Security News

CVE-2018-5459

National Vulnerability Database - Tue, 02/13/2018 - 16:29
An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via network by default on Port 2455. An attacker could execute some unauthenticated commands such as reading, writing, or deleting arbitrary files, or manipulate the PLC application during runtime by sending specially-crafted TCP packets to Port 2455.
Categories: Security News

CVE-2018-6910

National Vulnerability Database - Tue, 02/13/2018 - 16:29
DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.
Categories: Security News

CVE-2017-15709

National Vulnerability Database - Tue, 02/13/2018 - 15:29
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
Categories: Security News

CVE-2017-1711

National Vulnerability Database - Tue, 02/13/2018 - 15:29
IBM iNotes 8.5 and 9.0 SUService can be misguided into running malicious code from a DLL masquerading as a windows DLL in the temp directory. IBM X-Force ID: 134532.
Categories: Security News

CVE-2017-1714

National Vulnerability Database - Tue, 02/13/2018 - 15:29
IBM Notes and Domino NSD 8.5 and 9.0 could allow an authenticated local user without adminstrative privileges to gain System privilege. IBM X-Force ID: 134633.
Categories: Security News

CVE-2017-1720

National Vulnerability Database - Tue, 02/13/2018 - 15:29
IBM Notes 8.5 and 9.0 could allow a local attacker to execute arbitrary commands by carefully crafting a command line sent via the shared memory IPC. IBM X-Force ID: 134807.
Categories: Security News

CVE-2018-1383

National Vulnerability Database - Tue, 02/13/2018 - 15:29
A software logic bug creates a vulnerability in an AIX 6.1, 7.1, and 7.2 daemon which could allow a user with root privileges on one system, to obtain root access on another machine. IBM X-force ID: 138117.
Categories: Security News

CVE-2018-6953

National Vulnerability Database - Tue, 02/13/2018 - 15:29
In CCN-lite 2, the Parser of NDNTLV does not verify whether a certain component's length field matches the actual component length, which has a resultant buffer overflow and out-of-bounds memory accesses.
Categories: Security News

CVE-2018-6954

National Vulnerability Database - Tue, 02/13/2018 - 15:29
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.
Categories: Security News

CVE-2015-9252

National Vulnerability Database - Tue, 02/13/2018 - 14:29
An issue was discovered in QPDF before 7.0.0. Endless recursion causes stack exhaustion in QPDFTokenizer::resolveLiteral() in QPDFTokenizer.cc, related to the QPDF::resolve function in QPDF.cc.
Categories: Security News

CVE-2016-10713

National Vulnerability Database - Tue, 02/13/2018 - 14:29
An issue was discovered in GNU patch before 2.7.6. Out-of-bounds access within pch_write_line() in pch.c can possibly lead to DoS via a crafted input file.
Categories: Security News

CVE-2017-18183

National Vulnerability Database - Tue, 02/13/2018 - 14:29
An issue was discovered in QPDF before 7.0.0. There is an infinite loop in the QPDFWriter::enqueueObject() function in libqpdf/QPDFWriter.cc.
Categories: Security News

CVE-2017-18184

National Vulnerability Database - Tue, 02/13/2018 - 14:29
An issue was discovered in QPDF before 7.0.0. There is a stack-based out-of-bounds read in the function iterate_rc4 in QPDF_encryption.cc.
Categories: Security News

CVE-2017-18185

National Vulnerability Database - Tue, 02/13/2018 - 14:29
An issue was discovered in QPDF before 7.0.0. There is a large heap-based out-of-bounds read in the Pl_Buffer::write function in Pl_Buffer.cc. It is caused by an integer overflow in the PNG filter.
Categories: Security News

CVE-2017-18186

National Vulnerability Database - Tue, 02/13/2018 - 14:29
An issue was discovered in QPDF before 7.0.0. There is an infinite loop due to looping xref tables in QPDF.cc.
Categories: Security News

CVE-2018-6951

National Vulnerability Database - Tue, 02/13/2018 - 14:29
An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a "mangled rename" issue.
Categories: Security News

CVE-2018-6952

National Vulnerability Database - Tue, 02/13/2018 - 14:29
A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.
Categories: Security News

Bugtraq: CSNC-2017-027 Microsoft Intune - App PIN Bypass

SecurityFocus Vulnerabilities - Tue, 02/13/2018 - 14:20
CSNC-2017-027 Microsoft Intune - App PIN Bypass
Categories: Security News

Bugtraq: [SECURITY] [DSA 4111-2] libreoffice security update

SecurityFocus Vulnerabilities - Tue, 02/13/2018 - 14:20
[SECURITY] [DSA 4111-2] libreoffice security update
Categories: Security News

Bugtraq: [security bulletin] HPESBHF03819 rev.1 - HPE XP Storage using HGLM, Local Authentication Bypass

SecurityFocus Vulnerabilities - Tue, 02/13/2018 - 14:20
[security bulletin] HPESBHF03819 rev.1 - HPE XP Storage using HGLM, Local Authentication Bypass
Categories: Security News

Pages