News aggregator

CVE-2018-0577

National Vulnerability Database - Mon, 05/14/2018 - 09:29
Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Categories: Security News

Bugtraq: Vulnerabilities in IBMs Flashsystems and Storwize Products

SecurityFocus Vulnerabilities - Mon, 05/14/2018 - 08:20
Vulnerabilities in IBMs Flashsystems and Storwize Products
Categories: Security News

Vuln: Mozilla Firefox ESR Remote Memory Corruption and Buffer Overflow Vulnerabilities

SecurityFocus Vulnerabilities - Mon, 05/14/2018 - 00:00
Mozilla Firefox ESR Remote Memory Corruption and Buffer Overflow Vulnerabilities
Categories: Security News

Vuln: Mozilla Firefox and Firefox ESR Multiple Security Vulnerabilities

SecurityFocus Vulnerabilities - Mon, 05/14/2018 - 00:00
Mozilla Firefox and Firefox ESR Multiple Security Vulnerabilities
Categories: Security News

Vuln: Pivotal Greenplum Command Center CVE-2018-1280 SQL Injection Vulnerability

SecurityFocus Vulnerabilities - Mon, 05/14/2018 - 00:00
Pivotal Greenplum Command Center CVE-2018-1280 SQL Injection Vulnerability
Categories: Security News

CVE-2018-11037

National Vulnerability Database - Sun, 05/13/2018 - 23:29
In Exiv2 0.26, the Exiv2::PngImage::printStructure function in pngimage.cpp allows remote attackers to cause an information leak via a crafted file.
Categories: Security News

CVE-2018-10944

National Vulnerability Database - Sun, 05/13/2018 - 21:29
The request_dividend function of a smart contract implementation for ROC (aka Rasputin Online Coin), an Ethereum ERC20 token, allows attackers to steal all of the contract's Ether.
Categories: Security News

CVE-2018-11034

National Vulnerability Database - Sun, 05/13/2018 - 21:29
In 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x8000200D.
Categories: Security News

CVE-2018-11035

National Vulnerability Database - Sun, 05/13/2018 - 21:29
In 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x80002019.
Categories: Security News

CVE-2018-11031

National Vulnerability Database - Sun, 05/13/2018 - 20:29
application/home/controller/debug.php in PHPRAP 1.0.4 through 1.0.8 has SSRF via the /debug URI, as demonstrated by an api[url]=file:////etc/passwd&api[method]=get POST request.
Categories: Security News

CVE-2018-11032

National Vulnerability Database - Sun, 05/13/2018 - 20:29
PHPRAP 1.0.4 through 1.0.8 has SQL Injection via the application/home/controller/project.php search() function.
Categories: Security News

CVE-2018-11033

National Vulnerability Database - Sun, 05/13/2018 - 20:29
The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JPEG data.
Categories: Security News

CVE-2018-11018

National Vulnerability Database - Sun, 05/13/2018 - 18:29
An issue was discovered in PbootCMS v1.0.7. Cross-site request forgery (CSRF) vulnerability in apps/admin/controller/system/RoleController.php allows remote attackers to add administrator accounts via admin.php/role/add.html.
Categories: Security News

CVE-2018-11017

National Vulnerability Database - Sun, 05/13/2018 - 17:29
The newVar_N function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.
Categories: Security News

CVE-2018-10678

National Vulnerability Database - Sun, 05/13/2018 - 16:29
MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks.
Categories: Security News

CVE-2018-11013

National Vulnerability Database - Sun, 05/13/2018 - 11:29
Stack-based buffer overflow in the websRedirect function in GoAhead on D-Link DIR-816 A2 (CN) routers with firmware version 1.10B05 allows unauthenticated remote attackers to execute arbitrary code via a request with a long HTTP Host header.
Categories: Security News

CVE-2018-10996

National Vulnerability Database - Sat, 05/12/2018 - 00:29
The weblogin_log function in /htdocs/cgibin on D-Link DIR-629-B1 devices allows attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a session.cgi?ACTION=logout request involving a long REMOTE_ADDR environment variable.
Categories: Security News

CVE-2018-10998

National Vulnerability Database - Sat, 05/12/2018 - 00:29
An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call.
Categories: Security News

CVE-2018-10999

National Vulnerability Database - Sat, 05/12/2018 - 00:29
An issue was discovered in Exiv2 0.26. The Exiv2::Internal::PngChunk::parseTXTChunk function has a heap-based buffer over-read.
Categories: Security News

CVE-2018-11003

National Vulnerability Database - Sat, 05/12/2018 - 00:29
An issue was discovered in YXcms 1.4.7. Cross-site request forgery (CSRF) vulnerability in protected/apps/admin/controller/adminController.php allows remote attackers to delete administrator accounts via index.php?r=admin/admin/admindel.
Categories: Security News

Pages