Databáze Hot News 2019 February - 2019 January  February  March  April  May  June  July  August  September  October  November  December


27.2.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Tcpdump CVE-2018-19519 Stack Based Buffer Overflow Vulnerability
2019-02-27
http://www.securityfocus.com/bid/106098

PHP CVE-2019-9023 Multiple Heap Buffer Overflow Vulnerabilities
2019-02-26
http://www.securityfocus.com/bid/106765

PHP 'phar_detect_phar_fname_ext()' Heap Buffer Overflow Vulnerability
2019-02-26
http://www.securityfocus.com/bid/106747

GNU wget CVE-2018-20483 Local Information Disclosure Vulnerability
2019-02-26
http://www.securityfocus.com/bid/106358

F5 BIG-IP APM CVE-2019-6595 Cross Site Scripting Vulnerability
2019-02-26
http://www.securityfocus.com/bid/107173

Exploint

 

26.2.2019

Bugtraq

 

Malware

 

Phishing

�Dr.Ernest Kwamina Yedu Addiso

25th February 2019

From Bank of Ghana

Vulnerebility

PHP CVE-2019-9023 Multiple Heap Buffer Overflow Vulnerabilities
2019-02-26
http://www.securityfocus.com/bid/106765

PHP 'phar_detect_phar_fname_ext()' Heap Buffer Overflow Vulnerability
2019-02-26
http://www.securityfocus.com/bid/106747

GNU wget CVE-2018-20483 Local Information Disclosure Vulnerability
2019-02-26
http://www.securityfocus.com/bid/106358

Exploint

 

25.2.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Wireshark Multiple Denial of Service Vulnerabilities
2019-02-25
http://www.securityfocus.com/bid/106482

WinRAR Multiple Security Vulnerabilities
2019-02-25
http://www.securityfocus.com/bid/106948

Exploint

Drupal < 8.6.9 - REST Module Remote Code Execution

Xlight FTP Server 3.9.1 - Buffer Overflow (PoC)

Advance Gift Shop Pro Script 2.0.3 - SQL Injection

News Website Script 2.0.5 - SQL Injection

PHP Ecommerce Script 2.0.6 - Cross-Site Scripting / SQL Injection

Jenkins Plugin Script Security 1.49/Declarative 1.3.4/Groovy 2.60 - Remote Code Execution

24.2.2019

Bugtraq

 

Malware

 

Phishing

Dr.Ernest Kwamina Yedu Addison

23rd February 2019

PAYMENT FROM BANK OF GHANA

American Standard Walk-In Tubs

22nd February 2019

Walk In Tubs Only By American
Standard

Cannabliss Labs

22nd February 2019

The new cannabidiol medicine
that is sweeping the USA

Vulnerebility

 

Exploint

Drupal < 8.6.10 / < 8.5.11 - REST Module Remote Code Execution

Teracue ENC-400 - Command Injection / Missing Authentication

Micro Focus Filr 3.4.0.217 - Path Traversal / Local Privilege Escalation

Nuuo Central Management - Authenticated SQL Server SQL Injection (Metasploit)

WebKit JSC - reifyStaticProperty Needs to set the PropertyAttribute::CustomAccessor flag for CustomGetterSetter

22.2.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Rockwell Automation Allen-Bradley PowerMonitor Multiple Security Vulnerabilities
2019-02-22
http://www.securityfocus.com/bid/106333

Opencontainers runc CVE-2019-5736 Local Command Execution Vulnerability
2019-02-21
http://www.securityfocus.com/bid/106976

Exploint

Quest NetVault Backup Server < 11.4.5 - Process Manager Service SQL Injection / Remote Code Execution

AirDrop 2.0 - Denial of Service (DoS)

MikroTik RouterOS < 6.43.12 (stable) / < 6.42.12 (long-term) - Firewall and NAT Bypass

ScreenStream 3.0.15 - Denial of Service

Virtual VCR Max .0a - '.vcr' Buffer Overflow (PoC)

RealTerm Serial Terminal 2.0.0.70 - 'Echo Port' Buffer Overflow (SEH)

EI-Tube 3 - SQL Injection

Valentina Studio 9.0.5 Linux - 'Host' Buffer Overflow (PoC)

C4G Basic Laboratory Information System (BLIS) 3.4 - SQL Injection

Memu Play 6.0.7 - Privilege Escalation

21.2.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Opencontainers runc CVE-2019-5736 Local Command Execution Vulnerability
2019-02-21
http://www.securityfocus.com/bid/106976

Cisco Webex Meetings Online CVE-2019-1680 Security Bypass Vulnerability
2019-02-21
http://www.securityfocus.com/bid/106939

WPA2 Key Reinstallation Multiple Security Weaknesses
2019-02-21
http://www.securityfocus.com/bid/101274

Intel Data Center Manager SDK CVE-2019-0112 Denial of Service Vulnerability
2019-02-21
http://www.securityfocus.com/bid/107064

Intel Data Center Manager SDK CVE-2019-0111 Local Insecure File Permissions Vulnerability
2019-02-21
http://www.securityfocus.com/bid/107067

Intel Data Center Manager SDK CVE-2019-0110 Information Disclosure Vulnerability
2019-02-21
http://www.securityfocus.com/bid/107071

Intel Data Center Manager SDK CVE-2019-0103 Local Information Disclosure Vulnerability
2019-02-21
http://www.securityfocus.com/bid/107074

Intel Data Center Manager SDK Multiple Privilege Escalation Vulnerabilities
2019-02-21
http://www.securityfocus.com/bid/107069

Microsoft .NET Framework and Visual Studio CVE-2019-0657 Spoofing Vulnerability
2019-02-21
http://www.securityfocus.com/bid/106890

Microsoft Windows Device Guard CVE-2019-0631 Local Security Bypass Vulnerability
2019-02-21
http://www.securityfocus.com/bid/106875

Microsoft Windows Device Guard CVE-2019-0632 Local Security Bypass Vulnerability
2019-02-21
http://www.securityfocus.com/bid/106880

Microsoft Windows Device Guard CVE-2019-0627 Local Security Bypass Vulnerability
2019-02-21
http://www.securityfocus.com/bid/106857

Exploint

AirDrop 2.0 - Denial of Service (DoS)

MikroTik RouterOS < 6.43.12 (stable) / < 6.42.12 (long-term) - Firewall and NAT Bypass

ScreenStream 3.0.15 - Denial of Service

Virtual VCR Max .0a - '.vcr' Buffer Overflow (PoC)

RealTerm Serial Terminal 2.0.0.70 - 'Echo Port' Buffer Overflow (SEH)

EI-Tube 3 - SQL Injection

Valentina Studio 9.0.5 Linux - 'Host' Buffer Overflow (PoC)

C4G Basic Laboratory Information System (BLIS) 3.4 - SQL Injection

Memu Play 6.0.7 - Privilege Escalation

20.2.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

systemd CVE-2019-6454 Local Denial of Service Vulnerability
2019-02-20
http://www.securityfocus.com/bid/107081

LibVNCServer Incomplete Fix Multiple Heap Buffer Overflow Vulnerabilities
2019-02-19
http://www.securityfocus.com/bid/106825

Opencontainers runc CVE-2019-5736 Local Command Execution Vulnerability
2019-02-19
http://www.securityfocus.com/bid/106976

Elasticsearch Logstash CVE-2019-7612 Information Disclosure Vulnerability
2019-02-19
http://www.securityfocus.com/bid/107090

Exploint

Belkin Wemo UPnP - Remote Code Execution (Metasploit)

MatrixSSL < 4.0.2 - Stack Buffer Overflow Verifying x.509 Certificates

Android Kernel < 4.8 - ptrace seccomp Filter Bypass

FaceTime - Texture Processing Memory Corruption

WinRAR 5.61 - '.lng' Denial of Service

FTPShell Server 6.83 - 'Account name to ban' Denial of Service (PoC)

HotelDruid 2.3 - Cross-Site Scripting

Apple macOS 10.13.5 - Local Privilege Escalation

Jenkins - Remote Code Execution

Ask Expert Script 3.0.5 - Cross Site Scripting / SQL Injection

Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2 - Path Traversal / Cross-Site Scripting

XAMPP 5.6.8 - SQL Injection / Persistent Cross-Site Scripting

eDirectory - SQL Injection

BulletProof FTP Server 2019.0.0.50 - 'SMTP Server' Denial of Service (PoC)

Valentina Studio 9.0.4 - 'Host' Denial of Service (PoC)

Zuz Music 2.1 - 'zuzconsole/___contact ' Persistent Cross-Site Scripting

Listing Hub CMS 1.0 - 'pages.php id' SQL Injection

Find a Place CMS Directory 1.5 - 'assets/external/data_2.php cate' SQL Injection

NetSetMan 4.7.1 - 'Workgroup' Denial of Service (PoC)

MaxxAudio Drivers WavesSysSvc64.exe 1.6.2.0 - Local Privilege Escalation

19.2.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

LibVNCServer Incomplete Fix Multiple Heap Buffer Overflow Vulnerabilities
2019-02-19
http://www.securityfocus.com/bid/106825

Opencontainers runc CVE-2019-5736 Local Command Execution Vulnerability
2019-02-19
http://www.securityfocus.com/bid/106976

Multiple F5 BIG-IP Products CVE-2018-15319 Denial of Service Vulnerability
2019-02-18
http://www.securityfocus.com/bid/107052

SolarWinds Orion Network Performance Monitor (NPM) CVE-2019-8917 Remote Code Execution Vulnerability
2019-02-18
http://www.securityfocus.com/bid/107061

QEMU CVE-2019-3812 Out-Of-Bounds Read Local Information Disclosure Vulnerability
2019-02-18
http://www.securityfocus.com/bid/107059

Exploint

 

18.2.2019

Bugtraq

 

Malware

Trojan.Tinukebot.B

Phishing

 

Vulnerebility

Multiple F5 BIG-IP Products CVE-2018-15319 Denial of Service Vulnerability
2019-02-18
http://www.securityfocus.com/bid/107052

Exploint

WordPress Plugin WooCommerce - GloBee (cryptocurrency) Payment Gateway 1.1.1 - Payment Bypass / Unauthorized Order Status Spoofing

Zoho ManageEngine ServiceDesk Plus (SDP) < 10.0 build 10012 - Arbitrary File Upload

Oracle Java Runtime Environment - Heap Out-of-Bounds Read During TTF Font Rendering in AlternateSubstitutionSubtable::process

Oracle Java Runtime Environment - Heap Out-of-Bounds Read During TTF Font Rendering in ExtractBitMap_blocClass

Oracle Java Runtime Environment - Heap Out-of-Bounds Read During TTF Font Rendering in OpenTypeLayoutEngine::adjustGlyphPositions

Oracle Java Runtime Environment - Heap Out-of-Bounds Read During OTF Font Rendering in glyph_CloseContour

Comodo Dome Firewall 2.7.0 - Cross-Site Scripting

ArangoDB Community Edition 3.4.2-1 - Cross-Site Scripting

Apache CouchDB 2.3.0 - Cross-Site Scripting

Webiness Inventory 2.3 - 'ProductModel' Arbitrary File Upload

M/Monit 3.7.2 - Privilege Escalation

NBMonitor 1.6.5.0 - 'Key' Denial of Service (PoC)

CMSsite 1.0 - 'post' SQL Injection

MISP 2.4.97 - SQL Command Execution via Command Injection in STIX Module

Master IP CAM 01 3.3.4.2103 - Remote Command Execution

qdPM 9.1 - 'search[keywords]' Cross-Site Scripting

qdPM 9.1 - 'type' Cross-Site Scripting

mIRC < 7.55 - Remote Command Execution Using Argument Injection Through Custom URI Protocol Handlers

Realterm Serial Terminal 2.0.0.70 - Local Buffer Overflow (SEH)

Realterm Serial Terminal 2.0.0.70 - Denial of Service

17.2.2019

Bugtraq

 

Malware

 

Phishing

Support

17th February 2019

Update Your Information !!!

Vulnerebility

 

Exploint

UniSharp Laravel File Manager 2.0.0-alpha7 - Arbitrary File Upload

Linux - 'kvm_ioctl_create_device()' NULL Pointer Dereference

qdPM 9.1 - 'search_by_extrafields[]' SQL Injection

Jinja2 2.10 - 'from_string' Server Side Template Injection

VSCO 1.1.1.0 - Denial of Service (PoC)

MyBB Trash Bin Plugin 1.1.3 - Cross-Site Scripting / Cross-Site Request Forgery

Navicat for Oracle 12.1.15 - "Password" Denial of Service (PoC)

Free IP Switcher 3.1 - 'Computer Name' Denial of Service (PoC)

AirMore 1.6.1 - Denial of Service (PoC)

15.2.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Linux Kernel CVE-2018-5391 Remote Denial of Service Vulnerability
2019-02-15
http://www.securityfocus.com/bid/105108

Mozilla Firefox and Firefox ESR CVE-2019-5785 Integer Overflow Vulnerability
2019-02-15
http://www.securityfocus.com/bid/107008

Google Chrome Prior to 71.0.3578.80 Multiple Security Vulnerabilities
2019-02-15
http://www.securityfocus.com/bid/106084

SSL/TLS Protocol CVE-2016-2183 Information Disclosure Vulnerability
2019-02-14
http://www.securityfocus.com/bid/92630

Exploint

ApowerManager 3.1.7 - Phone Manager Remote Denial of Service (DoS)

LayerBB 1.1.2 - Cross-Site Request Forgery (Add Admin)

MediaMonkey 4.1.23 - '.mp3' URL Denial of Service (PoC)

WordPress Plugin Booking Calendar 8.4.3 - Authenticated SQL Injection

DomainMOD 4.11.01 - 'assets/edit/host.php?whid=5' Cross-Site Scripting

DomainMOD 4.11.01 - 'assets/add/dns.php' Cross-Site Scripting

DomainMOD 4.11.01 - 'category.php CatagoryName, StakeHolder' Cross-Site Scripting

DomainMOD 4.11.01 - 'ssl-accounts.php username' Cross-Site Scripting

DomainMOD 4.11.01 - 'ssl-provider-name' Cross-Site Scripting

Core FTP/SFTP Server 1.2 Build 589.42 - 'User domain' Denial of Service (PoC)

exacqVision ESM 5.12.2 - Privilege Escalation

14.2.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

 

Exploint

Android - binder Use-After-Free of VMA via race Between reclaim and munmap

Android - binder Use-After-Free via fdget() Optimization

Ubuntu snapd < 2.37.1 - Local Privilege Escalation

runc< 1.0-rc6 (Docker < 18.09.2) - Host Command Execution

Skyworth GPON HomeGateways and Optical Network Terminals - Stack Overflow

LayerBB 1.1.2 - Cross-Site Scripting

BlogEngine.NET 3.3.6 - Directory Traversal / Remote Code Execution

Jenkins 2.150.2 - Remote Command Execution (Metasploit)

OPNsense < 19.1.1 - Cross-Site Scripting

13.2.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Linux Kernel 'tcp_input.c' Remote Denial of Service Vulnerability
2019-02-13
http://www.securityfocus.com/bid/104976

OpenSSL CVE-2018-0739 Denial of Service Vulnerability
2019-02-13
http://www.securityfocus.com/bid/103518

OpenSSL CVE-2018-0732 Denial of Service Vulnerability
2019-02-13
http://www.securityfocus.com/bid/104442

OpenSSL CVE-2018-0737 Side Channel Attack Information Disclosure Vulnerability
2019-02-13
http://www.securityfocus.com/bid/103766

Apache CXF CVE-2018-8039 TLS Hostname Verification Security Bypass Vulnerability
2019-02-13
http://www.securityfocus.com/bid/106357

SAP Note Assistant XML External Entity Injection Vulnerability
2019-02-13
http://www.securityfocus.com/bid/99027

Adobe Flash Player CVE-2018-15983 DLL Loading Local Privilege Escalation Vulnerability
2019-02-12
http://www.securityfocus.com/bid/106108

Exploint

Android - binder Use-After-Free of VMA via race Between reclaim and munmap

Android - binder Use-After-Free via fdget() Optimization

NetworkSleuth 3.0 - 'Name' Denial of Service (PoC)

Rukovoditel Project Management CRM 2.4.1 - Cross-Site Scripting

Jiofi 4 (JMR 1140 Amtel_JMR1140_R12.07) - Cross-Site Request Forgery (Admin Token Disclosure)

Jiofi 4 (JMR 1140 Amtel_JMR1140_R12.07) - Cross-Site Request Forgery (Password Disclosure)

Jiofi 4 (JMR 1140 Amtel_JMR1140_R12.07) - Reflected Cross-Site Scripting

Ubuntu snapd < 2.37.1 - Local Privilege Escalation

snapd < 2.37 (Ubuntu) - 'dirty_sock' Local Privilege Escalation (2)

snapd < 2.37 (Ubuntu) - 'dirty_sock' Local Privilege Escalation (1)

runc< 1.0-rc6 (Docker < 18.09.2) - Host Command Execution

Skyworth GPON HomeGateways and Optical Network Terminals - Stack Overflow

LayerBB 1.1.2 - Cross-Site Scripting

BlogEngine.NET 3.3.6 - Directory Traversal / Remote Code Execution

Jenkins 2.150.2 - Remote Command Execution (Metasploit)

OPNsense < 19.1.1 - Cross-Site Scripting

12.2.2019

Bugtraq

 

Malware

Downloader.Keapot

Backdoor.Scuoter

Hacktool.Modlishka

Phishing

 

Vulnerebility

SAP Business Client Unspecified Security Vulnerability
2019-02-12
http://www.securityfocus.com/bid/104436

Adobe Acrobat and Reader CVE-2019-7030 Information Disclosure Vulnerability
2019-02-12
http://www.securityfocus.com/bid/106983

Adobe Creative Cloud CVE-2019-7093 DLL Loading Local Privilege Escalation Vulnerability
2019-02-12
http://www.securityfocus.com/bid/106982

Adobe Acrobat and Reader CVE-2019-7089 Information Disclosure Vulnerability
2019-02-12
http://www.securityfocus.com/bid/106981

Adobe Acrobat and Reader APSB19-07 Multiple Unspecified Arbitrary Code Execution Vulnerabilities
2019-02-12
http://www.securityfocus.com/bid/106980

Adobe Acrobat and Reader APSB19-07 Multiple Unspecified Arbitrary Code Execution Vulnerabilities
2019-02-12
http://www.securityfocus.com/bid/106979

Adobe Acrobat and Reader Out-Of-Bounds Write Multiple Arbitrary Code Execution Vulnerabilities
2019-02-12
http://www.securityfocus.com/bid/106978

Adobe Acrobat and Reader APSB19-07 Multiple Arbitrary Code Execution Vulnerabilities
2019-02-12
http://www.securityfocus.com/bid/106977

Adobe Acrobat and Reader APSB19-07 Multiple Arbitrary Code Execution Vulnerabilities
2019-02-12
http://www.securityfocus.com/bid/106975

Adobe Acrobat and Reader APSB19-07 Multiple Remote Privilege Escalation Vulnerabilities
2019-02-12
http://www.securityfocus.com/bid/106974

Adobe Acrobat and Reader APSB19-07 Multiple Information Disclosure Vulnerabilities
2019-02-12
http://www.securityfocus.com/bid/106973

SAP Netweaver ABAP CVE-2019-0265 XML External Entity Injection Vulnerability
2019-02-12
http://www.securityfocus.com/bid/106972

SAP Disclosure Management CVE-2019-0258 Remote Authorization Bypass Vulnerability
2019-02-12
http://www.securityfocus.com/bid/106969

Adobe ColdFusion CVE-2019-7091 Arbitrary Code Execution Vulnerability
2019-02-12
http://www.securityfocus.com/bid/106968

Adobe ColdFusion CVE-2019-7092 Unspecified Cross Site Scripting Vulnerability
2019-02-12
http://www.securityfocus.com/bid/106965

Multiple Siemens SIPROTEC Products ICSA-16-140-02 Information Disclosure Vulnerabilities
2019-02-11
http://www.securityfocus.com/bid/90773

Exploint

OPNsense < 19.1.1 - Cross-Site Scripting

Jenkins 2.150.2 - Remote Command Execution (Metasploit)

LayerBB 1.1.2 - Cross-Site Scripting

runc< 1.0-rc6 (Docker < 18.09.2) - Host Command Execution

Skyworth GPON HomeGateways and Optical Network Terminals - Stack Overflow

11.2.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Siemens EN100 Ethernet Communication Module Multiple Denial of Service Vulnerabilities
2019-02-11
http://www.securityfocus.com/bid/106221

IBM API Connect CVE-2019-4008 Information Disclosure Vulnerability
2019-02-11
http://www.securityfocus.com/bid/106961

SSL/TLS Protocol CVE-2016-2183 Information Disclosure Vulnerability
2019-02-08
http://www.securityfocus.com/bid/92630

Exploint

Smoothwall Express 3.1-SP4 - Cross-Site Scripting

River Past Cam Do 3.7.6 - Local Buffer Overflow (SEH)

IP-Tools 2.5 - Local Buffer Overflow (SEH) (Egghunter)

VA MAX 8.3.4 - Authenticated Remote Code Execution

MyBB Bans List 1.0 - Cross-Site Scripting

River Past Video Cleaner 7.6.3 - Local Buffer Overflow (SEH)

Avast Anti-Virus < 19.1.2360 - Local Credentials Disclosure

IPFire 2.21 - Cross-Site Scripting

NordVPN 6.19.6 - Denial of Service (PoC)

Indusoft Web Studio 8.1 SP2 - Remote Code Execution

Evince - CBT File Command Injection (Metasploit)

NUUO NVRmini - upgrade_handle.php Remote Command Execution (Metasploit)

Adobe Flash Player - DeleteRangeTimelineOperation Type Confusion (Metasploit)

FutureDj Pro 1.7.2.0 - Denial of Service

AirDroid 4.2.1.6 - Denial of Service

Coship Wireless Router 4.0.0.x/5.0.0.x - WiFi Password Reset

8.2.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

SSL/TLS Protocol CVE-2016-2183 Information Disclosure Vulnerability
2019-02-08
http://www.securityfocus.com/bid/92630

Google Android Multiple Kernel Components Multiple Information Disclosure Vulnerabilites
2019-02-08
http://www.securityfocus.com/bid/93326

Google Android Multiple Qualcomm Components Multiple Security Vulnerabilities
2019-02-08
http://www.securityfocus.com/bid/102974

Cisco Meeting Server CVE-2019-1678 Denial of Service Vulnerability
2019-02-08
http://www.securityfocus.com/bid/106943

Linux Kernel CVE-2018-1087 Local Privilege Escalation Vulnerability
2019-02-08
http://www.securityfocus.com/bid/104127

Apache Subversion CVE-2018-11803 Denial of Service Vulnerability
2019-02-08
http://www.securityfocus.com/bid/106770

Schneider Electric Zelio Soft 2 CVE-2018-7817 Remote Code Execution Vulnerability
2019-02-08
http://www.securityfocus.com/bid/106481

Exploint

 

7.2.2019

Bugtraq

 

Malware

Ransom.Gogalocker

Phishing

 

Vulnerebility

Jenkins Multiple Input Validation Security Vulnerabilities
2019-02-07
http://www.securityfocus.com/bid/106774

Siemens S7-1500 CPU Multiple Denial of Service Vulnerabilities
2019-02-06
http://www.securityfocus.com/bid/106788

Microsoft Exchange Server Remote Privilege Escalation Vulnerability
2019-02-06
http://www.securityfocus.com/bid/106725

OpenSSH CVE-2019-6111 Arbitrary File Overwrite Vulnerability
2019-02-06
http://www.securityfocus.com/bid/106741

Cisco Meeting Server CVE-2019-1676 Denial of Service Vulnerability
2019-02-06
http://www.securityfocus.com/bid/106909

Cisco Web Security Appliance CVE-2019-1672 Remote Security Bypass Vulnerability
2019-02-06
http://www.securityfocus.com/bid/106904

Exploint

 

6.2.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Siemens S7-1500 CPU Multiple Denial of Service Vulnerabilities
2019-02-06
http://www.securityfocus.com/bid/106788

Microsoft Exchange Server Remote Privilege Escalation Vulnerability
2019-02-06
http://www.securityfocus.com/bid/106725

OpenSSH CVE-2019-6111 Arbitrary File Overwrite Vulnerability
2019-02-06
http://www.securityfocus.com/bid/106741

Mozilla Firefox and Firefox ESR Multiple Security Vulnerabilities
2019-02-05
http://www.securityfocus.com/bid/106168

Exploint

Skia - Incorrect Convexity Assumptions Leading to Buffer Overflows

River Past Audio Converter 7.7.16 - Buffer Overflow (SEH)

osCommerce 2.3.4.1 - 'reviews_id' SQL Injection

osCommerce 2.3.4.1 - 'products_id' SQL Injection

osCommerce 2.3.4.1 - 'currency' SQL Injection

5.2.2019

Bugtraq

 

Malware

Linux.Speakup

Phishing

 

Vulnerebility

OpenSSL CVE-2018-0737 Side Channel Attack Information Disclosure Vulnerability
2019-02-05
http://www.securityfocus.com/bid/103766

OpenSSH CVE-2018-15473 User Enumeration Vulnerability
2019-02-05
http://www.securityfocus.com/bid/105140

Poppler 'XRef.cc' Heap Buffer Overflow Vulnerability
2019-02-02
http://www.securityfocus.com/bid/106829

SSL/TLS Protocol CVE-2016-2183 Information Disclosure Vulnerability
2019-02-01
http://www.securityfocus.com/bid/92630

Exploint

OpenMRS Platform < 2.24.0 - Insecure Object Deserialization

Zyxel VMG3312-B10B DSL-491HNU-B1B v2 Modem - Cross-Site Request Forgery

devolo dLAN 550 duo+ Starter Kit - Cross-Site Request Forgery

River Past Audio Converter 7.7.16 - Denial of Service (PoC)

Device Monitoring Studio 8.10.00.8925 - Denial of Service (PoC)

BEWARD N100 H.264 VGA IP Camera M2.1.6 - Arbitrary File Disclosure

BEWARD N100 H.264 VGA IP Camera M2.1.6 - Remote Code Execution

BEWARD N100 H.264 VGA IP Camera M2.1.6 - Cross-Site Request Forgery (Add Admin)

BEWARD N100 H.264 VGA IP Camera M2.1.6 - RTSP Stream Disclosure

4.2.2019

Bugtraq

 

Malware

 

Phishing

Amazon Order

4th February 2019

Amazon Order Confirmation
Pending

Vulnerebility

 

Exploint

Nessus 8.2.1 - Cross-Site Scripting

pfSense 2.4.4-p1 - Cross-Site Scripting

TaskInfo 8.2.0.280 - Denial of Service (PoC)

SpotAuditor 3.6.7 - Denial of Service (PoC)

LibSSH 0.7.6 / 0.8.4 - Unauthorized Access

MyVideoConverter Pro 3.14 - Denial of Service

River Past Ringtone Converter 2.7.6.1601 - Denial of Service (PoC)

SuiteCRM 7.10.7 - 'record' SQL Injection

SuiteCRM 7.10.7 - 'parentTab' SQL Injection

ResourceSpace 8.6 - 'watched_searches.php' SQL Injection

3.2.2019

Bugtraq

 

Malware

 

Phishing

Tesco

3rd February 2019

Important message for Steve

Amazon Order

3rd February 2019

Amazon Order Confirmation
Pending

AT&T

1st February 2019

Update!!!

Amazon Order

1st February 2019

Amazon Order Confirmation
Pending

Review Update

30th January 2019

AOL Mail (New Terms)

Chase

30th January 2019

ACH NOTICE OF CHANGE [SECURE]

Vulnerebility

SSL/TLS Protocol CVE-2016-2183 Information Disclosure Vulnerability
2019-02-01
http://www.securityfocus.com/bid/92630

Identicard Premisys Multiple Security Vulnerabilities
2019-02-01
http://www.securityfocus.com/bid/106552

Mozilla Firefox and Firefox ESR Multiple Security Vulnerabilities
2019-02-01
http://www.securityfocus.com/bid/101059

Expat XML Parsing Remote Denial of Service Vulnerability
2019-02-01
http://www.securityfocus.com/bid/37203

Exploint

SureMDM < 2018-11 Patch - Local / Remote File Inclusion

Remote Process Explorer 1.0.0.16 - Denial of Service SEH Overwrite (PoC)

1.2.2019

Bugtraq

 

Malware

Trojan.Formbook

Backdoor.Chafpe

Backdoor.Chafanty

Backdoor.Chafty

Backdoor.Chafpy

Phishing

 

Vulnerebility

Identicard Premisys Multiple Security Vulnerabilities
2019-02-01
http://www.securityfocus.com/bid/106552

Mozilla Firefox and Firefox ESR Multiple Security Vulnerabilities
2019-02-01
http://www.securityfocus.com/bid/101059

Expat XML Parsing Remote Denial of Service Vulnerability
2019-02-01
http://www.securityfocus.com/bid/37203

Solaris DTMail Mail Environment Variable Buffer Overflow Vulnerability
2019-01-31
http://www.securityfocus.com/bid/3081

Exploint

PassFab Excel Password Recovery 8.3.1 - SEH Local Exploit

31.1.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Google Chrome Prior to 72.0.3626.81 Multiple Security Vulnerabilities
2019-01-31
http://www.securityfocus.com/bid/106767

Oracle VM VirtualBox Mulltiple Local Security Vulnerabilities
2019-01-31
http://www.securityfocus.com/bid/106568

GuppY Error.PHP HTML Injection Vulnerability
2019-01-31
http://www.securityfocus.com/bid/14753

Check Point Firewall-1 RDP Header Firewall Bypassing Vulnerability
2019-01-31
http://www.securityfocus.com/bid/2952

Adobe Flash Player APSB17-17 Multiple Memory Corruption Vulnerabilities
2019-01-31
http://www.securityfocus.com/bid/99025

askSam Web Publisher Cross Site Scripting Vulnerability
2019-01-31
http://www.securityfocus.com/bid/4670

Adobe Flash Player APSB17-15 Multiple Memory Corruption Vulnerabilities
2019-01-31
http://www.securityfocus.com/bid/98349

Solaris xlock Heap Overflow Vulnerability
2019-01-31
http://www.securityfocus.com/bid/3160

Google Chrome Prior to 61.0.3163.79 Multiple Security Vulnerabilities
2019-01-31
http://www.securityfocus.com/bid/100610

WebKit Multiple Memory Corruption Vulnerabilities
2019-01-30
http://www.securityfocus.com/bid/106696

WebKit Multiple Memory Corruption Vulnerabilities
2019-01-30
http://www.securityfocus.com/bid/106699

WebKit Multiple Security Vulnerabilities
2019-01-30
http://www.securityfocus.com/bid/106691

SQLite 'FTS3' extension Remote Code Execution Vulnerability
2019-01-30
http://www.securityfocus.com/bid/106698

Exploint

macOS < 10.14.3 / iOS < 12.1.3 - Kernel Heap Overflow in PF_KEY due to Lack of Bounds Checking when Retrieving Statistics

macOS < 10.14.3 / iOS < 12.1.3 XNU - 'vm_map_copy' Optimization which Requires Atomicity isn't Atomic

macOS < 10.14.3 / iOS < 12.1.3 - Sandbox Escapes due to Type Confusions and Memory Safety Issues in iohideventsystem

macOS < 10.14.3 / iOS < 12.1.3 - Arbitrary mach Port Name Deallocation in XPC Services due to Invalid mach Message Parsing in _xpc_serializer_unpack

macOS XNU - Copy-on-Write Behaviour Bypass via Partial-Page Truncation of File

LanHelper 1.74 - Denial of Service (PoC)

FlexHEX 2.46 - Denial of Service SEH Overwrite (PoC)

ASPRunner Professional 6.0.766 - Denial of Service (PoC)

AMAC Address Change 5.4 - Denial of Service (PoC)

Advanced Host Monitor 11.90 Beta - 'Registration number' Denial of Service (PoC)

UltraISO 9.7.1.3519 - 'Output FileName' Local Buffer Overflow (SEH)

Anyburn 4.3 - 'Convert image to file format' Denial of Service

R 3.5.0 - Local Buffer Overflow (SEH)

Necrosoft DIG 0.4 - Denial of Service SEH Overwrite (PoC)

IP-Tools 2.50 - Denial of Service SEH Overwrite (PoC)

iOS/macOS 10.13.6 - 'if_ports_used_update_wakeuuid()' 16-byte Uninitialized Kernel Stack Disclosure

Advanced File Manager 3.4.1 - Denial of Service (PoC)

10-Strike Network Inventory Explorer 8.54 - Local Buffer Overflow (SEH) (DEP Bypass)

Rukovoditel Project Management CRM 2.4.1 - 'lists_id' SQL Injection