News aggregator

Vuln: GIMP CVE-2017-17786 Heap Buffer Overflow Vulnerability

SecurityFocus Vulnerabilities - Thu, 12/20/2018 - 00:00
GIMP CVE-2017-17786 Heap Buffer Overflow Vulnerability
Categories: Security News

Vuln: Multiple Huawei Products CVE-2017-17167 Information Disclosure Vulnerability

SecurityFocus Vulnerabilities - Sat, 12/15/2018 - 00:00
Multiple Huawei Products CVE-2017-17167 Information Disclosure Vulnerability
Categories: Security News

Vuln: FasterXML Jackson-databind CVE-2017-15095 Incomplete Fix Remote Code Execution Vulnerability

SecurityFocus Vulnerabilities - Fri, 11/02/2018 - 00:00
FasterXML Jackson-databind CVE-2017-15095 Incomplete Fix Remote Code Execution Vulnerability
Categories: Security News

Bugtraq: [SECURITY] [DSA 4206-1] gitlab security update

SecurityFocus Vulnerabilities - Tue, 05/22/2018 - 13:20
[SECURITY] [DSA 4206-1] gitlab security update
Categories: Security News

CVE-2018-11321

National Vulnerability Database - Tue, 05/22/2018 - 11:29
An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option.
Categories: Security News

CVE-2018-11322

National Vulnerability Database - Tue, 05/22/2018 - 11:29
An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled as executable PHP scripts by the webserver.
Categories: Security News

CVE-2018-11323

National Vulnerability Database - Tue, 05/22/2018 - 11:29
An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to modify the access levels of user groups with higher permissions.
Categories: Security News

CVE-2018-11324

National Vulnerability Database - Tue, 05/22/2018 - 11:29
An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core or extension updates, could create a race condition where a session that was expected to be destroyed would be recreated.
Categories: Security News

CVE-2018-11325

National Vulnerability Database - Tue, 05/22/2018 - 11:29
An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and display the plaintext password for the administrator account at the confirmation screen.
Categories: Security News

CVE-2018-11326

National Vulnerability Database - Tue, 05/22/2018 - 11:29
An issue was discovered in Joomla! Core before 3.8.8. Inadequate input filtering leads to a multiple XSS vulnerabilities. Additionally, the default filtering settings could potentially allow users of the default Administrator user group to perform a XSS attack.
Categories: Security News

CVE-2018-11327

National Vulnerability Database - Tue, 05/22/2018 - 11:29
An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to see the names of tags that were either unpublished or published with restricted view permission.
Categories: Security News

CVE-2018-11328

National Vulnerability Database - Tue, 05/22/2018 - 11:29
An issue was discovered in Joomla! Core before 3.8.8. Under specific circumstances (a redirect issued with a URI containing a username and password when the Location: header cannot be used), a lack of escaping the user-info component of the URI could result in an XSS vulnerability.
Categories: Security News

CVE-2018-11369

National Vulnerability Database - Tue, 05/22/2018 - 11:29
An issue was discovered in PbootCMS v1.0.9. There is a SQL Injection that can get important information from the database via the \apps\home\controller\ParserController.php scode parameter.
Categories: Security News

CVE-2018-6378

National Vulnerability Database - Tue, 05/22/2018 - 11:29
In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager.
Categories: Security News

CVE-2018-11366

National Vulnerability Database - Tue, 05/22/2018 - 09:29
init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS) because logging is mishandled. This is fixed in 1.4.0.
Categories: Security News

CVE-2018-11367

National Vulnerability Database - Tue, 05/22/2018 - 09:29
An issue was discovered in CppCMS before 1.2.1. There is a denial of service in the JSON parser module.
Categories: Security News

CVE-2018-1583

National Vulnerability Database - Tue, 05/22/2018 - 09:29
IBM StoredIQ 7.6 could allow an authenticated attacker to bypass certain security restrictions. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to access and manipulate documents on StoredIQ managed data sources. IBM X-Force ID: 143331.
Categories: Security News

CVE-2018-6962

National Vulnerability Database - Tue, 05/22/2018 - 09:29
VMware Fusion (10.x before 10.1.2) contains a signature bypass vulnerability which may lead to a local privilege escalation.
Categories: Security News

CVE-2018-6963

National Vulnerability Database - Tue, 05/22/2018 - 09:29
VMware Workstation (14.x before 14.1.2) and Fusion (10.x before 10.1.2) contain multiple denial-of-service vulnerabilities that occur due to NULL pointer dereference issues in the RPC handler. Successful exploitation of these issues may allow an attacker with limited privileges on the guest machine trigger a denial-of-Service of their guest machine.
Categories: Security News

CVE-2018-3639

National Vulnerability Database - Tue, 05/22/2018 - 08:29
On Intel-based platforms, systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
Categories: Security News

Pages