Databze Hot News 2015 August - 2015 January February March April May June July August September October November December
31.8.2015
Bugtraq
[security bulletin] HPSBGN03403 rev.1 - HP Virtualization Performance Viewer, Remote Unauthorized Disclosure of Information 2015-08-31
security-alert hp com
[security bulletin] HPSBMU03401 rev.1 - HP Operations Manager for UNIX and Linux, Remote Unauthorized Modification, Disclosure of Information 2015-08-31
security-alert hp com
Dogma India dogmaindia CMS - Auth Bypass Vulnerability 2015-08-28
Vulnerability Lab (research vulnerability-lab com)
Jenkins 1.626 - Cross Site Request Forgery / Code Execution 2015-08-28
smash devilteam pl
LinuxOptic CMS 2009 - Auth Bypass Session Vulnerability 2015-08-28
Vulnerability Lab (research vulnerability-lab com)
PayPal Bug Bounty #119 - Stored Cross Site Scripting Vulnerability 2015-08-28
Vulnerability Lab (research vulnerability-lab com)
[security bulletin] HPSBGN03407 rev.1 - HP Operations Manager for Windows, Remote Unauthorized Modification, Disclosure of Information 2015-08-28
security-alert hp com
[security bulletin] HPSBGN03387 rev.1 - HP Intelligent Provisioning, Remote Code Execution, Unauthorized Access 2015-08-28
security-alert hp com
[SECURITY] [DSA 3346-1] drupal7 security update 2015-08-31
Alessandro Ghedini (ghedo debian org)
[security bulletin] HPSBMU03416 rev.1 - HP Data Protector, Remote Disclosure of Information 2015-08-28
security-alert hp com
[SECURITY] [DSA 3345-1] iceweasel security update 2015-08-29
Salvatore Bonaccorso (carnil debian org)
[slackware-security] mozilla-firefox (SSA:2015-241-01) 2015-08-29
Slackware Security Team (security slackware com)
Re: Re: UAC Bypass Vulnerability on "Windows 7" in Windows Script Host 2015-08-30
kev r yahoo com
[SECURITY] [DSA 3344-1] php5 security update 2015-08-27
Sebastien Delafond (seb debian org)
Malware
TrojanDownloader:Win32/ExtenBro.A
BrowserModifier:Win32/Diplugem
DDoS:Win32/Nitol.J
TrojanDownloader:Win32/Olutall.B
TrojanDownloader:AutoIt/Fadef
SoftwareBundler:Win32/FakeDiX
Phishing
Vulnerebility
SANS News
Detecting file changes on Microsoft systems with FCIV
Threatpost
CoreBot Malware Steals Credentials-For Now
CERT Warns of Slew of Bugs in Belkin N600 Routers
NSF Awards $6M Grants for Internet of Things Security
CoreBot Malware Steals Credentials-For Now
Exploit
PhpWiki 1.5.4 - Multiple Vulnerabilities
Edimax PS-1206MF - Web Admin Auth Bypass
Ganglia Web Frontend < 3.5.1 - PHP Code Execution
Cyberoam Firewall CR500iNG-XP - 10.6.2 MR-1 - Blind SQL Injection Vulnerability
Apple OS X Entitlements Rootpipe Privilege Escalation
Microsoft Office 2007 - msxml5.dll Crash PoC
Viber 4.2.0 - Non-Printable Characters Handling Denial of Service Vulnerability
30.8.2015
Bugtraq
Malware
BrowserModifier:Win32/Diplugem
TrojanDownloader:Win32/ExtenBro.A
DDoS:Win32/Nitol.J
TrojanDownloader:Win32/Olutall.B
TrojanDownloader:AutoIt/Fadef
SoftwareBundler:Win32/FakeDiX
Phishing
Natwest | 29th August 2015 |
Vulnerebility
SANS News
Automating Metrics using RTIR REST API
Threatpost
Appeals Court Vacates Lower Courts Decision on National Security Letters
Exploit
MS SQL Server 2000/2005 SQLNS.SQLNamespace COM Object Refresh() Unhandled Pointer Exploit
Samsung SyncThruWeb 2.01.00.26 - SMB Hash Disclosure
Sysax Multi Server 6.40 SSH Component Denial of Service
28.8.2015
Bugtraq
[SECURITY] [DSA 3344-1] php5 security update 2015-08-27
Sebastien Delafond (seb debian org)
[security bulletin] HPSBGN03402 rev.2 - HP Performance Manager, Remote Disclosure of Information 2015-08-27
security-alert hp com
UAC Bypass Vulnerability on "Windows 7" in Windows Script Host 2015-08-27
vozzie gmail com (1 replies)
Malware
TrojanDownloader:Win32/Banload.BDQ
TrojanSpy:Win32/Bancos.ANS
TrojanDownloader:Win32/Banload.BDN
TrojanDownloader:Win32/Banload.BDL
PWS:Win32/Fareit.AF
TrojanDownloader:Win32/Zegost.H
Exploit:Win32/CVE-2015-2426
TrojanDownloader:MSIL/Winpud.A
Phishing
Barclays PLC. | 27th August 2015 |
Silvia Ribas. | 27th August 2015 |
Vulnerebility
SANS News
Test File: PDF With Embedded DOC Dropping EICAR
Threatpost
Adobe Hotfix Patches XXE Vulnerability in ColdFusion
Scanner Finds Malicious Android Apps at Scale
Google to Pause Flash Ads in Chrome Starting Next Week
FBI: Social Engineering, Hacks Lead to Millions Lost to Wire Fraud
Exploit
WordPress Responsive Thumbnail Slider Plugin 1.0 - Arbitrary File Upload
Jenkins 1.626 - Cross Site Request Forgery / Code Execution
Wolf CMS Arbitrary File Upload To Command Execution
Photo Transfer (2) 1.0 iOS - Denial of Service Vulnerability
27.8.2015
Bugtraq
UAC Bypass Vulnerability on "Windows 7" in Windows Script Host 2015-08-27
vozzie gmail com
[security bulletin] HPSBHF03408 rev.1 - HP PCs with HP lt4112 LTE/HSPA+ Gobi 4G Module, Remote Execution of Arbitrary Code 2015-08-26
security-alert hp com
[security bulletin] HPSBGN03411 rev.1 - HP Operations Agent Virtual Appliance, Remote Unauthorized Disclosure of Information 2015-08-26
security-alert hp com
CVE-2015-6535: Stored XSS in YouTube Embed (WordPress plugin) allows admins to compromise super admins 2015-08-26
grajalerts noreply gmail com
[security bulletin] HPSBGN03405 rev.1 - HP Integration Adaptor, Remote Unauthorized Modification, Disclosure of Information 2015-08-26
security-alert hp com
Malware
TrojanDownloader:Win32/Gratem.A
BrowserModifier:Win32/IstartSurf!lnk
BrowserModifier:Win32/DeltaHomes!lnk
BrowserModifier:Win32/OurSurfing!lnk
Phishing
Silvia Ribas. | 27th August 2015 |
PayPal | 27th August 2015 |
Vulnerebility
SANS News
Threatpost
Target Says SEC Wont Pursue Enforcement Action as a Result of Data Breach
Patched Ins0mnia Vulnerability Keeps Malicious iOS Apps Hidden
Endress+Hauser Patches Buffer Overflow In Dozens of ICS Products
Exploit
Magento eCommerce - Remote Code Execution
VLC Media Player 2.2.1 - m3u8/m3u Crash PoC
FHFS - FTP/HTTP File Server 2.1.2 Remote Command Execution
Xion Audio Player 1.5 build 155 Stack Based Buffer Overflow
QEMU Programmable Interrupt Timer Controller Heap Overflow
26.8.2015
Bugtraq
[security bulletin] HPSBMU03397 rev.1 - HP Version Control Agent (VCA) on Windows and Linux, Multiple Vulnerabilities 2015-08-24
security-alert hp com
[security bulletin] HPSBMU03413 rev.1 - HP Virtual Connect Enterprise Manager SDK, Multiple Vulnerabilities 2015-08-24
security-alert hp com
[security bulletin] HPSBMU03396 rev.1 - HP Version Control Repository Manager (VCRM) on Windows and Linux, Multiple Vulnerabilities 2015-08-24
security-alert hp com
[security bulletin] HPSBMU03409 rev.1 - HP Matrix Operating Environment, Multiple Vulnerabilities 2015-08-24
security-alert hp com
Malware
VBA / TrojanDownloader.Agent.AAC
VBA / TrojanDownloader.Agent.ZX
VBA / TrojanDownloader.Agent.ZS
Phishing
Natwest | 26th August 2015 |
PayPal | 26th August 2015 |
Vulnerebility
SANS News
Actor that tried Neutrino exploit kit now back to Angler
Threatpost
CERT Warns of Hard-Coded Credentials in DSL SOHO Routers
Researchers Uncover New Italian RAT uWarrior
Exploit
VLC Media Player 2.2.1 - m3u8/m3u Crash PoC
25.8.2015
Bugtraq
[security bulletin] HPSBMU03397 rev.1 - HP Version Control Agent (VCA) on Windows and Linux, Multiple Vulnerabilities 2015-08-24
security-alert hp com
[security bulletin] HPSBMU03413 rev.1 - HP Virtual Connect Enterprise Manager SDK, Multiple Vulnerabilities 2015-08-24
security-alert hp com
[security bulletin] HPSBMU03396 rev.1 - HP Version Control Repository Manager (VCRM) on Windows and Linux, Multiple Vulnerabilities 2015-08-24
security-alert hp com
[security bulletin] HPSBMU03409 rev.1 - HP Matrix Operating Environment, Multiple Vulnerabilities 2015-08-24
security-alert hp com
[security bulletin] HPSBGN03404 rev.1 - HP Service Health Reporter, Remote Unauthorized Modification 2015-08-24
security-alert hp com
[security bulletin] HPSBMU03345 rev.1 - HP Network Node Manager i (NNMi) and Smart Plugins (iSPIs) for HP-UX, Linux, Solaris, and Windows, Remote Disclosure of Information, Unauthorized Modification 2015-08-24
security-alert hp com
[SYSS-2015-026] Denial of Service (CWE-730) and Overly Restrictive Account Lockout Mechanism (CWE-645) in Page2Flip Premium App 2.5 2015-08-24
erlijn vangenuchten syss de
[SYSS-2015-027] Cross-Site Scripting (CWE-79) in Page2Flip Premium App 2.5 2015-08-24
erlijn vangenuchten syss de
[SYSS-2015-028] Cross-Site Scripting (CWE-79) in Page2Flip Premium App 2.5 2015-08-24
erlijn vangenuchten syss de
[SYSS-2015-029] Insecure Direct Object Reference (CWE-932) in Page2Flip Premium App 2.5 2015-08-24
erlijn vangenuchten syss de
[SYSS-2015-032] Broken Authentication and Session Management (CWE-930) in Page2Flip Premium App 2.5 2015-08-24
erlijn vangenuchten syss de
[SYSS-2015-030] Improper Handling of Insufficient Privileges (CWE-274) in Page2Flip Premium App 2.5 2015-08-24
erlijn vangenuchten syss de
SYSS-2015-033: Missing Function Level Access Control (CWE-935) in Page2Flip Premium App 2.5 2015-08-24
erlijn vangenuchten syss de
Dell SonicWall NetExtender Unquoted Autorun Privilege Escalation 2015-08-24
ajs swordshield com
Cross site request forgery vulnerability in Linksys WAG120N 2015-08-23
DonVallejo . (j v vallejo gmail com)
[SYSS-2015-025] Netop Remote Control - Insufficiently Protected Credentials 2015-08-24
matthias deeg syss de
Malware
Phishing
service@paypal.co.uk | 24th August 2015 |
ACTION REQUIRED -YOUR BANK HAS |
Vulnerebility
SANS News
Dropbox Phishing via Compromised Wordpress Site
Threatpost
Charlie Miller to Leave Twitter Security Team
AutoIt Used in Targeted Attacks to Move RATs
Exploit
Microsoft Office 2007 OneTableDocumentStream Invalid Object
Microsoft Office 2007 Malformed Document Stack-Based Buffer Overflow
Firefox PDF.js Privileged Javascript Injection
Pligg CMS 2.0.2 - CSRF Add Admin Exploit
WordPress GeoPlaces3 Theme - Arbitrary File Upload Vulnerbility
Mock SMTP Server 1.0 Remote Crash PoC
GOM Audio 2.0.8 - (.gas) Crash POC
Keeper IP Camera 3.2.2.10 - Authentication Bypass
24.8.2015
Bugtraq
Cross site request forgery vulnerability in Linksys WAG120N 2015-08-23
DonVallejo . (j v vallejo gmail com)
[SYSS-2015-025] Netop Remote Control - Insufficiently Protected Credentials 2015-08-24
matthias deeg syss de
Logstash vulnerability CVE-2015-5619 2015-08-21
Suyog Rao (suyog elastic co)
Malware
Phishing
SUPPORT | 24th August 2015 |
Microsoft | 24th August 2015 |
sales | 23rd August 2015 |
Chase Bank | 23rd August 2015 |
USAA | 23rd August 2015 |
Vulnerebility
SANS News
Are You Protecting your "Backdoor" ?
Threatpost
White House Support for CISA Worries Privacy Advocates - See more at: https://threatpost.com/#sthash.N0mq2Ham.dpuf
White House Support for CISA Worries Privacy Advocates
AlienSpy RAT Resurfaces as JSocket
Vulnerabilities Identified in Dolphin, Mercury Android Browsers
Exploit
Easy File Sharing Web Server 6.9 - USERID Remote Buffer Overflow
Easy Address Book Web Server 1.6 - USERID Remote Buffer Overflow
24.8.2015
Bugtraq
Logstash vulnerability CVE-2015-5619 2015-08-21
Suyog Rao (suyog elastic co)
[security bulletin] HPSBUX03410 SSRT102175 rev.1 - HP-UX Running BIND, Remote Denial of Service (DoS) 2015-08-21
security-alert hp com
Re: [SECURITY] [DSA 3325-2] apache2 regression update 2015-08-21
franzskinn gmail com
APPLE-SA-2015-08-20-1 QuickTime 7.7.8 2015-08-20
Apple Product Security (product-security-noreply lists apple com)
Re: Micro Login System v1.0 (userpwd.txt) Password Disclosure Vulnerability 2015-08-20
anonymous yahoo com
[security bulletin] HPSBUX03369 SSRT102037 rev.1 - HP-UX execve(2), Local Elevation of Privilege 2015-08-20
security-alert hp com
[SECURITY] [DSA 3342-1] vlc security update 2015-08-20
Alessandro Ghedini (ghedo debian org)
[oCERT-2015-009] VLC arbitrary pointer dereference 2015-08-20
Andrea Barisani (lcars ocert org)
UBNT Bug Bounty #3 - Persistent Filename Vulnerability 2015-08-20
Vulnerability Lab (research vulnerability-lab com)
UBNT Bug Bounty #1 - Client Side Cross Site Scripting Vulnerability 2015-08-20
Vulnerability Lab (research vulnerability-lab com)
WebSolutions India Design CMS - SQL Injection Vulnerability 2015-08-20
Vulnerability Lab (research vulnerability-lab com)
ChiefPDF Software v2.x - Buffer Overflow Vulnerability 2015-08-20
Vulnerability Lab (research vulnerability-lab com)
PDF Shaper v3.5 - (MSF) Remote Buffer Overflow Vulnerability 2015-08-20
Vulnerability Lab (research vulnerability-lab com)
Malware
Phishing
Chase Bank | 23rd August 2015 |
USAA | 23rd August 2015 |
Lloyds Bank | 22nd August 2015 |
Lloyds | 22nd August 2015 |
Vulnerebility
SSL/TLS RC4 CVE-2015-2808 Information Disclosure Weakness
2015-08-22
http://www.securityfocus.com/bid/73684
Symantec Endpoint Protection Manager CVE-2015-1487 Arbitrary File Write Vulnerability
2015-08-22
http://www.securityfocus.com/bid/76094
Linux Kernel 'perf_callchain_user_64()' Function Denial of Service Vulnerability
2015-08-22
http://www.securityfocus.com/bid/76401
Adobe Flash Player and AIR APSB15-19 Multiple Use After Free Remote Code Execution Vulnerabilities
2015-08-22
http://www.securityfocus.com/bid/76288
Adobe FlashPlayer and AIR APSB15-19 Type Confusion Multiple Remote Code Execution Vulnerabilities
2015-08-22
http://www.securityfocus.com/bid/76287
Microsoft Internet Explorer CVE-2015-2444 Remote Memory Corruption Vulnerability
2015-08-22
http://www.securityfocus.com/bid/76194
IBM WebSphere Application Server CVE-2015-1885 Remote Privilege Escalation Vulnerability
2015-08-22
http://www.securityfocus.com/bid/74219
Mozilla Firefox CVE-2015-4495 Same Origin Policy Security Bypass Vulnerability
2015-08-22
http://www.securityfocus.com/bid/76249
ISC BIND CVE-2015-5477 Remote Denial of Service Vulnerability
2015-08-22
http://www.securityfocus.com/bid/76092
OpenSSL DTLS CVE-2014-8176 Remote Memory Corruption Vulnerability
2015-08-22
http://www.securityfocus.com/bid/75159
OpenSSL CVE-2015-1790 Denial of Service Vulnerability
2015-08-22
http://www.securityfocus.com/bid/75157
OpenSSL CMS CVE-2015-1792 Denial of Service Vulnerability
2015-08-22
http://www.securityfocus.com/bid/75154
Oracle Java SE CVE-2015-4749 Remote Security Vulnerability
2015-08-22
http://www.securityfocus.com/bid/75890
Symantec Endpoint Protection Manager CVE-2015-1489 Remote Privilege Escalation Vulnerability
2015-08-22
http://www.securityfocus.com/bid/76078
OpenSSL CVE-2015-0288 Denial of Service Vulnerability
2015-08-22
http://www.securityfocus.com/bid/73237
OpenSSL 'ASN1_TYPE_cmp()' Function Denial of Service Vulnerability
2015-08-22
http://www.securityfocus.com/bid/73225
OpenSSL 'pk7_doit.c' NULL Pointer Dereference Denial of Service Vulnerability
2015-08-22
http://www.securityfocus.com/bid/73231
OpenSSL CVE-2015-0293 Denial of Service Vulnerability
2015-08-22
http://www.securityfocus.com/bid/73232
Symantec Endpoint Protection Manager CVE-2015-1486 Authentication Bypass Vulnerability
2015-08-22
http://www.securityfocus.com/bid/76074
IBM Security Directory Server CVE-2015-0138 Man in the Middle Security Bypass Vulnerability
2015-08-22
http://www.securityfocus.com/bid/73326
OpenSSL CVE-2015-0204 Man in the Middle Security Bypass Vulnerability
2015-08-22
http://www.securityfocus.com/bid/71936
Apple Mac OS X Multiple Privilege Escalation Vulnerabilities
2015-08-22
http://www.securityfocus.com/bid/76421
Elasticsearch CVE-2015-5377 Remote Code Execution Vulnerability
2015-08-22
http://www.securityfocus.com/bid/75938
Elasticsearch CVE-2015-5531 Directory Traversal Vulnerability
2015-08-22
http://www.securityfocus.com/bid/75935
IBM WebSphere Application Server CVE-2015-1927 Remote Privilege Escalation Vulnerability
2015-08-22
http://www.securityfocus.com/bid/75486
Oracle Java SE CVE-2015-0410 Remote Java SE, Java SE Embedded, JRockit Vulnerability
2015-08-22
http://www.securityfocus.com/bid/72165
Oracle Java SE CVE-2015-0437 Remote Java SE Vulnerability
2015-08-22
http://www.securityfocus.com/bid/72146
Oracle Java SE CVE-2015-0412 Remote Java SE Vulnerability
2015-08-22
http://www.securityfocus.com/bid/72136
Oracle Java SE CVE-2015-0408 Remote Java SE Vulnerability
2015-08-22
http://www.securityfocus.com/bid/72140
Oracle Java SE CVE-2015-0395 Remote Java SE Vulnerability
2015-08-22
http://www.securityfocus.com/bid/72142
SANS News
Threatpost
Exploit
Microsoft Office 2007 wwlib.dll fcPlcfFldMom Uninitialized Heap Usage
Microsoft Office 2007 wwlib.dll Type Confusion
Microsoft Office 2007 OGL.dll DpOutputSpanStretch::OutputSpan Out of Bounds Write
Microsoft Office 2007 MSO.dll Arbitrary Free
Microsoft Office 2007 MSO.dll Use-After-Free
Windows win32k.sys TTF Font Processing win32k!fsc_BLTHoriz Out-of-Bounds Pool Write
Windows win32k.sys TTF Font Processing win32k!fsc_RemoveDups Out-of-Bounds Pool Memory Access
Windows ATMFD.DLL Out-of-Bounds Read Due to Malformed FDSelect Offset in the CFF Table
Windows ATMFD.DLL Out-of-Bounds Read Due to Malformed Name INDEX in the CFF Table
Windows win32k.sys TTF Font Processing win32k!scl_ApplyTranslation Pool-Based Buffer Overflow
Windows win32k.sys TTF Font Processing IUP[] Program Instruction Pool-Based Buffer Overflow
Windows ATMFD.DLL Write to Uninitialized Address Due to Malformed CFF Table
Windows ATMFD.DLL CFF table (ATMFD+0x3440b / ATMFD+0x3440e) Invalid Memory Access
Windows ATMFD.DLL CFF table (ATMFD+0x34072 / ATMFD+0x3407b) Invalid Memory Access
Windows ATMFD.DLL CharString Stream Out-of-Bounds Reads
Microsoft Office 2007 MSPTLS Heap Index Integer Underflow
21.8.2015
Bugtraq
[security bulletin] HPSBUX03369 SSRT102037 rev.1 - HP-UX execve(2), Local Elevation of Privilege 2015-08-20
security-alert hp com
[SECURITY] [DSA 3342-1] vlc security update 2015-08-20
Alessandro Ghedini (ghedo debian org)
[oCERT-2015-009] VLC arbitrary pointer dereference 2015-08-20
Andrea Barisani (lcars ocert org)
UBNT Bug Bounty #3 - Persistent Filename Vulnerability 2015-08-20
Vulnerability Lab (research vulnerability-lab com)
UBNT Bug Bounty #1 - Client Side Cross Site Scripting Vulnerability 2015-08-20
Vulnerability Lab (research vulnerability-lab com)
WebSolutions India Design CMS - SQL Injection Vulnerability 2015-08-20
Vulnerability Lab (research vulnerability-lab com)
Malware
Win32/TrojanDownloader.Small.ACX
Phishing
Microsoft | 21st August 2015 |
HM Revenue & Customs | 21st August 2015 |
@aol.com | 20th August 2015 |
Amazon Support | 20th August 2015 |
Amazon Support | 19th August 2015 |
Vulnerebility
Multiple Zend Products CVE-2015-5161 XML External Entity Injection Vulnerability
2015-08-21
http://www.securityfocus.com/bid/76177
Apache Subversion CVE-2015-0248 Multiple Denial of Service Vulnerabilities
2015-08-21
http://www.securityfocus.com/bid/74260
Apache Subversion CVE-2015-3184 Information Disclosure Vulnerability
2015-08-21
http://www.securityfocus.com/bid/76274
Apache Subversion CVE-2014-8108 Remote Denial of Service Vulnerability
2015-08-21
http://www.securityfocus.com/bid/71725
Apache Subversion CVE-2015-3187 Information Disclosure Vulnerability
2015-08-21
http://www.securityfocus.com/bid/76273
Apache Subversion 'deadprops.c' Security Bypass Vulnerability
2015-08-21
http://www.securityfocus.com/bid/74259
Apache Subversion CVE-2014-3580 Remote Denial of Service Vulnerability
2015-08-21
http://www.securityfocus.com/bid/71726
Oracle Java SE CVE-2015-4749 Remote Security Vulnerability
2015-08-21
http://www.securityfocus.com/bid/75890
Oracle Java SE CVE-2015-2601 Remote Security Vulnerability
2015-08-21
http://www.securityfocus.com/bid/75867
Microsoft Internet Explorer CVE-2015-2444 Remote Memory Corruption Vulnerability
2015-08-21
http://www.securityfocus.com/bid/76194
SSL/TLS RC4 CVE-2015-2808 Information Disclosure Weakness
2015-08-21
http://www.securityfocus.com/bid/73684
Oracle Java SE CVE-2015-2628 Remote Security Vulnerability
2015-08-21
http://www.securityfocus.com/bid/75796
Oracle Java SE CVE-2015-2625 Remote Security Vulnerability
2015-08-21
http://www.securityfocus.com/bid/75895
Oracle Java SE CVE-2015-2621 Remote Security Vulnerability
2015-08-21
http://www.securityfocus.com/bid/75874
Oracle Java SE CVE-2015-2613 Remote Security Vulnerability
2015-08-21
http://www.securityfocus.com/bid/75871
SSL/TLS LogJam Man in the Middle Security Bypass Vulnerability
2015-08-21
http://www.securityfocus.com/bid/74733
Oracle Java SE CVE-2015-2590 Remote Security Vulnerability
2015-08-21
http://www.securityfocus.com/bid/75818
Oracle Java SE CVE-2015-4732 Remote Security Vulnerability
2015-08-21
http://www.securityfocus.com/bid/75823
Oracle Java SE CVE-2015-4748 Remote Security Vulnerability
2015-08-21
http://www.securityfocus.com/bid/75854
Oracle Java SE CVE-2015-2632 Remote Security Vulnerability
2015-08-21
http://www.securityfocus.com/bid/75861
Oracle Java SE CVE-2015-4733 Remote Security Vulnerability
2015-08-21
http://www.securityfocus.com/bid/75832
Oracle Java SE CVE-2015-4731 Remote Security Vulnerability
2015-08-21
http://www.securityfocus.com/bid/75812
Oracle Java SE CVE-2015-4760 Remote Security Vulnerability
2015-08-21
http://www.securityfocus.com/bid/75784
WordPress WP OAuth Server Plugin Multiple Predictable Random Number Generator Weaknesses
2015-08-21
http://www.securityfocus.com/bid/76363
Linux Kernel CVE-2015-3212 Local Security Bypass Vulnerability
2015-08-21
http://www.securityfocus.com/bid/76082
ISC BIND CVE-2015-5477 Remote Denial of Service Vulnerability
2015-08-21
http://www.securityfocus.com/bid/76092
ISC BIND CVE-2014-8500 Remote Denial of Service Vulnerability
2015-08-21
http://www.securityfocus.com/bid/71590
Huawei Mate 7 Smartphone Multiple Local Privilege Escalation Vulnerabilities
2015-08-21
http://www.securityfocus.com/bid/74742
Oracle MySQL Server CVE-2015-4752 Remote Security Vulnerability
2015-08-21
http://www.securityfocus.com/bid/75849
Oracle MySQL Server CVE-2015-2620 Remote Security Vulnerability
2015-08-21
http://www.securityfocus.com/bid/75837
SANS News
A recent decline in traffic associated with Operation Windigo
Threatpost
Uptick in Neutrino Exploit Kit Traffic Doesnt Mean Angler Reign Over
Details Surface on Patched Sandbox Violation Vulnerability in iOS
Facebook Updates Information-Sharing Platform
Exploit
WordPress MDC Private Message Plugin 1.0.0 - Persistent XSS
Valhala Honeypot 1.8 - Stack-Based Buffer Overflow
Win2003 x64 - Token Stealing shellcode - 59 bytes
20.8.2015
Bugtraq
[security bulletin] HPSBUX03400 SSRT102211 rev.1 - HP-UX Running BIND, Remote Denial of Service (DoS) 2015-08-19
security-alert hp com
CVE-2015-3269 Apache Flex BlazeDS Insecure Xml Entity Expansion Vulnerability 2015-08-19
Christofer Dutz (cdutz apache org)
Privilege escalation through RPC commands in EMC Documentum Content Server (incomplete fix in CVE-2015-4532) 2015-08-19
andrew panfilov tel
Re: CORE-2009-01515 - WordPress Privileges Unchecked in admin.php and Multiple Information 2015-08-19
Asher995 gmail com (2 replies)
Re: CORE-2009-01515 - WordPress Privileges Unchecked in admin.php and Multiple Information 2015-08-19
paul szabo sydney edu au
RE: CORE-2009-01515 - WordPress Privileges Unchecked in admin.php and Multiple Information 2015-08-19
Chillman, Paul, Vodafone UK (Paul Chillman vodafone com)
[SYSS-2015-041] XSS in OpenText Secure MFT 2015-08-19
adrian vollmer syss de
Malware
Phishing
Amazon Support | 20th August 2015 |
Amazon Support | 19th August 2015 |
PayPal Inc | 19th August 2015 |
[PAYPAL VERIFICATION] œ LAST |
Vulnerebility
Linux Kernel CVE-2015-3212 Local Security Bypass Vulnerability
2015-08-20
http://www.securityfocus.com/bid/76082
ISC BIND CVE-2015-5477 Remote Denial of Service Vulnerability
2015-08-20
http://www.securityfocus.com/bid/76092
ISC BIND CVE-2014-8500 Remote Denial of Service Vulnerability
2015-08-20
http://www.securityfocus.com/bid/71590
Huawei Mate 7 Smartphone Multiple Local Privilege Escalation Vulnerabilities
2015-08-20
http://www.securityfocus.com/bid/74742
Oracle MySQL Server CVE-2015-4752 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/75849
Oracle MySQL Server CVE-2015-2620 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/75837
Oracle MySQL Server CVE-2015-4737 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/75802
Oracle MySQL Server CVE-2015-2643 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/75830
Oracle MySQL Server CVE-2015-2648 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/75822
Oracle MySQL Server CVE-2015-0433 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/74089
Oracle MySQL Server CVE-2015-0505 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/74112
Oracle MySQL Server CVE-2015-0441 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/74103
Oracle MySQL Server CVE-2015-4757 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/75759
Oracle MySQL Server CVE-2015-0432 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/72217
Oracle MySQL Server CVE-2015-0499 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/74115
Oracle MySQL Server CVE-2015-2582 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/75751
Oracle MySQL Server CVE-2014-6568 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/72210
Oracle MySQL Server CVE-2015-0411 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/72191
Oracle MySQL Server CVE-2015-0381 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/72214
Oracle MySQL Server CVE-2015-2571 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/74095
Oracle MySQL Server CVE-2015-0391 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/72205
Oracle MySQL Server CVE-2015-2568 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/74073
Oracle MySQL Server CVE-2015-2573 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/74078
Oracle MySQL Server CVE-2015-0374 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/72227
Oracle MySQL Server CVE-2015-0382 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/72200
Oracle MySQL Server CVE-2015-0501 Remote Security Vulnerability
2015-08-20
http://www.securityfocus.com/bid/74070
Drupal Acquia Cloud Site Factory Connector Module Open Redirection Vulnerability
2015-08-20
http://www.securityfocus.com/bid/75280
Drupal LABjs Module Open Redirection Vulnerability
2015-08-20
http://www.securityfocus.com/bid/75279
Drupal Shibboleth authentication Module Cross Site Scripting Vulnerability
2015-08-20
http://www.securityfocus.com/bid/75410
Drupal HybridAuth Social Login Module Access Bypass Vulnerability
2015-08-20
http://www.securityfocus.com/bid/75412
SANS News
Actor using Angler exploit kit switched to Neutrino
Threatpost
Holes Patched in Online Bookmarking App Pocket
Web.com Loses 93,000 Credit Card Numbers in Breach
Inside the Unpatched OS X Vulnerabilities
Exploit
Aruba Mobility Controller 6.4.2.8 - Multiple vulnerabilities
Vifi Radio v1 - CSRF Vulnerability
up.time 7.5.0 Superadmin Privilege Escalation Exploit
up.time 7.5.0 XSS And CSRF Add Admin Exploit
up.time 7.5.0 Arbitrary File Disclose And Delete Exploit
up.time 7.5.0 Upload And Execute File Exploit
19.8.2015
Bugtraq
[SYSS-2015-041] XSS in OpenText Secure MFT 2015-08-19
adrian vollmer syss de
Trend Micro Deep Discovery XSS 2015-08-19
apparitionsec gmail com
Trend Micro Deep Discovery Authentication Bypass 2015-08-19
apparitionsec gmail com
Re: Hawkeye-G v3 CSRF Vulnerability ***[UPDATED CORRECTED] 2015-08-18
aabbccdd05407 gmail com
CVE-2015-5699 - Cumulus Linux's Switch Configuration Tools Backend, clcmd_server, Vulnerable to Local Privilege Escalation 2015-08-18
Gregory Pickett (gpickett71 yahoo com)
FreeBSD Security Advisory FreeBSD-SA-15:20.expat 2015-08-18
FreeBSD Security Advisories (security-advisories freebsd org)
[SECURITY] [DSA 3338-1] python-django security update 2015-08-18
Alessandro Ghedini (ghedo debian org)
Malware
TrojanDownloader:Win32/Upatre.BR
TrojanDownloader:MSIL/Torwofun.B
PWS:Win32/QQpass.GR
PWS:MSIL/Facepass.A
SoftwareBundler:Win32/Bestof
PWS:O97M/Wipha.A
Phishing
admin email | 19th August 2015 |
Lisa | 18th August 2015 |
285$ | 18th August 2015 |
Tesco Bank | 18th August 2015 |
Tracy Allen | 18th August 2015 |
Natwest | 18th August 2015 |
Mail Administrator | 18th August 2015 |
Arlene Horton | 18th August 2015 |
Unlimited | 18th August 2015 |
FRESH TOOLS / ONLINE LIVE | |
Apple | 18th August 2015 |
YOUR APPLE ID WAS USED TO SIGN |
Vulnerebility
Oracle MySQL Server CVE-2015-0381 Remote Security Vulnerability
2015-08-19
http://www.securityfocus.com/bid/72214
Oracle MySQL Server CVE-2015-0411 Remote Security Vulnerability
2015-08-19
http://www.securityfocus.com/bid/72191
Oracle MySQL Server CVE-2015-0391 Remote Security Vulnerability
2015-08-19
http://www.securityfocus.com/bid/72205
Oracle MySQL Server CVE-2015-0382 Remote Security Vulnerability
2015-08-19
http://www.securityfocus.com/bid/72200
Adobe Flash Player and AIR CVE-2015-5560 Unspecified Integer Overflow Vulnerability
2015-08-19
http://www.securityfocus.com/bid/76289
Adobe FlashPlayer and AIR APSB15-19 Type Confusion Multiple Remote Code Execution Vulnerabilities
2015-08-19
http://www.securityfocus.com/bid/76287
Adobe Flash Player and AIR APSB15-19 Multiple Use After Free Remote Code Execution Vulnerabilities
2015-08-19
http://www.securityfocus.com/bid/76288
Adobe Flash Player and AIR APSB15-19 Multiple Memroy Corruption Vulnerabilities
2015-08-19
http://www.securityfocus.com/bid/76291
Oracle MySQL Server CVE-2014-6568 Remote Security Vulnerability
2015-08-19
http://www.securityfocus.com/bid/72210
Adobe Flash Player and AIR CVE-2015-5124 Unspecified Memory Corruption Vulnerability
2015-08-19
http://www.securityfocus.com/bid/75959
Adobe Flash Player and AIR Multiple Unspecified Remote Code Execution Vulnerabilities
2015-08-19
http://www.securityfocus.com/bid/75087
Adobe FlashPlayer and AIR APSB15-19 Multiple Unspecified Heap Buffer Overflow Vulnerabilities
2015-08-19
http://www.securityfocus.com/bid/76282
Adobe Flash Player ActionScript 3 BitmapData Use After Free Remote Memory Corruption Vulnerability
2015-08-19
http://www.securityfocus.com/bid/75710
Adobe Flash Player CVE-2015-5122 Use After Free Remote Memory Corruption Vulnerability
2015-08-19
http://www.securityfocus.com/bid/75712
OpenSSH Login Handling Security Bypass Weakness
2015-08-19
http://www.securityfocus.com/bid/75990
OpenSSH 'x11_open_helper()' Function Security Bypass Vulnerability
2015-08-19
http://www.securityfocus.com/bid/75525
Net-SNMP snmptrapd CVE-2014-3565 Remote Denial of Service Vulnerability
2015-08-19
http://www.securityfocus.com/bid/69477
Fortinet FortiOS SSL-VPN Man in The Middle Security Bypass Vulnerability
2015-08-19
http://www.securityfocus.com/bid/76065
Linux Kernel 'get_bitmap_file()' Function Local Information Disclosure Vulnerability
2015-08-19
http://www.securityfocus.com/bid/76066
GNU glibc 'getaddrinfo.c' Remote Code Execution Vulnerability
2015-08-19
http://www.securityfocus.com/bid/72710
Linux Kernel Multiple Remote Denial of Service Vulnerability
2015-08-19
http://www.securityfocus.com/bid/75510
Mozilla Firefox CVE-2015-4492 Use After Free Memory Corruption Vulnerability
2015-08-19
http://www.securityfocus.com/bid/76297
Mozilla Firefox Out of Bounds Multiple Memory Corruption Vulnerabilities
2015-08-19
http://www.securityfocus.com/bid/76294
Mozilla Firefox CVE-2015-4495 Same Origin Policy Security Bypass Vulnerability
2015-08-19
http://www.securityfocus.com/bid/76249
Icecast Remote Denial of Service Vulnerability
2015-08-19
http://www.securityfocus.com/bid/73965
libgadu CVE-2014-3775 Memory Corruption Vulnerability
2015-08-19
http://www.securityfocus.com/bid/67471
Pidgin 'gg_http_watch_fd()' Function Buffer Overflow Vulnerability
2015-08-19
http://www.securityfocus.com/bid/65188
libgadu SSL Certificate Validation CVE-2013-4488 Security Bypass Vulnerability
2015-08-19
http://www.securityfocus.com/bid/63473
SQLite Versions Prior to 3.8.9 Multiple Security Vulnerabilities
2015-08-19
http://www.securityfocus.com/bid/74228
Apache Subversion CVE-2015-3187 Information Disclosure Vulnerability
2015-08-19
http://www.securityfocus.com/bid/76273
SANS News
Microsoft Security Bulletin MS15-093 - Critical OOB - Internet Explorer RCE
Threatpost
Emergency IE Patch Fixes Vulnerability Under Attack
IRS Hack May Implicate Three Times As Many Taxpayers Than Expected
Apple Zero Day Remains Unpatched
Core Infrastructure Initiative Launches Open Source Security Badge Program
Adobe Patches XXE Vulnerability in LiveCycle Data Services
Exploit
Flash Broker-Based Sandbox Escape via Forward Slash Instead of Backslash
Flash Broker-Based Sandbox Escape via Unexpected Directory Lock
Flash Broker-Based Sandbox Escape via Timing Attack Against File Moving
Flash Boundless Tunes - Universal SOP Bypass Through ActionSctipt's Sound Object
Flash PCRE Regex Compilation Zero-Length Assertion Arbitrary Bytecode Execution
Flash Player Integer Overflow in Function.apply
Flash AVSS.setSubscribedTags Use After Free Memory Corruption
Flash Uninitialized Stack Variable MPD Parsing Memory Corruption
Flash Issues in DefineBitsLossless and DefineBitsLossless2 Leads to Using Uninitialized Memory
Flash AS2 Use After Free in TextField.filters
Flash AS2 Use After Free While Setting TextField.filters
Flash Use-After-Free in Display List Handling
Flash Use-After-Free in NetConnection.connect
Adobe Flash Use-After-Free When Setting Variable
Flash AS2 Use After Free in DisplacementMapFilter.mapBitmap
Flash Use-After-Free with MovieClip.scrollRect in AS2
Adobe Flash Use-After-Free When Setting Value
Adobe Flash Out-of-Bounds Memory Read While Parsing a Mutated SWF File
Adobe Flash Out-of-Bounds Memory Read While Parsing a Mutated SWF File (2)
Adobe Flash Out-of-Bounds Memory Read While Parsing a Mutated TTF File Embedded in SWF
Adobe Flash Use-After-Free in XML.childNodes
Easy File Management Web Server 5.6 - USERID Remote Buffer Overflow
FTP Commander 8.02 - SEH Overwrite
OS X 10.10.5 - XNU Local Privilege Escalation
18.8.2015
Bugtraq
Re: [SECURITY] [DSA 3336-1] nss security update 2015-08-17
miguelmellolopes gmail com
EMC Documentum Content Server: arbitrary code execution (incomplete fix in CVE-2015-4532) 2015-08-17
andrew panfilov tel
[SECURITY] [DSA 3336-1] nss security update 2015-08-17
Salvatore Bonaccorso (carnil debian org)
sysadmin privilege in EMC Documentum Content Server 2015-08-17
andrew panfilov tel
Insufficient certificate validation in EMC Secure Remote Services Virtual Edition 2015-08-17
Securify B.V. (lists securify nl)
Weak authentication in EMC Secure Remote Services Virtual Edition Web Portal 2015-08-17
Securify B.V. (lists securify nl)
[ERPSCAN-15-013] SAP NetWeaver AS Java CIM UPLOAD ?? XXE 2015-08-17
ERPScan inc (erpscan online gmail com)
[ERPSCAN-15-012] SAP Afaria 7 XComms ?? Buffer Overflow 2015-08-17
ERPScan inc (erpscan online gmail com)
ESA-2015-130: EMC Documentum WebTop and WebTop Clients Cross-Site Request Forgery Vulnerability 2015-08-17
Security Alert (Security_Alert emc com)
ESA-2015-131: EMC Documentum Content Server Multiple Vulnerabilities 2015-08-17
Security Alert (Security_Alert emc com)
Malware
PWS:O97M/Wipha.A
PWS:Win32/Wipha.A
TrojanDownloader:Win32/Tembatch.B
Exploit:VBS/CVE-2014-6332
Exploit:SWF/CVE-2014-6332
Phishing
Barclays | 18th August 2015 |
TalkTalk | 17th August 2015 |
The payment for your latest | |
NEWF#CKFRIEND | 17th August 2015 |
6367$ | 17th August 2015 |
No need to stay awake all |
Vulnerebility
Linux Kernel 'get_bitmap_file()' Function Local Information Disclosure Vulnerability
2015-08-18
http://www.securityfocus.com/bid/76066
GNU glibc 'getaddrinfo.c' Remote Code Execution Vulnerability
2015-08-18
http://www.securityfocus.com/bid/72710
Linux Kernel Multiple Remote Denial of Service Vulnerability
2015-08-18
http://www.securityfocus.com/bid/75510
Mozilla Firefox CVE-2015-4492 Use After Free Memory Corruption Vulnerability
2015-08-18
http://www.securityfocus.com/bid/76297
Mozilla Firefox Out of Bounds Multiple Memory Corruption Vulnerabilities
2015-08-18
http://www.securityfocus.com/bid/76294
Mozilla Firefox CVE-2015-4495 Same Origin Policy Security Bypass Vulnerability
2015-08-18
http://www.securityfocus.com/bid/76249
Icecast Remote Denial of Service Vulnerability
2015-08-18
http://www.securityfocus.com/bid/73965
libgadu CVE-2014-3775 Memory Corruption Vulnerability
2015-08-18
http://www.securityfocus.com/bid/67471
Pidgin 'gg_http_watch_fd()' Function Buffer Overflow Vulnerability
2015-08-18
http://www.securityfocus.com/bid/65188
libgadu SSL Certificate Validation CVE-2013-4488 Security Bypass Vulnerability
2015-08-18
http://www.securityfocus.com/bid/63473
SQLite Versions Prior to 3.8.9 Multiple Security Vulnerabilities
2015-08-18
http://www.securityfocus.com/bid/74228
Apache Subversion CVE-2015-3187 Information Disclosure Vulnerability
2015-08-18
http://www.securityfocus.com/bid/76273
Apache Subversion 'deadprops.c' Security Bypass Vulnerability
2015-08-18
http://www.securityfocus.com/bid/74259
Apache Subversion CVE-2015-0248 Multiple Denial of Service Vulnerabilities
2015-08-18
http://www.securityfocus.com/bid/74260
IBM Domino Remote Cross Site Scripting Vulnerability
2015-08-18
http://www.securityfocus.com/bid/74908
Oracle Java SE CVE-2014-6593 Remote Java SE, Java SE Embedded, JRockit Vulnerability
2015-08-18
http://www.securityfocus.com/bid/72169
Linux Kernel 'x86/entry/entry_64.S' Local Privilege Escalation Vulnerability
2015-08-18
http://www.securityfocus.com/bid/76004
Linux Kernel CVE-2015-3212 Local Security Bypass Vulnerability
2015-08-18
http://www.securityfocus.com/bid/76082
Linux Kernel CVE-2014-9731 Local Information Disclosure Vulnerability
2015-08-18
http://www.securityfocus.com/bid/75001
Linux Kernel KVM 'kvm_apic_has_events()' Function Denial of Service Vulnerability
2015-08-18
http://www.securityfocus.com/bid/75142
Linux Kernel '/arch/x86/net/bpf_jit_comp.c' CVE-2015-4700 Local Denial of Service Vulnerability
2015-08-18
http://www.securityfocus.com/bid/75356
Linux Kernel UDF File System Multiple Local Denial of Service Vulnerabilities
2015-08-18
http://www.securityfocus.com/bid/74964
Linux Kernel 'ozwpan' Driver Multiple Heap Buffer Overflow Vulnerabilities
2015-08-18
http://www.securityfocus.com/bid/74672
Linux Kernel 'vhost/scsi.c' Local Memory Corruption Vulnerability
2015-08-18
http://www.securityfocus.com/bid/74664
Linux Kernel 'ozwpan' Driver Multiple Denial of Service Vulnerabilities
2015-08-18
http://www.securityfocus.com/bid/74668
Linux Kernel 'fs/udf/inode.c' Denial of Service Vulnerability
2015-08-18
http://www.securityfocus.com/bid/74963
Linux Kernel CVE-2015-3636 Local Privilege Escalation Vulnerability
2015-08-18
http://www.securityfocus.com/bid/74450
Linux Kernel 'fs/fhandle.c' Local Race Condition Vulnerability
2015-08-18
http://www.securityfocus.com/bid/72357
Linux Kernel 'sk_dst_get()' Denial of Service Vulnerability
2015-08-18
http://www.securityfocus.com/bid/72435
Linux Kernel CVE-2015-2922 Denial of Service Vulnerability
2015-08-18
http://www.securityfocus.com/bid/74315
SANS News
Tool Tip: Kansa Stafford released, PowerShell for DFIR
Threatpost
Risky Schneider Electric SCADA Vulnerabilities Remain Unpatched
Exploit
Risky Schneider Electric SCADA Vulnerabilities Remain Unpatched - See more at: https://threatpost.com/#sthash.fuC1gXrv.dpuf
Risky Schneider Electric SCADA Vulnerabilities Remain Unpatched
Uber to Quadruple Security Staff by 2016
Werkzeug Debug Shell Command Execution
Symantec Endpoint Protection Manager Authentication Bypass and Code Execution
VideoCharge Studio Buffer Overflow (SEH)
FTP Commander 8.02 - SEH Overwrite
Cisco Unified Communications Manager - Multiple Vulnerabilities
vBulletin < 4.2.2 - Memcache Remote Code Execution
Nuts CMS Remote PHP Code Injection / Execution
Magento CE < 1.9.0.1 Post Auth RCE
PHPfileNavigator 2.3.3 - XSS Vulnerabilities
PHPfileNavigator 2.3.3 - CSRF Vulnerability
Sagemcom F@ST 3864 V2 - Get Admin Password
17.8.2015
Bugtraq
Poor security in SOHO routers, again. Changing configuration parameters with a click. 2015-08-17
DonVallejo . (j v vallejo gmail com)
Re: Multiple vulnerabilites in vendor IKE implementations, including Cisco, 2015-08-16
arash yazdanfare gmail com
Re: NEW : VMSA-2015-0003 VMware product updates address critical information disclosure issue in JRE 2015-08-16
13669185678 139 com
Malware
PWS:Win32/Rugond.A
TrojanDropper:Win32/Notdinoti.B
TrojanDropper:Win32/Strakupa.A
TrojanSpy:Win32/Gucotut.A
TrojanDownloader:Win32/Lentrigy.A
TrojanDownloader:MSIL/Runtk.A
Backdoor:Win32/Venik.K
Phishing
FindMeAndF#ckMe | 17th August 2015 |
PayPal | 17th August 2015 |
ROCKSTAR SERVER | 15th August 2015 |
Vulnerebility
OpenSSL CVE-2015-1791 Race Condition Security Vulnerability
2015-08-17
http://www.securityfocus.com/bid/75161
OpenSSL CVE-2015-1790 Denial of Service Vulnerability
2015-08-17
http://www.securityfocus.com/bid/75157
cURL/libcURL 'fix_hostname()' Function Denial of Service Vulnerability
2015-08-17
http://www.securityfocus.com/bid/74300
Todd Miller Sudo 'validate_env_vars()' Local Privilege Escalation Vulnerability
2015-08-17
http://www.securityfocus.com/bid/65997
Todd Miller Sudo CVE-2014-9680 Local Security Bypass Vulnerability
2015-08-17
http://www.securityfocus.com/bid/72649
GNU Troff pdfroff Insecure Temporary File Creation and Arbitrary File Access Vulnerabilities
2015-08-17
http://www.securityfocus.com/bid/36381
tcpdump 'olsr_print()' Function Denial of Service Vulnerability
2015-08-17
http://www.securityfocus.com/bid/71150
tcpdump CVE-2014-8769 Out-of-bounds Memory Access Vulnerability
2015-08-17
http://www.securityfocus.com/bid/71153
Todd Miller Sudo CVE-2013-1775 Local Authentication Bypass Vulnerability
2015-08-17
http://www.securityfocus.com/bid/58203
Todd Miller Sudo CVE-2013-2776 Local Security Bypass Vulnerability
2015-08-17
http://www.securityfocus.com/bid/62741
Python 'ZipExtFile._read2()' Method Denial of Service Vulnerability
2015-08-17
http://www.securityfocus.com/bid/65179
Python 'sock_recvfrom_into()' Function Buffer Overflow Vulnerability
2015-08-17
http://www.securityfocus.com/bid/65379
BSD mailx CVE-2014-7844 Local Arbitrary Command Execution Vulnerability
2015-08-17
http://www.securityfocus.com/bid/71701
Perl CVE-2013-7422 Denial of Service Vulnerability
2015-08-17
http://www.securityfocus.com/bid/75704
Python CVE-2014-9365 TLS Certificate Validation Security Bypass Vulnerability
2015-08-17
http://www.securityfocus.com/bid/71639
cURL/libcURL CVE-2015-3145 Out of Bounds Read Denial of Service Vulnerability
2015-08-17
http://www.securityfocus.com/bid/74303
cURL/libcURL 'curl_easy_duphandle()' Function Heap Memory Corruption Vulnerability
2015-08-17
http://www.securityfocus.com/bid/70988
cURL/libcURL CVE-2015-3148 Remote Security Bypass Vulnerability
2015-08-17
http://www.securityfocus.com/bid/74301
cURL/libcURL CVE-2015-3153 Information Disclosure Vulnerability
2015-08-17
http://www.securityfocus.com/bid/74408
cURL/libcURL CVE-2014-3620 Cookies Handling Remote Security Bypass Vulnerability
2015-08-17
http://www.securityfocus.com/bid/69742
cURL/libcURL CVE-2014-8150 Remote Security Bypass Vulnerability
2015-08-17
http://www.securityfocus.com/bid/71964
Todd Miller Sudo CVE-2013-1776 Local Security Bypass Vulnerability
2015-08-17
http://www.securityfocus.com/bid/58207
tcpdump CVE-2014-9140 Buffer Overflow Vulnerability
2015-08-17
http://www.securityfocus.com/bid/71468
cURL/libcURL CVE-2014-3613 Remote Security Bypass Vulnerability
2015-08-17
http://www.securityfocus.com/bid/69748
cURL/libcURL NTLM connection CVE-2015-3143 Remote Security Bypass Vulnerability
2015-08-17
http://www.securityfocus.com/bid/74299
PostgreSQL CVE-2014-8161 Information Disclosure Vulnerability
2015-08-17
http://www.securityfocus.com/bid/72538
OpenSSL CVE-2015-1788 Denial of Service Vulnerability
2015-08-17
http://www.securityfocus.com/bid/75158
OpenSSL CVE-2015-1789 Out of Bounds Read Denial of Service Vulnerability
2015-08-17
http://www.securityfocus.com/bid/75156
PostgreSQL CVE-2015-0244 Security Bypass Vulnerability
2015-08-17
http://www.securityfocus.com/bid/72543
PostgreSQL 'to_char()' Function Buffer Overflow Vulnerability
2015-08-17
http://www.securityfocus.com/bid/72540
SANS News
Tool Tip: Kansa Stafford released, PowerShell for DFIR
Threatpost
Apple Patches Critical OS X DYLD Flaw in Monster Update - See more at: https://threatpost.com/#sthash.1zChwKF7.dpuf
Apple Patches Critical OS X DYLD Flaw in Monster Update - See more at: https://threatpost.com/#sthash.1zChwKF7.dpuf
AT&T Facilitated NSA Surveillance Efforts, Reports
Using BitTorrent Vulnerabilities to Launch Distributed Reflective DoS Attacks
Exploit
Microsoft Windows HTA (HTML Application) - Remote Code Execution (MS14-064)
Sagemcom F@ST 3864 V2 - Get Admin Password
MASM321 11 Quick Editor (.qeditor) 4.0g- .qse SEH Based Buffer Overflow (ASLR & SAFESEH bypass)
XMPlay 3.8.1.12 - .pls Local Crash PoC
16.8.2015
Bugtraq
Malware
Phishing
ROCKSTAR SERVER | 15th August 2015 |
PayPal | 15th August 2015 |
Apple Inc. | 15th August 2015 |
Vulnerebility
OpenSSL CVE-2015-1791 Race Condition Security Vulnerability
2015-08-16
http://www.securityfocus.com/bid/75161
OpenSSL CVE-2015-1790 Denial of Service Vulnerability
2015-08-16
http://www.securityfocus.com/bid/75157
cURL/libcURL 'fix_hostname()' Function Denial of Service Vulnerability
2015-08-16
http://www.securityfocus.com/bid/74300
Todd Miller Sudo 'validate_env_vars()' Local Privilege Escalation Vulnerability
2015-08-16
http://www.securityfocus.com/bid/65997
Todd Miller Sudo CVE-2014-9680 Local Security Bypass Vulnerability
2015-08-16
http://www.securityfocus.com/bid/72649
GNU Troff pdfroff Insecure Temporary File Creation and Arbitrary File Access Vulnerabilities
2015-08-16
http://www.securityfocus.com/bid/36381
tcpdump 'olsr_print()' Function Denial of Service Vulnerability
2015-08-16
http://www.securityfocus.com/bid/71150
tcpdump CVE-2014-8769 Out-of-bounds Memory Access Vulnerability
2015-08-16
http://www.securityfocus.com/bid/71153
Todd Miller Sudo CVE-2013-1775 Local Authentication Bypass Vulnerability
2015-08-16
http://www.securityfocus.com/bid/58203
Todd Miller Sudo CVE-2013-2776 Local Security Bypass Vulnerability
2015-08-16
http://www.securityfocus.com/bid/62741
Python 'ZipExtFile._read2()' Method Denial of Service Vulnerability
2015-08-16
http://www.securityfocus.com/bid/65179
Python 'sock_recvfrom_into()' Function Buffer Overflow Vulnerability
2015-08-16
http://www.securityfocus.com/bid/65379
BSD mailx CVE-2014-7844 Local Arbitrary Command Execution Vulnerability
2015-08-16
http://www.securityfocus.com/bid/71701
Perl CVE-2013-7422 Denial of Service Vulnerability
2015-08-16
http://www.securityfocus.com/bid/75704
Python CVE-2014-9365 TLS Certificate Validation Security Bypass Vulnerability
2015-08-16
http://www.securityfocus.com/bid/71639
cURL/libcURL CVE-2015-3145 Out of Bounds Read Denial of Service Vulnerability
2015-08-16
http://www.securityfocus.com/bid/74303
cURL/libcURL 'curl_easy_duphandle()' Function Heap Memory Corruption Vulnerability
2015-08-16
http://www.securityfocus.com/bid/70988
cURL/libcURL CVE-2015-3148 Remote Security Bypass Vulnerability
2015-08-16
http://www.securityfocus.com/bid/74301
cURL/libcURL CVE-2015-3153 Information Disclosure Vulnerability
2015-08-16
http://www.securityfocus.com/bid/74408
cURL/libcURL CVE-2014-3620 Cookies Handling Remote Security Bypass Vulnerability
2015-08-16
http://www.securityfocus.com/bid/69742
cURL/libcURL CVE-2014-8150 Remote Security Bypass Vulnerability
2015-08-16
http://www.securityfocus.com/bid/71964
Todd Miller Sudo CVE-2013-1776 Local Security Bypass Vulnerability
2015-08-16
http://www.securityfocus.com/bid/58207
tcpdump CVE-2014-9140 Buffer Overflow Vulnerability
2015-08-16
http://www.securityfocus.com/bid/71468
cURL/libcURL CVE-2014-3613 Remote Security Bypass Vulnerability
2015-08-16
http://www.securityfocus.com/bid/69748
cURL/libcURL NTLM connection CVE-2015-3143 Remote Security Bypass Vulnerability
2015-08-16
http://www.securityfocus.com/bid/74299
PostgreSQL CVE-2014-8161 Information Disclosure Vulnerability
2015-08-16
http://www.securityfocus.com/bid/72538
OpenSSL CVE-2015-1788 Denial of Service Vulnerability
2015-08-16
http://www.securityfocus.com/bid/75158
OpenSSL CVE-2015-1789 Out of Bounds Read Denial of Service Vulnerability
2015-08-16
http://www.securityfocus.com/bid/75156
PostgreSQL CVE-2015-0244 Security Bypass Vulnerability
2015-08-16
http://www.securityfocus.com/bid/72543
PostgreSQL 'to_char()' Function Buffer Overflow Vulnerability
2015-08-16
http://www.securityfocus.com/bid/72540
SANS News
Threatpost
Apple Patches Critical OS X DYLD Flaw in Monster Update
Exploit
15.8.2015
Bugtraq
Malware
Phishing
Apple Inc. | 15th August 2015 |
webmaster | 14th August 2015 |
EMail from Easy Biz (EARN $500 | |
Ashley Johnston | 14th August 2015 |
Vulnerebility
OpenSSL CVE-2015-1791 Race Condition Security Vulnerability
2015-08-15
http://www.securityfocus.com/bid/75161
OpenSSL CVE-2015-1790 Denial of Service Vulnerability
2015-08-15
http://www.securityfocus.com/bid/75157
cURL/libcURL 'fix_hostname()' Function Denial of Service Vulnerability
2015-08-15
http://www.securityfocus.com/bid/74300
Todd Miller Sudo 'validate_env_vars()' Local Privilege Escalation Vulnerability
2015-08-15
http://www.securityfocus.com/bid/65997
Todd Miller Sudo CVE-2014-9680 Local Security Bypass Vulnerability
2015-08-15
http://www.securityfocus.com/bid/72649
GNU Troff pdfroff Insecure Temporary File Creation and Arbitrary File Access Vulnerabilities
2015-08-15
http://www.securityfocus.com/bid/36381
tcpdump 'olsr_print()' Function Denial of Service Vulnerability
2015-08-15
http://www.securityfocus.com/bid/71150
tcpdump CVE-2014-8769 Out-of-bounds Memory Access Vulnerability
2015-08-15
http://www.securityfocus.com/bid/71153
Todd Miller Sudo CVE-2013-1775 Local Authentication Bypass Vulnerability
2015-08-15
http://www.securityfocus.com/bid/58203
Todd Miller Sudo CVE-2013-2776 Local Security Bypass Vulnerability
2015-08-15
http://www.securityfocus.com/bid/62741
Python 'ZipExtFile._read2()' Method Denial of Service Vulnerability
2015-08-15
http://www.securityfocus.com/bid/65179
Python 'sock_recvfrom_into()' Function Buffer Overflow Vulnerability
2015-08-15
http://www.securityfocus.com/bid/65379
BSD mailx CVE-2014-7844 Local Arbitrary Command Execution Vulnerability
2015-08-15
http://www.securityfocus.com/bid/71701
Perl CVE-2013-7422 Denial of Service Vulnerability
2015-08-15
http://www.securityfocus.com/bid/75704
Python CVE-2014-9365 TLS Certificate Validation Security Bypass Vulnerability
2015-08-15
http://www.securityfocus.com/bid/71639
cURL/libcURL CVE-2015-3145 Out of Bounds Read Denial of Service Vulnerability
2015-08-15
http://www.securityfocus.com/bid/74303
cURL/libcURL 'curl_easy_duphandle()' Function Heap Memory Corruption Vulnerability
2015-08-15
http://www.securityfocus.com/bid/70988
cURL/libcURL CVE-2015-3148 Remote Security Bypass Vulnerability
2015-08-15
http://www.securityfocus.com/bid/74301
cURL/libcURL CVE-2015-3153 Information Disclosure Vulnerability
2015-08-15
http://www.securityfocus.com/bid/74408
cURL/libcURL CVE-2014-3620 Cookies Handling Remote Security Bypass Vulnerability
2015-08-15
http://www.securityfocus.com/bid/69742
cURL/libcURL CVE-2014-8150 Remote Security Bypass Vulnerability
2015-08-15
http://www.securityfocus.com/bid/71964
Todd Miller Sudo CVE-2013-1776 Local Security Bypass Vulnerability
2015-08-15
http://www.securityfocus.com/bid/58207
tcpdump CVE-2014-9140 Buffer Overflow Vulnerability
2015-08-15
http://www.securityfocus.com/bid/71468
cURL/libcURL CVE-2014-3613 Remote Security Bypass Vulnerability
2015-08-15
http://www.securityfocus.com/bid/69748
cURL/libcURL NTLM connection CVE-2015-3143 Remote Security Bypass Vulnerability
2015-08-15
http://www.securityfocus.com/bid/74299
PostgreSQL CVE-2014-8161 Information Disclosure Vulnerability
2015-08-15
http://www.securityfocus.com/bid/72538
OpenSSL CVE-2015-1788 Denial of Service Vulnerability
2015-08-15
http://www.securityfocus.com/bid/75158
OpenSSL CVE-2015-1789 Out of Bounds Read Denial of Service Vulnerability
2015-08-15
http://www.securityfocus.com/bid/75156
PostgreSQL CVE-2015-0244 Security Bypass Vulnerability
2015-08-15
http://www.securityfocus.com/bid/72543
PostgreSQL 'to_char()' Function Buffer Overflow Vulnerability
2015-08-15
http://www.securityfocus.com/bid/72540
SANS News
Threatpost
OwnStar Attack Now Aimed at BMW, Chrysler, Mercedes Cars
Apple Patches Critical OS X DYLD Flaw in Monster Update
Exploit
Gkplugins Picasaweb - Download File
TOTOLINK Routers - Backdoor and RCE Exploit PoC
Joomla com_memorix component - SQL Injection vulnerability
Microsoft HTML Help Compiler 4.74.8702.0 - SEH Based Overflow
Firefox < 39.03 - pdf.js Same Origin Policy Exploit
Ability FTP Server 2.1.4 - afsmain.exe USER Command Remote DoS
Ability FTP Server 2.1.4 - Admin Panel AUTHCODE Command Remote DoS
Ubuntu 14.04 NetKit FTP Client - Crash/DoS PoC
14.8.2015
Bugtraq
Nuance PowerPDF Advanced Metadata Information Disclosure Vulnerability (low|local) 2015-08-13
Christopher Hudel (christopher hudel com)
APPLE-SA-2015-08-13-4 OS X Server v4.1.5 2015-08-13
Apple Product Security (product-security-noreply lists apple com)
APPLE-SA-2015-08-13-2 OS X Yosemite v10.10.5 and Security Update 2015-006 2015-08-13
Apple Product Security (product-security-noreply lists apple com)
APPLE-SA-2015-08-13-3 iOS 8.4.1 2015-08-13
Apple Product Security (product-security-noreply lists apple com)
APPLE-SA-2015-08-13-1 Safari 8.0.8, Safari 7.1.8, and Safari 6.2.8 2015-08-13
Apple Product Security (product-security-noreply lists apple com)
[security bulletin] HPSBGN03393 rev.1 - HP Operations Manager i, Remote Code Execution 2015-08-12
security-alert hp com
Malware
Phishing
Amazon | 13th August 2015 |
WebTeam | 13th August 2015 |
JAMES F. ENTWISTLE | 13th August 2015 |
PayPal | 13th August 2015 |
[PayPal Support] Your Account |
Vulnerebility
ISC BIND CVE-2015-5477 Remote Denial of Service Vulnerability
2015-08-14
http://www.securityfocus.com/bid/76092
WordPress Prior to 4.2.4 Multiple Security Vulnerabilities
2015-08-14
http://www.securityfocus.com/bid/76160
WordPress Prior to 4.2.3 Multiple Security Vulnerabilities
2015-08-14
http://www.securityfocus.com/bid/76011
Mozilla Firefox CVE-2015-4492 Use After Free Memory Corruption Vulnerability
2015-08-14
http://www.securityfocus.com/bid/76297
Mozilla Firefox Out of Bounds Multiple Memory Corruption Vulnerabilities
2015-08-14
http://www.securityfocus.com/bid/76294
SANS News
More patches! This time from Apple to Safari, OS X and OS X server
Microsoft patch tuesday problem with Symantec Cloud Endpoint protection?
Threatpost
Stagefright Patch Incomplete Leaving Android Devices Still Exposed
Salesforce Patches XSS on a Subdomain
Zero Day in Androids Google Admin App Can Bypass Sandbox
Exploit
13.8.2015
Bugtraq
phpipam-1.1.010 XSS Vulnerability 2015-08-12
apparitionsec gmail com
PHPfileNavigator v2.3.3 CSRF Add Arbitrary Users 2015-08-12
apparitionsec gmail com
phpipam-1.1.010 XSS Vulnerability 2015-08-12
apparitionsec gmail com
Malware
Phishing
iLOTTO INTERNET LOTTERY | 13th August 2015 |
iLOTTO INTERNET LOTTERY | 13th August 2015 |
iLOTTO INTERNET LOTTERY | 12th August 2015 |
Alexandra Smith | 12th August 2015 |
Vulnerebility
WordPress Prior to 4.2.4 Multiple Security Vulnerabilities
2015-08-13
http://www.securityfocus.com/bid/76160
WordPress Prior to 4.2.3 Multiple Security Vulnerabilities
2015-08-13
http://www.securityfocus.com/bid/76011
Mozilla Firefox CVE-2015-4492 Use After Free Memory Corruption Vulnerability
2015-08-13
http://www.securityfocus.com/bid/76297
Mozilla Firefox Out of Bounds Multiple Memory Corruption Vulnerabilities
2015-08-13
http://www.securityfocus.com/bid/76294
SANS News
Yes Virginia, Stored XSS's Do Exist!
Threatpost
Facebook Awards $100,000 for New Class of Vulnerabilities and Detection Tool
Exploit
Internet Explorer CTreeNode::GetCascadedLang Use-After-Free Vulnerability (MS15-079)
Windows 8.1 DCOM DCE/RPC Local NTLM Reflection Privilege Escalation (MS15-076)
Linux x86 - /bin/sh ROL/ROR Encoded Shellcode
12.8.2015
Bugtraq
[slackware-security] mozilla-firefox (SSA:2015-219-01) 2015-08-08
Slackware Security Team (security slackware com)
[SECURITY] [DSA 3330-1] activemq security update 2015-08-07
Moritz Muehlenhoff (jmm debian org)
QNAP crypto keys logged on unencrypted disk partition in world accessible files 2015-08-07
Andreas Steinmetz (ast domdv de)
[slackware-security] mozilla-nss (SSA:2015-219-02) 2015-08-08
Slackware Security Team (security slackware com)
Device Inspector v1.5 iOS - Command Inject Vulnerabilities 2015-08-07
Vulnerability Lab (research vulnerability-lab com)
Ferrari - PHP CGI Argument Injection (RCE) Vulnerability 2015-08-07
Vulnerability Lab (research vulnerability-lab com)
Malware
VBA / TrojanDownloader.Agent.ZH
VBA / TrojanDownloader.Agent.ZC
VBA / TrojanDownloader.Agent.YX
VBA / TrojanDownloader.Agent.YW
Phishing
noreply@intipaypal | 12th August 2015 |
PayPal | 12th August 2015 |
Mail Delivery Service | 11th August 2015 |
Wells Fargo | 11th August 2015 |
MS linda | 11th August 2015 |
linda lin | 11th August 2015 |
USAA | 11th August 2015 |
Vulnerebility
SSL/TLS RC4 CVE-2015-2808 Information Disclosure Weakness
2015-08-11
http://www.securityfocus.com/bid/73684
Oracle Java SE CVE-2015-0478 Remote Security Vulnerability
2015-08-11
http://www.securityfocus.com/bid/74147
Oracle Java SE CVE-2015-0488 Remote Security Vulnerability
2015-08-11
http://www.securityfocus.com/bid/74111
OpenSSL CVE-2015-0204 Man in the Middle Security Bypass Vulnerability
2015-08-11
http://www.securityfocus.com/bid/71936
FreeType Versions Prior to 2.5.4 Multiple Remote Vulnerabilities
2015-08-11
http://www.securityfocus.com/bid/72986
OpenSSL 'pk7_doit.c' NULL Pointer Dereference Denial of Service Vulnerability
2015-08-11
http://www.securityfocus.com/bid/73231
OpenSSL 'ASN1_TYPE_cmp()' Function Denial of Service Vulnerability
2015-08-11
http://www.securityfocus.com/bid/73225
OpenSSL CVE-2015-0293 Denial of Service Vulnerability
2015-08-11
http://www.securityfocus.com/bid/73232
OpenSSL CVE-2015-1789 Out of Bounds Read Denial of Service Vulnerability
2015-08-11
http://www.securityfocus.com/bid/75156
Apache Tomcat CVE-2014-0230 Denial of Service Vulnerability
2015-08-11
http://www.securityfocus.com/bid/74475
IBM WebSphere Application Server CVE-2015-1920 Remote Code Execution Vulnerability
2015-08-11
http://www.securityfocus.com/bid/74439
Froxlor 'class.Database.php' Information Disclosure Vulnerability
2015-08-11
http://www.securityfocus.com/bid/76097
Remind 'var.c' Buffer Overflow Vulnerability
2015-08-11
http://www.securityfocus.com/bid/76099
Apache Groovy CVE-2015-3253 Remote Code Execution Vulnerability
2015-08-11
http://www.securityfocus.com/bid/75919
OpenSSL DTLS CVE-2014-8176 Remote Memory Corruption Vulnerability
2015-08-11
http://www.securityfocus.com/bid/75159
OpenSSL CVE-2015-1790 Denial of Service Vulnerability
2015-08-11
http://www.securityfocus.com/bid/75157
OpenSSL CVE-2015-1791 Race Condition Security Vulnerability
2015-08-11
http://www.securityfocus.com/bid/75161
OpenSSL CMS CVE-2015-1792 Denial of Service Vulnerability
2015-08-11
http://www.securityfocus.com/bid/75154
SSL/TLS LogJam Man in the Middle Security Bypass Vulnerability
2015-08-11
http://www.securityfocus.com/bid/74733
PHP 'cgi_main.c' Out of Bounds Read Denial of Service Vulnerability
2015-08-11
http://www.securityfocus.com/bid/71833
OpenSSL CVE-2015-1788 Denial of Service Vulnerability
2015-08-11
http://www.securityfocus.com/bid/75158
Google Stagefright Media Playback Engine Multiple Remote Code Execution Vulnerabilities
2015-08-11
http://www.securityfocus.com/bid/76052
Mozilla Firefox CVE-2015-4495 Same Origin Policy Security Bypass Vulnerability
2015-08-11
http://www.securityfocus.com/bid/76249
XMLTooling-C CVE-2015-0851 Denial of Service Vulnerability
2015-08-11
http://www.securityfocus.com/bid/76134
Linux Kernel 'x86/entry/entry_64.S' Local Privilege Escalation Vulnerability
2015-08-11
http://www.securityfocus.com/bid/76004
Mozilla Firefox OS Graphics Buffer Management Memory Corruption Vulnerability
2015-08-11
http://www.securityfocus.com/bid/76253
Mozilla Firefox OS Same Origin Policy Security Bypass Vulnerability
2015-08-11
http://www.securityfocus.com/bid/76255
Mozilla Firefox OS USB Mass Storage handling Local Security Bypass Vulnerability
2015-08-11
http://www.securityfocus.com/bid/76254
Linux Kernel '/arch/x86/net/bpf_jit_comp.c' CVE-2015-4700 Local Denial of Service Vulnerability
2015-08-11
http://www.securityfocus.com/bid/75356
Linux Kernel 'path_openat()' Function Use After Free Memory Corruption Vulnerability
2015-08-11
http://www.securityfocus.com/bid/76142
SANS News
Threatpost
Huge Flash Update Patches More Than 30 Vulnerabilities
Sen. Warren Worried About Banks New Encrypted Messaging Platform
Patched Android Serialization Vulnerability Affects 55 Percent of Devices
Oracle CSO: You Must Not Reverse Engineer Our Code
Hack-Fueled Unprecedented Insider Trading Ring Nets $100M
Microsoft Patches Critical Vulnerabilities in New Edge Browser
Exploit
Internet Explorer CTreeNode::GetCascadedLang Use-After-Free Vulnerability (MS15-079)
11.8.2015
Bugtraq
[slackware-security] mozilla-firefox (SSA:2015-219-01) 2015-08-08
Slackware Security Team (security slackware com)
[SECURITY] [DSA 3330-1] activemq security update 2015-08-07
Moritz Muehlenhoff (jmm debian org)
QNAP crypto keys logged on unencrypted disk partition in world accessible files 2015-08-07
Andreas Steinmetz (ast domdv de)
[slackware-security] mozilla-nss (SSA:2015-219-02) 2015-08-08
Slackware Security Team (security slackware com)
Device Inspector v1.5 iOS - Command Inject Vulnerabilities 2015-08-07
Vulnerability Lab (research vulnerability-lab com)
Ferrari - PHP CGI Argument Injection (RCE) Vulnerability 2015-08-07
Vulnerability Lab (research vulnerability-lab com)
Thomson Reuters FATCA - Arbitrary File Upload 2015-08-07
jakub palaczynski ingservicespolska pl
[SECURITY] [DSA 3329-1] linux security update 2015-08-07
Salvatore Bonaccorso (carnil debian org)
Malware
Trojan:Win32/Hucnak.D!plock
Trojan:Win32/Hucnak.C!plock
Trojan:Win32/Hucnak.B!plock
Trojan:Win32/Hucnak.A!plock
Phishing
United Arab | 11th August 2015 |
USAA.Web.Services | 11th August 2015 |
Barclays Online | 10th August 2015 |
PayPal Inc | 10th August 2015 |
PayPal Inc | 10th August 2015 |
Account Notification | 9th August 2015 |
Vulnerebility
SANS News
.COM.COM Used For Malicious Typo Squatting
Threatpost
Exploit
10.8.2015
Bugtraq
Malware
TrojanDownloader:Win32/Zeagle.G
TrojanDownloader:Win32/Upatre.BW
Phishing
Account Notification | 9th August 2015 |
@aol.com | 8th August 2015 |
Apple Inc | 8th August 2015 |
ACCOUNT TEMPORARILY SUSPENDED | |
NatWest | 8th August 2015 |
Vulnerebility
SANS News
What Was Old is New Again: Honeypots!
Threatpost
Mozilla Patches Bug Used in Active Attacks
Privacy Badger 1.0 Released With Support For EFF Do Not Track Policy
Darkhotel APT Latest to Use Hacking Team Zero Day
Exploit
WordPress Video Gallery 2.7 SQL Injection
WordPress WPTF Image Gallery 1.03 - Aribtrary File Download
WordPress Recent Backups Plugin 0.7 - Arbitrary File Download
WordPress Simple Image Manipulator Plugin 1.0 - Arbitrary File Download
WordPress Video Gallery 2.7 SQL Injection
WordPress Candidate Application Form Plugin 1.0 - Arbitrary File Download
Havij Pro - Crash POC ,Linux x86 Egg Hunter Shellcode (19 bytes)
8.8.2015
Bugtraq
Thomson Reuters FATCA - Arbitrary File Upload 2015-08-07
jakub palaczynski ingservicespolska pl
[SECURITY] [DSA 3329-1] linux security update 2015-08-07
Salvatore Bonaccorso (carnil debian org)
Re: [FD] Mozilla extensions: a security nightmare 2015-08-06
Stefan Kanthak (stefan kanthak nexgo de) (2 replies)
Re: [FD] Mozilla extensions: a security nightmare 2015-08-07
Reindl Harald (h reindl thelounge net)
RE: [FD] Mozilla extensions: a security nightmare 2015-08-07
Steve Friedl (steve unixwiz net) (1 replies)
RE: [FD] Mozilla extensions: a security nightmare 2015-08-07
Frank Waarsenburg (fwaarsenburg ram-it nl) (1 replies)
Re: [FD] Mozilla extensions: a security nightmare 2015-08-07
Jakob Holderbaum (hi jakob io) (1 replies)
Re: [FD] Mozilla extensions: a security nightmare 2015-08-07
Teddy A PURWADI (teddyap access net id)
Malware
Phishing
NatWest | 7th August 2015 |
MBNA Limited | 6th August 2015 |
Account Support | 6th August 2015 |
TD Bank via Me | 6th August 2015 |
Vulnerebility
SANS News
Threatpost
Manipulating WSUS to Own Enterprises
Exploit
PCMan FTP Server 2.0.7 - PUT Command Buffer Overflow
Froxlor Server Management Panel 0.9.33.1 - MySQL Login Information Disclosure
PHP News Script 4.0.0 - SQL Injection
Microweber 1.0.3 - Stored XSS And CSRF Add Admin Exploit
Microweber 1.0.3 File Upload Filter Bypass Remote PHP Code Execution
WordPress Job Manager Plugin 0.7.22 - Persistent XSS
Heroes of Might and Magic III .h3m Map file Buffer Overflow
Linux x86 Memory Sinkhole Privilege Escalation PoC
Windows NDProxy Privilege Escalation XP SP3 x86 and 2003 SP2 x86 (MS14-002)
Dell Netvault Backup 10.0.1.24 - Denial of Service
7.8.2015
Bugtraq
Re: [FD] Mozilla extensions: a security nightmare 2015-08-06
Stefan Kanthak (stefan kanthak nexgo de) (2 replies)
Re: [FD] Mozilla extensions: a security nightmare 2015-08-07
Reindl Harald (h reindl thelounge net)
RE: [FD] Mozilla extensions: a security nightmare 2015-08-07
Steve Friedl (steve unixwiz net) (1 replies)
RE: [FD] Mozilla extensions: a security nightmare 2015-08-07
Frank Waarsenburg (fwaarsenburg ram-it nl) (1 replies)
Re: [FD] Mozilla extensions: a security nightmare 2015-08-07
Jakob Holderbaum (hi jakob io)
Re: [FD] Mozilla extensions: a security nightmare 2015-08-06
Stefan Kanthak (stefan kanthak nexgo de)
Re: [FD] Mozilla extensions: a security nightmare 2015-08-06
Stefan Kanthak (stefan kanthak nexgo de)
Malware
TrojanDownloader:Win32/Tembatch.A
TrojanDownloader:MSIL/Beldex.A
TrojanDownloader:MSIL/Golomak.A
TrojanDropper:Win32/Dexel.A
TrojanSpy:MSIL/Golroted.D
Phishing
MBNA Limited | 6th August 2015 |
Account Support | 6th August 2015 |
Vulnerebility
SANS News
Sigcheck and virustotal-search
Threatpost
Feasible Going Dark Crypto Solution Nowhere to be Found
Updated DGA Changer Malware Generates Fake Domain Stream
BLEKey Device Breaks RFID Physical Access Controls
Prohibition Era Of Security Research May Be Ahead
Exploit
6.8.2015
Bugtraq
[security bulletin] HPSBUX03388 SSRT102180 rev.1 - HP-UX running OpenSSL, Remote Disclosure of Information 2015-08-05
security-alert hp com
Re: [FD] Mozilla extensions: a security nightmare 2015-08-05
Stefan Kanthak (stefan kanthak nexgo de) (1 replies)
Re: [FD] Mozilla extensions: a security nightmare 2015-08-05
Ansgar Wiechers (bugtraq planetcobalt net)
SEC Consult SA-20150805-0 :: Websense Content Gateway Stack Buffer Overflow in handle_debug_network 2015-08-05
SEC Consult Vulnerability Lab (research sec-consult com)
[SECURITY] [DSA 3328-2] wordpress regression update 2015-08-04
Thijs Kinkhorst (thijs debian org)
Malware
TrojanDropper:Win32/Dexel.A
TrojanSpy:MSIL/Golroted.D
TrojanDownloader:MSIL/Bladabindi.I
Adware:Win32/Peapoon
TrojanDownloader:Win32/Paxer.A
TrojanDownloader:Win32/Upatre.BS
TrojanDownloader:Win32/Syten.A
Worm:Win32/Gamarue.AU
Phishing
TD Bank via Me | 6th August 2015 |
@aol.com | 5th August 2015 |
Vulnerebility
SANS News
Nuclear EK traffic patterns in August 2015
Threatpost
Feasible Going Dark Crypto Solution Nowhere to be Found
Google Plans Monthly Security Updates for Nexus Phones
APT Group Gets Selective About Data it Steals
Government Asks for Security Communitys Help on Technical Issues
Granick: Dream of Internet Freedom Dying
Software Liability Is Inevitable
Exploit
Linux Privilege Escalation Due to Nested NMIs Interrupting espfix64
5.8.2015
Bugtraq
[SECURITY] [DSA 3328-2] wordpress regression update 2015-08-04
Thijs Kinkhorst (thijs debian org)
Mozilla extensions: a security nightmare 2015-08-04
Stefan Kanthak (stefan kanthak nexgo de)
[SECURITY] [DSA 3328-1] wordpress security update 2015-08-04
Thijs Kinkhorst (thijs debian org)
[SECURITY] [DSA 3327-1] squid3 security update 2015-08-03
Salvatore Bonaccorso (carnil debian org)
[SECURITY] [DSA 3326-1] ghostscript security update 2015-08-02
Salvatore Bonaccorso (carnil debian org)
Malware
Adware:Win32/Peapoon
TrojanDownloader:Win32/Paxer.A
TrojanDownloader:Win32/Upatre.BS
TrojanDownloader:Win32/Syten.A
Worm:Win32/Gamarue.AU
TrojanDownloader:Win32/Mavradoi.C
TrojanDropper:Win32/Banload.BAX
TrojanSpy:Win32/Banker.VCW
TrojanDownloader:Win32/Banload.BCV
TrojanDownloader:Win32/Banload.ZEQ
Phishing
Pamela Hicks | 4th August 2015 |
Chase | 4th August 2015 |
åå½æ¥¼åå?åå¼èŒè¯å | 4th August 2015 |
Natwest | 4th August 2015 |
Smtpmercantile.in | 4th August 2015 |
Melanie Clark | 4th August 2015 |
Apple | 3rd August 2015 |
USAA | 3rd August 2015 |
Vulnerebility
SANS News
Whatever Happened to tmUnblock.cgi ("Moon Worm")
Threatpost
Researchers Uncover Terracotta Chinese VPN Service Used by APT Crews for Cover
Updated Rig Exploit Kit Closing in on 1 Million Victims
Exploit
4.8.2015
Bugtraq
[SECURITY] [DSA 3326-1] ghostscript security update 2015-08-02
Salvatore Bonaccorso (carnil debian org)
[SECURITY] [DSA 3325-1] apache2 security update 2015-08-01
Stefan Fritsch (sf debian org)
[SECURITY] [DSA 3324-1] icedove security update 2015-08-01
Alessandro Ghedini (ghedo debian org)
[SECURITY] [DSA 3323-1] icu security update 2015-08-01
Laszlo Boszormenyi (gcs debian org)
Multiple XSS vulnerabilities in FortiSandbox WebUI 2015-08-01
hyp3rlinx lycos com
Malware
TrojanDropper:Win32/Banload.BAX
TrojanSpy:Win32/Banker.VCW
TrojanDownloader:Win32/Banload.BCV
TrojanDownloader:Win32/Banload.ZEQ
Phishing
Melanie Clark | 4th August 2015 |
Apple | 3rd August 2015 |
USAA | 3rd August 2015 |
Discover | 2nd August 2015 |
Vulnerebility
SANS News
Threatpost
Windows 10 Upgrade Spam Carries CTB-Locker Ransomware
EFF, AdBlock and Others Launch New Do Not Track Standard
Thunderstrike 2 OS X Firmware Attack Self-Replicates to Peripherals
DHS Raises Privacy Concerns With Senate Cyber Threat Sharing Bill
Exploit
3.8.2015
Bugtraq
phpFileManager 0.9.8 Remote Command Execution 2015-07-31
hyp3rlinx lycos com
HP ArcSight Logger provides incorrect/invalid/incomplete results for queries with boolean operators 2015-07-31
roberto logsat com
[SECURITY] [DSA 3321-1] xmltooling security update 2015-07-30
Alessandro Ghedini (ghedo debian org)
viagra generic singapore 2015-07-30
info fast-isotretinoin com
Malware
Worm:Win32/NeksMiner.A
TrojanDropper:Win32/Bunitu.G
TrojanSpy:MSIL/Irstil.A
Worm:Win32/Xtrat.D
Worm:Win32/Xtrat.C
Phishing
USAA | 3rd August 2015 |
Discover | 2nd August 2015 |
Microsoft | 2nd August 2015 |
Nancy Morales | 2nd August 2015 |
Paypal Support | 2nd August 2015 |
Service Account | 2nd August 2015 |
SUPPORT | 2nd August 2015 |
Ashok Tools | 2nd August 2015 |
FRESH TOOLS / ONLINE LIVE | |
Chase Online | 1st August 2015 |
Vulnerebility
SANS News
Threatpost
Exploit
1.8.2015
Bugtraq
phpFileManager 0.9.8 Remote Command Execution 2015-07-31
hyp3rlinx lycos com
HP ArcSight Logger provides incorrect/invalid/incomplete results for queries with boolean operators 2015-07-31
roberto logsat com
[SECURITY] [DSA 3321-1] xmltooling security update 2015-07-30
Alessandro Ghedini (ghedo debian org)
Malware
Phishing
PayPal | 31st July 2015 |
iTunes | 31st July 2015 |
Vulnerebility
SANS News
Tech tip follow-up: Using the data Invoked with R's system command
Threatpost
FBI Warns of Increase in DDoS Extortion Scams
Unusual Re-Do of US Wassenaar Rules Applauded
Exploit
KMPlayer 3.9.x - .srt Crash PoC
T-Mobile Internet Manager - Contact Name Crash PoC
31.7.2015
Bugtraq
viagra generic singapore 2015-07-30
info fast-isotretinoin com
[SECURITY] [DSA 3320-1] openafs security update 2015-07-30
Sebastien Delafond (seb debian org)
Cisco Security Advisory: Cisco ASR 1000 Series Aggregation Services Routers Fragmented Packet Denial of Service Vulnerability 2015-07-30
Cisco Systems Product Security Incident Response Team (psirt cisco com)
Dell Netvault Backup Remote Denial of Service 2015-07-30
epoide gmail com
FreeBSD Security Advisory FreeBSD-SA-15:16.openssh [REVISED] 2015-07-30
FreeBSD Security Advisories (security-advisories freebsd org)
[security bulletin] HPSBGN03366 rev.1 - HP Business Process Insight with RC4 Stream Cipher, Remote Disclosure of Information 2015-07-29
security-alert hp com
Malware
Win32/TrojanDownloader.Nymaim.AY
Win32/TrojanDownloader.Small.CBA
Phishing
Microsoft | 31st July 2015 |
Apple | 30th July 2015 |
Verified by | 29th July 2015 |
Vulnerebility
Novius OS 'tab' parameter Local File Include Vulnerability
2015-07-29
http://www.securityfocus.com/bid/75533
Oracle Java SE CVE-2015-0488 Remote Security Vulnerability
2015-07-28
http://www.securityfocus.com/bid/74111
Debian OpenJDK CVE-2014-8873 Remote Code Execution Vulnerability
2015-07-28
http://www.securityfocus.com/bid/76019
Oracle Java SE CVE-2015-4732 Remote Security Vulnerability
2015-07-28
http://www.securityfocus.com/bid/75823
Oracle Java SE CVE-2015-0469 Remote Security Vulnerability
2015-07-28
http://www.securityfocus.com/bid/74072
Oracle Java SE CVE-2015-2601 Remote Security Vulnerability
2015-07-28
http://www.securityfocus.com/bid/75867
Oracle Java SE CVE-2015-4749 Remote Security Vulnerability
2015-07-28
http://www.securityfocus.com/bid/75890
SANS News
Tech tip: Invoke a system command in R
Threatpost
Cisco Fixes DoS Vulnerability in ASR 1000 Routers
Writing Advanced OS X Malware an Elegant Solution to Improving Detection
Moonpig Warns Customers of Security Issue
Exploit