Databáze Hot News - Rok - Úvod  2018  2017  2016  2015  2014  2013  - 1  2  3  4  5  6  7  8  9  10  11  12  13  14  15  List  - 2018  2017  2016  2015  2014  2013 
Poslední aktualizace v 08.10.2016 14:19:38
 

4.8.2017

Bugtraq

SEC Consult SA-20170804-1 :: Ubiquiti Networks UniFi Cloud Key authenticated command injection 2017-08-04
SEC Consult Vulnerability Lab (research sec-consult com)

SEC Consult SA-20170804-0 :: phpBB Server Side Request Forgery (SSRF) vulnerability 2017-08-04
SEC Consult Vulnerability Lab (research sec-consult com)

security bulletin] HPESB3P03767 rev.1 - HPE Proliant ML10 Gen9 servers using Intel Xeon E3-1200M v5 and 6th Generation Intel Core Processors, Unauthorized Write to Filesystem 2017-08-04
security-alert hpe com

SECURITY] DSA 3924-1] varnish security update 2017-08-02
Salvatore Bonaccorso (carnil debian org)

slackware-security] gnupg (SSA:2017-213-01) 2017-08-02
Slackware Security Team (security slackware com)

Malware

 

Phishing

 

Vulnerebility

Oracle Java SE CVE-2013-0425 Remote Java Runtime Environment Vulnerability
2017-08-04
http://www.securityfocus.com/bid/57709

Microsoft Windows LNK CVE-2017-8464 Remote Code Execution Vulnerability
2017-08-04
http://www.securityfocus.com/bid/98818

Apache HTTP Server CVE-2017-3169 Denial of Service Vulnerability
2017-08-04
http://www.securityfocus.com/bid/99134

Apache HTTP Server CVE-2017-7679 Buffer Overflow Vulnerability
2017-08-04
http://www.securityfocus.com/bid/99170

Apache HTTP Server CVE-2017-3167 Authentication Bypass Vulnerability
2017-08-04
http://www.securityfocus.com/bid/99135

Apache HTTP Server CVE-2017-7668 Denial of Service Vulnerability
2017-08-04
http://www.securityfocus.com/bid/99137

Oracle Java SE CVE-2013-0419 Java Runtime Environment Remote Security Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57714

Oracle Java SE CVE-2012-5075 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/56081

Apache FOP CVE-2017-5661 XML External Entity Information Disclosure Vulnerability
2017-08-03
http://www.securityfocus.com/bid/97947

Google Android Broadcom components Multiple Security Vulnerabilities
2017-08-03
http://www.securityfocus.com/bid/99482

Oracle Java SE CVE-2013-0432 Java Runtime Environment Remote Security Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57727

Oracle Java SE CVE-2013-0430 Java Runtime Environment Remote Security Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57722

Oracle Java SE CVE-2012-1721 Remote Code Execution Vulnerability
2017-08-03
http://www.securityfocus.com/bid/53959

Oracle Java SE CVE-2012-0497 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/52009

Linux Kernel CVE-2017-6214 Remote Denial of Service Vulnerability
2017-08-03
http://www.securityfocus.com/bid/96421

Linux Kernel CVE-2017-7187 Local Denial of Service Vulnerability
2017-08-03
http://www.securityfocus.com/bid/96989

Oracle Java SE CVE-2011-3552 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/50248

Oracle Java SE CVE-2012-0504 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/52020

Oracle Java SE CVE-2013-0429 Remote Java Runtime Environment Remote Security Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57710

Oracle Java SE CVE-2013-0426 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57711

Oracle Java SE CVE-2013-0423 Java Runtime Environment Remote Security Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57716

Oracle Java SE CVE-2013-0427 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57724

Oracle Java SE CVE-2013-0428 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57713

Oracle Java SE CVE-2013-0424 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57715

Oracle Java SE CVE-2013-0409 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57728

Oracle Java SE CVE-2012-5085 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/56067

Oracle Java SE CVE-2012-5084 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/56063

Oracle Java SE CVE-2013-0351 Java Runtime Environment Remote Security Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57720

Google Web Toolkit CVE-2012-5920 Cross Site Scripting Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57538

Oracle Java SE CVE-2012-5086 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/56039

SANS News

 

Threatpost

Two Popular IP Cameras Riddled With Vulnerabilities

Cisco Fixes DoS, Authentication Bypass Vulnerabilities, OSPF Bug

Exploit

 

3.8.2017

Bugtraq

 

Malware

W32.Emotet.B

Phishing

 

Vulnerebility

Apache FOP CVE-2017-5661 XML External Entity Information Disclosure Vulnerability
2017-08-03
http://www.securityfocus.com/bid/97947

Google Android Broadcom components Multiple Security Vulnerabilities
2017-08-03
http://www.securityfocus.com/bid/99482

Oracle Java SE CVE-2013-0432 Java Runtime Environment Remote Security Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57727

Oracle Java SE CVE-2013-0430 Java Runtime Environment Remote Security Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57722

Oracle Java SE CVE-2012-1721 Remote Code Execution Vulnerability
2017-08-03
http://www.securityfocus.com/bid/53959

Oracle Java SE CVE-2012-0497 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/52009

Linux Kernel CVE-2017-6214 Remote Denial of Service Vulnerability
2017-08-03
http://www.securityfocus.com/bid/96421

Linux Kernel CVE-2017-7187 Local Denial of Service Vulnerability
2017-08-03
http://www.securityfocus.com/bid/96989

Oracle Java SE CVE-2011-3552 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/50248

Oracle Java SE CVE-2012-0504 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/52020

Oracle Java SE CVE-2013-0429 Remote Java Runtime Environment Remote Security Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57710

Oracle Java SE CVE-2013-0426 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57711

Oracle Java SE CVE-2013-0423 Java Runtime Environment Remote Security Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57716

Oracle Java SE CVE-2013-0427 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57724

Oracle Java SE CVE-2013-0428 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57713

Oracle Java SE CVE-2013-0424 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57715

Oracle Java SE CVE-2013-0409 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57728

Oracle Java SE CVE-2012-5085 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/56067

Oracle Java SE CVE-2012-5084 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/56063

Oracle Java SE CVE-2013-0351 Java Runtime Environment Remote Security Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57720

Google Web Toolkit CVE-2012-5920 Cross Site Scripting Vulnerability
2017-08-03
http://www.securityfocus.com/bid/57538

Oracle Java SE CVE-2012-5086 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/56039

Oracle Java SE CVE-2012-5083 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/56025

Oracle Java SE CVE-2012-5089 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/56059

Oracle Java SE CVE-2012-5079 Remote Security Bypass Vulnerability
2017-08-03
http://www.securityfocus.com/bid/56082

Oracle Java Runtime Environment Remote Code Execution Vulnerability
2017-08-03
http://www.securityfocus.com/bid/55213

Oracle Java SE CVE-2012-5072 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/56083

Oracle Java SE CVE-2012-5069 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/56065

Oracle Java SE CVE-2012-5081 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/56071

Oracle Java SE CVE-2012-5077 Remote Java Runtime Environment Vulnerability
2017-08-03
http://www.securityfocus.com/bid/56058

SANS News

Using a Raspberry Pi honeypot to contribute data to DShield/ISC

Threatpost

IBM Patches Reflected XSS in Worklight, MobileFirst

Exploit

Solarwinds Kiwi Syslog 9.6.1.6 - Denial of Service

Premium Servers List Tracker 1.0 - SQL Injection

EDUMOD Pro 1.3 - SQL Injection

Muviko 1.0 - 'q' Parameter SQL Injection

VirtualBox 5.1.22 - Windows Process DLL Signature Bypass Privilege Escalation

VirtualBox 5.1.22 - Windows Process DLL UNC Path Signature Bypass Privilege...

2.8.2017

Bugtraq

slackware-security] gnupg (SSA:2017-213-01) 2017-08-02
Slackware Security Team (security slackware com)

CVE-2017-1500 - Relected XSS in IBM WorkLight OAuth Server Web Api 2017-08-02
gabriele gristina gmail com

security bulletin] HPESBHF03763 rev.1 - HPE Comware 7, IMC, VCX products using OpenSSL, Remote Denial of Service (DoS) 2017-08-01
security-alert hpe com

security bulletin] HPESBGN03766 rev.1 - HPE Project and Portfolio Management (PPM), Remote Cross-Site Scripting 2017-08-01
security-alert hpe com

CVE-2017-11494] SOL.Connect ISET-mpp meter 1.2.4.2 Authentication Bypass SQL Injection Vulnerability 2017-08-01
andys3c gmail com

SECURITY] DSA 3923-1] freerdp security update 2017-08-01
Sebastien Delafond (seb debian org)

FortiOS <= 5.6.0 Multiple XSS Vulnerabilities 2017-07-28
msg patrykbogdan com

Malware

 

Phishing

Apple Purchase

1st August 2017

If you did not make this
purchase.

National

31st July 2017

Notification : Update your
account to get back to
watching.

Vulnerebility

Pivotal RabbitMQ Products CVE-2016-9877 Authentication Bypass Vulnerability
2017-08-02
http://www.securityfocus.com/bid/95065

Apache ActiveMQ Artemis CVE-2016-4978 Remote Code Execution Vulnerability
2017-08-02
http://www.securityfocus.com/bid/93142

FasterXML Jackson-databind CVE-2017-7525 Deserialization Remote Code Execution Vulnerability
2017-08-02
http://www.securityfocus.com/bid/99623

Linux kernel CVE-2017-9242 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/98731

Linux Kernel CVE-2017-8890 Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/98562

Linux kernel CVE-2017-9076 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/98586

Linux kernel CVE-2017-9074 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/98577

Linux kernel CVE-2017-9075 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/98597

Linux Kernel CVE-2017-9150 Local Information Disclosure Vulnerability
2017-08-01
http://www.securityfocus.com/bid/98635

Linux Kernel CVE-2017-7618 Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/97534

Linux Kernel CVE-2017-7374 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/97308

Linux kernel CVE-2017-2671 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/97407

Linux kernel 'net/ipx/af_ipx.c' Use After Free Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/98439

Linux Kernel CVE-2017-7616 Multiple Local Information Disclosure Vulnerabilities
2017-08-01
http://www.securityfocus.com/bid/97527

Linux Kernel CVE-2017-7346 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/97257

Linux Kernel CVE-2017-7294 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/97177

Linux Kernel CVE-2017-7184 Local Privilege Escalation Vulnerability
2017-08-01
http://www.securityfocus.com/bid/97018

Linux kernel CVE-2017-7308 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/97234

Linux Kernel CVE-2017-7261 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/97096

Linux kernel 'ip_sockglue.c' Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/96233

Linux kernel CVE-2017-6345 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/96510

Linux Kernel CVE-2017-6347 Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/96487

Linux kernel CVE-2017-6346 Use After Free Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/96508

Linux Kernel CVE-2017-6353 Incomplete Fix Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/96473

Linux Kernel CVE-2017-2636 Local Privilege Escalation Vulnerability
2017-08-01
http://www.securityfocus.com/bid/96732

Linux kernel CVE-2017-9077 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/98583

Linux Kernel Multiple Local Memory Corruption Vulnerabilities
2017-08-01
http://www.securityfocus.com/bid/91451

Linux Kernel CVE-2017-2584 Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/95430

Linux Kernel CVE-2017-2596 Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/95878

Linux Kernel CVE-2016-9191 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/94129

SANS News

Attacking NoSQL applications (part 2)

Threatpost

Amazon Halts Sale of Android Blu Phone Amid Spyware Concerns

Legislation Proposed to Secure Connected IoT Devices

Exploit

iOS/macOS - xpc_data Objects Sandbox Escape Privelege Escalation

SOL.Connect ISET-mpp meter 1.2.4.2 - SQL Injection

Entrepreneur B2B Script - 'pid' Parameter SQL Injection

Joomla! Component SIMGenealogy 2.1.5 - SQL Injection

Joomla! Component PHP-Bridge 1.2.3 - SQL Injection

Joomla! Component LMS King Professional 3.2.4.0 - SQL Injection

Joomla! Component Event Registration Pro Calendar 4.1.3 - SQL Injection

Joomla! Component Ultimate Property Listing 1.0.2 - SQL Injection

Advantech SUSIAccess <= 3.0 - Directory Traversal / Information Disclosure...

1.8.2017

Bugtraq

CVE-2017-11494] SOL.Connect ISET-mpp meter 1.2.4.2 Authentication Bypass SQL Injection Vulnerability 2017-08-01
andys3c gmail com

SECURITY] DSA 3923-1] freerdp security update 2017-08-01
Sebastien Delafond (seb debian org)

FortiOS <= 5.6.0 Multiple XSS Vulnerabilities 2017-07-28
msg patrykbogdan com

security bulletin] HPESBHF03765 rev.1 - HPE ConvergedSystem 700 Solution with Comware v7 Switches using OpenSSL, Remote Denial of Service (DoS) and Disclosure of Sensitive Information 2017-07-26
HPE Product Security Response Team (security-alert hpe com)

SECURITY] DSA 3919-1] openjdk-8 security update 2017-07-25
Moritz Muehlenhoff (jmm debian org)

Malware

 

Phishing

National

31st July 2017

Notification : Update your
account to get back to
watching.

Vulnerebility

Linux kernel CVE-2017-9242 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/98731

Linux Kernel CVE-2017-8890 Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/98562

Linux kernel CVE-2017-9076 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/98586

Linux kernel CVE-2017-9074 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/98577

Linux kernel CVE-2017-9075 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/98597

Linux Kernel CVE-2017-9150 Local Information Disclosure Vulnerability
2017-08-01
http://www.securityfocus.com/bid/98635

Linux Kernel CVE-2017-7618 Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/97534

Linux Kernel CVE-2017-7374 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/97308

Linux kernel CVE-2017-2671 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/97407

Linux kernel 'net/ipx/af_ipx.c' Use After Free Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/98439

Linux Kernel CVE-2017-7616 Multiple Local Information Disclosure Vulnerabilities
2017-08-01
http://www.securityfocus.com/bid/97527

Linux Kernel CVE-2017-7346 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/97257

Linux Kernel CVE-2017-7294 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/97177

Linux Kernel CVE-2017-7184 Local Privilege Escalation Vulnerability
2017-08-01
http://www.securityfocus.com/bid/97018

Linux kernel CVE-2017-7308 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/97234

Linux Kernel CVE-2017-7261 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/97096

Linux kernel 'ip_sockglue.c' Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/96233

Linux kernel CVE-2017-6345 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/96510

Linux Kernel CVE-2017-6347 Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/96487

Linux kernel CVE-2017-6346 Use After Free Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/96508

Linux Kernel CVE-2017-6353 Incomplete Fix Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/96473

Linux Kernel CVE-2017-2636 Local Privilege Escalation Vulnerability
2017-08-01
http://www.securityfocus.com/bid/96732

Linux kernel CVE-2017-9077 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/98583

Linux Kernel Multiple Local Memory Corruption Vulnerabilities
2017-08-01
http://www.securityfocus.com/bid/91451

Linux Kernel CVE-2017-2584 Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/95430

Linux Kernel CVE-2017-2596 Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/95878

Linux Kernel CVE-2016-9191 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/94129

Linux Kernel CVE-2016-2117 Remote Buffer Overflow Vulnerability
2017-08-01
http://www.securityfocus.com/bid/84500

Linux Kernel CVE-2017-5551 Local Denial of Service Vulnerability
2017-08-01
http://www.securityfocus.com/bid/95717

Linux Kernel CVE-2017-5577 Remote Buffer Overflow Vulnerability
2017-08-01
http://www.securityfocus.com/bid/95765

SANS News

Rooting Out Hosts that Support Older Samba Versions

Threatpost

Android Banking Trojan Svpeng Adds Keylogger

ShieldFS Can Detect Ransomware, Recover Files

Exploit

Advantech SUSIAccess <= 3.0 - Directory Traversal / Information Disclosure...

Advantech SUSIAccess <= 3.0 - 'RecoveryMgmt' File Upload

DivFix++ 0.34 - Denial of Service

Vorbis Tools oggenc 1.4.0 - '.wav' Denial of Service

Sound eXchange (SoX) 14.4.2 - Multiple Vulnerabilities

libvorbis 1.3.5 - Multiple Vulnerabilities

libao 1.2.0 - Denial of Service

31.7.2017

Bugtraq

 

Malware

Trojan.Ismagent
Trojan.Karagany.B

Trojan.Heriplor

Phishing

 

Vulnerebility

Oracle MySQL Server CVE-2017-3653 Remote Security Vulnerability
2017-07-31
http://www.securityfocus.com/bid/99810

Oracle MySQL Server CVE-2017-3641 Remote Security Vulnerability
2017-07-31
http://www.securityfocus.com/bid/99767

Oracle MySQL Connectors/MySQL Server CVE-2017-3635 Remote Security Vulnerability
2017-07-31
http://www.securityfocus.com/bid/99730

Oracle MySQL Server CVE-2017-3652 Remote Security Vulnerability
2017-07-31
http://www.securityfocus.com/bid/99805

Oracle MySQL Server CVE-2017-3636 Local Security Vulnerability
2017-07-31
http://www.securityfocus.com/bid/99736

Oracle MySQL Server CVE-2017-3648 Remote Security Vulnerability
2017-07-31
http://www.securityfocus.com/bid/99789

Oracle MySQL Server CVE-2017-3651 Remote Security Vulnerability
2017-07-31
http://www.securityfocus.com/bid/99802

Linux kernel CVE-2017-9077 Local Denial of Service Vulnerability
2017-07-31
http://www.securityfocus.com/bid/98583

Linux Kernel CVE-2017-1000363 Integer Overflow Vulnerability
2017-07-31
http://www.securityfocus.com/bid/98651

Linux Kernel 'sound/core/timer.c' Local Information Disclosure Vulnerability
2017-07-31
http://www.securityfocus.com/bid/99121

Linux Kernel CVE-2017-7273 Local Denial of Service Vulnerability
2017-07-31
http://www.securityfocus.com/bid/97190

Linux Kernel 'btrfs/ctree.c' Local Privilege Escalation Vulnerability
2017-07-31
http://www.securityfocus.com/bid/73308

Linux Kernel 'sk_dst_get()' Denial of Service Vulnerability
2017-07-31
http://www.securityfocus.com/bid/72435

Linux Kernel 'fs/udf/inode.c' Denial of Service Vulnerability
2017-07-31
http://www.securityfocus.com/bid/74963

Linux Kernel 'iov_iter_init()' Function Security Bypass Vulnerability
2017-07-31
http://www.securityfocus.com/bid/73286

FreeRADIUS 'modules/proto_dhcp/dhcp.c' Out-of-Bounds Read Denial of Service Vulnerability
2017-07-31
http://www.securityfocus.com/bid/99970

FreeRADIUS 'src/lib/radius.c' Denial of Service Vulnerability
2017-07-31
http://www.securityfocus.com/bid/99968

FreeRADIUS CVE-2017-10986 Out-of-Bounds Read Denial of Service Vulnerability
2017-07-31
http://www.securityfocus.com/bid/99971

FreeRADIUS CVE-2017-10983 Denial of Service Vulnerability
2017-07-31
http://www.securityfocus.com/bid/99915

FreeRADIUS CVE-2017-10981 Denial of Service Vulnerability
2017-07-31
http://www.securityfocus.com/bid/99898

FreeRADIUS CVE-2017-10982 Denial of Service Vulnerability
2017-07-31
http://www.securityfocus.com/bid/99912

FreeRADIUS CVE-2017-10979 Out-Of-Bounds Write Remote Code Execution Vulnerability
2017-07-31
http://www.securityfocus.com/bid/99901

FreeRADIUS CVE-2017-10978 Out-of-Bounds Read/Write Denial of Service Vulnerability
2017-07-31
http://www.securityfocus.com/bid/99893

FreeRADIUS CVE-2017-10980 Denial of Service Vulnerability
2017-07-31
http://www.securityfocus.com/bid/99905

FreeRADIUS CVE-2017-10984 Out-Of-Bounds Write Remote Code Execution Vulnerability
2017-07-31
http://www.securityfocus.com/bid/99876

Apache HTTP Server CVE-2017-9788 Memory Corruption Vulnerability
2017-07-31
http://www.securityfocus.com/bid/99569

Apache Tomcat CVE-2017-5648 Information Disclosure Vulnerability
2017-07-31
http://www.securityfocus.com/bid/97530

Apache Tomcat CVE-2017-5664 Security Bypass Vulnerability
2017-07-31
http://www.securityfocus.com/bid/98888

Linux Kernel Local Security Bypass Vulnerability
2017-07-31
http://www.securityfocus.com/bid/92659

C-ares CVE-2017-1000381 Out of Bounds Read Information Disclosure Vulnerability
2017-07-28
http://www.securityfocus.com/bid/99148

SANS News

Text Banking Scams

Threatpost

Microsoft Releases Outlook and Office Click-to-Run Patches

Exploit

VehicleWorkshop - SQL Injection

Jenkins < 1.650 - Java Deserialization

DiskBoss Enterprise 8.2.14 - Buffer Overflow

VehicleWorkshop - SQL Injection

30.7.2017

Bugtraq

FortiOS <= 5.6.0 Multiple XSS Vulnerabilities 2017-07-28
msg patrykbogdan com

security bulletin] HPESBHF03765 rev.1 - HPE ConvergedSystem 700 Solution with Comware v7 Switches using OpenSSL, Remote Denial of Service (DoS) and Disclosure of Sensitive Information 2017-07-26
HPE Product Security Response Team (security-alert hpe com)

SECURITY] DSA 3919-1] openjdk-8 security update 2017-07-25
Moritz Muehlenhoff (jmm debian org)

SECURITY] DSA 3920-1] qemu security update 2017-07-25
Moritz Muehlenhoff (jmm debian org)

slackware-security] tcpdump (SSA:2017-205-01) 2017-07-24
Slackware Security Team (security slackware com)

SEC Consult SA-20170724-0 :: Cross-Site Scripting (XSS) issue in multiple Ubiquiti Networks products 2017-07-24
SEC Consult Vulnerability Lab (research sec-consult com)

Malware

Trojan.Ismagent

Phishing

RBS

28th July 2017

Friday Update

Tesco Bank

27th July 2017

:Tesco new security features

Email

27th July 2017

Email Terminates in 2days, Add
Recovery Phone No To Avoid
Account Loss!!

Vulnerebility

C-ares CVE-2017-1000381 Out of Bounds Read Information Disclosure Vulnerability
2017-07-28
http://www.securityfocus.com/bid/99148

Node.js CVE-2017-11499 Denial of Service Vulnerability
2017-07-28
http://www.securityfocus.com/bid/99959

Microsoft Windows LNK CVE-2017-8464 Remote Code Execution Vulnerability
2017-07-28
http://www.securityfocus.com/bid/98818

Cloud Foundry Cloud Controller API CVE-2017-8036 Incomplete Fix Remote Code Execution Vulnerability
2017-07-28
http://www.securityfocus.com/bid/100002

Ghostscript GhostXPS CVE-2017-9618 Denial of Service Vulnerability
2017-07-28
http://www.securityfocus.com/bid/99993

Cisco StarOS CVE-2017-6729 Remote Denial of Service Vulnerability
2017-07-28
http://www.securityfocus.com/bid/100015

VMware vCenter Server CVE-2017-4922 Local Information Disclosure Vulnerability
2017-07-28
http://www.securityfocus.com/bid/100012

Linux kernel CVE-2017-11473 Local Buffer Overflow Vulnerability
2017-07-28
http://www.securityfocus.com/bid/100010

FortiOS Multiple Cross Site Scripting Vulnerabilities
2017-07-28
http://www.securityfocus.com/bid/100009

Multiple IBM Products CVE-2017-1386 Security Bypass Vulnerability
2017-07-28
http://www.securityfocus.com/bid/100008

Oracle Java SE CVE-2017-10081 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99853

Oracle Java SE CVE-2017-10193 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99854

Oracle Java SE and JRockit CVE-2017-10109 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99847

Oracle Java SE and JRockit CVE-2017-10135 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99839

Oracle Java SE and JRockit CVE-2017-10053 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99842

Oracle Java SE and JRockit CVE-2017-10108 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99846

Oracle Java SE and JRockit CVE-2017-10198 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99818

Oracle Java SE and JRockit CVE-2017-10243 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99827

Oracle Java SE and JRockit CVE-2017-10118 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99782

Oracle Java SE and JRockit CVE-2017-10176 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99788

Oracle Java SE and JRockit CVE-2017-10115 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99774

Oracle Java SE and JRockit CVE-2017-10116 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99734

Oracle Java SE CVE-2017-10078 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99752

Oracle Java SE CVE-2017-10087 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99703

Oracle Java SE CVE-2017-10102 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99712

Oracle Java SE CVE-2017-10089 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99659

Oracle Java SE CVE-2017-10090 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99706

Oracle Java SE CVE-2017-10110 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99643

Oracle Java SE CVE-2017-10111 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99707

Oracle Java SE CVE-2017-10067 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99756

SANS News

Static Analysis of Emotet Maldoc

Threatpost

Shorting-For-Profit Viable Business Model For Security Community

Exploit

Joomla! Component CCNewsLetter 2.1.9 - 'sbid' Parameter SQL Injection

FortiOS < 5.6.0 - Cross-Site Scripting

SoundTouch 1.9.2 - Multiple Vulnerabilities

LAME 3.99.5 - Multiple Vulnerabilities

libjpeg-turbo 1.5.1 - Denial of Service

28.7.2017

Bugtraq

security bulletin] HPESBHF03765 rev.1 - HPE ConvergedSystem 700 Solution with Comware v7 Switches using OpenSSL, Remote Denial of Service (DoS) and Disclosure of Sensitive Information 2017-07-26
HPE Product Security Response Team (security-alert hpe com)

SECURITY] DSA 3919-1] openjdk-8 security update 2017-07-25
Moritz Muehlenhoff (jmm debian org)

SECURITY] DSA 3920-1] qemu security update 2017-07-25
Moritz Muehlenhoff (jmm debian org)

slackware-security] tcpdump (SSA:2017-205-01) 2017-07-24
Slackware Security Team (security slackware com)

Malware

 

Phishing

Tesco Bank

27th July 2017

:Tesco new security features

Email

27th July 2017

Email Terminates in 2days, Add
Recovery Phone No To Avoid
Account Loss!!

Vulnerebility

Oracle Java SE CVE-2017-10081 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99853

Oracle Java SE CVE-2017-10193 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99854

Oracle Java SE and JRockit CVE-2017-10109 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99847

Oracle Java SE and JRockit CVE-2017-10135 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99839

Oracle Java SE and JRockit CVE-2017-10053 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99842

Oracle Java SE and JRockit CVE-2017-10108 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99846

Oracle Java SE and JRockit CVE-2017-10198 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99818

Oracle Java SE and JRockit CVE-2017-10243 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99827

Oracle Java SE and JRockit CVE-2017-10118 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99782

Oracle Java SE and JRockit CVE-2017-10176 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99788

Oracle Java SE and JRockit CVE-2017-10115 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99774

Oracle Java SE and JRockit CVE-2017-10116 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99734

Oracle Java SE CVE-2017-10078 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99752

Oracle Java SE CVE-2017-10087 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99703

Oracle Java SE CVE-2017-10102 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99712

Oracle Java SE CVE-2017-10089 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99659

Oracle Java SE CVE-2017-10090 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99706

Oracle Java SE CVE-2017-10110 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99643

Oracle Java SE CVE-2017-10111 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99707

Oracle Java SE CVE-2017-10067 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99756

Oracle Java SE CVE-2017-10107 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99719

Oracle Java SE CVE-2017-10096 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99670

Oracle Java SE CVE-2017-10074 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99731

Oracle Java SE CVE-2017-10101 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99674

PHP 'zend_ini_do_op()' Function Stack Buffer Overflow Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99489

ImageMagick CVE-2017-11640 Denial of Service Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99989

Hashtopus CVE-2017-11679 Cross Site Request Forgery Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99984

Hashtopus CVE-2017-11678 SQL Injection Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99982

Libav CVE-2017-11684 Denail of Service Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99980

Hashtopus CVE-2017-11677 Cross Site Scripting Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99974

SANS News

TinyPot, My Small Honeypot

Threatpost

Android Spyware Still Collects PII Despite Outcry

Google Study Quantifies Ransomware Profits

Attack Uses Docker Containers To Hide, Persist, Plant Malware

Exploit

Friends in War Make or Break 1.7 - Cross-Site Request Forgery (Change Admin...

MediaCoder 0.8.48.5888 - Local Buffer Overflow (SEH)

AudioCoder 0.8.46 - Local Buffer Overflow (SEH)

27.7.2017

Bugtraq

security bulletin] HPESBHF03765 rev.1 - HPE ConvergedSystem 700 Solution with Comware v7 Switches using OpenSSL, Remote Denial of Service (DoS) and Disclosure of Sensitive Information 2017-07-26
HPE Product Security Response Team (security-alert hpe com)

SECURITY] DSA 3919-1] openjdk-8 security update 2017-07-25
Moritz Muehlenhoff (jmm debian org)

SECURITY] DSA 3920-1] qemu security update 2017-07-25
Moritz Muehlenhoff (jmm debian org)

slackware-security] tcpdump (SSA:2017-205-01) 2017-07-24
Slackware Security Team (security slackware com)

SEC Consult SA-20170724-0 :: Cross-Site Scripting (XSS) issue in multiple Ubiquiti Networks products 2017-07-24
SEC Consult Vulnerability Lab (research sec-consult com)

SEC Consult SA-20170724-1 :: Open Redirect issue in multiple Ubiquiti Networks products 2017-07-24
SEC Consult Vulnerability Lab (research sec-consult com)

RT-SA-2017-006] Arbitrary File Disclosure with root Privileges via RdxEngine-API in REDDOXX Appliance 2017-07-24
RedTeam Pentesting GmbH (release redteam-pentesting de)

RT-SA-2017-008] Unauthenticated Access to Diagnostic Functions in REDDOXX Appliance 2017-07-24
RedTeam Pentesting GmbH (release redteam-pentesting de)

RT-SA-2017-005] Unauthenticated Extraction of Session-IDs in REDDOXX Appliance 2017-07-24
RedTeam Pentesting GmbH (release redteam-pentesting de)

RT-SA-2017-009] Remote Command Execution as root in REDDOXX Appliance 2017-07-24
RedTeam Pentesting GmbH (release redteam-pentesting de)

RT-SA-2017-003] Cross-Site Scripting in REDDOXX Appliance 2017-07-24
RedTeam Pentesting GmbH (release redteam-pentesting de)

Malware

Backdoor.Krad

Ransom.Reyptson

Phishing

EUROMILLION INTERNATIONAL

26th July 2017

Congratulations: you have won
in Euromillions

National

26th July 2017

Notification : Update your
account to get back to
watching.

Vulnerebility

Oracle Java SE CVE-2017-10081 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99853

Oracle Java SE CVE-2017-10193 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99854

Oracle Java SE and JRockit CVE-2017-10109 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99847

Oracle Java SE and JRockit CVE-2017-10135 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99839

Oracle Java SE and JRockit CVE-2017-10053 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99842

Oracle Java SE and JRockit CVE-2017-10108 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99846

Oracle Java SE and JRockit CVE-2017-10198 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99818

Oracle Java SE and JRockit CVE-2017-10243 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99827

Oracle Java SE and JRockit CVE-2017-10118 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99782

Oracle Java SE and JRockit CVE-2017-10176 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99788

Oracle Java SE and JRockit CVE-2017-10115 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99774

Oracle Java SE and JRockit CVE-2017-10116 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99734

Oracle Java SE CVE-2017-10078 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99752

Oracle Java SE CVE-2017-10087 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99703

Oracle Java SE CVE-2017-10102 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99712

Oracle Java SE CVE-2017-10089 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99659

Oracle Java SE CVE-2017-10090 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99706

Oracle Java SE CVE-2017-10110 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99643

Oracle Java SE CVE-2017-10111 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99707

Oracle Java SE CVE-2017-10067 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99756

Oracle Java SE CVE-2017-10107 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99719

Oracle Java SE CVE-2017-10096 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99670

Oracle Java SE CVE-2017-10074 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99731

Oracle Java SE CVE-2017-10101 Remote Security Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99674

PHP 'zend_ini_do_op()' Function Stack Buffer Overflow Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99489

Hashtopus CVE-2017-11679 Cross Site Request Forgery Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99984

Hashtopus CVE-2017-11678 SQL Injection Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99982

Libav CVE-2017-11684 Denail of Service Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99980

Hashtopus CVE-2017-11677 Cross Site Scripting Vulnerability
2017-07-27
http://www.securityfocus.com/bid/99974

GNU libiberty CVE-2016-6131 Stack Based Buffer Overflow Vulnerability
2017-07-26
http://www.securityfocus.com/bid/91519

SANS News

TinyPot, My Small Honeypot

Threatpost

Academia’s Role in Security Skills Gap Examined

Vulnerable Radiation Monitoring Devices Won’t Be Patched

Android Sypware Still Collects PII Despite Outcry
 

Friends in War Make or Break 1.7 - Cross-Site Request Forgery (Change Admin...

Friends in War Make or Break 1.7 - Authentication Bypass

Friends in War Make or Break 1.7 - SQL Injection

Exploit

Friends in War Make or Break 1.7 - Authentication Bypass

Friends in War Make or Break 1.7 - SQL Injection

Microsoft Windows - LNK Shortcut File Code Execution (Metasploit)

26.7.2017

Bugtraq

SECURITY] DSA 3919-1] openjdk-8 security update 2017-07-25
Moritz Muehlenhoff (jmm debian org)

SECURITY] DSA 3920-1] qemu security update 2017-07-25
Moritz Muehlenhoff (jmm debian org)

slackware-security] tcpdump (SSA:2017-205-01) 2017-07-24
Slackware Security Team (security slackware com)

SEC Consult SA-20170724-0 :: Cross-Site Scripting (XSS) issue in multiple Ubiquiti Networks products 2017-07-24
SEC Consult Vulnerability Lab (research sec-consult com)

SEC Consult SA-20170724-1 :: Open Redirect issue in multiple Ubiquiti Networks products 2017-07-24
SEC Consult Vulnerability Lab (research sec-consult com)

RT-SA-2017-006] Arbitrary File Disclosure with root Privileges via RdxEngine-API in REDDOXX Appliance 2017-07-24
RedTeam Pentesting GmbH (release redteam-pentesting de)

RT-SA-2017-008] Unauthenticated Access to Diagnostic Functions in REDDOXX Appliance 2017-07-24
RedTeam Pentesting GmbH (release redteam-pentesting de)

RT-SA-2017-005] Unauthenticated Extraction of Session-IDs in REDDOXX Appliance 2017-07-24
RedTeam Pentesting GmbH (release redteam-pentesting de)

RT-SA-2017-009] Remote Command Execution as root in REDDOXX Appliance 2017-07-24
RedTeam Pentesting GmbH (release redteam-pentesting de)

RT-SA-2017-003] Cross-Site Scripting in REDDOXX Appliance 2017-07-24
RedTeam Pentesting GmbH (release redteam-pentesting de)

Malware

 

Phishing

service@paypal-support.co.uk

25th July 2017

New Message

Apple Store

24th July 2017

Apple Notification

Eve

24th July 2017

Action Required]Unrecognized
Account Access Notification

Vulnerebility

Ruby TclTkIp 'ip_cancel_eval()' Function Type Confusion Remote Code Execution Vulnerability
2017-07-26
http://www.securityfocus.com/bid/91233

Ruby 'dl/handle.c' Security Bypass Vulnerability
2017-07-26
http://www.securityfocus.com/bid/76060

Ruby CVE-2015-1855 Security Bypass Vulnerability
2017-07-26
http://www.securityfocus.com/bid/74446

Ruby 'initialize()' Function Heap Buffer Overflow Vulnerability
2017-07-26
http://www.securityfocus.com/bid/91234

Ruby OpenSSL Security Bypass Vulnerability
2017-07-26
http://www.securityfocus.com/bid/93031

Mozilla Firefox CVE-2017-5470 Multiple Unspecified Memory Corruption Vulnerabilities
2017-07-26
http://www.securityfocus.com/bid/99041

Mozilla Firefox Multiple Security Vulnerabilities
2017-07-26
http://www.securityfocus.com/bid/99057

Mozilla Firefox CVE-2017-5472 Use After Free Denial of Service Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99040

Oracle Java SE and JRockit CVE-2017-10108 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99846

Oracle Java SE CVE-2017-10193 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99854

Oracle Java SE CVE-2017-10074 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99731

Oracle Java SE CVE-2017-10101 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99674

Oracle Java SE and JRockit CVE-2017-10135 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99839

Oracle Java SE CVE-2017-10111 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99707

Oracle Java SE and JRockit CVE-2017-10109 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99847

Oracle Java SE and JRockit CVE-2017-10176 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99788

Oracle Java SE and JRockit CVE-2017-10118 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99782

Oracle Java SE and JRockit CVE-2017-10198 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99818

Oracle Java SE CVE-2017-10102 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99712

Oracle Java SE and JRockit CVE-2017-10053 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99842

Oracle Java SE and JRockit CVE-2017-10115 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99774

Oracle Java SE CVE-2017-10067 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99756

Oracle Java SE CVE-2017-10078 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99752

Oracle Java SE CVE-2017-10081 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99853

Oracle Java SE and JRockit CVE-2017-10116 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99734

Oracle Java SE CVE-2017-10110 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99643

Oracle Java SE CVE-2017-10090 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99706

Oracle Java SE CVE-2017-10096 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99670

Oracle Java SE CVE-2017-10107 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99719

Oracle Java SE CVE-2017-10089 Remote Security Vulnerability
2017-07-26
http://www.securityfocus.com/bid/99659

SANS News

Malspam pushing Emotet malware

Threatpost

Hacker Admits to Mirai Attack Against Deutsche Telekom

Black Hat USA 2017 Preview

Novel Attack Tricks Servers to Cache, Expose Personal Data

Academia’s Role in Security Skills Gap Examined

Exploit

WebKit JSC - 'JSObject::putInlineSlow and JSValue::putToPrimitive' Universal...

WebKit JSC - 'DFG::ByteCodeParser::flush(InlineStackEntry* inlineStackEntry)'...

WebKit JSC - 'arrayProtoFuncSplice' Uninitialized Memory Reference

WebKit JSC - 'JSArray::appendMemcpy' Uninitialized Memory Copy

WebKit JSC - 'ArgumentsEliminationPhase::transform' Incorrect LoadVarargs Handling

WebKit JSC - 'ObjectPatternNode::appendEntry' Stack Use-After-Free

25.7.2017

Bugtraq

slackware-security] tcpdump (SSA:2017-205-01) 2017-07-24
Slackware Security Team (security slackware com)

SEC Consult SA-20170724-0 :: Cross-Site Scripting (XSS) issue in multiple Ubiquiti Networks products 2017-07-24
SEC Consult Vulnerability Lab (research sec-consult com)

SEC Consult SA-20170724-1 :: Open Redirect issue in multiple Ubiquiti Networks products 2017-07-24
SEC Consult Vulnerability Lab (research sec-consult com)

RT-SA-2017-006] Arbitrary File Disclosure with root Privileges via RdxEngine-API in REDDOXX Appliance 2017-07-24
RedTeam Pentesting GmbH (release redteam-pentesting de)

RT-SA-2017-008] Unauthenticated Access to Diagnostic Functions in REDDOXX Appliance 2017-07-24
RedTeam Pentesting GmbH (release redteam-pentesting de)

RT-SA-2017-005] Unauthenticated Extraction of Session-IDs in REDDOXX Appliance 2017-07-24
RedTeam Pentesting GmbH (release redteam-pentesting de)

RT-SA-2017-009] Remote Command Execution as root in REDDOXX Appliance 2017-07-24
RedTeam Pentesting GmbH (release redteam-pentesting de)

RT-SA-2017-003] Cross-Site Scripting in REDDOXX Appliance 2017-07-24
RedTeam Pentesting GmbH (release redteam-pentesting de)

RT-SA-2017-007] Undocumented Administrative Service Account in REDDOXX Appliance 2017-07-24
RedTeam Pentesting GmbH (release redteam-pentesting de)

RT-SA-2017-004] Unauthenticated Arbitrary File Disclosure in REDDOXX Appliance 2017-07-24
RedTeam Pentesting GmbH (release redteam-pentesting de)

SECURITY] DSA 3917-1] catdoc security update 2017-07-23
Salvatore Bonaccorso (carnil debian org)

Malware

Trojan.Ismdoor.B

Phishing

 

Vulnerebility

X.Org X Server CVE-2017-10971 Stack Buffer Overflow Vulnerability
2017-07-25
http://www.securityfocus.com/bid/99546

X.Org X Server CVE-2017-10972 Information Disclosure Vulnerability
2017-07-25
http://www.securityfocus.com/bid/99543

X.org X Server Local Multiple Security Vulnerabilities
2017-07-25
http://www.securityfocus.com/bid/96480

QEMU 'hw/9pfs/9p-local.c' Privilege Escalation Vulnerability
2017-07-25
http://www.securityfocus.com/bid/98574

Google Android Kernel Trace Subsystem CVE-2017-0605 Privilege Escalation Vulnerability
2017-07-24
http://www.securityfocus.com/bid/98152

Samba CVE-2017-7494 Remote Code Execution Vulnerability
2017-07-24
http://www.securityfocus.com/bid/98636

Adobe Flash Player APSB17-17 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-07-24
http://www.securityfocus.com/bid/99023

Evince Comic Book Backend CVE-2017-1000083 Command Injection Vulnerability
2017-07-24
http://www.securityfocus.com/bid/99597

Mozilla Firefox CVE-2017-5472 Use After Free Denial of Service Vulnerability
2017-07-24
http://www.securityfocus.com/bid/99040

Mozilla Firefox CVE-2017-5470 Multiple Unspecified Memory Corruption Vulnerabilities
2017-07-24
http://www.securityfocus.com/bid/99041

ISC BIND CVE-2017-3143 Security Bypass Vulnerability
2017-07-24
http://www.securityfocus.com/bid/99337

ISC BIND CVE-2017-3142 Security Bypass Vulnerability
2017-07-24
http://www.securityfocus.com/bid/99339

Linux Kernel CVE-2017-7895 Multiple Security Bypass Vulnerabilities
2017-07-24
http://www.securityfocus.com/bid/98085

Linux Kernel CVE-2017-7477 Heap Buffer Overflow Vulnerability
2017-07-24
http://www.securityfocus.com/bid/98014

Linux Kernel CVE-2017-2583 Privilege Escalation Vulnerability
2017-07-24
http://www.securityfocus.com/bid/95673

Apache HTTP Server CVE-2016-8743 Security Bypass Vulnerability
2017-07-24
http://www.securityfocus.com/bid/95077

QEMU CVE-2017-9524 Denial of Service Vulnerability
2017-07-24
http://www.securityfocus.com/bid/99011

Linux Kernel CVE-2017-6214 Remote Denial of Service Vulnerability
2017-07-24
http://www.securityfocus.com/bid/96421

Mozilla Firefox Multiple Security Vulnerabilities
2017-07-24
http://www.securityfocus.com/bid/99057

GNU glibc CVE-2017-1000366 Local Memory Corruption Vulnerability
2017-07-24
http://www.securityfocus.com/bid/99127

Sudo CVE-2017-1000368 Incomplete Fix Local Privilege Escalation Vulnerability
2017-07-24
http://www.securityfocus.com/bid/98838

Linux Kernel CVE-2017-1000364 Local Memory Corruption Vulnerability
2017-07-24
http://www.securityfocus.com/bid/99130

FreeRADIUS TLS CVE-2017-9148 Authentication Bypass Vulnerability
2017-07-24
http://www.securityfocus.com/bid/98734

Mercurial CVE-2017-9462 Remote Code Execution Vulnerability
2017-07-24
http://www.securityfocus.com/bid/99123

Linux Kernel CVE-2017-7645 Multiple Denial of Service Vulnerabilities
2017-07-24
http://www.securityfocus.com/bid/97950

ImageMagick CVE-2017-11525 Denial of Service Vulnerability
2017-07-24
http://www.securityfocus.com/bid/99931

ImageMagick CVE-2017-11540 Heap Buffer Overflow Vulnerability
2017-07-24
http://www.securityfocus.com/bid/99929

Phamm CVE-2017-0378 Cross Site Scripting Vulnerability
2017-07-24
http://www.securityfocus.com/bid/99927

gnome-exe-thumbnailer CVE-2017-11421 Local Code Injection Vulnerability
2017-07-24
http://www.securityfocus.com/bid/99922

Debian CVE-2017-11565 Security Bypass Vulnerability
2017-07-23
http://www.securityfocus.com/bid/99933

SANS News

Uber drivers new threat: the "passenger"

Threatpost

Hacker Admits to Mirai Attack Against Deutsche Telekom

Exploit

Microsoft Internet Explorer - 'mshtml.dll' Remote Code Execution (MS17-007)

IPFire < 2.19 Update Core 110 - Remote Code Execution (Metasploit)

VICIdial 2.9 RC 1 to 2.13 RC1 - user_authorization Unauthenticated Command...

ManageEngine Desktop Central 10 Build 100087 - Remote Code Execution (Metasploit)

PaulShop - SQL Injection / Cross-Site Scripting

REDDOXX Appliance Build 2032 / 2.0.625 - Remote Command Execution

REDDOXX Appliance Build 2032 / 2.0.625 - Arbitrary File Disclosure

MAWK 1.3.3-17 - Local Buffer Overflow

Razer Synapse 2.20.15.1104 - rzpnk.sys ZwOpenProcess (Metasploit)

WebKit - 'WebCore::AccessibilityNodeObject::textUnderElement' Use-After-Free

WebKit - 'WebCore::AccessibilityRenderObject::handleAriaExpandedChanged' Use-After-Free

WebKit - 'WebCore::Node::nextSibling' Use-After-Free

WebKit - 'WebCore::RenderSearchField::addSearchResult' Heap Buffer Overflow

WebKit - 'WebCore::InputType::element' Use-After-Free

WebKit - 'WebCore::RenderObject' with Accessibility Enabled Use-After-Free

WebKit - 'WebCore::Node::getFlag' Use-After-Free

WebKit - 'WebCore::getCachedWrapper' Use-After-Free

24.7.2017

Bugtraq

SECURITY] DSA 3917-1] catdoc security update 2017-07-23
Salvatore Bonaccorso (carnil debian org)

slackware-security] seamonkey (SSA:2017-202-01) 2017-07-21
Slackware Security Team (security slackware com)

security bulletin] HPESBHF03745 rev.3 - HPE Intelligent Management Center (iMC) PLAT, Remote Code Execution 2017-07-21
security-alert hpe com

security bulletin] HPESBHF03766 rev.1 - HPE ConvergedSystem 700 Solution with Comware v5 Switches using NTP, Remote Denial of Service (DoS), Unauthorized Modification and Local Denial of Service (DoS) 2017-07-20
security-alert hpe com

File Upload in Integration Gateway (PSIGW) 2017-07-20
ERPScan inc (erpscan online gmail com)

Malware

 

Phishing

Apple

24th July 2017

Apple just sent you $3,543.00
USD with Paypal. Paypal
recommends to withdraw it now.

Vulnerebility

Mozilla Firefox CVE-2017-5472 Use After Free Denial of Service Vulnerability
2017-07-24
http://www.securityfocus.com/bid/99040

Mozilla Firefox CVE-2017-5470 Multiple Unspecified Memory Corruption Vulnerabilities
2017-07-24
http://www.securityfocus.com/bid/99041

ISC BIND CVE-2017-3143 Security Bypass Vulnerability
2017-07-24
http://www.securityfocus.com/bid/99337

ISC BIND CVE-2017-3142 Security Bypass Vulnerability
2017-07-24
http://www.securityfocus.com/bid/99339

Linux Kernel CVE-2017-7895 Multiple Security Bypass Vulnerabilities
2017-07-24
http://www.securityfocus.com/bid/98085

Linux Kernel CVE-2017-7477 Heap Buffer Overflow Vulnerability
2017-07-24
http://www.securityfocus.com/bid/98014

Linux Kernel CVE-2017-2583 Privilege Escalation Vulnerability
2017-07-24
http://www.securityfocus.com/bid/95673

Apache HTTP Server CVE-2016-8743 Security Bypass Vulnerability
2017-07-24
http://www.securityfocus.com/bid/95077

QEMU CVE-2017-9524 Denial of Service Vulnerability
2017-07-24
http://www.securityfocus.com/bid/99011

Linux Kernel CVE-2017-6214 Remote Denial of Service Vulnerability
2017-07-24
http://www.securityfocus.com/bid/96421

Mozilla Firefox Multiple Security Vulnerabilities
2017-07-24
http://www.securityfocus.com/bid/99057

GNU glibc CVE-2017-1000366 Local Memory Corruption Vulnerability
2017-07-24
http://www.securityfocus.com/bid/99127

Sudo CVE-2017-1000368 Incomplete Fix Local Privilege Escalation Vulnerability
2017-07-24
http://www.securityfocus.com/bid/98838

Linux Kernel CVE-2017-1000364 Local Memory Corruption Vulnerability
2017-07-24
http://www.securityfocus.com/bid/99130

FreeRADIUS TLS CVE-2017-9148 Authentication Bypass Vulnerability
2017-07-24
http://www.securityfocus.com/bid/98734

Mercurial CVE-2017-9462 Remote Code Execution Vulnerability
2017-07-24
http://www.securityfocus.com/bid/99123

Linux Kernel CVE-2017-7645 Multiple Denial of Service Vulnerabilities
2017-07-24
http://www.securityfocus.com/bid/97950

Irssi CVE-2017-9469 Denial of Service Vulnerability
2017-07-21
http://www.securityfocus.com/bid/99043

ICU CVE-2016-6293 Out of Bounds Read Denial of Service Vulnerability
2017-07-21
http://www.securityfocus.com/bid/92127

PHP 'ftp_genlist()' Function Integer Overflow Vulnerability
2017-07-21
http://www.securityfocus.com/bid/74902

PHP NULL Character CVE-2015-4025 Incomplete Fix Multiple Security Bypass Vulnerabilities
2017-07-21
http://www.securityfocus.com/bid/74904

PHP 'main/rfc1867.c' Remote Denial Of Service Vulnerability
2017-07-21
http://www.securityfocus.com/bid/74903

PHP PHAR 'phar_parse_tarfile()' Function Remote Memory Corruption Vulnerability
2017-07-21
http://www.securityfocus.com/bid/74700

PHP '/xmlrpc/libxmlrpc/simplestring.c' Heap Buffer Overflow Vulnerability
2017-07-21
http://www.securityfocus.com/bid/92095

PHP 'zip_stream.c' Integer Overflow Vulnerability
2017-07-21
http://www.securityfocus.com/bid/92099

PHP wdsl Extension CVE-2013-6501 Security Weakness
2017-07-21
http://www.securityfocus.com/bid/72530

PHP 'snmp.c' Denial of Service Vulnerability
2017-07-21
http://www.securityfocus.com/bid/92094

PHP 'zend_virtual_cwd.c' Integer Overflow Vulnerability
2017-07-21
http://www.securityfocus.com/bid/92074

PHP CVE-2016-6294 Local Information Disclosure Vulnerability
2017-07-21
http://www.securityfocus.com/bid/92115

PHP 'exif.c' NULL Pointer Dereference Denial of Service Vulnerability
2017-07-21
http://www.securityfocus.com/bid/92078

SANS News

Another .lnk File

Uber drivers new threat: the "passenger"

Threatpost

 

Exploit

Microsoft Internet Explorer - 'mshtml.dll' Remote Code Execution (MS17-007)

ManageEngine Desktop Central 10 Build 100087 - Remote Code Execution (Metasploit)

PaulShop - Sql Injection / Cross-Site Scripting

MAWK 1.3.3-17 - Local Buffer Overflow

23.7.2017

Bugtraq

security bulletin] HPESBHF03766 rev.1 - HPE ConvergedSystem 700 Solution with Comware v5 Switches using NTP, Remote Denial of Service (DoS), Unauthorized Modification and Local Denial of Service (DoS) 2017-07-20
security-alert hpe com

File Upload in Integration Gateway (PSIGW) 2017-07-20
ERPScan inc (erpscan online gmail com)

Multiple XSS (POST request) Vulnerabilities in TestServlet (PeopleSoft) 2017-07-20
ERPScan inc (erpscan online gmail com)

Directory Traversal vulnerability in Integration Gateway (PSIGW) 2017-07-20
ERPScan inc (erpscan online gmail com)

APPLE-SA-2017-07-19-7 iCloud for Windows 6.2.2 2017-07-19
Apple Product Security (product-security-noreply lists apple com)

APPLE-SA-2017-07-19-5 Safari 10.1.2 2017-07-19
Apple Product Security (product-security-noreply lists apple com)

Malware

 

Phishing

 

Vulnerebility

Mozilla Firefox CVE-2017-5472 Use After Free Denial of Service Vulnerability
2017-07-21
http://www.securityfocus.com/bid/99040

Mozilla Firefox CVE-2017-5470 Multiple Unspecified Memory Corruption Vulnerabilities
2017-07-21
http://www.securityfocus.com/bid/99041

Irssi CVE-2017-9469 Denial of Service Vulnerability
2017-07-21
http://www.securityfocus.com/bid/99043

ICU CVE-2016-6293 Out of Bounds Read Denial of Service Vulnerability
2017-07-21
http://www.securityfocus.com/bid/92127

PHP 'ftp_genlist()' Function Integer Overflow Vulnerability
2017-07-21
http://www.securityfocus.com/bid/74902

PHP NULL Character CVE-2015-4025 Incomplete Fix Multiple Security Bypass Vulnerabilities
2017-07-21
http://www.securityfocus.com/bid/74904

PHP 'main/rfc1867.c' Remote Denial Of Service Vulnerability
2017-07-21
http://www.securityfocus.com/bid/74903

PHP PHAR 'phar_parse_tarfile()' Function Remote Memory Corruption Vulnerability
2017-07-21
http://www.securityfocus.com/bid/74700

PHP '/xmlrpc/libxmlrpc/simplestring.c' Heap Buffer Overflow Vulnerability
2017-07-21
http://www.securityfocus.com/bid/92095

PHP 'zip_stream.c' Integer Overflow Vulnerability
2017-07-21
http://www.securityfocus.com/bid/92099

PHP wdsl Extension CVE-2013-6501 Security Weakness
2017-07-21
http://www.securityfocus.com/bid/72530

PHP 'snmp.c' Denial of Service Vulnerability
2017-07-21
http://www.securityfocus.com/bid/92094

PHP 'zend_virtual_cwd.c' Integer Overflow Vulnerability
2017-07-21
http://www.securityfocus.com/bid/92074

PHP CVE-2016-6294 Local Information Disclosure Vulnerability
2017-07-21
http://www.securityfocus.com/bid/92115

PHP 'exif.c' NULL Pointer Dereference Denial of Service Vulnerability
2017-07-21
http://www.securityfocus.com/bid/92078

PHP 'php_url_prase_ex()' Function Memory Corruption Vulnerability
2017-07-21
http://www.securityfocus.com/bid/92111

Mozilla Firefox CVE-2017-5426 Security Bypass Vulnerability
2017-07-21
http://www.securityfocus.com/bid/96694

Mozilla Firefox and Thunderbird Multiple Security Vulnerabilities
2017-07-21
http://www.securityfocus.com/bid/96693

Mozilla Firefox CVE-2017-5403 Denial of Service Vulnerability
2017-07-21
http://www.securityfocus.com/bid/96691

Graphviz 'agerr()' Function Remote Format String Vulnerability
2017-07-21
http://www.securityfocus.com/bid/71283

Graphviz 'yyerror()' Function Stack Buffer Overflow Vulnerability
2017-07-21
http://www.securityfocus.com/bid/64674

libpng NULL pointer Dereference 'png_set_text_2()' Function Remote Denial of Service Vulnerability
2017-07-21
http://www.securityfocus.com/bid/95157

Irssi CVE-2017-9468 Denial of Service Vulnerability
2017-07-21
http://www.securityfocus.com/bid/99015

Irssi Multiple Memory Corruption Vulnerabilities
2017-07-21
http://www.securityfocus.com/bid/95310

Mozilla Firefox Multiple Security Vulnerabilities
2017-07-21
http://www.securityfocus.com/bid/99057

Mozilla Firefox MFSA 2017-05 Multiple Security Vulnerabilities
2017-07-21
http://www.securityfocus.com/bid/96692

PHP 'ext/wddx/wddx.c' Denial of Service Vulnerability
2017-07-21
http://www.securityfocus.com/bid/94846

NVIDIA GPU Driver CVE-2017-0350 Local Privilege Escalation Vulnerability
2017-07-21
http://www.securityfocus.com/bid/98490

PHP 'pcnt_exec()' Function Null Character Security Bypass Vulnerability
2017-07-21
http://www.securityfocus.com/bid/75056

PHP 'session.c' Use After Free Remote Code Execution Vulnerability
2017-07-21
http://www.securityfocus.com/bid/92097

SANS News

Black Hat is coming and with it a good reason to update your "Broadcom-based" devices

Malicious .iso Attachments

Threatpost

Trickbot Malware Now Targets US Banks


Motivation Mystery Behind WannaCry, ExPetr

Exploit

NEC UNIVERGE UM4730 < 11.8 - SQL Injection

21.7.2017

Bugtraq

security bulletin] HPESBHF03766 rev.1 - HPE ConvergedSystem 700 Solution with Comware v5 Switches using NTP, Remote Denial of Service (DoS), Unauthorized Modification and Local Denial of Service (DoS) 2017-07-20
security-alert hpe com

File Upload in Integration Gateway (PSIGW) 2017-07-20
ERPScan inc (erpscan online gmail com)

Multiple XSS (POST request) Vulnerabilities in TestServlet (PeopleSoft) 2017-07-20
ERPScan inc (erpscan online gmail com)

Directory Traversal vulnerability in Integration Gateway (PSIGW) 2017-07-20
ERPScan inc (erpscan online gmail com)

APPLE-SA-2017-07-19-7 iCloud for Windows 6.2.2 2017-07-19
Apple Product Security (product-security-noreply lists apple com)

APPLE-SA-2017-07-19-5 Safari 10.1.2 2017-07-19
Apple Product Security (product-security-noreply lists apple com)

APPLE-SA-2017-07-19-2 macOS 10.12.6 2017-07-19
Apple Product Security (product-security-noreply lists apple com)

APPLE-SA-2017-07-19-3 watchOS 3.2.2 2017-07-19
Apple Product Security (product-security-noreply lists apple com)

APPLE-SA-2017-07-19-1 iOS 10.3.3 2017-07-19
Apple Product Security (product-security-noreply lists apple com)

APPLE-SA-2017-07-19-6 iTunes 12.6.2 2017-07-19
Apple Product Security (product-security-noreply lists apple com)

APPLE-SA-2017-07-19-4 tvOS 10.2.2 2017-07-19
Apple Product Security (product-security-noreply lists apple com)

SECURITY] DSA 3914-1] imagemagick security update 2017-07-18
Moritz Muehlenhoff (jmm debian org)

Malware

Backdoor.Rurtar

Phishing

 

Vulnerebility

ISC BIND CVE-2017-3142 Security Bypass Vulnerability
2017-07-21
http://www.securityfocus.com/bid/99339

Sudo CVE-2017-1000368 Incomplete Fix Local Privilege Escalation Vulnerability
2017-07-21
http://www.securityfocus.com/bid/98838

ISC BIND CVE-2017-3143 Security Bypass Vulnerability
2017-07-21
http://www.securityfocus.com/bid/99337

Linux Kernel CVE-2017-7477 Heap Buffer Overflow Vulnerability
2017-07-21
http://www.securityfocus.com/bid/98014

Linux Kernel CVE-2017-1000364 Local Memory Corruption Vulnerability
2017-07-21
http://www.securityfocus.com/bid/99130

Linux Kernel CVE-2017-7645 Multiple Denial of Service Vulnerabilities
2017-07-21
http://www.securityfocus.com/bid/97950

GNU glibc CVE-2017-1000366 Local Memory Corruption Vulnerability
2017-07-21
http://www.securityfocus.com/bid/99127

FreeRADIUS CVE-2017-10981 Denial of Service Vulnerability
2017-07-21
http://www.securityfocus.com/bid/99898

AlienVault Unified Security Management Heap Based Buffer Overflow Vulnerability
2017-07-21
http://www.securityfocus.com/bid/99897

QEMU CVE-2017-11334 Out of Bounds Read and Write Denial of Service Vulnerability
2017-07-21
http://www.securityfocus.com/bid/99895

Palo Alto Networks PAN-OS CVE-2017-9467 Cross Site Scripting Vulnerability
2017-07-20
http://www.securityfocus.com/bid/99907

Palo Alto Networks PAN-OS CVE-2017-9459 HTML Injection Vulnerability
2017-07-20
http://www.securityfocus.com/bid/99902

Multiple CorelDRAW Products Multiple Remote Code Execution Vulnerabilities
2017-07-20
http://www.securityfocus.com/bid/99900

Inmarsat AmosConnect 8 VU#586501 Security Bypass and SQL Injection Vulnerabilities
2017-07-20
http://www.securityfocus.com/bid/99899

Apple iOS and Safari Multiple Security Vulnerabilities
2017-07-20
http://www.securityfocus.com/bid/99887

Apple iOS/TvOS/Safari Multiple Security Vulnerabilities
2017-07-20
http://www.securityfocus.com/bid/99886

WebKit Multiple Memory Corruption Vulnerabilities
2017-07-20
http://www.securityfocus.com/bid/99885

Apple iTunes CVE-2017-7053 Arbitray Code Execution Vulnerability
2017-07-20
http://www.securityfocus.com/bid/99884

Apple macOS APPLE-SA-2017-07-19-2 Multiple Security Vulnerabilities
2017-07-20
http://www.securityfocus.com/bid/99882

Genivia gSOAP CVE-2017-9765 Stack Based Buffer Overflow Vulnerability
2017-07-19
http://www.securityfocus.com/bid/99868

Multiple Intel Products CVE-2017-5689 Privilege Escalation Vulnerability
2017-07-19
http://www.securityfocus.com/bid/98269

OpenSSL CVE-2017-3732 Information Disclosure Vulnerability
2017-07-19
http://www.securityfocus.com/bid/95814

OpenSSL Padding Oracle Incomplete Fix Information Disclosure Vulnerability
2017-07-19
http://www.securityfocus.com/bid/89760

SAP Netweaver Dynpro Engine Denial of Service Vulnerability
2017-07-19
http://www.securityfocus.com/bid/96874

SAP NetWeaver Visual Composer Denial of Service Vulnerability
2017-07-19
http://www.securityfocus.com/bid/96865

SAP NetWeaver ABAP CVE-2017-9843 Denial of Service Vulnerability
2017-07-19
http://www.securityfocus.com/bid/96900

Oracle Java Advanced Management Console CVE-2017-10104 Remote Security Vulnerability
2017-07-19
http://www.securityfocus.com/bid/99797

Apple iOS APPLE-SA-2017-07-19-1 Multiple Security Vulnerabilities
2017-07-19
http://www.securityfocus.com/bid/99891

Apple iTunes/iCloud/Safari/iOS Multiple Security Vulnerabilities
2017-07-19
http://www.securityfocus.com/bid/99890

Apple iOS/iCloud/iTunes/macOS/TvOS CVE-2017-7010 Information Disclosure Vulnerability
2017-07-19
http://www.securityfocus.com/bid/99889

SANS News

 

Threatpost

Senator Calls For Use Of DMARC To Curb Phishing

US, European Law Enforcement Shutter Massive AlphaBay Market

Exploit

Joomla! Component JoomRecipe 1.0.4 - 'search_author' Parameter SQL Injection

WordPress Plugin IBPS Online Exam 1.0 - SQL Injection / Cross-Site Scripting

20.7.2017

Bugtraq

File Upload in Integration Gateway (PSIGW) 2017-07-20
ERPScan inc (erpscan online gmail com)

Multiple XSS (POST request) Vulnerabilities in TestServlet (PeopleSoft) 2017-07-20
ERPScan inc (erpscan online gmail com)

Directory Traversal vulnerability in Integration Gateway (PSIGW) 2017-07-20
ERPScan inc (erpscan online gmail com)

APPLE-SA-2017-07-19-7 iCloud for Windows 6.2.2 2017-07-19
Apple Product Security (product-security-noreply lists apple com)

APPLE-SA-2017-07-19-5 Safari 10.1.2 2017-07-19
Apple Product Security (product-security-noreply lists apple com)

APPLE-SA-2017-07-19-2 macOS 10.12.6 2017-07-19
Apple Product Security (product-security-noreply lists apple com)

APPLE-SA-2017-07-19-3 watchOS 3.2.2 2017-07-19
Apple Product Security (product-security-noreply lists apple com)

APPLE-SA-2017-07-19-1 iOS 10.3.3 2017-07-19
Apple Product Security (product-security-noreply lists apple com)

APPLE-SA-2017-07-19-6 iTunes 12.6.2 2017-07-19
Apple Product Security (product-security-noreply lists apple com)

APPLE-SA-2017-07-19-4 tvOS 10.2.2 2017-07-19
Apple Product Security (product-security-noreply lists apple com)

SECURITY] DSA 3914-1] imagemagick security update 2017-07-18
Moritz Muehlenhoff (jmm debian org)

Malware

 

Phishing

Natwest Bank

18th July 2017

LATE PAYMENT

CapitalOne

17th July 2017

Customer support

Vulnerebility

Apple macOS APPLE-SA-2017-07-19-2 Multiple Security Vulnerabilities
2017-07-20
http://www.securityfocus.com/bid/99882

Genivia gSOAP CVE-2017-9765 Stack Based Buffer Overflow Vulnerability
2017-07-19
http://www.securityfocus.com/bid/99868

Multiple Intel Products CVE-2017-5689 Privilege Escalation Vulnerability
2017-07-19
http://www.securityfocus.com/bid/98269

OpenSSL CVE-2017-3732 Information Disclosure Vulnerability
2017-07-19
http://www.securityfocus.com/bid/95814

OpenSSL Padding Oracle Incomplete Fix Information Disclosure Vulnerability
2017-07-19
http://www.securityfocus.com/bid/89760

SAP Netweaver Dynpro Engine Denial of Service Vulnerability
2017-07-19
http://www.securityfocus.com/bid/96874

SAP NetWeaver Visual Composer Denial of Service Vulnerability
2017-07-19
http://www.securityfocus.com/bid/96865

SAP NetWeaver ABAP CVE-2017-9843 Denial of Service Vulnerability
2017-07-19
http://www.securityfocus.com/bid/96900

Oracle Java Advanced Management Console CVE-2017-10104 Remote Security Vulnerability
2017-07-19
http://www.securityfocus.com/bid/99797

Apple iOS/watchOS CVE-2017-7063 Denial of Service Vulnerability
2017-07-19
http://www.securityfocus.com/bid/99881

Apple iOS/macOS/tvOS CVE-2017-7008 Memory Corruption Vulnerability
2017-07-19
http://www.securityfocus.com/bid/99880

libxml2 CVE-2017-7013 XML External Entity Information Disclosure Vulnerability
2017-07-19
http://www.securityfocus.com/bid/99879

Cisco Prime Collaboration Provisioning Tool CVE-2017-6755 Cross Site Scripting Vulnerability
2017-07-19
http://www.securityfocus.com/bid/99878

Cisco AsyncOS Software CVE-2017-6746 Command Injection Vulnerability
2017-07-19
http://www.securityfocus.com/bid/99877

Cisco Web Security Appliance CVE-2017-6749 HTML Injection Vulnerability
2017-07-19
http://www.securityfocus.com/bid/99875

IBM InfoSphere Master Data Management Server Local Information Disclosure Vulnerability
2017-07-19
http://www.securityfocus.com/bid/99872

Apache Sling API CVE-2016-5394 Cross Site Scripting Vulnerability
2017-07-19
http://www.securityfocus.com/bid/99870

Oracle BI Publisher CVE-2017-10041 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99742

Oracle Java SE CVE-2017-10102 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99712

Oracle Java SE CVE-2017-10096 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99670

PHPMailer CVE-2016-10045 Incomplete Fix Remote Code Execution Vulnerability
2017-07-18
http://www.securityfocus.com/bid/95130

RETIRED: Linux Kernel 'saa7164-bus.c' Local Privilege Escalation Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99175

Apache Sling XSS Protection API CVE-2016-6798 XML External Entity Injection Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99873

Oracle Database Server CVE-2017-10120 Local Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99867

Oracle FLEXCUBE Universal Banking CVE-2017-10071 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99866

Oracle Database Server CVE-2017-10202 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99865

Oracle FLEXCUBE Private Banking CVE-2017-10022 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99864

Oracle Hospitality Applications CVE-2017-10213 Local Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99863

Oracle FLEXCUBE Private Banking CVE-2017-10012 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99862

Oracle Hospitality Applications CVE-2017-10220 Local Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99861

SANS News

 

Threatpost

Tor Project Opens Bounty Program To All Researchers

Modified Versions of Nukebot in Wild Since Source Code Leak

Senator Calls For Use Of DMARC To Curb Phishing

Exploit

Sonicwall Secure Remote Access 8.1.0.2-14sv - Command Injection

Sonicwall < 8.1.0.6-21sv - 'gencsr.cgi' Command Injection (Metasploit)

Netscaler SD-WAN 9.1.2.26.561201 - Command Injection (Metasploit)

Sonicwall < 8.1.0.2-14sv - 'sitecustomization.cgi' Command Injection (Metasploit)

Citrix CloudBridge - 'CAKEPHP' Cookie Command Injection

Linux/x86_64 - Reverse Shell (192.168.1.8:4444) Shellcode (104 bytes)

19.7.2017

Bugtraq

SECURITY] DSA 3914-1] imagemagick security update 2017-07-18
Moritz Muehlenhoff (jmm debian org)

CVE-2017-7728] - Authentication Bypass allows alarm's commands execution in iSmartAlarm 2017-07-13
ilia shnaidman bullguard com

CVE-2017-7684 - Apache OpenMeetings - Insecure File Upload 2017-07-13
Maxim Solodovnik (solomax apache org)

CVE-2017-7663 - Apache OpenMeetings - XSS in chat 2017-07-13
Maxim Solodovnik (solomax apache org)

Malware

SHELLBIND

Phishing

Natwest Bank

18th July 2017

LATE PAYMENT

CapitalOne

17th July 2017

Customer support

Bank of Scotland

16th July 2017

RBS Important Message

Vulnerebility

Multiple Intel Products CVE-2017-5689 Privilege Escalation Vulnerability
2017-07-19
http://www.securityfocus.com/bid/98269

OpenSSL CVE-2017-3732 Information Disclosure Vulnerability
2017-07-19
http://www.securityfocus.com/bid/95814

OpenSSL Padding Oracle Incomplete Fix Information Disclosure Vulnerability
2017-07-19
http://www.securityfocus.com/bid/89760

SAP Netweaver Dynpro Engine Denial of Service Vulnerability
2017-07-19
http://www.securityfocus.com/bid/96874

SAP NetWeaver Visual Composer Denial of Service Vulnerability
2017-07-19
http://www.securityfocus.com/bid/96865

SAP NetWeaver ABAP CVE-2017-9843 Denial of Service Vulnerability
2017-07-19
http://www.securityfocus.com/bid/96900

Oracle Java Advanced Management Console CVE-2017-10104 Remote Security Vulnerability
2017-07-19
http://www.securityfocus.com/bid/99797

Oracle BI Publisher CVE-2017-10041 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99742

Oracle Java SE CVE-2017-10102 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99712

Oracle Java SE CVE-2017-10096 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99670

PHPMailer CVE-2016-10045 Incomplete Fix Remote Code Execution Vulnerability
2017-07-18
http://www.securityfocus.com/bid/95130

RETIRED: Linux Kernel 'saa7164-bus.c' Local Privilege Escalation Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99175

Genivia gSOAP CVE-2017-9765 Stack Based Buffer Overflow Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99868

Oracle Database Server CVE-2017-10120 Local Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99867

Oracle FLEXCUBE Universal Banking CVE-2017-10071 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99866

Oracle Database Server CVE-2017-10202 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99865

Oracle FLEXCUBE Private Banking CVE-2017-10022 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99864

Oracle Hospitality Applications CVE-2017-10213 Local Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99863

Oracle FLEXCUBE Private Banking CVE-2017-10012 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99862

Oracle Hospitality Applications CVE-2017-10220 Local Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99861

Oracle FLEXCUBE Universal Banking CVE-2017-10072 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99860

Oracle Solaris Cluster CVE-2017-10234 Local Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99859

Oracle Hospitality Applications CVE-2017-10200 Local Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99858

Oracle Solaris CVE-2017-3632 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99857

Oracle FLEXCUBE Universal Banking CVE-2017-10098 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99856

Oracle Sun ZFS Storage Appliance Kit CVE-2017-10016 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99855

Oracle Java SE CVE-2017-10193 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99854

Oracle Java SE CVE-2017-10081 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99853

Oracle Solaris CVE-2017-10122 Local Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99852

Oracle Java SE CVE-2017-10105 Remote Security Vulnerability
2017-07-18
http://www.securityfocus.com/bid/99851

SANS News

Bots Searching for Keys & Config Files

Threatpost

Botnet Tweeting, Spamming Porn Shut Down

Privacy Activists Suffer Legal Setback In National Security Letter Case

CoinDash Hacked During its ICO

Oracle Releases Biggest Update Ever: 308 Vulnerabilities Patched

Exploit

Microsoft Internet Explorer 11.0.9600.18617 - 'CMarkup::DestroySplayTree' Memory...

Microsoft Internet Explorer 11.1066.14393.0 - VBScript Arithmetic Functions Type...

Microsoft Windows Kernel - 'IOCTL 0x120007 (NsiGetParameter)' nsiproxy/netio Pool...

Hashicorp vagrant-vmware-fusion <= 4.0.20 - Local root Privilege Esclation

PEGA Platform <= 7.2 ML0 - Missing Access Control / Cross-Site Scripting

18.7.2017

Bugtraq

 

Malware

Ransom.Shifr

Phishing

CapitalOne

17th July 2017

Customer support

Bank of Scotland

16th July 2017

RBS Important Message

MRS. CARMAN LAPOINTE

16th July 2017

UNITED NATIONS OFFICE OF
INTERNATIONAL OVERSIGHT
SERVICES

Vulnerebility

Apache Struts Spring AOP Functionality Denial of Service Vulnerability
2017-07-17
http://www.securityfocus.com/bid/99562

QEMU CVE-2017-9503 Denial of Service Vulnerability
2017-07-17
http://www.securityfocus.com/bid/99010

QEMU 'hw/usb/hcd-xhci.c' Denial of Service Vulnerability
2017-07-17
http://www.securityfocus.com/bid/98915

QEMU CVE-2017-9373 Denial of Service Vulnerability
2017-07-17
http://www.securityfocus.com/bid/98921

QEMU CVE-2017-9374 Denial of Service Vulnerability
2017-07-17
http://www.securityfocus.com/bid/98905

QEMU CVE-2017-8379 Denial of Service Vulnerability
2017-07-17
http://www.securityfocus.com/bid/98277

QEMU 'megasas_mmio_write()' Function Out-of-Bounds Read Vulnerability
2017-07-17
http://www.securityfocus.com/bid/98303

QEMU CVE-2017-8309 Denial of Service Vulnerability

SANS News

Investigation of BitTorrent Sync (v.2.0) as a P2P Cloud Service (Part 4 ? Windows Thumbnail Cache, Registry, Prefetch Files, and Link Files artefacts)

Threatpost

FreeRADIUS Update Patches Bugs Static Analysis Tools Missed

Cisco Patches Another Critical Ormandy Bug in WebEx Extension

Botnet Tweeting, Spamming Porn Shut Down

Exploit

Belkin NetCam F7D7601 - Multiple Vulnerabilities

Sophos Web Appliance 4.3.0.2 - 'trafficType' Remote Command Injection (Metasploit)

Barracuda Load Balancer Firmware <= 6.0.1.006 - Remote Command Injection...

17.7.2017

Bugtraq

 

Malware

 

Phishing

Bank of Scotland

16th July 2017

RBS Important Message

MRS. CARMAN LAPOINTE

16th July 2017

UNITED NATIONS OFFICE OF
INTERNATIONAL OVERSIGHT
SERVICES

Chase

16th July 2017

Request to update your details
with Chase Today!

Vulnerebility

Apache Struts Spring AOP Functionality Denial of Service Vulnerability
2017-07-17
http://www.securityfocus.com/bid/99562

QEMU CVE-2017-9503 Denial of Service Vulnerability
2017-07-17
http://www.securityfocus.com/bid/99010

QEMU 'hw/usb/hcd-xhci.c' Denial of Service Vulnerability
2017-07-17
http://www.securityfocus.com/bid/98915

QEMU CVE-2017-9373 Denial of Service Vulnerability
2017-07-17
http://www.securityfocus.com/bid/98921

QEMU CVE-2017-9374 Denial of Service Vulnerability
2017-07-17
http://www.securityfocus.com/bid/98905

QEMU CVE-2017-8379 Denial of Service Vulnerability
2017-07-17
http://www.securityfocus.com/bid/98277

QEMU 'megasas_mmio_write()' Function Out-of-Bounds Read Vulnerability
2017-07-17
http://www.securityfocus.com/bid/98303

QEMU CVE-2017-8309 Denial of Service Vulnerability
2017-07-17
http://www.securityfocus.com/bid/98302

Qemu 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-07-17
http://www.securityfocus.com/bid/97955

QEMU 'hw/9pfs/9p-local.c' Privilege Escalation Vulnerability
2017-07-17
http://www.securityfocus.com/bid/97970

QEMU CVE-2017-8086 Denial of Service Vulnerability
2017-07-17
http://www.securityfocus.com/bid/98012

QEMU 'hw/9pfs/9p.c' Multiple Denial of Service Vulnerabilities
2017-07-17
http://www.securityfocus.com/bid/97319

QEMU 'hw/sd/sdhci.c' Denial of Service Vulnerability
2017-07-17
http://www.securityfocus.com/bid/96263

QEMU 'hw/usb/hcd-ohci.c' Denial of Service Vulnerability
2017-07-17
http://www.securityfocus.com/bid/96611

QEMU CVE-2017-8112 Denial of Service Vulnerability
2017-07-17
http://www.securityfocus.com/bid/98015

QEMU 'hw/display/cirrus_vga_rop.h' Multiple Memory Corruption Vulnerabilities
2017-07-17
http://www.securityfocus.com/bid/97957

QEMU CVE-2016-9603 Heap Buffer Overflow Vulnerability
2017-07-17
http://www.securityfocus.com/bid/96893

QEMU 'hw/usb/hcd-xhci.c' Denial of Service Vulnerability
2017-07-17
http://www.securityfocus.com/bid/96220

QEMU CVE-2016-9602 Privilege Escalation Vulnerability
2017-07-17
http://www.securityfocus.com/bid/95461

QEMU CVE-2017-5579 Denial of Service Vulnerability
2017-07-17
http://www.securityfocus.com/bid/95780

Heimdal CVE-2017-11103 Man in the Middle Security Bypass Vulnerability
2017-07-17
http://www.securityfocus.com/bid/99551

phpCAS CVE-2017-1000071 Authentication Bypass Vulnerability
2017-07-17
http://www.securityfocus.com/bid/99609

radare2 CVE-2017-10929 Heap Buffer Overflow Vulnerability
2017-07-17
http://www.securityfocus.com/bid/99608

Moodle CVE-2017-2642 Information Disclosure Vulnerability
2017-07-17
http://www.securityfocus.com/bid/99606

ImageMagick 'coders/rle.c' Incomplete Fix Denial of Service Vulnerability
2017-07-17
http://www.securityfocus.com/bid/99600

Rpcbind CVE-2017-8779 Remote Denial of Service Vulnerability
2017-07-16
http://www.securityfocus.com/bid/98325

ATutor Multiple Security Vulnerabilities
2017-07-16
http://www.securityfocus.com/bid/99599

Microsoft Windows COM CVE-2017-0298 Local Privilege Escalation Vulnerability
2017-07-14
http://www.securityfocus.com/bid/98841

PHPMailer CVE-2016-10045 Incomplete Fix Remote Code Execution Vulnerability
2017-07-14
http://www.securityfocus.com/bid/95130

Knot DNS CVE-2017-11104 Authentication Bypass Vulnerability
2017-07-14
http://www.securityfocus.com/bid/99598

SANS News

SMS Phishing induces victims to photograph its own token card

Threatpost

 

Exploit

FTPGetter 5.89.0.85 - Buffer Overflow (SEH)

Orangescrum 1.6.1 - Multiple Vulnerabilities

16.7.2017

Bugtraq

CVE-2017-7728] - Authentication Bypass allows alarm's commands execution in iSmartAlarm 2017-07-13
ilia shnaidman bullguard com

CVE-2017-7684 - Apache OpenMeetings - Insecure File Upload 2017-07-13
Maxim Solodovnik (solomax apache org)

CVE-2017-7663 - Apache OpenMeetings - XSS in chat 2017-07-13
Maxim Solodovnik (solomax apache org)

CVE-2017-7688 - Apache OpenMeetings - Insecure Password Update 2017-07-13
Maxim Solodovnik (solomax apache org)

CVE-2017-7664 - Apache OpenMeetings - Missing XML Validation 2017-07-13
Maxim Solodovnik (solomax666 gmail com)

CVE-2017-9788: Uninitialized memory reflection in mod_auth_digest 2017-07-13
William A Rowe Jr (wrowe apache org)

CVE-2017-9789: Apache httpd 2.4 Read after free in mod_http2 2017-07-13
William A Rowe Jr (wrowe apache org)

SECURITY] DSA 3908-1] nginx security update 2017-07-12
Moritz Muehlenhoff (jmm debian org)

Malware

 

Phishing

Bank of Scotland

16th July 2017

RBS Important Message

MRS. CARMAN LAPOINTE

16th July 2017

UNITED NATIONS OFFICE OF
INTERNATIONAL OVERSIGHT
SERVICES

Chase

16th July 2017

Request to update your details
with Chase Today!

Chase

14th July 2017

Help us protect your Chase
Account

Microsoft

14th July 2017

Important Message From BB
PADDING-TOP: 10px;
PADDING-LEFT: 10px;
PADDING-RIGHT: 10px">

MR. IBRAHIM CISSOKO

14th July 2017

Re: Partnership Request

eBay

14th July 2017

This eBay member has a
question regarding your item
for sale.

Vulnerebility

Microsoft Windows COM CVE-2017-0298 Local Privilege Escalation Vulnerability
2017-07-14
http://www.securityfocus.com/bid/98841

PHPMailer CVE-2016-10045 Incomplete Fix Remote Code Execution Vulnerability
2017-07-14
http://www.securityfocus.com/bid/95130

Juniper ScreenOS Multiple HTML Injection Vulnerabilities
2017-07-14
http://www.securityfocus.com/bid/99590

Apache OpenMeetings CVE-2017-7684 Denial of Service Vulnerability
2017-07-14
http://www.securityfocus.com/bid/99584

Oracle July 2017 Critical Patch Update Multiple Vulnerabilities
2017-07-14
http://www.securityfocus.com/bid/99579

NTP CVE-2017-6462 Local Buffer Overflow Vulnerability
2017-07-13
http://www.securityfocus.com/bid/97045

NTP CVE-2017-6451 Local Denial of Service Vulnerability
2017-07-13
http://www.securityfocus.com/bid/97058

NTP CVE-2017-6464 Denial of Service Vulnerability
2017-07-13
http://www.securityfocus.com/bid/97050

NTP CVE-2017-6458 Buffer Overflow Vulnerability
2017-07-13
http://www.securityfocus.com/bid/97051

Microsoft Windows CVE-2014-4114 OLE Package Manager Remote Code Execution Vulnerability
2017-07-13
http://www.securityfocus.com/bid/70419

Microsoft Office CVE-2015-1641 Memory Corruption Vulnerability
2017-07-13
http://www.securityfocus.com/bid/73995

Microsoft Windows Kernel 'Win32k.sys' CVE-2016-7255 Local Privilege Escalation Vulnerability
2017-07-13
http://www.securityfocus.com/bid/94064

Heimdal CVE-2017-11103 Man in the Middle Security Bypass Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99551

Microsoft Windows CVE-2017-0170 XML External Entity Local Information Disclosure Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99398

Apache OpenMeetings CVE-2017-7673 Security Bypass Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99587

Apache OpenMeetings CVE-2017-7688 Security Bypass Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99586

ImageMagick CVE-2017-11310 Denial of Service Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99585

Siemens SIMATIC WinCC Sm@rtClient for Android ICSA-17-194-03 Multiple Security Vulnerabilities
2017-07-13
http://www.securityfocus.com/bid/99582

GE Communicator CVE-2017-7908 Heap Based Buffer Overflow Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99580

Siemens SiPass integrated ICSA-17-194-01 Multiple Security Vulnerabilities
2017-07-13
http://www.securityfocus.com/bid/99578

Apache OpenMeetings CVE-2017-7663 Cross Site Scripting Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99577

Apache OpenMeetings CVE-2017-7664 XML External Entity Injection Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99576

Jenkins Subversion Plugin CVE-2017-1000085 Cross Site Request Forgery Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99574

GNU Binutils CVE-2017-9955 Multiple Heap Based Buffer Overflow Vulnerabilities
2017-07-13
http://www.securityfocus.com/bid/99573

Jenkins Pipeline: Groovy Plugin CVE-2017-1000096 Remote Code Execution Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99571

Trend Micro Deep Discovery Director Multiple Security Vulnerabilities
2017-07-13
http://www.securityfocus.com/bid/99570

Apache HTTP Server CVE-2017-9789 Denial of Service Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99568

Juniper Junos CVE-2017-2345 Denial of Service Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99567

Apache Struts CVE-2017-7672 Denial of Service Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99563

Apache Struts Spring AOP Functionality Denial of Service Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99562

SANS News

Office maldoc + .lnk

Threatpost

Experts Warn Too Often AWS S3 Buckets Are Misconfigured, Leak Data

Cisco Patches Publicly Disclosed SNMP Vulnerabilities in IOS, IOS XE

Siemens Patches Authentication Bypass Flaw in SiPass Server

NemucodAES Ransomware, Kovter Click-Fraud Malware Spreading in Same Campaigns

Exploit

Firefox 50.0.1 - ASM.JS JIT-Spray Remote Code Execution

Apache Struts 2.3.x Showcase - Remote Code Execution (PoC)

WDTV Live SMP 2.03.20 - Remote Password Reset

Counter Strike: Condition Zero - '.BSP' Map File Code Execution

13.7.2017

Bugtraq

CVE-2017-7728] - Authentication Bypass allows alarm's commands execution in iSmartAlarm 2017-07-13
ilia shnaidman bullguard com

CVE-2017-7684 - Apache OpenMeetings - Insecure File Upload 2017-07-13
Maxim Solodovnik (solomax apache org)

CVE-2017-7663 - Apache OpenMeetings - XSS in chat 2017-07-13
Maxim Solodovnik (solomax apache org)

CVE-2017-7688 - Apache OpenMeetings - Insecure Password Update 2017-07-13
Maxim Solodovnik (solomax apache org)

CVE-2017-7664 - Apache OpenMeetings - Missing XML Validation 2017-07-13
Maxim Solodovnik (solomax666 gmail com)

CVE-2017-9788: Uninitialized memory reflection in mod_auth_digest 2017-07-13
William A Rowe Jr (wrowe apache org)

CVE-2017-9789: Apache httpd 2.4 Read after free in mod_http2 2017-07-13
William A Rowe Jr (wrowe apache org)

SECURITY] DSA 3908-1] nginx security update 2017-07-12
Moritz Muehlenhoff (jmm debian org)

Malware

 

Phishing

eBay

14th July 2017

This eBay member has a
question regarding your item
for sale.

U.S. Bank

13th July 2017

REQUEST TO UPDATE YOUR U.S.
BANK ACCOUNT INFORMATION!

CapitalOne

13th July 2017

Customer support

Vulnerebility

Microsoft Windows COM CVE-2017-0298 Local Privilege Escalation Vulnerability
2017-07-14
http://www.securityfocus.com/bid/98841

PHPMailer CVE-2016-10045 Incomplete Fix Remote Code Execution Vulnerability
2017-07-14
http://www.securityfocus.com/bid/95130

Juniper ScreenOS Multiple HTML Injection Vulnerabilities
2017-07-14
http://www.securityfocus.com/bid/99590

Apache OpenMeetings CVE-2017-7684 Denial of Service Vulnerability
2017-07-14
http://www.securityfocus.com/bid/99584

Oracle July 2017 Critical Patch Update Multiple Vulnerabilities
2017-07-14
http://www.securityfocus.com/bid/99579

NTP CVE-2017-6462 Local Buffer Overflow Vulnerability
2017-07-13
http://www.securityfocus.com/bid/97045

NTP CVE-2017-6451 Local Denial of Service Vulnerability
2017-07-13
http://www.securityfocus.com/bid/97058

NTP CVE-2017-6464 Denial of Service Vulnerability
2017-07-13
http://www.securityfocus.com/bid/97050

NTP CVE-2017-6458 Buffer Overflow Vulnerability
2017-07-13
http://www.securityfocus.com/bid/97051

Microsoft Windows CVE-2014-4114 OLE Package Manager Remote Code Execution Vulnerability
2017-07-13
http://www.securityfocus.com/bid/70419

Microsoft Office CVE-2015-1641 Memory Corruption Vulnerability
2017-07-13
http://www.securityfocus.com/bid/73995

Microsoft Windows Kernel 'Win32k.sys' CVE-2016-7255 Local Privilege Escalation Vulnerability
2017-07-13
http://www.securityfocus.com/bid/94064

Heimdal CVE-2017-11103 Man in the Middle Security Bypass Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99551

Microsoft Windows CVE-2017-0170 XML External Entity Local Information Disclosure Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99398

Apache OpenMeetings CVE-2017-7673 Security Bypass Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99587

Apache OpenMeetings CVE-2017-7688 Security Bypass Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99586

ImageMagick CVE-2017-11310 Denial of Service Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99585

Siemens SIMATIC WinCC Sm@rtClient for Android ICSA-17-194-03 Multiple Security Vulnerabilities
2017-07-13
http://www.securityfocus.com/bid/99582

GE Communicator CVE-2017-7908 Heap Based Buffer Overflow Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99580

Siemens SiPass integrated ICSA-17-194-01 Multiple Security Vulnerabilities
2017-07-13
http://www.securityfocus.com/bid/99578

Apache OpenMeetings CVE-2017-7663 Cross Site Scripting Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99577

Apache OpenMeetings CVE-2017-7664 XML External Entity Injection Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99576

Jenkins Subversion Plugin CVE-2017-1000085 Cross Site Request Forgery Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99574

GNU Binutils CVE-2017-9955 Multiple Heap Based Buffer Overflow Vulnerabilities
2017-07-13
http://www.securityfocus.com/bid/99573

Jenkins Pipeline: Groovy Plugin CVE-2017-1000096 Remote Code Execution Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99571

Trend Micro Deep Discovery Director Multiple Security Vulnerabilities
2017-07-13
http://www.securityfocus.com/bid/99570

Apache HTTP Server CVE-2017-9789 Denial of Service Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99568

Juniper Junos CVE-2017-2345 Denial of Service Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99567

Apache Struts CVE-2017-7672 Denial of Service Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99563

Apache Struts Spring AOP Functionality Denial of Service Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99562

SANS News

NemucodAES and the malspam that distributes it

Threatpost

Google Changes How it Analyzes Misbehaving Mobile Apps

Attackers Using Automated Scans to Takeover WordPress Installs

Scanner Shows EternalBlue Vulnerability Unpatched on Thousands of Machines

Exploit

Dasan Networks GPON ONT WiFi Router H64X Series - Authentication Bypass

Dasan Networks GPON ONT WiFi Router H64X Series - Cross-Site Request Forgery

Dasan Networks GPON ONT WiFi Router H64X Series - Privilege Escalation

Dasan Networks GPON ONT WiFi Router H64X Series - Configuration Download

13.7.2017

Bugtraq

CVE-2017-9788: Uninitialized memory reflection in mod_auth_digest 2017-07-13
William A Rowe Jr (wrowe apache org)

CVE-2017-9789: Apache httpd 2.4 Read after free in mod_http2 2017-07-13
William A Rowe Jr (wrowe apache org)

SECURITY] DSA 3908-1] nginx security update 2017-07-12
Moritz Muehlenhoff (jmm debian org)

SEC Consult SA-20170712-0 :: Multiple critical vulnerabilities in AGFEO smart home ES 5xx/6xx products 2017-07-12
SEC Consult Vulnerability Lab (research sec-consult com)

CVE request]linux kernel xfrm migrate out-of-bound access 2017-07-11
bo Zhang (zhangbo5891001 gmail com)

RT-SA-2017-011] Remote Command Execution in PDNS Manager 2017-07-11
RedTeam Pentesting GmbH (release redteam-pentesting de)

Malware

Ransom.Karo

Infostealer.Neupos

Backdoor.Goodor

Backdoor.Dorshel

Phishing

CapitalOne

13th July 2017

Customer support

noreply

12th July 2017

UPDATE YOUR ACCOUNT.

Natwest

12th July 2017

IMPORTANT INFORMATION FROM
NATWEST

Vulnerebility

Microsoft Windows CVE-2014-4114 OLE Package Manager Remote Code Execution Vulnerability
2017-07-13
http://www.securityfocus.com/bid/70419

Microsoft Office CVE-2015-1641 Memory Corruption Vulnerability
2017-07-13
http://www.securityfocus.com/bid/73995

Microsoft Windows Kernel 'Win32k.sys' CVE-2016-7255 Local Privilege Escalation Vulnerability
2017-07-13
http://www.securityfocus.com/bid/94064

Heimdal CVE-2017-11103 Man in the Middle Security Bypass Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99551

Microsoft Windows CVE-2017-0170 XML External Entity Local Information Disclosure Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99398

Apache HTTP Server CVE-2017-9789 Denial of Service Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99568

Juniper Junos CVE-2017-2345 Denial of Service Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99567

Apache Struts CVE-2017-7672 Denial of Service Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99563

Apache Struts Spring AOP Functionality Denial of Service Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99562

McAfee Advanced Threat Defense CVE-2017-4053 Command Injection Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99560

Juniper Junos CVE-2017-2344 Local Buffer Overflow Vulnerability
2017-07-13
http://www.securityfocus.com/bid/99556

Microsoft Office OLE Feature Remote Code Execution Vulnerability
2017-07-12
http://www.securityfocus.com/bid/97498

Microsoft Office CVE-2017-0262 Remote Code Execution Vulnerability
2017-07-12
http://www.securityfocus.com/bid/98279

Microsoft Windows Kernel 'Win32k.sys' CVE-2017-0263 Local Privilege Escalation Vulnerability
2017-07-12
http://www.securityfocus.com/bid/98258

X.Org X Server CVE-2017-10972 Information Disclosure Vulnerability
2017-07-12
http://www.securityfocus.com/bid/99543

Adobe Flash Player CVE-2017-3100 Information Disclosure Vulnerability
2017-07-12
http://www.securityfocus.com/bid/99523

Adobe Flash Player CVE-2017-3099 Remote Memory Corruption Vulnerability
2017-07-12
http://www.securityfocus.com/bid/99520

Adobe Flash Player CVE-2017-3080 Information Disclosure Vulnerability
2017-07-12
http://www.securityfocus.com/bid/99519

SAP NetWeaver Unspecified Security Bypass Vulnerability
2017-07-12
http://www.securityfocus.com/bid/96875

ImageMagick CVE-2017-11188 Denial of Service Vulnerability
2017-07-12
http://www.securityfocus.com/bid/99566

IBM Daeja ViewONE CVE-2017-1308 Arbitrary File Download Vulnerability
2017-07-12
http://www.securityfocus.com/bid/99549

Multiple IBM Products CVE-2016-8964 Brute Force Authentication Bypass Vulnerability
2017-07-12
http://www.securityfocus.com/bid/99548

IBM Emptoris Sourcing Multiple Cross Site Scripting and Open Redirection Vulnerabilities
2017-07-12
http://www.securityfocus.com/bid/99545

IBM Emptoris Spend Analysis Multiple Cross Site Scripting Vulnerabilities
2017-07-12
http://www.securityfocus.com/bid/99541

Microsoft Windows Kernel CVE-2016-3305 Local Privilege Escalation Vulnerability
2017-07-11
http://www.securityfocus.com/bid/92812

Microsoft Windows Search CVE-2017-8589 Remote Code Execution Vulnerability
2017-07-11
http://www.securityfocus.com/bid/99425

Siemens EN100 Ethernet Module CVE-2016-7113 Denial of Service Vulnerability
2017-07-11
http://www.securityfocus.com/bid/92748

Multiple Siemens SIPROTEC Products EN100 Module CVE-2015-5374 Denial of Service Vulnerability
2017-07-11
http://www.securityfocus.com/bid/75948

Siemens EN100 Ethernet Module CVE-2016-7114 Authentication Bypass Vulnerability
2017-07-11
http://www.securityfocus.com/bid/92745

Siemens EN100 Ethernet Module CVE-2016-7112 Authentication Bypass Vulnerability
2017-07-11
http://www.securityfocus.com/bid/92747

SANS News

Investigation of BitTorrent Sync (v.2.0) as a P2P Cloud Service (Part 3 ? Physical Memory artefacts)

Threatpost

SAP Patches High-Risk Flaws in SAP POS, Host Agent

Uber Patches Authentication Bypass Vulnerability on Custom SSO Solution

New Point-of-Sale Malware LockPoS Hitches Ride with FlokiBot

Third Party Exposes 14 Million Verizon Customer Records

Exploit

Skype for Business 2016 - Cross-Site Scripting

Dasan Networks GPON ONT WiFi Router H64X Series - Authentication Bypass

Dasan Networks GPON ONT WiFi Router H64X Series - Cross-Site Request Forgery

Dasan Networks GPON ONT WiFi Router H64X Series - Privilege Escalation

Dasan Networks GPON ONT WiFi Router H64X Series - Configuration Download

12.7.2017

Bugtraq

SEC Consult SA-20170712-0 :: Multiple critical vulnerabilities in AGFEO smart home ES 5xx/6xx products 2017-07-12
SEC Consult Vulnerability Lab (research sec-consult com)

CVE request]linux kernel xfrm migrate out-of-bound access 2017-07-11
bo Zhang (zhangbo5891001 gmail com)

RT-SA-2017-011] Remote Command Execution in PDNS Manager 2017-07-11
RedTeam Pentesting GmbH (release redteam-pentesting de)

CVE-2017-4918: Code Injection in VMware Horizonâ??s macOS Client 2017-07-10
Florian Bogner (florian bogner sh)

security bulletin] HPESBGN03763 rev.1 - HPE SiteScope, Disclosure of Sensitive Information, Bypass Security Restriction, Remote Arbitrary Code Execution 2017-07-10
HPE Product Security Response Team (security-alert hpe com)

security bulletin] HPESBGN03762 rev.1 - HPE Network Node Manager i (NNMi) Software, Remote Bypass Security Restrictions, Cross-Site Scripting (XSS), URL Redirection 2017-07-10
HPE Product Security Response Team (security-alert hpe com)

Malware

 

Phishing

noreply

12th July 2017

UPDATE YOUR ACCOUNT.

Natwest

12th July 2017

IMPORTANT INFORMATION FROM
NATWEST

Vulnerebility

Microsoft Office OLE Feature Remote Code Execution Vulnerability
2017-07-12
http://www.securityfocus.com/bid/97498

Microsoft Office CVE-2017-0262 Remote Code Execution Vulnerability
2017-07-12
http://www.securityfocus.com/bid/98279

Microsoft Windows Kernel 'Win32k.sys' CVE-2017-0263 Local Privilege Escalation Vulnerability
2017-07-12
http://www.securityfocus.com/bid/98258

X.Org X Server CVE-2017-10972 Information Disclosure Vulnerability
2017-07-12
http://www.securityfocus.com/bid/99543

Adobe Flash Player CVE-2017-3100 Information Disclosure Vulnerability
2017-07-12
http://www.securityfocus.com/bid/99523

Adobe Flash Player CVE-2017-3099 Remote Memory Corruption Vulnerability
2017-07-12
http://www.securityfocus.com/bid/99520

Adobe Flash Player CVE-2017-3080 Information Disclosure Vulnerability
2017-07-12
http://www.securityfocus.com/bid/99519

SAP NetWeaver Unspecified Security Bypass Vulnerability
2017-07-12
http://www.securityfocus.com/bid/96875

Heimdal CVE-2017-11103 Man in the Middle Security Bypass Vulnerability
2017-07-12
http://www.securityfocus.com/bid/99551

IBM Daeja ViewONE CVE-2017-1308 Arbitrary File Download Vulnerability
2017-07-12
http://www.securityfocus.com/bid/99549

Multiple IBM Products CVE-2016-8964 Brute Force Authentication Bypass Vulnerability
2017-07-12
http://www.securityfocus.com/bid/99548

IBM Emptoris Sourcing Multiple Cross Site Scripting and Open Redirection Vulnerabilities
2017-07-12
http://www.securityfocus.com/bid/99545

Microsoft Windows Kernel CVE-2016-3305 Local Privilege Escalation Vulnerability
2017-07-11
http://www.securityfocus.com/bid/92812

Microsoft Windows Search CVE-2017-8589 Remote Code Execution Vulnerability
2017-07-11
http://www.securityfocus.com/bid/99425

Siemens EN100 Ethernet Module CVE-2016-7113 Denial of Service Vulnerability
2017-07-11
http://www.securityfocus.com/bid/92748

Multiple Siemens SIPROTEC Products EN100 Module CVE-2015-5374 Denial of Service Vulnerability
2017-07-11
http://www.securityfocus.com/bid/75948

Siemens EN100 Ethernet Module CVE-2016-7114 Authentication Bypass Vulnerability
2017-07-11
http://www.securityfocus.com/bid/92745

Siemens EN100 Ethernet Module CVE-2016-7112 Authentication Bypass Vulnerability
2017-07-11
http://www.securityfocus.com/bid/92747

Multiple Siemens SIPROTEC Products ICSA-16-140-02 Information Disclosure Vulnerabilities
2017-07-11
http://www.securityfocus.com/bid/90773

Fuji Electric V-Server CVE-2017-9639 Memory Corruption Vulnerability
2017-07-11
http://www.securityfocus.com/bid/99544

OSIsoft PI Coresight CVE-2017-9641 Cross Site Request Forgery Vulnerability
2017-07-11
http://www.securityfocus.com/bid/99540

Siemens SIMATIC Logon CVE-2017-9938 Out of Bounds Write Denial of Service Vulnerability
2017-07-11
http://www.securityfocus.com/bid/99539

Schweitzer Engineering Laboratories SEL-3620/3622 CVE-2017-7928 Unauthorized Access Vulnerability
2017-07-11
http://www.securityfocus.com/bid/99536

Nginx CVE-2017-7529 Remote Integer Overflow Vulnerability
2017-07-11
http://www.securityfocus.com/bid/99534

Microsoft Exchange Server CVE-2017-8621 Open Redirection Vulnerability
2017-07-11
http://www.securityfocus.com/bid/99533

SAP Customer Relationship Management (CRM) Cross Site Scripting Vulnerability
2017-07-11
http://www.securityfocus.com/bid/99532

SAP Point of Sale (POS) Retail Xpress Server Authentication Bypass Vulnerability
2017-07-11
http://www.securityfocus.com/bid/99531

SAP BusinessObjects Enterprise Information Disclosure Vulnerability
2017-07-11
http://www.securityfocus.com/bid/99530

SAP Netweaver Data Orchestration Engine Unspecified Information Disclosure Vulnerability
2017-07-11
http://www.securityfocus.com/bid/99529

SAP Host Agent Unspecified Denial of Service Vulnerability
2017-07-11
http://www.securityfocus.com/bid/99528

SANS News

July's Microsoft Patch Tuesday

Backup Scripts, the FIM of the Poor

Threatpost

Adobe Fixes Six Vulnerabilities in Flash, Connect with July Update

Microsoft Addresses NTLM Bugs That Facilitate Credential Relay Attacks

Microsoft Patch Tuesday Update Fixes 19 Critical Vulnerabilities

Exploit

 

11.7.2017

Bugtraq

security bulletin] HPESBGN03763 rev.1 - HPE SiteScope, Disclosure of Sensitive Information, Bypass Security Restriction, Remote Arbitrary Code Execution 2017-07-10
HPE Product Security Response Team (security-alert hpe com)

security bulletin] HPESBGN03762 rev.1 - HPE Network Node Manager i (NNMi) Software, Remote Bypass Security Restrictions, Cross-Site Scripting (XSS), URL Redirection 2017-07-10
HPE Product Security Response Team (security-alert hpe com)

security bulletin] HPESBHF03745 rev.2 - HPE Intelligent Management Center (iMC) PLAT, Remote Code Execution 2017-07-10
HPE Product Security Response Team (security-alert hpe com)

security bulletin] HPESBNS03755 rev.1 - HPE NonStop Server using Samba, Multiple Remote Vulnerabilities 2017-07-10
HPE Product Security Response Team (security-alert hpe com)

CVE-2017-5640 Apache Impala (incubating) Information Disclosure 2017-07-10
Sailesh Mukil (sailesh apache org)

SECURITY] CVE-2017-5652 Apache Impala (incubating) Information Disclosure 2017-07-10
Sailesh Mukil (sailesh apache org)

ToorCon 19 Call For Papers Closing This Week! 2017-07-10
h1kari toorcon org

Malware

Ransom:Win32/Enestaller 
Ransom:Win32/Enestedel 

Trojan.Listrix

SoftwareBundler:Win32/FileTour

Phishing

 

Vulnerebility

Siemens EN100 Ethernet Module CVE-2016-7113 Denial of Service Vulnerability
2017-07-11
http://www.securityfocus.com/bid/92748

Multiple Siemens SIPROTEC Products EN100 Module CVE-2015-5374 Denial of Service Vulnerability
2017-07-11
http://www.securityfocus.com/bid/75948

Siemens EN100 Ethernet Module CVE-2016-7114 Authentication Bypass Vulnerability
2017-07-11
http://www.securityfocus.com/bid/92745

Siemens EN100 Ethernet Module CVE-2016-7112 Authentication Bypass Vulnerability
2017-07-11
http://www.securityfocus.com/bid/92747

Multiple Siemens SIPROTEC Products ICSA-16-140-02 Information Disclosure Vulnerabilities
2017-07-11
http://www.securityfocus.com/bid/90773

RETIRED:Siemens EN100 Ethernet Modules for Reyrolle ICSA-17-187-02 Multiple Security Vulnerabilities
2017-07-10
http://www.securityfocus.com/bid/99471

Apache Struts CVE-2017-9791 Remote Code Execution Vulnerability
2017-07-10
http://www.securityfocus.com/bid/99484

VLAN VLC CVE-2017-8313 Denial of Service Vulnerability
2017-07-10
http://www.securityfocus.com/bid/98633

VLAN VLC CVE-2017-8310 Denial of Service Vulnerability
2017-07-10
http://www.securityfocus.com/bid/98638

VideoLAN VLC CVE-2017-8311 Heap Based Buffer Overflow Vulnerability
2017-07-10
http://www.securityfocus.com/bid/98634

VideoLAN VLC CVE-2017-8312 Information Disclosure Vulnerability
2017-07-10
http://www.securityfocus.com/bid/98631

RoundCube Webmail CVE-2017-8114 Multiple Privilege Escalation Vulnerabilities
2017-07-10
http://www.securityfocus.com/bid/98445

Ubuntu Vivid CVE-2015-1336 Local Privilege Escalation Vulnerability
2017-07-10
http://www.securityfocus.com/bid/79723

WordPress Shortcodes Ultimate Plugin CVE-2017-2245 Directory Traversal Vulnerability
2017-07-10
http://www.securityfocus.com/bid/99495

PHP 'gd_gif_in.c' Memory Corruption Vulnerability
2017-07-10
http://www.securityfocus.com/bid/99492

PHP 'finish_nested_data()' Function Heap Buffer Overflow Vulnerability
2017-07-10
http://www.securityfocus.com/bid/99490

PHP 'zend_ini_do_op()' Function Stack Buffer Overflow Vulnerability
2017-07-10
http://www.securityfocus.com/bid/99489

ImageMagick CVE-2017-11141 Denial of Service Vulnerability
2017-07-09
http://www.securityfocus.com/bid/99506

GraphicsMagick CVE-2017-11139 Multiple Denial of Service Vulnerabilities
2017-07-09
http://www.securityfocus.com/bid/99504

GraphicsMagick 'coders/jpeg.c' Denial of Service Vulnerability
2017-07-09
http://www.securityfocus.com/bid/99503

SQLite CVE-2017-10989 Heap Buffer Overflow Vulnerability
2017-07-07
http://www.securityfocus.com/bid/99502

GraphicsMagick 'coders/png.c' Denial of Service Vulnerability
2017-07-07
http://www.securityfocus.com/bid/99498

Poppler PDF Library Multiple Heap Buffer Overflow and Integer Overflow Vulnerabilities
2017-07-07
http://www.securityfocus.com/bid/99497

ImageMagick CVE-2017-10995 Heap Buffer Overflow Vulnerability
2017-07-07
http://www.securityfocus.com/bid/99496

Apache Solr CVE-2017-7660 Security Bypass Vulnerability
2017-07-07
http://www.securityfocus.com/bid/99485

QEMU CVE-2017-10806 Stack Buffer Overflow Vulnerability
2017-07-07
http://www.securityfocus.com/bid/99475

Qualcomm Closed-Source Components Multiple Unspecified Vulnerabilities
2017-07-07
http://www.securityfocus.com/bid/99467

WordPress Responsive Lightbox Plugin CVE-2017-2243 Cross Site Scripting Vulnerability
2017-07-07
http://www.securityfocus.com/bid/99463

NTP CVE-2017-6458 Buffer Overflow Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97051

NTP CVE-2016-9042 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97046

SANS News

Basic Office maldoc analysis

Threatpost

Google to Fully Distrust WoSign/StartCom SSL Certs in Chrome 61

Energy, Nuclear Targeted with Template Injection Attacks

Telcos Singled Out for Prioritizing Government Requests for Data Over Privacy

Micro Market Vendor Warns of Bankcard And Biometric Data Breach

Exploit

Microsoft Windows Windows 7/8.1/2008 R2/2012 R2/2016 R2 - 'EternalBlue' SMB Remote...

NfSen < 1.3.7 / AlienVault OSSIM < 5.3.6 - Privilege Escalation

NfSen <= 1.3.7 / AlienVault OSSIM 5.3.4 - Command Injection

Pelco Sarix/Spectra Cameras - Cross-Site Request Forgery / Cross-Site Scripting

Pelco Sarix/Spectra Cameras - Remote Code Execution

Pelco VideoXpert 1.12.105 - Information Disclosure

Pelco VideoXpert 1.12.105 - Directory Traversal

Pelco VideoXpert 1.12.105 - Privilege Escalation

Pelco Sarix/Spectra Cameras - Cross-Site Request Forgery (Enable SSH Root Access)

10.7.2017

Bugtraq

slackware-security] irssi (SSA:2017-190-01) 2017-07-09
Slackware Security Team (security slackware com)

SECURITY] DSA 3905-1] xorg-server security update 2017-07-09
Moritz Muehlenhoff (jmm debian org)

SECURITY] DSA 3904-1] bind9 security update 2017-07-08
Yves-Alexis Perez (corsac debian org)

slackware-security] php (SSA:2017-188-01) 2017-07-08
Slackware Security Team (security slackware com)

CVE-2017-10974 Yaws Web Server v1.91 Unauthenticated Remote File Disclosure 2017-07-08
apparitionsec gmail com (hyp3rlinx)

ANNOUNCE] SECURITY] CVE-2017-7660: Security Vulnerability in secure inter-node communication in Apache Solr 2017-07-07
Shalin Shekhar Mangar (shalin apache org)

SYSS-2017-011] Office 365: Insufficient Session Expiration (CWE-613) 2017-07-07
Micha Borrmann (micha borrmann syss de)

Firefox v54.0.1 Denial Of Service 2017-07-07
apparitionsec gmail com

KL-001-2017-015 : Solarwinds LEM Hardcoded Credentials 2017-07-06
KoreLogic Disclosures (disclosures korelogic com)

KL-001-2017-014 : Barracuda WAF Support Tunnel Hijack 2017-07-06
KoreLogic Disclosures (disclosures korelogic com)

Malware

 

Phishing

 

Vulnerebility

Apache Struts CVE-2017-9791 Remote Code Execution Vulnerability
2017-07-10
http://www.securityfocus.com/bid/99484

VLAN VLC CVE-2017-8313 Denial of Service Vulnerability
2017-07-10
http://www.securityfocus.com/bid/98633

VLAN VLC CVE-2017-8310 Denial of Service Vulnerability
2017-07-10
http://www.securityfocus.com/bid/98638

VideoLAN VLC CVE-2017-8311 Heap Based Buffer Overflow Vulnerability
2017-07-10
http://www.securityfocus.com/bid/98634

VideoLAN VLC CVE-2017-8312 Information Disclosure Vulnerability
2017-07-10
http://www.securityfocus.com/bid/98631

RoundCube Webmail CVE-2017-8114 Multiple Privilege Escalation Vulnerabilities
2017-07-10
http://www.securityfocus.com/bid/98445

Ubuntu Vivid CVE-2015-1336 Local Privilege Escalation Vulnerability
2017-07-10
http://www.securityfocus.com/bid/79723

PHP 'gd_gif_in.c' Memory Corruption Vulnerability
2017-07-10
http://www.securityfocus.com/bid/99492

PHP 'zend_ini_do_op()' Function Stack Buffer Overflow Vulnerability
2017-07-10
http://www.securityfocus.com/bid/99489

Apache Solr CVE-2017-7660 Security Bypass Vulnerability
2017-07-07
http://www.securityfocus.com/bid/99485

QEMU CVE-2017-10806 Stack Buffer Overflow Vulnerability
2017-07-07
http://www.securityfocus.com/bid/99475

Qualcomm Closed-Source Components Multiple Unspecified Vulnerabilities
2017-07-07
http://www.securityfocus.com/bid/99467

WordPress Responsive Lightbox Plugin CVE-2017-2243 Cross Site Scripting Vulnerability
2017-07-07
http://www.securityfocus.com/bid/99463

NTP CVE-2017-6458 Buffer Overflow Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97051

NTP CVE-2016-9042 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97046

NTP CVE-2016-9310 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94452

NTP CVE-2016-2519 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/88204

NTP CVE-2016-7431 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94454

NTP CVE-2016-7433 Local Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94455

NTP CVE-2016-7427 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94447

NTP CVE-2017-6460 Stack Buffer Overflow Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97052

NTP CVE-2017-6463 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97049

NTP CVE-2016-7426 Local Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94451

NTP CVE-2016-7429 Local Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94453

NTP CVE-2016-7428 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94446

NTP CVE-2017-6462 Local Buffer Overflow Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97045

NTP CVE-2016-9311 NULL Pointer Dereference Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94444

NTP CVE-2016-7434 Local Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94448

NTP CVE-2017-6464 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97050

LibTIFF 'tif_dirwrite.c' Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/99359

SANS News

 

Threatpost

 

Exploit

 

9.7.2017

Bugtraq

ANNOUNCE] SECURITY] CVE-2017-7660: Security Vulnerability in secure inter-node communication in Apache Solr 2017-07-07
Shalin Shekhar Mangar (shalin apache org)

SYSS-2017-011] Office 365: Insufficient Session Expiration (CWE-613) 2017-07-07
Micha Borrmann (micha borrmann syss de)

Malware

 

Phishing

 

Vulnerebility

Apache Solr CVE-2017-7660 Security Bypass Vulnerability
2017-07-07
http://www.securityfocus.com/bid/99485

Apache Struts CVE-2017-9791 Remote Code Execution Vulnerability
2017-07-07
http://www.securityfocus.com/bid/99484

QEMU CVE-2017-10806 Stack Buffer Overflow Vulnerability
2017-07-07
http://www.securityfocus.com/bid/99475

Qualcomm Closed-Source Components Multiple Unspecified Vulnerabilities
2017-07-07
http://www.securityfocus.com/bid/99467

WordPress Responsive Lightbox Plugin CVE-2017-2243 Cross Site Scripting Vulnerability
2017-07-07
http://www.securityfocus.com/bid/99463

NTP CVE-2017-6458 Buffer Overflow Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97051

SANS News

A VBScript with Obfuscated Base64 Data

Adversary hunting with SOF-ELK

Threatpost

Hard Rock, Loews Hotels Among Sabre Corp Hospitality Breach Victims

Exploit

Easy File Sharing Web Server 7.2 - GET HTTP Request 'PassWD' Buffer Overflow (DEP...

7.7.2017

Bugtraq

ANNOUNCE] SECURITY] CVE-2017-7660: Security Vulnerability in secure inter-node communication in Apache Solr 2017-07-07
Shalin Shekhar Mangar (shalin apache org)

SYSS-2017-011] Office 365: Insufficient Session Expiration (CWE-613) 2017-07-07
Micha Borrmann (micha borrmann syss de)

Firefox v54.0.1 Denial Of Service 2017-07-07
apparitionsec gmail com

KL-001-2017-015 : Solarwinds LEM Hardcoded Credentials 2017-07-06
KoreLogic Disclosures (disclosures korelogic com)

KL-001-2017-014 : Barracuda WAF Support Tunnel Hijack 2017-07-06
KoreLogic Disclosures (disclosures korelogic com)

KL-001-2017-012 : Barracuda WAF Grub Password Complexity 2017-07-06
KoreLogic Disclosures (disclosures korelogic com)

KL-001-2017-011 : Barracuda WAF Internal Development Credential Disclosure 2017-07-06
KoreLogic Disclosures (disclosures korelogic com)

SECURITY] DSA 3903-1] tiff security update 2017-07-05
Moritz Muehlenhoff (jmm debian org)

SECURITY] DSA 3902-1] jabberd2 security update 2017-07-05
Salvatore Bonaccorso (carnil debian org)

security bulletin] HPSBMU02933 rev.3 - HPE SiteScope, issueSiebelCmd and loadFileContents SOAP Requests, Remote Code Execution, Arbitrary File download, Denial of Service (DoS) 2017-07-05
HPE Product Security Response Team (security-alert hpe com)

slackware-security] Slackware 14.0 kernel (SSA:2017-184-01) 2017-07-03
Slackware Security Team (security slackware com)

Malware

 

Phishing

Amazon

6th July 2017

Payment Refund Order
#D01-9294635-404748

Amazon

6th July 2017

Revision to Your Amazon.co.uk
Account

AppIe Support

5th July 2017

UPDATE YOUR ACCOUNT ID

Amazon-Store-Card

4th July 2017

Important-Information about
your
Amazon-Store-Card(5494753),
Customer ID: lemcool2

Vulnerebility

Qualcomm Closed-Source Components Multiple Unspecified Vulnerabilities
2017-07-07
http://www.securityfocus.com/bid/99467

WordPress Responsive Lightbox Plugin CVE-2017-2243 Cross Site Scripting Vulnerability
2017-07-07
http://www.securityfocus.com/bid/99463

NTP CVE-2017-6458 Buffer Overflow Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97051

NTP CVE-2016-9042 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97046

NTP CVE-2016-9310 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94452

NTP CVE-2016-2519 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/88204

NTP CVE-2016-7431 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94454

NTP CVE-2016-7433 Local Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94455

NTP CVE-2016-7427 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94447

NTP CVE-2017-6460 Stack Buffer Overflow Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97052

NTP CVE-2017-6463 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97049

NTP CVE-2016-7426 Local Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94451

NTP CVE-2016-7429 Local Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94453

NTP CVE-2016-7428 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94446

NTP CVE-2017-6462 Local Buffer Overflow Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97045

NTP CVE-2016-9311 NULL Pointer Dereference Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94444

NTP CVE-2016-7434 Local Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94448

NTP CVE-2017-6464 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97050

LibTIFF 'tif_dirwrite.c' Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/99359

LibTIFF CVE-2016-10095 Stack Based Buffer Overflow Vulnerability
2017-07-06
http://www.securityfocus.com/bid/95178

LibTIFF 'tif_jbig.c' Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/99300

LibTIFF 'tif_dir.c' Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/98594

Schneider Electric Ampla MES ICSA-17-187-05 Multiple Local Security Vulnerabilities
2017-07-06
http://www.securityfocus.com/bid/99469

Google Android Qualcomm Components Multiple Security Vulnerabilities
2017-07-06
http://www.securityfocus.com/bid/99465

Cisco Identity Services Engine (ISE) Software CVE-2017-6734 Cross Site Scripting Vulnerability
2017-07-06
http://www.securityfocus.com/bid/99459

Xen 'xen/arch/arm/vgic.c' Denial of Service Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99160

Xen 'xen/arch/arm/gic.c' Denial of Service Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99159

Xen XSA-222 Privilege Escalation Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99161

Xen 'xen/arch/x86/irq.c' NULL pointer Dereference Remote Denial of Service Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99157

Xen XSA-220 Information Disclosure Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99167

SANS News

 

Threatpost

CopyCat Malware Infected 14M Android Devices, Rooted 8M, in 2016

Let’s Encrypt to Offer Wildcard Certificates in 2018

Decryption Key to Original Petya Ransomware Released


Leaky WWE Database Exposes Personal Data of 3M Wrestling Fans

Exploit

Firefox 54.0.1 - Denial of Service

LibTIFF - 'tif_dirwrite.c' Denial of Service

LibTIFF - 'tif_jbig.c' Denial of Service

LibTIFF - '_TIFFVGetField (tiffsplit)' Out-of-Bounds Read

6.7.2017

Bugtraq

NTP CVE-2017-6458 Buffer Overflow Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97051

NTP CVE-2016-9042 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97046

NTP CVE-2016-9310 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94452

NTP CVE-2016-2519 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/88204

NTP CVE-2016-7431 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94454

NTP CVE-2016-7433 Local Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94455

NTP CVE-2016-7427 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94447

NTP CVE-2017-6460 Stack Buffer Overflow Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97052

NTP CVE-2017-6463 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97049

NTP CVE-2016-7426 Local Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94451

NTP CVE-2016-7429 Local Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94453

NTP CVE-2016-7428 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94446

NTP CVE-2017-6462 Local Buffer Overflow Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97045

NTP CVE-2016-9311 NULL Pointer Dereference Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94444

NTP CVE-2016-7434 Local Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94448

NTP CVE-2017-6464 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97050

LibTIFF 'tif_dirwrite.c' Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/99359

LibTIFF CVE-2016-10095 Stack Based Buffer Overflow Vulnerability
2017-07-06
http://www.securityfocus.com/bid/95178

LibTIFF 'tif_jbig.c' Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/99300

LibTIFF 'tif_dir.c' Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/98594

Cisco Identity Services Engine (ISE) Software CVE-2017-6734 Cross Site Scripting Vulnerability
2017-07-06
http://www.securityfocus.com/bid/99459

Xen 'xen/arch/arm/vgic.c' Denial of Service Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99160

Xen 'xen/arch/arm/gic.c' Denial of Service Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99159

Xen XSA-222 Privilege Escalation Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99161

Xen 'xen/arch/x86/irq.c' NULL pointer Dereference Remote Denial of Service Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99157

Xen XSA-220 Information Disclosure Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99167

Xen 'shadow/common.c' Privilege Escalation Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99174

Xen Page Transfer 'xen/arch/x86/mm.c' Privilege Escalation Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99158

Xen 'blkif' Response Information Disclosure Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99162

Resteasy CVE-2016-9606 Remote Code Execution Vulnerability
2017-07-05
http://www.securityfocus.com/bid/94940

Malware

SoftwareBundler:MSIL/Wizrem 
Ransom.Fakecry

VBS.Vlerli

Phishing

Amazon

6th July 2017

Revision to Your Amazon.co.uk
Account

AppIe Support

5th July 2017

UPDATE YOUR ACCOUNT ID

Amazon-Store-Card

4th July 2017

Important-Information about
your
Amazon-Store-Card(5494753),
Customer ID: lemcool2

Vulnerebility

NTP CVE-2017-6458 Buffer Overflow Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97051

NTP CVE-2016-9042 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97046

NTP CVE-2016-9310 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94452

NTP CVE-2016-2519 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/88204

NTP CVE-2016-7431 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94454

NTP CVE-2016-7433 Local Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94455

NTP CVE-2016-7427 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94447

NTP CVE-2017-6460 Stack Buffer Overflow Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97052

NTP CVE-2017-6463 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97049

NTP CVE-2016-7426 Local Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94451

NTP CVE-2016-7429 Local Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94453

NTP CVE-2016-7428 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94446

NTP CVE-2017-6462 Local Buffer Overflow Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97045

NTP CVE-2016-9311 NULL Pointer Dereference Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94444

NTP CVE-2016-7434 Local Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/94448

NTP CVE-2017-6464 Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/97050

LibTIFF 'tif_dirwrite.c' Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/99359

LibTIFF CVE-2016-10095 Stack Based Buffer Overflow Vulnerability
2017-07-06
http://www.securityfocus.com/bid/95178

LibTIFF 'tif_jbig.c' Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/99300

LibTIFF 'tif_dir.c' Denial of Service Vulnerability
2017-07-06
http://www.securityfocus.com/bid/98594

Xen 'xen/arch/arm/vgic.c' Denial of Service Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99160

Xen 'xen/arch/arm/gic.c' Denial of Service Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99159

Xen XSA-222 Privilege Escalation Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99161

Xen 'xen/arch/x86/irq.c' NULL pointer Dereference Remote Denial of Service Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99157

Xen XSA-220 Information Disclosure Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99167

Xen 'shadow/common.c' Privilege Escalation Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99174

Xen Page Transfer 'xen/arch/x86/mm.c' Privilege Escalation Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99158

Xen 'blkif' Response Information Disclosure Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99162

Resteasy CVE-2016-9606 Remote Code Execution Vulnerability
2017-07-05
http://www.securityfocus.com/bid/94940

RedHat RESTEasy CVE-2016-6346 Denial of Service Vulnerability
2017-07-05
http://www.securityfocus.com/bid/92744

SANS News

Investigation of BitTorrent Sync (v.2.0) as a P2P Cloud Service (Part 2 ? Log Files artefacts)

Selecting domains with random names

Threatpost

Threat Actors Target Chinese Language News Sites

Exploit

GoAutoDial 3.3 - Authentication Bypass / Command Injection (Metasploit)

Lepide Auditor Suite - 'createdb()' Web Console Database Injection Remote Code...

5.7.2017

Bugtraq

 

Malware

Ransom.Haknata

Phishing

 

Vulnerebility

Xen 'xen/arch/arm/vgic.c' Denial of Service Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99160

Xen 'xen/arch/arm/gic.c' Denial of Service Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99159

Xen XSA-222 Privilege Escalation Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99161

Xen 'xen/arch/x86/irq.c' NULL pointer Dereference Remote Denial of Service Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99157

Xen XSA-220 Information Disclosure Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99167

Xen 'shadow/common.c' Privilege Escalation Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99174

Xen Page Transfer 'xen/arch/x86/mm.c' Privilege Escalation Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99158

Xen 'blkif' Response Information Disclosure Vulnerability
2017-07-05
http://www.securityfocus.com/bid/99162

Resteasy CVE-2016-9606 Remote Code Execution Vulnerability
2017-07-05
http://www.securityfocus.com/bid/94940

RedHat RESTEasy CVE-2016-6346 Denial of Service Vulnerability
2017-07-05
http://www.securityfocus.com/bid/92744

Linux Kernel 'ipv4/udp.c' Remote Code Execution Vulnerability
2017-07-04
http://www.securityfocus.com/bid/97397

ISC BIND CVE-2017-3136 Remote Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/97653

ISC BIND CVE-2017-3135 Remote Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/96150

Linux Kernel 'Ack Challenge' Information Disclosure Vulnerability
2017-07-04
http://www.securityfocus.com/bid/91704

OpenSSL CVE-2016-8610 Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/93841

OpenVPN CVE-2017-7478 Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/98444

OpenVPN Multiple Security Vulnerabilities
2017-07-04
http://www.securityfocus.com/bid/99230

OpenVPN CVE-2017-7479 Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/98443

Linux kernel CVE-2017-9075 Local Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/98597

Linux kernel CVE-2017-9077 Local Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/98583

Linux kernel CVE-2017-9242 Local Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/98731

Linux kernel CVE-2017-9076 Local Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/98586

Linux Kernel CVE-2017-1000363 Integer Overflow Vulnerability
2017-07-04
http://www.securityfocus.com/bid/98651

Linux Kernel CVE-2017-7374 Local Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/97308

Linux Kernel CVE-2017-8890 Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/98562

Linux Kernel CVE-2017-5577 Remote Buffer Overflow Vulnerability
2017-07-04
http://www.securityfocus.com/bid/95765

Linux Kernel CVE-2017-7294 Local Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/97177

Linux kernel CVE-2017-9074 Local Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/98577

Libgcrypt CVE-2017-7526 Information Disclosure Vulnerability
2017-07-04
http://www.securityfocus.com/bid/99338

Libgcrypt 'cipher/ecc-eddsa.c' Information Disclosure Vulnerability
2017-07-04
http://www.securityfocus.com/bid/99046

SANS News

Selecting domains with random names

Threatpost

 

Exploit

OpenDreamBox 2.0.0 Plugin WebAdmin - Remote Code Execution

Linux/x86 - Reverse TCP Shellcode (67 bytes)

4.7.2017

Bugtraq

slackware-security] Slackware 14.0 kernel (SSA:2017-184-01) 2017-07-03
Slackware Security Team (security slackware com)

SECURITY] DSA 3901-1] libgcrypt20 security update 2017-07-02
Salvatore Bonaccorso (carnil debian org)

CVE-2017-9313] Webmin 1.840 Multiple XSS Vulnerabilities 2017-07-02
andys3c gmail com

InsomniaX loader allows loading of arbitrary Kernel Extensions 2017-07-02
Securify B.V. (lists securify nl)

slackware-security] glibc (SSA:2017-181-01) 2017-06-30
Slackware Security Team (security slackware com)

Malware

Trojan:JS/Jesapi.A!cl 

Phishing

Melissa

4th July 2017

Last Notice, Re: Your Payment
Info

Amazon-Store-Card

4th July 2017

Important-Information about
your
Amazon-Store-Card(5544232),
Customer ID: lemcool2

Amazon-Store-Card

4th July 2017

Important-Information about
your
Amazon-Store-Card(3802887),
Customer ID: lemcool2

Amazon-Store-Card

4th July 2017

Important-Information about
your
Amazon-Store-Card(6679016),
Customer ID: lemcool2

Amazon-Store-Card

3rd July 2017

Important-Information about
your
Amazon-Store-Card(4974043),
Customer ID: lemcool2

Vulnerebility

Linux Kernel 'ipv4/udp.c' Remote Code Execution Vulnerability
2017-07-04
http://www.securityfocus.com/bid/97397

ISC BIND CVE-2017-3136 Remote Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/97653

ISC BIND CVE-2017-3135 Remote Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/96150

Linux Kernel 'Ack Challenge' Information Disclosure Vulnerability
2017-07-04
http://www.securityfocus.com/bid/91704

OpenSSL CVE-2016-8610 Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/93841

OpenVPN CVE-2017-7478 Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/98444

OpenVPN Multiple Security Vulnerabilities
2017-07-04
http://www.securityfocus.com/bid/99230

OpenVPN CVE-2017-7479 Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/98443

Linux kernel CVE-2017-9075 Local Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/98597

Linux kernel CVE-2017-9077 Local Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/98583

Linux kernel CVE-2017-9242 Local Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/98731

Linux kernel CVE-2017-9076 Local Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/98586

Linux Kernel CVE-2017-1000363 Integer Overflow Vulnerability
2017-07-04
http://www.securityfocus.com/bid/98651

Linux Kernel CVE-2017-7374 Local Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/97308

Linux Kernel CVE-2017-8890 Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/98562

Linux Kernel CVE-2017-5577 Remote Buffer Overflow Vulnerability
2017-07-04
http://www.securityfocus.com/bid/95765

Linux Kernel CVE-2017-7294 Local Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/97177

Linux kernel CVE-2017-9074 Local Denial of Service Vulnerability
2017-07-04
http://www.securityfocus.com/bid/98577

Libgcrypt CVE-2017-7526 Information Disclosure Vulnerability
2017-07-04
http://www.securityfocus.com/bid/99338

Libgcrypt 'cipher/ecc-eddsa.c' Information Disclosure Vulnerability
2017-07-04
http://www.securityfocus.com/bid/99046

Drupal Core CVE-2017-6922 Access Bypass Vulnerability
2017-07-03
http://www.securityfocus.com/bid/99219

Drupal Core Overlay Module CVE-2015-7943 Incomplete Fix Open Redirection Vulnerability
2017-07-03
http://www.securityfocus.com/bid/77293

Linux Kernel CVE-2017-7645 Multiple Denial of Service Vulnerabilities
2017-07-03
http://www.securityfocus.com/bid/97950

FreeRADIUS TLS CVE-2017-9148 Authentication Bypass Vulnerability
2017-07-03
http://www.securityfocus.com/bid/98734

ISC BIND CVE-2017-3142 Security Bypass Vulnerability
2017-07-03
http://www.securityfocus.com/bid/99339

ISC BIND CVE-2017-3143 Security Bypass Vulnerability
2017-07-03
http://www.securityfocus.com/bid/99337

Linux Kernel CVE-2017-7895 Multiple Security Bypass Vulnerabilities
2017-07-03
http://www.securityfocus.com/bid/98085

Linux Kernel CVE-2017-7477 Heap Buffer Overflow Vulnerability
2017-07-03
http://www.securityfocus.com/bid/98014

Linux Kernel CVE-2017-6214 Remote Denial of Service Vulnerability
2017-07-03
http://www.securityfocus.com/bid/96421

Linux Kernel CVE-2017-2583 Privilege Escalation Vulnerability
2017-07-03
http://www.securityfocus.com/bid/95673

SANS News

 

Threatpost

Classic Ether Wallet Compromised via Social Engineering

Exploit

OpenDreamBox 2.0.0 Plugin WebAdmin - Remote Code Execution

3.7.2017

Bugtraq

SECURITY] DSA 3901-1] libgcrypt20 security update 2017-07-02
Salvatore Bonaccorso (carnil debian org)

CVE-2017-9313] Webmin 1.840 Multiple XSS Vulnerabilities 2017-07-02
andys3c gmail com

InsomniaX loader allows loading of arbitrary Kernel Extensions 2017-07-02
Securify B.V. (lists securify nl)

slackware-security] glibc (SSA:2017-181-01) 2017-06-30
Slackware Security Team (security slackware com)

slackware-security] kernel (SSA:2017-181-02) 2017-06-30
Slackware Security Team (security slackware com)

Malware

 

Phishing

✅ Yahoo! Mail

3rd July 2017

✅De-activation of Your
Yahoo! Email Address.

NatWest.

3rd July 2017

RESTRICTED ACCOUNT ACCESS -
NATWEST PLC.

Amazon-Store-Card

3rd July 2017

Important-Information about
your
Amazon-Store-Card(3811493),
Customer ID: lemcool2

Amazon-Store-Card

3rd July 2017

Important-Information about
your
Amazon-Store-Card(0018019),
Customer ID: lemcool2

spoof

3rd July 2017

On what?

Vulnerebility

Drupal Core CVE-2017-6922 Access Bypass Vulnerability
2017-07-03
http://www.securityfocus.com/bid/99219

Drupal Core Overlay Module CVE-2015-7943 Incomplete Fix Open Redirection Vulnerability
2017-07-03
http://www.securityfocus.com/bid/77293

OpenVPN Multiple Security Vulnerabilities
2017-07-03
http://www.securityfocus.com/bid/99230

OpenVPN CVE-2017-7479 Denial of Service Vulnerability
2017-07-03
http://www.securityfocus.com/bid/98443

Linux Kernel CVE-2017-7645 Multiple Denial of Service Vulnerabilities
2017-07-03
http://www.securityfocus.com/bid/97950

FreeRADIUS TLS CVE-2017-9148 Authentication Bypass Vulnerability
2017-07-03
http://www.securityfocus.com/bid/98734

ISC BIND CVE-2017-3142 Security Bypass Vulnerability
2017-07-03
http://www.securityfocus.com/bid/99339

ISC BIND CVE-2017-3143 Security Bypass Vulnerability
2017-07-03
http://www.securityfocus.com/bid/99337

Linux Kernel CVE-2017-7895 Multiple Security Bypass Vulnerabilities
2017-07-03
http://www.securityfocus.com/bid/98085

Linux Kernel CVE-2017-7477 Heap Buffer Overflow Vulnerability
2017-07-03
http://www.securityfocus.com/bid/98014

Linux Kernel CVE-2017-6214 Remote Denial of Service Vulnerability
2017-07-03
http://www.securityfocus.com/bid/96421

Linux Kernel CVE-2017-2583 Privilege Escalation Vulnerability
2017-07-03
http://www.securityfocus.com/bid/95673

Libgcrypt CVE-2017-7526 Information Disclosure Vulnerability
2017-07-03
http://www.securityfocus.com/bid/99338

GraphicsMagick 'coders/dpx.c' Denial of Service Vulnerability
2017-07-02
http://www.securityfocus.com/bid/99358

GraphicsMagick CVE-2017-10794 Buffer Overflow Vulnerability
2017-07-02
http://www.securityfocus.com/bid/99355

Linux kernel CVE-2017-9074 Local Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/98577

Linux kernel CVE-2017-9075 Local Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/98597

Linux Kernel CVE-2017-8890 Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/98562

Linux Kernel 'drivers/usb/serial/omninet.c' Local Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/98462

Linux Kernel CVE-2017-8924 Local Information Disclosure Vulnerability
2017-06-30
http://www.securityfocus.com/bid/98451

Linux Kernel CVE-2017-8064 Local Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/97975

Linux kernel CVE-2017-9076 Local Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/98586

Linux kernel CVE-2017-9077 Local Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/98583

Linux Kernel CVE-2017-1000364 Local Memory Corruption Vulnerability
2017-06-30
http://www.securityfocus.com/bid/99130

Linux kernel CVE-2017-9242 Local Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/98731

Exim CVE-2017-1000369 Local Privilege Escalation Vulnerability
2017-06-30
http://www.securityfocus.com/bid/99252

GNU glibc CVE-2017-1000366 Local Memory Corruption Vulnerability
2017-06-30
http://www.securityfocus.com/bid/99127

Google Chrome Multiple Security Vulnerabilities
2017-06-30
http://www.securityfocus.com/bid/99096

Irssi CVE-2017-9469 Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/99043

Irssi CVE-2017-9468 Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/99015

SANS News

PE Section Name Descriptions

Threatpost

Majority of Sites Fail Mozilla’s Comprehensive Security Review

Exploit

eVestigator Forensic PenTester - MITM Remote Code Execution

BestSafe Browser - MITM Remote Code Execution

BOA Web Server 0.94.14rc21 - Arbitrary File Access

2.7.2017

Bugtraq

Microsoft Dynamic CRM 2016 - Cross-Site Scripting vulnerability 2017-06-30
gregory draperi (gregory draperi gmail com)

SEC Consult SA-20170630-0 :: Multiple critical vulnerabilities in OSCI-Transport library 1.2 for German e-Government 2017-06-30
SEC Consult Vulnerability Lab (research sec-consult com)

Malware

 

Phishing

 

Vulnerebility

Linux kernel CVE-2017-9074 Local Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/98577

Linux kernel CVE-2017-9075 Local Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/98597

Linux Kernel CVE-2017-8890 Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/98562

Linux Kernel 'drivers/usb/serial/omninet.c' Local Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/98462

Linux Kernel CVE-2017-7645 Multiple Denial of Service Vulnerabilities
2017-06-30
http://www.securityfocus.com/bid/97950

Linux Kernel CVE-2017-8924 Local Information Disclosure Vulnerability
2017-06-30
http://www.securityfocus.com/bid/98451

Linux Kernel CVE-2017-7895 Multiple Security Bypass Vulnerabilities
2017-06-30
http://www.securityfocus.com/bid/98085

Linux Kernel CVE-2017-8064 Local Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/97975

Linux kernel CVE-2017-9076 Local Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/98586

Linux kernel CVE-2017-9077 Local Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/98583

Linux Kernel CVE-2017-1000364 Local Memory Corruption Vulnerability
2017-06-30
http://www.securityfocus.com/bid/99130

Linux kernel CVE-2017-9242 Local Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/98731

Exim CVE-2017-1000369 Local Privilege Escalation Vulnerability
2017-06-30
http://www.securityfocus.com/bid/99252

GNU glibc CVE-2017-1000366 Local Memory Corruption Vulnerability
2017-06-30
http://www.securityfocus.com/bid/99127

Google Chrome Multiple Security Vulnerabilities
2017-06-30
http://www.securityfocus.com/bid/99096

Irssi CVE-2017-9469 Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/99043

Irssi CVE-2017-9468 Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/99015

GnuTLS CVE-2017-7507 NULL Pointer Dereference Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/99102

Samba CVE-2017-7494 Remote Code Execution Vulnerability
2017-06-30
http://www.securityfocus.com/bid/98636

Samba CVE-2017-2619 Symlink Vulnerability
2017-06-30
http://www.securityfocus.com/bid/97033

Multiple Intel Products CVE-2017-5689 Privilege Escalation Vulnerability
2017-06-30
http://www.securityfocus.com/bid/98269

ISC BIND CVE-2017-3143 Security Bypass Vulnerability
2017-06-30
http://www.securityfocus.com/bid/99337

HP SiteScope Monitors Information Disclosure and Security Bypass Vulnerabilities
2017-06-30
http://www.securityfocus.com/bid/99331

OpenSSL CVE-2016-6304 Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/93150

Piwigo CVE-2017-10680 Cross-Site Request Forgery Vulnerability
2017-06-30
http://www.securityfocus.com/bid/99349

Schneider Electric U.motion Builder Multiple Security Vulnerabilities
2017-06-30
http://www.securityfocus.com/bid/99344

HP Network Node Manager i (NNMi) Software Multiple Unspecified Security Vulnerabilities
2017-06-30
http://www.securityfocus.com/bid/99342

Biscom Secure File Transfer CVE-2017-5241 Multiple HTML Injection Vulnerabilities
2017-06-30
http://www.securityfocus.com/bid/99341

Cisco IOS and IOS XE Software Multiple Remote Code Execution Vulnerabilities
2017-06-29
http://www.securityfocus.com/bid/99345

Siemens Viewport for Web Office Portal CVE-2017-6869 Remote Security Bypass Vulnerability
2017-06-29
http://www.securityfocus.com/bid/99343
SANS News

Using nmap to scan for MS17-010 (CVE-2017-0143 EternalBlue)

Threatpost

ExPetr Called a Wiper Attack, Not Ransomware

Majority of Sites Fail Mozilla’s Comprehensive Security Review

Siemens Patches Critical Intel AMT Flaw in Industrial Products

Exploit

Google Chrome - Out-of-Bounds Access in RegExp Stubs

Humax HG100R 2.0.6 - Backup File Download

LG MRA58K - 'ASFParser::SetMetaData' Stack Overflow

30.6.2017

Bugtraq

Microsoft Dynamic CRM 2016 - Cross-Site Scripting vulnerability 2017-06-30
gregory draperi (gregory draperi gmail com)

SEC Consult SA-20170630-0 :: Multiple critical vulnerabilities in OSCI-Transport library 1.2 for German e-Government 2017-06-30
SEC Consult Vulnerability Lab (research sec-consult com)

ESA-2017-062: VASA Provider Virtual Appliance Remote Code Execution Vulnerability 2017-06-28
EMC Product Security Response Center (Security_Alert emc com)

SECURITY] DSA 3900-1] openvpn security update 2017-06-27
Sebastien Delafond (seb untangle com)

SECURITY] DSA 3886-2] linux regression update 2017-06-27
Salvatore Bonaccorso (carnil debian org)

Malware

Ransom.Beeteeceeware

W32.Futurax

Phishing

spoof

30th June 2017

That Estus Flask though

Chase.com

29th June 2017

Unusual activity detected In
Your Chase Account

Vulnerebility

GnuTLS CVE-2017-7507 NULL Pointer Dereference Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/99102

Samba CVE-2017-7494 Remote Code Execution Vulnerability
2017-06-30
http://www.securityfocus.com/bid/98636

Samba CVE-2017-2619 Symlink Vulnerability
2017-06-30
http://www.securityfocus.com/bid/97033

Multiple Intel Products CVE-2017-5689 Privilege Escalation Vulnerability
2017-06-30
http://www.securityfocus.com/bid/98269

ISC BIND CVE-2017-3143 Security Bypass Vulnerability
2017-06-30
http://www.securityfocus.com/bid/99337

HP SiteScope Monitors Information Disclosure and Security Bypass Vulnerabilities
2017-06-30
http://www.securityfocus.com/bid/99331

OpenSSL CVE-2016-6304 Denial of Service Vulnerability
2017-06-30
http://www.securityfocus.com/bid/93150

Schneider Electric U.motion Builder Multiple Security Vulnerabilities
2017-06-30
http://www.securityfocus.com/bid/99344

HP Network Node Manager i (NNMi) Software Multiple Unspecified Security Vulnerabilities
2017-06-30
http://www.securityfocus.com/bid/99342

Biscom Secure File Transfer CVE-2017-5241 Multiple HTML Injection Vulnerabilities
2017-06-30
http://www.securityfocus.com/bid/99341

Cisco IOS and IOS XE Software Multiple Remote Code Execution Vulnerabilities
2017-06-29
http://www.securityfocus.com/bid/99345

Siemens Viewport for Web Office Portal CVE-2017-6869 Remote Security Bypass Vulnerability
2017-06-29
http://www.securityfocus.com/bid/99343

ISC BIND CVE-2017-3142 Security Bypass Vulnerability
2017-06-29
http://www.securityfocus.com/bid/99339

Libgcrypt CVE-2017-7526 Information Disclosure Vulnerability
2017-06-29
http://www.securityfocus.com/bid/99338

e-Tax software CVE-2017-2226 DLL Loading Remote Code Execution Vulnerability
2017-06-29
http://www.securityfocus.com/bid/99334

Kaspersky Anti-Virus for Linux File Server Multiple Security Vulnerabilities
2017-06-29
http://www.securityfocus.com/bid/99330

Adobe Flash Player and AIR APSB16-01 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-06-28
http://www.securityfocus.com/bid/79701

Linux kernel CVE-2017-9986 Local Denial of Service Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99336

Linux kernel CVE-2017-9985 Local Denial of Service Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99335

Red Hat CloudForms Management Engine CVE-2016-7047 Information Disclosure Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99329

Drupal SMTP Authentication Support Module Information Disclosure Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99327

FFmpeg CVE-2017-9996 Heap Buffer Overflow Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99323

ownCloud CVE-2017-9338 Cross-Site Scripting Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99322

ownCloud CVE-2017-8896 Cross-Site Scripting Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99321

FFmpeg CVE-2017-9995 Multiple Heap Buffer Overflow Vulnerabilities
2017-06-28
http://www.securityfocus.com/bid/99320

FFmpeg CVE-2017-9992 Heap Buffer Overflow Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99319

Drupal Services Module SQL Injection Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99318

FFmpeg CVE-2017-9994 Heap Buffer Overflow Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99317

FFmpeg CVE-2017-9991 Heap Buffer Overflow Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99316

FFmpeg CVE-2017-9993 Arbitrary File Read Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99315

SANS News

 

Threatpost

Microsoft Issues ‘Important’ Security Fix for Azure AD Connect

‘Little Hope’ to Recover Data Lost to Petya Ransomware

Linux Systemd Bug Could Have Led to Crash, Code Execution

ExPetr Called a Wiper Attack, Not Ransomware

Exploit

Veritas/Symantec Backup Exec - SSL NDMP Connection Use-After-Free (Metasploit)

ActiveMQ < 5.14.0 - web shell upload (Metasploit)

29.6.2017

Bugtraq

ESA-2017-062: VASA Provider Virtual Appliance Remote Code Execution Vulnerability 2017-06-28
EMC Product Security Response Center (Security_Alert emc com)

SECURITY] DSA 3900-1] openvpn security update 2017-06-27
Sebastien Delafond (seb untangle com)

SECURITY] DSA 3886-2] linux regression update 2017-06-27
Salvatore Bonaccorso (carnil debian org)

SECURITY] DSA 3899-1] vlc security update 2017-06-27
Salvatore Bonaccorso (carnil debian org)

slackware-security] kernel (SSA:2017-177-01) 2017-06-26
Slackware Security Team (security slackware com)

Malware

Ransom:Win32/Petya 

Phishing

Chase.com

29th June 2017

Unusual activity detected In
Your Chase Account

Vulnerebility

Kaspersky Anti-Virus for Linux File Server Multiple Security Vulnerabilities
2017-06-29
http://www.securityfocus.com/bid/99330

Adobe Flash Player and AIR APSB16-01 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-06-28
http://www.securityfocus.com/bid/79701

FFmpeg CVE-2017-9996 Heap Buffer Overflow Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99323

ownCloud CVE-2017-9338 Cross-Site Scripting Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99322

ownCloud CVE-2017-8896 Cross-Site Scripting Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99321

FFmpeg CVE-2017-9995 Multiple Heap Buffer Overflow Vulnerabilities
2017-06-28
http://www.securityfocus.com/bid/99320

FFmpeg CVE-2017-9992 Heap Buffer Overflow Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99319

Drupal Services Module SQL Injection Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99318

FFmpeg CVE-2017-9994 Heap Buffer Overflow Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99317

FFmpeg CVE-2017-9991 Heap Buffer Overflow Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99316

FFmpeg CVE-2017-9993 Arbitrary File Read Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99315

SANS News

Catching up with Blank Slate: a malspam campaign still going strong

Threatpost

Google Hit With $2.7 Billion Antitrust Fine

Average Bug Bounty Payments Growing

Microsoft Issues ‘Important’ Security Fix for Azure AD Connect

‘Little Hope’ to Recover Data Lost to Petya Ransomware

Exploit

Linux - 'ldso_hwcap' Local Root Stack Clash Exploit

Oracle Solaris 11.1 / 11.3 RSH - Local Root Stack Clash Exploit

Linux - 'ldso_hwcap_64' Local Root Stack Clash Exploit

OpenBSD - 'at' Local Root Stack Clash Exploit

Flat Assembler 1.7.21 - Buffer Overflow

Linux - 'ldso_dynamic' Local Root Stack Clash Exploit

Linux - 'offset2lib' Stack Clash Exploit

NetBSD - Stack Clash Proof of Concept

FreeBSD - 'FGPU' Stack Clash Proof of Concept

FreeBSD - 'FGPE' Stack Clash Proof of Concept

FreeBSD - 'setrlimit' Stack Clash Proof of Concept

28.6.2017

Bugtraq

SECURITY] DSA 3900-1] openvpn security update 2017-06-27
Sebastien Delafond (seb untangle com)

SECURITY] DSA 3886-2] linux regression update 2017-06-27
Salvatore Bonaccorso (carnil debian org)

SECURITY] DSA 3899-1] vlc security update 2017-06-27
Salvatore Bonaccorso (carnil debian org)

slackware-security] kernel (SSA:2017-177-01) 2017-06-26
Slackware Security Team (security slackware com)

CVE-2017-8831] Double-Fetch Vulnerability in Linux-4.10.1/drivers/media/pci/saa7164/saa7164-bus.c 2017-06-26
wpengfeinudt gmail com

DefenseCode Security Advisory: IBM DB2 Command Line Processor Buffer Overflow 2017-06-26
DefenseCode (defensecode defensecode com)

Microsoft Skype v7.2, v7.35 & v7.36 - Stack Buffer Overflow Vulnerability 2017-06-26
Vulnerability Lab (research vulnerability-lab com)

Malware

Ransom:Win32/Petya 
Ransom:Win32/Petya.B 

RANSOM_PETYA.SMA

Ransom:Win32/Petya.B 
Ransom:Win32/Petya 
Ransom:Win32/Petya.A 
Win32/Petya 
Trojan:Win32/Petya.G 
Ransom:DOS/Petya.B 
Ransom:DOS/Petya.A 

Phishing

Amazon

27th June 2017

Customer Service: Important
account information # 83369533

Bank of America

26th June 2017

Bank of America Alert: Unusual
Account Activity

Vulnerebility

Adobe Flash Player and AIR APSB16-01 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-06-28
http://www.securityfocus.com/bid/79701

ownCloud CVE-2017-8896 Cross-Site Scripting Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99321

FFmpeg CVE-2017-9995 Multiple Heap Buffer Overflow Vulnerabilities
2017-06-28
http://www.securityfocus.com/bid/99320

FFmpeg CVE-2017-9992 Heap Buffer Overflow Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99319

Drupal Services Module SQL Injection Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99318

FFmpeg CVE-2017-9994 Heap Buffer Overflow Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99317

FFmpeg CVE-2017-9991 Heap Buffer Overflow Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99316

FFmpeg CVE-2017-9993 Arbitrary File Read Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99315

Linux kernel CVE-2017-9984 Local Denial of Service Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99314

FFmpeg CVE-2017-9990 Stack Buffer Overflow Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99313

Libdwarf CVE-2017-9998 Remote Denial Of Service Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99310

GNU Binutils CVE-2017-9954 Remote Denial of Service Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99307

systemd CVE-2017-9445 Out-Of-Bounds Write Remote Code Execution Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99302

Linux Kernel CVE-2017-7482 Local Buffer Overflow Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99299

Linux Kernel CVE-2017-8797 Denial of Service Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99298

Lenovo VIBE Mobile CVE-2017-3748 Local Privilege Escalation Vulnerability
2017-06-28
http://www.securityfocus.com/bid/99295

Microsoft Skype 'MSFTEDIT.DLL' Buffer Overflow Vulnerability
2017-06-27
http://www.securityfocus.com/bid/99281

IBM DB2 CVE-2017-1297 Local Buffer Overflow Vulnerability
2017-06-27
http://www.securityfocus.com/bid/99271

Cisco AnyConnect Secure Mobility Client CVE-2017-6638 Local Privilege Escalation Vulnerability
2017-06-27
http://www.securityfocus.com/bid/98938

QEMU 'hw/display/cirrus_vga_rop.h' Multiple Memory Corruption Vulnerabilities
2017-06-27
http://www.securityfocus.com/bid/97957

Ghostscript CVE-2017-7207 Denial of Service Vulnerability
2017-06-27
http://www.securityfocus.com/bid/96995

Red Hat Gluster Storage Server CVE-2015-1795 Local Privilege Escalation Vulnerability
2017-06-27
http://www.securityfocus.com/bid/99311

TeamSpeak Client CVE-2017-9982 Denial of Service Vulnerability
2017-06-27
http://www.securityfocus.com/bid/99308

Microsoft Azure Active Directory Connect CVE-2017-8613 Remote Privilege Escalation Vulnerability
2017-06-27
http://www.securityfocus.com/bid/99294

Apache Ignite CVE-2017-7686 Information Disclosure Vulnerability
2017-06-27
http://www.securityfocus.com/bid/99292

Multiple Newport Products CVE-2017-7919 Authentication Bypass Vulnerability
2017-06-27
http://www.securityfocus.com/bid/99291

SANS News

Checking out the new Petya variant

Petya? I hardly know ya! - an ISC update on the 2017-06-27 ransomware outbreak

Threatpost

Major Hole Plugged in Secure File Transfer Tool


Second Global Ransomware Outbreak Under Way

Google Hit With $2.7 Billion Antitrust Fine

Exploit

Microsoft MsMpEng - mpengine x86 Emulator Heap Corruption in VFS API

Easy File Sharing Web Server 7.2 - GET HTTP Request (PassWD) Buffer Overflow (SEH)

GLPI 0.90.4 - SQL Injection

WordPress Plugin Ultimate Product Catalogue 4.2.2 - SQL Injection

27.6.2017

Bugtraq

SECURITY] DSA 3899-1] vlc security update 2017-06-27
Salvatore Bonaccorso (carnil debian org)

slackware-security] kernel (SSA:2017-177-01) 2017-06-26
Slackware Security Team (security slackware com)

CVE-2017-8831] Double-Fetch Vulnerability in Linux-4.10.1/drivers/media/pci/saa7164/saa7164-bus.c 2017-06-26
wpengfeinudt gmail com

DefenseCode Security Advisory: IBM DB2 Command Line Processor Buffer Overflow 2017-06-26
DefenseCode (defensecode defensecode com)

Microsoft Skype v7.2, v7.35 & v7.36 - Stack Buffer Overflow Vulnerability 2017-06-26
Vulnerability Lab (research vulnerability-lab com)

Malware

Trojan.Gordry
Backdoor.Pled

OSX.Macspy

Backdoor.Croxbow

Win32/Diskcoder.Petya

Win32/Diskcoder.Petya.A

Win32/Diskcoder.Petya.B

Win32/Diskcoder.Petya.C

Win32/Diskcoder.Petya.D

Win32/Diskcoder.Petya.E

Win32/Diskcoder.Petya.F

Phishing

Bank of America

26th June 2017

Bank of America Alert: Unusual
Account Activity

Vulnerebility

QEMU 'hw/display/cirrus_vga_rop.h' Multiple Memory Corruption Vulnerabilities
2017-06-27
http://www.securityfocus.com/bid/97957

Ghostscript CVE-2017-7207 Denial of Service Vulnerability
2017-06-27
http://www.securityfocus.com/bid/96995

Microsoft Skype 'MSFTEDIT.DLL' Buffer Overflow Vulnerability
2017-06-26
http://www.securityfocus.com/bid/99281

OCaml CVE-2017-9772 Local Privilege Escalation Vulnerability
2017-06-26
http://www.securityfocus.com/bid/99277

Expat CVE-2017-9233 XML External Entity Denial of Service Vulnerability
2017-06-26
http://www.securityfocus.com/bid/99276

LAME CVE-2017-9869 Buffer Overflow Vulnerability
2017-06-26
http://www.securityfocus.com/bid/99272

LAME CVE-2017-9872 Stack Buffer Overflow Vulnerability
2017-06-26
http://www.securityfocus.com/bid/99270

LAME CVE-2015-9101 Heap Based Buffer Overflow Vulnerability
2017-06-26
http://www.securityfocus.com/bid/99269

LAME CVE-2015-9099 Denial of Service Vulnerability
2017-06-25
http://www.securityfocus.com/bid/99279

LAME CVE-2015-9100 Denial of Service Vulnerability
2017-06-25
http://www.securityfocus.com/bid/99278

IBM QRadar SIEM CVE-2016-9972 Information Disclosure Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99268

IBM API Connect CVE-2017-1328 Security Bypass Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99267

IBM QRadar SIEM CVE-2016-9738 Security Bypass Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99266

IBM QRadar CVE-2017-1234 HTML Injection Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99265

Linux Kernel CVE-2017-7518 Privilage Escalation Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99263

Microsoft Malware Protection Engine CVE-2017-8558 Remote Code Execution Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99262

Huawei Smart Phones CVE-2017-8143 Local Denial of Service Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99256

SANS News

A Tale of Two Phishies

Wide-scale Petya variant ransomware attack noted

Checking out the new Petya variant

Threatpost

Another RCE Vulnerability Patched in Microsoft Malware Protection Engine

Anthem Agrees to Settle 2015 Data Breach for $115 Million

Svpeng Behind a Spike in Mobile Ransomware

Exploit

Symantec Messaging Gateway 10.6.2-7 - Remote Code Execution (Metasploit)

Netgear DGN2200 - dnslookup.cgi Command Injection (Metasploit)

Easy File Sharing HTTP Server 7.2 - POST Buffer Overflow (Metasploit)

Eltek SmartPack - Backdoor Account

JAD Java Decompiler 1.5.8e - Buffer Overflow

NTFS 3.1 - Master File Table Denial of Service

LAME 3.99.5 - 'II_step_one' Buffer Overflow

LAME 3.99.5 - 'III_dequantize_sample' Stack-Based Buffer Overflow

IBM DB2 9.7 / 10.1 / 10.5 / 11.1 - Command Line Processor Buffer Overflow

Linux/x86 - Bind Shell Shellcode (75 bytes)

26.6.2017

Bugtraq

CVE-2017-8831] Double-Fetch Vulnerability in Linux-4.10.1/drivers/media/pci/saa7164/saa7164-bus.c 2017-06-26
wpengfeinudt gmail com

DefenseCode Security Advisory: IBM DB2 Command Line Processor Buffer Overflow 2017-06-26
DefenseCode (defensecode defensecode com)

Microsoft Skype v7.2, v7.35 & v7.36 - Stack Buffer Overflow Vulnerability 2017-06-26
Vulnerability Lab (research vulnerability-lab com)

CVE-2017-8831] Double-Fetch Vulnerability in Linux-4.10.1/drivers/media/pci/saa7164/saa7164-bus.c 2017-06-24
wpengfeinudt gmail com

CVE-2017-8813] Double-Fetch Vulnerability in Linux-4.10.1/drivers/media/pci/saa7164/saa7164-bus.c 2017-06-22
wpengfeinudt gmail com

Malware

Ransom:Linux/Erebus.A

Phishing

Wells Fargo

24th June 2017

SECURITY UPDATE: You have
unread secured message

UNITED BANK OF AFRICA UBA

24th June 2017

YOUR PAYMENT NOTIFICATION

PayPal

24th June 2017

NOTIFICATION ABOUT YOUR PAYPAL
ACCOUNT (ROUTING CODE: C 826-L
003-Q190-T1830)

Vulnerebility

Microsoft Skype 'MSFTEDIT.DLL' Buffer Overflow Vulnerability
2017-06-26
http://www.securityfocus.com/bid/99281

OCaml CVE-2017-9772 Local Privilege Escalation Vulnerability
2017-06-26
http://www.securityfocus.com/bid/99277

Expat CVE-2017-9233 XML External Entity Denial of Service Vulnerability
2017-06-26
http://www.securityfocus.com/bid/99276

LAME CVE-2017-9869 Buffer Overflow Vulnerability
2017-06-26
http://www.securityfocus.com/bid/99272

LAME CVE-2017-9872 Stack Buffer Overflow Vulnerability
2017-06-26
http://www.securityfocus.com/bid/99270

LAME CVE-2015-9101 Heap Based Buffer Overflow Vulnerability
2017-06-26
http://www.securityfocus.com/bid/99269

LAME CVE-2015-9099 Denial of Service Vulnerability
2017-06-25
http://www.securityfocus.com/bid/99279

LAME CVE-2015-9100 Denial of Service Vulnerability
2017-06-25
http://www.securityfocus.com/bid/99278

IBM QRadar SIEM CVE-2016-9972 Information Disclosure Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99268

IBM API Connect CVE-2017-1328 Security Bypass Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99267

IBM QRadar SIEM CVE-2016-9738 Security Bypass Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99266

IBM QRadar CVE-2017-1234 HTML Injection Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99265

Linux Kernel CVE-2017-7518 Privilage Escalation Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99263

Microsoft Malware Protection Engine CVE-2017-8558 Remote Code Execution Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99262

Huawei Smart Phones CVE-2017-8143 Local Denial of Service Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99256

NetBSD CVE-2017-1000378 Arbitrary Code Execution Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99255

Multiple Pivotal Products CVE-2017-4974 SQL Injection Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99254

Siemens XHQ CVE-2017-6866 Access Bypass Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99247

IBM Sterling B2B Integrator CVE-2017-1348 Unspecified Cross Site Scripting Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99245

GNU Debugger (GDB) CVE-2017-9778 Denial of Service Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99244

EMC Avamar Authentication Bypass And Arbitrary File Upload Vulnerabilities
2017-06-23
http://www.securityfocus.com/bid/99243

Oracle Java SE and JRockit CVE-2017-3511 Local Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97731

zlib Multiple Denial of Service Vulnerabilities
2017-06-22
http://www.securityfocus.com/bid/95131

Oracle Java SE CVE-2017-3514 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97729

Oracle Java SE CVE-2017-3512 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97727

IBM Java SDK CVE-2017-1289 XML External Entity Injection Vulnerability
2017-06-22
http://www.securityfocus.com/bid/98401

Oracle Java SE CVE-2017-3539 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97752

Oracle Java SE CVE-2017-3509 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97737

Oracle Java SE and JRockit CVE-2017-3544 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97745

Oracle Java SE and JRockit CVE-2017-3533 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97740

SANS News

Investigation of BitTorrent Sync (v.2.0) as a P2P Cloud (Part 1)

Threatpost

New EU Privacy Laws Will Complicate B2B Data Sharing

Exploit

 

25.6.2017

Bugtraq

CVE-2017-8813] Double-Fetch Vulnerability in Linux-4.10.1/drivers/media/pci/saa7164/saa7164-bus.c 2017-06-22
wpengfeinudt gmail com

SECURITY] DSA 3893-1] jython security update 2017-06-22
Salvatore Bonaccorso (carnil debian org)

 

Malware

 

Phishing

PayPal

24th June 2017

NOTIFICATION ABOUT YOUR PAYPAL
ACCOUNT (ROUTING CODE: C 826-L
003-Q190-T1830)

PayPal

23rd June 2017

Why is my account access
limited?

Wells Fargo

23rd June 2017

SECURITY UPDATE: You have
unread secured message

TalkTalk

23rd June 2017

Security upgrade

Vulnerebility

Linux Kernel CVE-2017-7518 Privilage Escalation Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99263

Microsoft Malware Protection Engine CVE-2017-8558 Remote Code Execution Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99262

Huawei Smart Phones CVE-2017-8143 Local Denial of Service Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99256

NetBSD CVE-2017-1000378 Arbitrary Code Execution Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99255

Multiple Pivotal Products CVE-2017-4974 SQL Injection Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99254

Siemens XHQ CVE-2017-6866 Access Bypass Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99247

IBM Sterling B2B Integrator CVE-2017-1348 Unspecified Cross Site Scripting Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99245

GNU Debugger (GDB) CVE-2017-9778 Denial of Service Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99244

EMC Avamar Authentication Bypass And Arbitrary File Upload Vulnerabilities
2017-06-23
http://www.securityfocus.com/bid/99243

Oracle Java SE and JRockit CVE-2017-3511 Local Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97731

zlib Multiple Denial of Service Vulnerabilities
2017-06-22
http://www.securityfocus.com/bid/95131

Oracle Java SE CVE-2017-3514 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97729

Oracle Java SE CVE-2017-3512 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97727

IBM Java SDK CVE-2017-1289 XML External Entity Injection Vulnerability
2017-06-22
http://www.securityfocus.com/bid/98401

Oracle Java SE CVE-2017-3539 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97752

Oracle Java SE CVE-2017-3509 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97737

Oracle Java SE and JRockit CVE-2017-3544 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97745

Oracle Java SE and JRockit CVE-2017-3533 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97740

Drupal Core CVE-2017-6920 Remote Code Execution Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99211

JasPer 'jp2_dec.c' Remote Heap Buffer Overflow Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99171

IBM Tivoli Monitoring SOAP Server CVE-2016-6083 Information Disclosure Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99259

IBM API Connect CVE-2017-1322 XML External Entity Injection Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99258

MatrixSSL 'X509' Certificate Parsing Multiple Buffer Overflow Vulnerabilities
2017-06-22
http://www.securityfocus.com/bid/99249

ExpressionEngine CVE-2017-0897 Insufficient Entropy Weakness
2017-06-22
http://www.securityfocus.com/bid/99242

Poppler 'GfxState.cc' Stack Buffer Overflow Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99241

Poppler CVE-2017-9776 Denial of Service Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99240

LibTIFF 'libtiff/tif_dirread.c' Denial of Service Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99235

Siemens SIMATIC CP 44x-1 Redundant CVE-2017-6868 Authentication Bypass Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99234

OpenVPN Multiple Security Vulnerabilities
2017-06-22
http://www.securityfocus.com/bid/99230

IBM Sterling B2B Integrator CVE-2017-1193 Information Disclosure Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99229
SANS News

 

Threatpost

NSA Advocates Data Sharing Framework

Few Victims Reporting Ransomware Attacks to FBI

Siemens Patches Vulnerabilities in SIMATIC CP, XHQ

Exploit

Microsoft Windows - 'USP10!MergeLigRecords' Uniscribe Font Processing Heap-Based Memory...

Microsoft Windows - 'USP10!ttoGetTableData' Uniscribe Font Processing Out-of-Bounds...

Microsoft Windows - 'USP10!SubstituteNtoM' Uniscribe Font Processing Out-of-Bounds Memory...

Microsoft Windows - 'USP10!CreateIndexTable' Uniscribe Font Processing Out-of-Bounds...

Microsoft Windows - 'USP10!NextCharInLiga' Uniscribe Font Processing Out-of-Bounds Memory...

Microsoft Windows - 'USP10!otlSinglePosLookup::getCoverageTable' Uniscribe Font...

Microsoft Windows - 'USP10!otlValueRecord::adjustPos' Uniscribe Font Processing...

Microsoft Windows - 'USP10!otlReverseChainingLookup::apply' Uniscribe Font Processing...

Microsoft Windows - 'nt!NtQueryInformationResourceManager (information class 0)' Kernel...

Microsoft Windows - 'nt!NtQueryInformationResourceManager (information class 0)' Kernel...

Microsoft Windows - Kernel ATMFD.DLL Out-of-Bounds Read due to Malformed Name INDEX in...

Microsoft Windows - 'nt!NtQueryInformationWorkerFactory (WorkerFactoryBasicInformation)'...

unrar 5.40 - VMSF_DELTA Filter Arbitrary Memory Write

Microsoft Edge - 'CssParser::RecordProperty' Type Confusion

Adobe Flash - AVC Edge Processing Out-of-Bounds Read

Adobe Flash - Image Decoding Out-of-Bounds Read

Adobe Flash - ATF Parser Heap Corruption

23.6.2017

Bugtraq

CVE-2017-8813] Double-Fetch Vulnerability in Linux-4.10.1/drivers/media/pci/saa7164/saa7164-bus.c 2017-06-22
wpengfeinudt gmail com

SECURITY] DSA 3893-1] jython security update 2017-06-22
Salvatore Bonaccorso (carnil debian org)

Malware

Trojan:Win32/CrashOverride.A

OSX.Salgorea.B

Phishing

TalkTalk

23rd June 2017

Security upgrade

Vulnerebility

NetBSD CVE-2017-1000378 Arbitrary Code Execution Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99255

Siemens XHQ CVE-2017-6866 Access Bypass Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99247

IBM Sterling B2B Integrator CVE-2017-1348 Unspecified Cross Site Scripting Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99245

GNU Debugger (GDB) CVE-2017-9778 Denial of Service Vulnerability
2017-06-23
http://www.securityfocus.com/bid/99244

EMC Avamar Authentication Bypass And Arbitrary File Upload Vulnerabilities
2017-06-23
http://www.securityfocus.com/bid/99243

Oracle Java SE and JRockit CVE-2017-3511 Local Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97731

zlib Multiple Denial of Service Vulnerabilities
2017-06-22
http://www.securityfocus.com/bid/95131

Oracle Java SE CVE-2017-3514 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97729

Oracle Java SE CVE-2017-3512 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97727

IBM Java SDK CVE-2017-1289 XML External Entity Injection Vulnerability
2017-06-22
http://www.securityfocus.com/bid/98401

Oracle Java SE CVE-2017-3539 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97752

Oracle Java SE CVE-2017-3509 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97737

Oracle Java SE and JRockit CVE-2017-3544 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97745

Oracle Java SE and JRockit CVE-2017-3533 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97740

Drupal Core CVE-2017-6920 Remote Code Execution Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99211

JasPer 'jp2_dec.c' Remote Heap Buffer Overflow Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99171

MatrixSSL 'X509' Certificate Parsing Multiple Buffer Overflow Vulnerabilities
2017-06-22
http://www.securityfocus.com/bid/99249

ExpressionEngine CVE-2017-0897 Insufficient Entropy Weakness
2017-06-22
http://www.securityfocus.com/bid/99242

Poppler 'GfxState.cc' Stack Buffer Overflow Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99241

Poppler CVE-2017-9776 Denial of Service Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99240

LibTIFF 'libtiff/tif_dirread.c' Denial of Service Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99235

Siemens SIMATIC CP 44x-1 Redundant CVE-2017-6868 Authentication Bypass Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99234

OpenVPN Multiple Security Vulnerabilities
2017-06-22
http://www.securityfocus.com/bid/99230

IBM Sterling B2B Integrator CVE-2017-1193 Information Disclosure Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99229

IBM Sterling B2B Integrator CVE-2016-5893 Local Information Disclosure Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99228

IBM Sterling B2B Integrator CVE-2017-1131 Information Disclosure Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99227

Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL Injection Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99214

Mozilla Network Security Services CVE-2017-7502 Denial of Service Vulnerability
2017-06-21
http://www.securityfocus.com/bid/98744

Linux Kernel CVE-2017-8890 Denial of Service Vulnerability
2017-06-21
http://www.securityfocus.com/bid/98562

Linux kernel CVE-2017-7308 Local Denial of Service Vulnerability
2017-06-21
http://www.securityfocus.com/bid/97234

SANS News

Fake DDoS Extortions Continue. Please Forward Us Any Threats You Have Received.

Threatpost

Cisco Patches XXE, DOS, Code Execution Vulnerabilities

Average Cost of Breach Goes Down For the First Time Ever

Microsoft Says Fireball Threat ‘Overblown’

Drupal Patches Three Vulnerabilities in Core Engine

Exploit

Microsoft Windows - 'nt!NtQueryInformationResourceManager (information class 0)'...

Microsoft Windows - 'nt!NtQueryInformationWorkerFactory...

Microsoft Edge - 'CssParser::RecordProperty' Type Confusion

22.6.2017

Bugtraq

CVE-2017-8813] Double-Fetch Vulnerability in Linux-4.10.1/drivers/media/pci/saa7164/saa7164-bus.c 2017-06-22
wpengfeinudt gmail com

SECURITY] DSA 3893-1] jython security update 2017-06-22
Salvatore Bonaccorso (carnil debian org)

slackware-security] openvpn (SSA:2017-172-01) 2017-06-21
Slackware Security Team (security slackware com)

Sitecore 7.1-7.2 Cross Site Scripting Vulnerability 2017-06-21
hamedizadi gmail com

SECURITY] DSA 3890-1] spip security update 2017-06-21
Salvatore Bonaccorso (carnil debian org)

ESA-2017-053: EMC Isilon OneFS Privilege Escalation Vulnerability 2017-06-20
EMC Product Security Response Center (Security_Alert emc com)

Malware

Trojan.Bleagle

Phishing

CS Loxinfo

22nd June 2017

Loxinfo: You a Pending
Notification.

Vulnerebility

Oracle Java SE and JRockit CVE-2017-3511 Local Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97731

zlib Multiple Denial of Service Vulnerabilities
2017-06-22
http://www.securityfocus.com/bid/95131

Oracle Java SE CVE-2017-3514 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97729

Oracle Java SE CVE-2017-3512 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97727

IBM Java SDK CVE-2017-1289 XML External Entity Injection Vulnerability
2017-06-22
http://www.securityfocus.com/bid/98401

Oracle Java SE CVE-2017-3539 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97752

Oracle Java SE CVE-2017-3509 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97737

Oracle Java SE and JRockit CVE-2017-3544 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97745

Oracle Java SE and JRockit CVE-2017-3533 Remote Security Vulnerability
2017-06-22
http://www.securityfocus.com/bid/97740

Drupal Core CVE-2017-6920 Remote Code Execution Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99211

JasPer 'jp2_dec.c' Remote Heap Buffer Overflow Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99171

IBM Sterling B2B Integrator CVE-2016-5893 Local Information Disclosure Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99228

Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL Injection Vulnerability
2017-06-22
http://www.securityfocus.com/bid/99214

Mozilla Network Security Services CVE-2017-7502 Denial of Service Vulnerability
2017-06-21
http://www.securityfocus.com/bid/98744

Linux Kernel CVE-2017-8890 Denial of Service Vulnerability
2017-06-21
http://www.securityfocus.com/bid/98562

Linux kernel CVE-2017-7308 Local Denial of Service Vulnerability
2017-06-21
http://www.securityfocus.com/bid/97234

Linux Kernel CVE-2017-7895 Multiple Security Bypass Vulnerabilities
2017-06-21
http://www.securityfocus.com/bid/98085

Sudo '/src/ttyname.c' Local Privilege Escalation Vulnerability
2017-06-21
http://www.securityfocus.com/bid/98745

Oracle Solaris CVE-2017-3630 Local Privilege Escalation Vulnerability
2017-06-21
http://www.securityfocus.com/bid/99153

Oracle Solaris CVE-2017-3629 Local Privilege Escalation Vulnerability
2017-06-21
http://www.securityfocus.com/bid/99150

Oracle Solaris CVE-2017-3631 Local Privilege Escalation Vulnerability
2017-06-21
http://www.securityfocus.com/bid/99151

JasPer Null Pointer Dereference Denial of Service Vulnerability
2017-06-21
http://www.securityfocus.com/bid/93797

Cisco IOS XR Software CVE-2017-6718 Local Privilege Escalation Vulnerability
2017-06-21
http://www.securityfocus.com/bid/99226

Cisco Prime Collaboration Provisioning Tool CVE-2017-6703 Session Hijacking Vulnerability
2017-06-21
http://www.securityfocus.com/bid/99224

Cisco Prime Collaboration Provisioning CVE-2017-6704 Arbitrary File Download Vulnerability
2017-06-21
http://www.securityfocus.com/bid/99223

Drupal Core CVE-2017-6921 Security Bypass Vulnerability
2017-06-21
http://www.securityfocus.com/bid/99222

Cisco Prime Infrastructure and EPNM CVE-2017-6699 Cross Site Scripting Vulnerability
2017-06-21
http://www.securityfocus.com/bid/99221

Cisco Firepower Management Center CVE-2017-6716 HTML Injection Vulnerability
2017-06-21
http://www.securityfocus.com/bid/99220

Drupal Core CVE-2017-6922 Access Bypass Vulnerability
2017-06-21
http://www.securityfocus.com/bid/99219

Cisco StarOS for ASR 5500 Series Routers CVE-2017-3865 Remote Denial of Service Vulnerability
2017-06-21
http://www.securityfocus.com/bid/99218

SANS News

Obfuscating without XOR

Threatpost

Trump’s Cybersecurity Executive Order Under Fire


Microsoft Extends Edge Bug Bounty Program Indefinitely

 

OpenVPN Patches Critical Remote Code Execution Vulnerability

 

Honda Shut Down Plant Impacted by WannaCry

Exploit

PHPMailer < 5.2.20 with Exim MTA - Remote Code Execution

Linux/x86 - Reverse UDP Shellcode (668 bytes)

21.6.2017

Bugtraq

ESA-2017-053: EMC Isilon OneFS Privilege Escalation Vulnerability 2017-06-20
EMC Product Security Response Center (Security_Alert emc com)

ESA-2017-054: EMC Avamar Multiple Vulnerabilities 2017-06-20
EMC Product Security Response Center (Security_Alert emc com)

CVE-2017-3167: Apache httpd 2.x ap_get_basic_auth_pw authentication bypass 2017-06-19
Jacob Champion (jchampion apache org)

CVE-2017-7659: mod_http2 null pointer dereference 2017-06-19
Jim Jagielski (jim apache org)

SECURITY] DSA 3886-1] linux security update 2017-06-19
Salvatore Bonaccorso (carnil debian org)

SECURITY] DSA 3887-1] glibc security update 2017-06-19
Moritz Muehlenhoff (jmm debian org)

security bulletin] HPESBGN03758 rev.2 - HPE UCMDB, Remote Code Execution 2017-06-19
HPE Product Security Response Team (security-alert hpe com)

Malware

 

Phishing

NatWest

21st June 2017

IMPORTANT SECURITY INFORMATION

 

Vulnerebility

Mozilla Network Security Services CVE-2017-7502 Denial of Service Vulnerability
2017-06-21
http://www.securityfocus.com/bid/98744

Linux Kernel CVE-2017-8890 Denial of Service Vulnerability
2017-06-21
http://www.securityfocus.com/bid/98562

Linux kernel CVE-2017-7308 Local Denial of Service Vulnerability
2017-06-21
http://www.securityfocus.com/bid/97234

Linux Kernel CVE-2017-7895 Multiple Security Bypass Vulnerabilities
2017-06-21
http://www.securityfocus.com/bid/98085

Sudo '/src/ttyname.c' Local Privilege Escalation Vulnerability
2017-06-21
http://www.securityfocus.com/bid/98745

Oracle Solaris CVE-2017-3630 Local Privilege Escalation Vulnerability
2017-06-21
http://www.securityfocus.com/bid/99153

Oracle Solaris CVE-2017-3629 Local Privilege Escalation Vulnerability
2017-06-21
http://www.securityfocus.com/bid/99150

Oracle Solaris CVE-2017-3631 Local Privilege Escalation Vulnerability
2017-06-21
http://www.securityfocus.com/bid/99151

JasPer Null Pointer Dereference Denial of Service Vulnerability
2017-06-21
http://www.securityfocus.com/bid/93797

OpenBSD CVE-2017-1000373 Denial of Service Vulnerability
2017-06-21
http://www.securityfocus.com/bid/99177

EMC VASA Provider Virtual Appliance CVE-2017-4997 Remote Code Execution Vulnerability
2017-06-21
http://www.securityfocus.com/bid/99169

zlib Multiple Denial of Service Vulnerabilities
2017-06-20
http://www.securityfocus.com/bid/95131

IBM Java SDK CVE-2017-1289 XML External Entity Injection Vulnerability
2017-06-20
http://www.securityfocus.com/bid/98401

Oracle Java SE and JRockit CVE-2017-3533 Remote Security Vulnerability
2017-06-20
http://www.securityfocus.com/bid/97740

Oracle Java SE CVE-2017-3539 Remote Security Vulnerability
2017-06-20
http://www.securityfocus.com/bid/97752

Oracle Java SE CVE-2017-3509 Remote Security Vulnerability
2017-06-20
http://www.securityfocus.com/bid/97737

Oracle Java SE and JRockit CVE-2017-3544 Remote Security Vulnerability
2017-06-20
http://www.securityfocus.com/bid/97745

Oracle Java SE and JRockit CVE-2017-3526 Remote Security Vulnerability
2017-06-20
http://www.securityfocus.com/bid/97733

Oracle Java SE and JRockit CVE-2017-3511 Local Security Vulnerability
2017-06-20
http://www.securityfocus.com/bid/97731

Oracle Java SE CVE-2017-3512 Remote Security Vulnerability
2017-06-20
http://www.securityfocus.com/bid/97727

Oracle Java SE CVE-2017-3514 Remote Security Vulnerability
2017-06-20
http://www.securityfocus.com/bid/97729

Symantec Web Gateway CVE-2016-9096 Multiple Cross Site Scripting Vulnerabilities
2017-06-20
http://www.securityfocus.com/bid/96297

GnuTLS CVE-2017-7507 NULL Pointer Dereference Denial of Service Vulnerability
2017-06-20
http://www.securityfocus.com/bid/99102

Xen 'shadow/common.c' Privilege Escalation Vulnerability
2017-06-20
http://www.securityfocus.com/bid/99174

JasPer 'jp2_dec.c' Remote Heap Buffer Overflow Vulnerability
2017-06-20
http://www.securityfocus.com/bid/99171

Xen XSA-220 Information Disclosure Vulnerability
2017-06-20
http://www.securityfocus.com/bid/99167

EMC Isilon OneFS CVE-2017-4988 Remote Privilege Escalation Vulnerability
2017-06-20
http://www.securityfocus.com/bid/99165

Ecava IntegraXor CVE-2017-6050 SQL Injection Vulnerability
2017-06-20
http://www.securityfocus.com/bid/99164

Xen 'blkif' Response Information Disclosure Vulnerability
2017-06-20
http://www.securityfocus.com/bid/99162

Xen XSA-222 Privilege Escalation Vulnerability
2017-06-20
http://www.securityfocus.com/bid/99161

SANS News

Windows Error Reporting: DFIR Benefits and Privacy Concerns

It has been a month and a bit how is your new patching program holding up?

Threatpost

Avaya Patches Remote Code Execution Flaw in Aura

ProtonMail Launches Free VPN Service

University College London Ransomware Linked to AdGholas Malvertising Group

Internet-Enabled Drill Demonstrates IoT Security Done Right

TP-Link Fixes Code Execution Vulnerability in End-of-Life Routers

Exploit

Microsoft Windows - 'win32k!NtGdiGetOutlineTextMetricsInternalW' Kernel Pool Memory...

Microsoft Windows - 'IOCTL 0x390400, operation code 0x00020000' Kernel KsecDD Pool...

Microsoft Windows - 'IOCTL_MOUNTMGR_QUERY_POINTS' Kernel Mountmgr Pool Memory...

Microsoft Windows - '0x224000 IOCTL (WmiQueryAllData)' Kernel WMIDataDevice Pool...

Microsoft Windows - 'win32k!NtGdiEnumFonts' Kernel Pool Memory Disclosure

Microsoft Windows - 'IOCTL_VOLUME_GET_VOLUME_DISK_EXTENTS' volmgr Pool Memory...

Microsoft Windows - 'IOCTL_DISK_GET_DRIVE_GEOMETRY_EX' Kernel partmgr Pool Memory...

WonderCMS 2.1.0 - Cross-Site Request Forgery

Freeware Advanced Audio Coder (FAAC) 1.28 - Denial of Service

20.6.2017

Bugtraq

CVE-2017-3167: Apache httpd 2.x ap_get_basic_auth_pw authentication bypass 2017-06-19
Jacob Champion (jchampion apache org)

CVE-2017-7659: mod_http2 null pointer dereference 2017-06-19
Jim Jagielski (jim apache org)

SECURITY] DSA 3886-1] linux security update 2017-06-19
Salvatore Bonaccorso (carnil debian org)

SECURITY] DSA 3887-1] glibc security update 2017-06-19
Moritz Muehlenhoff (jmm debian org)

security bulletin] HPESBGN03758 rev.2 - HPE UCMDB, Remote Code Execution 2017-06-19
HPE Product Security Response Team (security-alert hpe com)

Ektron Version 9.10SP1(Build 9.1.0.184) Cross Site Scripting 2017-06-19
ghasseminia gmail com

Ektron Version 9.10SP1(Build 9.1.0.184) Cross Site Scripting 2017-06-19
ghasseminia gmail com

Malware

Ransom.Sorebrect

Trojan.Bleagle

Phishing

 

Vulnerebility

Oracle Solaris CVE-2017-3629 Local Privilege Escalation Vulnerability
2017-06-20
http://www.securityfocus.com/bid/99150

Symantec Web Gateway CVE-2016-9096 Multiple Cross Site Scripting Vulnerabilities
2017-06-20
http://www.securityfocus.com/bid/96297

GnuTLS CVE-2017-7507 NULL Pointer Dereference Denial of Service Vulnerability
2017-06-20
http://www.securityfocus.com/bid/99102

Xen Page Transfer 'xen/arch/x86/mm.c' Privilege Escalation Vulnerability
2017-06-20
http://www.securityfocus.com/bid/99158

Xen 'xen/arch/x86/irq.c' NULL pointer Dereference Remote Denial of Service Vulnerability
2017-06-20
http://www.securityfocus.com/bid/99157

Linux Kernel CVE-2017-1000365 Local Security Bypass Vulnerability
2017-06-20
http://www.securityfocus.com/bid/99156

Linux Kernel CVE-2017-1000370 Local Security Bypass Vulnerability
2017-06-20
http://www.securityfocus.com/bid/99149

C-ares CVE-2017-1000381 Out of Bounds Read Information Disclosure Vulnerability
2017-06-20
http://www.securityfocus.com/bid/99148

Multiple I-O DATA Network Camera Products CVE-2017-2223 Cross Site Request Forgery Vulnerability
2017-06-20
http://www.securityfocus.com/bid/99144

SAP Business Objects DS Open Redirection Vulnerability
2017-06-20
http://www.securityfocus.com/bid/99143

Microsoft Windows Uniscribe CVE-2017-0283 Remote Code Execution Vulnerability
2017-06-19
http://www.securityfocus.com/bid/98920

Oracle Solaris CVE-2017-3630 Local Privilege Escalation Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99153

Oracle Solaris CVE-2017-3631 Local Privilege Escalation Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99151

Zenbership CVE-2017-9759 SQL Injection Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99147

GNU GRUB CVE-2017-9763 Remote Denial Of Service Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99141

radare2 'libr/core/cmd_info.c' Remote Denial Of Service Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99140

radare2 'libr/core/cmd.c' Remote Denial Of Service Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99138

Apache HTTP Server CVE-2017-7668 Denial of Service Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99137

IBM WebSphere MQ CVE-2017-1117 Denial of Service Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99136

Apache HTTP Server CVE-2017-3167 Authentication Bypass Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99135

Apache HTTP Server CVE-2017-3169 Denial of Service Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99134

Apache HTTP Server CVE-2017-7659 Denial of Service Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99132

Linux Kernel CVE-2017-1000371 Local Security Bypass Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99131

Linux Kernel CVE-2017-1000364 Local Memory Corruption Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99130

PAX Linux CVE-2017-1000377 Security Bypass Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99129

Acronis True Image CVE-2017-3219 Man in the Middle Security Bypass Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99128

GNU glibc CVE-2017-1000366 Local Memory Corruption Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99127

GNU Binutils CVE-2017-9754 Remote Denial of Service Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99125

GNU Binutils CVE-2017-9755 Remote Denial of Service Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99124

GNU Binutils 'bfd/vms-alpha.c' Remote Buffer Overflow Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99122

SANS News

As Your Admin Walks Out the Door ..

Windows Error Reporting: DFIR Benefits and Privacy Concerns

Threatpost

Google Removes Two Ztorg Trojans from Play Marketplace

Republican Data Broker Exposes 198M Voter Records

Mexican Journalists, Lawyers Focus of Government Spyware

FIN10 Extorting Canadian Mining Companies, Casinos
Windows Error Reporting: DFIR Benefits and Privacy Concerns

Exploit

iBall Baton iB-WRA150N - Unauthenticated DNS Change

nuevoMailer 6.0 - SQL Injection

GNU binutils - 'rx_decode_opcode' Buffer Overflow

GNU binutils - 'disassemble_bytes' Heap Overflow

GNU binutils - 'bfd_get_string' Stack Buffer Overflow

GNU binutils - 'decode_pseudodbg_assert_0' Buffer Overflow

GNU binutils - 'ieee_object_p' Stack Buffer Overflow

GNU binutils - 'print_insn_score16' Buffer Overflow

GNU binutils - 'aarch64_ext_ldst_reglist' Buffer Overflow

19.6.2017

Bugtraq

SECURITY] DSA 3887-1] glibc security update 2017-06-19
Moritz Muehlenhoff (jmm debian org)

security bulletin] HPESBGN03758 rev.2 - HPE UCMDB, Remote Code Execution 2017-06-19
HPE Product Security Response Team (security-alert hpe com)

Ektron Version 9.10SP1(Build 9.1.0.184) Cross Site Scripting 2017-06-19
ghasseminia gmail com

Ektron Version 9.10SP1(Build 9.1.0.184) Cross Site Scripting 2017-06-19
ghasseminia gmail com

Ektron Version 9.10SP1(Build 9.1.0.184) Cross Site Scripting 2017-06-19
ghasseminia gmail com

ESA-2017-041: EMC VNX1 and VNX2 Family Multiple Vulnerabilities in VNX Control Station 2017-06-16
EMC Product Security Response Center (Security_Alert emc com)

June 2017 - Bamboo - Critical Security Advisory 2017-06-16
Atlassian (security atlassian com)

security bulletin] HPESBGN03761 rev.1 - HPE Virtualization Performance Viewer (VPV)/ Cloud Optimizer using Linux, Remote Escalation of Privilege 2017-06-15
security-alert hpe com

Malware

 

Phishing

 

Vulnerebility

GNU Binutils CVE-2017-9750 Remote Denial of Service Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99118

GNU Binutils 'objdump.c' Remote Denial of Service Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99117

GNU Binutils 'bfd/ieee.c' Remote Denial of Service Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99114

GNU Binutils CVE-2017-9749 Remote Denial of Service Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99113

GNU Binutils CVE-2017-9748 Remote Denial of Service Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99110

GNU Binutils 'bfd/vms-alpha.c' Heap Buffer Overflow Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99109

GNU Binutils 'bfd/elf32-sh.c' Remote Buffer Overflow Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99108

GNU Binutils 'opcodes/score7-dis.c' Remote Buffer Overflow Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99106

GNU Binutils 'opcodes/score7-dis.c' Remote Denial of Service Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99105

GNU Binutils 'opcodes/aarch64-dis.c' Remote Denial of Service Vulnerability
2017-06-19
http://www.securityfocus.com/bid/99103

Linux Kernel CVE-2017-8064 Local Denial of Service Vulnerability
2017-06-17
http://www.securityfocus.com/bid/97975

VMware vSphere Data Protection CVE-2016-7456 Authentication Bypass Vulnerability
2017-06-16
http://www.securityfocus.com/bid/94990

Multiple Blue Coat Products Security Bypass Vulnerability
2017-06-16
http://www.securityfocus.com/bid/91404

Jetty CVE-2017-9735 Security Bypass Vulnerability
2017-06-16
http://www.securityfocus.com/bid/99104

IBM Clustered Data ONTAP CVE-2016-3400 Man in the Middle Security Bypass Vulnerability
2017-06-16
http://www.securityfocus.com/bid/99101

Deluge CVE-2017-9031 Directory Traversal Vulnerability
2017-06-16
http://www.securityfocus.com/bid/99099

389 Directory Server CVE-2016-5416 Information Disclosure Vulnerability
2017-06-16
http://www.securityfocus.com/bid/99097

Linux Kernel 'drivers/gpu/drm/vmwgfx/vmwgfx_surface.c' Local Information Disclosure Vulnerability
2017-06-16
http://www.securityfocus.com/bid/99095

FreeType 2 CVE-2017-8105 Out of Bounds Write Heap Buffer Overflow Vulnerability
2017-06-16
http://www.securityfocus.com/bid/99093

Apache Standard Taglibs CVE-2015-0254 XML External Entity Injection Vulnerability
2017-06-15
http://www.securityfocus.com/bid/72809

Mozilla Firefox Multiple Security Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/99057

Mozilla Firefox CVE-2017-5470 Multiple Unspecified Memory Corruption Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/99041

Mozilla Firefox CVE-2017-5472 Use After Free Denial of Service Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99040

Samba CVE-2017-7494 Remote Code Execution Vulnerability
2017-06-15
http://www.securityfocus.com/bid/98636

QEMU 'hw/display/cirrus_vga_rop.h' Multiple Memory Corruption Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/97957

Qemu 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-06-15
http://www.securityfocus.com/bid/97955

GnuTLS GNUTLS-SA-2017-3 Multiple Security Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/97040

Libgcrypt 'cipher/ecc-eddsa.c' Information Disclosure Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99046

Adobe Flash Player APSB17-17 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/99023

Adobe Flash Player APSB17-17 Multiple Memory Corruption Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/99025

SANS News

 

Threatpost

IoT Malware Activity Already More Than Doubled 2016 Numbers

Exploit

iBall Baton iB-WRA150N - Unauthenticated DNS Change

nuevoMailer 6.0 - SQL Injection

UTstarcom WA3002G4 - Unauthenticated DNS Change

D-Link DSL-2640U - Unauthenticated DNS Change

Beetel BCM96338 Router - Unauthenticated DNS Change

D-Link DSL-2640B - Unauthenticated Remote DNS Change

18.6.2017

Bugtraq

ESA-2017-041: EMC VNX1 and VNX2 Family Multiple Vulnerabilities in VNX Control Station 2017-06-16
EMC Product Security Response Center (Security_Alert emc com)

June 2017 - Bamboo - Critical Security Advisory 2017-06-16
Atlassian (security atlassian com)

security bulletin] HPESBGN03761 rev.1 - HPE Virtualization Performance Viewer (VPV)/ Cloud Optimizer using Linux, Remote Escalation of Privilege 2017-06-15
security-alert hpe com

SECURITY] DSA 3882-1] request-tracker4 security update 2017-06-15
Salvatore Bonaccorso (carnil debian org)

Malware

Ransom:Win32/Sorikrypt.A 

Phishing

 

Vulnerebility

VMware vSphere Data Protection CVE-2016-7456 Authentication Bypass Vulnerability
2017-06-16
http://www.securityfocus.com/bid/94990

Multiple Blue Coat Products Security Bypass Vulnerability
2017-06-16
http://www.securityfocus.com/bid/91404

IBM Clustered Data ONTAP CVE-2016-3400 Man in the Middle Security Bypass Vulnerability
2017-06-16
http://www.securityfocus.com/bid/99101

Deluge CVE-2017-9031 Directory Traversal Vulnerability
2017-06-16
http://www.securityfocus.com/bid/99099

389 Directory Server CVE-2016-5416 Information Disclosure Vulnerability
2017-06-16
http://www.securityfocus.com/bid/99097

Linux Kernel 'drivers/gpu/drm/vmwgfx/vmwgfx_surface.c' Local Information Disclosure Vulnerability
2017-06-16
http://www.securityfocus.com/bid/99095

FreeType 2 CVE-2017-8105 Out of Bounds Write Heap Buffer Overflow Vulnerability
2017-06-16
http://www.securityfocus.com/bid/99093

Apache Standard Taglibs CVE-2015-0254 XML External Entity Injection Vulnerability
2017-06-15
http://www.securityfocus.com/bid/72809

Mozilla Firefox Multiple Security Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/99057

Mozilla Firefox CVE-2017-5470 Multiple Unspecified Memory Corruption Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/99041

Mozilla Firefox CVE-2017-5472 Use After Free Denial of Service Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99040

Samba CVE-2017-7494 Remote Code Execution Vulnerability
2017-06-15
http://www.securityfocus.com/bid/98636

QEMU 'hw/display/cirrus_vga_rop.h' Multiple Memory Corruption Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/97957

Qemu 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-06-15
http://www.securityfocus.com/bid/97955

GnuTLS GNUTLS-SA-2017-3 Multiple Security Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/97040

Libgcrypt 'cipher/ecc-eddsa.c' Information Disclosure Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99046

Adobe Flash Player APSB17-17 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/99023

Adobe Flash Player APSB17-17 Multiple Memory Corruption Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/99025

GNU oSIP CVE-2016-10324 Heap Buffer Overflow Vulnerability
2017-06-15
http://www.securityfocus.com/bid/97641

GNU oSIP 'osipparser2/osip_message_parse.c' Heap Buffer Overflow Vulnerability
2017-06-15
http://www.securityfocus.com/bid/97644

Libosip Multiple Denial of Service Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/92921

ZZIPlib Multiple Heap Buffer Overflow and Denial of Service Vulnerabilites
2017-06-15
http://www.securityfocus.com/bid/96268

FortiOS Multiple Cross Site Scripting Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/99098

Google Chrome Multiple Security Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/99096

APC UPS Daemon CVE-2017-7884 Insecure Permissions Local Privilege Escalation Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99092

Atlassian Confluence CVE-2017-9505 Security Bypass Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99086

D-Link DIR-605L CVE-2017-9675 Denial of Service Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99084

Samsung Magician CVE-2017-3218 Remote Code Execution Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99081

Pivotal Spring Security Deserialization CVE-2017-4995 Remote Code Execution Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99080

RedHat JBoss Enterprise Application Platform CVE-2016-3690 Remote Code Execution Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99079

SANS News

Mapping Use Cases to Logs. Which Logs are the Most Important to Collect?

Threatpost

Nigerian BEC Scams Hit 500 Companies in 50 Countries

Someone Failed to Contain WannaCry

Wikileaks Alleges Years of CIA D-Link and Linksys Router Hacking Via ‘Cherry Blossom’ Program

Exploit

WebKit JSC - JSGlobalObject::haveABadTime Causes Type Confusions

WebKit JSC - arrayProtoFuncSplice does not Initialize all Indices

WebKit JSC - JIT Optimization Check Failed in...

WebKit JSC - Heap Buffer Overflow in Intl.getCanonicalLocales

Easy File Sharing Web Server 7.2 - 'POST' Buffer Overflow (DEP Bypass)

KBVault MySQL 0.16a - Arbitrary File Upload

Joomla! Component JoomRecipe 1.0.3 - SQL Injection

16.6.2017

Bugtraq

ESA-2017-041: EMC VNX1 and VNX2 Family Multiple Vulnerabilities in VNX Control Station 2017-06-16
EMC Product Security Response Center (Security_Alert emc com)

June 2017 - Bamboo - Critical Security Advisory 2017-06-16
Atlassian (security atlassian com)

security bulletin] HPESBGN03761 rev.1 - HPE Virtualization Performance Viewer (VPV)/ Cloud Optimizer using Linux, Remote Escalation of Privilege 2017-06-15
security-alert hpe com

SECURITY] DSA 3882-1] request-tracker4 security update 2017-06-15
Salvatore Bonaccorso (carnil debian org)

CVE-2017-9613: Stored Cross-Site Scripting in SAP successfactors 2017-06-15
dunstan pinto gmail com

slackware-security] mozilla-firefox (SSA:2017-165-02) 2017-06-15
Slackware Security Team (security slackware com)

slackware-security] bind (SSA:2017-165-01) 2017-06-15
Slackware Security Team (security slackware com)

SECURITY] DSA 3881-1] firefox-esr security update 2017-06-14
Moritz Muehlenhoff (jmm debian org)

Malware

Ransom:Win32/Jaffrans 

Phishing

 

Vulnerebility

Multiple Blue Coat Products Security Bypass Vulnerability
2017-06-16
http://www.securityfocus.com/bid/91404

Apache Standard Taglibs CVE-2015-0254 XML External Entity Injection Vulnerability
2017-06-15
http://www.securityfocus.com/bid/72809

Mozilla Firefox Multiple Security Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/99057

Mozilla Firefox CVE-2017-5470 Multiple Unspecified Memory Corruption Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/99041

Mozilla Firefox CVE-2017-5472 Use After Free Denial of Service Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99040

Samba CVE-2017-7494 Remote Code Execution Vulnerability
2017-06-15
http://www.securityfocus.com/bid/98636

QEMU 'hw/display/cirrus_vga_rop.h' Multiple Memory Corruption Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/97957

Qemu 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-06-15
http://www.securityfocus.com/bid/97955

GnuTLS GNUTLS-SA-2017-3 Multiple Security Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/97040

Libgcrypt 'cipher/ecc-eddsa.c' Information Disclosure Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99046

Adobe Flash Player APSB17-17 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/99023

Adobe Flash Player APSB17-17 Multiple Memory Corruption Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/99025

GNU oSIP CVE-2016-10324 Heap Buffer Overflow Vulnerability
2017-06-15
http://www.securityfocus.com/bid/97641

GNU oSIP 'osipparser2/osip_message_parse.c' Heap Buffer Overflow Vulnerability
2017-06-15
http://www.securityfocus.com/bid/97644

Libosip Multiple Denial of Service Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/92921

ZZIPlib Multiple Heap Buffer Overflow and Denial of Service Vulnerabilites
2017-06-15
http://www.securityfocus.com/bid/96268

Atlassian Confluence CVE-2017-9505 Security Bypass Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99086

D-Link DIR-605L CVE-2017-9675 Denial of Service Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99084

Samsung Magician CVE-2017-3218 Remote Code Execution Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99081

Pivotal Spring Security Deserialization CVE-2017-4995 Remote Code Execution Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99080

RedHat JBoss Enterprise Application Platform CVE-2016-3690 Remote Code Execution Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99079

Tablib CVE-2017-2810 Arbitrary Command Execution Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99076

SAP Successfactors CVE-2017-9613 HTML Injection Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99072

Microsoft Windows Kernel CVE-2017-0167 Information Disclosure Vulnerability
2017-06-14
http://www.securityfocus.com/bid/97473

Microsoft Remote Desktop Protocol Remote Code Execution Vulnerability
2017-06-14
http://www.securityfocus.com/bid/98752

Microsoft Windows Graphics Device Interface CVE-2017-0190 Information Disclosure Vulnerability
2017-06-14
http://www.securityfocus.com/bid/98298

Microsoft Internet Explorer CVE-2017-0222 Remote Memory Corruption Vulnerability
2017-06-14
http://www.securityfocus.com/bid/98127

Microsoft Skype for Business and Lync Server CVE-2017-8550 Remote Code Execution Vulnerability
2017-06-14
http://www.securityfocus.com/bid/98916

ISC BIND CVE-2017-3141 Local Privilege Escalation Vulnerability
2017-06-14
http://www.securityfocus.com/bid/99089

ISC BIND CVE-2017-3140 Remote Denial of Service Vulnerability
2017-06-14
http://www.securityfocus.com/bid/99088

SANS News

Uberscammers

What is going on with Port 83?

Threatpost

Metadata Analysis Draws its Own Conclusions on WannaCry Authors

Ransomware Attack Hobbles Prestigious University College London

Nigerian BEC Scams Hit 500 Companies in 50 Countries

Exploit

Avast aswSnx.sys Kernel Driver 11.1.2253 - Memory Corruption Privilege Escalation

Easy File Sharing Web Server 7.2 - 'POST' Buffer Overflow (DEP Bypass)

KBVault MySQL 0.16a - Arbitrary File Upload

Joomla! Component JoomRecipe 1.0.3 - SQL Injection

Sudo - 'get_process_ttyname()' Privilege Escalation

VX Search Enterprise 9.7.18 - Local Buffer Overflow

15.6.2017

Bugtraq

CVE-2017-9613: Stored Cross-Site Scripting in SAP successfactors 2017-06-15
dunstan pinto gmail com

slackware-security] mozilla-firefox (SSA:2017-165-02) 2017-06-15
Slackware Security Team (security slackware com)

slackware-security] bind (SSA:2017-165-01) 2017-06-15
Slackware Security Team (security slackware com)

SECURITY] DSA 3881-1] firefox-esr security update 2017-06-14
Moritz Muehlenhoff (jmm debian org)

ESA-2017-043: EMC ESRS Virtual Edition Authentication Bypass Vulnerability 2017-06-14
EMC Product Security Response Center (Security_Alert emc com)

ESA-2017-031: RSA BSAFE® Cert-C Improper Certificate Processing Vulnerability 2017-06-14
EMC Product Security Response Center (Security_Alert emc com)

Malware

Ransom:Linux/Erebus.A 

Phishing

 

Vulnerebility

Mozilla Firefox CVE-2017-5472 Use After Free Denial of Service Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99040

Mozilla Firefox Multiple Security Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/99057

Samba CVE-2017-7494 Remote Code Execution Vulnerability
2017-06-15
http://www.securityfocus.com/bid/98636

Mozilla Firefox CVE-2017-5470 Multiple Unspecified Memory Corruption Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/99041

QEMU 'hw/display/cirrus_vga_rop.h' Multiple Memory Corruption Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/97957

Qemu 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-06-15
http://www.securityfocus.com/bid/97955

GnuTLS GNUTLS-SA-2017-3 Multiple Security Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/97040

Libgcrypt 'cipher/ecc-eddsa.c' Information Disclosure Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99046

Adobe Flash Player APSB17-17 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/99023

Adobe Flash Player APSB17-17 Multiple Memory Corruption Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/99025

GNU oSIP CVE-2016-10324 Heap Buffer Overflow Vulnerability
2017-06-15
http://www.securityfocus.com/bid/97641

GNU oSIP 'osipparser2/osip_message_parse.c' Heap Buffer Overflow Vulnerability
2017-06-15
http://www.securityfocus.com/bid/97644

Libosip Multiple Denial of Service Vulnerabilities
2017-06-15
http://www.securityfocus.com/bid/92921

ZZIPlib Multiple Heap Buffer Overflow and Denial of Service Vulnerabilites
2017-06-15
http://www.securityfocus.com/bid/96268

SAP Successfactors CVE-2017-9613 HTML Injection Vulnerability
2017-06-15
http://www.securityfocus.com/bid/99072

Microsoft Windows Kernel CVE-2017-0167 Information Disclosure Vulnerability
2017-06-14
http://www.securityfocus.com/bid/97473

Microsoft Remote Desktop Protocol Remote Code Execution Vulnerability
2017-06-14
http://www.securityfocus.com/bid/98752

Microsoft Windows Graphics Device Interface CVE-2017-0190 Information Disclosure Vulnerability
2017-06-14
http://www.securityfocus.com/bid/98298

Microsoft Internet Explorer CVE-2017-0222 Remote Memory Corruption Vulnerability
2017-06-14
http://www.securityfocus.com/bid/98127

Microsoft Skype for Business and Lync Server CVE-2017-8550 Remote Code Execution Vulnerability
2017-06-14
http://www.securityfocus.com/bid/98916

Apache Ranger CVE-2016-8751 HTML Injection Vulnerability
2017-06-14
http://www.securityfocus.com/bid/99067

IBM API Connect CVE-2017-1379 Information Disclosure Vulnerability
2017-06-14
http://www.securityfocus.com/bid/99063

Mozilla Firefox for Android CVE-2017-7759 Local Security Bypass Vulnerability
2017-06-14
http://www.securityfocus.com/bid/99052

Microsoft Windows Kernel CVE-2017-0297 Local Privilege Escalation Vulnerability
2017-06-13
http://www.securityfocus.com/bid/98840

SAP Web Dispatcher Remote Code Injection Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99070

Trihedral VTScada Multiple Security Vulnerabilities
2017-06-13
http://www.securityfocus.com/bid/99066

SAP BusinessObjects Intercompany Directory Traversal Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99062

IBM Jazz Foundation CVE-2016-9973 Cross Site Scripting Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99060

OSIsoft PI Server 2017 Multiple Authentication Bypass Vulnerabilities
2017-06-13
http://www.securityfocus.com/bid/99059

OSIsoft PI Web API CVE-2017-7926 Cross-Site Request Forgery Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99058

SANS News

 

Threatpost

Abuse of Apple Search Ads Feature Leading to Fraud


DHS, FBI Warn of North Korea ‘Hidden Cobra’ Strikes Against US Assets

Decryption Utility Unlocks Files Encrypted by Jaff Ransomware

Mozilla Fixes 32 Vulnerabilities in Firefox 54

Exploit

Linux/x86 - XOR encoded execve(/bin/sh) setuid(0) setgid(0) Shellcode (66 bytes)

Linux/x86 - execve("/bin/sh") Shellcode (24 bytes)

Google Chrome - V8 Private Property Arbitrary Code Execution

HP PageWide Printers / HP OfficeJet Pro Printers (OfficeJet Pro 8210) - Arbitrary...

Easy MOV Converter 1.4.24 - 'Enter User Name' Buffer Overflow (SEH)

14.6.2017

Bugtraq

ESA-2017-043: EMC ESRS Virtual Edition Authentication Bypass Vulnerability 2017-06-14
EMC Product Security Response Center (Security_Alert emc com)

ESA-2017-031: RSA BSAFE® Cert-C Improper Certificate Processing Vulnerability 2017-06-14
EMC Product Security Response Center (Security_Alert emc com)

SECURITY] DSA 3880-1] libgcrypt20 security update 2017-06-14
Salvatore Bonaccorso (carnil debian org)

Secunia Research: libsndfile "aiff_read_chanmap()" Information Disclosure Vulnerability 2017-06-13
Secunia Research (remove-vuln secunia com)

SEC Consult SA-20170613-0 :: Access Restriction Bypass in Atlassian Confluence 2017-06-13
SEC Consult Vulnerability Lab (research sec-consult com)

Zenbership 1.0.8 CMS - Multiple SQL Injection Vulnerabilities 2017-06-12
Vulnerability Lab (research vulnerability-lab com)

Evolution Script CMS v5.3 - Cross Site Scripting Vulnerability 2017-06-12
Vulnerability Lab (research vulnerability-lab com)

Malware

BrowserModifier:Win32/Xiazai

Phishing

 

Vulnerebility

Microsoft Skype for Business and Lync Server CVE-2017-8550 Remote Code Execution Vulnerability
2017-06-14
http://www.securityfocus.com/bid/98916

Microsoft Windows Kernel CVE-2017-0297 Local Privilege Escalation Vulnerability
2017-06-13
http://www.securityfocus.com/bid/98840

EMC VNX1/VNX2 OE for File CVE-2017-4987 Unspecified Local Untrusted Search Path vulnerability
2017-06-13
http://www.securityfocus.com/bid/99045

EMC RSA BSAFE Cert-C CVE-2017-4981 Denial of Service Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99044

Mozilla Firefox CVE-2017-5471 Multiple Memory Corruption Vulnerabilities
2017-06-13
http://www.securityfocus.com/bid/99042

Mozilla Firefox CVE-2017-5470 Multiple Unspecified Memory Corruption Vulnerabilities
2017-06-13
http://www.securityfocus.com/bid/99041

Mozilla Firefox CVE-2017-5472 Use After Free Denial of Service Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99040

EMC VNX1/VNX2 OE for File CVE-2017-4984 Remote Code Execution Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99039

SAP BusinessObjects Web Intelligence Unspecified Cross Site Scripting Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99038

EMC VNX1/VNX2 OE for File CVE-2017-4985 Local Privilege Escalation Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99037

EMC Secure Remote Services Virtual Edition CVE-2017-4986 Authentication Bypass Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99036

SAP NetWeaver AS ABAP Unspecified Denial of Service Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99034

SAP NetWeaver Composite Application Framework and Business Cross Site Scripting Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99033

SAP Management Console Unspecified Information Disclosure Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99032

SAP Business Planning and Consolidation XML External Entity Injection Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99031

SAP NetWeaver Application Server ABAP Certificate Validation Security Bypass Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99030

SAP BI Launchpad Multiple Cross Site Scripting Vulnerabilities
2017-06-13
http://www.securityfocus.com/bid/99029

SAP BILaunchPad and Central Management Console Unspecified Denial of Service Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99028

SAP Note Assistant XML External Entity Injection Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99027

SAP NetWeaver Instance Agent Service Denial of Service Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99026

Adobe Flash Player APSB17-17 Multiple Memory Corruption Vulnerabilities
2017-06-13
http://www.securityfocus.com/bid/99025

Adobe Digital Editions Multiple Privilege Escalation Vulnerabilities
2017-06-13
http://www.securityfocus.com/bid/99024

Adobe Flash Player APSB17-17 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-06-13
http://www.securityfocus.com/bid/99023

Adobe Digital Editions APSB17-20 Multiple Unspecified Stack Buffer Overflow Vulnerabilities
2017-06-13
http://www.securityfocus.com/bid/99021

Adobe Digital Editions APSB17-20 Multiple Unspecified Memory Corruption Vulnerabilities
2017-06-13
http://www.securityfocus.com/bid/99020

Adobe Shockwave Player CVE-2017-3086 Unspecified Memory Corruption Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99019

Microsoft Edge CVE-2017-8555 Security Bypass Vulnerability
2017-06-13
http://www.securityfocus.com/bid/98956

Microsoft Edge CVE-2017-8549 Remote Code Execution Vulnerability
2017-06-13
http://www.securityfocus.com/bid/98955

Microsoft Edge CVE-2017-8548 Remote Memory Corruption Vulnerability
2017-06-13
http://www.securityfocus.com/bid/98954

Microsoft Internet Explorer and Edge CVE-2017-8529 Information Disclosure Vulnerability
2017-06-13
http://www.securityfocus.com/bid/98953
SANS News

Systemd Could Fallback to Google DNS?

Threatpost

Post-WannaCry, 5.5 Million Devices Still Expose SMB Port

Patrick Wardle on MacRansom Ransomware-as-a-Service

Adobe Fixes 21 Critical Vulnerabilities with June Patch Tuesday Update

Microsoft Patches Two Critical Vulnerabilities Under Attack

Exploit

WordPress Plugin WP Jobs < 1.5 - SQL Injection

WordPress Plugin Event List <= 0.7.8 - SQL Injection

WordPress Plugin WP-Testimonials < 3.4.1 - SQL Injection

Easy MOV Converter 1.4.24 - 'Enter User Name' Buffer Overflow (SEH)

LG MRA58K - Out-of-Bounds Heap Read in CAVIFileParser::Destroy Resulting in Invalid...

LG MRA58K - Missing Bounds-Checking in AVI Stream Parsing

LG MRA58K - 'ASFParser::ParseHeaderExtensionObjects' Missing Bounds-Checking

13.6.2017

Bugtraq

Secunia Research: libsndfile "aiff_read_chanmap()" Information Disclosure Vulnerability 2017-06-13
Secunia Research (remove-vuln secunia com)

SEC Consult SA-20170613-0 :: Access Restriction Bypass in Atlassian Confluence 2017-06-13
SEC Consult Vulnerability Lab (research sec-consult com)

Zenbership 1.0.8 CMS - Multiple SQL Injection Vulnerabilities 2017-06-12
Vulnerability Lab (research vulnerability-lab com)

Evolution Script CMS v5.3 - Cross Site Scripting Vulnerability 2017-06-12
Vulnerability Lab (research vulnerability-lab com)

SECURITY] DSA 3877-1] tor security update 2017-06-10
Salvatore Bonaccorso (carnil debian org)

security bulletin] HPESBHF03730 rev.2 - HPE Aruba ClearPass Policy Manager, Multiple Vulnerabilities 2017-06-09
security-alert hpe com

SECURITY] DSA 3876-1] otrs2 security update 2017-06-09
Moritz Muehlenhoff (jmm debian org)

Malware

Ransom.Erebus

Backdoor.Industroyer

Android.WannaLocker

Phishing

Tesco Bank

12th June 2017

Your Online Account Activity
Alert

spoof

12th June 2017

Tristam hates trap?

Vulnerebility

EMC VNX1/VNX2 OE for File CVE-2017-4984 Remote Code Execution Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99039

SAP BusinessObjects Web Intelligence Unspecified Cross Site Scripting Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99038

EMC VNX1/VNX2 OE for File CVE-2017-4985 Local Privilege Escalation Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99037

EMC Secure Remote Services Virtual Edition CVE-2017-4986 Authentication Bypass Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99036

SAP NetWeaver AS ABAP Unspecified Denial of Service Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99034

SAP NetWeaver Composite Application Framework and Business Cross Site Scripting Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99033

SAP Management Console Unspecified Information Disclosure Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99032

SAP Business Planning and Consolidation XML External Entity Injection Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99031

SAP NetWeaver Application Server ABAP Certificate Validation Security Bypass Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99030

SAP BI Launchpad Multiple Cross Site Scripting Vulnerabilities
2017-06-13
http://www.securityfocus.com/bid/99029

SAP BILaunchPad and Central Management Console Unspecified Denial of Service Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99028

SAP Note Assistant XML External Entity Injection Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99027

SAP NetWeaver Instance Agent Service Denial of Service Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99026

Adobe Flash Player APSB17-17 Multiple Memory Corruption Vulnerabilities
2017-06-13
http://www.securityfocus.com/bid/99025

Adobe Digital Editions Multiple Privilege Escalation Vulnerabilities
2017-06-13
http://www.securityfocus.com/bid/99024

Adobe Flash Player APSB17-17 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-06-13
http://www.securityfocus.com/bid/99023

Adobe Digital Editions APSB17-20 Multiple Unspecified Stack Buffer Overflow Vulnerabilities
2017-06-13
http://www.securityfocus.com/bid/99021

Adobe Digital Editions APSB17-20 Multiple Unspecified Memory Corruption Vulnerabilities
2017-06-13
http://www.securityfocus.com/bid/99020

Adobe Shockwave Player CVE-2017-3086 Unspecified Memory Corruption Vulnerability
2017-06-13
http://www.securityfocus.com/bid/99019

Microsoft Edge CVE-2017-8496 Remote Memory Corruption Vulnerability
2017-06-13
http://www.securityfocus.com/bid/98880

Microsoft Windows Kernel CVE-2017-8491 Local Information Disclosure Vulnerability
2017-06-13
http://www.securityfocus.com/bid/98869

Microsoft Windows Kernel CVE-2017-8490 Local Information Disclosure Vulnerability
2017-06-13
http://www.securityfocus.com/bid/98867

Microsoft Windows Kernel CVE-2017-8489 Local Information Disclosure Vulnerability
2017-06-13
http://www.securityfocus.com/bid/98865

Microsoft Windows Kernel CVE-2017-8488 Local Information Disclosure Vulnerability
2017-06-13
http://www.securityfocus.com/bid/98864

Microsoft Edge CVE-2017-8530 Security Bypass Vulnerability
2017-06-13
http://www.securityfocus.com/bid/98863

Microsoft Windows Kernel CVE-2017-8481 Local Information Disclosure Vulnerability
2017-06-13
http://www.securityfocus.com/bid/98862

Microsoft Windows Kernel CVE-2017-8485 Local Information Disclosure Vulnerability
2017-06-13
http://www.securityfocus.com/bid/98860

Microsoft Windows Kernel CVE-2017-8483 Local Information Disclosure Vulnerability
2017-06-13
http://www.securityfocus.com/bid/98859

Microsoft Windows Kernel CVE-2017-8482 Local Information Disclosure Vulnerability
2017-06-13
http://www.securityfocus.com/bid/98858

Microsoft Windows Kernel CVE-2017-8480 Local Information Disclosure Vulnerability
2017-06-13
http://www.securityfocus.com/bid/98857

SANS News

An Introduction to VolUtility

Threatpost

Blinking Router LEDs Leak Data From Air-Gapped Networks

FIN7 Hitting Restaurants with Fileless Malware

Exploit

Easy File Sharing Web Server 7.2 - 'POST' Buffer Overflow

Logpoint < 5.6.4 - Unauthenticated Root Remote Code Execution

WordPress Plugin WP-Testimonials < 3.4.1 - SQL Injection

Real Estate Classifieds Script - SQL Injection

Disk Pulse 9.7.26 - 'Add Directory' Local Buffer Overflow

 

12.6.2017

Bugtraq

Zenbership 1.0.8 CMS - Multiple SQL Injection Vulnerabilities 2017-06-12
Vulnerability Lab (research vulnerability-lab com)

Evolution Script CMS v5.3 - Cross Site Scripting Vulnerability 2017-06-12
Vulnerability Lab (research vulnerability-lab com)

SECURITY] DSA 3877-1] tor security update 2017-06-10
Salvatore Bonaccorso (carnil debian org)

security bulletin] HPESBHF03730 rev.2 - HPE Aruba ClearPass Policy Manager, Multiple Vulnerabilities 2017-06-09
security-alert hpe com

SECURITY] DSA 3876-1] otrs2 security update 2017-06-09
Moritz Muehlenhoff (jmm debian org)

SECURITY] DSA 3875-1] libmwaw security update 2017-06-09
Moritz Muehlenhoff (jmm debian org)

Malware

 

Phishing

spoof

12th June 2017

Tristam hates trap?

Service PayPaI

10th June 2017

STATEMENT SERVICE] WE HAVE
UPDATES ON OUR POLICY UPDATE
PAGE.

Vulnerebility

VMware Horizon View Client CVE-2017-4918 Command Injection Vulnerability
2017-06-12
http://www.securityfocus.com/bid/98984

Cisco Elastic Services Controller CVE-2017-6688 Default Credentials Security Bypass Vulnerability
2017-06-09
http://www.securityfocus.com/bid/98973

Google Chrome Prior to 59.0.3071.86 Multiple Security Vulnerabilities
2017-06-09
http://www.securityfocus.com/bid/98861

Resteasy CVE-2016-9606 Remote Code Execution Vulnerability
2017-06-09
http://www.securityfocus.com/bid/94940

Red Hat Undertow CVE-2017-2670 Remote Denial of Service Vulnerability
2017-06-09
http://www.securityfocus.com/bid/98965

OpenSSL CVE-2016-7056 Local Information Disclosure Vulnerability
2017-06-09
http://www.securityfocus.com/bid/95375

SANS News

 

Threatpost

Attackers Mining Cryptocurrency Using Exploits for Samba Vulnerability

Exploit

Logpoint < 5.6.4 - Unauthenticated Root Remote Code Execution

Easy File Sharing Web Server 7.2 - Authentication Bypass

DiskBoss 8.0.16 - 'Input Directory' Local Buffer Overflow

VMware vSphere Data Protection 5.x/6.x - Java Deserialization

EFS Easy Chat Server 3.1 - Buffer Overflow (SEH)

IPFire 2.19 - Remote Code Execution

eCom Cart 1.3 - SQL Injection

EFS Easy Chat Server 3.1 - Password Disclosure

EFS Easy Chat Server 3.1 - Password Reset

PaulShop - SQL Injection

Disk Sorter 9.7.14 - 'Input Directory' Local Buffer Overflow

11.6.2017

Bugtraq

security bulletin] HPESBUX03747 rev.1 - HP-UX running BIND, Remote Denial of Service 2017-06-08
security-alert hpe com

ESA-2017-064: RSA Identity Governance and Lifecycle Multiple Vulnerabilities 2017-06-08
EMC Product Security Response Center (Security_Alert emc com)

SYSS-2017-018] OTRS - Access to Installation Dialog 2017-06-08
sebastian auwaerter syss de

security bulletin] HPESBGN03758 rev.1 - HPE UCMDB, Remote Code Execution 2017-06-07
security-alert hpe com

CVE update - fixed in Apache Ranger 0.7.1 2017-06-07
Velmurugan Periasamy (vel apache org)

security bulletin] HPESBHF03757 rev.1 - HPE Network Products including Comware 5 and Comware 7 running NTP, Remote Denial of Service (DoS) 2017-06-07
security-alert hpe com

Malware

 

Phishing

 

Vulnerebility

Cisco Elastic Services Controller CVE-2017-6688 Default Credentials Security Bypass Vulnerability
2017-06-09
http://www.securityfocus.com/bid/98973

Google Chrome Prior to 59.0.3071.86 Multiple Security Vulnerabilities
2017-06-09
http://www.securityfocus.com/bid/98861

Resteasy CVE-2016-9606 Remote Code Execution Vulnerability
2017-06-09
http://www.securityfocus.com/bid/94940

Red Hat Undertow CVE-2017-2670 Remote Denial of Service Vulnerability
2017-06-09
http://www.securityfocus.com/bid/98965

OpenSSL CVE-2016-7056 Local Information Disclosure Vulnerability
2017-06-09
http://www.securityfocus.com/bid/95375

Apache HTTP Server CVE-2016-8740 Denial of Service Vulnerability
2017-06-09
http://www.securityfocus.com/bid/94650

Apache HTTP Server CVE-2016-2161 Denial of Service Vulnerability
2017-06-09
http://www.securityfocus.com/bid/95076

Apache HTTP Server CVE-2016-0736 Remote Security Vulnerability
2017-06-09
http://www.securityfocus.com/bid/95078

Apache HTTP Server CVE-2016-8743 Security Bypass Vulnerability
2017-06-09
http://www.securityfocus.com/bid/95077

OpenSSL CVE-2016-8610 Denial of Service Vulnerability
2017-06-09
http://www.securityfocus.com/bid/93841

FreeRADIUS TLS CVE-2017-9148 Authentication Bypass Vulnerability
2017-06-09
http://www.securityfocus.com/bid/98734

SANS News

An Occasional Look in the Rear View Mirror

Threatpost

Platinum APT First to Abuse Intel Chip Management Feature

Google Releases reCAPTCHA API for Android

GameStop Online Shoppers Officially Warned of Breach

Exploit

Mapscrn 2.03 - Local Buffer Overflow

libcroco 0.6.12 - Denial of Service

libquicktime 1.2.4 - Denial of Service

9.6.2017

Bugtraq

security bulletin] HPESBUX03747 rev.1 - HP-UX running BIND, Remote Denial of Service 2017-06-08
security-alert hpe com

ESA-2017-064: RSA Identity Governance and Lifecycle Multiple Vulnerabilities 2017-06-08
EMC Product Security Response Center (Security_Alert emc com)

SYSS-2017-018] OTRS - Access to Installation Dialog 2017-06-08
sebastian auwaerter syss de

security bulletin] HPESBGN03758 rev.1 - HPE UCMDB, Remote Code Execution 2017-06-07
security-alert hpe com

CVE update - fixed in Apache Ranger 0.7.1 2017-06-07
Velmurugan Periasamy (vel apache org)

security bulletin] HPESBHF03757 rev.1 - HPE Network Products including Comware 5 and Comware 7 running NTP, Remote Denial of Service (DoS) 2017-06-07
security-alert hpe com

Xavier v2.4 PHP MP - SQL Injection Web Vulnerabilities 2017-06-07
Vulnerability Lab (research vulnerability-lab com)

Sophos Cyberoam Cross-site scripting (XSS) vulnerability 2017-06-06
bhdresh gmail com

Malware

Ransom:Win32/HydraCrypt.A
Ransom:Win32/Spora.A

Ransom:Win32/Wagcrypt.A

Android.Dvmap

JS.Heur.SNIC

VBS.Heur.SNIC

Phishing

SERVICE

9th June 2017

Notification

Tesco Bank

9th June 2017

Alert From Customer Service

Vulnerebility

Cisco Elastic Services Controller CVE-2017-6688 Default Credentials Security Bypass Vulnerability
2017-06-09
http://www.securityfocus.com/bid/98973

Google Chrome Prior to 59.0.3071.86 Multiple Security Vulnerabilities
2017-06-09
http://www.securityfocus.com/bid/98861

Resteasy CVE-2016-9606 Remote Code Execution Vulnerability
2017-06-09
http://www.securityfocus.com/bid/94940

Red Hat Undertow CVE-2017-2670 Remote Denial of Service Vulnerability
2017-06-09
http://www.securityfocus.com/bid/98965

OpenSSL CVE-2016-7056 Local Information Disclosure Vulnerability
2017-06-09
http://www.securityfocus.com/bid/95375

Apache HTTP Server CVE-2016-8740 Denial of Service Vulnerability
2017-06-09
http://www.securityfocus.com/bid/94650

Apache HTTP Server CVE-2016-2161 Denial of Service Vulnerability
2017-06-09
http://www.securityfocus.com/bid/95076

Apache HTTP Server CVE-2016-0736 Remote Security Vulnerability
2017-06-09
http://www.securityfocus.com/bid/95078

Apache HTTP Server CVE-2016-8743 Security Bypass Vulnerability
2017-06-09
http://www.securityfocus.com/bid/95077

OpenSSL CVE-2016-8610 Denial of Service Vulnerability
2017-06-09
http://www.securityfocus.com/bid/93841

FreeRADIUS TLS CVE-2017-9148 Authentication Bypass Vulnerability
2017-06-09
http://www.securityfocus.com/bid/98734

Apple iOS and Safari Multiple Security Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/98474

Webkit Cross Site Scripting and Arbitrary Code Execution Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/98473

WebKit CVE-2017-2530 Memory Corruption Vulnerability
2017-06-08
http://www.securityfocus.com/bid/98455

WebKit CVE-2017-2521 Unspecified Memory Corruption Vulnerability
2017-06-08
http://www.securityfocus.com/bid/98456

WebKit CVE-2017-2415 Remote Code Execution Vulnerability
2017-06-08
http://www.securityfocus.com/bid/97143

Apple macOS APPLE-SA-2017-03-27-3 Multiple Security Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/97140

WebKit CVE-2017-6984 Unspecified Memory Corruption Vulnerability
2017-06-08
http://www.securityfocus.com/bid/98454

Apple macOS/iOS Multiple Security Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/97147

WebKit Multiple Security Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/97130

WebKit CVE-2017-2471 Remote Code Execution Vulnerability
2017-06-08
http://www.securityfocus.com/bid/97133

Apple iOS and Safari Multiple Security Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/97129

Webkit CVE-2017-2371 Security Bypass Vulnerability
2017-06-08
http://www.securityfocus.com/bid/95735

WebKit Multiple Memory Corruption Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/95736

Apple iTunes/iCloud/Safari/iOS CVE-2017-2366 Multiple Memory Corruption Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/95733

WebKit Multiple Security Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/95727

WebKit CVE-2017-2363 Cross-Origin Security Bypass Vulnerability
2017-06-08
http://www.securityfocus.com/bid/95728

Apple Safari/Cloud/iTunes/iOS/tvOS Multiple Security Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/94907

WebKit CVE-2016-7623 Information Disclosure Vulnerability
2017-06-08
http://www.securityfocus.com/bid/94913

WebKit CVE-2016-7592 Denial of Service Vulnerability
2017-06-08
http://www.securityfocus.com/bid/94909

SANS News

 

Threatpost

VMware Patches Critical Vulnerabilities in vSphere Data Protection

Motorola Moto G4, G5 Vulnerable to Local Root Shell Attacks

Exploit

Apple macOS 10.12.3 / iOS < 10.3.2 - Userspace Entitlement Checking Race Condition

Apple macOS - Disk Arbitration Daemon Race Condition

Mapscrn 2.03 - Local Buffer Overflow

Craft CMS 2.6 - Cross-Site Scripting

8.6.2017

Bugtraq

SYSS-2017-018] OTRS - Access to Installation Dialog 2017-06-08
sebastian auwaerter syss de

security bulletin] HPESBGN03758 rev.1 - HPE UCMDB, Remote Code Execution 2017-06-07
security-alert hpe com

CVE update - fixed in Apache Ranger 0.7.1 2017-06-07
Velmurugan Periasamy (vel apache org)

security bulletin] HPESBHF03757 rev.1 - HPE Network Products including Comware 5 and Comware 7 running NTP, Remote Denial of Service (DoS) 2017-06-07
security-alert hpe com

Xavier v2.4 PHP MP - SQL Injection Web Vulnerabilities 2017-06-07
Vulnerability Lab (research vulnerability-lab com)

Sophos Cyberoam Cross-site scripting (XSS) vulnerability 2017-06-06
bhdresh gmail com

Malware

 

Phishing

 

Vulnerebility

Apple iOS and Safari Multiple Security Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/98474

Webkit Cross Site Scripting and Arbitrary Code Execution Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/98473

WebKit CVE-2017-2530 Memory Corruption Vulnerability
2017-06-08
http://www.securityfocus.com/bid/98455

WebKit CVE-2017-2521 Unspecified Memory Corruption Vulnerability
2017-06-08
http://www.securityfocus.com/bid/98456

WebKit CVE-2017-2415 Remote Code Execution Vulnerability
2017-06-08
http://www.securityfocus.com/bid/97143

Apple macOS APPLE-SA-2017-03-27-3 Multiple Security Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/97140

WebKit CVE-2017-6984 Unspecified Memory Corruption Vulnerability
2017-06-08
http://www.securityfocus.com/bid/98454

Apple macOS/iOS Multiple Security Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/97147

WebKit Multiple Security Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/97130

WebKit CVE-2017-2471 Remote Code Execution Vulnerability
2017-06-08
http://www.securityfocus.com/bid/97133

Apple iOS and Safari Multiple Security Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/97129

Webkit CVE-2017-2371 Security Bypass Vulnerability
2017-06-08
http://www.securityfocus.com/bid/95735

WebKit Multiple Memory Corruption Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/95736

Apple iTunes/iCloud/Safari/iOS CVE-2017-2366 Multiple Memory Corruption Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/95733

WebKit Multiple Security Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/95727

WebKit CVE-2017-2363 Cross-Origin Security Bypass Vulnerability
2017-06-08
http://www.securityfocus.com/bid/95728

Apple Safari/Cloud/iTunes/iOS/tvOS Multiple Security Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/94907

WebKit CVE-2016-7623 Information Disclosure Vulnerability
2017-06-08
http://www.securityfocus.com/bid/94913

WebKit CVE-2016-7592 Denial of Service Vulnerability
2017-06-08
http://www.securityfocus.com/bid/94909

WebKit CVE-2017-2364 Cross-Origin Security Bypass Vulnerability
2017-06-08
http://www.securityfocus.com/bid/95725

Apple iOS/WatchOS/tvOS/Safari/iTunes/iCloud CVE-2016-7589 Memory Corruption Vulnerability
2017-06-08
http://www.securityfocus.com/bid/94908

WebKit CVE-2016-9643 Denial of Service Vulnerability
2017-06-08
http://www.securityfocus.com/bid/94559

WebKit CVE-2016-9642 Memory Corruption Vulnerability
2017-06-08
http://www.securityfocus.com/bid/94554

WebKit Multiple Security Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/81263

WebKit Multiple Unspecified Memory Corruption Vulnerabilities
2017-06-08
http://www.securityfocus.com/bid/78720

Cisco TelePresence Endpoint CVE-2017-6648 Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/98934

Linux Kernel CVE-2017-7889 Multiple Local Security Bypass Vulnerabilities
2017-06-07
http://www.securityfocus.com/bid/97690

Linux Kernel CVE-2017-8063 Local Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97974

Linux Kernel CVE-2017-7277 Multiple Local Memory Corruption Vulnerabilities
2017-06-07
http://www.securityfocus.com/bid/97141

Linux Kernel CVE-2017-7895 Multiple Security Bypass Vulnerabilities
2017-06-07
http://www.securityfocus.com/bid/98085Cisco TelePresence Endpoint CVE-2017-6648 Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/98934

Linux Kernel CVE-2017-7889 Multiple Local Security Bypass Vulnerabilities
2017-06-07
http://www.securityfocus.com/bid/97690

Linux Kernel CVE-2017-8063 Local Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97974

Linux Kernel CVE-2017-7277 Multiple Local Memory Corruption Vulnerabilities
2017-06-07
http://www.securityfocus.com/bid/97141

Linux Kernel CVE-2017-7895 Multiple Security Bypass Vulnerabilities
2017-06-07
http://www.securityfocus.com/bid/98085

Linux Kernel 'drivers/char/virtio_console.c' Local Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97997

Linux kernel CVE-2017-2671 Local Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97407

Linux Kernel CVE-2017-7618 Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97534

Linux Kernel 'security/keys/keyctl.c' Local Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/98422

Linux Kernel CVE-2017-7645 Multiple Denial of Service Vulnerabilities
2017-06-07
http://www.securityfocus.com/bid/97950

Linux Kernel CVE-2017-7979 Local Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97969

Deluge CVE-2017-7178 Cross Site Request Forgery Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97041

Google Android Kernel Trace Subsystem CVE-2017-0605 Privilege Escalation Vulnerability
2017-06-07
http://www.securityfocus.com/bid/98152

FreeType 2 CVE-2017-7857 Multiple Out of Bounds Write Heap Buffer Overflow Vulnerabilities
2017-06-07
http://www.securityfocus.com/bid/97680

FreeType 2 CVE-2017-7864 Out of Bounds Write Heap Buffer Overflow Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97673

FreeType 2 CVE-2017-7858 Multiple Out Of Bounds Write Denial of Service Vulnerabilities
2017-06-07
http://www.securityfocus.com/bid/97682

Adobe Flash Player APSB16-10 Multiple Unspecified Memory Corruption Vulnerabilities
2017-06-07
http://www.securityfocus.com/bid/85932

Minicom CVE-2017-7467 Local Buffer Overflow Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97966

Linux Kernel CVE-2016-9083 Local Integer Overflow Vulnerability
2017-06-07
http://www.securityfocus.com/bid/93929

Linux Kernel CVE-2017-6001 Incomplete Fix Local Privilege Escalation Vulnerability
2017-06-07
http://www.securityfocus.com/bid/96264

Linux Kernel 'tuners/tuner-xc2028.c' Local Use After Free Memory Corruption Vulnerability
2017-06-07
http://www.securityfocus.com/bid/94201

Linux Kernel Vfio Driver CVE-2016-9084 Integer Overflow Vulnerability
2017-06-07
http://www.securityfocus.com/bid/93930

Linux Kernel CVE-2017-2596 Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/95878

Google Android Kernel Components Multiple Information Disclosure Vulnerabilites
2017-06-07
http://www.securityfocus.com/bid/94147

Wireshark WBXML Dissector 'packet-wbxml.c' Infinite Loop Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97633

Wireshark CVE-2017-6014 Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/96284

Wireshark BGP dissector Infinite Loop Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97632

Wireshark RPCoRDMA Dissector 'packet-rpcrdma.c' Infinite Loop Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97630

Wireshark 'dissectors/packet-imap.c' Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97636

Wireshark DOF Dissector 'packet-dof.c' Infinite Loop Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97634

SANS News

Summer STEM for Kids

Threatpost

Cisco Patches Critical Flaws in Prime Data Center Network Manager

Authentication Bypass, Potential Backdoors Plague Old WiMAX Routers

Google Removes Rooting Trojan Dvmap From Play Store

Zusy Malware Installs Via Mouseover – No Clicking Required

Windows 10 Mitigations Make Future EternalBlue Attacks Difficult

EFF Sues DOJ Over National Security Letter Disclosure Rules

Exploit

VMware Workstation 12 Pro - Denial of Service

Windows - UAC Protection Bypass via FodHelper Registry Key (Metasploit)

DC/OS Marathon UI - Docker Exploit (Metasploit)

Grav CMS 1.4.2 Admin Plugin - Cross-Site Scripting

Xavier 2.4 - SQL Injection

Artifex MuPDF mujstest 1.10a - Null Pointer Dereference

Artifex MuPDF - Null Pointer Dereference

PuTTY < 0.68 - 'ssh_agent_channel_data' Integer Overflow Heap Corruption

Linux Kernel < 4.10.13 - 'keyctl_set_reqkey_keyring' Local Denial of Service

Linux Kernel - 'ping' Local Denial of Service

7.6.2017

Bugtraq

Xavier v2.4 PHP MP - SQL Injection Web Vulnerabilities 2017-06-07
Vulnerability Lab (research vulnerability-lab com)

Sophos Cyberoam Cross-site scripting (XSS) vulnerability 2017-06-06
bhdresh gmail com

security bulletin] HPESBGN03752 rev.1 - HPE IceWall using OpenSSL, remote Denial of Service (DoS) 2017-06-05
security-alert hpe com

security bulletin] HPESBHF03756 rev.1 - HPE Network Products including Comware 7, iMC, and VCX running OpenSSL, Remote Denial of Service (DoS), Disclosure of Sensitive Information 2017-06-05
security-alert hpe com

X41-2017-005 - Multiple Vulnerabilities in peplink balance routers 2017-06-05
X41 D-Sec GmbH Advisories (advisories x41-dsec de)

SECURITY] DSA 3873-1] perl security update 2017-06-05
Salvatore Bonaccorso (carnil debian org)

Malware

 

Phishing

*****THANK YOU*****

6th June 2017

TUESDAY: Your $50 Amazon gift
card

TalkTalk

5th June 2017

Account authentication

Vulnerebility

Linux Kernel CVE-2017-7889 Multiple Local Security Bypass Vulnerabilities
2017-06-07
http://www.securityfocus.com/bid/97690

Linux Kernel CVE-2017-8063 Local Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97974

Linux Kernel CVE-2017-7277 Multiple Local Memory Corruption Vulnerabilities
2017-06-07
http://www.securityfocus.com/bid/97141

Linux Kernel CVE-2017-7895 Multiple Security Bypass Vulnerabilities
2017-06-07
http://www.securityfocus.com/bid/98085

Linux Kernel 'drivers/char/virtio_console.c' Local Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97997

Linux kernel CVE-2017-2671 Local Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97407

Linux Kernel CVE-2017-7618 Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97534

Linux Kernel 'security/keys/keyctl.c' Local Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/98422

Linux Kernel CVE-2017-7645 Multiple Denial of Service Vulnerabilities
2017-06-07
http://www.securityfocus.com/bid/97950

Linux Kernel CVE-2017-7979 Local Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97969

Deluge CVE-2017-7178 Cross Site Request Forgery Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97041

Google Android Kernel Trace Subsystem CVE-2017-0605 Privilege Escalation Vulnerability
2017-06-07
http://www.securityfocus.com/bid/98152

FreeType 2 CVE-2017-7857 Multiple Out of Bounds Write Heap Buffer Overflow Vulnerabilities
2017-06-07
http://www.securityfocus.com/bid/97680

FreeType 2 CVE-2017-7864 Out of Bounds Write Heap Buffer Overflow Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97673

FreeType 2 CVE-2017-7858 Multiple Out Of Bounds Write Denial of Service Vulnerabilities
2017-06-07
http://www.securityfocus.com/bid/97682

Adobe Flash Player APSB16-10 Multiple Unspecified Memory Corruption Vulnerabilities
2017-06-07
http://www.securityfocus.com/bid/85932

Minicom CVE-2017-7467 Local Buffer Overflow Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97966

Linux Kernel CVE-2016-9083 Local Integer Overflow Vulnerability
2017-06-07
http://www.securityfocus.com/bid/93929

Linux Kernel CVE-2017-6001 Incomplete Fix Local Privilege Escalation Vulnerability
2017-06-07
http://www.securityfocus.com/bid/96264

Linux Kernel 'tuners/tuner-xc2028.c' Local Use After Free Memory Corruption Vulnerability
2017-06-07
http://www.securityfocus.com/bid/94201

Linux Kernel Vfio Driver CVE-2016-9084 Integer Overflow Vulnerability
2017-06-07
http://www.securityfocus.com/bid/93930

Linux Kernel CVE-2017-2596 Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/95878

Google Android Kernel Components Multiple Information Disclosure Vulnerabilites
2017-06-07
http://www.securityfocus.com/bid/94147

Wireshark WBXML Dissector 'packet-wbxml.c' Infinite Loop Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97633

Wireshark CVE-2017-6014 Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/96284

Wireshark BGP dissector Infinite Loop Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97632

Wireshark RPCoRDMA Dissector 'packet-rpcrdma.c' Infinite Loop Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97630

Wireshark 'dissectors/packet-imap.c' Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97636

Wireshark DOF Dissector 'packet-dof.c' Infinite Loop Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97634

Wireshark NetScaler File Parser 'wiretap/netscaler.c' Infinite Loop Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97631Wireshark WBXML Dissector 'packet-wbxml.c' Infinite Loop Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97633

Wireshark CVE-2017-6014 Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/96284

Wireshark BGP dissector Infinite Loop Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97632

Wireshark RPCoRDMA Dissector 'packet-rpcrdma.c' Infinite Loop Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97630

Wireshark 'dissectors/packet-imap.c' Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97636

Wireshark DOF Dissector 'packet-dof.c' Infinite Loop Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97634

Wireshark NetScaler File Parser 'wiretap/netscaler.c' Infinite Loop Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/97631

PCRE 'compile_bracket_matchingpath()' Function Denial of Service Vulnerability
2017-06-07
http://www.securityfocus.com/bid/96295

Pidgin CVE 2017-2640 Out of Bounds Write Security Vulnerability
2017-06-07
http://www.securityfocus.com/bid/96775

Google Chrome Prior to 59.0.3071.86 Multiple Security Vulnerabilities
2017-06-07
http://www.securityfocus.com/bid/98861

Google Android libnl CVE-2017-0553 Remote Privilege Escalation Vulnerability
2017-06-06
http://www.securityfocus.com/bid/97340

PuTTY 'ssh_agent_channel_data()' Function Integer Overflow Vulnerability
2017-06-06
http://www.securityfocus.com/bid/97156

Rpcbind CVE-2017-8779 Remote Denial of Service Vulnerability
2017-06-06
http://www.securityfocus.com/bid/98325

Artifex MuPDF CVE-2017-5991 Null Pointer Dereference Denial of Service Vulnerability
2017-06-06
http://www.securityfocus.com/bid/96213

MuPDF 'jstest_main.c' Stack Buffer Overflow Vulnerability
2017-06-06
http://www.securityfocus.com/bid/96266

Adobe Flash Player APSB16-10 Multiple Unspecified Memory Corruption Vulnerabilities
2017-06-06
http://www.securityfocus.com/bid/85932

ImageWorsener 'iwgif_record_pixel()' Function Denial of Service Vulnerability
2017-06-06
http://www.securityfocus.com/bid/97497

ImageWorsener 'iwbmp_read_info_header()' Function Denial of Service Vulnerability
2017-06-06
http://www.securityfocus.com/bid/97496

ImageWorsener 'iwgif_record_pixel()' Function Remote Heap Buffer Overflow Vulnerability
2017-06-06
http://www.securityfocus.com/bid/97494

libxslt 'libxslt/preproc.c' Type Confusion Remote Denial of Service Vulnerability
2017-06-06
http://www.securityfocus.com/bid/77325

util-linux CVE-2017-2616 Local Denial of Service Vulnerability
2017-06-06
http://www.securityfocus.com/bid/96404

Shadow Multiple Local Security Vulnerabilities
2017-06-06
http://www.securityfocus.com/bid/92055

QEMU 'display/virtio-gpu.c' Denial of Service Vulnerability
2017-06-06
http://www.securityfocus.com/bid/98632

QEMU CVE-2017-8379 Denial of Service Vulnerability
2017-06-06
http://www.securityfocus.com/bid/98277

QEMU CVE-2017-9330 Denial of Service Vulnerability
2017-06-06
http://www.securityfocus.com/bid/98779

QEMU CVE-2017-8309 Denial of Service Vulnerability
2017-06-06
http://www.securityfocus.com/bid/98302

QEMU 'hw/9pfs/9p-local.c' Privilege Escalation Vulnerability
2017-06-06
http://www.securityfocus.com/bid/97970

QEMU 'hw/9pfs/9p.c' Multiple Denial of Service Vulnerabilities
2017-06-06
http://www.securityfocus.com/bid/97319

QEMU 'megasas_mmio_write()' Function Out-of-Bounds Read Vulnerability
2017-06-06
http://www.securityfocus.com/bid/98303

QEMU CVE-2017-9310 Denial of Service Vulnerability
2017-06-06
http://www.securityfocus.com/bid/98766

SANS News

Malware and XOR - Part 2

Threatpost

Google Fixes 30 Vulnerabilities, Five High Severity, in Chrome 59

IBM Backup Bug Gets Workaround Fix After Nine Months of Exposure

Curiosity Kills Security When it Comes to Phishing

Exploit

Apple Safari 10.1 - Spread Operator Integer Overflow Remote Code Execution

6.6.2017

Bugtraq

security bulletin] HPESBGN03752 rev.1 - HPE IceWall using OpenSSL, remote Denial of Service (DoS) 2017-06-05
security-alert hpe com

security bulletin] HPESBHF03756 rev.1 - HPE Network Products including Comware 7, iMC, and VCX running OpenSSL, Remote Denial of Service (DoS), Disclosure of Sensitive Information 2017-06-05
security-alert hpe com

X41-2017-005 - Multiple Vulnerabilities in peplink balance routers 2017-06-05
X41 D-Sec GmbH Advisories (advisories x41-dsec de)

SECURITY] DSA 3873-1] perl security update 2017-06-05
Salvatore Bonaccorso (carnil debian org)

SECURITY] DSA 3870-1] wordpress security update 2017-06-01
Sebastien Delafond (seb debian org)

SECURITY] DSA 3869-1] tnef security update 2017-06-01
Sebastien Delafond (seb debian org)

Malware

 

Phishing

 

Vulnerebility

GnuTLS CVE-2017-6891 Stack Buffer Overflow Vulnerability
2017-06-05
http://www.securityfocus.com/bid/98641

Multiple Puppet Products YAML Deserialization CVE-2017-2295 Remote Code Execution Vulnerability
2017-06-05
http://www.securityfocus.com/bid/98582

Multiple Puppet Products CVE-2014-3248 Remote Code Execution Vulnerability
2017-06-05
http://www.securityfocus.com/bid/68035

Cisco IOS and IOS XE Software CVE-2017-3881 Remote Code Execution Vulnerability
2017-06-05
http://www.securityfocus.com/bid/96960

RETIRED: Sendmail Remote Code Execution Vulnerability
2017-06-05
http://www.securityfocus.com/bid/98787

Cisco Mobility Express Software CVE-2017-3834 Default Credentials Security Bypass Vulnerability
2017-06-05
http://www.securityfocus.com/bid/97422

Google Android Motorola Bootloader CVE-2016-10277 Privilege Escalation Vulnerability
2017-06-05
http://www.securityfocus.com/bid/98149

Linux Kernel CVE-2017-1000363 Integer Overflow Vulnerability
2017-06-05
http://www.securityfocus.com/bid/98651

Samba CVE-2017-7494 Remote Code Execution Vulnerability
2017-06-05
http://www.securityfocus.com/bid/98636

Sudo CVE-2017-1000368 Incomplete Fix Local Privilege Escalation Vulnerability
2017-06-05
http://www.securityfocus.com/bid/98838

Screensaver Installers CVE-2017-2176 DLL Loading Remote Code Execution Vulnerability
2017-06-05
http://www.securityfocus.com/bid/98823

Wireshark 'epan/dissectors/packet-ipv6.c' Denial of Service Vulnerability
2017-06-05
http://www.securityfocus.com/bid/98805

Wireshark 'dissectors/asn1/ros/packet-ros-template.c' Denial of Service Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98800

Multiple Asterisk Products Denial of Service Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98578

Multiple Asterisk Products Denial of Service Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98573

Sudo '/src/ttyname.c' Local Privilege Escalation Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98745

Multiple Asterisk Products 'PJSIP Transaction Layer' Heap Based Buffer Overflow Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98572

Mozilla Network Security Services CVE-2017-5461 Memory Corruption Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98050

Mozilla Network Security Services CVE-2017-7502 Denial of Service Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98744

Mozilla Firefox Multiple Security Vulnerabilities
2017-06-02
http://www.securityfocus.com/bid/97940

Oracle Solaris CVE-2017-3622 Local Privilege Escalation Vulnerability
2017-06-02
http://www.securityfocus.com/bid/97774

Oracle Solaris CVE-2017-3623 Remote Code Execution Vulnerability
2017-06-02
http://www.securityfocus.com/bid/97778

IBM Security Access Manager Products CVE-2016-3019 Information Disclosure Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98832

IBM Security Privileged Identity Manager CVE-2016-5959 Information Disclosure Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98829

IBM Security Privileged Identity Manager CVE-2016-5960 Local Information Disclosure Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98825

SaAT Netizen CVE-2017-2206 DLL Loading Remote Code Execution Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98817

SaAT Personal Installer CVE-2017-2207 DLL Loading Remote Code Execution Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98809

Wireshark CVE-2017-9351 Heap Buffer Overflow Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98808

Wireshark 'epan/dissectors/packet-dof.c' Heap Buffer Overflow Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98801

Apache Hadoop CVE-2017-7669 Remote Privilege Escalation Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98795

SANS News

Malware and XOR - Part 1

Threatpost

53 Percent of Enterprise Flash Installs are Outdated

40,000 Subdomains Tied to RIG Exploit Kit Shut Down

QakBot Returns, Locking Out Active Directory Accounts

Exploit

Apple Safari 10.1 - Spread Operator Integer Overflow Remote Code Execution

Home Web Server 1.9.1 build 164 - Remote Code Execution

Kronos Telestaff < 2.92EU29 - SQL Injection

WordPress Plugin Tribulant Newsletters 4.6.4.2 - File Disclosure / Cross-Site...

Cisco Catalyst 2960 IOS 12.2(55)SE1 - 'ROCEM' Remote Code Execution

Linux/x86-64 - /bin/sh Shellcode (31 bytes)

Home Web Server 1.9.1 build 164 - Remote Code Execution

Kronos Telestaff < 2.92EU29 - SQL Injection

5.6.2017

Bugtraq

X41-2017-005 - Multiple Vulnerabilities in peplink balance routers 2017-06-05
X41 D-Sec GmbH Advisories (advisories x41-dsec de)

SECURITY] DSA 3873-1] perl security update 2017-06-05
Salvatore Bonaccorso (carnil debian org)

SECURITY] DSA 3870-1] wordpress security update 2017-06-01
Sebastien Delafond (seb debian org)

SECURITY] DSA 3869-1] tnef security update 2017-06-01
Sebastien Delafond (seb debian org)

Malware

 

Phishing

Bank of America

4th June 2017

Bank of America Alert: Your
Online Access is Temporarily
Locked

Vulnerebility

RETIRED: Sendmail Remote Code Execution Vulnerability
2017-06-05
http://www.securityfocus.com/bid/98787

Cisco Mobility Express Software CVE-2017-3834 Default Credentials Security Bypass Vulnerability
2017-06-05
http://www.securityfocus.com/bid/97422

Google Android Motorola Bootloader CVE-2016-10277 Privilege Escalation Vulnerability
2017-06-05
http://www.securityfocus.com/bid/98149

Linux Kernel CVE-2017-1000363 Integer Overflow Vulnerability
2017-06-05
http://www.securityfocus.com/bid/98651

Samba CVE-2017-7494 Remote Code Execution Vulnerability
2017-06-05
http://www.securityfocus.com/bid/98636

Wireshark 'epan/dissectors/packet-ipv6.c' Denial of Service Vulnerability
2017-06-05
http://www.securityfocus.com/bid/98805

Wireshark 'dissectors/asn1/ros/packet-ros-template.c' Denial of Service Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98800

Multiple Asterisk Products Denial of Service Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98578

Multiple Asterisk Products Denial of Service Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98573

Sudo '/src/ttyname.c' Local Privilege Escalation Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98745

Multiple Asterisk Products 'PJSIP Transaction Layer' Heap Based Buffer Overflow Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98572

Mozilla Network Security Services CVE-2017-5461 Memory Corruption Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98050

Mozilla Network Security Services CVE-2017-7502 Denial of Service Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98744

Mozilla Firefox Multiple Security Vulnerabilities
2017-06-02
http://www.securityfocus.com/bid/97940

Oracle Solaris CVE-2017-3622 Local Privilege Escalation Vulnerability
2017-06-02
http://www.securityfocus.com/bid/97774

Oracle Solaris CVE-2017-3623 Remote Code Execution Vulnerability
2017-06-02
http://www.securityfocus.com/bid/97778

SaAT Netizen CVE-2017-2206 DLL Loading Remote Code Execution Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98817

SaAT Personal Installer CVE-2017-2207 DLL Loading Remote Code Execution Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98809

Wireshark CVE-2017-9351 Heap Buffer Overflow Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98808

Wireshark 'epan/dissectors/packet-dof.c' Heap Buffer Overflow Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98801

Apache Hadoop CVE-2017-7669 Remote Privilege Escalation Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98795

OpenLDAP 'servers/slapd/back-mdb/search.c' Denial of Service Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98736

NVIDIA GPU Driver CVE-2017-0352 Local Privilege Escalation Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98517

NVIDIA GPU Driver CVE-2017-0351 Local Privilege Escalation Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98497

NVIDIA GPU Driver CVE-2017-0350 Local Privilege Escalation Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98490

WordPress Password Reset CVE-2017-8295 Security Bypass Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98295

WordPress Prior to 4.7.5 Multiple Security Vulnerabilities
2017-06-01
http://www.securityfocus.com/bid/98509

Tera Term Installer CVE-2017-2193 DLL Loading Remote Code Execution Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98807

Wireshark 'epan/dissectors/packet-opensafety.c' Denial of Service Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98806

Wireshark 'epan/dissectors/packet-bzr.c' Denial of Service Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98804

SANS News

 

Threatpost

 

Exploit

Joomla Component Payage 2.05 - 'aid' Parameter SQL Injection

Disk Sorter 9.7.14 - 'Input Directory' Local Buffer Overflow

EnGenius EnShare IoT Gigabit Cloud Service 1.4.11 - Remote Code Execution

Subsonic 6.1.1 - Cross-Site Request Forgery

Subsonic 6.1.1 - Server-Side Request Forgery

Subsonic 6.1.1 - Cross-Site Request Forgery / Cross-Site Scripting

Parallels Desktop - Virtual Machine Escape

Subsonic 6.1.1 - XML External Entity Injection

BIND 9.10.5 - Unquoted Service Path Privilege Escalation

Disk Sorter 9.7.14 - 'Input Directory' Local Buffer Overflow

DNSTracer 1.8.1 - Buffer Overflow

4.6.2017

Bugtraq

SECURITY] DSA 3870-1] wordpress security update 2017-06-01
Sebastien Delafond (seb debian org)

SECURITY] DSA 3869-1] tnef security update 2017-06-01
Sebastien Delafond (seb debian org)

CVE-2017-5688] Executable installers are vulnerable^WEVIL (case 52): Intel installation framework allows arbitrary code execution with escalation of privilege 2017-05-31
Stefan Kanthak (stefan kanthak nexgo de)

Malware

 

Phishing

User Support

3rd June 2017

New message for you

Netflix Inc

3rd June 2017

UPDATE YOUR NETFLIX
INFORMATION !

Vulnerebility

Wireshark 'dissectors/asn1/ros/packet-ros-template.c' Denial of Service Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98800

Multiple Asterisk Products Denial of Service Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98578

Multiple Asterisk Products Denial of Service Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98573

Sudo '/src/ttyname.c' Local Privilege Escalation Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98745

Multiple Asterisk Products 'PJSIP Transaction Layer' Heap Based Buffer Overflow Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98572

Mozilla Network Security Services CVE-2017-5461 Memory Corruption Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98050

Mozilla Network Security Services CVE-2017-7502 Denial of Service Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98744

Mozilla Firefox Multiple Security Vulnerabilities
2017-06-02
http://www.securityfocus.com/bid/97940

Oracle Solaris CVE-2017-3622 Local Privilege Escalation Vulnerability
2017-06-02
http://www.securityfocus.com/bid/97774

Oracle Solaris CVE-2017-3623 Remote Code Execution Vulnerability
2017-06-02
http://www.securityfocus.com/bid/97778

Wireshark 'epan/dissectors/packet-dof.c' Heap Buffer Overflow Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98801

Apache Hadoop CVE-2017-7669 Remote Privilege Escalation Vulnerability
2017-06-02
http://www.securityfocus.com/bid/98795

OpenLDAP 'servers/slapd/back-mdb/search.c' Denial of Service Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98736

NVIDIA GPU Driver CVE-2017-0352 Local Privilege Escalation Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98517

NVIDIA GPU Driver CVE-2017-0351 Local Privilege Escalation Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98497

NVIDIA GPU Driver CVE-2017-0350 Local Privilege Escalation Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98490

WordPress Password Reset CVE-2017-8295 Security Bypass Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98295

WordPress Prior to 4.7.5 Multiple Security Vulnerabilities
2017-06-01
http://www.securityfocus.com/bid/98509

Wireshark 'epan/dissectors/packet-slsk.c' Denial of Service Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98799

Wireshark 'epan/dissectors/packet-dns.c' Denial of Service Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98798

Wireshark CVE-2017-9343 Denial of Service Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98797

Wireshark 'dissectors/packet-btl2cap.c' Denial of Service Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98796

Phoenix Broadband Technologies LLC PowerAgent SC3 Site Controller Security Bypass Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98781

QEMU CVE-2017-9330 Denial of Service Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98779

Linux Kernel CVE-2017-6214 Remote Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/96421

Microsoft Domain Controller Remote Code Execution Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98757

Juniper Junos Space CVE-2017-2305 Remote Privilege Escalation Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98759

Multiple Hitachi Products CVE-2017-9295 XML External Entity Information Disclosure Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98761

strongSwan CVE-2017-9022 Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98760

Oracle Database Server Authentication Bypass Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98758

SANS News

 

Threatpost

Jaff Malware Probe Uncovers Link to Cybercrime Marketplace

SSH Configuration on Nexpose Servers Allowed Weak Encryption Algorithms

EternalBlue Exploit Spreading Gh0st RAT, Nitol

Exploit

 

2.6.2017

Bugtraq

SECURITY] DSA 3870-1] wordpress security update 2017-06-01
Sebastien Delafond (seb debian org)

SECURITY] DSA 3869-1] tnef security update 2017-06-01
Sebastien Delafond (seb debian org)

CVE-2017-5688] Executable installers are vulnerable^WEVIL (case 52): Intel installation framework allows arbitrary code execution with escalation of privilege 2017-05-31
Stefan Kanthak (stefan kanthak nexgo de)

DefenseCode ThunderScan SAST Advisory: WordPress Simple Slideshow Manager Plugin Multiple Security Vulnerabilities 2017-05-30
DefenseCode (defensecode defensecode com)

SECURITY] DSA 3867-1] sudo security update 2017-05-30
Salvatore Bonaccorso (carnil debian org)

Malware

 

Phishing

*****THANK YOU*****

1st June 2017

TUESDAY: Your $50 Amazon gift
card

*****THANK YOU*****

1st June 2017

THURSDAY: Your $50 Amazon gift
card

Vulnerebility

OpenLDAP 'servers/slapd/back-mdb/search.c' Denial of Service Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98736

NVIDIA GPU Driver CVE-2017-0352 Local Privilege Escalation Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98517

NVIDIA GPU Driver CVE-2017-0351 Local Privilege Escalation Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98497

NVIDIA GPU Driver CVE-2017-0350 Local Privilege Escalation Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98490

WordPress Password Reset CVE-2017-8295 Security Bypass Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98295

WordPress Prior to 4.7.5 Multiple Security Vulnerabilities
2017-06-01
http://www.securityfocus.com/bid/98509

Phoenix Broadband Technologies LLC PowerAgent SC3 Site Controller Security Bypass Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98781

QEMU CVE-2017-9330 Denial of Service Vulnerability
2017-06-01
http://www.securityfocus.com/bid/98779

Linux Kernel CVE-2017-6214 Remote Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/96421

Mozilla Network Security Services CVE-2017-7502 Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98744

Sudo '/src/ttyname.c' Local Privilege Escalation Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98745

Microsoft Domain Controller Remote Code Execution Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98757

Juniper Junos Space CVE-2017-2305 Remote Privilege Escalation Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98759

Multiple Hitachi Products CVE-2017-9295 XML External Entity Information Disclosure Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98761

strongSwan CVE-2017-9022 Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98760

Oracle Database Server Authentication Bypass Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98758

Real Networks RealPlayer CVE-2017-9302 Divide-By-Zero Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98754

strongSwan CVE-2017-9023 Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98756

Juniper Junos Space CVE-2017-2308 XML External Entity Information Disclosure Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98755

Microsoft Remote Desktop Protocol Remote Code Execution Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98752

Joomla! VirtueMart Extension 'administrator/index.php' Multiple SQL Injection Vulnerabilities
2017-05-31
http://www.securityfocus.com/bid/98753

Juniper Junos Space CVE-2017-2310 Security Bypass Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98751

Juniper Junos Space CVE-2017-2309 Information Disclosure Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98750

Juniper Junos Space CVE-2017-2311 Unspecified Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98748

Juniper Junos Space CVE-2017-2307 Cross Site Scripting Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98749

VideoLAN VLC CVE-2017-9300 Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98747

VideoLAN VLC CVE-2017-9301 Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98746

Apple iOS and Safari Multiple Security Vulnerabilities
2017-05-31
http://www.securityfocus.com/bid/98474

ImageMagick CVE-2017-9142 Local Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98683

ImageMagick CVE-2017-8830 Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98687
SANS News

Phishing Campaigns Follow Trends

Threatpost

Fireball Malware Infects 250 Million Computers Worldwide

WikiLeaks Dumps CIA Patient Zero Windows Implant

WannaCry Development Errors Enable File Recovery


OneLogin Breach Compromised Customer Data, Ability to Decrypt Encrypted Data


Insecure Backend Databases Blamed for Leaking 43TB of App Data

Exploit

 

1.6.2017

Bugtraq

SECURITY] DSA 3870-1] wordpress security update 2017-06-01
Sebastien Delafond (seb debian org)

SECURITY] DSA 3869-1] tnef security update 2017-06-01
Sebastien Delafond (seb debian org)

CVE-2017-5688] Executable installers are vulnerable^WEVIL (case 52): Intel installation framework allows arbitrary code execution with escalation of privilege 2017-05-31
Stefan Kanthak (stefan kanthak nexgo de)

DefenseCode ThunderScan SAST Advisory: WordPress Simple Slideshow Manager Plugin Multiple Security Vulnerabilities 2017-05-30
DefenseCode (defensecode defensecode com)

SECURITY] DSA 3867-1] sudo security update 2017-05-30
Salvatore Bonaccorso (carnil debian org)

SECURITY] DSA 3866-1] strongswan security update 2017-05-30
Yves-Alexis Perez (corsac debian org)

SECURITY] DSA 3865-1] mosquitto security update 2017-05-29
Moritz Muehlenhoff (jmm debian org)

Malware

 

Phishing

 

Vulnerebility

Linux Kernel CVE-2017-6214 Remote Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/96421

OpenLDAP 'servers/slapd/back-mdb/search.c' Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98736

Mozilla Network Security Services CVE-2017-7502 Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98744

Sudo '/src/ttyname.c' Local Privilege Escalation Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98745

Microsoft Domain Controller Remote Code Execution Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98757

Juniper Junos Space CVE-2017-2305 Remote Privilege Escalation Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98759

Multiple Hitachi Products CVE-2017-9295 XML External Entity Information Disclosure Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98761

strongSwan CVE-2017-9022 Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98760

Oracle Database Server Authentication Bypass Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98758

Real Networks RealPlayer CVE-2017-9302 Divide-By-Zero Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98754

strongSwan CVE-2017-9023 Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98756

Juniper Junos Space CVE-2017-2308 XML External Entity Information Disclosure Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98755

Microsoft Remote Desktop Protocol Remote Code Execution Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98752

Joomla! VirtueMart Extension 'administrator/index.php' Multiple SQL Injection Vulnerabilities
2017-05-31
http://www.securityfocus.com/bid/98753

Juniper Junos Space CVE-2017-2310 Security Bypass Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98751

Juniper Junos Space CVE-2017-2309 Information Disclosure Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98750

Juniper Junos Space CVE-2017-2311 Unspecified Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98748

Juniper Junos Space CVE-2017-2307 Cross Site Scripting Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98749

VideoLAN VLC CVE-2017-9300 Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98747

VideoLAN VLC CVE-2017-9301 Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98746

Apple iOS and Safari Multiple Security Vulnerabilities
2017-05-31
http://www.securityfocus.com/bid/98474

ImageMagick CVE-2017-9142 Local Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98683

ImageMagick CVE-2017-8830 Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98687

ImageMagick 'coders/rle.c' Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98603

ImageMagick CVE-2017-9143 Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98682

ImageMagick CVE-2017-9098 Local Information Disclosure Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98593

ImageMagick CVE-2017-7619 Multiple Denial of Service Vulnerabilities
2017-05-31
http://www.securityfocus.com/bid/98689

ImageMagick 'MagickCore/profile.c' Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98606

ImageMagick 'coders/rle.c' Remote Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98685

ImageMagick CVE-2017-8765 Denial of Service Vulnerability
2017-05-31
http://www.securityfocus.com/bid/98688

SANS News

Sharing Private Data with Webcast Invitations

Threatpost

Privacy Issue Fixed in Yopify Ecommerce Notification Plugin

New Machine Learning Behind Early Phishing Detection in Gmail

Patches Available for Linux Sudo Vulnerability

Hack Department of Homeland Security Act Would Bring Bug Bounty Program to DHS

Exploit

WebKit JSC - 'JSObject::ensureLength' ensureLengthSlow Check Failure

WebKit JSC - Incorrect Check in emitPutDerivedConstructorToArrowFunctionContextScope

WebKit - 'Element::setAttributeNodeNS' Use-After-Free

Piwigo Plugin Facetag 0.0.3 - SQL Injection

OV3 Online Administration 3.0 - Directory Traversal

OV3 Online Administration 3.0 - Remote Code Execution

OV3 Online Administration 3.0 - SQL Injection

Piwigo Plugin Facetag 0.0.3 - Cross-Site Scripting