security update
Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.
Multiple cross-site scripting (XSS) vulnerabilities in the file types table in b2evolution through 6.8.3 allow remote authenticated users to inject arbitrary web script or HTML via a .swf file in a (1) comment frame or (2) avatar frame.
Oncommand Unified Manager in 7-mode prior to version 5.2.3 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors.