Databáze Hot News 2019 March - 2019 January  February  March  April  May  June  July  August  September  October  November  December


31.3.2019

Bugtraq

 

Malware

 

Phishing

FEDEX

30th March 2019

eskram37,0rder Confirmation

Vulnerebility

 

Exploint

 

29.3.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

 

Exploint

 

28.3.2019

Bugtraq

 

Malware

Backdoor.Tinimeti

Hacktool.Gobrut

Phishing

 

Vulnerebility

Huawei PCManager Privilege Escalation and Remote Code Execution Vulnerabilities
2019-03-27
http://www.securityfocus.com/bid/106838

Cisco IOS XE Software CVE-2019-1756 Command Injection Vulnerability
2019-03-27
http://www.securityfocus.com/bid/107598

Cisco IOS and IOS XE Software CVE-2019-1762 Local Information Disclosure Vulnerability
2019-03-27
http://www.securityfocus.com/bid/107594

Cisco IOS XE Software CVE-2019-1743 Arbitrary File Upload Vulnerability
2019-03-27
http://www.securityfocus.com/bid/107591

Cisco IOS XE Software CVE-2019-1754 Remote Privilege Escalation Vulnerability
2019-03-27
http://www.securityfocus.com/bid/107590

Cisco IOS and IOS XE Software CVE-2019-1752 Denial of Service Vulnerability
2019-03-27
http://www.securityfocus.com/bid/107589

Cisco IOS XE Software CVE-2019-1745 Local Command Injection Vulnerability
2019-03-27
http://www.securityfocus.com/bid/107588

Cisco IOS XE Software CVE-2019-1755 Command Injection Vulnerability
2019-03-27
http://www.securityfocus.com/bid/107380

Mozilla Firefox and Firefox ESR Remote Memory Corruption and Buffer Overflow Vulnerabilities
2019-03-26
http://www.securityfocus.com/bid/107548

Net-SNMP CVE-2018-18065 Remote Denial of Service Vulnerability
2019-03-26
http://www.securityfocus.com/bid/106265

Multiple Phoenix Contact Products CVE-2019-9743 Command Injection Vulnerability
2019-03-26
http://www.securityfocus.com/bid/107596

Exploint

Base64 Decoder 1.1.2 - Local Buffer Overflow (SEH Egghunter)

Jettweb PHP Hazır Rent A Car Sitesi Scripti V2 - 'arac_kategori_id' SQL Injection

BigTree 4.3.4 CMS - Multiple SQL Injection

Job Portal 3.1 - 'job_submit' SQL Injection

Microsoft Visio 2016 16.0.4738.1000 - 'Log in accounts' Denial of Service

i-doit 1.12 - 'qr.php' Cross-Site Scripting

WordPress Plugin Loco Translate 2.2.1 - Local File Inclusion

WordPress Plugin Anti-Malware Security and Brute-Force Firewall 4.18.63 - Local File Inclusion

Fat Free CRM 0.19.0 - HTML Injection

Airbnb Clone Script - Multiple SQL Injection

Thomson Reuters Concourse & Firm Central < 2.13.0097 - Directory Traversal / Local File Inclusion

27.3.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Huawei PCManager Privilege Escalation and Remote Code Execution Vulnerabilities
2019-03-27
http://www.securityfocus.com/bid/106838

Mozilla Firefox and Firefox ESR Remote Memory Corruption and Buffer Overflow Vulnerabilities
2019-03-26
http://www.securityfocus.com/bid/107548

Net-SNMP CVE-2018-18065 Remote Denial of Service Vulnerability
2019-03-26
http://www.securityfocus.com/bid/106265

PCMan's FTP Server 'CDUP' Command Buffer Overflow Vulnerability
2019-03-26
http://www.securityfocus.com/bid/107574

Symantec Norton Core CVE-2019-9695 Unspecified Arbitrary Code Execution Vulnerability
2019-03-26
http://www.securityfocus.com/bid/107478

Exploint

Jettweb Hazır Rent A Car Scripti V4 - SQL Injection

Microsoft Windows 7/2008 - 'Win32k' Denial of Service (PoC)

Spidermonkey - IonMonkey Type Inference is Incorrect for Constructors Entered via OSR

SJS Simple Job Script - SQL Injection / Cross-Site Scripting

Titan FTP Server Version 2019 Build 3505 - Directory Traversal / Local File Inclusion

XooDigital - 'p' SQL Injection

XooGallery - Multiple SQL Injection

Rukovoditel ERP & CRM 2.4.1 - 'path' Cross-Site Scripting

Jettweb Php Hazır İlan Sitesi Scripti V2 - SQL Injection

26.3.2019

Bugtraq

 

Malware

Trojan.Susafone

Phishing

 

Vulnerebility

Mozilla Firefox and Firefox ESR Remote Memory Corruption and Buffer Overflow Vulnerabilities
2019-03-26
http://www.securityfocus.com/bid/107548

Net-SNMP CVE-2018-18065 Remote Denial of Service Vulnerability
2019-03-26
http://www.securityfocus.com/bid/106265

oVirt Engine CVE-2019-3879 Security Bypass Vulnerability
2019-03-25
http://www.securityfocus.com/bid/107561

Zoho ManageEngine ServiceDesk Plus CVE-2017-9376 Multiple Local File Include Vulnerabilities
2019-03-25
http://www.securityfocus.com/bid/107558

Exploint

VMware Workstation 14.1.5 / VMware Player 15 - Host VMX Process COM Class Hijack Privilege Escalation

VMware Workstation 14.1.5 / VMware Player 15.0.2 - Host VMX Process Impersonation Hijack Privilege Escalation

Zeeways Matrimony CMS - SQL Injection

Zeeways Jobsite CMS - 'id' SQL Injection

Jettweb PHP Hazır Haber Sitesi Scripti V3 - SQL Injection

Jettweb PHP Hazır Haber Sitesi Scripti V2 - SQL Injection (Authentication Bypass)

Jettweb PHP Hazır Haber Sitesi Scripti V1 - SQL Injection

X-NetStat Pro 5.63 - Local Buffer Overflow

Apache CouchDB 2.3.1 - Cross-Site Request Forgery / Cross-Site Scripting

24.3.2019

Bugtraq

 

Malware

Ransom.Ploc

Backdoor.Picigail

Phishing

 

Vulnerebility

 

Exploint

 

24.3.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

 

Exploint

snap - seccomp BBlacklist for TIOCSTI can be Circumvented

Inout Article Base CMS - SQL Injection

22.3.2019

Bugtraq

 

Malware

 

Phishing

Amazon Order

22nd March 2019

Amazon Order Confirmation

Vulnerebility

Oracle Java SE CVE-2019-2426 Information Disclosure Vulnerability
2019-03-22
http://www.securityfocus.com/bid/106590

IBM Java SDK CVE-2018-1890 Local Privilege Escalation Vulnerability
2019-03-22
http://www.securityfocus.com/bid/107448

QEMU CVE-2019-8934 Local Information Disclosure Vulnerability
2019-03-22
http://www.securityfocus.com/bid/107115

PuTTY Multiple Security Vulnerabilities
2019-03-22
http://www.securityfocus.com/bid/107484

Cloud Foundry Cloud Controller API CVE-2017-8037 Incomplete Fix Information Disclosure Vulnerability
2019-03-22
http://www.securityfocus.com/bid/100448

Opencontainers runc CVE-2019-5736 Local Command Execution Vulnerability
2019-03-22
http://www.securityfocus.com/bid/106976

Mozilla Firefox Unspecified Remote Code Execution Vulnerability
2019-03-22
http://www.securityfocus.com/bid/107534

Mozilla Firefox Unspecified Remote Code Execution Vulnerability
2019-03-22
http://www.securityfocus.com/bid/107533

Microsoft Edge Unspecified Security Bypass Vulnerability
2019-03-22
http://www.securityfocus.com/bid/107532

Ghostscript CVE-2019-3838 Security Bypass Vulnerability
2019-03-22
http://www.securityfocus.com/bid/107520

Atlassian SourceTree CVE-2018-20235 Arbitrary Code Execution Vulnerability
2019-03-21
http://www.securityfocus.com/bid/107407

Atlassian SourceTree CVE-2018-20234 Arbitrary Code Execution Vulnerability
2019-03-21
http://www.securityfocus.com/bid/107414

Red Hat JBoss BPMS CVE-2016-6343 Cross Site Scripting Vulnerability
2019-03-21
http://www.securityfocus.com/bid/96987

Exploint

Meeplace Business Review Script - 'id' SQL Injection

Matri4Web Matrimony Website Script - Multiple SQL Injection

21.3.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Red Hat JBoss BPMS CVE-2016-6343 Cross Site Scripting Vulnerability
2019-03-21
http://www.securityfocus.com/bid/96987

Mozilla Firefox MFSA2019-01 Multiple Security Vulnerabilities
2019-03-20
http://www.securityfocus.com/bid/106773

Gemalto Sentinel UltraPro ICSA-19-073-02 Security Vulnerability
2019-03-20
http://www.securityfocus.com/bid/107415

Cisco IP Phone 7800 Series and 8800 Series CVE-2019-1716 Remote Code Execution Vulnerability
2019-03-20
http://www.securityfocus.com/bid/107503

Cisco IP Phone 8800 Series CVE-2019-1764 Cross Site Request Forgery Vulnerability
2019-03-20
http://www.securityfocus.com/bid/107502

Cisco IP Phone 8800 Series CVE-2019-1765 Path Traversal Arbitrary File Write Vulnerability
2019-03-20
http://www.securityfocus.com/bid/107500

Cisco IP Phone 8800 Series CVE-2019-1763 Unauthorized Access Vulnerability
2019-03-20
http://www.securityfocus.com/bid/107499

Cisco IP Phone 8800 Series CVE-2019-1766 Denial of Service Vulnerability
2019-03-20
http://www.securityfocus.com/bid/107498

Exploint

Bootstrapy CMS - Multiple SQL Injection

Canarytokens 2019-03-01 - Detection Bypass

Placeto CMS Alpha v4 - 'page' SQL Injection

uHotelBooking System - 'system_page' SQL Injection

The Company Business Website CMS - Multiple Vulnerabilities

Rails 5.2.1 - Arbitrary File Content Disclosure

DVD X Player 5.5.3 - '.plf' Buffer Overflow

Netartmedia Vlog System - 'email' SQL Injection

20.3.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Mozilla Firefox MFSA2019-01 Multiple Security Vulnerabilities
2019-03-20
http://www.securityfocus.com/bid/106773

Gemalto Sentinel UltraPro ICSA-19-073-02 Security Vulnerability
2019-03-20
http://www.securityfocus.com/bid/107415

Oracle PeopleSoft Enterprise PeopleTools Multiple Remote Security Vulnerabilities
2019-03-19
http://www.securityfocus.com/bid/106592

Oracle E-Business Suite Cpujan2019 Multiple Security Vulnerabilities
2019-03-19
http://www.securityfocus.com/bid/106620

Oracle Web Cache CVE-2019-2438 Remote Security Vulnerability
2019-03-19
http://www.securityfocus.com/bid/106612

Oracle Java SE/Java SE Embedded/JRockit CVE-2018-3180 Remote Security Vulnerability
2019-03-19
http://www.securityfocus.com/bid/105617

Exploint

PLC Wireless Router GPN2.4P21-C-CN - Cross-Site Request Forgery

PLC Wireless Router GPN2.4P21-C-CN - Incorrect Access Control

202CMS v10beta - Multiple SQL Injection

NetShareWatcher 1.5.8.0 - Local SEH Buffer Overflow

Netartmedia PHP Business Directory 4.2 - SQL Injection

Netartmedia PHP Dating Site - SQL Injection

Netartmedia Jobs Portal 6.1 - SQL Injection

Netartmedia PHP Real Estate Agency 4.0 - SQL Injection

Netartmedia PHP Car Dealer - SQL Injection

19.3.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Oracle PeopleSoft Enterprise PeopleTools Multiple Remote Security Vulnerabilities
2019-03-19
http://www.securityfocus.com/bid/106592

Oracle E-Business Suite Cpujan2019 Multiple Security Vulnerabilities
2019-03-19
http://www.securityfocus.com/bid/106620

Oracle Web Cache CVE-2019-2438 Remote Security Vulnerability
2019-03-19
http://www.securityfocus.com/bid/106612

Oracle Java SE/Java SE Embedded/JRockit CVE-2018-3180 Remote Security Vulnerability
2019-03-19
http://www.securityfocus.com/bid/105617

PHP Information Disclosure and Heap Buffer Overflow Vulnerabilities
2019-03-18
http://www.securityfocus.com/bid/107156

Exploint

Microsoft Edge - Flash click2play Bypass with CObjectElement::FinalCreateObject

Microsoft VBScript - VbsErase Memory Corruption

Microsoft Internet Explorer 11 - VBScript Execution Policy Bypass in MSHTML

Google Chrome < M73 - FileSystemOperationRunner Use-After-Free

Google Chrome < M73 - MidiManagerWin Use-After-Free

Google Chrome < M73 - Data Race in ExtensionsGuestViewMessageFilter

Google Chrome < M73 - Double-Destruction Race in StoragePartitionService

Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming RCE (Metasploit)

libseccomp < 2.4.0 - Incorrect Compilation of Arithmetic Comparisons

Netartmedia Real Estate Portal 5.0 - SQL Injection

Netartmedia PHP Mall 4.1 - SQL Injection

Advanced Host Monitor 11.92 beta - Local Buffer Overflow

Netartmedia Event Portal 2.0 - 'Email' SQL Injection

eNdonesia Portal 8.7 - Multiple Vulnerabilities

MyBB Upcoming Events Plugin 1.32 - Cross-Site Scripting

Gila CMS 1.9.1 - Cross-Site Scripting

18.3.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

PHP Information Disclosure and Heap Buffer Overflow Vulnerabilities
2019-03-18
http://www.securityfocus.com/bid/107156

RSA Archer GRC Platform CVE-2019-3716 Local Information Disclosure Vulnerability
2019-03-18
http://www.securityfocus.com/bid/107406

Microsoft Azure Linux Guest Agent CVE-2019-0804 Local Information Disclosure Vulnerability
2019-03-18
http://www.securityfocus.com/bid/107410

IBM Spectrum Scale CVE-2018-1723 Information Disclosure Vulnerability
2019-03-18
http://www.securityfocus.com/bid/105975

Eclipse OpenJ9 CVE-2018-12539 Multiple Privilege Escalation Vulnerabilities
2019-03-18
http://www.securityfocus.com/bid/105126

Oracle Java SE CVE-2018-2973 Remote Security Vulnerability
2019-03-18
http://www.securityfocus.com/bid/104773

IBM Java SDK CVE-2018-1656 Directory Traversal Vulnerability
2019-03-18
http://www.securityfocus.com/bid/105118

Django CVE-2019-6975 Denial of Service Vulnerability
2019-03-18
http://www.securityfocus.com/bid/106964

Exploint

BMC Patrol Agent - Privilege Escalation Cmd Execution (Metasploit)

TheCarProject v2 - Multiple SQL Injection

WinAVI iPod/3GP/MP4/PSP Converter 4.4.2 - Denial of Service

WinMPG Video Convert 9.3.5 - Denial of Service

17.3.2019

Bugtraq

 

Malware

 

Phishing

Amazon Order

16th March 2019

Amazon Order Confirmation

Vulnerebility

 

Exploint

WinRAR 5.61 - Path Traversal

15.3.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Microsoft Windows Win32k CVE-2019-0808 Local Privilege Escalation Vulnerability
2019-03-15
http://www.securityfocus.com/bid/107331

Google Chrome Prior to 73.0.3683.75 Multiple Security Vulnerabilities
2019-03-15
http://www.securityfocus.com/bid/107363

Oracle Java SE CVE-2019-2422 Information Disclosure Vulnerability
2019-03-14
http://www.securityfocus.com/bid/106596

Exploint

Moodle 3.4.1 - Remote Code Execution

Laundry CMS - Multiple Vulnerabilities

Vembu Storegrid Web Interface 4.4.0 - Multiple Vulnerabilities

ICE HRM 23.0 - Multiple Vulnerabilities

Mail Carrier 2.5.1 - 'MAIL FROM' Buffer Overflow

CMS Made Simple Showtime2 Module 3.6.2 - Authenticated Arbitrary File Upload

NetData 1.13.0 - HTML Injection

14.3.2019

Bugtraq

 

Malware

Backdoor.Filensfer

Backdoor.Fakeslic

Phishing

 

Vulnerebility

Google Chrome Prior to 73.0.3683.75 Multiple Security Vulnerabilities
2019-03-15
http://www.securityfocus.com/bid/107363

Oracle Java SE CVE-2019-2422 Information Disclosure Vulnerability
2019-03-14
http://www.securityfocus.com/bid/106596

Oracle Java SE CVE-2019-2449 Remote Security Vulnerability
2019-03-14
http://www.securityfocus.com/bid/106597

Oracle Java SE CVE-2019-2426 Information Disclosure Vulnerability
2019-03-14
http://www.securityfocus.com/bid/106590

Exploint

Apache UNO / LibreOffice Version: 6.1.2 / OpenOffice 4.1.6 API - Remote Code Execution

FTPGetter Standard 5.97.0.177 - Remote Code Execution

Pegasus CMS 1.0 - 'extra_fields.php' Plugin Remote Code Execution

Intel Modular Server System 10.18 - Cross-Site Request Forgery (Change Admin Password)

13.3.2019

Bugtraq

 

Malware

Exp.CVE-2019-0808

Exp.CVE-2019-0797

W32.Extrat.C

Phishing

 

Vulnerebility

Google Chrome CVE-2019-5786 'FileReader' Use After Free Arbitrary Code Execution Vulnerability
2019-03-13
http://www.securityfocus.com/bid/107213

Wibu Systems WibuKey DRM Multiple Input Validation Vulnerabilities
2019-03-13
http://www.securityfocus.com/bid/107005

Microsoft NuGet Package Manager CVE-2019-0757 Tampering Security Bypass Vulnerability
2019-03-13
http://www.securityfocus.com/bid/107285

SAP BusinessObjects Business Intelligence CVE-2019-0268 XML External Entity Injection Vulnerability
2019-03-13
http://www.securityfocus.com/bid/107364

Vixie Cron CVE-2019-9705 Denial of Service Vulnerability
2019-03-13
http://www.securityfocus.com/bid/107378

Exploint

Microsoft Windows - .reg File / Dialog Box Message Spoofing

Microsoft Windows MSHTML Engine - "Edit" Remote Code Execution

Apache Tika-server < 1.18 - Command Injection

Core FTP Server FTP / SFTP Server v2 Build 674 - 'MDTM' Directory Traversal

Core FTP Server FTP / SFTP Server v2 Build 674 - 'SIZE' Directory Traversal

WordPress Plugin GraceMedia Media Player 1.0 - Local File Inclusion

pfSense 2.4.4-p1 (HAProxy Package 0.59_14) - Persistent Cross-Site Scripting

elFinder PHP Connector < 2.1.48 - exiftran Command Injection (Metasploit)

12.3.2019

Bugtraq

 

Malware

Backdoor.Sarhus

Backdoor.Xoratag

Phishing

 

Vulnerebility

SAP Business Client Unspecified Security Vulnerability
2019-03-12
http://www.securityfocus.com/bid/104436

SAP Enterprise Financial Services CVE-2018-2484 Remote Authorization Bypass Vulnerability
2019-03-12
http://www.securityfocus.com/bid/106477

SAP NetWeaver Java AS CVE-2019-0275 Cross Site Scripting Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107362

SAP Work and Inventory Manager CVE-2019-0274 Denial of Service Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107360

SAP BusinessObjects Business Intelligence Platform CVE-2019-0269 Cross Site Scripting Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107359

Adobe Photoshop CC CVE-2019-7094 Arbitrary Code Execution Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107357

SAP HANA Extended Application Services CVE-2019-0277 XML External Entity Injection Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107356

SAP Netweaver ABAP Server CVE-2019-0271 XML External Entity Injection Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107355

Adobe Digital Editions CVE-2019-7095 Unspecified Heap Buffer Overflow Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107354

Multiple SAP Products CVE-2019-0276 Remote Authorization Bypass Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107353

Microsoft Windows Win32k CVE-2019-0808 Local Privilege Escalation Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107331

Microsoft Windows Win32k CVE-2019-0797 Local Privilege Escalation Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107330

Microsoft Windows GDI Component CVE-2019-0614 Information Disclosure Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107250

Microsoft Windows VBScript Engine CVE-2019-0772 Remote Code Execution Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107239

Microsoft Windows DHCP Client CVE-2019-0726 Remote Code Execution Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107236

Microsoft Windows DHCP Client CVE-2019-0698 Remote Code Execution Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107235

Microsoft Windows Deployment Services TFTP Server CVE-2019-0603 Remote Code Execution Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107229

Microsoft Office SharePoint CVE-2019-0778 Cross Site Scripting Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107226

Microsoft Windows Subsystem for Linux CVE-2019-0682 Local Privilege Escalation Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107225

Microsoft Office Access Connectivity Engine CVE-2019-0748 Remote Code Execution Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107224

Microsoft Windows ActiveX CVE-2019-0784 Remote Code Execution Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107222

Microsoft Windows DHCP Client CVE-2019-0697 Remote Code Execution Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107221

Microsoft Windows Kernel CVE-2019-0755 Local Information Disclosure Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107194

Microsoft Windows Kernel CVE-2019-0702 Local Information Disclosure Vulnerability
2019-03-12
http://www.securityfocus.com/bid/107193

Google Chrome CVE-2019-5786 'FileReader' Use After Free Arbitrary Code Execution Vulnerability
2019-03-07
http://www.securityfocus.com/bid/107213

Exploint

Core FTP 2.0 build 653 - 'PBSZ' Denial of Service (PoC)

PilusCart 1.4.1 - Cross-Site Request Forgery (Add Admin)

11.3.2019

Bugtraq

 

Malware

 

Phishing

Amazon Order

11th March 2019

Amazon Order Confirmation

Vulnerebility

 

Exploint

OpenKM 6.3.2 < 6.3.7 - Remote Command Execution (Metasploit)

Liferay CE Portal < 7.1.2 ga3 - Remote Command Execution (Metasploit)

NetSetMan 4.7.1 - Local Buffer Overflow (SEH Unicode)

Linux Kernel 4.4 (Ubuntu 16.04) - 'snd_timer_user_ccallback()' Kernel Pointer Leak

Flexpaper PHP Publish Service 2.3.6 - Remote Code Execution

PRTG Network Monitor 18.2.38 - Authenticated Remote Code Execution

10.3.2019

Bugtraq

 

Malware

Trojan.Bitartra

Phishing

AOL Member Service

8th March 2019

AOL Account Notification
Regarding AOL Oath.

Vulnerebility

 

Exploint

DirectAdmin 1.55 - 'CMD_ACCOUNT_ADMIN' Cross-Site Request Forgery

McAfee ePO 5.9.1 - Registered Executable Local Access Bypass

OrientDB 3.0.17 GA Community Edition - Cross-Site Request Forgery / Cross-Site Scripting

8.3.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

 

Exploint

Drupal < 8.5.11 / < 8.6.10 - RESTful Web Services unserialize() Remote Command Execution (Metasploit)

Imperva SecureSphere 13.x - 'PWS' Command Injection (Metasploit)

FreeBSD - Intel SYSRET Privilege Escalation (Metasploit)

Anyburn 4.3 x86 - 'Copy disc to image file' Buffer Overflow (Unicode) (SEH)

QNAP TS-431 QTS < 4.2.2 - Remote Command Execution (Metasploit)

Kados R10 GreenBee - Multiple SQL Injection

7.3.2019

Bugtraq

 

Malware

Win32/Filecoder.LockedFile.I

Phishing

 

Vulnerebility

Google Chrome CVE-2019-5786 'FileReader' Use After Free Arbitrary Code Execution Vulnerability
2019-03-07
http://www.securityfocus.com/bid/107213

Linux kernel CVE-2019-7221 Local Denial of Service Vulnerability
2019-03-07
http://www.securityfocus.com/bid/107294

Linux kernel CVE-2019-9213 Local Denial of Service Vulnerability
2019-03-06
http://www.securityfocus.com/bid/107296

Exploint

 

6.3.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

RSLinx Classic CVE-2019-6553 Stack Buffer Overflow Vulnerability
2019-03-05
http://www.securityfocus.com/bid/107293

Exploint

Android - getpidcon() Usage in Hardware binder ServiceManager Permits ACL Bypass

Android - binder Use-After-Free via racy Initialization of ->allow_user_free

Linux < 4.20.14 - Virtual Address 0 is Mappable via Privileged write() to /proc/*/mem

5.3.2019

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

OpenDocMan 1.3.4 - 'search.php where' SQL Injection

Exploint

 

4.3.2019

Bugtraq

 

Malware

 

Phishing

ExxonMobil Smart Card

3rd March 2019

Get 12 cents off* every gallon
at 11,000+ Exxon & Mobil
stations

Vulnerebility

Multiple Cisco Products CVE-2019-1674 Local Command Injection Vulnerability
2019-03-04
http://www.securityfocus.com/bid/107184

Microsoft Teams CVE-2019-5922 DLL Loading Remote Code Execution Vulnerability
2019-03-04
http://www.securityfocus.com/bid/107200

Microsoft Windows CVE-2019-5921 DLL Loading Remote Code Execution Vulnerability
2019-03-04
http://www.securityfocus.com/bid/107218

EMC RSA Authentication Manager CVE-2019-3711 Information Disclosure Vulnerability
2019-03-03
http://www.securityfocus.com/bid/107210

Exploint

Microsoft Edge Chakra 1.11.4 - Read Permission via Type Confusion

Fiberhome AN5506-04-F RP2669 - Persistent Cross-Site Scripting

WordPress Plugin Cerber Security, Antispam & Malware Scan 8.0 - Multiple Bypass Vulnerabilities

Craft CMS 3.1.12 Pro - Cross-Site Scripting

Bolt CMS 3.6.4 - Cross-Site Scripting

MarcomCentral FusionPro VDP Creator < 10.0 - Directory Traversal

Raisecom XPON ISCOMHT803G-U_2.0.0_140521_R4.1.47.002 - Remote Code Execution

zzzphp CMS 1.6.1 - Cross-Site Request Forgery

Splunk Enterprise 7.2.4 - Custom App RCE (Persistent Backdoor - Custom Binary Payload)

Booked Scheduler 2.7.5 - Remote Command Execution (Metasploit)

FileZilla 3.40.0 - 'Local search' / 'Local site' Denial of Service (PoC)

OOP CMS BLOG 1.0 - Multiple Cross-Site Request Forgery

OOP CMS BLOG 1.0 - Multiple SQL Injection

elFinder 2.1.47 - Command Injection vulnerability in the PHP connector

CMSsite 1.0 - Multiple Cross-Site Request Forgery

1.3.2019

Bugtraq

 

Malware

Exp.CVE-2018-20250

Phishing

 

Vulnerebility

Juniper Junos CVE-2017-2303 Denial of Service Vulnerability
2019-03-01
http://www.securityfocus.com/bid/95408

Mozilla Firefox CVE-2018-18511 Information Disclosure Vulnerability
2019-03-01
http://www.securityfocus.com/bid/107009

Multiple PSI GridConnect GmbH Products CVE-2019-6528 Cross Site Scripting Vulnerability
2019-02-28
http://www.securityfocus.com/bid/107201

Exploint

macOS XNU - Copy-on-Write Behavior Bypass via Mount of User-Owned Filesystem Image

Linux < 4.14.103 / < 4.19.25 - Out-of-Bounds Read and Write in SNMP NAT Module

tcpdump < 4.9.3 - Multiple Heap-Based Out-of-Bounds Reads

Google Chrome < M72 - FileWriterImpl Use-After-Free

Google Chrome < M72 - Use-After-Free in RenderProcessHostImpl Binding for P2PSocketDispatcherHost

Google Chrome < M72 - RenderFrameHostImpl::CreateMediaStreamDispatcherHost Use-After-Free

Google Chrome < M72 - PaymentRequest Service Use-After-Free

28.2.2019

Bugtraq

 

Malware

 

Phishing

Wells Fargo Online

28th February 2019

Your Account Security
Notification

Vulnerebility

Google Chrome PDF File Handling Information Disclosure Vulnerability
2019-02-28
http://www.securityfocus.com/bid/107182

GNU wget CVE-2018-20483 Local Information Disclosure Vulnerability
2019-02-27
http://www.securityfocus.com/bid/106358

Tcpdump CVE-2018-19519 Stack Based Buffer Overflow Vulnerability
2019-02-27
http://www.securityfocus.com/bid/106098

Multiple Cisco Products CVE-2019-1674 Local Command Injection Vulnerability
2019-02-27
http://www.securityfocus.com/bid/107184

Exploint

Feng Office 3.7.0.5 - Remote Command Execution (Metasploit)

TransMac 12.3 - Denial of Service (PoC)

Usermin 1.750 - Remote Command Execution (Metasploit)

Joomla! Component J2Store < 3.3.7 - SQL Injection

Joomla! Component J2Store < 3.3.7 - SQL Injection

FTP Server 1.32 - Denial of Service

Simple Online Hotel Reservation System - Cross-Site Request Forgery (Delete Admin)

Simple Online Hotel Reservation System - Cross-Site Request Forgery (Add Admin)

Simple Online Hotel Reservation System - SQL Injection