CVE-2015-6061
published 2015-11-11CVE-2015-6061: Cross-site scripting (XSS) vulnerability in Microsoft Skype for Business 2016, Lync 2010 and 2013 SP1, Lync 2010 Attendee, and Lync Room System allows remote…
PriorityP425medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
12.81%
95.9th percentile
Cross-site scripting (XSS) vulnerability in Microsoft Skype for Business 2016, Lync 2010 and 2013 SP1, Lync 2010 Attendee, and Lync Room System allows remote attackers to inject arbitrary web script or HTML via an instant-message session, aka "Server Input Validation Information Disclosure Vulnerability."
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | lync | — | — |
| microsoft | lync | — | — |
| microsoft | skype_for_business | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - November 2015
blogs_talos·2015-11-10·CVSS 9.3
[CRITICAL] Microsoft Patch Tuesday - November 2015
## Microsoft Patch Tuesday - November 2015
Microsoft's Patch Tuesday has arrived. Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release contains 12 bulletins addressing 53 vulnerabilities. Four bulletins are rated critical and address vulnerabilities in Edge, Internet Explorer, Windows Journal, and Windows. The remaining eight bulletins are rated important and address vulnerabilities in .NET, IPsec, Kerberos, Lync/Skype for Business, NDIS, Office, SChannel, and Winsock.
## Bulletins Rated Critical Microsoft bulletins MS15-112 through MS15-115 are rated as critical in this month's release.
MS15-112 and MS15-113 are this month's Internet Explorer and Edge security bulletin respectively
Talos
Microsoft Patch Tuesday - November 2015
blogs_talos·2015-11-10·CVSS 9.3
[CRITICAL] Microsoft Patch Tuesday - November 2015
Microsoft's Patch Tuesday has arrived. Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release contains 12 bulletins addressing 53 vulnerabilities. Four bulletins are rated critical and address vulnerabilities in Edge, Internet Explorer, Windows Journal, and Windows. The remaining eight bulletins are rated important and address vulnerabilities in .NET, IPsec, Kerberos, Lync/Skype for Business, NDIS, Office, SChannel, and Winsock.
### Bulletins Rated Critical Microsoft bulletins MS15-112 through MS15-115 are rated as critical in this month's release.
MS15-112 and MS15-113 are this month's Internet Explorer and Edge security bulletin respectively. In total, 25 vulnerabilities are addresse
HackerOne
pngcrush double-free/segfault could result in DoS (CVE-2015-7700)
hackerone·2019-10-04·CVSS 9.8
CVE-2015-7700 [CRITICAL] pngcrush double-free/segfault could result in DoS (CVE-2015-7700)
pngcrush double-free/segfault could result in DoS (CVE-2015-7700)
All versions of pngcrush (pmt.sourceforge.net/pngcrush) prior to version 1.7.87 have a double-free segfault that can be triggered by reading a valid PNG file that contains the sPLT chunk. This bug has been fixed in 1.7.87 by the project maintainer.
Persuading someone to run pngcrush with a valid PNG file that contains the sPLT chunk, or submitting such PNG file remotely to a web-based service that accepts PNG files and processes them with pngcrush, will cause the application to segfault. This can at a minimum cause denial-of-service.
./pngcrush -reduce -brute ps1n0g08.png /dev/null
==56277== Invalid read of size 8
==56277== at 0x44989E: png_free_data (png.c:542)
==56277== by 0x412D99: main (pngcrush.c:6061)
==56277== Add
http://www.securitytracker.com/id/1034126http://www.securitytracker.com/id/1034127https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-123http://www.securitytracker.com/id/1034126http://www.securitytracker.com/id/1034127https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-123
2015-11-11
Published