News aggregator

CVE-2016-1000344

National Vulnerability Database - Mon, 06/04/2018 - 17:29
In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.
Categories: Security News

CVE-2016-1000345

National Vulnerability Database - Mon, 06/04/2018 - 17:29
In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack. For BC 1.55 and older, in an environment where timings can be easily observed, it is possible with enough observations to identify when the decryption is failing due to padding.
Categories: Security News

CVE-2016-1000346

National Vulnerability Database - Mon, 06/04/2018 - 17:29
In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated. This can cause issues as invalid keys can be used to reveal details about the other party's private key where static Diffie-Hellman is in use. As of release 1.56 the key parameters are checked on agreement calculation.
Categories: Security News

CVE-2016-1000352

National Vulnerability Database - Mon, 06/04/2018 - 17:29
In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.
Categories: Security News

CVE-2016-9042

National Vulnerability Database - Mon, 06/04/2018 - 16:29
An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.
Categories: Security News

CVE-2017-12092

National Vulnerability Database - Mon, 06/04/2018 - 16:29
An exploitable file write vulnerability exists in the memory module functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a file write resulting in a new program being written to the memory module. An attacker can send an unauthenticated packet to trigger this vulnerability.
Categories: Security News

CVE-2018-3853

National Vulnerability Database - Mon, 06/04/2018 - 16:29
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software Foxit PDF Reader version 9.0.1.1049. A specially crafted PDF document can trigger a previously freed object in memory to be reused resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Categories: Security News

CVE-2017-16040

National Vulnerability Database - Mon, 06/04/2018 - 15:29
gfe-sass is a library for promises (CommonJS/Promises/A,B,D) gfe-sass downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.
Categories: Security News

CVE-2017-16041

National Vulnerability Database - Mon, 06/04/2018 - 15:29
ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.
Categories: Security News

CVE-2017-16042

National Vulnerability Database - Mon, 06/04/2018 - 15:29
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
Categories: Security News

CVE-2017-16043

National Vulnerability Database - Mon, 06/04/2018 - 15:29
Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML scripts that will run in the victim's browser. Affects shout >=0.44.0 <=0.49.3.
Categories: Security News

CVE-2017-16044

National Vulnerability Database - Mon, 06/04/2018 - 15:29
`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Categories: Security News

CVE-2017-16045

National Vulnerability Database - Mon, 06/04/2018 - 15:29
`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Categories: Security News

CVE-2017-16046

National Vulnerability Database - Mon, 06/04/2018 - 15:29
`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Categories: Security News

CVE-2017-16048

National Vulnerability Database - Mon, 06/04/2018 - 15:29
`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Categories: Security News

CVE-2017-16049

National Vulnerability Database - Mon, 06/04/2018 - 15:29
`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Categories: Security News

CVE-2017-16050

National Vulnerability Database - Mon, 06/04/2018 - 15:29
`sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Categories: Security News

CVE-2017-16051

National Vulnerability Database - Mon, 06/04/2018 - 15:29
`sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Categories: Security News

CVE-2017-16052

National Vulnerability Database - Mon, 06/04/2018 - 15:29
`node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Categories: Security News

CVE-2017-16053

National Vulnerability Database - Mon, 06/04/2018 - 15:29
`fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Categories: Security News

Pages