Databáze Hot News 2019 June - 2019 January  February  March  April  May  June  July  August  September  October  November  December


28.6.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Intel Microarchitectural Data Sampling Multiple Local Information Disclosure Vulnerabilities
2019-06-28
http://www.securityfocus.com/bid/108330

IBM Sterling B2B Integrator CVE-2019-4377 Information Disclosure Vulnerability
2019-06-28
http://www.securityfocus.com/bid/108915

Symantec Endpoint Encryption CVE-2019-9703 Local Privilege Escalation Vulnerability
2019-06-28
http://www.securityfocus.com/bid/108796

Symantec Endpoint Encryption CVE-2019-9702 Local Privilege Escalation Vulnerability
2019-06-28
http://www.securityfocus.com/bid/108795

Exploint

LibreNMS 1.46 - 'addhost' Remote Code Execution

26.6.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Linux kernel CVE-2019-12817 Local Privilege Escalation Vulnerability
2019-06-26
http://www.securityfocus.com/bid/108884

Exploint

Nagios XI 5.5.6 - Magpie_debug.php Root Remote Code Execution (Metasploit)

Mozilla Spidermonkey - IonMonkey 'Array.prototype.pop' Type Confusion

25.6.2019

Bugtraq

 

Malware

Exp.CVE-2019-0888

Trojan.Amadey

Trojan.Malmsi

Backdoor.Powerton

Phishing

 

Vulnerebility

Multiple Cisco Products CVE-2019-1845 Denial of Service Vulnerability
2019-06-25
http://www.securityfocus.com/bid/108615

Kubernetes CVE-2019-11246 Incomplete Fix Arbitrary File Overwrite Vulnerability
2019-06-25
http://www.securityfocus.com/bid/108866

Exploint

WordPress Plugin Live Chat Unlimited 2.8.3 - Cross-Site Scripting

WordPress Plugin iLive 1.0.4 - Cross-Site Scripting

BlogEngine.NET 3.3.6/3.3.7 - 'path' Directory Traversal

AZADMIN CMS 1.0 - SQL Injection

Fortinet FCM-MB40 - Cross-Site Request Forgery / Remote Command Execution

SAPIDO RB-1732 - Remote Command Execution

SuperDoctor5 - 'NRPE' Remote Code Execution

24.6.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Samba CVE-2019-12436 Remote Denial of Service Vulnerability
2019-06-24
http://www.securityfocus.com/bid/108823

Samba CVE-2019-12435 Remote Denial of Service Vulnerability
2019-06-24
http://www.securityfocus.com/bid/108825

Exploint

Microsoft Windows Font Cache Service - Insecure Sections Privilege Escalation

Microsoft Windows - 'CmpAddRemoveContainerToCLFSLog' Arbitrary File/Directory Creation

GrandNode 4.40 - Path Traversal / Arbitrary File Download

GSearch 1.0.1.0 - Denial of Service (PoC)

SeedDMS < 5.1.11 - 'out.GroupMgr.php' Cross-Site Scripting

SeedDMS < 5.1.11 - 'out.UsrMgr.php' Cross-Site Scripting

SeedDMS versions < 5.1.11 - Remote Command Execution

dotProject 2.1.9 - SQL Injection

23.6.2019

Bugtraq

 

Malware

 

Phishing

=?UTF-8?Q?ESSENTIAL CBD EXTRAC

22nd June 2019

WHY IS EVERYONE TALKING ABOUT
CBD?

Vulnerebility

 

Exploint

 

21.6.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Microsoft Internet Explorer CVE-2019-0995 Security Bypass Vulnerability
2019-06-21
http://www.securityfocus.com/bid/108310

Mozilla Firefox and Firefox ESR CVE-2019-11708 Security Bypass Vulnerability
2019-06-21
http://www.securityfocus.com/bid/108835

Mozilla Firefox and Firefox ESR CVE-2019-11707 Denial of Service Vulnerability
2019-06-21
http://www.securityfocus.com/bid/108810

Cisco Prime Service Catalog CVE-2019-1875 Cross Site Scripting Vulnerability
2019-06-21
http://www.securityfocus.com/bid/108836

IBM Tririga Application Platform CVE-2018-2008 Unspecified Information Disclosure Vulnerability
2019-06-21
http://www.securityfocus.com/bid/108843

Cisco Integrated Management Controller CVE-2019-1629 Arbitrary File Write Vulnerability
2019-06-21
http://www.securityfocus.com/bid/108852

Exploint

EA Origin < 10.5.38 - Remote Code Execution

20.6.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Intel Microarchitectural Data Sampling Multiple Local Information Disclosure Vulnerabilities
2019-06-20
http://www.securityfocus.com/bid/108330

OpenSSL CVE-2019-1559 Information Disclosure Vulnerability
2019-06-20
http://www.securityfocus.com/bid/107174

Exploint

Cisco Prime Infrastructure - Runrshell Privilege Escalation (Metasploit)

Cisco Prime Infrastructure Health Monitor - TarArchive Directory Traversal (Metasploit)

Linux - Use-After-Free via race Between modify_ldt() and #BR Exception

BlogEngine.NET 3.3.6/3.3.7 - XML External Entity Injection

WebERP 4.15 - SQL injection

Tuneclone 2.20 - Local SEH Buffer Overflow

19.6.2019

Bugtraq

 

Malware

 

Phishing

Client service

19th June 2019

- Amazon - your friend with
benefits. Get yours now

Vulnerebility

Symantec DLP CVE-2019-9701 Cross Site Scripting Vulnerability
2019-06-19
http://www.securityfocus.com/bid/108733

Exploint

BlogEngine.NET 3.3.6/3.3.7 - 'theme Cookie' Directory Traversal / Remote Code Execution

BlogEngine.NET 3.3.6/3.3.7 - 'dirPath' Directory Traversal / Remote Code Execution

18.6.2019

Bugtraq

 

Malware

 

Phishing

AOL : Oath Team

17th June 2019

Account Review

AOL OATH Policy Change

16th June 2019

@2019 AOL OATH Member Policy &
Privacy Update

Vulnerebility

Microsoft Windows Remote Desktop Services CVE-2019-0708 Remote Code Execution Vulnerability
2019-06-18
http://www.securityfocus.com/bid/108273

WhatsApp CVE-2018-6350 Out of Bounds Read Denial of Service Vulnerability
2019-06-18
http://www.securityfocus.com/bid/108803

Exploint

Serv-U FTP Server < 15.1.7 - Local Privilege Escalation

Sahi pro 8.x - Cross-Site Scripting

Sahi pro 8.x - SQL Injection

Sahi pro 7.x/8.x - Directory Traversal

17.6.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Cisco Identity Services Engine CVE-2018-0187 Information Disclosure Vulnerability
2019-06-17
http://www.securityfocus.com/bid/106717

Google Chrome CVE-2019-5842 Remote Security Vulnerability
2019-06-17
http://www.securityfocus.com/bid/108758

QEMU 'tcp_subr.c' Local Heap Buffer Overflow Vulnerability
2019-06-17
http://www.securityfocus.com/bid/106758

Exploint

Microsoft Windows - UAC Protection Bypass (Via Slui File Handler Hijack) (PowerShell)

Thunderbird ESR < 60.7.XXX - 'icalrecur_add_bydayrules' Stack-Based Buffer Overflow

Thunderbird ESR < 60.7.XXX - 'parser_get_next_char' Heap-Based Buffer Overflow

Thunderbird ESR < 60.7.XXX - 'icalmemorystrdupanddequote' Heap-Based Buffer Overflow

Thunderbird ESR < 60.7.XXX - Type Confusion

Spring Security OAuth - Open Redirector

AROX School-ERP Pro - Unauthenticated Remote Command Execution (Metasploit)

Netperf 2.6.0 - Stack-Based Buffer Overflow

Exim 4.87 - 4.91 - Local Privilege Escalation

HC10 HC.Server Service 10.14 - Remote Invalid Pointer Write

CleverDog Smart Camera DOG-2W / DOG-2W-V4 - Multiple Vulnerabilities

RedwoodHQ 2.5.5 - Authentication Bypass

CleverDog Smart Camera DOG-2W / DOG-2W-V4 - Multiple Vulnerabilities

RedwoodHQ 2.5.5 - Authentication Bypass

16.6.2019

Bugtraq

 

Malware

 

Phishing

AOL OATH Policy Change

16th June 2019

@2019 AOL OATH Member Policy &
Privacy Update

Vulnerebility

 

Exploint

 

14.6.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

 

Exploint

CentOS 7.6 - 'ptrace_scope' Privilege Escalation

Aida64 6.00.5100 - 'Log to CSV File' Local SEH Buffer Overflow

13.6.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Apache httpd CVE-2019-0196 Security Bypass Vulnerability
2019-06-13
http://www.securityfocus.com/bid/107669

RETIRED: Microsoft Windows Task Scheduler CVE-2019-1069 Local Privilege Escalation Vulnerability
2019-06-13
http://www.securityfocus.com/bid/108588

Microsoft Windows 'SetJobFileSecurityByName()' Function Local Privilege Escalation Vulnerability
2019-06-13
http://www.securityfocus.com/bid/108423

Microsoft Windows CVE-2019-1064 Local Privilege Escalation Vulnerability
2019-06-13
http://www.securityfocus.com/bid/108587

Microsoft Windows Shell CVE-2019-1053 Local Privilege Escalation Vulnerability
2019-06-13
http://www.securityfocus.com/bid/108585

Microsoft Windows Installer CVE-2019-0973 DLL Loading Local Privilege Escalation Vulnerability
2019-06-13
http://www.securityfocus.com/bid/108651

Exploint

 

12.6.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

 

Exploint

FusionPBX 4.4.3 - Remote Command Execution

11.6.2019

Bugtraq

 

Malware

 

Phishing

National Bank of Abu Dhabi

11th June 2019

Re: Attn For Your
($15,500,000.00) Funds
Transfer

Vulnerebility

Microsoft Windows AppX Deployment Service Incomplete Fix Local Privilege Escalation Vulnerability
2019-06-11
http://www.securityfocus.com/bid/108696

SAP Enterprise Financial Services CVE-2018-2484 Remote Authorization Bypass Vulnerability
2019-06-11
http://www.securityfocus.com/bid/106477

SAP Solution Manager CVE-2019-0291 Local Information Disclosure Vulnerability
2019-06-11
http://www.securityfocus.com/bid/108313

SAP Business Client Unspecified Security Vulnerability
2019-06-11
http://www.securityfocus.com/bid/104436

SAP NetWeaver Process Integration CVE-2019-0316 Cross Site Scripting Vulnerability
2019-06-11
http://www.securityfocus.com/bid/108705

SAP R/3 Enterprise Application CVE-2019-0311 Cross Site Scripting Vulnerability
2019-06-11
http://www.securityfocus.com/bid/108704

SAP NetWeaver Process Integration CVE-2019-0305 Clickjacking Vulnerability
2019-06-11
http://www.securityfocus.com/bid/108702

SAP E-Commerce CVE-2019-0308 Remote Code Injection Vulnerability
2019-06-11
http://www.securityfocus.com/bid/108700

SAP HANA Extended Application Services CVE-2019-0306 Information Disclosure Vulnerability
2019-06-11
http://www.securityfocus.com/bid/108699

SAP Work and Inventory Manager CVE-2019-0314 Denial of Service Vulnerability
2019-06-11
http://www.securityfocus.com/bid/108698

Atlassian Crowd and Crowd Data Center CVE-2019-11580 Remote Code Execution Vulnerability
2019-06-11
http://www.securityfocus.com/bid/108637

Exploint

Webmin 1.910 - 'Package Updates' Remote Command Execution (Metasploit)

Liferay Portal 7.1 CE GA=3 / SimpleCaptcha API - Cross-Site Scripting

phpMyAdmin 4.8 - Cross-Site Request Forgery

WordPress Plugin Insert or Embed Articulate Content into WordPress - Remote Code Execution

ProShow 9.0.3797 - Local Privilege Escalation

10.6.2019

Bugtraq

 

Malware

 

Phishing

Microsoft Outlook

9th June 2019

Termination Request For Your
Hotmail Outlook Account

Vulnerebility

Infomir Ministra TV Platform Multiple Security Vulnerabilities
2019-06-10
http://www.securityfocus.com/bid/108695

Exploint

Ubuntu 18.04 - 'lxd' Privilege Escalation

UliCMS 2019.1 'Spitting Lama' - Persistent Cross-Site Scripting

9.6.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

VMware Workstation CVE-2019-5525 Local Code Execution Vulnerability
2019-06-06
http://www.securityfocus.com/bid/108674

VMware Tools CVE-2019-5522 Local Information Disclosure Vulnerability
2019-06-06
http://www.securityfocus.com/bid/108673

Exploint

Microsoft Windows - AppX Deployment Service Local Privilege Escalation (3)

Exim 4.87 < 4.91 - (Local / Remote) Command Execution

Vim < 8.1.1365 / Neovim < 0.3.6 - Arbitrary Code Execution

Nvidia GeForce Experience Web Helper - Command Injection

6.6.2019

Bugtraq

 

Malware

OSX.Keysteal

Phishing

 

Vulnerebility

 

Exploint

Supra Smart Cloud TV - 'openLiveURL()' Remote File Inclusion

5.6.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Microsoft Outlook Web Access with RSA SecurID Authentication Bypass Vulnerability
2019-06-05
http://www.securityfocus.com/bid/4390

Microsoft Exchange 2000 Post Authorization License Exhaustion Denial Of Service Vulnerability
2019-06-05
http://www.securityfocus.com/bid/5413

Microsoft Exchange 2000 Multiple MSRPC Denial Of Service Vulnerabilities
2019-06-05
http://www.securityfocus.com/bid/5412

Microsoft Outlook Web Access for Exchange Server 'redir.asp' URI Redirection Vulnerability
2019-06-05
http://www.securityfocus.com/bid/31765

Microsoft Outlook Web Access Login Form Remote URI Redirection Vulnerability
2019-06-05
http://www.securityfocus.com/bid/12459

Microsoft Outlook Web Access for Exchange Server 2003 Cross Site Request Forgery Vulnerability
2019-06-05
http://www.securityfocus.com/bid/41843

Microsoft Exchange Server Outlook Web Access Cross Site Request Forgery Vulnerability
2019-06-05
http://www.securityfocus.com/bid/41462

Microsoft Exchange Server Remote Privilege Escalation Vulnerability
2019-06-05
http://www.securityfocus.com/bid/106725

Django CVE-2019-12308 Cross Site Scripting Vulnerability
2019-06-05
http://www.securityfocus.com/bid/108559

Geutebruck G-Cam and G-Code HTML Injection and Multiple OS Command Injection Vulnerabilities
2019-06-05
http://www.securityfocus.com/bid/108579

Phoenix Contact FL NAT SMx Ethernet Switches CVE-2019-9744 Authorization Bypass Vulnerability
2019-06-05
http://www.securityfocus.com/bid/108576

Exploint

IBM Websphere Application Server - Network Deployment Untrusted Data Deserialization Remote Code Execution (Metasploit)

Google Chrome 73.0.3683.103 - 'WasmMemoryObject::Grow' Use-After-Free

Zimbra < 8.8.11 - XML External Entity Injection / Server-Side Request Forgery

LibreNMS - addhost Command Injection (Metasploit)

4.6.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Google Android 'Framework' Component Multiple Security Vulnerabilities
2019-06-04
http://www.securityfocus.com/bid/105847

ImageMagick CVE-2018-16750 Denial of Service Vulnerability
2019-06-03
http://www.securityfocus.com/bid/108492

FreeBSD CVE-2018-6918 Denial of Service Vulnerability
2019-06-03
http://www.securityfocus.com/bid/103666

Apache Hadoop CVE-2018-8029 Remote Privilege Escalation Vulnerability
2019-06-03
http://www.securityfocus.com/bid/108518

Django CVE-2019-12308 Cross Site Scripting Vulnerability
2019-06-03
http://www.securityfocus.com/bid/108559

Google Android Kernel Components CVE-2019-2101 Information Disclosure Vulnerability
2019-06-03
http://www.securityfocus.com/bid/108557

Qualcomm Components Multiple Security Vulnerabilities
2019-06-03
http://www.securityfocus.com/bid/108555

Google Android System Component Multiple Security Vulnerabilities
2019-06-03
http://www.securityfocus.com/bid/108554

Google Android Framework Component Multiple Privilege Escalation Vulnerabilities
2019-06-03
http://www.securityfocus.com/bid/108552

Linux Kernel CVE-2019-12614 Denial of Service Vulnerability
2019-06-03
http://www.securityfocus.com/bid/108550

Linux Kernel CVE-2019-12615 Denial of Service Vulnerability
2019-06-03
http://www.securityfocus.com/bid/108549

Google Android Media Framework Component Multiple Security Vulnerabilities
2019-06-03
http://www.securityfocus.com/bid/108548

Qualcomm Closed Source Components Multiple Unspecified Vulnerabilities
2019-06-03
http://www.securityfocus.com/bid/108546

Fortinet FortiOS CVE-2018-13383 Heap Buffer Overflow Vulnerability
2019-06-03
http://www.securityfocus.com/bid/108539

Exploint

Cisco RV130W 1.0.3.44 - Remote Stack Overflow

Zoho ManageEngine ServiceDesk Plus 9.3 - 'PurchaseRequest.do' Cross-Site Scripting

Zoho ManageEngine ServiceDesk Plus 9.3 - 'SearchN.do' Cross-Site Scripting

Zoho ManageEngine ServiceDesk Plus 9.3 - 'SolutionSearch.do' Cross-Site Scripting

Zoho ManageEngine ServiceDesk Plus 9.3 - 'SiteLookup.do' Cross-Site Scripting

DVD X Player 5.5 Pro - Local Buffer Overflow (SEH)

NUUO NVRMini 2 3.9.1 - 'sscanf' Stack Overflow

IceWarp 10.4.4 - Local File Inclusion

3.6.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

ImageMagick CVE-2018-16750 Denial of Service Vulnerability
2019-06-03
http://www.securityfocus.com/bid/108492

FreeBSD CVE-2018-6918 Denial of Service Vulnerability
2019-06-03
http://www.securityfocus.com/bid/103666

Apache Hadoop CVE-2018-8029 Remote Privilege Escalation Vulnerability
2019-06-03
http://www.securityfocus.com/bid/108518

Fortinet FortiOS CVE-2018-13383 Heap Buffer Overflow Vulnerability
2019-06-03
http://www.securityfocus.com/bid/108539

Dell Kace K1000 Systems Management Appliance Multiple Security Vulnerabilities
2019-06-01
http://www.securityfocus.com/bid/108538

Exploint

AUO Solar Data Recorder < 1.3.0 - Incorrect Access Control

WordPress Plugin Form Maker 1.13.3 - SQL Injection

KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilities

2.6.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Microsoft Exchange Server CVE-2019-0858 Spoofing Vulnerability
2019-05-31
http://www.securityfocus.com/bid/107757

Microsoft Exchange Server CVE-2019-0817 Spoofing Vulnerability
2019-05-31
http://www.securityfocus.com/bid/107756

Microsoft Exchange Server CVE-2019-0686 Remote Privilege Escalation Vulnerability
2019-05-31
http://www.securityfocus.com/bid/106937

Microsoft Exchange Server CVE-2019-0724 Remote Privilege Escalation Vulnerability
2019-05-31
http://www.securityfocus.com/bid/106906

Microsoft Exchange Server Remote Privilege Escalation Vulnerability
2019-05-31
http://www.securityfocus.com/bid/106725

Microsoft Exchange Server CVE-2018-8581 Remote Privilege Escalation Vulnerability
2019-05-31
http://www.securityfocus.com/bid/105837

Microsoft Exchange Server CVE-2018-8448 Remote Privilege Escalation Vulnerability
2019-05-31
http://www.securityfocus.com/bid/105492

Microsoft Exchange Server CVE-2018-8265 Remote Code Execution Vulnerability
2019-05-31
http://www.securityfocus.com/bid/105491

Microsoft Exchange Server CVE-2018-8159 Remote Privilege Escalation Vulnerability
2019-05-31
http://www.securityfocus.com/bid/104056

Microsoft Exchange Server CVE-2018-8153 Spoofing Vulnerability
2019-05-31
http://www.securityfocus.com/bid/104045

Microsoft Exchange Server CVE-2018-8152 Remote Privilege Escalation Vulnerability
2019-05-31
http://www.securityfocus.com/bid/104043

Microsoft Exchange Server CVE-2018-0940 Remote Privilege Escalation Vulnerability
2019-05-31
http://www.securityfocus.com/bid/103323

Microsoft Exchange Server CVE-2017-11932 Spoofing Vulnerability
2019-05-31
http://www.securityfocus.com/bid/102060

Microsoft Exchange Server CVE-2017-8560 Remote Privilege Escalation Vulnerability
2019-05-31
http://www.securityfocus.com/bid/99449

Microsoft Exchange Server CVE-2017-8559 Remote Privilege Escalation Vulnerability
2019-05-31
http://www.securityfocus.com/bid/99448

Microsoft Exchange Server CVE-2017-0110 Remote Privilege Escalation Vulnerability
2019-05-31
http://www.securityfocus.com/bid/96621

Microsoft Exchange Server CVE-2016-0030 Spoofing Vulnerability
2019-05-31
http://www.securityfocus.com/bid/79890

Microsoft Exchange Server CVE-2016-0029 Spoofing Vulnerability
2019-05-31
http://www.securityfocus.com/bid/79889

Microsoft Exchange Server CVE-2016-0031 Spoofing Vulnerability
2019-05-31
http://www.securityfocus.com/bid/79888

Microsoft Exchange Server CVE-2016-0032 Spoofing Vulnerability
2019-05-31
http://www.securityfocus.com/bid/79884

Microsoft Exchange Server CVE-2013-5072 Cross Site Scripting Vulnerability
2019-05-31
http://www.securityfocus.com/bid/64085

Microsoft Exchange Server RSS Feed Remote Denial of Service Vulnerability
2019-05-31
http://www.securityfocus.com/bid/56836

Microsoft Exchange Server 2007 Infinite Loop Remote Denial of Service Vulnerability
2019-05-31
http://www.securityfocus.com/bid/45297

Microsoft Outlook Web Access for Exchange Server 2003 Cross Site Request Forgery Vulnerability
2019-05-31
http://www.securityfocus.com/bid/41843

Microsoft Exchange Server Outlook Web Access Cross Site Request Forgery Vulnerability
2019-05-31
http://www.securityfocus.com/bid/41462

Microsoft Exchange Server EMSMDB2 MAPI Command Remote Denial of Service Vulnerability
2019-05-31
http://www.securityfocus.com/bid/33136

Microsoft Exchange Server TNEF Decoding Remote Code Execution Vulnerability
2019-05-31
http://www.securityfocus.com/bid/33134

Microsoft Outlook Web Access for Exchange Server 'redir.asp' URI Redirection Vulnerability
2019-05-31
http://www.securityfocus.com/bid/31765

Microsoft Outlook Web Access for Exchange Server Email Field Cross-Site Scripting Vulnerability
2019-05-31
http://www.securityfocus.com/bid/30130

Exploint