CVE-2015-1917
published 2015-07-14CVE-2015-1917: Cross-site scripting (XSS) vulnerability in the Active Content Filtering component in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.80%
76.2th percentile
Cross-site scripting (XSS) vulnerability in the Active Content Filtering component in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-4588 libwmf: heap overflow within the RLE decoding of embedded BMP images
bugzilla·2015-10-19·CVSS 6.8
CVE-2015-4588 [MEDIUM] CVE-2015-4588 libwmf: heap overflow within the RLE decoding of embedded BMP images
CVE-2015-4588 libwmf: heap overflow within the RLE decoding of embedded BMP images
It was discovered that libwmf did not correctly process certain WMF (Windows Metafiles) with embedded RLE-compressed BMP images. By tricking a victim into opening a specially crafted WMF file in an application using libwmf, a remote attacker could possibly use this flaw to execute arbitrary code with the privileges of the user running the application.
Previously, this issue was bundled in bug#1227243.
Discussion:
The patch for this issue can be found in bug 1227243, comment 7.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2015:1917 https://rhn.redhat.com/errata/RHSA-2015-1917.html
Bugzilla
CVE-2015-4696 libwmf: use-after-free flaw in meta.h
bugzilla·2015-06-25·CVSS 4.3
CVE-2015-4696 [MEDIUM] CVE-2015-4696 libwmf: use-after-free flaw in meta.h
CVE-2015-4696 libwmf: use-after-free flaw in meta.h
Use after free issue was reported in libwmf when processing a crafted WMF file.
Originally reported in https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=784192
Patch is attached in BZ 1227243: https://bugzilla.redhat.com/attachment.cgi?id=1042307
Discussion:
Created libwmf tracking bugs for this issue:
Affects: fedora-all [bug 1235671]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2015:1917 https://rhn.redhat.com/errata/RHSA-2015-1917.html
Bugzilla
CVE-2015-4695 libwmf: heap buffer overread in meta.h
bugzilla·2015-06-25·CVSS 5.0
CVE-2015-4695 [MEDIUM] CVE-2015-4695 libwmf: heap buffer overread in meta.h
CVE-2015-4695 libwmf: heap buffer overread in meta.h
A read from invalid address was reported in libwmf in couple of places in meta.h file
Originally reported in https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=784205
Patch is attached to BZ 1227243: https://bugzilla.redhat.com/attachment.cgi?id=1042306
Discussion:
Created libwmf tracking bugs for this issue:
Affects: fedora-all [bug 1235671]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2015:1917 https://rhn.redhat.com/errata/RHSA-2015-1917.html
http://www-01.ibm.com/support/docview.wss?uid=swg1PI38732http://www-01.ibm.com/support/docview.wss?uid=swg21958024http://www.securityfocus.com/bid/75479http://www.securitytracker.com/id/1032970http://www-01.ibm.com/support/docview.wss?uid=swg1PI38732http://www-01.ibm.com/support/docview.wss?uid=swg21958024http://www.securityfocus.com/bid/75479http://www.securitytracker.com/id/1032970
2015-07-14
Published