News aggregator

CVE-2018-18013

National Vulnerability Database - Wed, 10/24/2018 - 17:29
** DISPUTED *** Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this service is supplied with raw serialised Java objects, it deserialises them back into Java objects in memory, giving rise to a remote code execution vulnerability. NOTE: the vendor disputes that this is a vulnerability, stating it is "already mitigated by the internal firewall that limits access to configuration services to localhost."
Categories: Security News

CVE-2018-18014

National Vulnerability Database - Wed, 10/24/2018 - 17:29
** DISPUTED *** Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making requests to private services listening on ports 8000, 30000 and 30001. NOTE: the vendor disputes that this is a vulnerability, stating it is "already mitigated by the internal firewall that limits access to configuration services to localhost."
Categories: Security News

CVE-2018-18476

National Vulnerability Database - Wed, 10/24/2018 - 17:29
mysql-binuuid-rails 1.1.0 and earlier allows SQL Injection because it removes default string escaping for affected database columns.
Categories: Security News

CVE-2018-18517

National Vulnerability Database - Wed, 10/24/2018 - 17:29
Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x before 12.1.49.1 has XSS.
Categories: Security News

CVE-2018-11785

National Vulnerability Database - Wed, 10/24/2018 - 16:29
Missing authorization check in Apache Impala before 3.0.1 allows a Kerberos-authenticated but unauthorized user to inject random data into a running query, leading to wrong results for a query.
Categories: Security News

CVE-2018-11792

National Vulnerability Database - Wed, 10/24/2018 - 16:29
In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allows a user to move the table to a database with ALL, which will automatically grant that user with ALL privilege on that table due to the privilege inherited from the database.
Categories: Security News

CVE-2018-15442

National Vulnerability Database - Wed, 10/24/2018 - 15:29
A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. The vulnerability is due to insufficient validation of user-supplied parameters. An attacker could exploit this vulnerability by invoking the update service command with a crafted argument. An exploit could allow the attacker to run arbitrary commands with SYSTEM user privileges. While the CVSS Attack Vector metric denotes the requirement for an attacker to have local access, administrators should be aware that in Active Directory deployments, the vulnerability could be exploited remotely by leveraging the operating system remote management tools.
Categories: Security News

CVE-2018-11804

National Vulnerability Database - Wed, 10/24/2018 - 14:29
Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to speed up compilation. It has been included in release branches since 1.3.x, up to and including master. This server will accept connections from external hosts by default. A specially-crafted request to the zinc server could cause it to reveal information in files readable to the developer account running the build. Note that this issue does not affect end users of Spark, only developers building Spark from source code.
Categories: Security News

CVE-2018-17935

National Vulnerability Database - Wed, 10/24/2018 - 09:29
All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.
Categories: Security News

CVE-2018-1541

National Vulnerability Database - Wed, 10/24/2018 - 08:29
IBM WebSphere Commerce Enterprise V7, V8, and V9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142596.
Categories: Security News

Vuln: CakePHP CVE-2016-4793 Security Bypass Vulnerability

SecurityFocus Vulnerabilities - Wed, 10/24/2018 - 00:00
CakePHP CVE-2016-4793 Security Bypass Vulnerability
Categories: Security News

Vuln: Munin Remote Command Injection Vulnerability

SecurityFocus Vulnerabilities - Wed, 10/24/2018 - 00:00
Munin Remote Command Injection Vulnerability
Categories: Security News

Vuln: Adobe Digital Editions APSB18-27 Multiple Heap Buffer Overflow Vulnerabilities

SecurityFocus Vulnerabilities - Wed, 10/24/2018 - 00:00
Adobe Digital Editions APSB18-27 Multiple Heap Buffer Overflow Vulnerabilities
Categories: Security News

Vuln: Adobe Framemaker CVE-2018-15974 Privilege Escalation Vulnerability

SecurityFocus Vulnerabilities - Wed, 10/24/2018 - 00:00
Adobe Framemaker CVE-2018-15974 Privilege Escalation Vulnerability
Categories: Security News

CVE-2018-7427

National Vulnerability Database - Tue, 10/23/2018 - 17:31
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.7, and 6.5.x before 6.5.3; and Splunk Light before 6.6.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Categories: Security News

CVE-2018-7429

National Vulnerability Database - Tue, 10/23/2018 - 17:31
Splunkd in Splunk Enterprise 6.2.x before 6.2.14 6.3.x before 6.3.11, and 6.4.x before 6.4.8; and Splunk Light before 6.5.0 allow remote attackers to cause a denial of service via a malformed HTTP request.
Categories: Security News

CVE-2018-7431

National Vulnerability Database - Tue, 10/23/2018 - 17:31
Directory traversal vulnerability in the Splunk Django App in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3; and Splunk Light before 6.6.0 allows remote authenticated users to read arbitrary files via unspecified vectors.
Categories: Security News

CVE-2018-7432

National Vulnerability Database - Tue, 10/23/2018 - 17:31
Splunk Enterprise 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.7, and 6.5.x before 6.5.3; and Splunk Light before 6.6.0 allow remote attackers to cause a denial of service via a crafted HTTP request.
Categories: Security News

CVE-2018-18437

National Vulnerability Database - Tue, 10/23/2018 - 17:30
In AXIOS ITALIA Axioscloud Sissiweb Registro Elettronico 1.7.0, secret/relogoff.aspx has XSS via the Error_Desc parameter.
Categories: Security News

CVE-2018-18467

National Vulnerability Database - Tue, 10/23/2018 - 17:30
An issue was discovered in Daniel Gultsch Conversations 2.3.4. It is possible to spoof a custom message to an existing opened conversation by sending an intent.
Categories: Security News

Pages