Mail Index
- [SECURITY] [DSA 3432-1] icedove security update
- OSS-2016-01: Insufficient integrity checks in Uhlmann & Zacher Clex prime locking systems using 125 kHz EM4450 transponders
- [SECURITY] [DSA 3431-1] ganeti security update
- OSS-2016-03: Insufficient Integrity Protection in Winkhaus Bluesmart locking systems using Hitag S
- OSS-2016-02: Weak authentication in NXP Hitag S transponder allows an attacker to read, write and clone any tag
- [SECURITY] CVE-2015-5349: Apache Directory Studio command injection vulnerability
- Open Audit SQL Injection Vulnerability
- [SECURITY] [DSA 3433-1] samba security update
- From: Salvatore Bonaccorso
- Executable installers/self-extractors are vulnerable^WEVIL (case 17): Kaspersky Labs utilities
- Confluence Vulnerabilities
- CVE-2015-7944, CVE-2015-7945 - Ganeti Security Advisory (DoS, Unauthenticated Info Leak)
- [SECURITY] [DSA 3435-1] git security update
- From: Laszlo Boszormenyi (GCS)
- [SECURITY] [DSA 3434-1] linux security update
- [security bulletin] HPSBGN03530 rev.1 - HPE UCMDB Browser, Remote Disclosure of Sensitive Information, Local Unauthorized Access
- Executable installers are vulnerable^WEVIL (case 18): EMSISoft's installers allow arbitrary (remote) code execution and escalation of privilege
- [SYSS-2015-062] ownCloud Information Exposure Through Directory Listing (CVE-2016-1499)
- From: erlijn . vangenuchten
- Executable installers are vulnerable^WEVIL (case 19): ZoneAlarm's installers allow arbitrary (remote) code execution and escalation of privilege
- [RT-SA-2014-014] AVM FRITZ!Box: Arbitrary Code Execution Through Manipulated Firmware Images
- From: RedTeam Pentesting GmbH
- [RT-SA-2015-001] AVM FRITZ!Box: Remote Code Execution via Buffer Overflow
- From: RedTeam Pentesting GmbH
- Serendipity Security Advisory - XSS Vulnerability - CVE-2015-8603
- [CVE-2015-7242] AVM FRITZ!Box: HTML Injection Vulnerability
- Possible vulnerability in F5 BIG-IP LTM - Improper input validation of the HTTP version number of the HTTP reqest allows any payload size and conent to pass through
- APPLE-SA-2016-01-07-1 QuickTime 7.7.9
- From: Apple Product Security
- APPLE-SA-2016-01-07-1 QuickTime 7.7.9
- From: Apple Product Security
- [security bulletin] HPSBUX03435 SSRT102977 rev.1 - HP-UX Web Server Suite running Apache, Remote Denial of Service (DoS)
- Symantec EP DOS
- WP Symposium Pro Social Network Plugin XSS and Critical CSRF Vulnerability
- [RT-SA-2015-005] o2/Telefonica Germany: ACS Discloses VoIP/SIP Credentials
- From: RedTeam Pentesting GmbH
- MobaXTerm before version 8.5 vulnerability in "jump host" functionality
- Executable installers are vulnerable^WEVIL (case 20): TrueCrypt's installers allow arbitrary (remote) code execution and escalation of privilege
- [security bulletin] HPSBUX03435 SSRT102977 rev.1 - HP-UX Web Server Suite running Apache, Remote Denial of Service (DoS)
- [SECURITY] [DSA 3436-1] openssl security update
- From: Salvatore Bonaccorso
- CVE-2015-8397: GDCM out-of-bounds read in JPEGLSCodec::DecodeExtent
- CVE-2015-8396: GDCM buffer overflow in ImageRegionReader::ReadIntoBuffer
- [SECURITY] [DSA 3438-1] xscreensaver security update
- [SECURITY] [DSA 3437-1] gnutls26 security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 3439-1] prosody security update
- From: Salvatore Bonaccorso
- OpenBravo Hibernate HQL Injection
- Mozilla Firefox 44.0b2 Cross-site Scripting Vulnerability
- Mozilla Firefox 44.0b2 Cross-site Scripting Vulnerability
- Re: Executable installers are vulnerable^WEVIL (case 20): TrueCrypt's installers allow arbitrary (remote) code execution and escalation of privilege
- Re: TFTP Server 3CTftpSvc Buffer Overflow Vulnerability (Long transporting mode)
- Re: Mozilla Firefox 44.0b2 Cross-site Scripting Vulnerability
- Exploiting XXE vulnerabilities in AMF libraries
- [SECURITY] [DSA 3440-1] sudo security update
- [SECURITY] [DSA 3441-1] perl security update
- From: Salvatore Bonaccorso
- SEC Consult whitepaper: Bypassing McAfee Application Whitelisting for Critical Infrastructure Systems
- From: SEC Consult Vulnerability Lab
- WP Symposium Pro Social Network Plugin XSS Vulnerability
- [SECURITY] [DSA 3442-1] isc-dhcp security update
- Cisco Security Advisory: Cisco Identity Services Engine Unauthorized Access Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco Aironet 1800 Series Access Point Default Static Account Credentials Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- [SECURITY] [DSA 3445-1] pygments security update
- From: Salvatore Bonaccorso
- Cisco Security Advisory: Cisco Aironet 1800 Series Access Point Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Commentator Wordpress Plugin 2.5.2 XSS Vulnerability
- [SECURITY] [DSA 3444-1] wordpress security update
- From: Salvatore Bonaccorso
- Cisco Security Advisory: Cisco Wireless LAN Controller Unauthorized Access Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- [security bulletin] HPSBHF03535 rev.1 - HPE iMC OSS and iMC Plat running Adobe Flash, Multiple Remote Vulnerabilities
- Multiple SQL Injection Vulnerabilities in mcart.xls Bitrix Module
- From: High-Tech Bridge Security Research
- [security bulletin] HPSBGN03532 rev.1 - HPE ArcSight Logger, Multiple Vulnerabilities
- [CVE-2016-0014] Executable installers are vulnerable^WEVIL (case 1): Microsoft's IExpress resp. WExtract, SFXCab, BoxStub, ...
- Remote Code Execution in Roundcube
- From: High-Tech Bridge Security Research
- [slackware-security] dhcp (SSA:2016-012-01)
- From: Slackware Security Team
- [SECURITY] [DSA 3443-1] libpng security update
- From: Salvatore Bonaccorso
- [security bulletin] HPSBUX03359 SSRT102094 rev.3 - HP-UX pppoec, local elevation of privilege
- FreeBSD Security Advisory FreeBSD-SA-16:03.linux
- From: FreeBSD Security Advisories
- FreeBSD Security Advisory FreeBSD-SA-16:05.tcp
- From: FreeBSD Security Advisories
- FreeBSD Security Advisory FreeBSD-SA-16:02.ntp
- From: FreeBSD Security Advisories
- FreeBSD Security Advisory FreeBSD-SA-16:01.sctp
- From: FreeBSD Security Advisories
- FreeBSD Security Advisory FreeBSD-SA-16:06.bsnmpd
- From: FreeBSD Security Advisories
- FreeBSD Security Advisory FreeBSD-SA-16:04.linux
- From: FreeBSD Security Advisories
- [SECURITY] [DSA 3446-1] openssh security update
- Qualys Security Advisory - Roaming through the OpenSSH client: CVE-2016-0777 and CVE-2016-0778
- From: Qualys Security Advisory
- [SECURITY] [DSA 3431-2] ganeti regression update
- From: Salvatore Bonaccorso
- FreeBSD bsnmpd information disclosure
- FreeBSD Security Advisory FreeBSD-SA-16:07.openssh
- From: FreeBSD Security Advisories
- [slackware-security] openssh (SSA:2016-014-01)
- From: Slackware Security Team
- Executable installers are vulnerable^WEVIL (case 22): python.org's executable installers allow arbitrary (remote) code execution
- Defense in depth -- the Microsoft way (part 38): does Microsoft follow their own security guidance/advisories?
- [KIS-2016-01] CakePHP <= 3.2.0 "_method" CSRF Protection Bypass Vulnerability
- [CVE-2016-1920] VPN Man-in-the-Middle due to shared certificate store on KNOX 1.0 / Android 4.3
- [CVE-2016-1919] Weak eCryptFS Key generation from user password on KNOX 1.0 / Android 4.3
- [SECURITY] [DSA 3447-1] tomcat7 security update
- From: Salvatore Bonaccorso
- Advanced Electron Forum v1.0.9 CSRF
- Advanced Electron Forum v1.0.9 Persistent XSS
- Advanced Electron Forum v1.0.9 RFI / CSRF
- Quick CMS v 6.1 XSS Vulnerability
- [SECURITY] [DSA 3448-1] linux security update
- From: Salvatore Bonaccorso
- Quick Cart v6.6 XSS Vulnerability
- [CORE-2016-0001] - Intel Driver Update Utility MiTM
- From: CORE Advisories Team
- Executable installers are vulnerable^WEVIL (case 21): Panda Security's installers allow arbitrary (remote) code execution AND escalation of privilege with PANDAIS16.exe
- [security bulletin] HPSBGN03534 rev.1 - HPE Performance Center using Microsoft Report Viewer, Remote Disclosure of Information, Cross-Site Scripting (XSS)
- [SECURITY] [DSA 3449-1] bind9 security update
- From: Salvatore Bonaccorso
- APPLE-SA-2016-01-19-1 iOS 9.2.1
- From: Apple Product Security
- APPLE-SA-2016-01-19-2 OS X El Capitan 10.11.3 and Security Update 2016-001
- From: Apple Product Security
- APPLE-SA-2016-01-19-3 Safari 9.0.3
- From: Apple Product Security
- LiteSpeed Web Server - Security Advisory - HTTP Header Injection Vulnerability
- [CVE-2016-1926] XSS in Greenbone Security Assistant ≥ 6.0.0 and < 6.0.8
- Cisco Security Advisory: Cisco Unified Computing System Manager and Cisco Firepower 9000 Remote Command Execution Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- [SECURITY] [DSA 3450-1] ecryptfs-utils security update
- From: Salvatore Bonaccorso
- Cisco Security Advisory: Cisco Modular Encoding Platform D9036 Software Default Credentials Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Re: [CVE-2016-1920] VPN Man-in-the-Middle due to shared certificate store on KNOX 1.0 / Android 4.3
- Re: [CVE-2016-1919] Weak eCryptFS Key generation from user password on KNOX 1.0 / Android 4.3
- QuickAuth - Google Authenticator Pebble app vulnerable to MITM attack when configuring TOTP keys
- Oracle HtmlConverter.exe Buffer Overflow
- SEC Consult SA-20160121-0 :: Deliberately hidden backdoor account in AMX (Harman Professional) devices
- From: SEC Consult Vulnerability Lab
- Executable installers are vulnerable^WEVIL (case 3): WiX Toolset's bootstrapper "burn.exe"
- [SECURITY] [DSA 3451-1] fuse security update
- January 2016 - Bamboo - Critical Security Advisory
- imageone Cms Multiple vulnerabilities
- [SECURITY] [DSA 3452-1] claws-mail security update
- imageone Cms Multiple vulnerabilities
- XMB - eXtreme Message Board v1.9.11.13 Weak Crypto
- HP LaserJet Fax Preview DLL side loading vulnerability
- LEADTOOLS ActiveX control multiple DLL side loading vulnerabilities
- HP ToComMsg DLL side loading vulnerability
- ZyXel WAP3205 v1 Multiple XSS
- Remote shutdown vulnerability in Buffalo NAS (Linkstation 420)
- PHP-FPM fpm_log.c memory leak and buffer overflow
- PHP LiteSpeed SAPI secret key improper disposal
- WP Easy Gallery v4.1.4 Stored XSS Vulnerability
- [SECURITY] [DSA 3453-1] mariadb-10.0 security update
- From: Salvatore Bonaccorso
- glibc catopen() Multiple unbounded stack allocations
- Magento 1.9.x Multiple Man-In The Middle
- APPLE-SA-2016-01-25-1 tvOS 9.1.1
- From: Apple Product Security
- Authentication bypass in PHP File Manager 0.9.8
- [CORE-2016-0002] - Lenovo ShareIT Multiple Vulnerabilities
- From: CORE Advisories Team
- PHP LiteSpeed SAPI out of boundaries read due to missing input validation
- [security bulletin] HPSBGN03536 rev.1 - HP IceWall Products running OpenSSL, Remote and Local Denial of Service (DoS)
- [security bulletin] HPSBGN03537 rev.1 - HPE IceWall Federation Agent and IceWall File Manager running libXML2, Remote or Local Denial of Service (DoS)
- WP-Ultimate CSV Importer XSS Vulnerability
- [SECURITY] [DSA 3454-1] virtualbox security update
- FreeBSD Security Advisory FreeBSD-SA-16:08.bind
- From: FreeBSD Security Advisories
- FreeBSD Security Advisory FreeBSD-SA-16:09.ntp
- From: FreeBSD Security Advisories
- FreeBSD Security Advisory FreeBSD-SA-16:10.linux
- From: FreeBSD Security Advisories
- [ERPSCAN-15-024] SAP HANA hdbindexserver - Memory corruption
- [SECURITY] [DSA 3455-1] curl security update
- [SECURITY] [DSA 3456-1] chromium-browser security update
- BK Mobile CMS SQLi and XSS Vulnerability
- Secure Item Hub v1.0 iOS - Multiple Web Vulnerabilities
- Apple WatchOS v2.1 - Denial of Service Vulnerability
- Barracuda Networks Bug Bounty #38 Message Archiver - Multiple Vulnerabilities
- Telegram (API) - Cross Site Request Forgery Vulnerabilities
- Ebay Magento Bug Bounty #2 - Persistent Web Vulnerability
- Kleefa v1.7 (IR) - Multiple Web Vulnerabilities
- Classic Infomedia (Login) - Auth Bypass Web Vulnerability
- WebMartIndia CMS 2016 Q1 - SQL Injection Vulnerability
- los818 CMS 2016 Q1 - SQL Injection Web Vulnerability
- Netgear GS105Ev2 - Multiple Vulnerabilities
- From: benedikt . westermann
- Cisco Security Advisory: Cisco Wide Area Application Service CIFS DoS Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco RV220 Management Authentication Bypass Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Log2Space Central v 6.2 Multiple XSS Vulnerability
- [SECURITY] [DSA 3457-1] iceweasel security update
- [SECURITY] [DSA 3458-1] openjdk-7 security update
- HCA0005 - Liberty Global - Horizon HD STB - predictable WiFi passphrase
- From: Hacking Corporation Sàrl
- Trend Micro Direct Pass - Filter Bypass & Persistent Web Vulnerability
- New Era Company CMS - (id) SQL Injection Vulnerability
- [SECURITY] [DSA 3459-1] mysql-5.5 security update
- From: Salvatore Bonaccorso
- CVE-2015-7521: Apache Hive authorization bug disclosure
- [security bulletin] HPSBHF03535 rev.3 - HPE iMC Service Health Manager (SHM) and iMC PLAT running Adobe Flash, Multiple Remote Vulnerabilities
- [security bulletin] HPSBHF03538 rev.1 - HPE iMC Service Health Manager (SHM) and iMC PLAT running Adobe Flash, Remote Code Execution, Denial of Service (DoS)
- ProjectSend multiple vulnerabilities
- Netlife Photosuite Pro - Client Side Cross Site Scripting Vulnerability
- [security bulletin] HPSBGN03542 rev.1 - HPE Operations Manager for Windows using Java Deserialization, Remote Arbitrary Code Execution
- [security bulletin] HPSBHF03510 rev.1 - HP Integrated Lights-Out 2/3/4, Remote Unauthorized Modification
- [security bulletin] HPSBHF03539 rev.1 - HPE VCX running OpenSSH or BIND, Remote Denial of Service (DoS)
- [security bulletin] HPSBOV03540 rev.1 - HPE OpenVMS TCPIP Bind Services and OpenVMS TCPIP IPC Services for OpenVMS, Remote Disclosure of Information, Execution of Code, Denial of Service (DoS)
- ManageEngine Eventlog Analyzer v4-v10 Privilege Esacalation
- [security bulletin] HPSBGN03533 rev.1 - HP Enterprise Cloud Service Automation and Codar, Remote Unauthorized Modification
- Cross-Site Request Forgery (CSRF) Vulnerability in ManageEngine Network
- [security bulletin] HPSBHF03419 rev.3 - HPE Networking Products, Remote Denial of Service (DoS), Unauthorized Access
- FreeBSD Security Advisory FreeBSD-SA-16:11.openssl
- From: FreeBSD Security Advisories
Mail converted by MHonArc