CVE-2015-2522
published 2015-09-09CVE-2015-2522: Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 SP1 allows remote authenticated users to inject arbitrary web script or HTML…
PriorityP419low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
10.31%
95.2th percentile
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 SP1 allows remote authenticated users to inject arbitrary web script or HTML via crafted content, aka "Microsoft SharePoint XSS Spoofing Vulnerability."
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | sharepoint_foundation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - September 2015
blogs_talos·2015-09-08·CVSS 9.3
[CRITICAL] Microsoft Patch Tuesday - September 2015
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release sees a total of 12 bulletins released which address 55 CVEs. Five bulletins are rated "Critical" this month and address vulnerabilities in Edge, Graphics Component, Internet Explorer, Journal, and Office. The other seven bulletins are rated "Important" and address vulnerabilities in the .NET Framework, Active Directory, Exchange, Hyper-V, Media Center, Skype for Business, and Task Management.
## Bulletins Rated CriticalMS15-094, MS15-095, MS15-097, MS-098, and MS15-099 are rated "Critical".
MS15-094 is this month's Internet Explorer security bulletin. Seventeen CVEs are addressed this month which affected Internet Explorer versions
Talos
Microsoft Patch Tuesday - September 2015
blogs_talos·2015-09-08·CVSS 9.3
[CRITICAL] Microsoft Patch Tuesday - September 2015
## Microsoft Patch Tuesday - September 2015
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release sees a total of 12 bulletins released which address 55 CVEs. Five bulletins are rated "Critical" this month and address vulnerabilities in Edge, Graphics Component, Internet Explorer, Journal, and Office. The other seven bulletins are rated "Important" and address vulnerabilities in the .NET Framework, Active Directory, Exchange, Hyper-V, Media Center, Skype for Business, and Task Management.
## Bulletins Rated Critical MS15-094, MS15-095, MS15-097, MS-098, and MS15-099 are rated "Critical".
MS15-094 is this month's Internet Explorer security bulletin. Seventeen CVEs are addressed this m
Bugzilla
CVE-2015-8781 CVE-2015-8782 CVE-2015-8783 libtiff: invalid assertion
bugzilla·2016-01-25·CVSS 6.5
CVE-2015-8781 [MEDIUM] CVE-2015-8781 CVE-2015-8782 CVE-2015-8783 libtiff: invalid assertion
CVE-2015-8781 CVE-2015-8782 CVE-2015-8783 libtiff: invalid assertion
A flaw was discovered in a way libtiff decodes special data. A potential out-of-bounds write could occur for specifically crafted images.
External bug report (CVE-2015-8781):
http://bugzilla.maptools.org/show_bug.cgi?id=2522
CVE assignments:
http://seclists.org/oss-sec/2016/q1/190
Upstream fix (for all CVEs):
https://github.com/vadz/libtiff/commit/aaab5c3c9d2a2c6984f23ccbc79702610439bc65
Discussion:
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1301650]
---
On RHEL5, 6, 7, and Fedora, libtiff is compiled with assertions enabled. Thus, the impact of these flaws is limited to triggering an assertion.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlhttp://www.securitytracker.com/id/1033489https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-099http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlhttp://www.securitytracker.com/id/1033489https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-099
2015-09-09
Published