Databáze Hot News 2019 April - 2019 January  February  March  April  May  June  July  August  September  October  November  December


29.4.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Oracle WebLogic Server Deserialization Remote Command Execution Vulnerability
2019-04-29
http://www.securityfocus.com/bid/108074

Exploint

 

28.4.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Ghostscript Multiple Security Bypass Vulnerabilities
2019-04-26
http://www.securityfocus.com/bid/105122

Ghostscript CVE-2018-18284 Security Bypass Vulnerability
2019-04-26
http://www.securityfocus.com/bid/107451

Ghostscript 'shading_param' Remote Code Execution Vulnerability
2019-04-26
http://www.securityfocus.com/bid/105178

Atlassian Confluence Server and Confluence Data Center Directory Traversal Vulnerability
2019-04-26
http://www.securityfocus.com/bid/108067

Exploint

systemd - DynamicUser can Create setuid Binaries when Assisted by Another Process

Apache Pluto 3.0.0 / 3.0.1 - Persistent Cross-Site Scripting

NSauditor 3.1.2.0 - 'Name' Denial of Service (PoC)

NSauditor 3.1.2.0 - 'Community' Denial of Service (PoC)

26.4.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Ghostscript Multiple Security Bypass Vulnerabilities
2019-04-26
http://www.securityfocus.com/bid/105122

Ghostscript CVE-2018-18284 Security Bypass Vulnerability
2019-04-26
http://www.securityfocus.com/bid/107451

Ghostscript 'shading_param' Remote Code Execution Vulnerability
2019-04-26
http://www.securityfocus.com/bid/105178

Atlassian Confluence Server and Confluence Data Center Directory Traversal Vulnerability
2019-04-26
http://www.securityfocus.com/bid/108067

Exploint

RARLAB WinRAR 5.61 - ACE Format Input Validation Remote Code Execution (Metasploit)

Lavavo CD Ripper 4.20 - 'License Activation Name' Buffer Overflow (SEH)

AnMing MP3 CD Burner 2.0 - Denial of Service (PoC)

osTicket 1.11 - Cross-Site Scripting / Local File Inclusion

JioFi 4G M2S 1.0.2 - Denial of Service

JioFi 4G M2S 1.0.2 - 'mask' Cross-Site Scripting

Backup Key Recovery 2.2.4 - Denial of Service (PoC)

HeidiSQL 10.1.0.5464 - Denial of Service (PoC)

25.4.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Atlassian Confluence Server and Confluence Data Center Directory Traversal Vulnerability
2019-04-25
http://www.securityfocus.com/bid/108067

Linux Kernel 'perf_event_open()' Function Local Information Disclosure Vulnerability
2019-04-24
http://www.securityfocus.com/bid/89937

GraphicsMagick CVE-2019-11505 Heap Buffer Overflow Vulnerability
2019-04-24
http://www.securityfocus.com/bid/108063

TIBCO ActiveMatrix BPM CVE-2019-8995 Open Redirection Vulnerability
2019-04-24
http://www.securityfocus.com/bid/108062

Exploint

JioFi 4G M2S 1.0.2 - Denial of Service

JioFi 4G M2S 1.0.2 - 'mask' Cross-Site Scripting

Backup Key Recovery 2.2.4 - Denial of Service (PoC)

HeidiSQL 10.1.0.5464 - Denial of Service (PoC)

Google Chrome 72.0.3626.121 / 74.0.3725.0 - 'NewFixedDoubleArray' Integer Overflow

VirtualBox 6.0.4 r128413 - COM RPC Interface Code Injection Host Privilege Escalation

24.4.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Linux Kernel 'perf_event_open()' Function Local Information Disclosure Vulnerability
2019-04-24
http://www.securityfocus.com/bid/89937

Palo Alto Networks Global Protect Client CVE-2019-1573 Local Information Disclosure Vulnerability
2019-04-23
http://www.securityfocus.com/bid/107868

Linux Kernel CVE-2019-11487 Multiple Denial of Service Vulnerabilities
2019-04-23
http://www.securityfocus.com/bid/108054

Fujifilm FCR Capsula X/Carbon X Denial of Service and Access Bypass Vulnerabilities
2019-04-23
http://www.securityfocus.com/bid/108052

Apache Zeppelin CVE-2017-12619 Session Fixation Vulnerability
2019-04-23
http://www.securityfocus.com/bid/108050

Rockwell Automation MicroLogix 1400 and CompactLogix 5370 Controllers Open Redirection Vulnerability
2019-04-23
http://www.securityfocus.com/bid/108049

Google Chrome Prior to 74.0.3729.108 Multiple Security Vulnerabilities
2019-04-23
http://www.securityfocus.com/bid/108048

Apache Zeppelin Security Bypass and HTML Injection Vulnerabilities
2019-04-23
http://www.securityfocus.com/bid/108047

Apache Qpid Proton CVE-2019-0223 Man in the Middle Security Bypass Vulnerability
2019-04-23
http://www.securityfocus.com/bid/108044

Symantec Endpoint Protection CVE-2018-12244 Security Bypass Vulnerability
2019-04-23
http://www.securityfocus.com/bid/107999

Multiple Symantec Products CVE-2018-18369 DLL Loading Local Privilege Escalation Vulnerability
2019-04-23
http://www.securityfocus.com/bid/107997

Symantec Endpoint Protection Manager CVE-2018-18367 Local Privilege Escalation Vulnerability
2019-04-23
http://www.securityfocus.com/bid/107996

Multiple Symantec Products CVE-2018-18366 Local Information Disclosure Vulnerability
2019-04-23
http://www.securityfocus.com/bid/107994

Exploint

VirtualBox 6.0.4 r128413 - COM RPC Interface Code Injection Host Privilege Escalation

23.4.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Palo Alto Networks Global Protect Client CVE-2019-1573 Local Information Disclosure Vulnerability
2019-04-23
http://www.securityfocus.com/bid/107868

PHP Multiple Heap Buffer Overflow Vulnerabilities
2019-04-22
http://www.securityfocus.com/bid/107794

Exploint

Linux - 'page->_refcount' Overflow via FUSE

Linux - Missing Locking in Siemens R3964 Line Discipline Race Condition

systemd - Lack of Seat Verification in PAM Module Permits Spoofing Active Session to polkit

Ross Video DashBoard 8.5.1 - Insecure Permissions

22.4.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

PHP Multiple Heap Buffer Overflow Vulnerabilities
2019-04-22
http://www.securityfocus.com/bid/107794

Exploint

UliCMS 2019.2 / 2019.1 - Multiple Cross-Site Scripting

ManageEngine Applications Manager 14.0 - Authentication Bypass / Remote Command Execution (Metasploit)

Msvod 10 - Cross-Site Request Forgery (Change User Information)

74CMS 5.0.1 - Cross-Site Request Forgery (Add New Admin User)

LabF nfsAxe 3.7 Ping Client - 'Host IP' Buffer Overflow (Direct Ret)

Google Chrome 73.0.3683.103 V8 JavaScript Engine - Out-of-Memory in Invalid Table Size Denial of Service (PoC)

WordPress Plugin Contact Form Builder 1.0.67 - Cross-Site Request Forgery / Local File Inclusion

QNAP myQNAPcloud Connect 1.3.4.0317 - 'Username/Password' Denial of Service

Ease Audio Converter 5.30 - '.mp4' Denial of Service (PoC)

20.4.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

 

Exploint

Atlassian Confluence Widget Connector Macro - Velocity Template Injection (Metasploit)

SystemTap 1.3 - MODPROBE_OPTIONS Privilege Escalation (Metasploit)

Oracle Business Intelligence / XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - XML External Entity Injection

Oracle Business Intelligence 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - Directory Traversal

19.4.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

OpenSSH CVE-2018-20685 Access Bypass Vulnerability
2019-04-18
http://www.securityfocus.com/bid/106531

Microsoft Windows Win32k CVE-2019-0859 Local Privilege Escalation Vulnerability
2019-04-18
http://www.securityfocus.com/bid/107763

Spring Security and Spring Framework CVE-2018-1258 Authorization Bypass Vulnerability
2019-04-18
http://www.securityfocus.com/bid/104222

FreeType 2 CVE-2017-8105 Out of Bounds Write Heap Buffer Overflow Vulnerability
2019-04-18
http://www.securityfocus.com/bid/99093

FreeType 2 CVE-2017-8287 Out of Bounds Write Heap Buffer Overflow Vulnerability
2019-04-18
http://www.securityfocus.com/bid/99091

Apache Tika CVE-2018-11761 XML External Entity Denial of Service Vulnerability
2019-04-18
http://www.securityfocus.com/bid/105514

cURL/libcURL Multiple Buffer Overflow Vulnerabilities
2019-04-18
http://www.securityfocus.com/bid/106950

Apache Batik CVE-2018-8013 Information Disclosure Vulnerability
2019-04-18
http://www.securityfocus.com/bid/104252

Apache Tomcat CVE-2018-1305 Security Bypass Vulnerability
2019-04-18
http://www.securityfocus.com/bid/103144

SLF4J 'EventData' Constructor Remote Code Execution Vulnerability
2019-04-18
http://www.securityfocus.com/bid/103737

Spring Framework CVE-2018-15756 Denial-Of-Service Vulnerability
2019-04-18
http://www.securityfocus.com/bid/105703

Apache ActiveMQ CVE-2018-11775 Man in the Middle Security Bypass Vulnerability
2019-04-18
http://www.securityfocus.com/bid/105335

Cisco IOS Software CVE-2018-0161 Denial of Service Vulnerability
2019-04-18
http://www.securityfocus.com/bid/103573

IBM Java SDK CVE-2018-1656 Directory Traversal Vulnerability
2019-04-18
http://www.securityfocus.com/bid/105118

Apache Log4j CVE-2017-5645 Remote Code Execution Vulnerability
2019-04-18
http://www.securityfocus.com/bid/97702

JQuery CVE-2015-9251 Cross Site Scripting Vulnerability
2019-04-18
http://www.securityfocus.com/bid/105658

FasterXML Jackson-databind CVE-2018-14718 Remote Code Execution Vulnerability
2019-04-18
http://www.securityfocus.com/bid/106601

Exploint

LibreOffice < 6.0.7 / 6.1.3 - Macro Code Execution (Metasploit)

Netwide Assembler (NASM) 2.14rc15 - NULL Pointer Dereference (PoC)

ManageEngine Applications Manager 11.0 < 14.0 - SQL Injection / Remote Code Execution (Metasploit)

Evernote 7.9 - Code Execution via Path Traversal

18.4.2019

Bugtraq

 

Malware

Infostealer.Scranos

Phishing

 

Vulnerebility

Apache Log4j CVE-2017-5645 Remote Code Execution Vulnerability
2019-04-18
http://www.securityfocus.com/bid/97702

JQuery CVE-2015-9251 Cross Site Scripting Vulnerability
2019-04-18
http://www.securityfocus.com/bid/105658

FasterXML Jackson-databind CVE-2018-14718 Remote Code Execution Vulnerability
2019-04-18
http://www.securityfocus.com/bid/106601

Exploint

Oracle Java Runtime Environment - Heap Corruption During TTF font Rendering in GlyphIterator::setCurrGlyphID

Oracle Java Runtime Environment - Heap Corruption During TTF font Rendering in sc_FindExtrema4

17.4.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

FasterXML Jackson-databind CVE-2018-12023 Remote Code Execution Vulnerability
2019-04-17
http://www.securityfocus.com/bid/105659

Oracle Primavera Unifier Multiple Security Vulnerabilities
2019-04-17
http://www.securityfocus.com/bid/104823

Apache Tomcat CVE-2018-11784 Open Redirection Vulnerability
2019-04-17
http://www.securityfocus.com/bid/105524

Apache HTTP Server CVE-2018-11763 Denial of Service Vulnerability
2019-04-17
http://www.securityfocus.com/bid/105414

Bouncy Castle CVE-2018-1000180 Security Weakness
2019-04-17
http://www.securityfocus.com/bid/106567

OpenSSL CVE-2018-0734 Side Channel Attack Information Disclosure Vulnerability
2019-04-17
http://www.securityfocus.com/bid/105758

Novell NetIQ Sentinel CVE-2016-1000031 Remote Code Execution Vulnerability
2019-04-17
http://www.securityfocus.com/bid/93604

Oracle Enterprise Manager Ops Center CVE-2016-4000 Remote Security Vulnerability
2019-04-17
http://www.securityfocus.com/bid/105647

Multiple TIBCO Products CVE-2017-5533 Information Disclosure Vulnerability
2019-04-17
http://www.securityfocus.com/bid/101878

Multiple CPU Hardware CVE-2017-5754 Information Disclosure Vulnerability
2019-04-17
http://www.securityfocus.com/bid/102378

Pivotal Spring Integration CVE-2019-3772 XML External Entity Injection Vulnerability
2019-04-17
http://www.securityfocus.com/bid/106749

Apache Groovy CVE-2015-3253 Remote Code Execution Vulnerability
2019-04-17
http://www.securityfocus.com/bid/75919

Multiple Oracle Products CVE-2016-0635 Remote Security Vulnerability
2019-04-17
http://www.securityfocus.com/bid/91869

Apache Commons FileUpload CVE-2016-3092 Denial Of Service Vulnerability
2019-04-17
http://www.securityfocus.com/bid/91453

Apache Xalan-Java Library CVE-2014-0107 Security Bypass Vulnerability
2019-04-17
http://www.securityfocus.com/bid/66397

Apache Derby CVE-2015-1832 XML External Entity Information Disclosure Vulnerability
2019-04-17
http://www.securityfocus.com/bid/93132

JGroups CVE-2016-2141 Authorization Bypass Vulnerability
2019-04-17
http://www.securityfocus.com/bid/91481

Apache Struts ClassLoader Manipulation CVE-2014-0114 Security Bypass Vulnerability
2019-04-17
http://www.securityfocus.com/bid/67121

OpenSSL CVE-2019-1559 Information Disclosure Vulnerability
2019-04-17
http://www.securityfocus.com/bid/107174

Multiple CPU Hardware CVE-2017-5753 Information Disclosure Vulnerability
2019-04-17
http://www.securityfocus.com/bid/102371

Mozilla Network Security Services CVE-2018-12404 Information Disclosure Vulnerability
2019-04-17
http://www.securityfocus.com/bid/107260

Linux Kernel CVE-2017-0861 Local Privilege Escalation Vulnerability
2019-04-17
http://www.securityfocus.com/bid/102329

OpenSSL CVE-2018-0732 Denial of Service Vulnerability
2019-04-17
http://www.securityfocus.com/bid/104442

Apache Tomcat CVE-2017-5664 Security Bypass Vulnerability
2019-04-17
http://www.securityfocus.com/bid/98888

systemd-journald CVE-2018-16864 Stack-Based Buffer Overflow Vulnerability
2019-04-17
http://www.securityfocus.com/bid/106523

Apache Struts CVE-2016-1181 Remote Code Execution Vulnerability
2019-04-17
http://www.securityfocus.com/bid/91068

GNU glibc CVE-2018-11236 Stack Buffer Overflow Vulnerability
2019-04-17
http://www.securityfocus.com/bid/104255

Oracle Database Server Multiple Local Security Vulnerabilities
2019-04-17
http://www.securityfocus.com/bid/107940

Redis CVE-2018-11219 Integer Overflow Vulnerability
2019-04-17
http://www.securityfocus.com/bid/104552

FasterXML Jackson-databind CVE-2018-7489 Incomplete Fix Remote Code Execution Vulnerability
2019-04-17
http://www.securityfocus.com/bid/103203

Exploint

DHCP Server 2.5.2 - Denial of Service (PoC)

ASUS HG100 - Denial of Service

MailCarrier 2.51 - POP3 'RETR' SEH Buffer Overflow

16.4.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Action View CVE-2019-5418 Information Disclosure Vulnerability
2019-04-15
http://www.securityfocus.com/bid/107409

Cisco NX-OS CVE-2019-1601 Unauthorized File Access Vulnerability
2019-04-15
http://www.securityfocus.com/bid/107404

Google Chrome Prior to 66.0.3359.117 Multiple Security Vulnerabilities
2019-04-15
http://www.securityfocus.com/bid/103917

Exploint

Microsoft Windows 10 1809 - LUAFV PostLuafvPostReadWrite SECTION_OBJECT_POINTERS Race Condition Privilege Escalation

Microsoft Windows 10 1809 - LUAFV Delayed Virtualization Cache Manager Poisoning Privilege Escalation

Microsoft Windows 10 1809 - LUAFV NtSetCachedSigningLevel Device Guard Bypass

Microsoft Windows 10 1809 - LUAFV LuafvCopyShortName Arbitrary Short Name Privilege Escalation

Microsoft Windows 10 1809 - LUAFV Delayed Virtualization Cross Process Handle Duplication Privilege Escalation

Microsoft Windows 10 1809 - LUAFV Delayed Virtualization MAXIMUM_ACCESS DesiredAccess Privilege Escalation

Microsoft Windows 10 1809 / 1709 - CSRSS SxSSrv Cached Manifest Privilege Escalation

AdminExpress 1.2.5 - 'Folder Path' Denial of Service (PoC)

Joomla Core 1.5.0 - 3.9.4 - Directory Traversal / Authenticated Arbitrary File Deletion

PCHelpWare V2 1.0.0.5 - 'Group' Denial of Service (PoC)

PCHelpWare V2 1.0.0.5 - 'SC' Denial of Service (PoC)

Zoho ManageEngine ADManager Plus 6.6 (Build < 6659) - Privilege Escalation

Zyxel ZyWall 310 / ZyWall 110 / USG1900 / ATP500 / USG40 - Login Page Cross-Site Scripting

15.4.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Multiple Westermo Routers Multiple Security Vulnerabilities
2019-04-15
http://www.securityfocus.com/bid/100470

Qualcomm Closed-Source Components Multiple Unspecified Vulnerabilities
2019-04-15
http://www.securityfocus.com/bid/106128

Splunk Enterprise HTML Injection Vulnerability
2019-04-15
http://www.securityfocus.com/bid/97286

QNAP QTAP Qualcomm components Multiple Unspecified Security Vulnerabilities
2019-04-15
http://www.securityfocus.com/bid/97072

Oracle WebCenter Sites CVE-2017-3598 Remote Security Vulnerability
2019-04-15
http://www.securityfocus.com/bid/97905

Apple iOS/macOS/tvOS/watchOS Buffer Overflow Vulnerability
2019-04-15
http://www.securityfocus.com/bid/95731

Xen CVE-2017-17045 Privilege Escalation Vulnerability
2019-04-15
http://www.securityfocus.com/bid/102013

Dovecot CVE-2019-7524 Stack Buffer Overflow Vulnerability
2019-04-15
http://www.securityfocus.com/bid/107672

Exploint

Cisco RV130W Routers - Management Interface Remote Command Execution (Metasploit)

UltraVNC Launcher 1.2.2.4 - 'Path' Denial of Service (PoC)

UltraVNC Viewer 1.2.2.4 - 'VNC Server' Denial of Service (PoC)

MailCarrier 2.51 - POP3 'TOP' SEH Buffer Overflow

MailCarrier 2.51 - POP3 'LIST' SEH Buffer Overflow

MailCarrier 2.51 - POP3 'USER' Buffer Overflow

CuteNews 2.1.2 - 'avatar' Remote Code Execution (Metasploit)

RemoteMouse 3.008 - Arbitrary Remote Command Execution

MailCarrier 2.51 - 'RCPT TO' Buffer Overflow

DirectAdmin 1.561 - Multiple Vulnerabilities

14.4.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Citrix XenServer Multiple Security Vulnerabilities
2019-04-12
http://www.securityfocus.com/bid/102129

Xen CVE-2017-15592 Denial of Service Vulnerability
2019-04-12
http://www.securityfocus.com/bid/101513

IBM BigFix Platform Multiple Security Vulnerabilities
2019-04-12
http://www.securityfocus.com/bid/101571

Tidy CVE-2017-13692 Denial of Service Vulnerability
2019-04-12
http://www.securityfocus.com/bid/100506

SAP NetWeaver Knowledge Management XMLForms Unspecified Cross Site Scripting Vulnerability
2019-04-12
http://www.securityfocus.com/bid/101826

RETIRED: Oracle Retail Xstore Point of Service CVE-2017-10427 Remote Security Vulnerability
2019-04-12
http://www.securityfocus.com/bid/101388

RETIRED: Oracle Retail Back Office CVE-2017-10423 Remote Security Vulnerability
2019-04-12
http://www.securityfocus.com/bid/101380

RETIRED: Oracle BI Publisher CVE-2017-10034 Remote Security Vulnerability
2019-04-12
http://www.securityfocus.com/bid/101405

WordPress Mobile App Builder By Wappress Plugin Arbitrary File Upload Vulnerability
2019-04-12
http://www.securityfocus.com/bid/96905

Google Android Framework Multiple Privilege Escalation Vulnerabilities
2019-04-12
http://www.securityfocus.com/bid/102131

RETIRED: Google Android NFC CVE-2017-0481 Remote Privilege Escalation Vulnerability
2019-04-12
http://www.securityfocus.com/bid/96765

SAP Single Sign On Denial of Service Vulnerability
2019-04-12
http://www.securityfocus.com/bid/95363

GraphicsMagick CVE-2016-7800 Heap Buffer Overflow Vulnerability
2019-04-12
http://www.securityfocus.com/bid/93262

RETIRED: GraphicsMagick CVE-2016-7800 Remote Integer Underflow Vulnerability
2019-04-12
http://www.securityfocus.com/bid/96135

Sauter NovaWeb Web HMI CVE-2016-10224 Authentication Bypass Vulnerability
2019-04-12
http://www.securityfocus.com/bid/94782

Apple iOS Prior to 10 Multiple Security Vulnerabilities
2019-04-12
http://www.securityfocus.com/bid/92932

Katello CVE-2016-9595 Local Code Execution Vulnerability
2019-04-12
http://www.securityfocus.com/bid/95080

Google Android Multiple Qualcomm Components Multiple Security Vulnerabilities
2019-04-12
http://www.securityfocus.com/bid/102073

Apple Safari APPLE-SA-2016-03-21-6 Multiple Security Vulnerabilities
2019-04-12
http://www.securityfocus.com/bid/85055

ImageMagick CVE-2016-10054 Buffer Overflow Vulnerability
2019-04-12
http://www.securityfocus.com/bid/95191

IBM Sametime Proxy Server Multiple Security Vulnerabilities
2019-04-12
http://www.securityfocus.com/bid/100572

Cacti Multiple SQL Injection Vulnerabilities
2019-04-12
http://www.securityfocus.com/bid/75972

Drupal Wishlist Module Cross Site Request Forgery and Cross Site Scripting Vulnerabilities
2019-04-12
http://www.securityfocus.com/bid/72114

RETIRED: ManageEngine ADManager Plus CVE-2015-1026 Multiple Cross Site Scripting Vulnerabilities
2019-04-12
http://www.securityfocus.com/bid/73056

Cisco Unified Computing System CVE-2015-6415 Denial of Service Vulnerability
2019-04-12
http://www.securityfocus.com/bid/85711

RETIRED: Ida CVE-2014-9458 Remote Security Vulnerability
2019-04-12
http://www.securityfocus.com/bid/87981

RETIRED: Notepad%2B%2B CVE-2014-9456 Remote Security Vulnerability
2019-04-12
http://www.securityfocus.com/bid/88191

Schneider Electric ETG3000 FactoryCast HMI Gateway Authentication Bypass Vulnerability
2019-04-12
http://www.securityfocus.com/bid/72258

RETIRED: Tsxetg3010 CVE-2014-9198 Remote Security Vulnerability
2019-04-12
http://www.securityfocus.com/bid/77765

Apple Mac OS X Prior to 10.10.2 Multiple Security Vulnerabilities
2019-04-12
http://www.securityfocus.com/bid/72328

Exploint

 

12.4.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

RETIRED: LG On-Screen Phone CVE-2014-8757 Security Bypass Vulnerability
2019-04-12
http://www.securityfocus.com/bid/72544

RETIRED: Uberfire CVE-2014-8114 Remote Security Vulnerability
2019-04-12
http://www.securityfocus.com/bid/88199

RETIRED: GE Healthcare Centricity PACS Workstation Hardcoded Password Security Bypass Vulnerability
2019-04-12
http://www.securityfocus.com/bid/76169

RETIRED: Hancom Office 2010 SE CVE-2013-7420 Remote Security Vulnerability
2019-04-12
http://www.securityfocus.com/bid/88211

F5 BIG-IP APM CVE-2017-6139 Information Disclosure Vulnerability
2019-04-12
http://www.securityfocus.com/bid/106186

Multiple F5 Networks Products CVE-2013-6024 Local Information Disclosure Vulnerability
2019-04-12
http://www.securityfocus.com/bid/65422

Palo Alto Networks Global Protect Client CVE-2019-1573 Local Information Disclosure Vulnerability
2019-04-12
http://www.securityfocus.com/bid/107868

Oracle April 2019 Critical Patch Update Multiple Vulnerabilities
2019-04-12
http://www.securityfocus.com/bid/107875

Exploint

Zimbra Collaboration - Autodiscover Servlet XXE and ProxyServlet SSRF (Metasploit)

Microsoft Windows - Contact File Format Arbitary Code Execution (Metasploit)

ATutor < 2.2.4 - 'file_manager' Remote Code Execution (Metasploit)

Microsoft Internet Explorer 11 - XML External Entity Injection

CyberArk EPM 10.2.1.603 - Security Restrictions Bypass

11.4.2019

Bugtraq

 

Malware

VBS.Rosekernel

Backdoor.Darkteq

Phishing

Microsft Hotmail

11th April 2019

Microsoft Outlook Deactivation
Notification

Vulnerebility

IBM Spectrum LSF CVE-2018-1724 Local Security Bypass Vulnerability
2019-04-11
http://www.securityfocus.com/bid/106642

IBM QRadar SIEM CVE-2019-4210 Authentication Bypass Vulnerability
2019-04-11
http://www.securityfocus.com/bid/107859

GNU wget CVE-2019-5953 Remote Buffer Overflow Vulnerability
2019-04-10
http://www.securityfocus.com/bid/107734

Quagga CVE-2018-5379 Remote Code Execution Vulnerability
2019-04-10
http://www.securityfocus.com/bid/103105

cURL/libcURL Multiple Buffer Overflow Vulnerabilities
2019-04-10
http://www.securityfocus.com/bid/106950

Exploint

D-Link DI-524 V2.06RU - Multiple Cross-Site Scripting

10.4.2019

Bugtraq

 

Malware

Exp.CVE-2019-0803

Exp.CVE-2019-0859

Phishing

 

Vulnerebility

GNU wget CVE-2019-5953 Remote Buffer Overflow Vulnerability
2019-04-10
http://www.securityfocus.com/bid/107734

Quagga CVE-2018-5379 Remote Code Execution Vulnerability
2019-04-10
http://www.securityfocus.com/bid/103105

cURL/libcURL Multiple Buffer Overflow Vulnerabilities
2019-04-10
http://www.securityfocus.com/bid/106950

cURL/libcURL CVE-2018-16890 Heap Buffer Overflow Vulnerability
2019-04-10
http://www.securityfocus.com/bid/106947

Multiple Siemens Products CVE-2017-12741 Denial of Service Vulnerability
2019-04-10
http://www.securityfocus.com/bid/101964

Microsoft Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability
2019-04-09
http://www.securityfocus.com/bid/107752

Exploint

FTPShell Server 6.83 - 'Virtual Path Mapping' Local Buffer

FTPShell Server 6.83 - 'Account name to ban' Local Buffer

Dell KACE Systems Management Appliance (K1000) 6.4.120756 - Unauthenticated Remote Code Execution

Microsoft Windows - AppX Deployment Service Privilege Escalation

Apache Axis 1.4 - Remote Code Execution

9.4.2019

Bugtraq

 

Malware

Infostealer.Glitchpos

Phishing

 

Vulnerebility

Adobe Acrobat and Reader APSB19-17 Multiple Heap Buffer Overflow Vulnerabilities
2019-04-09
http://www.securityfocus.com/bid/107805

SAP Netweaver ABAP CVE-2019-0265 XML External Entity Injection Vulnerability
2019-04-09
http://www.securityfocus.com/bid/106972

SAP Business Client Unspecified Security Vulnerability
2019-04-09
http://www.securityfocus.com/bid/104436

Apache HTTP Server CVE-2019-0211 Local Privilege Escalation Vulnerability
2019-04-09
http://www.securityfocus.com/bid/107666

Adobe Acrobat and Reader Out-of-Bounds Read Multiple Information Disclosure Vulnerabilities
2019-04-09
http://www.securityfocus.com/bid/107815

Adobe Acrobat and Reader Out-Of-Bounds Write Multiple Arbitrary Code Execution Vulnerabilities
2019-04-09
http://www.securityfocus.com/bid/107812

Adobe Acrobat and Reader APSB19-17 Multiple Arbitrary Code Execution Vulnerabilities
2019-04-09
http://www.securityfocus.com/bid/107811

SAP NetWeaver Process Integration CVE-2019-0278 Information Disclosure Vulnerability
2019-04-09
http://www.securityfocus.com/bid/107807

WordPress Wordfence Plugin Unspecified Cross Site Scripting Vulnerability
2019-04-09
http://www.securityfocus.com/bid/107804

SAP NetWeaver Process Integration CVE-2019-0282 Information Disclosure Vulnerability
2019-04-09
http://www.securityfocus.com/bid/107801

SAP HANA CVE-2019-0284 XML External Entity Injection Vulnerability
2019-04-09
http://www.securityfocus.com/bid/107800

PHP Multiple Heap Buffer Overflow Vulnerabilities
2019-04-08
http://www.securityfocus.com/bid/107794

Exploint

PHP 7.2 - 'imagecolormatch()' Out of Band Heap Write

Ashop Shopping Cart Software - 'bannedcustomers.php?blacklistitemid' SQL Injection

TP-LINK TL-WR940N / TL-WR941ND - Buffer Overflow

8.4.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

PHP Multiple Heap Buffer Overflow Vulnerabilities
2019-04-08
http://www.securityfocus.com/bid/107794

Symantec Endpoint Encryption CVE-2019-9694 Local Privilege Escalation Vulnerability
2019-04-08
http://www.securityfocus.com/bid/107653

Exploint

Apache 2.4.17 < 2.4.38 - 'apache2ctl graceful' 'logrotate' Local Privilege Escalation

QNAP Netatalk < 3.1.12 - Authentication Bypass

ManageEngine ServiceDesk Plus 9.3 - User Enumeration

Download Accelerator Plus (DAP) 10.0.6.0 - SEH Buffer Overflow

WordPress Plugin Limit Login Attempts Reloaded 2.7.4 - Login Limit Bypass

Tradebox CryptoCurrency - 'symbol' SQL Injection

River Past Cam Do 3.7.6 - 'Activation Code' Local Buffer Overflow

CentOS Web Panel 0.9.8.793 (Free) / 0.9.8.753 (Pro) - Cross-Site Scripting

AllPlayer 7.4 - SEH Buffer Overflow (Unicode)

SaLICru -SLC-20-cube3(5) - HTML Injection

ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities

FlexHEX 2.71 - SEH Buffer Overflow (Unicode)

Bolt CMS 3.6.6 - Cross-Site Request Forgery / Remote Code Execution

Jobgator - 'experience' SQL Injection

5.4.2019

Bugtraq

 

Malware

Android.RemoteCode.152.origin 

Android.RemoteCode.127.origin

Trojan.DownLoad4.11892

Android.HiddenAds.1008

Backdoor.Vexdoor

Phishing

Google

4th April 2019

SEO+SMO PROPOSAL

Vulnerebility

Cisco IOS and IOS XE Software CVE-2018-15373 Denial of Service Vulnerability
2019-04-05
http://www.securityfocus.com/bid/105413

Cisco IOS Software CVE-2018-0473 Denial of Service Vulnerability
2019-04-05
http://www.securityfocus.com/bid/105427

Cisco IOS XE Software CVE-2018-0470 Denial of Service Vulnerability
2019-04-05
http://www.securityfocus.com/bid/105397

Cisco IOS and IOS XE Software CVE-2018-0466 Denial of Service Vulnerability
2019-04-05
http://www.securityfocus.com/bid/105403

Multiple Cisco Products CVE-2018-0472 Denial Of Service Vulnerability
2019-04-05
http://www.securityfocus.com/bid/105418

Google Android Qualcomm Components Multiple Security Vulnerabilities
2019-04-05
http://www.securityfocus.com/bid/105872

Exploint

 

4.4.2019

Bugtraq

 

Malware

W32.Beapy

Phishing

 

Vulnerebility

 

Exploint

FreeSMS 2.1.2 - SQL Injection (Authentication Bypass)

AIDA64 Engineer 5.99.4900 - 'Load from file' Field Buffer Overflow (SEH)

Magic ISO Maker 5.5(build 281) - 'Serial Code' Denial of Service (PoC)

Cisco RV320 and RV325 - Unauthenticated Remote Code Execution (Metasploit)

Google Chrome 72.0.3626.96 / 74.0.3702.0 - 'JSPromise::TriggerPromiseReactions' Type Confusion

Google Chrome 73.0.3683.39 / Chromium 74.0.3712.0 - 'ReadableStream' Internal Object Leak Type Confusion

Google Chrome 72.0.3626.81 - 'V8TrustedTypePolicyOptions::ToImpl' Type Confusion

WebKitGTK+ - 'ThreadedCompositor' Race Condition

WebKit JavaScriptCore - CodeBlock Dangling Watchpoints Use-After-Free

WebKit JavaScriptCore - Out-Of-Bounds Access in FTL JIT due to LICM Moving Array Access Before the Bounds Check

iOS < 12.2 / macOS < 10.14.4 XNU - pidversion Increment During execve is Unsafe

WebKit JavaScriptCore - 'createRegExpMatchesArray' Type Confusion

SpiderMonkey - IonMonkey Compiled Code Fails to Update Inferred Property Types (Type Confusion)

PhreeBooks ERP 5.2.3 - Remote Command Execution

PhreeBooks ERP 5.2.3 - Arbitrary File Upload

Ashop Shopping Cart Software - SQL Injection

Clinic Pro v4 - 'month' SQL Injection

TeemIp IPAM < 2.4.0 - 'new_config' Command Injection (Metasploit)

3.4.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Xen HLE Constructs Denial of Service Vulnerability
2019-04-03
http://www.securityfocus.com/bid/105954

Xen Multiple Privilege Escalation and Denial of Service Vulnerabilities
2019-04-03
http://www.securityfocus.com/bid/106182

Citrix XenServer Multiple Security Vulnerabilities
2019-04-03
http://www.securityfocus.com/bid/102129

Xen CVE-2017-17044 Denial of Service Vulnerability
2019-04-03
http://www.securityfocus.com/bid/102008

Drupal Core SA-CORE-2019-004 Cross Site Scripting Vulnerability
2019-04-03
http://www.securityfocus.com/bid/107497

Siemens SCALANCE X switches CVE-2019-6569 Security Weakness
2019-04-02
http://www.securityfocus.com/bid/107465

Fortinet FortiClient CVE-2019-5585 Access Bypass Vulnerability
2019-04-02
http://www.securityfocus.com/bid/107693

Advantech WebAccess/SCADA ICSA-19-092-01 Multiple Security Vulnerabilities
2019-04-02
http://www.securityfocus.com/bid/107675

Exploint

PhreeBooks ERP 5.2.3 - Arbitrary File Upload

Ashop Shopping Cart Software - SQL Injection

Clinic Pro v4 - 'month' SQL Injection

TeemIp IPAM < 2.4.0 - 'new_config' Command Injection (Metasploit)

iScripts ReserveLogic - SQL Injection

AIDA64 Business 5.99.4900 - SEH Buffer Overflow (EggHunter)

2.4.2019

Bugtraq

 

Malware

 

Phishing

Bank of America

2nd April 2019

Bank of America Alert: Unusual
debit card activity detected

Vulnerebility

Siemens SCALANCE X switches CVE-2019-6569 Security Weakness
2019-04-02
http://www.securityfocus.com/bid/107465

Dovecot CVE-2019-7524 Stack Buffer Overflow Vulnerability
2019-04-02
http://www.securityfocus.com/bid/107672

Linux Kernel Components Multiple Security Vulnerabilities
2019-04-01
http://www.securityfocus.com/bid/106503

Linux Kernel CVE-2018-18281 Local Security Bypass Vulnerability
2019-04-01
http://www.securityfocus.com/bid/105761

Linux Kernel 'mm/vmacache.c' Local Privilege Escalation Vulnerability
2019-04-01
http://www.securityfocus.com/bid/105417

Linux Kernel 'ext4_update_inline_data()' Function Local Denial of Service Vulnerability
2019-04-01
http://www.securityfocus.com/bid/104907

Linux Kernel 'ext4_ext_drop_refs()' Function Local Denial of Service Vulnerability
2019-04-01
http://www.securityfocus.com/bid/104878

Linux Kernel 'ext4_ext_remove_space()' Function Local Denial of Service Vulnerability
2019-04-01
http://www.securityfocus.com/bid/104904

Multiple VMware Products CVE-2019-5519 Local Code Execution Vulnerability
2019-04-01
http://www.securityfocus.com/bid/107535

Multiple VMware Products CVE-2019-5518 Out of Bounds Read Write Local Code Execution Vulnerability
2019-04-01
http://www.securityfocus.com/bid/107541

Apache HTTP Server CVE-2019-0220 Remote Security Vulnerability
2019-04-01
http://www.securityfocus.com/bid/107670

Exploint

phpFileManager 1.7.8 - Local File Inclusion

Fiverr Clone Script 1.2.2 - SQL Injection / Cross-Site Scripting

AIDA64 Extreme Edition 5.99.4800 - Local SEH Buffer Overflow

CMS Made Simple < 2.2.10 - SQL Injection

LimeSurvey < 3.16 - Remote Code Execution

JioFi 4G M2S 1.0.2 - Cross-Site Request Forgery

WordPress Plugin PayPal Checkout Payment Gateway 1.6.8 - Parameter Tampering

Inout RealEstate - 'city' SQL Injection

Inout EasyRooms - SQL Injection

1.4.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Multiple VMware Products CVE-2019-5519 Local Code Execution Vulnerability
2019-04-01
http://www.securityfocus.com/bid/107535

Multiple VMware Products CVE-2019-5518 Out of Bounds Read Write Local Code Execution Vulnerability
2019-04-01
http://www.securityfocus.com/bid/107541

Linux Kernel 'create_elf_tables()' Function Local Integer Overflow Vulnerability
2019-03-29
http://www.securityfocus.com/bid/105407

Exploint