclosure/2015/Sep/9&quot;&gt;FULLDISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blog.s9y.org/archives/265-Serendipity-2.0.2-Security-Fix-Release.html&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133427/Serendipity-2.0.1-Cross-Site-Scripting.html&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blog.curesec.com/article/blog/Serendipity-201-Persistent-XSS-51.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;securemoz -- securemoz_security_audit&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The tweet_info function in class/__functions.php in the SecureMoz Security Audit plugin 1.0.5 and earlier for WordPress does not use an HTTPS session for downloading serialized data, which allows man-in-the-middle attackers to conduct PHP object injection attacks and execute arbitrary PHP code by modifying the client-server data stream. NOTE: some of these details are obtained from third party information.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-16&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6828&amp;amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)&quot;&gt;6.8&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6828&quot;&gt;CVE-2015-6828&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://wpvulndb.com/vulnerabilities/8179&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.openwall.com/lists/oss-security/2015/09/06/3&quot;&gt;MLIST&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.openwall.com/lists/oss-security/2015/09/05/4&quot;&gt;MLIST&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;siemens -- ruggedcom_rugged_operating_system&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Siemens RUGGEDCOM ROS 3.8.0 through 4.1.x permanently enables the IP forwarding feature, which allows remote attackers to bypass a VLAN isolation protection mechanism via IP traffic.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6675&amp;amp;vector=(AV:A/AC:M/Au:N/C:P/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6675&quot;&gt;CVE-2015-6675&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://ics-cert.us-cert.gov/advisories/ICSA-15-244-01&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-720081.pdf&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;sourceafrica_project -- sourceafrica&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site scripting (XSS) vulnerability in js/window.php in the sourceAFRICA plugin 0.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wpbase parameter.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6920&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6920&quot;&gt;CVE-2015-6920&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://wpvulndb.com/vulnerabilities/8169&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133371/WordPress-sourceAFRICA-0.1.3-Cross-Site-Scripting.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;sprymedia -- datatables&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site scripting (XSS) vulnerability in the DataTables plugin 1.10.8 and earlier for jQuery allows remote attackers to inject arbitrary web script or HTML via the scripts parameter to media/unit_testing/templates/6776.php.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6584&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6584&quot;&gt;CVE-2015-6584&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.netsparker.com/cve-2015-6384-xss-vulnerability-identified-in-datatables/&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/archive/1/archive/1/536437/100/0/threaded&quot;&gt;BUGTRAQ&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;structured_dynamics -- open_semantic_framework&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site request forgery (CSRF) vulnerability in the OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF Import module is enabled, allows remote attackers to hijack the authentication of administrators for requests that create new OSF datasets via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-17&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7233&amp;amp;vector=(AV:N/AC:H/Au:N/C:P/I:P/A:P)&quot;&gt;5.1&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7233&quot;&gt;CVE-2015-7233&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.drupal.org/node/2537860&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.drupal.org/node/2537120&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;structured_dynamics -- open_semantic_framework&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF Ontology and OSF Import modules are enabled, allows user-assisted remote attackers to delete arbitrary files via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-17&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7234&amp;amp;vector=(AV:N/AC:H/Au:N/C:N/I:P/A:P)&quot;&gt;4.0&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7234&quot;&gt;CVE-2015-7234&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.drupal.org/node/2537860&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.drupal.org/node/2537120&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://cgit.drupalcode.org/osf/commit/?id=35c6e61&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;synology -- download_station&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site scripting (XSS) vulnerability in the &quot;Create download task via file upload&quot; feature in Synology Download Station before 3.5-2962 allows remote attackers to inject arbitrary web script or HTML via the name element in the Info dictionary in a torrent file.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6909&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6909&quot;&gt;CVE-2015-6909&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.synology.com/en-global/support/security/Download_Station_3_5_2962&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.synology.com/en-global/releaseNote/DownloadStation?model=DS715&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.securify.nl/advisory/SFY20150809/multiple_cross_site_scripting_vulnerabilities_in_synology_download_station.html&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/archive/1/archive/1/536428/100/0/threaded&quot;&gt;BUGTRAQ&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/fulldisclosure/2015/Sep/32&quot;&gt;FULLDISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133520/Synology-Download-Station-3.5-2956-3.5-2962-Cross-Site-Scripting.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;synology -- download_station&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site scripting (XSS) vulnerability in the &quot;Create download task via URL&quot; feature in Synology Download Station before 3.5-2967 allows remote attackers to inject arbitrary web script or HTML via the urls parameter in an add_url_task action to dlm/downloadman.cgi.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6913&amp;amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)&quot;&gt;4.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6913&quot;&gt;CVE-2015-6913&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.synology.com/en-global/releaseNote/DownloadStation?model=DS715&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.securify.nl/advisory/SFY20150809/multiple_cross_site_scripting_vulnerabilities_in_synology_download_station.html&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/archive/1/archive/1/536428/100/0/threaded&quot;&gt;BUGTRAQ&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/fulldisclosure/2015/Sep/32&quot;&gt;FULLDISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packetstormsecurity.com/files/133520/Synology-Download-Station-3.5-2956-3.5-2962-Cross-Site-Scripting.html&quot;&gt;MISC&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov#top&quot;&gt;Back to top&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;a rel=&quot;nofollow&quot; name=&quot;low&quot; id=&quot;low&quot;&gt;&lt;/a&gt;&lt;/p&gt;&lt;div id=&quot;low_v&quot;&gt;&lt;h2 id=&quot;low_v_title&quot;&gt;Low Vulnerabilities&lt;/h2&gt;&lt;table align=&quot;center&quot; border=&quot;1&quot;&gt;&lt;thead&gt;&lt;tr&gt;&lt;th scope=&quot;col&quot; style=&quot;width:24%;&quot;&gt;Primary&lt;br /&gt;Vendor -- Product&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:44%;&quot;&gt;Description&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:8%;&quot;&gt;Published&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:4%;&quot;&gt;CVSS Score&lt;/th&gt;&lt;th scope=&quot;col&quot; style=&quot;width:10%;&quot;&gt;Source &amp;amp; Patch Info&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The iTunes Store component in Apple iOS before 9 does not properly delete AppleID credentials from the keychain upon a signout action, which might allow physically proximate attackers to obtain sensitive information via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5832&amp;amp;vector=(AV:L/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;2.1&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5832&quot;&gt;CVE-2015-5832&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;XNU in the kernel in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows local users to obtain sensitive memory-layout information via unknown vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5842&amp;amp;vector=(AV:L/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;2.1&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5842&quot;&gt;CVE-2015-5842&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;AppleKeyStore in Apple iOS before 9 allows physically proximate attackers to reset the count of incorrect passcode attempts via a device backup.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5850&amp;amp;vector=(AV:L/AC:L/Au:N/C:N/I:P/A:N)&quot;&gt;2.1&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5850&quot;&gt;CVE-2015-5850&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not require an encrypted session, which allows local users to obtain cleartext multipeer data via an encrypted-to-unencrypted downgrade attack.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5851&amp;amp;vector=(AV:L/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;2.1&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5851&quot;&gt;CVE-2015-5851&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;SpringBoard in Apple iOS before 9 allows physically proximate attackers to bypass a lock-screen preview-disabled setting, and reply to an audio message, via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5861&amp;amp;vector=(AV:L/AC:L/Au:N/C:N/I:P/A:N)&quot;&gt;2.1&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5861&quot;&gt;CVE-2015-5861&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;IOStorageFamily in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows local users to obtain sensitive information from kernel memory via unknown vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5863&amp;amp;vector=(AV:L/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;2.1&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5863&quot;&gt;CVE-2015-5863&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Apple iOS before 9 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5869&amp;amp;vector=(AV:A/AC:L/Au:N/C:N/I:P/A:N)&quot;&gt;3.3&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5869&quot;&gt;CVE-2015-5869&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://openwall.com/lists/oss-security/2015/04/04/2&quot;&gt;MLIST&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Siri in Apple iOS before 9 allows physically proximate attackers to bypass an intended client-side protection mechanism and obtain sensitive content-notification information by listening to a device in the lock-screen state.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5892&amp;amp;vector=(AV:L/AC:L/Au:N/C:P/I:N/A:N)&quot;&gt;2.1&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5892&quot;&gt;CVE-2015-5892&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;apple -- iphone_os&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;WebKit in Apple iOS before 9 allows man-in-the-middle attackers to conduct redirection attacks by leveraging the mishandling of the resource cache of an SSL web site with an invalid X.509 certificate.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-18&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5907&amp;amp;vector=(AV:N/AC:H/Au:N/C:N/I:P/A:N)&quot;&gt;2.6&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5907&quot;&gt;CVE-2015-5907&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/HT205212&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html&quot;&gt;APPLE&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;structured_dynamics -- open_semantic_framework&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site scripting (XSS) vulnerability in unspecified administration pages in the OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF Ontology module is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-17&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-7232&amp;amp;vector=(AV:N/AC:H/Au:N/C:N/I:P/A:N)&quot;&gt;2.6&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7232&quot;&gt;CVE-2015-7232&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.drupal.org/node/2537860&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.drupal.org/node/2537120&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;typo3 -- typo3&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;The sanitizeLocalUrl function in TYPO3 6.x before 6.2.15, 7.x before 7.4.0, 4.5.40, and earlier allows remote authenticated users to bypass the XSS filter and conduct cross-site scripting (XSS) attacks via a base64 encoded data URI, as demonstrated by the (1) returnUrl parameter to show_rechis.php and the (2) redirect_url parameter to index.php.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-16&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-5956&amp;amp;vector=(AV:N/AC:M/Au:S/C:N/I:P/A:N)&quot;&gt;3.5&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5956&quot;&gt;CVE-2015-5956&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2015-009/&quot;&gt;CONFIRM&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/archive/1/archive/1/536464/100/0/threaded&quot;&gt;BUGTRAQ&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align:left;&quot; width=&quot;20%&quot;&gt;zendesk -- zendesk_feedback_tab&lt;/td&gt;&lt;td style=&quot;text-align:left;&quot;&gt;Cross-site scripting (XSS) vulnerability in the Zendesk Feedback Tab module 7.x-1.x before 7.x-1.1 for Drupal allows remote administrators with the &quot;Configure Zendesk Feedback Tab&quot; permission to inject arbitrary web script or HTML via unspecified vectors.&lt;/td&gt;&lt;td style=&quot;text-align:center;&quot;&gt;2015-09-11&lt;/td&gt;&lt;td style=&quot;text-align:center;width:5%;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/cvss.cfm?version=2&amp;amp;name=CVE-2015-6921&amp;amp;vector=(AV:N/AC:H/Au:N/C:N/I:P/A:N)&quot;&gt;2.6&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6921&quot;&gt;CVE-2015-6921&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.drupal.org/node/2561893&quot;&gt;MISC&lt;/a&gt;&lt;br /&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.drupal.org/node/2561887&quot;&gt;CONFIRM&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov#top&quot;&gt;Back to top&lt;/a&gt;&lt;/div&gt;	
		&lt;hr /&gt;
		
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;	&lt;br /&gt;</description>
         <guid isPermaLink="false">6258 at http://www.us-cert.gov</guid>
         <pubDate>Mon, 21 Sep 2015 10:23:18 +0000</pubDate>
      </item>
      <item>
         <title>VMware Releases Security Update</title>
         <link>http://www.us-cert.gov/ncas/current-activity/2015/09/17/VMware-Releases-Security-Update</link>
         <description>Original release date: September 17, 2015&lt;br /&gt;
	
		&lt;p&gt;VMware has released a security update to address a Lightweight Directory Access Protocol (LDAP) certificate validation vulnerability in vCenter Server. Exploitation of this vulnerability may allow an attacker to obtain sensitive information.&lt;/p&gt;&lt;p&gt;Available updates include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;VMware vCenter Server version 6.0 update 1&lt;/li&gt;&lt;li&gt;VMware vCenter Server version 5.5 update 3&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Users and administrators are encouraged  to review VMware security advisory &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.vmware.com/security/advisories/VMSA-2015-0006.html&quot;&gt;VSMA-2015-0006&lt;/a&gt; and apply the necessary updates.&lt;/p&gt;		
		&lt;hr /&gt;
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;		&lt;br /&gt;</description>
         <guid isPermaLink="false">6257 at http://www.us-cert.gov</guid>
         <pubDate>Thu, 17 Sep 2015 10:47:41 +0000</pubDate>
      </item>
      <item>
         <title>Cisco Releases Security Updates</title>
         <link>http://www.us-cert.gov/ncas/current-activity/2015/09/17/Cisco-Releases-Security-Updates</link>
         <description>Original release date: September 17, 2015&lt;br /&gt;
	
		&lt;p&gt;Cisco has released updates to address vulnerabilities in Prime Collaboration Assurance, Prime Collaboration Provisioning, and TelePresence Server software. Exploitation of these vulnerabilities could allow a remote attacker to escalate privileges, obtain sensitive information, or cause a denial-of-service condition.&lt;br /&gt; &lt;br /&gt;US-CERT encourages users and administrators to review Cisco advisories &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150916-pca&quot;&gt;cisco-sa-20150916-pca&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150916-pcp&quot;&gt;cisco-sa-20150916-pcp&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150916-tps&quot;&gt;cisco-sa-20150916-tps&lt;/a&gt; and apply the necessary updates.&lt;/p&gt;		
		&lt;hr /&gt;
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;		&lt;br /&gt;</description>
         <guid isPermaLink="false">6256 at http://www.us-cert.gov</guid>
         <pubDate>Thu, 17 Sep 2015 10:38:19 +0000</pubDate>
      </item>
      <item>
         <title>Apple Releases Security Updates for OS X Server, iTunes, Xcode, and iOS</title>
         <link>http://www.us-cert.gov/ncas/current-activity/2015/09/16/Apple-Releases-Security-Updates-OS-X-Server-iTunes-Xcode-and-iOS</link>
         <description>Original release date: September 16, 2015&lt;br /&gt;
	
		&lt;p&gt;Apple has released security updates for OS X Server, iTunes, Xcode, and iOS to address multiple vulnerabilities. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.&lt;/p&gt;&lt;p&gt;Available updates include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;OS X Server v5.0.3 for OS X Yosemite v10.10.4 or later&lt;/li&gt;&lt;li&gt;iTunes 12.3 for Windows 7 and later&lt;/li&gt;&lt;li&gt;Xcode 7.0 for OS X Yosemite v10.10.4 or later&lt;/li&gt;&lt;li&gt;iOS 9 for iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;US-CERT encourages users and administrators to review Apple security updates for &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/en-us/HT205219&quot;&gt;OS X Server&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/en-us/HT205221&quot;&gt;iTunes&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/en-us/HT205217&quot;&gt;Xcode&lt;/a&gt;, and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://support.apple.com/en-us/HT205212&quot;&gt;iOS&lt;/a&gt; and apply the necessary updates.&lt;/p&gt;		
		&lt;hr /&gt;
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;		&lt;br /&gt;</description>
         <guid isPermaLink="false">6255 at http://www.us-cert.gov</guid>
         <pubDate>Thu, 17 Sep 2015 00:53:35 +0000</pubDate>
      </item>
      <item>
         <title>Internet Systems Consortium (ISC) Releases Security Updates for BIND</title>
         <link>http://www.us-cert.gov/ncas/current-activity/2015/09/16/Internet-Systems-Consortium-ISC-Releases-Security-Updates-BIND</link>
         <description>Original release date: September 16, 2015&lt;br /&gt;
	
		&lt;p&gt;ISC has released security updates to address vulnerabilities in BIND. Exploitation of these vulnerabilities may allow a remote attacker to cause a denial-of-service condition.&lt;/p&gt;&lt;p&gt;Available updates include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;BIND 9 version 9.9.8&lt;/li&gt;&lt;li&gt;BIND 9 version 9.10.3&lt;/li&gt;&lt;li&gt;BIND 9 version 9.9.8-S1&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Users and administrators are encouraged to review ISC Knowledge Base Articles &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://kb.isc.org/article/AA-01305&quot;&gt;AA-01305&lt;/a&gt;,  &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://kb.isc.org/article/AA-01306&quot;&gt;AA-01306&lt;/a&gt;, and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://kb.isc.org/article/AA-01307&quot;&gt;AA-01307&lt;/a&gt; and apply the necessary updates.&lt;/p&gt;		
		&lt;hr /&gt;
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;		&lt;br /&gt;</description>
         <guid isPermaLink="false">6254 at http://www.us-cert.gov</guid>
         <pubDate>Wed, 16 Sep 2015 17:44:44 +0000</pubDate>
      </item>
      <item>
         <title>ST15-001: IRS and US-CERT Caution Users: Prepare for Heightened Phishing Risk This Tax Season</title>
         <link>http://www.us-cert.gov/ncas/tips/ST15-001</link>
         <description>Original release date: January 30, 2015&lt;br /&gt;&lt;br /&gt;

		&lt;table cellspacing=&quot;6&quot; cellpadding=&quot;6&quot; border=&quot;1&quot;&gt;
			&lt;tr&gt;
				&lt;td bgcolor=&quot;#96B4D2&quot;&gt;
					&lt;font face=&quot;arial, geneva, helvetica&quot;&gt;
											&lt;/font&gt;
				&lt;/td&gt;
			&lt;/tr&gt;
		&lt;/table&gt;	
	
		&lt;h2&gt;Overview&lt;/h2&gt;&lt;p&gt;Throughout the year, scam artists pose as legitimate entities—such as the Internal Revenue Service (IRS), other government agencies, and financial institutions—in an attempt to defraud taxpayers. They employ sophisticated phishing campaigns to lure users to malicious sites or entice them to activate malware in infected email attachments. To protect sensitive data, credentials, and payment information, US-CERT and the IRS recommend taxpayers prepare for heightened risk this tax season and remain vigilant year-round.&lt;/p&gt;&lt;h2&gt;Remain alert&lt;/h2&gt;&lt;p&gt;Phishing attacks use email or malicious websites to solicit personal information by posing as a trustworthy organization. In many successful incidents, recipients are fooled into believing the phishing communication is from someone they trust. An actor may take advantage of knowledge gained from research and earlier attempts to masquerade as a legitimate source, including the look and feel of authentic communications. These targeted messages can trick any user into taking action that may compromise enterprise security.&lt;/p&gt;&lt;h2&gt;Spot common elements of the phishing lifecycle&lt;/h2&gt;&lt;ol style=&quot;margin-left:40px;&quot;&gt;&lt;li&gt;&lt;strong&gt;A Lure&lt;/strong&gt;: enticing email content.&lt;ul&gt;&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.irs.gov/pub/irs-utl/phishing_email.pdf&quot;&gt;Example 1&lt;/a&gt; of actual phishing email&lt;/li&gt;&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.irs.gov/pub/irs-utl/phishing_email2.pdf&quot;&gt;Example 2&lt;/a&gt; of actual phishing email&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;A Hook&lt;/strong&gt;: an email-based exploit.&lt;ul&gt;&lt;li&gt;Email with embedded malicious content that is executed as a side effect of opening the email&lt;/li&gt;&lt;li&gt;Email with malicious attachments that are activated as a side effect of opening an attachment&lt;/li&gt;&lt;li&gt;Email with “clickable” URLs: the body of the email includes a link, which displays as a recognized, legitimate website, though the actual URL redirects the user to malicious content&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;A Catch&lt;/strong&gt;: a transaction conducted by an actor following a successful attempt.&lt;ul&gt;&lt;li&gt;Unexplainable charges&lt;/li&gt;&lt;li&gt;Unexplainable password changes&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Understand how the IRS communicates electronically with taxpayers&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;The IRS does not initiate contact with taxpayers by email, text messages or social media channels to request personal or financial information.&lt;/li&gt;&lt;li&gt;This includes requests for PIN numbers, passwords or similar access information for credit cards, banks or other financial accounts.&lt;/li&gt;&lt;li&gt;The official website of the IRS is &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.irs.gov&quot;&gt;www.irs.gov&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Take action to avoid becoming a victim&lt;/h2&gt;&lt;p&gt;If you believe you might have revealed sensitive information about your organization or access credentials, report it to the appropriate contacts within the organization, including network administrators. They can be alert for any suspicious or unusual activity.&lt;/p&gt;&lt;p&gt;Watch for any unexplainable charges to your financial accounts. If you believe your accounts may be compromised, contact your financial institution immediately and close those accounts.&lt;/p&gt;&lt;p&gt;If you believe you might have revealed sensitive account information, immediately change the passwords you might have revealed. If you used the same password for multiple accounts, make sure to change the password for each account and do not use that password in the future.&lt;/p&gt;&lt;h2&gt;Report suspicious phishing communications&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Email: If you read an email claiming to be from the IRS, do not reply or click on attachments and/or links. Forward the email as-is to &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.govmailto:phishing@irs.gov&quot;&gt;phishing@irs.gov&lt;/a&gt;, then delete the original email.&lt;/li&gt;&lt;li&gt;Website: If you find a website that claims to be the IRS and suspect it is fraudulent, send the URL of the suspicious site to &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.govmailto:phishing@irs.gov&quot;&gt;phishing@irs.gov&lt;/a&gt; with subject line, “Suspicious website”.&lt;/li&gt;&lt;li&gt;Text Message: If you receive a suspicious text message, do not reply or click on attachments and/or links. Forward the text as-is to 202-552-1226 (standard text rates apply), and then delete the original message (if you clicked on links in SMS and entered confidential information, visit the IRS’ &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.irs.gov/Individuals/Identity-Protection&quot;&gt;identity protection&lt;/a&gt; page).&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;If you are a victim of any of the above scams involving IRS impersonation, please report to &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.govmailto:phishing@irs.gov&quot;&gt;phishing@irs.gov&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.treasury.gov/tigta/contact_report_scam.shtml&quot;&gt;file a report&lt;/a&gt; with the Treasury Inspector General for Tax Administration (TIGTA), the Federal Trade Commission (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.ftccomplaintassistant.gov/&quot;&gt;FTC&lt;/a&gt;), and the police.&lt;/p&gt;&lt;h2&gt;Additional Resources&lt;/h2&gt;&lt;p&gt;For more information on phishing, other suspicious IRS-related communications including phone or fax scams, or additional guidance released by Treasury/IRS and DHS/US-CERT, visit:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.us-cert.gov/ncas/tips/ST04-014&quot;&gt;Avoiding Social Engineering and Phishing Attacks&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.us-cert.gov/security-publications/recognizing-and-avoiding-email-scams&quot;&gt;Recognizing and Avoiding Email Scams&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.irs.gov/uac/Phishing-and-Other-Schemes-Using-the-IRS-Name&quot;&gt;Phishing and Other Schemes Using the IRS Name&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.irs.gov/uac/Newsroom/IRS-Repeats-Warning-about-Phone-Scams&quot;&gt;IRS Repeats Warning about Phone Scams&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.irs.gov/uac/Report-Phishing&quot;&gt;Report Phishing and Online Scams&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.irs.gov/uac/Newsroom/Tips-for-Taxpayers,-Victims-about-Identity-Theft-and-Tax-Returns-2014&quot;&gt;Tips for Taxpayers, Victims about Identity Theft and Tax Returns&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;To report a cybersecurity incident, vulnerability, or phishing attempt, visit &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/report&quot;&gt;US-CERT.gov/report&lt;/a&gt;.&lt;/p&gt;		
				
		&lt;hr /&gt;
		
		Author: US-CERT and IRS		&lt;hr /&gt;
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;</description>
         <guid isPermaLink="false">6045 at http://www.us-cert.gov</guid>
         <pubDate>Fri, 30 Jan 2015 05:00:00 +0000</pubDate>
      </item>
      <item>
         <title>ST14-001: Sochi 2014 Olympic Games</title>
         <link>http://www.us-cert.gov/ncas/tips/ST14-001</link>
         <description>Original release date: February 04, 2014 | Last revised: March 10, 2014&lt;br /&gt;&lt;br /&gt;

		&lt;table cellspacing=&quot;6&quot; cellpadding=&quot;6&quot; border=&quot;1&quot;&gt;
			&lt;tr&gt;
				&lt;td bgcolor=&quot;#96B4D2&quot;&gt;
					&lt;font face=&quot;arial, geneva, helvetica&quot;&gt;
											&lt;/font&gt;
				&lt;/td&gt;
			&lt;/tr&gt;
		&lt;/table&gt;	
	
		&lt;h3&gt;Overview&lt;/h3&gt;&lt;p&gt;Whether traveling to Sochi, Russia for the XXII Olympic Winter Games, or viewing the games from locations abroad, there are several cyber-related risks to consider. As with many international level media events, hacktivists may attempt to take advantage of the large audience to spread their own message. Additionally, cyber criminals may use the games as a lure in spam, phishing or drive-by-download campaigns to gain personally identifiable information or harvest credentials for financial gain. Lastly, those physically attending the games should be cognizant that their communications will likely be monitored.&lt;/p&gt;&lt;h3&gt;Hacktivists&lt;/h3&gt;&lt;p&gt;A number of hacktivist campaigns may attach themselves to the upcoming Olympics simply to take advantage of the on-looking audience. For example, the hacktivist group, Anonymous Caucasus, has launched what appears to be a threat against any company that finances or supports the winter games. This group states the Sochi games infrastructure was built on the graves of 1 million innocent Caucasians who were murdered by the Russians in 1864. According to Trusted Third Party analysis, the group has been linked to distributed denial of service (DDoS) attacks on Russian banks in October 2013. Therefore, the group is likely capable of waging similar attacks on the websites of organizations they believe financed Olympic related activities; however, no specific threat or target has been identified at the time of this report. &lt;/p&gt;&lt;h3&gt;Olympic coverage&lt;/h3&gt;&lt;p&gt;Whether viewing live coverage, event replays, or checking medal statistics online, it’s important to visit only trusted websites. Events which gain significant public interest and media coverage are often used as lures for spam or spearphishing campaigns. Malicious actors may also create fake websites and domains that appear to be official Olympic news or coverage that can be used to deliver malware to an end user upon visiting the site (also known as drive-by downloads or wateringholes).&lt;/p&gt;&lt;p&gt;NBCUniversal offers exclusive coverage of the games for viewers via NBC, NBCSN, MSNBC, USA Network, NBCOlympics.com and corresponding Twitter, Facebook and Instagram accounts. Viewers should be wary of any other source claiming to provide live coverage. As always, it is best to visit trusted resources directly rather than clicking on emailed links or opening attachments. &lt;/p&gt;&lt;h3&gt;Purchasing tickets or merchandise at the Games&lt;/h3&gt;&lt;p&gt;According to the official Winter Olympics website: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.sochi2014.com/&quot;&gt;http://www.sochi2014.com&lt;/a&gt;, Visa will be the only card accepted for all purchases including tickets and merchandise at the Games. Tickets may only be purchased through Authorized Ticket Resellers (ATR). Individuals can validate the authenticity of an ATR offering tickets by using the “Website Checker” tool available on the official Sochi website. The designated ATR in the United States is CoSport, and at the time of this report, individuals purchasing tickets through CoSport may only pick up their tickets at CoSport’s Host City Collection Center in Sochi, Russia. Any ticket offer from a site not recognized as an ATR or accepting payment methods outside of VISA are likely fraudulent and should be met with skepticism.&lt;/p&gt;&lt;h3&gt;Traveling to Sochi&lt;/h3&gt;&lt;p&gt;When traveling abroad it’s important to know your host countries laws and policies, particularly when it comes to privacy. Russia has a national system of lawful interception of all electronic communications. The System of Operative-Investigative Measures, or SORM, legally allows the Russian FSB to monitor, intercept, and block any communication sent electronically (i.e. cell phone or landline calls, internet traffic, etc.). SORM-1 captures telephone and mobile phone communications, SORM-2 intercepts internet traffic, and SORM-3 collects information from all forms of communication, providing long-term storage of all information and data on subscribers, including actual recordings and locations. Reports of Rostelecom, Russia’s national telecom operator, installing deep packet inspection (DPI ) means authorities can easily use key words to search and filter communications. Therefore, it is important that attendees understand communications while at the Games should not be considered private.&lt;/p&gt;&lt;p&gt;Russia also retains broad inbound encryption license requirements. Taking laptops and other devices into the country is unrestricted; however software may be inspected upon departure. This means, any computer or software containing sensitive or encrypted data may be confiscated by Russian authorities when individuals depart from the country . Travelers may want to consider leaving personal electronic devices (e.g. laptops, smartphones, tablets) at home or alternatively bring loaner devices that do not already store sensitive data on them and can be wiped upon return to your home country. If individuals decide to bring their personal devices, consider all communications and files on them to be vulnerable to interception or confiscation. &lt;/p&gt;		
				
		&lt;h3&gt;References&lt;/h3&gt;
		&lt;ul&gt;
					&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.kavkazcenter.com/eng/content/2013/12/30/18723.shtml&quot;&gt;Message from Caucasus Anonymous on Operation Pay Back for Sochi 2014 to Russian government&lt;/a&gt;&lt;/li&gt;
						&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.nbcolympics.com/&quot;&gt;NBC Olympics&lt;/a&gt;&lt;/li&gt;
						&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://nbcsportsgrouppressbox.com/2013/12/19/nbcuniversal-to-provide-unprecedented-coverage-of-2014-sochi-olympics/&quot;&gt;NBC Sports Pressbox&lt;/a&gt;&lt;/li&gt;
						&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.cosport.com/&quot;&gt;CoSport&lt;/a&gt;&lt;/li&gt;
						&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.theguardian.com/world/2013/oct/06/sochi-olympic-venues-kremlin-surveillance&quot;&gt;As Sochi Olympic venues are built, so are Kremlin's surveillance networks&lt;/a&gt;&lt;/li&gt;
						&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.wired.co.uk/news/archive/2012-04/27/how-deep-packet-inspection-works&quot;&gt;How deep packet inspection works&lt;/a&gt;&lt;/li&gt;
						&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.nationaldefensemagazine.org/archive/2013/August/pages/UseCautionWhenTravelingWithEncryptionSoftware.aspx&quot;&gt;Use Caution When Traveling With Encryption Software  &lt;/a&gt;&lt;/li&gt;
					&lt;/ul&gt;
				
		&lt;hr /&gt;
		
		Author: NCCIC Watch &amp;amp; Warning		&lt;hr /&gt;
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;</description>
         <guid isPermaLink="false">5787 at http://www.us-cert.gov</guid>
         <pubDate>Tue, 04 Feb 2014 15:20:38 +0000</pubDate>
      </item>
      <item>
         <title>ST13-003: Handling Destructive Malware</title>
         <link>http://www.us-cert.gov/ncas/tips/ST13-003</link>
         <description>Original release date: November 04, 2013&lt;br /&gt;&lt;br /&gt;

		&lt;table cellspacing=&quot;6&quot; cellpadding=&quot;6&quot; border=&quot;1&quot;&gt;
			&lt;tr&gt;
				&lt;td bgcolor=&quot;#96B4D2&quot;&gt;
					&lt;font face=&quot;arial, geneva, helvetica&quot;&gt;
											&lt;/font&gt;
				&lt;/td&gt;
			&lt;/tr&gt;
		&lt;/table&gt;	
	
		&lt;h2&gt;Overview&lt;/h2&gt;&lt;p&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://ics-cert.us-cert.gov/jsar/JSAR-12-241-01B-0&quot;&gt;&lt;span&gt;Destructive malware&lt;/span&gt;&lt;/a&gt;&lt;span&gt; presents a direct threat to an organization’s daily operations, directly impacting the availability of critical assets and data. Organizations should increase vigilance and evaluate their capabilities encompassing planning, preparation, detection, and response for such an event. This publication is focused on the threat of enterprise-scale distributed propagation methods for malware and provides recommended guidance and considerations for an organization to address as part of their network architecture, security baseline, continuous monitoring, and Incident Response practices.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;While specific indicators and modules related to destructive malware may evolve over time, it is critical that an organization assess their capability to actively prepare for and respond to such an event.&lt;/span&gt;&lt;/p&gt;&lt;h2&gt;Potential Distribution Vectors&lt;/h2&gt;&lt;p&gt;&lt;span&gt;Destructive malware has the capability to target a large scope of systems, and can potentially execute across multiple systems throughout a network. As a result, it is important for an organization to assess their environment for atypical channels for potential  malware delivery and/or propagation throughout their systems. Systems to assess include:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Enterprise Applications – particularly those which have the capability to directly interface with and impact multiple hosts and endpoints. Common examples include&lt;/span&gt;&lt;ul style=&quot;list-style-type:circle;&quot;&gt;&lt;li&gt;&lt;span&gt;Patch Management Systems,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Asset Management Systems,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Remote Assistance software (typically utilized by the corporate Help Desk),&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Anti-Virus,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Systems assigned to system and network administrative personnel,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Centralized Backup Servers, and&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Centralized File Shares.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span&gt;While not applicable to malware specifically, threat actors could compromise additional resources to impact the availability of critical data and applications.  Common examples include:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Centralized storage devices&lt;/span&gt;&lt;ul style=&quot;list-style-type:circle;&quot;&gt;&lt;li&gt;&lt;span&gt;Potential Risk – direct access to partitions and data warehouses;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Network devices&lt;/span&gt;&lt;ul style=&quot;list-style-type:circle;&quot;&gt;&lt;li&gt;&lt;span&gt;Potential Risk – capability to inject false routes within the routing table, delete specific routes from the  routing table, or remove/modify configuration attributes - which could isolate or degrade availability of critical network resources.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Best Practices and Planning Strategies&lt;/h2&gt;&lt;p&gt;Common strategies can be followed to strengthen an organization’s resilience against destructive malware.  Targeted assessment and enforcement of best practices should be employed for enterprise components susceptible to destructive malware.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;Communication Flow&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://ics-cert.us-cert.gov/sites/default/files/recommended_practices/Defense_in_Depth_Oct09.pdf&quot;&gt;Ensure proper network segmentation&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Ensure that network-based access-control lists (ACLs) are configured to permit server-to-host and host-to-host connectivity via the minimum scope of ports and protocols – and that directional flows for connectivity are represented appropriately.&lt;ul style=&quot;list-style-type:circle;&quot;&gt;&lt;li&gt;Communication flow paths should be fully defined, documented, and authorized.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Increase awareness of systems which can be utilized as a gateway to pivot (lateral movement) or directly connect to additional endpoints throughout the enterprise.&lt;ul style=&quot;list-style-type:circle;&quot;&gt;&lt;li&gt;Ensure that these systems are contained within restrictive VLANs, with additional segmentation and network access-controls.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Ensure that centralized network and storage devices’ management interfaces are resident on restrictive VLANs.&lt;ul style=&quot;list-style-type:circle;&quot;&gt;&lt;li&gt;Layered access-control, and&lt;/li&gt;&lt;li&gt;Device-level access-control enforcement – restricting access from only pre-defined VLANs and trusted IP ranges.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;Access Control&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;For Enterprise systems which can directly interface with multiple endpoints:&lt;ul style=&quot;list-style-type:circle;&quot;&gt;&lt;li&gt;Require two factor authentication for interactive logons.&lt;/li&gt;&lt;li&gt;Ensure that authorized users are mapped to a specific subset of enterprise personnel.&lt;ul&gt;&lt;li&gt; If possible, the “Everyone” , “Domain Users”  or the “Authenticated Users” groups should not be permitted the capability to directly access or authenticate to these systems.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Ensure that unique domain accounts are utilized and documented for each Enterprise application service.&lt;ul&gt;&lt;li&gt;Context of permissions assigned to these accounts should be fully documented and configured based upon the concept of least privilege.&lt;/li&gt;&lt;li&gt;Provides an enterprise with the capability to track and monitor specific actions correlating to an application’s assigned service account.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;If possible, do not grant a service account with local or interactive logon permissions.&lt;ul&gt;&lt;li&gt;Service accounts should be explicitly denied permissions to access network shares and critical data locations.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Accounts which are utilized to authenticate to centralized enterprise application servers or devices should not contain elevated permissions on downstream systems and resources throughout the enterprise.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Continuously review centralized file share access-control lists and assigned permissions.&lt;ul style=&quot;list-style-type:circle;&quot;&gt;&lt;li&gt;Restrict Write/Modify/Full Control permissions when possible.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;Monitoring&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Audit and review security logs for anomalous references to enterprise-level administrative (privileged) and service accounts.&lt;ul style=&quot;list-style-type:circle;&quot;&gt;&lt;li&gt;Failed logon attempts,&lt;/li&gt;&lt;li&gt;File share access, and&lt;/li&gt;&lt;li&gt;Interactive logons via a remote session.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Review network flow data for signs of anomalous activity.&lt;ul style=&quot;list-style-type:circle;&quot;&gt;&lt;li&gt;Connections utilizing ports which do not correlate to the standard communication flow associated with an application,&lt;/li&gt;&lt;li&gt;Activity correlating to port scanning or enumeration, and&lt;/li&gt;&lt;li&gt;Repeated connections utilizing ports which can be utilized for command and control purposes.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Ensure that network devices log and audit all configuration changes.&lt;ul style=&quot;list-style-type:circle;&quot;&gt;&lt;li&gt;Continually review network device configurations and rule sets, to ensure that communication flows are restricted to the authorized subset of rules.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;File Distribution&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;When deploying patches or AV signatures throughout an enterprise, stage the distributions to include a specific grouping of systems (staggered over a pre-defined time period).&lt;ul style=&quot;list-style-type:circle;&quot;&gt;&lt;li&gt;This action can minimize the overall impact in the event that an enterprise patch management or AV system is leveraged as a distribution vector for a malicious payload.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Monitor and assess the integrity of patches and AV signatures which are distributed throughout the enterprise.&lt;ul style=&quot;list-style-type:circle;&quot;&gt;&lt;li&gt;Ensure updates are received only from trusted sources,&lt;/li&gt;&lt;li&gt;Perform file and data integrity checks, and&lt;/li&gt;&lt;li&gt;Monitor and audit – as related to the data that is distributed from an enterprise application.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;System and Application Hardening&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Ensure that the underlying Operating System (OS) and dependencies (ex: IIS, Apache, SQL) supporting an application are configured and hardened based upon industry-standard &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://web.nvd.nist.gov/view/ncp/repository&quot;&gt;best practice recommendations&lt;/a&gt;. Implement application-level security controls based upon best practice guidance provided by the vendor.  Common recommendations include:&lt;ul style=&quot;list-style-type:circle;&quot;&gt;&lt;li&gt;Utilize role-based access control,&lt;/li&gt;&lt;li&gt;Prevent end-user capabilities to bypass application-level security controls,&lt;ul&gt;&lt;li&gt;Example – disabling Antivirus on a local workstation&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Disable un-necessary or un-utilized features or packages, and&lt;/li&gt;&lt;li&gt;Implement robust application logging and auditing&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Thoroughly test and implement vendor patches in a timely manner.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Recovery and Reconstitution Planning&lt;/h2&gt;&lt;p&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://csrc.nist.gov/publications/nistpubs/800-34-rev1/sp800-34-rev1_errata-Nov11-2010.pdf&quot;&gt;A Business Impact Analysis (BIA)&lt;/a&gt; is a key component of contingency planning and preparation.   The overall output of a BIA will provide an organization with two key components (as related to critical mission/business operations):&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Characterization and classification of system components, and&lt;/li&gt;&lt;li&gt;Interdependencies.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Based upon the identification of an organization’s mission critical assets (and their associated interdependencies), in the event that an organization is impacted by a potentially destructive condition, recovery and reconstitution efforts should be considered.&lt;/p&gt;&lt;p&gt;To plan for this scenario, an organization should address the availability and accessibility for the following resources (and should include the scope of these items within Incident Response exercises and scenarios):&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Comprehensive inventory of all mission critical systems and applications:&lt;/span&gt;&lt;ul style=&quot;list-style-type:circle;&quot;&gt;&lt;li&gt;&lt;span&gt;Versioning information,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;System / application dependencies,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;System partitioning/ storage configuration and connectivity, and&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Asset Owners / Points of Contact.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Comprehensive inventory of all mission critical systems and applications:&lt;/span&gt;&lt;ul style=&quot;list-style-type:circle;&quot;&gt;&lt;li&gt;&lt;span&gt;Versioning information,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;System / application dependencies,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;System partitioning/ storage configuration and connectivity, and&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Asset Owners / Points of Contact.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Contact information for all essential personnel within the organization,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Secure communications channel for recovery teams,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Contact information for external organizational-dependant resources:&lt;/span&gt;&lt;ul style=&quot;list-style-type:circle;&quot;&gt;&lt;li&gt;&lt;span&gt;Communication Providers,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Vendors (hardware / software), and&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Outreach partners / External Stakeholders&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Service Contract Numbers - for engaging vendor support,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Organizational Procurement Points of Contact,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;ISO / image files for baseline restoration of critical systems and applications:&lt;/span&gt;&lt;ul style=&quot;list-style-type:circle;&quot;&gt;&lt;li&gt;&lt;span&gt;Operating System installation media,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Service Packs / Patches,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Firmware, and&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Application software installation packages.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Licensing/activation keys for Operating Systems (OS) and dependant applications, &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Enterprise Network Topology and Architecture diagrams,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;System and application documentation,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Hard copies of operational checklists and playbooks,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;System  and application configuration backup files, &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Data backup files (full/differential),&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;System and application security baseline and hardening checklists/guidelines, and&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;System and application integrity test and acceptance checklists.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Containment&lt;/h2&gt;&lt;p&gt;&lt;span&gt;In the event that an organization observes a large-scale outbreak that may be reflective of a &lt;/span&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://ics-cert.us-cert.gov/jsar/JSAR-12-241-01B-0&quot;&gt;&lt;span&gt;destructive malware attack&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, in accordance with Incident Response best practices, the immediate focus should be to contain the outbreak, and reduce the scope of additional systems which could be further impacted.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Strategies for containment include:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Determining a vector common to all systems experiencing anomalous behavior (or having been rendered unavailable) – from which a malicious payload could have been delivered:&lt;/span&gt;&lt;ul style=&quot;list-style-type:circle;&quot;&gt;&lt;li&gt;&lt;span&gt;Centralized Enterprise Application,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Centralized File Share (for which the identified systems were mapped or had access),&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Privileged User Account common to the identified systems,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Network Segment or Boundary, and&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Common DNS Server for name resolution.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Based upon the determination of a likely distribution vector, additional mitigation controls can be enforced to further minimize impact:&lt;/span&gt;&lt;ul style=&quot;list-style-type:circle;&quot;&gt;&lt;li&gt;&lt;span&gt;Implement network-based access-control lists to deny the identified application(s) the capability to directly communicate with additional systems,&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Provides an immediate capability to isolate and sandbox specific systems or resources&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Implement null network routes for specific IP addresses (or IP ranges) – from which the payload may be distributed,&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;An organization’s internal DNS can also be leveraged for this task – as a null pointer record could be added within a DNS zone for an identified server or application &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Readily disable access for suspected user or service account(s), and&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;For suspect file shares (which may be hosting the infection vector), remove access or disable the share path from being accessed by additional systems.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span&gt;As related to incident response and &lt;/span&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://ics-cert.us-cert.gov/sites/default/files/DHS_CyberSecurity_CSSP-Incident_Handling-v10.pdf&quot;&gt;&lt;span&gt;incident handling&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, organizations are reminded to:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Report the incident to &lt;/span&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/contact-us&quot;&gt;&lt;span&gt;US-CERT&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and/or &lt;/span&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://ics-cert.us-cert.gov/&quot;&gt;&lt;span&gt;ICS-CERT&lt;/span&gt;&lt;/a&gt;&lt;span&gt; for tracking and correlation purposes, and&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://ics-cert.us-cert.gov/sites/default/files/Incident_Handling_Brochure_Nov_2010.pdf&quot;&gt;&lt;span&gt;Preserve forensic data&lt;/span&gt;&lt;/a&gt;&lt;span&gt; for use in internal investigation of the incident or for possible law enforcement purposes.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style=&quot;margin-left:37.95pt;&quot;&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;		
				
		&lt;hr /&gt;
		
		Author: ICS-CERT and US-CERT		&lt;hr /&gt;
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;</description>
         <guid isPermaLink="false">5723 at http://www.us-cert.gov</guid>
         <pubDate>Mon, 04 Nov 2013 17:58:25 +0000</pubDate>
      </item>
      <item>
         <title>13-002: International Mobile Safety Tips</title>
         <link>http://www.us-cert.gov/ncas/tips/13-002</link>
         <description>Original release date: October 29, 2013 | Last revised: November 04, 2013&lt;br /&gt;&lt;br /&gt;

		&lt;table cellspacing=&quot;6&quot; cellpadding=&quot;6&quot; border=&quot;1&quot;&gt;
			&lt;tr&gt;
				&lt;td bgcolor=&quot;#96B4D2&quot;&gt;
					&lt;font face=&quot;arial, geneva, helvetica&quot;&gt;
											&lt;/font&gt;
				&lt;/td&gt;
			&lt;/tr&gt;
		&lt;/table&gt;	
	
		&lt;p&gt;October 29, 2013 marks the 4th Annual Asia Pacific Economic Cooperation Cyber Security Awareness Day. To recognize this occasion and in observance of the 10th year of National Cyber Security Awareness Month in the United States, US-CERT, along with its international partners from Asia and Europe, is promoting a set of International Mobile Safety Tips that were developed by the National Cyber Security Alliance, InfollutionZero, the Cyber Security Awareness Alliance in Singapore, and the iZ HERO Project.&lt;/p&gt;&lt;p&gt;The goal of the campaign is to use harmonized messaging to reach out to children, families, and schools across the world, and to provide them with core principles and simple tips that can help people of all ages enjoy safer and more secure use of digital devices and the Internet.&lt;/p&gt;&lt;p&gt;US-CERT encourages users and administrators to view the International Mobile Safety Tips at the following link and share them with their respective communities.&lt;/p&gt;&lt;p&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://stopthinkconnect.org/campaigns/details/?id=442&quot;&gt;http://stopthinkconnect.org/campaigns/details/?id=442&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;The guidelines below provide core principles and recommendations for more secure use of digital devices and the Internet.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Keep software updated. Running the most recent versions of your mobile operating system, security software, apps and Web browsers is among the best defenses against malware, viruses and other online threats.&lt;/li&gt;&lt;li&gt;Keep your device secure by using a strong password to lock your smartphone or tablet.&lt;/li&gt;&lt;li&gt;Enable two-step authentication when offered, and change passwords to any accounts you accessed while connected to an unfamiliar network. &lt;/li&gt;&lt;li&gt;Before downloading an application (app), make sure you understand what information (i.e., location, your contacts, social networking profiles, etc.) the app would access and share before you download it. Download apps from trusted sources.&lt;/li&gt;&lt;li&gt;Back up your contacts, photos, videos and other mobile device data with another device or cloud service on a weekly basis.&lt;/li&gt;&lt;li&gt;When using a public or unsecured wireless connection, avoid using sites and apps that require personal information like log-ins.&lt;/li&gt;&lt;li&gt;Automatically connecting to networks can create vulnerabilities exploitable by hackers and others. Switch off your Wi-Fi and Bluetooth connections when not in use.&lt;/li&gt;&lt;li&gt;Delete any online communications (i.e., texts, emails, social media posts) that look suspicious, even if you think you know the source.  &lt;/li&gt;&lt;li&gt;When banking or shopping online, use only trusted apps or websites that begin with https://.&lt;/li&gt;&lt;li&gt;The Golden Rule. Be respectful on your device. Treat others as you would like to be treated when texting, calling or using social networks.&lt;/li&gt;&lt;li&gt;Share with care. Be a true friend when taking and sharing photos and videos with your smartphone. Get permission from friends before you share them via text or social networks.&lt;/li&gt;&lt;li&gt;Be Web wise. Stay informed of the latest updates to your device and apps. Know what to do if something goes wrong. &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Related Topics:&lt;/p&gt;&lt;ul style=&quot;list-style-type:square;&quot;&gt;&lt;li&gt;&lt;span&gt;Safety and Security for the Business Professional Traveling Abroad &lt;/span&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.fbi.gov/about-us/investigate/counterintelligence/business-brochure&quot;&gt;&lt;span&gt;http://www.fbi.gov/about-us/investigate/counterintelligence/business-brochure&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;(ST05-017)&lt;/span&gt; Cybersecurity for Electronic Devices &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/ncas/tips/ST05-017&quot;&gt;&lt;span&gt;http://www.us-cert.gov/ncas/tips/ST05-017&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;(ST04-017) Protecting Physical Devices: Physical Security &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/ncas/tips/ST04-017&quot;&gt;http://www.us-cert.gov/ncas/tips/ST04-017&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;		
				
		&lt;h3&gt;References&lt;/h3&gt;
		&lt;ul&gt;
					&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://stopthinkconnect.org/campaigns/details/?id=442&quot;&gt;International Mobile Safety Tips - Stop Think Connect&lt;/a&gt;&lt;/li&gt;
					&lt;/ul&gt;
				
		&lt;hr /&gt;
		
		Author: US-CERT		&lt;hr /&gt;
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;</description>
         <guid isPermaLink="false">5717 at http://www.us-cert.gov</guid>
         <pubDate>Tue, 29 Oct 2013 17:32:47 +0000</pubDate>
      </item>
      <item>
         <title>ST04-017: Protecting Portable Devices: Physical Security</title>
         <link>http://www.us-cert.gov/ncas/tips/ST04-017</link>
         <description>Original release date: December 19, 2011 | Last revised: February 06, 2013&lt;br /&gt;&lt;br /&gt;

		&lt;table cellspacing=&quot;6&quot; cellpadding=&quot;6&quot; border=&quot;1&quot;&gt;
			&lt;tr&gt;
				&lt;td bgcolor=&quot;#96B4D2&quot;&gt;
					&lt;font face=&quot;arial, geneva, helvetica&quot;&gt;
						Many computer users, especially those who travel for business, rely on laptops and personal internet-enabled devices like smartphones and tablets because they are small and easily transported. But while these characteristics make them popular and convenient, they also make them an ideal target for thieves. Make sure to secure your mobile devices to protect both the machine and the information they contain.					&lt;/font&gt;
				&lt;/td&gt;
			&lt;/tr&gt;
		&lt;/table&gt;	
	
		&lt;h3&gt;What is at risk?&lt;/h3&gt;&lt;p&gt;Only you can determine what is actually at risk. If a thief steals your laptop or mobile device, the most obvious loss is the machine itself. However, if the thief is able to access the information on the computer or mobile device, all of the information stored on the device is at risk, as well as any additional information that could be accessed as a result of the data stored on the device itself.&lt;/p&gt;&lt;p&gt;Sensitive corporate information or customer account information should not be accessed by unauthorized people. You've probably heard news stories about organizations panicking because laptops with confidential information on them have been lost or stolen. But even if there isn't any sensitive corporate information on your laptop or mobile device, think of the other information at risk: information about appointments, passwords, email addresses and other contact information, personal information for online accounts, etc.&lt;/p&gt;&lt;h3&gt;How can you protect your laptop or internet-enabled device?&lt;/h3&gt;&lt;ul class=&quot;bulleted&quot;&gt;&lt;li&gt;&lt;b&gt;Password-protect your computer&lt;/b&gt; - Make sure that you have to enter a password to log in to your computer or mobile device (see &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/cas/tips/ST04-002.html&quot;&gt;Choosing and Protecting Passwords&lt;/a&gt; for more information).&lt;/li&gt;&lt;li&gt;&lt;b&gt;Keep your valuables with you at all times&lt;/b&gt; - When traveling, keep your device with you. Meal times are optimum times for thieves to check hotel rooms for unattended laptops. If you are attending a conference or trade show, be especially wary—these venues offer thieves a wider selection of devices that are likely to contain sensitive information, and the conference sessions offer more opportunities for thieves to access guest rooms.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Downplay your laptop or mobile device&lt;/b&gt; - There is no need to advertise to thieves that you have a laptop or mobile device. Avoid using your device in public areas, and consider non-traditional bags for carrying your laptop.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Be aware of your surroundings&lt;/b&gt; - If you do use your laptop or mobile device in a public area, pay attention to people around you. Take precautions to shield yourself from &quot;shoulder surfers&quot;—make sure that no one can see you type your passwords or see any sensitive information on your screen.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Consider an alarm or lock&lt;/b&gt; - Many companies sell alarms or locks that you can use to protect or secure your laptop. If you travel often or will be in a heavily populated area, you may want to consider investing in an alarm for your laptop bag or a lock to secure your laptop to a piece of furniture.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Back up your files&lt;/b&gt; - If your mobile device is stolen, it's bad enough that someone else may be able to access your information. To avoid losing all of the information, make backups of important information and store the backups in a separate location (see &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/cas/tips/ST04-003.html&quot;&gt;Good Security Habits&lt;/a&gt; for more information). Not only will you still be able to access the information, but you'll be able to identify and report exactly what information is at risk.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;What can you do if your laptop or mobile device is lost or stolen?&lt;/h3&gt;&lt;p&gt;Report the loss or theft to the appropriate authorities. These parties may include representatives from law enforcement agencies, as well as hotel or conference staff. If your device contained sensitive corporate or customer account information, immediately report the loss or theft to your organization so that they can act quickly.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;		
				
		&lt;hr /&gt;
		
		Author: Mindi McDowell		&lt;hr /&gt;
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;</description>
         <guid isPermaLink="false">106 at http://www.us-cert.gov</guid>
         <pubDate>Mon, 19 Dec 2011 18:01:34 +0000</pubDate>
      </item>
      <item>
         <title>ST11-001: Holiday Traveling with Personal Internet-Enabled Devices</title>
         <link>http://www.us-cert.gov/ncas/tips/ST11-001</link>
         <description>Original release date: December 19, 2011 | Last revised: February 06, 2013&lt;br /&gt;&lt;br /&gt;

		&lt;table cellspacing=&quot;6&quot; cellpadding=&quot;6&quot; border=&quot;1&quot;&gt;
			&lt;tr&gt;
				&lt;td bgcolor=&quot;#96B4D2&quot;&gt;
					&lt;font face=&quot;arial, geneva, helvetica&quot;&gt;
						The internet is at our fingertips with the widespread use of internet-enabled devices such as smart phones and tablets. When traveling and shopping anytime, and especially during the holidays, consider the wireless network you are using when you complete transactions on your device. 					&lt;/font&gt;
				&lt;/td&gt;
			&lt;/tr&gt;
		&lt;/table&gt;	
	
		&lt;h3&gt;Know the risks&lt;/h3&gt;&lt;p&gt;Your smart phone, tablet, or other device is a full-fledged computer. It is susceptible to risks inherent in online transactions. When shopping, banking, or sharing personal information online, take the same precautions with your smart phone or other device that you do with your personal computer — and then some. The mobile nature of these devices means that you should also take precautions for the physical security of your device (see &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/cas/tips/ST04-017.html&quot;&gt;Protecting Portable Devices: Physical Security&lt;/a&gt; for more information) and consider the way you are accessing the internet.&lt;/p&gt;&lt;h3&gt;Do not use public Wi-Fi networks&lt;/h3&gt;&lt;p&gt;Avoid using open Wi-Fi networks to conduct personal business, bank, or shop online. Open Wi-Fi networks at places such as airports, coffee shops, and other public locations present an opportunity for attackers to intercept sensitive information that you would provide to complete an online transaction.&lt;/p&gt;&lt;p&gt;If you simply must check your bank balance or make an online purchase while you are traveling, turn off your device's Wi-Fi connection and use your mobile device's cellular data internet connection instead of making the transaction over an unsecure Wi-Fi network.&lt;/p&gt;&lt;h3&gt;Turn off Bluetooth when not in use&lt;/h3&gt;&lt;p&gt;Bluetooth-enabled accessories can be helpful, such as earpieces for hands-free talking and external keyboards for ease of typing. When these devices are not in use, turn off the Bluetooth setting on your phone. Cyber criminals have the capability to pair with your phone's open Bluetooth connection when you are not using it and steal personal information.&lt;/p&gt;&lt;h3&gt;Be cautious when charging&lt;/h3&gt;&lt;p&gt;Avoid connecting your mobile device to any computer or charging station that you do not control, such as a charging station at an airport terminal or a shared computer at a library. Connecting a mobile device to a computer using a USB cable can allow software running on that computer to interact with the phone in ways that a user may not anticipate. As a result, a malicious computer could gain access to your sensitive data or install new software. Don't Fall Victim to Phishing Scams If you are in the shopping mode, an email that appears to be from a legitimate retailer might be difficult to resist. If the deal looks too good to be true, or the link in the email or attachment to the text seems suspicious, do not click on it!&lt;/p&gt;&lt;h3&gt;What to do if your accounts are compromised&lt;/h3&gt;&lt;p&gt;If you notice that one of your online accounts has been hacked, call the bank, store, or credit card company that owns your account. Reporting fraud in a timely manner helps minimize the impact and lessens your personal liability. You should also change your account passwords for any online services associated with your mobile device using a different computer that you control. If you are the victim of identity theft, additional information is available from &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.idtheft.gov/&quot;&gt;http://www.idtheft.gov/&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;For even more information about keeping your devices safe, read &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/cas/tips/ST05-017.html&quot;&gt;Cybersecurity for Electronic Devices&lt;/a&gt;.&lt;/p&gt;		
				
		&lt;h3&gt;References&lt;/h3&gt;
		&lt;ul&gt;
					&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/cas/tips/ST05-017.html&quot;&gt;For even more information about keeping your devices safe, read Cybersecurity for Electronic Devices.&lt;/a&gt;&lt;/li&gt;
					&lt;/ul&gt;
				
		&lt;hr /&gt;
		
		Author: Amanda Parente		&lt;hr /&gt;
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;</description>
         <guid isPermaLink="false">104 at http://www.us-cert.gov</guid>
         <pubDate>Mon, 19 Dec 2011 17:42:27 +0000</pubDate>
      </item>
      <item>
         <title>ST05-017: Cybersecurity for Electronic Devices</title>
         <link>http://www.us-cert.gov/ncas/tips/ST05-017</link>
         <description>Original release date: December 19, 2011 | Last revised: February 06, 2013&lt;br /&gt;&lt;br /&gt;

		&lt;table cellspacing=&quot;6&quot; cellpadding=&quot;6&quot; border=&quot;1&quot;&gt;
			&lt;tr&gt;
				&lt;td bgcolor=&quot;#96B4D2&quot;&gt;
					&lt;font face=&quot;arial, geneva, helvetica&quot;&gt;
						When you think about cybersecurity, remember that electronics such as smartphones and other internet-enabled devices may also be vulnerable to attack. Take appropriate precautions to limit your risk. 					&lt;/font&gt;
				&lt;/td&gt;
			&lt;/tr&gt;
		&lt;/table&gt;	
	
		&lt;h3&gt;Why does cybersecurity extend beyond computers?&lt;/h3&gt;&lt;p&gt;Actually, the issue is not that cybersecurity extends beyond computers; it is that computers extend beyond traditional laptops and desktops. Many electronic devices are computers—from cell phones and tablets to video games and car navigation systems. While computers provide increased features and functionality, they also introduce new risks. Attackers may be able to take advantage of these technological advancements to target devices previously considered &quot;safe.&quot; For example, an attacker may be able to infect your cell phone with a virus, steal your phone or wireless service, or access the data on your device. Not only do these activities have implications for your personal information, but they could also have serious consequences if you store corporate information on the device.&lt;/p&gt;&lt;h3&gt;What types of electronics are vulnerable?&lt;/h3&gt;&lt;p&gt;Any piece of electronic equipment that uses some kind of computerized component is vulnerable to software imperfections and vulnerabilities. The risks increase if the device is connected to the internet or a network that an attacker may be able to access. Remember that a wireless connection also introduces these risks (see &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/cas/tips/ST05-003.html&quot;&gt;Securing Wireless Networks&lt;/a&gt; for more information). The outside connection provides a way for an attacker to send information to or extract information from your device.&lt;/p&gt;&lt;h3&gt;How can you protect yourself?&lt;/h3&gt;&lt;ul class=&quot;bulleted&quot;&gt;&lt;li&gt;&lt;b&gt;Remember physical security&lt;/b&gt; - Having physical access to a device makes it easier for an attacker to extract or corrupt information. Do not leave your device unattended in public or easily accessible areas (see &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/cas/tips/ST04-017.html&quot;&gt;Protecting Portable Devices: Physical Security&lt;/a&gt; for more information).&lt;/li&gt;&lt;li&gt;&lt;b&gt;Keep software up to date&lt;/b&gt; - If the vendor releases updates for the software operating your device, install them as soon as possible. Installing them will prevent attackers from being able to take advantage of known problems or vulnerabilities (see &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/cas/tips/ST04-006.html&quot;&gt;Understanding Patches&lt;/a&gt; for more information).&lt;/li&gt;&lt;li&gt;&lt;b&gt;Use good passwords&lt;/b&gt; - Choose devices that allow you to protect your information with passwords. Select passwords that will be difficult for thieves to guess, and use different passwords for different programs and devices (see &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/cas/tips/ST04-002.html&quot;&gt;Choosing and Protecting Passwords&lt;/a&gt; for more information). Do not choose options that allow your computer to remember your passwords.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Disable remote connectivity&lt;/b&gt; - Some mobile devices are equipped with wireless technologies, such as Bluetooth, that can be used to connect to other devices or computers. You should disable these features when they are not in use (see &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/cas/tips/ST05-015.html&quot;&gt;Understanding Bluetooth Technology&lt;/a&gt; for more information).&lt;/li&gt;&lt;li&gt;&lt;b&gt;Encrypt files&lt;/b&gt; - If you are storing personal or corporate information, see if your device offers the option to encrypt the files. By encrypting files, you ensure that unauthorized people can't view data even if they can physically access it. When you use encryption, it is important to remember your passwords and passphrases; if you forget or lose them, you may lose your data.&lt;/li&gt;&lt;/ul&gt;		
				
		&lt;hr /&gt;
		
		Authors: Mindi McDowell and Matt Lytle		&lt;hr /&gt;
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;</description>
         <guid isPermaLink="false">102 at http://www.us-cert.gov</guid>
         <pubDate>Mon, 19 Dec 2011 17:27:06 +0000</pubDate>
      </item>
      <item>
         <title>ST06-001: Understanding Hidden Threats: Rootkits and Botnets</title>
         <link>http://www.us-cert.gov/ncas/tips/ST06-001</link>
         <description>Original release date: August 24, 2011 | Last revised: February 06, 2013&lt;br /&gt;&lt;br /&gt;

		&lt;table cellspacing=&quot;6&quot; cellpadding=&quot;6&quot; border=&quot;1&quot;&gt;
			&lt;tr&gt;
				&lt;td bgcolor=&quot;#96B4D2&quot;&gt;
					&lt;font face=&quot;arial, geneva, helvetica&quot;&gt;
						Attackers are continually finding new ways to access computer systems. The use of hidden methods such as rootkits and botnets has increased, and you may be a victim without even realizing it.					&lt;/font&gt;
				&lt;/td&gt;
			&lt;/tr&gt;
		&lt;/table&gt;	
	
		&lt;h3&gt;What are rootkits and botnets?&lt;/h3&gt;&lt;p&gt;A rootkit is a piece of software that can be installed and hidden on your computer without your knowledge. It may be included in a larger software package or installed by an attacker who has been able to take advantage of a vulnerability on your computer or has convinced you to download it (see &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/ncas/tips/st04-014&quot;&gt;Avoiding Social Engineering and Phishing Attacks&lt;/a&gt; for more information). Rootkits are not necessarily malicious, but they may hide malicious activities. Attackers may be able to access information, monitor your actions, modify programs, or perform other functions on your computer without being detected.&lt;/p&gt;&lt;p&gt;Botnet is a term derived from the idea of bot networks. In its most basic form, a bot is simply an automated computer program, or robot. In the context of botnets, bots refer to computers that are able to be controlled by one, or many, outside sources. An attacker usually gains control by infecting the computers with a virus or other malicious code that gives the attacker access. Your computer may be part of a botnet even though it appears to be operating normally. Botnets are often used to conduct a range of activities, from distributing spam and viruses to conducting denial-of-service attacks (see &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/ncas/tips/st04-015&quot;&gt;Understanding Denial-of-Service Attacks&lt;/a&gt; for more information).&lt;/p&gt;&lt;h3&gt;Why are they considered threats?&lt;/h3&gt;&lt;p&gt;The main problem with both rootkits and botnets is that they are hidden. Although botnets are not hidden the same way rootkits are, they may be undetected unless you are specifically looking for certain activity. If a rootkit has been installed, you may not be aware that your computer has been compromised, and traditional anti-virus software may not be able to detect the malicious programs. Attackers are also creating more sophisticated programs that update themselves so that they are even harder to detect.&lt;/p&gt;&lt;p&gt;Attackers can use rootkits and botnets to access and modify personal information, attack other computers, and commit other crimes, all while remaining undetected. By using multiple computers, attackers increase the range and impact of their crimes. Because each computer in a botnet can be programmed to execute the same command, an attacker can have each of them scanning multiple computers for vulnerabilities, monitoring online activity, or collecting the information entered in online forms.&lt;/p&gt;&lt;h3&gt;What can you do to protect yourself?&lt;/h3&gt;&lt;p&gt;If you practice good security habits, you may reduce the risk that your computer will be compromised:&lt;/p&gt;&lt;ul class=&quot;bulleted&quot;&gt;&lt;li&gt;&lt;b&gt;Use and maintain anti-virus software&lt;/b&gt; - Anti-virus software recognizes and protects your computer against most known viruses, so you may be able to detect and remove the virus before it can do any damage (see &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/ncas/tips/st04-005&quot;&gt;Understanding Anti-Virus Software&lt;/a&gt; for more information). Because attackers are continually writing new viruses, it is important to keep your definitions up to date. Some anti-virus vendors also offer anti-rootkit software.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Install a firewall&lt;/b&gt; - Firewalls may be able to prevent some types of infection by blocking malicious traffic before it can enter your computer and limiting the traffic you send (see &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/ncas/tips/st04-004&quot;&gt;Understanding Firewalls&lt;/a&gt; for more information). Some operating systems actually include a firewall, but you need to make sure it is enabled.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Use good passwords&lt;/b&gt; - Select passwords that will be difficult for attackers to guess, and use different passwords for different programs and devices (see &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/ncas/tips/st04-002&quot;&gt;Choosing and Protecting Passwords&lt;/a&gt; for more information). Do not choose options that allow your computer to remember your passwords.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Keep software up to date&lt;/b&gt; - Install software patches so that attackers can't take advantage of known problems or vulnerabilities (see &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/ncas/tips/st04-006&quot;&gt;Understanding Patches&lt;/a&gt; for more information). Many operating systems offer automatic updates. If this option is available, you should enable it.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Follow good security practices&lt;/b&gt; - Take appropriate precautions when using email and web browsers to reduce the risk that your actions will trigger an infection (see other &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/ncas/tips/index&quot;&gt;US-CERT security tips&lt;/a&gt; for more information).&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Unfortunately, if there is a rootkit on your computer or an attacker is using your computer in a botnet, you may not know it. Even if you do discover that you are a victim, it is difficult for the average user to effectively recover. The attacker may have modified files on your computer, so simply removing the malicious files may not solve the problem, and you may not be able to safely trust a prior version of a file. If you believe that you are a victim, consider contacting a trained system administrator.&lt;/p&gt;&lt;p&gt;As an alternative, some vendors are developing products and tools that may remove a rootkit from your computer. If the software cannot locate and remove the infection, you may need to reinstall your operating system, usually with a system restore disk that is often supplied with a new computer. Note that reinstalling or restoring the operating system typically erases all of your files and any additional software that you have installed on your computer. Also, the infection may be located at such a deep level that it cannot be removed by simply reinstalling or restoring the operating system.&lt;/p&gt;		
				
		&lt;hr /&gt;
		
		Author: Mindi McDowell		&lt;hr /&gt;
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;</description>
         <guid isPermaLink="false">118 at http://www.us-cert.gov</guid>
         <pubDate>Thu, 25 Aug 2011 02:41:31 +0000</pubDate>
      </item>
      <item>
         <title>ST04-024: Understanding ISPs</title>
         <link>http://www.us-cert.gov/ncas/tips/ST04-024</link>
         <description>Original release date: July 06, 2011 | Last revised: February 06, 2013&lt;br /&gt;&lt;br /&gt;

		&lt;table cellspacing=&quot;6&quot; cellpadding=&quot;6&quot; border=&quot;1&quot;&gt;
			&lt;tr&gt;
				&lt;td bgcolor=&quot;#96B4D2&quot;&gt;
					&lt;font face=&quot;arial, geneva, helvetica&quot;&gt;
						ISPs offer services like email and internet access. In addition to availability, you may want to consider other factors so that you find an ISP that supports all of your needs. 					&lt;/font&gt;
				&lt;/td&gt;
			&lt;/tr&gt;
		&lt;/table&gt;	
	
		&lt;h3&gt;What is an ISP?&lt;/h3&gt;&lt;p&gt;An ISP, or internet service provider, is a company that provides its customers access to the internet and other web services. In addition to maintaining a direct line to the internet, the company usually maintains web servers. By supplying necessary software, a password-protected user account, and a way to connect to the internet (e.g., modem), ISPs offer their customers the capability to browse the web and exchange email with other people. Some ISPs also offer additional services. With the development of smart phones, many cell phone providers are also ISPs.&lt;/p&gt;&lt;p&gt;ISPs can vary in size—some are operated by one individual, while others are large corporations. They may also vary in scope—some only support users in a particular city, while others have regional or national capabilities.&lt;/p&gt;&lt;h3&gt;What services do ISPs provide?&lt;/h3&gt;&lt;p&gt;Almost all ISPs offer email and web browsing capabilities. They also offer varying degrees of user support, usually in the form of an email address or customer support hotline. Most ISPs also offer web hosting capabilities, allowing users to create and maintain personal web pages; and some may even offer the service of developing the pages for you. Some ISPs bundle internet service with other services, such as television and telephone service. Many ISPs offer a wireless modem as part of their service so that customers can use devices equipped with Wi-Fi.&lt;/p&gt;&lt;p&gt;As part of normal operation, most ISPs perform backups of email and web files. If the ability to recover email and web files is important to you, check with your ISP to see if they back up the data; it might not be advertised as a service. Additionally, most ISPs implement firewalls to block some portion of incoming traffic, although you should consider this a supplement to your own security precautions, not a replacement (see &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/ncas/tips/ST04-004.html&quot;&gt;Understanding Firewalls&lt;/a&gt; for more information).&lt;/p&gt;&lt;h3&gt;How do you choose an ISP?&lt;/h3&gt;&lt;p&gt;Traditional, broadband ISPs typically offer internet access through cable, DSL, or fiberoptic options. The availability of these options may depend where you live. In addition to the type of access, there are other factors that you may want to consider:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;security - Do you feel that the ISP is concerned about security? Does it use encryption and SSL (see &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/ncas/tips/ST04-013.html&quot;&gt;Protecting Your Privacy&lt;/a&gt; for more information) to protect any information you submit (e.g., user name, password)? If the ISP provides a wireless modem, what wireless security standards does it support, and are those standards compatible with your existing devices?&lt;/li&gt;&lt;li&gt;privacy - Does the ISP have a published privacy policy? Are you comfortable with who has access to your information and how it is being handled and used?&lt;/li&gt;&lt;li&gt;services - Does your ISP offer the services you want? Do they meet your requirements? Is there adequate support for the services? If the ISP provides a wireless modem, are its wireless standards compatible with your existing devices?&lt;/li&gt;&lt;li&gt;cost - Are the ISP's costs affordable? Are they reasonable for the number of services you receive, as well as the level of those services? Are you sacrificing quality and security to get the lowest price?&lt;/li&gt;&lt;li&gt;reliability - Are the services your ISP provides reliable, or are they frequently unavailable due to maintenance, security problems, a high volume of users, or other reasons? If the ISP knows that services will be unavailable for a particular reason, does it adequately communicate that information?&lt;/li&gt;&lt;li&gt;user support - Are there published methods for contacting customer support? Do you receive prompt and friendly service? Do their hours of availability accommodate your needs? Do the consultants have the appropriate level of knowledge?&lt;/li&gt;&lt;li&gt;speed - How fast is your ISP's connection? Is it sufficient for accessing your email or navigating the internet?&lt;/li&gt;&lt;li&gt;recommendations - Have you heard or seen positive reviews about the ISP? Were they from trusted sources? Does the ISP serve your geographic area? If you've uncovered negative points, are they factors you are concerned about?&lt;/li&gt;&lt;/ul&gt;		
				
		&lt;hr /&gt;
		
		Author: Mindi McDowell		&lt;hr /&gt;
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;</description>
         <guid isPermaLink="false">40 at http://www.us-cert.gov</guid>
         <pubDate>Wed, 06 Jul 2011 14:10:11 +0000</pubDate>
      </item>
      <item>
         <title>ST06-005: Dealing with Cyberbullies</title>
         <link>http://www.us-cert.gov/ncas/tips/ST06-005</link>
         <description>Original release date: June 01, 2011 | Last revised: February 06, 2013&lt;br /&gt;&lt;br /&gt;

		&lt;table cellspacing=&quot;6&quot; cellpadding=&quot;6&quot; border=&quot;1&quot;&gt;
			&lt;tr&gt;
				&lt;td bgcolor=&quot;#96B4D2&quot;&gt;
					&lt;font face=&quot;arial, geneva, helvetica&quot;&gt;
						Bullies are taking advantage of technology to intimidate and harass their victims. Dealing with cyberbullying can be difficult, but there are steps you can take. 					&lt;/font&gt;
				&lt;/td&gt;
			&lt;/tr&gt;
		&lt;/table&gt;	
	
		&lt;h3&gt;What is cyberbullying?&lt;/h3&gt;&lt;p&gt;Cyberbullying refers to practice of using technology to harass, or bully, someone else. Bullies used to be restricted to methods such as physical intimidation, postal mail, or the telephone. Now, developments in electronic media offer forums such as email, instant messaging, web pages, and digital photos to add to the arsenal. Computers, cell phones, and PDAs are current tools that are being used to conduct an old practice.&lt;/p&gt;&lt;p&gt;Forms of cyberbullying can range in severity from cruel or embarrassing rumors to threats, harassment, or stalking. It can affect any age group; however, teenagers and young adults are common victims, and cyberbullying is a growing problem in schools.&lt;/p&gt;&lt;h3&gt;Why has cyberbullying become such a problem?&lt;/h3&gt;&lt;p&gt;The relative anonymity of the internet is appealing for bullies because it enhances the intimidation and makes tracing the activity more difficult. Some bullies also find it easier to be more vicious because there is no personal contact. Unfortunately, the internet and email can also increase the visibility of the activity. Information or pictures posted online or forwarded in mass emails can reach a larger audience faster than more traditional methods, causing more damage to the victims. And because of the amount of personal information available online, bullies may be able to arbitrarily choose their victims.&lt;/p&gt;&lt;p&gt;Cyberbullying may also indicate a tendency toward more serious behavior. While bullying has always been an unfortunate reality, most bullies grow out of it. Cyberbullying has not existed long enough to have solid research, but there is evidence that it may be an early warning for more violent behavior.&lt;/p&gt;&lt;h3&gt;How can you protect yourself or your children?&lt;/h3&gt;&lt;ul class=&quot;bulleted&quot;&gt;&lt;li&gt;&lt;b&gt;Teach your children good online habits&lt;/b&gt; - Explain the risks of technology, and teach children how to be responsible online (see &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/ncas/tips/ST05-002&quot;&gt;Keeping Children Safe Online&lt;/a&gt; for more information). Reduce their risk of becoming cyberbullies by setting guidelines for and monitoring their use of the internet and other electronic media (cell phones, PDAs, etc.).&lt;/li&gt;&lt;li&gt;&lt;b&gt;Keep lines of communication open&lt;/b&gt; - Regularly talk to your children about their online activities so that they feel comfortable telling you if they are being victimized.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Watch for warning signs&lt;/b&gt; - If you notice changes in your child's behavior, try to identify the cause as soon as possible. If cyberbullying is involved, acting early can limit the damage.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Limit availability of personal information&lt;/b&gt; - Limiting the number of people who have access to contact information or details about interests, habits, or employment reduces exposure to bullies that you or your child do not know. This may limit the risk of becoming a victim and may make it easier to identify the bully if you or your child are victimized.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Avoid escalating the situation&lt;/b&gt; - Responding with hostility is likely to provoke a bully and escalate the situation. Depending on the circumstances, consider ignoring the issue. Often, bullies thrive on the reaction of their victims. Other options include subtle actions. For example, you may be able to block the messages on social networking sites or stop unwanted emails by changing the email address. If you continue to get messages at the new email address, you may have a stronger case for legal action.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Document the activity&lt;/b&gt; - Keep a record of any online activity (emails, web pages, instant messages, etc.), including relevant dates and times. In addition to archiving an electronic version, consider printing a copy.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Report cyberbullying to the appropriate authorities&lt;/b&gt; - If you or your child are being harassed or threatened, report the activity. Many schools have instituted bullying programs, so school officials may have established policies for dealing with activity that involves students. If necessary, contact your local law enforcement. Law enforcement agencies have different policies, but your local police department or FBI branch are good starting points. Unfortunately, there is a distinction between free speech and punishable offenses, but the legal implications should be decided by the law enforcement officials and the prosecutors.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Additional information&lt;/h3&gt;&lt;p&gt;The following organizations offer additional information about this topic:&lt;/p&gt;&lt;ul class=&quot;bulleted&quot;&gt;&lt;li&gt;National Crime Prevention Council - &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.ncpc.org/cyberbullying&quot;&gt;http://www.ncpc.org/cyberbullying&lt;/a&gt;&lt;/li&gt;&lt;li&gt;StopBullying.gov - &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.stopbullying.gov/&quot;&gt;http://www.stopbullying.gov/&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;		
				
		&lt;hr /&gt;
		
		Author: Mindi McDowell		&lt;hr /&gt;
		&lt;p&gt;This product is provided subject to this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/notification&quot;&gt;Notification&lt;/a&gt; and this &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/privacy/&quot;&gt;Privacy &amp;amp; Use&lt;/a&gt; policy.&lt;/p&gt;</description>
         <guid isPermaLink="false">137 at http://www.us-cert.gov</guid>
         <pubDate>Wed, 01 Jun 2011 16:26:45 +0000</pubDate>
      </item>
   </channel>
</rss>
<!-- fe2.yql.bf1.yahoo.com compressed/chunked Thu Oct  1 23:12:51 UTC 2015 -->
