CVE-2015-2808 – SSL/TLS: "Invariance Weakness" vulnerability in RC4 stream cipher
https://notcve.org/view.php?id=CVE-2015-2808
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue. El algoritmo RC4, utilizado en el protocolo TLS y el protocolo SSL, no combina correctamente los datos de estados con los datos de claves durante la fase de inicialización, lo que facilita a atacantes remotos realizar ataques de recuperación de texto claro contra los bytes iniciales de un flujo mediante la captura de trafico de la red que ocasionalmente depende de claves afectadas por la debilidad de la invariabilidad (Invariance Weakness), y posteriormente utilizar un acercamiento de fuerza bruta que involucra valores LSB, también conocido como el problema de 'Bar Mitzvah'. • http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04779034 http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10727 http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.html http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.html http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.html http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.html • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •
CVE-2014-7253
https://notcve.org/view.php?id=CVE-2014-7253
FUJITSU F-12C, ARROWS Tab LTE F-01D, ARROWS Kiss F-03D, and REGZA Phone T-01D for Android allows local users to execute arbitrary commands via unspecified vectors. FUJITSU F-12C, ARROWS Tab LTE F-01D, ARROWS Kiss F-03D, y REGZA Phone T-01D para Android permiten a usuarios locales ejecutar comandos arbitrarios a través de vectores no especificados. • http://jvn.jp/en/jp/JVN06302787/995312/index.html http://jvn.jp/en/jp/JVN06302787/index.html http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-000138.html • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2014-7254
https://notcve.org/view.php?id=CVE-2014-7254
Unspecified vulnerability in ARROWS Me F-11D allows physically proximate attackers to read or modify flash memory via unknown vectors. Vulnerabilidad no especificada en ARROWS Me F-11D permite a atacantes físicamente próximos leer o modificar la memoria flash a través de vectores desconocidos. • http://jvn.jp/en/jp/JVN61593104/995312/index.html http://jvn.jp/en/jp/JVN61593104/index.html http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-000139.html •
CVE-2014-7252
https://notcve.org/view.php?id=CVE-2014-7252
Multiple unspecified vulnerabilities in the Syslink driver for Texas Instruments OMAP mobile processor, as used on NTT DOCOMO ARROWS Tab LTE F-01D, ARROWS X LTE F-05D, Disney Mobile on docomo F-08D, REGZA Phone T-01D, and PRADA phone by LG L-02D; and SoftBank SHARP handsets 102SH allow local users to execute arbitrary code or read kernel memory via unknown vectors related to userland data and "improper data validation." Múltiples vulnerabilidades no especificadas en el controlador Syslink para el procesador móvil de Texas Instruments OMAP, utilizado en NTT DOCOMO ARROWS Tab LTE F-01D, ARROWS X LTE F-05D, Disney Mobile on docomo F-08D, REGZA Phone T-01D, y PRADA phone por LG L-02D; y los teléfonos SoftBank SHARP 102SH permiten a usuarios locales ejecutar código arbitrario o leer la memoria del kernel a través de vectores desconocidos relacionados con los datos userland y 'la validación de datos incorrecta.' • http://jvn.jp/en/jp/JVN67792023/397327/index.html http://jvn.jp/en/jp/JVN67792023/995312/index.html http://jvn.jp/en/jp/JVN67792023/index.html http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-000137.html •
CVE-2014-3898
https://notcve.org/view.php?id=CVE-2014-3898
Cross-site scripting (XSS) vulnerability in Fujitsu ServerView Operations Manager 5.00.09 through 6.30.05 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en Fujitsu ServerView Operations Manager 5.00.09 hasta 6.30.05 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. • http://jp.fujitsu.com/platform/server/primequest/products/2000/catalog/manual/support/note_140729_svom.html http://jp.fujitsu.com/platform/server/primergy/note/page20.html http://jvn.jp/en/jp/JVN22534185/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2014-000091 http://secunia.com/advisories/59210 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •