Bugtraq: by author

67 messages starting Jun 13 18 and ending Jun 17 18
Date index | Thread index | Author index


Advisories

CSNC-2018-021 - Vert.x - HTTP Header Injection Advisories (Jun 13)

Amine Taouirsa

MachForm Multiple Vulnerabilities CVE-2018-6409/CVE-2018-6410/CVE-2018-6411 Amine Taouirsa (Jun 03)

Apple Product Security

APPLE-SA-2018-06-01-1 macOS High Sierra 10.13.5, Security Update 2018-003 Sierra, Security Update 2018-003 El Capitan Apple Product Security (Jun 03)
APPLE-SA-2018-06-01-5 watchOS 4.3.1 Apple Product Security (Jun 03)
APPLE-SA-2018-06-01-2 Safari 11.1.1 Apple Product Security (Jun 03)
APPLE-SA-2018-06-27-1 SwiftNIO 1.8.0 Apple Product Security (Jun 28)
APPLE-SA-2018-06-01-4 iOS 11.4 Apple Product Security (Jun 03)
APPLE-SA-2018-06-13-01 Xcode 9.4.1 Apple Product Security (Jun 14)
APPLE-SA-2018-06-01-7 iTunes 12.7.5 for Windows Apple Product Security (Jun 03)
APPLE-SA-2018-06-01-6 tvOS 11.4 Apple Product Security (Jun 03)
APPLE-SA-2018-06-01-3 iCloud for Windows 7.5 Apple Product Security (Jun 03)

Asterisk Security Team

AST-2018-007: Infinite loop when reading iostreams Asterisk Security Team (Jun 12)
AST-2018-008: PJSIP endpoint presence disclosure when using ACL Asterisk Security Team (Jun 12)

Branco, Rodrigo

CALL FOR PAPERS - INTEL SECURITY CONFERENCE (iSecCon) 2018 Branco, Rodrigo (Jun 14)

ch . sangsakul

SensioLabs Symfony version 3.3.6 - Cross-Site Scripting (Reflect) ch . sangsakul (Jun 11)

Core Security Advisories Team

[CORE-2018-0002] - Quest DR Series Disk Backup Multiple Vulnerabilities Core Security Advisories Team (Jun 03)
[CORE-2018-0004] - Quest KACE System Management Appliance Multiple Vulnerabilities Core Security Advisories Team (Jun 03)

cyber-psrt

[security bulletin] MFSBGN03810 rev.1 - Universal CMDB, Deserialization Java Objects and CSRF cyber-psrt (Jun 17)
[security bulletin] MFSBGN03809 rev.1 - Universal CMDB, Deserialization Java Objects and CSRF cyber-psrt (Jun 17)

Defense Code

DefenseCode ThunderScan SAST Advisory: WordPress WP Google Map Plugin Multiple SQL injection Security Vulnerabilities Defense Code (Jun 12)
DefenseCode ThunderScan SAST Advisory: WordPress Contact Form Maker Plugin Multiple Security Vulnerabilities Defense Code (Jun 07)
DefenseCode ThunderScan SAST Advisory: WordPress Form Maker Plugin Multiple Security Vulnerabilities Defense Code (Jun 07)
DefenseCode ThunderScan SAST Advisory: WordPress Ultimate Form Builder Lite Plugin Multiple Vulnerabilities (XSS and SQLi) Defense Code (Jun 12)

FreeBSD Security Advisories

FreeBSD Security Advisory FreeBSD-SA-18:07.lazyfpu FreeBSD Security Advisories (Jun 21)

Josh Berry

PRTG < 18.2.39 Command Injection Josh Berry (Jun 26)

KoreLogic Disclosures

KL-001-2018-008 : HPE VAN SDN Unauthenticated Remote Root Vulnerability KoreLogic Disclosures (Jun 25)

mehta . himanshu21

CVE-2018-11552 AXON PBX 2.02 Cross Site Scripting Vulnerability mehta . himanshu21 (Jun 03)

Michael Catanzaro

WebKitGTK+ and WPE WebKit Security Advisory WSA-2018-0005 Michael Catanzaro (Jun 14)

Michael Rossberg

Multiple Security Issues in Ecos Secure Boot Stick (SBS) Michael Rossberg (Jun 13)

Moritz Muehlenhoff

[SECURITY] [DSA 4221-1] libvncserver security update Moritz Muehlenhoff (Jun 11)
[SECURITY] [DSA 4217-1] wireshark security update Moritz Muehlenhoff (Jun 03)
[SECURITY] [DSA 4236-1] xen security update Moritz Muehlenhoff (Jun 28)
[SECURITY] [DSA 4233-1] bouncycastle security update Moritz Muehlenhoff (Jun 25)
[SECURITY] [DSA 4230-1] redis security update Moritz Muehlenhoff (Jun 17)
[SECURITY] [DSA 4235-1] firefox-esr security update Moritz Muehlenhoff (Jun 28)
[SECURITY] [DSA 4234-1] lava-server security update Moritz Muehlenhoff (Jun 25)
[SECURITY] [DSA 4214-1] zookeeper security update Moritz Muehlenhoff (Jun 03)
[SECURITY] [DSA 4225-1] openjdk-7 security update Moritz Muehlenhoff (Jun 11)
[SECURITY] [DSA 4232-1] xen security update Moritz Muehlenhoff (Jun 21)
[SECURITY] [DSA 4220-1] firefox-esr security update Moritz Muehlenhoff (Jun 11)

RYT

XSS in Canopy login page RYT (Jun 21)

Salvatore Bonaccorso

[SECURITY] [DSA 4227-1] plexus-archiver security update Salvatore Bonaccorso (Jun 12)
[SECURITY] [DSA 4231-1] libgcrypt20 security update Salvatore Bonaccorso (Jun 17)
[SECURITY] [DSA 4222-1] gnupg2 security update Salvatore Bonaccorso (Jun 11)
[SECURITY] [DSA 4218-1] memcached security update Salvatore Bonaccorso (Jun 06)
[SECURITY] [DSA 4223-1] gnupg1 security update Salvatore Bonaccorso (Jun 11)
[SECURITY] [DSA 4216-1] prosody security update Salvatore Bonaccorso (Jun 03)
[SECURITY] [DSA 4226-1] perl security update Salvatore Bonaccorso (Jun 12)
[SECURITY] [DSA 4224-1] gnupg security update Salvatore Bonaccorso (Jun 11)
[SECURITY] [DSA 4191-2] redmine regression update Salvatore Bonaccorso (Jun 03)

Sebastien Delafond

[SECURITY] [DSA 4228-1] spip security update Sebastien Delafond (Jun 14)
[SECURITY] [DSA 4215-1] batik security update Sebastien Delafond (Jun 03)
[SECURITY] [DSA 4219-1] jruby security update Sebastien Delafond (Jun 08)

Security Explorations

[SRP-2018-01] Reverse engineering tools for ST DVB chipsets (public release) Security Explorations (Jun 11)

Slackware Security Team

[slackware-security] gnupg (SSA:2018-170-01) Slackware Security Team (Jun 21)
[slackware-security] mozilla-firefox (SSA:2018-157-01) Slackware Security Team (Jun 06)
[slackware-security] gnupg2 (SSA:2018-159-01) Slackware Security Team (Jun 11)
[slackware-security] git (SSA:2018-152-01) Slackware Security Team (Jun 03)
[slackware-security] mozilla-firefox (SSA:2018-176-01) Slackware Security Team (Jun 25)

Tim Coen

TP-Link TL-WR841N v13: Broken Authentication (CVE-2018-12575) Tim Coen (Jun 28)
TP-Link TL-WR841N v13: Authenticated Blind Command Injection (CVE-2018-12577) Tim Coen (Jun 28)
TP-Link TL-WR841N v13: CSRF (CVE-2018-12574) Tim Coen (Jun 28)

Williams, Ken

CA20180614-01: Security Notice for CA Privileged Access Manager Williams, Ken (Jun 14)

yavuz atlas

Ignite Realtime Openfire Version 3.7.1 Reflected Cross Site Scripting (CVE-2018-11688) yavuz atlas (Jun 06)
Samsung Web Viewer for Samsung DVR Reflected Cross Site Scripting (XSS) CVE-2018-11689 yavuz atlas (Jun 13)
Gridbox extension for Joomla! <= 2.4.0 Reflected Cross Site Scripting (XSS) yavuz atlas (Jun 11)

Yves-Alexis Perez

[SECURITY] [DSA 4229-1] strongswan security update Yves-Alexis Perez (Jun 17)