Source
Packet Storm
Ubuntu Security Notice 7053-1 - It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or potentially leak sensitive information. These vulnerabilities included heap and stack-based buffer overflows, memory leaks, and improper handling of uninitialized values.
Debian Linux Security Advisory 5782-1 - Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
Ubuntu Security Notice 7055-1 - Goldberg, Miro Haller, Nadia Heninger, Mike Milano, Dan Shumow, Marc Stevens, and Adam Suhl discovered that FreeRADIUS incorrectly authenticated certain responses. An attacker able to intercept communications between a RADIUS client and server could possibly use this issue to forge responses, bypass authentication, and access network devices and services. This update introduces new configuration options called "limit_proxy_state" and "require_message_authenticator" that default to "auto" but should be set to "yes" once all RADIUS devices have been upgraded on a network.
MD-Pro version 1.0.76 suffers from remote SQL injection and shell upload vulnerabilities.
Computer Laboratory Management System 2024 version 1.0 suffers from a cross site scripting vulnerability.
Ubuntu Security Notice 7054-1 - It was discovered that unzip did not properly handle unicode strings under certain circumstances. If a user were tricked into opening a specially crafted zip file, an attacker could possibly use this issue to cause unzip to crash, resulting in a denial of service, or possibly execute arbitrary code.
Acronis Cyber Infrastructure version 5.0.1-61 suffers from a cross site request forgery vulnerability.
Vehicle Service Management System version 1.0 suffers from a WYSIWYG code injection vulnerability.
Vehicle Service Management System version 1.0 suffers from a PHP code injection vulnerability.
Transport Management System version 1.0 suffers from an arbitrary file upload vulnerability.