Databze Hot News 2016 January - 2016 January February March April May June July August September October November December
31.1.2016
Bugtraq
FreeBSD Security Advisory FreeBSD-SA-16:11.openssl 2016-01-30
FreeBSD Security Advisories (security-advisories freebsd org)
[security bulletin] HPSBHF03419 rev.3 - HPE Networking Products, Remote Denial of Service (DoS), Unauthorized Access 2016-01-29
security-alert hpe com
Cross-Site Request Forgery (CSRF) Vulnerability in ManageEngine Network 2016-01-29
kingkaustubh me com
[security bulletin] HPSBGN03533 rev.1 - HP Enterprise Cloud Service Automation and Codar, Remote Unauthorized Modification 2016-01-29
security-alert hpe com
ManageEngine Eventlog Analyzer v4-v10 Privilege Esacalation 2016-01-29
graphx sigaint org
Malware
Phishing
Vulnerebility
SANS News
Threatpost
Exploit
ProjectSend r582 - Multiple Vulnerabilities
x86_64 Linux shell_reverse_tcp with Password - Polymorphic Version
29.1.2016
Bugtraq
Netlife Photosuite Pro - Client Side Cross Site Scripting Vulnerability 2016-01-29
Vulnerability Lab (research vulnerability-lab com)
ProjectSend multiple vulnerabilities 2016-01-29
Filippo Cavallarin (filippo cavallarin wearesegment com)
[security bulletin] HPSBHF03538 rev.1 - HPE iMC Service Health Manager (SHM) and iMC PLAT running Adobe Flash, Remote Code Execution, Denial of Service (DoS) 2016-01-28
security-alert hpe com
[security bulletin] HPSBHF03535 rev.3 - HPE iMC Service Health Manager (SHM) and iMC PLAT running Adobe Flash, Multiple Remote Vulnerabilities 2016-01-28
security-alert hpe com
CVE-2015-7521: Apache Hive authorization bug disclosure 2016-01-28
khorgath apache org (Sushanth Sowmyan)
[SECURITY] [DSA 3459-1] mysql-5.5 security update 2016-01-28
Salvatore Bonaccorso (carnil debian org)
New Era Company CMS - (id) SQL Injection Vulnerability 2016-01-28
Vulnerability Lab (research vulnerability-lab com)
Trend Micro Direct Pass - Filter Bypass & Persistent Web Vulnerability 2016-01-28
Vulnerability Lab (research vulnerability-lab com)
HCA0005 - Liberty Global - Horizon HD STB - predictable WiFi passphrase 2016-01-28
Hacking Corporation SÃ rl (releases hackingcorp ch)
[SECURITY] [DSA 3458-1] openjdk-7 security update 2016-01-27
Moritz Muehlenhoff (jmm debian org)
[SECURITY] [DSA 3457-1] iceweasel security update 2016-01-27
Moritz Muehlenhoff (jmm debian org)
Log2Space Central v 6.2 Multiple XSS Vulnerability 2016-01-27
Rahul Pratap Singh (techno rps gmail com)
Malware
TrojanSpy:Win32/Nivdort.DI
TrojanSpy:Win32/Nivdort.DG
TrojanSpy:Win32/Nivdort.DF
TrojanSpy:Win32/Nivdort.DE
TrojanSpy:Win32/Nivdort.DD
TrojanSpy:Win32/Nivdort.DC
PWS:MSIL/Silog.A
Phishing
email update | 28th January 2016 |
eBay | 28th January 2016 |
AsianBeauties Team | 28th January 2016 |
Vulnerebility
SANS News
Threatpost
Oracle to Kill Java Browser Plugin
Exploit
Ramui Forum Script 9.0 - SQL Injection Exploit
Ramui Web Hosting Directory Script 4.0 - Remote File Inclusion
28.1.2016
Bugtraq
[SECURITY] [DSA 3459-1] mysql-5.5 security update 2016-01-28
Salvatore Bonaccorso (carnil debian org)
New Era Company CMS - (id) SQL Injection Vulnerability 2016-01-28
Vulnerability Lab (research vulnerability-lab com)
Trend Micro Direct Pass - Filter Bypass & Persistent Web Vulnerability 2016-01-28
Vulnerability Lab (research vulnerability-lab com)
HCA0005 - Liberty Global - Horizon HD STB - predictable WiFi passphrase 2016-01-28
Hacking Corporation SÃ rl (releases hackingcorp ch)
[SECURITY] [DSA 3458-1] openjdk-7 security update 2016-01-27
Moritz Muehlenhoff (jmm debian org)
[SECURITY] [DSA 3457-1] iceweasel security update 2016-01-27
Moritz Muehlenhoff (jmm debian org)
Log2Space Central v 6.2 Multiple XSS Vulnerability 2016-01-27
Rahul Pratap Singh (techno rps gmail com)
Cisco Security Advisory: Cisco RV220 Management Authentication Bypass Vulnerability 2016-01-27
Cisco Systems Product Security Incident Response Team (psirt cisco com)
Cisco Security Advisory: Cisco Wide Area Application Service CIFS DoS Vulnerability 2016-01-27
Cisco Systems Product Security Incident Response Team (psirt cisco com)
Netgear GS105Ev2 - Multiple Vulnerabilities 2016-01-27
benedikt westermann i-sec tuv com
los818 CMS 2016 Q1 - SQL Injection Web Vulnerability 2016-01-27
Vulnerability Lab (research vulnerability-lab com)
Kleefa v1.7 (IR) - Multiple Web Vulnerabilities 2016-01-27
Vulnerability Lab (research vulnerability-lab com)
Malware
TrojanDownloader:O97M/Skebpac.A
TrojanDownloader:Win32/Farfli.D
TrojanDownloader:Win32/Banload.BGD
TrojanDownloader:Win32/Banload.BGC
Phishing
AsianBeauties Team | 28th January 2016 |
NatWest | 27th January 2016 |
WILMA PEARSON | 27th January 2016 |
Vulnerebility
SANS News
Dridex malspam example from January 2016
Threatpost
Java Serialization Bug Crops Up At PayPal
Exploit
SAP HANA 1.00.095 - hdbindexserver Memory Corruption
OS X Kernel - IOAccelMemoryInfoUserClient Use-After-Free
OS X Kernel - no-more-senders Use-After-Free
OS X - IOBluetoothHCIPacketLogUserClient Memory Corruption
OS X - IOBluetoothHCIUserClient Arbitrary Kernel Code Execution
OS X Kernel - IOAccelDisplayPipeUserClient2 Use-After-Free
iOS/OS X - Unsandboxable Kernel Code Exection Due to iokit Double Release in IOKit
iOS/OS X - Multiple Kernel Uninitialized Variable Bugs Leading to Code Execution
iOS Kernel - AppleOscarGyro Use-After-Free
iOS Kernel - AppleOscarAccelerometer Use-After-Free
iOS Kernel - AppleOscarCompass Use-After-Free
iOS Kernel - AppleOscarCMA Use-After-Free
iOS Kernel - IOHIDEventService Use-After-Free
iOS Kernel - IOReportHub Use-After-Free
OS X and iOS Kernel - IOHDIXControllUserClient::clientClose Use-After-Free/Double Free
OS X and iOS Kernel - iokit Registry Iterator Manipulation Double Free
OSX - io_service_close Use-After-Free
OS X - gst_configure Kernel Buffer Overflow
OS X - IntelAccelerator::gstqConfigure Exploitable Kernel NULL Dereference
OS X Kernel - Hypervisor Driver Use-After-Free
OS X - IOSCSIPeripheralDeviceType00 Userclient Type 12 Exploitable Kernel NULL Dereference
OS X and iOS Unsandboxable Kernel Use-After-Free in Mach Vouchers
iOS and OS X - NECP System Control Socket Packet Parsing Kernel Code Execution Integer Overflow
iOS and OS X Kernel - Double-Delete IOHIDEventQueue::start Code Execution
OS X - OSMetaClassBase::safeMetaCast in IOAccelContext2::connectClient Exploitable NULL Dereference
OS X - IOHDIXControllerUserClient::convertClientBuffer Integer Overflow
Ramui Forum Script 9.0 - SQL Injection Exploit
Ramui Web Hosting Directory Script 4.0 - Remote File Inclusion
VLC Media Player 2.2.1 - .mp4 Heap Memory Corruption
Netgear WNR1000v4 - Authentication Bypass
27.1.2016
Bugtraq
los818 CMS 2016 Q1 - SQL Injection Web Vulnerability 2016-01-27
Vulnerability Lab (research vulnerability-lab com)
Kleefa v1.7 (IR) - Multiple Web Vulnerabilities 2016-01-27
Vulnerability Lab (research vulnerability-lab com)
WebMartIndia CMS 2016 Q1 - SQL Injection Vulnerability 2016-01-27
Vulnerability Lab (research vulnerability-lab com)
Classic Infomedia (Login) - Auth Bypass Web Vulnerability 2016-01-27
Vulnerability Lab (research vulnerability-lab com)
Ebay Magento Bug Bounty #2 - Persistent Web Vulnerability 2016-01-27
Vulnerability Lab (research vulnerability-lab com)
Telegram (API) - Cross Site Request Forgery Vulnerabilities 2016-01-27
Vulnerability Lab (research vulnerability-lab com)
Barracuda Networks Bug Bounty #38 Message Archiver - Multiple Vulnerabilities 2016-01-27
Vulnerability Lab (research vulnerability-lab com)
Apple WatchOS v2.1 - Denial of Service Vulnerability 2016-01-27
Vulnerability Lab (research vulnerability-lab com)
Secure Item Hub v1.0 iOS - Multiple Web Vulnerabilities 2016-01-27
Vulnerability Lab (research vulnerability-lab com)
BK Mobile CMS SQLi and XSS Vulnerability 2016-01-27
Rahul Pratap Singh (techno rps gmail com)
[SECURITY] [DSA 3456-1] chromium-browser security update 2016-01-27
Michael Gilbert (mgilbert debian org)
[SECURITY] [DSA 3455-1] curl security update 2016-01-27
Alessandro Ghedini (ghedo debian org)
[ERPSCAN-15-024] SAP HANA hdbindexserver - Memory corruption 2016-01-27
ERPScan inc (erpscan online gmail com)
FreeBSD Security Advisory FreeBSD-SA-16:10.linux 2016-01-27
FreeBSD Security Advisories (security-advisories freebsd org)
FreeBSD Security Advisory FreeBSD-SA-16:09.ntp 2016-01-27
FreeBSD Security Advisories (security-advisories freebsd org)
FreeBSD Security Advisory FreeBSD-SA-16:08.bind 2016-01-27
FreeBSD Security Advisories (security-advisories freebsd org)
[SECURITY] [DSA 3454-1] virtualbox security update 2016-01-26
Moritz Muehlenhoff (jmm debian org)
WP-Ultimate CSV Importer XSS Vulnerability 2016-01-26
Rahul Pratap Singh (techno rps gmail com)
Malware
Win32/TrojanDownloader.Phabeload.E
Phishing
WILMA PEARSON | 27th January 2016 |
Outlook Team | 27th January 2016 |
åå?è | 26th January 2016 |
Apple alert | 26th January 2016 |
CLARA MORAN | 26th January 2016 |
PayPal | 25th January 2016 |
P Service | 25th January 2016 |
Vulnerebility
SANS News
Threatpost
Apple Fixes Cookie Theft Bug in iOS 9.2.1
Apple Fixes Cookie Theft Bug in iOS 9.2.1
Magento Update Addresses XSS, CSRF Vulnerabilities
Amazon Certificate Manager Brings Free SSL Certs to AWS Users
Exploit
Android sensord Local Root Exploit
Android ADB Debug Server Remote Payload Execution
Linux x86/x86_64 tcp_bind Shellcode
Linux x86/x86_64 tcp_bind Shellcode #2
Linux x86/x86_64 Read etc/passwd Shellcode
Wordpress Booking Calendar Contact Form Plugin <=1.1.23 - Shortcode SQL Injection
Gongwalker API Manager 1.1 - Blind SQL Injection
pdfium - opj_jp2_apply_pclr (libopenjpeg) Heap-Based Out-of-Bounds Read
pdfium - opj_j2k_read_mcc (libopenjpeg) Heap-Based Out-of-Bounds Read
Wireshark - iseries_check_file_type Stack-Based Out-of-Bounds Read
Wireshark - dissect_nhdr_extopt Stack-Based Buffer Overflow
Wireshark - hiqnet_display_data Static Out-of-Bounds Read
Wireshark - nettrace_3gpp_32_423_file_open Stack-Based Out-of-Bounds Read
Wireshark dissect_ber_constrained_bitstring Heap-Based Out-of-Bounds Read
Foxit Reader <= 7.2.8.1124 - PDF Parsing Memory Corruption
26.1.2016
Bugtraq
PHP LiteSpeed SAPI out of boundaries read due to missing input validation 2016-01-25
Imre RAD (imre rad search-lab hu)
[CORE-2016-0002] - Lenovo ShareIT Multiple Vulnerabilities 2016-01-25
CORE Advisories Team (advisories coresecurity com)
Authentication bypass in PHP File Manager 0.9.8 2016-01-25
Imre Rad (imre rad search-lab hu)
APPLE-SA-2016-01-25-1 tvOS 9.1.1 2016-01-25
Apple Product Security (product-security-noreply lists apple com)
Magento 1.9.x Multiple Man-In The Middle 2016-01-25
cxsecurity protonmail com
glibc catopen() Multiple unbounded stack allocations 2016-01-25
cxsecurity protonmail com
[SECURITY] [DSA 3453-1] mariadb-10.0 security update 2016-01-25
Salvatore Bonaccorso (carnil debian org)
WP Easy Gallery v4.1.4 Stored XSS Vulnerability 2016-01-26
Rahul Pratap Singh (techno rps gmail com)
PHP LiteSpeed SAPI secret key improper disposal 2016-01-25
Imre RAD (imre rad search-lab hu)
PHP-FPM fpm_log.c memory leak and buffer overflow 2016-01-25
Imre RAD (imre rad search-lab hu)
Remote shutdown vulnerability in Buffalo NAS (Linkstation 420) 2016-01-24
zemnmez googlemail com
ZyXel WAP3205 v1 Multiple XSS 2016-01-23
graphx sigaint org
HP ToComMsg DLL side loading vulnerability 2016-01-23
Securify B.V. (lists securify nl)
Malware
Phishing
Apple alert | 26th January 2016 |
CLARA MORAN | 26th January 2016 |
PayPal | 25th January 2016 |
P Service | 25th January 2016 |
JOHN ABBOTT | 25th January 2016 |
TIFFANY RICE | 25th January 2016 |
RITA BURNS | 25th January 2016 |
Vulnerebility
SANS News
Pentest Time Machine: NMAP + Powershell + whatever tool is next
Threatpost
Exploit
25.1.2016
Bugtraq
PHP LiteSpeed SAPI secret key improper disposal 2016-01-25
Imre RAD (imre rad search-lab hu)
PHP-FPM fpm_log.c memory leak and buffer overflow 2016-01-25
Imre RAD (imre rad search-lab hu)
Remote shutdown vulnerability in Buffalo NAS (Linkstation 420) 2016-01-24
zemnmez googlemail com
ZyXel WAP3205 v1 Multiple XSS 2016-01-23
graphx sigaint org
HP ToComMsg DLL side loading vulnerability 2016-01-23
Securify B.V. (lists securify nl)
LEADTOOLS ActiveX control multiple DLL side loading vulnerabilities 2016-01-23
Securify B.V. (lists securify nl)
HP LaserJet Fax Preview DLL side loading vulnerability 2016-01-23
Securify B.V. (lists securify nl)
XMB - eXtreme Message Board v1.9.11.13 Weak Crypto 2016-01-23
hyp3rlinx lycos com
imageone Cms Multiple vulnerabilities 2016-01-23
iedb team gmail com
[SECURITY] [DSA 3452-1] claws-mail security update 2016-01-23
Ben Hutchings (benh debian org)
Malware
Ransom:Win32/Rackcrypt.A
Ransom:MSIL/Tarocrypt.B
Ransom:MSIL/Tarocrypt.A
TrojanProxy:Win32/Bunitu.O
Ransom:MSIL/Tarocrypt
Phishing
PayPal | 25th January 2016 |
P Service | 25th January 2016 |
JOHN ABBOTT | 25th January 2016 |
TIFFANY RICE | 25th January 2016 |
RITA BURNS | 25th January 2016 |
Security Team | 25th January 2016 |
AOL | 25th January 2016 |
Vulnerebility
SANS News
Assessing Remote Certificates with Powershell
Threatpost
Exploit
x86_64 Linux xor/not/div Encoded execve Shellcode
Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux 2 (MS16-008)
Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008)
Linux Kernel - prima WLAN Driver Heap Overflow
Wordpress Booking Calendar Contact Form Plugin <=1.1.23 - Unauthenticated SQL injection
pfSense Firewall <= 2.2.5 - Config File CSRF
FreeBSD SCTP ICMPv6 Error Processing Vulnerability
24.1.2016
Bugtraq
Malware
Win32/TrojanDownloader.Tiny.NMO
Win32/TrojanDownloader.Tiny.NMN
Win32/TrojanDownloader.Tiny.NMK
Phishing
Discover | 23rd January 2016 |
PayPal | 22nd January 2016 |
CHARLOTTE SHARP | 22nd January 2016 |
PayPal | 22nd January 2016 |
Vulnerebility
SANS News
Threatpost
Exploit
22.1.2016
Bugtraq
January 2016 - Bamboo - Critical Security Advisory 2016-01-22
David Black (dblack atlassian com)
[SECURITY] [DSA 3451-1] fuse security update 2016-01-21
Yves-Alexis Perez (corsac debian org)
Executable installers are vulnerable^WEVIL (case 3): WiX Toolset's bootstrapper "burn.exe" 2016-01-21
Stefan Kanthak (stefan kanthak nexgo de)
SEC Consult SA-20160121-0 :: Deliberately hidden backdoor account in AMX (Harman Professional) devices 2016-01-21
SEC Consult Vulnerability Lab (research sec-consult com)
Oracle HtmlConverter.exe Buffer Overflow 2016-01-21
hyp3rlinx lycos com
QuickAuth - Google Authenticator Pebble app vulnerable to MITM attack when configuring TOTP keys 2016-01-20
issues github com
Re: [CVE-2016-1919] Weak eCryptFS Key generation from user password on KNOX 1.0 / Android 4.3 2016-01-19
urikanonov gmail com
Re: [CVE-2016-1920] VPN Man-in-the-Middle due to shared certificate store on KNOX 1.0 / Android 4.3 2016-01-19
urikanonov gmail com
Cisco Security Advisory: Cisco Modular Encoding Platform D9036 Software Default Credentials Vulnerability 2016-01-20
Cisco Systems Product Security Incident Response Team (psirt cisco com)
[SECURITY] [DSA 3450-1] ecryptfs-utils security update 2016-01-20
Salvatore Bonaccorso (carnil debian org)
Cisco Security Advisory: Cisco Unified Computing System Manager and Cisco Firepower 9000 Remote Command Execution Vulnerability 2016-01-20
Cisco Systems Product Security Incident Response Team (psirt cisco com)
[CVE-2016-1926] XSS in Greenbone Security Assistant ≥ 6.0.0 and < 6.0.8 2016-01-20
bugtraq internetwache org
LiteSpeed Web Server - Security Advisory - HTTP Header Injection Vulnerability 2016-01-20
Onur Yilmaz (onur netsparker com)
APPLE-SA-2016-01-19-3 Safari 9.0.3 2016-01-19
Apple Product Security (product-security-noreply lists apple com)
Malware
TrojanSpy:Win32/Nivdort.DB
TrojanSpy:Win32/Nivdort.DA
TrojanSpy:Win32/Nivdort.CZ
Phishing
PayPal | 22nd January 2016 |
AUTO YOUTUBE SERVICE | 21st January 2016 |
PayPal Security | 21st January 2016 |
DAISY SPARKS | 21st January 2016 |
IMMO USA | 21st January 2016 |
Secure Facebook Notify | 21st January 2016 |
Vulnerebility
SANS News
Threatpost
Exploit
xWPE 1.5.30a-2.1 - Local Buffer Overflow
Oracle HtmlConverter.exe - Buffer Overflow
21.1.2016
Bugtraq
Executable installers are vulnerable^WEVIL (case 3): WiX Toolset's bootstrapper "burn.exe" 2016-01-21
Stefan Kanthak (stefan kanthak nexgo de)
SEC Consult SA-20160121-0 :: Deliberately hidden backdoor account in AMX (Harman Professional) devices 2016-01-21
SEC Consult Vulnerability Lab (research sec-consult com)
Oracle HtmlConverter.exe Buffer Overflow 2016-01-21
hyp3rlinx lycos com
QuickAuth - Google Authenticator Pebble app vulnerable to MITM attack when configuring TOTP keys 2016-01-20
issues github com
Re: [CVE-2016-1919] Weak eCryptFS Key generation from user password on KNOX 1.0 / Android 4.3 2016-01-19
urikanonov gmail com
Re: [CVE-2016-1920] VPN Man-in-the-Middle due to shared certificate store on KNOX 1.0 / Android 4.3 2016-01-19
urikanonov gmail com
Cisco Security Advisory: Cisco Modular Encoding Platform D9036 Software Default Credentials Vulnerability 2016-01-20
Cisco Systems Product Security Incident Response Team (psirt cisco com)
[SECURITY] [DSA 3450-1] ecryptfs-utils security update 2016-01-20
Salvatore Bonaccorso (carnil debian org)
Cisco Security Advisory: Cisco Unified Computing System Manager and Cisco Firepower 9000 Remote Command Execution Vulnerability 2016-01-20
Cisco Systems Product Security Incident Response Team (psirt cisco com)
[CVE-2016-1926] XSS in Greenbone Security Assistant ≥ 6.0.0 and < 6.0.8 2016-01-20
bugtraq internetwache org
LiteSpeed Web Server - Security Advisory - HTTP Header Injection Vulnerability 2016-01-20
Onur Yilmaz (onur netsparker com)
APPLE-SA-2016-01-19-3 Safari 9.0.3 2016-01-19
Apple Product Security (product-security-noreply lists apple com)
APPLE-SA-2016-01-19-2 OS X El Capitan 10.11.3 and Security Update 2016-001 2016-01-19
Apple Product Security (product-security-noreply lists apple com)
APPLE-SA-2016-01-19-1 iOS 9.2.1 2016-01-19
Apple Product Security (product-security-noreply lists apple com)
[SECURITY] [DSA 3449-1] bind9 security update 2016-01-19
Salvatore Bonaccorso (carnil debian org)
[security bulletin] HPSBGN03534 rev.1 - HPE Performance Center using Microsoft Report Viewer, Remote Disclosure of Information, Cross-Site Scripting (XSS) 2016-01-19
security-alert hpe com
Executable installers are vulnerable^WEVIL (case 21): Panda Security's installers allow arbitrary (remote) code execution AND escalation of privilege with PANDAIS16.exe 2016-01-19
Stefan Kanthak (stefan kanthak nexgo de)
Malware
TrojanSpy:MSIL/Dyzinew.A
TrojanSpy:MSIL/Rastabaf.A
HackTool:Win32/SmptMailStress
TrojanDownloader:MSIL/Banload.AN
Win32/TrojanDownloader.Tiny.NMI
Win32/TrojanDownloader.Tiny.NLK
Win32/TrojanDownloader.Tiny.NMN
Win32/TrojanDownloader.Tiny.NMK
Phishing
Apple Support | 20th January 2016 |
ANN FOWLER | 20th January 2016 |
Email Administrator | 20th January 2016 |
YOUR EMAIL ACCOUNT WAS | |
PaypaI Service | 20th January 2016 |
PayPal | 20th January 2016 |
AOL | 20th January 2016 |
AOL | 19th January 2016 |
PayPal | 19th January 2016 |
Vulnerebility
SANS News
Threatpost
Oracle Releases Record Number of Security Patches
Dridex Borrows Tricks From Dyre, Targets U.K. Users
Exploit
20.1.2016
Bugtraq
QuickAuth - Google Authenticator Pebble app vulnerable to MITM attack when configuring TOTP keys 2016-01-20
issues github com
Re: [CVE-2016-1919] Weak eCryptFS Key generation from user password on KNOX 1.0 / Android 4.3 2016-01-19
urikanonov gmail com
Re: [CVE-2016-1920] VPN Man-in-the-Middle due to shared certificate store on KNOX 1.0 / Android 4.3 2016-01-19
urikanonov gmail com
Cisco Security Advisory: Cisco Modular Encoding Platform D9036 Software Default Credentials Vulnerability 2016-01-20
Cisco Systems Product Security Incident Response Team (psirt cisco com)
[SECURITY] [DSA 3450-1] ecryptfs-utils security update 2016-01-20
Salvatore Bonaccorso (carnil debian org)
Cisco Security Advisory: Cisco Unified Computing System Manager and Cisco Firepower 9000 Remote Command Execution Vulnerability 2016-01-20
Cisco Systems Product Security Incident Response Team (psirt cisco com)
[CVE-2016-1926] XSS in Greenbone Security Assistant ≥ 6.0.0 and < 6.0.8 2016-01-20
bugtraq internetwache org
LiteSpeed Web Server - Security Advisory - HTTP Header Injection Vulnerability 2016-01-20
Onur Yilmaz (onur netsparker com)
APPLE-SA-2016-01-19-3 Safari 9.0.3 2016-01-19
Apple Product Security (product-security-noreply lists apple com)
APPLE-SA-2016-01-19-2 OS X El Capitan 10.11.3 and Security Update 2016-001 2016-01-19
Apple Product Security (product-security-noreply lists apple com)
APPLE-SA-2016-01-19-1 iOS 9.2.1 2016-01-19
Apple Product Security (product-security-noreply lists apple com)
[SECURITY] [DSA 3449-1] bind9 security update 2016-01-19
Salvatore Bonaccorso (carnil debian org)
[security bulletin] HPSBGN03534 rev.1 - HPE Performance Center using Microsoft Report Viewer, Remote Disclosure of Information, Cross-Site Scripting (XSS) 2016-01-19
security-alert hpe com
Malware
Ransom:Win32/Cryproto.A
TrojanDownloader:MSIL/Genmaldow.M
DDoS:MSIL/Loioir.A
Backdoor:Win32/Aimbot.D
TrojanDownloader:MSIL/Gurim.A
Adware:Win32/Chekua
Phishing
Email Administrator | 20th January 2016 |
YOUR EMAIL ACCOUNT WAS | |
PaypaI Service | 20th January 2016 |
PayPal | 20th January 2016 |
AOL | 20th January 2016 |
AOL | 19th January 2016 |
PayPal | 19th January 2016 |
LISA STRICKLAND | 19th January 2016 |
Vulnerebility
SANS News
/tmp, %TEMP%, ~/Desktop, T:\, ... A goldmine for pentesters!
Threatpost
Bot Fraud to Cost Advertisers $7 Billion in 2016
Apple Releases Patches for iOS, OS X and Safari
Exploit
Linux Kernel REFCOUNT Overflow/Use-After-Free in Keyrings
PDF-XChange Viewer 2.5.315.0 - Shading Type 7 Heap Memory Corruption
19.1.2016
Bugtraq
Executable installers are vulnerable^WEVIL (case 21): Panda Security's installers allow arbitrary (remote) code execution AND escalation of privilege with PANDAIS16.exe 2016-01-19
Stefan Kanthak (stefan kanthak nexgo de)
[CORE-2016-0001] - Intel Driver Update Utility MiTM 2016-01-19
CORE Advisories Team (advisories coresecurity com)
Quick Cart v6.6 XSS Vulnerability 2016-01-19
Rahul Pratap Singh (techno rps gmail com)
[SECURITY] [DSA 3448-1] linux security update 2016-01-19
Salvatore Bonaccorso (carnil debian org)
Quick CMS v 6.1 XSS Vulnerability 2016-01-19
Rahul Pratap Singh (techno rps gmail com)
Advanced Electron Forum v1.0.9 RFI / CSRF 2016-01-18
hyp3rlinx lycos com
Advanced Electron Forum v1.0.9 Persistent XSS 2016-01-18
hyp3rlinx lycos com
Advanced Electron Forum v1.0.9 CSRF 2016-01-18
hyp3rlinx lycos com
[SECURITY] [DSA 3447-1] tomcat7 security update 2016-01-17
Salvatore Bonaccorso (carnil debian org)
Malware
TrojanSpy:Win32/Nivdort.AC
TrojanSpy:Win32/Pstsca.A
Phishing
Pay-Pal Support | 18th January 2016 |
Microsoft | 18th January 2016 |
Vulnerebility
SANS News
Powershell and HTTPS ? It Ain?t All Rainbows And Lollipops! (or is it?)
Threatpost
Exploit
PDF-XChange Viewer 2.5.315.0 - Shading Type 7 Heap Memory Corruption
Advanced Electron Forum 1.0.9 - CSRF Vulnerabilities
18.1.2016
Bugtraq
Advanced Electron Forum v1.0.9 RFI / CSRF 2016-01-18
hyp3rlinx lycos com
Advanced Electron Forum v1.0.9 Persistent XSS 2016-01-18
hyp3rlinx lycos com
Advanced Electron Forum v1.0.9 CSRF 2016-01-18
hyp3rlinx lycos com
[SECURITY] [DSA 3447-1] tomcat7 security update 2016-01-17
Salvatore Bonaccorso (carnil debian org)
[CVE-2016-1919] Weak eCryptFS Key generation from user password on KNOX 1.0 / Android 4.3 2016-01-16
urikanonov gmail com
[CVE-2016-1920] VPN Man-in-the-Middle due to shared certificate store on KNOX 1.0 / Android 4.3 2016-01-16
urikanonov gmail com
[KIS-2016-01] CakePHP <= 3.2.0 "_method" CSRF Protection Bypass Vulnerability 2016-01-15
Egidio Romano (research karmainsecurity com)
Defense in depth -- the Microsoft way (part 38): does Microsoft follow their own security guidance/advisories? 2016-01-15
Stefan Kanthak (stefan kanthak nexgo de)
Executable installers are vulnerable^WEVIL (case 22): python.org's executable installers allow arbitrary (remote) code execution 2016-01-15
Stefan Kanthak (stefan kanthak nexgo de)
[slackware-security] openssh (SSA:2016-014-01) 2016-01-15
Slackware Security Team (security slackware com)
Malware
Phishing
Paypal Inc | 18th January 2016 |
Info | 18th January 2016 |
setting | 18th January 2016 |
AOL | 17th January 2016 |
Vulnerebility
SANS News
Some useful volatility plugins
Threatpost
Exploit
Advanced Electron Forum 1.0.9 - CSRF Vulnerabilities
Advanced Electron Forum 1.0.9 - Persistent XSS Vulnerabilities
Advanced Electron Forum 1.0.9 - RFI / CSRF Vulnerability
WEG SuperDrive G2 12.0.0 - Insecure File Permissions
17.1.2016
Bugtraq
[SECURITY] [DSA 3447-1] tomcat7 security update 2016-01-17
Salvatore Bonaccorso (carnil debian org)
[CVE-2016-1919] Weak eCryptFS Key generation from user password on KNOX 1.0 / Android 4.3 2016-01-16
urikanonov gmail com
[CVE-2016-1920] VPN Man-in-the-Middle due to shared certificate store on KNOX 1.0 / Android 4.3 2016-01-16
urikanonov gmail com
[KIS-2016-01] CakePHP <= 3.2.0 "_method" CSRF Protection Bypass Vulnerability 2016-01-15
Egidio Romano (research karmainsecurity com)
Defense in depth -- the Microsoft way (part 38): does Microsoft follow their own security guidance/advisories? 2016-01-15
Stefan Kanthak (stefan kanthak nexgo de)
Executable installers are vulnerable^WEVIL (case 22): python.org's executable installers allow arbitrary (remote) code execution 2016-01-15
Stefan Kanthak (stefan kanthak nexgo de)
[slackware-security] openssh (SSA:2016-014-01) 2016-01-15
Slackware Security Team (security slackware com)
Malware
Phishing
iCloud Helpdesk | 17th January 2016 |
PaypaI | 17th January 2016 |
PAYPAL | 17th January 2016 |
USAA | 16th January 2016 |
Paypal | 16th January 2016 |
YOUR ACCOUNT HAS BEEN LIMITED | |
Service PayPal | 16th January 2016 |
Vulnerebility
Oracle Java SE CVE-2015-4843 Remote Security Vulnerability
2016-01-15
http://www.securityfocus.com/bid/77160
Mozilla Network Security Services Memory Corruption and Heap Buffer Overflow Vulnerabilities
2016-01-15
http://www.securityfocus.com/bid/77416
TigerVNC Screen Size Handling Integer Overflow Vulnerability
2016-01-15
http://www.securityfocus.com/bid/70391
libwmf 'DecodeImage()' Function Heap Buffer Overflow Vulnerability
2016-01-15
http://www.securityfocus.com/bid/74923
Mozilla Netscape Portable Runtime CVE-2015-7183 Integer Overflow Vulnerability
2016-01-15
http://www.securityfocus.com/bid/77415
MPFR 'strtofr.c' Buffer Overflow Vulnerability
2016-01-15
http://www.securityfocus.com/bid/71542
Firebird CVE-2013-2492 Remote Code Execution Vulnerability
2016-01-15
http://www.securityfocus.com/bid/58393
Adobe Flash Player and AIR APSB16-01 Multiple Use After Free Remote Code Execution Vulnerabilities
2016-01-15
http://www.securityfocus.com/bid/79701
Adobe Flash Player and AIR CVE-2015-8651 Unspecified Integer Overflow Vulnerability
2016-01-15
http://www.securityfocus.com/bid/79705
Adobe Flash Player and AIR CVE-2015-8644 Type Confusion Remote Code Execution Vulnerability
2016-01-15
http://www.securityfocus.com/bid/79704
Adobe Flash Player and AIR APSB16-01 Multiple Memory Corruption Vulnerabilities
2016-01-15
http://www.securityfocus.com/bid/79700
Oracle Java SE CVE-2015-4881 Remote Security Vulnerability
2016-01-15
http://www.securityfocus.com/bid/77159
Linux Kernel 'virtio-net' Fragmented Packets Handling Buffer Overflow Vulnerability
2016-01-15
http://www.securityfocus.com/bid/76230
Oracle Java SE CVE-2015-4860 Remote Security Vulnerability
2016-01-15
http://www.securityfocus.com/bid/77162
Oracle Java SE CVE-2015-4844 Remote Security Vulnerability
2016-01-15
http://www.securityfocus.com/bid/77164
Oracle Java SE CVE-2015-4883 Remote Security Vulnerability
2016-01-15
http://www.securityfocus.com/bid/77161
KDE Workspace Arbitrary Command Execution Vulnerability
2016-01-15
http://www.securityfocus.com/bid/70904
Django CVE-2015-8213 Security Bypass Vulnerability
2016-01-15
http://www.securityfocus.com/bid/77750
Linux Kernel CVE-2010-5313 Local Denial of Service Vulnerability
2016-01-15
http://www.securityfocus.com/bid/71363
Linux Kernel CVE-2014-8559 Local Denial of Service Vulnerability
2016-01-15
http://www.securityfocus.com/bid/70854
NTP 'ntp-keygen.c' Predictable Random Number Generator Weakness
2016-01-15
http://www.securityfocus.com/bid/74045
cURL/libcURL CVE-2015-3148 Remote Security Bypass Vulnerability
2016-01-15
http://www.securityfocus.com/bid/74301
libxml2 'parser.c' Out of Bounds Read Multiple Information Disclosure Vulnerabilities
2016-01-15
http://www.securityfocus.com/bid/74241
libpng 'png_convert_to_rfc1123()' Function Out Of Bounds Read Memory Corruption Vulnerability
2016-01-15
http://www.securityfocus.com/bid/77304
netcf CVE-2014-8119 Remote Denial of Service Vulnerability
2016-01-15
http://www.securityfocus.com/bid/78046
Linux Kernel KVM CVE-2014-7842 Local Denial of Service Vulnerability
2016-01-15
http://www.securityfocus.com/bid/71078
cURL/libcURL NTLM connection CVE-2015-3143 Remote Security Bypass Vulnerability
2016-01-15
http://www.securityfocus.com/bid/74299
cups-filters CVE-2015-3279 Remote Heap Buffer Overflow Vulnerability
2016-01-15
http://www.securityfocus.com/bid/75557
cups-filters 'texttopdf' Remote Heap Buffer Overflow Vulnerability
2016-01-15
http://www.securityfocus.com/bid/75436
SANS News
Threatpost
Advantech EKI Vulnerable to Bypass, Possible Backdoor
Exploit
phpDolphin <= 2.0.5 - Multiple Vulnerabilities
15.1.2016
Bugtraq
[KIS-2016-01] CakePHP <= 3.2.0 "_method" CSRF Protection Bypass Vulnerability 2016-01-15
Egidio Romano (research karmainsecurity com)
Defense in depth -- the Microsoft way (part 38): does Microsoft follow their own security guidance/advisories? 2016-01-15
Stefan Kanthak (stefan kanthak nexgo de)
Executable installers are vulnerable^WEVIL (case 22): python.org's executable installers allow arbitrary (remote) code execution 2016-01-15
Stefan Kanthak (stefan kanthak nexgo de)
[slackware-security] openssh (SSA:2016-014-01) 2016-01-15
Slackware Security Team (security slackware com)
FreeBSD Security Advisory FreeBSD-SA-16:07.openssh 2016-01-15
FreeBSD Security Advisories (security-advisories freebsd org)
FreeBSD bsnmpd information disclosure 2016-01-15
Pierre Kim (pierre kim sec gmail com)
Cisco Security Advisory: Cisco Wireless LAN Controller Unauthorized Access Vulnerability 2016-01-13
Cisco Systems Product Security Incident Response Team (psirt cisco com)
FreeBSD Security Advisory FreeBSD-SA-16:05.tcp 2016-01-14
FreeBSD Security Advisories (security-advisories freebsd org)
FreeBSD Security Advisory FreeBSD-SA-16:01.sctp 2016-01-14
FreeBSD Security Advisories (security-advisories freebsd org)
Cisco Security Advisory: Cisco Aironet 1800 Series Access Point Denial of Service Vulnerability 2016-01-13
Cisco Systems Product Security Incident Response Team (psirt cisco com)
[slackware-security] dhcp (SSA:2016-012-01) 2016-01-13
Slackware Security Team (security slackware com)
Remote Code Execution in Roundcube 2016-01-13
High-Tech Bridge Security Research (advisory htbridge ch)
FreeBSD Security Advisory FreeBSD-SA-16:04.linux 2016-01-14
FreeBSD Security Advisories (security-advisories freebsd org)
[security bulletin] HPSBUX03359 SSRT102094 rev.3 - HP-UX pppoec, local elevation of privilege 2016-01-13
security-alert hpe com
[SECURITY] [DSA 3444-1] wordpress security update 2016-01-13
Salvatore Bonaccorso (carnil debian org)
Malware
TrojanDownloader:Win32/Farfli.C
TrojanSpy:Win32/Nivdort.CW
TrojanSpy:Win32/Nivdort.CV
TrojanDownloader:Win32/Silcon.A
Phishing
service.intl@paypal.com | 15th January 2016 |
ACTION REQUIRED: YOUR ACCOUNT | |
NAFCU | 14th January 2016 |
Heather ODonnell | 14th January 2016 |
Service Team | 14th January 2016 |
Vulnerebility
Oracle Java SE CVE-2015-4843 Remote Security Vulnerability
2016-01-15
http://www.securityfocus.com/bid/77160
Mozilla Network Security Services Memory Corruption and Heap Buffer Overflow Vulnerabilities
2016-01-15
http://www.securityfocus.com/bid/77416
TigerVNC Screen Size Handling Integer Overflow Vulnerability
2016-01-15
http://www.securityfocus.com/bid/70391
libwmf 'DecodeImage()' Function Heap Buffer Overflow Vulnerability
2016-01-15
http://www.securityfocus.com/bid/74923
Mozilla Netscape Portable Runtime CVE-2015-7183 Integer Overflow Vulnerability
2016-01-15
http://www.securityfocus.com/bid/77415
MPFR 'strtofr.c' Buffer Overflow Vulnerability
2016-01-15
http://www.securityfocus.com/bid/71542
Firebird CVE-2013-2492 Remote Code Execution Vulnerability
2016-01-15
http://www.securityfocus.com/bid/58393
Adobe Flash Player and AIR APSB16-01 Multiple Use After Free Remote Code Execution Vulnerabilities
2016-01-15
http://www.securityfocus.com/bid/79701
Adobe Flash Player and AIR CVE-2015-8651 Unspecified Integer Overflow Vulnerability
2016-01-15
http://www.securityfocus.com/bid/79705
Adobe Flash Player and AIR CVE-2015-8644 Type Confusion Remote Code Execution Vulnerability
2016-01-15
http://www.securityfocus.com/bid/79704
Adobe Flash Player and AIR APSB16-01 Multiple Memory Corruption Vulnerabilities
2016-01-15
http://www.securityfocus.com/bid/79700
Oracle Java SE CVE-2015-4881 Remote Security Vulnerability
2016-01-15
http://www.securityfocus.com/bid/77159
Linux Kernel 'virtio-net' Fragmented Packets Handling Buffer Overflow Vulnerability
2016-01-15
http://www.securityfocus.com/bid/76230
Oracle Java SE CVE-2015-4860 Remote Security Vulnerability
2016-01-15
http://www.securityfocus.com/bid/77162
Oracle Java SE CVE-2015-4844 Remote Security Vulnerability
2016-01-15
http://www.securityfocus.com/bid/77164
Oracle Java SE CVE-2015-4883 Remote Security Vulnerability
2016-01-15
http://www.securityfocus.com/bid/77161
KDE Workspace Arbitrary Command Execution Vulnerability
2016-01-15
http://www.securityfocus.com/bid/70904
Django CVE-2015-8213 Security Bypass Vulnerability
2016-01-15
http://www.securityfocus.com/bid/77750
Linux Kernel CVE-2010-5313 Local Denial of Service Vulnerability
2016-01-15
http://www.securityfocus.com/bid/71363
Linux Kernel CVE-2014-8559 Local Denial of Service Vulnerability
2016-01-15
http://www.securityfocus.com/bid/70854
NTP 'ntp-keygen.c' Predictable Random Number Generator Weakness
2016-01-15
http://www.securityfocus.com/bid/74045
cURL/libcURL CVE-2015-3148 Remote Security Bypass Vulnerability
2016-01-15
http://www.securityfocus.com/bid/74301
libxml2 'parser.c' Out of Bounds Read Multiple Information Disclosure Vulnerabilities
2016-01-15
http://www.securityfocus.com/bid/74241
libpng 'png_convert_to_rfc1123()' Function Out Of Bounds Read Memory Corruption Vulnerability
2016-01-15
http://www.securityfocus.com/bid/77304
netcf CVE-2014-8119 Remote Denial of Service Vulnerability
2016-01-15
http://www.securityfocus.com/bid/78046
Linux Kernel KVM CVE-2014-7842 Local Denial of Service Vulnerability
2016-01-15
http://www.securityfocus.com/bid/71078
cURL/libcURL NTLM connection CVE-2015-3143 Remote Security Bypass Vulnerability
2016-01-15
http://www.securityfocus.com/bid/74299
cups-filters CVE-2015-3279 Remote Heap Buffer Overflow Vulnerability
2016-01-15
http://www.securityfocus.com/bid/75557
cups-filters 'texttopdf' Remote Heap Buffer Overflow Vulnerability
2016-01-15
http://www.securityfocus.com/bid/75436
SANS News
Threatpost
Exploit
phpDolphin <= 2.0.5 - Multiple Vulnerabilities
Roundcube 1.1.3 - Path Traversal Vulnerability
mcart.xls Bitrix Module 6.5.2 - SQL Injection Vulnerability
Amanda <= 3.3.1 - amstar Command Injection Local Root
SevOne NMS <= 5.3.6.0 - Remote Root Exploit
Manage Engine Applications Manager 12 - Multiple Vulnerabilities
Manage Engine Application Manager 12.5 - Arbitrary Command Execution Vulnerability
14.1.2016
Bugtraq
Malware
VBS/TrojanDownloader.Agent.NUQ
Phishing
AOL | 14th January 2016 |
PayPal | 13th January 2016 |
Dr. | 13th January 2016 |
Vulnerebility
SANS News
Threatpost
Exploit
SevOne NMS <= 5.3.6.0 - Remote Root Exploit
Manage Engine Applications Manager 12 - Multiple Vulnerabilities
Manage Engine Application Manager 12.5 - Arbitrary Command Execution Vulnerability
Microsoft Office / COM Object DLL Planting with WMALFXGFXDSP.dll (MS-16-007)
Microsoft Windows devenum.dll!DeviceMoniker::Load() - Heap Corruption Buffer Underflow (MS16-007)
13.1.2016
Bugtraq
Malware
Phishing
Bank of America | 13th January 2016 |
michael swartz | 13th January 2016 |
service@paypal.co.uk | 12th January 2016 |
Vulnerebility
SANS News
Threatpost
Denial-of-Service Flaw Patched in DHCP
Exploit
SNScan 1.05 - Scan Hostname/IP Field Buffer Overflow Crash PoC
WhatsUp Gold 16.3 - Unauthenticated Remote Code Execution
12.1.2016
Bugtraq
SEC Consult whitepaper: Bypassing McAfee Application Whitelisting for Critical Infrastructure Systems 2016-01-12
SEC Consult Vulnerability Lab (research sec-consult com)
[SECURITY] [DSA 3441-1] perl security update 2016-01-11
Salvatore Bonaccorso (carnil debian org)
[SECURITY] [DSA 3440-1] sudo security update 2016-01-11
Ben Hutchings (benh debian org)
Exploiting XXE vulnerabilities in AMF libraries 2016-01-11
Nicolas Grgoire (nicolas gregoire agarri fr)
Re: Mozilla Firefox 44.0b2 Cross-site Scripting Vulnerability 2016-01-11
Reed Loden (reed reedloden com)
Re: TFTP Server 3CTftpSvc Buffer Overflow Vulnerability (Long transporting mode) 2016-01-10
fgghy dodo com
Mozilla Firefox 44.0b2 Cross-site Scripting Vulnerability 2016-01-11
iedb team gmail com
Mozilla Firefox 44.0b2 Cross-site Scripting Vulnerability 2016-01-11
iedb team gmail com
OpenBravo Hibernate HQL Injection 2016-01-11
Ng, Sam \(Fortify\) (samn hpe com)
[SECURITY] [DSA 3439-1] prosody security update 2016-01-10
Salvatore Bonaccorso (carnil debian org)
[SECURITY] [DSA 3437-1] gnutls26 security update 2016-01-09
Salvatore Bonaccorso (carnil debian org)
Malware
TrojanDownloader:MSIL/Genmaldow.B
TrojanDownloader:MSIL/Bladabindi.K
Backdoor:MSIL/Bladabindi.BI
HackTool:MSIL/Injector.A
TrojanDownloader:MSIL/Guplof.D
TrojanDownloader:Win32/Nymaim.I
Backdoor:Win32/Htbot.C
PWS:Win32/Fareit.AH
Backdoor:Win32/Farfli.DC
Ransom:JS/Enrume.A
Phishing
service@paypal.co.uk | 12th January 2016 |
setting | 12th January 2016 |
Dr. | 12th January 2016 |
Jim Johnson | 12th January 2016 |
Microsoft | 12th January 2016 |
Vulnerebility
Google Chrome Prior to 47.0.2526.73 Multiple Security Vulnerabilities
2016-01-12
http://www.securityfocus.com/bid/78416
Xen CVE-2015-8338 Denial of Service Vulnerability
2016-01-12
http://www.securityfocus.com/bid/78920
Antirez Redis 'lua_struct.c' Integer Overflow Vulnerability
2016-01-12
http://www.securityfocus.com/bid/77507
Oracle Java SE CVE-2015-0478 Remote Security Vulnerability
2016-01-12
http://www.securityfocus.com/bid/74147
Oracle Java SE CVE-2015-4883 Remote Security Vulnerability
2016-01-12
http://www.securityfocus.com/bid/77161
Oracle Java SE CVE-2015-4806 Remote Security Vulnerability
2016-01-12
http://www.securityfocus.com/bid/77126
Oracle Java SE CVE-2015-0458 Remote Security Vulnerability
2016-01-12
http://www.securityfocus.com/bid/74141
Oracle Java SE CVE-2015-0488 Remote Security Vulnerability
2016-01-12
http://www.securityfocus.com/bid/74111
Oracle Java SE CVE-2015-4843 Remote Security Vulnerability
2016-01-12
http://www.securityfocus.com/bid/77160
IBM Java SDK CVE-2015-5006 Local Information Disclosure Vulnerability
2016-01-12
http://www.securityfocus.com/bid/77645
Oracle Java SE CVE-2015-4840 Remote Security Vulnerability
2016-01-12
http://www.securityfocus.com/bid/77242
Oracle Java SE CVE-2015-4902 Remote Security Vulnerability
2016-01-12
http://www.securityfocus.com/bid/77241
Oracle Java SE CVE-2015-4871 Multiple Security Bypass Vulnerabilities
2016-01-12
http://www.securityfocus.com/bid/77238
Oracle Java SE CVE-2015-4810 Local Security Vulnerability
2016-01-12
http://www.securityfocus.com/bid/77229
Oracle Java SE CVE-2015-4872 Remote Security Vulnerability
2016-01-12
http://www.securityfocus.com/bid/77211
Oracle Java SE CVE-2015-4911 Remote Security Vulnerability
2016-01-12
http://www.securityfocus.com/bid/77209
Oracle Java SE CVE-2015-4893 Remote Security Vulnerability
2016-01-12
http://www.securityfocus.com/bid/77207
Oracle Java SE CVE-2015-4803 Remote Security Vulnerability
2016-01-12
http://www.securityfocus.com/bid/77200
Oracle Java SE CVE-2015-4844 Remote Security Vulnerability
2016-01-12
http://www.securityfocus.com/bid/77164
Oracle Java SE CVE-2015-4805 Remote Security Vulnerability
2016-01-12
http://www.securityfocus.com/bid/77163
Apache ActiveMQ CVE-2015-1830 Directory Traversal Vulnerability
2016-01-12
http://www.securityfocus.com/bid/76452
Apache ActiveMQ 'refresh' Parameter Cross Site Scripting Vulnerability
2016-01-12
http://www.securityfocus.com/bid/65615
Apache ActiveMQ Source Code Information Disclosure Vulnerability
2016-01-12
http://www.securityfocus.com/bid/39636
Apache ActiveMQ CVE-2013-3060 Information Disclosure and Denial of Service Vulnerability
2016-01-12
http://www.securityfocus.com/bid/59402
ActiveMQ Cron Jobs CVE-2013-1879 HTML Injection Vulnerability
2016-01-12
http://www.securityfocus.com/bid/61142
Apache ActiveMQ 'createDestination.action' HTML Injection Vulnerability
2016-01-12
http://www.securityfocus.com/bid/39119
Apache ActiveMQ CVE-2012-6092 Multiple Cross Site Scripting Vulnerabilities
2016-01-12
http://www.securityfocus.com/bid/59400
Apache ActiveMQ CVE-2014-8110 Multiple Cross Site Scripting Vulnerabilities
2016-01-12
http://www.securityfocus.com/bid/72511
SANS News
January 2016 Microsoft Patch Tuesday
Threatpost
Exploit
FingerTec Fingerprint Reader - Remote Access and Remote Enrollment
FortiGate OS Version 4.x - 5.0.7 - SSH Backdoor
Linux Kernel overlayfs - Local Privilege Escalation
Grassroots DICOM (GDCM) 2.6.0 and 2.6.1 - ImageRegionReader::ReadIntoBuffer Buffer Overflow
11.1.2016
Bugtraq
[SECURITY] [DSA 3441-1] perl security update 2016-01-11
Salvatore Bonaccorso (carnil debian org)
[SECURITY] [DSA 3440-1] sudo security update 2016-01-11
Ben Hutchings (benh debian org)
Exploiting XXE vulnerabilities in AMF libraries 2016-01-11
Nicolas Grgoire (nicolas gregoire agarri fr)
Re: Mozilla Firefox 44.0b2 Cross-site Scripting Vulnerability 2016-01-11
Reed Loden (reed reedloden com)
Re: TFTP Server 3CTftpSvc Buffer Overflow Vulnerability (Long transporting mode) 2016-01-10
fgghy dodo com
Mozilla Firefox 44.0b2 Cross-site Scripting Vulnerability 2016-01-11
iedb team gmail com
Mozilla Firefox 44.0b2 Cross-site Scripting Vulnerability 2016-01-11
iedb team gmail com
OpenBravo Hibernate HQL Injection 2016-01-11
Ng, Sam \(Fortify\) (samn hpe com)
[SECURITY] [DSA 3439-1] prosody security update 2016-01-10
Salvatore Bonaccorso (carnil debian org)
[SECURITY] [DSA 3437-1] gnutls26 security update 2016-01-09
Salvatore Bonaccorso (carnil debian org)
[SECURITY] [DSA 3438-1] xscreensaver security update 2016-01-10
Michael Gilbert (mgilbert debian org)
CVE-2015-8396: GDCM buffer overflow in ImageRegionReader::ReadIntoBuffer 2016-01-11
Stelios Tsampas (stelios census-labs com)
CVE-2015-8397: GDCM out-of-bounds read in JPEGLSCodec::DecodeExtent 2016-01-11
Stelios Tsampas (stelios census-labs com)
Malware
Phishing
NatWest | 11th January 2016 |
AOL | 10th January 2016 |
AOL | 10th January 2016 |
Vulnerebility
Google Chrome Prior to 47.0.2526.80 Multiple Security Vulnerabilities
2016-01-11
http://www.securityfocus.com/bid/78734
Kaspersky Antivirus Multiple Memory Corruption Vulnerabilities
2016-01-11
http://www.securityfocus.com/bid/77608
Multiple Kaspersky Products Certificate Handling Directory Traversal Vulnerability
2016-01-11
http://www.securityfocus.com/bid/77616
Multiple Kaspersky Products Local Security Bypass Vulnerability
2016-01-11
http://www.securityfocus.com/bid/77618
OpenSSL CVE-2015-3194 Denial of Service Vulnerability
2016-01-11
http://www.securityfocus.com/bid/78623
OpenSSL CVE-2015-3195 Information Disclosure Vulnerability
2016-01-11
http://www.securityfocus.com/bid/78626
OpenSSL CVE-2015-3196 Denial of Service Vulnerability
2016-01-11
http://www.securityfocus.com/bid/78622
Node.js CVE-2015-6764 Out of Bounds Denial of Service Vulnerability
2016-01-11
http://www.securityfocus.com/bid/78209
Apache ActiveMQ CVE-2015-1830 Directory Traversal Vulnerability
2016-01-11
http://www.securityfocus.com/bid/76452
Apache ActiveMQ 'refresh' Parameter Cross Site Scripting Vulnerability
2016-01-11
http://www.securityfocus.com/bid/65615
Apache ActiveMQ Source Code Information Disclosure Vulnerability
2016-01-11
http://www.securityfocus.com/bid/39636
Apache ActiveMQ CVE-2013-3060 Information Disclosure and Denial of Service Vulnerability
2016-01-11
http://www.securityfocus.com/bid/59402
ActiveMQ Cron Jobs CVE-2013-1879 HTML Injection Vulnerability
2016-01-11
http://www.securityfocus.com/bid/61142
Apache ActiveMQ 'createDestination.action' HTML Injection Vulnerability
2016-01-11
http://www.securityfocus.com/bid/39119
Apache ActiveMQ CVE-2012-6092 Multiple Cross Site Scripting Vulnerabilities
2016-01-11
http://www.securityfocus.com/bid/59400
Apache ActiveMQ CVE-2014-8110 Multiple Cross Site Scripting Vulnerabilities
2016-01-11
http://www.securityfocus.com/bid/72511
Apache ActiveMQ CVE-2012-6551 Denial of Service Vulnerability
2016-01-11
http://www.securityfocus.com/bid/59401
PHP PCRE Extension 'trunk/pcre_exec.c' Information Disclosure Vulnerability
2016-01-11
http://www.securityfocus.com/bid/76157
PCRE Regular Expression Handling Heap Buffer Overflow Vulnerability
2016-01-11
http://www.securityfocus.com/bid/76187
Mozilla Firefox Multiple Security Vulnerabilities
2016-01-11
http://www.securityfocus.com/bid/79279
PHPMailer 'class.phpmailer.php' Security Bypass Vulnerability
2016-01-11
http://www.securityfocus.com/bid/78619
IBM Installation Manager '/tmp' Local Command Injection Vulnerability
2016-01-11
http://www.securityfocus.com/bid/77558
Oracle Java SE CVE-2015-4903 Remote Security Vulnerability
2016-01-11
http://www.securityfocus.com/bid/77194
Oracle Java SE CVE-2015-4882 Remote Security Vulnerability
2016-01-11
http://www.securityfocus.com/bid/77181
Oracle Java SE CVE-2015-4734 Remote Security Vulnerability
2016-01-11
http://www.securityfocus.com/bid/77192
Cisco Integrated Management Controller CVE-2015-6399 Denial of Service Vulnerability
2016-01-11
http://www.securityfocus.com/bid/79031
Ganeti RESTful Control Interface Information Disclosure and Denial of Service Vulnerabilities
2016-01-11
http://www.securityfocus.com/bid/79787
Lepide Active Directory Self Service Password Reset Security Bypass Vulnerability
2016-01-11
http://www.securityfocus.com/bid/78729
SANS News
Threatpost
Exploit
TrendMicro node.js HTTP Server Listening on localhost Can Execute Commands
Amanda <= 3.3.1 - Local Root Exploit
KeePass Password Safe Classic 1.29 - Crash PoC
Adobe Flash BlurFilter Processing - Out-of-Bounds Memset
Adobe Flash - Use-After-Free When Rendering Displays From Multiple Scripts
Adobe Flash - Use-After-Free When Setting Stage
10.1.2016
Bugtraq
Executable installers are vulnerable^WEVIL (case 20): TrueCrypt's installers allow arbitrary (remote) code execution and escalation of privilege 2016-01-08
Stefan Kanthak (stefan kanthak nexgo de)
MobaXTerm before version 8.5 vulnerability in "jump host" functionality 2016-01-08
Thomas Bleier (thomas bleier at)
[RT-SA-2015-005] o2/Telefonica Germany: ACS Discloses VoIP/SIP Credentials 2016-01-08
RedTeam Pentesting GmbH (release redteam-pentesting de)
WP Symposium Pro Social Network Plugin XSS and Critical CSRF Vulnerability 2016-01-08
Rahul Pratap Singh (techno rps gmail com)
[security bulletin] HPSBUX03435 SSRT102977 rev.1 - HP-UX Web Server Suite running Apache, Remote Denial of Service (DoS) 2016-01-07
security-alert hpe com
Symantec EP DOS 2016-01-08
hyp3rphp gmail com
APPLE-SA-2016-01-07-1 QuickTime 7.7.9 2016-01-08
Apple Product Security (product-security-noreply lists apple com)
APPLE-SA-2016-01-07-1 QuickTime 7.7.9 2016-01-08
Apple Product Security (product-security-noreply lists apple com)
Possible vulnerability in F5 BIG-IP LTM - Improper input validation of the HTTP version number of the HTTP reqest allows any payload size and conent to pass through 2016-01-07
Eitan Caspi (eitanc yahoo com)
[CVE-2015-7242] AVM FRITZ!Box: HTML Injection Vulnerability 2016-01-07
Daniel Schliebner (mail ds-develop de)
Malware
Phishing
Dr. | 10th January 2016 |
iCloud-ID | 10th January 2016 |
PayPal | 9th January 2016 |
Dolores Hampton | 9th January 2016 |
Vulnerebility
Oracle Java SE CVE-2015-0458 Remote Security Vulnerability
2016-01-10
http://www.securityfocus.com/bid/74141
Oracle Java SE CVE-2015-0488 Remote Security Vulnerability
2016-01-10
http://www.securityfocus.com/bid/74111
Oracle Java SE CVE-2015-4843 Remote Security Vulnerability
2016-01-10
http://www.securityfocus.com/bid/77160
IBM Java SDK CVE-2015-5006 Local Information Disclosure Vulnerability
2016-01-10
http://www.securityfocus.com/bid/77645
Oracle Java SE CVE-2015-4840 Remote Security Vulnerability
2016-01-10
http://www.securityfocus.com/bid/77242
Oracle Java SE CVE-2015-4902 Remote Security Vulnerability
2016-01-10
http://www.securityfocus.com/bid/77241
Oracle Java SE CVE-2015-4871 Multiple Security Bypass Vulnerabilities
2016-01-10
http://www.securityfocus.com/bid/77238
Oracle Java SE CVE-2015-4810 Local Security Vulnerability
2016-01-10
http://www.securityfocus.com/bid/77229
Oracle Java SE CVE-2015-4872 Remote Security Vulnerability
2016-01-10
http://www.securityfocus.com/bid/77211
Oracle Java SE CVE-2015-4911 Remote Security Vulnerability
2016-01-10
http://www.securityfocus.com/bid/77209
Oracle Java SE CVE-2015-4893 Remote Security Vulnerability
2016-01-10
http://www.securityfocus.com/bid/77207
Oracle Java SE CVE-2015-4803 Remote Security Vulnerability
2016-01-10
http://www.securityfocus.com/bid/77200
Oracle Java SE CVE-2015-4844 Remote Security Vulnerability
2016-01-10
http://www.securityfocus.com/bid/77164
Oracle Java SE CVE-2015-4805 Remote Security Vulnerability
2016-01-10
http://www.securityfocus.com/bid/77163
Oracle Java SE CVE-2015-2625 Remote Security Vulnerability
2016-01-10
http://www.securityfocus.com/bid/75895
Oracle Java SE CVE-2015-4860 Remote Security Vulnerability
2016-01-10
http://www.securityfocus.com/bid/77162
Google Chrome Prior to 47.0.2526.80 Multiple Security Vulnerabilities
2016-01-10
http://www.securityfocus.com/bid/78734
Oracle Java SE CVE-2015-0477 Remote Security Vulnerability
2016-01-10
http://www.securityfocus.com/bid/74119
Kaspersky Antivirus Multiple Memory Corruption Vulnerabilities
2016-01-10
http://www.securityfocus.com/bid/77608
SSL/TLS RC4 CVE-2015-2808 Information Disclosure Weakness
2016-01-10
http://www.securityfocus.com/bid/73684
Multiple Kaspersky Products Certificate Handling Directory Traversal Vulnerability
2016-01-10
http://www.securityfocus.com/bid/77616
Multiple Kaspersky Products Local Security Bypass Vulnerability
2016-01-10
http://www.securityfocus.com/bid/77618
Oracle Java SE CVE-2015-4842 Remote Security Vulnerability
2016-01-10
http://www.securityfocus.com/bid/77154
OpenSSL CVE-2015-3194 Denial of Service Vulnerability
2016-01-10
http://www.securityfocus.com/bid/78623
OpenSSL CVE-2015-3195 Information Disclosure Vulnerability
2016-01-10
http://www.securityfocus.com/bid/78626
OpenSSL CVE-2015-3196 Denial of Service Vulnerability
2016-01-10
http://www.securityfocus.com/bid/78622
Oracle Java SE CVE-2015-0469 Remote Security Vulnerability
2016-01-10
http://www.securityfocus.com/bid/74072
Oracle Java SE CVE-2015-4835 Remote Security Vulnerability
2016-01-10
http://www.securityfocus.com/bid/77148
SANS News
Threatpost
Exploit
WP Symposium Pro Social Network Plugin 15.12 - Multiple Vulnerabilities
8.1.2016
Bugtraq
Executable installers are vulnerable^WEVIL (case 20): TrueCrypt's installers allow arbitrary (remote) code execution and escalation of privilege 2016-01-08
Stefan Kanthak (stefan kanthak nexgo de)
MobaXTerm before version 8.5 vulnerability in "jump host" functionality 2016-01-08
Thomas Bleier (thomas bleier at)
[RT-SA-2015-005] o2/Telefonica Germany: ACS Discloses VoIP/SIP Credentials 2016-01-08
RedTeam Pentesting GmbH (release redteam-pentesting de)
WP Symposium Pro Social Network Plugin XSS and Critical CSRF Vulnerability 2016-01-08
Rahul Pratap Singh (techno rps gmail com)
[security bulletin] HPSBUX03435 SSRT102977 rev.1 - HP-UX Web Server Suite running Apache, Remote Denial of Service (DoS) 2016-01-07
security-alert hpe com
Symantec EP DOS 2016-01-08
hyp3rphp gmail com
APPLE-SA-2016-01-07-1 QuickTime 7.7.9 2016-01-08
Apple Product Security (product-security-noreply lists apple com)
APPLE-SA-2016-01-07-1 QuickTime 7.7.9 2016-01-08
Apple Product Security (product-security-noreply lists apple com)
Possible vulnerability in F5 BIG-IP LTM - Improper input validation of the HTTP version number of the HTTP reqest allows any payload size and conent to pass through 2016-01-07
Eitan Caspi (eitanc yahoo com)
[CVE-2015-7242] AVM FRITZ!Box: HTML Injection Vulnerability 2016-01-07
Daniel Schliebner (mail ds-develop de)
Malware
Phishing
Vulnerebility
SANS News
Threatpost
Exploit
WP Symposium Pro Social Network Plugin 15.12 - Multiple Vulnerabilities
OpenMRS Reporting Module 0.9.7 - Remote Code Execution
AVM FRITZ!Box < 6.30 - Buffer Overflow
7.1.2016
Bugtraq
Possible vulnerability in F5 BIG-IP LTM - Improper input validation of the HTTP version number of the HTTP reqest allows any payload size and conent to pass through 2016-01-07
Eitan Caspi (eitanc yahoo com)
[CVE-2015-7242] AVM FRITZ!Box: HTML Injection Vulnerability 2016-01-07
Daniel Schliebner (mail ds-develop de)
Serendipity Security Advisory - XSS Vulnerability - CVE-2015-8603 2016-01-07
Onur Yilmaz (onur netsparker com)
[RT-SA-2015-001] AVM FRITZ!Box: Remote Code Execution via Buffer Overflow 2016-01-07
RedTeam Pentesting GmbH (release redteam-pentesting de)
[RT-SA-2014-014] AVM FRITZ!Box: Arbitrary Code Execution Through Manipulated Firmware Images 2016-01-07
RedTeam Pentesting GmbH (release redteam-pentesting de)
Executable installers are vulnerable^WEVIL (case 19): ZoneAlarm's installers allow arbitrary (remote) code execution and escalation of privilege 2016-01-07
Stefan Kanthak (stefan kanthak nexgo de)
[SYSS-2015-062] ownCloud Information Exposure Through Directory Listing (CVE-2016-1499) 2016-01-07
erlijn vangenuchten syss de
Executable installers are vulnerable^WEVIL (case 18): EMSISoft's installers allow arbitrary (remote) code execution and escalation of privilege 2016-01-07
Stefan Kanthak (stefan kanthak nexgo de)
[security bulletin] HPSBGN03530 rev.1 - HPE UCMDB Browser, Remote Disclosure of Sensitive Information, Local Unauthorized Access 2016-01-06
security-alert hpe com
Malware
Backdoor:MSIL/Corinrat.A
TrojanDownloader:Win32/Banload.BFZ
TrojanDownloader:MSIL/Banload.AO
Phishing
Microsoft | 6th January 2016 |
Pay-Pal | 6th January 2016 |
[Norton Anti][Shaw Suspected |
Vulnerebility
SANS News
A recent example of wire transfer fraud
Threatpost
Exploit
MediaAccess TG788vn - Unauthenticated File Disclosure
6.1.2016
Bugtraq
[SECURITY] [DSA 3434-1] linux security update 2016-01-05
Ben Hutchings (benh debian org)
[SECURITY] [DSA 3435-1] git security update 2016-01-05
Laszlo Boszormenyi \(GCS\) (gcs debian org)
CVE-2015-7944, CVE-2015-7945 - Ganeti Security Advisory (DoS, Unauthenticated Info Leak) 2016-01-04
Pierre Kim (pierre kim sec gmail com)
Confluence Vulnerabilities 2016-01-04
Sebastian Perez (s3bap3 gmail com)
Executable installers/self-extractors are vulnerable^WEVIL (case 17): Kaspersky Labs utilities 2016-01-03
Stefan Kanthak (stefan kanthak nexgo de)
[SECURITY] [DSA 3433-1] samba security update 2016-01-02
Salvatore Bonaccorso (carnil debian org)
Malware
Phishing
Microsoft | 6th January 2016 |
Pay-Pal | 6th January 2016 |
[Norton Anti][Shaw Suspected | |
Pvs Nr | 6th January 2016 |
USAA | 6th January 2016 |
Vulnerebility
SANS News
Threatpost
Cisco Jabber Client Vulnerable to Man-in-the-Middle Attack
Exploit
MediaAccess TG788vn - Unauthenticated File Disclosure
TCP Reverse Shell with Password Prompt - 151 bytes
5.1.2016
Bugtraq
CVE-2015-7944, CVE-2015-7945 - Ganeti Security Advisory (DoS, Unauthenticated Info Leak) 2016-01-04
Pierre Kim (pierre kim sec gmail com)
Confluence Vulnerabilities 2016-01-04
Sebastian Perez (s3bap3 gmail com)
Executable installers/self-extractors are vulnerable^WEVIL (case 17): Kaspersky Labs utilities 2016-01-03
Stefan Kanthak (stefan kanthak nexgo de)
[SECURITY] [DSA 3433-1] samba security update 2016-01-02
Salvatore Bonaccorso (carnil debian org)
Open Audit SQL Injection Vulnerability 2016-01-02
Rahul Pratap Singh (techno rps gmail com)
[SECURITY] CVE-2015-5349: Apache Directory Studio command injection vulnerability 2016-01-02
Stefan Seelmann (seelmann apache org)
OSS-2016-02: Weak authentication in NXP Hitag S transponder allows an attacker to read, write and clone any tag 2016-01-01
Ralf Spenneberg (info os-t de)
Malware
TrojanSpy:Win32/Ranbyus.R
Ransom:MSIL/Samas.A
Phishing
TEAM SUPPORT | 5th January 2016 |
Important Notice | 4th January 2016 |
SUPPORT TEAM | 4th January 2016 |
Mail Server X | 4th January 2016 |
Vulnerebility
libxml2 CVE-2015-8710 Out-of-bounds Memory Access Vulnerability
2016-12-31
http://www.securityfocus.com/bid/79811
Autodesk Design Review CVE-2015-8571 Remote Buffer Overflow Vulnerability
2016-12-08
http://www.securityfocus.com/bid/79800
Oracle Java SE CVE-2015-0491 Remote Security Vulnerability
2016-01-04
http://www.securityfocus.com/bid/74094
Oracle Java SE CVE-2015-0459 Remote Security Vulnerability
2016-01-04
http://www.securityfocus.com/bid/74083
OpenSSL CVE-2015-0204 Man in the Middle Security Bypass Vulnerability
2016-01-04
http://www.securityfocus.com/bid/71936
Oracle Java SE CVE-2015-0480 Remote Security Vulnerability
2016-01-04
http://www.securityfocus.com/bid/74104
WebKit CVE-2015-7050 Information Disclosure Vulnerability
2016-01-04
http://www.securityfocus.com/bid/78722
WebKit Multiple Unspecified Memory Corruption Vulnerabilities
2016-01-04
http://www.securityfocus.com/bid/78726
WebKit Multiple Unspecified Memory Corruption Vulnerabilities
2016-01-04
http://www.securityfocus.com/bid/78720
Linux Kernel CVE-2015-8104 Denial of Service Vulnerability
2016-01-04
http://www.securityfocus.com/bid/77524
Xen CVE-2015-8555 Information Disclosure Vulnerability
2016-01-04
http://www.securityfocus.com/bid/79543
Xen 'pt-msi.c' Heap Memory Corruption Vulnerability
2016-01-04
http://www.securityfocus.com/bid/79579
Multiple Adobe Products CVE-2015-5255 Server Side Request Forgery Security Bypass Vulnerability
2016-01-04
http://www.securityfocus.com/bid/77626
Network Time Protocol CVE-2015-7871 Authentication Bypass Vulnerability
2016-01-04
http://www.securityfocus.com/bid/77287
Network Time Protocol CVE-2015-7704 Denial of Service Vulnerability
2016-01-04
http://www.securityfocus.com/bid/77280
Network Time Protocol CVE-2015-5300 Man in the Middle Security Bypass Vulnerability
2016-01-04
http://www.securityfocus.com/bid/77312
Network Time Protocol CVE-2015-7855 Denial of Service Vulnerability
2016-01-04
http://www.securityfocus.com/bid/77283
Adobe Flash Player and AIR CVE-2015-7628 Same Origin Policy Security Bypass Vulnerability
2016-01-04
http://www.securityfocus.com/bid/77063
Mozilla Firefox Multiple Security Vulnerabilities
2016-01-04
http://www.securityfocus.com/bid/79279
IBM Installation Manager '/tmp' Local Command Injection Vulnerability
2016-01-04
http://www.securityfocus.com/bid/77558
Libxml2 'xmlParseConditionalSections()' Function Denial of Service Vulnerability
2016-01-04
http://www.securityfocus.com/bid/79507
Apache Tomcat CVE-2014-7810 Security Bypass Vulnerability
2016-01-04
http://www.securityfocus.com/bid/74665
libxml2 CVE-2015-7498 Denial of Service Vulnerability
2016-01-04
http://www.securityfocus.com/bid/79548
Libxml2 CVE-2015-1819 Denial of Service Vulnerability
2016-01-04
http://www.securityfocus.com/bid/75570
GNU GRUB2 CVE-2015-8370 Multiple Local Authentication Bypass Vulnerabilities
2016-01-04
http://www.securityfocus.com/bid/79358
cups-filters CVE-2015-8327 Arbitrary Command Execution Vulnerability
2016-01-04
http://www.securityfocus.com/bid/78524
Google Android 'PPP Character Device Driver' Local Denial of Service Vulnerability
2016-01-04
http://www.securityfocus.com/bid/77033
Multiple RedHat JBoss Products CVE-2015-7501 Remote Code Execution Vulnerability
2016-01-04
http://www.securityfocus.com/bid/78215
Libxml2 'xmlDictComputeFastQKey()' Function Denial of Service Vulnerability
2016-01-04
http://www.securityfocus.com/bid/79508
OpenStack Nova CVE-2015-7713 Security Bypass Vulnerability
2016-01-04
http://www.securityfocus.com/bid/76960
SANS News
Ransom32: The first javascript ransomware
Threatpost
Exploit
Online Airline Booking System - Multiple Vulnerabilities
Simple PHP Polling System - Multiple Vulnerabilities
Ubuntu 14.04 LTS, 15.10 overlayfs - Local Root Exploit
Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution
Atlassian Confluence 5.2 / 5.8.14 / 5.8.15 - Multiple Vulnerabilities
PHPIPAM 1.1.010 - Multiple Vulnerabilities
Ganeti - Multiple Vulnerabilities
4.1.2016
Bugtraq
CVE-2015-7944, CVE-2015-7945 - Ganeti Security Advisory (DoS, Unauthenticated Info Leak) 2016-01-04
Pierre Kim (pierre kim sec gmail com)
Confluence Vulnerabilities 2016-01-04
Sebastian Perez (s3bap3 gmail com)
Executable installers/self-extractors are vulnerable^WEVIL (case 17): Kaspersky Labs utilities 2016-01-03
Stefan Kanthak (stefan kanthak nexgo de)
[SECURITY] [DSA 3433-1] samba security update 2016-01-02
Salvatore Bonaccorso (carnil debian org)
Open Audit SQL Injection Vulnerability 2016-01-02
Rahul Pratap Singh (techno rps gmail com)
[SECURITY] CVE-2015-5349: Apache Directory Studio command injection vulnerability 2016-01-02
Stefan Seelmann (seelmann apache org)
OSS-2016-02: Weak authentication in NXP Hitag S transponder allows an attacker to read, write and clone any tag 2016-01-01
Ralf Spenneberg (info os-t de)
Malware
BrowserModifier:Win32/Shopperz
Phishing
Mail Server X | 4th January 2016 |
Diane Lynch | 4th January 2016 |
Barclays | 3rd January 2016 |
Amazon | 3rd January 2016 |
Vulnerebility
libxml2 CVE-2015-8710 Out-of-bounds Memory Access Vulnerability
2016-12-31
http://www.securityfocus.com/bid/79811
Autodesk Design Review CVE-2015-8571 Remote Buffer Overflow Vulnerability
2016-12-08
http://www.securityfocus.com/bid/79800
Oracle Java SE CVE-2015-0491 Remote Security Vulnerability
2016-01-04
http://www.securityfocus.com/bid/74094
Oracle Java SE CVE-2015-0459 Remote Security Vulnerability
2016-01-04
http://www.securityfocus.com/bid/74083
OpenSSL CVE-2015-0204 Man in the Middle Security Bypass Vulnerability
2016-01-04
http://www.securityfocus.com/bid/71936
Oracle Java SE CVE-2015-0480 Remote Security Vulnerability
2016-01-04
http://www.securityfocus.com/bid/74104
WebKit CVE-2015-7050 Information Disclosure Vulnerability
2016-01-04
http://www.securityfocus.com/bid/78722
WebKit Multiple Unspecified Memory Corruption Vulnerabilities
2016-01-04
http://www.securityfocus.com/bid/78726
WebKit Multiple Unspecified Memory Corruption Vulnerabilities
2016-01-04
http://www.securityfocus.com/bid/78720
Linux Kernel CVE-2015-8104 Denial of Service Vulnerability
2016-01-04
http://www.securityfocus.com/bid/77524
Xen CVE-2015-8555 Information Disclosure Vulnerability
2016-01-04
http://www.securityfocus.com/bid/79543
Xen 'pt-msi.c' Heap Memory Corruption Vulnerability
2016-01-04
http://www.securityfocus.com/bid/79579
Multiple Adobe Products CVE-2015-5255 Server Side Request Forgery Security Bypass Vulnerability
2016-01-04
http://www.securityfocus.com/bid/77626
Network Time Protocol CVE-2015-7871 Authentication Bypass Vulnerability
2016-01-04
http://www.securityfocus.com/bid/77287
Network Time Protocol CVE-2015-7704 Denial of Service Vulnerability
2016-01-04
http://www.securityfocus.com/bid/77280
Network Time Protocol CVE-2015-5300 Man in the Middle Security Bypass Vulnerability
2016-01-04
http://www.securityfocus.com/bid/77312
Network Time Protocol CVE-2015-7855 Denial of Service Vulnerability
2016-01-04
http://www.securityfocus.com/bid/77283
Adobe Flash Player and AIR CVE-2015-7628 Same Origin Policy Security Bypass Vulnerability
2016-01-04
http://www.securityfocus.com/bid/77063
Mozilla Firefox Multiple Security Vulnerabilities
2016-01-04
http://www.securityfocus.com/bid/79279
IBM Installation Manager '/tmp' Local Command Injection Vulnerability
2016-01-04
http://www.securityfocus.com/bid/77558
Libxml2 'xmlParseConditionalSections()' Function Denial of Service Vulnerability
2016-01-04
http://www.securityfocus.com/bid/79507
Apache Tomcat CVE-2014-7810 Security Bypass Vulnerability
2016-01-04
http://www.securityfocus.com/bid/74665
libxml2 CVE-2015-7498 Denial of Service Vulnerability
2016-01-04
http://www.securityfocus.com/bid/79548
Libxml2 CVE-2015-1819 Denial of Service Vulnerability
2016-01-04
http://www.securityfocus.com/bid/75570
GNU GRUB2 CVE-2015-8370 Multiple Local Authentication Bypass Vulnerabilities
2016-01-04
http://www.securityfocus.com/bid/79358
cups-filters CVE-2015-8327 Arbitrary Command Execution Vulnerability
2016-01-04
http://www.securityfocus.com/bid/78524
Google Android 'PPP Character Device Driver' Local Denial of Service Vulnerability
2016-01-04
http://www.securityfocus.com/bid/77033
Multiple RedHat JBoss Products CVE-2015-7501 Remote Code Execution Vulnerability
2016-01-04
http://www.securityfocus.com/bid/78215
Libxml2 'xmlDictComputeFastQKey()' Function Denial of Service Vulnerability
2016-01-04
http://www.securityfocus.com/bid/79508
OpenStack Nova CVE-2015-7713 Security Bypass Vulnerability
2016-01-04
http://www.securityfocus.com/bid/76960
SANS News
Threatpost
Exploit
Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution
pdfium CPDF_DIBSource::DownSampleScanline32Bit - Heap-Based Out-of-Bounds Read
pdfium CPDF_TextObject::CalcPositionData - Heap-Based Out-of-Bounds Read
pdfium IsFlagSet (v8 memory management) - SIGSEGV
pdfium CPDF_Function::Call - Stack-Based Buffer Overflow
3.1.2016
Bugtraq
Malware
Phishing
Amazon | 2nd January 2016 |
Amazon | 2nd January 2016 |
amtoandmxi | 2nd January 2016 |
Support | 2nd January 2016 |
Paypal Support | 2nd January 2016 |
Vulnerebility
SANS News
x86_64 Linux bind TCP port shellcode
tcp bindshell with password prompt in 162 bytes
Threatpost
Exploit
2.1.2016
Bugtraq
OSS-2016-02: Weak authentication in NXP Hitag S transponder allows an attacker to read, write and clone any tag 2016-01-01
Ralf Spenneberg (info os-t de)
OSS-2016-03: Insufficient Integrity Protection in Winkhaus Bluesmart locking systems using Hitag S 2016-01-01
Ralf Spenneberg (info os-t de)
[SECURITY] [DSA 3431-1] ganeti security update 2016-01-01
Moritz Muehlenhoff (jmm debian org)
OSS-2016-01: Insufficient integrity checks in Uhlmann & Zacher Clex prime locking systems using 125 kHz EM4450 transponders 2016-01-01
Ralf Spenneberg (info os-t de)
[SECURITY] [DSA 3432-1] icedove security update 2016-01-01
Moritz Muehlenhoff (jmm debian org)
Malware
Phishing
Support | 2nd January 2016 |
Paypal Support | 2nd January 2016 |
Natwest | 1st January 2016 |
Capital One 360 | 1st January 2016 |
Vulnerebility
SANS News
Threatpost
Exploit