News aggregator

CVE-2018-2377

National Vulnerability Database - Wed, 02/14/2018 - 07:29
In SAP HANA Extended Application Services, 1.0, some general server statistics and status information could be retrieved by unauthorized users.
Categories: Security News

CVE-2018-2378

National Vulnerability Database - Wed, 02/14/2018 - 07:29
In SAP HANA Extended Application Services, 1.0, unauthorized users can read statistical data about deployed applications including resource consumption.
Categories: Security News

CVE-2018-2379

National Vulnerability Database - Wed, 02/14/2018 - 07:29
In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint.
Categories: Security News

CVE-2018-2381

National Vulnerability Database - Wed, 02/14/2018 - 07:29
SAP ERP Financials Information System (SAP_APPL 6.00, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16; SAP_FIN 6.17, 6.18, 7.00, 7.20, 7.30 S4CORE 1.00, 1.01, 1.02) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Categories: Security News

CVE-2018-2382

National Vulnerability Database - Wed, 02/14/2018 - 07:29
A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to store graphics in a controlled area and as such gain information from system area, which is not available to the user otherwise.
Categories: Security News

Vuln: Jenkins CVE-2018-6356 Directory Traversal Vulnerability

SecurityFocus Vulnerabilities - Wed, 02/14/2018 - 00:00
Jenkins CVE-2018-6356 Directory Traversal Vulnerability
Categories: Security News

Vuln: Dell EMC Isilon OneFS Multiple Security Vulnerabilities

SecurityFocus Vulnerabilities - Wed, 02/14/2018 - 00:00
Dell EMC Isilon OneFS Multiple Security Vulnerabilities
Categories: Security News

CVE-2017-15699

National Vulnerability Database - Tue, 02/13/2018 - 17:29
A Denial of Service vulnerability was found in Apache Qpid Dispatch Router versions 0.7.0 and 0.8.0. To exploit this vulnerability, a remote user must be able to establish an AMQP connection to the Qpid Dispatch Router and send a specifically crafted AMQP frame which will cause it to segfault and shut down.
Categories: Security News

CVE-2018-5459

National Vulnerability Database - Tue, 02/13/2018 - 16:29
An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via network by default on Port 2455. An attacker could execute some unauthenticated commands such as reading, writing, or deleting arbitrary files, or manipulate the PLC application during runtime by sending specially-crafted TCP packets to Port 2455.
Categories: Security News

CVE-2018-6910

National Vulnerability Database - Tue, 02/13/2018 - 16:29
DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.
Categories: Security News

CVE-2017-15709

National Vulnerability Database - Tue, 02/13/2018 - 15:29
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
Categories: Security News

CVE-2017-1711

National Vulnerability Database - Tue, 02/13/2018 - 15:29
IBM iNotes 8.5 and 9.0 SUService can be misguided into running malicious code from a DLL masquerading as a windows DLL in the temp directory. IBM X-Force ID: 134532.
Categories: Security News

CVE-2017-1714

National Vulnerability Database - Tue, 02/13/2018 - 15:29
IBM Notes and Domino NSD 8.5 and 9.0 could allow an authenticated local user without adminstrative privileges to gain System privilege. IBM X-Force ID: 134633.
Categories: Security News

CVE-2017-1720

National Vulnerability Database - Tue, 02/13/2018 - 15:29
IBM Notes 8.5 and 9.0 could allow a local attacker to execute arbitrary commands by carefully crafting a command line sent via the shared memory IPC. IBM X-Force ID: 134807.
Categories: Security News

CVE-2018-1383

National Vulnerability Database - Tue, 02/13/2018 - 15:29
A software logic bug creates a vulnerability in an AIX 6.1, 7.1, and 7.2 daemon which could allow a user with root privileges on one system, to obtain root access on another machine. IBM X-force ID: 138117.
Categories: Security News

CVE-2018-6953

National Vulnerability Database - Tue, 02/13/2018 - 15:29
In CCN-lite 2, the Parser of NDNTLV does not verify whether a certain component's length field matches the actual component length, which has a resultant buffer overflow and out-of-bounds memory accesses.
Categories: Security News

CVE-2018-6954

National Vulnerability Database - Tue, 02/13/2018 - 15:29
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.
Categories: Security News

CVE-2015-9252

National Vulnerability Database - Tue, 02/13/2018 - 14:29
An issue was discovered in QPDF before 7.0.0. Endless recursion causes stack exhaustion in QPDFTokenizer::resolveLiteral() in QPDFTokenizer.cc, related to the QPDF::resolve function in QPDF.cc.
Categories: Security News

CVE-2016-10713

National Vulnerability Database - Tue, 02/13/2018 - 14:29
An issue was discovered in GNU patch before 2.7.6. Out-of-bounds access within pch_write_line() in pch.c can possibly lead to DoS via a crafted input file.
Categories: Security News

CVE-2017-18183

National Vulnerability Database - Tue, 02/13/2018 - 14:29
An issue was discovered in QPDF before 7.0.0. There is an infinite loop in the QPDFWriter::enqueueObject() function in libqpdf/QPDFWriter.cc.
Categories: Security News

Pages