News aggregator

CVE-2016-9040

National Vulnerability Database - Fri, 09/07/2018 - 08:29
An exploitable denial of service exists in the the Joyent SmartOS OS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFSADDENTRIES when used with a 32 bit model. An attacker can cause a buffer to be allocated and never freed. When repeatedly exploit this will result in memory exhaustion, resulting in a full system denial of service.
Categories: Security News

CVE-2018-16650

National Vulnerability Database - Fri, 09/07/2018 - 01:29
phpMyFAQ before 2.9.11 allows CSRF.
Categories: Security News

CVE-2018-16651

National Vulnerability Database - Fri, 09/07/2018 - 01:29
The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports.
Categories: Security News

CVE-2018-16653

National Vulnerability Database - Fri, 09/07/2018 - 01:29
rejucms 2.1 has XSS via the ucenter/cms_user_add.php u_name parameter.
Categories: Security News

CVE-2018-16654

National Vulnerability Database - Fri, 09/07/2018 - 01:29
Zurmo 3.2.4 Stable allows XSS via app/index.php/accounts/default/details?id=2&kanbanBoard=1&openToTaskId=1.
Categories: Security News

CVE-2018-16655

National Vulnerability Database - Fri, 09/07/2018 - 01:29
Gxlcms 1.0 has XSS via the PATH_INFO to gx/lib/ThinkPHP/Tpl/ThinkException.tpl.php.
Categories: Security News

CVE-2018-6320

National Vulnerability Database - Thu, 09/06/2018 - 19:29
A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5.2R9 and 5.4RX before 5.4R2 wherein an http(s) Host header received from the browser is trusted without validation.
Categories: Security News

CVE-2018-16261

National Vulnerability Database - Thu, 09/06/2018 - 19:29
In Pulse Secure Pulse Desktop Client 5.3RX before 5.3R5 and 9.0R1, there is a Privilege Escalation Vulnerability with Dynamic Certificate Trust.
Categories: Security News

CVE-2018-16285

National Vulnerability Database - Thu, 09/06/2018 - 19:29
The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/admin-ajax.php.
Categories: Security News

CVE-2018-16310

National Vulnerability Database - Thu, 09/06/2018 - 19:29
Technicolor TG588V V2 devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses, as demonstrated by macof. NOTE: this might overlap CVE-2018-15852 and CVE-2018-15907.
Categories: Security News

CVE-2018-16517

National Vulnerability Database - Thu, 09/06/2018 - 19:29
asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a crafted file.
Categories: Security News

CVE-2018-16590

National Vulnerability Database - Thu, 09/06/2018 - 19:29
FURUNO FELCOM 250 and 500 devices use only client-side JavaScript for authentication.
Categories: Security News

CVE-2018-16646

National Vulnerability Database - Thu, 09/06/2018 - 19:29
In Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack.
Categories: Security News

CVE-2018-16647

National Vulnerability Database - Thu, 09/06/2018 - 19:29
In Artifex MuPDF 1.13.0, the pdf_get_xref_entry function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation fault in fz_write_data in fitz/output.c) via a crafted pdf file.
Categories: Security News

CVE-2018-16648

National Vulnerability Database - Thu, 09/06/2018 - 19:29
In Artifex MuPDF 1.13.0, the fz_append_byte function in fitz/buffer.c allows remote attackers to cause a denial of service (segmentation fault) via a crafted pdf file. This is caused by a pdf/pdf-device.c pdf_dev_alpha array-index underflow.
Categories: Security News

CVE-2018-12234

National Vulnerability Database - Thu, 09/06/2018 - 19:29
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML response via the flexiportal/GeneralInfo.aspx strAction parameter.
Categories: Security News

CVE-2018-14366

National Vulnerability Database - Thu, 09/06/2018 - 19:29
download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and 5.4RX before 5.4R4 have an Open Redirect Vulnerability.
Categories: Security News

CVE-2018-15726

National Vulnerability Database - Thu, 09/06/2018 - 19:29
The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Privilege Escalation Vulnerability.
Categories: Security News

CVE-2018-15749

National Vulnerability Database - Thu, 09/06/2018 - 19:29
The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Format String Vulnerability.
Categories: Security News

CVE-2018-15865

National Vulnerability Database - Thu, 09/06/2018 - 19:29
The Pulse Secure Desktop (macOS) has a Privilege Escalation Vulnerability.
Categories: Security News

Pages