Bugtraq
[Prev Page][Next Page]
- [security bulletin] HPSBGN03108 rev.1 - HP Records Manager, Remote Cross-Site Scripting (XSS)
- [CERT VU#121036 / Multiple CVEs] RCE, domain admin creds leakage and more in BMC Track-It!
- [security bulletin] HPSBMU03118 rev.2 - HP Systems Insight Manager (SIM) on Linux and Windows, Multiple Remote Vulnerabilities
- Multiple vulnerabilities in DrayTek VigorACS SI
- OWTF 1.0 "Lionheart" released!
- Security advisory for Bugzilla 4.5.6, 4.4.6, 4.2.11, and 4.0.15
- CA20141001-01: Security Notice for Bash Shellshock Vulnerability
- Multiple Vulnerabilities in Draytek Vigor 2130
- PayPal Inc Bug Bounty #53 - Multiple Persistent Vulnerabilities
- Paypal Inc Bug Bounty #30 - Filter Bypass & Persistent Vulnerabilities
- [SECURITY] [DSA 3044-1] qemu-kvm security update
- [SECURITY] [DSA 3042-1] exuberant-ctags security update
- [SECURITY] [DSA 3046-1] mediawiki security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 3045-1] qemu security update
- [security bulletin] HPSBHF03124 rev.1 - HP Thin Clients running Bash, Remote Execution of Code
- PayPal Inc Bug Bounty Issue #70 France - Persistent (Escape Shopping) Mail Vulnerability
- HTTP Commander AJS v3.1.9 - Client Side Exception Vulnerability
- BulletProof Security Wordpress v50.8 - POST Inject Vulnerability
- CVE-2014-7278 DoS in ZyXEL SBG-3300 Security Gateway
- CVE-2014-7277 Stored Server XSS in ZyXEL SBG-3300 Security Gateway
- [ MDVSA-2014:195 ] libvirt
- [ MDVSA-2014:194 ] phpmyadmin
- [security bulletin] HPSBMU02895 SSRT101253 rev.3 - HP Data Protector, Remote Increase of Privilege, Denial of Service (DoS), Execution of Arbitrary Code
- [security bulletin] HPSBMU03118 rev.1 - HP Systems Insight Manager (SIM) on Linux and Windows, Multiple Remote Vulnerabilities
- Elasticsearch vulnerability CVE-2014-6439
- Ultra Electronics / AEP Networks - SSL VPN (Netilla / Series A / Ultra Protect) Vulnerabilities
- [security bulletin] HPSBHF03119 rev.2 - HP DreamColor Professional Display running Bash Shell, Remote Code Execution
- the other bash RCEs (CVE-2014-6277 and CVE-2014-6278)
- [ MDVSA-2014:193 ] xerces-j2
- [ MDVSA-2014:192 ] perl-Email-Address
- [SECURITY] [DSA 3041-1] xen security update
- Reflected Cross-Site Scripting (XSS) in Textpattern
- From: High-Tech Bridge Security Research
- Cross-Site Scripting (XSS) in Photo Gallery WordPress plugin
- From: High-Tech Bridge Security Research
- FreePBX (All Versions) RCE
- NEW VMSA-2014-0010 - VMware product updates address critical Bash security vulnerabilities
- From: VMware Security Response Center
- [security bulletin] HPSBHF03119 rev.1 - HP DreamColor Display running Bash Shell, Remote Code Execution
- [SECURITY] [DSA 3040-1] rsyslog security update
- [security bulletin] HPSBGN03117 rev.1 - HP Remote Device Access: Virtual Customer Access System (vCAS) running Bash Shell, Remote Code Execution
- [security bulletin] HPSBMU03112 rev.1 - HP System Management Homepage (SMH) on Linux and Windows, Multiple Vulnerabilities
- [security bulletin] HPSBST02958 rev.1 - HP MPIO Device Specific Module Manager, Local Execution of Arbitrary Code with Privilege Elevation
- All In One Wordpress Firewall 3.8.3 - Persistent Vulnerability
- PayPal Inc Bug Bounty #71 PPM - Persistent Filter Vulnerability
- PayPal Inc Bug Bounty #59 - Persistent Mail Encoding Vulnerability
- [slackware-security] seamonkey (SSA:2014-271-03)
- From: Slackware Security Team
- London DEFCON - September 30th 2014
- [ MDVSA-2014:191 ] perl-XML-DT
- [slackware-security] bash (SSA:2014-272-01)
- From: Slackware Security Team
- [slackware-security] mozilla-thunderbird (SSA:2014-271-02)
- From: Slackware Security Team
- Moab Authentication Bypass (insecure message signing) [CVE-2014-5376]
- Moab User Impersonation [CVE-2014-5375]
- Moab Authentication Bypass [CVE-2014-5300]
- [slackware-security] mozilla-firefox (SSA:2014-271-01)
- From: Slackware Security Team
- [SECURITY] [DSA 3039-1] chromium-browser security update
- [The ManageOwnage Series, part V]: RCE / file upload / arbitrary file deletion in OpManager, Social IT and IT360
- [SECURITY] [DSA 3038-1] libvirt security update
- From: Salvatore Bonaccorso
- Hands-on Mobile (Android & iOS) + ARM Exploitation Training at Toorcon
- WorldCIST 2015 - 3rd World Conference on Information Systems and Technologies
- [SECURITY] [DSA 3037-1] icedove security update
- Paypal Inc Bug Bounty #16 - Persistent Mail Encoding Vulnerability
- SmarterTools Smarter Track 6-10 - Information Disclosure Vulnerability
- Oracle Corporation MyOracle - Persistent Vulnerability
- Paypal Inc Bug Bounty #32 - Multiple Persistent Vulnerabilities
- GS Foto Uebertraeger v3.0 iOS - File Include Vulnerability
- [ MDVSA-2014:190 ] bash
- [slackware-security] bash (SSA:2014-268-01)
- From: Slackware Security Team
- [SECURITY] [DSA 3036-1] mediawiki security update
- [SECURITY] [DSA 3035-1] bash security update
- From: Salvatore Bonaccorso
- Cisco Security Advisory: GNU Bash Environmental Variable Command Injection Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- [slackware-security] bash (rebuild for Slackware 13.0 only) (SSA:2014-268-02)
- From: Slackware Security Team
- LSE Leading Security Experts GmbH - LSE-2014-06-10 - Perl CORE - Deep Recursion Stack Overflow
- [oCERT-2014-007] libvncserver multiple issues
- [slackware-security] bash (SSA:2014-267-01)
- From: Slackware Security Team
- [slackware-security] mozilla-nss (SSA:2014-267-02)
- From: Slackware Security Team
- [ MDVSA-2014:189 ] nss
- [ MDVSA-2014:187 ] curl
- [ MDVSA-2014:188 ] wireshark
- [SECURITY] [DSA 3034-1] iceweasel security update
- CVE-2014-4958: Stored Attribute-Based Cross-Site Scripting (XSS) Vulnerability in Telerik UI for ASP.NET AJAX RadEditor Control
- [SECURITY] [DSA 3033-1] nss security update
- [security bulletin] HPSBST03103 rev.1 - HP Storage EVA Command View Suite running OpenSSL, Remote Unauthorized Access, Disclosure of Information
- Re: [FD] Strength and Weakness of Methods to Confirm SSH Host Key
- [ MDVSA-2014:186 ] bash
- Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Multiple Vulnerabilities in Cisco IOS Software Multicast Domain Name System
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco IOS Software Network Address Translation Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco IOS Software DHCP Version 6 Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco IOS Software Metadata Vulnerabilities
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco IOS Software RSVP Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- [ MDVSA-2014:184 ] net-snmp
- [ MDVSA-2014:183 ] phpmyadmin
- [ MDVSA-2014:182 ] zarafa
- [ MDVSA-2014:181 ] dump
- [ MDVSA-2014:185 ] libgadu
- [ MDVSA-2014:183 ] phpmyadmin
- [SECURITY] [DSA 3032-1] bash security update
- Two SQL Injections in All In One WP Security WordPress plugin
- From: High-Tech Bridge Security Research
- [SECURITY] [DSA 3031-1] apt security update
- From: Salvatore Bonaccorso
- CVE-2014-6603 suricata 2.0.3 Out-of-bounds access in SSH parser
- [KIS-2014-10] X2Engine <= 4.1.7 (FileUploadsFilter.php) Unrestricted File Upload Vulnerability
- [KIS-2014-09] X2Engine <= 4.1.7 (SiteController.php) PHP Object Injection Vulnerability
- Glype proxy cookie jar path traversal allows code execution
- Glype proxy local address filter bypass
- [security bulletin] HPSBPI03107 rev.1 - Certain HP LaserJet Printers, MFPs and Certain HP OfficeJet Enterprise Printers using OpenSSL, Remote Unauthorized Access
- Glype proxy privacy settings can be disabled via CSRF
- Re: TP-LINK WDR4300 - Stored XSS & DoS
- [ MDVSA-2014:180 ] gnupg
- Re: TP-LINK WDR4300 - Stored XSS & DoS
- Strength and Weakness of Methods to Confirm SSH Host Key
- TP-LINK WDR4300 - Stored XSS & DoS
- [SECURITY] [DSA 3030-1] mantis security update
- CVE-2014-5516 CSRF protection bypass in "KonaKart" Java eCommerce product
- From: Christian Schneider
- [SECURITY] [DSA 3029-1] nginx security update
- From: Salvatore Bonaccorso
- Re: Multiple Vulnerabilities with Aztech Modem Routers
- From: Federick Joe P Fajardo
- CVE ID Syntax Change - Deadline Approaching
- From: Christey, Steven M.
- Apple iOS / OSX Foundation NSXMLParser XML eXternal Entity (XXE) Flaw
- [SECURITY] [DSA 3025-2] apt regression update
- From: Salvatore Bonaccorso
- AST-2014-010: Remote crash when handling out of call message in certain dialplan configurations
- From: Asterisk Security Team
- AST-2014-009: Remote crash based on malformed SIP subscription requests
- From: Asterisk Security Team
- APPLE-SA-2014-09-17-7 Xcode 6.0.1
- From: Apple Product Security
- Oracle Corporation MyOracle - Persistent Vulnerability
- Apple iOS / OSX Foundation NSXMLParser XML eXternal Entity (XXE) Flaw
- APPLE-SA-2014-09-17-6 OS X Server 2.2.3
- From: Apple Product Security
- APPLE-SA-2014-09-17-5 OS X Server 3.2.1
- From: Apple Product Security
- APPLE-SA-2014-09-17-3 OS X Mavericks 10.9.5 and Security Update 2014-004
- From: Apple Product Security
- APPLE-SA-2014-09-17-4 Safari 6.2 and Safari 7.1
- From: Apple Product Security
- CVE ID Syntax Change - Deadline Approaching
- From: Christey, Steven M.
- [SECURITY] [DSA 3028-1] icedove security update
- [SECURITY] [DSA 3027-1] libav security update
- APPLE-SA-2014-09-17-2 Apple TV 7
- From: Apple Product Security
- APPLE-SA-2014-09-17-1 iOS 8
- From: Apple Product Security
- Reflected Cross-Site Scripting (XSS) in MODX Revolution
- From: High-Tech Bridge Security Research
- Path Traversal in webEdition
- From: High-Tech Bridge Security Research
- MIUI Torch Open Vulnerability
- MIUI Wifi Connection Message Vulnerability
- Android Bluetooth Pairing Packet Processing Vulnerability(by wangzq from NCNIPC)
- [CORE-2014-0006] - Delphi and C++ Builder VCL library Heap Buffer Overflow
- From: CORE Advisories Team
- [SECURITY] [DSA 3026-1] dbus security update
- [SECURITY] [DSA 3025-1] apt security update
- From: Salvatore Bonaccorso
- USB&WiFi Flash Drive v1.3 iOS - Code Execution Vulnerability
- Osclass Security Advisory - Multiple XSS Vulnerabilities - CVE-2014-6280
- Osclass Security Advisory - LFI Vulnerability - CVE-2014-6308
- FreeBSD Security Advisory FreeBSD-SA-14:19.tcp
- From: FreeBSD Security Advisories
- ESA-2014-091: EMC Documentum Content Server Multiple Privilege Escalation Vulnerabilities
- Briefcase 4.0 iOS - Code Execution & File Include Vulnerability
- Multiple Vulnerabilities with Aztech Modem Routers
- From: Federick Joe P Fajardo
- Passwords^14 Norway - CFP
- Open-Xchange Security Advisory 2014-09-15
- Re: HttpFileServer 2.3.x Remote Command Execution
- From: danielelinguaglossa
- [security bulletin] HPSBOV03099 rev.1 - HP OpenVMS running OpenSSL, Remote Denial of Service (DoS) or Disclosure of Information
- HttpFileServer 2.3.x Remote Command Execution
- From: danielelinguaglossa
- NEW VMSA-2014-0009 VMware NSX and vCNS product updates address a critical information disclosure vulnerability
- From: VMware Security Response Center
- [SECURITY] [DSA 3024-1] gnupg security update
- [SECURITY] [DSA 3023-1] bind9 security update
- From: Salvatore Bonaccorso
- Call for Participation: Semantic Web Business and Innovation (SWBI2015) * Switzerland
- ChatSecure IM v2.2.4 iOS - Persistent Web Vulnerability
- Photorange v1.0 iOS - File Include Web Vulnerability
- PhotoSync v2.2 iOS - Command Inject Web Vulnerability
- [SECURITY] [DSA 3021-2] file regression update
- [SECURITY] [DSA 3022-1] curl security update
- [SECURITY] [DSA 3020-1] acpi-support security update
- [SECURITY] CVE-2013-4444 Remote Code Execution in Apache Tomcat
- [security bulletin] HPSBMU03075 rev.1 - HP Network Node Manager I (NNMi) for Windows and Linux, Remote Execution of Arbitrary Code
- [slackware-security] seamonkey (SSA:2014-252-01)
- From: Slackware Security Team
- NEW VMSA-2014-0008 VMware vSphere product updates to third party libraries
- From: VMware Security Response Center
- Re: Pro Chat Rooms v8.2.0 - Multiple Vulnerabilities
- [SECURITY] [DSA 3021-1] file security update
- FreeBSD Security Advisory FreeBSD-SA-14:18.openssl
- From: FreeBSD Security Advisories
- Cisco Security Advisory: Cisco Unified Computing System E-Series Blade Servers Cisco Integrated Management Controller SSH Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- IBM WebSphere Application Server (WAS) Integrated Solutions Console Login Page username Parameter Reflected XSS Security Vulnerability
- [security bulletin] HPSBST03106 rev.1 - HP P2000 G3 MSA Array System running OpenSSL, Remote Unauthorized Access or Disclosure of Information
- [slackware-security] php (SSA:2014-247-01)
- From: Slackware Security Team
- CVE-2014-5392 XML eXternal Entity (XXE) in "JobScheduler"
- From: Christian Schneider
- CVE-2014-5393 Path Traversal to Sensitive Files in Webroot in "JobScheduler"
- From: Christian Schneider
- CVE-2014-5391 DOM-based Cross-Site Scripting (XSS) in "JobScheduler"
- From: Christian Schneider
- t2’14 Challenge to be released 2014-09-13 10:00 EEST
- Defense in depth -- the Microsoft way (part 19): still no "perfect forward secrecy" per default in Windows 8/7/Vista/Server 2012/Server 2008 [R2]
- [security bulletin] HPSBUX03102 SSRT101681 rev.1 - HP-UX Apache Server Suite running Apache Tomcat or PHP, Remote Execution of Arbitrary Code and Denial of Service (DoS) and Other Vulnerabilities
- [slackware-security] mozilla-thunderbird (SSA:2014-247-03)
- From: Slackware Security Team
- [slackware-security] mozilla-firefox (SSA:2014-247-02)
- From: Slackware Security Team
- [ MDVSA-2014:179 ] python-django
- [ MDVSA-2014:178 ] ppp
- [ MDVSA-2014:175 ] glibc
- [ MDVSA-2014:177 ] squid
- [ MDVSA-2014:176 ] libgcrypt
- apache tomcat cookie handling problem - characters out of 0x80 - 0xff causing internal server error
- [WorldCIST'15]: Call for Workshops Proposals; Best papers published in ISI Journals
- [SECURITY] [DSA 3019-1] procmail security update
- From: Salvatore Bonaccorso
- Uninit memory disclosure via truncated images in Firefox
- [ MDVSA-2014:174 ] apache
- Avolve Software ProjectDox Multiple Vulnerability Disclosure
- [security bulletin] HPSBMU03083 rev.2 - HP BladeSystem c-Class Virtual Connect Firmware running OpenSSL, Remote Unauthorized Access or Disclosure of Information
- [SECURITY] [DSA 3018-1] iceweasel security update
- Reflected Cross-Site Scripting (XSS) in MyWebSQL
- From: High-Tech Bridge Security Research
- Reflected Cross-Site Scripting (XSS) in BlackCat CMS
- From: High-Tech Bridge Security Research
- [ MDVSA-2014:172 ] php
- [ MDVSA-2014:173 ] busybox
- Re: ntopng 1.2.0 XSS injection using monitored network traffic
- [CORE-2014-0005] - Advantech WebAccess Vulnerabilities
- From: CORE Advisories Team
- [security bulletin] HPSBGN03099 rev.1 - HP IceWall SSO Dfw, SSO Agent and MCRP running OpenSSL, Remote Disclosure of Information
- [SECURITY] [DSA 3017-1] php-cas security update
- Apple iOS v7.1.2 - Merge Apps Service Local Bypass Vulnerability
- Defense in depth -- the Microsoft way (part 18): Microsoft Office 2010 registers command lines with unquoted pathnames
- [ MDVSA-2014:171 ] dhcpcd
- [ MDVSA-2014:170 ] jakarta-commons-httpclient
- [ MDVSA-2014:169 ] bugzilla
- [ MDVSA-2014:168 ] libvncserver
- [ MDVSA-2014:167 ] file
- [ MDVSA-2014:166 ] serf
- [ MDVSA-2014:165 ] krb5
- [ MDVSA-2014:163 ] python-imaging
- [ MDVSA-2014:164 ] phpmyadmin
- [ MDVSA-2014:162 ] catfish
- [ MDVSA-2014:161 ] subversion
- [ MDVSA-2014:160 ] gpgme
- Re: [FD] SSH host key fingerprint - through HTTPS
- Re: SSH host key fingerprint - through HTTPS
- Re: [FD] SSH host key fingerprint - through HTTPS
- Re: [FD] SSH host key fingerprint - through HTTPS
- Re: SSH host key fingerprint - through HTTPS
- Re: SSH host key fingerprint - through HTTPS
- [SECURITY] [DSA 3016-1] lua5.2 security update
- Re: [FD] SSH host key fingerprint - through HTTPS
- Re: [FD] SSH host key fingerprint - through HTTPS
- [SECURITY] [DSA 3015-1] lua5.1 security update
- Re: [FD] SSH host key fingerprint - through HTTPS
- WWW File Share Pro v7.0 - Denial of Service Vulnerability
- Re: SSH host key fingerprint - through HTTPS
- Avira License Application - Cross Site Request Forgery Vulnerability
- Re: SSH host key fingerprint - through HTTPS
- CFP Deadline Approaching - Third International Conference on Informatics & Applications | Malaysia
- SSH host key fingerprint - through HTTPS
- [SECURITY] [DSA 2987-2] openjdk-7 regression update
- WordPress Slideshow Gallery 1.4.6 Shell Upload Vulnerability (CVE-2014-5460)
- From: jesus . ramirez . pichardo
- WordPress Slideshow Gallery 1.4.6 Shell Upload Vulnerability (CVE-2014-5460)
- From: jesus . ramirez . pichardo
- Re: Pro Chat Rooms v8.2.0 - Multiple Vulnerabilities
- Sierra Library Services Platform Multiple Vulnerability Disclosure
- Re: SaaS Marketing platform Hubspot export vulnerability
- [SECURITY] [DSA 3014-1] squid3 security update
- From: Salvatore Bonaccorso
- SEC Consult SA-20140828-0 :: F5 BIG-IP Reflected Cross-Site Scripting
- From: SEC Consult Vulnerability Lab
- Aerohive Hive Manager and Hive OS Multiple Vulnerabilities
- [The ManageOwnage Series, part II]: User credential disclosure in ManageEngine DeviceExpert
- [SECURITY] [DSA 3013-1] s3ql security update
- Last CFP: ICETC2014 - IEEE - Poland (Deadline: Aug. 30)
- [SECURITY] [DSA 3012-1] eglibc security update
- SaaS Marketing platform Hubspot export vulnerability
- Fwd: RFC 7359 on Layer 3 Virtual Private Network (VPN) Tunnel Traffic Leakages in Dual-Stack Hosts/Networks
- Mathematica10.0.0 on Linux /tmp/MathLink vulnerability
- Encore Discovery Solution Multiple Vulnerability Disclosure
- ESA-2014-081 RSA® Identity Management and Governance Authentication Bypass Vulnerability
- [security bulletin] HPSBMU03076 rev.2 - HP Systems Insight Manager (SIM) on Linux and Windows running OpenSSL, Multiple Vulnerabilities
- LSE Leading Security Experts GmbH - LSE-2014-07-13 - Granding Grand MA 300 - Weak Pin Verification
- ntopng 1.2.0 XSS injection using monitored network traffic
- DNN(DotNetNuke®) Iconbar Control Panel Bad Access Level config
- [WorldCIST'15]: Call for Workshops Proposals; Proceedings by Springer - Indexed by ISI, Scopus, DBLP, etc.
- MEHR Automation System Arbitrary File Download Vulnerability(persian portal)
- DNN(DotNetNuke®) Ribbon Bar Control Panel Bad Access Level config
- Barracuda Networks Web Security Flex v4.1 - Persistent Vulnerabilities (BNSEC-699)
- Barracuda Networks Web Security Flex Appliance Application v4.x - Filter Bypass & Persistent Vulnerabilities (BNSEC 707)
- [SECURITY] [DSA 3011-1] mediawiki security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 3010-1] python-django security update
- From: Salvatore Bonaccorso
- [security bulletin] HPSBMU03079 rev.1 - HP Service Manager, Multiple Vulnerabilities
- CVE-2014-3524: Apache OpenOffice Calc Command Injection Vulnerability
- CVE-2014-3575:OpenOffice Targeted Data Exposure Using Crafted OLE Objects
- DoS attacks (ICMPv6-based) resulting from IPv6 EH drops
- [security bulletin] HPSBST03098 rev.1 - HP StoreEver MSL6480 Tape Library running OpenSSL, Remote Unauthorized Access or Disclosure of Information
- [CVE-2014-5335] CSRF in Innovaphone PBX
- [SECURITY] [DSA 3009-1] python-imaging security update
- [SECURITY] [DSA 3008-2] php5 regression update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 2940-1] libstruts1.2-java security update
- [SECURITY] [DSA 3008-1] php5 security update
- From: Salvatore Bonaccorso
- ToorCon 16 Call For Papers!
- ArcGIS for Server Vulnerability Disclosure
- CVE-2014-4973 - Privilege Escalation in ESET Windows Products
- From: Portcullis Advisories
- SQL Injection Vulnerability in ArticleFR
- From: High-Tech Bridge Security Research
- ICETC2014 - IEEE Extended Submission until Aug. 28, 2014
- CVE-2014-5307 - Privilege Escalation in Panda Security Products
- From: Portcullis Advisories
- [SECURITY] [DSA 3007-1] cacti security update
- [security bulletin] HPSBUX03091 SSRT101667 rev.1 - HP-UX running Java7, Remote Unauthorized Access, Disclosure of Information, and Other Vulnerabilities
- Deutsche Telekom CERT Advisory [DTC-A-20140820-001] check_mk vulnerabilities
- [security bulletin] HPSBUX03095 SSRT101674 rev.1 - HP-UX running OpenSSL, Multiple Vulnerabilities
- [security bulletin] HPSBUX03092 SSRT101668 rev.1 - HP-UX running Java6, Remote Unauthorized Access, Disclosure of Information, and Other Vulnerabilities
- [security bulletin] HPSBMU03101 rev.1 - HP Asset Manager, CloudSystem Chargeback, running OpenSSL, Remote Disclosure of Information or Unauthorized Access
- [security bulletin] HPSBMU03094 rev.1 - HP Connect-IT, running OpenSSL, Remote Disclosure of Information or Unauthorized Access
- [Call For Papers] RiseCON - Rosario, Argentina
- ESA-2014-071: RSA Archer® GRC Platform Multiple Vulnerabilities
- [CVE-2014-0232] Apache OFBiz Cross-site scripting (XSS) vulnerability
- ESA-2014-079: EMC Documentum Content Server Multiple Vulnerabilities
- ESA-2014-067: EMC Documentum D2 Privilege Escalation Vulnerability
- ESA-2014-059: EMC Documentum Multiple Cross-Site Scripting Vulnerabilities
- ESA-2014-073: EMC Documentum Multiple Cross-Site Request Forgery Vulnerabilities
- [SECURITY] [DSA 3006-1] xen security update
- CVE-2014-3577: Apache HttpComponents client: Hostname verification susceptible to MITM attack
- From: Dirk-Willem van Gulik
- Outlook.com for Android fails to validate server certificates
- CVE-2014-5289 - Kolibri WebServer 2.0 Vulnerable to RCE via Overly Long POST Request
- Beginners error: Apple's iCloudServices for Windows run rogue program C:\Program.exe (and some more)
- Beginners error: Apple's Software Update runs rogue program C:\Program.exe (and some more)
- Beginners error: Windows Live Mail 2011 runs rogue C:\Program.exe when opening associated URLs
- [SECURITY] [DSA 3005-1] gpgme1.0 security update
- From: Salvatore Bonaccorso
- [security bulletin] HPSBMU03090 rev.1 - HP SiteScope, running Apache Struts, Remote Execution of Arbitrary Code
- APPLE-SA-2014-08-13-1 Safari 6.1.6 and Safari 7.0.6
- From: Apple Product Security
- [security bulletin] HPSBHF03088 rev.1 - HP Integrity SD2 CB900s i2 and i4 Servers running OpenSSL, Remote Unauthorized Access or Disclosure of Information
- Reflected Cross-Site Scripting (XSS) in Jamroom
- From: High-Tech Bridge Security Research
- [oCERT-2014-006] Ganeti insecure archive permission
- BlackBerry Z 10 - Storage and Access File-Exchange Authentication By-Pass [MZ-13-04]
- CVE-2014-5035 - Opendaylight Vulnerable to Local and Remote File Inclusion in the Netconf (TCP) Service
- Apache Cordova 3.5.1: CVE-2014-3502 update
- [security bulletin] HPSBMU03089 rev.1 - HP Executive Scorecard, Running OpenSSL, Disclosure of Information
- [SECURITY] [DSA 2984-2] acpi-support regression update
- IBM Maximo: Cross-site Scripting Vulnerability Addressed in Asset and Service Management (CVE-2014-0914 and -0915)
- [slackware-security] openssl (SSA:2014-220-01)
- From: Slackware Security Team
- [SECURITY] [DSA 3004-1] kde4libs security update
- [SECURITY] [DSA 3003-1] libav security update
- [SECURITY] [DSA 3002-1] wireshark security update
- MITKRB5-SA-2014-001 Buffer overrun in kadmind with LDAP backend
- [SECURITY] [DSA 3001-1] wordpress security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 3000-1] krb5 security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 2999-1] drupal7 security update
- From: Salvatore Bonaccorso
- [security bulletin] HPSBMU03062 rev.1 - HP Insight Control server deployment on Linux and Windows running OpenSSL, Multiple Vulnerabilities
- [ MDVSA-2014:158 ] openssl
- [ MDVSA-2014:159 ] wireshark
- ESA-2014-055: EMC Network Configuration Manager (NCM) Report Advisor Session Fixation Vulnerability
- [ MDVSA-2014:157 ] ipython
- [WorldCIST'15]: Call for Workshops Proposals - Proceedings by Springer
- [security bulletin] HPSBUX03087 SSRT101413 rev.1 - HP-UX CIFS Server (Samba), Remote Denial of Service (DoS), Execution of Arbitrary Code, Unauthorized Access
- Beginners error: QuickTime for Windows runs rogue program C:\Program.exe when opening associated files
- [security bulletin] HPSBMU03086 rev.1 - HP Operations Agent running Glance, Local Elevation of Privilege
- [security bulletin] HPSBHF03084 rev.1 HP PCs with UEFI Firmware, Execution of Arbitrary Code
- Easy FTP Pro v4.2 iOS - Command Inject Vulnerabilities
- [ MDVSA-2014:156 ] ocsinventory
- [ MDVSA-2014:154 ] readline
- TomatoCart v1.x (latest-stable) Multiple Vulnerabilities
- (kind of) new tool: american fuzzy lop
- [ MDVSA-2014:155 ] kernel
- (CVE-2014-3501/2/3) Apache Cordova for Android - Multiple Vulnerabilities
- [SECURITY] [DSA 2998-1] openssl security update
- [ MDVSA-2014:152 ] glibc
- [ MDVSA-2014:153 ] mediawiki
- [ MDVSA-2014:151 ] cups
- Cisco Security Advisory: Cisco IOS Software and Cisco IOS XE Software EnergyWise Crafted Packet Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- RE: ownCloud Unencrypted Private Key Exposure
- RE: ownCloud Unencrypted Private Key Exposure
- Re: ownCloud Unencrypted Private Key Exposure
- nullcon CFP is open
- [ MDVSA-2014:150 ] tor
- RE: ownCloud Unencrypted Private Key Exposure - version (6.0.4) reported not vulnerable
- PhotoSync v2.2 iOS - Command Inject Web Vulnerability
- [ MDVSA-2014:149 ] php
- PhotoSync Wifi & Bluetooth v1.0 - File Include Vulnerability
- [security bulletin] HPSBMU03085 rev.1 - HP Application Lifecycle Management / Quality Center, Elevation of Privilege
- Re: ownCloud Unencrypted Private Key Exposure
- [SECURITY] [DSA 2997-1] reportbug security update
- From: Salvatore Bonaccorso
- CVE-2014-5075 MitM Vulnerability in the Smack XMPP Library for Java
- Re: ownCloud Unencrypted Private Key Exposure
- Pro Chat Rooms v8.2.0 - Multiple Vulnerabilities
- SEC Consult SA-20140805-0 :: Multiple vulnerabilities in Readsoft Invoice Processing and Process Director
- From: SEC Consult Vulnerability Lab
- Re: ownCloud Unencrypted Private Key Exposure
- Apache Cordova 3.5.1
- Ebay Inc Magento ProStore CP #4 - Filter Validation Bypass & Persistent (Payment Information) Vulnerability
- [CVE- Requested][Vembu Storegrid - Multiple Critical Vulnerabilities]
- [security bulletin] HPSBMU03037 rev.2 - HP Multimedia Service Environment (MSE), (HP Network Interactive Voice Response (NIVR)), Remote Disclosure of Information
- CVE-2014-2595 - Authentication Bypass in Barracuda Web Application Firewall
- From: Portcullis Advisories
- [security bulletin] HPSBMU03083 rev.1 - HP BladeSystem c-Class Virtual Connect Firmware running OpenSSL, Remote Unauthorized Access or Disclosure of Information
- FreeDisk v1.01 iOS - Multiple Web Vulnerabilities
- Video WiFi Transfer 1.01 - Directory Traversal Vulnerability
- ownCloud Unencrypted Private Key Exposure
- From: Senderek Web Security
- [SECURITY] [DSA 2996-1] icedove security update
- [SECURITY] [DSA 2995-1] lzo2 security update
- From: Salvatore Bonaccorso
- [slackware-security] dhcpcd (SSA:2014-213-02)
- From: Slackware Security Team
- [slackware-security] samba (SSA:2014-213-01)
- From: Slackware Security Team
- Microsoft Exchange Multiple Vulnerabilities
- [SECURITY] [DSA 2993-1] tor security update
- From: Salvatore Bonaccorso
- Photo WiFi Transfer 1.01 - Directory Traversal Vulnerability
- C++11 <regex> insecure by default
- [security bulletin] HPSBMU03081 rev.1 - HP Enterprise Maps, Remote Information Disclosure
- [ MDVSA-2014:148 ] dbus
- [ MDVSA-2014:147 ] sendmail
- [SECURITY] [DSA 2994-1] nss security update
- TigerCom iFolder+ v1.2 iOS - Multiple Vulnerabilities
- [ MDVSA-2014:146 ] file
- [ MDVSA-2014:145 ] php-ZendFramework
- Improper Access Control in ArticleFR
- From: High-Tech Bridge Security Research
- Re: [FD] Beginner's error: import function of Windows Mail executes rogue program C:\Program.exe with credentials of other account
- RE: [FD] Beginner's error: import function of Windows Mail executes rogue program C:\Program.exe with credentials of other account
- [ MDVSA-2014:142 ] apache
- Re: [FD] Beginner's error: import function of Windows Mail executes rogue program C:\Program.exe with credentials of other account
- Re: [FD] Beginner's error: import function of Windows Mail executes rogue program C:\Program.exe with credentials of other account
- [ MDVSA-2014:144 ] live
- [ MDVSA-2014:143 ] phpmyadmin
- Vulnerabilities in Facebook and Facebook Messenger for Android [STIC-2014-0529]
- [ MDVSA-2014:140 ] owncloud
- [security bulletin] HPSBMU03078 rev.1 - HP CloudSystem Foundation and HP CloudSystem Enterprise Software running OpenSSL, Remote Unauthorized Access or Disclosure of Information
- [ MDVSA-2014:141 ] java-1.7.0-openjdk
- [Onapsis Security Advisory 2014-023] HTTP verb tampering issue in SAP_JTECHS
- From: Onapsis Research Labs
- [Onapsis Security Advisory 2014-024] Hard-coded Username in SAP FI Manager Self-Service
- From: Onapsis Research Labs
- [Onapsis Security Advisory 2014-022] SAP HANA IU5 SDK Authentication Bypass
- From: Onapsis Research Labs
- [ MDVSA-2014:139 ] nss
- [Onapsis Security Advisory 2014-026] Missing authorization check in function modules of BW-SYS-DB-DB4
- From: Onapsis Research Labs
- [Onapsis Security Advisory 2014-025] Multiple Cross Site Scripting Vulnerabilities in SAP HANA XS Administration Tool
- From: Onapsis Research Labs
- [Onapsis Security Advisory 2014-021] SAP HANA XS Missing encryption in form-based authentication
- From: Onapsis Research Labs
- Re: [FD] Beginner's error: import function of Windows Mail executes rogue program C:\Program.exe with credentials of other account
- Barracuda Networks Web Application Firewall v6.1.5 & LoadBalancer v4.2.2 #37 - Filter Bypass & Multiple Vulnerabilities
- WiFi HD v7.3.0 iOS - Multiple Web Vulnerabilities
- [SECURITY] [DSA 2992-1] linux security update
- From: Salvatore Bonaccorso
- Re: [FD] Beginner's error: import function of Windows Mail executes rogue program C:\Program.exe with credentials of other account
- Kunena Forum Extension for Joomla Multiple Reflected Cross-Site Scripting Vulnerabilities
- Kunena Forum Extension for Joomla Multiple SQL Injection Vulnerabilities
- Re: [FD] Beginner's error: import function of Windows Mail executes rogue program C:\Program.exe with credentials of other account
- Barracuda Networks Spam&Virus Firewall v5.1.3 - Client Side Cross Site Vulnerability
- [SECURITY] [DSA 2991-1] modsecurity-apache security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 2990-1] cups security update
- From: Salvatore Bonaccorso
- [security bulletin] HPSBGN02936 rev.1 - HP and H3C VPN Firewall Module Products, Remote Denial of Service (DoS)
- Web Encryption Extension security update
- Re: [FD] Beginner's error: import function of Windows Mail executes rogue program C:\Program.exe with credentials of other account
- Barracuda Networks Firewall 6.1.5 - Filter Bypass & Persistent Vulnerabilities
- Easy file sharing web server - persist XSS in forum msgs
- [SECURITY] [DSA 2988-1] transmission security update
- [SECURITY] [DSA 2989-1] apache2 security update
- Security advisory for Bugzilla 4.5.5, 4.4.5, 4.2.10, and 4.0.14
- Beginner's error: import function of Windows Mail executes rogue program C:\Program.exe with credentials of other account
- [SECURITY] [DSA 2987-1] openjdk-7 security update
- [slackware-security] mozilla-thunderbird (SSA:2014-204-03)
- From: Slackware Security Team
- Barracuda Networks Firewall 6.1.2 #36 - Filter Bypass & Exception Handling Vulnerability + PoC Video BNSEC-2398
- [slackware-security] mozilla-firefox (SSA:2014-204-02)
- From: Slackware Security Team
- [slackware-security] httpd (SSA:2014-204-01)
- From: Slackware Security Team
- [security bulletin] HPSBMU03076 rev.1 - HP Systems Insight Manager (SIM) on Linux and Windows running OpenSSL, Multiple Vulnerabilities
- [SECURITY] [DSA 2986-1] iceweasel security update
- [security bulletin] HPSBMU03074 rev.1 - HP Insight Control server migration on Linux and Windows running OpenSSL, Remote Denial of Service (DoS), Code Execution, Unauthorized Access, Disclosure of Information
- [security bulletin] HPSBMU03073 rev.1 - HP Network Virtualization, Remote Execution of Code, Disclosure of Information
- SQL Injection in Е2
- From: High-Tech Bridge Security Research
- [oCERT-2014-005] LPAR2RRD input sanitization errors
- Multiple Vulnerabilities in Parallels® Plesk Sitebuilder
- [SECURITY] [DSA 2985-1] mysql-5.5 security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 2984-1] acpi-support security update
- Barracuda Networks #35 Web Firewall 610 v6.0.1 - Filter Bypass & Persistent Vulnerability
- [security bulletin] HPSBMU03071 rev.1 - HP Autonomy IDOL, Running OpenSSL, Remote Unauthorized Access, Disclosure of Information
- Barracuda Networks Spam&Virus Firewall v6.0.2 (600 & Vx) - Client Side Cross Site Vulnerability
- Web Login Bruteforce in Symantec Endpoint Protection Manager 12.1.4023.4080
- Cross-site Scripting in EventLog Analyzer 9.0 build #9000
- [oCERT-2014-004] Ansible input sanitization errors
- Call for Papers / Speakers for ISACA Ireland Conference on 3rd Oct in Dublin
- [SECURITY] [DSA 2982-1] ruby-activerecord-3.2 security update
- CVE-2014-4326 Remote command execution in Logstash zabbix and nagios_nsca outputs.
- CVE-2014-4980 Parameter Tampering in Nessus Web UI - Remote Information Disclosure
- [SECURITY] [DSA 2983-1] drupal7 security update
- KL-001-2014-003 : Microsoft XP SP3 MQAC.sys Arbitrary Write Privilege Escalation
- From: KoreLogic Disclosures
- KL-001-2014-002 : Microsoft XP SP3 BthPan.sys Arbitrary Write Privilege Escalation
- From: KoreLogic Disclosures
- [SECURITY] [DSA 2981-1] polarssl security update
- From: Salvatore Bonaccorso
- ESA-2014-074: EMC RecoverPoint Appliance Security Control Bypass Vulnerability
- Microsoft MSN HBE - Blind SQL Injection Vulnerability
- Barracuda Networks Message Archiver 650 - Persistent Input Validation Vulnerability (BNSEC 703)
- [SECURITY] [DSA 2980-1] openjdk-6 security update
- [SECURITY] [DSA 2979-1] fail2ban security update
- Ignore the amount customers confirm is no security vulnerability according to PayPal
- [HITB-Announce] REMINDER: #HITB2014KUL CFP Deadline: 1st August
- IP.Board 3.4 cross-site scripting in Referer header
- [SECURITY] [DSA 2765-2] davfs regression update
- Cisco Security Advisory: Cisco Wireless Residential Gateway Remote Code Execution Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- SEC Consult SA-20140716-3 :: Multiple critical vulnerabilities in Bitdefender GravityZone
- From: SEC Consult Vulnerability Lab
- SEC Consult SA-20140716-2 :: Multiple vulnerabilities in Citrix NetScaler Application Delivery Controller and Citrix NetScaler Gateway
- From: SEC Consult Vulnerability Lab
- SEC Consult SA-20140716-1 :: Remote Code Execution via CSRF in OpenVPN Access Server "Desktop Client"
- From: SEC Consult Vulnerability Lab
- Reflected Cross-Site Scripting (XSS) in e107
- From: High-Tech Bridge Security Research
- VUPEN Security Research - Microsoft Windows "DirectShow" Privilege Escalation Vulnerability (Pwn2Own 2014)
- From: VUPEN Security Research
- VUPEN Security Research - Microsoft Internet Explorer "ShowSaveFileDialog()" Sandbox Bypass (Pwn2Own 2014)
- From: VUPEN Security Research
- VUPEN Security Research - Microsoft Internet Explorer "Request" Object Confusion Sandbox Bypass (Pwn2Own 2014)
- From: VUPEN Security Research
- VUPEN Security Research - Microsoft Internet Explorer CSS @import Memory Corruption (Pwn2Own 2014)
- From: VUPEN Security Research
- SEC Consult SA-20140716-0 :: Multiple SSRF vulnerabilities in Alfresco Community Edition
- From: SEC Consult Vulnerability Lab
- KL-001-2014-001 : Oracle VirtualBox Guest Additions Arbitrary Write Privilege Escalation
- From: KoreLogic Disclosures
- [security bulletin] HPSBMU03072 SSRT101644 rev.1 - HP Data Protector, Remote Execution of Arbitrary Code
- Node Browserify RCE vuln (<= 4.2.0)
- From: Cal Leeming [Simplicity Media Ltd]
- [security bulletin] HPSBGN03068 rev.1 - HP OneView running OpenSSL, Remote Denial of Service (DoS), Unauthorized Access, Disclosure of Information
- Ruxcon 2014 Final Call For Presentations
- [security bulletin] HPSBHF02913 rev.1 - HP Intelligent Management Center (iMC) and HP Branch Intelligent Management System (BIMS), Remote Disclosure of Information
- [security bulletin] HPSBST03039 rev.1 - HP StoreVirtual 4000 Storage and StoreVirtual VSA, Remote Disclosure of Information, Elevation of Privilege
- [KIS-2014-08] OpenCart <= 1.5.6.4 (cart.php) PHP Object Injection Vulnerability
- [slackware-security] php (SSA:2014-192-01)
- From: Slackware Security Team
- [ MDVSA-2014:138 ] asterisk
- [SECURITY] [DSA 2978-1] libxml2 security update
- [SECURITY] [DSA 2977-1] libav security update
- [ MDVSA-2014:137 ] apache-mod_wsgi
- [ MDVSA-2014:136 ] samba
- [SECURITY] [DSA 2976-1] eglibc security update
- Yahoo! Bug Bounty #29 YM - Filter Bypass & Persistent Web Vulnerability
- Yahoo! Bug Bounty #30 YM - Application-Side Mail Encoding (File Attachment) Vulnerability
- [ MDVSA-2014:135 ] python
- [ MDVSA-2014:134 ] liblzo
- SEC Consult SA-20140710-1 :: Multiple high risk vulnerabilities in Shopizer webshop
- From: SEC Consult Vulnerability Lab
- [ MDVSA-2014:133 ] gd
- SEC Consult SA-20140710-3 :: Design Issue / Password Disclosure in WAGO-I/O-SYSTEM with CODESYS V2.3 WebVisu
- From: SEC Consult Vulnerability Lab
- SEC Consult SA-20140710-2 :: Multiple critical vulnerabilites in Schrack MICROCONTROL emergency light system
- From: SEC Consult Vulnerability Lab
- SEC Consult SA-20140710-0 :: Multiple critical vulnerabilities in Shopizer webshop
- From: SEC Consult Vulnerability Lab
- [security bulletin] HPSBMU03070 rev.1 - HP Cloud Service Automation, OpenSSL Vulnerability, Unauthorized Access, Disclosure of Information
- [security bulletin] HPSBMU03069 rev.1 - HP Software Operation Orchestration, OpenSSL Vulnerability, SSL/TLS, Remote Code Execution, Denial of Service (DoS), Disclosure of Information
- [SECURITY] [DSA 2975-1] phpmyadmin security update
- Cisco Security Advisory: Apache Struts 2 Command Execution Vulnerability in Multiple Cisco Products
- From: Cisco Systems Product Security Incident Response Team
- Weak Local Database Credentials in Infoblox Network Automation
- OS Command Injection Infoblox Network Automation
- [ MDVSA-2014:132 ] libxfont
- [ MDVSA-2014:131 ] file
- [ MDVSA-2014:129 ] ffmpeg
- [ MDVSA-2014:130 ] php
- [ MDVSA-2014:128 ] iodine
- [ MDVSA-2014:127 ] gnupg
- [SECURITY] [DSA 2974-1] php5 security update
- From: Salvatore Bonaccorso
- Android NFC Service Denial of Service
- CVE-2014-4331 OctavoCMS reflected XSS vulnerability
- Cisco Security Advisory: Multiple Vulnerabilities in Cisco Unified Communications Domain Manager
- From: Cisco Systems Product Security Incident Response Team
- FreeBSD Security Advisory FreeBSD-SA-14:17.kmem
- From: FreeBSD Security Advisories
- [security bulletin] HPSBMU03065 rev.1 - HP Operations Analytics, OpenSSL Vulnerability, SSL/TLS, Remote Code Execution, Denial of Service (DoS), Disclosure of Information
- [ MDVSA-2014:126 ] phpmyadmin
- CVE-2014-3074 - Runtime Linker Allows Privilege Escalation Via Arbitrary File Writes in IBM AIX
- From: Portcullis Advisories
- [SECURITY] [DSA 2973-1] vlc security update
- Abusing Oracle's CREATE DATABASE LINK Privilege for fun and Profit
- [security bulletin] HPSBGN03050 rev.1 - HP IceWall SSO Dfw and HP IceWall MCRP running OpenSSL, Remote Denial of Service (DoS), Code Execution, Security Restriction Bypass, Disclosure of Information, or Unauthorized Access
- ESA-2014-057: EMC Documentum Foundation Services (DFS) XML External Entity (XXE) Vulnerability
- ESA-2014-064: EMC Documentum Content Server Privilege Escalation Vulnerabilities
- Photo Org WonderApplications v8.3 iOS - File Include Vulnerability
- CVE-2014-3863 - Stored XSS in JChatSocial
- [SECURITY] CVE-2014-3503 Apache Syncope
- From: Francesco Chicchiriccò
- Yahoo! Bug Bounty #25 Flickr API - Persistent Service Vulnerability
- Paypal Inc Bug Bounty #109 Multi Shipping Application API - Filter Bypass & Persistent Vulnerability
- PayPal Inc Bug Bounty #74 - Persistent Core Backend Vulnerability
- Backdoor access to Techboard/Syac devices
- {CVE-ID request} - OCS-Inventory-NG Multiple Stored Cross Site Scripting Vulnerabilities.
- iTunes 11.2.2 for Windows: completely outdated and vulnerable 3rd party libraries
- Re: Android KeyStore Stack Buffer Overflow (CVE-2014-3100)
- [SECURITY] [DSA 2972-1] linux security update
- From: Salvatore Bonaccorso
- Lime Survey 2-05+ Multiple Vulnerabilities
- [security bulletin] HPSBMU03051 rev.2 - HP System Management Homepage running OpenSSL on Linux and Windows, Remote Denial of Service (DoS), Code Execution, Unauthorized Access, Disclosure of Information
- POC2014 Call for Paper
- [security bulletin] HPSBMU03059 rev.1 - HP SiteScope, Remote Authentication Bypass
- [security bulletin] HPSBMU03064 rev.1 - HP Universal CMDB, Remote Information Disclosure, Execution of Code
- [SECURITY] [DSA 2971-1] dbus security update
- From: Salvatore Bonaccorso
- Cisco Security Advisory: Multiple Vulnerabilities in Cisco Unified Communications Domain Manager
- From: Cisco Systems Product Security Incident Response Team
- [security bulletin] HPSBMU03055 rev.1 - HP Smart Update Manager (HP SUM) running OpenSSL, Remote Denial of Service (DoS), Code Execution, Unauthorized Access, Disclosure of Information
- Cross-Site Request Forgery (CSRF) in Kanboard
- From: High-Tech Bridge Security Research
- CVE-2014-3149 - Reflected Cross-Site Scripting (XSS) in "Invision Power IP.Board"
- From: Christian Schneider
- SEC Consult SA-20140701-0 :: Stored cross-site scripting vulnerabilities in EMC Documentum eRoom
- From: SEC Consult Vulnerability Lab
- Kerio Control <= 8.3.1 Boolean-based blind SQL Injection
- ESA-2014-060: EMC Documentum eRoom Multiple Cross-Site Scripting Vulnerabilities
- APPLE-SA-2014-06-30-4 Apple TV 6.1.2
- From: Apple Product Security
- APPLE-SA-2014-06-30-3 iOS 7.1.2
- From: Apple Product Security
- [security bulletin] HPSBST03000 rev.4 - HP StoreEver ESL G3 Tape Library and Enterprise Library LTO-6 Tape Drives running OpenSSL, Remote Disclosure of Information
- APPLE-SA-2014-06-30-2 OS X Mavericks 10.9.4 and Security Update 2014-003
- From: Apple Product Security
- APPLE-SA-2014-06-30-1 Safari 6.1.5 and Safari 7.0.5
- From: Apple Product Security
- SEC Consult SA-20140630-0 :: Multiple vulnerabilities in IBM Algorithmics RICOS
- From: SEC Consult Vulnerability Lab
- ESA-2014-046: EMC Documentum Content Server Multiple Vulnerabilities
- ESA-2014-055: EMC Network Configuration Manager (NCM) Session Fixation Vulnerability
- [SECURITY] [DSA 2970-1] cacti security update
- [SECURITY] [DSA 2969-1] libemail-address-perl security update
- From: Salvatore Bonaccorso
- [security bulletin] HPSBMU03056 rev.1 - HP Version Control Repository Manager (HP VCRM) running OpenSSL on Linux and Windows, Remote Denial of Service (DoS), Code Execution, Unauthorized Access, Disclosure of Information
- [security bulletin] HPSBMU03057 rev.1 - HP Version Control Agent (HP VCA) running OpenSSL on Linux and Windows, Remote Denial of Service (DoS), Code Execution, Unauthorized Access, Disclosure of Information
- [security bulletin] HPSBMU03061 rev.1 - HP Release Control, Disclosure of Privileged Information and Elevation of Privilege
- [SECURITY] [DSA 2968-1] gnupg2 security update
- From: Salvatore Bonaccorso
- [security bulletin] HPSBMU03058 rev.1 - HP BladeSystem c-Class Onboard Administrator (OA) running OpenSSL, Remote Disclosure of Information
- CFP 1st International Conference on Information Systems Security and Privacy - ICISSP 2015
- [RT-SA-2014-008] Python CGIHTTPServer File Disclosure and Potential Code Execution
- From: RedTeam Pentesting GmbH
- [SECURITY] [DSA 2967-1] gnupg security update
- From: Salvatore Bonaccorso
- CVE-2014-3752 - Arbitrary Code Execution in G Data TotalProtection 2014
- From: Portcullis Advisories
- CVE-2014-2385 - Multiple Cross Site Scripting in Sophos Antivirus Configuration Console (Linux)
- From: Portcullis Advisories
- [RT-SA-2013-003] Endeca Latitude Cross-Site Scripting
- From: RedTeam Pentesting GmbH
- [RT-SA-2013-002] Endeca Latitude Cross-Site Request Forgery
- From: RedTeam Pentesting GmbH
- Reflected Cross-Site Scripting (XSS) Vulnerability in Storesprite
- From: High-Tech Bridge Security Research
- [slackware-security] bind (SSA:2014-175-01)
- From: Slackware Security Team
- NEW VMSA-2014-0007 - VMware product updates address security vulnerabilities in Apache Struts library
- From: "VMware Security Response Center"
- [slackware-security] seamonkey (SSA:2014-175-05)
- From: Slackware Security Team
- [slackware-security] samba (SSA:2014-175-04)
- From: Slackware Security Team
- [slackware-security] gnupg (SSA:2014-175-02)
- From: Slackware Security Team
- [slackware-security] gnupg2 (SSA:2014-175-03)
- From: Slackware Security Team
- FreeBSD Security Advisory FreeBSD-SA-14:16.file
- From: FreeBSD Security Advisories
- FreeBSD Security Advisory FreeBSD-SA-14:15.iconv
- From: FreeBSD Security Advisories
- [security bulletin] HPSBMU03053 rev.1 - HP Software Database and Middleware Automation, OpenSSL Vulnerability, Remote Unauthorized Access or Disclosure of Information
- [HITB-Announce] #HITB2014KUL round 1 CFP submission deadline in < 1 week
- [security bulletin] HPSBMU03051 rev.1 - HP System Management Homepage running OpenSSL on Linux and Windows, Remote Denial of Service (DoS), Code Execution, Unauthorized Access, Disclosure of Information
- Boolean algebra and CSS history theft
- Android KeyStore Stack Buffer Overflow (CVE-2014-3100)
- [security bulletin] HPSBHF03052 rev.1 - HP Intelligent Management Center (iMC), HP Network Products including H3C and 3COM Routers and Switches running OpenSSL, Remote Denial of Service (DoS), Code Execution, Unauthorized Access, Modification or Disclosure of Information
- [SECURITY] [DSA 2964-1] iodine security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 2966-1] samba security update
- [SECURITY] [DSA 2965-1] tiff security update
- [security bulletin] HPSBOV03047 rev.1 - HP OpenVMS running OpenSSL, Remote Denial of Service (DoS), Code Execution, Unauthorized Access, Disclosure of Information
- Secunia CSI/VIM - Filter Bypass & Persistent Validation Vulnerabilities
- Paypal Inc Bug Bounty #36 - SecurityKey Card Serialnumber Module Vulnerability
- Multiple SQL Injection Vulnerabilities in web2Project
- From: High-Tech Bridge Security Research
- SQL Injection in Dolphin
- From: High-Tech Bridge Security Research
- [security bulletin] HPSBMU03048 rev.1 - HP Software Executive Scorecard, Remote Execution of Code, Directory Traversal
- [security bulletin] HPSBUX03046 SSRT101590 rev.2 - HP-UX Running OpenSSL, Remote Denial of Service (DoS), Code Execution, Security Restriction Bypass, Disclosure of Information, or Unauthorized Access
- [SECURITY] [DSA 2962-1] nspr security update
- [SECURITY] [DSA 2963-1] lucene-solr security update
- [SECURITY] [DSA 2961-1] php5 security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 2950-2] openssl update
- [SECURITY] [DSA 2960-1] icedove security update
- [CFP] Hacktivity 2014 CFP is open
- [SE-2014-01] Security vulnerabilities in Oracle Database Java VM
- From: Security Explorations
- [SECURITY] [DSA 2959-1] chromium-browser security update
- ClipBucket CMS Xss Vulnerability
- [ MDVSA-2014:125 ] nspr
- [ MDVSA-2014:124 ] kernel
- [SECURITY] CVE-2013-2251: Apache Continuum affected by Remote Command Execution
- [security bulletin] HPSBUX03046 SSRT101590 rev.1 - HP-UX Running OpenSSL, Remote Denial of Service (DoS), Code Execution, Security Restriction Bypass, Disclosure of Information, or Unauthorized Access
- AST-2014-006: Asterisk Manager User Unauthorized Shell Access
- From: Asterisk Security Team
- CVE-2014-0228: Apache Hive Authorization vulnerability
- [SECURITY] [DSA 2957-1] mediawiki security update
- [security bulletin] HPSBST03016 rev.4 - HP P2000 G3 MSA Array Systems, HP MSA 2040 Storage, and HP MSA 1040 Storage running OpenSSL, Remote Disclosure of Information
- AST-2014-008: Denial of Service in PJSIP Channel Driver Subscriptions
- From: Asterisk Security Team
- AST-2014-007: Exhaustion of Allowed Concurrent HTTP Connections
- From: Asterisk Security Team
- AST-2014-005: Remote Crash in PJSIP Channel Driver's Publish/Subscribe Framework
- From: Asterisk Security Team
- [SECURITY] [DSA 2958-1] apt security update
- [slackware-security] mozilla-thunderbird (SSA:2014-163-01)
- From: Slackware Security Team
- CVE-2014-3427 CRLF Injection and CVE-2014-3428 XSS Injection in Yealink VoIP Phones
- [SECURITY] [DSA 2955-1] iceweasel security update
- [SECURITY] [DSA 2956-1] icinga security update
- Cisco Security Advisory: Cisco IOS XR Software IPv6 Malformed Packet Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- [ MDVSA-2014:122 ] chkrootkit
- [ MDVSA-2014:123 ] tor
- NEW : VMSA-2014-0006 - VMware product updates address OpenSSL security vulnerabilities
- From: "VMware Security Response Center"
- CVE-2014-3977 - Privilege Escalation in IBM AIX
- From: Portcullis Advisories
- [security bulletin] HPSBMU03045 rev.1 - HP Service Virtualization Running AutoPass License Server, Remote Code Execution
- [ MDVSA-2014:120 ] miniupnpc
- [ MDVSA-2014:118 ] emacs
- [ MDVSA-2014:121 ] libgadu
- [ MDVSA-2014:119 ] mediawiki
- CodeIgniter <= 2.1.4 Session Decoding Vulnerability
- [ MDVSA-2014:117 ] libcap-ng
- [ MDVSA-2014:116 ] file
- [ MDVSA-2014:115 ] php
- [ MDVSA-2014:114 ] squid
- [ MDVSA-2014:113 ] python-django
- Re: MacOSX Safari Firefox Kaspersky RegExp Remote/Local Denial of Service
- [ MDVSA-2014:110 ] curl
- [ MDVSA-2014:112 ] python-django
- [ MDVSA-2014:111 ] otrs
- [ MDVSA-2014:106 ] openssl
- [slackware-security] php (SSA:2014-160-01)
- From: Slackware Security Team
- [ MDVSA-2014:108 ] gnutls
- [SECURITY] [DSA 2954-1] dovecot security update
- From: Salvatore Bonaccorso
- [ MDVSA-2014:109 ] gnutls
- [ MDVSA-2014:105 ] openssl
- [ MDVSA-2014:107 ] libtasn1
- [security bulletin] HPSBMU03024 rev.3 - HP Insight Control Server Deployment on Linux and Windows running OpenSSL with System Management Homepage and Systems Insight Manager, Remote Disclosure of Information
- DNN (DotNetNuke®) dnnUI_NewsArticlesSlider Module Arbitrary File Download Vulnerability
- DNN (DotNetNuke®) responsivesidebar Module Arbitrary File Download Vulnerability
- DNN (DotNetNuke®) eventscalendar Module Arbitrary File Download Vulnerability
- DNN (DotNetNuke®) EasyDnnGallery Module Arbitrary File Download Vulnerability
- DNN (DotNetNuke®) CodeEditor Module Arbitrary File Download Vulnerability
- DNN (DotNetNuke®) ASPSlideshow Module Arbitrary File Download Vulnerability
- [SECURITY] [DSA 2953-1] dpkg security update
- [slackware-security] mozilla-firefox (SSA:2014-157-01)
- From: Slackware Security Team
- CVE-2014-3740 - SpiceWorks Cross-site scripting
- NeginGroup CMS Multiple Vulnerability
- [Onapsis Security Advisories] Multiple Hard-coded Usernames in SAP Components
- From: Onapsis Research Labs
- [Onapsis Security Advisory 2014-020] SAP SLD Information Tampering
- From: Onapsis Research Labs
- [slackware-security] openssl (SSA:2014-156-03)
- From: Slackware Security Team
- [slackware-security] sendmail (SSA:2014-156-04)
- From: Slackware Security Team
- SEC Consult SA-20140606-0 :: Multiple critical vulnerabilities in WebTitan
- From: SEC Consult Vulnerability Lab
- [slackware-security] gnutls (SSA:2014-156-01)
- From: Slackware Security Team
- [slackware-security] libtasn1 (SSA:2014-156-02)
- From: Slackware Security Team
- Re: [FD] [oss-security] Bug in bash <= 4.3 [security feature bypassed]
- [SECURITY] [DSA 2952-1] kfreebsd-9 security update
- Cisco Security Advisory: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
- From: Cisco Systems Product Security Incident Response Team
- Re: Bug in bash <= 4.3 [security feature bypassed]
- [SECURITY] [DSA 2951-1] mupdf security update
- Details for CVE-2014-0220
- [security bulletin] HPSBMU03029 rev.2 - HP Insight Control Server Migration running OpenSSL, Remote Disclosure of Information
- ESA-2014-046: EMC Documentum Content Server Multiple Vulnerabilities
- [security bulletin] HPSBMU03028 rev.2 - HP Matrix Operating Environment and HP CloudSystem Matrix Software Components running OpenSSL, Remote Disclosure of Information
- multiple Vulnerability in "WahmShoppes eStore"
[Index of Archives]
[Linux Security]
[Netfilter]
[PHP]
[Yosemite News]
[Linux Kernel]