Bugtraq: by author

69 messages starting Aug 15 18 and ending Aug 22 18
Date index | Thread index | Author index


Advisories

CSNC-2018-016 - ownCloud iOS Application - Cross-Site Scripting Advisories (Aug 15)
CSNC-2018-023 - Atmosphere Framework - Reflected Cross-Site Scripting (XSS) Advisories (Aug 15)
CSNC-2018-015 - ownCloud Impersonate - Authorization Bypass Advisories (Aug 29)

Andrius Duksta

RE: [FD] Executable installers are vulnerable^WEVIL (case 56): arbitrary code execution WITH escalation of privilege via rufus*.exe Andrius Duksta (Aug 06)

cyber-psrt

[security bulletin] MFSBGN03814 rev.1 - Service Management Automation (SMA) containerized, Remote Code Execution cyber-psrt (Aug 30)
[security bulletin] MFSBGN03821 rev.1 - Micro Focus Hybrid Cloud Management (HCM) containerized suite, Remote Code Execution cyber-psrt (Aug 30)
[security bulletin] MFSBGN03815 rev.1 - Data Center Automation Containerized (DCA) suite, remote code execution cyber-psrt (Aug 30)
[security bulletin] MFSBGN03812 rev.1 - Application Performance Management, remote cross-site tracing cyber-psrt (Aug 29)
[security bulletin] MFSBGN03818 rev.1 - Micro Focus Operations Bridge containerized suite, Remote Code Execution cyber-psrt (Aug 30)
[security bulletin] MFSBGN03820 rev.1 - Micro Focus Hybrid Cloud Management (HCM) containerized suites, remote code execution cyber-psrt (Aug 30)
[security bulletin] MFSBGN03817 rev.1 - Operations Bridge containerized suite, Remote Code Execution cyber-psrt (Aug 30)
[security bulletin] MFSBGN03813 rev.1 - Network Operations Management (NOM) Suite CDF, Remote Code Execution cyber-psrt (Aug 30)

eL_Bart0

[CVE-2018-14429] man-cgi < 1.16 Local File Include eL_Bart0 (Aug 08)

FreeBSD Security Advisories

FreeBSD Security Advisory FreeBSD-SA-18:11.hostapd FreeBSD Security Advisories (Aug 14)
FreeBSD Security Advisory FreeBSD-SA-18:08.tcp FreeBSD Security Advisories (Aug 14)
FreeBSD Security Advisory FreeBSD-SA-18:08.tcp FreeBSD Security Advisories (Aug 06)
FreeBSD Security Advisory FreeBSD-SA-18:10.ip FreeBSD Security Advisories (Aug 14)
FreeBSD Security Advisory FreeBSD-SA-18:09.l1tf FreeBSD Security Advisories (Aug 14)

Hafez Kamal

[HITB-Announce] Reminder: HITBSecConf2018 Dubai CFP Hafez Kamal (Aug 29)

Joachim De Zutter

[CVE-2018-12584] Heap overflow vulnerability in reSIProcate through 1.10.2 Joachim De Zutter (Aug 08)

Kotas, Kevin J

CA20180802-01: Security Notice for CA API Developer Portal Kotas, Kevin J (Aug 08)

kyle Lovett

ASUSTOR NAS ADM - 3.1.0 Remote Command Execution, SQL Injections kyle Lovett (Aug 14)

Lydéric LEFEBVRE

[CVE-2018-15877] Plainview Activity Monitor RCE Lydéric LEFEBVRE (Aug 27)
[CVE-2018-15877] Plainview Activity Monitor RCE Lydéric LEFEBVRE (Aug 27)

mamurch

[CVE-2018-15528] Reflected XSS in Java System Solutions SSO Plugin 4.0.13.1 for BMC MyIT mamurch (Aug 20)

Michael Catanzaro

WebKitGTK+ and WPE WebKit Security Advisory WSA-2018-0006 Michael Catanzaro (Aug 08)

Moritz Bechler

[SYSS-2018-010] Dojo Toolkit - dojox.grid.DataGrid editing XSS Moritz Bechler (Aug 27)

Moritz Muehlenhoff

[SECURITY] [DSA 4262-1] symfony security update Moritz Muehlenhoff (Aug 05)
[SECURITY] [DSA 4278-1] jetty9 security update Moritz Muehlenhoff (Aug 19)
[SECURITY] [DSA 4273-1] intel-microcode security update Moritz Muehlenhoff (Aug 16)
[SECURITY] [DSA 4274-1] xen security update Moritz Muehlenhoff (Aug 16)
[SECURITY] [DSA 4275-1] keystone security update Moritz Muehlenhoff (Aug 16)
[SECURITY] [DSA 4265-1] xml-security-c security update Moritz Muehlenhoff (Aug 05)

nick . m . mckenna

Signal IOS Remote Memory Exhaustion and Restart nick . m . mckenna (Aug 29)

reggie . dodd30

Mutiny Monitoring Appliance < 6.1.0-5263 - Command Injection (CVE-2018-15529) reggie . dodd30 (Aug 21)

research

Sensitive Data Exposure via WiFi Broadcasts in Android OS [CVE-2018-9489] research (Aug 29)

Salvatore Bonaccorso

[SECURITY] [DSA 4267-1] kamailio security update Salvatore Bonaccorso (Aug 08)
[SECURITY] [DSA 4277-1] mutt security update Salvatore Bonaccorso (Aug 19)
[SECURITY] [DSA 4266-1] linux security update Salvatore Bonaccorso (Aug 06)
[SECURITY] [DSA 4272-1] linux security update Salvatore Bonaccorso (Aug 14)
[SECURITY] [DSA 4260-1] libmspack security update Salvatore Bonaccorso (Aug 02)
[SECURITY] [DSA 4271-1] samba security update Salvatore Bonaccorso (Aug 14)
[SECURITY] [DSA 4279-2] linux regression update Salvatore Bonaccorso (Aug 23)
[SECURITY] [DSA 4279-1] linux security update Salvatore Bonaccorso (Aug 20)

Sebastien Delafond

[SECURITY] [DSA 4276-1] php-horde-image security update Sebastien Delafond (Aug 17)
[SECURITY] [DSA 4281-1] tomcat8 security update Sebastien Delafond (Aug 29)
[SECURITY] [DSA 4280-1] openssh security update Sebastien Delafond (Aug 21)

SEC Consult Vulnerability Lab

SEC Consult SA-20180813-0 :: SQL Injection, XSS & CSRF vulnerabilities in Pimcore SEC Consult Vulnerability Lab (Aug 16)

Slackware Security Team

[slackware-security] openssl (SSA:2018-226-01) Slackware Security Team (Aug 14)
[slackware-security] libX11 (SSA:2018-233-01) Slackware Security Team (Aug 21)
[slackware-security] ntp (SSA:2018-229-01) Slackware Security Team (Aug 19)
[slackware-security] samba (SSA:2018-229-02) Slackware Security Team (Aug 19)
[slackware-security] lftp (SSA:2018-214-01) Slackware Security Team (Aug 02)
[slackware-security] blueman (SSA:2018-213-01) Slackware Security Team (Aug 01)
[slackware-security] Slackware 14.2 kernel (SSA:2018-240-01) Slackware Security Team (Aug 29)

Stefan Kanthak

Defense in depth -- the Microsoft way (part 57): all the latest MSVCRT installers allow escalation of privilege Stefan Kanthak (Aug 14)
Executable installers are vulnerable^WEVIL (case 55): escalation of privilege with VMware Player 12.5.9 Stefan Kanthak (Aug 02)
CVE-2016-7085 NOT fixed in VMware-player-12.5.9-7535481.exe Stefan Kanthak (Aug 01)

Summer of Pwnage

Seagate Media Server multiple SQL injection vulnerabilities Summer of Pwnage (Aug 23)

VMware Security Response Center

New VMSA-2018-0019 - Horizon 6, 7, and Horizon Client for Windows updates address an out-of-bounds read vulnerability VMware Security Response Center (Aug 08)

X41 D-Sec GmbH Advisories

X41 D-Sec GmbH Security Advisory X41-2018-004: Multiple Vulnerabilities in Yubico libykneomgr X41 D-Sec GmbH Advisories (Aug 14)
X41 D-Sec GmbH Security Advisory X41-2018-002: Multiple Vulnerabilities in OpenSC X41 D-Sec GmbH Advisories (Aug 14)
X41 D-Sec GmbH Security Advisory X41-2018-001: Multiple Vulnerabilities in Yubico Piv X41 D-Sec GmbH Advisories (Aug 14)
X41 D-Sec GmbH Security Advisory X41-2018-003: Multiple Vulnerabilities in pam_pkcs11 X41 D-Sec GmbH Advisories (Aug 14)
X41 D-Sec GmbH Security Advisory X41-2018-005: Multiple Vulnerabilities in Apple smartcardservices X41 D-Sec GmbH Advisories (Aug 14)

x ksi

Couchbase Server - Remote Code Execution x ksi (Aug 24)
Couchbase Server - Remote Code Execution x ksi (Aug 23)
Couchbase Server - Remote Code Execution x ksi (Aug 24)

Yasser Zamani

[ANN] CVE-2018-11776 Apache Struts 2.3 to 2.3.34 and 2.5 to 2.5.16 Yasser Zamani (Aug 22)