Mail Index
- [FD] Multiple SQL injection vulnerabilities in dotCMS (8x CVE)
- [FD] Vulnerabilities in D-Link DIR-300
- [FD] Researchers Claim Wickr Patched Flaws but Didn't Pay Rewards
- Re: [FD] Multiple SQL injection vulnerabilities in dotCMS (8x CVE)
- [FD] MySQL / MariaDB / PerconaDB - Privilege Escalation / Race Condition Exploit [CVE-2016-6663 / OCVE-2016-5616]
- [FD] CVE-2016-8583 - Alienvault OSSIM/USM Reflected XSS
- [FD] CVE-2016-8582 - Alienvault OSSIM/USM SQL Injection Vulnerability
- [FD] CVE-2016-8581 - Alienvault OSSIM/USM Stored XSS Vulnerability
- [FD] CVE-2016-8580 - Alienvault OSSIM/USM Object Injection Vulnerability
- [FD] Microsoft Internet Explorer 9 MSHTML CAttrArray use-after-free details
- [FD] MSIE 11 MSHTML CView::CalculateImageImmunity use-after-free details
- Re: [FD] Multiple SQL injection vulnerabilities in dotCMS (8x CVE)
- [FD] Disclose [10 * cve] in Exponent CMS
- [FD] Sparkjava Framework - Arbitrary File Read Vulnerability
- [FD] MSIE 10 MSHTML CElement::GetPlainTextInScope out-of-bounds read
- Re: [FD] [oss-security] CVE request:Lynx invalid URL parsing with '?'
- Re: [FD] [oss-security] CVE request:Lynx invalid URL parsing with '?'
- [FD] [oss-security] CVE request:Lynx invalid URL parsing with '?'
- [FD] KL-001-2016-008 : Sophos Web Appliance Privilege Escalation
- From: KoreLogic Disclosures
- [FD] KL-001-2016-009 : Sophos Web Appliance Remote Code Execution
- From: KoreLogic Disclosures
- [FD] MSIE 9 MSHTML CPtsTextParaclient::CountApes out-of-bounds read
- [FD] MySQL / MariaDB / PerconaDB - Root Privilege Escalation Exploit ( CVE-2016-6664 / CVE-2016-5617 )
- [FD] Bypass Imperva by confusing HTTP Pollution Normalization Engine
- Re: [FD] [oss-security] CVE request:Lynx invalid URL parsing with '?'
- Re: [FD] [oss-security] CVE request:Lynx invalid URL parsing with '?'
- [FD] Actiontec WCB3000N (Telus Branded) Local Unauthenticated Privilege Elevation
- [FD] WinaXe v7.7 FTP 'Server Ready' CMD Remote Buffer Overflow
- [FD] Axessh 4.2.2 Denial Of Service
- [FD] Rapid PHP Editor CSRF Remote Command Execution
- [FD] Edusson (Robotdon) BB - Filter Bypass & Persistent Vulnerability
- [FD] Edusson (Robotdon) BB - Client Side Cross Site Scripting Vulnerability
- [FD] Schoolhos CMS v2.29 - (kelas) Data Siswa SQL Injection Vulnerability
- [FD] Intel(R) HD Graphics 10 - Unquoted Path Privilege Escalation
- [FD] [SYSS-2016-085] Aruba OS Improper Authentication - (CWE-287)
- [FD] Several unpatched vulns in OwnCloud
- [FD] [RootedCON 2017] Call for Papers open for RootedCON Madrid 2017!
- [FD] VBScript CRegExp..Execute use of uninitialized memory details (MSIE 8-11, IIS, CScript.exe/WScript.exe)
- [FD] [KIS-2016-13] Piwik <= 2.16.0 (saveLayout) PHP Object Injection Vulnerability
- [FD] [CVE-2016-6563 / VU#677427]: Dlink DIR routers HNAP Login stack buffer overflow
- [FD] Crashing Android devices with large Proxy Auto Config (PAC) Files [CVE-2016-6723]
- From: Nightwatch Cybersecurity Research
- [FD] Cross Site Scripting Vulnerability In Verint Impact 360
- [FD] YITH WooCommerce Compare WordPress Plugin unauthenticated PHP Object injection vulnerability
- [FD] Cross-Site Scripting vulnerability in Quotes Collection WordPress Plugin
- [FD] Cross-Site Scripting vulnerability in Caldera Forms WordPress Plugin
- [FD] Persistent Cross-Site Scripting in WassUp Real Time Analytics WordPress Plugin
- [FD] Cross-Site Scripting in Calendar WordPress Plugin
- [FD] Stored Cross-Site Scripting vulnerability in 404 to 301 WordPress Plugin
- [FD] Adobe Connect & Desktop v9.5.7 - Persistent Vulnerability (APSB16-35) [CVE-2016-7851]
- [FD] VBScript RegExpComp::PnodeParse out-of-bounds read details (MSIE 8-11, IIS, CScript.exe/WScript.exe)
- [FD] Avira Antivirus >= 15.0.21.86 Command Execution (SYSTEM)
- [FD] MSIE 9-11 MSHTML PROPERTYDESC::HandleStyleComponentProperty OOB read details
- [FD] WININET CHttpHeaderParser::ParseStatusLine out-of-bounds read details
- Re: [FD] WININET CHttpHeaderParser::ParseStatusLine out-of-bounds read details
- [FD] Vlany: A Linux (LD_PRELOAD) rootkit
- [FD] CA20161109-02: Security Notice for CA Service Desk Manager
- [FD] CA20161109-01: Security Notice for CA Unified Infrastructure Management
- [FD] Release - Shellcode Compiler
- [FD] MyBB 1.8.6: XSS
- From: Curesec Research Team (CRT)
- [FD] e107 CMS <= 2.1.2 Privilege Escalation
- [FD] [CT-2016-1110] Unauthenticated RCE in Observium network monitor
- [FD] Persistent Cross-Site Scripting in WP Google Maps Plugin via CSRF
- [FD] Weak validation of Amazon SNS push messages in W3 Total Cache WordPress Plugin
- [FD] Information disclosure race condition in W3 Total Cache WordPress Plugin
- [FD] Reflected Cross-Site Scripting vulnerability in W3 Total Cache plugin
- [FD] Teradata Virtual Machine Community Edition v15.10 has insecure file permission
- From: Larry W. Cashdollar
- [FD] Google Chrome blink Serializer::doSerialize bad cast details
- [FD] Trango Systems hidden default root login (all models)
- [FD] Unexpected behavior of cmd.exe while processing .bat files leads to potential command injection vulnerabilities
- From: Julian Horoszkiewicz
- [FD] New VMSA-2016-0019 - VMware product updates address multiple information disclosure issues
- From: VMware Security Response Center
- [FD] SEC Consult SA-20161114-0 :: Multiple vulnerabilities in I-Panda SolarEagle - Solar Controller Administration Software / MPPT Solar Controller SMART2
- From: SEC Consult Vulnerability Lab
- [FD] CVE-2015-0040: Microsoft Internet Explorer 11 MSHTML CMapElement::Notify use-after-free details
- [FD] Microsoft Edge edgehtml CAttrArray::Destroy use-after-free details
- [FD] CVE-2016-4484: - Cryptsetup Initrd root Shell
- Re: [FD] [oss-security] CVE-2016-4484: - Cryptsetup Initrd root Shell - Update: Dracut is also vulnerable
- From: Hector Marco-Gisbert
- [FD] OS-S 2016-22 - Local DoS: Linux Kernel EXT4 Memory Corruption / SLAB-Out-of-Bounds Read
- [FD] OS-S 2016-21 - Local DoS: Linux Kernel Nullpointer Dereference via keyctl
- Re: [FD] [oss-security] CVE-2016-4484: - Cryptsetup Initrd root Shell
- [FD] New VMSA-2016-0020 - VMware product updates address multiple information disclosure issues
- From: VMware Security Response Center
- [FD] Nginx (Debian-based distros) - Root Privilege Escalation Vulnerability (CVE-2016-1247)
- [FD] Cross-Site Scripting in All In One WP Security & Firewall WordPress Plugin
- Re: [FD] QUANTUMSQUIRREL - attrition.org unmasked as NSA TAO OP
- Re: [FD] [oss-security] CVE-2016-4484: - Cryptsetup Initrd root Shell
- [FD] Apple iOS 10.1 - Multiple Access Permission Vulnerabilities
- [FD] Habari CMS v0.9.2 - (Backend Comments) XSS Vulnerability
- [FD] EditMe CMS - CSRF Privilege Escalate Web Vulnerability
- [FD] Reason Core Security v1.2.0.1 - Unqoted Path Privilege Escalation Vulnerability
- [FD] CVE request - Samsumg Mobile Phone SVE-2016-6343: Unauthorized API access via system service call
- [FD] CVE-2015-2482 MSIE 8 jscript RegExpBase::FBadHeader use-after-free details
- [FD] Microsoft Internet Explorer 11 iertutil LCIEGetTypedComponentFromThread use-after-free details
- [FD] MyLittleForum 2.3.6.1: XSS & RPO
- From: Curesec Research Team (CRT)
- [FD] SPIP 3.1: XSS & Host Header Injection
- From: Curesec Research Team (CRT)
- [FD] Mezzanine 4.2.0: XSS
- From: Curesec Research Team (CRT)
- [FD] MyLittleForum 2.3.6.1: CSRF
- From: Curesec Research Team (CRT)
- [FD] MoinMoin 1.9.8: XSS
- From: Curesec Research Team (CRT)
- [FD] Lepton 2.2.2: SQL Injection
- From: Curesec Research Team (CRT)
- [FD] Lepton 2.2.2: CSRF, Open Redirect, Insecure Bruteforce Protection & Password Handling
- From: Curesec Research Team (CRT)
- [FD] Lepton 2.2.2: Code Execution
- From: Curesec Research Team (CRT)
- [FD] Jaws 1.1.1: Code Execution
- From: Curesec Research Team (CRT)
- [FD] FUDforum 3.0.6: Multiple Persistent XSS & Login CSRF
- From: Curesec Research Team (CRT)
- [FD] Jaws 1.1.1: Object Injection, Open Redirect, Cookie Flags
- From: Curesec Research Team (CRT)
- [FD] FUDforum 3.0.6: LFI
- From: Curesec Research Team (CRT)
- [FD] [ERPSCAN-16-031] SAP NetWeaver AS ABAP – directory traversal using READ DATASET
- [FD] [ERPSCAN-16-032] SAP Telnet Console – Directory traversal vulnerability
- [FD] Teradata Virtual Machine Community Edition v15.10 Insecure creation of files in /tmp
- From: Larry W. Cashdollar
- [FD] /tmp race condition in Teradata Studio Express v15.12.00.00 studioexpressinstall
- From: Larry W. Cashdollar
- [FD] SQL Injection in Post Indexer allows super admins to read the contents of the database (WordPress plugin)
- [FD] Unserialisation in Post Indexer could allow man-in-the-middle to execute arbitrary code (in some circumstances) (WordPress plugin)
- [FD] Unserialization vulnerability in Relevanssi Premium could allow admins to execute arbitrary code (in some circumstances) (WordPress plugin)
- [FD] SQL injection and unserialization vulnerability in Relevanssi Premium could allow admins to execute arbitrary code (in some circumstances) (WordPress plugin)
- [FD] Executable installers are vulnerable^WEVIL (case 41): EmsiSoft's Emergency Kit allows elevation of privilege for everybody
- [FD] Huawei Flybox B660 3G/4G Router - Auth Bypass Vulnerability
- [FD] CVE-2016-3247 Microsoft Edge CTextExtractor::GetBlockText OOB read details
- [FD] Tetris heap spraying: spraying the heap on a budget
- [FD] Cross-Site Scripting in Check Email WordPress Plugin
- [FD] Cross-Site Scripting in Huge IT Portfolio Gallery WordPress Plugin
- [FD] Persistent Cross-Site Scripting in Instagram Feed plugin via CSRF
- [FD] Stored Cross-Site Scripting in WP Canvas - Shortcodes WordPress Plugin
- [FD] Joomla plugin K2 RCE via CSRF or WCI
- Re: [FD] Stored Cross-Site Scripting in WP Canvas - Shortcodes WordPress Plugin
- From: Larry W. Cashdollar
- Re: [FD] Stored Cross-Site Scripting in WP Canvas - Shortcodes WordPress Plugin
- [FD] [RCESEC-2016-007] AppFusions Doxygen for Atlassian Confluence v1.3.0 getTemporaryDirectory() tempId Path Traversal/Remote Code Execution
- [FD] [RCESEC-2016-008] AppFusions Doxygen for Atlassian Confluence v1.3.2 renderContent() Full Path Information Disclosure
- [FD] [RCESEC-2016-009] AppFusions Doxygen for Atlassian Confluence v1.3.2 renderContent() Persistent Cross-Site Scripting
- [FD] Multiple issues in OpManager 12100 & 12200
- [FD] Reflected XSS in WonderCMS <= v0.9.8
- From: Manuel Garcia Cardenas
- [FD] PHDays VII Call for Papers: How to Stand Up at the Standoff
- [FD] MSIE8 MSHTML Ptls5::LsFindSpanVisualBoundaries memory corruption
- [FD] [x33fcon] Call for Papers (and Trainers)
- [FD] [ERPSCAN-16-033] SAP NetWeaver AS JAVA icman - DoS vulnerability
- [FD] [ERPSCAN-16-034] SAP NetWeaver AS JAVA - XXE vulnerability in BC-BMT-BPM-DSK component
- [FD] [CVE-2016-7434] ntpd remote pre-auth DoS
- [FD] [CORE-2016-0007] - TP-LINK TDDP Multiple Vulnerabilities
- From: CORE Advisories Team
- [FD] Stored Cross-Site Scripting in Gallery - Image Gallery WordPress Plugin
- [FD] [RT-SA-2016-003] Less.js: Compilation of Untrusted LESS Files May Lead to Code Execution through the JavaScript Less Compiler
- From: RedTeam Pentesting GmbH
- [FD] MobSF v0.9.3 is Released: Now supports Windows APPX Static Analysis
- [FD] CVE-2015-0050: Microsoft Internet Explorer 8 MSHTML SRunPointer::SpanQualifier/RunType OOB read details
- [FD] CVE-2015-1251: Chrome blink SpeechRecognitionController use-after-free details
- [FD] Microsoft Internet Explorer 11 MSHTML CGeneratedContent::HasGeneratedSVGMarker type confusion
- [FD] CVE-2013-3120 MSIE 10 MSHTML CEditAdorner::Detach use-after-free details
- [FD] The HS-110 Smart Plug aka Projekt Kasa
- From: Curesec Research Team (CRT)
- [FD] [CVE-2016-7098] GNU Wget < 1.18 Access List Bypass / Race Condition
- [FD] Faraday v2.2: Collaborative Penetration Test and Vulnerability Management Platform
- [FD] Red Hat JBoss EAP deserialization of untrusted data
- [FD] [SYSS-2016-064] Multi Kon Trade M2B GSM Wireless Alarm System - Improper Restriction of Excessive Authentication Attempts (CWE-307)
- [FD] [SYSS-2016-066] Multi Kon Trade M2B GSM Wireless Alarm System - Missing Protection against Replay Attacks
- [FD] [SYSS-2016-071] Blaupunkt Smart GSM Alarm SA 2500 Kit - Missing Protection against Replay Attacks
- [FD] [SYSS-2016-072] Olypmia Protect 9061 - Missing Protection against Replay Attacks
- [FD] [SYSS-2016-106] EASY HOME Alarmanlagen-Set - Missing Protection against Replay Attacks
- [FD] [SYSS-2016-107] EASY HOME Alarmanlagen-Set - Cryptographic Issues (CWE-310)
- [FD] NEW VMSA-2016-0022 VMware product updates address information disclosure vulnerabilities
- From: VMware Security Response Center
- [FD] NEW VMSA-2016-0021 VMware product updates address partial information disclosure vulnerability
- From: VMware Security Response Center
- [FD] UCanCode multiple vulnerabilities
- [FD] Schoolhos CMS v2.29 - userberita SQL injection Vulnerability
- [FD] Burden TMA v2.1.1 - (Task) Persistent Web Vulnerability
- [FD] Tenda, Dlink & Tplink TD-W8961ND - DHCP XSS Vulnerability
- [FD] Apple iOS 10.1 - Multiple Access Permission Vulnerabilities
- [FD] SEC Consult SA-20161128-0 :: DoS & heap-based buffer overflow in Guidance Software EnCase Forensic
- From: SEC Consult Vulnerability Lab
- [FD] CVE-2016-0063: MSIE 8-11 MSHTML DOMImplementation type confusion details
- [FD] [ndhXV] Call For Paper - 15th anniversary - 24-25 June 2017
- [FD] CFP - BloomCON 0x02 - March 24-25, 2017 Bloomsburg, PA
- Re: [FD] Tenda, Dlink & Tplink TD-W8961ND - DHCP XSS Vulnerability
- From: Simon Waters (Surevine)
- [FD] Cross-Site Request Forgery in Insert Html Snippet WordPress Plugin
Mail converted by MHonArc