Databáze Hot News 2018 March - 2018 January February March April May June July August September October November December


31 .3.2018

Bugtraq

[SECURITY] [DSA 4158-1] openssl1.0 security update 2018-03-29
Salvatore Bonaccorso (carnil debian org)

APPLE-SA-2018-3-29-2 watchOS 4.3 2018-03-29
Apple Product Security (product-security-noreply lists apple com)

CA20180329-01: Security Notice for CA Workload Automation AE and CA Workload Control Center 2018-03-30
Williams, Ken (Ken Williams ca com)

[SECURITY] [DSA 4157-1] openssl security update 2018-03-29
Salvatore Bonaccorso (carnil debian org)

APPLE-SA-2018-3-29-4 Xcode 9.3 2018-03-29
Apple Product Security (product-security-noreply lists apple com)

APPLE-SA-2018-3-29-7 iTunes 12.7.4 for Windows 2018-03-29
Apple Product Security (product-security-noreply lists apple com)

APPLE-SA-2018-3-29-8 iCloud for Windows 7.4 2018-03-29
Apple Product Security (product-security-noreply lists apple com)

APPLE-SA-2018-3-29-3 tvOS 11.3 2018-03-29
Apple Product Security (product-security-noreply lists apple com)

Malware

Heur.AdvML.M

Phishing

 

Vulnerebility

Microsoft Windows Kernel CVE-2018-1038 Local Privilege Escalation Vulnerability
2018-03-30
http://www.securityfocus.com/bid/103549

OpenSSL CVE-2017-3738 Information Disclosure Vulnerability
2018-03-28
http://www.securityfocus.com/bid/102118

Cisco IOS XE Software CVE-2018-0157 Denial of Service Vulnerability
2018-03-28
http://www.securityfocus.com/bid/103561

Cisco IOS XE Software CVE-2018-0170 Denial of Service Vulnerability
2018-03-28
http://www.securityfocus.com/bid/103560

Cisco IOS Software Integrated Services Module for VPN CVE-2018-0154 Denial of Service Vulnerability
2018-03-28
http://www.securityfocus.com/bid/103559

Cisco IOS XE Software CVE-2018-0152 Remote Privilege Escalation Vulnerability
2018-03-28
http://www.securityfocus.com/bid/103558

Cisco IOS XE Software CVE-2018-0195 Authorization Bypass Vulnerability
2018-03-28
http://www.securityfocus.com/bid/103557

Cisco IOS Login Enhancements Feature Multiple Denial of Service Vulnerabilities
2018-03-28
http://www.securityfocus.com/bid/103556

Cisco IOS XE Software CVE-2018-0183 Local Privilege Escalation Vulnerability
2018-03-28
http://www.securityfocus.com/bid/103555

Cisco IOS and IOS XE Software CVE-2018-0174 Denial of Service Vulnerability
2018-03-28
http://www.securityfocus.com/bid/103554

Cisco IOS XE Software CVE-2018-0164 Denial of Service Vulnerability
2018-03-28
http://www.securityfocus.com/bid/103553

Cisco IOS and IOS XE Software CVE-2018-0172 Denial of Service Vulnerability
2018-03-28
http://www.securityfocus.com/bid/103552

Cisco IOS XE Software Multiple Cross Site Scripting Vulnerabilities
2018-03-28
http://www.securityfocus.com/bid/103551

Cisco IOS XE Software CVE-2018-0184 Local Privilege Escalation Vulnerability
2018-03-28
http://www.securityfocus.com/bid/103550

Cisco IOS and IOS XE Software CVE-2018-0189 Denial of Service Vulnerability
2018-03-28
http://www.securityfocus.com/bid/103548

Cisco IOS XE Software Multiple Command Injection Vulnerabilities
2018-03-28
http://www.securityfocus.com/bid/103547

SANS News

Version 7 of the CIS Controls Released

Threatpost

 

Exploint

Exodus Wallet (ElectronJS Framework) - Remote Code Execution (Metasploit)

Joomla Component Fields - SQLi Remote Code Execution (Metasploit)

30 .3.2018

Bugtraq

[SECURITY] [DSA 4156-1] drupal7 security update 2018-03-28
Salvatore Bonaccorso (carnil debian org)

CA20180328-01: Security Notice for CA API Developer Portal 2018-03-29
Kotas, Kevin J (Kevin Kotas ca com)

[SECURITY] [DSA 4155-1] thunderbird security update 2018-03-28
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 4154-1] net-snmp security update 2018-03-28
Salvatore Bonaccorso (carnil debian org)

[SECURITY] [DSA 4153-1] firefox-esr security update 2018-03-27
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 4152-1] mupdf security update 2018-03-27
Luciano Bello (luciano debian org)

Malware

Win32/Shyape.T

Win64/Emotet.AB

Phishing

 

Vulnerebility

OpenSSL CVE-2017-3738 Information Disclosure Vulnerability
2018-03-28
http://www.securityfocus.com/bid/102118

ImageMagick CVE-2018-8960 Heap Buffer Overflow Vulnerability
2018-03-28
http://www.securityfocus.com/bid/103523

Google Chrome Prior to 63.0.3239.84 Multiple Security Vulnerabilities
2018-03-27
http://www.securityfocus.com/bid/102098

OpenSSL CVE-2018-0739 Denial of Service Vulnerability
2018-03-27
http://www.securityfocus.com/bid/103518

OpenSSL CVE-2018-0733 Security Bypass Vulnerability
2018-03-27
http://www.securityfocus.com/bid/103517

Apache Struts CVE-2018-1327 Denial of Service Vulnerability
2018-03-27
http://www.securityfocus.com/bid/103516

Nortek Linear eMerge E3 Series CVE-2018-5439 Remote Command Injection Vulnerability
2018-03-26
http://www.securityfocus.com/bid/103053

Novell NetIQ Identity Manager CVE-2018-1350 Information Disclosure Vulnerability
2018-03-26
http://www.securityfocus.com/bid/103532

SANS News

One hash to rule them all: drupalgeddon2

Threatpost

 

Exploint

Exodus Wallet (ElectronJS Framework) - Remote Code Execution (Metasploit)

GitStack - Unsanitized Argument Remote Code Execution (Metasploit)

Joomla Component Fields - SQLi Remote Code Execution (Metasploit)

29 .3.2018

Bugtraq

[SECURITY] [DSA 4154-1] net-snmp security update 2018-03-28
Salvatore Bonaccorso (carnil debian org)

[SECURITY] [DSA 4153-1] firefox-esr security update 2018-03-27
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 4152-1] mupdf security update 2018-03-27
Luciano Bello (luciano debian org)

Microsoft Skype Mobile v81.2 & v8.13 - Remote Denial of Service Vulnerability 2018-03-27
Vulnerability Lab (research vulnerability-lab com)

Sandoba CP:Shop CMS v2016.1 - Multiple Cross Site Scripting Vulnerabilities 2018-03-27
Vulnerability Lab (research vulnerability-lab com)

Weblication CMS Core & Grid v12.6.24 - Multiple Cross Site Scripting Vulnerabilities 2018-03-27
Vulnerability Lab (research vulnerability-lab com)

AEF CMS v1.0.9 - (PM) Persistent Cross Site Scripting Vulnerability 2018-03-27
Vulnerability Lab (research vulnerability-lab com)

Malware

Ransom.Zenis

Phishing

 

Vulnerebility

Multiple Huawei Products CVE-2017-17167 Information Disclosure Vulnerability
2018-12-15
http://www.securityfocus.com/bid/103513

OpenSSL CVE-2017-3738 Information Disclosure Vulnerability
2018-03-28
http://www.securityfocus.com/bid/102118

Google Chrome Prior to 63.0.3239.84 Multiple Security Vulnerabilities
2018-03-27
http://www.securityfocus.com/bid/102098

OpenSSL CVE-2018-0739 Denial of Service Vulnerability
2018-03-27
http://www.securityfocus.com/bid/103518

OpenSSL CVE-2018-0733 Security Bypass Vulnerability
2018-03-27
http://www.securityfocus.com/bid/103517

Apache Struts CVE-2018-1327 Denial of Service Vulnerability
2018-03-27
http://www.securityfocus.com/bid/103516

Nortek Linear eMerge E3 Series CVE-2018-5439 Remote Command Injection Vulnerability
2018-03-26
http://www.securityfocus.com/bid/103053

Mozilla Firefox and Firefox ESR CVE-2018-5148 Use After Free Denial of Service Vulnerability
2018-03-26
http://www.securityfocus.com/bid/103506

Symantec Norton App Lock for Android CVE-2017-15534 Local Authentication Bypass Vulnerability
2018-03-26
http://www.securityfocus.com/bid/103377

GraphicsMagick CVE-2018-9018 Denial of Service Vulnerability
2018-03-25
http://www.securityfocus.com/bid/103526

Multiple AMD Processors Multiple Remote Security Vulnerabilities
2018-03-23
http://www.securityfocus.com/bid/103409

ARM mbed TLS CVE-2017-18187 Integer Overflow Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103055

ARM mbed TLS CVE-2018-0488 Remote Code Execution Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103057

ARM mbed TLS CVE-2018-0487 Remote Code Execution Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103056

Memcached Multiple Integer Overflow Vulnerabilities
2018-03-23
http://www.securityfocus.com/bid/94083

Memcached CVE-2017-9951 Incomplete Fix Integer Overflow Vulnerability
2018-03-23
http://www.securityfocus.com/bid/99874

Memcached verbose mode CVE-2013-7291 Denial of Service Vulnerability
2018-03-23
http://www.securityfocus.com/bid/64989

memcache SASL Authentication Security Bypass Vulnerability
2018-03-23
http://www.securityfocus.com/bid/64559

memcached Verbose Mode Denial of Service Vulnerability
2018-03-23
http://www.securityfocus.com/bid/64978

Memcached 'items.c' Denial of Service Vulnerability
2018-03-23
http://www.securityfocus.com/bid/64988

SANS News

How are Your Vulnerabilities?

Threatpost

Alleged Mastermind Behind Carbanak Crime Gang Arrested

Exploint

Microsoft Windows Remote Assistance - XML External Entity Injection

TwonkyMedia Server 7.0.11-8.5 - Persistent Cross-Site Scripting

TwonkyMedia Server 7.0.11-8.5 - Directory Traversal

ClipBucket - beats_uploader Unauthenticated Arbitrary File Upload (Metasploit)

TestLink Open Source Test Management < 1.9.16 - Remote Code Execution (PoC)

ClipBucket - beats_uploader Unauthenticated Arbitrary File Upload (Metasploit)

28 .3.2018

Bugtraq

Microsoft Skype Mobile v81.2 & v8.13 - Remote Denial of Service Vulnerability 2018-03-27
Vulnerability Lab (research vulnerability-lab com)

Sandoba CP:Shop CMS v2016.1 - Multiple Cross Site Scripting Vulnerabilities 2018-03-27
Vulnerability Lab (research vulnerability-lab com)

Weblication CMS Core & Grid v12.6.24 - Multiple Cross Site Scripting Vulnerabilities 2018-03-27
Vulnerability Lab (research vulnerability-lab com)

AEF CMS v1.0.9 - (PM) Persistent Cross Site Scripting Vulnerability 2018-03-27
Vulnerability Lab (research vulnerability-lab com)

[slackware-security] mozilla-firefox (SSA:2018-085-01) 2018-03-27
Slackware Security Team (security slackware com)

[SECURITY] [DSA 4151-1] librelp security update 2018-03-26
Salvatore Bonaccorso (carnil debian org)

Malware

MSH.Gosopad

Phishing

 

Vulnerebility

Multiple Huawei Products CVE-2017-17167 Information Disclosure Vulnerability
2018-12-15
http://www.securityfocus.com/bid/103513

Google Chrome Prior to 63.0.3239.84 Multiple Security Vulnerabilities
2018-03-27
http://www.securityfocus.com/bid/102098

OpenSSL CVE-2018-0739 Denial of Service Vulnerability
2018-03-27
http://www.securityfocus.com/bid/103518

OpenSSL CVE-2018-0733 Security Bypass Vulnerability
2018-03-27
http://www.securityfocus.com/bid/103517

Apache Struts CVE-2018-1327 Denial of Service Vulnerability
2018-03-27
http://www.securityfocus.com/bid/103516

Nortek Linear eMerge E3 Series CVE-2018-5439 Remote Command Injection Vulnerability
2018-03-26
http://www.securityfocus.com/bid/103053

Mozilla Firefox and Firefox ESR CVE-2018-5148 Use After Free Denial of Service Vulnerability
2018-03-26
http://www.securityfocus.com/bid/103506

Symantec Norton App Lock for Android CVE-2017-15534 Local Authentication Bypass Vulnerability
2018-03-26
http://www.securityfocus.com/bid/103377

Multiple AMD Processors Multiple Remote Security Vulnerabilities
2018-03-23
http://www.securityfocus.com/bid/103409

ARM mbed TLS CVE-2017-18187 Integer Overflow Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103055

ARM mbed TLS CVE-2018-0488 Remote Code Execution Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103057

ARM mbed TLS CVE-2018-0487 Remote Code Execution Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103056

Memcached Multiple Integer Overflow Vulnerabilities
2018-03-23
http://www.securityfocus.com/bid/94083

Memcached CVE-2017-9951 Incomplete Fix Integer Overflow Vulnerability
2018-03-23
http://www.securityfocus.com/bid/99874

SANS News

Side-channel information leakage in mobile applications

Threatpost

Sanny Malware Updates Delivery Method

Facebook Woes Continue as FTC Opens Data Privacy Probe

Exploint

ClipBucket - beats_uploader Unauthenticated Arbitrary File Upload (Metasploit)

27 .3.2018

Bugtraq

Microsoft Skype Mobile v81.2 & v8.13 - Remote Denial of Service Vulnerability 2018-03-27
Vulnerability Lab (research vulnerability-lab com)

Sandoba CP:Shop CMS v2016.1 - Multiple Cross Site Scripting Vulnerabilities 2018-03-27
Vulnerability Lab (research vulnerability-lab com)

Weblication CMS Core & Grid v12.6.24 - Multiple Cross Site Scripting Vulnerabilities 2018-03-27
Vulnerability Lab (research vulnerability-lab com)

AEF CMS v1.0.9 - (PM) Persistent Cross Site Scripting Vulnerability 2018-03-27
Vulnerability Lab (research vulnerability-lab com)

[slackware-security] mozilla-firefox (SSA:2018-085-01) 2018-03-27
Slackware Security Team (security slackware com)

[SECURITY] [DSA 4151-1] librelp security update 2018-03-26
Salvatore Bonaccorso (carnil debian org)

Malware

MSH.Gosopad

Phishing

 

Vulnerebility

Multiple Huawei Products CVE-2017-17167 Information Disclosure Vulnerability
2018-12-15
http://www.securityfocus.com/bid/103513

Google Chrome Prior to 63.0.3239.84 Multiple Security Vulnerabilities
2018-03-27
http://www.securityfocus.com/bid/102098

OpenSSL CVE-2018-0739 Denial of Service Vulnerability
2018-03-27
http://www.securityfocus.com/bid/103518

OpenSSL CVE-2018-0733 Security Bypass Vulnerability
2018-03-27
http://www.securityfocus.com/bid/103517

Apache Struts CVE-2018-1327 Denial of Service Vulnerability
2018-03-27
http://www.securityfocus.com/bid/103516

Nortek Linear eMerge E3 Series CVE-2018-5439 Remote Command Injection Vulnerability
2018-03-26
http://www.securityfocus.com/bid/103053

Mozilla Firefox and Firefox ESR CVE-2018-5148 Use After Free Denial of Service Vulnerability
2018-03-26
http://www.securityfocus.com/bid/103506

Symantec Norton App Lock for Android CVE-2017-15534 Local Authentication Bypass Vulnerability
2018-03-26
http://www.securityfocus.com/bid/103377

Multiple AMD Processors Multiple Remote Security Vulnerabilities
2018-03-23
http://www.securityfocus.com/bid/103409

ARM mbed TLS CVE-2017-18187 Integer Overflow Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103055

ARM mbed TLS CVE-2018-0488 Remote Code Execution Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103057

ARM mbed TLS CVE-2018-0487 Remote Code Execution Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103056

Memcached Multiple Integer Overflow Vulnerabilities
2018-03-23
http://www.securityfocus.com/bid/94083

Memcached CVE-2017-9951 Incomplete Fix Integer Overflow Vulnerability
2018-03-23
http://www.securityfocus.com/bid/99874

SANS News

Side-channel information leakage in mobile applications

Threatpost

Sanny Malware Updates Delivery Method

Facebook Woes Continue as FTC Opens Data Privacy Probe

Exploint

ClipBucket - beats_uploader Unauthenticated Arbitrary File Upload (Metasploit)

26 .3.2018

Bugtraq

Cross-Site Scripting vulnerability in Zimbra Collaboration Suite due to the way it handles attachment links 2018-03-24
Securify B.V. (lists securify nl)

[slackware-security] mozilla-thunderbird (SSA:2018-082-01) 2018-03-24
Slackware Security Team (security slackware com)

[SECURITY] [DSA 4150-1] icu security update 2018-03-23
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 4149-1] plexus-utils2 security update 2018-03-22
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 4148-1] kamailio security update 2018-03-22
Moritz Muehlenhoff (jmm debian org)

Malware

Trojan.Ipafanli

Phishing

 

Vulnerebility

Nortek Linear eMerge E3 Series CVE-2018-5439 Remote Command Injection Vulnerability
2018-03-26
http://www.securityfocus.com/bid/103053

Symantec Norton App Lock for Android CVE-2017-15534 Local Authentication Bypass Vulnerability
2018-03-26
http://www.securityfocus.com/bid/103377

Multiple AMD Processors Multiple Remote Security Vulnerabilities
2018-03-23
http://www.securityfocus.com/bid/103409

ARM mbed TLS CVE-2017-18187 Integer Overflow Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103055

ARM mbed TLS CVE-2018-0488 Remote Code Execution Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103057

ARM mbed TLS CVE-2018-0487 Remote Code Execution Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103056

SANS News

Windows IRC Bot in the Wild

Threatpost

Facebook Woes Continue as FTC Opens Data Privacy Probe

FBI: Iranian Firm Stole Data In Massive Spear Phishing Campaign

Exploint

Acrolinx Server < 5.2.5 - Directory Traversal

Laravel Log Viewer < 0.13.0 - Local File Download

LabF nfsAxe 3.7 - Privilege Escalation

Fast AVI MPEG Splitter 1.2 - Stack-Based Buffer Overflow

24 .3.2018

Bugtraq

[SECURITY] [DSA 4149-1] plexus-utils2 security update 2018-03-22
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 4148-1] kamailio security update 2018-03-22
Moritz Muehlenhoff (jmm debian org)

ModSecurity WAF 3.0 for Nginx - Denial of Service 2018-03-22
x ksi (s3810 pjwstk edu pl)

Bomgar Remote Support Portal JavaStart Applet <= 52970 - Path Traversal 2018-03-22
x ksi (s3810 pjwstk edu pl)

Kaseya AgentMon.exe <= 9.3.0.11 - Local Privilege Escalation 2018-03-22
x ksi (s3810 pjwstk edu pl)

Malware

 

Phishing

 

Vulnerebility

Multiple AMD Processors Multiple Remote Security Vulnerabilities
2018-03-23
http://www.securityfocus.com/bid/103409

ARM mbed TLS CVE-2017-18187 Integer Overflow Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103055

ARM mbed TLS CVE-2018-0488 Remote Code Execution Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103057

ARM mbed TLS CVE-2018-0487 Remote Code Execution Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103056

Memcached Multiple Integer Overflow Vulnerabilities
2018-03-23
http://www.securityfocus.com/bid/94083

Memcached CVE-2017-9951 Incomplete Fix Integer Overflow Vulnerability
2018-03-23
http://www.securityfocus.com/bid/99874

Memcached verbose mode CVE-2013-7291 Denial of Service Vulnerability
2018-03-23
http://www.securityfocus.com/bid/64989

memcache SASL Authentication Security Bypass Vulnerability
2018-03-23
http://www.securityfocus.com/bid/64559

memcached Verbose Mode Denial of Service Vulnerability
2018-03-23
http://www.securityfocus.com/bid/64978

Memcached 'items.c' Denial of Service Vulnerability
2018-03-23
http://www.securityfocus.com/bid/64988

memcached Remote Denial of Service Vulnerability
2018-03-23
http://www.securityfocus.com/bid/59567

Qemu CVE-2018-7550 Out of Bounds Read and Write Arbitrary Code Execution Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103181

QEMU CVE-2018-5683 Denial of Service Vulnerability
2018-03-23
http://www.securityfocus.com/bid/102518

Multiple CPU Hardware CVE-2017-5715 Information Disclosure Vulnerability
2018-03-23
http://www.securityfocus.com/bid/102376

Linux Kernel CVE-2018-1068 Local Privilege Escalation Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103459

Linux Kernel 'drivers/net/wireless/mac80211_hwsim.c' Local Denial of Service Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103397

Xen 'xen/common/grant_table.c' Denial of Service Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103177

Xen 'xen/common/memory.c' Denial of Service vulnerability
2018-03-23
http://www.securityfocus.com/bid/103174

Open vSwitch CVE-2016-2074 Multiple Buffer Overflow Vulnerabilities
2018-03-23
http://www.securityfocus.com/bid/85700

SIMATIC WinCC OA UI CVE-2018-4844 Access Bypass Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103475

Google Updater for MacOS CVE-2018-6084 Local Privilege Escalation Vulnerability
2018-03-22
http://www.securityfocus.com/bid/103468

Atlassian Bitbucket Server CVE-2018-5225 Remote Code Execution Vulnerability
2018-03-22
http://www.securityfocus.com/bid/103488

Beckhoff TwinCAT CVE-2018-7502 Multiple Local Privilege Escalation Vulnerabilities
2018-03-22
http://www.securityfocus.com/bid/103487

Linux Kernel CVE-2018-8822 Multiple Memory Corruption Vulnerabilities
2018-03-22
http://www.securityfocus.com/bid/103476

Linux Kernel CVE-2017-17806 Stack Based Buffer Overflow Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102293

Linux Kernel CVE-2017-17741 Denial of Service Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102227

Linux kernel Multiple CVE-2017-17805 Local Denial of Service Vulnerabilities
2018-03-21
http://www.securityfocus.com/bid/102291

Linux Kernel CVE-2017-17807 Local Denial of Service Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102301

Multiple CPU Hardware CVE-2017-5754 Information Disclosure Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102378

Linux Kernel 'net/netlink/af_netlink.c' Local Information Disclosure Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102122

SANS News

"Error 19874: You must have Office Professional Edition to read this content, please upgrade your licence."

Threatpost

Senate Gives Nod To Controversial Cross-Border Data Access Bill

A Closer Look at APT Group Sofacy’s Latest Targets

Exploint

 

23 .3.2018

Bugtraq

[SECURITY] [DSA 4149-1] plexus-utils2 security update 2018-03-22
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 4148-1] kamailio security update 2018-03-22
Moritz Muehlenhoff (jmm debian org)

ModSecurity WAF 3.0 for Nginx - Denial of Service 2018-03-22
x ksi (s3810 pjwstk edu pl)

Bomgar Remote Support Portal JavaStart Applet <= 52970 - Path Traversal 2018-03-22
x ksi (s3810 pjwstk edu pl)

Kaseya AgentMon.exe <= 9.3.0.11 - Local Privilege Escalation 2018-03-22
x ksi (s3810 pjwstk edu pl)

Secunia Research: Microsoft Windows Embedded OpenType Font Engine hdmx Table Information Disclosure Vulnerability 2018-03-21
Secunia Research (remove-vuln secunia com)

Advisory - Bitbucket Server - CVE-2018-5225 2018-03-22
Matthew Hart (mhart atlassian com)

Malware

Win64/CoinMiner

JS/CoinMiner

Phishing

 

Vulnerebility

Multiple AMD Processors Multiple Remote Security Vulnerabilities
2018-03-23
http://www.securityfocus.com/bid/103409

ARM mbed TLS CVE-2017-18187 Integer Overflow Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103055

ARM mbed TLS CVE-2018-0488 Remote Code Execution Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103057

ARM mbed TLS CVE-2018-0487 Remote Code Execution Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103056

Memcached Multiple Integer Overflow Vulnerabilities
2018-03-23
http://www.securityfocus.com/bid/94083

Memcached CVE-2017-9951 Incomplete Fix Integer Overflow Vulnerability
2018-03-23
http://www.securityfocus.com/bid/99874

Memcached verbose mode CVE-2013-7291 Denial of Service Vulnerability
2018-03-23
http://www.securityfocus.com/bid/64989

memcache SASL Authentication Security Bypass Vulnerability
2018-03-23
http://www.securityfocus.com/bid/64559

memcached Verbose Mode Denial of Service Vulnerability
2018-03-23
http://www.securityfocus.com/bid/64978

Memcached 'items.c' Denial of Service Vulnerability
2018-03-23
http://www.securityfocus.com/bid/64988

memcached Remote Denial of Service Vulnerability
2018-03-23
http://www.securityfocus.com/bid/59567

Qemu CVE-2018-7550 Out of Bounds Read and Write Arbitrary Code Execution Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103181

QEMU CVE-2018-5683 Denial of Service Vulnerability
2018-03-23
http://www.securityfocus.com/bid/102518

Multiple CPU Hardware CVE-2017-5715 Information Disclosure Vulnerability
2018-03-23
http://www.securityfocus.com/bid/102376

Linux Kernel CVE-2018-1068 Local Privilege Escalation Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103459

Linux Kernel 'drivers/net/wireless/mac80211_hwsim.c' Local Denial of Service Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103397

Xen 'xen/common/grant_table.c' Denial of Service Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103177

Xen 'xen/common/memory.c' Denial of Service vulnerability
2018-03-23
http://www.securityfocus.com/bid/103174

Open vSwitch CVE-2016-2074 Multiple Buffer Overflow Vulnerabilities
2018-03-23
http://www.securityfocus.com/bid/85700

SIMATIC WinCC OA UI CVE-2018-4844 Access Bypass Vulnerability
2018-03-23
http://www.securityfocus.com/bid/103475

Google Updater for MacOS CVE-2018-6084 Local Privilege Escalation Vulnerability
2018-03-22
http://www.securityfocus.com/bid/103468

Atlassian Bitbucket Server CVE-2018-5225 Remote Code Execution Vulnerability
2018-03-22
http://www.securityfocus.com/bid/103488

Beckhoff TwinCAT CVE-2018-7502 Multiple Local Privilege Escalation Vulnerabilities
2018-03-22
http://www.securityfocus.com/bid/103487

Linux Kernel CVE-2018-8822 Multiple Memory Corruption Vulnerabilities
2018-03-22
http://www.securityfocus.com/bid/103476

Linux Kernel CVE-2017-17806 Stack Based Buffer Overflow Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102293

Linux Kernel CVE-2017-17741 Denial of Service Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102227

Linux kernel Multiple CVE-2017-17805 Local Denial of Service Vulnerabilities
2018-03-21
http://www.securityfocus.com/bid/102291

Linux Kernel CVE-2017-17807 Local Denial of Service Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102301

Multiple CPU Hardware CVE-2017-5754 Information Disclosure Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102378

Linux Kernel 'net/netlink/af_netlink.c' Local Information Disclosure Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102122

SANS News

Extending Hunting Capabilities in Your Network

Threatpost

A Closer Look at APT Group Sofacy’s Latest Targets

Drupal Forewarns ‘Highly Critical’ Bug to be Patched Next Week

Orbitz Warns 880,000 Payment Cards Suspected Stolen

Exploint

Linux Kernel < 4.15.4 - 'show_floppy' KASLR Address Leak

Wordpress Plugin Site Editor 1.1.1 - Local File Inclusion

MyBB Plugin Last User's Threads in Profile Plugin 1.2 - Persistent Cross-Site Scripting

XenForo 2 - CSS Loader Denial of Service

TL-WR720N 150Mbps Wireless N Router - Cross-Site Request Forgery

Hikvision IP Camera versions 5.2.0 - 5.3.9 (Builds 140721 - 170109) - Access Control...

Easy CD DVD Copy 1.3.24 - Local Buffer Overflow (SEH)

Crashmail 1.6 - Stack-Based Buffer Overflow ( ROP execve )

Allok Quicktime to AVI MPEG DVD Converter 4.6.1217 - Stack-Based Buffer Overflow

Linux Kernel < 4.15.4 - 'show_floppy' KASLR Address Leak

Easy Avi Divx Xvid to DVD Burner 2.9.11 - '.avi' Denial of Service

WM Recorder 16.8.1 - Denial of Service

Dell EMC NetWorker - Denial of Service

Android Bluetooth - BNEP BNEP_SETUP_CONNECTION_REQUEST_MSG Out-of-Bounds Read

Android Bluetooth - BNEP bnep_data_ind() Remote Heap Disclosure

22 .3.2018

Bugtraq

ModSecurity WAF 3.0 for Nginx - Denial of Service 2018-03-22
x ksi (s3810 pjwstk edu pl)

Bomgar Remote Support Portal JavaStart Applet <= 52970 - Path Traversal 2018-03-22
x ksi (s3810 pjwstk edu pl)

Kaseya AgentMon.exe <= 9.3.0.11 - Local Privilege Escalation 2018-03-22
x ksi (s3810 pjwstk edu pl)

Secunia Research: Microsoft Windows Embedded OpenType Font Engine hdmx Table Information Disclosure Vulnerability 2018-03-21
Secunia Research (remove-vuln secunia com)

Advisory - Bitbucket Server - CVE-2018-5225 2018-03-22
Matthew Hart (mhart atlassian com)

Secunia Research: Microsoft Windows Embedded OpenType Font Engine "MTX_IS_MTX_Data()" Information Disclosure Vulnerability 2018-03-21
Secunia Research (remove-vuln secunia com)

Secunia Research: Microsoft Windows Embedded OpenType Font Engine Font Glyphs Handling Information Disclosure Vulnerability 2018-03-21
Secunia Research (remove-vuln secunia com)

[SECURITY] [DSA 4147-1] polarssl security update 2018-03-21
Sebastien Delafond (seb debian org)

[SECURITY] [DSA 4146-1] plexus-utils security update 2018-03-20
Moritz Muehlenhoff (jmm debian org)

CSNC-2017-026 Microsoft Intune - Preserved Keychain Entries 2018-03-20
Advisories (advisories compass-security com) (1 replies)

Malware

Trojan.Fakeinstall

Phishing

 

Vulnerebility

Linux Kernel CVE-2017-17806 Stack Based Buffer Overflow Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102293

Linux Kernel CVE-2017-17741 Denial of Service Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102227

Linux kernel Multiple CVE-2017-17805 Local Denial of Service Vulnerabilities
2018-03-21
http://www.securityfocus.com/bid/102291

Linux Kernel CVE-2017-17807 Local Denial of Service Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102301

Multiple CPU Hardware CVE-2017-5754 Information Disclosure Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102378

Linux Kernel 'net/netlink/af_netlink.c' Local Information Disclosure Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102122

Linux Kernel CVE-2017-1000410 Information Disclosure Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102101

Linux Kernel 'arch/x86/kvm/vmx.c' Denial of Service Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102038

Linux Kernel CVE-2017-8824 Local Privilege Escalation Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102056

Linux Kernel CVE-2017-15868 Local Privilege Escalation Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102084

Linux Kernel 'net/netfilter/nfnetlink_cthelper.c' Local Security Bypass Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102117

Linux Kernel CVE-2017-16939 Local Privilege Escalation Vulnerability
2018-03-21
http://www.securityfocus.com/bid/101954

Linux Kernel '/netfilter/xt_osf.c' Local Security Bypass Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102110

ISC BIND CVE-2017-3145 Remote Denial of Service Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102716

Google Updater for MacOS CVE-2018-6084 Local Privilege Escalation Vulnerability
2018-03-21
http://www.securityfocus.com/bid/103468

Multiple CPU Hardware CVE-2017-5715 Information Disclosure Vulnerability
2018-03-20
http://www.securityfocus.com/bid/102376

SANS News

Automatic Hunting for Malicous Files Crossing your Network

Threatpost

Netflix Opens Public Bug Bounty Program with $15K Payout Cap

Orbitz Warns 880,000 Payment Cards Suspected Stolen

Experts Call Facebook’s Latest Controversy a Social Media ‘Breach Of Trust’

Exploint

 

21 .3.2018

Bugtraq

[SECURITY] [DSA 4146-1] plexus-utils security update 2018-03-20
Moritz Muehlenhoff (jmm debian org)

CSNC-2017-026 Microsoft Intune - Preserved Keychain Entries 2018-03-20
Advisories (advisories compass-security com) (1 replies)

Unsubscribe - Re: CSNC-2017-026 Microsoft Intune - Preserved Keychain Entries 2018-03-20
Gary Frank (garoo7 hotmail com)

ES2018-05 Kamailio heap overflow 2018-03-20
Sandro Gauci (sandro enablesecurity com) (1 replies)

Unsubscribe - Re: ES2018-05 Kamailio heap overflow 2018-03-20
Gary Frank (garoo7 hotmail com)

[SECURITY] [DSA 4145-1] gitlab security update 2018-03-18
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 4142-1] uwsgi security update 2018-03-17
Salvatore Bonaccorso (carnil debian org)

Malware

Exp.CVE-2018-4897

Exp.CVE-2018-4898

Exp.CVE-2018-4920

Exp.CVE-2018-4899

Exp.CVE-2018-4919

Exp.CVE-2018-4900

Exp.CVE-2018-4902

Exp.CVE-2018-4901

Exp.CVE-2018-4915

Exp.CVE-2018-4905

Exp.CVE-2018-4913

Exp.CVE-2018-4907

Exp.CVE-2018-4910

Exp.CVE-2018-4909

Exp.CVE-2018-4914

Exp.CVE-2018-4889

Exp.CVE-2018-4890

Exp.CVE-2018-4892

Exp.CVE-2018-4895

Exp.CVE-2018-4896

Exp.CVE-2018-4887

Exp.CVE-2018-4882

Exp.CVE-2018-4883

Exp.CVE-2018-4885

Exp.CVE-2018-4879

Exp.CVE-2018-4903

Exp.CVE-2018-4904

Exp.CVE-2018-4906

Exp.CVE-2018-4912

Exp.CVE-2018-4908

Phishing

 

Vulnerebility

Linux Kernel CVE-2017-17806 Stack Based Buffer Overflow Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102293

Linux Kernel CVE-2017-17741 Denial of Service Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102227

Linux kernel Multiple CVE-2017-17805 Local Denial of Service Vulnerabilities
2018-03-21
http://www.securityfocus.com/bid/102291

Linux Kernel CVE-2017-17807 Local Denial of Service Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102301

Multiple CPU Hardware CVE-2017-5754 Information Disclosure Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102378

Linux Kernel 'net/netlink/af_netlink.c' Local Information Disclosure Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102122

Linux Kernel CVE-2017-1000410 Information Disclosure Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102101

Linux Kernel 'arch/x86/kvm/vmx.c' Denial of Service Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102038

Linux Kernel CVE-2017-8824 Local Privilege Escalation Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102056

Linux Kernel CVE-2017-15868 Local Privilege Escalation Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102084

Linux Kernel 'net/netfilter/nfnetlink_cthelper.c' Local Security Bypass Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102117

Linux Kernel CVE-2017-16939 Local Privilege Escalation Vulnerability
2018-03-21
http://www.securityfocus.com/bid/101954

Linux Kernel '/netfilter/xt_osf.c' Local Security Bypass Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102110

ISC BIND CVE-2017-3145 Remote Denial of Service Vulnerability
2018-03-21
http://www.securityfocus.com/bid/102716

Google Updater for MacOS CVE-2018-6084 Local Privilege Escalation Vulnerability
2018-03-21
http://www.securityfocus.com/bid/103468

Multiple CPU Hardware CVE-2017-5715 Information Disclosure Vulnerability
2018-03-20
http://www.securityfocus.com/bid/102376

Multiple CPU Hardware CVE-2017-5753 Information Disclosure Vulnerability
2018-03-20
http://www.securityfocus.com/bid/102371

Siemens SIMATIC/SINUMERIK/PROFINET IO CVE-2018-4843 Denial of Service Vulnerability
2018-03-20
http://www.securityfocus.com/bid/103465

Bouncy Castle BKS-V1 CVE-2018-5382 Security Weakness
2018-03-19
http://www.securityfocus.com/bid/103453

SANS News

Surge in blackmailing?

Administrator's Password Bad Practice 

Threatpost

Telegram Ordered to Hand Over Encryption Keys to Russian Authorities

Facebook Data Privacy Policies Bashed By Critics After Cambridge Analytica Incident

A Mirai Botnet Postscript: Lessons Learned

Exploint

Microsoft Windows - Desktop Bridge Virtual Registry NtLoadKey Arbitrary File Read/Write...

Microsoft Windows - Desktop Bridge Virtual Registry Arbitrary File Read/Write Privilege...
Microsoft Windows - Desktop Bridge VFS Privilege Escalation

Microsoft Windows Kernel - 'nt!NtWaitForDebugEvent' 64-bit Stack Memory Disclosure

Microsoft Windows Kernel - 'nt!KiDispatchException' 64-bit Stack Memory Disclosure

Microsoft Windows Kernel - 'NtQueryInformationThread(ThreadBasicInformation)' 64-bit...

Microsoft Windows Kernel - 'NtQueryVirtualMemory(MemoryMappedFilenameInformation)' 64-bit...

Google Software Updater macOS - Unsafe use of Distributed Objects Privilege Escalation

Cisco node-jos < 0.11.0 - Re-sign Tokens

Vehicle Sales Management System - Multiple Vulnerabilities

Intelbras Telefone IP TIP200 LITE - Local File Disclosure
Cisco node-jos < 0.11.0 - Re-sign Tokens

Linux/x86 - execve(/bin/sh) Shellcode (18 bytes)

 

19 .3.2018

Bugtraq

[SECURITY] [DSA 4145-1] gitlab security update 2018-03-18
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 4142-1] uwsgi security update 2018-03-17
Salvatore Bonaccorso (carnil debian org)

[slackware-security] libvorbis (SSA:2018-076-01) 2018-03-18
Slackware Security Team (security slackware com)

[SECURITY] [DSA 4143-1] firefox-esr security update 2018-03-17
Moritz Muehlenhoff (jmm debian org)

[slackware-security] mozilla-firefox (SSA:2018-075-01) 2018-03-17
Slackware Security Team (security slackware com)

[SECURITY] [DSA 4144-1] openjdk-8 security update 2018-03-17
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 4141-1] libvorbisidec security update 2018-03-16
Salvatore Bonaccorso (carnil debian org)

Malware

Backdoor.Teawhy

Phishing

 

Vulnerebility

 

SANS News

 

Threatpost

 

Exploint

Linux Kernel < 4.4.0-21 (Ubuntu 16.04 x64) - 'netfilter target_offset' Local Privilege...

Linux Kernel < 3.5.0-23 (Ubuntu 12.04.2 x64) - 'SOCK_DIAG' SMEP Bypass Local Privilege...

Linux Kernel < 4.4.0-116 (Ubuntu 16.04.4) - Local Privilege Escalation

18 .3.2018

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

 

SANS News

[Wireshark-announce] Wireshark 2.5.1 is now available

Wireshark and USB

Threatpost

 

Exploint

Firefox 44.0.2 - ASM.JS JIT-Spray Remote Code Execution
Firefox 46.0.1 - ASM.JS JIT-Spray Remote Code Execution

MikroTik RouterOS < 6.41.3/6.42rc27 - SMB Buffer Overflow

SAP NetWeaver AS JAVA CRM - Log injection Remote Command Execution

Contec Smart Home 4.15 - Unauthorized Password Reset

Android DRM Services - Buffer Overflow

16 .3.2018

Bugtraq

[SECURITY] [DSA 4139-1] firefox-esr security update 2018-03-15
Moritz Muehlenhoff (jmm debian org)

[slackware-security] curl (SSA:2018-074-01) 2018-03-16
Slackware Security Team (security slackware com)

Secunia Research: LibRaw Multiple Denial of Service Vulnerabilities 2018-03-15
Secunia Research (remove-vuln secunia com)

[SECURITY] [DSA 4138-1] mbedtls security update 2018-03-15
Sebastien Delafond (seb debian org)

[SECURITY] [DSA 4137-1] libvirt security update 2018-03-14
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 4136-1] curl security update 2018-03-14
Alessandro Ghedini (ghedo debian org)

SEC Consult SA-20180314-0 :: Arbitrary Shortcode Execution & Local File Inclusion in WooCommerce Products Filter (PluginUs.Net) 2018-03-14
SEC Consult Vulnerability Lab (research sec-consult com)

Malware

Backdoor.Ohlotus

W32.Xiaobaminer

Phishing

 

Vulnerebility

Linux Kernel CVE-2017-18232 Local Denial of Service Vulnerability
2018-03-16
http://www.securityfocus.com/bid/103423

MikroTik RouterOS CVE-2018-7445 Buffer Overflow Vulnerability
2018-03-15
http://www.securityfocus.com/bid/103427

ZOHO ManageEngine Event LogAnalyzer CVE-2018-8721 HTML Injection Vulnerability
2018-03-15
http://www.securityfocus.com/bid/103424

IBM DB2 CVE-2017-1677 Local Arbitrary Code Execution Vulnerability
2018-03-14
http://www.securityfocus.com/bid/103422

cURL/libcURL CVE-2018-1000121 Denial of Service Vulnerability
2018-03-14
http://www.securityfocus.com/bid/103415

cURL/libcURL CVE-2018-1000120 Buffer Overflow Vulnerability
2018-03-14
http://www.securityfocus.com/bid/103414

spice-gtk CVE-2017-12194 Integer Overflow Vulnerability
2018-03-14
http://www.securityfocus.com/bid/103413

SANS News

 

Threatpost

Intel Details CPU ‘Virtual Fences’ Fix As Safeguard Against Spectre, Meltdown Flaws

GandCrab Ransomware Crooks Take Agile Development Approach

Walmart Jewelry Partner Exposes Personal Data Of 1.3M Customers

Iran-Linked Group ‘TEMP.Zagros’ Updates Tactics, Techniques In Latest Campaign

Exploint

 

15 .3.2018

Bugtraq

[SECURITY] [DSA 4137-1] libvirt security update 2018-03-14
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 4136-1] curl security update 2018-03-14
Alessandro Ghedini (ghedo debian org)

SEC Consult SA-20180314-0 :: Arbitrary Shortcode Execution & Local File Inclusion in WooCommerce Products Filter (PluginUs.Net) 2018-03-14
SEC Consult Vulnerability Lab (research sec-consult com)

FreeBSD Security Advisory FreeBSD-SA-18:03.speculative_execution 2018-03-14
FreeBSD Security Advisories (security-advisories freebsd org)

[slackware-security] mozilla-firefox (SSA:2018-072-01) 2018-03-13
Slackware Security Team (security slackware com)

Malware

Downloader.Miner

Phishing

 

Vulnerebility

cURL/libcURL CVE-2018-1000121 Denial of Service Vulnerability
2018-03-14
http://www.securityfocus.com/bid/103415

cURL/libcURL CVE-2018-1000120 Buffer Overflow Vulnerability
2018-03-14
http://www.securityfocus.com/bid/103414

spice-gtk CVE-2017-12194 Integer Overflow Vulnerability
2018-03-14
http://www.securityfocus.com/bid/103413

Multiple AMD Processors Multiple Remote Security Vulnerabilities
2018-03-14
http://www.securityfocus.com/bid/103409

SAP HANA CVE-2018-2369 Information Disclosure Vulnerability
2018-03-13
http://www.securityfocus.com/bid/102997

GE Medical Devices CVE-2017-14002 Authentication Bypass Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103405

GE Medical Devices CVE-2017-14008 Authentication Bypass Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103400

OSIsoft PI Data Archive Privilege Escalation and Denial of Service Vulnerabilities
2018-03-13
http://www.securityfocus.com/bid/103399

OSIsoft PI Web API Privilege Escalation and Cross Site Scripting Vulnerabilities
2018-03-13
http://www.securityfocus.com/bid/103396

Adobe Dreamweaver CC CVE-2018-4924 OS Command Injection Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103395

Omron CX-Supervisor Multiple Security Vulnerabilities
2018-03-13
http://www.securityfocus.com/bid/103394

Adobe Connect CVE-2018-4921 Arbitrary File Upload Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103393

Adobe Connect CVE-2018-4923 OS Command Injection Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103391

OSIsoft PI Vision Cross Site Scripting and Information Disclosure Vulnerabilities
2018-03-13
http://www.securityfocus.com/bid/103390

Mozilla Firefox and Firefox ESR Multiple Security Vulnerabilities
2018-03-13
http://www.securityfocus.com/bid/103388

Samba CVE-2018-1050 Remote Denial of Service Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103387

Mozilla Firefox MFSA2018-06 Multiple Security Vulnerabilities
2018-03-13
http://www.securityfocus.com/bid/103386

Adobe Flash Player CVE-2018-4919 Use After Free Remote Code Execution Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103385

SANS News

SPECTRE and Meltdown To patch or not to patch?..and HOW (Guest Diary)

Threatpost

Hyperbole Swirls Around AMD Processor Security Threat

Iran-Linked Group ‘TEMP.Zagros’ Updates Tactics, Techniques In Latest Campaign

Exploint

Spring Data REST < 2.6.9 (Ingalls SR9), 3.0.1 (Kay SR1) - PATCH Request Remote Code...

WordPress Plugin Duplicator 1.2.32 - Cross-Site Scripting

14 .3.2018

Bugtraq

FreeBSD Security Advisory FreeBSD-SA-18:03.speculative_execution 2018-03-14
FreeBSD Security Advisories (security-advisories freebsd org)

[slackware-security] mozilla-firefox (SSA:2018-072-01) 2018-03-13
Slackware Security Team (security slackware com)

[slackware-security] samba (SSA:2018-072-02) 2018-03-13
Slackware Security Team (security slackware com)

[RT-SA-2017-012] Shopware Cart Accessible by Third-Party Websites 2018-03-13
RedTeam Pentesting GmbH (release redteam-pentesting de)

[SECURITY] [DSA 4135-1] samba security update 2018-03-13
Salvatore Bonaccorso (carnil debian org)

Malware

Exp.CVE-2018-0872

Exp.CVE-2018-0874

Exp.CVE-2018-0889

Exp.CVE-2018-0893

Exp.CVE-2018-0930

Exp.CVE-2018-0933

Exp.CVE-2018-0934

Exp.CVE-2018-0817

Exp.CVE-2018-0877

Exp.CVE-2018-0880

Ransom.DataKeeper

Phishing

 

Vulnerebility

SAP HANA CVE-2018-2369 Information Disclosure Vulnerability
2018-03-13
http://www.securityfocus.com/bid/102997

Mozilla Firefox and Firefox ESR Multiple Security Vulnerabilities
2018-03-13
http://www.securityfocus.com/bid/103388

Samba CVE-2018-1050 Remote Denial of Service Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103387

Mozilla Firefox MFSA2018-06 Multiple Security Vulnerabilities
2018-03-13
http://www.securityfocus.com/bid/103386

Adobe Flash Player CVE-2018-4919 Use After Free Remote Code Execution Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103385

Mozilla Firefox ESR Multiple Security Vulnerabilities
2018-03-13
http://www.securityfocus.com/bid/103384

SANS News

Malspam pushing Sigma ransomware

Microsoft March 2018 Patch Tuesday

Threatpost

Microsoft Patches 15 Critical Bugs in March Patch Tuesday Update

Samba Patches Two Critical Vulnerabilities in Server Software

China-Linked APT15 Used Myriad of New Tools To Hack UK Government Contractor

Exploint

 

13 .3.2018

Bugtraq

[RT-SA-2017-012] Shopware Cart Accessible by Third-Party Websites 2018-03-13
RedTeam Pentesting GmbH (release redteam-pentesting de)

[SECURITY] [DSA 4135-1] samba security update 2018-03-13
Salvatore Bonaccorso (carnil debian org)

SEC Consult SA-20180312-0 :: Multiple Critical Vulnerabilities in SecurEnvoy SecurMail 2018-03-12
SEC Consult Vulnerability Lab (research sec-consult com)

[SECURITY] [DSA 4134-1] util-linux security update 2018-03-10
Salvatore Bonaccorso (carnil debian org)

Malware

Ransom.Rapid

Phishing

 

Vulnerebility

SAP HANA CVE-2018-2369 Information Disclosure Vulnerability
2018-03-13
http://www.securityfocus.com/bid/102997

REDWOOD Business Process Automation CVE-2018-2400 Information Disclosure Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103375

REDWOOD Business Process Automation CVE-2018-2401 XML External Entity Injection Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103374

SAP Business Objects Business Intelligence Platform CVE-2018-2397 Cross Site Scripting Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103373

SAP Process Monitoring Infrastructure CVE-2018-2399 Cross Site Scripting Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103372

REDWOOD Business Process Automation CVE-2018-2366 Directory Traversal Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103371

SAP NetWeaver Business Client CVE-2018-2398 Unspecified Information Disclosure Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103370

SAP HANA CVE-2018-2402 Information Disclosure Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103369

Microsoft SharePoint Server CVE-2018-0910 Remote Privilege Escalation Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103280

Microsoft SharePoint Server CVE-2018-0909 Remote Privilege Escalation Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103279

Microsoft ChakraCore Scripting Engine CVE-2018-0936 Remote Memory Corruption Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103270

Microsoft ChakraCore Scripting Engine CVE-2018-0874 Remote Memory Corruption Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103269

Microsoft ChakraCore Scripting Engine CVE-2018-0873 Remote Memory Corruption Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103268

Microsoft ChakraCore Scripting Engine CVE-2018-0872 Remote Memory Corruption Vulnerability
2018-03-13
http://www.securityfocus.com/bid/103267

Cisco Secure Access Control System CVE-2018-0147 Deserialization Remote Code Execution Vulnerability
2018-03-12
http://www.securityfocus.com/bid/103328

Samba CVE-2018-1057 Remote Security Bypass Vulnerability
2018-03-12
http://www.securityfocus.com/bid/103382

Linux Kernel 'fs/ocfs2/aops.c' Local Denial of Service Vulnerability
2018-03-11
http://www.securityfocus.com/bid/103353

SANS News

How did it all start? Early Memcached DDoS Attack Precursors and Ransom Notes

Threatpost

CCleaner Attackers Intended To Deploy Keylogger In Third Stage

Exploint

Tuleap 9.17.99.189 - Blind SQL Injection

SecurEnvoy SecurMail 9.1.501 - Multiple Vulnerabilities

ACL Analytics 11.X - 13.0.0.579 - Arbitrary Code Execution

MikroTik RouterOS < 6.38.4 (x86) - 'Chimay Red' Stack Clash Remote Code Execution

MikroTik RouterOS < 6.38.4 (MIPSBE) - 'Chimay Red' Stack Clash Remote Code Execution

Eclipse Equinoxe OSGi Console - Command Execution (Metasploit)

DEWESoft X3 SP1 (64-bit) - Remote Command Execution

ACL Analytics 11.X - 13.0.0.579 - Arbitrary Code Execution

Advantech WebAccess < 8.3 - Directory Traversal / Remote Code Execution

SC 7.16 - Stack-Based Buffer Overflow

Sony Playstation 4 (PS4) 4.55 < 5.50 - WebKit Code Execution (PoC)

12 .3.2018

Bugtraq

[SECURITY] [DSA 4134-1] util-linux security update 2018-03-10
Salvatore Bonaccorso (carnil debian org)

[RT-SA-2018-001] Arbitrary Redirect in Tuleap 2018-03-08
RedTeam Pentesting GmbH (release redteam-pentesting de)

FreeBSD Security Advisory FreeBSD-SA-18:01.ipsec [REVISED] 2018-03-08
FreeBSD Security Advisories (security-advisories freebsd org)

Malware

 

Phishing

 

Vulnerebility

Cisco Secure Access Control System CVE-2018-0147 Deserialization Remote Code Execution Vulnerability
2018-03-12
http://www.securityfocus.com/bid/103328

Linux Kernel 'fs/ocfs2/aops.c' Local Denial of Service Vulnerability
2018-03-11
http://www.securityfocus.com/bid/103353

Zsh 'exec.c:hashcmd()' Function Local Denial of Service Vulnerability
2018-03-09
http://www.securityfocus.com/bid/103359

SANS News

Payload delivery via SMB

Threatpost

 

Exploint

Eclipse Equinoxe OSGi Console - Command Execution (Metasploit)

DEWESoft X3 SP1 (64-bit) - Remote Command Execution

Advantech WebAccess < 8.3 - Directory Traversal / Remote Code Execution

TextPattern 4.6.2 - 'qty' SQL Injection

Prisma Industriale Checkweigher PrismaWEB 1.21 - Hard-Coded Credentials

ManageEngine Applications Manager 13.5 - Remote Code Execution (Metasploit)

SC 7.16 - Stack-Based Buffer Overflow

11 .3.2018

Bugtraq

[RT-SA-2018-001] Arbitrary Redirect in Tuleap 2018-03-08
RedTeam Pentesting GmbH (release redteam-pentesting de)

Malware

 

Phishing

 

Vulnerebility

 

SANS News

 

Threatpost

Cyber Espionage Campaign ‘Slingshot’ Targets Victims Via Routers

Exploint

 

9 .3.2018

Bugtraq

[RT-SA-2018-001] Arbitrary Redirect in Tuleap 2018-03-08
RedTeam Pentesting GmbH (release redteam-pentesting de)

FreeBSD Security Advisory FreeBSD-SA-18:01.ipsec [REVISED] 2018-03-08
FreeBSD Security Advisories (security-advisories freebsd org)

[SECURITY] [DSA 4133-1] isc-dhcp security update 2018-03-07
Salvatore Bonaccorso (carnil debian org)

FreeBSD Security Advisory FreeBSD-SA-18:01.ipsec 2018-03-07
FreeBSD Security Advisories (security-advisories freebsd org)

[SECURITY] [DSA 4128-1] trafficserver security update 2018-03-02
Sebastien Delafond (seb debian org)

Malware

Win32/XeyoRat.C

Phishing

 

Vulnerebility

GraphicsMagick CVE-2017-18219 Denial of Service Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103258

Cisco Identity Services Engine CVE-2018-0221 Local Command Injection Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103347

Cisco StarOS for ASR 5000 Series Routers CVE-2018-0217 Local Command Injection Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103346

Cisco Secure Access Control Server XML External Entity Information Disclosure Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103345

Cisco StarOS for ASR 5000 Series Routers CVE-2018-0224 Local Command Injection Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103344

Cisco Secure Access Control Server XML External Entity Information Disclosure Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103343

Cisco Videoscape AnyRes Live CVE-2018-0220 Cross Site Scripting Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103342

Cisco Security Manager CVE-2018-0223 Cross Site Scripting Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103341

Cisco Registered Envelope Service CVE-2018-0208 Cross Site Scripting Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103337

Cisco Identity Services Engine CVE-2018-0216 Cross Site Request Forgery Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103336

Cisco Data Center Network Manager CVE-2018-0210 Cross Site Request Forgery Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103335

Cisco Identity Services Engine CVE-2018-0211 Local Denial of Service Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103334

Cisco Identity Services Engine CVE-2018-0212 Cross Site Scripting Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103333

Cisco Identity Services Engine CVE-2018-0213 Privilege Escalation Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103332

Cisco Identity Services Engine CVE-2018-0214 Local Command Injection Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103331

Cisco Prime Collaboration Provisioning Hardcoded Credentials Local Security Bypass Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103329

Cisco Secure Access Control System CVE-2018-0147 Deserialization Remote Code Execution Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103328

Cisco Prime Data Center Network Manager CVE-2018-0144 Cross Site Scripting Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103327

Cisco Unified Computing System (UCS) Director CVE-2018-0219 Cross Site Scripting Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103326

Cisco Identity Services Engine CVE-2018-0215 Cross Site Request Forgery Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103324

Linux Kernel 'mm/hugetlb.c' Local Denial of Service Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103316

Linux Kernel 'fs/ocfs2/cluster/nodemanager.c' Local Denial of Service Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103278

Linux Kernel 'drivers/net/ethernet/hisilicon/hns/hns_enet.c' Local Denial of Service Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103277

Multiple Belden Products Multiple Security Vulnerabilities
2018-03-06
http://www.securityfocus.com/bid/103340

Multiple Schneider Electric Products CVE-2018-7239 DLL Loading Local Code Execution Vulnerability
2018-03-06
http://www.securityfocus.com/bid/103338

Eaton ELCSoft Programming Software CVE-2018-7511 Multiple Buffer Overflow Vulnerabilities
2018-03-06
http://www.securityfocus.com/bid/103301

Google Chrome Prior to 65.0.3325.146 Multiple Security Vulnerabilities
2018-03-06
http://www.securityfocus.com/bid/103297

EMC RSA Archer GRC Multiple Security Vulnerabilities
2018-03-05
http://www.securityfocus.com/bid/103319

Multiple EMC Products CVE-2018-1182 Local Privilege Escalation Vulnerability
2018-03-05
http://www.securityfocus.com/bid/103317

Google Android Multiple Qualcomm Components Multiple Unspecified Security Vulnerabilities
2018-03-05
http://www.securityfocus.com/bid/103292

SANS News

Apache SOLR: the new target for cryptominers

Threatpost

Security Camera Found Riddled With Bugs

Vulnerability in Robots Can Lead To Costly Ransomware Attacks

Olympic Destroyer: A False Flag Confusion Bomb

Exploint

Bacula-Web < 8.0.0-rc2 - SQL Injection

WebLog Expert Enterprise 9.4 - Authentication Bypass

WebLog Expert Enterprise 9.4 - Denial of Service

Memcached 1.5.5 - 'Memcrashed ' Insufficient Control of Network Message Volume Denial of...

8 .3.2018

Bugtraq

[RT-SA-2018-001] Arbitrary Redirect in Tuleap 2018-03-08
RedTeam Pentesting GmbH (release redteam-pentesting de)

FreeBSD Security Advisory FreeBSD-SA-18:01.ipsec [REVISED] 2018-03-08
FreeBSD Security Advisories (security-advisories freebsd org)

[SECURITY] [DSA 4133-1] isc-dhcp security update 2018-03-07
Salvatore Bonaccorso (carnil debian org)

FreeBSD Security Advisory FreeBSD-SA-18:01.ipsec 2018-03-07
FreeBSD Security Advisories (security-advisories freebsd org)

[SECURITY] [DSA 4128-1] trafficserver security update 2018-03-02
Sebastien Delafond (seb debian org)

Malware

 

Phishing

 

Vulnerebility

GraphicsMagick CVE-2017-18219 Denial of Service Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103258

Cisco Prime Collaboration Provisioning Hardcoded Credentials Local Security Bypass Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103329

Cisco Secure Access Control System CVE-2018-0147 Deserialization Remote Code Execution Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103328

Cisco Prime Data Center Network Manager CVE-2018-0144 Cross Site Scripting Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103327

Cisco Unified Computing System (UCS) Director CVE-2018-0219 Cross Site Scripting Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103326

Cisco Identity Services Engine CVE-2018-0215 Cross Site Request Forgery Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103324

Linux Kernel 'mm/hugetlb.c' Local Denial of Service Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103316

Linux Kernel 'fs/ocfs2/cluster/nodemanager.c' Local Denial of Service Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103278

Linux Kernel 'drivers/net/ethernet/hisilicon/hns/hns_enet.c' Local Denial of Service Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103277

Eaton ELCSoft Programming Software CVE-2018-7511 Multiple Buffer Overflow Vulnerabilities
2018-03-06
http://www.securityfocus.com/bid/103301

Google Chrome Prior to 65.0.3325.146 Multiple Security Vulnerabilities
2018-03-06
http://www.securityfocus.com/bid/103297

EMC RSA Archer GRC Multiple Security Vulnerabilities
2018-03-05
http://www.securityfocus.com/bid/103319

Multiple EMC Products CVE-2018-1182 Local Privilege Escalation Vulnerability
2018-03-05
http://www.securityfocus.com/bid/103317

Google Android Multiple Qualcomm Components Multiple Unspecified Security Vulnerabilities
2018-03-05
http://www.securityfocus.com/bid/103292

Google Android NVIDIA Components Multiple Privilege Escalation Vulnerabilities
2018-03-05
http://www.securityfocus.com/bid/103286

Google Android Kernel Components CVE-2017-16529 Information Disclosure Vulnerability
2018-03-05
http://www.securityfocus.com/bid/103284

GraphicsMagick CVE-2017-18220 Multiple Denial of Service Vulnerabilities
2018-03-05
http://www.securityfocus.com/bid/103276

Google Android Media framework Multiple Remote Code Execution Vulnerabilities
2018-03-05
http://www.securityfocus.com/bid/103255

Google Android Qualcomm Component Multiple Security Vulnerabilities
2018-03-05
http://www.securityfocus.com/bid/103254

Google Android System Component Multiple Security Vulnerabilities
2018-03-05
http://www.securityfocus.com/bid/103253

SANS News

CRIMEB4NK IRC Bot

Threatpost

Lookout: Dark Caracal Points To APT Actors Moving To Mobile Targets

Exploint

antMan 0.9.0c - Authentication Bypass

Redaxo CMS Addon MyEvents 2.2.1 - SQL Injection

7 .3.2018

Bugtraq

FreeBSD Security Advisory FreeBSD-SA-18:01.ipsec 2018-03-07
FreeBSD Security Advisories (security-advisories freebsd org)

[SECURITY] [DSA 4128-1] trafficserver security update 2018-03-02
Sebastien Delafond (seb debian org)

DefenseCode Security Advisory: Magento Backups Cross-Site Request Forgery 2018-03-06
Defense Code (defensecode defensecode com)

KL-001-2018-007 : Sophos UTM 9 loginuser Privilege Escalation via confd Service 2018-03-02
KoreLogic Disclosures (disclosures korelogic com)

[SECURITY] [DSA 4131-1] xen security update 2018-03-04
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 4129-1] freexl security update 2018-03-02
Moritz Muehlenhoff (jmm debian org)

Malware

Trojan.Oldishell

VBS.Tendnob

Trojan.Udpos

Downloader.Powload

Backdoor.Mogefla

Trojan.Shminer

Trojan.Minjen

Win32/XeyoRat.A

Win32/XeyoRat.B

Phishing

 

Vulnerebility

GraphicsMagick CVE-2017-18219 Denial of Service Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103258

Linux Kernel 'fs/ocfs2/cluster/nodemanager.c' Local Denial of Service Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103278

Linux Kernel 'drivers/net/ethernet/hisilicon/hns/hns_enet.c' Local Denial of Service Vulnerability
2018-03-07
http://www.securityfocus.com/bid/103277

Eaton ELCSoft Programming Software CVE-2018-7511 Multiple Buffer Overflow Vulnerabilities
2018-03-06
http://www.securityfocus.com/bid/103301

Google Chrome Prior to 65.0.3325.146 Multiple Security Vulnerabilities
2018-03-06
http://www.securityfocus.com/bid/103297

Google Android Multiple Qualcomm Components Multiple Unspecified Security Vulnerabilities
2018-03-05
http://www.securityfocus.com/bid/103292

Google Android NVIDIA Components Multiple Privilege Escalation Vulnerabilities
2018-03-05
http://www.securityfocus.com/bid/103286

Google Android Kernel Components CVE-2017-16529 Information Disclosure Vulnerability
2018-03-05
http://www.securityfocus.com/bid/103284

GraphicsMagick CVE-2017-18220 Multiple Denial of Service Vulnerabilities
2018-03-05
http://www.securityfocus.com/bid/103276

Google Android Media framework Multiple Remote Code Execution Vulnerabilities
2018-03-05
http://www.securityfocus.com/bid/103255

Google Android Qualcomm Component Multiple Security Vulnerabilities
2018-03-05
http://www.securityfocus.com/bid/103254

Google Android System Component Multiple Security Vulnerabilities
2018-03-05
http://www.securityfocus.com/bid/103253

Red Hat '389-ds-base' CVE-2018-1054 Remote Denial of Service Vulnerability
2018-03-05
http://www.securityfocus.com/bid/103228

SANS News

Ransomware news: GlobeImposter gets a facelift, GandCrab is still out there

Threatpost

POS Malware Found at 160 Applebee’s Restaurant Locations

IoT Security Disconnect: As Attacks Spike, Device Patching Still Lags

Exploint

Bravo Tejari Web Portal - Cross-Site Request Forgery

Memcached - 'memcrashed' Denial of Service

antMan 0.9.0c - Authentication Bypass

Redaxo CMS Addon MyEvents 2.2.1 - SQL Injection

Bravo Tejari Web Portal - Cross-Site Request Forgery

6 .3.2018

Bugtraq

DefenseCode Security Advisory: Magento Multiple Stored Cross-Site Scripting Vulnerabilities 2018-03-06
Defense Code (defensecode defensecode com)

DefenseCode Security Advisory: Magento Stored Cross-Site Scripting â?? Product Attributes 2018-03-06
Defense Code (defensecode defensecode com)

DefenseCode Security Advisory: Magento Stored Cross-Site Scripting â?? Downloadable Products 2018-03-06
Defense Code (defensecode defensecode com)

DefenseCode Security Advisory: Magento Backups Cross-Site Request Forgery 2018-03-06
Defense Code (defensecode defensecode com)

[SECURITY] [DSA 4127-1] simplesamlphp security update 2018-03-02
Thijs Kinkhorst (thijs debian org)

Malware

 

Phishing

 

Vulnerebility

 

SANS News

The joys of changing Privacy Laws

Threatpost

IoT Security Disconnect: As Attacks Spike, Device Patching Still Lags

Cryptomining Gold Rush: One Gang Rakes In $7M Over 6 Months

Exploint

Chrome V8 JIT - Empty BytecodeJumpTable Out-of-Bounds Read

Chrome V8 JIT - 'GetSpecializationContext' Type Confusion

Chrome V8 JIT - JSBuiltinReducer::ReduceObjectCreate Fails to Ensure that the Prototype...

Chrome V8 JIT - Simplified-lowererer IrOpcode::kStoreField, IrOpcode::kStoreElement...

Softros Network Time System Server 2.3.4 - Denial of Service

Memcached - 'memcrashed' Denial of Service

Bravo Tejari Web Portal - Cross-Site Request Forgery

5 .3.2018

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

 

SANS News

The Crypto Miners Fight For CPU Cycles

Malicious Bash Script with Multiple Features

Threatpost

 

Exploint

NETGEAR - 'TelnetEnable' Magic Packet (Metasploit)

ClipBucket < 4.0.0 - Release 4902 - Command Injection / File Upload / SQL Injection

Sophos UTM 9.410 - 'loginuser' 'confd' Service Privilege Escalation

Dup Scout Enterprise 10.5.12 - 'Share Username' Local Buffer Overflow

Xion 1.0.125 - '.m3u' Local SEH-Based Unicode Venetian Exploit

ActivePDF Toolkit < 8.1.0.19023 - Multiple Memory Corruptions Suricata < 4.0.4 - IDS Detection Bypass

4 .3.2018

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Multiple CPU Hardware CVE-2017-5715 Information Disclosure Vulnerability
2018-03-02
http://www.securityfocus.com/bid/102376

GNU libcdio 'iso-info.c' Denial of Service Vulnerability
2018-03-02
http://www.securityfocus.com/bid/103200

PHP CVE-2018-7584 Stack Buffer Overflow Vulnerability
2018-03-01
http://www.securityfocus.com/bid/103204

Dovecot CVE-2017-14461 Out-Of-Bounds Read Information Disclosure Vulnerability
2018-03-01
http://www.securityfocus.com/bid/103201

Delta Industrial Automation DOPSoft CVE-2018-5476 Stack Based Buffer Overflow Vulnerability
2018-03-01
http://www.securityfocus.com/bid/103195

Xen 'xen/arch/x86/domain.c' Denial of Service Vulnerability
2018-02-28
http://www.securityfocus.com/bid/103175

Xen 'xen/common/memory.c' Denial of Service vulnerability
2018-02-28
http://www.securityfocus.com/bid/103174

SANS News

Reminder: Beware of the "Cloud"

Threatpost

Equifax Adds 2.4 Million More People to List of Those Impacted By 2017 Breach

Bug in HP Remote Management Tool Leaves Servers Open to Attack

Exploint

TestLink Open Source Test Management < 1.9.16 - Remote Code Execution

uWSGI < 2.0.17 - Directory Traversal

D-Link DIR-600M Wireless - Cross-Site Scripting

DualDesk 20 - 'Proxy.exe' Denial of Service SEGGER embOS/IP FTP Server 3.22 - Denial of Service

2 .3.2018

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Delta Industrial Automation DOPSoft CVE-2018-5476 Stack Based Buffer Overflow Vulnerability
2018-03-01
http://www.securityfocus.com/bid/103195

Xen 'xen/arch/x86/domain.c' Denial of Service Vulnerability
2018-02-28
http://www.securityfocus.com/bid/103175

Xen 'xen/common/memory.c' Denial of Service vulnerability
2018-02-28
http://www.securityfocus.com/bid/103174

Xen 'xen/common/grant_table.c' Denial of Service Vulnerability
2018-02-28
http://www.securityfocus.com/bid/103177

ISC BIND CVE-2018-5734 Remote Denial of Service Vulnerability
2018-02-28
http://www.securityfocus.com/bid/103189

ISC DHCP CVE-2018-5733 Remote Denial of Service Vulnerability
2018-02-28
http://www.securityfocus.com/bid/103188

ISC DHCP CVE-2018-5732 Remote Buffer Overflow Vulnerability
2018-02-28
http://www.securityfocus.com/bid/103187

SANS News

Why Does Emperor Xi Dislike Winnie the Pooh and Scrambled Eggs?

Common Patterns Used in Phishing Campaigns Files

Threatpost

Sophisticated RedDrop Malware Targets Android Phones

Ad Network Circumvents Ad-Blocking Tools To Run In-Browser Cryptojacker Scripts

Exploint

D-Link DIR-600M Wireless - Cross-Site Scripting

IrfanView 4.50 Email Plugin - Buffer Overflow (SEH Unicode)

IrfanView 4.44 Email Plugin - Buffer Overflow (SEH)

SEGGER embOS/IP FTP Server 3.22 - Denial of Service

1 .3.2018

Bugtraq

[security bulletin] MFSBGN03794 rev.2 - Micro Focus Operations Agent Multiple vulnerabilities 2018-02-28
cyber-psrt microfocus com

Secunia Research: Linux Kernel "_sctp_make_chunk()" Denial of Service Vulnerability 2018-02-28
Secunia Research (remove-vuln secunia com)

SEC Consult SA-20180228-0 :: Insecure Direct Object Reference vulnerability in TestLink Open Source Test Management 2018-02-28
SEC Consult Vulnerability Lab (research sec-consult com)

[SECURITY] [DSA 4124-1] lucene-solr security update 2018-02-27
Moritz Muehlenhoff (jmm debian org)

[security bulletin] HPESBHF03826 rev.1 - HPE Integrated Lights-Out 3 (iLO 3) Remote Denial of Service 2018-02-27
security-alert hpe com

SEC Consult SA-20180227-0 :: OS command injection, arbitrary file upload & SQL injection in ClipBucket 2018-02-27
SEC Consult Vulnerability Lab (research sec-consult com)

ES2018-03 Asterisk pjsip sdp invalid media format description segfault 2018-02-26
Sandro Gauci (sandro enablesecurity com)

Malware

 

Phishing

 

Vulnerebility

Xen 'xen/arch/x86/domain.c' Denial of Service Vulnerability
2018-02-28
http://www.securityfocus.com/bid/103175

Xen 'xen/common/memory.c' Denial of Service vulnerability
2018-02-28
http://www.securityfocus.com/bid/103174

Xen 'xen/common/grant_table.c' Denial of Service Vulnerability
2018-02-28
http://www.securityfocus.com/bid/103177

ISC BIND CVE-2018-5734 Remote Denial of Service Vulnerability
2018-02-28
http://www.securityfocus.com/bid/103189

ISC DHCP CVE-2018-5733 Remote Denial of Service Vulnerability
2018-02-28
http://www.securityfocus.com/bid/103188

ISC DHCP CVE-2018-5732 Remote Buffer Overflow Vulnerability
2018-02-28
http://www.securityfocus.com/bid/103187

Citrix NetScaler ADC and NetScaler Gateway CVE-2018-5314 Authentication Bypass Vulnerability
2018-02-28
http://www.securityfocus.com/bid/103186

NTP CVE-2018-7184 Denial of Service Vulnerability
2018-02-27
http://www.securityfocus.com/bid/103192

SANS News

Why Does Emperor Xi Dislike Winnie the Pooh and Scrambled Eggs?

Threatpost

Massive Malspam Campaign Targets Unpatched Systems

Exploint

Sony Playstation 4 (PS4) 4.55 - Jailbreak (WebKit 5.01 / 'bpf' Kernel Loader 4.55)

Routers2 2.24 - Cross-Site Scripting

Apple iOS 11.2.5 / watchOS 4.2.2 / tvOS 11.2.5 - 'bluetoothd' Memory Corruption

Sony Playstation 4 (PS4) 5.01 < 5.05 - WebKit Code Execution (PoC)