News aggregator

CVE-2018-20621 (memu)

National Vulnerability Database - Wed, 03/13/2019 - 04:29
An issue was discovered in Microvirt MEmu 6.0.6. The MemuService.exe service binary is vulnerable to local privilege escalation through binary planting due to insecure permissions set at install time. This allows code to be run as NT AUTHORITY/SYSTEM.
Categories: Security News

CVE-2019-9741 (go)

National Vulnerability Database - Wed, 03/13/2019 - 04:29
An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command.
Categories: Security News

Vuln: Wibu Systems WibuKey DRM Multiple Input Validation Vulnerabilities

SecurityFocus Vulnerabilities - Wed, 03/13/2019 - 00:00
Wibu Systems WibuKey DRM Multiple Input Validation Vulnerabilities
Categories: Security News

Vuln: Microsoft NuGet Package Manager CVE-2019-0757 Tampering Security Bypass Vulnerability

SecurityFocus Vulnerabilities - Wed, 03/13/2019 - 00:00
Microsoft NuGet Package Manager CVE-2019-0757 Tampering Security Bypass Vulnerability
Categories: Security News

Vuln: SAP BusinessObjects Business Intelligence CVE-2019-0268 XML External Entity Injection Vulnerability

SecurityFocus Vulnerabilities - Wed, 03/13/2019 - 00:00
SAP BusinessObjects Business Intelligence CVE-2019-0268 XML External Entity Injection Vulnerability
Categories: Security News

CVE-2019-9740 (python)

National Vulnerability Database - Tue, 03/12/2019 - 23:29
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.2. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n followed by an HTTP header or a Redis command.
Categories: Security News

CVE-2019-9735 (neutron)

National Vulnerability Database - Tue, 03/12/2019 - 22:29
An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security group rules for instances from any project/tenant on the compute hosts to which it's applied. (Only deployments using the iptables security group driver are affected.)
Categories: Security News

CVE-2019-9736 (1024tools)

National Vulnerability Database - Tue, 03/12/2019 - 22:29
DOM-based XSS exists in 1024Tools Markdown 1.0 via vectors involving the '<EMBED SRC="data:image/svg+xml' substring.
Categories: Security News

CVE-2019-9737 (editor.md)

National Vulnerability Database - Tue, 03/12/2019 - 22:29
Editor.md 1.5.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring.
Categories: Security News

CVE-2019-9738 (gopher)

National Vulnerability Database - Tue, 03/12/2019 - 22:29
jimmykuu Gopher 2.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring.
Categories: Security News

CVE-2019-5921 (windows_7)

National Vulnerability Database - Tue, 03/12/2019 - 18:29
Untrusted search path vulnerability in Windows 7 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Categories: Security News

CVE-2019-5922 (teams)

National Vulnerability Database - Tue, 03/12/2019 - 18:29
Untrusted search path vulnerability in The installer of Microsoft Teams allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Categories: Security News

CVE-2019-5923 (insurance_wallet)

National Vulnerability Database - Tue, 03/12/2019 - 18:29
Directory traversal vulnerability in iChain Insurance Wallet App for iOS Version 1.3.0 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
Categories: Security News

CVE-2019-5924 (smart_forms)

National Vulnerability Database - Tue, 03/12/2019 - 18:29
Cross-site request forgery (CSRF) vulnerability in Smart Forms 2.6.15 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page.
Categories: Security News

CVE-2019-5925 (dradis)

National Vulnerability Database - Tue, 03/12/2019 - 18:29
Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Professional Edition v3.1.1 and earlier allow remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
Categories: Security News

CVE-2019-9729 (maplestory_online)

National Vulnerability Database - Tue, 03/12/2019 - 18:29
In Shanda MapleStory Online V160, the SdoKeyCrypt.sys driver allows privilege escalation to NT AUTHORITY\SYSTEM because of not validating the IOCtl 0x8000c01c input value, leading to an integer signedness error and a heap-based buffer underflow.
Categories: Security News

CVE-2019-0268 (businessobjects_business_intelligence)

National Vulnerability Database - Tue, 03/12/2019 - 18:29
SAP BusinessObjects Business Intelligence Platform (CMC Module), versions 4.10, 4.20 and 4.30, does not sufficiently validate an XML document accepted from an untrusted source.
Categories: Security News

CVE-2019-0269 (businessobjects_business_intelligence)

National Vulnerability Database - Tue, 03/12/2019 - 18:29
SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.10 and 4.20, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Categories: Security News

CVE-2019-0270

National Vulnerability Database - Tue, 03/12/2019 - 18:29
ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has been corrected in the following versions: KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.74, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, 7.74, 8.04, KERNEL 7.21, 7.45, 7.49, 7.53, 7.73, 7.74, 7.75, 8.04.
Categories: Security News

CVE-2019-0271

National Vulnerability Database - Tue, 03/12/2019 - 18:29
ABAP Server (used in NetWeaver and Suite/ERP) and ABAP Platform does not sufficiently validate an XML document accepted from an untrusted source, leading to an XML External Entity (XEE) vulnerability. Fixed in Kernel 7.21 or 7.22, that is ABAP Server 7.00 to 7.31 and Kernel 7.45, 7.49 or 7.53, that is ABAP Server 7.40 to 7.52 or ABAP Platform.
Categories: Security News

Pages