Bugtraq: by author

78 messages starting Sep 05 18 and ending Sep 24 18
Date index | Thread index | Author index


Alessandro Ghedini

[SECURITY] [DSA 4286-1] curl security update Alessandro Ghedini (Sep 05)
[SECURITY] [DSA 4293-1] discount security update Alessandro Ghedini (Sep 17)

alphan yavaş

Disclose SSRF Vulnerability alphan yavaş (Sep 17)
Disclose SSRF Vulnerability Alphan Yavaş (Sep 12)

Antoine Neuenschwander

CVE-2018-16242 - oBike Electronic Lock Bypass Antoine Neuenschwander (Sep 13)

Apple Product Security

APPLE-SA-2018-9-17-1 iOS 12 Apple Product Security (Sep 17)
APPLE-SA-2018-9-24-4 Additional information for APPLE-SA-2018-9-17-1 iOS 12 Apple Product Security (Sep 24)
APPLE-SA-2018-9-17-5 Apple Support 2.4 for iOS Apple Product Security (Sep 17)
APPLE-SA-2018-9-17-4 Safari 12 Apple Product Security (Sep 17)
APPLE-SA-2018-9-24-6 Additional information for APPLE-SA-2018-9-17-3 tvOS 12 Apple Product Security (Sep 24)
APPLE-SA-2018-9-17-3 tvOS 12 Apple Product Security (Sep 17)
APPLE-SA-2018-9-17-2 watchOS 5 Apple Product Security (Sep 17)
APPLE-SA-2018-9-24-1 macOS Mojave 10.14 Apple Product Security (Sep 24)
APPLE-SA-2018-9-24-3 Additional information for APPLE-SA-2018-9-17-4 Safari 12 Apple Product Security (Sep 24)
APPLE-SA-2018-9-24-2 iTunes 12.9 for Windows Apple Product Security (Sep 24)
APPLE-SA-2018-9-24-5 Additional information for APPLE-SA-2018-9-17-2 watchOS 5 Apple Product Security (Sep 24)

Asterisk Security Team

AST-2018-009: Remote crash vulnerability in HTTP websocket upgrade Asterisk Security Team (Sep 20)

come2waraxe

[waraxe-2018-SA#108] - Username Disclosure in Breadcrumb NavXT Wordpress plugin come2waraxe (Sep 27)
[waraxe-2018-SA#107] - Reflected XSS in FV Flowplayer Wordpress plugin come2waraxe (Sep 20)

Filippo Cavallarin

CVE-2017-16541 details: Deanonymize Tor Browser Users with Automount Filippo Cavallarin (Sep 10)
CVE-2017-16639 - Tor Browser Deanonymization With SMB Filippo Cavallarin (Sep 12)

FreeBSD Security Advisories

FreeBSD Security Advisory FreeBSD-SA-18:12.elf FreeBSD Security Advisories (Sep 12)

Hafez Kamal

[HITB-Announce] #HITBSecConf2018PEK Call for CTF Hafez Kamal (Sep 19)

jack . m . mckenna

Amcrest Cameras SSL Key Reuse Across installations jack . m . mckenna (Sep 04)

Jonas Lejon

CVE-2017-17762 - XXE Vulnerability in Episerver Jonas Lejon (Sep 07)

Joshua Hudson

race condition in .net core System.IO.Directory.Delete allowing deletion of entire drives Joshua Hudson (Sep 17)

ludwig . stage

[SYSS-2018-016] Postman - Improper Certificate Validation ludwig . stage (Sep 24)

Lyderic LEFEBVRE

[CVE-2018-15876] Ajax BootModal Login Captcha Reuse Lyderic LEFEBVRE (Sep 07)

Michael Gilbert

[SECURITY] [DSA 4289-1] chromium-browser security update Michael Gilbert (Sep 10)
[SECURITY] [DSA 4297-1] chromium-browser security update Michael Gilbert (Sep 18)

Moritz Muehlenhoff

[SECURITY] [DSA 4298-1] hylafax security update Moritz Muehlenhoff (Sep 20)
[SECURITY] [DSA 4306-1] python2.7 security update Moritz Muehlenhoff (Sep 28)
[SECURITY] [DSA 4283-1] ruby-json-jwt security update Moritz Muehlenhoff (Sep 02)
[SECURITY] [DSA 4294-1] ghostscript security update Moritz Muehlenhoff (Sep 17)
[SECURITY] [DSA 4284-1] lcms2 security update Moritz Muehlenhoff (Sep 04)
[SECURITY] [DSA 4287-1] firefox-esr security update Moritz Muehlenhoff (Sep 10)
[SECURITY] [DSA 4282-1] trafficserver security update Moritz Muehlenhoff (Sep 02)
[SECURITY] [DSA 4295-1] thunderbird security update Moritz Muehlenhoff (Sep 17)
[SECURITY] [DSA 4296-1] mbedtls security update Moritz Muehlenhoff (Sep 17)
[SECURITY] [DSA 4303-1] okular security update Moritz Muehlenhoff (Sep 24)
[SECURITY] [DSA 4304-1] firefox-esr security update Moritz Muehlenhoff (Sep 24)
[SECURITY] [DSA 4288-1] ghostscript security update Moritz Muehlenhoff (Sep 10)
[SECURITY] [DSA 4301-1] mediawiki security update Moritz Muehlenhoff (Sep 24)
[SECURITY] [DSA 4273-2] intel-microcode security update Moritz Muehlenhoff (Sep 17)

Murat Aydemir

OPManager SQL Injection Vulnerability Murat Aydemir (Sep 20)

Qualys Security Advisory

Integer overflow in Linux's create_elf_tables() (CVE-2018-14634) Qualys Security Advisory (Sep 25)

Salvatore Bonaccorso

[SECURITY] [DSA 4285-1] sympa security update Salvatore Bonaccorso (Sep 05)
[SECURITY] [DSA 4290-1] libextractor security update Salvatore Bonaccorso (Sep 11)
[SECURITY] [DSA 4302-1] openafs security update Salvatore Bonaccorso (Sep 24)
[SECURITY] [DSA 4292-1] kamailio security update Salvatore Bonaccorso (Sep 11)
[SECURITY] [DSA 4300-1] libarchive-zip-perl security update Salvatore Bonaccorso (Sep 24)

sebastian . auwaerter

[SYSS-2018-015] HiScout GRC Suite < 3.1.5 - Unrestricted Upload of File with Dangerous Type sebastian . auwaerter (Sep 12)

Sebastian Neuner

Vulnerabilities in KONEs Group Controller (KGC) Sebastian Neuner (Sep 06)

SEC Consult Vulnerability Lab

SEC Consult SA-20180926-0 :: SEC Consult Vulnerability Lab (Sep 27)
SEC Consult SA-20180924-0 :: Multiple Vulnerabilities in Citrix StorageZones Controller SEC Consult Vulnerability Lab (Sep 26)
SEC Consult SA-20180918-0 :: Remote Code Execution via PHP unserialize in Moodle open-source learning platform SEC Consult Vulnerability Lab (Sep 18)
Re: SEC Consult SA-20180926-0 :: Stored Cross-Site Scripting in Progress Kendo UI Editor SEC Consult Vulnerability Lab (Sep 27)
SEC Consult SA-20180906-0 :: CSV Formula Injection in DokuWiki SEC Consult Vulnerability Lab (Sep 07)

Securify B.V.

Authentication bypass vulnerability in Western Digital My Cloud allows escalation to admin privileges Securify B.V. (Sep 18)

Slackware Security Team

[slackware-security] ghostscript (SSA:2018-256-01) Slackware Security Team (Sep 13)
[slackware-security] php (SSA:2018-257-01) Slackware Security Team (Sep 17)
[slackware-security] Slackware 14.2 mozilla-thunderbird (SSA:2018-249-04) Slackware Security Team (Sep 06)
[slackware-security] mozilla-firefox (SSA:2018-249-03) Slackware Security Team (Sep 06)
[slackware-security] mozilla-firefox (SSA:2018-265-01) Slackware Security Team (Sep 24)
[slackware-security] ghostscript (SSA:2018-249-02) Slackware Security Team (Sep 06)
[slackware-security] Slackware 14.2 kernel (SSA:2018-264-01) Slackware Security Team (Sep 24)
[slackware-security] curl (SSA:2018-249-01) Slackware Security Team (Sep 06)

Socket_0x03

tekno.Portal v0.1b - Cross-Site Scripting Vulnerability in "link.php" Socket_0x03 (Sep 25)

Stefan Kanthak

Defense in depth -- the Microsoft way (part 57): installation of security updates fails on Windows Embedded POSReady 2009 Stefan Kanthak (Sep 02)

Summer of Pwnage

Seagate Personal Cloud multiple information disclosure vulnerabilities Summer of Pwnage (Sep 12)

Williams, Ken

CA20180829-01: Security Notice for CA PPM Williams, Ken (Sep 02)
CA20180829-03: Security Notice for CA Release Automation Williams, Ken (Sep 02)
CA20180829-02: Security Notice for CA Unified Infrastructure Management Williams, Ken (Sep 02)

X41 D-Sec GmbH Advisories

X41 D-Sec GmbH Security Advisory X41-2018-008: Multiple Vulnerabilities in HylaFAX X41 D-Sec GmbH Advisories (Sep 19)
X41 D-Sec GmbH Security Advisory X41-2018-007: Multiple Vulnerabilities in mgetty X41 D-Sec GmbH Advisories (Sep 19)

Yves-Alexis Perez

[SECURITY] [DSA 4305-1] strongswan security update Yves-Alexis Perez (Sep 24)
[SECURITY] [DSA 4291-1] mgetty security update Yves-Alexis Perez (Sep 11)
[SECURITY] [DSA 4299-1] texlive-bin security update Yves-Alexis Perez (Sep 24)