Databáze Hot News 2018 December - 2018 January February March April May June July August September October November December


31.12.2018

Bugtraq

 

Malware

 

Phishing

Yahooreminder 31st December 2018
ChristmasGift Ruby31804,
Monday, 31 December 2018
Walmart Order 31st December 2018
Thank You For Buying From
Walmart - Confirmation Needed
Amazon Order 31st December 2018
Amazon Order Confirmation
Pending

Vulnerebility

JasPer CVE-2018-20584 Denial of Service Vulnerability
2018-12-30
http://www.securityfocus.com/bid/106356

Apache NetBeans CVE-2018-17191 Remote Command Execution Vulnerability
2018-12-30
http://www.securityfocus.com/bid/106352

SAP BusinessObjects BI Platform Server Side Request Forgery Security Bypass Vulnerability
2018-12-28
http://www.securityfocus.com/bid/105064

SANS News

 

Threatpost

 

Exploint

 

30.12.2018

Bugtraq

 

Malware

Backdoor.Linux.MIRAI.AS

Backdoor.Linux.MIRAI.AR

Trojan.MSIL.BERBOMTHUM.AA

Coinminer.Linux.MALXMR.UWEIS
AndroidOS_FraudBot.OPS

TrojanSpy.Win32.TRICKBOT.AL

Worm.Win32.BLADABINDI.AA

BKDR_BINLODR.ZNFJ-A

COINMINER.WIN32.MALXMR.TIAOODAM
TrojanSpy.Win32.TRICKBOT.AK

Phishing

 

Vulnerebility

 

SANS News

 

Threatpost

 

Exploint

 

28.12.2018

Bugtraq

 

Malware

 

Phishing

Apple 26th December 2018
Re: Your invoice for
transaction #15967416853 is
available at December 26,
2018, 9:00 am
Walmart Order 26th December 2018
Thank You For Buying From
Walmart - Confirmation Needed

Vulnerebility

SAP BusinessObjects BI Platform Server Side Request Forgery Security Bypass Vulnerability
2018-12-28
http://www.securityfocus.com/bid/105064

Linux Kernel 'drivers/net/appletalk/ipddp.c ' Local Information Disclosure Vulnerability
2018-12-27
http://www.securityfocus.com/bid/106347

Kubernetes API Server of Gardener CVE-2018-2475 Unauthorized Access Vulnerability
2018-12-26
http://www.securityfocus.com/bid/105579

SANS News

 

Threatpost

 

Exploint

ShareAlarmPro 2.1.4 - Denial of Service (PoC)

NetShareWatcher 1.5.8 - Denial of Service (PoC)

WordPress Plugin Baggage Freight Shipping Australia 0.1.0 - Arbitrary File Upload

bludit Pages Editor 3.0.0 - Arbitrary File Upload

Iperius Backup 5.8.1 - Buffer Overflow (SEH)

Terminal Services Manager 3.1 - Local Buffer Overflow (SEH)

Product Key Explorer 4.0.9 - Denial of Service (PoC)

MAGIX Music Editor 3.1 - Buffer Overflow (SEH)

WordPress Plugin Audio Record 1.0 - Arbitrary File Upload

Craft CMS 3.0.25 - Cross-Site Scripting

24.12.2018

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Kubernetes API Server of Gardener CVE-2018-2475 Unauthorized Access Vulnerability
2018-12-26
http://www.securityfocus.com/bid/105579

Foxit Quick PDF Library Multiple Security Vulnerabilities
2018-12-24
http://www.securityfocus.com/bid/106306

GNU Libextractor Multiple Security Vulnerabilities
2018-12-24
http://www.securityfocus.com/bid/106300

SANS News

 

Threatpost

 

Exploint

Microsoft Edge 42.17134.1.0 - 'Tree::ANode::DocumentLayout' Denial of Service

Microsoft Windows - 'MsiAdvertiseProduct' Arbitrary File Read

Netatalk < 3.1.12 - Authentication Bypass

SQLScan 1.0 - Denial of Service (PoC)

ZeusCart 4.0 - Cross-Site Request Forgery (Deactivate Customer Accounts)

AnyBurn 4.3 - Local Buffer Overflow (SEH)

Angry IP Scanner for Linux 3.5.3 - Denial of Service (PoC)

FrontAccounting 2.4.5 - 'SubmitUser' SQL Injection

WSTMart 2.0.8 - Cross-Site Request Forgery (Add Admin)

WSTMart 2.0.8 - Cross-Site Scripting

21.12.2018

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

3S-Smart Software Solutions GmbH CODESYS ICSA-18-352-03 Access Bypass Vulnerability
2018-12-21
http://www.securityfocus.com/bid/106248

3S-Smart Software CODESYS ICSA-18-352-04 Multiple Security Vulnerabilities
2018-12-21
http://www.securityfocus.com/bid/106251

Jenkins Multiple Security Vulnerabilities
2018-12-20
http://www.securityfocus.com/bid/106176

Dokan CVE-2018-5410 Stack Based Buffer Overflow Vulnerability
2018-12-20
http://www.securityfocus.com/bid/106274

SANS News

 

Threatpost

 

Exploint

Erlang - Port Mapper Daemon Cookie RCE (Metasploit)

VBScript - MSXML Execution Policy Bypass

VBScript - VbsErase Reference Leak Use-After-Free

Base64 Decoder 1.1.2 - Local Buffer Overflow (SEH)

XMPlay 3.8.3 - '.m3u' Local Stack Overflow Code Execution

LanSpy 2.0.1.159 - Buffer Overflow (SEH) (Egghunter)

20.12.2018

Bugtraq

 

Malware

Exp.CVE-2018-8653

MSH.Backdoor

Phishing

 

Vulnerebility

 

SANS News

 

Threatpost

 

Exploint

IBM Operational Decision Manager 8.x - XML External Entity Injection

LanSpy 2.0.1.159 - Buffer Overflow (SEH) (Egghunter)

19.12.2018

Bugtraq

 

Malware

Trojan.Stolepen

Phishing

 

Vulnerebility

OpenSSL CVE-2018-0737 Side Channel Attack Information Disclosure Vulnerability
2018-12-19
http://www.securityfocus.com/bid/103766

OpenSSL CVE-2018-0732 Denial of Service Vulnerability
2018-12-19
http://www.securityfocus.com/bid/104442

Multiple IBM Products CVE-2018-1447 Local Information Disclosure Vulnerability
2018-12-19
http://www.securityfocus.com/bid/104511

IBM GSKit CVE-2018-1426 Remote Security Vulnerability
2018-12-19
http://www.securityfocus.com/bid/105580

IBM Global Security Kit CVE-2018-1388 Information Disclosure Vulnerability
2018-12-19
http://www.securityfocus.com/bid/103698

IBM DB2 CVE-2018-1427 Multiple Local Buffer Overflow Vulnerabilities
2018-12-19
http://www.securityfocus.com/bid/103536

Oracle Java SE/Java SE Embedded/JRockit CVE-2018-3214 Remote Security Vulnerability
2018-12-19
http://www.securityfocus.com/bid/105615

Oracle Java SE/Java SE Embedded CVE-2018-3136 Remote Security Vulnerability
2018-12-19
http://www.securityfocus.com/bid/105601

Oracle Java SE/Java SE Embedded/JRockit CVE-2018-3149 Remote Security Vulnerability
2018-12-19
http://www.securityfocus.com/bid/105608

Oracle Java SE/Java SE Embedded CVE-2018-13785 Remote Security Vulnerability
2018-12-19
http://www.securityfocus.com/bid/105599

Oracle Java SE/Java SE Embedded CVE-2018-3139 Remote Security Vulnerability
2018-12-19
http://www.securityfocus.com/bid/105602

Oracle Java SE/Java SE Embedded CVE-2018-3169 Remote Security Vulnerability
2018-12-19
http://www.securityfocus.com/bid/105587

Oracle Java SE/Java SE Embedded/JRockit CVE-2018-3180 Remote Security Vulnerability
2018-12-19
http://www.securityfocus.com/bid/105617

Oracle Java SE/Java SE Embedded/JRockit CVE-2018-3183 Remote Security Vulnerability
2018-12-19
http://www.securityfocus.com/bid/105622

Siemens TIM 1531 IRC CVE-2018-13816 Authentication Bypass Vulnerability
2018-12-19
http://www.securityfocus.com/bid/106194

Linux Kernel CVE-2018-16884 Denial of Service Vulnerability
2018-12-19
http://www.securityfocus.com/bid/106253

Symfony Local File Include and Open Redirection Vulnerabilities
2018-12-19
http://www.securityfocus.com/bid/106249

ABB CMS-770 CVE-2018-17928 Authentication Bypass Vulnerability
2018-12-19
http://www.securityfocus.com/bid/106244

Linux Kernel CVE-2018-16882 Local Denial of Service Vulnerability
2018-12-18
http://www.securityfocus.com/bid/106254

Multiple GIGABYTE Products Multiple Arbitrary Code Execution Vulnerabilities
2018-12-18
http://www.securityfocus.com/bid/106252

3S-Smart Software CODESYS ICSA-18-352-04 Multiple Security Vulnerabilities
2018-12-18
http://www.securityfocus.com/bid/106251

Asus Aura Sync Multiple Arbitrary Code Execution Vulnerabilities
2018-12-18
http://www.securityfocus.com/bid/106250

3S-Smart Software Solutions GmbH CODESYS ICSA-18-352-03 Access Bypass Vulnerability
2018-12-18
http://www.securityfocus.com/bid/106248

ABB GATE-E2 ICSA-18-352-01 Authentication Bypass and Cross-site Scripting Vulnerability
2018-12-18
http://www.securityfocus.com/bid/106247

Bind Server CVE-2018-5742 Buffer Overflow Vulnerability
2018-12-18
http://www.securityfocus.com/bid/106246

Advantech WebAccess/SCADA CVE-2018-18999 Stack Buffer Overflow Vulnerability
2018-12-18
http://www.securityfocus.com/bid/106245

ABB M2M ETHERNET CVE-2018-17926 Authentication Bypass Vulnerability
2018-12-18
http://www.securityfocus.com/bid/106243

VMware vRealize Operations CVE-2018-6978 Local Privilege Escalation Vulnerability
2018-12-18
http://www.securityfocus.com/bid/106242

NTP CVE-2018-12327 Stack Buffer Overflow Vulnerability
2018-12-17
http://www.securityfocus.com/bid/104517

OpenSSL CVE-2018-0739 Denial of Service Vulnerability
2018-12-17
http://www.securityfocus.com/bid/103518

SANS News

 

Threatpost

 

Exploint

 

18.12.2018

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

NTP CVE-2018-12327 Stack Buffer Overflow Vulnerability
2018-12-17
http://www.securityfocus.com/bid/104517

OpenSSL CVE-2018-0739 Denial of Service Vulnerability
2018-12-17
http://www.securityfocus.com/bid/103518

ImageMagick Multiple Heap Buffer Overflow Vulnerabilities
2018-12-17
http://www.securityfocus.com/bid/106229

ImageMagick 'ReadDIBImage()' Function Denial of Service Vulnerability
2018-12-17
http://www.securityfocus.com/bid/106227

SANS News

 

Threatpost

 

Exploint

Microsoft Windows - 'jscript!JsArrayFunctionHeapSort' Out-of-Bounds Write

Exel Password Recovery 8.2.0.0 - Local Buffer Overflow Denial of Service

AnyBurn 4.3 - Local Buffer Overflow Denial of Service

SDL Web Content Manager 8.5.0 - XML External Entity Injection

MiniShare 1.4.1 - Remote Buffer Overflow HEAD and POST Method

17.12.2018

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

NTP CVE-2018-12327 Stack Buffer Overflow Vulnerability
2018-12-17
http://www.securityfocus.com/bid/104517

OpenSSL CVE-2018-0739 Denial of Service Vulnerability
2018-12-17
http://www.securityfocus.com/bid/103518

SANS News

 

Threatpost

 

Exploint

 

14.12.2018

Bugtraq

 

Malware

Backdoor.Cobalt

Trojan.Filerase

Phishing

 

Vulnerebility

Geutebrück GmbH E2 Series IP Cameras CVE-2018-19007 OS Command Injection Vulnerability
2018-12-14
http://www.securityfocus.com/bid/106208

FreeBSD Network File System Multiple Security Vulnerabilities
2018-12-13
http://www.securityfocus.com/bid/106192

Google Chrome Prior to 71.0.3578.80 Multiple Security Vulnerabilities
2018-12-13
http://www.securityfocus.com/bid/106084

Pixar Tractor CVE-2018-5411 HTML Injection Vulnerability
2018-12-13
http://www.securityfocus.com/bid/106209

QEMU CVE-2018-16867 Directory Traversal Vulnerability
2018-12-13
http://www.securityfocus.com/bid/106195

SANS News

 

Threatpost

 

Exploint

Zortam MP3 Media Studio 24.15 - Local Buffer Overflow (SEH)

Responsive FileManager 9.13.4 - Multiple Vulnerabilities

Cisco RV110W - Password Disclosure / Command Execution

Angry IP Scanner 3.5.3 - Denial of Service (PoC)

Facebook And Google Reviews System For Businesses - Cross-Site Request Forgery (Change Admin Password)

Huawei Router HG532e - Command Execution

Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure (2)

Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure

13.12.2018

Bugtraq

 

Malware

Exp.CVE-2018-8611

Phishing

 

Vulnerebility

FreeBSD Network File System Multiple Security Vulnerabilities
2018-12-13
http://www.securityfocus.com/bid/106192

Google Chrome Prior to 71.0.3578.80 Multiple Security Vulnerabilities
2018-12-13
http://www.securityfocus.com/bid/106084

QEMU CVE-2018-16867 Directory Traversal Vulnerability
2018-12-13
http://www.securityfocus.com/bid/106195

phpMyAdmin CVE-2018-19968 Local File Include Vulnerability
2018-12-12
http://www.securityfocus.com/bid/106178

OpenSSL CVE-2018-5407 Side Channel Attack Information Disclosure Vulnerability
2018-12-12
http://www.securityfocus.com/bid/105897

OpenSSL CVE-2018-0734 Side Channel Attack Information Disclosure Vulnerability
2018-12-12
http://www.securityfocus.com/bid/105758

SANS News

 

Threatpost

 

Exploint

CyberLink LabelPrint 2.5 - Stack Buffer Overflow (Metasploit)

WebKit JIT - Int32/Double Arrays can have Proxy Objects in the Prototype Chains

Linux - 'userfaultfd' Bypasses tmpfs File Permissions

12.12.2018

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

phpMyAdmin CVE-2018-19968 Local File Include Vulnerability
2018-12-12
http://www.securityfocus.com/bid/106178

OpenSSL CVE-2018-5407 Side Channel Attack Information Disclosure Vulnerability
2018-12-12
http://www.securityfocus.com/bid/105897

OpenSSL CVE-2018-0734 Side Channel Attack Information Disclosure Vulnerability
2018-12-12
http://www.securityfocus.com/bid/105758

Oracle Solaris CVE-2017-3623 Remote Code Execution Vulnerability
2018-12-12
http://www.securityfocus.com/bid/97778

X.Org X Server CVE-2018-14665 Multiple Local Privilege Escalation Vulnerability
2018-12-12
http://www.securityfocus.com/bid/105741

SAP Kernel and Change and Transport System CVE-2018-2441 Security Bypass Vulnerability
2018-12-11
http://www.securityfocus.com/bid/105090

SANS News

 

Threatpost

 

Exploint

Adobe ColdFusion 2018 - Arbitrary File Upload

ThinkPHP 5.0.23/5.1.31 - Remote Code Execution

WordPress Plugin AutoSuggest 0.24 - 'wpas_keys' SQL Injection

HotelDruid 2.3.0 - 'id_utente_mod' SQL Injection

Apache OFBiz 16.11.05 - Cross-Site Scripting

ZTE ZXHN H168N - Improper Access Restrictions

Huawei B315s-22 - Information Leak

TP-Link wireless router Archer C1200 - Cross-Site Scripting

PrinterOn Enterprise 4.1.4 - Arbitrary File Deletion

LanSpy 2.0.1.159 - Local Buffer Overflow (PoC)

DomainMOD 4.11.01 - Cross-Site Scripting

SmartFTP Client 9.0.2623.0 - Denial of Service (PoC)

PrestaShop 1.6.x/1.7.x - Remote Code Execution

McAfee True Key - McAfee.TrueKey.Service Privilege Escalation

XNU - POSIX Shared Memory Mappings have Incorrect Maximum Protection

11.12.2018

Bugtraq

 

Malware

Android.BankBot.495.origin

Phishing

 

Vulnerebility

 SAP Kernel and Change and Transport System CVE-2018-2441 Security Bypass Vulnerability
2018-12-11
http://www.securityfocus.com/bid/105090

SAP Business Client Unspecified Security Vulnerability
2018-12-11
http://www.securityfocus.com/bid/104436

Kubernetes API Server of Gardener CVE-2018-2475 Unauthorized Access Vulnerability
2018-12-11
http://www.securityfocus.com/bid/105579

Ghostscript CVE-2018-19409 Security Bypass Vulnerability
2018-12-11
http://www.securityfocus.com/bid/105990

Mozilla Firefox MFSA2018-29 Multiple Security Vulnerabilities
2018-12-11
http://www.securityfocus.com/bid/106167

Adobe Acrobat and Reader APSB18-41 Multiple Arbitrary Code Execution Vulnerabilities
2018-12-11
http://www.securityfocus.com/bid/106164

Adobe Acrobat and Reader APSB18-41 Multiple Information Disclosure Vulnerabilities
2018-12-11
http://www.securityfocus.com/bid/106162

Adobe Acrobat and Reader APSB18-41 Multiple Unspecified Arbitrary Code Execution Vulnerabilities
2018-12-11
http://www.securityfocus.com/bid/106161

Adobe Acrobat and Reader APSB18-41 Multiple Integer Overflow Vulnerabilities
2018-12-11
http://www.securityfocus.com/bid/106160

Adobe Acrobat and Reader CVE-2018-16042 Security Bypass Vulnerability
2018-12-11
http://www.securityfocus.com/bid/106159

Adobe Acrobat and Reader APSB18-41 Multiple Heap Buffer Overflow Vulnerabilities
2018-12-11
http://www.securityfocus.com/bid/106158

SAP Mobile Secure for Android CVE-2018-2500 Information Disclosure Vulnerability
2018-12-11
http://www.securityfocus.com/bid/106157

SAP NetWeaver CVE-2018-2503 Information Disclosure Vulnerability
2018-12-11
http://www.securityfocus.com/bid/106156

SAP NetWeaver AS Java CVE-2018-2492 XML External Entity Injection Vulnerability
2018-12-11
http://www.securityfocus.com/bid/106153

SAP HANA CVE-2018-2497 Security Bypass Vulnerability
2018-12-11
http://www.securityfocus.com/bid/106152

SAP Hybris Commerce CVE-2018-2505 Cross Site Scripting Vulnerability
2018-12-11
http://www.securityfocus.com/bid/106151

SAP NetWeaver AS JAVA CVE-2018-2504 Cross Site Scripting Vulnerability
2018-12-11
http://www.securityfocus.com/bid/106150

Microsoft Edge Chakra Scripting Engine CVE-2018-8617 Remote Memory Corruption Vulnerability
2018-12-11
http://www.securityfocus.com/bid/106112

Microsoft Edge Chakra Scripting Engine CVE-2018-8583 Remote Memory Corruption Vulnerability
2018-12-11
http://www.securityfocus.com/bid/106111

Microsoft SharePoint Server CVE-2018-8580 Information Disclosure Vulnerability
2018-12-11
http://www.securityfocus.com/bid/106096

IBM Maximo Asset Management CVE-2018-1872 Cross Site Scripting Vulnerability
2018-12-10
http://www.securityfocus.com/bid/106140

GNU Binutils CVE-2018-20002 Denial of Service Vulnerability
2018-12-09
http://www.securityfocus.com/bid/106142

SANS News

 

Threatpost

 

Exploint

McAfee True Key - McAfee.TrueKey.Service Privilege Escalation

Alumni Tracer SMS Notification - SQL Injection / Cross-Site Request Forgery

Tourism Website Blog - Remote Code Execution / SQL Injection

XNU - POSIX Shared Memory Mappings have Incorrect Maximum Protection

10.12.2018

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

IBM Maximo Asset Management CVE-2018-1872 Cross Site Scripting Vulnerability
2018-12-10
http://www.securityfocus.com/bid/106140

GNU Binutils CVE-2018-20002 Denial of Service Vulnerability
2018-12-09
http://www.securityfocus.com/bid/106142

Linux Kernel CVE-2018-10840 Local Heap Based Buffer Overflow Vulnerability
2018-12-07
http://www.securityfocus.com/bid/104858

PHP CVE-2018-19935 Denial of Service Vulnerability
2018-12-07
http://www.securityfocus.com/bid/106143

SANS News

 

Threatpost

 

Exploint

DomainMOD 4.11.01 - 'DisplayName' Cross-Site Scripting

Adiscon LogAnalyzer 4.1.7 - Cross-Site Scripting

i-doit CMDB 1.11.2 - Remote Code Execution

Textpad 8.1.2 - Denial Of Service (PoC)

9.12.2018

Bugtraq

 

Malware

Win32/Rootkit.Agent.OCL

Phishing

 

Vulnerebility

 

SANS News

 

Threatpost

 

Exploint

 

7.12.2018

Bugtraq

 

Malware

Ransom.Wixido

Exp.CVE-2018-15982

Phishing

Wells Fargo

6th December 2018

AN UPDATE ON YOUR ACCOUNT
ACTIVITY

Vulnerebility

Linux Kernel CVE-2018-10840 Local Heap Based Buffer Overflow Vulnerability
2018-12-07
http://www.securityfocus.com/bid/104858

Adobe Flash Player CVE-2018-15982 Use After Free Remote Code Execution Vulnerability
2018-12-06
http://www.securityfocus.com/bid/106116

Google Chrome Prior to 71.0.3578.80 Multiple Security Vulnerabilities
2018-12-06
http://www.securityfocus.com/bid/106084

Philips HealthSuite Health for Android CVE-2018-19001 Weak Encryption Local Security Weakness
2018-12-06
http://www.securityfocus.com/bid/106126

Symantec Norton Password Manager for Android CVE-2018-18362 Local Cross Site Scripting Vulnerability
2018-12-06
http://www.securityfocus.com/bid/106055

SANS News

 

Threatpost

 

Exploint

 

6.12.2018

Bugtraq

 

Malware

 

Phishing

service@paypal.com

6th December 2018

Payment

Vulnerebility

Google Chrome Prior to 71.0.3578.80 Multiple Security Vulnerabilities
2018-12-06
http://www.securityfocus.com/bid/106084

Adobe Flash Player CVE-2018-15982 Use After Free Remote Code Execution Vulnerability
2018-12-05
http://www.securityfocus.com/bid/106116

Adobe Flash Player CVE-2018-15983 DLL Loading Local Privilege Escalation Vulnerability
2018-12-05
http://www.securityfocus.com/bid/106108

INVT Electric VT-Designer Remote Code Execution and Heap Based Buffer Overflow Vulnerabilities
2018-12-05
http://www.securityfocus.com/bid/106071

SANS News

 

Threatpost

 

Exploint

 

5.12.2018

Bugtraq

 

Malware

Linux.Chalubo

Phishing

PayPal

5th December 2018

Transaction ID:
9FB71675F9224162B

Vulnerebility

INVT Electric VT-Designer Remote Code Execution and Heap Based Buffer Overflow Vulnerabilities
2018-12-05
http://www.securityfocus.com/bid/106071

3GPP IP-Multimedia Subsystem Multiple Security Vulnerabilities
2018-12-04
http://www.securityfocus.com/bid/106070

SANS News

 

Threatpost

 

Exploint

 

4.12.2018

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

3GPP IP-Multimedia Subsystem Multiple Security Vulnerabilities
2018-12-04
http://www.securityfocus.com/bid/106070

Kubernetes API Server CVE-2018-1002105 Remote Privilege Escalation Vulnerability
2018-12-04
http://www.securityfocus.com/bid/106068

Google Android Framework Component Multiple Security Vulnerabilities
2018-12-03
http://www.securityfocus.com/bid/106067

Google Android System Component CVE-2018-9565 Information Disclosure Vulnerability
2018-12-03
http://www.securityfocus.com/bid/106065

Google Android HTC Component CVE-2018-9567 Local Privilege Escalation Vulnerability
2018-12-03
http://www.securityfocus.com/bid/106064

Pulse Secure Desktop Client CVE-2018-11002 Local Privilege Escalation Vulnerability
2018-12-03
http://www.securityfocus.com/bid/106054

SANS News

Malspam pushing Lokibot malware

Threatpost

 

Exploint

Microsoft Lync for Mac 2011 - Injection Forced Browsing/Download

Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control Authentication Bypass

Xorg X11 Server (AIX) - Local Privilege Escalation

OpenSSH < 7.7 - User Enumeration (2)

DomainMOD 4.11.01 - Owner name Field Cross-Site Scripting

NEC Univerge Sv9100 WebPro - 6.00 - Predictable Session ID / Clear Text Password Storage

KeyBase Botnet 1.5 - SQL Injection

Dolibarr ERP/CRM 8.0.3 - Cross-Site Scripting

DomainMOD 4.11.01 - Custom Domain Fields Cross-Site Scripting

DomainMOD 4.11.01 - Custom SSL Fields Cross-Site Scripting

NUUO NVRMini2 3.9.1 - Authenticated Command Injection

DomainMOD 4.11.01 - Registrar Cross-Site Scripting

Wireshark - 'cdma2k_message_ACTIVE_SET_RECORD_FIELDS' Stack Corruption

Wireshark - 'find_signature' Heap Out-of-Bounds Read

HP Intelligent Management - Java Deserialization RCE (Metasploit)

Emacs - movemail Privilege Escalation (Metasploit)

FreshRSS 1.11.1 - Cross-Site Scripting

3.12.2018

Bugtraq

 

Malware

Backdoor.Powemuddy

Phishing

 

Vulnerebility

Pulse Secure Desktop Client CVE-2018-11002 Local Privilege Escalation Vulnerability
2018-12-03
http://www.securityfocus.com/bid/106054

SANS News

Video: Dissecting a CVE-2017-18822 Exploit

Threatpost

 

Exploint

PaloAlto Networks Expedition Migration Tool 1.0.106 - Information Disclosure

Rockwell Automation Allen-Bradley PowerMonitor 1000 - Cross-Site Scripting

Fleetco Fleet Maintenance Management 1.2 - Remote Code Execution

CyberArk 9.7 - Memory Disclosure

1.12.2018

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

 

SANS News

Wireshark update 2.6.5 available

Threatpost

 

Exploint

Apache Spark - Unauthenticated Command Execution (Metasploit)

VBScript - 'rtFilter' Out-of-Bounds Read

VBScript - 'OLEAUT32!VariantClear' and 'scrrun!VBADictionary::put_Item' Use-After-Free

xorg-x11-server < 1.20.3 - 'modulepath' Local Privilege Escalation

HTML5 Video Player 1.2.5 - Buffer Overflow (Metasploit)