Security News

CVE-2018-0317

National Vulnerability Database - Thu, 06/07/2018 - 08:29
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning (PCP) could allow an authenticated, remote attacker to escalate their privileges. The vulnerability is due to insufficient web portal access control checks. An attacker could exploit this vulnerability by modifying an access request. An exploit could allow the attacker to promote their account to any role defined on the system. This vulnerability affects Cisco Prime Collaboration Provisioning (PCP) Releases 12.2 and prior. Cisco Bug IDs: CSCvc90286.
Categories: Security News

CVE-2018-0318

National Vulnerability Database - Thu, 06/07/2018 - 08:29
A vulnerability in the password reset function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient validation of a password reset request. An attacker could exploit this vulnerability by submitting a password reset request and changing the password for any user on an affected system. An exploit could allow the attacker to gain administrative-level privileges on the affected system. This vulnerability affects Cisco Prime Collaboration Provisioning (PCP) Releases 11.6 and prior. Cisco Bug IDs: CSCvd07245.
Categories: Security News

CVE-2018-0319

National Vulnerability Database - Thu, 06/07/2018 - 08:29
A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient validation of a password recovery request. An attacker could exploit this vulnerability by submitting a password recovery request and changing the password for any user on an affected system. An exploit could allow the attacker to gain administrative-level privileges on the affected system. This vulnerability affects Cisco Prime Collaboration Provisioning (PCP) Releases 11.6 and prior. Cisco Bug IDs: CSCvd07253.
Categories: Security News

CVE-2018-0320

National Vulnerability Database - Thu, 06/07/2018 - 08:29
A vulnerability in the web framework code of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation on user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected application. This vulnerability affects Cisco Prime Collaboration Provisioning (PCP) Releases 12.1 and prior. Cisco Bug IDs: CSCvd61754.
Categories: Security News

CVE-2018-0321

National Vulnerability Database - Thu, 06/07/2018 - 08:29
A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invocation (RMI) system. The vulnerability is due to an open port in the Network Interface and Configuration Engine (NICE) service. An attacker could exploit this vulnerability by accessing the open RMI system on an affected PCP instance. An exploit could allow the attacker to perform malicious actions that affect PCP and the devices that are connected to it. This vulnerability affects Cisco Prime Collaboration Provisioning (PCP) Releases 11.6 and prior. Cisco Bug IDs: CSCvd61746.
Categories: Security News

CVE-2018-0322

National Vulnerability Database - Thu, 06/07/2018 - 08:29
A vulnerability in the web management interface of Cisco Prime Collaboration Provisioning (PCP) could allow an authenticated, remote attacker to modify sensitive data that is associated with arbitrary accounts on an affected device. The vulnerability is due to a failure to enforce access restrictions on the Help Desk and User Provisioning roles that are assigned to authenticated users. This failure could allow an authenticated attacker to modify critical attributes of higher-privileged accounts on the device. A successful exploit could allow the attacker to gain elevated privileges on the device. This vulnerability affects Cisco Prime Collaboration Provisioning (PCP) Releases 12.1 and prior. Cisco Bug IDs: CSCvd61779.
Categories: Security News

CVE-2018-0353

National Vulnerability Database - Thu, 06/07/2018 - 08:29
A vulnerability in traffic-monitoring functions in Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to circumvent Layer 4 Traffic Monitor (L4TM) functionality and bypass security protections. The vulnerability is due to a change in the underlying operating system software that is responsible for monitoring affected traffic. An attacker could exploit this vulnerability by sending crafted IP packets to an affected device. A successful exploit could allow the attacker to pass traffic through the device, which the WSA was configured to deny. This vulnerability affects both IPv4 and IPv6 traffic. This vulnerability affects Cisco AsyncOS versions for WSA on both virtual and hardware appliances running any release of the 10.5.1, 10.5.2, or 11.0.0 WSA Software. The WSA is vulnerable if it is configured for L4TM. Cisco Bug IDs: CSCvg78875.
Categories: Security News

Vuln: Multiplle Rockwell Automation Products CVE-2018-10619 Local Privilege Escalation Vulnerability

SecurityFocus Vulnerabilities - Thu, 06/07/2018 - 00:00
Multiplle Rockwell Automation Products CVE-2018-10619 Local Privilege Escalation Vulnerability
Categories: Security News

Vuln: Adobe Flash Player APSB18-19 Multiple Security Vulnerabilities

SecurityFocus Vulnerabilities - Thu, 06/07/2018 - 00:00
Adobe Flash Player APSB18-19 Multiple Security Vulnerabilities
Categories: Security News

Vuln: Linux Kernel CVE-2018-1000200 Local Denial of Service Vulnerability

SecurityFocus Vulnerabilities - Thu, 06/07/2018 - 00:00
Linux Kernel CVE-2018-1000200 Local Denial of Service Vulnerability
Categories: Security News

Bugtraq: Ignite Realtime Openfire Version 3.7.1 Reflected Cross Site Scripting (CVE-2018-11688)

SecurityFocus Vulnerabilities - Wed, 06/06/2018 - 23:20
Ignite Realtime Openfire Version 3.7.1 Reflected Cross Site Scripting (CVE-2018-11688)
Categories: Security News

CVE-2018-3715

National Vulnerability Database - Wed, 06/06/2018 - 22:29
glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to it, which allows a malicious user to read content of any file with known path.
Categories: Security News

CVE-2018-3716

National Vulnerability Database - Wed, 06/06/2018 - 22:29
simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
Categories: Security News

CVE-2018-3717

National Vulnerability Database - Wed, 06/06/2018 - 22:29
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.
Categories: Security News

CVE-2018-3718

National Vulnerability Database - Wed, 06/06/2018 - 22:29
serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.
Categories: Security News

CVE-2018-3719

National Vulnerability Database - Wed, 06/06/2018 - 22:29
mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
Categories: Security News

CVE-2018-3720

National Vulnerability Database - Wed, 06/06/2018 - 22:29
assign-deep node module before 0.4.7 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
Categories: Security News

CVE-2018-3721

National Vulnerability Database - Wed, 06/06/2018 - 22:29
lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
Categories: Security News

CVE-2018-3722

National Vulnerability Database - Wed, 06/06/2018 - 22:29
merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
Categories: Security News

CVE-2018-3723

National Vulnerability Database - Wed, 06/06/2018 - 22:29
defaults-deep node module before 0.2.4 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
Categories: Security News

Pages