DELTA 448985 0 2617 SVNjf.x}AN@HX x^Rn0 =WDӴւB& mvڴc%$]"K) &qZ.ɳiJMi^,r$\O3 9*er61&ptѢ6 wZDzO]mKej'ΆAA%hlp1q+pCKFDvq%gMP!mVb.G=DWLW*ch?VWIFi^G}cbkT2hJeЪd#y Ed'; o#/@>M\7jkOs|-.bdg}'z֣SC ˦xqZaZObHiqv^y`39"*_Fn6͆hv}J|\ x^Mk0ͯr%v,az_JDtEɕơ+;tK|#m)+X.x64u{RGo )WU+UUM2Lhhv>8uY<eJ-]2(+Xr>#a{0),rQ-ЗL|1-w@C@m3Yx^͐ EWBfA$F+.RlM YqL.9 ,_;+ oeG(+hLEqi^1r;GNc\>1, ,rL4=l)SbʾM'lcK|pkHޢ^j՛?sloe$#'WpPYMzx-Jv Qx^1o0g+NIUAn0tA0:ΑX8v*}mZڎt|{gƜ)I .z8Ɨ1[Ky2zUd

On SVM (AMD hardware): a malicious unprivileged guest process can escalate its privilege to that of the guest operating system.

On both SVM and VMX (Intel hardware): a malicious unprivileged guest process can crash the guestcvename>CVE-2016-9382250ac2e96-ba4d-11e6-ae1b-002590263bf5"> xen-kernel -- x86 null segments not always treated as unusable6UwAt 4 addressed in FreeBSD-SA-16:25.bspatch, but some possible integer overflows remainedfreebsdsa>SA-16:29.bspatch10-10 2016-10-10 mkvtoolnix -- code execution via specially crafted files mkvtoolnix 9.4.1p>Moritz Bunkus reports:

FreeBSD -- Multiple integer overflows in expat (libbsdxml) XML parser18 10.210.2_1 9.39.3_2h1>Problem Description:

Multiple integer overflows have been discovered in the XML_GetBuffer() function in the expat library.

Impact:

T3 d@| |x^Oo0)F=n" jčJUOHxx&3CQ{o7KHsI@M7ol:_(xbEu)tNw[4[1>\4V&M zl$I󊍆V8 '0Oe`a()0%Fp ,1|`pMpObzcAWPA-:=1b%HJu J<W ;}#EX]!3eq1ϙT~C}B(%*k*G,&ŋfu>/O)Wїe_Ue>#ۦ xwjtr:1ys92P(SNw4,N 8{9ձ><'{P/¤J5QMm'"yBN?/^cv@y'ex^1o W,v;mET:tZ`8l+I3z2^[8:,hW#g]+oՀZ_&K;)~ 6/MV&&+냭>cq;t#XVP$8ꃉ'H"+DhB^ s|3jNfp^Ơf&#欒BCDJ)޺jT%Jgy

By calling a particular script that is part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed7^x|Z@MSax^Rˎ0]O1cPUSn6khEXbw)휿eWEi"0\t}:Tp:⾄xƮ:}ը3pl}oH~l7lydCsx Qdȡx4OX%'ңU  ?ڪ(^xy}ס^)V-?S)i&Ì˶pcWޝ5/k xUYtWtQcrAqVUހG?jA͓0%`LޥyY9kѩ[r2/<,U@5G8"7Nj{)'~ b<г߃c ,-&L8>\@B^Yt|QQgX?:$362|?yzҨ^H;=VXˀ#|r :Nyh= !6.html", perhaps indefinite period. If a host watchdog (Xen or dom0) is in use, this can lead to a watchdog timeout and consequently a reboot of the host. If another, innocent, guest, is configured with a watchdog, this issue can lead to a reboot of such a guestcvename>CVE-2015-5307 CVE-2015-8104 http://xenbits.xen.org/xsa/advisory-1566 Ѡ)[(H@I?H@H@#fz- Y011112113114/ 2015-09-22 2015-09-22 ffmpeg -- multiple vulnerabilities libav 1.5.90 gstreamer-ffmpeg