News aggregator

CVE-2018-11203

National Vulnerability Database - Wed, 05/16/2018 - 11:29
A division by zero was discovered in H5D__btree_decode_key in H5Dbtree.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.
Categories: Security News

CVE-2018-11204

National Vulnerability Database - Wed, 05/16/2018 - 11:29
A NULL pointer dereference was discovered in H5O__chunk_deserialize in H5Ocache.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.
Categories: Security News

CVE-2018-11205

National Vulnerability Database - Wed, 05/16/2018 - 11:29
A out of bounds read was discovered in H5VM_memcpyvv in H5VM.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.
Categories: Security News

CVE-2018-11206

National Vulnerability Database - Wed, 05/16/2018 - 11:29
A out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.
Categories: Security News

CVE-2018-11207

National Vulnerability Database - Wed, 05/16/2018 - 11:29
A division by zero was discovered in H5D__chunk_init in H5Dchunk.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.
Categories: Security News

CVE-2018-11208

National Vulnerability Database - Wed, 05/16/2018 - 11:29
** DISPUTED ** An issue was discovered in Z-BlogPHP 2.0.0. There is a persistent XSS that allows remote attackers to inject arbitrary web script or HTML into background web site settings via the "copyright information office" field. NOTE: the vendor indicates that the product was not intended to block this type of XSS by a user with the admin privilege.
Categories: Security News

CVE-2018-11209

National Vulnerability Database - Wed, 05/16/2018 - 11:29
** DISPUTED ** An issue was discovered in Z-BlogPHP 2.0.0. zb_system/cmd.php?act=verify relies on MD5 for the password parameter, which might make it easier for attackers to bypass intended access restrictions via a dictionary or rainbow-table attack. NOTE: the vendor declined to accept this as a valid issue.
Categories: Security News

CVE-2018-11210

National Vulnerability Database - Wed, 05/16/2018 - 11:29
TinyXML2 6.2.0 has a heap-based buffer over-read in the XMLDocument::Parse function in libtinyxml2.so.
Categories: Security News

CVE-2018-10240

National Vulnerability Database - Wed, 05/16/2018 - 10:29
SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's value can be brute-forced by an attacker to obtain the corresponding session cookie and hijack the user's session.
Categories: Security News

CVE-2018-10241

National Vulnerability Database - Wed, 05/16/2018 - 10:29
A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the application (with a NULL pointer dereference) via a specially crafted URL beginning with the /Web%20Client/ substring.
Categories: Security News

CVE-2018-10759

National Vulnerability Database - Wed, 05/16/2018 - 10:29
PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attackers to execute arbitrary commands or SQL statements via the id parameter.
Categories: Security News

CVE-2018-10760

National Vulnerability Database - Wed, 05/16/2018 - 10:29
Unrestricted file upload vulnerability in the Files plugin in ProjectPier 0.88 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in the tmp directory under the document root.
Categories: Security News

CVE-2018-10123

National Vulnerability Database - Wed, 05/16/2018 - 09:29
p910nd on Inteno IOPSYS 2.0 through 4.2.0 allows remote attackers to read, or append data to, arbitrary files via requests on TCP port 9100.
Categories: Security News

CVE-2018-10735

National Vulnerability Database - Wed, 05/16/2018 - 09:29
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.
Categories: Security News

CVE-2018-10736

National Vulnerability Database - Wed, 05/16/2018 - 09:29
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.
Categories: Security News

CVE-2018-10737

National Vulnerability Database - Wed, 05/16/2018 - 09:29
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter.
Categories: Security News

CVE-2018-10738

National Vulnerability Database - Wed, 05/16/2018 - 09:29
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.
Categories: Security News

CVE-2018-10810

National Vulnerability Database - Wed, 05/16/2018 - 09:29
chat/mobile/index.php in LiveZilla Live Chat 7.0.9.5 and prior is affected by Cross-Site Scripting via the Accept-Language HTTP header.
Categories: Security News

CVE-2018-5231

National Vulnerability Database - Wed, 05/16/2018 - 09:29
The ForgotLoginDetails resource in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7.9.2 allows remote attackers to perform a denial of service attack via sending requests to it.
Categories: Security News

Bugtraq: [SECURITY] [DSA 4201-1] xen security update

SecurityFocus Vulnerabilities - Wed, 05/16/2018 - 09:20
[SECURITY] [DSA 4201-1] xen security update
Categories: Security News

Pages