Mail Index
- Python v2.7 v1.5.4 iOS - Filter Bypass & Persistent Vulnerability
- WebKitGTK+ Security Advisory WSA-2016-0003
- From: Carlos Alberto Lopez Perez
- APPLE-SA-2016-03-31-1 iBooks Author 2.4.1
- From: Apple Product Security
- [security bulletin] HPSBGN3547 rev.1 - HP Device Manager, Remote Read Access to Arbitrary Files
- [security bulletin] HPSBGN03567 rev.1 - HP Asset Manager using Java Deserialization, Remote Arbitrary Code Execution
- [security bulletin] HPSBUX03561 rev.1 - HPE HP-UX using Apache Tomcat, Remote Access Restriction Bypass, Arbitrary Code Execution, Execution of Arbitrary Code With Privilege Elevation, Unauthorized Read Access to Files
- [security bulletin] HPSBHF03431 rev.3 - HPE Network Switches, local Bypass of Security Restrictions, Indirect Vulnerabilities
- [slackware-security] php (SSA:2016-092-02)
- From: Slackware Security Team
- [slackware-security] mercurial (SSA:2016-092-01)
- From: Slackware Security Team
- [security bulletin] HPSBGN03565 rev.1 - HPE Virtualization Performance Viewer, Local Denial of Service (DoS)
- Open-Xchange Security Advisory 2016-04-02
- [SECURITY] [DSA 3539-1] srtp security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 3540-1] lhasa security update
- Bugcrowd CSV injection vulnerability
- Wordpress Scoreme Theme - Client Side Cross Site Scripting Web Vulnerability
- Techsoft Web Solutions CMS 2016 Q2 - SQL Injection Web Vulnerability
- FortiManager & FortiAnalyzer 5.x (Appliance Application) - (filename) Persistent Web Vulnerability
- ManageEngine Password Manager Pro Multiple Vulnerabilities
- CVE-2016-2191: optipng: invalid write
- From: Hans Jerry Illikainen
- [SE-2012-01] Broken security fix in IBM Java 7/8
- From: Security Explorations
- ESA-2016-034: EMC Documentum D2 Configuration Object Vulnerability
- Bitcoin/Altcoin Stratum Pool Mass Duplicate Shares Exploit
- From: lists@xxxxxxxxxxxxxxxxxx
- [slackware-security] mozilla-thunderbird (SSA:2016-095-01)
- From: Slackware Security Team
- [security bulletin] HPSBGN03569 rev.1 - HPE OneView for VMware vCenter (OV4VC), Remote Disclosure of Information
- [SECURITY] [DSA 3541-1] roundcube security update
- Apple iOS 9.3.1 (iPhone 6S & iPhone Plus) - (3D Touch) Passcode Bypass Vulnerability
- [SECURITY] [DSA 3542-1] mercurial security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 3543-1] oar security update
- Re: [SE-2012-01] Broken security fix in IBM Java 7/8
- From: Security Explorations
- CA20160405-01: Security Notice for CA API Gateway
- op5 v7.1.9 Remote Command Execution
- [slackware-security] subversion (SSA:2016-097-01)
- From: Slackware Security Team
- RE: FortiManager & FortiAnalyzer 5.x (Appliance Application) - (filename) Persistent Web Vulnerability
- SQL Injection in SocialEngine
- From: High-Tech Bridge Security Research
- CVE-2016-3672 - Unlimiting the stack not longer disables ASLR
- From: Hector Marco-Gisbert
- Cisco Security Advisory: Cisco TelePresence Server Crafted IPv6 Packet Handling Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco TelePresence Server Crafted URL Handling Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco UCS Invicta Default SSH Key Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco TelePresence Server Malformed STUN Packet Processing Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco Prime Infrastructure and Evolved Programmable Network Manager Privilege Escalation API Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- [security bulletin] HPSBGN03569 rev.2 - HPE OneView for VMware vCenter (OV4VC), Remote Disclosure of Information
- [security bulletin] HPSBST03568 rev.1 - HP XP7 Command View Advanced Edition Suite including Device Manager and Hitachi Automation Director (HAD), Remote Server-Side Request Forgery (SSRF)
- Techsoft WS CMS (2016 Q2) - SQL Injection Web Vulnerability
- Virtual Freer v1.58 - Client Side Cross Site Scripting Vulnerability
- Quicksilver HQ VoHo Concept4E CMS v1.0 - Multiple SQL Injection Web Vulnerabilities
- Eight Webcom CMS (2016 Q2) - SQL Injection Vulnerability
- Perli v2.6 iOS - Filter Bypass & Persistent Vulnerability
- [security bulletin] HPSBGN03570 rev.1 - HPE Universal CMDB, Remote Information Disclosure, URL Redirection
- [SECURITY] [DSA 3544-1] python-django security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 3545-1] cgit security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 3546-1] optipng security update
- AccelSite Content Manager v1.0 - SQL Injection Vulnerability
- JAWS Weak Service Permissions leads to Privilege Escalation
- CVE-2015-3268: Apache OFBiz information disclosure vulnerability
- CVE-2016-2170: Apache OFBiz information disclosure vulnerability
- WPN-XM Serverstack v0.8.6 XSS
- CSRF - MySQL / PHP.INI Hijacking
- WPN-XM Serverstack v0.8.6 CSRF - MySQL / PHP.INI Hijacking
- WPN-XM Serverstack v0.8.6 CSRF - MySQL / PHP.INI Hijacking
- Directadmin ControlPanel 1.50.0 Version Xss Vulnerability
- OpenCart json_decode function Remote PHP Code Execution
- Directadmin ControlPanel 1.50.0 Version Xss Vulnerability
- Directadmin cp ( Delete User ) 1.50.0 Version Xss Vulnerability
- [Multiple CVE]: RCE, info disclosure, HQL injection and stored XSS in Novell Service Desk 7.1.0
- Blind SQL injections in CivicRM
- From: Simon Waters (Surevine)
- ESA-2016-013: RSA BSAFE® Micro Edition Suite, Crypto-C Micro Edition, Crypto-J, SSL-J and SSL-C Lenstra’s Attack Vulnerability
- [SECURITY] [DSA 3547-1] imagemagick security update
- [SECURITY] [DSA 3485-2] didiwiki security update
- Wordpress Robo Gallery v2.0.14 - Code Execution Vulnerability
- Open redirect on Google.com
- .NET Framework 4.6 allows side loading of Windows API Set DLL
- CAM UnZip v5.1 Archive Directory Traversal
- [SE-2012-01] Yet another broken security fix in IBM Java 7/8
- From: Security Explorations
- Vbulletin Cms (Sendmessage.php Page) 0Day Exploit
- Webline CMS (2016Q2) - SQL Injection Vulnerability
- Mybb Cms (create forum and edit) Cross-Site Script Vulnerability
- Cisco Security Advisory:Cisco Unified Computing System Central Software Arbitrary Command Execution Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- [SECURITY] [DSA 3548-1] samba security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 3548-2] samba regression update
- From: Salvatore Bonaccorso
- Django CMS v3.2.3 - Filter Bypass & Persistent Vulnerability
- Mybb Cms (private.php Page) Denial Of Service Vulnerability
- Securing Android Applications from Screen Capture
- ESA-2016-036: EMC Unisphere for VMAX Virtual Appliance Arbitrary File Upload Vulnerability
- NEW VMSA-2016-0004 VMware product updates address a critical security issue in the VMware Client Integration Plugin
- From: VMware Security Response Center
- AST-2016-004: Long Contact URIs in REGISTER requests can crash Asterisk
- From: Asterisk Security Team
- AST-2016-005: TCP denial of service in PJProject
- From: Asterisk Security Team
- [SECURITY] [DSA 3549-1] chromium-browser security update
- [ERPSCAN-16-001] SAP NetWeaver 7.4 - XSS vulnerability
- [ERPSCAN-16-002] SAP HANA - log injection and no size restriction
- [ERPSCAN-16-003] SAP NetWeaver 7.4 - cryptographic issues
- Microsoft Internet Explorer 11 MSHTML.DLL Remote Binary Planting Vulnerability
- [SECURITY] [DSA 3550-1] openssh security update
- [slackware-security] mozilla-thunderbird (SSA:2016-106-01)
- From: Slackware Security Team
- [slackware-security] samba (SSA:2016-106-02)
- From: Slackware Security Team
- [CVE-2016-3996]KNOX clipboard data disclosure KNOX 1.0 - KNOX 2.3 / Android
- Ahrare Andeysheh Cms Multiple Vulnerabilities
- [SECURITY] [DSA 3551-1] fuseiso security update
- [SECURITY] [DSA 3552-1] tomcat7 security update
- CVE-2016-4021: pgpdump 0.29 - Endless loop parsing specially crafted input (SYSS-2016-030)
- [security bulletin] HPSBGN03555 rev.1 - HPE Vertica Analytics, Management Console, Remote Disclosure of Sensitive information, Execution of Arbitrary Code with Root Privileges
- [security bulletin] HPSBST03576 rev.2 - HP P9000, XP7 Command View Advanced Edition (CVAE) Suite including Device Manager and Tiered Storage Manager using Java Deserialization, Remote Arbitrary Code Execution
- Executable installers are vulnerable^WEVIL (case 33): GData's installers allow escalation of privilege
- [ERPSCAN-16-005] SAP HANA hdbxsengine JSON – DoS vulnerability
- [ERPSCAN-16-004] SAP NetWeaver 7.4 (Pmitest servlet) – XSS vulnerability
- Multiple Reflected XSS vulnerabilities in Oliver (formerly Webshare) v1.3.1
- From: research@xxxxxxxxxx
- ESA-2016-039: EMC ViPR SRM Multiple Cross-Site Request Forgery Vulnerabilities
- [security bulletin] HPSBMU03575 rev.1 - HP Smart Update Manager (SUM), Remote Denial of Service (DoS), Disclosure of Information
- PHPBack v1.3.0 SQL Injection
- *.Shell.com Port 443 DROWN decryption attack
- shell.com vulnerable TLS
- RCE via CSRF in phpMyFAQ
- From: High-Tech Bridge Security Research
- Cisco Security Advisory: Cisco Wireless LAN Controller Management Interface Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco Wireless LAN Controller Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco Wireless LAN Controller HTTP Parsing Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Cisco Adaptive Security Appliance Software DHCPv6 Relay Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Multiple Cisco Products libSRTP Denial of Service Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Webutler CMS 3.2 - Cross-Site Request Forgery
- OpenTSDB RCE
- exploit CVE-2016-2203
- CVE-2016-3074: libgd: signedness vulnerability
- From: Hans Jerry Illikainen
- [SECURITY] [DSA 3554-1] xen security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 3553-1] varnish security update
- SEC Consult SA-20160422-0 :: Insecure credential storage in my devolo Android app
- From: SEC Consult Vulnerability Lab
- SEC Consult SA-20160422-1 :: Multiple vulnerabilities in Digitalstrom Konfigurator
- From: SEC Consult Vulnerability Lab
- [security bulletin] HPSBGN03580 rev.1 - HP Data Protector, Remote Code Execution, Remote Unauthorized Disclosure of Information
- [security bulletin] HPSBMU03573 rev.1 - HPE System Management Homepage (SMH), Remote Disclosure of Information
- Remote Code Execution in Shopware <5.1.5 (CVE-2016-3109)
- From: david . vieira-kurz
- Persian-woocommerce-sms XSS Vulnerability
- Tweet-wheel XSS Vulnerability
- Echosign Plugin for WordPress XSS Vulnerability
- Google SEO Pressor Snippet Plugin XSS Vulnerability
- Easy Social Share Buttons for WordPress XSS Vulnerability
- CM-AD-Changer XSS Vulnerability
- Unlimited Pop-Ups WordPress Plugin XSS Vulnerability
- [SECURITY] [DSA 3555-1] imlib2 security update
- [SECURITY] [DSA 3556-1] libgd2 security update
- From: Salvatore Bonaccorso
- Telisca IPS Lock 2 Vulnerability
- C & C++ for OS - Filter Bypass & Persistent Vulnerability
- Totemomail v4.x & v5.x - Filter Bypass & Persistent Vulnerability
- UBNT Bug Bounty #2 - XML External Entity Vulnerability
- Cyberoam Central Console v02.03.1 - Multiple Persistent Vulnerabilities
- Django CMS v3.2.3 - Filter Bypass & Persistent Vulnerability
- Negin Group CMS - (v) Multiple Web Vulnerabilities
- [security bulletin] HPSBGN03582 rev.1 - HPE Helion CloudSystem using glibc, Remote Code Execution, Denial of Service (DoS)
- Trend Micro (Account) - Email Spoofing Web Vulnerability
- VoipNow v4.0.1 - (xajax_handler) Persistent Vulnerability
- Sophos XG Firewall (SF01V) - Persistent Web Vulnerability
- [SECURITY] [DSA 3557-1] mysql-5.5 security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 3558-1] openjdk-7 security update
- [slackware-security] mozilla-firefox (SSA:2016-117-01)
- From: Slackware Security Team
- Oracle Discoverer Viewer BI - Open Redirect Vulnerability
- EMC M&R (Watch4net) lacks Cross-Site Request Forgery protection
- [SECURITY] [DSA 3559-1] iceweasel security update
- CVE-2015-5208 - Arbitrary plugin execution issue in Apache Cordova iOS
- CVE-2015-5207 - Bypass of Access Restrictions in Apache Cordova iOS
- Re: [ERPSCAN-16-005] SAP HANA hdbxsengine JSON – DoS vulnerability
- From: Mahmut Firuz Dumlupinar - Vendor
- CVE-2015-5207 - Bypass of Access Restrictions in Apache Cordova iOS
- [SECURITY] [DSA 3560-1] php5 security update
- From: Salvatore Bonaccorso
- CVE-2016-3078: php: integer overflow in ZipArchive::getFrom*
- From: Hans Jerry Illikainen
- [security bulletin] HPSBUX03583 SSRT110084 rev.1 - HP-UX BIND Service running Named, Remote Denial of Service (DoS)
- Mozilla doesn't care for upstream security fixes, and doesn't bother to send own security fixes upstream
- Wordpress Truemag Theme - Client Side Cross Site Scripting Web Vulnerability
- SQL Injection in GLPI
- From: High-Tech Bridge Security Research
- [SECURITY] [DSA 3561-1] subversion security update
- From: Salvatore Bonaccorso
Mail converted by MHonArc