Databáze Hot News 2017 March - 2017 January February March April May June July August September October November December


31.3.2017

Bugtraq

[security bulletin] HPESBHF03723 rev.1 - HPE Aruba ClearPass Policy Manager, using Apache Struts, Remote Code Execution 2017-03-29
security-alert hpe com

[security bulletin] HPESBUX03725 rev.1 - HPE HP-UX Web Server Suite running Apache, Multiple Vulnerabilities 2017-03-29
security-alert hpe com

ESA-2017-013: RSA Archer® GRC Security Operations Management Sensitive Information Disclosure Vulnerability 2017-03-29
EMC Product Security Response Center (Security_Alert emc com)

ESA-2017-028: EMC Isilon OneFS Path Traversal Vulnerability 2017-03-29
EMC Product Security Response Center (Security_Alert emc com)

[SECURITY] [DSA 3824-1] firebird2.5 security update 2017-03-29
Sebastien Delafond (seb debian org)

Malware

Backdoor.Khrat

Phishing

Yahoo UK

31st March 2017

Yahoo UK Security Issue

MR ANTHONY CHARLES

30th March 2017

UNITED BANK OF AFRICA
INTERNATIONAL

Vulnerebility

Pixie CVE-2017-7363 Cross Site Scripting Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97259

NetIQ Sentinel CVE-2017-5185 Denial of Service Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97267

Dahua IP Camera CVE-2017-7253 Privilege Escalation and Information Disclosure Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/97263

MikroTik RouterBoard CVE-2017-7285 Remote Denial of Service Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97266

NetIQ Sentinel CVE-2017-5184 Information Disclosure Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97262

Sophos Web Appliance Multiple Command Injection and Session Fixation Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/97261

Bubblewrap CVE-2017-5226 Security Bypass Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97260

Linux Kernel CVE-2017-2647 Null Pointer Deference Local Privilege Escalation Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97258

Linux Kernel CVE-2017-7346 Local Denial of Service Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97257

Wonderware InTouch Access Anywhere Multiple Security Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/97256

Multiple eMLi Products CVE-2017-7258 Directory Traversal Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97255

Multiple Schneider Electric Modicon Products Weak Cryptography Multiple Security Weaknesses
2017-03-31
http://www.securityfocus.com/bid/97254

MantisBT CVE-2017-7241 Cross Site Scripting Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97253

MantisBT CVE-2017-6973 Cross Site Scripting Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97252

MantisBT CVE-2017-7309 Cross Site Scripting Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97251

Mozilla Firefox CVE-2017-5426 Security Bypass Vulnerability
2017-03-31
http://www.securityfocus.com/bid/96694

Mozilla Firefox and Thunderbird Multiple Security Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/96693

Mozilla Firefox CVE-2017-5403 Denial of Service Vulnerability
2017-03-31
http://www.securityfocus.com/bid/96691

Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/96664

Mozilla Firefox MFSA 2017-05 Multiple Security Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/96692

Mozilla Firefox and Thunderbird CVE-2017-5401 Memory Corruption Vulnerability
2017-03-31
http://www.securityfocus.com/bid/96677

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/96651

Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/96654

IBM Algo One CVE-2017-1154 Unauthorized Access Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97248

Xen 'xenstore' Denial of Service Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97250

CentreCOM AR260S V2 CVE-2017-2125 Privilege Escalation Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97249

IBM TRIRIGA Application Platform CVE-2017-1171 Unspecified Remote Privilege Escalation Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97245

IBM Cúram Social Program Management CVE-2016-6111 XML External Entity Injection Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97244

Miele Professional PG 8528 CVE-2017-7240 Directory Traversal Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97080

Trango Altum AC600 Devices CVE-2016-10306 Insecure Default Password Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97241MantisBT CVE-2017-6973 Cross Site Scripting Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97252

MantisBT CVE-2017-7309 Cross Site Scripting Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97251

Mozilla Firefox CVE-2017-5426 Security Bypass Vulnerability
2017-03-31
http://www.securityfocus.com/bid/96694

Mozilla Firefox and Thunderbird Multiple Security Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/96693

Mozilla Firefox CVE-2017-5403 Denial of Service Vulnerability
2017-03-31
http://www.securityfocus.com/bid/96691

Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/96664

Mozilla Firefox MFSA 2017-05 Multiple Security Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/96692

Mozilla Firefox and Thunderbird CVE-2017-5401 Memory Corruption Vulnerability
2017-03-31
http://www.securityfocus.com/bid/96677

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/96651

Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/96654

IBM Algo One CVE-2017-1154 Unauthorized Access Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97248

Xen 'xenstore' Denial of Service Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97250

CentreCOM AR260S V2 CVE-2017-2125 Privilege Escalation Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97249

IBM TRIRIGA Application Platform CVE-2017-1171 Unspecified Remote Privilege Escalation Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97245

IBM Cúram Social Program Management CVE-2016-6111 XML External Entity Injection Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97244

Miele Professional PG 8528 CVE-2017-7240 Directory Traversal Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97080

Trango Altum AC600 Devices CVE-2016-10306 Insecure Default Password Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97241

Multiple Trango devices CVE-2016-10307 Insecure Default Password Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97242

Siklu EtherHaul radios CVE-2016-10308 Insecure Default Password Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97243

Multiple IBM Products CVE-2017-1133 Cross Site Scripting Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97239

Exponent CMS CVE-2016-9019 SQL Injection Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97240

Multiple VMware Products CVE-2017-4902 Heap-Based Buffer Overflow Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97163

Multiple VMware Products CVE-2017-4904 Memory Corruption Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97165

Multiple VMware Products CVE-2017-4903 Memory Corruption Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97160

Multiple VMware Products CVE-2017-4905 Information Disclosure Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97164

Honeywell Intermec Industrial Printers CVE-2017-5671 Local Privilege Escalation Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97236

Exponent CMS CVE-2016-7789 SQL Injection Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97235

Exponent CMS CVE-2016-7788 SQL Injection Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97233

Wordpress BuddyPress Plugin CVE-2017-6954 Security Bypass Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97238

Multiple Flexense Products CVE-2017-7310 Buffer Overflow Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97237

SANS News

Pro & Con of Outsourcing your SOC

Threatpost

NukeBot Banking Trojan Source Code Leaked Online by Author

Industry Braces for Repeal of ISP Privacy Rules

Github Repository Owners Targeted by Data-Stealing Malware

New Mirai Variant Carries Out 54-Hour DDoS Attacks

Exploit

Apple macOS/IOS 10.12.2(16C67) - mach_msg Heap Overflow

30.3.2017

Bugtraq

[security bulletin] HPESBHF03723 rev.1 - HPE Aruba ClearPass Policy Manager, using Apache Struts, Remote Code Execution 2017-03-29
security-alert hpe com

[security bulletin] HPESBUX03725 rev.1 - HPE HP-UX Web Server Suite running Apache, Multiple Vulnerabilities 2017-03-29
security-alert hpe com

ESA-2017-013: RSA Archer® GRC Security Operations Management Sensitive Information Disclosure Vulnerability 2017-03-29
EMC Product Security Response Center (Security_Alert emc com)

ESA-2017-028: EMC Isilon OneFS Path Traversal Vulnerability 2017-03-29
EMC Product Security Response Center (Security_Alert emc com)

[SECURITY] [DSA 3824-1] firebird2.5 security update 2017-03-29
Sebastien Delafond (seb debian org)

[SECURITY] [DSA 3798-2] tnef regression update 2017-03-29
Sebastien Delafond (seb debian org)

[slackware-security] mariadb (SSA:2017-087-01) 2017-03-28
Slackware Security Team (security slackware com)

Malware

Trojan.Dimnie

Backdoor.Khrat

Phishing

MR ANTHONY CHARLES

30th March 2017

UNITED BANK OF AFRICA
INTERNATIONAL

CTTExpresso

29th March 2017

=?UTF-8?Q?Erro_no_endere=C3=A7
o_de_entrega.?=

Credit One Platinum Visa Credi

28th March 2017

Earn cash back on
purchases—See if you
Pre-Qualify

Vulnerebility

Multiple Siklu EtherHaul Devices CVE-2017-7318 Remote Command Execution Vulnerability
2017-12-29
http://www.securityfocus.com/bid/97227

MODX Revolution CMS Multiple Security Vulnerabilities
2017-03-30
http://www.securityfocus.com/bid/97228

Apache Ambari CVE-2016-4976 Local Information Disclosure Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97229

XOOPS CVE-2017-7290 SQL Injection Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97230

cURL/libcURL Incomplete Fix CVE-2017-2628 Remote Security Bypass Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97187

Firebird CVE-2017-6369 Remote Code Execution Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97070

RSA Archer Security Operations Management with RSA UCF Local Information Disclosure Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97225

Apache Camel CVE-2017-5643 Server Side Request Forgery Security Bypass Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97226

Linux Kernel CVE-2017-2636 Local Privilege Escalation Vulnerability
2017-03-30
http://www.securityfocus.com/bid/96732

Linux Kernel CVE-2017-7184 Local Privilege Escalation Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97018

Samba CVE-2017-2619 Symlink Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97033

Huawei TIT-AL00 CVE-2017-2735 Local Security Bypass Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97224

Ubuntu AppArmor CVE-2017-6507 Security Bypass Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97223

EMC Isilon OneFS CVE-2017-4980 Directory Traversal Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97222

Google Chrome CVE-2017-5055 Use After Free Memory Corruption Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97221

Google Chrome and Chrome OS Multiple Security Vulnerabilities
2017-03-30
http://www.securityfocus.com/bid/97220

GNU Binutils CVE-2017-7300 Remote Heap Buffer Overflow Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97219

GNU Binutils 'aout_link_add_symbols()' Function Remote Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97218

Exponent CMS CVE-2016-7783 SQL Injection Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97212

GNU Binutils CVE-2017-7299 Remote Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97217

GNU Binutils 'swap_std_reloc_out()' Function Remote Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97216

Exponent CMS CVE-2016-7782 SQL Injection Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97210

GNU Binutils CVE-2017-7304 Remote Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97215

phpMyAdmin PMASA-2017-8 Security Bypass Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97211

HP Intelligent Management Center CVE-2017-5797 Information Disclosure Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97214

Exponent CMS CVE-2016-7780 SQL Injection Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97208

GNU Binutils CVE-2017-7303 Remote Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97213

Samsung Account CVE-2015-0864 Information Disclosure Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97207

Exponent CMS CVE-2016-7781 SQL Injection Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97206

GNU Binutils CVE-2017-7227 Remote Heap Buffer Overflow Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97209
GNU Binutils CVE-2017-7300 Remote Heap Buffer Overflow Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97219

GNU Binutils 'aout_link_add_symbols()' Function Remote Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97218

Exponent CMS CVE-2016-7783 SQL Injection Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97212

GNU Binutils CVE-2017-7299 Remote Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97217

GNU Binutils 'swap_std_reloc_out()' Function Remote Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97216

Exponent CMS CVE-2016-7782 SQL Injection Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97210

GNU Binutils CVE-2017-7304 Remote Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97215

phpMyAdmin PMASA-2017-8 Security Bypass Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97211

HP Intelligent Management Center CVE-2017-5797 Information Disclosure Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97214

Exponent CMS CVE-2016-7780 SQL Injection Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97208

GNU Binutils CVE-2017-7303 Remote Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97213

Samsung Account CVE-2015-0864 Information Disclosure Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97207

Exponent CMS CVE-2016-7781 SQL Injection Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97206

GNU Binutils CVE-2017-7227 Remote Heap Buffer Overflow Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97209

CMS Made Simple CVE-2017-7257 Cross-Site Scripting Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97205

CMS Made Simple CVE-2017-7256 Cross-Site Scripting Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97204

Allwinner Linux kernel 'sunxi-debug.c' Local Privilege Escalation Vulnerability
2017-03-30
http://www.securityfocus.com/bid/93442

Multiple F5 BIG-IP CVE-2016-7474 Local Information Disclosure Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97198

LibTIFF CVE-2016-10269 Heap Based Buffer Overflow Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97201

LibTIFF CVE-2016-10268 Heap Based Buffer Overflow Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97202

LibTIFF CVE-2016-10271 Heap Based Buffer Overflow Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97199

Wonder CMS CVE-2014-8702 Information Disclosure Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97192

LibTIFF CVE-2016-10270 Heap Based Buffer Overflow Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97200

LibTIFF CVE-2016-10272 Heap Based Buffer Overflow Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97197

Disk Sorter Enterprise CVE-2017-7230 Buffer Overflow Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97195

cloudflare-scrape CVE-2017-7235 Remote Code Execution Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97191

Eclipse tinydtls CVE-2017-7243 Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97193

Subrion CMS CVE-2017-6069 Cross Site Request Forgery Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97196

cURL/libcURL Incomplete Fix CVE-2017-2628 Remote Security Bypass Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97187

Eview EV-07S GPS Tracker Buffer Overflow and Information Disclosure Vulnerabilities
2017-03-30
http://www.securityfocus.com/bid/97194

SANS News

Critical VMware vulnerabilities disclosed

Diverting built-in features for the bad

Threatpost

Workarounds Available for Flaws in Siemens RUGGEDCOM Gear

Publicly Attacked Microsoft IIS Zero Day Unlikely to be Patched

Industry Braces for Repeal of ISP Privacy Rules

Exploit

Sync Breeze Enterprise 9.5.16 - 'GET' Buffer Overflow (SEH)

Opensource Classified Ads Script - 'keyword' Parameter SQL Injection

EyesOfNetwork (EON) 5.1 - SQL Injection

AUFS (Ubuntu 15.10) - 'allow_userns' Fuse/Xattr User Namespaces Privilege Escalation

DiskBoss Enterprise 7.8.16 - 'Import Command' Buffer Overflow

DiskBoss Enterprise 7.8.16 - 'Import Command' Buffer Overflow

29.3.2017

Bugtraq

[SECURITY] [DSA 3798-2] tnef regression update 2017-03-29
Sebastien Delafond (seb debian org)

[slackware-security] mariadb (SSA:2017-087-01) 2017-03-28
Slackware Security Team (security slackware com)

APPLE-SA-2017-03-28-1 iCloud for Windows 6.2 2017-03-28
Apple Product Security (product-security-noreply lists apple com)

[SECURITY] [DSA 3823-1] eject security update 2017-03-28
Salvatore Bonaccorso (carnil debian org)

APPLE-SA-2017-03-27-7 macOS Server 5.3 2017-03-27
Apple Product Security (product-security-noreply lists apple com)

[SECURITY] [DSA 3821-1] gst-plugins-ugly1.0 security update 2017-03-27
Moritz Muehlenhoff (jmm debian org)

Malware

Trojan.Dimnie

Phishing

Credit One Platinum Visa Credi

28th March 2017

Earn cash back on
purchases—See if you
Pre-Qualify

Bank of America

28th March 2017

Bank of America Alert: Your
Online Access is Temporarily
Locked

CardApprovalUSA

27th March 2017

Open a new credit account

Vulnerebility

Disk Sorter Enterprise CVE-2017-7230 Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97195

cloudflare-scrape CVE-2017-7235 Remote Code Execution Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97191

Eclipse tinydtls CVE-2017-7243 Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97193

Subrion CMS CVE-2017-6069 Cross Site Request Forgery Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97196

cURL/libcURL Incomplete Fix CVE-2017-2628 Remote Security Bypass Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97187

Eview EV-07S GPS Tracker Buffer Overflow and Information Disclosure Vulnerabilities
2017-03-29
http://www.securityfocus.com/bid/97194

audiofile CVE-2017-6829 Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97189

Symphony CMS CVE-2017-6006 Cross Site Scripting Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97188

Linux Kernel CVE-2017-7273 Local Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97190

Irssi CVE-2017-7191 Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97185

Eview EV-07S GPS Tracker CVE-2017-5237 Security Bypass Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97186

Apache Ambari CVE-2016-6807 Remote Command Execution Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97184

Moodle CVE-2017-7298 Cross Site Scripting Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97182

audiofile CVE-2017-6828 Heap Based Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97183

radare2 'libr/util/r_pkcs7.c' Remote Denial Of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97181

icoutils 'decode_ne_resource_id()' Function Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/96292

icoutils 'simple_vec()' Function Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/96267

icoutils CVE-2017-5332 Local Code Execution Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95380

icoutils CVE-2017-5333 Local Integer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95678

icoutils 'extract_icons()' Function Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/96288

icoutils CVE-2017-5208 Local Integer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95315

Apache Camel CVE-2016-8749 Java Deserialization Multiple Remote Code Execution Vulnerabilities
2017-03-29
http://www.securityfocus.com/bid/97179

Rancher Server CVE-2017-7297 Security Bypass Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97180

Revive Adserver Multiple Security Vulnerabilities
2017-03-29
http://www.securityfocus.com/bid/83964

PHP CVE-2017-7272 Server Side Request Forgery Security Bypass Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97178

Yii framework CVE-2017-7271 Cross Site Scripting Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97167

Deluge CVE-2017-7178 Cross Site Request Forgery Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97041

Eject dmcrypt-get-device CVE-2017-6964 Local Code Execution Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97154

Linux Kernel CVE-2017-7294 Local Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97177

OCaml CVE-2015-8869 Multiple Security Vulnerabilities
2017-03-29
http://www.securityfocus.com/bid/89318IBM Rational Quality Manager CVE-2016-6031 Cross Site Scripting Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97169

F5 BIG-IP APM CVE-2016-7472 Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97168

LibTIFF CVE-2016-9533 Heap Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94742

Ruby on Rails Action Pack CVE-2016-0751 Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/81800

Apache And Microsoft IIS Range Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/21865

ImageMagick Incomplete Fix CVE-2017-7275 Memory Corruption Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97166

OpenSSH CVE-2016-10011 Local Information Disclosure Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94977

Python CVE-2016-5636 Heap Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/91247

tcpdump Multiple Buffer Overflow Vulnerabilities
2017-03-29
http://www.securityfocus.com/bid/95852

OpenSSH CVE-2016-10010 Privilege Escalation Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94972

OpenSSH CVE-2016-10012 Security Bypass Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94975

PHP 'ext/wddx/wddx.c' Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94846

LibTIFF CVE-2016-3619 Out Of Bounds Read Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/85919

OpenSSH CVE-2016-10009 Remote Code Execution Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94968

OpenSSL CVE-2016-7056 Local Information Disclosure Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95375

cURL/libcURL CVE-2016-9586 Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95019

PHP CVE-2016-10161 Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95768

PHP CVE-2016-10159 Integer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95774

Apache HTTP Server CVE-2016-8743 Security Bypass Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95077

PHP CVE-2016-10158 Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95764

PHP CVE-2016-10160 Remote Code Execution Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95783

Apache HTTP Server CVE-2016-0736 Remote Security Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95078

Apache HTTP Server CVE-2016-2161 Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95076

Apache HTTP Server CVE-2016-8740 Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94650

Brave Browsers CVE-2016-9473 Address Bar Spoofing Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97155

Apache HTTP Server CVE-2016-5387 Security Bypass Vulnerability
2017-03-29
http://www.securityfocus.com/bid/91816

LibTIFF CVE-2016-9539 Memory Corruption Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94754

LibTIFF CVE-2016-9540 Heap Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94747

LibTIFF CVE-2016-9536 Heap Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94745

LibTIFF CVE-2016-9538 Integer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94753

SANS News

Logical & Physical Security Correlation

Critical VMware vulnerabilities disclosed

Threatpost

Apple Fixes 223 Vulnerabilities Across macOS, iOS, Safari

Microsoft Offers Analysis of Zero-Day Exploited By Zirconium Group

Harley Geiger on Cybersecurity Policy

‘Anonymous’ FTP Servers Leaving Healthcare Data Exposed

Exploit

Vm86 - Syscall Task Switch Kernel Panic / Privilege Escalation

Ubuntu 15.10 - 'USERNS ' Overlayfs Over Fuse Privilege Escalation

Ubuntu < 15.10 - PT Chown Arbitrary PTs Access Via UserNamespace Privilege...

Disk Sorter Enterprise 9.5.12 - 'Import Command' Buffer Overflow

NTP - Privilege Escalation

AUFS (Ubuntu 15.10) - 'allow_userns' Fuse/Xattr User Namespaces Privilege Escalation

DiskBoss Enterprise 7.8.16 - 'Import Command' Buffer Overflow

Apache 2.2 - Scoreboard Invalid Free On Shutdown

Apache < 2.0.64 / < 2.2.21 mod_setenvif - Integer Overflow

Linux Kernel (Ubuntu 11.10/12.04) - binfmt_script Stack Data Disclosure

DzSoft PHP Editor 4.2.7 - File Enumeration

Intermec PM43 Industrial Printer - Privilege Escalation

MikroTik RouterBoard 6.38.5 - Denial of Service

VX Search Enterprise 9.5.12 - 'Verify Email' Buffer Overflow

Microsoft Outlook - HTML Email Denial of Service

28.3.2017

Bugtraq

APPLE-SA-2017-03-27-7 macOS Server 5.3 2017-03-27
Apple Product Security (product-security-noreply lists apple com)

[SECURITY] [DSA 3821-1] gst-plugins-ugly1.0 security update 2017-03-27
Moritz Muehlenhoff (jmm debian org)

APPLE-SA-2017-03-27-1 Pages 6.1, Numbers 4.1, and Keynote 7.1 for Mac; Pages 3.1, Numbers 3.1, and Keynote 3.1 for iOS 2017-03-27
Apple Product Security (product-security-noreply lists apple com)

[SECURITY] [DSA 3817-1] jbig2dec security update 2017-03-24
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 3816-1] samba security update 2017-03-23
Salvatore Bonaccorso (carnil debian org)

Malware

Trojan.Aczibo

Phishing

Bank of America

28th March 2017

Bank of America Alert: Your
Online Access is Temporarily
Locked

CardApprovalUSA

27th March 2017

Open a new credit account

Cheap Auto Insurance Today

27th March 2017

New Auto Insurance Rates for
2017

LifeLock

26th March 2017

Your W-2 can be a 1-stop shop
for identity thieves

Vulnerebility

Cherry­Music CVE-2015-8309 Directory Traversal Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97149

Cherry­Music CVE-2015-8310 Cross Site Scripting Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97148

Icinga CVE-2015-8010 Cross Site Scripting Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97145

Revive Adserver Multiple Security Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/83964

Nghttp2 CVE-2017-2428 Multiple Remote Security Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97146

Apple iOS/tvOS/macOS/watchOS Multiple Security Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97137

Apple iOS APPLE-SA-2017-03-27-4 Multiple Security Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97138

McAfee Anti-Malware Scan CVE-2016-8031 Engine Multiple Local Security Bypass Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97142

McAfee Anti-Malware Scan Engine CVE-2016-8032 Multiple Local Security Bypass Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97144

Apple macOS APPLE-SA-2017-03-27-3 Multiple Security Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97140

WebKit CVE-2017-2415 Remote Code Execution Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97143

Pivotal Cloud Foundry Elastic Runtime CVE-2017-2773 Security Bypass Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97135

Apple Safari CVE-2017-2385 Local Security Bypass Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97136

Linux Kernel CVE-2017-7277 Multiple Local Memory Corruption Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97141

Apple macOS, iOS and tvOS CVE-2017-2448 Security Bypass Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97134

Apple iOS/WatchOS/tvOS/Safari CVE-2017-2444 Multiple Memory Corruption Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97131

WebKit CVE-2017-2471 Remote Code Execution Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97133

Apple iOS/macOS/WatchOS/tvOS CVE-2017-2485 Memory Corruption Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97132

WebKit Multiple Security Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97130

Apple iOS and Safari Multiple Security Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97129

pngdefry CVE-2017-7231 Heap Based Buffer Overflow Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97037

Apple macOS Server CVE-2017-2382 User Enumeration Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97128

Microsoft Internet Information Services CVE-2017-7269 Buffer Overflow Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97127

Apple iOS/Mac CVE-2017-2391 Information Disclosure Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97126

Schneider Electric VAMPSET Local Memory Corruption Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97124

WordPress recent-backups Plugin 'download-file.php' Arbitrary File Download Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97125

ZoneMinder CVE-2016-10203 Cross Site Scripting Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97122

Zimbra Collaboration Suite CVE-2016-9924 XML External Entity Injection Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97121

Multiple F5 BIG-IP Products CVE-2016-7468 Denial of Service Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97119

Firejail CVE-2017-5206 Security Bypass Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97120Microsoft Internet Information Services CVE-2017-7269 Buffer Overflow Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97127

Apple iOS/Mac CVE-2017-2391 Information Disclosure Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97126

Schneider Electric VAMPSET Local Memory Corruption Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97124

WordPress recent-backups Plugin 'download-file.php' Arbitrary File Download Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97125

ZoneMinder CVE-2016-10203 Cross Site Scripting Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97122

Zimbra Collaboration Suite CVE-2016-9924 XML External Entity Injection Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97121

Multiple F5 BIG-IP Products CVE-2016-7468 Denial of Service Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97119

Firejail CVE-2017-5206 Security Bypass Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97120

ZoneMinder CVE-2016-10206 Cross Site Request Forgery Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97114

PhishWall Client CVE-2017-2130 DLL Loading Remote Code Execution Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97113

ZoneMinder CVE-2016-10205 Session Fixation Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97116

WordPress YOP Poll Plugin CVE-2017-2127 Unspecified Cross Site Scripting Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97118

LibTIFF 'libtiff/tif_ojpeg.c' Divide By Zero Denial of Service Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97117

LibTIFF 'libtiff/tif_read.c' Divide By Zero Denial of Service Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97115

EyesOfNetwork CVE-2017-6087 Multiple Arbitrary Code Execution Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97109

Nessus CVE-2017-7199 Local Privilege Escalation Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97110

Potrace CVE-2017-7263 Incomplete Fix Heap Buffer Overflow Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97112

MuPDF CVE-2017-7264 Use After Free Denial of Service Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97111

Multiple Zyxel Products CVE-2016-10227 Remote Denial of Service Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97105

WordPress Filedownload Plugin CVE-2015-1000004 Cross-Site Scripting Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97107

candidate-application-form Wordpress Plugin CVE-2015-1000005 Arbitrary File Download Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97108

WordPress Filedownload Plugin CVE-2015-1000003 SQL Injection Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97106

Linux Kernel CVE-2010-5328 Local Denial of Service Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97103

GOsa CVE-2014-9760 Cross Site Scripting Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97104

Node.js CVE-2014-9772 Cross Site Scripting Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97102

AMD Ryzen Processor CVE-2017-7262 Local Denial of Service Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97098

Artifex MuPDF CVE-2016-10247 Denial of Service Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97099

Symphony CMS CVE-2017-6067 Cross Site Scripting Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97101

Trend Micro InterScan Messaging Security Suite Directory Traversal Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97097

Linux Kernel CVE-2017-7261 Local Denial of Service Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97096

SANS News

 

Threatpost

Fileless UAC Bypass Uses Windows Backup and Restore Utility

APT29 Used Domain Fronting, Tor to Execute Backdoor

New Clues Surface on Shamoon 2’s Destructive Behavior

Exploit

Microsoft Visual Studio 2015 update 3 - Denial of Service

Apple Safari - 'DateTimeFormat.format' Type Confusion

Apple Safari - Builtin JavaScript Allows Function.caller to be Used in Strict Mode

Apple Safari - Out-of-Bounds Read when Calling Bound Function

Internet Information Services (IIS) 6.0 WebDAV - 'ScStoragePathFromUrl' Buffer...

Samba 4.5.2 - Symlink Race Permits Opening Files Outside Share Directory

Github Enterprise - Default Session Secret And Deserialization (Metasploit)

Professional Bus Booking Script - 'hid_Busid' Parameter SQL Injection

CouponPHP CMS 3.1 - 'code' Parameter SQL Injection

EyesOfNetwork (EON) 5.0 - Remote Code Execution

EyesOfNetwork (EON) 5.0 - SQL Injection

Nuxeo 6.0 / 7.1 / 7.2 / 7.3 - Remote Code Execution (Metasploit)

inoERP 0.6.1 - Cross-Site Scripting / Cross-Site Request Forgery / SQL Injection /...

QNAP QTS < 4.2.4 - Domain Privilege Escalation

Disk Sorter Enterprise 9.5.12 - Local Buffer Overflow

27.3.2017

Bugtraq

[SECURITY] [DSA 3817-1] jbig2dec security update 2017-03-24
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 3816-1] samba security update 2017-03-23
Salvatore Bonaccorso (carnil debian org)

APPLE-SA-2017-03-22-1 iTunes for Windows 12.6 2017-03-22
Apple Product Security (product-security-noreply lists apple com)

SEC Consult SA-20170322-0 :: Multiple vulnerabilities in Solare Datensysteme Solar-Log devices 2017-03-22
SEC Consult Vulnerability Lab (research sec-consult com)

Defense in depth -- the Microsoft way (part 47): "AppLocker bypasses are not serviced via monthly security roll-ups" 2017-03-21
Stefan Kanthak (stefan kanthak nexgo de)

Malware

Backdoor:PowerShell/Tarpeg.D
Backdoor:PowerShell/Tarpeg.C

Backdoor:PowerShell/Tarpeg.B

Backdoor:PowerShell/Tarpeg.A

Phishing

LifeLock

26th March 2017

Your W-2 can be a 1-stop shop
for identity thieves

amazon

26th March 2017

[IMPORTANT]:UPDATE YOUR
ACCOUNT INFORMATION NOW

CardApprovalUSA

26th March 2017

Open a new credit account

Lexington Law Credit Repair

25th March 2017

FREE Credit Score Analysis

Indigo Platinum MasterCard

25th March 2017

A Platinum MasterCard for Less
Than Perfect Credit

Vulnerebility

Linux Kernel CVE-2010-5328 Local Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97103

GOsa CVE-2014-9760 Cross Site Scripting Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97104

Node.js CVE-2014-9772 Cross Site Scripting Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97102

AMD Ryzen Processor CVE-2017-7262 Local Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97098

Artifex MuPDF CVE-2016-10247 Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97099

Symphony CMS CVE-2017-6067 Cross Site Scripting Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97101

Trend Micro InterScan Messaging Security Suite Directory Traversal Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97097

Linux Kernel CVE-2017-7261 Local Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97096

Wordpress Filedownload Plugin CVE-2015-1000002 Security Bypass Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97100

Ghostscript CVE-2016-9601 Local Integer Overflow Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97095

SolarWinds Log and Event Manager CVE-2017-5198 Local Privilege Escalation Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97094

Subrion CMS CVE-2017-6068 Cross Site Request Forgery Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97091

OnePlus OxygenOS CVE-2017-5622 Local Code Execution Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97092

Netflix Security Monkey CVE-2017-7266 Open Redirection Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97088

SolarWinds Log and Event Manager CVE-2017-5199 Remote Code Execution Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97090

Subrion CMS 'admin/database' SQL Injection Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97093

Subrion CMS CVE-2017-6066 Cross Site Request Forgery Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97087

dotCMS CVE-2017-6003 Cross Site Scripting Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97089

Trend Micro Control Manager Multiple SQL Injection Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/97086

Logsign Remote Command Injection Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97038

EyesOfNetwork CVE-2017-6088 Multiple SQL Injection Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/97084

HexChat CVE-2016-2233 Stack-Based Buffer Overflow Vulnerability
2017-03-27
http://www.securityfocus.com/bid/95920

Google Android NFC CVE-2017-0481 Remote Privilege Escalation Vulnerability
2017-03-27
http://www.securityfocus.com/bid/96765

Apple macOS CVE-2016-4617 Multiple Security Bypass Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/96329

Python 'urrlib2/urllib/httplib/http.client' HTTP Header Injection Vulnerability
2017-03-27
http://www.securityfocus.com/bid/91226

Python CVE-2016-5636 Heap Buffer Overflow Vulnerability
2017-03-27
http://www.securityfocus.com/bid/91247

Pivotal Cloud Foundry Elastic Runtime CVE-2017-4955 Information Disclosure Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97082

Nuxeo Platform CVE-2017-5869 Arbitrary File Upload Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97083

Miele Professional PG 8528 CVE-2017-7240 Directory Traversal Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97080

IBM Kenexa LCMS Premier CVE-2017-1142 Man in the Middle Information Disclosure Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97081
Mozilla Firefox and Thunderbird Multiple Security Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/96693

Mozilla Firefox and Thunderbird CVE-2017-5401 Memory Corruption Vulnerability
2017-03-27
http://www.securityfocus.com/bid/96677

Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/96664

Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/96654

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/96651

Samba CVE-2017-2619 Symlink Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97033

IBM Kenexa LMS on Cloud CVE-2016-8935 Cross-Site Scripting Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97077

NTP CVE-2017-6452 Local Stack Based Buffer Overflow Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97078

NTP CVE-2017-6459 Local Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97076

IBM WebSphere Portal CVE-2017-1120 Cross Site Scripting Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97075

NTP CVE-2017-6455 Local Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97074

QNAP QTAP Qualcomm components Multiple Unspecified Security Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/97072

OpenJPEG CVE-2016-9573 Out of Bounds Read Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97073

TYPO3 CVE-2017-6370 Information Disclosure Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97071

Firebird CVE-2017-6369 Remote Code Execution Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97070

Chef Manage CVE-2017-7174 Remote Code Execution Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97069

GNU BinUtils CVE-2017-6969 Remote Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97065

libpcre Multiple Security Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/97067

Cloudera CDH CVE-2013-6446 Information Disclosure Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97068

SLiMS 7 Cendana CVE-2017-7242 Multiple Cross Site Scripting Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/97062

IBM TRIRIGA Application Platform CVE-2016-9737 Unspecified Cross Site Scripting Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97064

Redhat Wildfly CVE-2016-9589 Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97060

Gazelle Multiple Cross Site Scripting Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/97063

IBM TRIRIGA Applications CVE-2017-1153 Unspecified Remote Privilege Escalation Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97066

Pi Engine CVE-2017-7251 Cross Site Scripting Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97061

QNAP QTS Multiple Arbitrary Command Execution Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/97059

NTP CVE-2017-6451 Local Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97058

Multiple BD Products CVE-2017-6022 Hardcoded Credentials Information Disclosure Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97057

GNU glibc '__res_vinit()' Function Information Disclosure Vulnerability
2017-03-27
http://www.securityfocus.com/bid/92257

GNU glibc CVE-2016-6323 Infinite Loop Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/92532

SANS News

Symantec vs. Google: The CA Fight Continues. What do you need to know?

Threatpost

 

Exploit

Linux/x86 - Reverse /bin/bash Shellcode (110 bytes)

Php Real Estate Property Script - SQL Injection

Php Real Estate Property Script - SQL Injection

Alibaba Clone Script - SQL Injection

Adult Tube Video Script - SQL Injection

Just Another Video Script 1.4.3 - SQL Injection

CouponPHP CMS 3.1 - 'code' Parameter SQL Injection

Professional Bus Booking Script - 'hid_Busid' Parameter SQL Injection

26.3.2017

Bugtraq

[SECURITY] [DSA 3816-1] samba security update 2017-03-23
Salvatore Bonaccorso (carnil debian org)

APPLE-SA-2017-03-22-1 iTunes for Windows 12.6 2017-03-22
Apple Product Security (product-security-noreply lists apple com)

SEC Consult SA-20170322-0 :: Multiple vulnerabilities in Solare Datensysteme Solar-Log devices 2017-03-22
SEC Consult Vulnerability Lab (research sec-consult com)

Defense in depth -- the Microsoft way (part 47): "AppLocker bypasses are not serviced via monthly security roll-ups" 2017-03-21
Stefan Kanthak (stefan kanthak nexgo de)

Malware

Trojan.Cadanif

Exp.CVE-2017-0015

Exp.CVE-2017-0018

Exp.CVE-2017-0154

Exp.CVE-2017-0050

Exp.CVE-2017-0149

Exp.CVE-2017-0067

Exp.CVE-2017-0141

Exp.CVE-2017-0010

Phishing

Indigo Platinum MasterCard

25th March 2017

A Platinum MasterCard for Less
Than Perfect Credit

 

Bank of America

24th March 2017

Bank of America Alert: Your
Online Access is Temporarily
Locked

LawsuitWinning

24th March 2017

You may qualify for
compensation for your personal
injuries!

Apple

23rd March 2017

YOUR APPLE ID HAS BEEN
DISABLED FOR SECURITY REASONS
YEEBDSPVRK

Yes BlueSky Auto Finance

23rd March 2017

Finance your new or used car
purchase. Fast App Response

Vulnerebility

Samba CVE-2017-2619 Symlink Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97033

IBM Kenexa LMS on Cloud CVE-2016-8935 Cross-Site Scripting Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97077

NTP CVE-2017-6452 Local Stack Based Buffer Overflow Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97078

NTP CVE-2017-6459 Local Denial of Service Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97076

IBM WebSphere Portal CVE-2017-1120 Cross Site Scripting Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97075

NTP CVE-2017-6455 Local Denial of Service Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97074

QNAP QTAP Qualcomm components Multiple Unspecified Security Vulnerabilities
2017-03-26
http://www.securityfocus.com/bid/97072

OpenJPEG CVE-2016-9573 Out of Bounds Read Denial of Service Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97073

TYPO3 CVE-2017-6370 Information Disclosure Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97071

Firebird CVE-2017-6369 Remote Code Execution Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97070

Chef Manage CVE-2017-7174 Remote Code Execution Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97069

GNU BinUtils CVE-2017-6969 Remote Denial of Service Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97065

libpcre Multiple Security Vulnerabilities
2017-03-26
http://www.securityfocus.com/bid/97067

Cloudera CDH CVE-2013-6446 Information Disclosure Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97068

SLiMS 7 Cendana CVE-2017-7242 Multiple Cross Site Scripting Vulnerabilities
2017-03-26
http://www.securityfocus.com/bid/97062

IBM TRIRIGA Application Platform CVE-2016-9737 Unspecified Cross Site Scripting Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97064

Redhat Wildfly CVE-2016-9589 Denial of Service Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97060

Gazelle Multiple Cross Site Scripting Vulnerabilities
2017-03-26
http://www.securityfocus.com/bid/97063

IBM TRIRIGA Applications CVE-2017-1153 Unspecified Remote Privilege Escalation Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97066

Pi Engine CVE-2017-7251 Cross Site Scripting Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97061

QNAP QTS Multiple Arbitrary Command Execution Vulnerabilities
2017-03-26
http://www.securityfocus.com/bid/97059

NTP CVE-2017-6451 Local Denial of Service Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97058

Multiple BD Products CVE-2017-6022 Hardcoded Credentials Information Disclosure Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97057

GNU glibc '__res_vinit()' Function Information Disclosure Vulnerability
2017-03-26
http://www.securityfocus.com/bid/92257

GNU glibc CVE-2016-6323 Infinite Loop Denial of Service Vulnerability
2017-03-26
http://www.securityfocus.com/bid/92532

GNU glibc 'libio/wstrops.c' Local Integer Overflow Vulnerability
2017-03-26
http://www.securityfocus.com/bid/72740

GNU glibc CVE-2016-1234 Local Buffer Overflow Vulnerability
2017-03-26
http://www.securityfocus.com/bid/84204

GNU glibc 'strxfrm()' Function Local Integer Overflow and Stack Overflow Vulnerabilities
2017-03-26
http://www.securityfocus.com/bid/72602

GNU glibc 'fnmatch_loop.c' Local Buffer Overflow Vulnerability
2017-03-26
http://www.securityfocus.com/bid/72789

QNAP QTS CVE-2017-5227 Local Information Disclosure Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97056IBM Kenexa LMS on Cloud CVE-2016-8935 Cross-Site Scripting Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97077

NTP CVE-2017-6452 Local Stack Based Buffer Overflow Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97078

NTP CVE-2017-6459 Local Denial of Service Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97076

IBM WebSphere Portal CVE-2017-1120 Cross Site Scripting Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97075

NTP CVE-2017-6455 Local Denial of Service Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97074

QNAP QTAP Qualcomm components Multiple Unspecified Security Vulnerabilities
2017-03-25
http://www.securityfocus.com/bid/97072

OpenJPEG CVE-2016-9573 Out of Bounds Read Denial of Service Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97073

TYPO3 CVE-2017-6370 Information Disclosure Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97071

Firebird CVE-2017-6369 Remote Code Execution Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97070

Chef Manage CVE-2017-7174 Remote Code Execution Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97069

GNU BinUtils CVE-2017-6969 Remote Denial of Service Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97065

libpcre Multiple Security Vulnerabilities
2017-03-25
http://www.securityfocus.com/bid/97067

Cloudera CDH CVE-2013-6446 Information Disclosure Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97068

SLiMS 7 Cendana CVE-2017-7242 Multiple Cross Site Scripting Vulnerabilities
2017-03-25
http://www.securityfocus.com/bid/97062

IBM TRIRIGA Application Platform CVE-2016-9737 Unspecified Cross Site Scripting Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97064

Redhat Wildfly CVE-2016-9589 Denial of Service Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97060

Gazelle Multiple Cross Site Scripting Vulnerabilities
2017-03-25
http://www.securityfocus.com/bid/97063

IBM TRIRIGA Applications CVE-2017-1153 Unspecified Remote Privilege Escalation Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97066

Pi Engine CVE-2017-7251 Cross Site Scripting Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97061

Samba CVE-2017-2619 Symlink Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97033

QNAP QTS Multiple Arbitrary Command Execution Vulnerabilities
2017-03-25
http://www.securityfocus.com/bid/97059

NTP CVE-2017-6451 Local Denial of Service Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97058

Multiple BD Products CVE-2017-6022 Hardcoded Credentials Information Disclosure Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97057

GNU glibc '__res_vinit()' Function Information Disclosure Vulnerability
2017-03-25
http://www.securityfocus.com/bid/92257

GNU glibc CVE-2016-6323 Infinite Loop Denial of Service Vulnerability
2017-03-25
http://www.securityfocus.com/bid/92532

GNU glibc 'libio/wstrops.c' Local Integer Overflow Vulnerability
2017-03-25
http://www.securityfocus.com/bid/72740

GNU glibc CVE-2016-1234 Local Buffer Overflow Vulnerability
2017-03-25
http://www.securityfocus.com/bid/84204

GNU glibc 'strxfrm()' Function Local Integer Overflow and Stack Overflow Vulnerabilities
2017-03-25
http://www.securityfocus.com/bid/72602

GNU glibc 'fnmatch_loop.c' Local Buffer Overflow Vulnerability
2017-03-25
http://www.securityfocus.com/bid/72789

QNAP QTS CVE-2017-5227 Local Information Disclosure Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97056

SANS News

Nicely Obfuscated JavaScript Sample

Distraction as a Service

Threatpost

Adware Apps Booted from Google Play

Instagram Adds Two-Factor Authentication

Privacy Advocates Vow to Fight Rollback of Broadband Privacy Rules

Experts Doubt Hackers’ Claim Of Millions Of Breached Apple Credentials

Exploit

Forticlient 5.2.3 Windows 10 x64 (Pre Anniversary) - Privilege Escalation

Forticlient 5.2.3 Windows 10 x64 (Post Anniversary) - Privilege Escalation

Miele Professional PG 8528 - Directory Traversal

NETGEAR WNR2000v5 - (Un)authenticated hidden_lang_avi Stack Overflow (Metasploit)

Logsign 4.4.2 / 4.4.137 - Remote Command Injection (Metasploit)

Gr8 Gallery Script - SQL Injection

wifirxpower - Local Buffer Overflow

Gr8 Tutorial Script - SQL Injection

24.3.2017

Bugtraq

[SECURITY] [DSA 3816-1] samba security update 2017-03-23
Salvatore Bonaccorso (carnil debian org)

APPLE-SA-2017-03-22-1 iTunes for Windows 12.6 2017-03-22
Apple Product Security (product-security-noreply lists apple com)

SEC Consult SA-20170322-0 :: Multiple vulnerabilities in Solare Datensysteme Solar-Log devices 2017-03-22
SEC Consult Vulnerability Lab (research sec-consult com)

Defense in depth -- the Microsoft way (part 47): "AppLocker bypasses are not serviced via monthly security roll-ups" 2017-03-21
Stefan Kanthak (stefan kanthak nexgo de)

[ERPSCAN-16-041] SAP NETWEAVER DIRECTORY CREATION OUTSIDE OF THE JVM 2017-03-21
ERPScan inc (erpscan online gmail com)

ESA-2017-010: EMC RecoverPoint SSL Stripping Vulnerability 2017-03-20
EMC Product Security Response Center (Security_Alert emc com)

[SECURITY] [DSA 3796-2] sitesummary regression update 2017-03-20
Sebastien Delafond (seb debian org)

[security bulletin] HPSBUX03596 rev.2 - HPE HP-UX running CIFS Server (Samba), Remote Access Restriction Bypass, Unauthorized Access 2017-03-20
security-alert hpe com

Malware

SupportScam:Win32/Monitnev.A

Infostealer.Bitral

Phishing

Apple

23rd March 2017

YOUR APPLE ID HAS BEEN
DISABLED FOR SECURITY REASONS
YEEBDSPVRK

Yes BlueSky Auto Finance

23rd March 2017

Finance your new or used car
purchase. Fast App Response

IT Cosmetics

23rd March 2017

Special Offer! Get Bye Bye
Foundation & 4 other beauty
favorites for just $39.95

VeteransVALoans

23rd March 2017

Did you serve? New VA Loan
Program

Vulnerebility

Cloudera CDH CVE-2013-6446 Information Disclosure Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97068

SLiMS 7 Cendana CVE-2017-7242 Multiple Cross Site Scripting Vulnerabilities
2017-03-24
http://www.securityfocus.com/bid/97062

IBM TRIRIGA Application Platform CVE-2016-9737 Unspecified Cross Site Scripting Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97064

Redhat Wildfly CVE-2016-9589 Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97060

Gazelle Multiple Cross Site Scripting Vulnerabilities
2017-03-24
http://www.securityfocus.com/bid/97063

IBM TRIRIGA Applications CVE-2017-1153 Unspecified Remote Privilege Escalation Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97066

Pi Engine CVE-2017-7251 Cross Site Scripting Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97061

Samba CVE-2017-2619 Symlink Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97033

QNAP QTS Multiple Arbitrary Command Execution Vulnerabilities
2017-03-24
http://www.securityfocus.com/bid/97059

NTP CVE-2017-6451 Local Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97058

Multiple BD Products CVE-2017-6022 Hardcoded Credentials Information Disclosure Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97057

GNU glibc '__res_vinit()' Function Information Disclosure Vulnerability
2017-03-24
http://www.securityfocus.com/bid/92257

GNU glibc CVE-2016-6323 Infinite Loop Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/92532

GNU glibc 'libio/wstrops.c' Local Integer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/72740

GNU glibc CVE-2016-1234 Local Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/84204

GNU glibc 'strxfrm()' Function Local Integer Overflow and Stack Overflow Vulnerabilities
2017-03-24
http://www.securityfocus.com/bid/72602

GNU glibc 'fnmatch_loop.c' Local Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/72789

QNAP QTS CVE-2017-5227 Local Information Disclosure Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97056

LAquis SCADA Software CVE-2017-6020 Directory Traversal Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97055

APNGDis Multiple Buffer Overflow Vulnerabilities
2017-03-24
http://www.securityfocus.com/bid/97053

Broadcom BCM4339 SoC CVE-2017-6957 Stack-Based Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97054

NTP CVE-2017-6458 Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97051

NTP CVE-2017-6460 Stack Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97052

NTP CVE-2017-6462 Local Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97045

NTP CVE-2017-6464 Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97050

NTP CVE-2016-9042 Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97046

NTP CVE-2017-6463 Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97049

Suricata CVE-2017-7177 Security Bypass Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97047

OnePlus OxygenOS CVE-2017-5623 Local Security Bypass Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97048

Pidgin CVE 2017-2640 Out of Bounds Write Security Vulnerability
2017-03-24
http://www.securityfocus.com/bid/96775APNGDis Multiple Buffer Overflow Vulnerabilities
2017-03-24
http://www.securityfocus.com/bid/97053

Broadcom BCM4339 SoC CVE-2017-6957 Stack-Based Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97054

NTP CVE-2017-6458 Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97051

NTP CVE-2017-6460 Stack Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97052

NTP CVE-2017-6462 Local Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97045

NTP CVE-2017-6464 Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97050

NTP CVE-2016-9042 Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97046

NTP CVE-2017-6463 Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97049

Suricata CVE-2017-7177 Security Bypass Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97047

OnePlus OxygenOS CVE-2017-5623 Local Security Bypass Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97048

Pidgin CVE 2017-2640 Out of Bounds Write Security Vulnerability
2017-03-24
http://www.securityfocus.com/bid/96775

Multiple Huawei Honor CVE-2017-2728 Local Security Bypass Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97042

GnuTLS GNUTLS-SA-2017-3 Multiple Security Vulnerabilities
2017-03-24
http://www.securityfocus.com/bid/97040

Deluge CVE-2017-7178 Cross Site Request Forgery Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97041

LastPass for Firefox Security Bypass Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97043

LastPass 'websiteConnector.js' Remote Code Execution Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97039

SAP GUI CVE-2017-6950 Remote Code Execution Vulnerability
2017-03-24
http://www.securityfocus.com/bid/96872

NetIQ Access Manager CVE-2016-5758 Cross Site Request Forgery Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97035

pngdefry 'pngdefry.c' Heap Based Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97037

W3C High Resolution Time API CVE-2017-5928 Security Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97036

Expat CVE-2016-5300 Incomplete Fix Remote Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/91159

Expat CVE-2016-4472 Incomplete Fix Remote Code Execution Vulnerability
2017-03-24
http://www.securityfocus.com/bid/91528

Admidio 'dates_function.php' SQL Injection Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97034

Google Chrome Prior to 44.0.2403.89 Multiple Security Vulnerabilities
2017-03-24
http://www.securityfocus.com/bid/75973

Expat XML Parsing Multiple Remote Denial of Service Vulnerabilities
2017-03-24
http://www.securityfocus.com/bid/52379

Libexpat Expat CVE-2012-6702 Predictable Random Number Generator Weakness
2017-03-24
http://www.securityfocus.com/bid/91483

Expat UTF-8 Character XML Parsing Remote Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/36097

Internet Explorer CVE-2009-3270 Denial-Of-Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/79354

Expat CVE-2016-0718 Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/90729

Drupal Linkit Module Access Bypass Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97029

SANS News

Nicely Obfuscated JavaScript Sample

Threatpost

Half of Android Devices Unpatched Last Year

Malware That Targets Both Microsoft, Apple Operating Systems Found

Cisco Patches Critical IOx Vulnerability

Exploit

Miele Professional PG 8528 - Directory Traversal

Gr8 Tutorial Script - SQL Injection

Gr8 Gallery Script - SQL Injection

Sun Java Web Start Plugin - Command Line Argument Injection (Metasploit)

Adobe Flash Player - Nellymoser Audio Decoding Buffer Overflow (Metasploit)

VMware Host Guest Client Redirector - DLL Side Loading (Metasploit)

23.3.2017

Bugtraq

[SECURITY] [DSA 3816-1] samba security update 2017-03-23
Salvatore Bonaccorso (carnil debian org)

APPLE-SA-2017-03-22-1 iTunes for Windows 12.6 2017-03-22
Apple Product Security (product-security-noreply lists apple com)

SEC Consult SA-20170322-0 :: Multiple vulnerabilities in Solare Datensysteme Solar-Log devices 2017-03-22
SEC Consult Vulnerability Lab (research sec-consult com)

Defense in depth -- the Microsoft way (part 47): "AppLocker bypasses are not serviced via monthly security roll-ups" 2017-03-21
Stefan Kanthak (stefan kanthak nexgo de)

[ERPSCAN-16-041] SAP NETWEAVER DIRECTORY CREATION OUTSIDE OF THE JVM 2017-03-21
ERPScan inc (erpscan online gmail com)

ESA-2017-010: EMC RecoverPoint SSL Stripping Vulnerability 2017-03-20
EMC Product Security Response Center (Security_Alert emc com)

[SECURITY] [DSA 3796-2] sitesummary regression update 2017-03-20
Sebastien Delafond (seb debian org)

[security bulletin] HPSBUX03596 rev.2 - HPE HP-UX running CIFS Server (Samba), Remote Access Restriction Bypass, Unauthorized Access 2017-03-20
security-alert hpe com

Malware

Ransom.Vortex

JS.Vajawom

Phishing

IT Cosmetics

23rd March 2017

Special Offer! Get Bye Bye
Foundation & 4 other beauty
favorites for just $39.95

VeteransVALoans

23rd March 2017

Did you serve? New VA Loan
Program

Bank of America

22nd March 2017

Bank of America Alert: Your
Online Access is Temporarily
Locked

Vulnerebility

pngdefry 'pngdefry.c' Heap Based Buffer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97037

W3C High Resolution Time API CVE-2017-5928 Security Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97036

Expat CVE-2016-5300 Incomplete Fix Remote Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/91159

Expat CVE-2016-4472 Incomplete Fix Remote Code Execution Vulnerability
2017-03-23
http://www.securityfocus.com/bid/91528

Admidio 'dates_function.php' SQL Injection Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97034

Google Chrome Prior to 44.0.2403.89 Multiple Security Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/75973

Expat XML Parsing Multiple Remote Denial of Service Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/52379

Libexpat Expat CVE-2012-6702 Predictable Random Number Generator Weakness
2017-03-23
http://www.securityfocus.com/bid/91483

Expat UTF-8 Character XML Parsing Remote Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/36097

Internet Explorer CVE-2009-3270 Denial-Of-Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/79354

Expat CVE-2016-0718 Buffer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/90729

Drupal Linkit Module Access Bypass Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97029

SQLite CVE-2016-6153 Insecure Temporary File Creation Vulnerability
2017-03-23
http://www.securityfocus.com/bid/91546

SQLite CVE-2015-6607 Multiple Local Privilege Escalation Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/76970

Apple Mac OS X and iOS Multiple Security Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/75491

SQLite CVE-2013-7443 Local Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/76089

SQLite Versions Prior to 3.8.9 Multiple Security Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/74228

Samba CVE-2017-2619 Symlink Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97033

podofo CVE-2017-5852 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97032

PCRE CVE-2017-7186 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97030

sane-backends CVE-2017-6318 Information Disclosure Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97028

USBPcap CVE-2017-6178 Local Privilege Escalation Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97026

Drupal Office Hours Module Cross Site Scripting Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97027

Multiple Trend Micro Products CVE-2017-5565 DLL Loading Local Code Injection Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97031

WordPress Prior to 4.7.3 Multiple Cross Site Scripting Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/96601

WordPress Prior to 4.7.3 Security Bypass Vulnerability
2017-03-23
http://www.securityfocus.com/bid/96598

WordPress Prior to 4.7.3 URL Redirection Vulnerability
2017-03-23
http://www.securityfocus.com/bid/96600

Red Hat Dashbuilder CVE-2017-2658 Clickjacking Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97025

Multiple Bitdefender Products CVE-2017-6186 DLL Loading Local Code Injection Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97024

GNU Bash CVE-2016-0634 Local Code Execution Vulnerability
2017-03-23
http://www.securityfocus.com/bid/92999GNU Bash CVE-2016-0634 Local Code Execution Vulnerability
2017-03-23
http://www.securityfocus.com/bid/92999

GNU Bash CVE-2016-9401 Local Security Bypass Vulnerability
2017-03-23
http://www.securityfocus.com/bid/94398

GNU Bash CVE-2016-7543 Local Command Execution Vulnerability
2017-03-23
http://www.securityfocus.com/bid/93183

Samba CVE-2016-2125 User Impersonation Vulnerability
2017-03-23
http://www.securityfocus.com/bid/94988

Samba CVE-2016-2126 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/94994

Multiple AVG Products CVE-2017-5566 DLL Loading Local Code Injection Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97022

Linux kernel 'ip_sockglue.c' Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/96233

Ni LabVIEW CVE-2017-2775 Memory Corruption Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97020

Multiple Avira Products CVE-2017-6417 DLL Loading Local Code Injection Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97021

NfSen CVE-2017-6972 Unspecified Security Bypass Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97016

Linux Kernel CVE-2017-7184 Local Privilege Escalation Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97018

Multiple Avast Products CVE-2017-5567 DLL Loading Local Code Injection Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97017

icoutils 'simple_vec()' Function Buffer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/96267

icoutils CVE-2017-5332 Local Code Execution Vulnerability
2017-03-23
http://www.securityfocus.com/bid/95380

icoutils CVE-2017-5333 Local Integer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/95678

icoutils CVE-2017-5208 Local Integer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/95315

icoutils 'extract_icons()' Function Buffer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/96288

icoutils 'decode_ne_resource_id()' Function Buffer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/96292

OpenJPEG CVE-2016-9675 Incomplete Fix Multiple Remote Heap Based Buffer Overflow Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/94589

OpenJPEG CVE-2016-7163 Integer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/92897

Google Chrome Prior to 53.0.2785.89 Multiple Security Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/92717

Google Chrome Prior to 52.0.2743.116 Multiple Security Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/92276

Candlepin subscription-manager CVE-2017-2663 Multiple Local Privilege Escalation Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/97015

Cisco Application-Hosting Framework CVE-2017-3852 Arbitrary File Creation Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97014

Cisco Application-Hosting Framework CVE-2017-3851 Directory Traversal Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97013

Multiple Cisco Products CVE-2017-3853 Stack Buffer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97011

Cisco IOS and IOS XE Software CVE-2017-3864 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97012

libavcodec CVE-2017-7206 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97006

Cisco IOS and IOS XE Software CVE-2017-3857 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97010

Cisco IOS XE Software CVE-2017-3859 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97008
Linux Kernel CVE-2017-7184 Local Privilege Escalation Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97018

Multiple Avast Products CVE-2017-5567 DLL Loading Local Code Injection Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97017

icoutils 'simple_vec()' Function Buffer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/96267

icoutils CVE-2017-5332 Local Code Execution Vulnerability
2017-03-23
http://www.securityfocus.com/bid/95380

icoutils CVE-2017-5333 Local Integer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/95678

icoutils CVE-2017-5208 Local Integer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/95315

icoutils 'extract_icons()' Function Buffer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/96288

icoutils 'decode_ne_resource_id()' Function Buffer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/96292

OpenJPEG CVE-2016-9675 Incomplete Fix Multiple Remote Heap Based Buffer Overflow Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/94589

OpenJPEG CVE-2016-7163 Integer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/92897

Google Chrome Prior to 53.0.2785.89 Multiple Security Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/92717

Google Chrome Prior to 52.0.2743.116 Multiple Security Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/92276

Candlepin subscription-manager CVE-2017-2663 Multiple Local Privilege Escalation Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/97015

Cisco Application-Hosting Framework CVE-2017-3852 Arbitrary File Creation Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97014

Cisco Application-Hosting Framework CVE-2017-3851 Directory Traversal Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97013

Multiple Cisco Products CVE-2017-3853 Stack Buffer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97011

Cisco IOS and IOS XE Software CVE-2017-3864 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97012

libavcodec CVE-2017-7206 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97006

Cisco IOS and IOS XE Software CVE-2017-3857 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97010

Cisco IOS XE Software CVE-2017-3859 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97008

Cisco IOS XE Software CVE-2017-3858 Command Injection Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97009

Cisco IOS XE Software CVE-2017-3856 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97007

libavcodec CVE-2017-7208 Out of Bounds Read Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97005

Rockwell Automation Connected Components Workbench DLL Loading Local Code Execution Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97000

imdbphp CVE-2017-7204 Cross Site Scripting Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97002

Microsoft Internet Explorer CVE-2016-0162 Information Disclosure Vulnerability
2017-03-23
http://www.securityfocus.com/bid/85939

Microsoft Internet Explorer CVE-2016-0164 Remote Memory Corruption Vulnerability
2017-03-23
http://www.securityfocus.com/bid/85922

Apple Safari APPLE-SA-2016-03-21-6 Multiple Security Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/85055

Symantec Endpoint Protection Manager and Client CVE-2015-8154 Security Bypass Vulnerability
2017-03-23
http://www.securityfocus.com/bid/84344

Symantec Endpoint Protection Manager CVE-2015-8152 Cross Site Request Forgery Vulnerability
2017-03-23
http://www.securityfocus.com/bid/84343

SANS News

SSMA Usage

Threatpost

Blank Slate Spam Campaign Spreads Cerber Ransomware

Google, Jigsaw Partner on Free Tools to Secure Elections

Exploit

Ceragon FibeAir IP-10 - SSH Private Key Exposure (Metasploit)

ExaGrid - Known SSH Key and Default Password (Metasploit)

GIT 1.8.5.6 / 1.9.5 / 2.0.5 / 2.1.4/ 2.2.1 & Mercurial < 3.2.3 - Multiple...

Ruby on Rails 4.0.x / 4.1.x / 4.2.x (Web Console v2) - Whitelist Bypass Code...

Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code...

Samba 2.2.2 < 2.2.6 - 'nttrans' Buffer Overflow (Metasploit)

SSH - User Code Execution (Metasploit)

Joomla! Component Modern Booking 1.0 - 'coupon' Parameter SQL Injection

Flippa Clone - SQL Injection

Centreon < 2.5.1 / Centreon Enterprise Server < 2.2 - SQL Injection / Command...

D-Link/TRENDnet - NCC Service Command Injection (Metasploit)

Seagate Business NAS - Unauthenticated Remote Command Execution (Metasploit)

MantisBT 1.2.0a3 < 1.2.17 - XmlImportExport Plugin PHP Code Injection (Metasploit)

OP5 5.3.5 / 5.4.0 / 5.4.2 / 5.5.0 / 5.5.1 - 'license.php' Remote Command Execution...

Lenovo System Update - Privilege Escalation (Metasploit)

MOXA MediaDBPlayback - ActiveX Control Buffer Overflow (Metasploit)

Malwarebytes Anti-Malware < 2.0.3 / Anti-Exploit < 1.03.1.1220 - Update Remote Code...

CADA 3S CoDeSys Gateway Server - Directory Traversal (Metasploit)

Mozilla Firefox 5.0 < 15.0.1 - __exposedProps__ XCS Code Execution (Metasploit)

Firebird - Relational Database CNCT Group Number Buffer Overflow (Metasploit)

Microsoft Silverlight - ScriptObject Unsafe Memory Access (MS13-022/MS13-087)...

Disk Sorter Enterprise 9.5.12 - 'GET' Buffer Overflow (SEH)

SysGauge 1.5.18 - SMTP Validation Buffer Overflow (Metasploit)

GLink Word Link Script 1.2.3 - SQL Injection

Solare Datensysteme Solar-Log Devices 2.8.4-56 / 3.5.2-85 - Multiple Vulnerabilities

SpyCamLizard 1.230 - Denial of Service

APNGDis 2.8 - 'chunk size descriptor' Heap Buffer Overflow

APNGDis 2.8 - 'image width / height chunk' Heap Buffer Overflow

APNGDis 2.8 - 'filename' Stack Buffer Overflow

22.3.2017

Bugtraq

SEC Consult SA-20170322-0 :: Multiple vulnerabilities in Solare Datensysteme Solar-Log devices 2017-03-22
SEC Consult Vulnerability Lab (research sec-consult com)

Defense in depth -- the Microsoft way (part 47): "AppLocker bypasses are not serviced via monthly security roll-ups" 2017-03-21
Stefan Kanthak (stefan kanthak nexgo de)

[ERPSCAN-16-041] SAP NETWEAVER DIRECTORY CREATION OUTSIDE OF THE JVM 2017-03-21
ERPScan inc (erpscan online gmail com)

ESA-2017-010: EMC RecoverPoint SSL Stripping Vulnerability 2017-03-20
EMC Product Security Response Center (Security_Alert emc com)

[SECURITY] [DSA 3796-2] sitesummary regression update 2017-03-20
Sebastien Delafond (seb debian org)

[security bulletin] HPSBUX03596 rev.2 - HPE HP-UX running CIFS Server (Samba), Remote Access Restriction Bypass, Unauthorized Access 2017-03-20
security-alert hpe com

CVE-2017-7183 ExtraPuTTY v029_RC2 TFTP Denial Of Service 2017-03-20
apparitionsec gmail com (hyp3rlinx)

[SECURITY] [DSA 3813-1] r-base security update 2017-03-19
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 3812-1] ioquake3 security update 2017-03-18
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 3811-1] wireshark security update 2017-03-18
Moritz Muehlenhoff (jmm debian org)

Malware

Exploit:HTML/Meadgive.AC

Trojan:Win32/Fuery.B!cl 

Trojan:PDF/Phish

Phishing

Getit-Free

21st March 2017

Congrats! Youve Been Selected
for FREE -- Dewalt -- Samples.

Bank of America

21st March 2017

Bank of America Alert: Your
Online Access is Temporarily
Locked

Amazon.com

21st March 2017

ACCOUNT AMAZON : Failed to
verify your account Amazon
-4:00:00 - 3/21/2017-

Royal Bank of Scotland

21st March 2017

PAYMENT PENDING

Vulnerebility

D-Link DIR-600M CVE-2017-5874 Cross Site Request Forgery Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96999

OpenStack Nova CVE-2017-7214 Information Disclosure Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96998

Malware Information Sharing Platform CVE-2017-7215 Multiple Cross Site Scripting Vulnerabilities
2017-03-22
http://www.securityfocus.com/bid/96997

Ghostscript CVE-2017-7207 Denial of Service Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96995

Rockwell Automation FactoryTalk Activation CVE-2017-6015 Local Privilege Escalation Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96996

Printing Communications Association Rawether CVE-2017-3196 Local Privilege Escalation Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96993

Binutils CVE-2017-7209 Remote Denial of Service Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96994

Binutils CVE-2017-7210 Multiple Remote Denial of Service Vulnerabilities
2017-03-22
http://www.securityfocus.com/bid/96992

AppSamvid DLL Loading Local Code Execution Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96990

Linux Kernel CVE-2017-7187 Local Denial of Service Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96989

OpenStack Glance CVE-2017-7200 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96988

Red Hat JBoss BPMS CVE-2016-6343 Cross Site Scripting Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96987

Mozilla Firefox CVE-2017-5428 Integer Overflow Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96959

IBM PowerKVM CVE-2016-7076 Local Command Execution Vulnerability
2017-03-22
http://www.securityfocus.com/bid/95778

IBM PowerKVM CVE-2016-7032 Multiple Local Command Execution Vulnerabilities
2017-03-22
http://www.securityfocus.com/bid/95776

GnuPG and Libgcrypt CVE-2016-6313 Local Predictable Random Number Generator Weakness
2017-03-22
http://www.securityfocus.com/bid/92527

policycoreutils CVE-2016-7545 Remote Privilege Escalation Vulnerability
2017-03-22
http://www.securityfocus.com/bid/93156

Microsoft Internet Explorer and Edge CVE-2016-7282 Information Disclosure Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94724

Microsoft Office CVE-2016-7298 Memory Corruption Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94720

Microsoft Auto Updater for Mac CVE-2016-7300 Local Privilege Escalation Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94784

Microsoft Windows Graphics Component CVE-2016-7272 Remote Code Execution Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94739

Microsoft Windows Graphics Component CVE-2016-7273 Remote Code Execution Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94752

Microsoft Windows Kernel 'Win32k.sys' CVE-2016-7260 Local Privilege Escalation Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94785

Microsoft Internet Explorer and Edge CVE-2016-7287 Remote Memory Corruption Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94722

Jenkins SSH Slaves Plugin CVE-2017-2648 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96985

Jenkins Active Directory Plugin CVE-2017-2649 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96986

Jenkins Mailer Plugin CVE-2017-2651 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96984

Jenkins CVE-2017-2650 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96981

Apache POI CVE-2017-5644 Denial Of Service Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96983

Moodle CVE-2017-2645 HTML Injection Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96982Malware Information Sharing Platform CVE-2017-7215 Multiple Cross Site Scripting Vulnerabilities
2017-03-22
http://www.securityfocus.com/bid/96997

Ghostscript CVE-2017-7207 Denial of Service Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96995

Rockwell Automation FactoryTalk Activation CVE-2017-6015 Local Privilege Escalation Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96996

Printing Communications Association Rawether CVE-2017-3196 Local Privilege Escalation Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96993

Binutils CVE-2017-7209 Remote Denial of Service Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96994

Binutils CVE-2017-7210 Multiple Remote Denial of Service Vulnerabilities
2017-03-22
http://www.securityfocus.com/bid/96992

AppSamvid DLL Loading Local Code Execution Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96990

Linux Kernel CVE-2017-7187 Local Denial of Service Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96989

OpenStack Glance CVE-2017-7200 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96988

Red Hat JBoss BPMS CVE-2016-6343 Cross Site Scripting Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96987

Mozilla Firefox CVE-2017-5428 Integer Overflow Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96959

IBM PowerKVM CVE-2016-7076 Local Command Execution Vulnerability
2017-03-22
http://www.securityfocus.com/bid/95778

IBM PowerKVM CVE-2016-7032 Multiple Local Command Execution Vulnerabilities
2017-03-22
http://www.securityfocus.com/bid/95776

GnuPG and Libgcrypt CVE-2016-6313 Local Predictable Random Number Generator Weakness
2017-03-22
http://www.securityfocus.com/bid/92527

policycoreutils CVE-2016-7545 Remote Privilege Escalation Vulnerability
2017-03-22
http://www.securityfocus.com/bid/93156

Microsoft Internet Explorer and Edge CVE-2016-7282 Information Disclosure Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94724

Microsoft Office CVE-2016-7298 Memory Corruption Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94720

Microsoft Auto Updater for Mac CVE-2016-7300 Local Privilege Escalation Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94784

Microsoft Windows Graphics Component CVE-2016-7272 Remote Code Execution Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94739

Microsoft Windows Graphics Component CVE-2016-7273 Remote Code Execution Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94752

Microsoft Windows Kernel 'Win32k.sys' CVE-2016-7260 Local Privilege Escalation Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94785

Microsoft Internet Explorer and Edge CVE-2016-7287 Remote Memory Corruption Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94722

Jenkins SSH Slaves Plugin CVE-2017-2648 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96985

Jenkins Active Directory Plugin CVE-2017-2649 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96986

Jenkins Mailer Plugin CVE-2017-2651 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96984

Jenkins CVE-2017-2650 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96981

Apache POI CVE-2017-5644 Denial Of Service Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96983

Moodle CVE-2017-2645 HTML Injection Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96982

Jenkins Distributed Fork Plugin CVE-2017-2652 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96980

Moodle CVE-2017-2644 HTML Injection Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96979

SANS News

"Blank Slate" campaign still pushing Cerber ransomware

Threatpost

Locky, Cerber Ransomware Skilled at Hiding

Code Execution Vulnerability Found in Libpurple IM Library

Critical Moodle Vulnerability Could Lead to Server Compromise

SAP Vulnerability Puts Business Data at Risk for Thousands of Companies

Exploit

Joomla! Component Extra Search 2.2.8 - 'establename' Parameter SQL Injection

Disk Sorter Enterprise 9.5.12 - 'GET' Buffer Overflow (SEH)

GLink Word Link Script 1.2.3 - SQL Injection

22.3.2017

Bugtraq

Defense in depth -- the Microsoft way (part 47): "AppLocker bypasses are not serviced via monthly security roll-ups" 2017-03-21
Stefan Kanthak (stefan kanthak nexgo de)

[ERPSCAN-16-041] SAP NETWEAVER DIRECTORY CREATION OUTSIDE OF THE JVM 2017-03-21
ERPScan inc (erpscan online gmail com)

ESA-2017-010: EMC RecoverPoint SSL Stripping Vulnerability 2017-03-20
EMC Product Security Response Center (Security_Alert emc com)

[SECURITY] [DSA 3796-2] sitesummary regression update 2017-03-20
Sebastien Delafond (seb debian org)

[security bulletin] HPSBUX03596 rev.2 - HPE HP-UX running CIFS Server (Samba), Remote Access Restriction Bypass, Unauthorized Access 2017-03-20
security-alert hpe com

CVE-2017-7183 ExtraPuTTY v029_RC2 TFTP Denial Of Service 2017-03-20
apparitionsec gmail com (hyp3rlinx)

[SECURITY] [DSA 3813-1] r-base security update 2017-03-19
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 3812-1] ioquake3 security update 2017-03-18
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 3811-1] wireshark security update 2017-03-18
Moritz Muehlenhoff (jmm debian org)

Malware

TrojanSpy:MSIL/Omaneat
TrojanDownloader:Win32/Zdowbot.C

TrojanSpy:Win32/Bancos.XN

Trojan.Vanatmox

Trojan.Nexlogger

Phishing

Lloyds Bank

20th March 2017

Telephone Banking Verification

service@uk.paypal.com

19th March 2017

Your recent PayPal transfer is
under review

Vulnerebility

Microsoft Internet Explorer and Edge CVE-2016-7282 Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94724

Microsoft Office CVE-2016-7298 Memory Corruption Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94720

Microsoft Auto Updater for Mac CVE-2016-7300 Local Privilege Escalation Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94784

Microsoft Windows Graphics Component CVE-2016-7272 Remote Code Execution Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94739

Microsoft Windows Graphics Component CVE-2016-7273 Remote Code Execution Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94752

Microsoft Windows Kernel 'Win32k.sys' CVE-2016-7260 Local Privilege Escalation Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94785

Microsoft Internet Explorer and Edge CVE-2016-7287 Remote Memory Corruption Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94722

Jenkins SSH Slaves Plugin CVE-2017-2648 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96985

Jenkins Active Directory Plugin CVE-2017-2649 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96986

Jenkins Mailer Plugin CVE-2017-2651 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96984

Jenkins CVE-2017-2650 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96981

Apache POI CVE-2017-5644 Denial Of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96983

Moodle CVE-2017-2645 HTML Injection Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96982

Jenkins Distributed Fork Plugin CVE-2017-2652 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96980

Moodle CVE-2017-2644 HTML Injection Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96979

Quagga CVE-2017-5495 Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/95745

Quagga CVE-2016-1245 Buffer Overflow Vulnerability
2017-03-21
http://www.securityfocus.com/bid/93775

Quagga CVE-2016-2342 Stack Buffer Overflow Vulnerability
2017-03-21
http://www.securityfocus.com/bid/84318

Quagga CVE-2013-2236 Stack Buffer Overflow Vulnerability
2017-03-21
http://www.securityfocus.com/bid/60955

Moodle CVE-2017-2643 Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96978

Linux Kernel CVE-2016-10088 Incomplete Fix Multiple Local Memory Corruption Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/95169

Linux Kernel CVE-2016-9576 Use After Free Memory Corruption Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94821

Linux Kernel CVE-2016-2069 TLB Flush Local Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/81809

Linux Kernel CVE-2016-6480 Local Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/92214

Linux Kernel Local Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/92659

IETF IPv6 Protocol CVE-2016-10142 Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/95797

Linux Kernel CVE-2016-7042 Local Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/93544

Moodle CVE-2017-2641 SQL Injection Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96977

IBM Call Center for Commerce CVE-2016-6056 Cross Site Scripting Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96975

IBM Security Key Lifecycle Manager CVE-2016-6102 Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96976ExtraPuTTY CVE-2017-7183 Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96973

Cisco IOS and IOS XE Software CVE-2017-3849 Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96972

Cisco IOS and IOS XE Software CVE-2017-3850 Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96971

Skype CVE-2017-6517 DLL Loading Local Code Execution Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96969

USB Pratirodh CVE-2017-6911 Insecure Password Storage Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96970

Ubiquiti Networking Products Multiple Command Injection Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96967

IBM Algorithmics One-Algo Risk Application CVE-2017-1155 Unauthorized Access Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96968

Red Hat CloudForms Management App CVE-2017-2653 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96964

Microsoft Windows Local Privilege Escalation Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96966

Wordpress Anyone Plugin 'by-email.php' Session Management Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96965

IBM Cognos Business Intelligence CVE-2016-8960 Privilege Escalation Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96963

IBM Cognos Business Intelligence Server CVE-2016-9985 Local Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96962

Trend Micro ServerProtect for Linux Unspecified Cross Site Scripting Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96961

Cisco IOS and IOS XE Software CVE-2017-3881 Remote Code Execution Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96960

Mozilla Firefox CVE-2017-5428 Integer Overflow Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96959

Google Android Qualcomm Fingerprint Sensor Driver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96950

Google Android Audioserver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96958

Nexpose Information Disclosure and DLL Loading Remote Code Execution Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96956

Metasploit Multiple Directory Traversal Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96954

Google Android NFC CVE-2017-0481 Privilege Escalation Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96953

Rapid7 AppSpider CVE-2017-5233 DLL Loading Remote Code Execution Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96957

EPESI Multiple Cross Site Scripting Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96955

Google Android Kernel ION Subsystem Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96952

Google Android Networking Driver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96948

Google Android Qualcomm IPA Driver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96947

Google Android Qualcomm Camera Driver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96951

Google Android HTC Sensor Hub Driver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96949

django-epiceditor CVE-2017-6591 Cross Site Scripting Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96946

b2evolution CVE-2017-6902 Arbitrary File Upload Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96945

Easy File Sharing FTP Server CVE-2017-6510 Directory Traversal Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96944

SANS News

Malspam with password-protected Word documents

Threatpost

Local Windows Admins Can Hijack Sessions Without Credentials

Latest Tax Scams Include Phishing Lures, Malware

Exploit

Microsoft Windows - Uniscribe Font Processing Out-of-Bounds Read in...

Microsoft Windows - 'USP10!otlList::insertAt' Uniscribe Font Processing Heap-Based Buffer...

Microsoft Windows Kernel - Registry Hive Loading Crashes in nt!nt!HvpGetBinMemAlloc and...

Microsoft Windows - Uniscribe Font Processing Heap-Based Out-of-Bounds Read/Write in...

Microsoft Windows - Uniscribe Font Processing Heap-Based Memory Corruption in...

Microsoft Windows - Uniscribe Font Processing Heap-Based Memory Corruption in...

Microsoft Windows - Uniscribe Font Processing Heap-Based Buffer Overflow in...

Microsoft Windows - Uniscribe Font Processing Heap-Based Out-of-Bounds Write in...

Microsoft Windows - Uniscribe Font Processing Heap-Based Memory Corruption Around...

Microsoft Windows - Uniscribe Font Processing Buffer Overflow in...

Microsoft Windows - Uniscribe Font Processing Multiple Heap-Based Out-of-Bounds and Wild...

Microsoft GDI+ - 'gdiplus!GetRECTSForPlayback' Out-of-Bounds Read (MS17-013)

Microsoft Color Management Module 'icm32.dll' - 'icm32!Fill_ushort_ELUTs_from_lut16Tag'...

Microsoft Windows - Uniscribe Heap-Based Out-of-Bounds Read in...

Microsoft Color Management Module 'icm32.dll' - 'icm32!LHCalc3toX_Di16_Do16_Lut8_G32'...

Microsoft Internet Explorer - 'textarea.defaultValue' Memory Disclosure (MS17-006)

Mozilla Firefox - 'table' Use-After-Free

D-Link DGS-1510 - Multiple Vulnerabilities

Google Nest Cam 5.2.1
 - Buffer Overflow Conditions Over Bluetooth LE

ExtraPuTTY 0.29-RC2 - Denial of Service

21.3.2017

Bugtraq

Defense in depth -- the Microsoft way (part 47): "AppLocker bypasses are not serviced via monthly security roll-ups" 2017-03-21
Stefan Kanthak (stefan kanthak nexgo de)

[ERPSCAN-16-041] SAP NETWEAVER DIRECTORY CREATION OUTSIDE OF THE JVM 2017-03-21
ERPScan inc (erpscan online gmail com)

ESA-2017-010: EMC RecoverPoint SSL Stripping Vulnerability 2017-03-20
EMC Product Security Response Center (Security_Alert emc com)

[SECURITY] [DSA 3796-2] sitesummary regression update 2017-03-20
Sebastien Delafond (seb debian org)

[security bulletin] HPSBUX03596 rev.2 - HPE HP-UX running CIFS Server (Samba), Remote Access Restriction Bypass, Unauthorized Access 2017-03-20
security-alert hpe com

CVE-2017-7183 ExtraPuTTY v029_RC2 TFTP Denial Of Service 2017-03-20
apparitionsec gmail com (hyp3rlinx)

[SECURITY] [DSA 3813-1] r-base security update 2017-03-19
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 3812-1] ioquake3 security update 2017-03-18
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 3811-1] wireshark security update 2017-03-18
Moritz Muehlenhoff (jmm debian org)

Malware

TrojanSpy:MSIL/Omaneat
TrojanDownloader:Win32/Zdowbot.C

TrojanSpy:Win32/Bancos.XN

Trojan.Vanatmox

Trojan.Nexlogger

Phishing

Lloyds Bank

20th March 2017

Telephone Banking Verification

service@uk.paypal.com

19th March 2017

Your recent PayPal transfer is
under review

Vulnerebility

Microsoft Internet Explorer and Edge CVE-2016-7282 Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94724

Microsoft Office CVE-2016-7298 Memory Corruption Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94720

Microsoft Auto Updater for Mac CVE-2016-7300 Local Privilege Escalation Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94784

Microsoft Windows Graphics Component CVE-2016-7272 Remote Code Execution Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94739

Microsoft Windows Graphics Component CVE-2016-7273 Remote Code Execution Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94752

Microsoft Windows Kernel 'Win32k.sys' CVE-2016-7260 Local Privilege Escalation Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94785

Microsoft Internet Explorer and Edge CVE-2016-7287 Remote Memory Corruption Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94722

Jenkins SSH Slaves Plugin CVE-2017-2648 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96985

Jenkins Active Directory Plugin CVE-2017-2649 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96986

Jenkins Mailer Plugin CVE-2017-2651 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96984

Jenkins CVE-2017-2650 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96981

Apache POI CVE-2017-5644 Denial Of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96983

Moodle CVE-2017-2645 HTML Injection Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96982

Jenkins Distributed Fork Plugin CVE-2017-2652 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96980

Moodle CVE-2017-2644 HTML Injection Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96979

Quagga CVE-2017-5495 Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/95745

Quagga CVE-2016-1245 Buffer Overflow Vulnerability
2017-03-21
http://www.securityfocus.com/bid/93775

Quagga CVE-2016-2342 Stack Buffer Overflow Vulnerability
2017-03-21
http://www.securityfocus.com/bid/84318

Quagga CVE-2013-2236 Stack Buffer Overflow Vulnerability
2017-03-21
http://www.securityfocus.com/bid/60955

Moodle CVE-2017-2643 Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96978

Linux Kernel CVE-2016-10088 Incomplete Fix Multiple Local Memory Corruption Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/95169

Linux Kernel CVE-2016-9576 Use After Free Memory Corruption Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94821

Linux Kernel CVE-2016-2069 TLB Flush Local Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/81809

Linux Kernel CVE-2016-6480 Local Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/92214

Linux Kernel Local Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/92659

IETF IPv6 Protocol CVE-2016-10142 Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/95797

Linux Kernel CVE-2016-7042 Local Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/93544

Moodle CVE-2017-2641 SQL Injection Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96977

IBM Call Center for Commerce CVE-2016-6056 Cross Site Scripting Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96975

IBM Security Key Lifecycle Manager CVE-2016-6102 Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96976ExtraPuTTY CVE-2017-7183 Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96973

Cisco IOS and IOS XE Software CVE-2017-3849 Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96972

Cisco IOS and IOS XE Software CVE-2017-3850 Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96971

Skype CVE-2017-6517 DLL Loading Local Code Execution Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96969

USB Pratirodh CVE-2017-6911 Insecure Password Storage Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96970

Ubiquiti Networking Products Multiple Command Injection Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96967

IBM Algorithmics One-Algo Risk Application CVE-2017-1155 Unauthorized Access Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96968

Red Hat CloudForms Management App CVE-2017-2653 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96964

Microsoft Windows Local Privilege Escalation Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96966

Wordpress Anyone Plugin 'by-email.php' Session Management Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96965

IBM Cognos Business Intelligence CVE-2016-8960 Privilege Escalation Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96963

IBM Cognos Business Intelligence Server CVE-2016-9985 Local Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96962

Trend Micro ServerProtect for Linux Unspecified Cross Site Scripting Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96961

Cisco IOS and IOS XE Software CVE-2017-3881 Remote Code Execution Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96960

Mozilla Firefox CVE-2017-5428 Integer Overflow Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96959

Google Android Qualcomm Fingerprint Sensor Driver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96950

Google Android Audioserver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96958

Nexpose Information Disclosure and DLL Loading Remote Code Execution Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96956

Metasploit Multiple Directory Traversal Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96954

Google Android NFC CVE-2017-0481 Privilege Escalation Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96953

Rapid7 AppSpider CVE-2017-5233 DLL Loading Remote Code Execution Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96957

EPESI Multiple Cross Site Scripting Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96955

Google Android Kernel ION Subsystem Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96952

Google Android Networking Driver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96948

Google Android Qualcomm IPA Driver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96947

Google Android Qualcomm Camera Driver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96951

Google Android HTC Sensor Hub Driver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96949

django-epiceditor CVE-2017-6591 Cross Site Scripting Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96946

b2evolution CVE-2017-6902 Arbitrary File Upload Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96945

Easy File Sharing FTP Server CVE-2017-6510 Directory Traversal Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96944
 

SANS News

 

Threatpost

 

Exploit

 

21.3.2017

Bugtraq

CVE-2017-7183 ExtraPuTTY v029_RC2 TFTP Denial Of Service 2017-03-20
apparitionsec gmail com (hyp3rlinx)

[SECURITY] [DSA 3813-1] r-base security update 2017-03-19
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 3812-1] ioquake3 security update 2017-03-18
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 3811-1] wireshark security update 2017-03-18
Moritz Muehlenhoff (jmm debian org)

MS Internet Information Services XSS / HTML Injection vulnerability 2017-03-16
David FM (david fdmv gmail com)

Malware

 

Phishing

Lloyds Bank

20th March 2017

Telephone Banking Verification

service@uk.paypal.com

19th March 2017

Your recent PayPal transfer is
under review

service@paypal.com

19th March 2017

You have added
richie.005@yahoo.com as a new
email address for your Paypal
account.

Vulnerebility

Red Hat CloudForms Management App CVE-2017-2653 Security Bypass Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96964

Microsoft Windows Local Privilege Escalation Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96966

Wordpress Anyone Plugin 'by-email.php' Session Management Security Bypass Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96965

IBM Cognos Business Intelligence CVE-2016-8960 Privilege Escalation Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96963

IBM Cognos Business Intelligence Server CVE-2016-9985 Local Information Disclosure Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96962

Trend Micro ServerProtect for Linux Unspecified Cross Site Scripting Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96961

Cisco IOS and IOS XE Software CVE-2017-3881 Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96960

Mozilla Firefox CVE-2017-5428 Integer Overflow Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96959

Google Android Qualcomm Fingerprint Sensor Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96950

Google Android Audioserver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96958

Nexpose Information Disclosure and DLL Loading Remote Code Execution Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96956

Metasploit Multiple Directory Traversal Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96954

Google Android NFC CVE-2017-0481 Privilege Escalation Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96953

Rapid7 AppSpider CVE-2017-5233 DLL Loading Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96957

EPESI Multiple Cross Site Scripting Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96955

Google Android Kernel ION Subsystem Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96952

Google Android Networking Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96948

Google Android Qualcomm IPA Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96947

Google Android Qualcomm Camera Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96951

Google Android HTC Sensor Hub Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96949

django-epiceditor CVE-2017-6591 Cross Site Scripting Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96946

b2evolution CVE-2017-6902 Arbitrary File Upload Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96945

Easy File Sharing FTP Server CVE-2017-6510 Directory Traversal Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96944

Linux Kernel CVE-2017-6951 Local Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96943

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96378

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95993

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95990

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96112

QEMU 'sdhci.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95885

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95999
Trend Micro ServerProtect for Linux Unspecified Cross Site Scripting Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96961

Cisco IOS and IOS XE Software CVE-2017-3881 Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96960

Mozilla Firefox CVE-2017-5428 Integer Overflow Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96959

Google Android Qualcomm Fingerprint Sensor Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96950

Google Android Audioserver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96958

Nexpose Information Disclosure and DLL Loading Remote Code Execution Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96956

Metasploit Multiple Directory Traversal Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96954

Google Android NFC CVE-2017-0481 Privilege Escalation Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96953

Rapid7 AppSpider CVE-2017-5233 DLL Loading Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96957

EPESI Multiple Cross Site Scripting Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96955

Google Android Kernel ION Subsystem Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96952

Google Android Networking Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96948

Google Android Qualcomm IPA Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96947

Google Android Qualcomm Camera Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96951

Google Android HTC Sensor Hub Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96949

django-epiceditor CVE-2017-6591 Cross Site Scripting Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96946

b2evolution CVE-2017-6902 Arbitrary File Upload Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96945

Easy File Sharing FTP Server CVE-2017-6510 Directory Traversal Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96944

Linux Kernel CVE-2017-6951 Local Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96943

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96378

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95993

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95990

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96112

QEMU 'sdhci.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95885

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95999

QEMU 'ac97.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95671

QEMU 'virtio-gpu.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95781

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/94803

QEMU 'es1370.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95669

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95773Google Android Audioserver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96958

Nexpose Information Disclosure and DLL Loading Remote Code Execution Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96956

Metasploit Multiple Directory Traversal Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96954

Google Android NFC CVE-2017-0481 Privilege Escalation Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96953

Rapid7 AppSpider CVE-2017-5233 DLL Loading Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96957

EPESI Multiple Cross Site Scripting Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96955

Google Android Kernel ION Subsystem Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96952

Google Android Networking Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96948

Google Android Qualcomm IPA Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96947

Google Android Qualcomm Camera Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96951

Google Android HTC Sensor Hub Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96949

django-epiceditor CVE-2017-6591 Cross Site Scripting Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96946

b2evolution CVE-2017-6902 Arbitrary File Upload Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96945

Easy File Sharing FTP Server CVE-2017-6510 Directory Traversal Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96944

Linux Kernel CVE-2017-6951 Local Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96943

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96378

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95993

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95990

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96112

QEMU 'sdhci.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95885

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95999

QEMU 'ac97.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95671

QEMU 'virtio-gpu.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95781

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/94803

QEMU 'es1370.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95669

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95773

LAquis SCADA CVE-2017-6016 Local Access Bypass Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96942

Google Chrome Prior to 52.0.2743.82 Multiple Security Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/92053

Apple iOS/tvOS/MacOS/watchOS Multiple Security Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/93054

Microsoft Windows Uniscribe CVE-2016-7274 Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/94758

SANS News

Searching for Base64-encoded PE Files

Threatpost

Jon Oberheide on Perimeter Security

Exploit

HttpServer 1.0 - Directory Traversal

FTPShell Server 6.56 - 'ChangePassword' Buffer Overflow

ExtraPuTTY 0.29-RC2 - Denial of Service

Joomla! Component JooCart 2.x - 'product_id' Parameter SQL Injection

19.3.2017

Bugtraq

 

Malware

 

Phishing

Apple

17th March 2017

ALERT: We have updates on our
Policy Update Page.[521510]

Account Support

17th March 2017

Please check your account
information

Mea

17th March 2017

Mea just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Anamaria

17th March 2017

Anamaria just sent you
$3,182.00 USD with Paypal.
Paypal recommends to withdraw
it now.

Vulnerebility

Google Android Audioserver Multiple Privilege Escalation Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/96958

Nexpose Information Disclosure and DLL Loading Remote Code Execution Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/96956

Metasploit Multiple Directory Traversal Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/96954

Google Android NFC CVE-2017-0481 Privilege Escalation Vulnerability
2017-03-19
http://www.securityfocus.com/bid/96953

Rapid7 AppSpider CVE-2017-5233 DLL Loading Remote Code Execution Vulnerability
2017-03-19
http://www.securityfocus.com/bid/96957

EPESI Multiple Cross Site Scripting Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/96955

Google Android Kernel ION Subsystem Multiple Privilege Escalation Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/96952

Google Android Networking Driver Multiple Privilege Escalation Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/96948

Google Android Qualcomm IPA Driver Multiple Privilege Escalation Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/96947

Google Android Qualcomm Camera Driver Multiple Privilege Escalation Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/96951

Google Android HTC Sensor Hub Driver Multiple Privilege Escalation Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/96949

django-epiceditor CVE-2017-6591 Cross Site Scripting Vulnerability
2017-03-19
http://www.securityfocus.com/bid/96946

b2evolution CVE-2017-6902 Arbitrary File Upload Vulnerability
2017-03-19
http://www.securityfocus.com/bid/96945

Easy File Sharing FTP Server CVE-2017-6510 Directory Traversal Vulnerability
2017-03-19
http://www.securityfocus.com/bid/96944

Linux Kernel CVE-2017-6951 Local Denial of Service Vulnerability
2017-03-19
http://www.securityfocus.com/bid/96943

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-03-19
http://www.securityfocus.com/bid/96378

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-19
http://www.securityfocus.com/bid/95993

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-19
http://www.securityfocus.com/bid/95990

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-19
http://www.securityfocus.com/bid/96112

QEMU 'sdhci.c' Denial of Service Vulnerability
2017-03-19
http://www.securityfocus.com/bid/95885

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-19
http://www.securityfocus.com/bid/95999

QEMU 'ac97.c' Denial of Service Vulnerability
2017-03-19
http://www.securityfocus.com/bid/95671

QEMU 'virtio-gpu.c' Denial of Service Vulnerability
2017-03-19
http://www.securityfocus.com/bid/95781

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/94803

QEMU 'es1370.c' Denial of Service Vulnerability
2017-03-19
http://www.securityfocus.com/bid/95669

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-19
http://www.securityfocus.com/bid/95773

LAquis SCADA CVE-2017-6016 Local Access Bypass Vulnerability
2017-03-19
http://www.securityfocus.com/bid/96942

Google Chrome Prior to 52.0.2743.82 Multiple Security Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/92053

Apple iOS/tvOS/MacOS/watchOS Multiple Security Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/93054

Microsoft Windows Uniscribe CVE-2016-7274 Remote Code Execution Vulnerability
2017-03-19
http://www.securityfocus.com/bid/94758Google Android Audioserver Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96958

Nexpose Information Disclosure and DLL Loading Remote Code Execution Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96956

Metasploit Multiple Directory Traversal Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96954

Google Android NFC CVE-2017-0481 Privilege Escalation Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96953

Rapid7 AppSpider CVE-2017-5233 DLL Loading Remote Code Execution Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96957

EPESI Multiple Cross Site Scripting Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96955

Google Android Kernel ION Subsystem Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96952

Google Android Networking Driver Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96948

Google Android Qualcomm IPA Driver Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96947

Google Android Qualcomm Camera Driver Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96951

Google Android HTC Sensor Hub Driver Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96949

django-epiceditor CVE-2017-6591 Cross Site Scripting Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96946

b2evolution CVE-2017-6902 Arbitrary File Upload Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96945

Easy File Sharing FTP Server CVE-2017-6510 Directory Traversal Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96944

Linux Kernel CVE-2017-6951 Local Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96943

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96378

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95993

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95990

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96112

QEMU 'sdhci.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95885

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95999

QEMU 'ac97.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95671

QEMU 'virtio-gpu.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95781

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/94803

QEMU 'es1370.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95669

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95773

LAquis SCADA CVE-2017-6016 Local Access Bypass Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96942

Google Chrome Prior to 52.0.2743.82 Multiple Security Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/92053

Apple iOS/tvOS/MacOS/watchOS Multiple Security Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/93054

Microsoft Windows Uniscribe CVE-2016-7274 Remote Code Execution Vulnerability
2017-03-18
http://www.securityfocus.com/bid/94758Google Android Audioserver Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96958

Nexpose Information Disclosure and DLL Loading Remote Code Execution Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96956

Metasploit Multiple Directory Traversal Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96954

Google Android NFC CVE-2017-0481 Privilege Escalation Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96953

Rapid7 AppSpider CVE-2017-5233 DLL Loading Remote Code Execution Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96957

EPESI Multiple Cross Site Scripting Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96955

Google Android Kernel ION Subsystem Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96952

Google Android Networking Driver Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96948

Google Android Qualcomm IPA Driver Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96947

Google Android Qualcomm Camera Driver Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96951

Google Android HTC Sensor Hub Driver Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96949

django-epiceditor CVE-2017-6591 Cross Site Scripting Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96946

b2evolution CVE-2017-6902 Arbitrary File Upload Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96945

Easy File Sharing FTP Server CVE-2017-6510 Directory Traversal Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96944

Linux Kernel CVE-2017-6951 Local Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96943

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96378

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95993

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95990

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96112

QEMU 'sdhci.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95885

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95999

QEMU 'ac97.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95671

QEMU 'virtio-gpu.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95781

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/94803

QEMU 'es1370.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95669

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95773

LAquis SCADA CVE-2017-6016 Local Access Bypass Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96942

Google Chrome Prior to 52.0.2743.82 Multiple Security Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/92053

Apple iOS/tvOS/MacOS/watchOS Multiple Security Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/93054

Microsoft Windows Uniscribe CVE-2016-7274 Remote Code Execution Vulnerability
2017-03-18
http://www.securityfocus.com/bid/94758

SANS News

Example of Multiple Stages Dropper

Threatpost

Vulnerability Disclosed in Ubquiti Networks Admin Interface

VM Escape Earns Hackers $105K at Pwn2Own

Exploit

Linux/x86 - Encoded exceve("/bin/sh") Shellcode (44 Bytes)

Linux/x86 - Bind Shell Shellcode (51 bytes)

iFdate Social Dating Script 2.0 - SQL Injection

DIGISOL DG-HR1400 1.00.02 Wireless Router - Privilege Escalation

Omegle Clone - SQL Injection

Secure Download Links - 'dc' Parameter SQL Injection

17.3.2017

Bugtraq

MS Internet Information Services XSS / HTML Injection vulnerability 2017-03-16
David FM (david fdmv gmail com)

CVE-2017-6805 MobaXterm Personal Edition v9.4 Path Traversal Remote File Disclosure 2017-03-16
apparitionsec gmail com (hyp3rlinx)

SEC Consult SA-20170316-0 :: Authenticated command injection in multiple Ubiquiti Networks products 2017-03-16
SEC Consult Vulnerability Lab (research sec-consult com)

CVE-2017-6911: USB Pratirodh Insecure Password Storage Information Disclosure Vulnerability 2017-03-16
wsachin092 gmail com

[slackware-security] pidgin (SSA:2017-074-01) 2017-03-16
Slackware Security Team (security slackware com)

Path Traversal Remote File Disclosure 2017-03-16
apparitionsec gmail com (hyp3rlinx)

Malware

Trojan.Majikpos

Phishing

Mea

17th March 2017

Mea just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Anamaria

17th March 2017

Anamaria just sent you
$3,182.00 USD with Paypal.
Paypal recommends to withdraw
it now.

Kelly

17th March 2017

Kelly just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Vulnerebility

Google Android HTC Sensor Hub Driver Multiple Privilege Escalation Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96949

django-epiceditor CVE-2017-6591 Cross Site Scripting Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96946

b2evolution CVE-2017-6902 Arbitrary File Upload Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96945

Easy File Sharing FTP Server CVE-2017-6510 Directory Traversal Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96944

Linux Kernel CVE-2017-6951 Local Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96943

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96378

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95993

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95990

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96112

QEMU 'sdhci.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95885

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95999

QEMU 'ac97.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95671

QEMU 'virtio-gpu.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95781

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/94803

QEMU 'es1370.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95669

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95773

LAquis SCADA CVE-2017-6016 Local Access Bypass Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96942

Google Chrome Prior to 52.0.2743.82 Multiple Security Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/92053

Apple iOS/tvOS/MacOS/watchOS Multiple Security Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/93054

Microsoft Windows Uniscribe CVE-2016-7274 Remote Code Execution Vulnerability
2017-03-17
http://www.securityfocus.com/bid/94758

Libxml2 CVE-2016-4448 Remote Format String Vulnerability
2017-03-17
http://www.securityfocus.com/bid/90856

Commvault Edge CVE-2017-3195 Stack Buffer Overflow Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96941

Agora-Project Multiple Cross Site Scripting Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96940

Asus ASUSWRT Multiple Security Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96938

MaNGOSWebV4 Multiple Cross Site Scripting Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96939

Zammad Multiple Security Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96937

CMS Made Simple Multiple Cross Site Scripting Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96933

MagniComp Sysinfo CVE-2017-6516 Local Privilege Escalation Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96934

USB Pratirodh CVE-2017-6895 XML External Entity Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96936

IBM WebSphere Application Server CVE-2015-7450 Remote Code Execution Vulnerability
2017-03-17
http://www.securityfocus.com/bid/77653QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95993

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95990

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96112

QEMU 'sdhci.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95885

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95999

QEMU 'ac97.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95671

QEMU 'virtio-gpu.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95781

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/94803

QEMU 'es1370.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95669

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95773

Google Chrome Prior to 52.0.2743.82 Multiple Security Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/92053

Apple iOS/tvOS/MacOS/watchOS Multiple Security Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/93054

Microsoft Windows Uniscribe CVE-2016-7274 Remote Code Execution Vulnerability
2017-03-17
http://www.securityfocus.com/bid/94758

Libxml2 CVE-2016-4448 Remote Format String Vulnerability
2017-03-17
http://www.securityfocus.com/bid/90856

Commvault Edge CVE-2017-3195 Stack Buffer Overflow Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96941

Agora-Project Multiple Cross Site Scripting Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96940

Asus ASUSWRT Multiple Security Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96938

MaNGOSWebV4 Multiple Cross Site Scripting Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96939

Zammad Multiple Security Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96937

CMS Made Simple Multiple Cross Site Scripting Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96933

MagniComp Sysinfo CVE-2017-6516 Local Privilege Escalation Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96934

USB Pratirodh CVE-2017-6895 XML External Entity Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96936

IBM WebSphere Application Server CVE-2015-7450 Remote Code Execution Vulnerability
2017-03-17
http://www.securityfocus.com/bid/77653

Shimmie CVE-2017-6909 Cross Site Scripting Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96932

webpagetest Multiple Cross Site Scripting Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96935

ImageMagick CVE-2017-6498 Local Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96591

ImageMagick 'coders/sun.c' Local Heap Buffer Overflow Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96592

ImageMagick CVE-2017-6499 Local Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96590

McAfee Advanced Threat Defense CVE-2017-3899 SQL Injection Vulnerabilitiy
2017-03-17
http://www.securityfocus.com/bid/96929

Cisco Prime Infrastructure CVE-2017-3869 Security Bypass Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96931

SANS News

 

Threatpost

GitHub Code Execution Bug Fetches $18,000 Bounty

US-CERT Warns HTTPS Inspection May Degrade TLS Security

Exploit

Microsoft Edge 38.14393.0.0 - JavaScript Engine Use-After-Free

AXIS Communications - Cross-Site Scripting / Content Injection

AXIS Multiple Products - Cross-Site Request Forgery

Wordpress Plugin Membership Simplified 1.58 - Arbitrary File Download

16.3.2017

Bugtraq

MS Internet Information Services XSS / HTML Injection vulnerability 2017-03-16
David FM (david fdmv gmail com)

CVE-2017-6805 MobaXterm Personal Edition v9.4 Path Traversal Remote File Disclosure 2017-03-16
apparitionsec gmail com (hyp3rlinx)

SEC Consult SA-20170316-0 :: Authenticated command injection in multiple Ubiquiti Networks products 2017-03-16
SEC Consult Vulnerability Lab (research sec-consult com)

CVE-2017-6911: USB Pratirodh Insecure Password Storage Information Disclosure Vulnerability 2017-03-16
wsachin092 gmail com

[slackware-security] pidgin (SSA:2017-074-01) 2017-03-16
Slackware Security Team (security slackware com)

Path Traversal Remote File Disclosure 2017-03-16
apparitionsec gmail com (hyp3rlinx)

CVE-2017-0045 Windows DVD Maker XML External Entity File Disclosure 2017-03-16
apparitionsec gmail com (hyp3rlinx)

Microsoft Edge Fetch API allows setting of arbitrary request headers 2017-03-14
Securify B.V. (lists securify nl)

Joomla com_virtuemart Component - 'id' Parameter Sql Injection Vulnerability 2017-03-14
iedb team gmail com

Malware

Backdoor.Actoin

JS.Adashic!inf

Trojan.Modruner

Phishing

Card Services Online

15th March 2017

Natwest Card Services.

service@paypal.com

15th March 2017

Receipt for Your Payment to
cleverbridge, Inc

Account Amazon UK

14th March 2017

Your Amazon.co.uk Account
Updates

Vulnerebility

CMS Made Simple Multiple Cross Site Scripting Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96933

MagniComp Sysinfo CVE-2017-6516 Local Privilege Escalation Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96934

USB Pratirodh CVE-2017-6895 XML External Entity Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96936

IBM WebSphere Application Server CVE-2015-7450 Remote Code Execution Vulnerability
2017-03-16
http://www.securityfocus.com/bid/77653

Shimmie CVE-2017-6909 Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96932

webpagetest Multiple Cross Site Scripting Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96935

ImageMagick CVE-2017-6498 Local Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96591

ImageMagick 'coders/sun.c' Local Heap Buffer Overflow Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96592

ImageMagick CVE-2017-6499 Local Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96590

McAfee Advanced Threat Defense CVE-2017-3899 SQL Injection Vulnerabilitiy
2017-03-16
http://www.securityfocus.com/bid/96929

Cisco Prime Infrastructure CVE-2017-3869 Security Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96931

Cisco Prime Optical for Service Providers CVE-2017-3871 Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96928

Cisco Nexus 7000 Series Switches CVE-2017-3875 Security Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96930

Cisco Adaptive Security Appliance Software CVE-2017-3867 Security Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96926

Cisco NX-OS Software CVE-2017-3878 Remote Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96927

Palo Alto Networks Terminal Services CVE-2017-6356 Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96925

Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96654

Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96664

Mozilla Firefox and Thunderbird CVE-2017-5401 Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96677

Mozilla Firefox and Thunderbird Multiple Security Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96693

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96651

netpbm CVE-2017-5849 Multiple Denial of Service Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96011

Apache Tomcat CVE-2016-8745 Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/94828

RabbitMQ CVE-2015-8786 Multiple Denial of Service Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/91508

Linux Kernel CVE-2017-5551 Local Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/95717

Linux Kernel 'EXT4 image' Local Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/94354

Oracle MySQL Server CVE-2017-3313 Local Security Vulnerability
2017-03-16
http://www.securityfocus.com/bid/95527

MariaDB and MySQL CVE-2017-3302 Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96162

Adobe Flash Player APSB17-07 Multiple Memory Corruption Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96866

Adobe Flash Player CVE-2017-2997 Buffer Overflow Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96860Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96654

Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96664

Mozilla Firefox and Thunderbird CVE-2017-5401 Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96677

Mozilla Firefox and Thunderbird Multiple Security Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96693

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96651

netpbm CVE-2017-5849 Multiple Denial of Service Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96011

Apache Tomcat CVE-2016-8745 Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/94828

RabbitMQ CVE-2015-8786 Multiple Denial of Service Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/91508

Linux Kernel CVE-2017-5551 Local Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/95717

Linux Kernel 'EXT4 image' Local Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/94354

Oracle MySQL Server CVE-2017-3313 Local Security Vulnerability
2017-03-16
http://www.securityfocus.com/bid/95527

MariaDB and MySQL CVE-2017-3302 Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96162

Adobe Flash Player APSB17-07 Multiple Memory Corruption Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96866

Adobe Flash Player CVE-2017-2997 Buffer Overflow Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96860

Adobe Flash Player CVE-2017-3000 Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96862

Adobe Flash Player APSB17-07 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96861

Drupal Private Module Access Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96924

Apache Tomcat CVE-2016-6816 Security Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/94461

Security guide for website operators CVE-2017-2128 OS Command Injection Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96923

Cisco NX-OS Software CVE-2017-3879 Remote Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96920

Cisco TelePresence Server Software CVE-2017-3815 Privilege Escalation Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96922

Cisco UCS Director CVE-2017-3868 Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96921

Drupal Core DRUPAL-SA-CORE-2017-001 Multiple Security Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96919

Cisco WebEx Meetings Server CVE-2017-3880 Authentication Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96918

Microsoft Windows Graphics Component CVE-2017-0108 Remote Code Execution Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96722

Cisco Prime Service Catalog CVE-2017-3866 Multiple Cross Site Scripting Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96917

Cisco Unified Communications Manager CVE-2017-3874 Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96914

Cisco Unified Communications Manager CVE-2017-3872 Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96916

Cisco StarOS CVE-2017-3819 Privilege Escalation Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96913

Cisco Unified Communications Manager CVE-2017-3877 Cross Site Request Forgery Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96915Microsoft Office CVE-2017-0020 Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96050

Microsoft Office CVE-2017-0027 Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96043

Microsoft Windows CVE-2017-0055 Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96622

Foxit Reader and Foxit PhantomPDF CVE-2017-6883 Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96870

Microsoft Edge CVE-2017-0151 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96727

Microsoft Edge CVE-2017-0150 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96725

Microsoft Edge CVE-2017-0070 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96690

Microsoft Edge CVE-2017-0137 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96689

Microsoft Edge CVE-2017-0136 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96688

Microsoft Edge CVE-2017-0134 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96687

Microsoft Edge CVE-2017-0132 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96686

Microsoft Edge CVE-2017-0141 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96685

Microsoft Edge CVE-2017-0138 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96684

Microsoft Edge CVE-2017-0133 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96683

Microsoft Edge CVE-2017-0094 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96682

Microsoft Edge CVE-2017-0071 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96681

Microsoft Edge CVE-2017-0131 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96671

Microsoft Edge CVE-2017-0067 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96662

Microsoft Edge CVE-2017-0135 Security Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96656

Microsoft Edge CVE-2017-0140 Security Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96653

Microsoft Edge CVE-2017-0066 Security Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96655

Microsoft Edge CVE-2017-0069 Spoofing Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96650

Microsoft Edge CVE-2017-0068 Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96649

Microsoft Edge CVE-2017-0065 Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96648

Microsoft Windows CVE-2017-0043 XML External Entity Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96628

Microsoft Windows CVE-2017-0102 Local Privilege Escalation Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96627

Microsoft Windows CVE-2017-0101 Local Privilege Escalation Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96625

Microsoft Windows Kernel CVE-2017-0103 Local Privilege Escalation Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96623

Microsoft Windows Kernel CVE-2017-0050 Local Privilege Escalation Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96025

Microsoft Windows Kernel 'Win32k.sys' CVE-2017-0081 Local Privilege Escalation Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96634Cisco UCS Director CVE-2017-3868 Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96921

Drupal Core DRUPAL-SA-CORE-2017-001 Multiple Security Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96919

Cisco WebEx Meetings Server CVE-2017-3880 Authentication Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96918

Microsoft Windows Graphics Component CVE-2017-0108 Remote Code Execution Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96722

Cisco Prime Service Catalog CVE-2017-3866 Multiple Cross Site Scripting Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96917

Cisco Unified Communications Manager CVE-2017-3874 Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96914

Cisco Unified Communications Manager CVE-2017-3872 Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96916

Cisco StarOS CVE-2017-3819 Privilege Escalation Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96913

Cisco Unified Communications Manager CVE-2017-3877 Cross Site Request Forgery Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96915

Cisco WebEx Meetings Server CVE-2017-3811 XML External Entity Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96912

Cisco Wireless LAN Controller CVE-2017-3854 Remote Security Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96911

Cisco AsyncOS CVE-2017-3870 Remote Security Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96907

Multiple Cisco Products CVE-2017-3846 Arbitrary File Read Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96910

Cisco Mobility Express 1800 Access Point Series CVE-2017-3831 Authentication Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96909

WordPress Wp2android Plugin CVE-2017-1002003 Arbitrary File Upload Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96908

WordPress Webapp-Builder Plugin CVE-2017-1002002 Arbitrary File Upload Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96906

WordPress Mobile App Builder By Wappress Plugin Arbitrary File Upload Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96905

SAP Travel Management Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96904

SAP NetWeaver Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96903

SAP HANA Unspecified Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96900

WordPress Mobile Friendly App Builder By Easytouch Plugin Arbitrary File Upload Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96899

SiberianCMS CVE-2017-6906 Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96898

SAP Security Diagnostic Tool Unspecified Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96901

SAP Enterprise Portal 'styleservice' Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96902

Open.GL CVE-2017-6907 Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96897

Apache Tomcat CVE-2016-8747 Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96895

Red Hat JBoss Enterprise Application Platform CVE-2016-8657 Local Privilege Escalation Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96896

Microsoft Windows Hyper-V CVE-2017-0098 Remote Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96642

Microsoft Windows Hyper-V CVE-2017-0076 Remote Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96636

Microsoft Windows Hyper-V CVE-2017-0097 Remote Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96639

SANS News

 

Threatpost

Intel, Microsoft Announce New Bug Bounties

Hackers Take Down Reader, Safari, Edge, Ubuntu Linux at Pwn2Own 2017

Fileless Malware Campaigns Tied to Same Attacker

Exploit

Microsoft Windows - COM Session Moniker Privilege Escalation (MS17-012)

Microsoft Windows - 'LoadUvsTable()' Heap-based Buffer Overflow

Adobe Flash - Metadata Parsing Out-of-Bounds Read

Adobe Flash - MovieClip Attach init Object Use-After-Free

Adobe Flash - ATF Thumbnailing Heap Overflow

Adobe Flash - ATF Planar Decompression Heap Overflow

Adobe Flash - AVC Header Slicing Heap Overflow

IBM WebSphere - RCE Java Deserialization (Metasploit)

Apache Struts Jakarta - Multipart Parser OGNL Injection (Metasploit)

Joomla! Component Vik Appointments 1.5 - SQL Injection

Joomla! Component Vik Rent Items 1.3 - SQL Injection

Joomla! Component Vik Rent Car 1.11 - SQL Injection

GitHub Enterprise 2.8.0 < 2.8.6 - Remote Code Execution

Steam Profile Integration 2.0.11 - SQL injection

Sitecore CMS 8.1 Update-3 - Cross-Site Scripting

Windows DVD Maker 6.1.7 - XML External Entity Injection

PCAUSA Rawether (ASUS PCE-AC56 WLAN Card Utilities Windows 10 x64) - Local...

15.3.2017

Bugtraq

Microsoft Edge Fetch API allows setting of arbitrary request headers 2017-03-14
Securify B.V. (lists securify nl)

Joomla com_virtuemart Component - 'id' Parameter Sql Injection Vulnerability 2017-03-14
iedb team gmail com

Joomla com_kunena Component - 'id' Parameter Sql Injection Vulnerability 2017-03-14
iedb team gmail com

Joomla com_sngevents Component - 'id' Parameter Sql Injection Vulnerability 2017-03-14
iedb team gmail com

Joomla com_fidecalendar Component - 'aid' Parameter Sql Injection Vulnerability 2017-03-14
iedb team gmail com

Malware

TrojanDownloader:Win32/Zdowbot.C
TrojanSpy:Win32/Bancos.XN

Phishing

Account Amazon UK

14th March 2017

Your Amazon.co.uk Account
Updates

Chantal

14th March 2017

Chantal just sent you
$3,182.00 USD with Paypal.
Paypal recommends to withdraw
it now.

Bank of America

14th March 2017

Bank of America Alert: Your
Online Access is Temporarily
Locked

Vulnerebility

Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96729

JIRA Server XML External Entity Injection and Arbitrary Code Execution Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96894

concrete5 Multiple Cross Site Scripting Vulnerabilities
2017-03-15
http://www.securityfocus.com/bid/96891

Fatek Automation PLC Ethernet Module CVE-2017-6023 Stack Based Buffer Overflow Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96892

WordPress DTracker Plugin Multiple Content Injection Vulnerabilities
2017-03-15
http://www.securityfocus.com/bid/96890

FIYO CMS CVE-2017-6823 Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96889

SAP NetWeaver Log Viewer Security Bypass Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96888

Cerberus FTP CVE-2017-6367 Denial of Service Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96887

MobaXterm Personal Edition CVE-2017-6805 Directory Traversal Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96886

SAP Cross Site Scripting Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96884

SAP BusinessObjects Unspecified Cross Site Scripting Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96885

keycloak CVE-2017-2646 Denial of Service Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96882

SAP 3D Visual Enterprise Author, Generator and Viewer Unspecified Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96883

SAP NetWeaver Visual Composer Denial of Service Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96865

SAP NetWeaver Monitoring Application Unspecified Cross Site Scripting Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96878

SAP Web Dynpro ABAP Unspecified Cross Site Scripting Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96879

Multiple VMware Products CVE-2017-4901 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96881

SAP Enterprise Portal 'GenericSemanticTest' Component Cross Site Scripting Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96880

GNU Wget CVE-2017-6508 CRLF Injection Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96877

Microsoft Windows SMB Server CVE-2017-0147 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96709

Microsoft Windows SMB Server CVE-2017-0145 Remote Code Execution Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96705

Microsoft Windows SMB Server CVE-2017-0146 Remote Code Execution Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96707

Microsoft Windows SMB Server CVE-2017-0143 Remote Code Execution Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96703

Microsoft Windows SMB Server CVE-2017-0148 Remote Code Execution Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96706

Microsoft Windows SMB Server CVE-2017-0144 Remote Code Execution Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96704

Microsoft Office CVE-2017-0029 Denial of Service Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96045

Microsoft Windows Hyper-V CVE-2017-0096 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96701

Microsoft Windows DirectShow CVE-2017-0042 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96098

Microsoft Windows Hyper-V CVE-2017-0075 Remote Code Execution Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96698

Microsoft Windows Hyper-V CVE-2017-0109 Remote Code Execution Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96644
Microsoft Windows Hyper-V CVE-2017-0021 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96020

Adobe Flash Player APSB17-07 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-03-15
http://www.securityfocus.com/bid/96861

Adobe Flash Player CVE-2017-3000 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96862

Adobe Flash Player APSB17-07 Multiple Memory Corruption Vulnerabilities
2017-03-15
http://www.securityfocus.com/bid/96866

Microsoft Internet Explorer CVE-2017-0049 Scripting Engine Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96095

Adobe Flash Player CVE-2017-2997 Buffer Overflow Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96860

Microsoft Windows Kernel 'Win32k.sys' CVE-2017-0082 Local Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96635

Microsoft Office CVE-2017-0105 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96746

Microsoft Office CVE-2017-0019 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96042

Microsoft Internet Explorer CVE-2017-0018 Remote Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96086

Microsoft Internet Explorer CVE-2017-0040 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96094

Microsoft Internet Explorer and Edge CVE-2017-0033 Spoofing Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96087

Microsoft Internet Explorer and Edge CVE-2017-0012 Spoofing Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96085

Microsoft Internet Explorer and Edge CVE-2017-0009 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96077

Microsoft Internet Explorer CVE-2017-0008 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96073

Microsoft Windows Graphics CVE-2017-0001 Local Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96057

Microsoft Internet Explorer and Edge CVE-2017-0037 Remote Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96088

Microsoft Windows Graphics CVE-2017-0047 Local Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96034

Microsoft Windows Graphics CVE-2017-0005 Local Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96033

Microsoft Windows CVE-2017-0038 Incomplete Fix Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96023

Microsoft Exchange Server CVE-2017-0110 Remote Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96621

SAP NetWeaver Visual Composer Denial of Service Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96865

Microsoft Office CVE-2017-0031 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96052

Microsoft Office CVE-2017-0030 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96051

Microsoft Office CVE-2017-0029 Denial of Service Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96045

Microsoft Office CVE-2017-0020 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96050

Microsoft Office CVE-2017-0027 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96043

Microsoft Windows CVE-2017-0055 Cross Site Scripting Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96622

Foxit Reader and Foxit PhantomPDF CVE-2017-6883 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96870

Microsoft Edge CVE-2017-0151 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96727Microsoft Windows Hyper-V CVE-2017-0021 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96020

Adobe Flash Player APSB17-07 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-03-15
http://www.securityfocus.com/bid/96861

Adobe Flash Player CVE-2017-3000 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96862

Adobe Flash Player APSB17-07 Multiple Memory Corruption Vulnerabilities
2017-03-15
http://www.securityfocus.com/bid/96866

Microsoft Internet Explorer CVE-2017-0049 Scripting Engine Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96095

Adobe Flash Player CVE-2017-2997 Buffer Overflow Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96860

Microsoft Windows Kernel 'Win32k.sys' CVE-2017-0082 Local Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96635

Microsoft Office CVE-2017-0105 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96746

Microsoft Office CVE-2017-0019 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96042

Microsoft Internet Explorer CVE-2017-0018 Remote Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96086

Microsoft Internet Explorer CVE-2017-0040 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96094

Microsoft Internet Explorer and Edge CVE-2017-0033 Spoofing Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96087

Microsoft Internet Explorer and Edge CVE-2017-0012 Spoofing Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96085

Microsoft Internet Explorer and Edge CVE-2017-0009 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96077

Microsoft Internet Explorer CVE-2017-0008 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96073

Microsoft Windows Graphics CVE-2017-0001 Local Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96057

Microsoft Internet Explorer and Edge CVE-2017-0037 Remote Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96088

Microsoft Windows Graphics CVE-2017-0047 Local Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96034

Microsoft Windows Graphics CVE-2017-0005 Local Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96033

Microsoft Windows CVE-2017-0038 Incomplete Fix Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96023

Microsoft Exchange Server CVE-2017-0110 Remote Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96621

SAP NetWeaver Visual Composer Denial of Service Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96865

Microsoft Office CVE-2017-0031 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96052

Microsoft Office CVE-2017-0030 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96051

Microsoft Office CVE-2017-0029 Denial of Service Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96045

Microsoft Office CVE-2017-0020 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96050

Microsoft Office CVE-2017-0027 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96043

Microsoft Windows CVE-2017-0055 Cross Site Scripting Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96622

Foxit Reader and Foxit PhantomPDF CVE-2017-6883 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96870

Microsoft Edge CVE-2017-0151 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96727

SANS News

Retro Hunting!

Threatpost

Google Eliminates Android Adfraud Botnet Chamois

JSON Libraries Patched Against Invalid Curve Crypto Attack

FSB Officers, Criminal Hackers Indicted in Yahoo Breach

WhatsApp, Telegram Vulnerabilities Exposed Users to Account Takeover

Patch Tuesday Returns; Microsoft Quiet on Postponement

Google Eliminates Android Adfraud Botnet Chamois

Exploit

Rawether for Windows - Privilege Escalation

ASUS PCE-AC56 WLAN Card Utilities (PCAUSA Rawether Windows 10 x64) - Local...

MikroTik Router - ARP Table OverFlow Denial Of Service

Joomla! Component Vik Appointments 1.5 - SQL Injection

Joomla! Component Vik Rent Items 1.3 - SQL Injection

Joomla! Component Vik Rent Car 1.11 - SQL Injection

Joomla! Component Advertisement Board 3.0.4 - 'id' Parameter SQL Injection

Joomla! Component Simple Membership 3.3.3 - 'userId' Parameter SQL Injection

14.3.2017

Bugtraq

Joomla com_kunena Component - 'id' Parameter Sql Injection Vulnerability 2017-03-14
iedb team gmail com

Joomla com_sngevents Component - 'id' Parameter Sql Injection Vulnerability 2017-03-14
iedb team gmail com

Joomla com_fidecalendar Component - 'aid' Parameter Sql Injection Vulnerability 2017-03-14
iedb team gmail com

Joomla com_registrationpro Component - 'did' Parameter Sql Injection Vulnerability 2017-03-14
iedb team gmail com

Joomla com_easyblog Component - 'id' Parameter Sql Injection Vulnerability 2017-03-14
iedb team gmail com

Atlassian - March 2017 - Bamboo, Crowd and HipChat Server - Critical Security Advisory 2017-03-14
David Black (dblack atlassian com)

[SECURITY] [DSA 3808-1] imagemagick security update 2017-03-13
Moritz Muehlenhoff (jmm debian org)

Malware

TrojanSpy:MSIL/Omaneat

Exp.CVE-2017-2984

Exp.CVE-2017-2982

Phishing

Bank of America

14th March 2017

Bank of America Alert: Your
Online Access is Temporarily
Locked

Card Services Online

14th March 2017

NATWEST CARD SERVICES.

Vulnerebility

SAP ERP Remote Authorization Bypass Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96871

Adobe Flash Player CVE-2017-3000 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96862

Adobe Flash Player CVE-2017-2997 Buffer Overflow Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96860

Trend Micro InterScan Messaging Security CVE-2017-6398 Remote Code Execution Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96859

SAP HANA Cockpit for Offline Administration Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96869

SAP ERP Remote Authorization Bypass Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96867

SAP HANA Unspecified Session Fixation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96864

Adobe Shockwave Player CVE-2017-2983 Local Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96863

Adobe Flash Player APSB17-07 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-03-14
http://www.securityfocus.com/bid/96861

Adobe Flash Player APSB17-07 Multiple Memory Corruption Vulnerabilities
2017-03-14
http://www.securityfocus.com/bid/96866

Adups CVE-2016-10139 Multiple Local Privilege Escalation Vulnerabilities
2017-03-14
http://www.securityfocus.com/bid/96858

Lutim CVE-2017-6877 Cross Site Scripting Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96855

Adups Fota CVE-2016-10138 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96853

Trend Micro Endpoint Sensor CVE-2017-6798 DLL Loading Remote Code Execution Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96857

Pidgin CVE 2017-2640 Out of Bounds Write Security Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96775

Linux kernel CVE-2017-6874 Use After Free Local Denial of Service Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96856

ZoneMinder CVE-2016-10140 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96849

Adups CVE-2016-10136 Local Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96854

Adups CVE-2016-10137 Local Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96852

CodeIgniter 'system/libraries/Email.php' Remote Code Execution Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96851

Multiple LG Android Mobile Devices CVE-2016-10135 Multiple Security Bypass Vulnerabilities
2017-03-14
http://www.securityfocus.com/bid/96846

Hitek Software Automize CVE-2016-10103 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96850

WordPress 'wp_ajax_update_plugin()' Function Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96847

Hitek Software Automize CVE-2016-10104 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96845

Hitek Software Automize CVE-2016-10102 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96848

Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96729

Hitek Software Automize CVE-2016-10101 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96840

Multiple F5 BIG-IP Products CVE-2016-7469 HTML Injection Vulnerability
2017-03-14
http://www.securityfocus.com/bid/95320

Symantec Web Gateway CVE-2016-9096 Multiple Cross Site Scripting Vulnerabilities
2017-03-14
http://www.securityfocus.com/bid/96297

IBM WebSphere Application Server CVE-2017-1151 Remote Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96841Pidgin CVE 2017-2640 Out of Bounds Write Security Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96775

Adups CVE-2016-10136 Local Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96854

Adups CVE-2016-10137 Local Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96852

CodeIgniter 'system/libraries/Email.php' Remote Code Execution Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96851

Multiple LG Android Mobile Devices CVE-2016-10135 Multiple Security Bypass Vulnerabilities
2017-03-14
http://www.securityfocus.com/bid/96846

Hitek Software Automize CVE-2016-10103 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96850

WordPress 'wp_ajax_update_plugin()' Function Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96847

Hitek Software Automize CVE-2016-10104 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96845

Hitek Software Automize CVE-2016-10102 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96848

Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96729

Hitek Software Automize CVE-2016-10101 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96840

Multiple F5 BIG-IP Products CVE-2016-7469 HTML Injection Vulnerability
2017-03-14
http://www.securityfocus.com/bid/95320

Symantec Web Gateway CVE-2016-9096 Multiple Cross Site Scripting Vulnerabilities
2017-03-14
http://www.securityfocus.com/bid/96297

IBM WebSphere Application Server CVE-2017-1151 Remote Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96841

Cybozu KUNAI CVE-2017-2109 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96844

Linux Kernel CVE-2016-8650 Null Pointer Deference Local Denial of Service Vulnerability
2017-03-14
http://www.securityfocus.com/bid/94532

Uninett mod_auth_mellon Module CVE-2017-6807 Authentication Bypass Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96843

Linux Kernel 'net/mac80211/tx.c' Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/70965

ISC BIND CVE-2016-9131 Remote Denial of Service Vulnerability
2017-03-14
http://www.securityfocus.com/bid/95386

Cybozu Kintone App CVE-2016-1185 Unspecified Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96842

NetIQ Self Service Password Reset CVE-2016-1599 Cross Site Scripting Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96837

Linux Kernel CVE-2016-2853 Local Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96839

Linux Kernel CVE-2016-2854 Local Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96838

Google Android MediaTek Video Codec Driver CVE-2017-0532 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96834

Google Nexus Qualcomm Camera Driver CVE-2017-0452 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96836

Google Nexus HTC Sound Codec Driver CVE-2017-0535 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96833

Google Android Kernel USB Gadget Driver CVE-2017-0537 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96831

Google Nexus Qualcomm Camera Driver CVE-2016-8417 Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96832

Google Nexus Synaptics Touchscreen Driver CVE-2017-0536 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96835

IBM Rational Rhapsody Design Manager CVE-2016-9698 XML External Entity Injection Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96829Multiple F5 BIG-IP Products CVE-2016-7469 HTML Injection Vulnerability
2017-03-14
http://www.securityfocus.com/bid/95320

Symantec Web Gateway CVE-2016-9096 Multiple Cross Site Scripting Vulnerabilities
2017-03-14
http://www.securityfocus.com/bid/96297

IBM WebSphere Application Server CVE-2017-1151 Remote Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96841

Cybozu KUNAI CVE-2017-2109 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96844

Linux Kernel CVE-2016-8650 Null Pointer Deference Local Denial of Service Vulnerability
2017-03-14
http://www.securityfocus.com/bid/94532

Uninett mod_auth_mellon Module CVE-2017-6807 Authentication Bypass Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96843

Linux Kernel 'net/mac80211/tx.c' Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/70965

Hitek Software Automize CVE-2016-10101 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96840

ISC BIND CVE-2016-9131 Remote Denial of Service Vulnerability
2017-03-14
http://www.securityfocus.com/bid/95386

Cybozu Kintone App CVE-2016-1185 Unspecified Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96842

NetIQ Self Service Password Reset CVE-2016-1599 Cross Site Scripting Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96837

Linux Kernel CVE-2016-2853 Local Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96839

Linux Kernel CVE-2016-2854 Local Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96838

Google Android MediaTek Video Codec Driver CVE-2017-0532 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96834

Google Nexus Qualcomm Camera Driver CVE-2017-0452 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96836

Google Nexus HTC Sound Codec Driver CVE-2017-0535 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96833

Google Android Kernel USB Gadget Driver CVE-2017-0537 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96831

Google Nexus Qualcomm Camera Driver CVE-2016-8417 Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96832

Google Nexus Synaptics Touchscreen Driver CVE-2017-0536 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96835

IBM Rational Rhapsody Design Manager CVE-2016-9698 XML External Entity Injection Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96829

IBM Rational Rhapsody Design Manager CVE-2016-9696 HTML Injection Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96830

IBM Rational Rhapsody Design Manager CVE-2016-8973 Arbitrary File Upload Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96826

IBM Rational Rhapsody Design Manager CVE-2016-9697 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96828

Livebox 3 Sagemcom CVE-2017-6552 Local Denial of Service Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96827

Azure Data Expert Ultimate CVE-2017-6506 Buffer Overflow Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96824

IBM Rational Rhapsody Design Manager CVE-2016-9694 Cross Site Scripting Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96825

dnaLIMS Multiple Security Vulnerabilities
2017-03-14
http://www.securityfocus.com/bid/96823

Wireshark 'wiretap/netscaler.c' Denial of Service Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96566

Wireshark WSP Dissector 'tcp_graph.c' Denial of Service Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96564

Wireshark LDSS Dissector 'epan/dissectors/packet-ldss.c' Denial of Service Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96577

SANS News

February and March Microsoft Patch Tuesday

Threatpost

Adobe Fixes Six Code Execution Bugs in Flash

Credit Card Scrapers Continue to Target Magento

38 Android Devices Infected with Malware Preinstalled in Supply Chain

WordPress REST API Bug Could Be Used in Stored XSS Attacks

Exploit

MikroTik Router - ARP Table OverFlow Denial Of Service

VirtualBox - Cooperating VMs can Escape from Shared Folder

Joomla! Component Simple Membership 3.3.3 - 'userId' Parameter SQL Injection

Joomla! Component Advertisement Board 3.0.4 - 'id' Parameter SQL Injection

Car Workshop System - SQL Injection

Fiyo CMS 2.0.6.1 - Privilege Escalation

Cerberus FTP Server 8.0.10.1 - Denial of Service

13.3.2017

Bugtraq

Joomla com_carocci Component - 'isbn' Parameter Sql Injection Vulnerability 2017-03-12
iedb team gmail com

Joomla com_kide Component - 'view' Parameter Sql Injection Vulnerability 2017-03-12
iedb team gmail com

Joomla com_eventlist Component - 'id' Parameter Sql Injection Vulnerability 2017-03-12
iedb team gmail com

[security bulletin] HPESBUX03706 rev.1 - HP-UX NTP service running ntpd, Multiple Vulnerabilities 2017-03-10
security-alert hpe com

[security bulletin] HPESBHF03711 rev.1 - HPE 2620 Series Network Switches, Remote Cross Site Request Forgery (CSRF) 2017-03-10
security-alert hpe com

[security bulletin] HPESBGN03707 rev.1 - HPE ConvergedSystem 700 2.0 VMware Kit, Remote Increase of Privilege 2017-03-10
security-alert hpe com

[security bulletin] HPESBHF03716 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Remote Authentication Bypass 2017-03-10
security-alert hpe com

CVE-2016-10143: Vulnerability to read arbitrary files in "Tiki Wiki" 2017-03-10
Leon Zhao 7 gmail com

Malware

Trojan.Powire

Phishing

Tesco Bank

12th March 2017

TESCO BANK - WAS SUSPENDED DUE
TO A VIOLATION

PayPal

12th March 2017

Your account has been limited
until we hear from you

=?iso-8859-1?Q?R=E9seau_Paix_e

12th March 2017

TR: Nila just sent you
$3,182.00 USD with Paypal.
Paypal recommends to withdraw
it now.

Vulnerebility

Google Android MediaTek Video Codec Driver CVE-2017-0532 Information Disclosure Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96834

Google Nexus Qualcomm Camera Driver CVE-2017-0452 Information Disclosure Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96836

Google Nexus HTC Sound Codec Driver CVE-2017-0535 Information Disclosure Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96833

Google Android Kernel USB Gadget Driver CVE-2017-0537 Information Disclosure Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96831

Google Nexus Qualcomm Camera Driver CVE-2016-8417 Privilege Escalation Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96832

Google Nexus Synaptics Touchscreen Driver CVE-2017-0536 Information Disclosure Vulnerability

IBM Rational Rhapsody Design Manager CVE-2016-9698 XML External Entity Injection Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96829

IBM Rational Rhapsody Design Manager CVE-2016-9696 HTML Injection Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96830

IBM Rational Rhapsody Design Manager CVE-2016-8973 Arbitrary File Upload Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96826

IBM Rational Rhapsody Design Manager CVE-2016-9697 Information Disclosure Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96828

Livebox 3 Sagemcom CVE-2017-6552 Local Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96827

Azure Data Expert Ultimate CVE-2017-6506 Buffer Overflow Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96824

IBM Rational Rhapsody Design Manager CVE-2016-9694 Cross Site Scripting Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96825

dnaLIMS Multiple Security Vulnerabilities
2017-03-13
http://www.securityfocus.com/bid/96823

Wireshark 'wiretap/netscaler.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96566

Wireshark WSP Dissector 'tcp_graph.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96564

Wireshark LDSS Dissector 'epan/dissectors/packet-ldss.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96577

Wireshark NetScaler File Parser 'wiretap/netscaler.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96569

Wireshark IAX2 Dissector 'packet-iax2.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96563

Wireshark RTMPT Dissector 'dissectors/packet-rtmpt.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96571

Wireshark Netscaler File Parser 'netscaler.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96561

Wireshark 'k12.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96565

iBall Baton 150M Wireless Router CVE-2017-6558 Authentication Bypass Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96822

Kinsey Infor-Lawson CVE-2017-6550 Multiple SQL Injection Vulnerabilities
2017-03-13
http://www.securityfocus.com/bid/96821

Evostream Media Server CVE-2017-6427 Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96820

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96378

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96112

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/95999

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-13
http://www.securityfocus.com/bid/95990

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-13
http://www.securityfocus.com/bid/94803

QEMU 'sdhci.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/95885

QEMU 'ehci_init_transfer()' Function Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/94762

QEMU '/hw/usb/redirect.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/94759

QEMU '/hw/net/mcf_fec.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/94638

MantisBT 'view_filters_page.php' Cross Site Scripting Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96819

MantisBT 'bug_change_status_page.php' Cross Site Scripting Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96818

Evostream Media Server CVE-2017-6427 Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96820

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96378

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96112

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/95999

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-13
http://www.securityfocus.com/bid/95990

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-13
http://www.securityfocus.com/bid/94803

QEMU 'sdhci.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/95885

QEMU 'ehci_init_transfer()' Function Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/94762

QEMU '/hw/usb/redirect.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/94759

QEMU '/hw/net/mcf_fec.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/94638

MantisBT 'view_filters_page.php' Cross Site Scripting Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96819

MantisBT 'bug_change_status_page.php' Cross Site Scripting Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96818

Roundcube CVE-2017-6820 Cross Site Scripting Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96817

Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96729

icoutils 'extract_icons()' Function Buffer Overflow Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96288

icoutils 'decode_ne_resource_id()' Function Buffer Overflow Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96292

icoutils 'simple_vec()' Function Buffer Overflow Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96267

Juniper Networks IDP Appliance Configuration Manager Cross Site Scripting Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96816

HP Intelligent Management Center CVE-2017-5791 Authentication Bypass Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96815

WordPress Prior to 4.7.3 Cross Site Request Forgery Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96602

WordPress Prior to 4.7.3 Security Bypass Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96598

WordPress Prior to 4.7.3 URL Redirection Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96600

WordPress Prior to 4.7.3 Multiple Cross Site Scripting Vulnerabilities
2017-03-13
http://www.securityfocus.com/bid/96601

FTP Voyager Scheduler CVE-2017-6803 Multiple Cross Site Request Forgery Vulnerabilities
2017-03-13
http://www.securityfocus.com/bid/96814

HP 2620 Series Network Switches CVE-2017-5796 Cross Site Request Forgery Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96813

Symantec Endpoint Protection CVE-2016-9094 Local Command Injection Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96298

Symantec Endpoint Protection Client CVE-2016-9093 Local Privilege Escalation Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96294

Google Pixel Qualcomm Bootloader CVE-2017-0455 Information Disclosure Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96812

Google Android MediaTek Driver CVE-2017-0529 Information Disclosure Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96810

Google Nexus Kernel Security Subsystem CVE-2017-0528 Privilege Escalation Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96807

SANS News

New tool: sigs.py

Honeypot Logs and Tracking a VBE Script

Threatpost

Cody Pierce on the Future of Exploit Development

Telepresence Robots Patched Against Data Leaks

March Android Security Update Breaks SafetyNet, Android Pay

Exploit

Netgear R7000 and R6400 - cgi-bin Command Injection (Metasploit)

Cerberus FTP Server 8.0.10.1 - Denial of Service

Car Workshop System - SQL Injection

Fiyo CMS 2.0.6.1 - Privilege Escalation

11.3.2017

Bugtraq

[security bulletin] HPESBUX03706 rev.1 - HP-UX NTP service running ntpd, Multiple Vulnerabilities 2017-03-10
security-alert hpe com

[security bulletin] HPESBHF03711 rev.1 - HPE 2620 Series Network Switches, Remote Cross Site Request Forgery (CSRF) 2017-03-10
security-alert hpe com

[security bulletin] HPESBGN03707 rev.1 - HPE ConvergedSystem 700 2.0 VMware Kit, Remote Increase of Privilege 2017-03-10
security-alert hpe com

[security bulletin] HPESBHF03716 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Remote Authentication Bypass 2017-03-10
security-alert hpe com

CVE-2016-10143: Vulnerability to read arbitrary files in "Tiki Wiki" 2017-03-10
Leon Zhao 7 gmail com

[SECURITY] [DSA 3805-1] firefox-esr security update 2017-03-09
Moritz Muehlenhoff (jmm debian org)

[security bulletin] HPESBHF03714 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Local Arbitrary File Download 2017-03-08
security-alert hpe com

[SECURITY] [DSA 3804-1] linux security update 2017-03-08
Salvatore Bonaccorso (carnil debian org)

[security bulletin] HPESBHF03713 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Deserialization of Untrusted Data, Remote Code Execution 2017-03-08
security-alert hpe com

Malware

 

Phishing

Gwyneth

11th March 2017

Gwyneth just sent you
$3,182.00 USD with Paypal.
Paypal recommends to withdraw
it now.

Clare

11th March 2017

Clare just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Marsha

11th March 2017

Marsha just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

service@apple.com

11th March 2017

URGENT! Your Apple ID (
howiem@bigfoot.com ) was used
to sign in to iCloud

Vulnerebility

Symantec Endpoint Protection CVE-2016-9094 Local Command Injection Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96298

Symantec Endpoint Protection Client CVE-2016-9093 Local Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96294

Google Pixel Qualcomm Bootloader CVE-2017-0455 Information Disclosure Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96812

Google Android MediaTek Driver CVE-2017-0529 Information Disclosure Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96810

Google Nexus Kernel Security Subsystem CVE-2017-0528 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96807

Google Android Synaptics Touchscreen Driver CVE-2017-0524 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96808

Google Android NVIDIA GPU Driver CVE-2017-0307 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96809

Google Nexus Qualcomm Power Driver CVE-2016-8483 Information Disclosure Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96805

Google Android Audioserver CVE-2017-0499 Denial of Service Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96806

Google Android MediaTek Hardware Sensor Driver CVE-2017-0517 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96799

Google Nexus Kernel FIQ Debugger CVE-2017-0510 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96800

Google Nexus Qualcomm Crypto Engine Driver CVE-2017-0520 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96804

Google Android MediaTek APK CVE-2017-0522 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96798

Google Nexus Qualcomm Input Hardware Driver CVE-2017-0516 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96802

Google Nexus Qualcomm ADSPRPC Driver CVE-2017-0457 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96803

Google Android Mediaserver CVE-2017-0495 Information Disclosure Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96796

Google Nexus Qualcomm GPU Driver CVE-2016-8479 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96801

Google Android Broadcom Wi-Fi Driver CVE-2017-0509 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96797

Google Android Mediaserver CVE-2017-0497 Denial of Service Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96795

Google Android AOSP Messaging CVE-2017-0494 Information Disclosure Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96789

Google Android Setup Wizard CVE-2017-0498 Denial of Service Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96793

Google Android System UI CVE-2017-0492 Remote Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96794

Google Android Location Manager CVE-2017-0489 Remote Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96792

Google Android Package Manager CVE-2017-0491 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96791

Google Android Wi-Fi CVE-2017-0490 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96790

Google Android Setup Wizard CVE-2017-0496 Denial of Service Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96788

Tiki Wiki CMS CVE-2016-10143 Arbitrary File Disclosure Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96787

R Programming Language CVE-2016-8714 Buffer Overflow Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96785

F-Secure Anti-Virus CVE-2017-6466 Remote Code Execution Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96784

WordPress Mail Masta Plugin Multiple SQL Injection Vulnerabilities
2017-03-12
http://www.securityfocus.com/bid/96783Symantec Endpoint Protection CVE-2016-9094 Local Command Injection Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96298

Symantec Endpoint Protection Client CVE-2016-9093 Local Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96294

Google Pixel Qualcomm Bootloader CVE-2017-0455 Information Disclosure Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96812

Google Android MediaTek Driver CVE-2017-0529 Information Disclosure Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96810

Google Nexus Kernel Security Subsystem CVE-2017-0528 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96807

Google Android Synaptics Touchscreen Driver CVE-2017-0524 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96808

Google Android NVIDIA GPU Driver CVE-2017-0307 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96809

Google Nexus Qualcomm Power Driver CVE-2016-8483 Information Disclosure Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96805

Google Android Audioserver CVE-2017-0499 Denial of Service Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96806

Google Android MediaTek Hardware Sensor Driver CVE-2017-0517 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96799

Google Nexus Kernel FIQ Debugger CVE-2017-0510 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96800

Google Nexus Qualcomm Crypto Engine Driver CVE-2017-0520 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96804

Google Android MediaTek APK CVE-2017-0522 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96798

Google Nexus Qualcomm Input Hardware Driver CVE-2017-0516 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96802

Google Nexus Qualcomm ADSPRPC Driver CVE-2017-0457 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96803

Google Android Mediaserver CVE-2017-0495 Information Disclosure Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96796

Google Nexus Qualcomm GPU Driver CVE-2016-8479 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96801

Google Android Broadcom Wi-Fi Driver CVE-2017-0509 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96797

Google Android Mediaserver CVE-2017-0497 Denial of Service Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96795

Google Android AOSP Messaging CVE-2017-0494 Information Disclosure Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96789

Google Android Setup Wizard CVE-2017-0498 Denial of Service Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96793

Google Android System UI CVE-2017-0492 Remote Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96794

Google Android Location Manager CVE-2017-0489 Remote Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96792

Google Android Package Manager CVE-2017-0491 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96791

Google Android Wi-Fi CVE-2017-0490 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96790

Google Android Setup Wizard CVE-2017-0496 Denial of Service Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96788

Tiki Wiki CMS CVE-2016-10143 Arbitrary File Disclosure Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96787

R Programming Language CVE-2016-8714 Buffer Overflow Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96785

F-Secure Anti-Virus CVE-2017-6466 Remote Code Execution Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96784

WordPress Mail Masta Plugin Multiple SQL Injection Vulnerabilities
2017-03-11
http://www.securityfocus.com/bid/96783

SANS News

What's On Your Not To Do List?

Threatpost

 

Exploit

Windows x86 - Hide Console Window Shellcode (182 bytes)

Domain Marketplace Script - SQL Injection

Global In - SQL Injection

Global In - Arbitrary File Upload

Pet Listing Script 3.0 - SQL Injection

10.3.2017

Bugtraq

CVE-2016-10143: Vulnerability to read arbitrary files in "Tiki Wiki" 2017-03-10
Leon Zhao 7 gmail com

[SECURITY] [DSA 3805-1] firefox-esr security update 2017-03-09
Moritz Muehlenhoff (jmm debian org)

[security bulletin] HPESBHF03714 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Local Arbitrary File Download 2017-03-08
security-alert hpe com

[SECURITY] [DSA 3804-1] linux security update 2017-03-08
Salvatore Bonaccorso (carnil debian org)

[security bulletin] HPESBHF03713 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Deserialization of Untrusted Data, Remote Code Execution 2017-03-08
security-alert hpe com

Malware

 

Phishing

Lorrie

10th March 2017

Lorrie just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Bank of America

10th March 2017

Bank of America Alert: Your
Online Access is Temporarily
Locked

Mrs.Helen Smith Shabangu

9th March 2017

PICK UP YOUR FIRST PAYMENT OF
$4,500 USD IN MONEY GRAM

Westpac Bank

9th March 2017

Online Verification

Vulnerebility

Google Android Package Manager CVE-2017-0491 Privilege Escalation Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96791

Google Android Wi-Fi CVE-2017-0490 Privilege Escalation Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96790

Google Android Setup Wizard CVE-2017-0496 Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96788

Tiki Wiki CMS CVE-2016-10143 Arbitrary File Disclosure Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96787

R Programming Language CVE-2016-8714 Buffer Overflow Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96785

F-Secure Anti-Virus CVE-2017-6466 Remote Code Execution Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96784

WordPress Mail Masta Plugin Multiple SQL Injection Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96783

WordPress DTracker Plugin Multiple SQL Injection Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96781

Multiple Cloud Foundry Products CVE-2017-4960 Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96780

Unisys ClearPath MCP CVE-2017-5872 Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96782

gdk-pixbuf Integer Overflow and Denial of Service Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96779

Multiple KDE Products Products Information Disclosure Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96515

LXC 'lxc/lxc_user_nic.c' Remote Privilege Escalation Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96777

ImageMagick CVE-2017-6502 Local Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96763

Linux Kernel 'x86/mm/gup.c' Local Security Bypass Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96776

Pidgin CVE 2017-2640 Out of Bounds Write Security Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96775

HP LoadRunner and Performance Center CVE-2017-5789 Remote Heap Buffer Overflow Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96774

libarchive 'archive_write_set_format_iso9660.c' Integer Overflow Vulnerability
2017-03-10
http://www.securityfocus.com/bid/92036

libarchive Multiple Security Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/93781

libarchive 'lha_read_file_header_1()' Function Memory Corruption Vulnerability
2017-03-10
http://www.securityfocus.com/bid/95837

libarchive CVE-2016-7166 Denial Of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/92901

libarchive CVE-2016-5418 Arbitrary File Write Vulnerability
2017-03-10
http://www.securityfocus.com/bid/93165

Multiple VMware Workstation Products CVE-2017-4900 Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96770

HP Intelligent Management Center CVE-2017-5795 Arbitrary File Download Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96773

Mozilla Firefox and Thunderbird CVE-2017-5401 Memory Corruption Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96677

Multiple VMware Workstation Products CVE-2017-4898 DLL Loading Remote Code Execution Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96772

Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96664

Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96654

Mozilla Firefox and Thunderbird Multiple Security Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96693

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96651Multiple Cloud Foundry Products CVE-2017-4960 Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96780

Unisys ClearPath MCP CVE-2017-5872 Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96782

gdk-pixbuf Integer Overflow and Denial of Service Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96779

Multiple KDE Products Products Information Disclosure Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96515

LXC 'lxc/lxc_user_nic.c' Remote Privilege Escalation Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96777

ImageMagick CVE-2017-6502 Local Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96763

Linux Kernel 'x86/mm/gup.c' Local Security Bypass Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96776

Pidgin CVE 2017-2640 Out of Bounds Write Security Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96775

HP LoadRunner and Performance Center CVE-2017-5789 Remote Heap Buffer Overflow Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96774

libarchive 'archive_write_set_format_iso9660.c' Integer Overflow Vulnerability
2017-03-10
http://www.securityfocus.com/bid/92036

libarchive Multiple Security Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/93781

libarchive 'lha_read_file_header_1()' Function Memory Corruption Vulnerability
2017-03-10
http://www.securityfocus.com/bid/95837

libarchive CVE-2016-7166 Denial Of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/92901

libarchive CVE-2016-5418 Arbitrary File Write Vulnerability
2017-03-10
http://www.securityfocus.com/bid/93165

Multiple VMware Workstation Products CVE-2017-4900 Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96770

HP Intelligent Management Center CVE-2017-5795 Arbitrary File Download Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96773

Mozilla Firefox and Thunderbird CVE-2017-5401 Memory Corruption Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96677

Multiple VMware Workstation Products CVE-2017-4898 DLL Loading Remote Code Execution Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96772

Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96664

Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96654

Mozilla Firefox and Thunderbird Multiple Security Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96693

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96651

Multiple VMware Workstation Products CVE-2017-4899 Out of Bound Read Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96771

HP Intelligent Management Center CVE-2017-5792 Remote Code Execution Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96769

Schneider Electric ClearSCADA CVE-2017-6021 Remote Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96768

Google Chrome Prior to 57.0.2987.98 Multiple Security Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96767

IBM Tivoli System Automation for Multiplatforms Local Privilege Escalation Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96764

IBM Content Navigator CVE-2017-1146 Cross Site Scripting Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96761

Google Android Framesequence Library CVE-2017-0478 Remote Code Execution Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96762

Google Android libgdx CVE-2017-0477 Remote Code Execution Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96760Schneider Electric ClearSCADA CVE-2017-6021 Remote Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96768

Google Chrome Prior to 57.0.2987.98 Multiple Security Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96767

IBM Tivoli System Automation for Multiplatforms Local Privilege Escalation Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96764

IBM Content Navigator CVE-2017-1146 Cross Site Scripting Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96761

Google Android Framesequence Library CVE-2017-0478 Remote Code Execution Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96762

Google Android libgdx CVE-2017-0477 Remote Code Execution Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96760

qBittorrent CVE-2017-6503 Cross Site Scripting Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96758

Linux Kernel CVE-2017-5669 Local Security Bypass Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96754

IBM WebSphere MQ CVE-2017-1145 Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96759

IBM UrbanCode Deploy CVE-2016-9006 Multiple Cross Site Scripting Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96757

Google Android AOSP Messaging CVE-2017-0476 Memory Corruption Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96756

libevent Multiple Security Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96014

HP Intelligent Management Center CVE-2017-5790 Remote Code Execution Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96755

wuhu CVE-2017-6544 Cross Site Scripting Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96751

Multiple D-Link Routers CVE-2017-3193 Stack Buffer Overflow Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96747

Linux Kernel CVE-2017-2636 Local Privilege Escalation Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96732

Linux kernel CVE-2017-6345 Local Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96510

Linux kernel CVE-2017-6346 Use After Free Local Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96508

Linux Kernel CVE-2017-6353 Incomplete Fix Local Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96473

Linux Kernel CVE-2017-6348 Local Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96483

Linux Kernel CVE-2017-6214 Remote Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96421

Linux Kernel 'net/sctp/socket.c' Local Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96222

Linux Kernel 'arch/x86/kvm/vmx.c' Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/94933

Nessus Arbitrary File Upload Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96418

Pharos PopUp Printer Client Multiple Heap Based Buffer Overflow Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96742

IBM Jazz Reporting Service CVE-2015-7464 Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96750

HP Operations Manager CVE-2016-1985 Remote Code Execution Vulnerability
2017-03-10
http://www.securityfocus.com/bid/82259

Google Android Qualcomm Wi-Fi Driver Multiple Information Disclosure Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96743

Google Android Qualcomm Camera Driver Multiple Information Disclosure Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96749

Oracle Java SE and JRockit CVE-2017-3252 Remote Security Vulnerability
2017-03-10
http://www.securityfocus.com/bid/95509

SANS News

The Side Effect of GeoIP Filters

Threatpost

Google Chrome 57 Browser Update Patches ‘High’ Severity Flaws

Hundreds of Thousands of Vulnerable IP Cameras Easy Target for Botnet, Researcher Says

Zero Days Have Staying Power

Privilege Escalation Flaw Patched in Schneider Wonderware

Exploit

ASUSWRT RT-AC53 (3.0.0.4.380.6038) - Cross-Site Scripting

ASUSWRT RT-AC53 (3.0.0.4.380.6038) - Session Stealing

ASUSWRT RT-AC53 (3.0.0.4.380.6038) - Remote Code Execution

FTP Voyager Scheduler 16.2.0 - Cross-Site Request Forgery

Country on Sale Script - SQL Injection

Media Search Engine Script - 'search' Parameter SQL Injection

Soundify 1.1 - 'tid' Parameter SQL Injection

9.3.2017

Bugtraq

[security bulletin] HPESBHF03714 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Local Arbitrary File Download 2017-03-08
security-alert hpe com

[SECURITY] [DSA 3804-1] linux security update 2017-03-08
Salvatore Bonaccorso (carnil debian org)

[security bulletin] HPESBHF03713 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Deserialization of Untrusted Data, Remote Code Execution 2017-03-08
security-alert hpe com

[security bulletin] HPESBGN03712 rev.1 - HPE LoadRunner and Performance Center, Remote Code Execution 2017-03-08
security-alert hpe com

SEC Consult SA-20170308-0 :: Multiple vulnerabilities in Navetti PricePoint 2017-03-08
SEC Consult Vulnerability Lab (research sec-consult com)

[slackware-security] mozilla-firefox (SSA:2017-066-01) 2017-03-08
Slackware Security Team (security slackware com)

Malware

Misleading:Win32/Vigorf.A

Trojan.Stonedrill

Trojan.Powire

Phishing

Westpac Bank

9th March 2017

Online Verification

Online® ID Team

8th March 2017

Mail Suspended!

Support

8th March 2017

UPDATE YOUR ACCOUNT
INFORMATION

Farah

7th March 2017

Farah just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Vulnerebility

Google Android AOSP Messaging CVE-2017-0476 Memory Corruption Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96756

libevent Multiple Security Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96014

HP Intelligent Management Center CVE-2017-5790 Remote Code Execution Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96755

wuhu CVE-2017-6544 Cross Site Scripting Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96751

Multiple D-Link Routers CVE-2017-3193 Stack Buffer Overflow Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96747

Linux Kernel CVE-2017-2636 Local Privilege Escalation Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96732

Linux kernel CVE-2017-6345 Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96510

Linux kernel CVE-2017-6346 Use After Free Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96508

Linux Kernel CVE-2017-6353 Incomplete Fix Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96473

Linux Kernel CVE-2017-6348 Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96483

Linux Kernel CVE-2017-6214 Remote Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96421

Linux Kernel 'net/sctp/socket.c' Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96222

Linux Kernel 'arch/x86/kvm/vmx.c' Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/94933

Nessus Arbitrary File Upload Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96418

Pharos PopUp Printer Client Multiple Heap Based Buffer Overflow Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96742

IBM Jazz Reporting Service CVE-2015-7464 Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96750

HP Operations Manager CVE-2016-1985 Remote Code Execution Vulnerability
2017-03-09
http://www.securityfocus.com/bid/82259

Google Android Qualcomm Wi-Fi Driver Multiple Information Disclosure Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96743

Google Android Qualcomm Camera Driver Multiple Information Disclosure Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96749

Oracle Java SE and JRockit CVE-2017-3252 Remote Security Vulnerability
2017-03-09
http://www.securityfocus.com/bid/95509

Pharos PopUp Printer Client CVE-2017-2787 Heap Based Buffer Overflow Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96738

Drupal Services Module Remote Code Execution Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96744

Drupal Password Reset Landing Page Module Access Bypass Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96739

Netpbm CVE-2017-2587 Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96702

Netpbm CVE-2017-2586 Null Pointer Dereference Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96708

Netpbm CVE-2017-2579 Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96714

Netpbm CVE-2017-2581 Local Integer Overflow Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96710

Netpbm CVE-2017-2580 Local Heap Buffer Overflow Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96712

Pharos PopUp Printer Client CVE-2017-2786 Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96736

Oracle Java SE CVE-2017-3259 Remote Security Vulnerability
2017-03-09
http://www.securityfocus.com/bid/95570Google Android NVIDIA GPU Driver Multiple Privilege Escalation Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96723

Google Android MediaTek Components Multiple Privilege Escalation Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96726

Schneider Electric Wonderware Intelligence Default Credentials Security Bypass Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96721

Flash Seats for iOS CVE-2017-3190 SSL Certificate Validation Security Bypass Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96719

Google Android Recovery Verifier CVE-2017-0475 Privilege Escalation Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96716

ACTi Cameras Models Multiple Security Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96720

PHP FormMail Generator Cross Site Scripting and Arbitrary File Upload Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96718

OpenSSL 'BN_bn2dec()' Function Out of Bounds Write Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/92557

Google Android Mediaserver Multiple Remote Code Execution Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96717

Netpbm CVE-2017-2579 Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96714

Netpbm CVE-2017-2581 Local Integer Overflow Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96710

Netpbm CVE-2017-2580 Local Heap Buffer Overflow Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96712

Netpbm CVE-2017-2586 Null Pointer Dereference Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96708

Netpbm CVE-2017-2587 Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96702

Mozilla Firefox CVE-2017-5409 Arbitrary File Deletion Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96696

Mozilla Firefox and Thunderbird Multiple Security Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96693

Mozilla Firefox CVE-2017-5426 Security Bypass Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96694

Mozilla Firefox MFSA 2017-05 Multiple Security Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96692

Mozilla Firefox CVE-2017-5403 Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96691

Mozilla Firefox and Thunderbird CVE-2017-5401 Memory Corruption Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96677

Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96664

Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96654

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96651

BlackBerry Good Control Server CVE-2016-3127 Information Disclosure Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96629

IBM WebSphere Commerce CVE-2016-5894 Local Information Disclosure Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96624

Multiple IBM DB2 Products CVE-2017-1150 Information Disclosure Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96597

Multiple I-O DATA Network Camera Products Multiple Security Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96620

CloudFlare Information Disclosure Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96617

Access CX App CVE-2017-2110 SSL Certificate Validation Security Bypass Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96615

OneThird CMS CVE-2017-2123 Cross Site Scripting Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96613

SANS News

Critical Apache Struts 2 Vulnerability (Patch Now!)

Threatpost

Firefox 52 Expands Non-Secure HTTP Warnings, Enables SHA-1 Deprecation

Confide Updates App After Critical Security Issues Are Raised

Senator Demands Answers About CloudPets Breach

Attacks Heating Up Against Apache Struts 2 Vulnerability

Exploit

Country on Sale Script - SQL Injection

Media Search Engine Script - 'search' Parameter SQL Injection

Soundify 1.1 - 'tid' Parameter SQL Injection

BistroStays 3.0 - 'guests' Parameter SQL Injection

Nlance 2.2 - SQL Injection

Busewe 1.2 - SQL Injection

Fashmark 1.2 - 'category' Parameter SQL Injection

8.3.2017

Bugtraq

[security bulletin] HPESBHF03713 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Deserialization of Untrusted Data, Remote Code Execution 2017-03-08
security-alert hpe com

[security bulletin] HPESBGN03712 rev.1 - HPE LoadRunner and Performance Center, Remote Code Execution 2017-03-08
security-alert hpe com

SEC Consult SA-20170308-0 :: Multiple vulnerabilities in Navetti PricePoint 2017-03-08
SEC Consult Vulnerability Lab (research sec-consult com)

[slackware-security] mozilla-firefox (SSA:2017-066-01) 2017-03-08
Slackware Security Team (security slackware com)

Multiple vulnerabilities found in Wireless IP Camera (P2P) WIFICAM cameras and vulnerabilities in GoAhead 2017-03-08
Pierre Kim (pierre kim sec gmail com)

[security bulletin] HPESBHF03710 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Multiple Remote Vulnerabilities 2017-03-07
security-alert hpe com

Stack-based buffer overflow in Western Digital My Cloud allows for remote code execution 2017-03-07
Securify B.V. (lists securify nl)

SEC Consult SA-20170307-0 :: Unauthenticated OS command injection & arbitrary file upload in Western Digital WD My Cloud 2017-03-07
SEC Consult Vulnerability Lab (research sec-consult com)

Malware

 

Phishing

Farah

7th March 2017

Farah just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Audrina

7th March 2017

Audrina just sent you
$3,182.00 USD with Paypal.
Paypal recommends to withdraw
it now.

Vulnerebility

Mozilla Firefox MFSA 2017-05 Multiple Security Vulnerabilities
2017-03-08
http://www.securityfocus.com/bid/96692

Mozilla Firefox CVE-2017-5403 Denial of Service Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96691

Mozilla Firefox and Thunderbird CVE-2017-5401 Memory Corruption Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96677

Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-03-08
http://www.securityfocus.com/bid/96664

Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-03-08
http://www.securityfocus.com/bid/96654

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-03-08
http://www.securityfocus.com/bid/96651

BlackBerry Good Control Server CVE-2016-3127 Information Disclosure Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96629

IBM WebSphere Commerce CVE-2016-5894 Local Information Disclosure Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96624

Multiple IBM DB2 Products CVE-2017-1150 Information Disclosure Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96597

Multiple I-O DATA Network Camera Products Multiple Security Vulnerabilities
2017-03-08
http://www.securityfocus.com/bid/96620

CloudFlare Information Disclosure Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96617

Access CX App CVE-2017-2110 SSL Certificate Validation Security Bypass Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96615

OneThird CMS CVE-2017-2123 Cross Site Scripting Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96613

Trend Micro SafeSync for Enterprise Multiple Security Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96612

PrimeDrive Desktop Application Installer DLL Loading Remote Code Execution Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96619

dotCMS VU#168699 Multiple Security Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96616

IBM QRadar SIEM CVE-2016-2880 Local Hardcoded Credentials Information Disclosure Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96614

QEMU 'hw/usb/hcd-ohci.c' Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96611

Ansible CVE-2016-9587 Arbitrary Command Execution Vulnerability
2017-03-07
http://www.securityfocus.com/bid/95352

Multiple AlienVault Products Authentication Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93043

WordPress Prior to 4.7.3 Cross Site Request Forgery Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96602

WordPress Prior to 4.7.3 Multiple Cross Site Scripting Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96601

Linux Kernel CVE-2016-9083 Local Integer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93929

Linux Kernel CVE-2016-8655 Local Race Condition Vulnerability
2017-03-07
http://www.securityfocus.com/bid/94692

Linux Kernel 'kvm/emulate.c' Null Pointer Dereference Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/94459

Linux Kernel Vfio Driver CVE-2016-9084 Integer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93930

WordPress Prior to 4.7.3 URL Redirection Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96600

WordPress Prior to 4.7.3 Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96598

Symantec Endpoint Protection CVE-2016-9094 Local Command Injection Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96298

Symantec Endpoint Protection Client CVE-2016-9093 Local Privilege Escalation Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96294
Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-03-08
http://www.securityfocus.com/bid/96664

Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-03-08
http://www.securityfocus.com/bid/96654

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-03-08
http://www.securityfocus.com/bid/96651

BlackBerry Good Control Server CVE-2016-3127 Information Disclosure Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96629

IBM WebSphere Commerce CVE-2016-5894 Local Information Disclosure Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96624

Multiple IBM DB2 Products CVE-2017-1150 Information Disclosure Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96597

Multiple I-O DATA Network Camera Products Multiple Security Vulnerabilities
2017-03-08
http://www.securityfocus.com/bid/96620

CloudFlare Information Disclosure Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96617

Access CX App CVE-2017-2110 SSL Certificate Validation Security Bypass Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96615

OneThird CMS CVE-2017-2123 Cross Site Scripting Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96613

Trend Micro SafeSync for Enterprise Multiple Security Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96612

PrimeDrive Desktop Application Installer DLL Loading Remote Code Execution Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96619

dotCMS VU#168699 Multiple Security Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96616

IBM QRadar SIEM CVE-2016-2880 Local Hardcoded Credentials Information Disclosure Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96614

QEMU 'hw/usb/hcd-ohci.c' Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96611

Ansible CVE-2016-9587 Arbitrary Command Execution Vulnerability
2017-03-07
http://www.securityfocus.com/bid/95352

Multiple AlienVault Products Authentication Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93043

WordPress Prior to 4.7.3 Cross Site Request Forgery Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96602

WordPress Prior to 4.7.3 Multiple Cross Site Scripting Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96601

Linux Kernel CVE-2016-9083 Local Integer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93929

Linux Kernel CVE-2016-8655 Local Race Condition Vulnerability
2017-03-07
http://www.securityfocus.com/bid/94692

Linux Kernel 'kvm/emulate.c' Null Pointer Dereference Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/94459

Linux Kernel Vfio Driver CVE-2016-9084 Integer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93930

WordPress Prior to 4.7.3 URL Redirection Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96600

WordPress Prior to 4.7.3 Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96598

Symantec Endpoint Protection CVE-2016-9094 Local Command Injection Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96298

Symantec Endpoint Protection Client CVE-2016-9093 Local Privilege Escalation Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96294

OpenBSD Man in the Middle Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96596

JasPer 'jpc_dec.c' Null Pointer Dereference Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96595

TeX Live CVE-2016-10243 Remote Code Execution Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96593

SANS News

Not All Malware Samples Are Complex

Threatpost

Dahua Patching Backdoor in DVRs, IP Cameras

Unpatched Western Digital Bugs Leave NAS Boxes Open to Attack

WordPress 4.7.3 Patches Half-Dozen Vulnerabilities

Exploit

USBPcap - Privilege Escalation

Themeforest Clone Script - SQL Injection

Graphicriver Clone Script - SQL Injection

Codecanyon Clone Script - SQL Injection

Audiojungle Clone Script - SQL Injection

Videohive Clone Script - SQL Injection

Azure Data Expert Ultimate 2.2.16 - Buffer Overflow

Themeforest Clone Script - SQL Injection

Graphicriver Clone Script - SQL Injection

Mini CMS 1.1 - 'name' Parameter SQL Injection

Daily Deals Script 1.0 - 'id' Parameter SQL Injection

Bull/IBM AIX Clusterwatch/Watchware - Multiple Vulnerabilities

Evostream Media Server 1.7.1 (x64) - Denial of Service

7.3.2017

Bugtraq

Stack-based buffer overflow in Western Digital My Cloud allows for remote code execution 2017-03-07
Securify B.V. (lists securify nl)

SEC Consult SA-20170307-0 :: Unauthenticated OS command injection & arbitrary file upload in Western Digital WD My Cloud 2017-03-07
SEC Consult Vulnerability Lab (research sec-consult com)

WordPress audio playlist functionality is affected by Cross-Site Scripting 2017-03-06
Summer of Pwnage (lists securify nl)

EasyCom PHP API Stack Buffer Overflow 2017-03-06
apparitionsec gmail securityfocus com (hyp3rlinx)

Sawmill Enterprise v8.7.9 Pass The Hash Authentication Bypass 2017-03-06
apparitionsec gmail securityfocus com (hyp3rlinx)

Malware

W32.Disttrack.C

Phishing

Audrina

7th March 2017

Audrina just sent you
$3,182.00 USD with Paypal.
Paypal recommends to withdraw
it now.

Louise

6th March 2017

Louise just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Lara

6th March 2017

Lara just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Vulnerebility

Linux Kernel Local Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/92659

Linux Kernel 'kernel/process.c' Local Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/91415

Linux Kernel CVE-2016-6480 Local Information Disclosure Vulnerability
2017-03-07
http://www.securityfocus.com/bid/92214

Linux Kernel CVE-2016-6130 Local Information Disclosure Vulnerability
2017-03-07
http://www.securityfocus.com/bid/91540

Linux Kernel 'tcp_xmit_retransmit_queue()' Function Use After Free Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/92452

Linux Kernel 'usbhid/hiddev.c' Local Heap Buffer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/91450

Linux Kernel Multiple Local Memory Corruption Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/91451

Linux kernel 'key_reject_and_link()' Function Local Use After Free Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/91211

Cisco Prime Collaboration Assurance CVE-2017-3844 Information Disclosure Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96247

OpenStack qemu-imge CVE-2015-5162 Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/76849

ISC BIND CVE-2017-3135 Remote Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96150

w3m Multiple Security Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/94407

Cisco Unified Communications Manager CVE-2017-3833 Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96246

Cisco Prime Collaboration Assurance CVE-2017-3845 Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96245

libevent Multiple Security Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96014

Multiple Hughes Satellite Modems VU#614751 Multiple Security Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96244

Adobe Flash Player APSB17-04 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96199

Adobe Flash Player APSB17-04 Multiple Heap Buffer Overflow Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96193

Adobe Flash Player APSB17-04 Multiple Unspecified Memory Corruption Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96190

Adobe Flash Player CVE-2017-2995 Type Confusion Remote Code Execution Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96191

Adobe Flash Player CVE-2017-2987 Unspecified Integer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96194

Cisco Meeting Server CVE-2017-3837 Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96243

Cisco Unified Communications Manager CVE-2017-3821 Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96241

Cisco AsyncOS for Email and Web Security Appliances Remote Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96239

Cisco Meeting Server CVE-2017-3830 Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96242

Cisco Secure Access Control System CVE-2017-3841 Information Disclosure Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96237

Cisco Unified Communications Manager CVE-2017-3828 Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96240

Cisco Secure Access Control System CVE-2017-3840 Open Redirection Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96238

Cisco Secure Access Control System XML External Entity Information Disclosure Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96236

Cisco Secure Access Control System CVE-2017-3838 Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96234Ansible CVE-2016-9587 Arbitrary Command Execution Vulnerability
2017-03-07
http://www.securityfocus.com/bid/95352

Multiple AlienVault Products Authentication Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93043

WordPress Prior to 4.7.3 Multiple Cross Site Scripting Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96601

Linux Kernel CVE-2016-9083 Local Integer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93929

Linux Kernel CVE-2016-8655 Local Race Condition Vulnerability
2017-03-07
http://www.securityfocus.com/bid/94692

Linux Kernel 'kvm/emulate.c' Null Pointer Dereference Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/94459

Linux Kernel Vfio Driver CVE-2016-9084 Integer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93930

WordPress Prior to 4.7.3 URL Redirection Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96600

WordPress Prior to 4.7.3 Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96598

Symantec Endpoint Protection CVE-2016-9094 Local Command Injection Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96298

Symantec Endpoint Protection Client CVE-2016-9093 Local Privilege Escalation Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96294

Multiple IBM DB2 Products CVE-2017-1150 Information Disclosure Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96597

OpenBSD Man in the Middle Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96596

JasPer 'jpc_dec.c' Null Pointer Dereference Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96595

TeX Live CVE-2016-10243 Remote Code Execution Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96593

ImageMagick 'coders/psd.c' Local Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96594

ImageMagick 'coders/sun.c' Local Heap Buffer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96592

FenixHosting fenix-open-source 'forums/search.php' Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96587

ImageMagick CVE-2017-6499 Local Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96590

WePresent WiPG-1500 Device CVE-2017-6351 Hardcoded Password Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96588

ImageMagick CVE-2017-6498 Local Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96591

ImageMagick CVE-2017-6501 Local Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96589

OpenElec CVE-2017-6445 Man in the Middle Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96580

Wireshark LDSS Dissector 'epan/dissectors/packet-ldss.c' Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96577

EPESI CVE-2017-6487 Multiple Cross Site Scripting Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96586

MaNGOSWebV4 CVE-2017-6478 Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96584

Groovel CVE-2017-6480 Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96585

Dotclear CVE-2017-6446 Multiple Cross Site Scripting Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96575

mcollective-puppet-agent CVE-2017-2290 Privilege Escalation Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96583

Ettercap CVE-2017-6430 Out of Bounds Read Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96582

Linux Kernel CVE-2016-9083 Local Integer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93929

Linux Kernel CVE-2016-8655 Local Race Condition Vulnerability
2017-03-07
http://www.securityfocus.com/bid/94692

Linux Kernel 'kvm/emulate.c' Null Pointer Dereference Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/94459

Linux Kernel Vfio Driver CVE-2016-9084 Integer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93930

Symantec Endpoint Protection CVE-2016-9094 Local Command Injection Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96298

Symantec Endpoint Protection Client CVE-2016-9093 Local Privilege Escalation Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96294

Multiple IBM DB2 Products CVE-2017-1150 Information Disclosure Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96597

OpenBSD Man in the Middle Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96596

JasPer 'jpc_dec.c' Null Pointer Dereference Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96595

TeX Live CVE-2016-10243 Remote Code Execution Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96593

ImageMagick 'coders/psd.c' Local Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96594

ImageMagick 'coders/sun.c' Local Heap Buffer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96592

FenixHosting fenix-open-source 'forums/search.php' Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96587

ImageMagick CVE-2017-6499 Local Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96590

WePresent WiPG-1500 Device CVE-2017-6351 Hardcoded Password Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96588

ImageMagick CVE-2017-6498 Local Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96591

ImageMagick CVE-2017-6501 Local Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96589

OpenElec CVE-2017-6445 Man in the Middle Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96580

Wireshark LDSS Dissector 'epan/dissectors/packet-ldss.c' Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96577

EPESI CVE-2017-6487 Multiple Cross Site Scripting Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96586

MaNGOSWebV4 CVE-2017-6478 Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96584

Groovel CVE-2017-6480 Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96585

Dotclear CVE-2017-6446 Multiple Cross Site Scripting Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96575

mcollective-puppet-agent CVE-2017-2290 Privilege Escalation Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96583

Ettercap CVE-2017-6430 Out of Bounds Read Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96582

Irssi CVE-2017-5356 Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96581

ATutor CVE-2017-6483 Multiple Cross Site Scripting Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96578

Tcpreplay 'Tcpcapinfo' Utility CVE-2017-6429 Buffer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96579

OpenEMR CVE-2017-6482 Multiple Cross Site Scripting Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96576

phpipam CVE-2017-6481 Multiple Cross Site Scripting Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96573

SANS News

A very convincing Typosquatting + Social Engineering campaign is targeting Santander corporate customers in Brazil

Threatpost

Spammer’s Leaky Backup Exposes Massive Empire

DOJ Dismisses Playpen Case to Keep Tor Hack Private

Active Defense Bill Raises Concerns Of Potential Consequences

Exploit

Mini CMS 1.1 - 'name' Parameter SQL Injection

Daily Deals Script 1.0 - 'id' Parameter SQL Injection

6.3.2017

Bugtraq

EasyCom PHP API Stack Buffer Overflow 2017-03-06
apparitionsec gmail securityfocus com (hyp3rlinx)

Sawmill Enterprise v8.7.9 Pass The Hash Authentication Bypass 2017-03-06
apparitionsec gmail securityfocus com (hyp3rlinx)

CVE-2016-7955 - Alienvault OSSIM/USM Authentication Bypass 2017-03-06
Peter Lapp (lappsec gmail com)

CVE-2017-6430: Out-of-Bounds Read (DOS) Vulnerability in Ettercap Etterfilter utility 2017-03-06
ddos2me gmail com

OpenElec: Remote Code Execution Vulnerability through Man-In-The-Middle(CVE-2017-6445) 2017-03-06
Wolfgang (lister feedyourhead at)

CVE-2017-6429: Buffer overflow vulnerability in Tcpreplay tcpcapinfo utility 2017-03-06
ddos2me gmail com

EasyCom SQL iPlug Denial Of Service 2017-03-04
apparitionsec gmail com (hyp3rlinx)

Malware

 

Phishing

support

6th March 2017

your account will be limited
please update your information

CableTV

6th March 2017

Get more channels than ever
before with cable.

Katharine

5th March 2017

Katharine just sent you
$3,182.00 USD with Paypal.
Paypal recommends to withdraw
it now.

Vulnerebility

EPESI CVE-2017-6487 Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96586

MaNGOSWebV4 CVE-2017-6478 Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96584

Groovel CVE-2017-6480 Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96585

Dotclear CVE-2017-6446 Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96575

mcollective-puppet-agent CVE-2017-2290 Privilege Escalation Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96583

Ettercap CVE-2017-6430 Out of Bounds Read Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96582

Irssi CVE-2017-5356 Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96581

ATutor CVE-2017-6483 Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96578

Tcpreplay 'Tcpcapinfo' Utility CVE-2017-6429 Buffer Overflow Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96579

OpenEMR CVE-2017-6482 Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96576

phpipam CVE-2017-6481 Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96573

SilverStripe CMS CVE-2017-5197 Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96572

FTPShell Client CVE-2017-6465 Buffer Overflow Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96570

SysGauge CVE-2017-6416 Buffer Overflow Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96568

Wireshark NetScaler File Parser 'wiretap/netscaler.c' Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96569

Wireshark RTMPT Dissector 'dissectors/packet-rtmpt.c' Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96571

Wireshark 'wiretap/netscaler.c' Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96566

Piwik Remote Code Execution Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96567

Wireshark WSP Dissector 'tcp_graph.c' Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96564

sysPass CVE-2017-5999 Cryptographic Security Bypass Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96562

Wireshark 'k12.c' Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96565

Wireshark IAX2 Dissector 'packet-iax2.c' Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96563

Wireshark Netscaler File Parser 'netscaler.c' Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96561

rubyzip CVE-2017-5946 Directory Traversal Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96445

Linux Kernel CVE-2016-8655 Local Race Condition Vulnerability
2017-03-06
http://www.securityfocus.com/bid/94692

Linux Kernel CVE-2016-9083 Local Integer Overflow Vulnerability
2017-03-06
http://www.securityfocus.com/bid/93929

Linux Kernel Vfio Driver CVE-2016-9084 Integer Overflow Vulnerability
2017-03-06
http://www.securityfocus.com/bid/93930

Linux Kernel 'kvm/emulate.c' Null Pointer Dereference Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/94459

D-Link DSL-2730U CVE-2017-6411 Cross Site Request Forgery Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96560

VMware Horizon DaaS CVE-2017-4897 Security Bypass Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96559Zabbix CVE-2016-10134 SQL Injection Vulnerability
2017-03-06
http://www.securityfocus.com/bid/95423

EPSON TMNet WebConfig CVE-2017-6443 Multiple HTML Injection Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96556

FreeIPA CVE-2017-2590 Multiple Security Bypass Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96557

WordPress fast-image-adder Plugin CVE-2015-1000001 Arbitrary File Upload Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96554

Soruly whatanime.ga CVE-2017-6390 Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96555

Atheme IRC Services CVE-2017-6384 Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96552

FlightAirMap CVE-2017-6397 Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96551

WPO-Foundation WebPageTest CVE-2017-6396 Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96553

Remember Me Module DRUPAL-SA-CONTRIB-2017-025 Unspecified Security Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96546

Ping Identity 'mod_auth_openidc' Module CVE-2017-6413 Authentication Bypass Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96549

Rapid7 Metasploit Pro CVE-2017-5235 DLL Loading Remote Code Execution Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96548

HashOver CVE-2017-6395 Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96550

Rapid7 Insight Collector CVE-2017-5234 DLL Loading Remote Code Execution Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96545

WordPress Mobile App Plugin CVE-2017-6104 Arbitrary File Upload Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96547

Multiple KDE Products Products Information Disclosure Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96515

ImageMagick CVE-2017-6335 Local Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96544

Eaton xComfort Ethernet Communication Interface CVE-2017-9368 Information Disclosure Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96542

IBM Development Package for Apache Spark CVE-2016-4970 Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96540

Schneider Electric Conext ComBox CVE-2017-6019 Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96543

NagVis 'share/userfiles/gadgets/std_table.php' Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96537

Multiple Siemens Products CVE-2017-2685 Man in the Middle Security Bypass Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96519

OpenEMR CVE-2017-6394 Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96539

Multiple IBM Products CVE-2017-1124 Local Information Disclosure Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96536

QEMU '/src/card_7816.c' Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96541

w3m Multiple Security Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/94407

w3m Multiple Security Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/94464

WordPress AnyVar Plugin CVE-2017-6103 Multiple HTML Injection Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96532

IBM QRadar SIEM CVE-2016-9729 Authentication Bypass Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96538

WordPress rockhoist-badges Plugin CVE-2017-6102 HTML Injection Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96533

Kaltura server Lynx Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96534WordPress fast-image-adder Plugin CVE-2015-1000001 Arbitrary File Upload Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96554

Soruly whatanime.ga CVE-2017-6390 Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96555

Atheme IRC Services CVE-2017-6384 Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96552

FlightAirMap CVE-2017-6397 Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96551

WPO-Foundation WebPageTest CVE-2017-6396 Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96553

Remember Me Module DRUPAL-SA-CONTRIB-2017-025 Unspecified Security Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96546

Ping Identity 'mod_auth_openidc' Module CVE-2017-6413 Authentication Bypass Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96549

Rapid7 Metasploit Pro CVE-2017-5235 DLL Loading Remote Code Execution Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96548

HashOver CVE-2017-6395 Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96550

Rapid7 Insight Collector CVE-2017-5234 DLL Loading Remote Code Execution Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96545

WordPress Mobile App Plugin CVE-2017-6104 Arbitrary File Upload Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96547

Multiple KDE Products Products Information Disclosure Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96515

ImageMagick CVE-2017-6335 Local Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96544

Eaton xComfort Ethernet Communication Interface CVE-2017-9368 Information Disclosure Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96542

IBM Development Package for Apache Spark CVE-2016-4970 Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96540

Schneider Electric Conext ComBox CVE-2017-6019 Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96543

NagVis 'share/userfiles/gadgets/std_table.php' Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96537

Multiple Siemens Products CVE-2017-2685 Man in the Middle Security Bypass Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96519

OpenEMR CVE-2017-6394 Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96539

Multiple IBM Products CVE-2017-1124 Local Information Disclosure Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96536

QEMU '/src/card_7816.c' Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96541

w3m Multiple Security Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/94407

w3m Multiple Security Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/94464

WordPress AnyVar Plugin CVE-2017-6103 Multiple HTML Injection Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96532

IBM QRadar SIEM CVE-2016-9729 Authentication Bypass Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96538

WordPress rockhoist-badges Plugin CVE-2017-6102 HTML Injection Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96533

Kaltura server Lynx Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96534

IBM QRadar SIEM CVE-2016-9740 Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96535

IBM QRadar SIEM CVE-2016-9725 Information Disclosure Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96530

IBM QRadar SIEM and Incident Forensics CVE-2016-9720 Information Disclosure Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96531

SANS News

Another example of maldoc string obfuscation, with extra bonus: UAC bypass

A very convincing Typosquatting + Social Engineering campaign is targeting Santander corporate customers in Brazil

Threatpost

Bruce Schneier on IoT Regulation

Exploit

Conext ComBox 865-1058 - Denial of Service

CyberGhost 6.0.4.2205 - Privilege Escalation

FTPShell Client 6.53 - Buffer Overflow

Advanced Bus Booking Script 2.04 - SQL Injection

Entrepreneur Bus Booking Script 3.03 - 'hid_Busid' Parameter SQL Injection

Single Theater Booking Script - 'newsid' Parameter SQL Injection

Responsive Events & Movie Ticket Booking Script - SQL Injection

Online Cinema and Event Booking Script 2.01 - 'newsid' Parameter SQL Injection

Redbus Clone Script 3.05 - 'hid_Busid' Parameter SQL Injection

Groupon Clone Script 3.01 - 'catid' Parameter SQL Injection

Naukri Clone Script 3.02 - 'type' Parameter SQL Injection

Yellow Pages Clone Script 1.3.4 - SQL Injection

Advanced Matrimonial Script 2.0.3 - SQL Injection

Advanced Real Estate Script 4.0.6 - SQL Injection

PHP Classifieds Rental Script 3.6.0 - 'scatid' Parameter SQL Injection

Entrepreneur B2B Script 2.0.4 - 'id' Parameter SQL Injection

PHP Matrimonial Script 3.0 - SQL Injection

MLM Binary Plan Script 2.0.5 - SQL Injection

MLM Forced Matrix 2.0.7 - SQL Injection

MLM Forex Market Plan Script 2.0.1 - SQL Injection

MLM Membership Plan Script 2.0.5 - SQL Injection

Multireligion Responsive Matrimonial Script 4.7.1 - SQL Injection

Network Community Script 3.0.2 - SQL Injection

PHP B2B Script 3.05 - SQL Injection

Responsive Matrimonial Script 4.0.1 - SQL Injection

Schools Alert Management Script 2.01 - 'list_id' Parameter SQL Injection

Select Your College Script 2.01 - SQL Injection

Social Network Script 3.01 - 'id' Parameter SQL Injection

Website Broker Script 3.02 - 'view' Parameter SQL Injection

Linux/x86-64 - Polymorphic Flush IPTables Shellcode (47 bytes)

Linux/x86-64 - NetCat Reverse Shell Shellcode (72 bytes)

Linux/x86-64 - Polymorphic NetCat Reverse Shell Shellcode (106 bytes)

EPSON TMNet WebConfig 1.00 - Cross-Site Scripting

Joomla! Component JUX EventOn 1.0.1 - 'id' Parameter SQL Injection

Joomla! Component Monthly Archive 3.6.4 - 'author_form' Parameter SQL Injection

Joomla! Component AltaUserPoints 1.1 - 'userid' Parameter SQL Injection

Joomla! Component Content ConstructionKit 1.1 - SQL Injection

Joomla! Component AYS Quiz 1.0 - 'id' Parameter SQL Injection

4.3.2017

Bugtraq

 

Malware

SupportScam:JS/TechBrolo
SupportScam:JS/TechBrolo.A

JS/TechBrolo

Backdoor.Oliner

Phishing

auto-confirm-amazon.co.uk

3rd March 2017

Your Amazon.co.uk order
"Online Rental Movies.."

Tesco

3rd March 2017

BAG YOURSELF £300 OF TESCO
VOUCHERS!

Amazon

3rd March 2017

Customer Service: Important
account information

Chase

3rd March 2017

Irregular Activity

Apple Service

2nd March 2017

YOUR RECEIPT FROM APPLE STORE

Paypal inc

2nd March 2017

TEMPORARILY UNABLE TO LOAD
YOUR ACCOUNT

Vulnerebility

Linux Kernel Multiple Information Disclosure Vulnerabilities
2017-03-05
http://www.securityfocus.com/bid/94138

Linux Kernel CVE-2016-9083 Local Integer Overflow Vulnerability
2017-03-05
http://www.securityfocus.com/bid/93929

Broadcom Wifi Driver 'brcmf_cfg80211_start_ap()' Function Stack Buffer Overflow Vulnerability
2017-03-05
http://www.securityfocus.com/bid/93541

Linux Kernel CVE-2016-7042 Local Denial of Service Vulnerability
2017-03-05
http://www.securityfocus.com/bid/93544

Google Android Multiple Kernel Components Multiple Information Disclosure Vulnerabilites
2017-03-05
http://www.securityfocus.com/bid/93326

Linux Kernel Vfio Driver CVE-2016-9084 Integer Overflow Vulnerability
2017-03-05
http://www.securityfocus.com/bid/93930

Linux Kernel SCSI arcmsr Driver CVE-2016-7425 Local Heap Buffer Overflow Vulnerability
2017-03-05
http://www.securityfocus.com/bid/93037

Linux Kernel Local Security Bypass Vulnerability
2017-03-05
http://www.securityfocus.com/bid/92659

Linux Kernel 'kernel/process.c' Local Denial of Service Vulnerability
2017-03-05
http://www.securityfocus.com/bid/91415

Linux Kernel CVE-2016-6480 Local Information Disclosure Vulnerability
2017-03-05
http://www.securityfocus.com/bid/92214

Linux Kernel CVE-2016-6130 Local Information Disclosure Vulnerability
2017-03-05
http://www.securityfocus.com/bid/91540

Linux Kernel 'tcp_xmit_retransmit_queue()' Function Use After Free Denial of Service Vulnerability
2017-03-05
http://www.securityfocus.com/bid/92452

Linux Kernel 'usbhid/hiddev.c' Local Heap Buffer Overflow Vulnerability
2017-03-05
http://www.securityfocus.com/bid/91450

Linux Kernel Multiple Local Memory Corruption Vulnerabilities
2017-03-05
http://www.securityfocus.com/bid/91451

Linux kernel 'key_reject_and_link()' Function Local Use After Free Denial of Service Vulnerability
2017-03-05
http://www.securityfocus.com/bid/91211

Cisco Prime Collaboration Assurance CVE-2017-3844 Information Disclosure Vulnerability
2017-03-05
http://www.securityfocus.com/bid/96247

OpenStack qemu-imge CVE-2015-5162 Security Bypass Vulnerability
2017-03-05
http://www.securityfocus.com/bid/76849

ISC BIND CVE-2017-3135 Remote Denial of Service Vulnerability
2017-03-05
http://www.securityfocus.com/bid/96150

w3m Multiple Security Vulnerabilities
2017-03-05
http://www.securityfocus.com/bid/94407

Cisco Unified Communications Manager CVE-2017-3833 Cross Site Scripting Vulnerability
2017-03-05
http://www.securityfocus.com/bid/96246

Cisco Prime Collaboration Assurance CVE-2017-3845 Cross Site Scripting Vulnerability
2017-03-05
http://www.securityfocus.com/bid/96245

libevent Multiple Security Vulnerabilities
2017-03-05
http://www.securityfocus.com/bid/96014

Multiple Hughes Satellite Modems VU#614751 Multiple Security Vulnerabilities
2017-03-05
http://www.securityfocus.com/bid/96244

Adobe Flash Player APSB17-04 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-03-05
http://www.securityfocus.com/bid/96199

Adobe Flash Player APSB17-04 Multiple Heap Buffer Overflow Vulnerabilities
2017-03-05
http://www.securityfocus.com/bid/96193

Adobe Flash Player APSB17-04 Multiple Unspecified Memory Corruption Vulnerabilities
2017-03-05
http://www.securityfocus.com/bid/96190

Adobe Flash Player CVE-2017-2995 Type Confusion Remote Code Execution Vulnerability
2017-03-05
http://www.securityfocus.com/bid/96191

Adobe Flash Player CVE-2017-2987 Unspecified Integer Overflow Vulnerability
2017-03-05
http://www.securityfocus.com/bid/96194

Cisco Meeting Server CVE-2017-3837 Denial of Service Vulnerability
2017-03-05
http://www.securityfocus.com/bid/96243

Cisco Unified Communications Manager CVE-2017-3821 Cross Site Scripting Vulnerability
2017-03-05
http://www.securityfocus.com/bid/96241Linux Kernel 'net/llc/af_llc.c' Local Information Disclosure Vulnerability
2017-03-04
http://www.securityfocus.com/bid/90015

Linux Kernel CVE-2016-4482 Local Information Disclosure Vulnerability
2017-03-04
http://www.securityfocus.com/bid/90029

Graphviz 'yyerror()' Function Incomplete Fix Stack Buffer Overflow Vulnerability
2017-03-04
http://www.securityfocus.com/bid/64736

Graphviz 'yyerror()' Function Stack Buffer Overflow Vulnerability
2017-03-04
http://www.securityfocus.com/bid/64674

Graphviz 'chkNum()' Function Stack Buffer Overflow Vulnerability
2017-03-04
http://www.securityfocus.com/bid/64737

Lsyncd 'default-rsyncssh.lua' Remote Command Injection Vulnerability
2017-03-04
http://www.securityfocus.com/bid/71179

GnuTLS CVE-2017-5335 Multiple Buffer Overflow Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/95374

GnuTLS CVE-2017-5334 Security Bypass Vulnerability
2017-03-04
http://www.securityfocus.com/bid/95370

GnuTLS CVE-2017-5336 Stack Buffer Overflow Vulnerability
2017-03-04
http://www.securityfocus.com/bid/95377

GnuTLS 'lib/opencdk/read-packet.c' Multiple Heap Buffer Overflow Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/95372

OpenSSL CVE-2016-8610 Denial of Service Vulnerability
2017-03-04
http://www.securityfocus.com/bid/93841

MIT Kerberos KDC CVE-2016-3120 NULL Pointer Dereference Denial Of Service Vulnerability
2017-03-04
http://www.securityfocus.com/bid/92132

util-linux CVE-2016-5011 Local Denial of Service Vulnerability
2017-03-04
http://www.securityfocus.com/bid/91683

MuPDF 'fitz/pixmap.c' Heap Based Buffer Overflow Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96139

OpenSSH CVE-2016-10009 Remote Code Execution Vulnerability
2017-03-04
http://www.securityfocus.com/bid/94968

OpenSSH 'ssh/kex.c' Denial of Service Vulnerability
2017-03-04
http://www.securityfocus.com/bid/93776

OpenSSH CVE-2016-10012 Security Bypass Vulnerability
2017-03-04
http://www.securityfocus.com/bid/94975

S-nail CVE-2017-5899 Local Privilege Escalation Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96138

OpenSSH CVE-2016-10011 Local Information Disclosure Vulnerability
2017-03-04
http://www.securityfocus.com/bid/94977

PostfixAdmin CVE-2017-5930 Session Management Security Bypass Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96142

Tor Browser Launcher CVE-2016-3180 Arbitrary Code Execution Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96140

QEMU 'virtio-crypto.c' Integer Overflow Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96141

Symfony CVE-2016-2403 Authentication Bypass Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96137

GNU Bash CVE-2017-5932 Multiple Arbitrary Code Execution Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/96136

SimpleSAMLphp CVE-2016-3124 Information Disclosure Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96134

GraphicsMagick CVE-2016-7800 Remote Integer Underflow Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96135

Trend Micro Control Manager Multiple Directory Traversal Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/96131

Trend Micro Control Manager Multiple Information Disclosure Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/95972

IBM Security Access Manager Products CVE-2016-3029 Cross Site Request Forgery Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96133

SendQuick Entera and Avera SMS Gateway Appliances Remote Command Injection Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96129WordPress fast-image-adder Plugin CVE-2015-1000001 Arbitrary File Upload Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96554

Soruly whatanime.ga CVE-2017-6390 Cross Site Scripting Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96555

Atheme IRC Services CVE-2017-6384 Denial of Service Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96552

FlightAirMap CVE-2017-6397 Multiple Cross Site Scripting Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/96551

WPO-Foundation WebPageTest CVE-2017-6396 Cross Site Scripting Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96553

Remember Me Module DRUPAL-SA-CONTRIB-2017-025 Unspecified Security Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96546

Ping Identity 'mod_auth_openidc' Module CVE-2017-6413 Authentication Bypass Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96549

Rapid7 Metasploit Pro CVE-2017-5235 DLL Loading Remote Code Execution Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96548

HashOver CVE-2017-6395 Cross Site Scripting Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96550

Rapid7 Insight Collector CVE-2017-5234 DLL Loading Remote Code Execution Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96545

WordPress Mobile App Plugin CVE-2017-6104 Arbitrary File Upload Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96547

Multiple KDE Products Products Information Disclosure Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96515

ImageMagick CVE-2017-6335 Local Denial of Service Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96544

Eaton xComfort Ethernet Communication Interface CVE-2017-9368 Information Disclosure Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96542

IBM Development Package for Apache Spark CVE-2016-4970 Denial of Service Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96540

Schneider Electric Conext ComBox CVE-2017-6019 Denial of Service Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96543

NagVis 'share/userfiles/gadgets/std_table.php' Cross Site Scripting Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96537

Multiple Siemens Products CVE-2017-2685 Man in the Middle Security Bypass Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96519

OpenEMR CVE-2017-6394 Multiple Cross Site Scripting Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/96539

Multiple IBM Products CVE-2017-1124 Local Information Disclosure Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96536

QEMU '/src/card_7816.c' Denial of Service Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96541

w3m Multiple Security Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/94407

w3m Multiple Security Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/94464

WordPress AnyVar Plugin CVE-2017-6103 Multiple HTML Injection Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/96532

IBM QRadar SIEM CVE-2016-9729 Authentication Bypass Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96538

WordPress rockhoist-badges Plugin CVE-2017-6102 HTML Injection Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96533

Kaltura server Lynx Multiple Cross Site Scripting Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/96534

IBM QRadar SIEM CVE-2016-9740 Denial of Service Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96535

IBM QRadar SIEM CVE-2016-9725 Information Disclosure Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96530

IBM QRadar SIEM and Incident Forensics CVE-2016-9720 Information Disclosure Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96531

SANS News

How your pictures may affect your website reputation

Threatpost

New Fileless Attack Using DNS Queries to Carry Out PowerShell Commands

Exploit

Linux/x86-64 - Polymorphic Setuid(0) & Execve(/bin/sh) Shellcode (31 bytes)

Wordpress < 4.7.1 - Username Enumeration

NetGain Enterprise Manager 7.2.562 - 'Ping' Command Injection

Joomla! Component Coupon 3.5 - SQL Injection

pfSense 2.3.2 - Cross-Site Scripting / Cross-Site Request Forgery

3.3.2017

Bugtraq

Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0 2017-03-02
Larry W. Cashdollar (larry0 me com)

[SECURITY] [DSA 3794-2] munin regression update 2017-03-02
Salvatore Bonaccorso (carnil debian org)

Joomla com_publication Component - 'sid' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_news Component - 'id' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_filecabinet Component - 'id' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_frontpage Component - 'Itemid' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Malware

Ransom:Win32/Ergop.A

Trojan.Bachosens

Exp.CVE-2017-0037

Phishing

Chase

3rd March 2017

Irregular Activity

Apple Service

2nd March 2017

YOUR RECEIPT FROM APPLE STORE

Paypal inc

2nd March 2017

TEMPORARILY UNABLE TO LOAD
YOUR ACCOUNT

Shawna

2nd March 2017

Shawna just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Amazon

1st March 2017

ABOUT YOUR ACCOUNT!

Vulnerebility

HashOver CVE-2017-6395 Cross Site Scripting Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96550

Rapid7 Insight Collector CVE-2017-5234 DLL Loading Remote Code Execution Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96545

WordPress Mobile App Plugin CVE-2017-6104 Arbitrary File Upload Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96547

Multiple KDE Products Products Information Disclosure Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96515

ImageMagick CVE-2017-6335 Local Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96544

Eaton xComfort Ethernet Communication Interface CVE-2017-9368 Information Disclosure Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96542

IBM Development Package for Apache Spark CVE-2016-4970 Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96540

Schneider Electric Conext ComBox CVE-2017-6019 Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96543

NagVis 'share/userfiles/gadgets/std_table.php' Cross Site Scripting Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96537

Multiple Siemens Products CVE-2017-2685 Man in the Middle Security Bypass Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96519

OpenEMR CVE-2017-6394 Multiple Cross Site Scripting Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/96539

Multiple IBM Products CVE-2017-1124 Local Information Disclosure Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96536

QEMU '/src/card_7816.c' Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96541

w3m Multiple Security Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/94407

w3m Multiple Security Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/94464

WordPress AnyVar Plugin CVE-2017-6103 Multiple HTML Injection Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/96532

IBM QRadar SIEM CVE-2016-9729 Authentication Bypass Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96538

WordPress rockhoist-badges Plugin CVE-2017-6102 HTML Injection Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96533

Kaltura server Lynx Multiple Cross Site Scripting Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/96534

IBM QRadar SIEM CVE-2016-9740 Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96535

IBM QRadar SIEM CVE-2016-9725 Information Disclosure Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96530

IBM QRadar SIEM and Incident Forensics CVE-2016-9720 Information Disclosure Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96531

Linux kernel CVE-2017-2634 Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96529

Hesiod Security Bypass and Privilege Escalation Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/90952

PHP CVE-2016-7479 Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/95151

PHP CVE-2016-7478 Remote Denial Of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/95150

PHP CVE-2016-7480 Remote Code Execution Vulnerability
2017-03-03
http://www.securityfocus.com/bid/95152

PHP CVE-2016-9138 Remote Code Execution Vulnerability
2017-03-03
http://www.securityfocus.com/bid/95268

PHP CVE-2017-5340 Remote Code Execution Vulnerability
2017-03-03
http://www.securityfocus.com/bid/95371

GNU glibc CVE-2016-10228 Infinite Loop Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96525
Linux Kernel 'tcp_xmit_retransmit_queue()' Function Use After Free Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/92452

Linux Kernel 'usbhid/hiddev.c' Local Heap Buffer Overflow Vulnerability
2017-03-03
http://www.securityfocus.com/bid/91450

Linux Kernel Multiple Local Memory Corruption Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/91451

Linux kernel 'key_reject_and_link()' Function Local Use After Free Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/91211

Cisco Prime Collaboration Assurance CVE-2017-3844 Information Disclosure Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96247

OpenStack qemu-imge CVE-2015-5162 Security Bypass Vulnerability
2017-03-03
http://www.securityfocus.com/bid/76849

ISC BIND CVE-2017-3135 Remote Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96150

w3m Multiple Security Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/94407

Cisco Unified Communications Manager CVE-2017-3833 Cross Site Scripting Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96246

Cisco Prime Collaboration Assurance CVE-2017-3845 Cross Site Scripting Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96245

libevent Multiple Security Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/96014

Multiple Hughes Satellite Modems VU#614751 Multiple Security Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/96244

Adobe Flash Player APSB17-04 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/96199

Adobe Flash Player APSB17-04 Multiple Heap Buffer Overflow Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/96193

Adobe Flash Player APSB17-04 Multiple Unspecified Memory Corruption Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/96190

Adobe Flash Player CVE-2017-2995 Type Confusion Remote Code Execution Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96191

Adobe Flash Player CVE-2017-2987 Unspecified Integer Overflow Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96194

Cisco Meeting Server CVE-2017-3837 Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96243

Cisco Unified Communications Manager CVE-2017-3821 Cross Site Scripting Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96241

Cisco AsyncOS for Email and Web Security Appliances Remote Security Bypass Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96239

Cisco Meeting Server CVE-2017-3830 Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96242

Cisco Secure Access Control System CVE-2017-3841 Information Disclosure Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96237

Cisco Unified Communications Manager CVE-2017-3828 Cross Site Scripting Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96240

Cisco Secure Access Control System CVE-2017-3840 Open Redirection Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96238

Cisco Secure Access Control System XML External Entity Information Disclosure Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96236

Cisco Secure Access Control System CVE-2017-3838 Cross Site Scripting Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96234

Cisco UCS Director CVE-2017-3801 Local Privilege Escalation Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96235

TVer App CVE-2017-2105 SSL Certificate Validation Security Bypass Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96232

Linux kernel 'ip_sockglue.c' Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96233

Apache Brooklyn Cross Site Request Forgery and Multiple Cross Site Scripting Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/96228

SANS News

BitTorrent or Something Else?

Threatpost

Cisco Warns of High Severity Bug in NetFlow Appliance

Howard Schmidt’s Legacy of Service Remembered

HackerOne Offers Open Source Projects Free Access to Platform

Exploit

Php Classified OLX Clone Script - 'category' Parameter SQL Injection

Joomla! Component Abstract 2.1 - SQL Injection

Joomla! Component StreetGuessr Game 1.0 - SQL Injection

Joomla! Component Guesser 1.0.4 - 'type' Parameter SQL Injection

Joomla! Component Recipe Manager 2.2 - 'id' Parameter SQL Injection

2.3.2017

Bugtraq

Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0 2017-03-02
Larry W. Cashdollar (larry0 me com)

[SECURITY] [DSA 3794-2] munin regression update 2017-03-02
Salvatore Bonaccorso (carnil debian org)

Joomla com_publication Component - 'sid' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_news Component - 'id' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_filecabinet Component - 'id' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_frontpage Component - 'Itemid' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_phocadownload Component - 'id' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Malware

 

Phishing

Shawna

2nd March 2017

Shawna just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Amazon

1st March 2017

ABOUT YOUR ACCOUNT!

Paypal inc

1st March 2017

TEMPORARILY UNABLE TO LOAD
YOUR ACCOUNT

Vulnerebility

ImageMagick CVE-2016-10062 Security Bypass Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95209

ImageMagick CVE-2016-10144 Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95750

ImageMagick CVE-2016-10145 Local Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95749

Drupal AES encryption Module Security Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96507

podofo CVE-2017-5886 Heap Overflow Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96512

Virglrenderer CVE-2017-6386 Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96506

Multiple Cisco NetFlow Generation Appliances CVE-2017-3826 Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96509

Drupal RESTful Web Services Information Disclosure Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96511

Linux kernel CVE-2017-6345 Local Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96510

Imagemagick CVE-2017-5506 Local Memory Corruption Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95753

ImageMagick CVE-2017-5507 Local Information Disclosure Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95752

ImageMagick CVE-2017-5510 Local Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95755

ImageMagick 'coders/tiff.c' Remote Buffer Overflow Vulnerability
2017-03-02
http://www.securityfocus.com/bid/94727

ImageMagick CVE-2017-5508 Local Heap Buffer Overflow Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95748

ImageMagick CVE-2016-10146 Local Information Disclosure Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95744

ImageMagick CVE-2017-5511 Local Heap Buffer Overflow Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95746

libgd CVE-2016-6906 Buffer Overflow Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96503

OpenStack Swift CVE-2016-9590 Information Disclosure Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95448

Linux kernel CVE-2017-6346 Use After Free Local Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96508

Cisco Prime Infrastructure CVE-2017-3848 Cross Site Scripting Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96505

Veritas NetBackup Server and Client/NetBackup Appliance Authentication Bypass Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96504

TYPO3 Frontend Authentication Bypass Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96501

IBM QRadar Security Information and Event Manager Local Information Disclosure Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96502

Veritas NetBackup Server and Client/ NetBackup Appliance Hardcoded Credentials Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96500

Linux Kernel CVE-2017-2583 Privilege Escalation Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95673

Linux Kernel CVE-2017-2584 Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95430

Linux Kernel CVE-2016-9806 Local Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/94653

Libgd CVE-2016-6912 Security Bypass Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95843

Linux Kernel CVE-2016-7117 Use-After-Free Remote Code Execution Vulnerability
2017-03-02
http://www.securityfocus.com/bid/93304

Veritas NetBackup and NetBackup Appliance Local Insecure File Permissions Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96494TYPO3 Frontend Authentication Bypass Vulnerability
2017-03-28
http://www.securityfocus.com/bid/96501

Veritas NetBackup Server and Client/ NetBackup Appliance Hardcoded Credentials Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96500

Linux Kernel CVE-2017-2583 Privilege Escalation Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95673

Linux Kernel CVE-2017-2584 Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95430

Linux Kernel CVE-2016-9806 Local Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/94653

Libgd CVE-2016-6912 Security Bypass Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95843

Linux Kernel CVE-2016-7117 Use-After-Free Remote Code Execution Vulnerability
2017-03-02
http://www.securityfocus.com/bid/93304

Veritas NetBackup and NetBackup Appliance Local Insecure File Permissions Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96494

Veritas NetBackup Server and Client/ NetBackup Appliance Local Privilege Escalation Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96491

Veritas NetBackup Server and Client/NetBackup Appliance Local Command Execution Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96493

Ghostscript CVE-2013-5653 Multiple Information Disclosure Vulnerabilities
2017-03-02
http://www.securityfocus.com/bid/96497

AirWave Management Platform Multiple Security Vulnerabilities
2017-03-02
http://www.securityfocus.com/bid/96495

Node.js Minimatch Package 'pattern' Parameter Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96496

Linux kernel 'ip_sockglue.c' Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96233

Veritas NetBackup Server and Client/ NetBackup Appliance Arbitrary Command Execution Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96490

Linux Kernel CVE-2017-5577 Remote Buffer Overflow Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95765

Linux kernel 'ip6_gre.c' Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96037

Linux Kernel 'kernel/ptrace.c' Local Privilege Escalation Vulnerability
2017-03-02
http://www.securityfocus.com/bid/79899

Linux Kernel 'net/sctp/socket.c' Local Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96222

Linux Kernel CVE-2017-5576 Integer Overflow Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95767

Linux Kernel CVE-2017-5551 Local Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95717

Veritas NetBackup Server and Client/ NetBackup Appliance Arbitrary Command Execution Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96489

Veritas NetBackup Server and Client/NetBackup Appliance DNS Spoofing Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96488

Veritas NetBackup Server and Client/ NetBackup Appliance Denial-of-Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96485

Linux Kernel CVE-2017-6347 Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96487

Veritas NetBackup Server and Client/NetBackup Appliance Multiple Directory Traversal Vulnerabilities
2017-03-02
http://www.securityfocus.com/bid/96486

QEMU 'ehci_init_transfer()' Function Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/94762

Linux Kernel CVE-2017-6348 Local Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96483

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95999

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-02
http://www.securityfocus.com/bid/94803

SANS News

SSL/TLS on port 389. Say what?

Phishing for Big Money Wire Transfers is Still Alive and Well (or: For Want of Good Punctuation, all was Lost)

Infected Apps in Google Play Store (it's not what you think)

Threatpost

Slack Fixes Cross-Origin Token Theft Bug

CloudPets Notifies California AG of Data Breach

Google reCaptcha Bypass Technique Uses Google’s Own Tools

Yahoo Tells SEC Executives Failed to Act on Breach

Keys for Dharma Ransomware Released

132 Google Play Apps Booted For Malicious IFrames

Exploit

Php Classified OLX Clone Script - 'category' Parameter SQL Injection

DLink DSL-2730U Wireless N 150 - Cross-Site Request Forgery

Aruba AirWave 8.2.3 - XML External Entity Injection / Cross-Site Scripting

WordPress Plugin Contact Form Manager - Cross-Site Request Forgery / Cross-Site Scripting

WordPress Plugin User Login Log 2.2.1 - Cross-Site Scripting

WordPress Plugin Popup by Supsystic 1.7.6 - Cross-Site Request Forgery

WordPress Plugin Global Content Blocks 2.1.5 - Cross-Site Request Forgery

WordPress Plugin File Manager 3.0.1 - Cross-Site Request Forgery

SchoolDir - SQL Injection

Rage Faces Script 1.3 - SQL Injection

Meme Maker Script 2.1 - 'user' Parameter SQL Injection

WordPress Plugin NewStatPress 1.2.4 - Cross-Site Scripting

SysGauge 1.5.18 - Buffer Overflow

WePresent WiPG-1500 - Backdoor Account

Windows x86 - Reverse TCP Staged Alphanumeric Shellcode (332 Bytes)

1.3.2017

Bugtraq

Joomla com_publication Component - 'sid' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_news Component - 'id' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_filecabinet Component - 'id' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_frontpage Component - 'Itemid' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_phocadownload Component - 'id' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

[SECURITY] [DSA 3798-1] tnef security update 2017-03-01
Sebastien Delafond (seb debian org)

Joomla com_jdownloads Component - 'cid' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_webgrouper Component - 'Itemid' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Stored Cross-Site Scripting vulnerability in Contact Form WordPress Plugin 2017-03-01
Summer of Pwnage (lists securify nl)

Cross-Site Request Forgery & Cross-Site Scripting in Contact Form Manager WordPress Plugin 2017-03-01
Summer of Pwnage (lists securify nl)

Stored Cross-Site Scripting vulnerability in User Login Log WordPress Plugin 2017-03-01
Summer of Pwnage (lists securify nl)

Cross-Site Scripting in Magic Fields 1 WordPress Plugin 2017-03-01
Summer of Pwnage (lists securify nl)

Cross-Site Request Forgery in Atahualpa WordPress Theme 2017-03-01
Summer of Pwnage (lists securify nl)

Gwolle Guestbook mass action vulnerable for Cross-Site Request Forgery 2017-03-01
Summer of Pwnage (lists securify nl)

Cross-Site Request Forgery in WordPress Download Manager Plugin 2017-03-01
Summer of Pwnage (lists securify nl)

Persistent Cross-Site Scripting in the WordPress NewStatPress plugin 2017-03-01
Summer of Pwnage (lists securify nl)

Cross-Site Scripting vulnerability in Gwolle Guestbook WordPress Plugin 2017-03-01
Summer of Pwnage (lists securify nl)

Cross-Site Request Forgery in Global Content Blocks WordPress Plugin 2017-03-01
Summer of Pwnage (lists securify nl)

Cross-Site Request Forgery in File Manager WordPress plugin 2017-03-01
Summer of Pwnage (lists securify nl)

Admin Custom Login WordPress plugin custom login page affected by persistent Cross-Site Scripting 2017-03-01
Summer of Pwnage (lists securify nl)

Admin Custom Login WordPress plugin affected by persistent Cross-Site Scripting via Logo URL field 2017-03-01
Summer of Pwnage (lists securify nl)

Analytics Stats Counter Statistics WordPress Plugin unauthenticated PHP Object injection vulnerability 2017-03-01
Summer of Pwnage (lists securify nl)

Malware

Trojan:Win32/Fuery.B!cl

Trojan:Win32/Rundas.A
Ransom:Win32/Lamdelim.A

Phishing

PayPal Notice

1st March 2017

[Security] Please check the
information associated with
your account

KohlsGiftCards

28th February 2017

Hi (Customer ID: birdwell269)
$50_KOHLs-Gift-card expires
soon, ClaimNow

Capital One

28th February 2017

Capital One: Update Your
Account

CHASE BANK

28th February 2017

Verify Your Chase Account
Information
 

Vulnerebility

Veritas NetBackup Server and Client/NetBackup Appliance Multiple Directory Traversal Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/96486

QEMU 'ehci_init_transfer()' Function Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/94762

Linux Kernel CVE-2017-6348 Local Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96483

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/95999

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/94803

QEMU 'hw/usb/hcd-xhci.c' Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96220

QEMU 'hw/net/eepro100.c' Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/93957

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96112

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-01
http://www.securityfocus.com/bid/95990

QEMU CVE-2017-5579 Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/95780

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96378

QEMU '/hw/usb/redirect.c' Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/94759

QEMU '/hw/net/mcf_fec.c' Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/94638

QEMU 'cirrus_vga.c' Security Bypass Vulnerability
2017-03-01
http://www.securityfocus.com/bid/71477

Siemens RUGGEDCOM NMS CVE-2017-2682 Cross Site Request Forgery Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96458

Siemens RUGGEDCOM NMS CVE-2017-2683 HTML Injection Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96455

Veritas NetBackup Server and Client/ NetBackup Appliance Arbitrary Command Execution Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96484

Multiple Intel Products CVE-2017-5682 Local Privilege Escalation Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96482

MuPDF 'pdf-object.c' Use After Free Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/93127

Artifex MuPDF CVE-2017-5991 Null Pointer Dereference Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96213

MuPDF 'fitz/pixmap.c' Heap Based Buffer Overflow Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96139

X.org X Server Local Multiple Security Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/96480

libgd Multiple Security Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/95869

libgd 'gdImageCreate()' Function Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/95841

PHP 'src/gd.c' Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/94865

Kodi Chorus2 CVE-2017-5982 Directory Traversal Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96481

tnef Multiple Integer Overflow, Type Confusion and Out of Bounds Write Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/96427

TYPO3 CMS Unspecified Multiple Cross Site Scripting Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/96479

Red Hat CloudForms Management Engine CVE-2017-2632 Privilege Escalation Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96478

D-link DI-524 CVE-2017-5633 Multiple Cross Site Request Forgery Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/96475tnef Multiple Integer Overflow, Type Confusion and Out of Bounds Write Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/96427

D-link DI-524 CVE-2017-5633 Multiple Cross Site Request Forgery Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/96475

Sage XRT Treasury CVE-2017-3183 SQL Injection Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96477

Amazon Kindle Setup CVE-2017-6189 DLL Loading Local Code Execution Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96476

Multiple Intel Ethernet Controller CVE-2016-8105 Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96474

Iceni Argus Multiple Security Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/96472

Linux Kernel CVE-2017-6353 Incomplete Fix Local Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96473

Multiple F5 BIG-IP Products CVE-2016-9245 Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96471

Linux Kernel CVE-2017-6074 Local Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96310

Iceni Argus CVE-2016-8715 Remote Code Execution Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96470

Iceni Argus CVE-2016-8389 Remote Integer Overflow Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96469

Iceni Argus CVE-2016-8387 Remote Heap Buffer Overflow Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96468

WBCE CMS Multiple Remote Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/96467

CubeCart CVE-2017-2117 Directory Traversal Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96466

Multiple F5 BIG-IP Products CVE-2016-9256 Privilege Escalation Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96464

McAfee ePolicy Orchestrator CVE-2017-3902 Cross Site Scripting Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96465

NETGEAR DGN2200 CVE-2017-6334 Remote Code Execution Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96463

ESET Endpoint Antivirus CVE-2016-9892 Remote Code Execution Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96462

SAP BusinessObjects Financial Consolidation CVE-2017-6061 Cross Site Scripting Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96461

Linux Kernel CVE-2017-6214 Remote Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96421

Virglrenderer CVE-2017-6355 Integer Overflow Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96460

Multiple ARM Processor CVE-2017-5927 Local Security Bypass Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96459

Dahua Security Multiple Products CVE-2017-6342 Information Disclosure Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96454

Multiple Intel Processor CVE-2017-5925 Local Security Bypass Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96452

Dahua Security Multiple Products CVE-2017-6341 Information Disclosure Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96456

Siemens RUGGEDCOM NMS CVE-2017-2682 Cross Site Request Forgery Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96458

Multiple AMD Processor CVE-2017-5926 Local Security Bypass Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96457

Siemens RUGGEDCOM NMS CVE-2017-2683 HTML Injection Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96455

IBM Connections CVE-2016-5932 Cross Site Scripting Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96453

Virglrenderer CVE-2017-6317 Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96450

SANS News

Amazon S3 Outage

My Catch Of 4 Months In The Amazon IP Address Space

Threatpost

Dridex Trojan Gets A Major ‘AtomBombing’ Update

Siemens RUGGEDCOM NMS Equipment Vulnerable to CSRF, XSS

Million-Plus WordPress Sites Exposed by Vulnerable Plugin

Exploit

NETGEAR DGN2200v1/v2/v3/v4 - Cross-Site Request Forgery

Cisco AnyConnect Secure Mobility Client 4.3.04027 - Privilege Escalation

BlueIris 4.5.1.4 - Denial of Service

Synchronet BBS 3.16c - Denial of Service

Linux/x86-64 - Reverse Shell Shellcode (84 bytes)