EXPLOIT DATABASE
- Wed, 16 Jul 2014 00:00:00 +0000: [webapps] - Bitdefender GravityZone 5.1.5.386 - Multiple Vulnerabilities - Exploit-DB updates
Bitdefender GravityZone 5.1.5.386 - Multiple Vulnerabilities - Wed, 16 Jul 2014 00:00:00 +0000: [remote] - Boat Browser 8.0 and 8.0.1 - Remote Code Execution Vulnerability - Exploit-DB updates
Boat Browser 8.0 and 8.0.1 - Remote Code Execution Vulnerability - Wed, 16 Jul 2014 00:00:00 +0000: [dos] - Node Browserify 4.2.0 - Remote Code Execution Vulnerability - Exploit-DB updates
Node Browserify 4.2.0 - Remote Code Execution Vulnerability - Wed, 16 Jul 2014 00:00:00 +0000: [webapps] - Joomla Youtube Gallery Component - SQL Injection Vulnerability - Exploit-DB updates
Joomla Youtube Gallery Component - SQL Injection Vulnerability - Mon, 14 Jul 2014 00:00:00 +0000: [remote] - D-Link Unauthenticated UPnP M-SEARCH Multicast Command Injection - Exploit-DB updates
D-Link Unauthenticated UPnP M-SEARCH Multicast Command Injection - Mon, 14 Jul 2014 00:00:00 +0000: [remote] - HP Data Protector Manager 8.10 - Remote Command Execution - Exploit-DB updates
HP Data Protector Manager 8.10 - Remote Command Execution - Mon, 14 Jul 2014 00:00:00 +0000: [local] - OpenVPN Private Tunnel Core Service - Unquoted Service Path Elevation Of Privilege - Exploit-DB updates
OpenVPN Private Tunnel Core Service - Unquoted Service Path Elevation Of Privilege - Mon, 14 Jul 2014 00:00:00 +0000: [remote] - D-Link info.cgi POST Request Buffer Overflow - Exploit-DB updates
D-Link info.cgi POST Request Buffer Overflow - Mon, 14 Jul 2014 00:00:00 +0000: [remote] - D-Link HNAP Request Remote Buffer Overflow - Exploit-DB updates
D-Link HNAP Request Remote Buffer Overflow - Mon, 14 Jul 2014 00:00:00 +0000: [webapps] - Shopizer 1.1.5 - Multiple Vulnerabilities - Exploit-DB updates
Shopizer 1.1.5 - Multiple Vulnerabilities
PACKETSTORM DATABASE
- 16 July 2014: Oracle Data Redaction Is Broken - Files ≈ Packet Storm
Oracle data redaction is a simple but clever and innovative idea from Oracle. However, at present, there are weaknesses that undermine its effectiveness as a good security mechanism. These weaknesses can be exploited via web based SQL injection attacks and this paper details those weaknesses and provides suggestions on how it can be improved and made more secure. - 16 July 2014: pyClamd 0.3.10 - Files ≈ Packet Storm
pyClamd is a python interface to Clamd (Clamav daemon). By using pyClamd, you can add virus detection capabilities to your python software in an efficient and easy way. Instead of pyClamav which uses libclamav, pyClamd may be used by a closed source product. - 16 July 2014: Bitdefender GravityZone File Disclosure / Missing Authentication - Files ≈ Packet Storm
Bitdefender GravityZone versions prior to 5.1.11.432 suffer from local file disclosure, insecure service configuration, and missing authentication vulnerabilities. - 16 July 2014: Microsoft Windows DirectShow Privilege Escalation - Files ≈ Packet Storm
VUPEN Vulnerability Research Team discovered a critical vulnerability in Microsoft Windows. The vulnerability is caused by an input validation error in DirectShow when processing and unserializing "Stretch" objects in memory, which could be exploited to elevate privileges and execute arbitrary code in the context of the logged on user, or e.g. bypass Internet Explorer's Enhanced Protected Mode (EPM) sandbox. - 16 July 2014: e107 2.0 alpha2 Cross Site Scripting - Files ≈ Packet Storm
e107 version 2.0 alpha2 suffers from a reflective cross site scripting vulnerability. - 16 July 2014: Citrix Netscaler Disclosure / Cross Site Scripting - Files ≈ Packet Storm
Citrix NetScaler Application Delivery Controller and Citrix NetScaler Gateway are susceptible to cookie disclosure and reflective cross site scripting vulnerabilities. - 16 July 2014: Microsoft Internet Explorer ShowSaveFileDialog() Sandbox Bypass - Files ≈ Packet Storm
VUPEN Vulnerability Research Team discovered a critical vulnerability in Microsoft Internet Explorer. The vulnerability is caused due to an invalid handling of a sequence of actions aimed to save a file when calling "ShowSaveFileDialog()", which could be exploited by a sandboxed process to write files to arbitrary locations on the system and bypass IE Protected Mode sandbox. Versions 8, 9, 10, and 11 are affected. - 16 July 2014: OpenVPN Access Server Arbitrary Code Execution - Files ≈ Packet Storm
Remote attackers can execute arbitrary code and execute other attacks on computers with the OpenVPN Access Server "Desktop Client" installed. - 16 July 2014: Microsoft Internet Explorer Request Object Confusion Sandbox Bypass - Files ≈ Packet Storm
VUPEN Vulnerability Research Team discovered a critical vulnerability in Microsoft Internet Explorer. The vulnerability is caused by an object confusion vulnerability when processing object types within data shared between the broker and sandboxed processes, which could be exploited by a sandboxed process to achieve code execution within the broker context and bypass IE Protected Mode sandbox. Versions 8, 9, 10, and 11 are affected. - 16 July 2014: Microsoft Internet Explorer CSS @import Memory Corruption - Files ≈ Packet Storm
VUPEN Vulnerability Research Team discovered a critical vulnerability in Microsoft Internet Explorer. The vulnerability is caused by a use-after-free vulnerability when manipulating CSS @import statements through "addImport()" or "removeImport()", which could be exploited by attackers to leak arbitrary memory or execute arbitrary code via a malicious web page. Versions 9, 10, and 11 are affected. - 16 July 2014: Alfresco Community Edition 4.2.f Server Side Request Forgery - Files ≈ Packet Storm
Alfresco Community Edition versions 4.2.f and below suffer from multiple server side request forgery vulnerabilities. - 16 July 2014: HP Security Bulletin HPSBMU03072 SSRT101644 - Files ≈ Packet Storm
HP Security Bulletin HPSBMU03072 SSRT101644 - A potential security vulnerability has been identified with HP Data Protector. This vulnerability could be remotely exploited to execute arbitrary code. Revision 1 of this advisory. - 16 July 2014: Ubuntu Security Notice USN-2280-1 - Files ≈ Packet Storm
Ubuntu Security Notice 2280-1 - It was discovered that MiniUPnPc incorrectly handled certain buffer lengths. A remote attacker could possibly use this issue to cause applications using MiniUPnPc to crash, resulting in a denial of service. - 16 July 2014: Ubuntu Security Notice USN-2279-1 - Files ≈ Packet Storm
Ubuntu Security Notice 2279-1 - Ben Hawkes discovered that Transmission incorrectly handled certain peer messages. A remote attacker could use this issue to cause a denial of service, or possibly execute arbitrary code. - 16 July 2014: Red Hat Security Advisory 2014-0889-01 - Files ≈ Packet Storm
Red Hat Security Advisory 2014-0889-01 - The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime Environment and the OpenJDK 7 Java Software Development Kit. It was discovered that the Hotspot component in OpenJDK did not properly verify bytecode from the class files. An untrusted Java application or applet could possibly use these flaws to bypass Java sandbox restrictions. A format string flaw was discovered in the Hotspot component event logger in OpenJDK. An untrusted Java application or applet could use this flaw to crash the Java Virtual Machine or, potentially, execute arbitrary code with the privileges of the Java Virtual Machine.
CERT VULNERABILITY DATABASE
- Mon, 14 Jul 2014 17:26:14 +0000: VU#204988: Kaseya's agent driver contains NULL pointer dereference - CERT Recently Published Vulnerability Notes
Kaseya's agent driver,kapfa.sys,is vulnerable to a NULL pointer dereference. - Fri, 11 Jul 2014 17:47:15 +0000: VU#917348: Datum Systems satellite modem devices contain multiple vulnerabilities - CERT Recently Published Vulnerability Notes
Datum Systems PSM-4500 and PSM-500 series satellite modem devices contain multiple vulnerabilities - Thu, 10 Jul 2014 19:01:14 +0000: VU#712660: Raritian PX power distribution software is vulnerable to the cipher zero attack. - CERT Recently Published Vulnerability Notes
Raritan PX power distribution software version 01.05.08 and previous running on a model DPXR20A-16 device allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0(aka cipher zero)and an arbitrary password. - Wed, 09 Jul 2014 14:40:14 +0000: VU#100972: Liferay Portal PCE contains multiple cross-site scripting vulnerabilities - CERT Recently Published Vulnerability Notes
Liferay Portal versions 6.1.2 CE GA3,6.1.X EE,6.2.X EE,Master contain multiple cross-site scripting vulnerabilities - Tue, 08 Jul 2014 01:05:04 +0000: VU#960193: AVG Safeguard and Secure Search ActiveX controls provides insecure methods - CERT Recently Published Vulnerability Notes
The AVG Secure Search toolbar,also known as AVG Safeguard includes an ActiveX control that provides a number of unsafe methods,which may allow a remote,unauthenticated attacker to execute arbitrary code with the privileges of the user. - Thu, 03 Jul 2014 15:02:04 +0000: VU#402020: Autodesk VRED contains an unauthenticated remote code execution vulnerability - CERT Recently Published Vulnerability Notes
Autodesk VRED contains an unauthenticated remote code execution vulnerability. - Thu, 03 Jul 2014 14:05:04 +0000: VU#143740: Netgear GS105PE Prosafe Plus Switch contains hard-coded login credentials - CERT Recently Published Vulnerability Notes
Netgear GS105PE Prosafe Plus Switch firmware version 1.2.0.5 contains hard-coded credentials. (CWE-798) - Mon, 23 Jun 2014 13:47:04 +0000: VU#849500: SpamTitan contains a reflected cross-site scripting (XSS) vulnerability - CERT Recently Published Vulnerability Notes
SpamTitan contains a reflected cross-site scripting(XSS)vulnerability. - Wed, 18 Jun 2014 12:00:04 +0000: VU#774788: Belkin N150 path traversal vulnerability - CERT Recently Published Vulnerability Notes
Belkin N150 wireless routers contain a path traversal vulnerability. - Tue, 17 Jun 2014 20:13:04 +0000: VU#210884: F5 ARX Data Manager contains a SQL injection vulnerability - CERT Recently Published Vulnerability Notes
F5 ARX Data Manager 3.0.0 - 3.1.0 contains a SQL injection vulnerability. - Tue, 17 Jun 2014 15:42:04 +0000: VU#719172: Symantec Web Gateway contains SQL injection and cross-site scripting vulnerabilities - CERT Recently Published Vulnerability Notes
Symantec Web Gateway 5.1.1.24,and possibly earlier versions,contains cross-site scripting and SQL injection vulnerabilities. - Tue, 10 Jun 2014 13:51:57 +0000: VU#613308: Cisco AsyncOS contains a reflected cross-site scripting (XSS) vulnerability - CERT Recently Published Vulnerability Notes
Cisco AsyncOS contains a reflected cross-site scripting(XSS)vulnerability. - Mon, 09 Jun 2014 15:22:05 +0000: VU#758382: Unauthorized modification of UEFI variables in UEFI systems - CERT Recently Published Vulnerability Notes
Certain firmware implementations may not correctly protect and validate information contained in certain UEFI variables. Exploitation of such vulnerabilities could potentially lead to bypass of security features and/or denial of service for the platform. - Thu, 05 Jun 2014 17:06:04 +0000: VU#978508: OpenSSL is vulnerable to a man-in-the-middle attack - CERT Recently Published Vulnerability Notes
OpenSSL is vulnerable to a man-in-the-middle attack. - Fri, 30 May 2014 18:45:56 +0000: VU#124908: Dell ML6000 and Quantum Scalar i500 tape backup system command injection vulnerability - CERT Recently Published Vulnerability Notes
Dell ML6000 and Quantum Scalar i500 tape backup system contain a command injection vulnerability.
SECURITYFOCUS DATABASE
- Thu, 17 Jul 2014 00:00:00 +0000: Vuln: Oracle Java SE CVE-2014-0453 Remote Security Vulnerability - SecurityFocus Vulnerabilities
Oracle Java SE CVE-2014-0453 Remote Security Vulnerability - Thu, 17 Jul 2014 00:00:00 +0000: Vuln: Oracle Java SE CVE-2014-2401 Remote Security Vulnerability - SecurityFocus Vulnerabilities
Oracle Java SE CVE-2014-2401 Remote Security Vulnerability - Thu, 17 Jul 2014 00:00:00 +0000: Vuln: Oracle Java SE CVE-2014-0448 Remote Security Vulnerability - SecurityFocus Vulnerabilities
Oracle Java SE CVE-2014-0448 Remote Security Vulnerability - Thu, 17 Jul 2014 00:00:00 +0000: Vuln: Oracle Java SE CVE-2014-0455 Remote Code Execution Vulnerability - SecurityFocus Vulnerabilities
Oracle Java SE CVE-2014-0455 Remote Code Execution Vulnerability - : Bugtraq: SEC Consult SA-20140716-3 :: Multiple critical vulnerabilities in Bitdefender GravityZone - SecurityFocus Vulnerabilities
SEC Consult SA-20140716-3 :: Multiple critical vulnerabilities in Bitdefender GravityZone - : Bugtraq:
SEC Consult SA-20140716-2 :: Multiple vulnerabilities in Citrix
NetScaler Application Delivery Controller and Citrix NetScaler Gateway - SecurityFocus Vulnerabilities
SEC Consult SA-20140716-2 :: Multiple vulnerabilities in Citrix NetScaler Application Delivery Controller and Citrix NetScaler Gateway - : Bugtraq: SEC Consult SA-20140716-1 :: Remote Code Execution via CSRF in OpenVPN Access Server "Desktop Client" - SecurityFocus Vulnerabilities
SEC Consult SA-20140716-1 :: Remote Code Execution via CSRF in OpenVPN Access Server "Desktop Client" - : Bugtraq: Reflected Cross-Site Scripting (XSS) in e107 - SecurityFocus Vulnerabilities
Reflected Cross-Site Scripting (XSS) in e107 - : More rss feeds from SecurityFocus - SecurityFocus Vulnerabilities
News, Infocus, Columns, Vulnerabilities, Bugtraq ...
1 komentar:
I would like to say that this blog really convinced me to do it! Thanks, very good post
Posting Komentar