Security News

CVE-2017-17425

National Vulnerability Database - Thu, 02/08/2018 - 13:29
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NVBUSourceDeviceSet Get method requests. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the underlying database. Was ZDI-CAN-4237.
Categories: Security News

CVE-2017-17652

National Vulnerability Database - Thu, 02/08/2018 - 13:29
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NVBUBackup Count method requests. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the underlying database. Was ZDI-CAN-4238.
Categories: Security News

CVE-2017-17653

National Vulnerability Database - Thu, 02/08/2018 - 13:29
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NVBUBackupOptionSet Get method requests. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the underlying database. Was ZDI-CAN-4286.
Categories: Security News

CVE-2017-17654

National Vulnerability Database - Thu, 02/08/2018 - 13:29
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NVBUBackup ClientList method requests. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the underlying database. Was ZDI-CAN-4287.
Categories: Security News

CVE-2018-1000030

National Vulnerability Database - Thu, 02/08/2018 - 12:29
Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well as a Heap-Use-After-Free. Python versions prior to 2.7.14 may also be vulnerable and it appears that Python 2.7.17 and prior may also be vulnerable however this has not been confirmed. The vulnerability lies when multiply threads are handling large amounts of data. In both cases there is essentially a race condition that occurs. For the Heap-Buffer-Overflow, Thread 2 is creating the size for a buffer, but Thread1 is already writing to the buffer without knowing how much to write. So when a large amount of data is being processed, it is very easy to cause memory corruption using a Heap-Buffer-Overflow. As for the Use-After-Free, Thread3->Malloc->Thread1->Free's->Thread2-Re-uses-Free'd Memory. The PSRT has stated that this is not a security vulnerability due to the fact that the attacker must be able to run code, however in some situations, such as function as a service, this vulnerability can potentially be used by an attacker to violate a trust boundary, as such the DWF feels this issue deserves a CVE.
Categories: Security News

CVE-2018-6846

National Vulnerability Database - Thu, 02/08/2018 - 11:29
Z-BlogPHP 1.5.1 allows remote attackers to discover the full path via a direct request to zb_system/function/lib/upload.php.
Categories: Security News

CVE-2017-7351

National Vulnerability Database - Thu, 02/08/2018 - 10:29
A SQL injection issue exists in a file upload handler in REDCap 7.x before 7.0.11 via a trailing substring to SendITController:upload.
Categories: Security News

Bugtraq: [SECURITY] [DSA 4107-1] django-anymail security update

SecurityFocus Vulnerabilities - Thu, 02/08/2018 - 10:20
[SECURITY] [DSA 4107-1] django-anymail security update
Categories: Security News

Bugtraq: [security bulletin] HPSBHF02981 rev.2 - HPE Integrated Lights-Out 2, 3, 4 (iLO2, iLO3, iLO4) and HPE Superdome Flex RMC - IPMI 2.0 RCMP+ Authentication Remote Password Hash Vulnerability (RAKP)

SecurityFocus Vulnerabilities - Thu, 02/08/2018 - 10:20
[security bulletin] HPSBHF02981 rev.2 - HPE Integrated Lights-Out 2, 3, 4 (iLO2, iLO3, iLO4) and HPE Superdome Flex RMC - IPMI 2.0 RCMP+ Authentication Remote Password Hash Vulnerability (RAKP)
Categories: Security News

Bugtraq: [SECURITY] [DSA 4106-1] libtasn1-6 security update

SecurityFocus Vulnerabilities - Thu, 02/08/2018 - 10:20
[SECURITY] [DSA 4106-1] libtasn1-6 security update
Categories: Security News

Bugtraq: SEC Consult SA-20180207-0 :: Multiple buffer overflow vulnerabilities in InfoZip UnZip

SecurityFocus Vulnerabilities - Thu, 02/08/2018 - 10:20
SEC Consult SA-20180207-0 :: Multiple buffer overflow vulnerabilities in InfoZip UnZip
Categories: Security News

CVE-2018-0512

National Vulnerability Database - Thu, 02/08/2018 - 09:29
Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to execute arbitrary OS commands via unspecified vectors.
Categories: Security News

CVE-2018-0513

National Vulnerability Database - Thu, 02/08/2018 - 09:29
Cross-site scripting vulnerability in MTS Simple Booking C, MTS Simple Booking Business version 1.28.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Categories: Security News

CVE-2018-0514

National Vulnerability Database - Thu, 02/08/2018 - 09:29
MP Form Mail CGI eCommerce Edition Ver 2.0.13 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
Categories: Security News

CVE-2018-0517

National Vulnerability Database - Thu, 02/08/2018 - 09:29
Untrusted search path vulnerability in Anshin net security for Windows Version 16.0.1.44 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Categories: Security News

CVE-2018-0140

National Vulnerability Database - Thu, 02/08/2018 - 02:29
A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authenticated, remote attacker to download any message from the spam quarantine by modifying browser string information. The vulnerability is due to a lack of verification of authenticated user accounts. An attacker could exploit this vulnerability by modifying browser strings to see messages submitted by other users to the spam quarantine within their company. Cisco Bug IDs: CSCvg39759, CSCvg42295.
Categories: Security News

CVE-2018-6834

National Vulnerability Database - Thu, 02/08/2018 - 02:29
static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href.
Categories: Security News

CVE-2018-6835

National Vulnerability Database - Thu, 02/08/2018 - 02:29
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions.
Categories: Security News

CVE-2018-6836

National Vulnerability Database - Thu, 02/08/2018 - 02:29
The netmonrec_comment_destroy function in wiretap/netmon.c in Wireshark through 2.4.4 performs a free operation on an uninitialized memory address, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
Categories: Security News

CVE-2018-6844

National Vulnerability Database - Thu, 02/08/2018 - 02:29
MyBB 1.8.14 has XSS via the Title or Description field on the Edit Forum screen.
Categories: Security News

Pages