Mail Index
- Fing v3.3.0 iOS - Persistent Mail Encoding Vulnerability
- [SYSS-2015-073] perfact::mpa - URL Redirection to Untrusted Site
- [SYSS-2015-072] perfact::mpa - Insecure Direct Object References
- [SYSS-2015-071] perfact::mpa - Cross-Site Request Forgery
- [SYSS-2015-070] perfact::mpa - Cross-Site Scripting
- [SYSS-2015-066] perfact::mpa - Cross-Site Scripting
- [SYSS-2015-067] perfact::mpa - Insecure Direct Object References
- [SYSS-2015-069] perfact::mpa - Insecure Direct Object References
- [security bulletin] HPSBUX03552 SSRT102983 rev.1 - HP-UX BIND running Named, Remote Denial of Service (DoS)
- Microsoft PowerPointViewer Code Execution
- WordPress plugin GravityForms Cross-site Scripting vulnerability
- [SYSS-2016-009] Sophos UTM 525 Web Application Firewall - Cross-Site Scripting in
- Executable installers are vulnerable^WEVIL (case 29): putty-0.66-installer.exe allowa arbitrary (remote) code execution WITH escalation of privilege
- [SECURITY] [DSA 3500-1] openssl security update
- [SECURITY] [DSA 3501-1] perl security update
- From: Salvatore Bonaccorso
- Vivint Sky Control Panel Unauthenticated Access Vulnerability
- [security bulletin] HPSBGN03442 rev.1 - HP Helion OpenStack using glibc, Remote Denial of Service (DoS), Arbitrary Code Execution
- [security bulletin] HPSBHF03545 rev. 1 - HP EliteBook and Zbook Products with Windows NVidia Graphics Driver, Multiple Local Vulnerabilities
- [REVIVE-SA-2016-001] Revive Adserver - Multiple vulnerabilities
- Cisco Security Advisory: Cisco NX-OS Software SNMP Packet Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco NX-OS Software TCP Netstack Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco Web Security Appliance HTTPS Packet Processing Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco Nexus 3000 Series and 3500 Platform Switches Insecure Default Credentials Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2016
- From: Cisco Systems Product Security Incident Response Team
- Open-Xchange Security Advisory 2016-03-02
- Panda SM Manager iOS Application - MITM SSL Certificate Vulnerability
- [security bulletin] HPSBHF03436 rev.1 - HP Thin Client with ThinPro OS, running Linux, Local Elevated Privileges
- WordPress Bulk Delete Plugin [Privilege Escalation]
- [slackware-security] php (SSA:2016-062-03)
- From: Slackware Security Team
- [slackware-security] openssl (SSA:2016-062-02)
- From: Slackware Security Team
- [slackware-security] mailx (SSA:2016-062-01)
- From: Slackware Security Team
- [SECURITY] [DSA 3502-1] roundup security update
- [SECURITY] [DSA 3426-2] ctdb regression update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 3503-1] linux security update
- From: Salvatore Bonaccorso
- [security bulletin] HPSBGN03550 rev.2 - HP Operations Manager i and BSM using Apache Flex BlazeDS, Remote Disclosure of Information
- [security bulletin] HPSBHF03439 rev.1 - HP Commercial PCs with Sure Start, Local Denial of Service
- [security bulletin] HPSBPI03546 rev.1 - HP LaserJet Printers and MFPs, HP OfficeJet Enterprise Printers, Remote Disclosure of Information
- [SYSS-2015-053] innovaphone IP222/IP232 - Denial of Service
- [SYSS-2015-064] Thru Managed File Transfer Portal 9.0.2 - Insecure Direct Object Reference (REVISED)
- From: erlijn . vangenuchten
- [SYSS-2015-060] Thru Managed File Transfer Portal 9.0.2 - Improperly Implemented Security Check for Standard (REVISED)
- From: erlijn . vangenuchten
- [SYSS-2015-059] Thru Managed File Transfer Portal 9.0.2 - Insecure Direct Object Reference (REVISED)
- From: erlijn . vangenuchten
- [SYSS-2015-058] Thru Managed File Transfer Portal 9.0.2 - Insecure Direct Object Reference (REVISED)
- From: erlijn . vangenuchten
- [SECURITY] [DSA 3506-1] libav security update
- [SECURITY] [DSA 3505-1] wireshark security update
- [SECURITY] [DSA 3504-1] bsh security update
- McAfee VirusScan Enterprise security restrictions bypass
- Executable installers are vulnerable^WEVIL (case 31): MalwareBytes' installers allows arbitrary (remote) code execution WITH escalation of privilege
- Executable installers are vulnerable^WEVIL (case 30): clamwin-0.99-setup.exe allows arbitrary (remote) code execution WITH escalation of privilege
- [SECURITY] [DSA 3507-1] chromium-browser security update
- Multiple vulnerabilities in Wordpress plugin SP Projects & Document Manager
- [SECURITY] [DSA 3508-1] jasper security update
- From: Salvatore Bonaccorso
- Apple iOS v9.2.1 - Multiple PassCode Bypass Vulnerabilities (App Store Link, Buy Tones Link & Weather Channel Link)
- Re: Apple iOS v9.2.1 - Multiple PassCode Bypass Vulnerabilities (App Store Link, Buy Tones Link & Weather Channel Link)
- Re: Apple iOS v9.2.1 - Multiple PassCode Bypass Vulnerabilities (App Store Link, Buy Tones Link & Weather Channel Link)
- ESA-2016-012: EMC Documentum xCP – User Information Disclosure Vulnerability
- [slackware-security] php (SSA:2016-067-01)
- From: Slackware Security Team
- Re: Apple iOS v9.2.1 - Multiple PassCode Bypass Vulnerabilities (App Store Link, Buy Tones Link & Weather Channel Link)
- [security bulletin] HPSBHF03557 rev.1 - HPE Networking Products using Comware 7 (CW7) running NTP, Remote Denial of Service (DoS)
- Windows Mail Find People DLL side loading vulnerability
- [slackware-security] samba (SSA:2016-068-02)
- From: Slackware Security Team
- [slackware-security] mozilla-firefox (SSA:2016-068-01)
- From: Slackware Security Team
- Thomson TWG850 Wireless Router Multiple Vulnerabilities
- LSE Leading Security Experts GmbH - LSE-2016-01-01 - Wordpress ProjectTheme - Multiple Vulnerabilities
- OS-S 2016-05 Linux aiptek Nullpointer Dereference CVE-2015-7515
- OS-S 2016-06 Linux cdc_acm Nullpointer Dereference
- OS-S 2016-07 Linux cypress_m8 Nullpointer Dereference
- Re: OS-S 2016-06 Linux cdc_acm Nullpointer Dereference
- OS-S 2016-08 Linux mct_u232 Nullpointer Dereference
- OS-S 2016-09 Linux visor clie_5_attach Nullpointer Dereference CVE-2015-7566
- OS-S 2016-10 Linux visor (treo_attach) Nullpointer Dereference CVE-2016-2782
- OS-S 2016-11 Linux wacom multiple Nullpointer Dereferences
- OS-S 2016-12 Linux digi_acceleport Nullpointer Dereference
- Re: Windows Mail Find People DLL side loading vulnerability
- Cisco Security Advisory: Cisco Wireless Residential Gateway with EDVA Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory:Cisco Wireless Residential Gateway Information Disclosure Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco Cable Modem with Digital Voice Remote Code Execution Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Re: Windows Mail Find People DLL side loading vulnerability
- [SECURITY] [DSA 3509-1] rails security update
- [SECURITY] [DSA 3509-1] rails security update
- Advisory X41-2016-001: Memory Corruption Vulnerability in "libotr"
- From: X41 D-Sec GmbH Advisories
- [CORE-2016-0004] - SAP Download Manager Password Weak Encryption
- From: CORE Advisories Team
- Cisco Security Advisory: Cisco ASA Content Security and Control Security Services Module Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- [SECURITY] [DSA 3510-1] iceweasel security update
- [SECURITY] [DSA 3509-1] rails security update
- [CORE-2016-0003] - Samsung SW Update Tool MiTM
- From: CORE Advisories Team
- [SECURITY] [DSA 3511-1] bind9 security update
- [SECURITY] [DSA 3512-1] libotr security update
- From: Salvatore Bonaccorso
- [SE-2012-01] Broken security fix in Oracle Java SE 7/8/9
- From: Security Explorations
- [slackware-security] bind (SSA:2016-069-01)
- From: Slackware Security Team
- [slackware-security] mozilla-nss (SSA:2016-069-02)
- From: Slackware Security Team
- FreeBSD Security Advisory FreeBSD-SA-16:13.bind
- From: FreeBSD Security Advisories
- FreeBSD Security Advisory FreeBSD-SA-16:12.openssl
- From: FreeBSD Security Advisories
- [ANNOUNCE] CVE-2016-0782: ActiveMQ Web Console - Cross-Site Scripting
- From: Christopher Shannon
- [ANNOUNCE] CVE-2016-0734: ActiveMQ Web Console - Clickjacking
- From: Christopher Shannon
- [SECURITY] [DSA 3513-1] chromium-browser security update
- oss-2016-13: Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (powermate driver)
- oss-2016-14: Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (gtco driver)
- oss-2016-15: Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (iowarrior driver)
- oss-2016-16: Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (snd-usb-audio driver)
- oss-2016-17: Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes (multiple free) on invalid USB device descriptors (snd-usb-audio driver)
- oss-2016-18: Multiple Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (ati_remote2 driver)
- [slackware-security] openssh (SSA:2016-070-01)
- From: Slackware Security Team
- DW Question Answer Stored XSS Vulnerability
- WebKitGTK+ Security Advisory WSA-2016-0002
- From: Carlos Alberto Lopez Perez
- Microsoft Edge CDOMTextNode::get_data type confusion
- [SECURITY] [DSA 3514-1] samba security update
- From: Salvatore Bonaccorso
- Soundy Background Music XSS Vulnerability
- [SECURITY] [DSA 3515-1] graphite2 security update
- [SECURITY] [DSA 3516-1] wireshark security update
- Re: oss-2016-13: Local RedHat Enterprise Linux DoS â?? RHEL 7.1 Kernel crashes on invalid USB device descriptors (powermate driver)
- Re: oss-2016-15: Local RedHat Enterprise Linux DoS â?? RHEL 7.1 Kernel crashes on invalid USB device descriptors (iowarrior driver)
- Re: oss-2016-18: Multiple Local RedHat Enterprise Linux DoS â?? RHEL 7.1 Kernel crashes on invalid USB device descriptors (ati_remote2 driver)
- Re: oss-2016-17: Local RedHat Enterprise Linux DoS â?? RHEL 7.1 Kernel crashes (multiple free) on invalid USB device descriptors (snd-usb-audio driver)
- ESA-2016-012: EMC Documentum xCP – User Information Disclosure Vulnerability
- Reflected Cross-Site Scripiting in CuteEditor
- ChitaSoft (Web-Application) - SQL Injection Vulnerability
- Chamlio LMS v1.10.2 - (Profile) Persistent Web Vulnerability
- Yahoo Bug Bounty #37 - Sender Spoofing Vulnerability
- [security bulletin] HPSBGN03373 rev.2 - HP Release Control running TLS, Remote Disclosure of Information
- [security bulletin] HPSBMU03377 rev.2 - HP Release Control running RC4, Remote Disclosure of Information
- Re: OS-S 2016-06 Linux cdc_acm Nullpointer Dereference
- Re: OS-S 2016-07 Linux cypress_m8 Nullpointer Dereference
- Re: OS-S 2016-08 Linux mct_u232 Nullpointer Dereference
- Re: OS-S 2016-12 Linux digi_acceleport Nullpointer Dereference
- Re: OS-S 2016-11 Linux wacom multiple Nullpointer Dereferences
- Re: oss-2016-17: Local RedHat Enterprise Linux DoS â?? RHEL 7.1 Kernel crashes (multiple free) on invalid USB device descriptors (snd-usb-audio driver)
- Re: oss-2016-18: Multiple Local RedHat Enterprise Linux DoS â?? RHEL 7.1 Kernel crashes on invalid USB device descriptors (ati_remote2 driver)
- Re: oss-2016-13: Local RedHat Enterprise Linux DoS â?? RHEL 7.1 Kernel crashes on invalid USB device descriptors (powermate driver)
- Re: oss-2016-15: Local RedHat Enterprise Linux DoS â?? RHEL 7.1 Kernel crashes on invalid USB device descriptors (iowarrior driver)
- [security bulletin] HPSBGN03556 rev.1 - ArcSight ESM and ESM Express, Remote Arbitrary File Download, Local Arbitrary Command Execution
- Defense in depth -- the Microsoft way (part 39): vulnerabilities, please meet the bar for security servicing
- [ANNOUNCE][CVE-2016-0779] Apache TomEE 1.7.4 and 7.0.0-M3 releases
- [slackware-security] git (SSA:2016-075-01)
- From: Slackware Security Team
- [slackware-security] seamonkey (SSA:2016-075-02)
- From: Slackware Security Team
- Reflected Cross-Site Scripting (XSS) Vulnerability in Litecart CMS
- [SECURITY] [DSA 3518-1] spip security update
- [security bulletin] HPSBGN03558 rev.1 - ArcSight ESM and ESM Express, Remote Disclosure of Sensitive Information
- [CORE-2016-0005] - FreeBSD Kernel amd64_set_ldt Heap Overflow
- From: CORE Advisories Team
- Re: [FD] [CORE-2016-0005] - FreeBSD Kernel amd64_set_ldt Heap Overflow
- FreeBSD Security Advisory FreeBSD-SA-16:14.openssh
- From: FreeBSD Security Advisories
- FreeBSD Security Advisory FreeBSD-SA-16:15.sysarch
- From: FreeBSD Security Advisories
- Multiple (persistent) XSS in ProjectSend
- CVE-2016-1518: GrandStream Android VoIP Phone / App Provisioning Vulnerability
- CVE-2016-1519: GrandStream Android VoIP App TLS MitM Vulnerability
- CVE-2016-1520: GrandStream Android VoIP App Update Redirection
- Re: [ANNOUNCE] CVE-2016-0782: ActiveMQ Web Console - Cross-Site Scripting
- [CVE-2016-2345] Solarwinds Dameware Mini Remote Control Remote Code Execution Vulnerability
- [SECURITY] [DSA 3519-1] xen security update
- [slackware-security] mozilla-firefox (SSA:2016-077-01)
- From: Slackware Security Team
- Xoops 2.5.7.2 CSRF - Arbitrary User Deletions
- Xoops 2.5.7.2 Directory Traversal Bypass
- Re: server and client side remote code execution through a buffer overflow in all git versions before 2.7.1 (unpublished ᴄᴠᴇ-2016-2324 and ᴄᴠᴇ‑2016‑2315)
- Remote Code Execution via CSRF in iTop
- From: High-Tech Bridge Security Research
- Admin Password Reset & RCE via CSRF in Dating Pro
- From: High-Tech Bridge Security Research
- SQL Injection and RCE in WebsiteBaker
- From: High-Tech Bridge Security Research
- [SECURITY] [DSA 3520-1] icedove security update
- [security bulletin] HPSBGN03438 rev.1 - HP Support Assistant, Local Authentication Bypass
- [SECURITY] [DSA 3521-1] git security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 3522-1] squid3 security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 3523-1] iceweasel security update
- [SECURITY] [DSA 3524-1] activemq security update
- AbsoluteTelnet 10.14 DLL Hijack Code Exec
- [security bulletin] HPSBGN03551 rev.1 - HPE Helion Development Platform using glibc, Remote Denial of Service (DoS), Arbitrary Code Execution
- [security bulletin] HPSBGN03560 rev.1 - HP Operations Orchestration using Java Deserialization, Remote Arbitrary Code Execution
- [security bulletin] HPSBMU03562 rev.1 - HPE Service Manager using Java Deserialization, Remote Arbitrary Code Execution
- APPLE-SA-2016-03-21-1 iOS 9.3
- From: Apple Product Security
- APPLE-SA-2016-03-21-2 watchOS 2.2
- From: Apple Product Security
- APPLE-SA-2016-03-21-4 Xcode 7.3
- From: Apple Product Security
- APPLE-SA-2016-03-21-7 OS X Server 5.1
- From: Apple Product Security
- APPLE-SA-2016-03-21-3 tvOS 9.2
- From: Apple Product Security
- APPLE-SA-2016-03-21-6 Safari 9.1
- From: Apple Product Security
- APPLE-SA-2016-03-21-5 OS X El Capitan 10.11.4 and Security Update 2016-002
- From: Apple Product Security
- [RT-SA-2016-002] Cross-site Scripting in Securimage 3.6.2
- From: RedTeam Pentesting GmbH
- [SECURITY] [DSA 3525-1] pixman security update
- From: Salvatore Bonaccorso
- Remote Code Execution in DVR affecting over 70 different vendors
- [SECURITY] [DSA 3526-1] libmatroska security update
- CVE-2016-2166: Apache Qpid Proton python binding silently ignores request for 'amqps' if SSL/TLS not supported
- CA20160323-01: Security Notice for CA Single Sign-On Web Agents
- Hardcoded root password in Zyxel MAX3XX series Wimax CPEs
- Cisco Security Advisory: Cisco IOS and IOS XE Software DHCPv6 Relay Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco IOS and IOS XE and Cisco Unified Communications Manager Software Session Initiation Protocol Memory Leak Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco IOS and IOS XE Software Internet Key Exchange Version 2 Fragmentation Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco IOS and IOS XE Software Smart Install Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco IOS and NX-OS Software Locator/ID Separation Protocol Packet Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco IOS Software Wide Area Application Services Express Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- [SECURITY] [DSA 3528-1] pidgin-otr security update
- [SECURITY] [DSA 3529-1] redmine security update
- XSS (Cross Site Scripting) in Social CRM & Community Solutions powered by Lithium in Knowledge base section
- [SECURITY] [DSA 3527-1] inspircd security update
- [SYSS-2016-017] innovaphone IP222 - Improper Input Validation
- [SYSS-2016-018] innovaphone IP222 - Improper Restriction of Excessive Authentication Attempts
- [SYSS-2016-016] innovaphone IP222 - Improper Input Validation
- [security bulletin] HPSBMU03562 rev.2 - HPE Service Manager using Java Deserialization, Remote Arbitrary Code Execution
- [security bulletin] HPSBGN03563 rev.1 - HPE IceWall Products using OpenSSL, Remote Denial of Service (DoS), Local Denial of Service (DoS), Disclosure of Information
- [CVE-2016-0783] Predictable password reset token
- [CVE-2016-2164] Arbitrary file read via SOAP API
- [CVE-2016-2163] Stored Cross Site Scripting in Event description
- [SECURITY] [DSA 3530-1] tomcat6 security update
- [slackware-security] libevent (SSA:2016-085-01)
- From: Slackware Security Team
- [slackware-security] mozilla-thunderbird (SSA:2016-085-02)
- From: Slackware Security Team
- [SECURITY] [DSA 3531-1] chromum-browser security update
- TrendMicro DDI Cross Site Request Forgerys
- [SECURITY] [DSA 3532-1] quagga security update
- From: Salvatore Bonaccorso
- Validation Bypass in C2Box application : CVE - 2015-4626
- BMC-2015-0010: User enumeration vulnerability in BMC Server Automation (BSA) Unix/Linux RSCD Agent (CVE-2016-1542)
- BMC-2015-0011: Unauthorized password reset vulnerability in BMC Server Automation (BSA) (CVE-2016-1543)
- [SECURITY] [DSA 3533-1] openvswitch security update
- From: Salvatore Bonaccorso
- Fireware XTM Web UI - Open Redirect
- [SECURITY] [DSA 3534-1] dhcpcd security update
- From: Salvatore Bonaccorso
- [security bulletin] HPSBGN03444 rev.2 - HPE Network Automation, Remote Code Execution, Disclosure of Sensitive Information
- [SECURITY] [DSA 3535-1] kamailio security update
- Easy Hosting Control Panel (EHCP) - Multiple Vulnerabilities
- CVE-2016-2385 Kamailio SEAS module heap buffer overflow
- Multiple Vulnerabilities in CubeCart
- From: High-Tech Bridge Security Research
- [CVE-2016-0784] Apache OpenMeetings ZIP file path traversal
- Cisco Security Advisory: Cisco Firepower Malware Block Bypass Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- RE: Cisco Security Advisory: Cisco Firepower Malware Block Bypass Vulnerability
- [SECURITY] [DSA 3536-1] libstruts1.2-java security update
- [SECURITY] [DSA 3537-1] imlib2 security update
- [SECURITY] [DSA 3538-1] libebml security update
- Patron Info System - SQL Injection Vulnerability
- Hi Technology & Services CMS - SQL Injection Vulnerabilities
- WP External Links v1.80 - Cross Site Scripting Web Vulnerabilities
- Docker UI v0.10.0 - Multiple Client Side Cross Site Request Forgery Web Vulnerabilities
- Cades (2016Q1) - (id) Multiple SQL Injection Vulnerabilities
- Dorsa Web CMS - Multiple SQL Injection Vulnerabilities
- Docker UI v0.10.0 - Multiple Persistent Vulnerabilities
- Trend Micro (SSO) - (Backend) SSO Redirect & Session Vulnerability
Mail converted by MHonArc