Databáze Hot News 2017 September - 2017 January February March April May June July August September October November December


29.9.2017

Bugtraq

CVE-2017-14087 Trend Micro OfficeScan v11.0 and XG (12.0)* Host Header Injection (apparitionsec / hyp3rlinx) 2017-09-28
apparitionsec gmail com

security bulletin] HPESBGN03773 rev.2 - HPE Application Performance Management (BSM), Remote Code Execution 2017-09-28
swpmb cyber-psrt microfocus com

CVE-2017-14084 Trend Micro OfficeScan v11.0 and XG (12.0)* CURL (MITM) Remote Code Execution (apparitionsec / hyp3rlinx) 2017-09-28
apparitionsec gmail com

CVE-2017-9538] Persistent Application Denial of Service 2017-09-29
andys3c gmail com

CVE-2017-9537] Persistent Cross-Site Scripting Vulnerabilities 2017-09-29
andys3c gmail com

Faleemi FSC-880 Multiple Security Vulnerabilities 2017-09-27
oleg iotsploit co

Malware

Trojan.Starloader

Phishing

contact

29th September 2017

ACCOUNT UPDATE RECIEPT #DA5413

Natwest

28th September 2017

Temporarily Restriction Notice

Admin

28th September 2017

Secure your rgwalker99@aol.com
email account

Vulnerebility

Adobe FlashPlayer and AIR APSB15-32 Multiple Unspecified Heap Buffer Overflow Vulnerabilities
2017-09-28
http://www.securityfocus.com/bid/78712

Adobe Flash Player and AIR CVE-2015-8651 Unspecified Integer Overflow Vulnerability
2017-09-28
http://www.securityfocus.com/bid/79705

Adobe Flash Player and AIR APSB16-08 Multiple Unspecified Integer Overflow Vulnerabilities
2017-09-28
http://www.securityfocus.com/bid/84308

Adobe Flash Player CVE-2016-1019 Unspecified Remote Code Execution Vulnerability
2017-09-28
http://www.securityfocus.com/bid/85856

Microsoft Internet Explorer CVE-2016-0189 Scripting Engine Remote Memory Corruption Vulnerability
2017-09-28
http://www.securityfocus.com/bid/90012

Adobe Flash Player CVE-2016-4117 Unspecified Remote Code Execution Vulnerability
2017-09-28
http://www.securityfocus.com/bid/90505

Microsoft XML Core Services CVE-2017-0022 Information Disclosure Vulnerability
2017-09-28
http://www.securityfocus.com/bid/96069

Microsoft Internet Explorer and Edge CVE-2017-0037 Remote Memory Corruption Vulnerability
2017-09-28
http://www.securityfocus.com/bid/96088

Drupal Ctools Module Cross Site Scripting and Access Bypass Vulnerabilities
2017-09-28
http://www.securityfocus.com/bid/76441

Mozilla Firefox and Firefox ESR Multiple Use After Free Denial of Service Vulnerabilities
2017-09-28
http://www.securityfocus.com/bid/101055

Mozilla Firefox CVE-2017-7810 Multiple Unspecified Memory Corruption Vulnerabilities
2017-09-28
http://www.securityfocus.com/bid/101054

Mozilla Firefox and Firefox ESR CVE-2017-7824 Buffer Overflow Vulnerability
2017-09-28
http://www.securityfocus.com/bid/101053

Perl CVE-2017-12814 Stack Based Buffer Overflow Vulnerability
2017-09-28
http://www.securityfocus.com/bid/101051

WordPress 2kb Amazon Affiliates Store Plugin Multiple Cross Site Scripting Vulnerabilities
2017-09-28
http://www.securityfocus.com/bid/101050

libvorbis CVE-2017-14160 Denial of Service Vulnerability
2017-09-28
http://www.securityfocus.com/bid/101045

Multiple Siemens Products Discovery Protocol CVE-2017-12736 Remote Security Bypass Vulnerability
2017-09-28
http://www.securityfocus.com/bid/101041

Apache HTTP Server CVE-2016-8743 Security Bypass Vulnerability
2017-09-27
http://www.securityfocus.com/bid/95077

Apache Struts CVE-2017-9793 Denial of Service Vulnerability
2017-09-27
http://www.securityfocus.com/bid/100611

Apache Struts CVE-2017-9804 Incomplete Fix Denial of Service Vulnerability
2017-09-27
http://www.securityfocus.com/bid/100612

Apache Struts Spring AOP Functionality Denial of Service Vulnerability
2017-09-27
http://www.securityfocus.com/bid/99562

Apache Struts CVE-2017-12611 Remote Code Execution Vulnerability
2017-09-27
http://www.securityfocus.com/bid/100829

Apache Struts CVE-2017-7672 Denial of Service Vulnerability
2017-09-27
http://www.securityfocus.com/bid/99563

Apache Struts CVE-2017-9791 Remote Code Execution Vulnerability
2017-09-27
http://www.securityfocus.com/bid/99484

Apache Struts CVE-2017-9805 Remote Code Execution Vulnerability
2017-09-27
http://www.securityfocus.com/bid/100609

Apple iOS and tvOS Wi-Fi Chip Multiple Arbitray Code Execution Vulnerabilities
2017-09-27
http://www.securityfocus.com/bid/100984

Oracle Java SE and JRockit CVE-2017-10115 Remote Security Vulnerability
2017-09-27
http://www.securityfocus.com/bid/99774

Cisco IOS Software CVE-2017-12232 Denial of Service Vulnerability
2017-09-27
http://www.securityfocus.com/bid/101044

Cisco IOS Software CVE-2017-12235 Denial of Service Vulnerability
2017-09-27
http://www.securityfocus.com/bid/101043

Multiple Cisco Products CVE-2017-12239 Local Unauthorized Access Vulnerability
2017-09-27
http://www.securityfocus.com/bid/101042

Cisco IOS Software for Cisco Catalyst 6800 Series Switches Denial of Service Vulnerability
2017-09-27
http://www.securityfocus.com/bid/101040

SANS News

The easy way to analyze huge amounts of PCAP data

Threatpost

Civil Liberties Activists Hit By Phishing Campaign

Google to Enforce HSTS on TLDs it Operates

Macs Not Receiving EFI Firmware Security Updates as Expected

Exploit

FileRun <= 2017.09.18 - SQL Injection

Trend Micro OfficeScan 11.0/XG (12.0) - Memory Corruption

Easy Blog PHP Script 1.3a - 'id' Parameter SQL Injection

Roteador Wireless Intelbras WRN150 - Autentication Bypass

Trend Micro OfficeScan 11.0/XG (12.0) - 'Host' Header Injection

Trend Micro OfficeScan 11.0/XG (12.0) - Server Side Request Forgery

Trend Micro OfficeScan 11.0/XG (12.0) - Information Disclosure

Trend Micro OfficeScan 11.0/XG (12.0) - Code Execution / Memory Corruption

Trend Micro OfficeScan 11.0/XG (12.0) - Private Key Disclosure

Roteador Wireless Intelbras WRN150 - Autentication Bypass

Easy Blog PHP Script 1.3a - 'id' Parameter SQL Injection

28.9.2017

Bugtraq

 

Malware

MSIL/Spy.Netpune.A

MSIL/Spy.RinLog.A

Win32/TrojanProxy.Hioles.AD

Win32/Emotet.AW

Win32/TrickBot.V

Phishing

Admin

28th September 2017

Secure your rgwalker99@aol.com
email account

Security Team

27th September 2017

Your account has been limited.

Vulnerebility

Adobe Flash Player and AIR CVE-2015-8651 Unspecified Integer Overflow Vulnerability
2017-09-28
http://www.securityfocus.com/bid/79705

Adobe Flash Player and AIR APSB16-08 Multiple Unspecified Integer Overflow Vulnerabilities
2017-09-28
http://www.securityfocus.com/bid/84308

Adobe Flash Player CVE-2016-1019 Unspecified Remote Code Execution Vulnerability
2017-09-28
http://www.securityfocus.com/bid/85856

Microsoft Internet Explorer CVE-2016-0189 Scripting Engine Remote Memory Corruption Vulnerability
2017-09-28
http://www.securityfocus.com/bid/90012

Adobe Flash Player CVE-2016-4117 Unspecified Remote Code Execution Vulnerability
2017-09-28
http://www.securityfocus.com/bid/90505

Microsoft XML Core Services CVE-2017-0022 Information Disclosure Vulnerability
2017-09-28
http://www.securityfocus.com/bid/96069

Microsoft Internet Explorer and Edge CVE-2017-0037 Remote Memory Corruption Vulnerability
2017-09-28
http://www.securityfocus.com/bid/96088

Drupal Ctools Module Cross Site Scripting and Access Bypass Vulnerabilities
2017-09-28
http://www.securityfocus.com/bid/76441

libvorbis CVE-2017-14160 Denial of Service Vulnerability
2017-09-28
http://www.securityfocus.com/bid/101045

Multiple Siemens Products Discovery Protocol CVE-2017-12736 Remote Security Bypass Vulnerability
2017-09-28
http://www.securityfocus.com/bid/101041

Apache HTTP Server CVE-2016-8743 Security Bypass Vulnerability
2017-09-27
http://www.securityfocus.com/bid/95077

Apache Struts CVE-2017-9793 Denial of Service Vulnerability
2017-09-27
http://www.securityfocus.com/bid/100611

Apache Struts CVE-2017-9804 Incomplete Fix Denial of Service Vulnerability
2017-09-27
http://www.securityfocus.com/bid/100612

Apache Struts Spring AOP Functionality Denial of Service Vulnerability
2017-09-27
http://www.securityfocus.com/bid/99562

Apache Struts CVE-2017-12611 Remote Code Execution Vulnerability
2017-09-27
http://www.securityfocus.com/bid/100829

Apache Struts CVE-2017-7672 Denial of Service Vulnerability
2017-09-27
http://www.securityfocus.com/bid/99563

Apache Struts CVE-2017-9791 Remote Code Execution Vulnerability
2017-09-27
http://www.securityfocus.com/bid/99484

Apache Struts CVE-2017-9805 Remote Code Execution Vulnerability
2017-09-27
http://www.securityfocus.com/bid/100609

Apple iOS and tvOS Wi-Fi Chip Multiple Arbitray Code Execution Vulnerabilities
2017-09-27
http://www.securityfocus.com/bid/100984

Oracle Java SE and JRockit CVE-2017-10115 Remote Security Vulnerability
2017-09-27
http://www.securityfocus.com/bid/99774

Cisco IOS Software CVE-2017-12232 Denial of Service Vulnerability
2017-09-27
http://www.securityfocus.com/bid/101044

Cisco IOS Software CVE-2017-12235 Denial of Service Vulnerability
2017-09-27
http://www.securityfocus.com/bid/101043

Multiple Cisco Products CVE-2017-12239 Local Unauthorized Access Vulnerability
2017-09-27
http://www.securityfocus.com/bid/101042

Cisco IOS Software for Cisco Catalyst 6800 Series Switches Denial of Service Vulnerability
2017-09-27
http://www.securityfocus.com/bid/101040

Cisco IOS Software CVE-2017-12231 Remote Denial of Service Vulnerability
2017-09-27
http://www.securityfocus.com/bid/101039

Cisco IOS Software Common Industrial Protocol Multiple Denial of Service Vulnerabilities
2017-09-27
http://www.securityfocus.com/bid/101038

Cisco IOS and IOS XE Software CVE-2017-12237 Denial of Service Vulnerability
2017-09-27
http://www.securityfocus.com/bid/101037

Cisco IOS XE Software CVE-2017-12230 Privilege Escalation Vulnerability
2017-09-27
http://www.securityfocus.com/bid/101036

Cisco IOS XE Software CVE-2017-12222 Denial of Service Vulnerability
2017-09-27
http://www.securityfocus.com/bid/101035

Cisco IOS and IOS XE Software CVE-2017-12240 Buffer Overflow Vulnerability
2017-09-27
http://www.securityfocus.com/bid/101034

SANS News

 

Threatpost

Gatekeeper Alone Won’t Mitigate Apple Keychain Attack

Exploit

Cisco Prime Collaboration Provisioning < 12.1 - Authentication Bypass / Remote Code...

LAquis SCADA 4.1.0.2385 - Directory Traversal (Metasploit)

27.9.2017

Bugtraq

Faleemi FSC-880 Multiple Security Vulnerabilities 2017-09-27
oleg iotsploit co

Bitdefender Total Security 2017 Unquoted Service Path Vulnerability 2017-09-27
wsachin092 gmail com

SECURITY] DSA 3984-1] git security update 2017-09-26
Florian Weimer (fw deneb enyo de)

Qualys Security Advisory - Linux PIE/stack corruption (CVE-2017-1000253) 2017-09-26
Qualys Security Advisory (qsa qualys com)

security bulletin] HPESBGN03773 rev.1 - HPE Application Performance Management (BSM), Remote Code Execution 2017-09-25
swpmb cyber-psrt microfocus com

Mako Web Server v2.5 Multiple Unauthenticated Vulnerabilities (apparitionsec / hyp3rlinx) 2017-09-25
apparitionsec gmail com

Kaltura - Remote Code Execution and Cross-Site Scripting 2017-09-24
robin verton telekom de

Malware

 

Phishing

Navy Federal Credit Union

26th September 2017

You Have 1 New Security
Message Alert !

Vulnerebility

Apache Struts CVE-2017-9805 Remote Code Execution Vulnerability
2017-09-27
http://www.securityfocus.com/bid/100609

Apple iOS and tvOS Wi-Fi Chip Multiple Arbitray Code Execution Vulnerabilities
2017-09-27
http://www.securityfocus.com/bid/100984

Oracle Java SE and JRockit CVE-2017-10115 Remote Security Vulnerability
2017-09-27
http://www.securityfocus.com/bid/99774

Bitdefender Total Security Local Code Execution Vulnerability
2017-09-27
http://www.securityfocus.com/bid/101014

Oracle Java SE and JRockit CVE-2017-10116 Remote Security Vulnerability
2017-09-26
http://www.securityfocus.com/bid/99734

Apple iTunes CVE-2017-7079 Access Bypass Vulnerability
2017-09-26
http://www.securityfocus.com/bid/100983

Linux Kernel CVE-2017-1000253 Local Privilege Escalation Vulnerability
2017-09-26
http://www.securityfocus.com/bid/101010

EMC Data Protection Advisor CVE-2017-10955 Remote Command Injection Vulnerability
2017-09-26
http://www.securityfocus.com/bid/101008

Symantec Norton Remove and Reinstall DLL Loading CVE-2017-13676 Local Code Execution Vulnerability
2017-09-26
http://www.securityfocus.com/bid/100939

SANS News

 

Threatpost

Remote Wi-Fi Attack Backdoors iPhone 7

Exploit

WordPress Plugin WPAMS - SQL Injection

WordPress Plugin School Management System - SQL Injection

WordPress Plugin Hospital Management System - SQL Injection

WordPress Plugin WPGYM - SQL Injection

WordPress Plugin WPCHURCH - SQL Injection

AMC Master - Arbitrary File Upload

SMSmaster - SQL Injection

26.9.2017

Bugtraq

security bulletin] HPESBGN03773 rev.1 - HPE Application Performance Management (BSM), Remote Code Execution 2017-09-25
swpmb cyber-psrt microfocus com

Mako Web Server v2.5 Multiple Unauthenticated Vulnerabilities (apparitionsec / hyp3rlinx) 2017-09-25
apparitionsec gmail com

Malware

Ransom.Redboot

Phishing

*****CONGRATULATION*****

25th September 2017

TODAY ONLY: Your $50 Amazon
gift card

AMERICAN EXPRESS

25th September 2017

News] Message From AMERICAN
EXPRESS

Vulnerebility

Apple iOS and tvOS Wi-Fi Chip Multiple Arbitray Code Execution Vulnerabilities
2017-09-26
http://www.securityfocus.com/bid/100984

Apple iTunes CVE-2017-7079 Access Bypass Vulnerability
2017-09-26
http://www.securityfocus.com/bid/100983

Adobe Flash Player CVE-2015-0313 Remote Code Execution Vulnerability
2017-09-25
http://www.securityfocus.com/bid/72429

Microsoft Windows Kernel 'Win32k.sys' CVE-2016-7255 Local Privilege Escalation Vulnerability
2017-09-25
http://www.securityfocus.com/bid/94064

Adobe Flash Player CVE-2016-7855 Use After Free Remote Code Execution Vulnerability
2017-09-25
http://www.securityfocus.com/bid/93861

Microsoft Windows Common Controls ActiveX Control Remote Code Execution Vulnerability
2017-09-25
http://www.securityfocus.com/bid/52911

Expat CVE-2016-0718 Buffer Overflow Vulnerability
2017-09-25
http://www.securityfocus.com/bid/90729

Cisco Integrated Management Controller CVE-2017-6619 Remote Command Execution Vulnerability
2017-09-25
http://www.securityfocus.com/bid/97925

SANS News

XPCTRA Malware Steals Banking and Digital Wallet User's Credentials

Threatpost

Deloitte: ‘Very Few Clients’ Impacted by Cyber Attack
Android Lockscreen Patterns Less Secure Than PINs

Exploit

Oracle 9i XDB 9.2.0.1 - HTTP PASS Buffer Overflow

Supervisor 3.0a1 - 3.3.2 - XML-RPC Authenticated Remote Code Execution (Metasploit)

Disk Pulse Enterprise 10.0.12 - GET Buffer Overflow (SEH)

NodeJS Debugger - Command Injection (Metasploit)

FLIR Thermal Camera F/FC/PT/D - SSH Backdoor

Sitefinity CMS 9.2 - Cross-Site Scripting

FLIR Thermal Camera F/FC/PT/D - Stream Disclosure

FLIR Thermal Camera FC-S/PT - Command Injection

FLIR Thermal Camera F/FC/PT/D - Information Disclosure

FLIR Thermal Camera PT-Series (PT-334 200562) - Root Remote Code Execution

Linux/x86_64 - mkdir() 'evil' Shellcode (30 bytes)

25.9.2017

Bugtraq

Mako Web Server v2.5 Multiple Unauthenticated Vulnerabilities (apparitionsec / hyp3rlinx) 2017-09-25
apparitionsec gmail com

Kaltura - Remote Code Execution and Cross-Site Scripting 2017-09-24
robin verton telekom de

slackware-security] libxml2 (SSA:2017-266-01) 2017-09-23
Slackware Security Team (security slackware com)

SECURITY] DSA 3983-1] samba security update 2017-09-22
Moritz Muehlenhoff (jmm debian org)

APPLE-SA-2017-09-19-1 iOS 11 2017-09-19
Apple Product Security (product-security-noreply lists apple com)

slackware-security] httpd (SSA:2017-261-01) 2017-09-18
Slackware Security Team (security slackware com)

Malware

Linux.Proxym

Phishing

AMERICAN EXPRESS

25th September 2017

News] Message From AMERICAN
EXPRESS

M5N 0ffice-team

25th September 2017

Account Issue

Vulnerebility

Cisco Integrated Management Controller CVE-2017-6619 Remote Command Execution Vulnerability
2017-09-25
http://www.securityfocus.com/bid/97925

Cisco Integrated Management Controller CVE-2017-6616 Remote Code Execution Vulnerability
2017-09-25
http://www.securityfocus.com/bid/97928

IPython JSON Error Responses Multiple Cross Site Scripting Vulnerabilities
2017-09-25
http://www.securityfocus.com/bid/75328

WordPress Prior to 4.8.2 Multiple Input Validation Security Vulnerabilities
2017-09-25
http://www.securityfocus.com/bid/100912

Linux kernel CVE-2017-14106 Local Denial of Service Vulnerability
2017-09-25
http://www.securityfocus.com/bid/100878

Linux Kernel CVE-2017-12154 Denial of Service Vulnerability
2017-09-25
http://www.securityfocus.com/bid/100856

Linux Kernel CVE-2017-1000111 Local Privilege Escalation Vulnerability
2017-09-25
http://www.securityfocus.com/bid/100267

Linux Kernel 'drivers/video/fbdev/aty/atyfb_base.c' Local Information Disclosure Vulnerability
2017-09-25
http://www.securityfocus.com/bid/100634

Linux Kernel 'net/xfrm/xfrm_policy.c' Local Denial of Service Vulnerability
2017-09-25
http://www.securityfocus.com/bid/99928

Linux Kernel CVE-2017-14340 Local Denial of Service Vulnerability
2017-09-25
http://www.securityfocus.com/bid/100851

Linux Kernel CVE-2017-14497 Local Buffer Overflow Vulnerability
2017-09-25
http://www.securityfocus.com/bid/100871

Google Android Kernel Components Multiple Privilege Escalation Vulnerabilities
2017-09-25
http://www.securityfocus.com/bid/100215

Linux Kernel CVE-2017-1000370 Local Security Bypass Vulnerability
2017-09-25
http://www.securityfocus.com/bid/99149

Linux Kernel CVE-2017-12146 Local Race Condition Vulnerability
2017-09-25
http://www.securityfocus.com/bid/100651

Xen CVE-2017-12134 Memory Corruption Vulnerability
2017-09-25
http://www.securityfocus.com/bid/100343

Linux Kernel CVE-2017-12153 Null Pointer Dereference Local Denial of Service Vulnerability
2017-09-25
http://www.securityfocus.com/bid/100855

Linux Kernel 'sound/core/timer.c' Local Information Disclosure Vulnerability
2017-09-25
http://www.securityfocus.com/bid/99121

Linux Kernel CVE-2017-7518 Privilage Escalation Vulnerability
2017-09-25
http://www.securityfocus.com/bid/99263

Linux Kernel 'mm/migrate.c' Local Information Disclosure Vulnerability
2017-09-25
http://www.securityfocus.com/bid/100876

Linux Kernel CVE-2017-1000371 Local Security Bypass Vulnerability
2017-09-25
http://www.securityfocus.com/bid/99131

Linux Kernel CVE-2017-7558 Multiple Local Information Disclosure Vulnerabilities
2017-09-25
http://www.securityfocus.com/bid/100466

Linux Kernel Bluetooth Subsystem CVE-2017-1000251 Stack Based Buffer Overflow Vulnerability
2017-09-25
http://www.securityfocus.com/bid/100809

Linux Kernel CVE-2017-1000112 Local Memory Corruption Vulnerability
2017-09-25
http://www.securityfocus.com/bid/100262

Perl CVE-2017-12837 Heap Buffer Overflow Vulnerability
2017-09-25
http://www.securityfocus.com/bid/100860

Perl CVE-2017-12883 Buffer Overflow Vulnerability
2017-09-25
http://www.securityfocus.com/bid/100852

Samba CVE-2017-12151 Man in the Middle Security Bypass Vulnerability
2017-09-25
http://www.securityfocus.com/bid/100917

Samba CVE-2017-12163 Arbitrary File Write Vulnerability
2017-09-25
http://www.securityfocus.com/bid/100925

Samba CVE-2017-12150 Man in the Middle Security Bypass Vulnerability
2017-09-25
http://www.securityfocus.com/bid/100918

Kaltura Community Edition Multiple Security Vulnerabilities
2017-09-25
http://www.securityfocus.com/bid/100976

Trend Micro Mobile Security (Enterprise) CVE-2017-14078 Multiple SQL Injection Vulnerabilities
2017-09-25
http://www.securityfocus.com/bid/100966

SANS News

Back to Basics: Writing Change Requests in Natural Language

Threatpost

Chris Vickery on Amazon S3 Data Leaks

Exploit

 

24.9.2017

Bugtraq

 

Malware

 

Phishing

Apple

22nd September 2017

YOUR ACCOUNT ACCESS HAS BEEN
DISABLED ! CASEID:98301

iTunes Store

21st September 2017

 SUMMARY REPORT ] FRAUD
ACTIVITY : PLEASE REVIEW YOUR
RECEIPT FROM APPLE

Vulnerebility

Samba CVE-2017-12151 Man in the Middle Security Bypass Vulnerability
2017-09-22
http://www.securityfocus.com/bid/100917

Samba CVE-2017-12150 Man in the Middle Security Bypass Vulnerability
2017-09-22
http://www.securityfocus.com/bid/100918

Samba CVE-2017-12163 Arbitrary File Write Vulnerability
2017-09-22
http://www.securityfocus.com/bid/100925

Apache Struts CVE-2017-9805 Remote Code Execution Vulnerability
2017-09-22
http://www.securityfocus.com/bid/100609

Oracle Java SE and JRockit CVE-2017-10108 Remote Security Vulnerability
2017-09-22
http://www.securityfocus.com/bid/99846

Oracle Java SE and JRockit CVE-2017-10135 Remote Security Vulnerability
2017-09-22
http://www.securityfocus.com/bid/99839

Oracle Java SE and JRockit CVE-2017-10053 Remote Security Vulnerability
2017-09-22
http://www.securityfocus.com/bid/99842

Oracle Java SE and JRockit CVE-2017-10198 Remote Security Vulnerability
2017-09-22
http://www.securityfocus.com/bid/99818

Oracle Java SE and JRockit CVE-2017-10176 Remote Security Vulnerability
2017-09-22
http://www.securityfocus.com/bid/99788

Oracle Java SE and JRockit CVE-2017-10118 Remote Security Vulnerability
2017-09-22
http://www.securityfocus.com/bid/99782

Oracle Java SE CVE-2017-10078 Remote Security Vulnerability
2017-09-22
http://www.securityfocus.com/bid/99752

Oracle Java SE CVE-2017-10102 Remote Security Vulnerability
2017-09-22
http://www.securityfocus.com/bid/99712

GraphicsMagick CVE-2017-14649 Denial of Service Vulnerability
2017-09-21
http://www.securityfocus.com/bid/100958

CA Identity Manager CVE-2017-9393 Information Disclosure Vulnerability
2017-09-21
http://www.securityfocus.com/bid/100956

Apache Tomcat CVE-2017-12617 Incomplete Fix Remote Code Execution Vulnerability
2017-09-21
http://www.securityfocus.com/bid/100954

Ctek SkyRouter CVE-2017-14000 Authentication Bypass Vulnerability
2017-09-21
http://www.securityfocus.com/bid/100953

Multiple Schneider Electric Products CVE-2017-13997 Authentication Bypass Vulnerability
2017-09-21
http://www.securityfocus.com/bid/100952

IniNet Solutions SCADA Web Server CVE-2017-13995 Authentication Bypass Vulnerability
2017-09-21
http://www.securityfocus.com/bid/100951

Digium Asterisk GUI CVE-2017-14001 OS Command Injection Vulnerability
2017-09-21
http://www.securityfocus.com/bid/100950

PCD CVE-2017-9628 Unspecified Information Disclosure Vulnerability
2017-09-21
http://www.securityfocus.com/bid/100949

Multiple Pivotal Products CVE-2017-8046 Remote Code Execution Vulnerability
2017-09-21
http://www.securityfocus.com/bid/100948

Google Chrome V8 Multiple Out-of-Bounds Memory Access Vulnerabilities
2017-09-21
http://www.securityfocus.com/bid/100947

ImageMagick CVE-2017-14607 Heap Buffer Overflow Vulnerability
2017-09-21
http://www.securityfocus.com/bid/100944

ImageMagick CVE-2017-14626 Denial of Service Vulnerability
2017-09-21
http://www.securityfocus.com/bid/100943

ImageMagick CVE-2017-14625 Denial of Service Vulnerability
2017-09-21
http://www.securityfocus.com/bid/100941

ImageMagick CVE-2017-14624 Denial of Service Vulnerability
2017-09-21
http://www.securityfocus.com/bid/100940

WordPress Prior to 4.8.2 Multiple Input Validation Security Vulnerabilities
2017-09-20
http://www.securityfocus.com/bid/100912

Git CVE-2017-1000117 Remote Command Injection Vulnerability
2017-09-20
http://www.securityfocus.com/bid/100283

Apache Subversion CVE-2017-9800 Remote Command Execution Vulnerability
2017-09-20
http://www.securityfocus.com/bid/100259

Multiple SAP Products 'DBISQL' Information Disclosure Vulnerability
2017-09-20
http://www.securityfocus.com/bid/97581

SANS News

Forensic use of mount --bind

What is the State of Your Union?

Malspam pushing Word documents with Hancitor malware

Threatpost

Verizon Wireless Internal Credentials, Infrastructure Details Exposed in Amazon S3 Bucket

EternalBlue Exploit Used in Retefe Banking Trojan Campaign

2016 SEC Hack May Have Benefited Insider Trading

Samba Update Patches Two SMB-Related MiTM Bugs

Exploit

 

22.9.2017

Bugtraq

 

Malware

 

Phishing

iTunes Store

21st September 2017

 SUMMARY REPORT ] FRAUD
ACTIVITY : PLEASE REVIEW YOUR
RECEIPT FROM APPLE

iTunes Store

21st September 2017

 NEW STATEMENT UPDATE ] FRAUD
ACTIVITY : PLEASE REVIEW YOUR
RECEIPT FROM APPLE

Netflix

20th September 2017

WALMART EGIFT CARD (INSIDE).

Vulnerebility

Oracle Java SE and JRockit CVE-2017-10198 Remote Security Vulnerability
2017-09-22
http://www.securityfocus.com/bid/99818

Oracle Java SE and JRockit CVE-2017-10176 Remote Security Vulnerability
2017-09-22
http://www.securityfocus.com/bid/99788

Oracle Java SE and JRockit CVE-2017-10118 Remote Security Vulnerability
2017-09-22
http://www.securityfocus.com/bid/99782

Oracle Java SE CVE-2017-10078 Remote Security Vulnerability
2017-09-22
http://www.securityfocus.com/bid/99752

Oracle Java SE CVE-2017-10102 Remote Security Vulnerability
2017-09-22
http://www.securityfocus.com/bid/99712

ImageMagick CVE-2017-14607 Heap Buffer Overflow Vulnerability
2017-09-21
http://www.securityfocus.com/bid/100944

ImageMagick CVE-2017-14626 Denial of Service Vulnerability
2017-09-21
http://www.securityfocus.com/bid/100943

ImageMagick CVE-2017-14625 Denial of Service Vulnerability
2017-09-21
http://www.securityfocus.com/bid/100941

ImageMagick CVE-2017-14624 Denial of Service Vulnerability
2017-09-21
http://www.securityfocus.com/bid/100940

WordPress Prior to 4.8.2 Multiple Input Validation Security Vulnerabilities
2017-09-20
http://www.securityfocus.com/bid/100912

Git CVE-2017-1000117 Remote Command Injection Vulnerability
2017-09-20
http://www.securityfocus.com/bid/100283

Apache Subversion CVE-2017-9800 Remote Command Execution Vulnerability
2017-09-20
http://www.securityfocus.com/bid/100259

Multiple SAP Products 'DBISQL' Information Disclosure Vulnerability
2017-09-20
http://www.securityfocus.com/bid/97581

HP ArcSight ESM and ArcSight ESM Express Multiple Security Vulnerabilities
2017-09-20
http://www.securityfocus.com/bid/100935

Drupal Page Access Module Unspecified Security Vulnerability
2017-09-20
http://www.securityfocus.com/bid/100934

Multiple Cisco Products CVE-2017-6720 Denial of Service Vulnerability
2017-09-20
http://www.securityfocus.com/bid/100933

Cisco UCS Central Software Command Line Interface CVE-2017-12255 Command Injection Vulnerability
2017-09-20
http://www.securityfocus.com/bid/100932

Cisco Unified Customer Voice Portal CVE-2017-12214 Remote Privilege Escalation Vulnerability
2017-09-20
http://www.securityfocus.com/bid/100931

SANS News

Malspam pushing Word documents with Hancitor malware

Threatpost

Iranian APT33 Targets US Firms with Destructive Malware


Joomla Patches Eight-Year-Old LDAP Injection Vulnerability

Malware Steals Data From Air-Gapped Network via Security Cameras

Exploit

 

21.9.2017

Bugtraq

 

Malware

Trojan.Famberp

Phishing

Netflix

20th September 2017

WALMART EGIFT CARD (INSIDE).

*****CONGRATULATION*****

19th September 2017

TODAY ONLY: Your $50 Amazon
gift card

Vulnerebility

WordPress Prior to 4.8.2 Multiple Input Validation Security Vulnerabilities
2017-09-20
http://www.securityfocus.com/bid/100912

Git CVE-2017-1000117 Remote Command Injection Vulnerability
2017-09-20
http://www.securityfocus.com/bid/100283

Apache Subversion CVE-2017-9800 Remote Command Execution Vulnerability
2017-09-20
http://www.securityfocus.com/bid/100259

Multiple SAP Products 'DBISQL' Information Disclosure Vulnerability
2017-09-20
http://www.securityfocus.com/bid/97581

Apache Struts CVE-2017-12611 Remote Code Execution Vulnerability
2017-09-19
http://www.securityfocus.com/bid/100829

Apache Struts CVE-2017-9793 Denial of Service Vulnerability
2017-09-19
http://www.securityfocus.com/bid/100611

Apache Struts CVE-2017-9805 Remote Code Execution Vulnerability
2017-09-19
http://www.securityfocus.com/bid/100609

Apache Struts CVE-2017-9804 Incomplete Fix Denial of Service Vulnerability
2017-09-19
http://www.securityfocus.com/bid/100612

Apache Tomcat CVE-2017-12615 Remote Code Execution Vulnerability
2017-09-19
http://www.securityfocus.com/bid/100901

Joomla! CVE-2017-14595 Information Disclosure Vulnerability
2017-09-19
http://www.securityfocus.com/bid/100900

Joomla! CVE-2017-14596 Information Disclosure Vulnerability
2017-09-19
http://www.securityfocus.com/bid/100898

Apache Tomcat CVE-2017-12616 Information Disclosure Vulnerability
2017-09-19
http://www.securityfocus.com/bid/100897

Apple Safari and iOS CVE-2017-7085 Address Bar Spoofing Vulnerability
2017-09-19
http://www.securityfocus.com/bid/100895

Apple Xcode Multiple Memory Corruption Vulnerabilities
2017-09-19
http://www.securityfocus.com/bid/100894

WebKit Multiple Security Vulnerabilities
2017-09-19
http://www.securityfocus.com/bid/100893

Apple iOS APPLE-SA-2017-09-19-1 Multiple Security Vulnerabilities
2017-09-19
http://www.securityfocus.com/bid/100892

Apache Tomcat CVE-2017-7674 Security Bypass Vulnerability
2017-09-18
http://www.securityfocus.com/bid/100280

SANS News

Email attachment using CVE-2017-8759 exploit targets Argentina

Threatpost

What Triggers HTTPS Chrome Browser Warnings?

Malware Steals Data From Air-Gapped Network via Security Cameras

Deep-Learning PassGAN Tool Improves Password Guessing

Exploit

 

20.9.2017

Bugtraq

APPLE-SA-2017-09-19-1 iOS 11 2017-09-19
Apple Product Security (product-security-noreply lists apple com)

[slackware-security] httpd (SSA:2017-261-01) 2017-09-18
Slackware Security Team (security slackware com)

[slackware-security] libgcrypt (SSA:2017-261-02) 2017-09-18
Slackware Security Team (security slackware com)

[slackware-security] ruby (SSA:2017-261-03) 2017-09-18
Slackware Security Team (security slackware com)

Watchguard Fireware OS DOS & Stored XSS 2017-09-18
David Fernandez (david fdmv gmail com)

Malware

Exp.CVE-2017-8737

Exp.CVE-2017-8728

Exp.CVE-2017-8753

Exp.CVE-2017-8757

Exp.CVE-2017-8734

Exp.CVE-2017-8738

Exp.CVE-2017-8747

Exp.CVE-2017-8749

Phishing

Netflix

20th September 2017

WALMART EGIFT CARD (INSIDE).

*****CONGRATULATION*****

19th September 2017

TODAY ONLY: Your $50 Amazon
gift card

Santander Bank Plc

18th September 2017

Important Notice (New Online
Banking Authentication
Procedure)

Vulnerebility

Multiple SAP Products 'DBISQL' Information Disclosure Vulnerability
2017-09-20
http://www.securityfocus.com/bid/97581

Apache Struts CVE-2017-12611 Remote Code Execution Vulnerability
2017-09-19
http://www.securityfocus.com/bid/100829

Apache Struts CVE-2017-9793 Denial of Service Vulnerability
2017-09-19
http://www.securityfocus.com/bid/100611

Apache Struts CVE-2017-9805 Remote Code Execution Vulnerability
2017-09-19
http://www.securityfocus.com/bid/100609

Apache Struts CVE-2017-9804 Incomplete Fix Denial of Service Vulnerability
2017-09-19
http://www.securityfocus.com/bid/100612

Apache Tomcat CVE-2017-12615 Remote Code Execution Vulnerability
2017-09-19
http://www.securityfocus.com/bid/100901

Joomla! CVE-2017-14595 Information Disclosure Vulnerability
2017-09-19
http://www.securityfocus.com/bid/100900

Joomla! CVE-2017-14596 Information Disclosure Vulnerability
2017-09-19
http://www.securityfocus.com/bid/100898

Apache Tomcat CVE-2017-12616 Information Disclosure Vulnerability
2017-09-19
http://www.securityfocus.com/bid/100897

Apple Safari and iOS CVE-2017-7085 Address Bar Spoofing Vulnerability
2017-09-19
http://www.securityfocus.com/bid/100895

Apple Xcode Multiple Memory Corruption Vulnerabilities
2017-09-19
http://www.securityfocus.com/bid/100894

WebKit Multiple Security Vulnerabilities
2017-09-19
http://www.securityfocus.com/bid/100893

Apple iOS APPLE-SA-2017-09-19-1 Multiple Security Vulnerabilities
2017-09-19
http://www.securityfocus.com/bid/100892

Apache Tomcat CVE-2017-7674 Security Bypass Vulnerability
2017-09-18
http://www.securityfocus.com/bid/100280

Apache Tomcat CVE-2017-7675 Directory Traversal Vulnerability
2017-09-18
http://www.securityfocus.com/bid/100256

Apache HTTP Server CVE-2017-9798 Information Disclosure Vulnerability
2017-09-18
http://www.securityfocus.com/bid/100872

Apache Solr CVE-2017-9803 Remote Privilege Escalation Vulnerability
2017-09-18
http://www.securityfocus.com/bid/100870

Moodle CVE-2017-12156 Cross Site Scripting Vulnerability
2017-09-18
http://www.securityfocus.com/bid/100867

Moodle CVE-2017-12157 Information Disclosure Vulnerability
2017-09-18
http://www.securityfocus.com/bid/100848

SANS News

Ongoing Ykcol (Locky) campaign

Threatpost

Cloud-Focused Firms Earn High Marks for Software Security in BSIMM8 Report

iOS 11 Update includes Patches for Eight Vulnerabilities

Risks Limited With Latest Apache Bug, Optionsbleed

Exploit

 

19.9.2017

Bugtraq

[slackware-security] httpd (SSA:2017-261-01) 2017-09-18
Slackware Security Team (security slackware com)

[slackware-security] libgcrypt (SSA:2017-261-02) 2017-09-18
Slackware Security Team (security slackware com)

[slackware-security] ruby (SSA:2017-261-03) 2017-09-18
Slackware Security Team (security slackware com)

Watchguard Fireware OS DOS & Stored XSS 2017-09-18
David Fernandez (david fdmv gmail com)

[SECURITY] [DSA 3978-1] gdk-pixbuf security update 2017-09-18
Moritz Muehlenhoff (jmm debian org)

ZK Time_Web Software 2.0 - Broken Authentication 2017-09-18
Arvind Vishwakarma (arvind12786 gmail com)

ZKTime_Web Software 2.0 - Cross Site Request Forgery 2017-09-18
Arvind Vishwakarma (arvind12786 gmail com)

[SECURITY] [DSA 3976-1] freexl security update 2017-09-17
Salvatore Bonaccorso (carnil debian org)

Malware

Python.Fakelib

Phishing

 

Vulnerebility

Apache Tomcat CVE-2017-7674 Security Bypass Vulnerability
2017-09-18
http://www.securityfocus.com/bid/100280

Apache Tomcat CVE-2017-7675 Directory Traversal Vulnerability
2017-09-18
http://www.securityfocus.com/bid/100256

Apache Solr CVE-2017-9803 Remote Privilege Escalation Vulnerability
2017-09-18
http://www.securityfocus.com/bid/100870

Moodle CVE-2017-12156 Cross Site Scripting Vulnerability
2017-09-18
http://www.securityfocus.com/bid/100867

Moodle CVE-2017-12157 Information Disclosure Vulnerability
2017-09-18
http://www.securityfocus.com/bid/100848

SANS News

New tool: mac-robber.py

Threatpost

Pirate Bay Spotted Hosting Monero Cryptocurrency Miner

Exploit

 

18.9.2017

Bugtraq

ZK Time_Web Software 2.0 - Broken Authentication 2017-09-18
Arvind Vishwakarma (arvind12786 gmail com)

ZKTime_Web Software 2.0 - Cross Site Request Forgery 2017-09-18
Arvind Vishwakarma (arvind12786 gmail com)

[SECURITY] [DSA 3976-1] freexl security update 2017-09-17
Salvatore Bonaccorso (carnil debian org)

[slackware-security] kernel (SSA:2017-258-02) 2017-09-15
Slackware Security Team (security slackware com)

Malware

JS.Dosdeming
Trojan.Sibakdi

Phishing

HBL InternetBanking

18th September 2017

HBL InternetBanking User ID Is
Blocked.

Hulu Video

18th September 2017

WALMART EGIFT CARD (INSIDE).

Disable account apple

18th September 2017

Notice to Your AppleID

Vulnerebility

Apache Tomcat CVE-2017-7674 Security Bypass Vulnerability
2017-09-18
http://www.securityfocus.com/bid/100280

Apache Tomcat CVE-2017-7675 Directory Traversal Vulnerability
2017-09-18
http://www.securityfocus.com/bid/100256

Moodle CVE-2017-12157 Information Disclosure Vulnerability
2017-09-18
http://www.securityfocus.com/bid/100848

VMware vCenter Server CVE-2017-4926 HTML Injection Vulnerability
2017-09-15
http://www.securityfocus.com/bid/100844

Xen 'mm.c' Remote Privilege Escalation Vulnerability
2017-09-15
http://www.securityfocus.com/bid/100819

Xen CVE-2017-14316 Arbitrary Code Execution Vulnerability
2017-09-15
http://www.securityfocus.com/bid/100818

SANS News

Getting some intelligence from malspam

Threatpost

 

Exploit

 

17.9.2017

Bugtraq

 

Malware

 

Phishing

BMO

17th September 2017

-Action: Changes made in your
Internet Banking Profile-

Vulnerebility

 

SANS News

rockNSM as a Incident Response Package

Threatpost

Rogue WordPress Plugin Allowed Spam Injection

VMware Patches Bug That Allows Guest to Execute Code on Host


Premium SMS Malware ‘ExpensiveWall’ Infects Millions of Android Devices

Exploit

 

15.9.2017

Bugtraq

 

Malware

 

Phishing

*****CONGRATULATION*****

15th September 2017

TODAY ONLY: Your $50 Amazon
gift card

Vulnerebility

Xen 'mm.c' Remote Privilege Escalation Vulnerability
2017-09-15
http://www.securityfocus.com/bid/100819

Xen CVE-2017-14316 Arbitrary Code Execution Vulnerability
2017-09-15
http://www.securityfocus.com/bid/100818

Xen 'grant_table.c' Privilege Escalation Vulnerability
2017-09-15
http://www.securityfocus.com/bid/100817

Oracle MySQL Server CVE-2017-3456 Remote Security Vulnerability
2017-09-15
http://www.securityfocus.com/bid/97831

Oracle MySQL Server CVE-2017-3464 Remote Security Vulnerability
2017-09-15
http://www.securityfocus.com/bid/97818

Oracle MySQL Server CVE-2017-3453 Remote Security Vulnerability
2017-09-15
http://www.securityfocus.com/bid/97776

Oracle MySQL Server CVE-2017-3600 Remote Security Vulnerability
2017-09-15
http://www.securityfocus.com/bid/97765

Oracle MySQL Server CVE-2017-3309 Remote Security Vulnerability
2017-09-15
http://www.securityfocus.com/bid/97742

Oracle MySQL Server CVE-2017-3308 Remote Security Vulnerability
2017-09-15
http://www.securityfocus.com/bid/97725

Oracle MySQL Server CVE-2017-3318 Local Security Vulnerability
2017-09-15
http://www.securityfocus.com/bid/95588

Oracle MySQL Server CVE-2017-3317 Local Security Vulnerability
2017-09-15
http://www.securityfocus.com/bid/95585

Oracle MySQL Server CVE-2017-3238 Remote Security Vulnerability
2017-09-15
http://www.securityfocus.com/bid/95571

Oracle MySQL Server CVE-2017-3244 Remote Security Vulnerability
2017-09-15
http://www.securityfocus.com/bid/95565

Oracle MySQL Server CVE-2017-3258 Remote Security Vulnerability
2017-09-15
http://www.securityfocus.com/bid/95560

Oracle MySQL Server CVE-2017-3243 Remote Security Vulnerability
2017-09-15
http://www.securityfocus.com/bid/95538

Oracle MySQL Server CVE-2017-3265 Local Security Vulnerability
2017-09-15
http://www.securityfocus.com/bid/95520

Oracle MySQL Server CVE-2017-3291 Local Security Vulnerability
2017-09-15
http://www.securityfocus.com/bid/95501

Oracle MySQL Server CVE-2017-3312 Local Security Vulnerability
2017-09-15
http://www.securityfocus.com/bid/95491

Oracle MySQL CVE-2016-6664 Local Security Vulnerability
2017-09-15
http://www.securityfocus.com/bid/93612

Oracle MySQL Server CVE-2017-3313 Local Security Vulnerability
2017-09-15
http://www.securityfocus.com/bid/95527

Microsoft Windows .NET Framework CVE-2017-8759 Remote Code Execution Vulnerability
2017-09-14
http://www.securityfocus.com/bid/100742

Microsoft Windows Bluetooth Driver CVE-2017-8628 Man in the Middle Spoofing Vulnerability
2017-09-14
http://www.securityfocus.com/bid/100744

MariaDB and MySQL CVE-2017-3302 Denial of Service Vulnerability
2017-09-14
http://www.securityfocus.com/bid/96162

Google Android CVE-2017-0781 Heap Buffer Overflow Vulnerability
2017-09-14
http://www.securityfocus.com/bid/100810

Python Ansible Vault Package CVE-2017-2809 Remote Code Execution Vulnerability
2017-09-14
http://www.securityfocus.com/bid/100824

LibOFX CVE-2017-2816 Stack Based Buffer Overflow Vulnerability
2017-09-13
http://www.securityfocus.com/bid/100828

Cisco Meeting Server CVE-2017-12249 Unauthorized Access Vulnerability
2017-09-13
http://www.securityfocus.com/bid/100821

Google Android Broadcom components Multiple Security Vulnerabilities
2017-09-12
http://www.securityfocus.com/bid/99482

SAP Point of Sale (POS) Retail Xpress Server Authentication Bypass Vulnerability
2017-09-12
http://www.securityfocus.com/bid/99531

SAP Note Assistant Unspecified Security Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100832

SANS News

 

Threatpost

Equifax Confirms March Struts Vulnerability Behind Breach

Premium SMS Malware ‘ExpensiveWall’ Infects Millions of Android Devices

Exploit

 

14.9.2017

Bugtraq

 

Malware

Exp.CVE-2017-8759

Android.Wirex

Phishing

 

Vulnerebility

MariaDB and MySQL CVE-2017-3302 Denial of Service Vulnerability
2017-09-14
http://www.securityfocus.com/bid/96162

Google Android CVE-2017-0781 Heap Buffer Overflow Vulnerability
2017-09-14
http://www.securityfocus.com/bid/100810

Google Android Broadcom components Multiple Security Vulnerabilities
2017-09-12
http://www.securityfocus.com/bid/99482

Microsoft Windows .NET Framework CVE-2017-8759 Remote Code Execution Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100742

SANS News

Another webshell, another backdoor!

Threatpost

Thousands of Elasticsearch Servers Hijacked to Host PoS Malware

Exploit

Jungo DriverWizard WinDriver <= 12.4.0 - Kernel Pool Overflow

ICLowBidAuction 3.3 - SQL Injection

ICMLM 2.1 - 'key' Parameter SQL Injection

Mako Web Server 2.5 - Multiple Vulnerabilities

13.9.2017

Bugtraq

[slackware-security] emacs (SSA:2017-255-01) 2017-09-12
Slackware Security Team (security slackware com)

[slackware-security] libzip (SSA:2017-255-02) 2017-09-12
Slackware Security Team (security slackware com)

[SECURITY] [DSA 3970-1] emacs24 security update 2017-09-12
Moritz Muehlenhoff (jmm debian org)

SEC Consult SA-20170912-0 :: Email verification bypass in SAP E-Recruiting 2017-09-12
SEC Consult Vulnerability Lab (research sec-consult com)

[slackware-security] bash (SSA:2017-251-01) 2017-09-08
Slackware Security Team (security slackware com)

[slackware-security] mariadb (SSA:2017-251-02) 2017-09-08
Slackware Security Team (security slackware com)

Malware

 

Phishing

*****CONGRATULATION*****

13th September 2017

TODAY ONLY: Your $50 Amazon
gift card

Apple ID has been locked your

13th September 2017

YOUR ACCOUNT INFORMATION

Lloyds Bank

12th September 2017

IMPORTANT ACCOUNT NOTICE
INFORMATION

Vulnerebility

Google Android Broadcom components Multiple Security Vulnerabilities
2017-09-12
http://www.securityfocus.com/bid/99482

Microsoft Windows .NET Framework CVE-2017-8759 Remote Code Execution Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100742

SAP Point of Sale (POS) Retail Xpress Server Authentication Bypass Vulnerability
2017-09-12
http://www.securityfocus.com/bid/99531

Microsoft Windows Hyper-V CVE-2017-8713 Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100796

Microsoft Windows Hyper-V CVE-2017-8712 Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100795

Microsoft Windows Hyper-V CVE-2017-8711 Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100794

Microsoft Windows CVE-2017-8710 Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100793

Microsoft Windows Kernel CVE-2017-8709 Local Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100792

Microsoft Windows Kernel CVE-2017-8708 Local Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100791

Microsoft Windows Hyper-V CVE-2017-8707 Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100790

Microsoft Windows Hyper-V CVE-2017-8706 Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100789

Microsoft Windows Hyper-V CVE-2017-8704 Remote Denial of Service Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100787

Microsoft Windows Error Reporting CVE-2017-8702 Remote Privilege Escalation Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100785

SAP Netweaver Cross Site Scripting Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100784

Microsoft Windows Shell CVE-2017-8699 Remote Code Execution Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100783

Microsoft Windows GDI+ Component CVE-2017-8684 Local Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100782

Microsoft Windows Graphics Component CVE-2017-8683 Local Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100781

Microsoft Windows Graphics Component CVE-2017-8696 Remote Code Execution Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100780

Microsoft Edge Content Security Policy CVE-2017-8754 Security Bypass Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100779

Microsoft Edge Scripting Engine CVE-2017-8755 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100778

Microsoft Edge CVE-2017-8724 Spoofing Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100777

Microsoft Edge Scripting Engine CVE-2017-8753 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100776

Microsoft Edge Scripting Engine CVE-2017-8752 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100775

Microsoft Windows Graphics Component CVE-2017-8695 Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100773

Microsoft Windows Graphics Component CVE-2017-8682 Remote Code Execution Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100772

Microsoft Internet Explorer and Edge CVE-2017-8750 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100771

Microsoft Internet Explorer CVE-2017-8749 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100770

Microsoft Windows Kernel 'Win32k.sys' CVE-2017-8678 Local Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100769

Microsoft Edge Content Security Policy CVE-2017-8723 Security Bypass Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100768

Microsoft Windows GDI+ Component CVE-2017-8677 Local Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100767
 

Microsoft Internet Explorer and Edge CVE-2017-8748 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100766

Microsoft Internet Explorer CVE-2017-8747 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100765

Microsoft Internet Explorer and Edge CVE-2017-8741 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100764

Microsoft Edge Scripting Engine CVE-2017-8740 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100763

Microsoft Windows Uniscribe CVE-2017-8692 Remote Code Execution Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100762

Microsoft Edge Scripting Engine CVE-2017-8739 Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100761

Microsoft Windows Device Guard CVE-2017-8746 Local Security Bypass Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100760

Microsoft Edge Scripting Engine CVE-2017-8738 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100759

Microsoft Office Publisher CVE-2017-8725 Remote Code Execution Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100758

Microsoft Edge Scripting Engine CVE-2017-8660 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100757

Microsoft Windows GDI+ Component CVE-2017-8688 Local Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100756

Microsoft Windows Graphics Device Interface CVE-2017-8676 Local Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100755

Microsoft Edge Scripting Engine CVE-2017-8649 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100754

Microsoft SharePoint CVE-2017-8745 Cross Site Scripting Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100753

Microsoft Windows Kernel 'Win32k.sys' CVE-2017-8675 Local Privilege Escalation Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100752

Microsoft Office CVE-2017-8631 Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100751

Microsoft Edge CVE-2017-8648 Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100750

Microsoft Windows PDF CVE-2017-8737 Remote Code Execution Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100749

Microsoft Office CVE-2017-8744 Remote Code Execution Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100748

Microsoft Edge CVE-2017-8643 Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100747

Microsoft PowerPoint CVE-2017-8743 Remote Code Execution Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100746

Microsoft Edge CVE-2017-8597 Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100745

Microsoft Windows Bluetooth Driver CVE-2017-8628 Man in the Middle Spoofing Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100744

Microsoft Internet Explorer and Edge CVE-2017-8736 Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100743

Microsoft PowerPoint CVE-2017-8742 Remote Code Execution Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100741

Microsoft Edge CVE-2017-8735 Spoofing Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100740

Microsoft Windows PDF CVE-2017-8728 Remote Code Execution Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100739

Microsoft Edge CVE-2017-8734 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100738

Microsoft Internet Explorer CVE-2017-8733 Spoofing Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100737

Microsoft Windows Kernel CVE-2017-8687 Local Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100736

Microsoft Edge CVE-2017-8731 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100735

Microsoft Office CVE-2017-8632 Remote Code Execution Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100734

Microsoft Edge Scripting Engine CVE-2017-8729 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100733

Microsoft Office CVE-2017-8630 Remote Code Execution Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100732

Microsoft Exchange Server CVE-2017-11761 Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100731

Microsoft Windows DHCP Server CVE-2017-8686 Remote Code Execution Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100730

Microsoft Edge CVE-2017-11766 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100729

Microsoft Windows NetBIOS CVE-2017-0161 Remote Code Execution Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100728

Microsoft Windows GDI+ Component CVE-2017-8681 Local Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100727

Microsoft Edge Scripting Engine CVE-2017-11764 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100726

Microsoft SharePoint Server CVE-2017-8629 Remote Privilege Escalation Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100725

Microsoft Windows GDI+ CVE-2017-8685 Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100724

Microsoft Exchange Server CVE-2017-8758 Cross Site Scripting Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100723

Microsoft Windows GDI+ Component CVE-2017-8680 Local Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100722

Microsoft Edge CVE-2017-8757 Remote Code Execution Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100721

Microsoft Windows Kernel CVE-2017-8679 Local Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100720

Microsoft Office CVE-2017-8567 Remote Code Execution Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100719

Microsoft Edge Scripting Engine CVE-2017-8756 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100718

SAP NetWeaver Adapter Engine Cache Monitor Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100717

Adobe Flash Player CVE-2017-11282 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100716

Adobe Coldfusion CVE-2017-11286 XML External Entity Information Disclosure Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100715

SAP NetWeaver 'SLC Sell Side Registration Page' Cross Site Scripting Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100714

SAP Point of Sale (POS) Retail Xpress Server Authentication Bypass Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100713

SAP Electronic Ledger Management for Turkey Cross Site Request Forgery Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100712

Adobe ColdFusion CVE-2017-11285 Unspecified Cross Site Scripting Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100711

Adobe Flash Player CVE-2017-11281 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100710

Adobe RoboHelp CVE-2017-3105 Open Redirect Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100709

Adobe ColdFusion APSB17-30 Deserialization Multiple Remote Code Execution Vulnerabilities
2017-09-12
http://www.securityfocus.com/bid/100708

Adobe RoboHelp CVE-2017-3104 Cross Site Scripting Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100707

SANS News

Microsoft Patch Tuesday September 2017

No IPv6? Challenge Accepted! (Part 1)

Threatpost

Microsoft Patches .NET Zero Day Vulnerability in September Update

Adobe Fixes Eight Vulnerabilities in Flash, RoboHelp, ColdFusion

Exploit

Trend Micro Control Manager - ImportFile Directory Traversal RCE (Metasploit)

ZScada Modbus Buffer 2.0 - Stack-Based Buffer Overflow (Metasploit)

Viap Automation WinPLC7 5.0.45.5921 - Recv Buffer Overflow (Metasploit)

Sielco Sistemi Winlog 2.07.16 - Buffer Overflow (Metasploit)

Alienvault Open Source SIEM (OSSIM) < 4.8.0 - 'get_file' Information Disclosure...

Motorola Netopia Netoctopus SDCS - Stack Buffer Overflow (Metasploit)

Jungo DriverWizard WinDriver <= 12.4.0 - Kernel Pool Overflow

WebKit JSC - 'BytecodeGenerator::emitGetByVal' Incorrect Optimization

Mako Web Server 2.5 - Multiple Vulnerabilities

ICLowBidAuction 3.3 - SQL Injection

ICMLM 2.1 - 'key' Parameter SQL Injection

ICHotelReservation 3.3 - 'key' Parameter SQL Injection

ICAuction 2.2 - 'id' Parameter SQL Injection

ICDoctor Appointment 1.3 - 'key' Parameter SQL Injection

ICRestaurant software 1.4 - 'key' Parameter SQL Injection

ICDutchAuction 1.2 - SQL Injection

12.9.2017

Bugtraq

 

Malware

 

Phishing

Lloyds Bank

12th September 2017

IMPORTANT ACCOUNT NOTICE
INFORMATION

Amazon Customer Service

11th September 2017

AMAZON - TAKE OUR 60 SEC
SURVEY FOR A CHANCE TO WIN A
$1,000 SHOPPING SPREE ON US!

Vulnerebility

SAP Electronic Ledger Management for Turkey Cross Site Request Forgery Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100712

Adobe ColdFusion CVE-2017-11285 Unspecified Cross Site Scripting Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100711

Adobe Flash Player CVE-2017-11281 Remote Memory Corruption Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100710

Adobe RoboHelp CVE-2017-3105 Open Redirect Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100709

Adobe ColdFusion APSB17-30 Deserialization Multiple Remote Code Execution Vulnerabilities
2017-09-12
http://www.securityfocus.com/bid/100708

Adobe RoboHelp CVE-2017-3104 Cross Site Scripting Vulnerability
2017-09-12
http://www.securityfocus.com/bid/100707

Apache Struts CVE-2017-9805 Remote Code Execution Vulnerability
2017-09-10
http://www.securityfocus.com/bid/100609

Apache Struts CVE-2017-9793 Denial of Service Vulnerability
2017-09-10
http://www.securityfocus.com/bid/100611

Apache Struts CVE-2017-9804 Incomplete Fix Denial of Service Vulnerability
2017-09-10
http://www.securityfocus.com/bid/100612

FFmpeg 'libavutil/pixdesc.c' NULL pointer Dereference Remote Denial of Service Vulnerability
2017-09-09
http://www.securityfocus.com/bid/100704

EMC AppSync CVE-2017-8015 SQL Injection Vulnerability
2017-09-09
http://www.securityfocus.com/bid/100683

Openswan IKEv2 payloads Remote Denial Of Service Vulnerability
2017-09-08
http://www.securityfocus.com/bid/65155

FFmpeg 'libavformat/asfdec_f.c' Denial of Service Vulnerability
2017-09-08
http://www.securityfocus.com/bid/100703

ImageMagick CVE-2017-14224 Heap Buffer Overflow Vulnerability
2017-09-08
http://www.securityfocus.com/bid/100702

FFmpeg 'libavformat/mov.c' Denial of Service Vulnerability
2017-09-08
http://www.securityfocus.com/bid/100701

IBM DB2 CVE-2017-1520 Security Bypass Vulnerability
2017-09-08
http://www.securityfocus.com/bid/100684

Das U-Boot Security Weakness and Information Disclosure Vulnerabilities
2017-09-08
http://www.securityfocus.com/bid/100675

Oracle Java SE CVE-2017-10089 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/99659

Oracle Database Server CVE-2012-1746 Remote Network Layer Vulnerability
2017-09-07
http://www.securityfocus.com/bid/54507

Oracle Java SE CVE-2017-10087 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/99703

Mahara Resume Blocktype Cross Site Scripting Vulnerability
2017-09-07
http://www.securityfocus.com/bid/36892

Oracle CVE-2010-3534 Local Primavera P6 Enterprise Project Portfolio Management
2017-09-07
http://www.securityfocus.com/bid/44019

Oracle Document Capture CVE-2010-3592 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45871

Oracle Transportation Manager CVE-2010-4432 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45875

Mahara Admin Password Reset Security Bypass Vulnerability
2017-09-07
http://www.securityfocus.com/bid/36893

Oracle Fusion Middleware CVE-2010-3501 Remote OID Vulnerability
2017-09-07
http://www.securityfocus.com/bid/43995

Oracle Supply Chain Product CVE-2010-4429 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45860

Oracle Supply Chain Product CVE-2010-3505 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45872

Oracle Oracle Enterprise Manager Grid Control CVE-2011-0875 Remote EMCTL Vulnerability
2017-09-07
http://www.securityfocus.com/bid/48760

Oracle Sun Java System Portal Server CVE-2010-4431 Local Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45898

SANS News

 

Threatpost

FreeXL Library Fixes Two Remote Code Execution Vulnerabilities


Apache Foundation Refutes Involvement in Equifax Breach

Exploit

tcprewrite - Heap-Based Buffer Overflow

PHP Dashboards NEW 4.4 - Arbitrary File Read

PHP Dashboards NEW 4.4 - SQL Injection

JobStar Monster Clone Script 1.0 - SQL Injection

iTech Book Store Script 2.02 - SQL Injection

Docker Daemon - Unprotected TCP Socket (Metasploit)

Nimble Professional 1.0 - Cross-Site Request Forgery (Update Admin)

FiberHome ADSL AN1020-25 - Improper Access Restrictions

WiseGiga NAS - Multiple Vulnerabilities

11.9.2017

Bugtraq

 

Malware

 

Phishing

Amazon Customer Service

11th September 2017

AMAZON - TAKE OUR 60 SEC
SURVEY FOR A CHANCE TO WIN A
$1,000 SHOPPING SPREE ON US!

kaminanga on behalf of Bank C

9th September 2017

You recieved money on your
account!

iTunes

9th September 2017

NEW STATEMENT RECEIPT ORDER ID
: IN63483482469 DOCUMENT NO
:575255676567

Vulnerebility

Apache Struts CVE-2017-9805 Remote Code Execution Vulnerability
2017-09-10
http://www.securityfocus.com/bid/100609

Apache Struts CVE-2017-9793 Denial of Service Vulnerability
2017-09-10
http://www.securityfocus.com/bid/100611

Apache Struts CVE-2017-9804 Incomplete Fix Denial of Service Vulnerability
2017-09-10
http://www.securityfocus.com/bid/100612

Openswan IKEv2 payloads Remote Denial Of Service Vulnerability
2017-09-08
http://www.securityfocus.com/bid/65155

Das U-Boot Security Weakness and Information Disclosure Vulnerabilities
2017-09-08
http://www.securityfocus.com/bid/100675

Oracle Java SE CVE-2017-10089 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/99659

Oracle Database Server CVE-2012-1746 Remote Network Layer Vulnerability
2017-09-07
http://www.securityfocus.com/bid/54507

Oracle Java SE CVE-2017-10087 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/99703

Mahara Resume Blocktype Cross Site Scripting Vulnerability
2017-09-07
http://www.securityfocus.com/bid/36892

Oracle CVE-2010-3534 Local Primavera P6 Enterprise Project Portfolio Management
2017-09-07
http://www.securityfocus.com/bid/44019

Oracle Document Capture CVE-2010-3592 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45871

Oracle Transportation Manager CVE-2010-4432 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45875

Mahara Admin Password Reset Security Bypass Vulnerability
2017-09-07
http://www.securityfocus.com/bid/36893

Oracle Fusion Middleware CVE-2010-3501 Remote OID Vulnerability
2017-09-07
http://www.securityfocus.com/bid/43995

Oracle Supply Chain Product CVE-2010-4429 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45860

Oracle Supply Chain Product CVE-2010-3505 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45872

Oracle Oracle Enterprise Manager Grid Control CVE-2011-0875 Remote EMCTL Vulnerability
2017-09-07
http://www.securityfocus.com/bid/48760

Oracle Sun Java System Portal Server CVE-2010-4431 Local Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45898

Oracle Sun Solaris CVE-2011-3542 Local Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50244

Oracle PeopleSoft Enterprise FIN CVE-2011-2250 Remote PeopleSoft Enterprise FIN Vulnerability
2017-09-07
http://www.securityfocus.com/bid/48778

Oracle Sun Solaris CVE-2010-3586 Local Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45903

Oracle PeopleSoft Products CVE-2011-3533 Remote PeopleSoft Enterprise HRMS Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50249

Oracle Spatial CVE-2010-3590 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45880

Oracle PeopleSoft Products CVE-2011-2315 Remote PeopleSoft Enterprise PeopleTools Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50263

Oracle Fusion Middleware CVE-2012-0522 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53053

Oracle Outside In Technology CVE-2012-0557 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53054

Oracle Sun Products Suite CVE-2011-3507 Remote Oracle Communications Unified Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50264

Oracle E-Business Suite CVE-2012-0513 Remote Oracle Application Object Library Vulnerabilty
2017-09-07
http://www.securityfocus.com/bid/53055

Oracle PeopleSoft CVE-2011-3529 Remote PeopleSoft Enterprise HRMS Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50267

Oracle Sun Products Suite CVE-2011-2292 Local Solaris Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50268

SANS News

Windows Auditing with WINspect

Threatpost

Popular D-Link Router Riddled with Vulnerabilities

Exploit

Linux/ARM (Raspberry Pi) - Reverse TCP Shell (192.168.0.12:4444/TCP) Shellcode (160...

Linux/ARM (Raspberry Pi) - Bind TCP Shell (4444/TCP) Shellcode (192 bytes)

Escort Marketplace 1.0 - SQL Injection

Babysitter Website Script 1.0 - SQL Injection

Job Board Software 1.0 - SQL Injection

RPi Cam Control <= 6.3.14 - Multiple Vulnerabilities

Just Dial Marketplace 1.0 - SQL Injection

Online Print Business 1.0 - SQL Injection

Professional Service Booking 1.0 - SQL Injection

10.9.2017

Bugtraq

[SECURITY] [DSA 3967-1] mbedtls security update 2017-09-08
Salvatore Bonaccorso (carnil debian org)

Pwning the Dlink 850L routers and abusing the MyDlink Cloud protocol 2017-09-07
Pierre Kim (pierre kim sec gmail com)

August 2017 - SourceTree - Critical Security Advisory 2017-09-06
David Black (dblack atlassian com)

Malware

 

Phishing

Outlook.com team

9th September 2017

Re-confirm Your E-mail
paulhammon@hotmail.com

iTunes Store

8th September 2017

NEW STATMENT RECEIPT ORDER ID
: IN83486438369 DOCUMENT NO
:165153293544
 

Vulnerebility

Openswan IKEv2 payloads Remote Denial Of Service Vulnerability
2017-09-08
http://www.securityfocus.com/bid/65155

Das U-Boot Security Weakness and Information Disclosure Vulnerabilities
2017-09-08
http://www.securityfocus.com/bid/100675

Oracle Java SE CVE-2017-10089 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/99659

Oracle Database Server CVE-2012-1746 Remote Network Layer Vulnerability
2017-09-07
http://www.securityfocus.com/bid/54507

Oracle Java SE CVE-2017-10087 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/99703

Mahara Resume Blocktype Cross Site Scripting Vulnerability
2017-09-07
http://www.securityfocus.com/bid/36892

Oracle CVE-2010-3534 Local Primavera P6 Enterprise Project Portfolio Management
2017-09-07
http://www.securityfocus.com/bid/44019

Oracle Document Capture CVE-2010-3592 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45871

Oracle Transportation Manager CVE-2010-4432 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45875

Mahara Admin Password Reset Security Bypass Vulnerability
2017-09-07
http://www.securityfocus.com/bid/36893

Oracle Fusion Middleware CVE-2010-3501 Remote OID Vulnerability
2017-09-07
http://www.securityfocus.com/bid/43995

Oracle Supply Chain Product CVE-2010-4429 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45860

Oracle Supply Chain Product CVE-2010-3505 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45872

Oracle Oracle Enterprise Manager Grid Control CVE-2011-0875 Remote EMCTL Vulnerability
2017-09-07
http://www.securityfocus.com/bid/48760

Oracle Sun Java System Portal Server CVE-2010-4431 Local Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45898

Oracle Sun Solaris CVE-2011-3542 Local Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50244

Oracle PeopleSoft Enterprise FIN CVE-2011-2250 Remote PeopleSoft Enterprise FIN Vulnerability
2017-09-07
http://www.securityfocus.com/bid/48778

Oracle Sun Solaris CVE-2010-3586 Local Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45903

Oracle PeopleSoft Products CVE-2011-3533 Remote PeopleSoft Enterprise HRMS Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50249

Oracle Spatial CVE-2010-3590 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45880

Oracle PeopleSoft Products CVE-2011-2315 Remote PeopleSoft Enterprise PeopleTools Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50263

Oracle Fusion Middleware CVE-2012-0522 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53053

Oracle Outside In Technology CVE-2012-0557 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53054

Oracle Sun Products Suite CVE-2011-3507 Remote Oracle Communications Unified Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50264

Oracle E-Business Suite CVE-2012-0513 Remote Oracle Application Object Library Vulnerabilty
2017-09-07
http://www.securityfocus.com/bid/53055

Oracle PeopleSoft CVE-2011-3529 Remote PeopleSoft Enterprise HRMS Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50267

Oracle Sun Products Suite CVE-2011-2292 Local Solaris Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50268

Oracle Outside In Technology CVE-2012-0555 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53070

Oracle Database Server CVE-2012-0519 Remote Core RDBMS Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53072

Oracle Identity Manager CVE-2012-0532 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53060

SANS News

YASRV (Yet Another Struts RCE Vulnerability) yes a different one from yesterday

Malware analysis output sanitization

Threatpost

Android Users Vulnerable to ‘High-Severity’ Overlay Attacks

Exploit

 

8.9.2017

Bugtraq

Pwning the Dlink 850L routers and abusing the MyDlink Cloud protocol 2017-09-07
Pierre Kim (pierre kim sec gmail com)

August 2017 - SourceTree - Critical Security Advisory 2017-09-06
David Black (dblack atlassian com)

[SECURITY] [DSA 3965-1] file security update 2017-09-05
Salvatore Bonaccorso (carnil debian org)

Malware

VBS.Forbiks

Phishing

**Amazon Prime** _

7th September 2017

***Final Notice: Amazon
Rewards expiring soon!** _

ANZ BANK

7th September 2017

CUSTOMER SUPPORT SECURITY
NOTIFICATION

ANZ BANK

6th September 2017

ACCOUNT SECURITY NOTIFICATION

Vulnerebility

Openswan IKEv2 payloads Remote Denial Of Service Vulnerability
2017-09-08
http://www.securityfocus.com/bid/65155

Oracle Java SE CVE-2017-10089 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/99659

Oracle Database Server CVE-2012-1746 Remote Network Layer Vulnerability
2017-09-07
http://www.securityfocus.com/bid/54507

Oracle Java SE CVE-2017-10087 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/99703

Mahara Resume Blocktype Cross Site Scripting Vulnerability
2017-09-07
http://www.securityfocus.com/bid/36892

Oracle CVE-2010-3534 Local Primavera P6 Enterprise Project Portfolio Management
2017-09-07
http://www.securityfocus.com/bid/44019

Oracle Document Capture CVE-2010-3592 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45871

Oracle Transportation Manager CVE-2010-4432 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45875

Mahara Admin Password Reset Security Bypass Vulnerability
2017-09-07
http://www.securityfocus.com/bid/36893

Oracle Fusion Middleware CVE-2010-3501 Remote OID Vulnerability
2017-09-07
http://www.securityfocus.com/bid/43995

Oracle Supply Chain Product CVE-2010-4429 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45860

Oracle Supply Chain Product CVE-2010-3505 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45872

Oracle Oracle Enterprise Manager Grid Control CVE-2011-0875 Remote EMCTL Vulnerability
2017-09-07
http://www.securityfocus.com/bid/48760

Oracle Sun Java System Portal Server CVE-2010-4431 Local Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45898

Oracle Sun Solaris CVE-2011-3542 Local Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50244

Oracle PeopleSoft Enterprise FIN CVE-2011-2250 Remote PeopleSoft Enterprise FIN Vulnerability
2017-09-07
http://www.securityfocus.com/bid/48778

Oracle Sun Solaris CVE-2010-3586 Local Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45903

Oracle PeopleSoft Products CVE-2011-3533 Remote PeopleSoft Enterprise HRMS Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50249

Oracle Spatial CVE-2010-3590 Remote Security Vulnerability
2017-09-07
http://www.securityfocus.com/bid/45880

Oracle PeopleSoft Products CVE-2011-2315 Remote PeopleSoft Enterprise PeopleTools Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50263

Oracle Fusion Middleware CVE-2012-0522 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53053

Oracle Outside In Technology CVE-2012-0557 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53054

Oracle Sun Products Suite CVE-2011-3507 Remote Oracle Communications Unified Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50264

Oracle E-Business Suite CVE-2012-0513 Remote Oracle Application Object Library Vulnerabilty
2017-09-07
http://www.securityfocus.com/bid/53055

Oracle PeopleSoft CVE-2011-3529 Remote PeopleSoft Enterprise HRMS Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50267

Oracle Sun Products Suite CVE-2011-2292 Local Solaris Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50268

Oracle Outside In Technology CVE-2012-0555 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53070

Oracle Database Server CVE-2012-0519 Remote Core RDBMS Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53072

Oracle Identity Manager CVE-2012-0532 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53060

Oracle E-Business Suite CVE-2012-0542 Remote Oracle iStore Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53068

SANS News

Equifax breach

YASRV (Yet Another Struts RCE Vulnerability) yes a different one from yesterday

Threatpost

New Dridex Phishing Campaign Delivers Fake Accounting Invoices

Microsoft Won’t Fix Security Bypass Vulnerability in Edge

Exploit

EzBan 5.3 - 'id' Parameter SQL Injection

EzInvoice 6.02 - SQL Injection

Roteador Wireless Intelbras WRN150 - Cross-Site Scripting

Huawei HG255s - Directory Traversal

7.9.2017

Bugtraq

August 2017 - SourceTree - Critical Security Advisory 2017-09-06
David Black (dblack atlassian com)

[SECURITY] [DSA 3965-1] file security update 2017-09-05
Salvatore Bonaccorso (carnil debian org)

[security bulletin] HPESBUX03772 rev.1 - HP-UX BIND Service Running Named, Multiple Vulnerabilities 2017-09-05
security-alert hpe com

CVE-2017-11567 Mongoose Web Server v6.5 CSRF Command Execution ( apparitionsec @ gmail / hyp3rlinx ) 2017-09-05
apparitionsec gmail com

Malware

 

Phishing

ANZ BANK

7th September 2017

CUSTOMER SUPPORT SECURITY
NOTIFICATION

ANZ BANK

6th September 2017

ACCOUNT SECURITY NOTIFICATION

iTunes Payments

5th September 2017

[NEW STATMENT RECIPT] YOUR
ORDER IS COMFIRMED ORDER ID :
IN83486432569,DOCUMENT NO
:165153576544

Vulnerebility

Oracle PeopleSoft Products CVE-2011-2315 Remote PeopleSoft Enterprise PeopleTools Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50263

Oracle Fusion Middleware CVE-2012-0522 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53053

Oracle Outside In Technology CVE-2012-0557 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53054

Oracle Sun Products Suite CVE-2011-3507 Remote Oracle Communications Unified Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50264

Oracle E-Business Suite CVE-2012-0513 Remote Oracle Application Object Library Vulnerabilty
2017-09-07
http://www.securityfocus.com/bid/53055

Oracle PeopleSoft CVE-2011-3529 Remote PeopleSoft Enterprise HRMS Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50267

Oracle Sun Products Suite CVE-2011-2292 Local Solaris Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50268

Oracle Outside In Technology CVE-2012-0555 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53070

Oracle Database Server CVE-2012-0519 Remote Core RDBMS Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53072

Oracle Identity Manager CVE-2012-0532 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53060

Oracle E-Business Suite CVE-2012-0542 Remote Oracle iStore Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53068

Oracle E-Business Suite CVE-2012-0537 Remote Oracle Application Object Library Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53066

Oracle E-Business Suite CVE-2012-0535 Remote Oracle Application Object Library Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53059

Oracle Outside In Technology CVE-2012-0554 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53069

Oracle Outside In Technology CVE-2012-0556 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53087

Oracle Database Server CVE-2012-1708 Remote Application Express Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53104

Oracle Database Server CVE-2012-0520 Remote Enterprise Manager Base Platform Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53081

Oracle FLEXCUBE Universal Bank CVE-2012-0571 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53103

Oracle BI Publisher CVE-2012-0543 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53083

Oracle FLEXCUBE Direct Banking CVE-2012-1707 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53107

Oracle Identity Manager Connector CVE-2012-0515 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53079

Oracle FLEXCUBE Universal Banking CVE-2012-0567 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53114

Oracle FLEXCUBE Universal Banking CVE-2012-0545 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53122

Oracle FLEXCUBE Universal Banking CVE-2012-0575 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53111

Oracle FLEXCUBE Direct Banking CVE-2012-0576 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53113

Oracle FLEXCUBE Direct Banking CVE-2012-1706 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53116

Oracle Solaris CVE-2012-1698 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53128

Oracle FLEXCUBE Universal Banking CVE-2012-0546 Remote Vulnerability
2017-09-07
http://www.securityfocus.com/bid/53108

Oracle E-Business Suite CVE-2011-2303 Remote Oracle Application Object Library Vulnerability
2017-09-07
http://www.securityfocus.com/bid/50225

Oracle Supply Chain Products Suite CVE-2011-3532 Remote Oracle Agile Product Supplier Collaboration
2017-09-07
http://www.securityfocus.com/bid/50227

SANS News

Modern Web Application Penetration Testing , Hash Length Extension Attacks

Threatpost

Tor Project Brings Security Slider Feature to Android App Orfox

IDN Homograph Attack Spreading Betabot Backdoor

13 Critical Remote Code Execution Bugs Fixed in September Android Update

Exploit

Apache Struts 2.5 - Remote Code Execution

Ultimate HR System <= 1.2 - Directory Traversal / Cross-Site Scripting

Gh0st Client - Buffer Overflow (Metasploit)

Ultimate HR System <= 1.2 - Directory Traversal / Cross-Site Scripting

Online Invoice System 3.0 - SQL Injection

6.9.2017

Bugtraq

August 2017 - SourceTree - Critical Security Advisory 2017-09-06
David Black (dblack atlassian com)

[SECURITY] [DSA 3965-1] file security update 2017-09-05
Salvatore Bonaccorso (carnil debian org)

[security bulletin] HPESBUX03772 rev.1 - HP-UX BIND Service Running Named, Multiple Vulnerabilities 2017-09-05
security-alert hpe com

CVE-2017-11567 Mongoose Web Server v6.5 CSRF Command Execution ( apparitionsec @ gmail / hyp3rlinx ) 2017-09-05
apparitionsec gmail com

Wibu Systems AG CodeMeter 6.50 - Persistent XSS Vulnerability 2017-09-04
Vulnerability Lab (research vulnerability-lab com)

[SECURITY] [DSA 3963-1] mercurial security update 2017-09-04
Sebastien Delafond (seb debian org)

Malware

 

Phishing

 

Vulnerebility

Apache Struts CVE-2017-9805 Remote Code Execution Vulnerability
2017-09-06
http://www.securityfocus.com/bid/100609

TYPO3 'fileDenyPattern' Arbitrary Code Execution Vulnerability
2017-09-06
http://www.securityfocus.com/bid/100620

GNU glibc CVE-2017-1000366 Local Memory Corruption Vulnerability
2017-09-05
http://www.securityfocus.com/bid/99127

Sudo CVE-2017-1000368 Incomplete Fix Local Privilege Escalation Vulnerability
2017-09-05
http://www.securityfocus.com/bid/98838

Linux Kernel CVE-2017-1000364 Local Memory Corruption Vulnerability
2017-09-05
http://www.securityfocus.com/bid/99130

Linux Kernel 'net/ipv6/output_core.c' Local Denial of Service Vulnerability
2017-09-05
http://www.securityfocus.com/bid/99953

Oracle Java SE CVE-2017-10193 Remote Security Vulnerability
2017-09-05
http://www.securityfocus.com/bid/99854

TYPO3 Information Disclosure Vulnerability
2017-09-05
http://www.securityfocus.com/bid/100621

TYPO3 Unspecified Cross Site Scripting Vulnerability
2017-09-05
http://www.securityfocus.com/bid/100616

Apache Struts CVE-2017-9804 Incomplete Fix Denial of Service Vulnerability
2017-09-05
http://www.securityfocus.com/bid/100612

Apache Struts CVE-2017-9793 Denial of Service Vulnerability
2017-09-05
http://www.securityfocus.com/bid/100611

Google Chrome Prior to 61.0.3163.79 Multiple Security Vulnerabilities
2017-09-05
http://www.securityfocus.com/bid/100610

TYPO3 User Permission Handling Information Disclosure Vulnerability
2017-09-05
http://www.securityfocus.com/bid/100568

GNU Binutils CVE-2017-14130 Heap Buffer Overflow Vulnerability
2017-09-04
http://www.securityfocus.com/bid/100625

OpenJPEG CVE-2017-14040 Memory Corruption Vulnerability
2017-09-01
http://www.securityfocus.com/bid/100553

OpenJPEG 'bin/jp2/convert.c' Remote Stack Based Buffer Overflow Vulnerability
2017-09-01
http://www.securityfocus.com/bid/100555

OpenJPEG 'mqc.c' Remote Heap Based Buffer Overflow Vulnerability
2017-09-01
http://www.securityfocus.com/bid/100564

RubyGems CVE-2017-0901 Local Arbitrary File Overwrite Vulnerability
2017-09-01
http://www.securityfocus.com/bid/100580

RubyGems CVE-2017-0900 Denial of Service Vulnerability
2017-09-01
http://www.securityfocus.com/bid/100579

Openstack instack-undercloud CVE-2017-7549 Insecure Temporary File Handling Vulnerability
2017-08-31
http://www.securityfocus.com/bid/100407

FasterXML Jackson-databind CVE-2017-7525 Deserialization Remote Code Execution Vulnerability
2017-08-31
http://www.securityfocus.com/bid/99623

Apache Batik CVE-2017-5662 XML External Entity Information Disclosure Vulnerability
2017-08-31
http://www.securityfocus.com/bid/97948

FFmpeg CVE-2017-14058 Denial of Service Vulnerability
2017-08-31
http://www.securityfocus.com/bid/100629

FFmpeg CVE-2017-14056 Denial of Service Vulnerability
2017-08-31
http://www.securityfocus.com/bid/100628

FFmpeg 'libavformat/rmdec.c' Denial of Service Vulnerability
2017-08-31
http://www.securityfocus.com/bid/100627

FFmpeg CVE-2017-14055 Denial of Service Vulnerability
2017-08-31
http://www.securityfocus.com/bid/100626

Palo Alto Networks PAN-OS CVE-2017-12416 Cross Site Scripting Vulnerability
2017-08-31
http://www.securityfocus.com/bid/100619

Pivotal Single Sign-On for PCF CVE-2017-8044 Cross Site Scripting Vulnerability
2017-08-31
http://www.securityfocus.com/bid/100618

Pivotal Single Sign-On for PCF CVE-2017-8040 XML External Entity Injection Vulnerability
2017-08-31
http://www.securityfocus.com/bid/100617

Pivotal Single Sign-On for PCF CVE-2017-8041 Cross Site Scripting Vulnerability
2017-08-31
http://www.securityfocus.com/bid/100615

SANS News

Struts vulnerability patch released by apache, patch now

The Mirai Botnet: A Look Back and Ahead At What's Next

Threatpost

Patch Released for Critical Apache Struts Bug

Four Million Time Warner Cable Records Left on Misconfigured AWS S3

Military Contractor’s Vendor Leaks Resumes in Misconfigured AWS S3

Exploit

Cory Support - 'pr' Parameter SQL Injection

Advertiz PHP Script 0.2 - Cross-Site Request Forgery (Update Admin)

Pay Banner Text Link Ad 1.0.6.1 - Cross-Site Request Forgery (Update Admin)

Pay Banner Text Link Ad 1.0.6.1 - SQL Injection

Jungo DriverWizard WinDriver - Kernel Pool Overflow

Jungo DriverWizard WinDriver - Kernel Out-of-Bounds Write Privilege Escalation

Tor - Linux Sandbox Breakout via X11

Mongoose Web Server 6.5 - Cross-Site Request Forgery / Remote Code Execution

A2billing 2.x - Backup File Download / Remote Code Execution

iGreeting Cards 1.0 - SQL Injection

WordPress Plugin Participants Database < 1.7.5.10 - Cross-Site Scripting

The Car Project 1.0 - SQL Injection

5.9.2017

Bugtraq

CVE-2017-11567 Mongoose Web Server v6.5 CSRF Command Execution ( apparitionsec @ gmail / hyp3rlinx ) 2017-09-05
apparitionsec gmail com

Wibu Systems AG CodeMeter 6.50 - Persistent XSS Vulnerability 2017-09-04
Vulnerability Lab (research vulnerability-lab com)

[SECURITY] [DSA 3963-1] mercurial security update 2017-09-04
Sebastien Delafond (seb debian org)

[SECURITY] [DSA 3962-1] strongswan security update 2017-09-03
Yves-Alexis Perez (corsac debian org)

[SECURITY] [DSA 3961-1] libgd2 security update 2017-09-03
Salvatore Bonaccorso (carnil debian org)

[security bulletin] HPESBGN03765 rev.2 - HPE LoadRunner and HPE Performance Center, Remote Disclosure of Information 2017-08-31
security-alert hpe com

[security bulletin] HPESBGN03767 rev.1 - HPE Operations Orchestration, Remote Code Execution 2017-08-31
security-alert hpe com

[SECURITY] [DSA 3957-1] ffmpeg security update 2017-08-28
Luciano Bello (luciano debian org)

Malware

 

Phishing

iTunes Payments

5th September 2017

[NEW STATMENT RECIPT] YOUR
ORDER IS COMFIRMED ORDER ID :
IN83486432569,DOCUMENT NO
:165153576544

NotificationFacebook

4th September 2017

Your 2 unread messages will be
deleted in a few days flirt

Vulnerebility

Linux Kernel 'net/ipv6/output_core.c' Local Denial of Service Vulnerability
2017-09-05
http://www.securityfocus.com/bid/99953

Oracle Java SE CVE-2017-10193 Remote Security Vulnerability
2017-09-05
http://www.securityfocus.com/bid/99854

OpenJPEG CVE-2017-14040 Memory Corruption Vulnerability
2017-09-01
http://www.securityfocus.com/bid/100553

OpenJPEG 'bin/jp2/convert.c' Remote Stack Based Buffer Overflow Vulnerability
2017-09-01
http://www.securityfocus.com/bid/100555

OpenJPEG 'mqc.c' Remote Heap Based Buffer Overflow Vulnerability
2017-09-01
http://www.securityfocus.com/bid/100564

RubyGems CVE-2017-0901 Local Arbitrary File Overwrite Vulnerability
2017-09-01
http://www.securityfocus.com/bid/100580

SANS News

It is a resume - Part 2

The Mirai Botnet: A Look Back and Ahead At What's Next

Threatpost

 

Exploit

Mongoose Web Server 6.5 - Cross-Site Request Forgery / Remote Code Execution

A2billing 2.x - Backup File Download / Remote Code Execution

iGreeting Cards 1.0 - SQL Injection

WordPress Plugin Participants Database < 1.7.5.10 - Cross-Site Scripting

The Car Project 1.0 - SQL Injection

Joomla! Component Survey Force Deluxe 3.2.4 - 'invite' Parameter SQL Injection

4.9.2017

Bugtraq

 

Malware

 

Phishing

MBNA Credit Card

4th September 2017

Your Lastest MBNA credit card
statement

Vulnerebility

 

SANS News

It is a resume - Part 1

Threatpost

 

Exploit

FineCMS 1.0 - Multiple Vulnerabilities

Lotus Notes Diagnostic Tool 8.5/9.0 - Privilege Escalation

IBM Notes 8.5.x/9.0.x - Denial of Service (2)

IBM Notes 8.5.x/9.0.x - Denial of Service

Wireless Repeater BE126 - Remote Code Execution

Symantec Messaging Gateway < 10.6.3-267 - Cross-Site Request Forgery

Wireless Repeater BE126 - Remote Code Execution

RubyGems < 2.6.13 - Arbitrary File Overwrite

Dup Scout Enterprise 9.9.14 - 'Input Directory' Local Buffer Overflow

3.9.2017

Bugtraq

 

Malware

 

Phishing

DocuSign

2nd September 2017

Docusign Notifications-

Accounts

1st September 2017

You have 2 unread messages
that will be deleted in a few
days satisfied

Nationwide

30th August 2017

Online Account Disabled:
30/08/2017

Vulnerebility

OpenJPEG CVE-2017-14040 Memory Corruption Vulnerability
2017-09-01
http://www.securityfocus.com/bid/100553

OpenJPEG 'bin/jp2/convert.c' Remote Stack Based Buffer Overflow Vulnerability
2017-09-01
http://www.securityfocus.com/bid/100555

OpenJPEG 'mqc.c' Remote Heap Based Buffer Overflow Vulnerability
2017-09-01
http://www.securityfocus.com/bid/100564

RubyGems CVE-2017-0901 Local Arbitrary File Overwrite Vulnerability
2017-09-01
http://www.securityfocus.com/bid/100580

RubyGems CVE-2017-0900 Denial of Service Vulnerability
2017-09-01
http://www.securityfocus.com/bid/100579

Openstack instack-undercloud CVE-2017-7549 Insecure Temporary File Handling Vulnerability
2017-08-31
http://www.securityfocus.com/bid/100407

FasterXML Jackson-databind CVE-2017-7525 Deserialization Remote Code Execution Vulnerability
2017-08-31
http://www.securityfocus.com/bid/99623

Apache Batik CVE-2017-5662 XML External Entity Information Disclosure Vulnerability
2017-08-31
http://www.securityfocus.com/bid/97948

RubyGems CVE-2017-0899 Security Bypass Vulnerability
2017-08-31
http://www.securityfocus.com/bid/100576

Siemens 7KM PAC Switched Ethernet PROFINET Expansion Module Denial of Service Vulnerability
2017-08-31
http://www.securityfocus.com/bid/100562

Multiple Siemens Products CVE-2017-12069 XML External Entity Injection Vulnerability
2017-08-31
http://www.securityfocus.com/bid/100559

Multiple Automated Logic Corporation CVE-2016-5795 XML External Entity Injection Vulnerability
2017-08-31
http://www.securityfocus.com/bid/100558

Moxa SoftCMS CVE-2017-50137 SQL Injection Vulnerability
2017-08-31
http://www.securityfocus.com/bid/100557

libgcrypt CVE-2017-0379 Information Disclosure Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100503

GraphicsMagick CVE-2017-13777 Denial of Service Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100575

GraphicsMagick CVE-2017-13776 Denial of Service Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100574

OpenJPEG 'pi.c' Divide-By-Zero Multiple Denial of Service Vulnerabilities
2017-08-30
http://www.securityfocus.com/bid/100573

Linux Kernel CVE-2017-14051 Local Integer Overflow Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100571

GraphicsMagick CVE-2017-13775 Denial of Service Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100570

ImageMagick CVE-2017-13768 Denial of Service Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100569

OpenJPEG CVE-2016-10507 Local Integer Overflow Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100567

Multiple OPW Products ICSA-17-243-04 SQL Injection and Authentication Bypass Vulnerabilities
2017-08-30
http://www.securityfocus.com/bid/100563

Siemens LOGO!8 BM CVE-2017-12735 Man in the Middle Security Bypass Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100561

Siemens LOGO!8 BM CVE-2017-12734 Information Disclosure Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100560

Drupal H5P module Module DRUPAL-SA-CONTRIB-2017-071 Cross Site Scripting Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100548

Ledger CLI CVE-2017-2808 Remote Code Execution Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100546

Wireshark Modbus Dissector CVE-2017-13764 Denial of Service Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100545

Drupal 'Commerce Invoices' Module SQL Injection and Cross-Site Scripting Vulnerabilities
2017-08-30
http://www.securityfocus.com/bid/100544

Ledger CLI CVE-2017-2807 Remote Code Execution Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100543

gdk-pixbuf Integer Overflow and Heap Based Buffer Overflow Vulnerabilities
2017-08-30
http://www.securityfocus.com/bid/100541

SANS News

AutoIT based malware back in the wild

Threatpost

‘HoeflerText’ Popups Target Browsers With RAT and Locky Ransomware

No Fix Planned For LabVIEW Bug, Says National Instruments


US Government Site Was Hosting Ransomware

Exploit

Motorola Bootloader - Kernel Cmdline Injection Secure Boot and Device Locking Bypass

OpenJPEG - 'mqc.c' Heap-Based Buffer Overflow

FineCMS 1.0 - Multiple Vulnerabilities

IBM Notes 8.5.x/9.0.x - Denial of Service

1.9.2017

Bugtraq

[security bulletin] HPESBGN03765 rev.2 - HPE LoadRunner and HPE Performance Center, Remote Disclosure of Information 2017-08-31
security-alert hpe com

[security bulletin] HPESBGN03767 rev.1 - HPE Operations Orchestration, Remote Code Execution 2017-08-31
security-alert hpe com

[SECURITY] [DSA 3957-1] ffmpeg security update 2017-08-28
Luciano Bello (luciano debian org)

[security bulletin] HPESBHF03770 rev.1 - HPE Comware 7 MSR Routers using PHP, Go, Apache Http Server, and Tomcat, Remote Arbitrary Code Execution 2017-08-28
HPE Product Security Response Team (security-alert hpe com)

[SECURITY] [DSA 3956-1] connman security update 2017-08-27
Luciano Bello (luciano debian org)

Malware

Backdoor.Vodiboti

Ransom.Lukitus

Trojan.Turbear

Trojan.Downblocker

Phishing

Accounts

1st September 2017

You have 2 unread messages
that will be deleted in a few
days satisfied

Nationwide

30th August 2017

Online Account Disabled:
30/08/2017

Vulnerebility

Openstack instack-undercloud CVE-2017-7549 Insecure Temporary File Handling Vulnerability
2017-08-31
http://www.securityfocus.com/bid/100407

FasterXML Jackson-databind CVE-2017-7525 Deserialization Remote Code Execution Vulnerability
2017-08-31
http://www.securityfocus.com/bid/99623

Apache Batik CVE-2017-5662 XML External Entity Information Disclosure Vulnerability
2017-08-31
http://www.securityfocus.com/bid/97948

Siemens 7KM PAC Switched Ethernet PROFINET Expansion Module Denial of Service Vulnerability
2017-08-31
http://www.securityfocus.com/bid/100562

Multiple Siemens Products CVE-2017-12069 XML External Entity Injection Vulnerability
2017-08-31
http://www.securityfocus.com/bid/100559

Multiple Automated Logic Corporation CVE-2016-5795 XML External Entity Injection Vulnerability
2017-08-31
http://www.securityfocus.com/bid/100558

Moxa SoftCMS CVE-2017-50137 SQL Injection Vulnerability
2017-08-31
http://www.securityfocus.com/bid/100557

libgcrypt CVE-2017-0379 Information Disclosure Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100503

OpenJPEG 'mqc.c' Remote Heap Based Buffer Overflow Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100564

Multiple OPW Products ICSA-17-243-04 SQL Injection and Authentication Bypass Vulnerabilities
2017-08-30
http://www.securityfocus.com/bid/100563

Siemens LOGO!8 BM CVE-2017-12735 Man in the Middle Security Bypass Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100561

Siemens LOGO!8 BM CVE-2017-12734 Information Disclosure Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100560

OpenJPEG CVE-2017-14040 Memory Corruption Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100553

Drupal H5P module Module DRUPAL-SA-CONTRIB-2017-071 Cross Site Scripting Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100548

Ledger CLI CVE-2017-2808 Remote Code Execution Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100546

Wireshark Modbus Dissector CVE-2017-13764 Denial of Service Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100545

Drupal 'Commerce Invoices' Module SQL Injection and Cross-Site Scripting Vulnerabilities
2017-08-30
http://www.securityfocus.com/bid/100544

Ledger CLI CVE-2017-2807 Remote Code Execution Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100543

gdk-pixbuf Integer Overflow and Heap Based Buffer Overflow Vulnerabilities
2017-08-30
http://www.securityfocus.com/bid/100541

QEMU 'hw/display/vga.c' Denial of Service Vulnerability
2017-08-30
http://www.securityfocus.com/bid/100540

Linux kernel CVE-2017-11176 Local Denial of Service Vulnerability
2017-08-29
http://www.securityfocus.com/bid/99919

Linux Kernel 'brcmf_cfg80211_mgmt_tx()' Function Local Memory Corruption Vulnerability
2017-08-29
http://www.securityfocus.com/bid/99955

Linux Kernel 'securelevel/secureboot' Local Security Bypass Vulnerability
2017-08-29
http://www.securityfocus.com/bid/77097

Linux Kernel CVE-2017-7495 Local Information Disclosure Vulnerability
2017-08-29
http://www.securityfocus.com/bid/98491

PHP LibGD CVE-2016-3074 Heap Buffer Overflow Vulnerability
2017-08-29
http://www.securityfocus.com/bid/87087

Linux kernel 'net/ipx/af_ipx.c' Use After Free Local Denial of Service Vulnerability
2017-08-29
http://www.securityfocus.com/bid/98439

Nginx CVE-2017-7529 Remote Integer Overflow Vulnerability
2017-08-29
http://www.securityfocus.com/bid/99534

Linux Kernel CVE-2017-7616 Multiple Local Information Disclosure Vulnerabilities
2017-08-29
http://www.securityfocus.com/bid/97527

Linux Kernel CVE-2017-7261 Local Denial of Service Vulnerability
2017-08-29
http://www.securityfocus.com/bid/97096

Linux Kernel Multiple Information Disclosure Vulnerabilities
2017-08-29
http://www.securityfocus.com/bid/94138

SANS News

Malspam pushing Locky ransomware tries HoeflerText notifications for Chrome and FireFox

Threatpost

Bugs in Arris Modems Distributed by AT&T Vulnerable to Trivial Attacks

FDA Recalls 465K Pacemakers Tied to MedSec Research

Reflected XSS Bug Patched in Popular WooCommerce WordPress Plugin

Exploit