Databáze Hot News - Rok - Úvod  2018  2017  2016  2015  2014  2013  - 1  2  3  4  5  6  7  8  9  10  11  12  13  14  15  List  - 2018  2017  2016  2015  2014  2013 
Poslední aktualizace v 08.10.2016 14:19:38
 

31.5.2017

Bugtraq

DefenseCode ThunderScan SAST Advisory: WordPress Simple Slideshow Manager Plugin Multiple Security Vulnerabilities 2017-05-30
DefenseCode (defensecode defensecode com)

[SECURITY] [DSA 3867-1] sudo security update 2017-05-30
Salvatore Bonaccorso (carnil debian org)

[SECURITY] [DSA 3866-1] strongswan security update 2017-05-30
Yves-Alexis Perez (corsac debian org)

[SECURITY] [DSA 3865-1] mosquitto security update 2017-05-29
Moritz Muehlenhoff (jmm debian org)

Malware

Backdoor:ASP/Seasharpee.A

Phishing

 

Vulnerebility

Apple iOS and Safari Multiple Security Vulnerabilities
2017-05-30
http://www.securityfocus.com/bid/98474

ImageMagick CVE-2017-9142 Local Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98683

ImageMagick CVE-2017-8830 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98687

ImageMagick 'coders/rle.c' Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98603

ImageMagick CVE-2017-9143 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98682

ImageMagick CVE-2017-9098 Local Information Disclosure Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98593

ImageMagick CVE-2017-7619 Multiple Denial of Service Vulnerabilities
2017-05-30
http://www.securityfocus.com/bid/98689

ImageMagick 'MagickCore/profile.c' Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98606

ImageMagick 'coders/rle.c' Remote Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98685

ImageMagick CVE-2017-8765 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98688

ImageMagick CVE-2017-8354 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98374

ImageMagick CVE-2017-8352 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98372

ImageMagick 'ept.c' Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98388

ImageMagick 'sfw.c' Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98370

ImageMagick CVE-2017-8351 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98371

ImageMagick CVE-2017-8355 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98380

ImageMagick 'png.c' Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98373

ImageMagick 'pict.c' Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98377

ImageMagick CVE-2017-8356 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98378

ImageMagick CVE-2017-8345 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98138

ImageMagick CVE-2017-7943 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/97956

ImageMagick CVE-2017-7942 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/97946

ImageMagick CVE-2017-8343 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98132

ImageMagick CVE-2017-8346 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98346

ImageMagick CVE-2017-8344 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98136

ImageMagick 'exr.c' Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98363

ImageMagick 'mat.c' Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98364

ImageMagick CVE-2017-7941 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/97944

RETIRED: IBM Domino CVE-2017-1274 Stack Buffer Overflow Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98019

IBM Domino CVE-2017-1274 Stack Buffer Overflow Vulnerability
2017-05-30
http://www.securityfocus.com/bid/97910

SANS News

Analysis of Competing Hypotheses, WCry and Lazarus (ACH part 2)

Threatpost

FreeRADIUS Update Resolves Authentication Bypass

Exploit

Piwigo Plugin Facetag 0.0.3 - SQL Injection

uc-http Daemon - Local File Inclusion / Directory Traversal

KEMP LoadMaster 7.135.0.13245 - Persistent Cross-Site Scripting / Remote Code...

30.5.2017

Bugtraq

DefenseCode ThunderScan SAST Advisory: WordPress Simple Slideshow Manager Plugin Multiple Security Vulnerabilities 2017-05-30
DefenseCode (defensecode defensecode com)

[SECURITY] [DSA 3867-1] sudo security update 2017-05-30
Salvatore Bonaccorso (carnil debian org)

[SECURITY] [DSA 3866-1] strongswan security update 2017-05-30
Yves-Alexis Perez (corsac debian org)

[SECURITY] [DSA 3865-1] mosquitto security update 2017-05-29
Moritz Muehlenhoff (jmm debian org)

Multiple Local Privilege Escalation Vulnerabilities in Acunetix Web Vulnerability Scanner 11 2017-05-28
Florian Bogner (florian bogner sh)

Wordpress Plugin Social-Stream - Exposure of Twitter API Secret Key and Token 2017-05-26
kyle Lovett (krlovett gmail com)

[security bulletin] HPESBHF03730 rev.1 - HPE Aruba ClearPass Policy Manager, Multiple Vulnerabilities 2017-05-26
security-alert hpe com

Malware

 

Phishing

Dropbox

29th May 2017

You Have A New Document

Tesco Bank

28th May 2017

Account Activity Alert

Vulnerebility

Apple iOS and Safari Multiple Security Vulnerabilities
2017-05-30
http://www.securityfocus.com/bid/98474

ImageMagick CVE-2017-9142 Local Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98683

ImageMagick CVE-2017-8830 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98687

ImageMagick 'coders/rle.c' Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98603

ImageMagick CVE-2017-9143 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98682

ImageMagick CVE-2017-9098 Local Information Disclosure Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98593

ImageMagick CVE-2017-7619 Multiple Denial of Service Vulnerabilities
2017-05-30
http://www.securityfocus.com/bid/98689

ImageMagick 'MagickCore/profile.c' Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98606

ImageMagick 'coders/rle.c' Remote Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98685

ImageMagick CVE-2017-8765 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98688

ImageMagick CVE-2017-8354 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98374

ImageMagick CVE-2017-8352 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98372

ImageMagick 'ept.c' Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98388

ImageMagick 'sfw.c' Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98370

ImageMagick CVE-2017-8351 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98371

ImageMagick CVE-2017-8355 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98380

ImageMagick 'png.c' Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98373

ImageMagick 'pict.c' Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98377

ImageMagick CVE-2017-8356 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98378

ImageMagick CVE-2017-8345 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98138

ImageMagick CVE-2017-7943 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/97956

ImageMagick CVE-2017-7942 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/97946

ImageMagick CVE-2017-8343 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98132

ImageMagick CVE-2017-8346 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98346

ImageMagick CVE-2017-8344 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98136

ImageMagick 'exr.c' Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98363

ImageMagick 'mat.c' Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98364

ImageMagick CVE-2017-7941 Denial of Service Vulnerability
2017-05-30
http://www.securityfocus.com/bid/97944

RETIRED: IBM Domino CVE-2017-1274 Stack Buffer Overflow Vulnerability
2017-05-30
http://www.securityfocus.com/bid/98019

IBM Domino CVE-2017-1274 Stack Buffer Overflow Vulnerability
2017-05-30
http://www.securityfocus.com/bid/97910Oracle Java SE and JRockit CVE-2017-3533 Remote Security Vulnerability
2017-05-29
http://www.securityfocus.com/bid/97740

Oracle Java SE CVE-2017-3539 Remote Security Vulnerability
2017-05-29
http://www.securityfocus.com/bid/97752

Oracle Java SE CVE-2017-3509 Remote Security Vulnerability
2017-05-29
http://www.securityfocus.com/bid/97737

Oracle Java SE and JRockit CVE-2017-3544 Remote Security Vulnerability
2017-05-29
http://www.securityfocus.com/bid/97745

Oracle Java SE CVE-2017-3512 Remote Security Vulnerability
2017-05-29
http://www.securityfocus.com/bid/97727

Oracle Java SE CVE-2017-3289 Remote Security Vulnerability
2017-05-29
http://www.securityfocus.com/bid/95525

Oracle Java SE and JRockit CVE-2017-3526 Remote Security Vulnerability
2017-05-29
http://www.securityfocus.com/bid/97733

Oracle Java SE CVE-2017-3514 Remote Security Vulnerability
2017-05-29
http://www.securityfocus.com/bid/97729

Oracle Java SE and JRockit CVE-2017-3511 Local Security Vulnerability
2017-05-29
http://www.securityfocus.com/bid/97731

Apache FOP CVE-2017-5661 XML External Entity Information Disclosure Vulnerability
2017-05-29
http://www.securityfocus.com/bid/97947

Linux Kernel 'EXT4 image' Local Denial of Service Vulnerability
2017-05-29
http://www.securityfocus.com/bid/94354

Linux kernel Local Use After Free Multiple Denial of Service Vulnerabilities
2017-05-29
http://www.securityfocus.com/bid/94135

Linux kernel CVE-2017-7308 Local Denial of Service Vulnerability
2017-05-29
http://www.securityfocus.com/bid/97234

Linux Kernel 'net/sctp/socket.c' Local Denial of Service Vulnerability
2017-05-29
http://www.securityfocus.com/bid/96222

Linux Kernel 'crypto/algif_hash.c' Local Denial of Service Vulnerability
2017-05-29
http://www.securityfocus.com/bid/94309

Samba CVE-2017-7494 Remote Code Execution Vulnerability
2017-05-29
http://www.securityfocus.com/bid/98636

Oracle Solaris CVE-2017-3622 Local Privilege Escalation Vulnerability
2017-05-29
http://www.securityfocus.com/bid/97774

OpenSSL CVE-2016-7055 Denial of Service Vulnerability
2017-05-29
http://www.securityfocus.com/bid/94242

Oracle Solaris CVE-2017-3623 Remote Code Execution Vulnerability
2017-05-29
http://www.securityfocus.com/bid/97778

OpenLDAP 'servers/slapd/back-mdb/search.c' Denial of Service Vulnerability
2017-05-29
http://www.securityfocus.com/bid/98736

ImageMagick CVE-2017-9262 Denial of Service Vulnerability
2017-05-29
http://www.securityfocus.com/bid/98735

FreeRADIUS TLS CVE-2017-9148 Authentication Bypass Vulnerability
2017-05-29
http://www.securityfocus.com/bid/98734

ImageMagick CVE-2017-9261 Denial of Service Vulnerability
2017-05-29
http://www.securityfocus.com/bid/98730

Microsoft Windows NTFS File System Denial of Service Vulnerability
2017-05-29
http://www.securityfocus.com/bid/98729

ZoneMinder CVE-2016-10203 Cross Site Scripting Vulnerability
2017-05-26
http://www.securityfocus.com/bid/97122

Rpcbind CVE-2017-8779 Remote Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98325

Ansible CVE-2017-7481 Security Bypass Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98492

Ansible CVE-2017-7466 Incomplete Fix Arbitrary Command Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/97595

Teeworlds 'client.cpp' Memory Corruption Vulnerability
2017-05-26
http://www.securityfocus.com/bid/94381

Adobe Flash Player CVE-2017-3071 Use After Free Remote Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98347

SANS News

FreeRadius Authentication Bypass

Threatpost

ShadowBrokers Put Price on Monthly Zero Day Leaks

Exploit

Microsoft MsMpEng - Use-After-Free via Saved Callers

Microsoft MsMpEng - Remotely Exploitable Use-After-Free due to Design Issue in GC...

Trend Micro Deep Security version 6.5 - XML External Entity Injection / Local...

Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files

Samba - is_known_pipename() Arbitrary Module Load (Metasploit)

Octopus Deploy - Authenticated Code Execution (Metasploit)

CERIO DT-100G-N/DT-300N/CW-300N - Multiple Vulnerabilities

uc-http Daemon - Local File Inclusion / Directory Traversal

WordPress Plugin Huge-IT Video Gallery 2.0.4 - SQL Injection

29.5.2017

Bugtraq

Multiple Local Privilege Escalation Vulnerabilities in Acunetix Web Vulnerability Scanner 11 2017-05-28
Florian Bogner (florian bogner sh)

Wordpress Plugin Social-Stream - Exposure of Twitter API Secret Key and Token 2017-05-26
kyle Lovett (krlovett gmail com)

[security bulletin] HPESBHF03730 rev.1 - HPE Aruba ClearPass Policy Manager, Multiple Vulnerabilities 2017-05-26
security-alert hpe com

Malware

 

Phishing

Tesco Bank

28th May 2017

Account Activity Alert

Indian

26th May 2017

RECEIPT EMAIL CONFIRMATIONS :
STATEMENT ACCOUNT SUBMITTED TO
RESET YOUR PASSWORD FOR OUR
CLIENT AREA

Vulnerebility

OpenSSL CVE-2016-7055 Denial of Service Vulnerability
2017-05-29
http://www.securityfocus.com/bid/94242

Oracle Solaris CVE-2017-3623 Remote Code Execution Vulnerability
2017-05-29
http://www.securityfocus.com/bid/97778

Samba CVE-2017-7494 Remote Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98636

ZoneMinder CVE-2016-10203 Cross Site Scripting Vulnerability
2017-05-26
http://www.securityfocus.com/bid/97122

Rpcbind CVE-2017-8779 Remote Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98325

Ansible CVE-2017-7481 Security Bypass Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98492

Ansible CVE-2017-7466 Incomplete Fix Arbitrary Command Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/97595

Teeworlds 'client.cpp' Memory Corruption Vulnerability
2017-05-26
http://www.securityfocus.com/bid/94381

Adobe Flash Player CVE-2017-3071 Use After Free Remote Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98347

Adobe Flash Player APSB17-15 Multiple Memory Corruption Vulnerabilities
2017-05-26
http://www.securityfocus.com/bid/98349

Xen CVE-2017-8905 Arbitrary Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98436

Xen CVE-2017-8904 Arbitrary Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98428

Xen CVE-2017-8903 Arbitrary Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98426

Linux kernel Local Use After Free Multiple Denial of Service Vulnerabilities
2017-05-26
http://www.securityfocus.com/bid/94135

Linux Kernel 'EXT4 image' Local Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/94354

Linux kernel CVE-2017-7308 Local Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/97234

Linux Kernel 'net/sctp/socket.c' Local Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/96222

Linux Kernel 'crypto/algif_hash.c' Local Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/94309

Linux Kernel CVE-2017-7895 Multiple Security Bypass Vulnerabilities
2017-05-26
http://www.securityfocus.com/bid/98085

Linux Kernel CVE-2017-8890 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98562

Multiple Puppet Products YAML Deserialization CVE-2017-2295 Remote Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98582

ImageMagick 'ept.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98388

ImageMagick 'MagickCore/profile.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98606

ImageMagick CVE-2017-8356 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98378

ImageMagick 'pict.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98377

ImageMagick CVE-2017-8346 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98346

ImageMagick 'png.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98373

ImageMagick CVE-2017-8345 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98138

ImageMagick CVE-2017-8352 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98372

ImageMagick 'mat.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98364
SANS News

Analysis of Competing Hypotheses (ACH part 1)

Threatpost

Microsoft Quietly Patches Another Critical Malware Protection Engine Flaw

Exploit

CERIO DT-100G-N/DT-300N/CW-300N - Multiple Vulnerabilities

27.5.2017

Bugtraq

Wordpress Plugin Social-Stream - Exposure of Twitter API Secret Key and Token 2017-05-26
kyle Lovett (krlovett gmail com)

[security bulletin] HPESBHF03730 rev.1 - HPE Aruba ClearPass Policy Manager, Multiple Vulnerabilities 2017-05-26
security-alert hpe com

[security bulletin] HPESBHF03754 rev.1 - HPE ML10 Gen 9 Server using Intel Xeon E3-1200 v5 Processor, Remote Access Restriction Bypass 2017-05-26
security-alert hpe com

[security bulletin] HPESBHF03750 rev.1 - HPE Network Products including Comware 5, Comware 7 and VCX running NTP, Remote Denial of Service (DoS), Unauthorized Modification, Local Denial of Service (DoS) 2017-05-25
security-alert hpe com

[SECURITY] [DSA 3863-1] imagemagick security update 2017-05-25
Moritz Muehlenhoff (jmm debian org)

[security bulletin] HPESBHF03746 rev.1 - HPE Intelligent Management Center (iMC) PLAT, Remote Code Execution 2017-05-25
HPE Product Security Response Team (security-alert hpe com)

WebKitGTK+ Security Advisory WSA-2017-0004 2017-05-25
Carlos Alberto Lopez Perez (clopez igalia com)

[slackware-security] samba (SSA:2017-144-01) 2017-05-24
Slackware Security Team (security slackware com)

Malware

 

Phishing

Indian

26th May 2017

RECEIPT EMAIL CONFIRMATIONS :
STATEMENT ACCOUNT SUBMITTED TO
RESET YOUR PASSWORD FOR OUR
CLIENT AREA

Apple

26th May 2017

Reminder : Apple ID has
temporary locked due
suspicious activity !

Vulnerebility

Samba CVE-2017-7494 Remote Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98636

ZoneMinder CVE-2016-10203 Cross Site Scripting Vulnerability
2017-05-26
http://www.securityfocus.com/bid/97122

Rpcbind CVE-2017-8779 Remote Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98325

Ansible CVE-2017-7481 Security Bypass Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98492

Ansible CVE-2017-7466 Incomplete Fix Arbitrary Command Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/97595

Teeworlds 'client.cpp' Memory Corruption Vulnerability
2017-05-26
http://www.securityfocus.com/bid/94381

Adobe Flash Player CVE-2017-3071 Use After Free Remote Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98347

Adobe Flash Player APSB17-15 Multiple Memory Corruption Vulnerabilities
2017-05-26
http://www.securityfocus.com/bid/98349

Xen CVE-2017-8905 Arbitrary Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98436

Xen CVE-2017-8904 Arbitrary Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98428

Xen CVE-2017-8903 Arbitrary Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98426

Linux kernel Local Use After Free Multiple Denial of Service Vulnerabilities
2017-05-26
http://www.securityfocus.com/bid/94135

Linux Kernel 'EXT4 image' Local Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/94354

Linux kernel CVE-2017-7308 Local Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/97234

Linux Kernel 'net/sctp/socket.c' Local Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/96222

Linux Kernel 'crypto/algif_hash.c' Local Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/94309

Linux Kernel CVE-2017-7895 Multiple Security Bypass Vulnerabilities
2017-05-26
http://www.securityfocus.com/bid/98085

Linux Kernel CVE-2017-8890 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98562

Multiple Puppet Products YAML Deserialization CVE-2017-2295 Remote Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98582

ImageMagick 'ept.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98388

ImageMagick 'MagickCore/profile.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98606

ImageMagick CVE-2017-8356 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98378

ImageMagick 'pict.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98377

ImageMagick CVE-2017-8346 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98346

ImageMagick 'png.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98373

ImageMagick CVE-2017-8345 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98138

ImageMagick CVE-2017-8352 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98372

ImageMagick 'mat.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98364

ImageMagick CVE-2017-8354 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98374

ImageMagick 'exr.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98363

SANS News

File2pcap - A new tool for your toolkit!

CyberChef a Must Have Tool in your Tool bag!

Analysis of Competing Hypotheses (ACH part 1)

Threatpost

Rash Of Phishing Attacks Use HTTPS To Con Victims

Pacemaker Ecosystem Fails its Cybersecurity Checkup

Mark Dowd on Exploit Mitigation Development

Exploit

Google Chrome 60.0.3080.5 V8 JavaScript Engine - Out-of-Bounds Write

D-Link DCS Series Cameras - Insecure Crossdomain

QWR-1104 Wireless-N Router - Cross-Site Scripting

Microsoft MsMpEng - Multiple Problems Handling ntdll!NtControlChannel Commands

JAD java Decompiler 1.5.8e - Local Buffer Overflow

Sandboxie 5.18 - Local Denial of Service

26.5.2017

Bugtraq

[security bulletin] HPESBHF03750 rev.1 - HPE Network Products including Comware 5, Comware 7 and VCX running NTP, Remote Denial of Service (DoS), Unauthorized Modification, Local Denial of Service (DoS) 2017-05-25
security-alert hpe com

[SECURITY] [DSA 3863-1] imagemagick security update 2017-05-25
Moritz Muehlenhoff (jmm debian org)

[security bulletin] HPESBHF03746 rev.1 - HPE Intelligent Management Center (iMC) PLAT, Remote Code Execution 2017-05-25
HPE Product Security Response Team (security-alert hpe com)

WebKitGTK+ Security Advisory WSA-2017-0004 2017-05-25
Carlos Alberto Lopez Perez (clopez igalia com)

[slackware-security] samba (SSA:2017-144-01) 2017-05-24
Slackware Security Team (security slackware com)

[security bulletin] HPESBHF03751 rev.1 - HPE Aruba AirWave Glass, Remote Code Execution 2017-05-24
security-alert hpe com

DefenseCode ThunderScan SAST Advisory: WordPress AffiliateWP Plugin Security Vulnerability 2017-05-24
DefenseCode (defensecode defensecode com)

DefenseCode ThunderScan SAST Advisory: WordPress Huge-IT Video Gallery Plugin Security Vulnerability 2017-05-24
DefenseCode (defensecode defensecode com)

DefenseCode ThunderScan SAST Advisory: WordPress All In One Schema.org Rich Snippets Plugin Security Vulnerability 2017-05-24
DefenseCode (defensecode defensecode com)

Malware

Ransom.Jaff

Ransom.GlobeImposter

Phishing

Apple

26th May 2017

Reminder : Apple ID has
temporary locked due
suspicious activity !

Vulnerebility

ZoneMinder CVE-2016-10203 Cross Site Scripting Vulnerability
2017-05-26
http://www.securityfocus.com/bid/97122

Rpcbind CVE-2017-8779 Remote Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98325

Ansible CVE-2017-7481 Security Bypass Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98492

Ansible CVE-2017-7466 Incomplete Fix Arbitrary Command Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/97595

Teeworlds 'client.cpp' Memory Corruption Vulnerability
2017-05-26
http://www.securityfocus.com/bid/94381

Adobe Flash Player CVE-2017-3071 Use After Free Remote Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98347

Adobe Flash Player APSB17-15 Multiple Memory Corruption Vulnerabilities
2017-05-26
http://www.securityfocus.com/bid/98349

Xen CVE-2017-8905 Arbitrary Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98436

Xen CVE-2017-8904 Arbitrary Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98428

Xen CVE-2017-8903 Arbitrary Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98426

Linux kernel Local Use After Free Multiple Denial of Service Vulnerabilities
2017-05-26
http://www.securityfocus.com/bid/94135

Linux Kernel 'EXT4 image' Local Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/94354

Linux kernel CVE-2017-7308 Local Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/97234

Linux Kernel 'net/sctp/socket.c' Local Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/96222

Linux Kernel 'crypto/algif_hash.c' Local Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/94309

Linux Kernel CVE-2017-7895 Multiple Security Bypass Vulnerabilities
2017-05-26
http://www.securityfocus.com/bid/98085

Linux Kernel CVE-2017-8890 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98562

Multiple Puppet Products YAML Deserialization CVE-2017-2295 Remote Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98582

ImageMagick 'ept.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98388

ImageMagick 'MagickCore/profile.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98606

ImageMagick CVE-2017-8356 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98378

ImageMagick 'pict.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98377

ImageMagick CVE-2017-8346 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98346

ImageMagick 'png.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98373

ImageMagick CVE-2017-8345 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98138

ImageMagick CVE-2017-8352 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98372

ImageMagick 'mat.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98364

ImageMagick CVE-2017-8354 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98374

ImageMagick 'exr.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98363

ImageMagick 'sfw.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98370Linux kernel Local Use After Free Multiple Denial of Service Vulnerabilities
2017-05-26
http://www.securityfocus.com/bid/94135

Linux Kernel 'EXT4 image' Local Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/94354

Linux kernel CVE-2017-7308 Local Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/97234

Linux Kernel 'net/sctp/socket.c' Local Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/96222

Linux Kernel 'crypto/algif_hash.c' Local Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/94309

Linux Kernel CVE-2017-7895 Multiple Security Bypass Vulnerabilities
2017-05-26
http://www.securityfocus.com/bid/98085

Linux Kernel CVE-2017-8890 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98562

Multiple Puppet Products YAML Deserialization CVE-2017-2295 Remote Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98582

ImageMagick 'ept.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98388

ImageMagick 'MagickCore/profile.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98606

ImageMagick CVE-2017-8356 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98378

ImageMagick 'pict.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98377

ImageMagick CVE-2017-8346 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98346

ImageMagick 'png.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98373

ImageMagick CVE-2017-8345 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98138

ImageMagick CVE-2017-8352 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98372

ImageMagick 'mat.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98364

ImageMagick CVE-2017-8354 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98374

ImageMagick 'exr.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98363

ImageMagick 'sfw.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98370

ImageMagick CVE-2017-8343 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98132

ImageMagick CVE-2017-8355 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98380

ImageMagick 'coders/rle.c' Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98603

ImageMagick CVE-2017-8344 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98136

ImageMagick CVE-2017-7941 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/97944

ImageMagick CVE-2017-9098 Local Information Disclosure Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98593

ImageMagick CVE-2017-7943 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/97956

ImageMagick CVE-2017-8351 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98371

Mozilla Firefox Multiple Security Vulnerabilities
2017-05-26
http://www.securityfocus.com/bid/97940

Mozilla Network Security Services CVE-2017-5461 Memory Corruption Vulnerability
2017-05-26
http://www.securityfocus.com/bid/98050Apache Tomcat CVE-2017-5651 Information Disclosure Vulnerability
2017-05-26
http://www.securityfocus.com/bid/97544

Apache Tomcat CVE-2015-5351 Cross Site Request Forgery Vulnerability
2017-05-26
http://www.securityfocus.com/bid/83330

Apache Tomcat CVE-2015-5345 Directory Traversal Vulnerability
2017-05-26
http://www.securityfocus.com/bid/83328

Apache Commons FileUpload CVE-2016-3092 Denial Of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/91453

Apache Tomcat Security Manager CVE-2016-0714 Remote Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/83327

Apache Tomcat CVE-2017-5648 Information Disclosure Vulnerability
2017-05-26
http://www.securityfocus.com/bid/97530

Apache Tomcat CVE-2016-8745 Information Disclosure Vulnerability
2017-05-26
http://www.securityfocus.com/bid/94828

Apache Tomcat CVE-2016-1240 Local Privilege Escalation Vulnerability
2017-05-26
http://www.securityfocus.com/bid/93263

Apache Tomcat CVE-2016-0763 Security Bypass Vulnerability
2017-05-26
http://www.securityfocus.com/bid/83326

Apache Tomcat CVE-2015-5346 Session Fixation Vulnerability
2017-05-26
http://www.securityfocus.com/bid/83323

Apache Tomcat CVE-2017-5650 Denial of Service Vulnerability
2017-05-26
http://www.securityfocus.com/bid/97531

Apache Tomcat CVE-2015-5174 Directory Traversal Vulnerability
2017-05-26
http://www.securityfocus.com/bid/83329

Apache Tomcat Security Manager CVE-2016-0706 Information Disclosure Vulnerability
2017-05-26
http://www.securityfocus.com/bid/83324

Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
2017-05-26
http://www.securityfocus.com/bid/96729

Linux Kernel 'EXT4 image' Local Denial of Service Vulnerability
2017-05-25
http://www.securityfocus.com/bid/94354

Samba CVE-2017-7494 Remote Code Execution Vulnerability
2017-05-25
http://www.securityfocus.com/bid/98636

Linux Kernel 'net/sctp/socket.c' Local Denial of Service Vulnerability
2017-05-25
http://www.securityfocus.com/bid/96222

Linux kernel CVE-2017-7308 Local Denial of Service Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97234

Linux Kernel 'crypto/algif_hash.c' Local Denial of Service Vulnerability
2017-05-25
http://www.securityfocus.com/bid/94309

Linux kernel Local Use After Free Multiple Denial of Service Vulnerabilities
2017-05-25
http://www.securityfocus.com/bid/94135

Ghostscript CVE-2017-5951 Denial of Service Vulnerability
2017-05-25
http://www.securityfocus.com/bid/98665

Ghostscript CVE-2017-8291 Multiple Remote Code Execution Vulnerabilities
2017-05-25
http://www.securityfocus.com/bid/98476

Ghostscript CVE-2016-9601 Local Integer Overflow Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97095

Ghostscript CVE-2017-7207 Denial of Service Vulnerability
2017-05-25
http://www.securityfocus.com/bid/96995

Linux Kernel CVE-2017-7184 Local Privilege Escalation Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97018

Linux Kernel 'sound/core/pcm_lib.c' Local Use After Free Memory Corruption Vulnerability
2017-05-25
http://www.securityfocus.com/bid/94654

OpenSSL CVE-2016-7056 Local Information Disclosure Vulnerability
2017-05-25
http://www.securityfocus.com/bid/95375

giflib 'util/giffix.c' Heap Based Buffer Overflow Vulnerability
2017-05-25
http://www.securityfocus.com/bid/81697

Cisco TelePresence IX5000 Series CVE-2017-6652 Directory Traversal Vulnerability
2017-05-25
http://www.securityfocus.com/bid/98519

Linux Kernel CVE-2017-7294 Local Denial of Service Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97177

SANS News

 

Threatpost

WannaCry Ransom Note Written by Chinese, English Speaking Authors

Revised Active Defense Bill Allows Victims to Recover or Destroy Stolen Data

Keybase Extension Brings End-to-End Encrypted Chat To Twitter, Reddit, GitHub

Exploit

 

25.5.2017

Bugtraq

[security bulletin] HPESBHF03746 rev.1 - HPE Intelligent Management Center (iMC) PLAT, Remote Code Execution 2017-05-25
HPE Product Security Response Team (security-alert hpe com)

WebKitGTK+ Security Advisory WSA-2017-0004 2017-05-25
Carlos Alberto Lopez Perez (clopez igalia com)

[slackware-security] samba (SSA:2017-144-01) 2017-05-24
Slackware Security Team (security slackware com)

[security bulletin] HPESBHF03751 rev.1 - HPE Aruba AirWave Glass, Remote Code Execution 2017-05-24
security-alert hpe com

DefenseCode ThunderScan SAST Advisory: WordPress AffiliateWP Plugin Security Vulnerability 2017-05-24
DefenseCode (defensecode defensecode com)

DefenseCode ThunderScan SAST Advisory: WordPress Huge-IT Video Gallery Plugin Security Vulnerability 2017-05-24
DefenseCode (defensecode defensecode com)

DefenseCode ThunderScan SAST Advisory: WordPress All In One Schema.org Rich Snippets Plugin Security Vulnerability 2017-05-24
DefenseCode (defensecode defensecode com)

[SECURITY] [DSA 3861-1] libtasn1-6 security update 2017-05-24
Sebastien Delafond (seb debian org)

Secunia Research: Microsoft Windows Heap-based Buffer Overflow Vulnerabilities 2017-05-23
Secunia Research (remove-vuln secunia com)

Malware

W32.Styes

Phishing

 

Vulnerebility

Samba CVE-2017-7494 Remote Code Execution Vulnerability
2017-05-25
http://www.securityfocus.com/bid/98636

Linux Kernel 'net/sctp/socket.c' Local Denial of Service Vulnerability
2017-05-25
http://www.securityfocus.com/bid/96222

Linux kernel CVE-2017-7308 Local Denial of Service Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97234

Linux Kernel 'crypto/algif_hash.c' Local Denial of Service Vulnerability
2017-05-25
http://www.securityfocus.com/bid/94309

Linux kernel Local Use After Free Multiple Denial of Service Vulnerabilities
2017-05-25
http://www.securityfocus.com/bid/94135

Ghostscript CVE-2017-5951 Denial of Service Vulnerability
2017-05-25
http://www.securityfocus.com/bid/98665

Ghostscript CVE-2017-8291 Multiple Remote Code Execution Vulnerabilities
2017-05-25
http://www.securityfocus.com/bid/98476

Ghostscript CVE-2016-9601 Local Integer Overflow Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97095

Ghostscript CVE-2017-7207 Denial of Service Vulnerability
2017-05-25
http://www.securityfocus.com/bid/96995

Linux Kernel CVE-2017-7184 Local Privilege Escalation Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97018

Linux Kernel 'sound/core/pcm_lib.c' Local Use After Free Memory Corruption Vulnerability
2017-05-25
http://www.securityfocus.com/bid/94654

OpenSSL CVE-2016-7056 Local Information Disclosure Vulnerability
2017-05-25
http://www.securityfocus.com/bid/95375

giflib 'util/giffix.c' Heap Based Buffer Overflow Vulnerability
2017-05-25
http://www.securityfocus.com/bid/81697

Cisco TelePresence IX5000 Series CVE-2017-6652 Directory Traversal Vulnerability
2017-05-25
http://www.securityfocus.com/bid/98519

Linux Kernel CVE-2017-7294 Local Denial of Service Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97177

Linux Kernel CVE-2017-7261 Local Denial of Service Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97096

Linux Kernel CVE-2017-7616 Multiple Local Information Disclosure Vulnerabilities
2017-05-25
http://www.securityfocus.com/bid/97527

Linux Kernel CVE-2017-7187 Local Denial of Service Vulnerability
2017-05-25
http://www.securityfocus.com/bid/96989

Oracle Java SE and JRockit CVE-2017-3511 Local Security Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97731

Oracle Java SE and JRockit CVE-2017-3533 Remote Security Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97740

IBM Java SDK CVE-2017-1289 XML External Entity Injection Vulnerability
2017-05-25
http://www.securityfocus.com/bid/98401

Oracle Java SE and JRockit CVE-2017-3544 Remote Security Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97745

zlib Multiple Denial of Service Vulnerabilities
2017-05-25
http://www.securityfocus.com/bid/95131

Oracle Java SE CVE-2017-3539 Remote Security Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97752

Oracle Java SE CVE-2017-3509 Remote Security Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97737

Resteasy CVE-2016-9606 Remote Code Execution Vulnerability
2017-05-25
http://www.securityfocus.com/bid/94940

GNU Bash CVE-2016-9401 Local Security Bypass Vulnerability
2017-05-25
http://www.securityfocus.com/bid/94398

GNU Bash CVE-2016-7543 Local Command Execution Vulnerability
2017-05-25
http://www.securityfocus.com/bid/93183

GNU Bash CVE-2016-0634 Local Code Execution Vulnerability
2017-05-25
http://www.securityfocus.com/bid/92999

GNU Bash CVE-2017-5932 Multiple Arbitrary Code Execution Vulnerabilities
2017-05-25
http://www.securityfocus.com/bid/96136Oracle Java SE CVE-2017-3539 Remote Security Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97752

IBM Java SDK CVE-2017-1289 XML External Entity Injection Vulnerability
2017-05-25
http://www.securityfocus.com/bid/98401

Oracle Java SE and JRockit CVE-2017-3511 Local Security Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97731

Oracle Java SE CVE-2017-3509 Remote Security Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97737

Oracle Java SE and JRockit CVE-2017-3533 Remote Security Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97740

Oracle Java SE and JRockit CVE-2017-3544 Remote Security Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97745

zlib Multiple Denial of Service Vulnerabilities
2017-05-25
http://www.securityfocus.com/bid/95131

collectd CVE-2017-7401 Multiple Denial of Service Vulnerabilities
2017-05-24
http://www.securityfocus.com/bid/97321

cURL/libcURL CVE-2016-8624 Remote Security Bypass Vulnerability
2017-05-24
http://www.securityfocus.com/bid/94103

cURL/libcURL CVE-2016-8621 Information Disclosure Vulnerability
2017-05-24
http://www.securityfocus.com/bid/94101

ICU CVE-2017-7867 Multiple Heap Buffer Overflow Vulnerabilities
2017-05-24
http://www.securityfocus.com/bid/97672

ISC BIND CVE-2017-3136 Remote Denial of Service Vulnerability
2017-05-24
http://www.securityfocus.com/bid/97653

ISC BIND CVE-2017-3137 Remote Denial of Service Vulnerability
2017-05-24
http://www.securityfocus.com/bid/97651

Oracle MySQL Connectors CVE-2017-3589 Local Security Vulnerability
2017-05-24
http://www.securityfocus.com/bid/97836

Apache Tomcat CVE-2017-5648 Information Disclosure Vulnerability
2017-05-24
http://www.securityfocus.com/bid/97530

Apache Tomcat CVE-2016-8745 Information Disclosure Vulnerability
2017-05-24
http://www.securityfocus.com/bid/94828

Oracle MySQL Connectors CVE-2017-3586 Remote Security Vulnerability
2017-05-24
http://www.securityfocus.com/bid/97784

Multiple BlackBerry Products CVE-2017-3894 HTML Injection Vulnerability
2017-05-24
http://www.securityfocus.com/bid/98552

Rpcbind CVE-2017-8779 Remote Denial of Service Vulnerability
2017-05-24
http://www.securityfocus.com/bid/98325

HP Aruba AirWave Glass CVE-2017-8946 Unspecified Remote Code Execution Vulnerability
2017-05-24
http://www.securityfocus.com/bid/98644

VLAN VLC CVE-2017-8310 Denial of Service Vulnerability
2017-05-24
http://www.securityfocus.com/bid/98638

Samba CVE-2017-7494 Remote Code Execution Vulnerability
2017-05-24
http://www.securityfocus.com/bid/98636

SAP HANA Multiple Security Vulnerabilities
2017-05-23
http://www.securityfocus.com/bid/96206

SAP Netweaver Visual Composer XML External Entity Information Disclosure Vulnerability
2017-05-23
http://www.securityfocus.com/bid/96204

OneThird CMS CVE-2017-2124 Cross Site Scripting Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98604

elfutils CVE-2017-7608 Remote Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98609

elfutils CVE-2017-7607 Remote Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98608

LibRaw CVE-2017-6886 Memory Corruption Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98605

ImageMagick 'MagickCore/profile.c' Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98606

WordPress WP Statistics Plugin CVE-2017-2135 Unspecified Cross Site Scripting Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98610Oracle Java SE CVE-2017-3539 Remote Security Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97752

IBM Java SDK CVE-2017-1289 XML External Entity Injection Vulnerability
2017-05-25
http://www.securityfocus.com/bid/98401

Oracle Java SE and JRockit CVE-2017-3511 Local Security Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97731

Oracle Java SE CVE-2017-3509 Remote Security Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97737

Oracle Java SE and JRockit CVE-2017-3533 Remote Security Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97740

Oracle Java SE and JRockit CVE-2017-3544 Remote Security Vulnerability
2017-05-25
http://www.securityfocus.com/bid/97745

zlib Multiple Denial of Service Vulnerabilities
2017-05-25
http://www.securityfocus.com/bid/95131

collectd CVE-2017-7401 Multiple Denial of Service Vulnerabilities
2017-05-24
http://www.securityfocus.com/bid/97321

cURL/libcURL CVE-2016-8624 Remote Security Bypass Vulnerability
2017-05-24
http://www.securityfocus.com/bid/94103

cURL/libcURL CVE-2016-8621 Information Disclosure Vulnerability
2017-05-24
http://www.securityfocus.com/bid/94101

ICU CVE-2017-7867 Multiple Heap Buffer Overflow Vulnerabilities
2017-05-24
http://www.securityfocus.com/bid/97672

ISC BIND CVE-2017-3136 Remote Denial of Service Vulnerability
2017-05-24
http://www.securityfocus.com/bid/97653

ISC BIND CVE-2017-3137 Remote Denial of Service Vulnerability
2017-05-24
http://www.securityfocus.com/bid/97651

Oracle MySQL Connectors CVE-2017-3589 Local Security Vulnerability
2017-05-24
http://www.securityfocus.com/bid/97836

Apache Tomcat CVE-2017-5648 Information Disclosure Vulnerability
2017-05-24
http://www.securityfocus.com/bid/97530

Apache Tomcat CVE-2016-8745 Information Disclosure Vulnerability
2017-05-24
http://www.securityfocus.com/bid/94828

Oracle MySQL Connectors CVE-2017-3586 Remote Security Vulnerability
2017-05-24
http://www.securityfocus.com/bid/97784

Multiple BlackBerry Products CVE-2017-3894 HTML Injection Vulnerability
2017-05-24
http://www.securityfocus.com/bid/98552

Rpcbind CVE-2017-8779 Remote Denial of Service Vulnerability
2017-05-24
http://www.securityfocus.com/bid/98325

HP Aruba AirWave Glass CVE-2017-8946 Unspecified Remote Code Execution Vulnerability
2017-05-24
http://www.securityfocus.com/bid/98644

VLAN VLC CVE-2017-8310 Denial of Service Vulnerability
2017-05-24
http://www.securityfocus.com/bid/98638

Samba CVE-2017-7494 Remote Code Execution Vulnerability
2017-05-24
http://www.securityfocus.com/bid/98636

SAP HANA Multiple Security Vulnerabilities
2017-05-23
http://www.securityfocus.com/bid/96206

SAP Netweaver Visual Composer XML External Entity Information Disclosure Vulnerability
2017-05-23
http://www.securityfocus.com/bid/96204

OneThird CMS CVE-2017-2124 Cross Site Scripting Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98604

elfutils CVE-2017-7608 Remote Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98609

elfutils CVE-2017-7607 Remote Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98608

LibRaw CVE-2017-6886 Memory Corruption Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98605

ImageMagick 'MagickCore/profile.c' Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98606

WordPress WP Statistics Plugin CVE-2017-2135 Unspecified Cross Site Scripting Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98610

SANS News

Critical Vulnerability in Samba from 3.5.0 onwards

Threatpost

Malware Network Communication Provides Better Early Warning Signal

Twitter Flaw Could Have Allowed Attacker to Tweet From Any Account

Android Overlay and Accessibility Features Leave Millions at Risk

Password Breaches Fueling Booming Credential Stuffing Business

Exploit

Apple WebKit / Safari 10.0.3(12602.4.8) - 'WebCore::FrameView::scheduleRelayout'...

Skia Graphics Library - Heap Overflow due to Rounding Error in SkEdge::setLine

Mozilla Firefox < 53 - 'gfxTextRun' Out-of-Bounds Read

Mozilla Firefox < 53 - 'ConvolvePixel' Memory Disclosure

Apple WebKit / Safari 10.0.3(12602.4.8) - 'Editor::Command::execute' Universal Cross-Site...

WebKit - 'ContainerNode::parserRemoveChild' Universal Cross-Site Scripting

WebKit - 'ContainerNode::parserInsertBefore' Universal Cross-Site Scripting

WebKit - enqueuePageshowEvent and enqueuePopstateEvent Universal Cross-Site Scripting

WebKit - Stealing Variables via Page Navigation in FrameLoader::clear

Apple Safari 10.0.3(12602.4.8) / WebKit - 'HTMLObjectElement::updateWidget' Universal...

NetGain EM 7.2.647 build 941 - Authentication Bypass / Local File Inclusion

NetGain EM 7.2.647 build 941 - Authentication Bypass / Local File Inclusion

Dup Scout Enterprise 9.7.18 - '.xml' Local Buffer Overflow

Samba 3.5.0 - Remote Code Execution

24.5.2017

Bugtraq

Secunia Research: Microsoft Windows Heap-based Buffer Overflow Vulnerabilities 2017-05-23
Secunia Research (remove-vuln secunia com)

HPESBHF03744 rev.1 - HPE Intelligent Management Center (iMC) PLAT running OpenSSL, Remote Denial of Service (DoS) 2017-05-22
HPE Product Security Response Team (security-alert hpe com)

CVE-2017-9024 Secure Auditor - v3.0 Directory Traversal 2017-05-22
apparitionsec gmail com (hyp3rlinx)

CVE-2017-9046 Pegasus "winpm-32.exe" v4.72 Mailto: Link Remote Code Execution 2017-05-22
apparitionsec gmail com (hyp3rlinx)

CVE-2017-9046 Mantis Bug Tracker 1.3.10 / v2.3.0 CSRF Permalink Injection 2017-05-22
apparitionsec gmail com (hyp3rlinx)

May 2017 - SourceTree - Critical Security Advisory 2017-05-22
Atlassian (security atlassian com)

Malware

Ransom:Win32/WannaCrypt
Ransom:Win32/Tescrypt.T

Phishing

*****THANK YOU*****

23rd May 2017

MONDAY: Your $50 Amazon gift
card

Amazon.com

23rd May 2017

Amazon.com - Your Cancellation
166-193417-3158469

Vulnerebility

SAP HANA Multiple Security Vulnerabilities
2017-05-23
http://www.securityfocus.com/bid/96206

Rpcbind CVE-2017-8779 Remote Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98325

SAP Netweaver Visual Composer XML External Entity Information Disclosure Vulnerability
2017-05-23
http://www.securityfocus.com/bid/96204

OneThird CMS CVE-2017-2124 Cross Site Scripting Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98604

elfutils CVE-2017-7608 Remote Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98609

elfutils CVE-2017-7607 Remote Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98608

LibRaw CVE-2017-6886 Memory Corruption Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98605

ImageMagick 'MagickCore/profile.c' Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98606

WordPress WP Statistics Plugin CVE-2017-2135 Unspecified Cross Site Scripting Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98610

GNU Binutils CVE-2017-9041 Remote Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98598

Foreman CVE-2017-7505 Remote Privilege Escalation Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98607

ImageMagick 'coders/rle.c' Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98603

libxml2 CVE-2017-9049 Heap Buffer Overflow Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98601

OpenSSL CVE-2016-7053 NULL Pointer Dereference Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/94244

OpenSSL CVE-2016-7054 Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/94238

OpenSSL CVE-2016-7055 Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/94242

Libxml2 CVE-2017-9047 Buffer Overflow Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98599

Linux kernel CVE-2017-9075 Local Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98597

Ghostscript CVE-2017-8908 Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98427

PHP 'Zend/zend_variables.h' Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98596

Red Hat Jboss Application Server CVE-2017-7504 Remote Code Execution Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98595

LibTIFF 'tif_dir.c' Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98594

ImageMagick CVE-2017-9098 Local Information Disclosure Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98593

LibRaw CVE-2017-6887 Memory Corruption Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98592

Linux kernel CVE-2017-9076 Local Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98586

Apple iOS/macOS/WatchOS/tvOS CVE-2017-2522 Memory Corruption Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98588

GNU Binutils CVE-2017-9038 Multiple Denial of Service Vulnerabilities
2017-05-23
http://www.securityfocus.com/bid/98589

Samba CVE-2016-2126 Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/94994

Samba CVE-2017-2619 Symlink Vulnerability
2017-05-23
http://www.securityfocus.com/bid/97033

Samba CVE-2016-2125 User Impersonation Vulnerability
2017-05-23
http://www.securityfocus.com/bid/94988

SANS News

Jaff ransomware gets a makeover

Threatpost

Yahoo Retires ImageMagick After Bugs Leak Server Memory

Google Elevates Security in Android O

Exploit

Apple iOS/macOS - Memory Corruption Due to Bad Bounds Checking in NSCharacterSet Coding...

Apple iOS/macOS - NSUnarchiver Heap Corruption Due to Lack of Bounds Checking in...

Apple iOS/macOS - NSKeyedArchiver Heap Corruption Due to Rounding Error in...

Apple iOS/macOS - NSKeyedArchiver Memory Corruption Due to Lack of Bounds Checking in...

Apple iOS/macOS Kernel - Use-After-Free Due to Bad Locking in Unix Domain Socket File...

Apple iOS/macOS Kernel - Memory Disclosure Due to Lack of Bounds Checking in netagent...

Apple macOS - Local Privilege Escalation Due to Lack of Bounds Checking in HIServices...

VX Search Enterprise 9.5.12 - GET Buffer Overflow (Metasploit)

KDE 4/5 - 'KAuth' Privilege Escalation

23.5.2017

Bugtraq

Secunia Research: Microsoft Windows Heap-based Buffer Overflow Vulnerabilities 2017-05-23
Secunia Research (remove-vuln secunia com)

HPESBHF03744 rev.1 - HPE Intelligent Management Center (iMC) PLAT running OpenSSL, Remote Denial of Service (DoS) 2017-05-22
HPE Product Security Response Team (security-alert hpe com)

CVE-2017-9024 Secure Auditor - v3.0 Directory Traversal 2017-05-22
apparitionsec gmail com (hyp3rlinx)

CVE-2017-9046 Pegasus "winpm-32.exe" v4.72 Mailto: Link Remote Code Execution 2017-05-22
apparitionsec gmail com (hyp3rlinx)

CVE-2017-9046 Mantis Bug Tracker 1.3.10 / v2.3.0 CSRF Permalink Injection 2017-05-22
apparitionsec gmail com (hyp3rlinx)

May 2017 - SourceTree - Critical Security Advisory 2017-05-22
Atlassian (security atlassian com)

CVE-2017-9024 Secure Auditor - v3.0 Directory Traversal 2017-05-20
apparitionsec gmail com (hyp3rlinx)

[SECURITY] [DSA 3858-1] openjdk-7 security update 2017-05-19
Moritz Muehlenhoff (jmm debian org)

[SECURITY] CVE-2017-5657: Apache Archiva CSRF vulnerability for REST endpoints 2017-05-19
Martin (martin_s apache org)

Malware

 

Phishing

Amazon.com

23rd May 2017

Amazon.com - Your Cancellation
166-193417-3158469

Vulnerebility

OneThird CMS CVE-2017-2124 Cross Site Scripting Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98604

elfutils CVE-2017-7608 Remote Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98609

elfutils CVE-2017-7607 Remote Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98608

LibRaw CVE-2017-6886 Memory Corruption Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98605

ImageMagick 'MagickCore/profile.c' Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98606

WordPress WP Statistics Plugin CVE-2017-2135 Unspecified Cross Site Scripting Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98610

GNU Binutils CVE-2017-9041 Remote Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98598

Foreman CVE-2017-7505 Remote Privilege Escalation Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98607

ImageMagick 'coders/rle.c' Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98603

libxml2 CVE-2017-9049 Heap Buffer Overflow Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98601

OpenSSL CVE-2016-7053 NULL Pointer Dereference Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/94244

OpenSSL CVE-2016-7054 Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/94238

OpenSSL CVE-2016-7055 Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/94242

Libxml2 CVE-2017-9047 Buffer Overflow Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98599

Linux kernel CVE-2017-9075 Local Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98597

Ghostscript CVE-2017-8908 Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98427

PHP 'Zend/zend_variables.h' Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98596

Red Hat Jboss Application Server CVE-2017-7504 Remote Code Execution Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98595

LibTIFF 'tif_dir.c' Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98594

ImageMagick CVE-2017-9098 Local Information Disclosure Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98593

LibRaw CVE-2017-6887 Memory Corruption Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98592

Linux kernel CVE-2017-9076 Local Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98586

Apple iOS/macOS/WatchOS/tvOS CVE-2017-2522 Memory Corruption Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98588

GNU Binutils CVE-2017-9038 Multiple Denial of Service Vulnerabilities
2017-05-23
http://www.securityfocus.com/bid/98589

Samba CVE-2016-2126 Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/94994

Samba CVE-2017-2619 Symlink Vulnerability
2017-05-23
http://www.securityfocus.com/bid/97033

Samba CVE-2016-2125 User Impersonation Vulnerability
2017-05-23
http://www.securityfocus.com/bid/94988

GNU Binutils CVE-2017-9043 Remote Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98591

Rpcbind CVE-2017-8779 Remote Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98325

SAP Business One for Android CVE-2016-6256 XML External Entity Injection Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98590OpenSSL CVE-2016-7053 NULL Pointer Dereference Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/94244

OpenSSL CVE-2016-7054 Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/94238

OpenSSL CVE-2016-7055 Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/94242

Ghostscript CVE-2017-8908 Denial of Service Vulnerability
2017-05-23
http://www.securityfocus.com/bid/98427

Samba CVE-2016-2126 Denial of Service Vulnerability
2017-05-22
http://www.securityfocus.com/bid/94994

Samba CVE-2017-2619 Symlink Vulnerability
2017-05-22
http://www.securityfocus.com/bid/97033

Samba CVE-2016-2125 User Impersonation Vulnerability
2017-05-22
http://www.securityfocus.com/bid/94988

Rpcbind CVE-2017-8779 Remote Denial of Service Vulnerability
2017-05-22
http://www.securityfocus.com/bid/98325

KDE KAuth CVE-2017-8422 Local Privilege Escalation Vulnerability
2017-05-22
http://www.securityfocus.com/bid/98412

Oracle Java SE and JRockit CVE-2017-3533 Remote Security Vulnerability
2017-05-22
http://www.securityfocus.com/bid/97740

Oracle Java SE CVE-2017-3539 Remote Security Vulnerability
2017-05-22
http://www.securityfocus.com/bid/97752

Oracle Java SE and JRockit CVE-2017-3544 Remote Security Vulnerability
2017-05-22
http://www.securityfocus.com/bid/97745

Oracle Java SE and JRockit CVE-2017-3526 Remote Security Vulnerability
2017-05-22
http://www.securityfocus.com/bid/97733

Oracle Java SE CVE-2017-3509 Remote Security Vulnerability
2017-05-22
http://www.securityfocus.com/bid/97737

Oracle Java SE and JRockit CVE-2017-3511 Local Security Vulnerability
2017-05-22
http://www.securityfocus.com/bid/97731

Juniper Junos CVE-2017-2312 Denial of Service Vulnerability
2017-05-22
http://www.securityfocus.com/bid/97611

OpenSSL CVE-2015-0204 Man in the Middle Security Bypass Vulnerability
2017-05-22
http://www.securityfocus.com/bid/71936

OpenSSL CVE-2016-6304 Denial of Service Vulnerability
2017-05-22
http://www.securityfocus.com/bid/93150

Dropbear SSH Server Use After Free Remote Code Execution Vulnerability
2017-05-22
http://www.securityfocus.com/bid/52159

FreeBSD CVE-2013-5209 Information Disclosure Vulnerability
2017-05-22
http://www.securityfocus.com/bid/61939

Apple iOS/WatchOS/tvOS/macOS Multiple Security Vulnerabilities
2017-05-22
http://www.securityfocus.com/bid/98468

Foreman CVE-2017-7505 Remote Privilege Escalation Vulnerability
2017-05-22
http://www.securityfocus.com/bid/98607

ImageMagick 'MagickCore/profile.c' Denial of Service Vulnerability
2017-05-22
http://www.securityfocus.com/bid/98606

ImageMagick 'coders/rle.c' Denial of Service Vulnerability
2017-05-22
http://www.securityfocus.com/bid/98603

LibTIFF 'tif_dir.c' Denial of Service Vulnerability
2017-05-22
http://www.securityfocus.com/bid/98594

ImageMagick CVE-2017-9098 Local Information Disclosure Vulnerability
2017-05-22
http://www.securityfocus.com/bid/98593

Apple iOS/macOS/WatchOS/tvOS CVE-2017-2523 Memory Corruption Vulnerability
2017-05-22
http://www.securityfocus.com/bid/98584

PHP 'Zend/zend_variables.h' Denial of Service Vulnerability
2017-05-21
http://www.securityfocus.com/bid/98596

LibTIFF CVE-2017-9117 Heap Based Buffer Overflow Vulnerability
2017-05-21
http://www.securityfocus.com/bid/98581

SAP Business One for Android CVE-2016-6256 XML External Entity Injection Vulnerability
2017-05-20
http://www.securityfocus.com/bid/98590Samba CVE-2016-2126 Denial of Service Vulnerability
2017-05-22
http://www.securityfocus.com/bid/94994

Samba CVE-2017-2619 Symlink Vulnerability
2017-05-22
http://www.securityfocus.com/bid/97033

Samba CVE-2016-2125 User Impersonation Vulnerability
2017-05-22
http://www.securityfocus.com/bid/94988

Rpcbind CVE-2017-8779 Remote Denial of Service Vulnerability
2017-05-22
http://www.securityfocus.com/bid/98325

KDE KAuth CVE-2017-8422 Local Privilege Escalation Vulnerability
2017-05-22
http://www.securityfocus.com/bid/98412

Oracle Java SE and JRockit CVE-2017-3533 Remote Security Vulnerability
2017-05-22
http://www.securityfocus.com/bid/97740

Oracle Java SE CVE-2017-3539 Remote Security Vulnerability
2017-05-22
http://www.securityfocus.com/bid/97752

Oracle Java SE and JRockit CVE-2017-3544 Remote Security Vulnerability
2017-05-22
http://www.securityfocus.com/bid/97745

Oracle Java SE and JRockit CVE-2017-3526 Remote Security Vulnerability
2017-05-22
http://www.securityfocus.com/bid/97733

Oracle Java SE CVE-2017-3509 Remote Security Vulnerability
2017-05-22
http://www.securityfocus.com/bid/97737

Oracle Java SE and JRockit CVE-2017-3511 Local Security Vulnerability
2017-05-22
http://www.securityfocus.com/bid/97731

Juniper Junos CVE-2017-2312 Denial of Service Vulnerability
2017-05-22
http://www.securityfocus.com/bid/97611

OpenSSL CVE-2015-0204 Man in the Middle Security Bypass Vulnerability
2017-05-22
http://www.securityfocus.com/bid/71936

OpenSSL CVE-2016-6304 Denial of Service Vulnerability
2017-05-22
http://www.securityfocus.com/bid/93150

Dropbear SSH Server Use After Free Remote Code Execution Vulnerability
2017-05-22
http://www.securityfocus.com/bid/52159

FreeBSD CVE-2013-5209 Information Disclosure Vulnerability
2017-05-22
http://www.securityfocus.com/bid/61939

Apple iOS/WatchOS/tvOS/macOS Multiple Security Vulnerabilities
2017-05-22
http://www.securityfocus.com/bid/98468

ImageMagick CVE-2017-9098 Local Information Disclosure Vulnerability
2017-05-22
http://www.securityfocus.com/bid/98593

Apple iOS/macOS/WatchOS/tvOS CVE-2017-2523 Memory Corruption Vulnerability
2017-05-22
http://www.securityfocus.com/bid/98584

LibTIFF CVE-2017-9117 Heap Based Buffer Overflow Vulnerability
2017-05-21
http://www.securityfocus.com/bid/98581

SAP Business One for Android CVE-2016-6256 XML External Entity Injection Vulnerability
2017-05-20
http://www.securityfocus.com/bid/98590

Linux Kernel 'net/core/sock.c' Multiple Local Memory Corruption Vulnerabilities
2017-05-19
http://www.securityfocus.com/bid/94655

Linux Kernel CVE-2017-6348 Local Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/96483

OpenSSL CVE-2015-1790 Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/75157

Linux Kernel 'net/x25/x25_facilities.c' Local Information Disclosure Vulnerability
2017-05-19
http://www.securityfocus.com/bid/90528

SSL/TLS RC4 CVE-2013-2566 Information Disclosure Weakness
2017-05-19
http://www.securityfocus.com/bid/58796

OpenSSL CVE-2015-1791 Race Condition Security Vulnerability
2017-05-19
http://www.securityfocus.com/bid/75161

Linux kernel 'ip_sockglue.c' Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/96233

Oracle MySQL Connectors CVE-2017-3586 Remote Security Vulnerability
2017-05-19
http://www.securityfocus.com/bid/97784

Oracle MySQL Connectors CVE-2017-3589 Local Security Vulnerability
2017-05-19
http://www.securityfocus.com/bid/97836

SANS News

Investigating Sites After They are Gone; And a Case of Uber Phishing With SSL

What did we Learn from WannaCry? - Oh Wait, We Already Knew That!

Threatpost

Jaya Baloo on WannaCry and Defending Against Advanced Attacks

Verizon Patches XSS Issues in its Messaging Client

Trump’s Cybersecurity Boss Talks Priorities

Exploit

Apple macOS - '32-bit syscall exit' Kernel Register Leak

Apple macOS - 'stackshot' Raw Frame Pointers

Linux Kernel 4.11 - eBPF Verifier Log Leaks Lower Half of map Pointer

Sure Thing Disc Labeler 6.2.138.0 - Buffer Overflow (PoC)

VMware Workstation for Linux 12.5.2 build-4638234 - ALSA Config Host Root Privilege...

22.5.2017

Bugtraq

CVE-2017-9024 Secure Auditor - v3.0 Directory Traversal 2017-05-22
apparitionsec gmail com (hyp3rlinx)

CVE-2017-9046 Pegasus "winpm-32.exe" v4.72 Mailto: Link Remote Code Execution 2017-05-22
apparitionsec gmail com (hyp3rlinx)

CVE-2017-9046 Mantis Bug Tracker 1.3.10 / v2.3.0 CSRF Permalink Injection 2017-05-22
apparitionsec gmail com (hyp3rlinx)

May 2017 - SourceTree - Critical Security Advisory 2017-05-22
Atlassian (security atlassian com)

CVE-2017-9024 Secure Auditor - v3.0 Directory Traversal 2017-05-20
apparitionsec gmail com (hyp3rlinx)

[SECURITY] [DSA 3858-1] openjdk-7 security update 2017-05-19
Moritz Muehlenhoff (jmm debian org)

[SECURITY] CVE-2017-5657: Apache Archiva CSRF vulnerability for REST endpoints 2017-05-19
Martin (martin_s apache org)

Malware

 

Phishing

 

Vulnerebility

2015-5241
2017-4978
2017-4979
2017-7475
2017-7504
2017-7968
2017-9077
2017-9078
2017-9079
2017-9080
2017-9083
2017-9090
2017-9091
2017-9093
2017-9094
2017-9098
2017-0619
2017-5173
2017-5174
2017-5176
2017-5177
2017-6016
2017-6025
2017-6027
2017-6250
2017-7240
2017-7907
2017-8358
2017-9076

SANS News

 

Threatpost

 

Exploit

Secure Auditor 3.0 - Directory Traversal

KMCIS CaseAware - Cross-Site Scripting

Mantis Bug Tracker 1.3.10/2.3.0 - Cross-Site Request Forgery

Sure Thing Disc Labeler 6.2.138.0 - Buffer Overflow (PoC)

PlaySMs 1.4 - 'import.php' Remote Code Execution

21.5.2017

Bugtraq

[SECURITY] [DSA 3853-1] bitlbee security update 2017-05-15
Sebastien Delafond (seb untangle com)

Secunia Research: LibRaw "parse_tiff_ifd()" Memory Corruption Vulnerability 2017-05-15
Secunia Research (remove-vuln secunia com)

PingID (MFA) - Reflected Cross-Site Scripting 2017-05-17
Advisories (advisories compass-security com)

[slackware-security] kdelibs (SSA:2017-136-02) 2017-05-16
Slackware Security Team (security slackware com)

[security bulletin] HPESBGN03748 rev.1 - HPE Cloud Optimizer, Remote Disclosure of Information 2017-05-18
security-alert hpe com

[SECURITY] [DSA 3856-1] deluge security update 2017-05-18
Moritz Muehlenhoff (jmm debian org)

Malware

 

Phishing

 

Vulnerebility

Linux Kernel 'net/core/sock.c' Multiple Local Memory Corruption Vulnerabilities
2017-05-19
http://www.securityfocus.com/bid/94655

Linux Kernel CVE-2017-6348 Local Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/96483

OpenSSL CVE-2015-1790 Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/75157

Linux Kernel 'net/x25/x25_facilities.c' Local Information Disclosure Vulnerability
2017-05-19
http://www.securityfocus.com/bid/90528

SSL/TLS RC4 CVE-2013-2566 Information Disclosure Weakness
2017-05-19
http://www.securityfocus.com/bid/58796

OpenSSL CVE-2015-1791 Race Condition Security Vulnerability
2017-05-19
http://www.securityfocus.com/bid/75161

Linux kernel 'ip_sockglue.c' Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/96233

Oracle MySQL Connectors CVE-2017-3586 Remote Security Vulnerability
2017-05-19
http://www.securityfocus.com/bid/97784

Oracle MySQL Connectors CVE-2017-3589 Local Security Vulnerability
2017-05-19
http://www.securityfocus.com/bid/97836

Deluge CVE-2017-7178 Cross Site Request Forgery Vulnerability
2017-05-19
http://www.securityfocus.com/bid/97041

Oracle PeopleSoft Enterprise PeopleTools CVE-2017-3548 Remote Security Vulnerability
2017-05-19
http://www.securityfocus.com/bid/97880

Cisco Aironet Access Points CVE-2017-3873 Arbitrary Code Execution Vulnerability
2017-05-19
http://www.securityfocus.com/bid/98296

JasPer 'jpc_pi_nextcprl()' Function Local Integer Overflow Vulnerability
2017-05-19
http://www.securityfocus.com/bid/97584

JasPer CVE-2016-9591 Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/94952

JasPer 'jpc_dec.c' Null Pointer Dereference Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/95864

Jasper 'jpc_tsfb.c' Stack Buffer Overflow Vulnerability
2017-05-19
http://www.securityfocus.com/bid/94428

JasPer CVE-2016-8654 Multiple Remote Heap Buffer Overflow Vulnerabilities
2017-05-19
http://www.securityfocus.com/bid/94583

JasPer 'jpc_dec.c' Remote Heap Buffer Overflow Vulnerability
2017-05-19
http://www.securityfocus.com/bid/93838

JasPer CVE-2016-8691 Divide By Zero Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/93593

JasPer CVE-2016-8692 Divide By Zero Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/93588

JasPer CVE-2016-8693 Double Free Remote Code Execution Vulnerability
2017-05-19
http://www.securityfocus.com/bid/93587

JasPer CVE-2016-1867 Out of Bound Read Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/81488

JasPer 'jas_seq.c' Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/83108

Microsoft Windows SMB Server CVE-2017-0144 Remote Code Execution Vulnerability
2017-05-19
http://www.securityfocus.com/bid/96704

Google Android Qualcomm Components CVE-2014-9925 Unspecified Security Vulnerabilities
2017-05-19
http://www.securityfocus.com/bid/98227

RedHat JBoss Enterprise Application Platform XML External Entity Injection Vulnerability
2017-05-19
http://www.securityfocus.com/bid/98450

WordPress Prior to 4.7.5 Multiple Security Vulnerabilities
2017-05-19
http://www.securityfocus.com/bid/98509

IBM Development Package for Apache Spark CVE-2016-4970 Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/96540

infinispan CVE-2017-2638 Authentication Bypass Vulnerability
2017-05-19
http://www.securityfocus.com/bid/97964

ISC BIND CVE-2016-2775 Remote Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/92037

SANS News

Typosquatting: Awareness and Hunting

Threatpost

Available Tools Making Dent in WannaCry Encryption

Terror Exploit Kit Evolves Into Larger Threat

Exploit

Joomla 3.7.0 - 'com_fields' SQL Injection

Oracle PeopleSoft - Server-Side Request Forgery

Belden Garrettcom 6K/10K Switches - Authentication Bypass / Memory Corruption

SAP Business One for Android 1.2.3 - XML External Entity Injection

ManageEngine ServiceDesk Plus 9.0 - Authentication Bypass

PlaySMS 1.4 - Remote Code Execution

D-Link DIR-600M Wireless N 150 - Authentication Bypass

19.5.2017

Bugtraq

[security bulletin] HPESBGN03748 rev.1 - HPE Cloud Optimizer, Remote Disclosure of Information 2017-05-18
security-alert hpe com

[SECURITY] [DSA 3856-1] deluge security update 2017-05-18
Moritz Muehlenhoff (jmm debian org)

Nextcloud/Owncloud - Reflected Cross Site Scripting in error pages 2017-05-15
Manuel Mancera (sinkmanu gmail com)

APPLE-SA-2017-05-15-6 iTunes 12.6.1 2017-05-15
Apple Product Security (product-security-noreply lists apple com)

APPLE-SA-2017-05-15-4 watchOS 3.2.1 2017-05-15
Apple Product Security (product-security-noreply lists apple com)

Malware

Ransom:Win32/WannaCrypt

Trojan:Win32/Adylkuzz.B

Phishing

 

Vulnerebility

Google Android Qualcomm Components CVE-2014-9925 Unspecified Security Vulnerabilities
2017-05-19
http://www.securityfocus.com/bid/98227

RedHat JBoss Enterprise Application Platform XML External Entity Injection Vulnerability
2017-05-19
http://www.securityfocus.com/bid/98450

WordPress Prior to 4.7.5 Multiple Security Vulnerabilities
2017-05-19
http://www.securityfocus.com/bid/98509

IBM Development Package for Apache Spark CVE-2016-4970 Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/96540

infinispan CVE-2017-2638 Authentication Bypass Vulnerability
2017-05-19
http://www.securityfocus.com/bid/97964

ISC BIND CVE-2016-2775 Remote Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/92037

ISC BIND CVE-2016-6170 Remote Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/91611

Miele Professional PG85 Series CVE-2017-7240 Directory Traversal Vulnerability
2017-05-19
http://www.securityfocus.com/bid/97080

Apple iOS APPLE-SA-2017-05-15-2 Security Bypass and Denial of Service Vulnerabilities
2017-05-19
http://www.securityfocus.com/bid/98479

Linux kernel CVE-2017-7308 Local Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/97234

Linux Kernel CVE-2017-7294 Local Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/97177

ISC BIND CVE-2017-3136 Remote Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/97653

ISC BIND CVE-2017-3137 Remote Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/97651

ICU CVE-2017-7868 Multiple Heap Buffer Overflow Vulnerabilities
2017-05-19
http://www.securityfocus.com/bid/97674

ICU CVE-2017-7867 Multiple Heap Buffer Overflow Vulnerabilities
2017-05-19
http://www.securityfocus.com/bid/97672

Linux Kernel CVE-2017-2636 Local Privilege Escalation Vulnerability
2017-05-19
http://www.securityfocus.com/bid/96732

LibreOffice CVE-2017-3157 Local Information Disclosure Vulnerability
2017-05-19
http://www.securityfocus.com/bid/96402

PostgreSQL CVE-2016-5423 NULL Pointer Dereference Remote Code Execution Vulnerability
2017-05-19
http://www.securityfocus.com/bid/92433

PostgreSQL CVE-2016-5424 Multiple Local Privilege Escalation Vulnerabilities
2017-05-19
http://www.securityfocus.com/bid/92435

QEMU CVE-2016-9603 Heap Buffer Overflow Vulnerability
2017-05-19
http://www.securityfocus.com/bid/96893

Linux Kernel CVE-2016-8645 Local Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/94264

ISC BIND CVE-2017-3138 Remote Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/97657

Squirrelmail CVE-2017-7692 Command Injection Vulnerability
2017-05-19
http://www.securityfocus.com/bid/98067

Git CVE-2017-8386 Security Bypass Vulnerability
2017-05-19
http://www.securityfocus.com/bid/98409

PostgreSQL CVE-2017-7484 Information Disclosure Vulnerability
2017-05-19
http://www.securityfocus.com/bid/98459

PostgreSQL CVE-2017-7486 Information Disclosure Vulnerability
2017-05-19
http://www.securityfocus.com/bid/98460

PostgreSQL CVE-2017-7485 Man in the Middle Security Bypass Vulnerability
2017-05-19
http://www.securityfocus.com/bid/98461

RTMPDump NULL pointer Dereference Remote Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/95123

RTMPDump NULL pointer Dereference CVE-2015-8270 Remote Denial of Service Vulnerability
2017-05-19
http://www.securityfocus.com/bid/95126

RTMPDump CVE-2015-8271 Remote Code Execution Vulnerability
2017-05-19
http://www.securityfocus.com/bid/95125

SANS News

 

Threatpost

WordPress Fixes CSRF, XSS Bugs, Announces Bug Bounty Program

PATCH Act Calls for VEP Review Board

Exploit

Microsoft Windows Windows 8/2012 R2 (x64) - 'EternalBlue' SMB Remote Code Execution...

Microsoft Windows Windows 7/2008 R2 (x64) - 'EternalBlue' SMB Remote Code Execution...

Joomla 3.7.0 - 'com_fields' SQL Injection

18.5.2017

Bugtraq

Nextcloud/Owncloud - Reflected Cross Site Scripting in error pages 2017-05-15
Manuel Mancera (sinkmanu gmail com)

APPLE-SA-2017-05-15-6 iTunes 12.6.1 2017-05-15
Apple Product Security (product-security-noreply lists apple com)

APPLE-SA-2017-05-15-4 watchOS 3.2.1 2017-05-15
Apple Product Security (product-security-noreply lists apple com)

[security bulletin] HPESBHF03745 rev.1 - HPE Intelligent Management Center (iMC) PLAT, Remote Code Execution 2017-05-14
security-alert hpe com

Secunia Research: FLAC "read_metadata_vorbiscomment_()" Memory Leak Denial of Service Vulnerability 2017-05-15
Secunia Research (remove-vuln secunia com)

DefenseCode ThunderScan SAST Advisory: GOOGLE google-api-php-client Multiple Security Vulnerabilities 2017-05-11
DefenseCode (defensecode defensecode com)

SEC Consult SA-20170511-0 :: Stack-based buffer overflow vulnerability in Guidance Software EnCase Forensic Imager 2017-05-11
SEC Consult Vulnerability Lab (research sec-consult com)

DefenseCode WebScanner DAST Advisory: WordPress User Access Manager Plugin Security Vulnerability 2017-05-11
DefenseCode (defensecode defensecode com)

DefenseCode ThunderScan SAST Advisory: WordPress Tracking Code Manager Plugin Multiple Security Vulnerabilities 2017-05-11
DefenseCode (defensecode defensecode com)

Malware

Trojan.Adylkuzz

Hacktool.Seasharpee

MonitoringTool:Win32/MicTrayDebugger

Ransom:Win32/Uiwix.A!rsm

Phishing

Bradley Groholski

17th May 2017

MICROSORT UPDATE

Chase

17th May 2017

CHASE ONLINE CONFIRMATION
ALERT

spoof

15th May 2017

Thank you!

USAA Online

15th May 2017

Important Information

Vulnerebility

2011-0540
2012-1619
2012-3545
2013-4360
2014-9931
2014-9932
2014-9933
2014-9934
2014-9935
2014-9936
2014-9937
2015-8995
2015-8996
2015-8997
2015-8998
2015-8999
2015-9000
2015-9001
2015-9002
2015-9003
2016-10237
2016-10238
2016-10239
2016-10242
2016-10372
2017-3825
2017-3873
2017-3876
2017-3882
2017-6079
2017-6651
2017-6657
2017-6658
2017-6885
2017-6886
2017-6887
2017-7488
2017-7661
2017-7662

2016-8741 
2017-0620 
2017-8852 

SANS News

My Little CVE Bot

Threatpost

APT3 Linked to Chinese Ministry of State Security

Exploit

Microsoft Windows - COM Aggregate Marshaler/IRemUnknown2 Type Confusion Privilege...

Windows x32 / Windows x64 - cmd.exe Shellcode (718 bytes)

Apple iOS < 10.3.2 - Notifications API Denial of Service

Microsoft Windows - Running Object Table Register ROTFLAGS_ALLOWANYCLIENT Privilege...

Mozilla Firefox 50 - 55 - Stack Overflow Denial of Service

INFOR EAM 11.0 Build 201410 - 'filtervalue' SQL Injection

INFOR EAM 11.0 Build 201410 - Persistent Cross-Site Scripting via Comment Fields

Oracle PeopleSoft - XML External Entity to SYSTEM Remote Code Execution

BuilderEngine 3.5.0 - Arbitrary File Upload and Execution (Metasploit)

WordPress PHPMailer 4.6 - Host Header Command Injection (Metasploit)

Serviio Media Server - checkStreamUrl Command Execution (Metasploit)

Dup Scout Enterprise 9.5.14 - GET Buffer Overflow (Metasploit)

17.5.2017

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

 

SANS News

 

Threatpost

Chrome Browser Hack Opens Door to Credential Theft

WannaCry Shares Code with Lazarus APT Samples

Apple Patches Pwn2Own Vulnerabilities in Safari, macOS, iOS

DocuSign Phishing Campaign Includes Hancitor Downloader

Exploit

 

16.5.2017

Bugtraq

 

Malware

Ransom:Win32/WannaCrypt 

Phishing

spoof

15th May 2017

Thank you!

USAA Online

15th May 2017

Important Information

Vulnerebility

2015-6542
2016-10274
2016-10275
2016-10276
2016-10277
2016-10280
2016-10281
2016-10282
2016-10283
2016-10284
2016-10285
2016-10286
2016-10287
2016-10288
2016-10289
2016-10290
2016-10291
2016-10292
2016-10293
2016-10294
2016-10295
2016-10296
2016-10329
2016-10330
2016-10331
2016-4838
2016-4839
2016-4855
2016-4856
2016-4857
2016-4858
2016-4859
2016-4864
2016-4876
2016-4877
2016-4878
2016-4879
2016-4880
2016-4881
2016-4882
2016-4883
2016-4884
2016-4885
2016-4886
2016-4887
2017-0064
2017-0077
2017-0171
2017-0175
2017-0190
2017-0212
2017-0213
2017-0214
2017-0220
2017-0221
2017-0222
2017-0224
2017-0226
2017-0227
2017-0228
2017-0229
2017-0230
2017-0231
2017-0233
2017-0234
2017-0235
2017-0236
2017-0238
2017-0240
2017-0241
2017-0242
2017-0244
2017-0245
2017-0246
2017-0247
2017-0248
2017-0249
2017-0254
2017-0255
2017-0256
2017-0258
2017-0259
2017-0261
2017-0262
2017-0263
2017-0264
2017-0265
2017-0266
2017-0267
2017-0268
2017-0269
2017-0270
2017-0271
2017-0272
2017-0273
2017-0274
2017-0275
2017-0276
2017-0277
2017-0278
2017-0279
2017-0280
2017-0281
2017-0465
2017-0493
2017-0587
2017-0588
2017-0589
2017-0590
2017-0591
2017-0592
2017-0593
2017-0594
2017-0595
2017-0596
2017-0597
2017-0598
2017-0599
2017-0600
2017-0601
2017-0602
2017-0603
2017-0604
2017-0605
2017-0606
2017-0607
2017-0608
2017-0609
2017-0610
2017-0611
2017-0612
2017-0613
2017-0614
2017-0615
2017-0616
2017-0617
2017-0618
2017-0619
2017-0620
2017-0621
2017-0622
2017-0623
2017-0624
2017-0625
2017-0626
2017-0627
2017-0628
2017-0629
2017-0630
2017-0631
2017-0632
2017-0633
2017-0634
2017-0635
2017-2122
2017-2157
2017-2163
2017-2164
2017-2167
2017-5654
2017-7474
2017-7484
2017-7485
2017-7486
2017-8244
2017-8245
2017-8246
2017-8921
2017-8923
2017-8924
2017-8925

2016-4875
2016-4888
2016-4889
2016-4890
2016-7476
2017-0290

SANS News

WannaCry? Do your own data analysis.

Threatpost

OpenVPN Audits Yield Mixed Bag

WikiLeaks Reveals Two CIA Malware Frameworks

ShadowBrokers Planning Monthly Exploit, Data Dump Service

Exploit

Microsoft Windows 7 Kernel - Uninitialized Memory in the Default dacl Descriptor of...

Microsoft Windows 10 Kernel - nt!NtTraceControl (EtwpSetProviderTraits) Pool Memory...

Microsoft Windows 7 Kernel - 'win32k!xxxClientLpkDrawTextEx' Stack Memory Disclosure

Microsoft Windows 7 Kernel - Pool-Based Out-of-Bounds Reads Due to bind()...

Quest Privilege Manager - pmmasterd Buffer Overflow (Metasploit)

Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple...

Sophos Web Appliance 4.3.1.1 - Session Fixation

Quest Privilege Manager - pmmasterd Buffer Overflow (Metasploit)

15.5.2017

Bugtraq

 

Malware

Ransom:Win32/WannaCrypt

Phishing

 

Vulnerebility

2017-7213
2017-7487
2017-8928
2017-8929
2017-8930

SANS News

WannaCry/WannaCrypt Ransomware Summary

Threatpost

Matthew Hickey on WannaCry Ransomware Outbreak

Exploit

PlaySms 1.4 - Remote Code Execution

Mailcow 0.14 - Cross-Site Request Forgery

Halliburton LogView Pro 10.0.1 - Local Buffer Overflow (SEH)

Larson VizEx Reader 9.7.5 - Local Buffer Overflow (SEH)

14.5.2017

Bugtraq

 

Malware

Ransom:Win32/WannaCrypt
Trojan:Win32/Mulrolu.A!cl
Program:Win32/Vigram.A

Phishing

 

Vulnerebility

 

SANS News

Massive wave of ransomware ongoing

Microsoft Released Guidance for WannaCrypt

Threatpost

New Jaff Ransomware Part Of Active Necurs Spam Blitz

Exploit

Vanilla Forums < 2.3 - Remote Code Execution

CMS Made Simple 2.1.6 - Multiple Vulnerabilities

Linux Kernel 3.x (Ubuntu 14.04 / Mint 17.3 / Fedora 22) - Double-free usb-midi SMEP...

Linux Kernel 3.11 < 4.8 0 - 'SO_SNDBUFFORCE' & 'SO_RCVBUFFORCE' Local Privilege...

12.5.2017

Bugtraq

 

Malware

Exp.CVE-2017-0262

Trojan.Boyapki

Trojan.Halabake

Phishing

 

Vulnerebility

 

SANS News

When Bad Guys are Pwning Bad Guys...

Threatpost

Microsoft’s New Security Update Guides Get Mixed Reviews

Vanilla Forums Open Source Software Vulnerable to RCE, Host Header Injection Vulnerability


Trump Signs Cybersecurity Executive Order

Anti Public Combo List Analysis Reveals Password Habits Improving

Exploit

Linux Kernel 4.8.0 (Ubuntu) - Packet Socket Local Privilege Escalation

OpenVPN 2.4.0 - Unauthenticated Denial of Service

Vanilla Forums < 2.3 - Remote Code Execution

Microsoft IIS - WebDav 'ScStoragePathFromUrl' Overflow (Metasploit)

CMS Made Simple 2.1.6 - Multiple Vulnerabilities

Linux Kernel 3.11 < 4.8 0 - 'SO_SNDBUFFORCE' & 'SO_RCVBUFFORCE' Local Privilege...

Linux Kernel 4.8.0 (Ubuntu) - Packet Socket Local Privilege Escalation

OpenVPN 2.4.0 - Unauthenticated Denial of Service

11.5.2017

Bugtraq

 

Malware

 

Phishing

 

Vulnerebility

Cisco WebEx Meetings Server CVE-2017-6651 Information Disclosure Vulnerability
2017-05-11
http://www.securityfocus.com/bid/98387

Red Hat JBoss BRMS and BPM Suite CVE-2017-7463 Cross Site Scripting Vulnerability
2017-05-11
http://www.securityfocus.com/bid/98385

ImageMagick CVE-2017-8356 Denial of Service Vulnerability
2017-05-11
http://www.securityfocus.com/bid/98378

Veritas Backup Exec Use After Free Remote Code Execution Vulnerability
2017-05-11
http://www.securityfocus.com/bid/98386

Fortinet Fortiweb CVE-2017-3129 Cross Site Scripting Vulnerability
2017-05-11
http://www.securityfocus.com/bid/98382

Veritas NetBackup and NetBackup Appliance Arbitrary Command Execution Vulnerability
2017-05-11
http://www.securityfocus.com/bid/98384

ImageMagick CVE-2017-8355 Denial of Service Vulnerability
2017-05-11
http://www.securityfocus.com/bid/98380

Google Android Mediaserver CVE-2017-0599 Denial Of Service Vulnerability
2017-05-11
http://www.securityfocus.com/bid/98134

ImageMagick CVE-2017-8352 Denial of Service Vulnerability
2017-05-11
http://www.securityfocus.com/bid/98372

ImageMagick CVE-2017-8354 Denial of Service Vulnerability
2017-05-11
http://www.securityfocus.com/bid/98374

Veritas NetBackup and NetBackup Appliance Arbitrary Command Execution Vulnerability
2017-05-11
http://www.securityfocus.com/bid/98379

Veritas NetBackup Appliance CVE-2017-8859 Arbitrary Command Execution Vulnerability
2017-05-11
http://www.securityfocus.com/bid/98383

OpenSSL 'ssl/s3_srvr.c' Denial of Service Vulnerability
2017-05-11
http://www.securityfocus.com/bid/73238

Veritas NetBackup and NetBackup Appliance CVE-2017-8858 Arbitrary File Write Vulnerability
2017-05-11
http://www.securityfocus.com/bid/98381

OpenSSL CVE-2015-0293 Denial of Service Vulnerability
2017-05-11
http://www.securityfocus.com/bid/73232

OpenSSL '/evp/encode.c' Remote Memory Corruption Vulnerability
2017-05-11
http://www.securityfocus.com/bid/73228

OpenSSL CVE-2015-0290 Denial of Service Vulnerability
2017-05-11
http://www.securityfocus.com/bid/73226

OpenSSL CVE-2015-0291 Denial of Service Vulnerability
2017-05-11
http://www.securityfocus.com/bid/73235

OpenSSL CVE-2015-0288 Denial of Service Vulnerability
2017-05-11
http://www.securityfocus.com/bid/73237

OpenSSL 'pk7_doit.c' NULL Pointer Dereference Denial of Service Vulnerability
2017-05-11
http://www.securityfocus.com/bid/73231

OpenSSL 'tasn_dec.c' Remote Memory Corruption Vulnerability
2017-05-11
http://www.securityfocus.com/bid/73227

OpenSSL CVE-2015-0285 Insufficient Entropy Security Weakness
2017-05-11
http://www.securityfocus.com/bid/73234

Trend Micro Threat Discovery Appliance CVE-2016-8586 Command Injection Vulnerability
2017-05-11
http://www.securityfocus.com/bid/98376

OpenSSL CVE-2015-0209 Remote Memory Corruption Vulnerability
2017-05-11
http://www.securityfocus.com/bid/73239

OpenSSL CVE-2015-0207 Denial of Service Vulnerability
2017-05-11
http://www.securityfocus.com/bid/73229

Cisco IOS and IOS XE Software CVE-2015-0646 Denial of Service Vulnerability
2017-05-11
http://www.securityfocus.com/bid/73340

Cisco IOS and IOS XE Software 'IKEv2' Module Multiple Denial of Service Vulnerabilities
2017-05-11
http://www.securityfocus.com/bid/73333

NTP CVE-2015-1799 Denial of Service Vulnerability
2017-05-11
http://www.securityfocus.com/bid/73950

Network Time Protocol CVE-2015-7871 Authentication Bypass Vulnerability
2017-05-11
http://www.securityfocus.com/bid/77287

NTP CVE-2015-1798 Man in the Middle Security Bypass Vulnerability
2017-05-11
http://www.securityfocus.com/bid/73951

SANS News

Seamless Campaign using Rig Exploit Kit to send Ramnit Trojan

Threatpost

Cisco Patches IOS XE Vulnerability Leaked in Vault 7 Dump

Microsoft Makes it Official, Cuts off SHA-1 Support in IE, Edge

Android Permissions Flaw Will Linger Until O Release

Session Hijacking, Cookie-Stealing WordPress Malware Spotted

Exploit

Microsoft Windows - SrvOs2FeaToNt SMB Remote Code Execution (MS17-010)

Microsoft IIS WebDav - ScStoragePathFromUrl Overflow (Metasploit)

QNAP PhotoStation 5.2.4 / MusicStation 4.8.4 - Authentication Bypass

BanManager WebUI 1.5.8 - PHP Code Injection

Gongwalker API Manager 1.1 - Cross-Site Request Forgery

SAP SAPCAR 721.510 - Heap-Based Buffer Overflow

10.5.2017

Bugtraq

 

Malware

 

Phishing

Microsoft

9th May 2017

Security Alert.

spoof

9th May 2017

Dude. This acid.

NatWest Bank

7th May 2017

Important Message

Vulnerebility

Microsoft Malware Protection Engine CVE-2017-0290 Remote Code Execution Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98330

Microsoft Windows Graphics Device Interface CVE-2017-0190 Information Disclosure Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98298

SAP NetWeaver Denial of Service Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98362

Microsoft Office CVE-2017-0281 Remote Code Execution Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98297

Microsoft Edge CVE-2017-0227 Remote Memory Corruption Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98281

Microsoft Edge CVE-2017-0266 Remote Code Execution Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98276

Microsoft Windows CVE-2017-0242 ActiveX Control Local Information Disclosure Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98275

Microsoft Windows SMB Server CVE-2017-0279 Remote Code Execution Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98272

Microsoft Windows SMB Server CVE-2017-0273 Remote Denial of Service Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98274

Microsoft Windows SMB Server CVE-2017-0277 Remote Code Execution Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98270

Microsoft Windows SMB Server CVE-2017-0278 Remote Code Execution Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98271

Microsoft Windows SMB Server CVE-2017-0276 Information Disclosure Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98268

Microsoft Windows SMB Server CVE-2017-0275 Information Disclosure Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98267

Microsoft Windows SMB Server CVE-2017-0271 Information Disclosure Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98265

Microsoft Windows SMB Server CVE-2017-0274 Information Disclosure Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98266

Microsoft Windows SMB Server CVE-2017-0270 Information Disclosure Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98264

Microsoft Edge and Internet Explorer CVE-2017-0238 Remote Memory Corruption Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98237

Microsoft Edge CVE-2017-0235 Remote Memory Corruption Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98230

Microsoft Edge CVE-2017-0236 Remote Memory Corruption Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98234

Microsoft Edge CVE-2017-0230 Remote Memory Corruption Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98222

Microsoft Edge CVE-2017-0234 Remote Memory Corruption Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98229

Microsoft Edge CVE-2017-0224 Remote Memory Corruption Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98214

Microsoft Edge CVE-2017-0229 Remote Memory Corruption Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98217

Microsoft Edge CVE-2017-0241 Remote Privilege Escalation Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98208

Microsoft Edge CVE-2017-0240 Remote Memory Corruption Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98203

Microsoft Edge CVE-2017-0233 Remote Privilege Escalation Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98179

Microsoft DirectX Graphics Kernel CVE-2017-0077 Local Privilege Escalation Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98114

Microsoft Internet Explorer and Edge CVE-2017-0228 Remote Memory Corruption Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98164

Microsoft Internet Explorer and Edge CVE-2017-0231 Spoofing Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98173

Microsoft Internet Explorer CVE-2017-0226 Remote Memory Corruption Vulnerability
2017-05-10
http://www.securityfocus.com/bid/98139

SANS News

OAuth, and It's High Time for Some Personal "Security-Scaping" Today

Threatpost

Hikvision Patches Backdoor in IP Cameras

Adobe Patches Seven Critical Vulnerabilities in Flash, AEM


Google’s OSS-Fuzz Finds 1,000 Open Source Bugs


Microsoft Plugs Three Zero Day Holes as Part of May Patch Tuesday

Exploit

Microsoft Windows 8 / 8.1 / 10 / Windows Server / SCEP, Microsoft Security...

Oracle GoldenGate 12.1.2.0.0 - Unauthenticated Remote Code Execution

Crypttech CryptoLog - Remote Code Execution (Metasploit)

LogRhythm Network Monitor - Authentication Bypass / Command Injection

I, Librarian 4.6 / 4.7 - Command Injection / Server Side Request Forgery /...

LG G4 MRA58K - 'liblg_parser_mkv.so' Bad Allocation Calls

LG G4 MRA58K - 'mkvparser::Tracks constructor' Failure to Initialise Pointers

LG G4 MRA58K - 'mkvparser::Block::Block' Heap Buffer Overflows

wolfSSL 3.10.2 - x509 Certificate Text Parsing Off-by-One

9.5.2017

Bugtraq

SEC Consult SA-20170509-0 :: Multiple vulnerabilities in I, Librarian PDF manager 2017-05-09
SEC Consult Vulnerability Lab (research sec-consult com)

[SECURITY] [DSA 3846-1] libytnef security update 2017-05-09
Sebastien Delafond (seb debian org)

[SECURITY] [DSA 3845-1] libtirpc security update 2017-05-08
Moritz Muehlenhoff (jmm debian org)

ESA-2017-035: EMC Mainframe Enablers ResourcePak Base privilege management vulnerability 2017-05-08
EMC Product Security Response Center (Security_Alert emc com)

CA20170504-01: Security Notice for CA Client Automation OS Installation Management 2017-05-05
Kotas, Kevin J (Kevin Kotas ca com)

Malware

Trojan.Reblight

Phishing

spoof

9th May 2017

Dude. This acid.

Vulnerebility

Citrix XenMobile Server CVE-2016-6877 Host Header Injection Vulnerability
2017-05-20
http://www.securityfocus.com/bid/98341

IBM WebSphere Portal CVE-2017-1156 Unspecified Open Redirection Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98340

Google Android Qualcomm Secure Channel Manager Driver Privilege Escalation Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98193

Microsoft Malware Protection Engine CVE-2017-0290 Remote Code Execution Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98330

GNU glibc CVE-2017-8804 Remote Denial of Service Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98339

Trend Micro OfficeScan Multiple Privilege Escalation and Cross Site Scripting Vulnerabilities
2017-05-09
http://www.securityfocus.com/bid/98007

IBM Tivoli Storage Manager CVE-2016-8916 Local Information Disclosure Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98335

IBM WebSphere Cast Iron Solution CVE-2016-9692 Denial of Service Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98337

IBM Marketing Platform CVE-2016-0255 Unspecified HTML Injection Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98336

ISC BIND CVE-2017-3139 Remote Denial of Service Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98334

Trend Micro Threat Discovery Appliance CVE-2016-8584 Authentication Bypass Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98333

Google Android Mediatek Power Driver CVE-2017-0615 Privilege Escalation Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98188

HP Network Automation Multiple Unspecified Security Vulnerabilities
2017-05-09
http://www.securityfocus.com/bid/98331

Google Android Qualcomm Sound Codec Driver CVE-2016-5862 Privilege Escalation Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98194

Google Android Qualcomm Sound Driver CVE-2016-5347 Information Disclosure Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98218

Google Chrome Prior to 57.0.2987.98 Multiple Security Vulnerabilities
2017-05-09
http://www.securityfocus.com/bid/96767

Google ANGLE CVE-2017-5031 Use After Free Denial of Service Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98326

HP StoreFabric B-series Switches CVE-2016-8202 Remote Privilege Escalation Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98332

Google Android Qualcomm Video Driver CVE-2016-10293 Information Disclosure Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98206

Atlassian SourceTree CVE-2017-8768 Command Injection Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98329

Citrix XenServer Multiple Security Vulnerabilities
2017-05-09
http://www.securityfocus.com/bid/98328

Panda Mobile Security for iOS CVE-2017-8060 TLS Certificate Validation Security Bypass Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98327

Google Android Goodix Touchscreen Driver CVE-2017-0622 Privilege Escalation Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98198

Google Android Qualcomm Crypto Engine Driver CVE-2017-0626 Information Disclosure Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98202

Microsoft Windows SMB Server CVE-2017-0146 Remote Code Execution Vulnerability
2017-05-09
http://www.securityfocus.com/bid/96707

Microsoft Windows SMB Server CVE-2017-0145 Remote Code Execution Vulnerability
2017-05-09
http://www.securityfocus.com/bid/96705

Microsoft Windows SMB Server CVE-2017-0143 Remote Code Execution Vulnerability
2017-05-09
http://www.securityfocus.com/bid/96703

Microsoft Windows SMB Server CVE-2017-0144 Remote Code Execution Vulnerability
2017-05-09
http://www.securityfocus.com/bid/96704

Microsoft Windows SMB Server CVE-2017-0147 Information Disclosure Vulnerability
2017-05-09
http://www.securityfocus.com/bid/96709

Oracle Java SE and JRockit CVE-2017-3533 Remote Security Vulnerability
2017-05-09
http://www.securityfocus.com/bid/97740Trend Micro OfficeScan Multiple Privilege Escalation and Cross Site Scripting Vulnerabilities
2017-05-09
http://www.securityfocus.com/bid/98007

IBM Tivoli Storage Manager CVE-2016-8916 Local Information Disclosure Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98335

IBM WebSphere Cast Iron Solution CVE-2016-9692 Denial of Service Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98337

IBM Marketing Platform CVE-2016-0255 Unspecified HTML Injection Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98336

ISC BIND CVE-2017-3139 Remote Denial of Service Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98334

Trend Micro Threat Discovery Appliance CVE-2016-8584 Authentication Bypass Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98333

Google Android Mediatek Power Driver CVE-2017-0615 Privilege Escalation Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98188

HP Network Automation Multiple Unspecified Security Vulnerabilities
2017-05-09
http://www.securityfocus.com/bid/98331

Google Android Qualcomm Sound Codec Driver CVE-2016-5862 Privilege Escalation Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98194

Google Android Qualcomm Sound Driver CVE-2016-5347 Information Disclosure Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98218

Microsoft Windows Unspecified Remote Code Execution Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98330

Google Chrome Prior to 57.0.2987.98 Multiple Security Vulnerabilities
2017-05-09
http://www.securityfocus.com/bid/96767

Google ANGLE CVE-2017-5031 Use After Free Denial of Service Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98326

HP StoreFabric B-series Switches CVE-2016-8202 Remote Privilege Escalation Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98332

Google Android Qualcomm Video Driver CVE-2016-10293 Information Disclosure Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98206

Atlassian SourceTree CVE-2017-8768 Command Injection Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98329

Citrix XenServer Multiple Security Vulnerabilities
2017-05-09
http://www.securityfocus.com/bid/98328

Panda Mobile Security for iOS CVE-2017-8060 TLS Certificate Validation Security Bypass Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98327

Google Android Goodix Touchscreen Driver CVE-2017-0622 Privilege Escalation Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98198

Google Android Qualcomm Crypto Engine Driver CVE-2017-0626 Information Disclosure Vulnerability
2017-05-09
http://www.securityfocus.com/bid/98202

Microsoft Windows SMB Server CVE-2017-0146 Remote Code Execution Vulnerability
2017-05-09
http://www.securityfocus.com/bid/96707

Microsoft Windows SMB Server CVE-2017-0145 Remote Code Execution Vulnerability
2017-05-09
http://www.securityfocus.com/bid/96705

Microsoft Windows SMB Server CVE-2017-0143 Remote Code Execution Vulnerability
2017-05-09
http://www.securityfocus.com/bid/96703

Microsoft Windows SMB Server CVE-2017-0144 Remote Code Execution Vulnerability
2017-05-09
http://www.securityfocus.com/bid/96704

Microsoft Windows SMB Server CVE-2017-0147 Information Disclosure Vulnerability
2017-05-09
http://www.securityfocus.com/bid/96709

Oracle Java SE and JRockit CVE-2017-3533 Remote Security Vulnerability
2017-05-09
http://www.securityfocus.com/bid/97740

Oracle Java SE and JRockit CVE-2017-3511 Local Security Vulnerability
2017-05-09
http://www.securityfocus.com/bid/97731

Oracle Java SE and JRockit CVE-2017-3544 Remote Security Vulnerability
2017-05-09
http://www.securityfocus.com/bid/97745

Oracle Java SE CVE-2017-3512 Remote Security Vulnerability
2017-05-09
http://www.securityfocus.com/bid/97727

Oracle Java SE CVE-2017-3514 Remote Security Vulnerability
2017-05-09
http://www.securityfocus.com/bid/97729

SANS News

 

Threatpost

Researchers Disclose Intel AMT Flaw Research

HandBrake for Mac Compromised with Proton Spyware

Hikvision Patches Backdoor in IP Cameras

Exploit

Microsoft Windows 8 / 8.1 / 10 / Windows Server / SCEP, Microsoft Security...

Gemalto SmartDiag Diagnosis Tool < 2.5 - Buffer Overflow (SEH)

Xen 64bit PV Guest - pagetable use-after-type-change Breakout

Linux/x86 - Disable ASLR Shellcode (80 bytes)

Linux/x86-64 - Reverse Shell Shellcode (IPv6) (113 bytes)

RPCBind / libtirpc - Denial of Service

8.5.2017

Bugtraq

 

Malware

 

Phishing

NatWest Bank

7th May 2017

Important Message

NatWest

7th May 2017

JONNYHU321@AOL.COM ACCOUNT
SECURITY VERIFICATION CODE

Vulnerebility

Oracle Java SE and JRockit CVE-2017-3533 Remote Security Vulnerability
2017-05-08
http://www.securityfocus.com/bid/97740

Oracle Java SE and JRockit CVE-2017-3511 Local Security Vulnerability
2017-05-08
http://www.securityfocus.com/bid/97731

Oracle Java SE and JRockit CVE-2017-3544 Remote Security Vulnerability
2017-05-08
http://www.securityfocus.com/bid/97745

Oracle Java SE CVE-2017-3512 Remote Security Vulnerability
2017-05-08
http://www.securityfocus.com/bid/97727

Oracle Java SE CVE-2017-3514 Remote Security Vulnerability
2017-05-08
http://www.securityfocus.com/bid/97729

Oracle Java SE CVE-2017-3539 Remote Security Vulnerability
2017-05-08
http://www.securityfocus.com/bid/97752

Oracle Java SE CVE-2017-3509 Remote Security Vulnerability
2017-05-08
http://www.securityfocus.com/bid/97737

Google Android Qualcomm Components CVE-2016-10297 Unspecified Security Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98241

Mozilla Firefox CVE-2017-5031 Use After Free Denial of Service Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98326

Microsoft Windows SMB Server CVE-2017-0146 Remote Code Execution Vulnerability
2017-05-08
http://www.securityfocus.com/bid/96707

Microsoft Windows SMB Server CVE-2017-0148 Remote Code Execution Vulnerability
2017-05-08
http://www.securityfocus.com/bid/96706

Microsoft Windows SMB Server CVE-2017-0147 Information Disclosure Vulnerability
2017-05-08
http://www.securityfocus.com/bid/96709

Microsoft Windows SMB Server CVE-2017-0144 Remote Code Execution Vulnerability
2017-05-08
http://www.securityfocus.com/bid/96704

Microsoft Windows SMB Server CVE-2017-0143 Remote Code Execution Vulnerability
2017-05-08
http://www.securityfocus.com/bid/96703

Microsoft Windows SMB Server CVE-2017-0145 Remote Code Execution Vulnerability
2017-05-08
http://www.securityfocus.com/bid/96705

Google Android Kernel Trace Subsystem CVE-2017-0630 Information Disclosure Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98213

Google Android Framework Apis CVE-2017-0593 Privilege Escalation Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98126

Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
2017-05-08
http://www.securityfocus.com/bid/96729

Google Android Framework Apis CVE-2017-0598 Information Disclosure Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98133

Google Android Bluetooth CVE-2017-0602 Information Disclosure Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98141

Foxit Reader and PhantomPDF CVE-2017-8454 Out-Of-Bounds Read Information Disclosure Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98320

Google Android Mediaserver CVE-2017-0596 Privilege Escalation Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98130

Google Android Qualcomm Components CVE-2015-9005 Unspecified Security Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98322

Google Android Mediaserver CVE-2017-0594 Privilege Escalation Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98128

Google Android Qualcomm Components CVE-2015-9006 Unspecified Security Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98321

Google Android Qualcomm Components CVE-2014-9930 Unspecified Security Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98323

Google Android Qualcomm Components CVE-2015-9007 Unspecified Security Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98324

Foxit Reader and PhantomPDF CVE-2017-8455 Out-Of-Bounds Read Information Disclosure Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98319

Google Android Qualcomm Wi-Fi Driver CVE-2016-10292 Denial Of Service Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98204

Google Android Audioserver CVE-2017-0597 Privilege Escalation Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98131Microsoft Windows SMB Server CVE-2017-0146 Remote Code Execution Vulnerability
2017-05-08
http://www.securityfocus.com/bid/96707

Microsoft Windows SMB Server CVE-2017-0148 Remote Code Execution Vulnerability
2017-05-08
http://www.securityfocus.com/bid/96706

Microsoft Windows SMB Server CVE-2017-0147 Information Disclosure Vulnerability
2017-05-08
http://www.securityfocus.com/bid/96709

Microsoft Windows SMB Server CVE-2017-0144 Remote Code Execution Vulnerability
2017-05-08
http://www.securityfocus.com/bid/96704

Microsoft Windows SMB Server CVE-2017-0143 Remote Code Execution Vulnerability
2017-05-08
http://www.securityfocus.com/bid/96703

Microsoft Windows SMB Server CVE-2017-0145 Remote Code Execution Vulnerability
2017-05-08
http://www.securityfocus.com/bid/96705

Google Android Kernel Trace Subsystem CVE-2017-0630 Information Disclosure Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98213

Google Android Framework Apis CVE-2017-0593 Privilege Escalation Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98126

Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
2017-05-08
http://www.securityfocus.com/bid/96729

Google Android Framework Apis CVE-2017-0598 Information Disclosure Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98133

Google Android Bluetooth CVE-2017-0602 Information Disclosure Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98141

Foxit Reader and PhantomPDF CVE-2017-8454 Out-Of-Bounds Read Information Disclosure Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98320

Google Android Mediaserver CVE-2017-0596 Privilege Escalation Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98130

Google Android Qualcomm Components CVE-2015-9005 Unspecified Security Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98322

Google Android Mediaserver CVE-2017-0594 Privilege Escalation Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98128

Google Android Qualcomm Components CVE-2015-9006 Unspecified Security Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98321

Google Android Qualcomm Components CVE-2014-9930 Unspecified Security Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98323

Google Android Qualcomm Components CVE-2015-9007 Unspecified Security Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98324

Foxit Reader and PhantomPDF CVE-2017-8455 Out-Of-Bounds Read Information Disclosure Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98319

Google Android Qualcomm Wi-Fi Driver CVE-2016-10292 Denial Of Service Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98204

Google Android Audioserver CVE-2017-0597 Privilege Escalation Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98131

Rpcbind CVE-2017-8779 Remote Denial of Service Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98325

Google Android Synaptics Touchscreen Driver CVE-2017-0634 Information Disclosure Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98224

Atlassian HipChat for iOS CVE-2017-8058 TLS Certificate Validation Security Bypass Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98318

Multiple Google Devices kernel UVC Driver CVE-2017-0627 Information Disclosure Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98205

Multiple Google Devices Qualcomm Camera Driver CVE-2017-0631 Information Disclosure Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98216

Apple Safari CVE-2017-2491 Use After Free Remote Code Execution Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98316

Foxit Reader and PhantomPDF CVE-2017-8453 Out-Of-Bounds Read Information Disclosure Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98317

Cisco TelePresence Collaboration Endpoint CVE-2017-3825 Denial of Service Vulnerability
2017-05-08
http://www.securityfocus.com/bid/98293

MySQL CVE-2017-3305 Man in the Middle Security Bypass Vulnerability
2017-05-08
http://www.securityfocus.com/bid/97023

SANS News

Exploring a P2P Transient Botnet - From Discovery to Enumeration

What Can You Learn On Your Own?

Threatpost

 

Exploit

Linux/x86 - Disable ASLR Shellcode (80 bytes)

Linux/x86-64 - Reverse Shell Shellcode (IPv6) (113 bytes)

7.5.2017

Bugtraq

CA20170504-01: Security Notice for CA Client Automation OS Installation Management 2017-05-05
Kotas, Kevin J (Kevin Kotas ca com)

[security bulletin] HPESBHF03736 rev.1 - HPE Aruba and HPE ProVision network switches using Diffie Hellman Group1 Sha1 Exchange Algorithm, Remote Disclosure of Information 2017-05-04
security-alert hpe com

[security bulletin] HPESBGN03740 rev.1 - HPE Network Automation, Multiple Remote Vulnerabilities 2017-05-04
security-alert hpe com

WordPress Core <= 4.7.4 Potential Unauthorized Password Reset (0day) [CVE-2017-8295] 2017-05-03
Dawid Golunski (dawid legalhackers com)

Malware

 

Phishing

anita@beeeco.co.uk

4th May 2017

MWQM-524 & 6106 Steve Scott

service@paypal.co.uk

3rd May 2017

Your account will be limited
until we hear from you.

Vulnerebility

Microsoft Windows SMB Server CVE-2017-0146 Remote Code Execution Vulnerability
2017-05-07
http://www.securityfocus.com/bid/96707

Microsoft Windows SMB Server CVE-2017-0148 Remote Code Execution Vulnerability
2017-05-07
http://www.securityfocus.com/bid/96706

Microsoft Windows SMB Server CVE-2017-0147 Information Disclosure Vulnerability
2017-05-07
http://www.securityfocus.com/bid/96709

Microsoft Windows SMB Server CVE-2017-0144 Remote Code Execution Vulnerability
2017-05-07
http://www.securityfocus.com/bid/96704

Microsoft Windows SMB Server CVE-2017-0143 Remote Code Execution Vulnerability
2017-05-07
http://www.securityfocus.com/bid/96703

Microsoft Windows SMB Server CVE-2017-0145 Remote Code Execution Vulnerability
2017-05-07
http://www.securityfocus.com/bid/96705

Google Android Kernel Trace Subsystem CVE-2017-0630 Information Disclosure Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98213

Google Android Framework Apis CVE-2017-0593 Privilege Escalation Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98126

Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
2017-05-07
http://www.securityfocus.com/bid/96729

Google Android Framework Apis CVE-2017-0598 Information Disclosure Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98133

Google Android Bluetooth CVE-2017-0602 Information Disclosure Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98141

Foxit Reader and PhantomPDF CVE-2017-8454 Out-Of-Bounds Read Information Disclosure Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98320

Google Android Mediaserver CVE-2017-0596 Privilege Escalation Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98130

Google Android Qualcomm Components CVE-2015-9005 Unspecified Security Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98322

Google Android Mediaserver CVE-2017-0594 Privilege Escalation Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98128

Google Android Qualcomm Components CVE-2015-9006 Unspecified Security Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98321

Google Android Qualcomm Components CVE-2014-9930 Unspecified Security Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98323

Google Android Qualcomm Components CVE-2015-9007 Unspecified Security Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98324

Foxit Reader and PhantomPDF CVE-2017-8455 Out-Of-Bounds Read Information Disclosure Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98319

Google Android Qualcomm Wi-Fi Driver CVE-2016-10292 Denial Of Service Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98204

Google Android Audioserver CVE-2017-0597 Privilege Escalation Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98131

Rpcbind CVE-2017-8779 Remote Denial of Service Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98325

Google Android Synaptics Touchscreen Driver CVE-2017-0634 Information Disclosure Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98224

Atlassian HipChat for iOS CVE-2017-8058 TLS Certificate Validation Security Bypass Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98318

Multiple Google Devices kernel UVC Driver CVE-2017-0627 Information Disclosure Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98205

Multiple Google Devices Qualcomm Camera Driver CVE-2017-0631 Information Disclosure Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98216

Apple Safari CVE-2017-2491 Use After Free Remote Code Execution Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98316

Foxit Reader and PhantomPDF CVE-2017-8453 Out-Of-Bounds Read Information Disclosure Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98317

Cisco TelePresence Collaboration Endpoint CVE-2017-3825 Denial of Service Vulnerability
2017-05-07
http://www.securityfocus.com/bid/98293

MySQL CVE-2017-3305 Man in the Middle Security Bypass Vulnerability
2017-05-07
http://www.securityfocus.com/bid/97023
Microsoft Windows SMB Server CVE-2017-0146 Remote Code Execution Vulnerability
2017-05-06
http://www.securityfocus.com/bid/96707

Microsoft Windows SMB Server CVE-2017-0148 Remote Code Execution Vulnerability
2017-05-06
http://www.securityfocus.com/bid/96706

Microsoft Windows SMB Server CVE-2017-0147 Information Disclosure Vulnerability
2017-05-06
http://www.securityfocus.com/bid/96709

Microsoft Windows SMB Server CVE-2017-0144 Remote Code Execution Vulnerability
2017-05-06
http://www.securityfocus.com/bid/96704

Microsoft Windows SMB Server CVE-2017-0143 Remote Code Execution Vulnerability
2017-05-06
http://www.securityfocus.com/bid/96703

Microsoft Windows SMB Server CVE-2017-0145 Remote Code Execution Vulnerability
2017-05-06
http://www.securityfocus.com/bid/96705

Google Android Kernel Trace Subsystem CVE-2017-0630 Information Disclosure Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98213

Google Android Framework Apis CVE-2017-0593 Privilege Escalation Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98126

Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
2017-05-06
http://www.securityfocus.com/bid/96729

Google Android Framework Apis CVE-2017-0598 Information Disclosure Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98133

Google Android Bluetooth CVE-2017-0602 Information Disclosure Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98141

Foxit Reader and PhantomPDF CVE-2017-8454 Out-Of-Bounds Read Information Disclosure Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98320

Google Android Mediaserver CVE-2017-0596 Privilege Escalation Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98130

Google Android Qualcomm Components CVE-2015-9005 Unspecified Security Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98322

Google Android Mediaserver CVE-2017-0594 Privilege Escalation Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98128

Google Android Qualcomm Components CVE-2015-9006 Unspecified Security Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98321

Google Android Qualcomm Components CVE-2014-9930 Unspecified Security Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98323

Google Android Qualcomm Components CVE-2015-9007 Unspecified Security Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98324

Foxit Reader and PhantomPDF CVE-2017-8455 Out-Of-Bounds Read Information Disclosure Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98319

Google Android Qualcomm Wi-Fi Driver CVE-2016-10292 Denial Of Service Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98204

Google Android Audioserver CVE-2017-0597 Privilege Escalation Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98131

Rpcbind CVE-2017-8779 Remote Denial of Service Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98325

Google Android Synaptics Touchscreen Driver CVE-2017-0634 Information Disclosure Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98224

Atlassian HipChat for iOS CVE-2017-8058 TLS Certificate Validation Security Bypass Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98318

Multiple Google Devices kernel UVC Driver CVE-2017-0627 Information Disclosure Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98205

Multiple Google Devices Qualcomm Camera Driver CVE-2017-0631 Information Disclosure Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98216

Apple Safari CVE-2017-2491 Use After Free Remote Code Execution Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98316

Foxit Reader and PhantomPDF CVE-2017-8453 Out-Of-Bounds Read Information Disclosure Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98317

Cisco TelePresence Collaboration Endpoint CVE-2017-3825 Denial of Service Vulnerability
2017-05-06
http://www.securityfocus.com/bid/98293

MySQL CVE-2017-3305 Man in the Middle Security Bypass Vulnerability
2017-05-06
http://www.securityfocus.com/bid/97023Atlassian HipChat for iOS CVE-2017-8058 TLS Certificate Validation Security Bypass Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98318

Multiple Google Devices kernel UVC Driver CVE-2017-0627 Information Disclosure Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98205

Multiple Google Devices Qualcomm Camera Driver CVE-2017-0631 Information Disclosure Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98216

Apple Safari CVE-2017-2491 Use After Free Remote Code Execution Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98316

Foxit Reader and PhantomPDF CVE-2017-8453 Out-Of-Bounds Read Information Disclosure Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98317

Cisco TelePresence Collaboration Endpoint CVE-2017-3825 Denial of Service Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98293

MySQL CVE-2017-3305 Man in the Middle Security Bypass Vulnerability
2017-05-05
http://www.securityfocus.com/bid/97023

PCRE 'pcre2_match.c' Stack Buffer Overflow Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98315

Xen CVE-2017-7995 Information Disclosure Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98314

Multiple Hikvision Cameras ICSA-17-124-01 Multiple Securtiy Vulnerabilities
2017-05-05
http://www.securityfocus.com/bid/98313

Google Nexus Nvidia Video Driver CVE-2017-0331 Privilege Escalation Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98150

Google Android Qualcomm Adsprpc Driver CVE-2017-0465 Privilege Escalation Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98184

Dahua Technology Authentication Bypass and Information Disclosure Vulnerabilities
2017-05-05
http://www.securityfocus.com/bid/98312

Advantech WebAccess CVE-2017-7929 Directory Traversal Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98311

Multiple Rockwell Automation Products CVE-2017-6024 Remote Denial of Service Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98309

IBM Maximo Asset Management CVE-2016-9976 Unspecified Remote Code Execution Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98305

Think Mutual Bank Mobile Banking App SSL Certificate Validation Security Bypass Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98308

Google Android Qualcomm Components CVE-2014-9951 Unspecified Security Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98252

Google Android Qualcomm Components CVE-2014-9941 Unspecified Security Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98242

Google Android Qualcomm Components CVE-2014-9944 Unspecified Security Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98245

SCCU Mobile for Android and iPhone SSL Certificate Validation Security Bypass Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98307

Google Android Qualcomm Video Driver CVE-2016-10286 Privilege Escalation Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98165

Google Android Qualcomm Components CVE-2014-9952 Unspecified Security Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98253

Google Android Qualcomm Components CVE-2014-9945 Unspecified Security Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98246

Google Android Qualcomm Components CVE-2014-9943 Unspecified Security Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98244

Google Android Qualcomm Components CVE-2014-9942 Unspecified Security Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98243

Google Android Qualcomm Components CVE-2014-9947 Unspecified Security Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98248

Google Android Qualcomm Components CVE-2014-9948 Unspecified Security Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98249

Google Android Qualcomm Video Driver CVE-2016-10285 Privilege Escalation Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98163

Google Android Qualcomm Driver CVE-2017-0613 Privilege Escalation Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98186

SANS News

The story of the CFO and CEO...

Threatpost

Carbanak Attackers Devise Clever New Persistence Trick

Business Email Compromise Losses Up 2,370 Percent Since 2015

Ultrasonic Beacons Are Tracking Your Every Movement

Supply Chain Update Software Unknowingly Used in Attacks

Exploit

WordPress Plugin WebDorado Gallery 1.3.29 - SQL Injection

ViMbAdmin 3.0.15 - Multiple Cross-Site Request Forgery

CloudBees Jenkins 2.32.1 - Java Deserialization

5.5.2017

Bugtraq

[security bulletin] HPESBHF03736 rev.1 - HPE Aruba and HPE ProVision network switches using Diffie Hellman Group1 Sha1 Exchange Algorithm, Remote Disclosure of Information 2017-05-04
security-alert hpe com

[security bulletin] HPESBGN03740 rev.1 - HPE Network Automation, Multiple Remote Vulnerabilities 2017-05-04
security-alert hpe com

WordPress Core <= 4.7.4 Potential Unauthorized Password Reset (0day) [CVE-2017-8295] 2017-05-03
Dawid Golunski (dawid legalhackers com)

ESA-2017-036: EMC Data Domain Privilege Escalation Vulnerability 2017-05-03
EMC Product Security Response Center (Security_Alert emc com)

Zenario CMS v7.6 - (Delete) Persistent Cross Site Vulnerability 2017-05-03
Vulnerability Lab (research vulnerability-lab com)

Zenario v7.6 - Persistent Cross Site Scripting Vulnerability 2017-05-03
Vulnerability Lab (research vulnerability-lab com)

Arachni v1.5-0.5.11 - Persistent Cross Site Vulnerability 2017-05-03
Vulnerability Lab (research vulnerability-lab com)

Super File Explorer 1.0.1 - Arbitrary File Upload Vulnerability 2017-05-03
Vulnerability Lab (research vulnerability-lab com)

Joomla com_tag v1.7.6 - (tag) SQL Injection Vulnerability 2017-05-03
Vulnerability Lab (research vulnerability-lab com)

Hola VPN v1.34 - Privilege Escalation Vulnerability 2017-05-03
Vulnerability Lab (research vulnerability-lab com)

Malware

 

Phishing

anita@beeeco.co.uk

4th May 2017

MWQM-524 & 6106 Steve Scott

service@paypal.co.uk

3rd May 2017

Your account will be limited
until we hear from you.

spoof

3rd May 2017

Sure thing!

Vulnerebility

Advantech WebAccess CVE-2017-7929 Directory Traversal Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98311

Multiple Rockwell Automation Products CVE-2017-6024 Remote Denial of Service Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98309

IBM Maximo Asset Management CVE-2016-9976 Unspecified Remote Code Execution Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98305

Think Mutual Bank Mobile Banking App SSL Certificate Validation Security Bypass Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98308

Google Android Qualcomm Components CVE-2014-9951 Unspecified Security Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98252

Google Android Qualcomm Components CVE-2014-9941 Unspecified Security Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98242

Google Android Qualcomm Components CVE-2014-9944 Unspecified Security Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98245

SCCU Mobile for Android and iPhone SSL Certificate Validation Security Bypass Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98307

Google Android Qualcomm Video Driver CVE-2016-10286 Privilege Escalation Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98165

Google Android Qualcomm Components CVE-2014-9952 Unspecified Security Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98253

Google Android Qualcomm Components CVE-2014-9945 Unspecified Security Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98246

Google Android Qualcomm Components CVE-2014-9943 Unspecified Security Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98244

Google Android Qualcomm Components CVE-2014-9942 Unspecified Security Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98243

Google Android Qualcomm Components CVE-2014-9947 Unspecified Security Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98248

Google Android Qualcomm Components CVE-2014-9948 Unspecified Security Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98249

Google Android Qualcomm Video Driver CVE-2016-10285 Privilege Escalation Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98163

Google Android Qualcomm Driver CVE-2017-0613 Privilege Escalation Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98186

Google Android Qualcomm Networking Driver CVE-2016-5868 Privilege Escalation Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98197

Google Android Qualcomm Sound Codec Driver CVE-2016-5858 Information Disclosure Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98215

Google Android Qualcomm Video Driver CVE-2016-10284 Privilege Escalation Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98162

QEMU 'megasas_mmio_write()' Function Out-of-Bounds Read Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98303

Google Android Kernel Performance Subsystem CVE-2015-9004 Privilege Escalation Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98166

LibTIFF CVE-2017-7595 Divide By Zero Denial of Service Vulnerability
2017-05-05
http://www.securityfocus.com/bid/97501

Apache FOP CVE-2017-5661 XML External Entity Information Disclosure Vulnerability
2017-05-05
http://www.securityfocus.com/bid/97947

Google Android Qualcomm Wi-fi Driver CVE-2017-0624 Information Disclosure Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98200

Trend Micro OfficeScan Multiple Privilege Escalation and Cross Site Scripting Vulnerabilities
2017-05-05
http://www.securityfocus.com/bid/98007

IBM BigFix Remote Control CVE-2016-2930 Security Bypass Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98304

QEMU CVE-2017-8309 Denial of Service Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98302

IBM Tealeaf Customer Experience CVE-2016-0382 Local Information Disclosure Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98301

Google Android Htc Bootloader CVE-2017-0623 Privilege Escalation Vulnerability
2017-05-05
http://www.securityfocus.com/bid/98199

SANS News

HTTP Headers... the Achilles' heel of many applications

Threatpost

Unpatched WordPress Password Reset Vulnerability Lingers

Blackmoon Banking Trojan Using New Infection Technique

Many Commercial Drones ‘Insecure by Design’

Stealthy RAT Targeting North Korea Since 2014

Exploit

Safari 10.0.3 - 'JSC::CachedCall' Use-After-Free

WordPress 4.6 - Unauthenticated Remote Code Execution

WordPress < 4.7.4 - Unauthorized Password Reset

4.5.2017

Bugtraq

WordPress Core <= 4.7.4 Potential Unauthorized Password Reset (0day) [CVE-2017-8295] 2017-05-03
Dawid Golunski (dawid legalhackers com)

ESA-2017-036: EMC Data Domain Privilege Escalation Vulnerability 2017-05-03
EMC Product Security Response Center (Security_Alert emc com)

Zenario CMS v7.6 - (Delete) Persistent Cross Site Vulnerability 2017-05-03
Vulnerability Lab (research vulnerability-lab com)

Zenario v7.6 - Persistent Cross Site Scripting Vulnerability 2017-05-03
Vulnerability Lab (research vulnerability-lab com)

Arachni v1.5-0.5.11 - Persistent Cross Site Vulnerability 2017-05-03
Vulnerability Lab (research vulnerability-lab com)

Super File Explorer 1.0.1 - Arbitrary File Upload Vulnerability 2017-05-03
Vulnerability Lab (research vulnerability-lab com)

Joomla com_tag v1.7.6 - (tag) SQL Injection Vulnerability 2017-05-03
Vulnerability Lab (research vulnerability-lab com)

Hola VPN v1.34 - Privilege Escalation Vulnerability 2017-05-03
Vulnerability Lab (research vulnerability-lab com)

Mura CMS Cross-Site Scripting (XSS) Vulnerability 2017-05-03
Leon Zhao 7 gmail com

[SECURITY] [DSA 3843-1] tomcat8 security update 2017-05-03
Sebastien Delafond (seb debian org)

[SECURITY] [DSA 3842-1] tomcat7 security update 2017-05-03
Sebastien Delafond (seb debian org)

Malware

Trojan:Win32/Fuery.A!cl
Trojan:Win32/Fuery.B!cl

Phishing

anita@beeeco.co.uk

4th May 2017

MWQM-524 & 6106 Steve Scott

service@paypal.co.uk

3rd May 2017

Your account will be limited
until we hear from you.

spoof

3rd May 2017

Sure thing!

BT Internet UK

2nd May 2017

Changes To Your Account

spoof

2nd May 2017

Hayes wants to get paid.

Vulnerebility

Multiple Intel Products CVE-2017-5689 Privilege Escalation Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98269

Multiple Google Devices Qualcomm Camera Driver CVE-2017-0631 Information Disclosure Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98216

Drupal Shibboleth authentication Module Access Bypass Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98299

Cisco Aironet Access Points CVE-2017-3873 Arbitrary Code Execution Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98296

WordPress Password Reset CVE-2017-8295 Security Bypass Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98295

Cisco Wide Area Application Services CVE-2017-6628 Remote Denial of Service Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98294

Google Android HTC Touchscreen Driver CVE-2017-0563 Privilege Escalation Vulnerability
2017-05-04
http://www.securityfocus.com/bid/97342

Cisco TelePresence Collaboration Endpoint CVE-2017-3825 Denial of Service Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98293

Cisco Firepower System Software CVE-2016-6368 Denial of Service Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98292

Cisco Finesse CVE-2017-6626 Information Disclosure Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98291

Cisco IOS Software CVE-2017-6624 Unauthorized Access Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98283

Cisco CVR100W Wireless-N VPN Router CVE-2017-6620 Security Bypass Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98289

Cisco IOS XR Software CVE-2017-3876 Denial of Service Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98284

Cisco CVR100W Wireless-N VPN Router CVE-2017-3882 Buffer Overflow Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98287

Google Chrome CVE-2017-5068 Unspecified Race Condition Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98288

Cisco Unity Connection CVE-2017-6629 Unauthorized Access Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98286

Google Chrome Prior to 58.0.3029.81 Multiple Security Vulnerabilities
2017-05-04
http://www.securityfocus.com/bid/97939

Google gRPC CVE-2017-8359 Heap Buffer Overflow Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98280

QEMU CVE-2017-8379 Denial of Service Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98277

Atlassian Hipchat Server CVE-2017-8080 Remote Code Execution Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98262

Google Android Mediaserver CVE-2017-0603 Denial Of Service Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98143

Google Android Broadcom Wi-fi Driver CVE-2017-0633 Information Disclosure Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98223

CyberVision Kaa IoT Platform CVE-2017-7911 Remote Code Injection Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98256

Advantech B+B SmartWorx MESR901 CVE-2017-7909 Authentication Bypass Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98257

Wonderware Historian Client CVE-2017-7907 Local XML External Entity Injection Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98254

Google Android Qualcomm Sound Driver CVE-2017-0610 Privilege Escalation Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98255

Google Android Qualcomm Sound Driver CVE-2016-5859 Privilege Escalation Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98175

Google Android Qualcomm Sound Driver CVE-2016-5853 Privilege Escalation Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98178

Google Android Qualcomm Sound Driver CVE-2017-0609 Privilege Escalation Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98174

Google Android Qualcomm Sound Driver CVE-2017-0608 Privilege Escalation Vulnerability
2017-05-04
http://www.securityfocus.com/bid/98172

SANS News

OAUTH phishing against Google Docs ? beware!

Threatpost

Proposed NIST Password Guidelines Soften Length, Complexity Focus

Researcher: ‘Baseless Assumptions’ Exist About Intel AMT Vulnerability

Sabre Corp. Investigating Breach of Reservation System

Exploit

Microsoft Internet Explorer 11 - 'CMarkup::DestroySplayTree' Use-After-Free

WordPress 4.6 - Unauthenticated Remote Code Execution

WordPress < 4.7.4 - Unauthorized Password Reset

Serviio PRO 1.8 DLNA Media Streaming Server - REST API Information Disclosure

Serviio PRO 1.8 DLNA Media Streaming Server - REST API Arbitrary Password Change

Serviio PRO 1.8 DLNA Media Streaming Server - REST API Arbitrary Code Execution

Serviio PRO 1.8 DLNA Media Streaming Server - Local Privilege Escalation

3.5.2017

Bugtraq

Zenario CMS v7.6 - (Delete) Persistent Cross Site Vulnerability 2017-05-03
Vulnerability Lab (research vulnerability-lab com)

Zenario v7.6 - Persistent Cross Site Scripting Vulnerability 2017-05-03
Vulnerability Lab (research vulnerability-lab com)

Arachni v1.5-0.5.11 - Persistent Cross Site Vulnerability 2017-05-03
Vulnerability Lab (research vulnerability-lab com)

Super File Explorer 1.0.1 - Arbitrary File Upload Vulnerability 2017-05-03
Vulnerability Lab (research vulnerability-lab com)

Joomla com_tag v1.7.6 - (tag) SQL Injection Vulnerability 2017-05-03
Vulnerability Lab (research vulnerability-lab com)

Hola VPN v1.34 - Privilege Escalation Vulnerability 2017-05-03
Vulnerability Lab (research vulnerability-lab com)

Mura CMS Cross-Site Scripting (XSS) Vulnerability 2017-05-03
Leon Zhao 7 gmail com

[SECURITY] [DSA 3843-1] tomcat8 security update 2017-05-03
Sebastien Delafond (seb debian org)

[SECURITY] [DSA 3842-1] tomcat7 security update 2017-05-03
Sebastien Delafond (seb debian org)

MODX Revolution 2.0.1-pl - 2.5.6-pl blind SQLi 2017-05-02
Anti Räis (antirais gmail com)

[security bulletin] HPESBHF03741 rev.1 - HPE Network products including Comware 7, IMC, and VCX running OpenSSL, Local Unauthorized Disclosure of Information, Remote Denial of Service (DoS), Unauthorized Disclosure of Information 2017-05-02
security-alert hpe com

IML 2017 Conference, ACM digital library proceedings, Venue: Liverpool John Moores University, United Kingdom 2017-04-29
IML 2017 Conference (cfp iml-conference site)

SyntaxHighlight MediaWiki extension allows injection of arbitrary Pygments options 2017-04-29
Securify B.V. (lists securify nl)

Multiple local privilege escalation vulnerabilities in HideMyAss Pro VPN client v2.x for OS X 2017-04-29
Securify B.V. (lists securify nl)

[security bulletin] HPESBHF03738 rev.1 - HPE Intelligent Management Center (iMC) PLAT, Remote Code Execution 2017-04-28
security-alert hpe com

[SECURITY] [DSA 3838-1] ghostscript security update 2017-04-28
Salvatore Bonaccorso (carnil debian org)

Malware

 

Phishing

BT Internet UK

2nd May 2017

Changes To Your Account

spoof

2nd May 2017

Hayes wants to get paid.

spoof

2nd May 2017

You, I like you.

spoof

2nd May 2017

The .jpg is real.

Vulnerebility

Google Android Broadcom Wi-fi Driver CVE-2017-0633 Information Disclosure Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98223

CyberVision Kaa IoT Platform CVE-2017-7911 Remote Code Injection Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98256

Advantech B+B SmartWorx MESR901 CVE-2017-7909 Authentication Bypass Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98257

Wonderware Historian Client CVE-2017-7907 Local XML External Entity Injection Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98254

Google Android Qualcomm Sound Driver CVE-2017-0610 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98255

Google Android Qualcomm Sound Driver CVE-2016-5859 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98175Google Android Qualcomm Sound Driver CVE-2017-0609 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98174

Google Android Qualcomm Sound Driver CVE-2017-0608 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98172

Google Android Qualcomm Sound Driver CVE-2016-5867 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98170

Google Android Qualcomm Sound Driver CVE-2017-0607 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98171

Google Android Qualcomm Sound Driver CVE-2016-10287 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98167

Google Android Qualcomm Sound Driver CVE-2017-0606 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98168

EMC RSA Security Analytics CVE-2016-8215 Unspecified Cross Site Scripting Vulnerability
2017-05-03
http://www.securityfocus.com/bid/95718
Google Android Mediaserver CVE-2017-0595 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98129

Google Android Qualcomm Components CVE-2014-9946 Unspecified Security Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98247

Google Android Qualcomm Components CVE-2014-9950 Unspecified Security Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98251

Google Android Qualcomm Sound Driver CVE-2017-0611 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98177

Google Android Qualcomm Components CVE-2014-9949 Unspecified Security Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98250

Google Android Qualcomm Camera Driver CVE-2017-0628 Information Disclosure Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98211

Google Android Qualcomm Sound Driver CVE-2016-5860 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98169

Google Android CVE-2017-0561 Remote Code Execution Vulnerability
2017-05-03
http://www.securityfocus.com/bid/97367

Google Android Qualcomm Camera Driver CVE-2017-0629 Information Disclosure Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98212

Google Android Qualcomm Wi-Fi Driver CVE-2016-10283 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98160

Google Android Motorola Bootloader CVE-2016-10277 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98149

Google Android Qualcomm Driver CVE-2017-0614 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98187

Google Android Qualcomm Bootloader CVE-2016-10276 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98148

Google Android Qualcomm Bootloader CVE-2016-10275 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98146

Microsoft Windows Kernel 'Win32k.sys' Local Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/90989

Google Android Qualcomm Sound Codec Driver CVE-2017-0632 Information Disclosure Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98221

Google Android File-based Encryption CVE-2017-0493 Information Disclosure Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98140

Google Android Qualcomm CVE-2017-0612 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98231

Google Android Qualcomm Shared Memory Driver CVE-2016-10290 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98182

Google Android Qualcomm Slimbus Driver CVE-2016-10291 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98183

Google Android Mediaserver CVE-2017-0587 Remote Code Execution Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98119

Google Android Qualcomm Camera Driver CVE-2017-0621 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98196

Google Android Kernel Trace Subsystem CVE-2017-0605 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98152

Google Android Bluetooth CVE-2017-0601 Privilege Escalation Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98137

Google Android Mediaserver CVE-2017-0588 Remote Code Execution Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98120

Google Android Mediaserver CVE-2017-0589 Remote Code Execution Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98122

ImageMagick CVE-2017-8343 Denial of Service Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98132

Google Android Mediaserver CVE-2017-0590 Remote Code Execution Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98123

IBM Insights Foundation for Energy CVE-2017-1141 Information Disclosure Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98161

IBM WebSphere Application Server CVE-2017-1194 Cross Site Request Forgery Vulnerability
2017-05-03
http://www.securityfocus.com/bid/98142

SANS News

Powershelling with exploits

Threatpost

Malware Hunter Crawls Internet Looking for RAT C2s

DDoS Attacks Can Cost Businesses Up to $2.5M Per Attack, Report Says

IBM: Destroy USBs Infected with Malware Dropper

Shamoon Collaborator Greenbug Adopts New Communication Tool

Exploit

Ghostscript 9.21 - Type Confusion Arbitrary Command Execution (Metasploit)

2.5.2017

Bugtraq

 

Malware

 

Phishing

spoof

2nd May 2017

The .jpg is real.

CardApprovalUSA

1st May 2017

Open a new credit account

spoof

1st May 2017

E-I-E-I-O!!

Moneygram office

1st May 2017

Dear Customer

Allergens U. Manson

1st May 2017

Like a plauge?

Vulnerebility

Google Android File-based Encryption CVE-2017-0493 Information Disclosure Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98140

Google Android Mediaserver CVE-2017-0588 Remote Code Execution Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98120

Google Android Mediaserver CVE-2017-0589 Remote Code Execution Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98122

ImageMagick CVE-2017-8343 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98132

Google Android Mediaserver CVE-2017-0590 Remote Code Execution Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98123

IBM Insights Foundation for Energy CVE-2017-1141 Information Disclosure Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98161

IBM WebSphere Application Server CVE-2017-1194 Cross Site Request Forgery Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98142

Google Android Mediaserver CVE-2017-0591 Remote Code Execution Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98124

Google Android Mediaserver CVE-2017-0592 Remote Code Execution Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98125

Multiple Siklu EtherHaul Devices CVE-2017-7318 Remote Command Execution Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97227

ImageMagick CVE-2017-8344 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98136

ImageMagick CVE-2017-8345 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98138

libevent Multiple Security Vulnerabilities
2017-05-02
http://www.securityfocus.com/bid/96014

Mozilla Firefox Multiple Security Vulnerabilities
2017-05-02
http://www.securityfocus.com/bid/97940

Mozilla Network Security Services CVE-2017-5461 Memory Corruption Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98050

Randombit Botan CVE-2017-2801 Certificate Validation Security Bypass Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98106

Linux Kernel CVE-2016-5195 Local Privilege Escalation Vulnerability
2017-05-02
http://www.securityfocus.com/bid/93793

Huawei eSpace IAD CVE-2016-8271 Remote Information Disclosure Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98096

Gnulib CVE-2017-7476 Local Heap Overflow Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98098

NetIQ Access Manager CVE-2017-5191 Cross Site Scripting Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98093

WordPress CopySafe Web Protection Plugin CVE-2017-8100 Cross Site Request Forgery Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98091

Zabbix Proxy Server CVE-2017-2825 Man in the Middle Security Bypass Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98094

SaltStack Salt CVE-2017-8109 Local Information Disclosure Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98095

FreeBSD CVE-2017-1081 Use After Free Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98089

Revive Adserver Multiple Security Vulnerabilities
2017-05-02
http://www.securityfocus.com/bid/83964

Zimbra Collaboration Suite CVE-2017-6813 Unspecified Privilege Escalation Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98087

Technicolor DPC3928SL CVE-2017-5135 SNMP Authentication Bypass Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98092

Zimbra Collaboration Suite CVE-2017-6821 Unspecified Security Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98090

HP Intelligent Management Center Multiple Unspecified Remote Code Execution Vulnerabilities
2017-05-02
http://www.securityfocus.com/bid/98088

Zimbra Collaboration Suite CVE-2017-7288 Unspecified HTML Injection Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98081OpenSSL CVE-2016-6304 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/93150

OpenSSL CVE-2016-6305 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/93149

OpenSSL 'BN_bn2dec()' Function Out of Bounds Write Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/92557

OpenSSL CVE-2016-6302 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/92628

SSL/TLS Protocol CVE-2016-2183 Information Disclosure Vulnerability
2017-05-02
http://www.securityfocus.com/bid/92630

OpenSSL CVE-2016-2179 Multiple Denial of Service Vulnerabilities
2017-05-02
http://www.securityfocus.com/bid/92987

OpenSSL CVE-2016-2181 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/92982

OpenSSL CVE-2016-2180 Local Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/92117

Cisco Firepower System Software CVE-2016-6368 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97932

Cisco IOS XE Software CVE-2017-6615 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97930

Cisco Prime Infrastructure CVE-2017-6611 Cross Site Scripting Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97931

Cisco Integrated Management Controller CVE-2017-6616 Remote Code Execution Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97928

Cisco Integrated Management Controller CVE-2017-6617 Session Hijacking Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97929

Cisco Integrated Management Controller CVE-2017-6618 Cross Site Scripting Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97927

Cisco FindIT Network Probe CVE-2017-6614 Information Disclosure Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97926

Cisco Integrated Management Controller CVE-2017-6619 Remote Command Execution Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97925

Cisco ASA Software and FTD Software CVE-2017-3793 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97923

Cisco Prime Network Registrar CVE-2017-6613 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97924

Cisco Unified Communications Manager CVE-2017-3808 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97922

VMware Workstation and Horizon Client CVE-2017-4913 Integer Overflow Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97920

OpenSSL CVE-2016-6307 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/93152

VMware Workstation and Horizon View Client CVE-2017-4912 Remote Code Execution Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97921

IBM Cognos TM1 CVE-2016-3036 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97918

VMware Workstation and Horizon View Client CVE-2017-4911 Remote Code Execution Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97916

IBM Cognos TM1 CVE-2016-3037 Information Disclosure Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97917

IBM Cognos TM1 CVE-2016-3038 Cross Site Scripting Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97915

VMware Unified Access Gateway and Horizon View Heap Based Buffer Overflow Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97914

VMware Workstation and Horizon View Client CVE-2017-4910 Remote Code Execution Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97913

OpenSSL CVE-2016-6308 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/93151

YUI 'SWF' File Multiple Cross-Site Scripting Vulnerabilities
2017-05-02
http://www.securityfocus.com/bid/56385Randombit Botan CVE-2017-2801 Certificate Validation Security Bypass Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98106

Linux Kernel CVE-2016-5195 Local Privilege Escalation Vulnerability
2017-05-02
http://www.securityfocus.com/bid/93793

Huawei eSpace IAD CVE-2016-8271 Remote Information Disclosure Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98096

Gnulib CVE-2017-7476 Local Heap Overflow Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98098

NetIQ Access Manager CVE-2017-5191 Cross Site Scripting Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98093

WordPress CopySafe Web Protection Plugin CVE-2017-8100 Cross Site Request Forgery Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98091

Zabbix Proxy Server CVE-2017-2825 Man in the Middle Security Bypass Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98094

SaltStack Salt CVE-2017-8109 Local Information Disclosure Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98095

FreeBSD CVE-2017-1081 Use After Free Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98089

Revive Adserver Multiple Security Vulnerabilities
2017-05-02
http://www.securityfocus.com/bid/83964

Zimbra Collaboration Suite CVE-2017-6813 Unspecified Privilege Escalation Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98087

Technicolor DPC3928SL CVE-2017-5135 SNMP Authentication Bypass Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98092

Zimbra Collaboration Suite CVE-2017-6821 Unspecified Security Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98090

HP Intelligent Management Center Multiple Unspecified Remote Code Execution Vulnerabilities
2017-05-02
http://www.securityfocus.com/bid/98088

Zimbra Collaboration Suite CVE-2017-7288 Unspecified HTML Injection Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98081

Avast! Antivirus CVE-2017-8307 Arbitrary File Deletion Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98086

Linux Kernel CVE-2017-7895 Multiple Security Bypass Vulnerabilities
2017-05-02
http://www.securityfocus.com/bid/98085

symetrie CVE-2017-7386 Cross Site Scripting Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98082

Zabbix CVE-2017-2824 Command Injection Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98083

Avast! Antivirus CVE-2017-8308 Security Bypass Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98084

McAfee Security Scan Plus CVE-2016-8026 Unspecified Local Command Execution Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98068

illumos CVE-2016-6561 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98079

eXtplorer CVE-2016-4313 Local Directory Traversal Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98069

YARA 'yara_yyparse()' Function Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98080

YARA 'yy_get_next_buffer()' Function Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98077

YARA CVE-2017-5924 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98075

Multiple IBM Products CVE-2016-9693 Unspecified Arbitrary File Download Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98074

YARA CVE-2016-10211 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98078

LibreSSL CVE-2017-8301 Certificate Validation Security Bypass Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98076

Multiple IBM Products CVE-2016-9723 Cross Site Scripting Vulnerability
2017-05-02
http://www.securityfocus.com/bid/98073Red Hat OpenShift Enterprise CVE-2016-5409 Information Disclosure Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97988

WeeChat CVE-2017-8073 Buffer Overflow Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97987

pcs CVE-2016-0720 Cross Site Request Forgery Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97984

Linux Kernel CVE-2010-5329 Local Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97986

TP-Link TL-SG108E CVE-2017-8078 Security Bypass Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97985

TP-Link TL-SG108E CVE-2017-8075 Information Disclosure Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97983

TP-Link TL-SG108E CVE-2017-8074 Information Disclosure Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97981

Oracle MySQL Connectors CVE-2017-3586 Remote Security Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97982

podofo CVE-2017-7994 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97980

Shopware CVE-2016-3109 Arbitrary Code Execution Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97979

XOOPS CVE-2017-7944 Cross Site Scripting Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97978

pcs daemon CVE-2016-0721 Session Fixation Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97977

Linux Kernel CVE-2017-8064 Local Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97975

NTP CVE-2016-7427 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/94447

NTP CVE-2016-7429 Local Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/94453

NTP CVE-2015-8158 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/81814

NTP CVE-2015-8138 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/81811

Linux Kernel CVE-2017-8062 Local Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97973

NTP CVE-2016-7431 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/94454

Linux Kernel CVE-2017-8063 Local Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97974

NTP CVE-2015-7979 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/81816

Cybozu Kintone App CVE-2016-1186 SSL Certificate Validation Security Bypass Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97976

NTP CVE-2015-7973 Security Bypass Vulnerability
2017-05-02
http://www.securityfocus.com/bid/81963

Linux Kernel CVE-2017-8061 Local Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97972

QEMU 'hw/9pfs/9p-local.c' Privilege Escalation Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97970

NTP CVE-2016-9310 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/94452

Linux Kernel CVE-2017-7979 Local Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97969

Apache ActiveMQ CVE-2015-7559 Denial of Service Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97967

Perl YAML-LibYAML Module 'perl_libyaml.c' Multiple Format String Vulnerabilities
2017-05-02
http://www.securityfocus.com/bid/52381

Minicom CVE-2017-7467 Local Buffer Overflow Vulnerability
2017-05-02
http://www.securityfocus.com/bid/97966

SANS News

Do you have Intel AMT? Then you have a problem today! Intel Active Management Technology INTEL-SA-00075

Threatpost

Apple Revokes Certificate Used By OSX/Dok Malware

Fuze Patches Bug That Exposed Recordings of Private Business Meetings

Exploit

Alerton Webtalk 2.5 / 3.3 - Multiple Vulnerabilities

Tuleap Project Wiki 8.3 <= 9.6.99.86 - Command Injection

HideMyAss Pro VPN Client for OS X 2.2.7.0 - Privilege Escalation

HideMyAss Pro VPN Client for macOS 3.x - Privilege Escalation

MySQL <= 5.6.35 / <= 5.7.17 - Integer Overflow

1.5.2017

Bugtraq

IML 2017 Conference, ACM digital library proceedings, Venue: Liverpool John Moores University, United Kingdom 2017-04-29
IML 2017 Conference (cfp iml-conference site)

SyntaxHighlight MediaWiki extension allows injection of arbitrary Pygments options 2017-04-29
Securify B.V. (lists securify nl)

Multiple local privilege escalation vulnerabilities in HideMyAss Pro VPN client v2.x for OS X 2017-04-29
Securify B.V. (lists securify nl)

[security bulletin] HPESBHF03738 rev.1 - HPE Intelligent Management Center (iMC) PLAT, Remote Code Execution 2017-04-28
security-alert hpe com

[SECURITY] [DSA 3838-1] ghostscript security update 2017-04-28
Salvatore Bonaccorso (carnil debian org)

Malware

Trojan:Win32/Msposer.C 

Phishing

Moneygram office

1st May 2017

Dear Customer

Allergens U. Manson

1st May 2017

Like a plauge?

spoof

30th April 2017

Spies?

WhatsApp

30th April 2017

Subscription has Expired

? Morrisons ?

30th April 2017

Steve Scott, your Morrisons
present is here

SunTrust

29th April 2017

Unusual activity detected In
Your SunTrust Account

Vulnerebility

Gnulib CVE-2017-7476 Local Heap Overflow Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98098

NetIQ Access Manager CVE-2017-5191 Cross Site Scripting Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98093

WordPress CopySafe Web Protection Plugin CVE-2017-8100 Cross Site Request Forgery Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98091

Zabbix Proxy Server CVE-2017-2825 Man in the Middle Security Bypass Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98094

SaltStack Salt CVE-2017-8109 Local Information Disclosure Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98095

FreeBSD CVE-2017-1081 Use After Free Denial of Service Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98089

Revive Adserver Multiple Security Vulnerabilities
2017-05-01
http://www.securityfocus.com/bid/83964

Zimbra Collaboration Suite CVE-2017-6813 Unspecified Privilege Escalation Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98087

Technicolor DPC3928SL CVE-2017-5135 SNMP Authentication Bypass Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98092

Zimbra Collaboration Suite CVE-2017-6821 Unspecified Security Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98090

HP Intelligent Management Center Multiple Unspecified Remote Code Execution Vulnerabilities
2017-05-01
http://www.securityfocus.com/bid/98088

Zimbra Collaboration Suite CVE-2017-7288 Unspecified HTML Injection Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98081

Avast! Antivirus CVE-2017-8307 Arbitrary File Deletion Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98086

Linux Kernel CVE-2017-7895 Multiple Security Bypass Vulnerabilities
2017-05-01
http://www.securityfocus.com/bid/98085

symetrie CVE-2017-7386 Cross Site Scripting Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98082

Zabbix CVE-2017-2824 Command Injection Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98083

Avast! Antivirus CVE-2017-8308 Security Bypass Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98084

McAfee Security Scan Plus CVE-2016-8026 Unspecified Local Command Execution Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98068

illumos CVE-2016-6561 Denial of Service Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98079

eXtplorer CVE-2016-4313 Local Directory Traversal Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98069

YARA 'yara_yyparse()' Function Denial of Service Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98080

YARA 'yy_get_next_buffer()' Function Denial of Service Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98077

YARA CVE-2017-5924 Denial of Service Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98075

Multiple IBM Products CVE-2016-9693 Unspecified Arbitrary File Download Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98074

YARA CVE-2016-10211 Denial of Service Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98078

LibreSSL CVE-2017-8301 Certificate Validation Security Bypass Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98076

Multiple IBM Products CVE-2016-9723 Cross Site Scripting Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98073

YARA CVE-2017-8294 Denial of Service Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98072

GNOME gnome-shell CVE-2017-8288 Lock Screen Local Security Bypass Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98070

Jenkins CVE-2017-1000355 Denial of Service Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98066HP Intelligent Management Center Multiple Unspecified Remote Code Execution Vulnerabilities
2017-05-01
http://www.securityfocus.com/bid/98088

Zimbra Collaboration Suite CVE-2017-7288 Unspecified HTML Injection Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98081

Avast! Antivirus CVE-2017-8307 Arbitrary File Deletion Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98086

Linux Kernel CVE-2017-7895 Multiple Security Bypass Vulnerabilities
2017-05-01
http://www.securityfocus.com/bid/98085

symetrie CVE-2017-7386 Cross Site Scripting Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98082

Zabbix CVE-2017-2824 Command Injection Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98083

Avast! Antivirus CVE-2017-8308 Security Bypass Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98084

McAfee Security Scan Plus CVE-2016-8026 Unspecified Local Command Execution Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98068

illumos CVE-2016-6561 Denial of Service Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98079

eXtplorer CVE-2016-4313 Local Directory Traversal Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98069

YARA 'yara_yyparse()' Function Denial of Service Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98080

YARA 'yy_get_next_buffer()' Function Denial of Service Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98077

YARA CVE-2017-5924 Denial of Service Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98075

Multiple IBM Products CVE-2016-9693 Unspecified Arbitrary File Download Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98074

YARA CVE-2016-10211 Denial of Service Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98078

LibreSSL CVE-2017-8301 Certificate Validation Security Bypass Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98076

Multiple IBM Products CVE-2016-9723 Cross Site Scripting Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98073

YARA CVE-2017-8294 Denial of Service Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98072

GNOME gnome-shell CVE-2017-8288 Lock Screen Local Security Bypass Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98070

Jenkins CVE-2017-1000355 Denial of Service Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98066

Squirrelmail CVE-2017-7692 Command Injection Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98067

GE Multiple Products CVE-2017-7905 Weak Password Security Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98063

dpkg CVE-2017-8283 Directory Traversal Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98064

Jenkins CVE-2017-1000354 User Impersonation Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98065

Jenkins CVE-2017-1000356 Multiple Cross Site Request Forgery Vulnerabilities
2017-05-01
http://www.securityfocus.com/bid/98062

Oracle E-Business Suite CVE-2017-3342 Remote Security Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98061

Oracle E-Business Suite CVE-2017-3356 Remote Security Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98058

Oracle E-Business Suite CVE-2017-3347 Remote Security Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98060

Oracle E-Business Suite CVE-2017-3355 Remote Security Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98059

Jenkins Java Deserialization CVE-2017-1000353 Remote Code Execution Vulnerability
2017-05-01
http://www.securityfocus.com/bid/98056

SANS News

 

Threatpost

Flickr Vulnerability Worth $7K Bounty to Researcher

Exploit

Panda Free Antivirus - 'PSKMAD.sys' Denial of Service

Emby MediaServer 3.2.5 - SQL Injection

Emby MediaServer 3.2.5 - Password Reset

Emby MediaServer 3.2.5 - Directory Traversal

IrfanView 4.44 - Denial of Service

30.4.2017

Bugtraq

[security bulletin] HPESBHF03738 rev.1 - HPE Intelligent Management Center (iMC) PLAT, Remote Code Execution 2017-04-28
security-alert hpe com

[SECURITY] [DSA 3838-1] ghostscript security update 2017-04-28
Salvatore Bonaccorso (carnil debian org)

Apple iOS 10.2 & 10.3 - Control Panel Denial of Service Vulnerability 2017-04-28
Vulnerability Lab (research vulnerability-lab com)

Live Helper Chat - Cross-Site Scripting 2017-04-28
Advisories (advisories compass-security com)

Malware

Trojan:PDF/Tetomek.A 

Phishing

WhatsApp

30th April 2017

Subscription has Expired

? Morrisons ?

30th April 2017

Steve Scott, your Morrisons
present is here

SunTrust

29th April 2017

Unusual activity detected In
Your SunTrust Account

spoof

29th April 2017

What did he hit?

CardApprovalUSA

28th April 2017

Open a new credit account

Vulnerebility

Avast! Antivirus CVE-2017-8307 Arbitrary File Deletion Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98086

Linux Kernel CVE-2017-7895 Multiple Security Bypass Vulnerabilities
2017-04-30
http://www.securityfocus.com/bid/98085

symetrie CVE-2017-7386 Cross Site Scripting Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98082

Zabbix CVE-2017-2824 Command Injection Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98083

Zimbra Collaboration Suite CVE-2017-7288 Unspecified HTML Injection Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98081

Avast! Antivirus CVE-2017-8308 Security Bypass Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98084

McAfee Security Scan Plus CVE-2016-8026 Unspecified Local Command Execution Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98068

illumos CVE-2016-6561 Denial of Service Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98079

eXtplorer CVE-2016-4313 Local Directory Traversal Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98069

YARA 'yara_yyparse()' Function Denial of Service Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98080

YARA 'yy_get_next_buffer()' Function Denial of Service Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98077

YARA CVE-2017-5924 Denial of Service Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98075

Multiple IBM Products CVE-2016-9693 Unspecified Arbitrary File Download Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98074

YARA CVE-2016-10211 Denial of Service Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98078

LibreSSL CVE-2017-8301 Certificate Validation Security Bypass Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98076

Multiple IBM Products CVE-2016-9723 Cross Site Scripting Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98073

YARA CVE-2017-8294 Denial of Service Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98072

GNOME gnome-shell CVE-2017-8288 Lock Screen Local Security Bypass Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98070

Jenkins CVE-2017-1000355 Denial of Service Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98066

Squirrelmail CVE-2017-7692 Command Injection Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98067

GE Multiple Products CVE-2017-7905 Weak Password Security Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98063

dpkg CVE-2017-8283 Directory Traversal Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98064

Jenkins CVE-2017-1000354 User Impersonation Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98065

Jenkins CVE-2017-1000356 Multiple Cross Site Request Forgery Vulnerabilities
2017-04-30
http://www.securityfocus.com/bid/98062

Oracle E-Business Suite CVE-2017-3342 Remote Security Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98061

Oracle E-Business Suite CVE-2017-3356 Remote Security Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98058

Oracle E-Business Suite CVE-2017-3347 Remote Security Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98060

Oracle E-Business Suite CVE-2017-3355 Remote Security Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98059

Jenkins Java Deserialization CVE-2017-1000353 Remote Code Execution Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98056

Mediawiki 'Parser::replaceInternalLinks2()' Method Cross-Site Scripting Vulnerability
2017-04-30
http://www.securityfocus.com/bid/98057Avast! Antivirus CVE-2017-8307 Arbitrary File Deletion Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98086

Linux Kernel CVE-2017-7895 Multiple Security Bypass Vulnerabilities
2017-04-29
http://www.securityfocus.com/bid/98085

symetrie CVE-2017-7386 Cross Site Scripting Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98082

Zabbix CVE-2017-2824 Command Injection Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98083

Zimbra Collaboration Suite CVE-2017-7288 Unspecified HTML Injection Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98081

Avast! Antivirus CVE-2017-8308 Security Bypass Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98084

McAfee Security Scan Plus CVE-2016-8026 Unspecified Local Command Execution Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98068

illumos CVE-2016-6561 Denial of Service Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98079

eXtplorer CVE-2016-4313 Local Directory Traversal Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98069

YARA 'yara_yyparse()' Function Denial of Service Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98080

YARA 'yy_get_next_buffer()' Function Denial of Service Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98077

YARA CVE-2017-5924 Denial of Service Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98075

Multiple IBM Products CVE-2016-9693 Unspecified Arbitrary File Download Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98074

YARA CVE-2016-10211 Denial of Service Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98078

LibreSSL CVE-2017-8301 Certificate Validation Security Bypass Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98076

Multiple IBM Products CVE-2016-9723 Cross Site Scripting Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98073

YARA CVE-2017-8294 Denial of Service Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98072

GNOME gnome-shell CVE-2017-8288 Lock Screen Local Security Bypass Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98070

Jenkins CVE-2017-1000355 Denial of Service Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98066

Squirrelmail CVE-2017-7692 Command Injection Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98067

GE Multiple Products CVE-2017-7905 Weak Password Security Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98063

dpkg CVE-2017-8283 Directory Traversal Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98064

Jenkins CVE-2017-1000354 User Impersonation Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98065

Jenkins CVE-2017-1000356 Multiple Cross Site Request Forgery Vulnerabilities
2017-04-29
http://www.securityfocus.com/bid/98062

Oracle E-Business Suite CVE-2017-3342 Remote Security Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98061

Oracle E-Business Suite CVE-2017-3356 Remote Security Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98058

Oracle E-Business Suite CVE-2017-3347 Remote Security Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98060

Oracle E-Business Suite CVE-2017-3355 Remote Security Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98059

Jenkins Java Deserialization CVE-2017-1000353 Remote Code Execution Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98056

Mediawiki 'Parser::replaceInternalLinks2()' Method Cross-Site Scripting Vulnerability
2017-04-29
http://www.securityfocus.com/bid/98057

SANS News

KNOW before NO

Threatpost

WikiLeaks Reveals CIA Tool ‘Scribbles’ For Document Tracking

Exploit

 

28.4.2017

Bugtraq

[security bulletin] HPESBHF03738 rev.1 - HPE Intelligent Management Center (iMC) PLAT, Remote Code Execution 2017-04-28
security-alert hpe com

[SECURITY] [DSA 3838-1] ghostscript security update 2017-04-28
Salvatore Bonaccorso (carnil debian org)

Apple iOS 10.2 & 10.3 - Control Panel Denial of Service Vulnerability 2017-04-28
Vulnerability Lab (research vulnerability-lab com)

Live Helper Chat - Cross-Site Scripting 2017-04-28
Advisories (advisories compass-security com)

[SECURITY] [DSA 3836-1] weechat security update 2017-04-27
Salvatore Bonaccorso (carnil debian org)

FreeBSD Security Advisory FreeBSD-SA-17:04.ipfilter 2017-04-27
FreeBSD Security Advisories (security-advisories freebsd org)

CVE-2017-3162: Apache Hadoop DataNode web UI vulnerability 2017-04-26
Chris Douglas (cdouglas apache org)

April 2017 - Confluence - Security Advisory 2017-04-26
David Black (dblack atlassian com)

[SECURITY] [DSA 3834-1] mysql-5.5 security update 2017-04-25
Salvatore Bonaccorso (carnil debian org)

Malware

Trojan:Win32/Emotet.K 

Phishing

PayPal

28th April 2017

Last Reminder: Your account
will be limited until we hear
from you.

Tesco Bank

27th April 2017

ALERT FROM TESCO BANK

spoof

26th April 2017

Okay I might try that.

CardApprovalUSA

26th April 2017

Open a new credit account

Vulnerebility

YARA 'yy_get_next_buffer()' Function Denial of Service Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98077

YARA CVE-2017-8294 Denial of Service Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98072

GNOME gnome-shell CVE-2017-8288 Lock Screen Local Security Bypass Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98070

Jenkins CVE-2017-1000355 Denial of Service Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98066

Squirrelmail CVE-2017-7692 Command Injection Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98067

GE Multiple Products CVE-2017-7905 Weak Password Security Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98063

dpkg CVE-2017-8283 Directory Traversal Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98064

Jenkins CVE-2017-1000354 User Impersonation Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98065

Jenkins CVE-2017-1000356 Multiple Cross Site Request Forgery Vulnerabilities
2017-04-28
http://www.securityfocus.com/bid/98062

Oracle E-Business Suite CVE-2017-3342 Remote Security Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98061

Oracle E-Business Suite CVE-2017-3356 Remote Security Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98058

Oracle E-Business Suite CVE-2017-3347 Remote Security Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98060

Oracle E-Business Suite CVE-2017-3355 Remote Security Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98059

Jenkins Java Deserialization CVE-2017-1000353 Remote Code Execution Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98056

Mediawiki 'Parser::replaceInternalLinks2()' Method Cross-Site Scripting Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98057

Mediawiki 'Special:MyPage/common.css' Cross-Site Scripting Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98053

HP NonStop Servers CVE-2017-5803 Information Disclosure Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98052

Oracle E-Business Suite CVE-2017-3345 Remote Security Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98055

Oracle E-Business Suite CVE-2017-3434 Remote Security Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98054

EMC ResourcePak Base CVE-2017-4982 Local Privilege Escalation Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98049

Fortinet FortiOS CVE-2017-3127 Cross Site Scripting Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98048

Mozilla Network Security Services CVE-2017-5461 Memory Corruption Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98050

OpenSSL CVE-2016-2177 Integer Overflow Vulnerability
2017-04-28
http://www.securityfocus.com/bid/91319

OpenSSL CVE-2016-2178 Side Channel Attack Information Disclosure Vulnerability
2017-04-28
http://www.securityfocus.com/bid/91081

Mozilla Firefox Multiple Security Vulnerabilities
2017-04-28
http://www.securityfocus.com/bid/97940

IrfanView CVE-2017-2813 Integer Overflow Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98046

EMC Data Domain OS CVE-2017-4983 Local Privilege Escalation Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98047

Revive Adserver Multiple Security Vulnerabilities
2017-04-28
http://www.securityfocus.com/bid/83964

Apache Struts CVE-2016-1182 Security Bypass Vulnerability
2017-04-28
http://www.securityfocus.com/bid/91067

Apache Struts CVE-2012-1007 Multiple Cross Site Scripting Vulnerabilities
2017-04-28
http://www.securityfocus.com/bid/51900Jenkins CVE-2017-1000356 Multiple Cross Site Request Forgery Vulnerabilities
2017-04-28
http://www.securityfocus.com/bid/98062

Oracle E-Business Suite CVE-2017-3342 Remote Security Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98061

Oracle E-Business Suite CVE-2017-3356 Remote Security Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98058

Oracle E-Business Suite CVE-2017-3347 Remote Security Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98060

Oracle E-Business Suite CVE-2017-3355 Remote Security Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98059

Jenkins Java Deserialization CVE-2017-1000353 Remote Code Execution Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98056

Mediawiki 'Parser::replaceInternalLinks2()' Method Cross-Site Scripting Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98057

Mediawiki 'Special:MyPage/common.css' Cross-Site Scripting Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98053

HP NonStop Servers CVE-2017-5803 Information Disclosure Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98052

Oracle E-Business Suite CVE-2017-3345 Remote Security Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98055

Oracle E-Business Suite CVE-2017-3434 Remote Security Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98054

EMC ResourcePak Base CVE-2017-4982 Local Privilege Escalation Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98049

Fortinet FortiOS CVE-2017-3127 Cross Site Scripting Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98048

Mozilla Network Security Services CVE-2017-5461 Memory Corruption Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98050

OpenSSL CVE-2016-2177 Integer Overflow Vulnerability
2017-04-28
http://www.securityfocus.com/bid/91319

OpenSSL CVE-2016-2178 Side Channel Attack Information Disclosure Vulnerability
2017-04-28
http://www.securityfocus.com/bid/91081

Mozilla Firefox Multiple Security Vulnerabilities
2017-04-28
http://www.securityfocus.com/bid/97940

IrfanView CVE-2017-2813 Integer Overflow Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98046

EMC Data Domain OS CVE-2017-4983 Local Privilege Escalation Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98047

Revive Adserver Multiple Security Vulnerabilities
2017-04-28
http://www.securityfocus.com/bid/83964

Apache Struts CVE-2016-1182 Security Bypass Vulnerability
2017-04-28
http://www.securityfocus.com/bid/91067

Apache Struts CVE-2012-1007 Multiple Cross Site Scripting Vulnerabilities
2017-04-28
http://www.securityfocus.com/bid/51900

Apache Struts ClassLoader Manipulation CVE-2014-0114 Security Bypass Vulnerability
2017-04-28
http://www.securityfocus.com/bid/67121

Apache Tomcat CVE-2016-0763 Security Bypass Vulnerability
2017-04-28
http://www.securityfocus.com/bid/83326

MyBB CVE-2017-8104 Directory Traversal Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98045

Apache Xerces-C CVE-2016-0729 Buffer Overflow Vulnerability
2017-04-28
http://www.securityfocus.com/bid/83423

OpenSSL CVE-2017-3731 Denial of Service Vulnerability
2017-04-28
http://www.securityfocus.com/bid/95813

OpenSSL 'crypto/asn1/a_d2i_fp.c' Local Denial of Service Vulnerability
2017-04-28
http://www.securityfocus.com/bid/87940

OpenSSL CVE-2016-2176 Information Disclosure Vulnerability
2017-04-28
http://www.securityfocus.com/bid/89746

OpenSSL CVE-2016-2105 Buffer Overflow Vulnerability
2017-04-28
http://www.securityfocus.com/bid/89757Oracle E-Business Suite CVE-2017-3355 Remote Security Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98059

Jenkins Java Deserialization CVE-2017-1000353 Remote Code Execution Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98056

Mediawiki 'Parser::replaceInternalLinks2()' Method Cross-Site Scripting Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98057

Mediawiki 'Special:MyPage/common.css' Cross-Site Scripting Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98053

HP NonStop Servers CVE-2017-5803 Information Disclosure Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98052

Oracle E-Business Suite CVE-2017-3345 Remote Security Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98055

Oracle E-Business Suite CVE-2017-3434 Remote Security Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98054

EMC ResourcePak Base CVE-2017-4982 Local Privilege Escalation Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98049

Fortinet FortiOS CVE-2017-3127 Cross Site Scripting Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98048

Mozilla Network Security Services CVE-2017-5461 Memory Corruption Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98050

OpenSSL CVE-2016-2177 Integer Overflow Vulnerability
2017-04-28
http://www.securityfocus.com/bid/91319

OpenSSL CVE-2016-2178 Side Channel Attack Information Disclosure Vulnerability
2017-04-28
http://www.securityfocus.com/bid/91081

Mozilla Firefox Multiple Security Vulnerabilities
2017-04-28
http://www.securityfocus.com/bid/97940

IrfanView CVE-2017-2813 Integer Overflow Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98046

EMC Data Domain OS CVE-2017-4983 Local Privilege Escalation Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98047

Revive Adserver Multiple Security Vulnerabilities
2017-04-28
http://www.securityfocus.com/bid/83964

Apache Struts CVE-2016-1182 Security Bypass Vulnerability
2017-04-28
http://www.securityfocus.com/bid/91067

Apache Struts CVE-2012-1007 Multiple Cross Site Scripting Vulnerabilities
2017-04-28
http://www.securityfocus.com/bid/51900

Apache Struts ClassLoader Manipulation CVE-2014-0114 Security Bypass Vulnerability
2017-04-28
http://www.securityfocus.com/bid/67121

Apache Tomcat CVE-2016-0763 Security Bypass Vulnerability
2017-04-28
http://www.securityfocus.com/bid/83326

MyBB CVE-2017-8104 Directory Traversal Vulnerability
2017-04-28
http://www.securityfocus.com/bid/98045

Apache Xerces-C CVE-2016-0729 Buffer Overflow Vulnerability
2017-04-28
http://www.securityfocus.com/bid/83423

OpenSSL CVE-2017-3731 Denial of Service Vulnerability
2017-04-28
http://www.securityfocus.com/bid/95813

OpenSSL 'crypto/asn1/a_d2i_fp.c' Local Denial of Service Vulnerability
2017-04-28
http://www.securityfocus.com/bid/87940

OpenSSL CVE-2016-2176 Information Disclosure Vulnerability
2017-04-28
http://www.securityfocus.com/bid/89746

OpenSSL CVE-2016-2105 Buffer Overflow Vulnerability
2017-04-28
http://www.securityfocus.com/bid/89757

OpenSSL CVE-2016-2106 Integer Overflow Vulnerability
2017-04-28
http://www.securityfocus.com/bid/89744

OpenSSL Padding Oracle Incomplete Fix Information Disclosure Vulnerability
2017-04-28
http://www.securityfocus.com/bid/89760

Apache Axis Incomplete Fix CVE-2014-3596 SSL Certificate Validation Security Bypass Vulnerability
2017-04-28
http://www.securityfocus.com/bid/69295

Apache Commons FileUpload CVE-2016-3092 Denial Of Service Vulnerability
2017-04-28
http://www.securityfocus.com/bid/91453

SANS News

Another Day, Another Obfuscation Technique

Threatpost

Attack Method Highlights Weaknesses in Microsoft CFG

The Time Has Arrived to Embrace Hackers


Chrome to Mark More HTTP Pages ‘Not Secure’

Lack of Communication Achilles’ Heel for Ransomware Fighters

ransomware-cyberespionage-dominate-verizon-dbir

Exploit

Mercurial - Custom hg-ssh Wrapper Remote Code Exec (Metasploit)

TYPO3 News Module - SQL Injection

Simple File Uploader - Arbitrary File Download

Easy File Uploader - Arbitrary File Upload

27.4.2017

Bugtraq

FreeBSD Security Advisory FreeBSD-SA-17:04.ipfilter 2017-04-27
FreeBSD Security Advisories (security-advisories freebsd org)

CVE-2017-3162: Apache Hadoop DataNode web UI vulnerability 2017-04-26
Chris Douglas (cdouglas apache org)

April 2017 - Confluence - Security Advisory 2017-04-26
David Black (dblack atlassian com)

[SECURITY] [DSA 3834-1] mysql-5.5 security update 2017-04-25
Salvatore Bonaccorso (carnil debian org)

Malware

Backdoor.Miskip

Trojan.Pidief.X

Infostealer.Lokibot

Linux.Shishiga

Phishing

spoof

26th April 2017

Okay I might try that.

CardApprovalUSA

26th April 2017

Open a new credit account

Federal Bureau of Investigatio

26th April 2017

Executive Director FBI

Vulnerebility

EMC ResourcePak Base CVE-2017-4982 Local Privilege Escalation Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98049

Fortinet FortiOS CVE-2017-3127 Cross Site Scripting Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98048

Mozilla Network Security Services CVE-2017-5461 Memory Corruption Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98050

OpenSSL CVE-2016-2177 Integer Overflow Vulnerability
2017-04-27
http://www.securityfocus.com/bid/91319

OpenSSL CVE-2016-2178 Side Channel Attack Information Disclosure Vulnerability
2017-04-27
http://www.securityfocus.com/bid/91081

Mozilla Firefox Multiple Security Vulnerabilities
2017-04-27
http://www.securityfocus.com/bid/97940

IrfanView CVE-2017-2813 Integer Overflow Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98046

EMC Data Domain OS CVE-2017-4983 Local Privilege Escalation Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98047

Revive Adserver Multiple Security Vulnerabilities
2017-04-27
http://www.securityfocus.com/bid/83964

Apache Struts CVE-2016-1182 Security Bypass Vulnerability
2017-04-27
http://www.securityfocus.com/bid/91067

Apache Struts CVE-2012-1007 Multiple Cross Site Scripting Vulnerabilities
2017-04-27
http://www.securityfocus.com/bid/51900

Apache Struts ClassLoader Manipulation CVE-2014-0114 Security Bypass Vulnerability
2017-04-27
http://www.securityfocus.com/bid/67121

Apache Tomcat CVE-2016-0763 Security Bypass Vulnerability
2017-04-27
http://www.securityfocus.com/bid/83326

MyBB CVE-2017-8104 Directory Traversal Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98045

Apache Xerces-C CVE-2016-0729 Buffer Overflow Vulnerability
2017-04-27
http://www.securityfocus.com/bid/83423

OpenSSL CVE-2017-3731 Denial of Service Vulnerability
2017-04-27
http://www.securityfocus.com/bid/95813

OpenSSL 'crypto/asn1/a_d2i_fp.c' Local Denial of Service Vulnerability
2017-04-27
http://www.securityfocus.com/bid/87940

OpenSSL CVE-2016-2176 Information Disclosure Vulnerability
2017-04-27
http://www.securityfocus.com/bid/89746

OpenSSL CVE-2016-2105 Buffer Overflow Vulnerability
2017-04-27
http://www.securityfocus.com/bid/89757

OpenSSL CVE-2016-2106 Integer Overflow Vulnerability
2017-04-27
http://www.securityfocus.com/bid/89744

OpenSSL Padding Oracle Incomplete Fix Information Disclosure Vulnerability
2017-04-27
http://www.securityfocus.com/bid/89760

Apache Axis Incomplete Fix CVE-2014-3596 SSL Certificate Validation Security Bypass Vulnerability
2017-04-27
http://www.securityfocus.com/bid/69295

Apache Commons FileUpload CVE-2016-3092 Denial Of Service Vulnerability
2017-04-27
http://www.securityfocus.com/bid/91453

cURL/libcURL CVE-2015-3236 Information Disclosure Vulnerability
2017-04-27
http://www.securityfocus.com/bid/75385

OpenSSL CVE-2016-7052 Denial of Service Vulnerability
2017-04-27
http://www.securityfocus.com/bid/93171

cURL/libcURL 'smb_request_state()' Function Security Vulnerability
2017-04-27
http://www.securityfocus.com/bid/75387

Apache Tomcat Security Manager CVE-2016-0706 Information Disclosure Vulnerability
2017-04-27
http://www.securityfocus.com/bid/83324

Apache Tomcat CVE-2015-5351 Cross Site Request Forgery Vulnerability
2017-04-27
http://www.securityfocus.com/bid/83330

Apache Struts CVE-2016-1181 Remote Code Execution Vulnerability
2017-04-27
http://www.securityfocus.com/bid/91068

Apache Tomcat Security Manager CVE-2016-0714 Remote Code Execution Vulnerability
2017-04-27
http://www.securityfocus.com/bid/83327OpenSSL CVE-2016-7052 Denial of Service Vulnerability
2017-04-27
http://www.securityfocus.com/bid/93171

cURL/libcURL 'smb_request_state()' Function Security Vulnerability
2017-04-27
http://www.securityfocus.com/bid/75387

Apache Tomcat Security Manager CVE-2016-0706 Information Disclosure Vulnerability
2017-04-27
http://www.securityfocus.com/bid/83324

Apache Tomcat CVE-2015-5351 Cross Site Request Forgery Vulnerability
2017-04-27
http://www.securityfocus.com/bid/83330

Apache Struts CVE-2016-1181 Remote Code Execution Vulnerability
2017-04-27
http://www.securityfocus.com/bid/91068

Apache Tomcat Security Manager CVE-2016-0714 Remote Code Execution Vulnerability
2017-04-27
http://www.securityfocus.com/bid/83327

ISC BIND CVE-2016-9444 Remote Denial of Service Vulnerability
2017-04-27
http://www.securityfocus.com/bid/95393

ISC BIND CVE-2016-9147 Remote Denial of Service Vulnerability
2017-04-27
http://www.securityfocus.com/bid/95390

ISC BIND CVE-2016-9131 Remote Denial of Service Vulnerability
2017-04-27
http://www.securityfocus.com/bid/95386

ISC BIND CVE-2016-8864 Remote Denial of Service Vulnerability
2017-04-27
http://www.securityfocus.com/bid/94067

OpenIDM CVE-2017-7590 HTML Injection Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98044

Linux Kernel CVE-2016-3672 ASLR Implementation Local Security Weakness
2017-04-27
http://www.securityfocus.com/bid/85884

Multiple RedHat JBoss Products CVE-2015-7501 Remote Code Execution Vulnerability
2017-04-27
http://www.securityfocus.com/bid/78215

ISC BIND 'buffer.c' Remote Denial of Service Vulnerability
2017-04-27
http://www.securityfocus.com/bid/93188

OpenSSL CVE-2016-6303 Integer Overflow Vulnerability
2017-04-27
http://www.securityfocus.com/bid/92984

Exponent CMS CVE-2017-8085 Cross Site Scripting Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98043

Pillow CVE-2016-3076 Heap Buffer Overflow Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98042

Vivaldi Installer CVE-2017-2156 DLL Loading Remote Code Execution Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98040

McAfee VirusScan Enterprise CVE-2016-8030 Memory Corruption Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98041

Lenovo System Update CVE-2015-8109 Local Privilege Escalation Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98039

OpenText Documentum Content Server CVE-2017-7221 Incomplete Fix Remote Code Execution Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98038

Lenovo System Update CVE-2015-8110 Local Privilege Escalation Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98037

BlackBerry Broadcom Wi-Fi Driver CVE-2016-2433 Arbitrary Code Execution Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98034

Sierra Wireless AirLink Raven ICSA-17-115-02 Multiple Security Vulnerabilities
2017-04-27
http://www.securityfocus.com/bid/98036

aescrypt gem CVE-2013-7463 Multiple Security Bypass Vulnerabilities
2017-04-27
http://www.securityfocus.com/bid/98035

BLF-Tech LLC VisualView HMI CVE-2017-6051 DLL Loading Local Code Execution Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98031

Hyundai Motor America Blue Link ICSA-17-115-03 Multiple Security Vulnerabilities
2017-04-27
http://www.securityfocus.com/bid/98033

Joomla! CVE-2017-8057 Multiple Full Path Information Disclosure Vulnerabilities
2017-04-27
http://www.securityfocus.com/bid/98028

OpenStack Keystone CVE-2017-2673 Security Bypass Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98032

Joomla! Core CVE-2017-7989 Arbitrary File Upload Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98029OpenText Documentum Content Server CVE-2017-7221 Incomplete Fix Remote Code Execution Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98038

Lenovo System Update CVE-2015-8110 Local Privilege Escalation Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98037

BlackBerry Broadcom Wi-Fi Driver CVE-2016-2433 Arbitrary Code Execution Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98034

Sierra Wireless AirLink Raven ICSA-17-115-02 Multiple Security Vulnerabilities
2017-04-27
http://www.securityfocus.com/bid/98036

aescrypt gem CVE-2013-7463 Multiple Security Bypass Vulnerabilities
2017-04-27
http://www.securityfocus.com/bid/98035

BLF-Tech LLC VisualView HMI CVE-2017-6051 DLL Loading Local Code Execution Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98031

Hyundai Motor America Blue Link ICSA-17-115-03 Multiple Security Vulnerabilities
2017-04-27
http://www.securityfocus.com/bid/98033

Joomla! CVE-2017-8057 Multiple Full Path Information Disclosure Vulnerabilities
2017-04-27
http://www.securityfocus.com/bid/98028

OpenStack Keystone CVE-2017-2673 Security Bypass Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98032

Joomla! Core CVE-2017-7989 Arbitrary File Upload Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98029

IBM License Metric Tool and IBM BigFix Inventory CVE-2016-8962 Weak Password Security Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98030

IBM WebSphere Commerce CVE-2017-1170 Local Session Hijacking Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98027

Google Nexus Qualcomm Sound Driver CVE-2017-0586 Information Disclosure Vulnerability
2017-04-27
http://www.securityfocus.com/bid/97357

Google Pixel Qualcomm Sound Codec Driver CVE-2016-10231 Privilege Escalation Vulnerability
2017-04-27
http://www.securityfocus.com/bid/97402

Apache Hadoop CVE-2017-3161 Cross Site Scripting Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98025

IBM Domino CVE-2017-1274 Stack Buffer Overflow Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98019

Multiple IBM Products CVE-2016-8924 Session Hijacking Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98023

IBM UrbanCode Deploy CVE-2017-1149 XML External Entity Injection Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98026

OpenSSL CVE-2016-2177 Integer Overflow Vulnerability
2017-04-27
http://www.securityfocus.com/bid/91319

Joomla! CVE-2017-7988 Security Bypass Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98022

Joomla! CVE-2017-7985 Cross Site Scripting Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98020

Joomla! CVE-2017-7986 Cross Site Scripting Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98024

Joomla! CVE-2017-7987 Cross Site Scripting Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98021

Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
2017-04-27
http://www.securityfocus.com/bid/96729

Apache Hadoop CVE-2017-3162 Input Validation Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98017

Joomla! CVE-2017-7984 Cross Site Scripting Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98018

Joomla! CVE-2017-7983 Information Disclosure Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98016

QEMU CVE-2017-8112 Denial of Service Vulnerability
2017-04-27
http://www.securityfocus.com/bid/98015

OpenSSL CVE-2017-3733 Denial of Service Vulnerability
2017-04-27
http://www.securityfocus.com/bid/96269

OpenSSL Padding Oracle Incomplete Fix Information Disclosure Vulnerability
2017-04-27
http://www.securityfocus.com/bid/89760

SANS News

BGP Hijacking: The Internet is Still/Again Broken

Threatpost

Auto Lender Exposes Loan Data For Up To 1 Million Applicants

Lack of Security Talent Afflicts Healthcare

Air Force Hopes To Attract Hackers With Bug Bounty Program

Exploit

Microsoft Internet Explorer 11.576.14393.0 -...

Revive Ad Server 4.0.1 - Cross-Site Scripting / Cross-Site Request Forgery

Mercurial - Custom hg-ssh Wrapper Remote Code Exec (Metasploit)

TYPO3 News Module - SQL Injection

Revive Ad Server 4.0.1 - Cross-Site Scripting / Cross-Site Request Forgery

26.4.2017

Bugtraq

CVE-2017-3162: Apache Hadoop DataNode web UI vulnerability 2017-04-26
Chris Douglas (cdouglas apache org)

April 2017 - Confluence - Security Advisory 2017-04-26
David Black (dblack atlassian com)

[SECURITY] [DSA 3834-1] mysql-5.5 security update 2017-04-25
Salvatore Bonaccorso (carnil debian org)

[slackware-security] mozilla-firefox (SSA:2017-114-01) 2017-04-24
Slackware Security Team (security slackware com)

[SECURITY] [DSA 3833-1] libav security update 2017-04-24
Moritz Muehlenhoff (jmm debian org)

KL-001-2017-009 : Solarwinds LEM Database Listener with Hardcoded Credentials 2017-04-24
KoreLogic Disclosures (disclosures korelogic com)

KL-001-2017-008 : Solarwinds LEM Management Shell Arbitrary File Read 2017-04-24
KoreLogic Disclosures (disclosures korelogic com)

KL-001-2017-007 : Solarwinds LEM Management Shell Escape via Command Injection 2017-04-24
KoreLogic Disclosures (disclosures korelogic com)

KL-001-2017-006 : Solarwinds LEM Privilege Escalation via Sudo Script Abuse 2017-04-24
KoreLogic Disclosures (disclosures korelogic com)

KL-001-2017-005 : Solarwinds LEM Privilege Escalation via Controlled Sudo Path 2017-04-24
KoreLogic Disclosures (disclosures korelogic com)

Malware

 

Phishing

Federal Bureau of Investigatio

26th April 2017

Executive Director FBI

Chase

24th April 2017

Chase Bank Online Access
Limitation!

NatWest CreditCard

24th April 2017

You Have One Security Message
From NatWest CreditCard

test@gamblingsale.ru test@gamb

24th April 2017

Unsuccessful login attempts

Vulnerebility

OpenSSL CVE-2016-2177 Integer Overflow Vulnerability
2017-04-26
http://www.securityfocus.com/bid/91319

Joomla! CVE-2017-7987 Cross Site Scripting Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98021

Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
2017-04-26
http://www.securityfocus.com/bid/96729

Apache Hadoop CVE-2017-3162 Input Validation Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98017

Joomla! CVE-2017-7984 Cross Site Scripting Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98018

Joomla! CVE-2017-7983 Information Disclosure Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98016

QEMU CVE-2017-8112 Denial of Service Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98015

OpenSSL CVE-2017-3733 Denial of Service Vulnerability
2017-04-26
http://www.securityfocus.com/bid/96269

OpenSSL Padding Oracle Incomplete Fix Information Disclosure Vulnerability
2017-04-26
http://www.securityfocus.com/bid/89760

HP OpenCall Media Platform Multiple Cross Site Scripting and Remote File Include Vulnerabilities
2017-04-26
http://www.securityfocus.com/bid/98013

Linux Kernel CVE-2017-7477 Heap Buffer Overflow Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98014

QEMU CVE-2017-8086 Denial of Service Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98012

RETIRED: Oracle Primavera Products CVE-2017-3508 Remote Security Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97889

Oracle MySQL Connectors CVE-2017-3523 Remote Security Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97982

QuickHeal CVE-2015-8285 Denial of Service Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97996

Linux Kernel 'drivers/net/usb/catc.c' Local Denial of Service Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98011

Linux Kernel CVE-2007-6761 Local Information Disclosure Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98001

Google Android CVE-2016-0833 Unspecified Denial of Service Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98009

Linux Kernel 'drivers/hid/hid-cp2112.c' Local Denial of Service Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98010

Linux Kernel 'drivers/net/usb/rtl8150.c' Local Denial of Service Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98008

Opera Web Browser CVE-2016-4075 Address Bar Spoofing Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98004

Trend Micro OfficeScan Multiple Privilege Escalation and Cross Site Scripting Vulnerabilities
2017-04-26
http://www.securityfocus.com/bid/98007

Multiple IBM Products CVE-2015-0104 Unspecified Remote Code Execution Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97999

Portrait Displays SDK CVE-2017-3210 Local Privilege Escalation Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98006

IBM Cúram Social Program Management CVE-2016-9980 Unspecified Cross Site Scripting Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98005

Adobe Flex BlazeDS CVE-2017-3066 Remote Code Execution Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98003

Multiple IBM Products CVE-2015-0107 Directory Traversal Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97998

Linux Kernel 'drivers/net/usb/pegasus.c' Local Denial of Service Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98000

Adobe ColdFusion CVE-2017-3008 Unspecified Cross Site Scripting Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98002

Google Nexus Qualcomm Crypto Engine Driver CVE-2016-10230 Remote Code Execution Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97400RETIRED: Oracle Primavera Products CVE-2017-3508 Remote Security Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97889

Oracle MySQL Connectors CVE-2017-3523 Remote Security Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97982

QuickHeal CVE-2015-8285 Denial of Service Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97996

Linux Kernel 'drivers/net/usb/catc.c' Local Denial of Service Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98011

Linux Kernel CVE-2007-6761 Local Information Disclosure Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98001

Google Android CVE-2016-0833 Unspecified Denial of Service Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98009

Linux Kernel 'drivers/hid/hid-cp2112.c' Local Denial of Service Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98010

Linux Kernel 'drivers/net/usb/rtl8150.c' Local Denial of Service Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98008

Opera Web Browser CVE-2016-4075 Address Bar Spoofing Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98004

Trend Micro OfficeScan Multiple Privilege Escalation and Cross Site Scripting Vulnerabilities
2017-04-26
http://www.securityfocus.com/bid/98007

Multiple IBM Products CVE-2015-0104 Unspecified Remote Code Execution Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97999

Portrait Displays SDK CVE-2017-3210 Local Privilege Escalation Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98006

IBM Cúram Social Program Management CVE-2016-9980 Unspecified Cross Site Scripting Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98005

Adobe Flex BlazeDS CVE-2017-3066 Remote Code Execution Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98003

Multiple IBM Products CVE-2015-0107 Directory Traversal Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97998

Linux Kernel 'drivers/net/usb/pegasus.c' Local Denial of Service Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98000

Adobe ColdFusion CVE-2017-3008 Unspecified Cross Site Scripting Vulnerability
2017-04-26
http://www.securityfocus.com/bid/98002

Google Nexus Qualcomm Crypto Engine Driver CVE-2016-10230 Remote Code Execution Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97400

IBM Security Guardium CVE-2017-1122 Local Command Injection Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97995

Linux Kernel CVE-2017-8066 Local Denial of Service Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97992

Linux Kernel 'drivers/char/virtio_console.c' Local Denial of Service Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97997

Linux Kernel 'crypto/ccm.c' Local Denial of Service Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97994

Linux Kernel 'drivers/hid/hid-cp2112.c' Local Denial of Service Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97991

IBM Cúram Social Program Management CVE-2016-9979 Unspecified Cross Site Scripting Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97993

Palo Alto Networks PAN-OS CVE-2017-7216 Information Disclosure Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97590

IBM Curam Social Program Management CVE-2016-9978 Information Disclosure Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97990

Google Chrome Prior to 50.0.2661.94 Multiple Security Vulnerabilities
2017-04-26
http://www.securityfocus.com/bid/89106

IBM Curam Social Program Management CVE-2016-8923 Information Disclosure Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97989

Google Chrome Prior to 57.0.2987.98 Multiple Security Vulnerabilities
2017-04-26
http://www.securityfocus.com/bid/96767

Red Hat OpenShift Enterprise CVE-2016-5409 Information Disclosure Vulnerability
2017-04-26
http://www.securityfocus.com/bid/97988

SANS News

If there are some unexploited MSSQL Servers With Weak Passwords Left: They got you now (again)

Threatpost

Zimperium Acquisition Program Publishes Exploits for Patched Android Bugs

ColdFusion Hotfix Resolves XSS, Java Deserialization Bugs

xDedic Market Spilling Over With School Servers, PCs

Atlassian Resets HipChat Passwords Following Breach

Exploit

Microsoft Windows 2003 SP2 - 'ERRATICGOPHER' SMB Remote Code Execution

Microsoft Office Word - Malicious Hta Execution (Metasploit)

Apple Safari - Array concat Memory Corruption

WePresent WiPG-1000 - Command Injection (Metasploit)

FlySpray 1.0-rc4 - Cross-Site Scripting / Cross-Site Request Forgery

WordPress Plugin KittyCatfish 2.2 - SQL Injection

Realtek Audio Driver 6.0.1.7898 (Windows 10) - Dolby Audio X2 Service Privilege...

PrivateTunnel Client 2.8 - Local Buffer Overflow (SEH)

Oracle VirtualBox Guest Additions 5.1.18 - Unprivileged Windows User-Mode Guest...

25.4.2017

Bugtraq

[slackware-security] mozilla-firefox (SSA:2017-114-01) 2017-04-24
Slackware Security Team (security slackware com)

[SECURITY] [DSA 3833-1] libav security update 2017-04-24
Moritz Muehlenhoff (jmm debian org)

KL-001-2017-009 : Solarwinds LEM Database Listener with Hardcoded Credentials 2017-04-24
KoreLogic Disclosures (disclosures korelogic com)

KL-001-2017-008 : Solarwinds LEM Management Shell Arbitrary File Read 2017-04-24
KoreLogic Disclosures (disclosures korelogic com)

KL-001-2017-007 : Solarwinds LEM Management Shell Escape via Command Injection 2017-04-24
KoreLogic Disclosures (disclosures korelogic com)

KL-001-2017-006 : Solarwinds LEM Privilege Escalation via Sudo Script Abuse 2017-04-24
KoreLogic Disclosures (disclosures korelogic com)

KL-001-2017-005 : Solarwinds LEM Privilege Escalation via Controlled Sudo Path 2017-04-24
KoreLogic Disclosures (disclosures korelogic com)

CVE-2017-7221. OpenText Documentum Content Server: arbitrary code execution in dm_bp_transition.ebs docbase method 2017-04-24
Andrey B. Panfilov (andrew panfilov tel)

Re: CVE-2017-7692: Squirrelmail 1.4.22 Remote Code Execution 2017-04-23
Dawid Golunski (dawid legalhackers com)

[slackware-security] ntp (SSA:2017-112-02) 2017-04-22
Slackware Security Team (security slackware com)

Malware

 

Phishing

Chase

24th April 2017

Chase Bank Online Access
Limitation!

NatWest CreditCard

24th April 2017

You Have One Security Message
From NatWest CreditCard

Vulnerebility

Adobe Flex BlazeDS CVE-2017-3066 Remote Code Execution Vulnerability
2017-04-25
http://www.securityfocus.com/bid/98003

Multiple IBM Products CVE-2015-0107 Directory Traversal Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97998

Linux Kernel 'drivers/net/usb/pegasus.c' Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/98000

Adobe ColdFusion CVE-2017-3008 Unspecified Cross Site Scripting Vulnerability
2017-04-25
http://www.securityfocus.com/bid/98002

Google Nexus Qualcomm Crypto Engine Driver CVE-2016-10230 Remote Code Execution Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97400

IBM Security Guardium CVE-2017-1122 Local Command Injection Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97995

Linux Kernel CVE-2017-8066 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97992

Linux Kernel 'drivers/char/virtio_console.c' Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97997

Linux Kernel 'crypto/ccm.c' Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97994

Linux Kernel 'drivers/hid/hid-cp2112.c' Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97991

IBM Cúram Social Program Management CVE-2016-9979 Unspecified Cross Site Scripting Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97993

Palo Alto Networks PAN-OS CVE-2017-7216 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97590

IBM Curam Social Program Management CVE-2016-9978 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97990

Google Chrome Prior to 50.0.2661.94 Multiple Security Vulnerabilities
2017-04-25
http://www.securityfocus.com/bid/89106

IBM Curam Social Program Management CVE-2016-8923 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97989

Google Chrome Prior to 57.0.2987.98 Multiple Security Vulnerabilities
2017-04-25
http://www.securityfocus.com/bid/96767

Red Hat OpenShift Enterprise CVE-2016-5409 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97988

WeeChat CVE-2017-8073 Buffer Overflow Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97987

pcs CVE-2016-0720 Cross Site Request Forgery Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97984

Linux Kernel CVE-2010-5329 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97986

TP-Link TL-SG108E CVE-2017-8078 Security Bypass Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97985

TP-Link TL-SG108E CVE-2017-8075 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97983

TP-Link TL-SG108E CVE-2017-8074 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97981

Oracle MySQL Connectors CVE-2017-3586 Remote Security Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97982

podofo CVE-2017-7994 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97980

Shopware CVE-2016-3109 Arbitrary Code Execution Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97979

XOOPS CVE-2017-7944 Cross Site Scripting Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97978

pcs daemon CVE-2016-0721 Session Fixation Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97977

Linux Kernel CVE-2017-8064 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97975

NTP CVE-2016-7427 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/94447Google Nexus Qualcomm Crypto Engine Driver CVE-2016-10230 Remote Code Execution Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97400

IBM Security Guardium CVE-2017-1122 Local Command Injection Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97995

Linux Kernel CVE-2017-8066 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97992

Linux Kernel 'drivers/char/virtio_console.c' Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97997

Linux Kernel 'crypto/ccm.c' Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97994

Linux Kernel 'drivers/hid/hid-cp2112.c' Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97991

IBM Cúram Social Program Management CVE-2016-9979 Unspecified Cross Site Scripting Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97993

Palo Alto Networks PAN-OS CVE-2017-7216 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97590

IBM Curam Social Program Management CVE-2016-9978 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97990

Google Chrome Prior to 50.0.2661.94 Multiple Security Vulnerabilities
2017-04-25
http://www.securityfocus.com/bid/89106

IBM Curam Social Program Management CVE-2016-8923 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97989

Google Chrome Prior to 57.0.2987.98 Multiple Security Vulnerabilities
2017-04-25
http://www.securityfocus.com/bid/96767

Red Hat OpenShift Enterprise CVE-2016-5409 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97988

WeeChat CVE-2017-8073 Buffer Overflow Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97987

pcs CVE-2016-0720 Cross Site Request Forgery Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97984

Linux Kernel CVE-2010-5329 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97986

TP-Link TL-SG108E CVE-2017-8078 Security Bypass Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97985

TP-Link TL-SG108E CVE-2017-8075 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97983

TP-Link TL-SG108E CVE-2017-8074 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97981

Oracle MySQL Connectors CVE-2017-3586 Remote Security Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97982

podofo CVE-2017-7994 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97980

Shopware CVE-2016-3109 Arbitrary Code Execution Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97979

XOOPS CVE-2017-7944 Cross Site Scripting Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97978

pcs daemon CVE-2016-0721 Session Fixation Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97977

Linux Kernel CVE-2017-8064 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97975

NTP CVE-2016-7427 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/94447

NTP CVE-2016-7429 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/94453

NTP CVE-2015-8158 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/81814

NTP CVE-2015-8138 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/81811

Linux Kernel CVE-2017-8062 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97973
Palo Alto Networks PAN-OS CVE-2017-7216 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97590

Google Chrome Prior to 50.0.2661.94 Multiple Security Vulnerabilities
2017-04-25
http://www.securityfocus.com/bid/89106

Google Chrome Prior to 57.0.2987.98 Multiple Security Vulnerabilities
2017-04-25
http://www.securityfocus.com/bid/96767

Red Hat OpenShift Enterprise CVE-2016-5409 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97988

WeeChat CVE-2017-8073 Buffer Overflow Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97987

pcs CVE-2016-0720 Cross Site Request Forgery Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97984

Linux Kernel CVE-2010-5329 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97986

TP-Link TL-SG108E CVE-2017-8078 Security Bypass Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97985

TP-Link TL-SG108E CVE-2017-8075 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97983

TP-Link TL-SG108E CVE-2017-8074 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97981

Oracle MySQL Connectors CVE-2017-3586 Remote Security Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97982

podofo CVE-2017-7994 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97980

Shopware CVE-2016-3109 Arbitrary Code Execution Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97979

XOOPS CVE-2017-7944 Cross Site Scripting Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97978

pcs daemon CVE-2016-0721 Session Fixation Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97977

Linux Kernel CVE-2017-8064 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97975

NTP CVE-2016-7427 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/94447

NTP CVE-2016-7429 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/94453

NTP CVE-2015-8158 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/81814

NTP CVE-2015-8138 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/81811

Linux Kernel CVE-2017-8062 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97973

NTP CVE-2016-7431 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/94454

Linux Kernel CVE-2017-8063 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97974

NTP CVE-2015-7979 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/81816

Cybozu Kintone App CVE-2016-1186 SSL Certificate Validation Security Bypass Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97976

NTP CVE-2015-7973 Security Bypass Vulnerability
2017-04-25
http://www.securityfocus.com/bid/81963

Linux Kernel CVE-2017-8061 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97972

QEMU 'hw/9pfs/9p-local.c' Privilege Escalation Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97970

NTP CVE-2016-9310 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/94452

Linux Kernel CVE-2017-7979 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97969TP-Link TL-SG108E CVE-2017-8078 Security Bypass Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97985

TP-Link TL-SG108E CVE-2017-8075 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97983

TP-Link TL-SG108E CVE-2017-8074 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97981

Oracle MySQL Connectors CVE-2017-3586 Remote Security Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97982

podofo CVE-2017-7994 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97980

Shopware CVE-2016-3109 Arbitrary Code Execution Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97979

XOOPS CVE-2017-7944 Cross Site Scripting Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97978

pcs daemon CVE-2016-0721 Session Fixation Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97977

Linux Kernel CVE-2017-8064 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97975

NTP CVE-2016-7427 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/94447

NTP CVE-2016-7429 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/94453

NTP CVE-2015-8158 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/81814

NTP CVE-2015-8138 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/81811

Linux Kernel CVE-2017-8062 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97973

NTP CVE-2016-7431 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/94454

Linux Kernel CVE-2017-8063 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97974

NTP CVE-2015-7979 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/81816

Cybozu Kintone App CVE-2016-1186 SSL Certificate Validation Security Bypass Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97976

NTP CVE-2015-7973 Security Bypass Vulnerability
2017-04-25
http://www.securityfocus.com/bid/81963

Linux Kernel CVE-2017-8061 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97972

QEMU 'hw/9pfs/9p-local.c' Privilege Escalation Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97970

NTP CVE-2016-9310 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/94452

Linux Kernel CVE-2017-7979 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97969

Apache ActiveMQ CVE-2015-7559 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97967

Perl YAML-LibYAML Module 'perl_libyaml.c' Multiple Format String Vulnerabilities
2017-04-25
http://www.securityfocus.com/bid/52381

Minicom CVE-2017-7467 Local Buffer Overflow Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97966

NTP CVE-2016-9311 NULL Pointer Dereference Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/94444

Novell NetIQ Access Manager CVE-2017-5190 Remote Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97965

Apache CXF CVE-2017-5656 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97971

Apache CXF CVE-2017-5653 Spoofing Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97968Shopware CVE-2016-3109 Arbitrary Code Execution Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97979

XOOPS CVE-2017-7944 Cross Site Scripting Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97978

pcs daemon CVE-2016-0721 Session Fixation Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97977

Linux Kernel CVE-2017-8064 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97975

NTP CVE-2016-7427 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/94447

NTP CVE-2016-7429 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/94453

NTP CVE-2015-8158 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/81814

NTP CVE-2015-8138 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/81811

Linux Kernel CVE-2017-8062 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97973

NTP CVE-2016-7431 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/94454

Linux Kernel CVE-2017-8063 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97974

NTP CVE-2015-7979 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/81816

Cybozu Kintone App CVE-2016-1186 SSL Certificate Validation Security Bypass Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97976

NTP CVE-2015-7973 Security Bypass Vulnerability
2017-04-25
http://www.securityfocus.com/bid/81963

Linux Kernel CVE-2017-8061 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97972

QEMU 'hw/9pfs/9p-local.c' Privilege Escalation Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97970

NTP CVE-2016-9310 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/94452

Linux Kernel CVE-2017-7979 Local Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97969

Apache ActiveMQ CVE-2015-7559 Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97967

Perl YAML-LibYAML Module 'perl_libyaml.c' Multiple Format String Vulnerabilities
2017-04-25
http://www.securityfocus.com/bid/52381

Minicom CVE-2017-7467 Local Buffer Overflow Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97966

NTP CVE-2016-9311 NULL Pointer Dereference Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/94444

Novell NetIQ Access Manager CVE-2017-5190 Remote Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97965

Apache CXF CVE-2017-5656 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97971

Apache CXF CVE-2017-5653 Spoofing Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97968

infinispan CVE-2017-2638 Authentication Bypass Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97964

cURL/libcURL CVE-2017-7468 Remote Security Bypass Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97962

libbpg 'image_alloc()' Function Null Pointer Dereference Denial of Service Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97963

Atlassian Confluence CVE-2017-7415 Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97961

MySQL-GUI-tools CVE-2010-4178 Local Information Disclosure Vulnerability
2017-04-25
http://www.securityfocus.com/bid/97960

SANS News

Analysis of the Shadow Z118 PayPal phishing site

CAA Records and Certificate Issuance

Threatpost

Hard Target: Fileless Malware

Hyundai Patches Leaky Blue Link Mobile App

No Fix for SquirrelMail Remote Code Execution Vulnerability

Locky Ransomware Roars Back to Life Via Necurs Botnet

Original XPan Ransomware Returns, Targets Brazilian SMBs

Exploit

FlySpray 1.0-rc4 - Cross-Site Scripting / Cross-Site Request Forgery

WordPress Plugin KittyCatfish 2.2 - SQL Injection

WordPress Plugin Car Rental System 2.5 - SQL Injection

WordPress Plugin Wow Viral Signups 2.1 - SQL Injection

WordPress Plugin Wow Forms 2.1 - SQL Injection

Oracle PeopleSoft - 'PeopleSoftServiceListeningConnector' XML External Entity via...

Oracle E-Business Suite 12.2.3 - 'IESFOOTPRINT' SQL Injection

HPE OpenCall Media Platform (OCMP) 4.3.2 - Cross-Site Scripting / Remote File Inclusion

Easy MOV Converter 1.4.24 - Local Buffer Overflow (SEH)

PrivateTunnel Client 2.8 - Local Buffer Overflow (SEH)

Dell Customer Connect 1.3.28.0 - Privilege Escalation

24.4.2017

Bugtraq

 

Malware

 

Phishing

PayPal

23rd April 2017

Your account will be limited.

Tesco Bank

21st April 2017

Urgent Message From Tesco
Secure

Chase

21st April 2017

New Notification from Chase

Dropbox team

20th April 2017

One Attached Document Via
Dropbox

Vulnerebility

Perl YAML-LibYAML Module 'perl_libyaml.c' Multiple Format String Vulnerabilities
2017-04-24
http://www.securityfocus.com/bid/52381

NTP CVE-2016-9311 NULL Pointer Dereference Denial of Service Vulnerability
2017-04-24
http://www.securityfocus.com/bid/94444

Novell NetIQ Access Manager CVE-2017-5190 Remote Information Disclosure Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97965

Apache CXF CVE-2017-5656 Information Disclosure Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97971

Apache CXF CVE-2017-5653 Spoofing Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97968

infinispan CVE-2017-2638 Authentication Bypass Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97964

cURL/libcURL CVE-2017-7468 Remote Security Bypass Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97962

libbpg 'image_alloc()' Function Null Pointer Dereference Denial of Service Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97963

Atlassian Confluence CVE-2017-7415 Information Disclosure Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97961

MySQL-GUI-tools CVE-2010-4178 Local Information Disclosure Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97960

MySQL-GUI-tools CVE-2010-4177 Local Information Disclosure Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97959

Google Chrome Prior to 58.0.3029.81 Multiple Security Vulnerabilities
2017-04-24
http://www.securityfocus.com/bid/97939

Multiple McAfee Products CVE-2017-4028 Local Code Injection Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97958

QEMU 'hw/display/cirrus_vga_rop.h' Multiple Memory Corruption Vulnerabilities
2017-04-24
http://www.securityfocus.com/bid/97957

ImageMagick CVE-2017-7943 Denial of Service Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97956

Mozilla Firefox Multiple Security Vulnerabilities
2017-04-24
http://www.securityfocus.com/bid/97940

Pexip Infinity CVE-2017-6551 Remote Code Execution Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97954

Qemu 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97955

Palo Alto Networks PAN-OS CVE-2017-7409 Cross Site Scripting Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97953

Nessus CVE-2017-7850 Local Privilege Escalation Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97952

OpenSSL CVE-2017-3731 Denial of Service Vulnerability
2017-04-24
http://www.securityfocus.com/bid/95813

OpenSSL CVE-2015-1789 Out of Bounds Read Denial of Service Vulnerability
2017-04-24
http://www.securityfocus.com/bid/75156

OpenSSL CVE-2015-1788 Denial of Service Vulnerability
2017-04-24
http://www.securityfocus.com/bid/75158

OpenSSL CVE-2015-3195 Information Disclosure Vulnerability
2017-04-24
http://www.securityfocus.com/bid/78626

OpenSSL 'ASN1_TYPE_cmp()' Function Denial of Service Vulnerability
2017-04-24
http://www.securityfocus.com/bid/73225

OpenSSL 'dtls1_get_record()' Function NULL Pointer Dereference Denial of Service Vulnerability
2017-04-24
http://www.securityfocus.com/bid/71937

FreeBSD CVE-2013-5209 Information Disclosure Vulnerability
2017-04-24
http://www.securityfocus.com/bid/61939

Dropbear SSH Server Use After Free Remote Code Execution Vulnerability
2017-04-24
http://www.securityfocus.com/bid/52159

OpenSSL CVE-2015-0204 Man in the Middle Security Bypass Vulnerability
2017-04-24
http://www.securityfocus.com/bid/71936

Multiple Oracle Products CVE-2016-0635 Remote Security Vulnerability
2017-04-24
http://www.securityfocus.com/bid/91869
Multiple McAfee Products CVE-2017-4028 Local Code Injection Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97958

QEMU 'hw/display/cirrus_vga_rop.h' Multiple Memory Corruption Vulnerabilities
2017-04-24
http://www.securityfocus.com/bid/97957

ImageMagick CVE-2017-7943 Denial of Service Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97956

Mozilla Firefox Multiple Security Vulnerabilities
2017-04-24
http://www.securityfocus.com/bid/97940

Pexip Infinity CVE-2017-6551 Remote Code Execution Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97954

Qemu 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97955

Palo Alto Networks PAN-OS CVE-2017-7409 Cross Site Scripting Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97953

Nessus CVE-2017-7850 Local Privilege Escalation Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97952

OpenSSL CVE-2017-3731 Denial of Service Vulnerability
2017-04-24
http://www.securityfocus.com/bid/95813

OpenSSL CVE-2015-1789 Out of Bounds Read Denial of Service Vulnerability
2017-04-24
http://www.securityfocus.com/bid/75156

OpenSSL CVE-2015-1788 Denial of Service Vulnerability
2017-04-24
http://www.securityfocus.com/bid/75158

OpenSSL CVE-2015-3195 Information Disclosure Vulnerability
2017-04-24
http://www.securityfocus.com/bid/78626

OpenSSL 'ASN1_TYPE_cmp()' Function Denial of Service Vulnerability
2017-04-24
http://www.securityfocus.com/bid/73225

OpenSSL 'dtls1_get_record()' Function NULL Pointer Dereference Denial of Service Vulnerability
2017-04-24
http://www.securityfocus.com/bid/71937

FreeBSD CVE-2013-5209 Information Disclosure Vulnerability
2017-04-24
http://www.securityfocus.com/bid/61939

Dropbear SSH Server Use After Free Remote Code Execution Vulnerability
2017-04-24
http://www.securityfocus.com/bid/52159

OpenSSL CVE-2015-0204 Man in the Middle Security Bypass Vulnerability
2017-04-24
http://www.securityfocus.com/bid/71936

Multiple Oracle Products CVE-2016-0635 Remote Security Vulnerability
2017-04-24
http://www.securityfocus.com/bid/91869

OpenSSL CVE-2017-3732 Information Disclosure Vulnerability
2017-04-24
http://www.securityfocus.com/bid/95814

Nessus CVE-2017-7849 Local Denial of Service Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97951

Apache Batik CVE-2017-5662 XML External Entity Information Disclosure Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97948

Linux Kernel CVE-2017-7645 Multiple Denial of Service Vulnerabilities
2017-04-24
http://www.securityfocus.com/bid/97950

Apache Traffic Server CVE-2017-5659 Denial of Service Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97949

Apache Traffic Server CVE-2016-5396 Denial of Service Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97945

LibYAML and Perl YAML-LibYAML Module 'scanner.c' Remote Denial of Service Vulnerability
2017-04-24
http://www.securityfocus.com/bid/71349

LibYAML 'yaml_parser_scan_uri_escapes()' Function Remote Heap Based Buffer Overflow Vulnerability
2017-04-24
http://www.securityfocus.com/bid/66478

LibYAML 'scanner.c' Remote Heap Based Buffer Overflow Vulnerability
2017-04-24
http://www.securityfocus.com/bid/65258

ImageMagick CVE-2017-7942 Denial of Service Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97946

ImageMagick CVE-2017-7941 Denial of Service Vulnerability
2017-04-24
http://www.securityfocus.com/bid/97944

Splunk Enterprise and Lite Multiple Cross Site Scripting Vulnerabilities
2017-04-24
http://www.securityfocus.com/bid/97942

SANS News

Malicious Documents: A Bit Of News

Threatpost

SMSVova Spyware Hiding in ‘System Update’ App Ejected From Google Play Store

Exploit

SquirrelMail < 1.4.22 - Remote Code Execution

23.4.2017

Bugtraq

CVE-2017-7192: Starscream library before 2.0.4 allows SSL pinning bypass 2017-04-21
Security Advisories (security advisories centralway com)

[SECURITY] [DSA 3831-1] firefox-esr security update 2017-04-19
Moritz Muehlenhoff (jmm debian org)

[HITB-Announce] HITB GSEC 2017 CFP Closes April 30th 2017-04-19
Hafez Kamal (aphesz hackinthebox org)

October CMS v1.0.412 several vulnerabilities 2017-04-19
Anti Räis (antirais gmail com)

Malware

Trojan.Lodarat

Backdoor.Doublepulsar

Phishing

 

Vulnerebility

Multiple McAfee Products CVE-2017-4028 Local Code Injection Vulnerability
2017-04-23
http://www.securityfocus.com/bid/97958

QEMU 'hw/display/cirrus_vga_rop.h' Multiple Memory Corruption Vulnerabilities
2017-04-23
http://www.securityfocus.com/bid/97957

ImageMagick CVE-2017-7943 Denial of Service Vulnerability
2017-04-23
http://www.securityfocus.com/bid/97956

Mozilla Firefox Multiple Security Vulnerabilities
2017-04-23
http://www.securityfocus.com/bid/97940

Pexip Infinity CVE-2017-6551 Remote Code Execution Vulnerability
2017-04-23
http://www.securityfocus.com/bid/97954

Qemu 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-04-23
http://www.securityfocus.com/bid/97955

Palo Alto Networks PAN-OS CVE-2017-7409 Cross Site Scripting Vulnerability
2017-04-23
http://www.securityfocus.com/bid/97953

Nessus CVE-2017-7850 Local Privilege Escalation Vulnerability
2017-04-23
http://www.securityfocus.com/bid/97952

OpenSSL CVE-2017-3731 Denial of Service Vulnerability
2017-04-23
http://www.securityfocus.com/bid/95813

OpenSSL CVE-2015-1789 Out of Bounds Read Denial of Service Vulnerability
2017-04-23
http://www.securityfocus.com/bid/75156

OpenSSL CVE-2015-1788 Denial of Service Vulnerability
2017-04-23
http://www.securityfocus.com/bid/75158

OpenSSL CVE-2015-3195 Information Disclosure Vulnerability
2017-04-23
http://www.securityfocus.com/bid/78626

OpenSSL 'ASN1_TYPE_cmp()' Function Denial of Service Vulnerability
2017-04-23
http://www.securityfocus.com/bid/73225

OpenSSL 'dtls1_get_record()' Function NULL Pointer Dereference Denial of Service Vulnerability
2017-04-23
http://www.securityfocus.com/bid/71937

FreeBSD CVE-2013-5209 Information Disclosure Vulnerability
2017-04-23
http://www.securityfocus.com/bid/61939

Dropbear SSH Server Use After Free Remote Code Execution Vulnerability
2017-04-23
http://www.securityfocus.com/bid/52159

OpenSSL CVE-2015-0204 Man in the Middle Security Bypass Vulnerability
2017-04-23
http://www.securityfocus.com/bid/71936

Multiple Oracle Products CVE-2016-0635 Remote Security Vulnerability
2017-04-23
http://www.securityfocus.com/bid/91869

OpenSSL CVE-2017-3732 Information Disclosure Vulnerability
2017-04-23
http://www.securityfocus.com/bid/95814

Nessus CVE-2017-7849 Local Denial of Service Vulnerability
2017-04-23
http://www.securityfocus.com/bid/97951

Apache Batik CVE-2017-5662 XML External Entity Information Disclosure Vulnerability
2017-04-23
http://www.securityfocus.com/bid/97948

Linux Kernel CVE-2017-7645 Multiple Denial of Service Vulnerabilities
2017-04-23
http://www.securityfocus.com/bid/97950

Apache Traffic Server CVE-2017-5659 Denial of Service Vulnerability
2017-04-23
http://www.securityfocus.com/bid/97949

Apache Traffic Server CVE-2016-5396 Denial of Service Vulnerability
2017-04-23
http://www.securityfocus.com/bid/97945

LibYAML and Perl YAML-LibYAML Module 'scanner.c' Remote Denial of Service Vulnerability
2017-04-23
http://www.securityfocus.com/bid/71349

LibYAML 'yaml_parser_scan_uri_escapes()' Function Remote Heap Based Buffer Overflow Vulnerability
2017-04-23
http://www.securityfocus.com/bid/66478

LibYAML 'scanner.c' Remote Heap Based Buffer Overflow Vulnerability
2017-04-23
http://www.securityfocus.com/bid/65258

ImageMagick CVE-2017-7942 Denial of Service Vulnerability
2017-04-23
http://www.securityfocus.com/bid/97946

ImageMagick CVE-2017-7941 Denial of Service Vulnerability
2017-04-23
http://www.securityfocus.com/bid/97944

Splunk Enterprise and Lite Multiple Cross Site Scripting Vulnerabilities
2017-04-23
http://www.securityfocus.com/bid/97942Multiple McAfee Products CVE-2017-4028 Local Code Injection Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97958

QEMU 'hw/display/cirrus_vga_rop.h' Multiple Memory Corruption Vulnerabilities
2017-04-22
http://www.securityfocus.com/bid/97957

ImageMagick CVE-2017-7943 Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97956

Mozilla Firefox Multiple Security Vulnerabilities
2017-04-22
http://www.securityfocus.com/bid/97940

Pexip Infinity CVE-2017-6551 Remote Code Execution Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97954

Qemu 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97955

Palo Alto Networks PAN-OS CVE-2017-7409 Cross Site Scripting Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97953

Nessus CVE-2017-7850 Local Privilege Escalation Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97952

OpenSSL CVE-2017-3731 Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/95813

OpenSSL CVE-2015-1789 Out of Bounds Read Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/75156

OpenSSL CVE-2015-1788 Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/75158

OpenSSL CVE-2015-3195 Information Disclosure Vulnerability
2017-04-22
http://www.securityfocus.com/bid/78626

OpenSSL 'ASN1_TYPE_cmp()' Function Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/73225

OpenSSL 'dtls1_get_record()' Function NULL Pointer Dereference Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/71937

FreeBSD CVE-2013-5209 Information Disclosure Vulnerability
2017-04-22
http://www.securityfocus.com/bid/61939

Dropbear SSH Server Use After Free Remote Code Execution Vulnerability
2017-04-22
http://www.securityfocus.com/bid/52159

OpenSSL CVE-2015-0204 Man in the Middle Security Bypass Vulnerability
2017-04-22
http://www.securityfocus.com/bid/71936

Multiple Oracle Products CVE-2016-0635 Remote Security Vulnerability
2017-04-22
http://www.securityfocus.com/bid/91869

OpenSSL CVE-2017-3732 Information Disclosure Vulnerability
2017-04-22
http://www.securityfocus.com/bid/95814

Nessus CVE-2017-7849 Local Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97951

Apache Batik CVE-2017-5662 XML External Entity Information Disclosure Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97948

Linux Kernel CVE-2017-7645 Multiple Denial of Service Vulnerabilities
2017-04-22
http://www.securityfocus.com/bid/97950

Apache Traffic Server CVE-2017-5659 Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97949

Apache Traffic Server CVE-2016-5396 Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97945

LibYAML and Perl YAML-LibYAML Module 'scanner.c' Remote Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/71349

LibYAML 'yaml_parser_scan_uri_escapes()' Function Remote Heap Based Buffer Overflow Vulnerability
2017-04-22
http://www.securityfocus.com/bid/66478

LibYAML 'scanner.c' Remote Heap Based Buffer Overflow Vulnerability
2017-04-22
http://www.securityfocus.com/bid/65258

ImageMagick CVE-2017-7942 Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97946

ImageMagick CVE-2017-7941 Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97944

Splunk Enterprise and Lite Multiple Cross Site Scripting Vulnerabilities
2017-04-22
http://www.securityfocus.com/bid/97942Multiple McAfee Products CVE-2017-4028 Local Code Injection Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97958

QEMU 'hw/display/cirrus_vga_rop.h' Multiple Memory Corruption Vulnerabilities
2017-04-22
http://www.securityfocus.com/bid/97957

ImageMagick CVE-2017-7943 Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97956

Mozilla Firefox Multiple Security Vulnerabilities
2017-04-22
http://www.securityfocus.com/bid/97940

Pexip Infinity CVE-2017-6551 Remote Code Execution Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97954

Qemu 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97955

Palo Alto Networks PAN-OS CVE-2017-7409 Cross Site Scripting Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97953

Nessus CVE-2017-7850 Local Privilege Escalation Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97952

OpenSSL CVE-2017-3731 Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/95813

OpenSSL CVE-2015-1789 Out of Bounds Read Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/75156

OpenSSL CVE-2015-1788 Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/75158

OpenSSL CVE-2015-3195 Information Disclosure Vulnerability
2017-04-22
http://www.securityfocus.com/bid/78626

OpenSSL 'ASN1_TYPE_cmp()' Function Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/73225

OpenSSL 'dtls1_get_record()' Function NULL Pointer Dereference Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/71937

FreeBSD CVE-2013-5209 Information Disclosure Vulnerability
2017-04-22
http://www.securityfocus.com/bid/61939

Dropbear SSH Server Use After Free Remote Code Execution Vulnerability
2017-04-22
http://www.securityfocus.com/bid/52159

OpenSSL CVE-2015-0204 Man in the Middle Security Bypass Vulnerability
2017-04-22
http://www.securityfocus.com/bid/71936

Multiple Oracle Products CVE-2016-0635 Remote Security Vulnerability
2017-04-22
http://www.securityfocus.com/bid/91869

OpenSSL CVE-2017-3732 Information Disclosure Vulnerability
2017-04-22
http://www.securityfocus.com/bid/95814

Nessus CVE-2017-7849 Local Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97951

Apache Batik CVE-2017-5662 XML External Entity Information Disclosure Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97948

Linux Kernel CVE-2017-7645 Multiple Denial of Service Vulnerabilities
2017-04-22
http://www.securityfocus.com/bid/97950

Apache Traffic Server CVE-2017-5659 Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97949

Apache Traffic Server CVE-2016-5396 Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97945

LibYAML and Perl YAML-LibYAML Module 'scanner.c' Remote Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/71349

LibYAML 'yaml_parser_scan_uri_escapes()' Function Remote Heap Based Buffer Overflow Vulnerability
2017-04-22
http://www.securityfocus.com/bid/66478

LibYAML 'scanner.c' Remote Heap Based Buffer Overflow Vulnerability
2017-04-22
http://www.securityfocus.com/bid/65258

ImageMagick CVE-2017-7942 Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97946

ImageMagick CVE-2017-7941 Denial of Service Vulnerability
2017-04-22
http://www.securityfocus.com/bid/97944

Splunk Enterprise and Lite Multiple Cross Site Scripting Vulnerabilities
2017-04-22
http://www.securityfocus.com/bid/97942

SANS News

WTF tcp port 81

Threatpost

Mirai and Hajime Locked Into IoT Botnet Battle

Google Pleads for Better Cross-Border Exchange of Digital Evidence

Skype Fixes ‘SPYKE’ Credential Phishing Remote Execution Bug

Exploit

Linux/x86 - Egg-hunter Shellcode (18 bytes)

21.4.2017

Bugtraq

CVE-2017-7192: Starscream library before 2.0.4 allows SSL pinning bypass 2017-04-21
Security Advisories (security advisories centralway com)

[SECURITY] [DSA 3831-1] firefox-esr security update 2017-04-19
Moritz Muehlenhoff (jmm debian org)

[HITB-Announce] HITB GSEC 2017 CFP Closes April 30th 2017-04-19
Hafez Kamal (aphesz hackinthebox org)

October CMS v1.0.412 several vulnerabilities 2017-04-19
Anti Räis (antirais gmail com)

DefenseCode ThunderScan SAST Advisory: Ultimate Form Builder Cross-Site Scripting (XSS) Vulnerability 2017-04-19
DefenseCode (defensecode defensecode com)

CVE-2017-7220. OpenText Documentum Content Server: privilege evaluation using crafted RPC save-commands. 2017-04-19
Andrey B. Panfilov (andrew panfilov tel)

CVE-2017-7692: Squirrelmail 1.4.22 Remote Code Execution 2017-04-19
Filippo Cavallarin (filippo cavallarin wearesegment com)

[slackware-security] minicom (SSA:2017-108-01) 2017-04-19
Slackware Security Team (security slackware com)

Malware

SMG.Ransom!gen

Trojan.Darkpulsar

Trojan.Lodarat

Phishing

Tesco Bank

21st April 2017

Urgent Message From Tesco
Secure

Chase

21st April 2017

New Notification from Chase

Dropbox team

20th April 2017

One Attached Document Via
Dropbox

AOL

20th April 2017

RETURNED MESSAGES

Apple ID

20th April 2017

YOUR APPLE ID INFORMATION HAS
BEEN UPDATED

HSBC

20th April 2017

Confirm your email address

Vulnerebility

QEMU 'hw/display/cirrus_vga_rop.h' Multiple Memory Corruption Vulnerabilities
2017-04-21
http://www.securityfocus.com/bid/97957

ImageMagick CVE-2017-7943 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97956

Mozilla Firefox Multiple Security Vulnerabilities
2017-04-21
http://www.securityfocus.com/bid/97940

Pexip Infinity CVE-2017-6551 Remote Code Execution Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97954

Qemu 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97955

Palo Alto Networks PAN-OS CVE-2017-7409 Cross Site Scripting Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97953

Nessus CVE-2017-7850 Local Privilege Escalation Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97952

OpenSSL CVE-2017-3731 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/95813

OpenSSL CVE-2015-1789 Out of Bounds Read Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/75156

OpenSSL CVE-2015-1788 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/75158

OpenSSL CVE-2015-3195 Information Disclosure Vulnerability
2017-04-21
http://www.securityfocus.com/bid/78626

OpenSSL 'ASN1_TYPE_cmp()' Function Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/73225

OpenSSL 'dtls1_get_record()' Function NULL Pointer Dereference Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/71937

FreeBSD CVE-2013-5209 Information Disclosure Vulnerability
2017-04-21
http://www.securityfocus.com/bid/61939

Dropbear SSH Server Use After Free Remote Code Execution Vulnerability
2017-04-21
http://www.securityfocus.com/bid/52159

OpenSSL CVE-2015-0204 Man in the Middle Security Bypass Vulnerability
2017-04-21
http://www.securityfocus.com/bid/71936

Multiple Oracle Products CVE-2016-0635 Remote Security Vulnerability
2017-04-21
http://www.securityfocus.com/bid/91869

OpenSSL CVE-2017-3732 Information Disclosure Vulnerability
2017-04-21
http://www.securityfocus.com/bid/95814

Nessus CVE-2017-7849 Local Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97951

Apache Batik CVE-2017-5662 XML External Entity Information Disclosure Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97948

Linux Kernel CVE-2017-7645 Multiple Denial of Service Vulnerabilities
2017-04-21
http://www.securityfocus.com/bid/97950

Apache Traffic Server CVE-2017-5659 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97949

Apache Traffic Server CVE-2016-5396 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97945

LibYAML and Perl YAML-LibYAML Module 'scanner.c' Remote Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/71349

LibYAML 'yaml_parser_scan_uri_escapes()' Function Remote Heap Based Buffer Overflow Vulnerability
2017-04-21
http://www.securityfocus.com/bid/66478

LibYAML 'scanner.c' Remote Heap Based Buffer Overflow Vulnerability
2017-04-21
http://www.securityfocus.com/bid/65258

ImageMagick CVE-2017-7942 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97946

ImageMagick CVE-2017-7941 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97944

Splunk Enterprise and Lite Multiple Cross Site Scripting Vulnerabilities
2017-04-21
http://www.securityfocus.com/bid/97942

Drupal CVE-2017-6919 Access Bypass Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97941Mozilla Firefox Multiple Security Vulnerabilities
2017-04-21
http://www.securityfocus.com/bid/97940

Apache Batik CVE-2017-5662 XML External Entity Information Disclosure Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97948

Linux Kernel CVE-2017-7645 Multiple Denial of Service Vulnerabilities
2017-04-21
http://www.securityfocus.com/bid/97950

Apache Traffic Server CVE-2017-5659 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97949

Apache Traffic Server CVE-2016-5396 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97945

LibYAML and Perl YAML-LibYAML Module 'scanner.c' Remote Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/71349

LibYAML 'yaml_parser_scan_uri_escapes()' Function Remote Heap Based Buffer Overflow Vulnerability
2017-04-21
http://www.securityfocus.com/bid/66478

LibYAML 'scanner.c' Remote Heap Based Buffer Overflow Vulnerability
2017-04-21
http://www.securityfocus.com/bid/65258

ImageMagick CVE-2017-7942 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97946

ImageMagick CVE-2017-7941 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97944

Splunk Enterprise and Lite Multiple Cross Site Scripting Vulnerabilities
2017-04-21
http://www.securityfocus.com/bid/97942

Drupal CVE-2017-6919 Access Bypass Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97941

Google Chrome Prior to 58.0.3029.81 Multiple Security Vulnerabilities
2017-04-21
http://www.securityfocus.com/bid/97939

Trend Micro InterScan Messaging Security Virtual Appliance Cross Site Scripting Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97938

Cisco Adaptive Security Appliance (ASA) Software CVE-2017-6608 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97937

Cisco ASA Software CVE-2017-6609 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97936

Cisco ASA Software CVE-2017-6610 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97934

Cisco IOS and IOS XE Software Multiple Denial of Service Vulnerabilities
2017-04-21
http://www.securityfocus.com/bid/97935

Cisco Adaptive Security Appliance (ASA) Software CVE-2017-6607 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97933

OpenSSL CVE-2016-6306 Local Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/93153

OpenSSL CVE-2016-6304 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/93150

OpenSSL CVE-2016-6305 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/93149

OpenSSL 'BN_bn2dec()' Function Out of Bounds Write Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/92557

OpenSSL CVE-2016-6302 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/92628

SSL/TLS Protocol CVE-2016-2183 Information Disclosure Vulnerability
2017-04-21
http://www.securityfocus.com/bid/92630

OpenSSL CVE-2016-2179 Multiple Denial of Service Vulnerabilities
2017-04-21
http://www.securityfocus.com/bid/92987

OpenSSL CVE-2016-2181 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/92982

OpenSSL CVE-2016-2180 Local Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/92117

Cisco Firepower System Software CVE-2016-6368 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97932

Cisco IOS XE Software CVE-2017-6615 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97930LibYAML and Perl YAML-LibYAML Module 'scanner.c' Remote Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/71349

LibYAML 'yaml_parser_scan_uri_escapes()' Function Remote Heap Based Buffer Overflow Vulnerability
2017-04-21
http://www.securityfocus.com/bid/66478

LibYAML 'scanner.c' Remote Heap Based Buffer Overflow Vulnerability
2017-04-21
http://www.securityfocus.com/bid/65258

ImageMagick CVE-2017-7942 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97946

ImageMagick CVE-2017-7941 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97944

Mozilla Firefox Multiple Security Vulnerabilities
2017-04-21
http://www.securityfocus.com/bid/97940

Splunk Enterprise and Lite Multiple Cross Site Scripting Vulnerabilities
2017-04-21
http://www.securityfocus.com/bid/97942

Drupal CVE-2017-6919 Access Bypass Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97941

Google Chrome Prior to 58.0.3029.81 Multiple Security Vulnerabilities
2017-04-21
http://www.securityfocus.com/bid/97939

Trend Micro InterScan Messaging Security Virtual Appliance Cross Site Scripting Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97938

Cisco Adaptive Security Appliance (ASA) Software CVE-2017-6608 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97937

Cisco ASA Software CVE-2017-6609 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97936

Cisco ASA Software CVE-2017-6610 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97934

Cisco IOS and IOS XE Software Multiple Denial of Service Vulnerabilities
2017-04-21
http://www.securityfocus.com/bid/97935

Cisco Adaptive Security Appliance (ASA) Software CVE-2017-6607 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97933

OpenSSL CVE-2016-6306 Local Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/93153

OpenSSL CVE-2016-6304 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/93150

OpenSSL CVE-2016-6305 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/93149

OpenSSL 'BN_bn2dec()' Function Out of Bounds Write Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/92557

OpenSSL CVE-2016-6302 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/92628

SSL/TLS Protocol CVE-2016-2183 Information Disclosure Vulnerability
2017-04-21
http://www.securityfocus.com/bid/92630

OpenSSL CVE-2016-2179 Multiple Denial of Service Vulnerabilities
2017-04-21
http://www.securityfocus.com/bid/92987

OpenSSL CVE-2016-2181 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/92982

OpenSSL CVE-2016-2180 Local Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/92117

Cisco Firepower System Software CVE-2016-6368 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97932

Cisco IOS XE Software CVE-2017-6615 Denial of Service Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97930

Cisco Prime Infrastructure CVE-2017-6611 Cross Site Scripting Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97931

Cisco Integrated Management Controller CVE-2017-6616 Remote Code Execution Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97928

Cisco Integrated Management Controller CVE-2017-6617 Session Hijacking Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97929

Cisco Integrated Management Controller CVE-2017-6618 Cross Site Scripting Vulnerability
2017-04-21
http://www.securityfocus.com/bid/97927

SANS News

Analysis of a Maldoc with Multiple Layers of Obfuscation

Threatpost

Stuxnet LNK Exploits Still Widely Circulated

20 Linksys Router Models Vulnerable To Attack

Google Fixes Unicode Phishing Vulnerability in Chrome 58, Firefox Standing Pat

Exploit

Microsoft Windows - ManagementObject Arbitrary .NET Serialization Remote Code...

Microsoft Windows 10 - Runtime Broker ClipboardBroker Privilege Escalation

Microsoft Windows 10 10586 - IEETWCollector Arbitrary Directory/File Deletion...

Apple WebKit / Safari 10.0.2(12602.3.12.0.1) - 'PrototypeMap::createEmptyStructure'...

Apple WebKit / Safari 10.0.2(12602.3.12.0.1) - 'operationSpreadGeneric' Universal...

VirtualBox 5.0.32 r112930 x64 - Windows Process COM Injection Privilege Escalation

VirtualBox - Guest-to-Host Privilege Escalation via Broken Length Handling in slirp...

VirtualBox 5.1.14 r112924 - Unprivileged Host User to Host Kernel Privilege...

VirtualBox - Environment and ioctl Unprivileged Host User to Host Kernel Privilege...

VirtualBox - 'virtio-net' Guest-to-Host Out-of-Bounds Write

20.4.2017

Bugtraq

[SECURITY] [DSA 3831-1] firefox-esr security update 2017-04-19
Moritz Muehlenhoff (jmm debian org)

[HITB-Announce] HITB GSEC 2017 CFP Closes April 30th 2017-04-19
Hafez Kamal (aphesz hackinthebox org)

October CMS v1.0.412 several vulnerabilities 2017-04-19
Anti Räis (antirais gmail com)

DefenseCode ThunderScan SAST Advisory: Ultimate Form Builder Cross-Site Scripting (XSS) Vulnerability 2017-04-19
DefenseCode (defensecode defensecode com)

CVE-2017-7220. OpenText Documentum Content Server: privilege evaluation using crafted RPC save-commands. 2017-04-19
Andrey B. Panfilov (andrew panfilov tel)

CVE-2017-7692: Squirrelmail 1.4.22 Remote Code Execution 2017-04-19
Filippo Cavallarin (filippo cavallarin wearesegment com)

[slackware-security] minicom (SSA:2017-108-01) 2017-04-19
Slackware Security Team (security slackware com)

CVE-2017-7615 Mantis Bug Tracker v1.3.0 / 2.3.0 Pre-Auth Remote Password Reset 2017-04-18
apparitionsec gmail com (hyp3rlinx)

[CVE-2017-5661] Apache XML Graphics FOP information disclosure vulnerability 2017-04-18
Simon Steiner (simonsteiner1984 gmail com)

[ANNOUNCE] HPACK Bomb Attack vulnerability in ATS - CVE-2016-5396 2017-04-17
Bryan Call (bcall apache org)

Malware

 

Phishing

HSBC

20th April 2017

Confirm your email address

Vulnerebility

VMware Workstation and Horizon Client CVE-2017-4913 Integer Overflow Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97920

OpenSSL CVE-2016-6307 Denial of Service Vulnerability
2017-04-20
http://www.securityfocus.com/bid/93152

VMware Workstation and Horizon View Client CVE-2017-4912 Remote Code Execution Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97921

IBM Cognos TM1 CVE-2016-3036 Denial of Service Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97918

VMware Workstation and Horizon View Client CVE-2017-4911 Remote Code Execution Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97916

IBM Cognos TM1 CVE-2016-3037 Information Disclosure Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97917

IBM Cognos TM1 CVE-2016-3038 Cross Site Scripting Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97915

VMware Unified Access Gateway and Horizon View Heap Based Buffer Overflow Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97914

VMware Workstation and Horizon View Client CVE-2017-4910 Remote Code Execution Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97913

OpenSSL CVE-2016-6308 Denial of Service Vulnerability
2017-04-20
http://www.securityfocus.com/bid/93151

YUI 'SWF' File Multiple Cross-Site Scripting Vulnerabilities
2017-04-20
http://www.securityfocus.com/bid/56385

VMware Workstation and Horizon View Client CVE-2016-4908 Heap Based Buffer Overflow Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97912

VMware Workstation and Horizon View Client CVE-2016-4909 Heap Based Buffer Overflow Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97911

Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
2017-04-20
http://www.securityfocus.com/bid/96729

XStream CVE-2016-3674 XML External Entity Multiple Information Disclosure Vulnerabilities
2017-04-20
http://www.securityfocus.com/bid/85381

PHP 'zip_stream.c' Integer Overflow Vulnerability
2017-04-20
http://www.securityfocus.com/bid/92099

PHP '/xmlrpc/libxmlrpc/simplestring.c' Heap Buffer Overflow Vulnerability
2017-04-20
http://www.securityfocus.com/bid/92095

Apache MyFaces Trinidad CVE-2016-5019 Remote Code Execution Vulnerability
2017-04-20
http://www.securityfocus.com/bid/93236

PHP 'snmp.c' Denial of Service Vulnerability
2017-04-20
http://www.securityfocus.com/bid/92094

PHP CVE-2016-6294 Local Information Disclosure Vulnerability
2017-04-20
http://www.securityfocus.com/bid/92115

PHP 'exif.c' NULL Pointer Dereference Denial of Service Vulnerability
2017-04-20
http://www.securityfocus.com/bid/92078

OpenSSL CVE-2016-6309 Remote Code Execution Vulnerability
2017-04-20
http://www.securityfocus.com/bid/93177

PHP 'exif_process_IFD_in_MAKERNOTE' Out of Bounds Read Information Disclosure Vulnerability
2017-04-20
http://www.securityfocus.com/bid/92073

PHP 'zend_virtual_cwd.c' Integer Overflow Vulnerability
2017-04-20
http://www.securityfocus.com/bid/92074

PHP 'php_url_prase_ex()' Function Memory Corruption Vulnerability
2017-04-20
http://www.securityfocus.com/bid/92111

PHP 'session.c' Use After Free Remote Code Execution Vulnerability
2017-04-20
http://www.securityfocus.com/bid/92097

Oracle VM VirtualBox CVE-2017-3538 Local Security Bypass Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97698

Apache Struts CVE-2016-4436 Security Bypass Vulnerability
2017-04-20
http://www.securityfocus.com/bid/91280

Apache Tomcat CVE-2016-8735 Remote Code Execution Vulnerability
2017-04-20
http://www.securityfocus.com/bid/94463

BeanShell CVE-2016-2510 Remote Code Execution Vulnerability
2017-04-20
http://www.securityfocus.com/bid/84139
VMware Workstation and Horizon Client CVE-2017-4913 Integer Overflow Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97920

OpenSSL CVE-2016-6307 Denial of Service Vulnerability
2017-04-20
http://www.securityfocus.com/bid/93152

VMware Workstation and Horizon View Client CVE-2017-4912 Remote Code Execution Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97921

IBM Cognos TM1 CVE-2016-3036 Denial of Service Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97918

VMware Workstation and Horizon View Client CVE-2017-4911 Remote Code Execution Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97916

IBM Cognos TM1 CVE-2016-3037 Information Disclosure Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97917

IBM Cognos TM1 CVE-2016-3038 Cross Site Scripting Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97915

VMware Unified Access Gateway and Horizon View Heap Based Buffer Overflow Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97914

VMware Workstation and Horizon View Client CVE-2017-4910 Remote Code Execution Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97913

OpenSSL CVE-2016-6308 Denial of Service Vulnerability
2017-04-20
http://www.securityfocus.com/bid/93151

YUI 'SWF' File Multiple Cross-Site Scripting Vulnerabilities
2017-04-20
http://www.securityfocus.com/bid/56385

VMware Workstation and Horizon View Client CVE-2016-4908 Heap Based Buffer Overflow Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97912

VMware Workstation and Horizon View Client CVE-2016-4909 Heap Based Buffer Overflow Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97911

Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
2017-04-20
http://www.securityfocus.com/bid/96729

XStream CVE-2016-3674 XML External Entity Multiple Information Disclosure Vulnerabilities
2017-04-20
http://www.securityfocus.com/bid/85381

PHP 'zip_stream.c' Integer Overflow Vulnerability
2017-04-20
http://www.securityfocus.com/bid/92099

PHP '/xmlrpc/libxmlrpc/simplestring.c' Heap Buffer Overflow Vulnerability
2017-04-20
http://www.securityfocus.com/bid/92095

Apache MyFaces Trinidad CVE-2016-5019 Remote Code Execution Vulnerability
2017-04-20
http://www.securityfocus.com/bid/93236

PHP 'snmp.c' Denial of Service Vulnerability
2017-04-20
http://www.securityfocus.com/bid/92094

PHP CVE-2016-6294 Local Information Disclosure Vulnerability
2017-04-20
http://www.securityfocus.com/bid/92115

PHP 'exif.c' NULL Pointer Dereference Denial of Service Vulnerability
2017-04-20
http://www.securityfocus.com/bid/92078

OpenSSL CVE-2016-6309 Remote Code Execution Vulnerability
2017-04-20
http://www.securityfocus.com/bid/93177

PHP 'exif_process_IFD_in_MAKERNOTE' Out of Bounds Read Information Disclosure Vulnerability
2017-04-20
http://www.securityfocus.com/bid/92073

PHP 'zend_virtual_cwd.c' Integer Overflow Vulnerability
2017-04-20
http://www.securityfocus.com/bid/92074

PHP 'php_url_prase_ex()' Function Memory Corruption Vulnerability
2017-04-20
http://www.securityfocus.com/bid/92111

PHP 'session.c' Use After Free Remote Code Execution Vulnerability
2017-04-20
http://www.securityfocus.com/bid/92097

Oracle VM VirtualBox CVE-2017-3538 Local Security Bypass Vulnerability
2017-04-20
http://www.securityfocus.com/bid/97698

Apache Struts CVE-2016-4436 Security Bypass Vulnerability
2017-04-20
http://www.securityfocus.com/bid/91280

Apache Tomcat CVE-2016-8735 Remote Code Execution Vulnerability
2017-04-20
http://www.securityfocus.com/bid/94463

BeanShell CVE-2016-2510 Remote Code Execution Vulnerability
2017-04-20
http://www.securityfocus.com/bid/84139

SANS News

DNS Query Length... Because Size Does Matter

Threatpost

Facebook Delegated Account Recovery SDKs Published for Java, Ruby Apps

IHG Confirms Second Credit Card Breach Impacting 1,000-Plus Hotels

Patched Flaw in Bosch Diagnostic Dongle Allowed Researchers to Shut Off Engine

Microsoft Touts New Phone-Based Login Mechanism

Exploit

Huawei HG532n - Command Injection (Metasploit)

19.4.2017

Bugtraq

DefenseCode ThunderScan SAST Advisory: Ultimate Form Builder Cross-Site Scripting (XSS) Vulnerability 2017-04-19
DefenseCode (defensecode defensecode com)

CVE-2017-7220. OpenText Documentum Content Server: privilege evaluation using crafted RPC save-commands. 2017-04-19
Andrey B. Panfilov (andrew panfilov tel)

CVE-2017-7692: Squirrelmail 1.4.22 Remote Code Execution 2017-04-19
Filippo Cavallarin (filippo cavallarin wearesegment com)

[slackware-security] minicom (SSA:2017-108-01) 2017-04-19
Slackware Security Team (security slackware com)

CVE-2017-7615 Mantis Bug Tracker v1.3.0 / 2.3.0 Pre-Auth Remote Password Reset 2017-04-18
apparitionsec gmail com (hyp3rlinx)

[CVE-2017-5661] Apache XML Graphics FOP information disclosure vulnerability 2017-04-18
Simon Steiner (simonsteiner1984 gmail com)

[ANNOUNCE] HPACK Bomb Attack vulnerability in ATS - CVE-2016-5396 2017-04-17
Bryan Call (bcall apache org)

Watchguard Fireware XXE DoS & User Enumeration 2017-04-17
David Fernandez (david fdmv gmail com)

Malware

TrojanDownloader:Win32/Adload.DO

JS.Downloader.H

Phishing

 

Vulnerebility

Bouncy Castle CVE-2015-7940 Information Disclosure Vulnerability
2017-04-19
http://www.securityfocus.com/bid/79091

OpenSSL CMS CVE-2015-1792 Denial of Service Vulnerability
2017-04-19
http://www.securityfocus.com/bid/75154

Apache Tomcat CVE-2016-6817 Denial of Service Vulnerability
2017-04-19
http://www.securityfocus.com/bid/94462

Apache Tomcat CVE-2016-6816 Security Bypass Vulnerability
2017-04-19
http://www.securityfocus.com/bid/94461

Apache Tomcat CVE-2016-6797 Security Bypass Vulnerability
2017-04-19
http://www.securityfocus.com/bid/93940

Apache Tomcat Security Manager CVE-2016-6796 Security Bypass Vulnerability
2017-04-19
http://www.securityfocus.com/bid/93944

Apache Tomcat CVE-2016-6794 Security Bypass Vulnerability
2017-04-19
http://www.securityfocus.com/bid/93943

Apache Tomcat Security Manager CVE-2016-5018 Security Bypass Vulnerability
2017-04-19
http://www.securityfocus.com/bid/93942

X.Org libXt CVE-2013-2005 Multiple Memory Corruption Vulnerabilities
2017-04-19
http://www.securityfocus.com/bid/60133

X.Org libXcursor '_XcursorFileHeaderCreate()' Function Remote Code Execution Vulnerability
2017-04-19
http://www.securityfocus.com/bid/60121

X.Org libXt '_XtResourceConfigurationEH()' Function Remote Code Execution Vulnerability
2017-04-19
http://www.securityfocus.com/bid/60137

X.Org libXi CVE-2013-1998 Multiple Remote Code Execution Vulnerabilities
2017-04-19
http://www.securityfocus.com/bid/60127

X.Org libXrender CVE-2013-1987 Multiple Remote Code Execution Vulnerabilities
2017-04-19
http://www.securityfocus.com/bid/60132

X.Org libXi 'XListInputDevices()' Memory Corruption Vulnerability
2017-04-19
http://www.securityfocus.com/bid/60124

cURL CVE-2016-8620 Remote Security Bypass Vulnerability
2017-04-19
http://www.securityfocus.com/bid/94102

cURL CVE-2016-8619 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/94100

cURL/libcURL CVE-2016-8617 Remote Security Bypass Vulnerability
2017-04-19
http://www.securityfocus.com/bid/94097

cURL/libcURL CVE-2016-8618 Remote Security Bypass Vulnerability
2017-04-19
http://www.securityfocus.com/bid/94098

cURL/libcURL CVE-2016-8616 Remote Security Bypass Vulnerability
2017-04-19
http://www.securityfocus.com/bid/94094

cURL/libcURL CVE-2016-8615 Cookie Injection Security Bypass Vulnerability
2017-04-19
http://www.securityfocus.com/bid/94096

cURL/libcurl CVE-2016-5421 Local Use After Free Denial of Service Vulnerability
2017-04-19
http://www.securityfocus.com/bid/92306

cURL/libcURL CVE-2016-5420 Certificate Validation Security Bypass Vulnerability
2017-04-19
http://www.securityfocus.com/bid/92309

cURL/libcURL CVE-2016-5419 Remote Security Bypass Vulnerability
2017-04-19
http://www.securityfocus.com/bid/92292

cURL CVE-2016-4802 DLL Loading Local Code Execution Vulnerability
2017-04-19
http://www.securityfocus.com/bid/90997

IETF RFC 3279 X.509 Certificate MD5 Signature Collision Vulnerability
2017-04-19
http://www.securityfocus.com/bid/33065

Samba CVE-2015-5252 Symlink Vulnerability
2017-04-19
http://www.securityfocus.com/bid/79733

MariaDB and MySQL CVE-2017-3302 Denial of Service Vulnerability
2017-04-19
http://www.securityfocus.com/bid/96162

MySQL CVE-2017-3305 Man in the Middle Security Bypass Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97023

OpenSSL CVE-2017-3730 NULL Pointer Dereference Denial of Service Vulnerability
2017-04-19
http://www.securityfocus.com/bid/95812

cURL/libcURL CVE-2016-8625 Remote Security Bypass Vulnerability
2017-04-19
http://www.securityfocus.com/bid/94107Oracle WebCenter Sites CVE-2017-3541 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97809

Oracle PeopleSoft Enterprise SCM eBill Payment CVE-2017-3571 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97909

Oracle PeopleSoft Enterprise PeopleTools CVE-2017-3520 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97908

Oracle WebCenter Sites CVE-2017-3602 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97823

Oracle WebCenter Sites CVE-2017-3598 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97905

Oracle PeopleSoft Enterprise FSCM CVE-2017-3570 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97906

Oracle WebCenter Sites CVE-2017-3603 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97907

Oracle PeopleSoft Enterprise CS Campus Community CVE-2017-3577 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97903

Oracle WebCenter Sites CVE-2017-3597 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97904

Oracle PeopleSoft Enterprise SCM Strategic Sourcing CVE-2017-3524 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97902

Oracle WebCenter Sites CVE-2017-3594 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97901

Oracle PeopleSoft Enterprise PeopleTools CVE-2017-3536 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97898

Oracle WebCenter Sites CVE-2017-3591 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97899

Oracle GlassFish Server CVE-2017-3626 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97896

Oracle PeopleSoft Enterprise FIN Receivables CVE-2017-3502 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97897

Oracle Primavera Unifier CVE-2017-3501 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97895

Oracle Primavera Products CVE-2017-3583 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97893

Oracle WebLogic Server CVE-2017-3531 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97894

Oracle PeopleSoft Enterprise PeopleTools CVE-2017-3547 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97892

Oracle Primavera Products CVE-2017-3503 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97891

Oracle Service Bus CVE-2017-3507 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97888

Oracle PeopleSoft Enterprise SCM eSupplier Connection CVE-2017-3522 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97890

Oracle Primavera Products CVE-2017-3508 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97889

Oracle Primavera Products CVE-2017-3579 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97886

Oracle PeopleSoft Enterprise PeopleTools CVE-2017-3519 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97885

Oracle WebCenter Sites CVE-2017-3595 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97887

Linux Kernel CVE-2015-8104 Denial of Service Vulnerability
2017-04-19
http://www.securityfocus.com/bid/77524

Oracle PeopleSoft Enterprise SCM Service Procurement CVE-2017-3525 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97882

Oracle Primavera Gateway CVE-2017-3508 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97883

Oracle WebLogic Server CVE-2017-3506 Remote Security Vulnerability
2017-04-19
http://www.securityfocus.com/bid/97884

SANS News

Hunting for Malicious Excel Sheets

Threatpost

Low-Cost Ransomware Service Discovered

Facebook Delegated Account Recovery SDKs Published for Java, Ruby Apps

IHG Confirms Second Credit Card Breach Impacting 1,000-Plus Hotels

Exploit

Microsoft Word - .RTF Remote Code Execution

Huawei HG532n - Command Injection (Metasploit)

Tenable Appliance < 4.5 - Unauthenticated Remote Root Code Execution

pinfo 0.6.9 - Local Buffer Overflow

18.4.2017

Bugtraq

CVE-2017-7615 Mantis Bug Tracker v1.3.0 / 2.3.0 Pre-Auth Remote Password Reset 2017-04-18
apparitionsec gmail com (hyp3rlinx)

[CVE-2017-5661] Apache XML Graphics FOP information disclosure vulnerability 2017-04-18
Simon Steiner (simonsteiner1984 gmail com)

[ANNOUNCE] HPACK Bomb Attack vulnerability in ATS - CVE-2016-5396 2017-04-17
Bryan Call (bcall apache org)

Watchguard Fireware XXE DoS & User Enumeration 2017-04-17
David Fernandez (david fdmv gmail com)

concrete5 v8.1.0 Host Header Injection 2017-04-14
apparitionsec gmail com (hyp3rlinx)

Malware

 

Phishing

National Westminster Bank

17th April 2017

Account Reveiw

Vulnerebility

MantisBT CVE-2017-7615 Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97707

SourceBans++ sourcebans-pp CVE-2017-7891 Cross Site Scripting Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97710

ASSETBASE CVE-2017-2134 Cross Site Scripting Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97708

HP Vertica Analytics Platform CVE-2017-5802 Remote Privilege Escalation Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97706

Huawei Honor 6X CVE-2017-2733 Local Information Disclosure Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97700

Multiple Samsung Galaxy Products CVE-2016-4031 Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97703

Apache Log4j CVE-2017-5645 Remote Code Execution Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97702

Multiple Samsung Galaxy Products CVE-2016-4030 Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97701

Axis Network Cameras CVE-2015-8256 HTML Injection and Cross Site Scripting vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/97699

Huawei Smart Phones Multiple Local Buffer Overflow Vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/97696

Oracle VM VirtualBox CVE-2017-3538 Local Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97698

Multiple Toshiba memory card installers DLL Loading Remote Code Execution Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97697

Asterisk Open Source and Certified Asterisk RTP Resource Exhaustion Denial of Service Vulnerability
2017-04-18
http://www.securityfocus.com/bid/92888

Google gRPC CVE-2017-7861 Heap Based Buffer Overflow Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97694

PostgreSQL CVE-2016-5424 Multiple Local Privilege Escalation Vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/92435

PostgreSQL CVE-2016-5423 NULL Pointer Dereference Remote Code Execution Vulnerability
2017-04-18
http://www.securityfocus.com/bid/92433

Google gRPC CVE-2017-7860 Heap Buffer Overflow Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97695

Juniper NorthStar Controller Application CVE-2017-2321 Remote Privilege Escalation Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97693

Linux Kernel CVE-2017-7889 Multiple Local Security Bypass Vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/97690

Juniper NorthStar Controller Application CVE-2017-2326 Local Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97691

Philips In.Sight CVE-2015-2884 Information Disclosure Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97683

python-pysaml2 CVE-2016-10149 XML Entity Expansion Denial of Service Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97692

ISC BIND CVE-2016-2775 Remote Denial of Service Vulnerability
2017-04-18
http://www.securityfocus.com/bid/92037

ISC BIND CVE-2016-6170 Remote Denial of Service Vulnerability
2017-04-18
http://www.securityfocus.com/bid/91611

Juniper NorthStar Controller Application CVE-2017-2320 Remote Privilege Escalation Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97687

Quest Privilege Manager CVE-2017-6554 Arbitrary File Overwrite Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97686

Ubuntu AppArmor CVE-2017-6507 Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97223

Schneider Electric Modicon CVE-2017-7575 Information Disclosure Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97523

Linux Kernel CVE-2017-2636 Local Privilege Escalation Vulnerability
2017-04-18
http://www.securityfocus.com/bid/96732

Schneider Electric SoMachine and Modicon CVE-2017-7574 Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97518Oracle April 2017 Critical Patch Update Multiple Vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/97655

WordPress Spider Event Calendar Plugin CVE-2017-7719 Multiple SQL Injection Vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/97656

Samsung SecEmailSync CVE-2016-2565 Information Disclosure Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97658

Samsung SecEmailSync CVE-2016-2566 SQL Injection Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97654

Drupal Book access Module Unspecified Security Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97645

ISC BIND CVE-2017-3136 Remote Denial of Service Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97653

ISC BIND CVE-2017-3138 Remote Denial of Service Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97657

Juniper NorthStar Controller Application CVE-2017-2319 Authentication Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97659

ISC BIND CVE-2017-3137 Remote Denial of Service Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97651

Multiple Samsung Galaxy Products CVE-2016-4032 Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97650

Drupal References Module Unspecified Security Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97643

Drupal Media Module Unspecified Security Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97647

GNU oSIP 'osipparser2/osip_message_parse.c' Heap Buffer Overflow Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97644

Drupal Open Atrium Module Information Disclosure Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97646

radare2 '/format/wasm/wasm.c' Heap Buffer Overflow Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97648

Red Hat 389-ds-base CVE-2017-2668 Remote Denial of Service Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97524

Linux kernel Local Use After Free Multiple Denial of Service Vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/94135

Apache Tomcat CVE-2016-6816 Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/94461

Apache Tomcat CVE-2016-8745 Information Disclosure Vulnerability
2017-04-18
http://www.securityfocus.com/bid/94828

Magento CMS 'RetrieveImage.php' Arbitrary File Upload Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97642

LibreOffice CVE-2017-3157 Local Information Disclosure Vulnerability
2017-04-18
http://www.securityfocus.com/bid/96402

Adobe Flash Player APSB17-10 Multiple Memory Corruption Vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/97557

Adobe Flash Player APSB17-10 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/97551

Apache HTTP Server CVE-2016-8743 Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/95077

Apache HTTP Server CVE-2016-0736 Remote Security Vulnerability
2017-04-18
http://www.securityfocus.com/bid/95078

Apache HTTP Server CVE-2016-2161 Denial of Service Vulnerability
2017-04-18
http://www.securityfocus.com/bid/95076

Libosip Multiple Denial of Service Vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/92921

GNU oSIP CVE-2016-10324 Heap Buffer Overflow Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97641

Drupal Legal Module Unspecified Security Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97640

Wireshark 'dissectors/packet-packetbb.c' Denial of Service Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97638Huawei Honor 6X CVE-2017-2733 Local Information Disclosure Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97700

Multiple Samsung Galaxy Products CVE-2016-4031 Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97703

Apache Log4j CVE-2017-5645 Remote Code Execution Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97702

Multiple Samsung Galaxy Products CVE-2016-4030 Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97701

Axis Network Cameras CVE-2015-8256 HTML Injection and Cross Site Scripting vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/97699

Huawei Smart Phones Multiple Local Buffer Overflow Vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/97696

Oracle VM VirtualBox CVE-2017-3538 Local Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97698

Multiple Toshiba memory card installers DLL Loading Remote Code Execution Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97697

Asterisk Open Source and Certified Asterisk RTP Resource Exhaustion Denial of Service Vulnerability
2017-04-18
http://www.securityfocus.com/bid/92888

Google gRPC CVE-2017-7861 Heap Based Buffer Overflow Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97694

PostgreSQL CVE-2016-5424 Multiple Local Privilege Escalation Vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/92435

PostgreSQL CVE-2016-5423 NULL Pointer Dereference Remote Code Execution Vulnerability
2017-04-18
http://www.securityfocus.com/bid/92433

Google gRPC CVE-2017-7860 Heap Buffer Overflow Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97695

Juniper NorthStar Controller Application CVE-2017-2321 Remote Privilege Escalation Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97693

Linux Kernel CVE-2017-7889 Multiple Local Security Bypass Vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/97690

Juniper NorthStar Controller Application CVE-2017-2326 Local Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97691

Philips In.Sight CVE-2015-2884 Information Disclosure Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97683

python-pysaml2 CVE-2016-10149 XML Entity Expansion Denial of Service Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97692

ISC BIND CVE-2016-2775 Remote Denial of Service Vulnerability
2017-04-18
http://www.securityfocus.com/bid/92037

ISC BIND CVE-2016-6170 Remote Denial of Service Vulnerability
2017-04-18
http://www.securityfocus.com/bid/91611

Juniper NorthStar Controller Application CVE-2017-2320 Remote Privilege Escalation Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97687

Quest Privilege Manager CVE-2017-6554 Arbitrary File Overwrite Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97686

Ubuntu AppArmor CVE-2017-6507 Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97223

Schneider Electric Modicon CVE-2017-7575 Information Disclosure Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97523

Linux Kernel CVE-2017-2636 Local Privilege Escalation Vulnerability
2017-04-18
http://www.securityfocus.com/bid/96732

Schneider Electric SoMachine and Modicon CVE-2017-7574 Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97518

Linux kernel Local Use After Free Multiple Denial of Service Vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/94135

Dovecot CVE-2017-2669 Denial of Service Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97536

Apple macOS APPLE-SA-2017-03-27-3 Multiple Security Vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/97140

WebKit CVE-2017-2415 Remote Code Execution Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97143Huawei Honor 6X CVE-2017-2733 Local Information Disclosure Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97700

Multiple Samsung Galaxy Products CVE-2016-4031 Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97703

Apache Log4j CVE-2017-5645 Remote Code Execution Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97702

Multiple Samsung Galaxy Products CVE-2016-4030 Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97701

Axis Network Cameras CVE-2015-8256 HTML Injection and Cross Site Scripting vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/97699

Huawei Smart Phones Multiple Local Buffer Overflow Vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/97696

Oracle VM VirtualBox CVE-2017-3538 Local Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97698

Multiple Toshiba memory card installers DLL Loading Remote Code Execution Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97697

Asterisk Open Source and Certified Asterisk RTP Resource Exhaustion Denial of Service Vulnerability
2017-04-18
http://www.securityfocus.com/bid/92888

Google gRPC CVE-2017-7861 Heap Based Buffer Overflow Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97694

PostgreSQL CVE-2016-5424 Multiple Local Privilege Escalation Vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/92435

PostgreSQL CVE-2016-5423 NULL Pointer Dereference Remote Code Execution Vulnerability
2017-04-18
http://www.securityfocus.com/bid/92433

Google gRPC CVE-2017-7860 Heap Buffer Overflow Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97695

Juniper NorthStar Controller Application CVE-2017-2321 Remote Privilege Escalation Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97693

Linux Kernel CVE-2017-7889 Multiple Local Security Bypass Vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/97690

Juniper NorthStar Controller Application CVE-2017-2326 Local Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97691

Philips In.Sight CVE-2015-2884 Information Disclosure Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97683

python-pysaml2 CVE-2016-10149 XML Entity Expansion Denial of Service Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97692

ISC BIND CVE-2016-2775 Remote Denial of Service Vulnerability
2017-04-18
http://www.securityfocus.com/bid/92037

ISC BIND CVE-2016-6170 Remote Denial of Service Vulnerability
2017-04-18
http://www.securityfocus.com/bid/91611

Juniper NorthStar Controller Application CVE-2017-2320 Remote Privilege Escalation Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97687

Quest Privilege Manager CVE-2017-6554 Arbitrary File Overwrite Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97686

Ubuntu AppArmor CVE-2017-6507 Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97223

Schneider Electric Modicon CVE-2017-7575 Information Disclosure Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97523

Linux Kernel CVE-2017-2636 Local Privilege Escalation Vulnerability
2017-04-18
http://www.securityfocus.com/bid/96732

Schneider Electric SoMachine and Modicon CVE-2017-7574 Security Bypass Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97518

Linux kernel Local Use After Free Multiple Denial of Service Vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/94135

Dovecot CVE-2017-2669 Denial of Service Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97536

Apple macOS APPLE-SA-2017-03-27-3 Multiple Security Vulnerabilities
2017-04-18
http://www.securityfocus.com/bid/97140

WebKit CVE-2017-2415 Remote Code Execution Vulnerability
2017-04-18
http://www.securityfocus.com/bid/97143

SANS News

Tool to Detect Active Phishing Attacks Using Unicode Look-Alike Domains

Yet Another Apple Phish and Some DNS Lessons Learned From It

Threatpost

VMware Fixes Critical RCE in vCenter Server

ShadowBrokers’ Windows Zero-Days Already Patched

Wave of Java-Based RATs Target Tax Filers

Exploit

Microsoft Windows - Uncredentialed SMB RCE (MS17-010) (Metasploit)

Mantis Bug Tracker 1.3.0/2.3.0 - Password Reset

WinSCP 5.9.4 - 'LIST' Denial of Service (Metasploit)

17.4.2017

Bugtraq

Watchguard Fireware XXE DoS & User Enumeration 2017-04-17
David Fernandez (david fdmv gmail com)

concrete5 v8.1.0 Host Header Injection 2017-04-14
apparitionsec gmail com (hyp3rlinx)

[slackware-security] bind (SSA:2017-103-01) 2017-04-13
Slackware Security Team (security slackware com)

Malware

Trojan.Spanderditz

Backdoor.Raslup

Backdoor.Objod

Trojan.Symmi

Ransom.Mole

Phishing

Apple ID

15th April 2017

Reminder: statement account
update information login

FEDERAL BUREAU OF INVESTIGATIO

14th April 2017

Executive Director FBI

Vulnerebility

LibreOffice CVE-2017-7870 Heap Buffer Overflow Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97671

IBM API Connect CVE-2017-1161 Command Execution Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97665

Juniper NorthStar Controller Application CVE-2017-2318 Remote Privilege Escalation Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97660

IBM Marketing Platform CVE-2016-0228 Open Redirect Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97670

Bitrix CVE-2015-8356 Multiple SQL Injection Vulnerabilities
2017-04-17
http://www.securityfocus.com/bid/97669

Multiple IBM Products CVE-2017-1160 Multiple Cross Site Scripting Vulnerabilities
2017-04-17
http://www.securityfocus.com/bid/97666

LibreOffice CVE-2016-10327 Heap Buffer Overflow Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97668

FFmpeg CVE-2017-7859 Heap Buffer Overflow Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97663

LibreOffice CVE-2017-7856 Heap Buffer Overflow Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97667

Apache Flex BlazeDS CVE-2017-5641 Remote Code Execution Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97383

FFmpeg CVE-2017-7866 Stack Buffer Overflow Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97664

ISC BIND CVE-2017-3137 Remote Denial of Service Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97651

Google Android CVE-2016-1155 HTTP Header Injection Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97662

Juniper NorthStar Controller Application CVE-2017-2317 Unspecified Denial of Service Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97652

SAP Business Intelligence CVE-2016-6818 SQL Injection Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97661

Concrete5 CVE-2017-7725 HTML Injection Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97649

Oracle April 2017 Critical Patch Update Multiple Vulnerabilities
2017-04-17
http://www.securityfocus.com/bid/97655

WordPress Spider Event Calendar Plugin CVE-2017-7719 Multiple SQL Injection Vulnerabilities
2017-04-17
http://www.securityfocus.com/bid/97656

Samsung SecEmailSync CVE-2016-2565 Information Disclosure Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97658

Samsung SecEmailSync CVE-2016-2566 SQL Injection Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97654

Drupal Book access Module Unspecified Security Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97645

ISC BIND CVE-2017-3136 Remote Denial of Service Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97653

ISC BIND CVE-2017-3138 Remote Denial of Service Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97657

Juniper NorthStar Controller Application CVE-2017-2319 Authentication Bypass Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97659

Multiple Samsung Galaxy Products CVE-2016-4032 Security Bypass Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97650

Drupal References Module Unspecified Security Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97643

Drupal Media Module Unspecified Security Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97647

GNU oSIP 'osipparser2/osip_message_parse.c' Heap Buffer Overflow Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97644

Drupal Open Atrium Module Information Disclosure Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97646

radare2 '/format/wasm/wasm.c' Heap Buffer Overflow Vulnerability
2017-04-17
http://www.securityfocus.com/bid/97648

SANS News

Detecting SMB Covert Channel ("Double Pulsar")

Threatpost

 

Exploit

VirusChaser 8.0 - Buffer Overflow (SEH)

Mantis Bug Tracker 1.3.0/2.3.0 - Password Reset

WinSCP 5.9.4 - 'LIST' Denial of Service (Metasploit)

16.4.2017

Bugtraq

concrete5 v8.1.0 Host Header Injection 2017-04-14
apparitionsec gmail com (hyp3rlinx)

[slackware-security] bind (SSA:2017-103-01) 2017-04-13
Slackware Security Team (security slackware com)

[security bulletin] HPESBGN03728 rev.1 - HPE Operations Agent using OpenSSL, Remote Denial of Service (DoS), Unauthorized Access to Data 2017-04-13
security-alert hpe com

[SYSS-2017-009] agorum core Pro - Improper Restriction of XML External Entity Reference ('XXE') 2017-04-13
erlijn vangenuchten syss de

[SYSS-2017-008] agorum core Pro - Cross-Site Request Forgery 2017-04-13
erlijn vangenuchten syss de

Malware

TrojanDownloader:Win32/Rivit.A!dha 

Phishing

FEDERAL BUREAU OF INVESTIGATIO

14th April 2017

Executive Director FBI

Apple

14th April 2017

Please Verify your Apple ID
before We closed your account

Chase

13th April 2017

Request to Update Your Chase
Account Information!

O2

13th April 2017

RECEIVE YOUR O2 BILL IS READY
(CONTAINS MALWARE
SANESECURITY.MALWARE.26842.UNO
FFICIAL)

Vulnerebility

QEMU 'hw/block/fdc.c' VENOM Remote Memory Corruption Vulnerability
2017-04-15
http://www.securityfocus.com/bid/74640

QEMU AMD PCnet Ethernet Emulation Heap Based Buffer Overflow Vulnerability
2017-04-15
http://www.securityfocus.com/bid/75123

ISC BIND CVE-2015-5477 Remote Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/76092

Node.js CVE-2013-4450 Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/63229

ISC BIND 'isselfsigned()' Function Remote Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/75588

Juniper NorthStar Controller Application CVE-2017-2334 Security Bypass Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97616

Juniper Junos CVE-2017-2312 Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97611

Juniper NorthStar Controller Application CVE-2017-2329 Local Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97614

Juniper Junos CVE-2017-2340 Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97607

Adobe Flash Player APSB17-10 Multiple Memory Corruption Vulnerabilities
2017-04-15
http://www.securityfocus.com/bid/97557

Adobe Flash Player APSB17-10 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-04-15
http://www.securityfocus.com/bid/97551

util-linux CVE-2017-2616 Local Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/96404

Red Hat CloudForms Management App CVE-2017-2653 Security Bypass Vulnerability
2017-04-15
http://www.securityfocus.com/bid/96964

Juniper NorthStar Controller Application CVE-2017-2333 Unspecified Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97608

Trend Micro Threat Discovery Appliance CVE-2016-7547 Command Execution Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97610

Red Hat 389-ds-base CVE-2017-2668 Remote Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97524

Juniper Junos CVE-2017-2313 Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97606

Juniper NorthStar Controller Application CVE-2017-2327 Local Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97609

Red Hat JBoss Enterprise Application Platform CVE-2017-7465 Remote Code Injection Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97605

Linux Kernel 'selinux/hooks.c' Local Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/96272

Linux Kernel CVE-2016-8650 Null Pointer Deference Local Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/94532

Linux Kernel CVE-2017-2636 Local Privilege Escalation Vulnerability
2017-04-15
http://www.securityfocus.com/bid/96732

Fortinet FortiWLC-SD CVE-2017-3134 Privilege Escalation Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97603

Juniper NorthStar Controller Application CVE-2017-2324 Unspecified Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97604

Linux Kernel CVE-2017-6074 Local Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/96310

Linux kernel Local Use After Free Multiple Denial of Service Vulnerabilities
2017-04-15
http://www.securityfocus.com/bid/94135

Google Android Bouncy Castle CVE-2015-6644 Information Disclosure Vulnerability
2017-04-15
http://www.securityfocus.com/bid/79865

QEMU 'hw/usb/hcd-ohci.c' Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/96611

Xen 'memory_exchange()' Function Incomplete Fix Privilege Escalation Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97375

Dovecot CVE-2017-2669 Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97536LibreOffice CVE-2017-7870 Heap Buffer Overflow Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97671

IBM API Connect CVE-2017-1161 Command Execution Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97665

Juniper NorthStar Controller Application CVE-2017-2318 Remote Privilege Escalation Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97660

IBM Marketing Platform CVE-2016-0228 Open Redirect Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97670

Bitrix CVE-2015-8356 Multiple SQL Injection Vulnerabilities
2017-04-15
http://www.securityfocus.com/bid/97669

Multiple IBM Products CVE-2017-1160 Multiple Cross Site Scripting Vulnerabilities
2017-04-15
http://www.securityfocus.com/bid/97666

LibreOffice CVE-2016-10327 Heap Buffer Overflow Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97668

FFmpeg CVE-2017-7859 Heap Buffer Overflow Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97663

LibreOffice CVE-2017-7856 Heap Buffer Overflow Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97667

Apache Flex BlazeDS CVE-2017-5641 Remote Code Execution Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97383

FFmpeg CVE-2017-7866 Stack Buffer Overflow Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97664

ISC BIND CVE-2017-3137 Remote Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97651

Google Android CVE-2016-1155 HTTP Header Injection Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97662

Juniper NorthStar Controller Application CVE-2017-2317 Unspecified Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97652

SAP Business Intelligence CVE-2016-6818 SQL Injection Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97661

Concrete5 CVE-2017-7725 HTML Injection Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97649

Oracle April 2017 Critical Patch Update Multiple Vulnerabilities
2017-04-15
http://www.securityfocus.com/bid/97655

WordPress Spider Event Calendar Plugin CVE-2017-7719 Multiple SQL Injection Vulnerabilities
2017-04-15
http://www.securityfocus.com/bid/97656

Samsung SecEmailSync CVE-2016-2565 Information Disclosure Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97658

Samsung SecEmailSync CVE-2016-2566 SQL Injection Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97654

Drupal Book access Module Unspecified Security Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97645

ISC BIND CVE-2017-3136 Remote Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97653

ISC BIND CVE-2017-3138 Remote Denial of Service Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97657

Juniper NorthStar Controller Application CVE-2017-2319 Authentication Bypass Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97659

Multiple Samsung Galaxy Products CVE-2016-4032 Security Bypass Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97650

Drupal References Module Unspecified Security Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97643

Drupal Media Module Unspecified Security Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97647

GNU oSIP 'osipparser2/osip_message_parse.c' Heap Buffer Overflow Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97644

Drupal Open Atrium Module Information Disclosure Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97646

radare2 '/format/wasm/wasm.c' Heap Buffer Overflow Vulnerability
2017-04-15
http://www.securityfocus.com/bid/97648

SANS News

ETERNALBLUE: Confirmed Unpatched Window SMBv1 Exploit

Threatpost

Stories From Two Years in an IoT Honeypot

Google Making Life Difficult for Ransomware to Thrive on Android

Exploit

Concrete5 8.1.0 - 'Host' Header Injection

Linux Kernel 4.8.0 UDEV < 232 - Privilege Escalation

14.4.2017

Bugtraq

concrete5 v8.1.0 Host Header Injection 2017-04-14
apparitionsec gmail com (hyp3rlinx)

[slackware-security] bind (SSA:2017-103-01) 2017-04-13
Slackware Security Team (security slackware com)

[security bulletin] HPESBGN03728 rev.1 - HPE Operations Agent using OpenSSL, Remote Denial of Service (DoS), Unauthorized Access to Data 2017-04-13
security-alert hpe com

[SYSS-2017-009] agorum core Pro - Improper Restriction of XML External Entity Reference ('XXE') 2017-04-13
erlijn vangenuchten syss de

[SYSS-2017-008] agorum core Pro - Cross-Site Request Forgery 2017-04-13
erlijn vangenuchten syss de

[SYSS-2017-007] agorum core Pro - Cross-Site Scripting 2017-04-13
erlijn vangenuchten syss de

[SYSS-2017-006] agorum core Pro - Insecure Direct Object Reference 2017-04-13
erlijn vangenuchten syss de

[SYSS-2017-005] agorum core Pro - Persistent Cross-Site Scripting 2017-04-13
erlijn vangenuchten syss de

April 2017 - HipChat Server Advisory 2017-04-13
Matthew Hart (mhart atlassian com)

Malware

VBS.Dropper.A

Ransom.Mole

Phishing

Apple

14th April 2017

Please Verify your Apple ID
before We closed your account

Chase

13th April 2017

Request to Update Your Chase
Account Information!

O2

13th April 2017

RECEIVE YOUR O2 BILL IS READY
(CONTAINS MALWARE
SANESECURITY.MALWARE.26842.UNO
FFICIAL)

Vulnerebility

Libosip Multiple Denial of Service Vulnerabilities
2017-04-14
http://www.securityfocus.com/bid/92921

Drupal Legal Module Unspecified Security Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97640

Wireshark 'dissectors/packet-packetbb.c' Denial of Service Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97638

Wecon Technologies LEVI Studio HMI Editor Multiple Security Vulnerabilities
2017-04-14
http://www.securityfocus.com/bid/97639

Wireshark WBXML Dissector 'packet-wbxml.c' Infinite Loop Denial of Service Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97633

Drupal Filemaker Form Module Unspecified Security Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97637

Wireshark DOF Dissector 'packet-dof.c' Infinite Loop Denial of Service Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97634

Wireshark RPCoRDMA Dissector 'packet-rpcrdma.c' Infinite Loop Denial of Service Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97630

Wireshark 'dissectors/packet-imap.c' Denial of Service Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97636

Drupal @Base Module Unspecified Security Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97623

Wireshark SLSK Dissector 'dissectors/packet-slsk.c' Infinite Loop Denial of Service Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97635

Drupal Scheduler Workbench Integration Module Unspecified Security Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97622

Wireshark BGP dissector Infinite Loop Denial of Service Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97632

Juniper NorthStar Controller Application CVE-2017-2332 Remote Privilege Escalation Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97624

Wireshark WSP Dissector 'packet-wsp.c' Infinite Loop Denial of Service Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97628

Wireshark NetScaler File Parser 'wiretap/netscaler.c' Infinite Loop Denial of Service Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97631

Adobe Flash Player APSB17-10 Multiple Memory Corruption Vulnerabilities
2017-04-14
http://www.securityfocus.com/bid/97557

Adobe Flash Player APSB17-10 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-04-14
http://www.securityfocus.com/bid/97551

IBM Tivoli Application Dependency Discovery Manager CVE-2016-8927 Cross Site Scripting Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97629

Juniper NorthStar Controller Application CVE-2017-2328 Local Information Disclosure Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97617

Wireshark SIGCOMP Dissector 'packet-sigcomp.c' Infinite Loop Denial of Service Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97627

IBM Tivoli Application Dependency Discovery Manager CVE-2016-8925 Remote File Include Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97625

Juniper NorthStar Controller Application CVE-2017-2331 Authentication Bypass Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97619

Juniper NorthStar Controller Application CVE-2017-2330 Local Denial of Service Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97618

Atlassian Hipchat Server CVE-2017-7357 Remote Code Execution Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97621

Citrix NetScaler Gateway CVE-2017-7219 Heap Buffer Overflow Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97626

Red Hat Storage Console CVE-2017-2665 Insecure Password Storage Information Disclosure Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97612

D-Link DWR-116 CVE-2017-6190 Arbitrary File Download Vulnerabilitiy
2017-04-14
http://www.securityfocus.com/bid/97620

Juniper NorthStar Controller Application CVE-2017-2322 Local Denial of Service Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97613

Juniper Junos CVE-2017-2315 Denial of Service Vulnerability
2017-04-14
http://www.securityfocus.com/bid/97615

SANS News

 

Threatpost

Exploit Kit Activity Quiets, But Is Far From Silent

FDA Demands St. Jude Take Action on Medical Device Security

Exploit

Microsoft Windows Kernel win32k.sys - Multiple Bugs in the NtGdiGetDIBitsInternal...

Microsoft Windows Kernel - 'win32kfull!SfnINLPUAHDRAWMENUITEM' Stack Memory...

Linux/x86-64 - execve("/bin/sh") Shellcode (31 bytes)

13.4.2017

Bugtraq

[SYSS-2017-009] agorum core Pro - Improper Restriction of XML External Entity Reference ('XXE') 2017-04-13
erlijn vangenuchten syss de

[SYSS-2017-008] agorum core Pro - Cross-Site Request Forgery 2017-04-13
erlijn vangenuchten syss de

[SYSS-2017-007] agorum core Pro - Cross-Site Scripting 2017-04-13
erlijn vangenuchten syss de

[SYSS-2017-006] agorum core Pro - Insecure Direct Object Reference 2017-04-13
erlijn vangenuchten syss de

[SYSS-2017-005] agorum core Pro - Persistent Cross-Site Scripting 2017-04-13
erlijn vangenuchten syss de

April 2017 - HipChat Server Advisory 2017-04-13
Matthew Hart (mhart atlassian com)

DefenseCode Security Advisory: Magento 0day Arbitrary File Upload Vulnerability (Remote Code Execution, CSRF) 2017-04-12
DefenseCode (defensecode defensecode com)

CVE-2017-7456 Moxa MXview v2.8 Denial Of Service 2017-04-12
apparitionsec gmail com (hyp3rlinx)

CVE-2017-7455 Moxa MXview v2.8 Remote Private Key Disclosure 2017-04-12
apparitionsec gmail com (hyp3rlinx)

CVE-2017-7457 Moxa MX AOPC-Server v1.5 XML External Entity Injection 2017-04-12
apparitionsec gmail com (hyp3rlinx)

Malware

Phishing

 

Vulnerebility

Linux Kernel 'selinux/hooks.c' Local Denial of Service Vulnerability
2017-04-13
http://www.securityfocus.com/bid/96272

Linux Kernel CVE-2016-8650 Null Pointer Deference Local Denial of Service Vulnerability
2017-04-13
http://www.securityfocus.com/bid/94532

Linux Kernel CVE-2017-2636 Local Privilege Escalation Vulnerability
2017-04-13
http://www.securityfocus.com/bid/96732

Fortinet FortiWLC-SD CVE-2017-3134 Privilege Escalation Vulnerability
2017-04-13
http://www.securityfocus.com/bid/97603

Juniper NorthStar Controller Application CVE-2017-2324 Unspecified Denial of Service Vulnerability
2017-04-13
http://www.securityfocus.com/bid/97604

Linux Kernel CVE-2017-6074 Local Denial of Service Vulnerability
2017-04-13
http://www.securityfocus.com/bid/96310

Linux kernel Local Use After Free Multiple Denial of Service Vulnerabilities
2017-04-13
http://www.securityfocus.com/bid/94135

Google Android Bouncy Castle CVE-2015-6644 Information Disclosure Vulnerability
2017-04-13
http://www.securityfocus.com/bid/79865

QEMU 'hw/usb/hcd-ohci.c' Denial of Service Vulnerability
2017-04-13
http://www.securityfocus.com/bid/96611

Xen 'memory_exchange()' Function Incomplete Fix Privilege Escalation Vulnerability
2017-04-13
http://www.securityfocus.com/bid/97375

Dovecot CVE-2017-2669 Denial of Service Vulnerability
2017-04-13
http://www.securityfocus.com/bid/97536

Juniper NorthStar Controller Application CVE-2017-2325 Buffer Overflow Vulnerability
2017-04-13
http://www.securityfocus.com/bid/97602

Pidgin CVE 2017-2640 Out of Bounds Write Security Vulnerability
2017-04-13
http://www.securityfocus.com/bid/96775

Juniper NorthStar Controller Application CVE-2017-2316 Local Buffer Overflow Vulnerability
2017-04-13
http://www.securityfocus.com/bid/97601

X.org X Server Local Multiple Security Vulnerabilities
2017-04-13
http://www.securityfocus.com/bid/96480

X.Org libXi CVE-2016-7946 Multiple Unspecified Security Vulnerabilities
2017-04-13
http://www.securityfocus.com/bid/93374

X.Org libXrender CVE-2016-7950 Out of Bounds Write Denial of Service Vulnerability
2017-04-13
http://www.securityfocus.com/bid/93369

X.Org libXvMC CVE-2016-7953 Memory Corruption Vulnerability
2017-04-13
http://www.securityfocus.com/bid/93371

X.Org libXrender CVE-2016-7949 Buffer Overflow Vulnerability
2017-04-13
http://www.securityfocus.com/bid/93366

X.Org libX11 CVE-2016-7942 Memory Corruption Vulnerability
2017-04-13
http://www.securityfocus.com/bid/93363

X.Org libXrandr CVE-2016-7948 Multiple Unspecified Security Vulnerabilities
2017-04-13
http://www.securityfocus.com/bid/93373

X.Org libXfixes CVE-2016-7944 Integer Overflow Vulnerability
2017-04-13
http://www.securityfocus.com/bid/93361

X.Org libXv CVE-2016-5407 Memory Corruption Vulnerability
2017-04-13
http://www.securityfocus.com/bid/93368

X.Org libXrandr CVE-2016-7947 Multiple Integer Overflow Vulnerabilities
2017-04-13
http://www.securityfocus.com/bid/93365

X.Org libXfixes CVE-2016-7945 Multiple Integer Overflow Vulnerabilities
2017-04-13
http://www.securityfocus.com/bid/93364

X.Org libX11 CVE-2016-7943 Memory Corruption Vulnerability
2017-04-13
http://www.securityfocus.com/bid/93362

Google Chrome and Chrome OS Multiple Security Vulnerabilities
2017-04-13
http://www.securityfocus.com/bid/97220

Google Chrome CVE-2017-5055 Use After Free Memory Corruption Vulnerability
2017-04-13
http://www.securityfocus.com/bid/97221

QEMU CVE-2017-6058 Denial of Service Vulnerability
2017-04-13
http://www.securityfocus.com/bid/96277

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-04-13
http://www.securityfocus.com/bid/96378Wireshark 'packet-btl2cap.c' Denial of Service Vulnerability
2017-04-13
http://www.securityfocus.com/bid/97597

Microsoft Office OLE Feature Remote Code Execution Vulnerability
2017-04-13
http://www.securityfocus.com/bid/97498

Palo Alto Networks PAN-OS CVE-2017-7218 Local Privilege Escalation Vulnerability
2017-04-13
http://www.securityfocus.com/bid/97592

Symphony CMS CVE-2017-7694 Remote Code Execution Vulnerability
2017-04-13
http://www.securityfocus.com/bid/97594

audiofile CVE-2017-6832 Heap Based Buffer Overflow Vulnerability
2017-04-13
http://www.securityfocus.com/bid/97589

Ansible CVE-2017-7466 Incomplete Fix Arbitrary Command Execution Vulnerability
2017-04-13
http://www.securityfocus.com/bid/97595

SAP NetWeaver TREX and BWA Remote Code Execution Vulnerability
2017-04-13
http://www.securityfocus.com/bid/97567

audiofile CVE-2017-6831 Heap Based Buffer Overflow Vulnerability
2017-04-13
http://www.securityfocus.com/bid/97588

libsamplerate 'src_sinc.c' Local Buffer Overflow Vulnerability
2017-04-13
http://www.securityfocus.com/bid/97587

Trend Micro Deep Discovery Email Inspector 'policy_setting' Arbitrary File Upload Vulnerability
2017-04-13
http://www.securityfocus.com/bid/97591

Palo Alto Networks PAN-OS CVE-2017-7126 Information Disclosure Vulnerability
2017-04-13
http://www.securityfocus.com/bid/97590

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-04-13
http://www.securityfocus.com/bid/96378

QEMU 'hw/usb/hcd-ohci.c' Denial of Service Vulnerability
2017-04-13
http://www.securityfocus.com/bid/96611

QEMU CVE-2017-6058 Denial of Service Vulnerability
2017-04-13
http://www.securityfocus.com/bid/96277

QEMU 'hw/usb/hcd-xhci.c' Denial of Service Vulnerability
2017-04-13
http://www.securityfocus.com/bid/96220

QEMU CVE-2016-9602 Privilege Escalation Vulnerability
2017-04-13
http://www.securityfocus.com/bid/95461

QEMU 'hw/sd/sdhci.c' Denial of Service Vulnerability
2017-04-13
http://www.securityfocus.com/bid/96263

QEMU 'nbd/client.c' Stack Buffer Overflow Vulnerability
2017-04-13
http://www.securityfocus.com/bid/96265

X.org X Server Local Multiple Security Vulnerabilities
2017-04-13
http://www.securityfocus.com/bid/96480

X.Org libXi CVE-2016-7946 Multiple Unspecified Security Vulnerabilities
2017-04-13
http://www.securityfocus.com/bid/93374

X.Org libXrandr CVE-2016-7948 Multiple Unspecified Security Vulnerabilities
2017-04-13
http://www.securityfocus.com/bid/93373

X.Org libXvMC CVE-2016-7953 Memory Corruption Vulnerability
2017-04-13
http://www.securityfocus.com/bid/93371

X.Org libXrender CVE-2016-7949 Buffer Overflow Vulnerability
2017-04-13
http://www.securityfocus.com/bid/93366

X.Org libXrender CVE-2016-7950 Out of Bounds Write Denial of Service Vulnerability
2017-04-13
http://www.securityfocus.com/bid/93369

X.Org libXv CVE-2016-5407 Memory Corruption Vulnerability
2017-04-13
http://www.securityfocus.com/bid/93368

X.Org libXfixes CVE-2016-7945 Multiple Integer Overflow Vulnerabilities
2017-04-13
http://www.securityfocus.com/bid/93364

X.Org libXrandr CVE-2016-7947 Multiple Integer Overflow Vulnerabilities
2017-04-13
http://www.securityfocus.com/bid/93365

X.Org libX11 CVE-2016-7943 Memory Corruption Vulnerability
2017-04-13
http://www.securityfocus.com/bid/93362

X.Org libX11 CVE-2016-7942 Memory Corruption Vulnerability
2017-04-13
http://www.securityfocus.com/bid/93363

X.Org libXfixes CVE-2016-7944 Integer Overflow Vulnerability
2017-04-13
http://www.securityfocus.com/bid/93361

SANS News

Packet Captures Filtered by Process

Threatpost

Office Zero Day Delivering FINSPY Spyware to Victims in Russia

Phone Hack Uses Sensors To Steal PINs

Netflix’s HTTPS Update Can’t Combat Passive Traffic Analysis Attacks

Exploit

Cisco Catalyst 2960 IOS 12.2(55)SE11 - 'ROCEM' Remote Code Execution

GNS3 Mac OS-X 1.5.2 - 'ubridge' Privilege Escalation

Solaris 7 - 11 (x86 & SPARC) - 'EXTREMEPARR' dtappgather Privilege Escalation

Cisco Catalyst 2960 IOS 12.2(55)SE11 - 'ROCEM' Remote Code Execution

Coppermine Gallery < 1.5.44 - Directory Traversal Weaknesses

SedSystems D3 Decimator - Multiple Vulnerabilities

PonyOS 4.0 - 'fluttershy' LD_LIBRARY_PATH Local Kernel Exploit

Adobe Creative Cloud Desktop Application <= 4.0.0.185 - Privilege Escalation

12.4.2017

Bugtraq

FreeBSD Security Advisory FreeBSD-SA-17:03.ntp 2017-04-12
FreeBSD Security Advisories (security-advisories freebsd org)

[SECURITY] [DSA 3829-1] bouncycastle security update 2017-04-11
Moritz Muehlenhoff (jmm debian org)

Microsoft Office OneNote 2007 DLL side loading vulnerability 2017-04-11
Securify B.V. (lists securify nl)

Multiple local privilege escalation vulnerabilities in Proxifier for Mac 2017-04-11
Securify B.V. (lists securify nl)

[SECURITY] CVE-2017-5648 Apache Tomcat Information Disclosure 2017-04-10
Mark Thomas (markt apache org)

[SECURITY] CVE-2017-5651 Apache Tomcat Information Disclosure 2017-04-10
Mark Thomas (markt apache org)

DefenseCode ThunderScan SAST Advisory: WordPress Tribulant Slideshow Gallery Plugin - Cross-Site Scripting Vulnerabilities 2017-04-10
DefenseCode (defensecode defensecode com)

ChromeOS / ChromeBooks Persist Certain Network Settings in Guest Mode 2017-04-09
Nightwatch Cybersecurity Research (research nightwatchcybersecurity com)

Foscam All networked devices, multiple Design Errors. SSL bypass. 2017-04-09
nick m mckenna gmail com

Malware

 

Phishing

Amazon

11th April 2017

Amazon - 3rd attempt failed

Vulnerebility

Google Chrome Prior to 50.0.2661.102 Multiple Security Vulnerabilities
2017-04-12
http://www.securityfocus.com/bid/90584

Keycloak CVE-2016-8629 Security Bypass Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97392

Redhat Wildfly CVE-2016-9589 Denial of Service Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97060

Keycloak CVE-2017-2585 Security Bypass Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97393

Fiyo CMS '/dapur/apps/app_theme/libs/save_file.php' Arbitrary File Upload Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97571

SAPLPD Multiple Unspecified Security Vulnerabilities
2017-04-12
http://www.securityfocus.com/bid/97574

SAP ERP Stakeholder Relationship Management Multiple Unspecified Security Vulnerabilities
2017-04-12
http://www.securityfocus.com/bid/97569

Google Android CVE-2016-8399 Remote Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/94708

JasPer CVE-2016-9591 Denial of Service Vulnerability
2017-04-12
http://www.securityfocus.com/bid/94952

SAP NetWeaver Knowledge Management XML External Entity Injection Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97572

Apache Camel CVE-2017-3159 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/96321

Apache Commons HttpClient CVE-2012-5783 SSL Certificate Validation Security Bypass Vulnerability
2017-04-12
http://www.securityfocus.com/bid/58073

SparkJava Spark CVE-2016-9177 Directory Traversal Vulnerability
2017-04-12
http://www.securityfocus.com/bid/94218

Apache Groovy CVE-2016-6814 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/95429

Elasticsearch Groovy Scripting Engine Sandbox Security Bypass Vulnerability
2017-04-12
http://www.securityfocus.com/bid/72585

SAP NetWeaver ADBC Demo Programs Remote Authorization Bypass Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97568

SAP ERP Remote Authorization Bypass Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97570

SAP NetWeaver TREX and BWA Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97567

Multiple SAP Products Memory Corruption Vulnerability
2017-04-12
http://www.securityfocus.com/bid/96205

SAP GUI CVE-2017-6950 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/96872

SAP NetWeaver Central Technical Configuration Unspecified Cross Site Scripting Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97566

SAP NetWeaver Java Archiving Framework Unspecified Cross Site Scripting Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97565

DBPOWER U818A CVE-2017-3209 Security Bypass Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97564

Multiple Dell iDRAC Products CVE-2015-7271 Remote Format String Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97561

SAP BI LaunchPad Unspecified Cross Site Request Forgery Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97563

Schneider Electric Modicon Modbus Protocol Multiple Authentication Bypass Vulnerabilities
2017-04-12
http://www.securityfocus.com/bid/97562

libjpeg/libjpeg-turbo Library CVE-2013-6629 Memory Corruption Vulnerability
2017-04-12
http://www.securityfocus.com/bid/63676

Lenovo CVE-2016-8237 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97560

Microsoft Windows Hyper-V CVE-2017-0178 Remote Denial of Service Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97416

Microsoft Windows OLE CVE-2017-0211 Local Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97514
Adobe Reader and Acrobat APSB17-11 Multiple Remote Code Execution Vulnerabilities
2017-04-12
http://www.securityfocus.com/bid/97547

Dell iDRAC6 CVE-2015-7274 Arbitrary Command Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97546

Dell iDRAC6 CVE-2015-7274 Arbitrary Command Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97545

Lenovo CCSDK CVE-2016-8235 Local Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97543

Google Android CVE-2016-8399 Remote Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/94708

JasPer CVE-2016-9591 Denial of Service Vulnerability
2017-04-12
http://www.securityfocus.com/bid/94952

Apache Camel CVE-2017-3159 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/96321

Apache Commons HttpClient CVE-2012-5783 SSL Certificate Validation Security Bypass Vulnerability
2017-04-12
http://www.securityfocus.com/bid/58073

SparkJava Spark CVE-2016-9177 Directory Traversal Vulnerability
2017-04-12
http://www.securityfocus.com/bid/94218

Apache Groovy CVE-2016-6814 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/95429

Elasticsearch Groovy Scripting Engine Sandbox Security Bypass Vulnerability
2017-04-12
http://www.securityfocus.com/bid/72585

SAP ERP Remote Authorization Bypass Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97570

SAP NetWeaver TREX and BWA Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97567

Multiple SAP Products Memory Corruption Vulnerability
2017-04-12
http://www.securityfocus.com/bid/96205

SAP GUI CVE-2017-6950 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/96872

SAP NetWeaver Central Technical Configuration Unspecified Cross Site Scripting Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97566

SAP NetWeaver Java Archiving Framework Unspecified Cross Site Scripting Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97565

DBPOWER U818A CVE-2017-3209 Security Bypass Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97564

Multiple Dell iDRAC Products CVE-2015-7271 Remote Format String Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97561

SAP BI LaunchPad Unspecified Cross Site Request Forgery Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97563

Schneider Electric Modicon Modbus Protocol Multiple Authentication Bypass Vulnerabilities
2017-04-12
http://www.securityfocus.com/bid/97562

libjpeg/libjpeg-turbo Library CVE-2013-6629 Memory Corruption Vulnerability
2017-04-12
http://www.securityfocus.com/bid/63676

Lenovo CVE-2016-8237 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97560

Microsoft Windows Hyper-V CVE-2017-0178 Remote Denial of Service Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97416

Microsoft Windows OLE CVE-2017-0211 Local Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97514

Microsoft Office OLE Feature Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97498

Microsoft Windows Hyper-V CVE-2017-0181 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97445

Microsoft Internet Explorer CVE-2017-0210 Remote Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97512

Microsoft Windows Kernel 'Win32k.sys' CVE-2017-0188 Local Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97475

Microsoft Windows Graphics Component CVE-2017-0156 Local Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97507
libjpeg/libjpeg-turbo Library CVE-2013-6629 Memory Corruption Vulnerability
2017-04-12
http://www.securityfocus.com/bid/63676

Lenovo CVE-2016-8237 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97560

Microsoft Windows Hyper-V CVE-2017-0178 Remote Denial of Service Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97416

Microsoft Windows OLE CVE-2017-0211 Local Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97514

Microsoft Office OLE Feature Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97498

Microsoft Windows Hyper-V CVE-2017-0181 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97445

Microsoft Internet Explorer CVE-2017-0210 Remote Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97512

Microsoft Windows Kernel 'Win32k.sys' CVE-2017-0188 Local Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97475

Microsoft Windows Graphics Component CVE-2017-0156 Local Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97507

Microsoft Windows Graphics CVE-2017-0155 Local Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97471

Microsoft Edge CVE-2017-0200 Scripting Engine Remote Memory Corruption Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97456

Microsoft Windows Hyper-V CVE-2017-0180 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97444

Microsoft Windows Hyper-V CVE-2017-0163 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97465

Microsoft Internet Explorer CVE-2017-0158 Scripting Engine Remote Memory Corruption Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97455

Microsoft Windows ADFS CVE-2017-0159 Security Bypass Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97449

Microsoft Internet Explorer CVE-2017-0201 Scripting Engine Remote Memory Corruption Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97454

Microsoft Windows ATMFD.dll CVE-2017-0192 Information Disclosure Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97452

Microsoft Windows Active Directory CVE-2017-0164 Denial of Service Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97448

Microsoft Windows CVE-2017-0165 Local Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97467

Microsoft Windows Hyper-V CVE-2017-0162 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97461

Microsoft Edge CVE-2017-0208 Scripting Engine Information Disclosure Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97460

Microsoft Outlook for Mac CVE-2017-0207 Spoofing Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97463

Microsoft Edge CVE-2017-0093 Scripting Engine Remote Memory Corruption Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97419

Microsoft Windows Kernel CVE-2017-0167 Information Disclosure Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97473

Microsoft Windows .NET Framework CVE-2017-0160 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97447

Microsoft Office CVE-2017-0197 DLL Loading Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97411

Microsoft Windows Hyper-V CVE-2017-0169 Information Disclosure Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97459

Microsoft Office CVE-2017-0195 Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97417

Microsoft Outlook CVE-2017-0106 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97413

Microsoft Windows Hyper-V CVE-2017-0168 Information Disclosure Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97418libjpeg/libjpeg-turbo Library CVE-2013-6629 Memory Corruption Vulnerability
2017-04-12
http://www.securityfocus.com/bid/63676

Lenovo CVE-2016-8237 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97560

Microsoft Windows Hyper-V CVE-2017-0178 Remote Denial of Service Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97416

Microsoft Windows OLE CVE-2017-0211 Local Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97514

Microsoft Office OLE Feature Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97498

Microsoft Windows Hyper-V CVE-2017-0181 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97445

Microsoft Internet Explorer CVE-2017-0210 Remote Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97512

Microsoft Windows Kernel 'Win32k.sys' CVE-2017-0188 Local Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97475

Microsoft Windows Graphics Component CVE-2017-0156 Local Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97507

Microsoft Windows Graphics CVE-2017-0155 Local Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97471

Microsoft Edge CVE-2017-0200 Scripting Engine Remote Memory Corruption Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97456

Microsoft Windows Hyper-V CVE-2017-0180 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97444

Microsoft Windows Hyper-V CVE-2017-0163 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97465

Microsoft Internet Explorer CVE-2017-0158 Scripting Engine Remote Memory Corruption Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97455

Microsoft Windows ADFS CVE-2017-0159 Security Bypass Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97449

Microsoft Internet Explorer CVE-2017-0201 Scripting Engine Remote Memory Corruption Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97454

Microsoft Windows ATMFD.dll CVE-2017-0192 Information Disclosure Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97452

Microsoft Windows Active Directory CVE-2017-0164 Denial of Service Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97448

Microsoft Windows CVE-2017-0165 Local Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97467

Microsoft Windows Hyper-V CVE-2017-0162 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97461

Microsoft Edge CVE-2017-0208 Scripting Engine Information Disclosure Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97460

Microsoft Outlook for Mac CVE-2017-0207 Spoofing Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97463

Microsoft Edge CVE-2017-0093 Scripting Engine Remote Memory Corruption Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97419

Microsoft Windows Kernel CVE-2017-0167 Information Disclosure Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97473

Microsoft Windows .NET Framework CVE-2017-0160 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97447

Microsoft Office CVE-2017-0197 DLL Loading Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97411

Microsoft Windows Hyper-V CVE-2017-0169 Information Disclosure Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97459

Microsoft Office CVE-2017-0195 Privilege Escalation Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97417

Microsoft Outlook CVE-2017-0106 Remote Code Execution Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97413

Microsoft Windows Hyper-V CVE-2017-0168 Information Disclosure Vulnerability
2017-04-12
http://www.securityfocus.com/bid/97418

SANS News

Malspam on 2017-04-11 pushes yet another ransomware variant

Threatpost

Spammer’s Arrest Puts End to Kelihos Botnet

Microsoft Patches Word Zero-Day Spreading Dridex Malware

Adobe Patches 59 Vulnerabilities Across Flash, Reader, Photoshop

Microsoft Patches Three Vulnerabilities Under Attack

SAP Updates Two-Year-Old Patch for TREX Vulnerability

Exploit

Apple WebKit - 'Document::adoptNode' Use-After-Free

Apple WebKit - 'JSC::B3::Procedure::resetReachability' Use-After-Free

Apple WebKit - 'JSC::SymbolTableEntry::isWatchable' Heap Buffer Overflow

Apple WebKit / Safari 10.0.3 (12602.4.8) - Synchronous Page Load Universal Cross-Site...

Apple WebKit / Safari 10.0.3 (12602.4.8) - Universal Cross-Site Scripting via a Focus...

Xen - Broken Check in 'memory_exchange()' Permits PV Guest Breakout

Proxifier for Mac 2.18 - Multiple Vulnerabilities

Proxifier for Mac 2.17 / 2.18 - Privesc Escalation

Adobe Multiple Products - XML Injection File Content Disclosure

MyClassifiedScript 5.1 - SQL Injection

Social Directory Script 2.0 - SQL Injection

FAQ Script 3.1.3 - 'category_id' Parameter SQL Injection

WordPress Plugin Spider Event Calendar 1.5.51 - Blind SQL Injection

MyBB < 1.8.11 - 'email' MyCode Cross-Site Scripting

MyBB smilie Module < 1.8.11 - 'pathfolder' Directory Traversal

Quest Privilege Manager 6.0.0 - Arbitrary File Write

Brother MFC-J6520DW - Authentication Bypass / Password Change

Horde Groupware Webmail 3 / 4 / 5 - Multiple Remote Code Execution

11.4.2017

Bugtraq

Multiple local privilege escalation vulnerabilities in Proxifier for Mac 2017-04-11
Securify B.V. (lists securify nl)

[SECURITY] CVE-2017-5648 Apache Tomcat Information Disclosure 2017-04-10
Mark Thomas (markt apache org)

[SECURITY] CVE-2017-5651 Apache Tomcat Information Disclosure 2017-04-10
Mark Thomas (markt apache org)

DefenseCode ThunderScan SAST Advisory: WordPress Tribulant Slideshow Gallery Plugin - Cross-Site Scripting Vulnerabilities 2017-04-10
DefenseCode (defensecode defensecode com)

ChromeOS / ChromeBooks Persist Certain Network Settings in Guest Mode 2017-04-09
Nightwatch Cybersecurity Research (research nightwatchcybersecurity com)

Foscam All networked devices, multiple Design Errors. SSL bypass. 2017-04-09
nick m mckenna gmail com

[slackware-security] libtiff (SSA:2017-098-01) 2017-04-08
Slackware Security Team (security slackware com)

Malware

Linux.Migajick

Trojan.Crusader

Linux.Cheepori

Trojan.Sathurbot

Phishing

American Express

10th April 2017

Important Statement from
American Express

Vulnerebility

Apache Tomcat CVE-2017-5650 Denial of Service Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97531

IBM Platform LSF CVE-2017-1205 Local Privilege Escalation Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97528

Linux Kernel CVE-2017-7616 Multiple Local Information Disclosure Vulnerabilities
2017-04-11
http://www.securityfocus.com/bid/97527

Bluecoat SSL Visibility CVE-2016-10259 Denial of Service Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97525

Microsoft Office OLE Feature Remote Code Execution Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97498

Foreman CVE-2017-2672 Information Disclosure Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97526

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-04-11
http://www.securityfocus.com/bid/96651

Mozilla Firefox CVE-2017-5426 Security Bypass Vulnerability
2017-04-11
http://www.securityfocus.com/bid/96694

Mozilla Firefox and Thunderbird Multiple Security Vulnerabilities
2017-04-11
http://www.securityfocus.com/bid/96693

Mozilla Firefox MFSA 2017-05 Multiple Security Vulnerabilities
2017-04-11
http://www.securityfocus.com/bid/96692

Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-04-11
http://www.securityfocus.com/bid/96664

Mozilla Firefox CVE-2017-5403 Denial of Service Vulnerability
2017-04-11
http://www.securityfocus.com/bid/96691

Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-04-11
http://www.securityfocus.com/bid/96654

Mozilla Firefox and Thunderbird CVE-2017-5401 Memory Corruption Vulnerability
2017-04-11
http://www.securityfocus.com/bid/96677

SAP NetWeaver AS JAVA Denial of Service Vulnerability
2017-04-11
http://www.securityfocus.com/bid/91733

SAP NetWeaver SAPSTARTSRV Remote Buffer Overflow Vulnerability
2017-04-11
http://www.securityfocus.com/bid/91734

SAP Sybase SQL Anywhere Denial of Service Vulnerability
2017-04-11
http://www.securityfocus.com/bid/91197

Multiple Asterisk Products Remote Buffer Overflow Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97377

libsndfile 'src/common.c' Stack Buffer Overflow Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97522

Dell iDRAC CVE-2015-7270 Local Directory Traversal Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97521

Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
2017-04-11
http://www.securityfocus.com/bid/96729

Foxit PDF Toolkit CVE-2017-7584 Memory Corruption Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97519

Schneider Electric SoMachine and Modicon CVE-2017-7574 Security Bypass Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97518

Schneider Electric Modicon CVE-2017-7575 Information Disclosure Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97523

Multiple Dell iDRAC Products CVE-2015-7275 Cross Site Scripting Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97520

Atlassian JIRA Server CVE-2016-4319 Cross Site Request Forgery Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97517

Atlassian Bitbucket Server CVE-2016-4320 Directory Traversal Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97515

Atlassian JIRA 'project/ViewDefaultProjectRoleActors.jspa' HTML Injection Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97516

Atlassian Confluence 'viewmyprofile.action' Cross Site Scripting Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97513

Apache Ignite CVE-2016-6805 Information Disclosure and XML External Entity Injection Vulnerabilities
2017-04-11
http://www.securityfocus.com/bid/97509Bluecoat SSL Visibility CVE-2016-10259 Denial of Service Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97525

Microsoft Office OLE Feature Remote Code Execution Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97498

Foreman CVE-2017-2672 Information Disclosure Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97526

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-04-11
http://www.securityfocus.com/bid/96651

Mozilla Firefox CVE-2017-5426 Security Bypass Vulnerability
2017-04-11
http://www.securityfocus.com/bid/96694

Mozilla Firefox and Thunderbird Multiple Security Vulnerabilities
2017-04-11
http://www.securityfocus.com/bid/96693

Mozilla Firefox MFSA 2017-05 Multiple Security Vulnerabilities
2017-04-11
http://www.securityfocus.com/bid/96692

Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-04-11
http://www.securityfocus.com/bid/96664

Mozilla Firefox CVE-2017-5403 Denial of Service Vulnerability
2017-04-11
http://www.securityfocus.com/bid/96691

Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-04-11
http://www.securityfocus.com/bid/96654

Mozilla Firefox and Thunderbird CVE-2017-5401 Memory Corruption Vulnerability
2017-04-11
http://www.securityfocus.com/bid/96677

SAP NetWeaver AS JAVA Denial of Service Vulnerability
2017-04-11
http://www.securityfocus.com/bid/91733

SAP NetWeaver SAPSTARTSRV Remote Buffer Overflow Vulnerability
2017-04-11
http://www.securityfocus.com/bid/91734

SAP Sybase SQL Anywhere Denial of Service Vulnerability
2017-04-11
http://www.securityfocus.com/bid/91197

Multiple Asterisk Products Remote Buffer Overflow Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97377

libsndfile 'src/common.c' Stack Buffer Overflow Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97522

Dell iDRAC CVE-2015-7270 Local Directory Traversal Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97521

Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
2017-04-11
http://www.securityfocus.com/bid/96729

Foxit PDF Toolkit CVE-2017-7584 Memory Corruption Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97519

Schneider Electric SoMachine and Modicon CVE-2017-7574 Security Bypass Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97518

Schneider Electric Modicon CVE-2017-7575 Information Disclosure Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97523

Multiple Dell iDRAC Products CVE-2015-7275 Cross Site Scripting Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97520

Atlassian JIRA Server CVE-2016-4319 Cross Site Request Forgery Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97517

Atlassian Bitbucket Server CVE-2016-4320 Directory Traversal Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97515

Atlassian JIRA 'project/ViewDefaultProjectRoleActors.jspa' HTML Injection Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97516

Atlassian Confluence 'viewmyprofile.action' Cross Site Scripting Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97513

Apache Ignite CVE-2016-6805 Information Disclosure and XML External Entity Injection Vulnerabilities
2017-04-11
http://www.securityfocus.com/bid/97509

LibTIFF CVE-2017-7599 Denial of Service Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97505

LibTIFF CVE-2017-7594 Denial of Service Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97503

LibTIFF CVE-2017-7601 Denial of Service Vulnerability
2017-04-11
http://www.securityfocus.com/bid/97511

SANS News

Dridex malspam seen on Monday 2017-04-10

Threatpost

Travel Routers, NAS Devices Among Easily Hacked IoT Devices

ShadowBrokers Dump More Equation Group Hacks, Auction File Password

Tools Used by Lamberts APT Found in Vault 7 Dumps

Exploit

Jobscript4Web 4.5 - Authentication Bypass

10.4.2017

Bugtraq

DefenseCode ThunderScan SAST Advisory: WordPress Tribulant Slideshow Gallery Plugin - Cross-Site Scripting Vulnerabilities 2017-04-10
DefenseCode (defensecode defensecode com)

ChromeOS / ChromeBooks Persist Certain Network Settings in Guest Mode 2017-04-09
Nightwatch Cybersecurity Research (research nightwatchcybersecurity com)

Foscam All networked devices, multiple Design Errors. SSL bypass. 2017-04-09
nick m mckenna gmail com

[slackware-security] libtiff (SSA:2017-098-01) 2017-04-08
Slackware Security Team (security slackware com)

[SECURITY] [DSA 3827-1] jasper security update 2017-04-07
Moritz Muehlenhoff (jmm debian org)

[security bulletin] HPESBGN03733 rev.1 - HPE Universal CMDB using Apache Struts, Remote Code Execution 2017-04-07
security-alert hpe com

[CVE-2016-6805] Arbitrary File Read due to eXternal Xml Entity attack in Apache Ignite 2017-04-07
Denis Magda (dmagda apache org)

D-Link DWR-116 - CVE-2017-6190 - Arbitrary File Download 2017-04-07
patrykgnt gmail com

Malware

Linux.Valsheesy

Trojan.Sathurbot

Phishing

 

Vulnerebility

Schneider Electric Modicon CVE-2017-7575 Information Disclosure Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97523

Multiple Dell iDRAC Products CVE-2015-7275 Cross Site Scripting Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97520

Atlassian JIRA Server CVE-2016-4319 Cross Site Request Forgery Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97517

Atlassian Bitbucket Server CVE-2016-4320 Directory Traversal Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97515

Atlassian JIRA 'project/ViewDefaultProjectRoleActors.jspa' HTML Injection Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97516

Atlassian Confluence 'viewmyprofile.action' Cross Site Scripting Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97513

Apache Ignite CVE-2016-6805 Information Disclosure and XML External Entity Injection Vulnerabilities
2017-04-10
http://www.securityfocus.com/bid/97509

LibTIFF CVE-2017-7599 Denial of Service Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97505

LibTIFF CVE-2017-7594 Denial of Service Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97503

LibTIFF CVE-2017-7601 Denial of Service Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97511

LibTIFF CVE-2017-7599 Denial of Service Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97508

LibTIFF CVE-2017-7592 Denial of Service Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97510

LibTIFF CVE-2017-7593 Information Disclosure Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97502

LibTIFF CVE-2017-7596 Integer Overflow Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97506

LibTIFF CVE-2017-7597 Integer Overflow Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97504

Oracle Java SE CVE-2017-3259 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95570

Oracle Java SE CVE-2017-3261 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95566

Oracle Java SE CVE-2017-3231 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95563

Oracle Java SE and JRockit CVE-2016-5552 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95512

Oracle Java SE CVE-2016-5548 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95559

Oracle Java SE and JRockit CVE-2016-5547 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95521

Oracle Java SE CVE-2016-5549 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95530

Oracle Java SE and JRockit CVE-2017-3252 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95509

Oracle Java SE and JRockit CVE-2017-3253 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95498

Oracle Java SE and JRockit CVE-2017-3241 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95488

Oracle Java SE and JRockit CVE-2016-5546 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95506

Oracle Java SE CVE-2017-3289 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95525

Oracle Java SE CVE-2017-3272 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95533

LibTIFF CVE-2017-7602 Integer Overflow Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97500

LibTIFF 'tif_dirread.c' Divide By Zero Denial of Service Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97499Oracle Java SE CVE-2017-3259 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95570

Oracle Java SE CVE-2017-3261 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95566

Oracle Java SE CVE-2017-3231 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95563

Oracle Java SE and JRockit CVE-2016-5552 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95512

Oracle Java SE CVE-2016-5548 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95559

Oracle Java SE and JRockit CVE-2016-5547 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95521

Oracle Java SE CVE-2016-5549 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95530

Oracle Java SE and JRockit CVE-2017-3252 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95509

Oracle Java SE and JRockit CVE-2017-3253 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95498

Oracle Java SE and JRockit CVE-2017-3241 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95488

Oracle Java SE and JRockit CVE-2016-5546 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95506

Oracle Java SE CVE-2017-3289 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95525

Oracle Java SE CVE-2017-3272 Remote Security Vulnerability
2017-04-10
http://www.securityfocus.com/bid/95533

LibTIFF CVE-2017-7602 Integer Overflow Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97500

LibTIFF 'tif_dirread.c' Divide By Zero Denial of Service Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97499

Microsoft Office OLE Feature Remote Code Execution Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97498

Dropbox Lepton CVE-2017-7448 Denial of Service Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97490

ImageWorsener 'iwgif_record_pixel()' Function Denial of Service Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97497

WebsiteBaker CVE-2017-7410 Multiple SQL Injection Vulnerabilities
2017-04-10
http://www.securityfocus.com/bid/97495

ImageWorsener 'iwbmp_read_info_header()' Function Denial of Service Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97496

Faveo CVE-2017-7571 Cross Site Request Forgery Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97493

ImageWorsener 'iwgif_record_pixel()' Function Remote Heap Buffer Overflow Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97494

Trend Micro InterScan Web Security Virtual Appliance CVE-2017-6339 Security Bypass Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97492

Nextcloud Server CVE-2017-0888 Content Spoofing Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97491

Tryton Trytond CVE-2017-0360 Incomplete Fix Information Disclosure Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97489

Trend Micro InterScan Web Security Virtual Appliance CVE-2017-6340 HTML Injection Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97487

LightDM CVE-2017-7358 Local Directory Traversal Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97486

HelpDEZK CVE-2017-7447 Cross Site Request Forgery Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97485

Google Chrome CVE-2017-5055 Use After Free Memory Corruption Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97221

Google Chrome and Chrome OS Multiple Security Vulnerabilities
2017-04-10
http://www.securityfocus.com/bid/97220ImageWorsener 'iwgif_record_pixel()' Function Denial of Service Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97497

WebsiteBaker CVE-2017-7410 Multiple SQL Injection Vulnerabilities
2017-04-10
http://www.securityfocus.com/bid/97495

ImageWorsener 'iwbmp_read_info_header()' Function Denial of Service Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97496

Faveo CVE-2017-7571 Cross Site Request Forgery Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97493

ImageWorsener 'iwgif_record_pixel()' Function Remote Heap Buffer Overflow Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97494

Trend Micro InterScan Web Security Virtual Appliance CVE-2017-6339 Security Bypass Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97492

Nextcloud Server CVE-2017-0888 Content Spoofing Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97491

Tryton Trytond CVE-2017-0360 Incomplete Fix Information Disclosure Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97489

Trend Micro InterScan Web Security Virtual Appliance CVE-2017-6340 HTML Injection Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97487

LightDM CVE-2017-7358 Local Directory Traversal Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97486

HelpDEZK CVE-2017-7447 Cross Site Request Forgery Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97485

Google Chrome CVE-2017-5055 Use After Free Memory Corruption Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97221

Google Chrome and Chrome OS Multiple Security Vulnerabilities
2017-04-10
http://www.securityfocus.com/bid/97220

HelpDEZk CVE-2017-7446 Cross Site Request Forgery Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97484

Ruby 'dl/handle.c' Security Bypass Vulnerability
2017-04-10
http://www.securityfocus.com/bid/76060

Ruby 'initialize()' Function Heap Buffer Overflow Vulnerability
2017-04-10
http://www.securityfocus.com/bid/91234

Veritas System Recovery CVE-2017-7444 DLL Loading Local Code Execution Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97483

MyBB CVE-2017-7566 Server Side Request Forgery Security Bypass Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97480

Trend Micro InterScan Web Security Virtual Appliance Privilege Escalation Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97482

Certec EDV GmbH atvise scada Cross Site Scripting and HTTP Header Injection Vulnerabilities
2017-04-10
http://www.securityfocus.com/bid/97479

Golang Go SSH Library CVE-2017-3204 Security Bypass Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97481

FortiClient SSLVPN CVE-2016-8497 Privilege Escalation Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97478

Multiple Cisco Products CVE-2017-6601 Local Command Injection Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97477

Fortinet FortiMail CVE-2017-3125 Unspecified Cross Site Scripting Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97474

Multiple Cisco Products CVE-2017-6597 Local Command Injection Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97476

Multiple Cisco Products CVE-2017-3884 Information Disclosure Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97470

Cisco Mobility Express 2800 and 3800 Series CVE-2016-9197 Local Security Bypass Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97469

Cisco Aironet Access Points CVE-2016-9196 Local Privilege Escalation Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97468

Multiple Cisco Products CVE-2017-6602 Local Command Injection Vulnerability
2017-04-10
http://www.securityfocus.com/bid/97472

Ping Identity 'mod_auth_openidc' Module CVE-2017-6059 Content Spoofing Vulnerability
2017-04-10
http://www.securityfocus.com/bid/96299

SANS News

Password History: Insights Shared by a Reader

Threatpost

Riverbed Patches Vulnerabilities in Application Monitoring Portal

Exploit

Jobscript4Web 4.5 - Authentication Bypass

Moxa MXview 2.8 - Private Key Disclosure

Moxa MX AOPC-Server 1.5 - XML External Entity Injection

Moxa MXview 2.8 - Denial of Service

9.4.2017

Bugtraq

SEC Consult SA-20170407-0 :: Server-Side Request Forgery in MyBB forum 2017-04-07
SEC Consult Vulnerability Lab (research sec-consult com)

Apple Music Android Application - MITM SSL Certificate Vulnerability (CVE-2017-2387) 2017-04-06
David Coomber (davidcoomber infosec gmail com)

Trend Micro Enterprise Mobile Security Android Application - MITM SSL Certificate Vulnerability (CVE-2016-9319) 2017-04-06
David Coomber (davidcoomber infosec gmail com)

Spiceworks 7.5 TFTP Improper Access Control File Overwrite / Upload 2017-04-06
apparitionsec gmail com (hyp3rlinx)

Malware

 

Phishing

American Express

8th April 2017

Alert Notice from American
Express

Vulnerebility

ImageWorsener 'iwgif_record_pixel()' Function Denial of Service Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97497

WebsiteBaker CVE-2017-7410 Multiple SQL Injection Vulnerabilities
2017-04-09
http://www.securityfocus.com/bid/97495

ImageWorsener 'iwbmp_read_info_header()' Function Denial of Service Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97496

Faveo CVE-2017-7571 Cross Site Request Forgery Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97493

ImageWorsener 'iwgif_record_pixel()' Function Remote Heap Buffer Overflow Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97494

Trend Micro InterScan Web Security Virtual Appliance CVE-2017-6339 Security Bypass Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97492

Nextcloud Server CVE-2017-0888 Content Spoofing Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97491

Tryton Trytond CVE-2017-0360 Incomplete Fix Information Disclosure Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97489

Trend Micro InterScan Web Security Virtual Appliance CVE-2017-6340 HTML Injection Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97487

LightDM CVE-2017-7358 Local Directory Traversal Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97486

HelpDEZK CVE-2017-7447 Cross Site Request Forgery Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97485

Google Chrome CVE-2017-5055 Use After Free Memory Corruption Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97221

Google Chrome and Chrome OS Multiple Security Vulnerabilities
2017-04-09
http://www.securityfocus.com/bid/97220

HelpDEZk CVE-2017-7446 Cross Site Request Forgery Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97484

Ruby 'dl/handle.c' Security Bypass Vulnerability
2017-04-09
http://www.securityfocus.com/bid/76060

Ruby 'initialize()' Function Heap Buffer Overflow Vulnerability
2017-04-09
http://www.securityfocus.com/bid/91234

Veritas System Recovery CVE-2017-7444 DLL Loading Local Code Execution Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97483

MyBB CVE-2017-7566 Server Side Request Forgery Security Bypass Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97480

Trend Micro InterScan Web Security Virtual Appliance Privilege Escalation Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97482

Certec EDV GmbH atvise scada Cross Site Scripting and HTTP Header Injection Vulnerabilities
2017-04-09
http://www.securityfocus.com/bid/97479

Golang Go SSH Library CVE-2017-3204 Security Bypass Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97481

FortiClient SSLVPN CVE-2016-8497 Privilege Escalation Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97478

Multiple Cisco Products CVE-2017-6601 Local Command Injection Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97477

Fortinet FortiMail CVE-2017-3125 Unspecified Cross Site Scripting Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97474

Multiple Cisco Products CVE-2017-6597 Local Command Injection Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97476

Multiple Cisco Products CVE-2017-3884 Information Disclosure Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97470

Cisco Mobility Express 2800 and 3800 Series CVE-2016-9197 Local Security Bypass Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97469

Cisco Aironet Access Points CVE-2016-9196 Local Privilege Escalation Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97468

Multiple Cisco Products CVE-2017-6602 Local Command Injection Vulnerability
2017-04-09
http://www.securityfocus.com/bid/97472

Ping Identity 'mod_auth_openidc' Module CVE-2017-6059 Content Spoofing Vulnerability
2017-04-09
http://www.securityfocus.com/bid/96299ImageWorsener 'iwgif_record_pixel()' Function Denial of Service Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97497

WebsiteBaker CVE-2017-7410 Multiple SQL Injection Vulnerabilities
2017-04-08
http://www.securityfocus.com/bid/97495

ImageWorsener 'iwbmp_read_info_header()' Function Denial of Service Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97496

Faveo CVE-2017-7571 Cross Site Request Forgery Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97493

ImageWorsener 'iwgif_record_pixel()' Function Remote Heap Buffer Overflow Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97494

Trend Micro InterScan Web Security Virtual Appliance CVE-2017-6339 Security Bypass Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97492

Nextcloud Server CVE-2017-0888 Content Spoofing Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97491

Tryton Trytond CVE-2017-0360 Incomplete Fix Information Disclosure Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97489

Trend Micro InterScan Web Security Virtual Appliance CVE-2017-6340 HTML Injection Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97487

LightDM CVE-2017-7358 Local Directory Traversal Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97486

HelpDEZK CVE-2017-7447 Cross Site Request Forgery Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97485

Google Chrome CVE-2017-5055 Use After Free Memory Corruption Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97221

Google Chrome and Chrome OS Multiple Security Vulnerabilities
2017-04-08
http://www.securityfocus.com/bid/97220

HelpDEZk CVE-2017-7446 Cross Site Request Forgery Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97484

Ruby 'dl/handle.c' Security Bypass Vulnerability
2017-04-08
http://www.securityfocus.com/bid/76060

Ruby 'initialize()' Function Heap Buffer Overflow Vulnerability
2017-04-08
http://www.securityfocus.com/bid/91234

Veritas System Recovery CVE-2017-7444 DLL Loading Local Code Execution Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97483

MyBB CVE-2017-7566 Server Side Request Forgery Security Bypass Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97480

Trend Micro InterScan Web Security Virtual Appliance Privilege Escalation Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97482

Certec EDV GmbH atvise scada Cross Site Scripting and HTTP Header Injection Vulnerabilities
2017-04-08
http://www.securityfocus.com/bid/97479

Golang Go SSH Library CVE-2017-3204 Security Bypass Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97481

FortiClient SSLVPN CVE-2016-8497 Privilege Escalation Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97478

Multiple Cisco Products CVE-2017-6601 Local Command Injection Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97477

Fortinet FortiMail CVE-2017-3125 Unspecified Cross Site Scripting Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97474

Multiple Cisco Products CVE-2017-6597 Local Command Injection Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97476

Multiple Cisco Products CVE-2017-3884 Information Disclosure Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97470

Cisco Mobility Express 2800 and 3800 Series CVE-2016-9197 Local Security Bypass Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97469

Cisco Aironet Access Points CVE-2016-9196 Local Privilege Escalation Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97468

Multiple Cisco Products CVE-2017-6602 Local Command Injection Vulnerability
2017-04-08
http://www.securityfocus.com/bid/97472

Ping Identity 'mod_auth_openidc' Module CVE-2017-6059 Content Spoofing Vulnerability
2017-04-08
http://www.securityfocus.com/bid/96299

SANS News

Domain Whitelisting With Alexa and Umbrella Lists

Threatpost

Creating a More Altruistic Bug Bounty Program

Researcher Warns SIEMs Are Weak Link In Network Security Chain

Exploit

 

7.4.2017

Bugtraq

SEC Consult SA-20170407-0 :: Server-Side Request Forgery in MyBB forum 2017-04-07
SEC Consult Vulnerability Lab (research sec-consult com)

Apple Music Android Application - MITM SSL Certificate Vulnerability (CVE-2017-2387) 2017-04-06
David Coomber (davidcoomber infosec gmail com)

Trend Micro Enterprise Mobile Security Android Application - MITM SSL Certificate Vulnerability (CVE-2016-9319) 2017-04-06
David Coomber (davidcoomber infosec gmail com)

Spiceworks 7.5 TFTP Improper Access Control File Overwrite / Upload 2017-04-06
apparitionsec gmail com (hyp3rlinx)

[security bulletin] HPESBGN03727 rev.1 - HPE Business Process Monitor, Remote Unauthorized Access to Data 2017-04-04
security-alert hpe com

DefenseCode ThunderScan SAST Advisory: Apache Tomcat Directory/Path Traversal 2017-04-04
DefenseCode (defensecode defensecode com)

[SECURITY] [DSA 3826-1] tryton-server security update 2017-04-04
Salvatore Bonaccorso (carnil debian org)

AST-2017-001: Buffer overflow in CDR's set user 2017-04-04
Asterisk Security Team (security asterisk org)

Malware

Backdoor.Rokrat

Trojan.Kasperbogi

Linux.Amnesiark

Phishing

Argos.co.uk

6th April 2017

[!! ] Failed to validate your
account info

moneygram office

4th April 2017

Money Transfer Control Number
(M.T.C.N):: #:94575379

Vulnerebility

Trend Micro InterScan Web Security Virtual Appliance CVE-2017-6340 HTML Injection Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97487

LightDM CVE-2017-7358 Local Directory Traversal Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97486

HelpDEZK CVE-2017-7447 Cross Site Request Forgery Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97485

Google Chrome CVE-2017-5055 Use After Free Memory Corruption Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97221

Google Chrome and Chrome OS Multiple Security Vulnerabilities
2017-04-07
http://www.securityfocus.com/bid/97220

HelpDEZk CVE-2017-7446 Cross Site Request Forgery Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97484

Ruby 'dl/handle.c' Security Bypass Vulnerability
2017-04-07
http://www.securityfocus.com/bid/76060

Ruby 'initialize()' Function Heap Buffer Overflow Vulnerability
2017-04-07
http://www.securityfocus.com/bid/91234

Veritas System Recovery CVE-2017-7444 DLL Loading Local Code Execution Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97483

MyBB CVE-2017-7566 Server Side Request Forgery Security Bypass Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97480

Trend Micro InterScan Web Security Virtual Appliance Privilege Escalation Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97482

Certec EDV GmbH atvise scada Cross Site Scripting and HTTP Header Injection Vulnerabilities
2017-04-07
http://www.securityfocus.com/bid/97479

Golang Go SSH Library CVE-2017-3204 Security Bypass Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97481

FortiClient SSLVPN CVE-2016-8497 Privilege Escalation Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97478

Multiple Cisco Products CVE-2017-6601 Local Command Injection Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97477

Fortinet FortiMail CVE-2017-3125 Unspecified Cross Site Scripting Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97474

Multiple Cisco Products CVE-2017-6597 Local Command Injection Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97476

Multiple Cisco Products CVE-2017-3884 Information Disclosure Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97470

Cisco Mobility Express 2800 and 3800 Series CVE-2016-9197 Local Security Bypass Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97469

Cisco Aironet Access Points CVE-2016-9196 Local Privilege Escalation Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97468

Multiple Cisco Products CVE-2017-6602 Local Command Injection Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97472

Ping Identity 'mod_auth_openidc' Module CVE-2017-6059 Content Spoofing Vulnerability
2017-04-07
http://www.securityfocus.com/bid/96299

Cisco IOS XR Software CVE-2017-6599 Denial of Service Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97464

Cisco Integrated Management Controller CVE-2017-6604 Open Redirection Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97457

Linux Kernel CVE-2016-0723 Local Race Condition Vulnerability
2017-04-07
http://www.securityfocus.com/bid/82950

Cisco Firepower System Software CVE-2017-3887 Denial of Service Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97453

Cisco ASR 903 and ASR 920 Series CVE-2017-6603 Denial of Service Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97450

Cisco Firepower System Software CVE-2017-3885 Denial of Service Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97451

Samba CVE-2017-2619 Symlink Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97033

Django 'django.contrib.auth.views.login()' Function Open Redirection Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97406MyBB CVE-2017-7566 Server Side Request Forgery Security Bypass Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97480

Trend Micro InterScan Web Security Virtual Appliance Privilege Escalation Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97482

Certec EDV GmbH atvise scada Cross Site Scripting and HTTP Header Injection Vulnerabilities
2017-04-07
http://www.securityfocus.com/bid/97479

Golang Go SSH Library CVE-2017-3204 Security Bypass Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97481

FortiClient SSLVPN CVE-2016-8497 Privilege Escalation Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97478

Multiple Cisco Products CVE-2017-6601 Local Command Injection Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97477

Fortinet FortiMail CVE-2017-3125 Unspecified Cross Site Scripting Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97474

Multiple Cisco Products CVE-2017-6597 Local Command Injection Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97476

Multiple Cisco Products CVE-2017-3884 Information Disclosure Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97470

Cisco Mobility Express 2800 and 3800 Series CVE-2016-9197 Local Security Bypass Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97469

Cisco Aironet Access Points CVE-2016-9196 Local Privilege Escalation Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97468

Multiple Cisco Products CVE-2017-6602 Local Command Injection Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97472

Ping Identity 'mod_auth_openidc' Module CVE-2017-6059 Content Spoofing Vulnerability
2017-04-07
http://www.securityfocus.com/bid/96299

Cisco IOS XR Software CVE-2017-6599 Denial of Service Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97464

Cisco Integrated Management Controller CVE-2017-6604 Open Redirection Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97457

Linux Kernel CVE-2016-0723 Local Race Condition Vulnerability
2017-04-07
http://www.securityfocus.com/bid/82950

Cisco Firepower System Software CVE-2017-3887 Denial of Service Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97453

Cisco ASR 903 and ASR 920 Series CVE-2017-6603 Denial of Service Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97450

Cisco Firepower System Software CVE-2017-3885 Denial of Service Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97451

Samba CVE-2017-2619 Symlink Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97033

Django 'django.contrib.auth.views.login()' Function Open Redirection Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97406

Django 'django.views.static.serve()' Function Open Redirection Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97401

Linux kernel CVE-2017-7308 Local Denial of Service Vulnerability
2017-04-07
http://www.securityfocus.com/bid/97234

Linux Kernel CVE-2016-9178 Local Information Disclosure Vulnerability
2017-04-07
http://www.securityfocus.com/bid/94144

Linux kernel CVE-2017-6345 Local Denial of Service Vulnerability
2017-04-07
http://www.securityfocus.com/bid/96510

Linux Kernel Multiple Local Information Disclosure Vulnerabilities
2017-04-07
http://www.securityfocus.com/bid/79428

Linux Kernel CVE-2017-7187 Local Denial of Service Vulnerability
2017-04-07
http://www.securityfocus.com/bid/96989

Linux Kernel '/arch/x86/net/bpf_jit_comp.c' CVE-2015-4700 Local Denial of Service Vulnerability
2017-04-07
http://www.securityfocus.com/bid/75356

Linux Kernel CVE-2016-8633 Local Buffer Overflow Vulnerability
2017-04-07
http://www.securityfocus.com/bid/94149

Linux Kernel CVE-2016-10088 Incomplete Fix Multiple Local Memory Corruption Vulnerabilities
2017-04-07
http://www.securityfocus.com/bid/95169

SANS News

Tracking Website Defacers with HTTP Referers

Threatpost

Chrome Security Team Tackles ‘Friendly Fire’ To Keep Browser Safe

Samsung Tizen Security ‘Feels like 2005’

Apache Struts 2 Exploits Installing Cerber Ransomware

Exploit

Windows 10 x64 - Egghunter Shellcode (45 bytes)

Intellinet NFC-30IR Camera - Multiple Vulnerabilities

Faveo Helpdesk Community 1.9.3 - Cross-Site Request Forgery

Invoice Template - 'hash' Parameter SQL Injection

Document Management Template - 'hash' Parameter SQL Injection

SpiceWorks 7.5 TFTP - Remote File Overwrite / Upload

GeoMoose < 2.9.2 - Directory Traversal

Moodle 2.x/3.x - SQL Injection

HelpDEZK 1.1.1 - Cross-Site Request Forgery / Code Execution

Cesanta Mongoose OS - Use-After-Free

CommVault Edge 11 SP6 - Stack Buffer Overflow (PoC)

6.4.2017

Bugtraq

Apple Music Android Application - MITM SSL Certificate Vulnerability (CVE-2017-2387) 2017-04-06
David Coomber (davidcoomber infosec gmail com)

Trend Micro Enterprise Mobile Security Android Application - MITM SSL Certificate Vulnerability (CVE-2016-9319) 2017-04-06
David Coomber (davidcoomber infosec gmail com)

Spiceworks 7.5 TFTP Improper Access Control File Overwrite / Upload 2017-04-06
apparitionsec gmail com (hyp3rlinx)

[security bulletin] HPESBGN03727 rev.1 - HPE Business Process Monitor, Remote Unauthorized Access to Data 2017-04-04
security-alert hpe com

DefenseCode ThunderScan SAST Advisory: Apache Tomcat Directory/Path Traversal 2017-04-04
DefenseCode (defensecode defensecode com)

[SECURITY] [DSA 3826-1] tryton-server security update 2017-04-04
Salvatore Bonaccorso (carnil debian org)

AST-2017-001: Buffer overflow in CDR's set user 2017-04-04
Asterisk Security Team (security asterisk org)

The password for the project protection of the Schneider Modicon TM221CE16R is hard-coded and cannot be changed. 2017-04-04
Ralf Spenneberg (info os-t de)

OS-S-2017-01: The password for the application protection of the Schneider Modicon TM221CE16R can be retrieved without authentication. Subsequently the application may be arbitrarily downloaded, uploaded and modified. CVSS 10. 2017-04-04
Ralf Spenneberg (info os-t de)

Moodle URL Manipulation Remote Account Information Disclosure 2017-04-04
Patrick Webster (patrick osisecurity com au)

iPlatinum iOneView Multiple Parameter Reflected XSS 2017-04-04
Patrick Webster (patrick osisecurity com au)

Kaseya information disclosure vulnerability 2017-04-04
Patrick Webster (patrick osisecurity com au)

Malware

Backdoor.Lisdazz

Backdoor.Rokrat

Trojan.Ismdoor!gm

Backdoor.Rokrat

Trojan.Kasperbogi

Phishing

moneygram office

4th April 2017

Money Transfer Control Number
(M.T.C.N):: #:94575379

Chase

3rd April 2017

Important Update

Economic and Financial Crimes

3rd April 2017

Dear Victim

Vulnerebility

Linux Kernel CVE-2016-0723 Local Race Condition Vulnerability
2017-04-06
http://www.securityfocus.com/bid/82950

Cisco Firepower System Software CVE-2017-3887 Denial of Service Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97453

Cisco ASR 903 and ASR 920 Series CVE-2017-6603 Denial of Service Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97450

Cisco Firepower System Software CVE-2017-3885 Denial of Service Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97451

Samba CVE-2017-2619 Symlink Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97033

Django 'django.contrib.auth.views.login()' Function Open Redirection Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97406

Django 'django.views.static.serve()' Function Open Redirection Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97401

Linux kernel CVE-2017-7308 Local Denial of Service Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97234

Linux Kernel CVE-2016-9178 Local Information Disclosure Vulnerability
2017-04-06
http://www.securityfocus.com/bid/94144

Linux kernel CVE-2017-6345 Local Denial of Service Vulnerability
2017-04-06
http://www.securityfocus.com/bid/96510

Linux Kernel Multiple Local Information Disclosure Vulnerabilities
2017-04-06
http://www.securityfocus.com/bid/79428

Linux Kernel CVE-2017-7187 Local Denial of Service Vulnerability
2017-04-06
http://www.securityfocus.com/bid/96989

Linux Kernel '/arch/x86/net/bpf_jit_comp.c' CVE-2015-4700 Local Denial of Service Vulnerability
2017-04-06
http://www.securityfocus.com/bid/75356

Linux Kernel CVE-2016-8633 Local Buffer Overflow Vulnerability
2017-04-06
http://www.securityfocus.com/bid/94149

Linux Kernel CVE-2016-10088 Incomplete Fix Multiple Local Memory Corruption Vulnerabilities
2017-04-06
http://www.securityfocus.com/bid/95169

IETF IPv6 Protocol CVE-2016-10142 Denial of Service Vulnerability
2017-04-06
http://www.securityfocus.com/bid/95797

Linux Kernel 'arch/x86/kvm/vmx.c' Denial of Service Vulnerability
2017-04-06
http://www.securityfocus.com/bid/94933

Linux Kernel CVE-2017-2636 Local Privilege Escalation Vulnerability
2017-04-06
http://www.securityfocus.com/bid/96732

Linux Kernel SCSI arcmsr Driver CVE-2016-7425 Local Heap Buffer Overflow Vulnerability
2017-04-06
http://www.securityfocus.com/bid/93037

Google Android CVE-2016-8399 Remote Privilege Escalation Vulnerability
2017-04-06
http://www.securityfocus.com/bid/94708

Linux Kernel '/scsi/sg.c' Integer Overflow Vulnerability
2017-04-06
http://www.securityfocus.com/bid/76145

Linux Kernel CVE-2016-8645 Local Denial of Service Vulnerability
2017-04-06
http://www.securityfocus.com/bid/94264

Linux Kernel 'digi_acceleport.c' Local Denial of Service Vulnerability
2017-04-06
http://www.securityfocus.com/bid/84304

Cisco IOS XE Software CVE-2017-6606 Local Command Execution Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97434

Multiple Cisco Products CVE-2017-6600 Local Command Injection Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97439

Cisco Registered Envelope Service CVE-2017-3889 Open Redirection Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97433

Cisco Unified Communications Manager CVE-2017-3886 SQL Injection Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97432

Cisco Unified Communications Manager CVE-2017-3888 Cross Site Scripting Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97431

Multiple Cisco Products CVE-2017-6598 Local Privilege Escalation Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97429

Cisco Unified Computing System Director CVE-2017-3817 Information Disclosure Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97430Cisco IOS XE Software CVE-2017-6606 Local Command Execution Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97434

Multiple Cisco Products CVE-2017-6600 Local Command Injection Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97439

Cisco Registered Envelope Service CVE-2017-3889 Open Redirection Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97433

Cisco Unified Communications Manager CVE-2017-3886 SQL Injection Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97432

Cisco Unified Communications Manager CVE-2017-3888 Cross Site Scripting Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97431

Multiple Cisco Products CVE-2017-6598 Local Privilege Escalation Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97429

Cisco Unified Computing System Director CVE-2017-3817 Information Disclosure Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97430

Cisco Wireless LAN Controller CVE-2016-9195 Denial of Service Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97425

Cisco Wireless LAN Controller CVE-2016-9194 Denial of Service Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97424

Cisco Wireless LAN Controller CVE-2016-9219 Denial of Service Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97423

Cisco Wireless LAN Controller CVE-2017-3832 Denial of Service Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97421

Cisco Mobility Express Software CVE-2017-3834 Default Credentials Security Bypass Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97422

Linux Kernel CVE-2016-5870 Null Pointer Dereference Local Denial of Service Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97414

HP Operations Bridge Analytics CVE-2017-5800 Unspecified Cross Site Scripting Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97412

Linux Kernel CVE-2016-10318 Denial of Service Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97404

Ghostscript 'base/gxht_thresh.c' Heap Buffer Overflow Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97410

Google Nexus Qualcomm Crypto Engine Driver CVE-2017-10230 Remote Code Execution Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97400

Linux kernel CVE-2017-2671 Local Denial of Service Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97407

ProFTPD CVE-2017-7418 Local Security Bypass Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97409

Intel NUC and Compute Stick DCI Multiple Local Information Disclosure Vulnerabilities
2017-04-06
http://www.securityfocus.com/bid/97408

Google Pixel Qualcomm Sound Codec Driver CVE-2016-10231 Privilege Escalation Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97402

Google Android Qualcomm Crypto Engine Driver CVE-2017-0576 Privilege Escalation Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97395

Google Android Qualcomm Audio Driver CVE-2017-0454 Privilege Escalation Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97399

Google Android Freetype CVE-2016-10244 Remote Code Execution Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97405

Google Android Qualcomm Wi-Fi Driver CVE-2017-0575 Privilege Escalation Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97403

Django 'django.contrib.auth.views.login()' Function Open Redirection Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97406

Django 'django.views.static.serve()' Function Open Redirection Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97401

Google Android libskia CVE-2017-0548 Denial of Service Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97398

Linux Kernel 'ipv4/udp.c' Remote Code Execution Vulnerability
2017-04-06
http://www.securityfocus.com/bid/97397

ManageEngine Applications Manager Multiple Security Vulnerabilities
2017-04-06
http://www.securityfocus.com/bid/97394

SANS News

Java Struts2 Vulnerability Used To Install Cerber Crypto Ransomware

Threatpost

 

Exploit

CommVault Edge 11 SP6 - Stack Buffer Overflow (PoC)

GeoMoose <= 2.9.2 - Directory Traversal

ImagePro Lazygirls Clone Script - SQL Injection

Airbnb Crashpadder Clone Script - SQL Injection

Premium Penny Auction Script - SQL Injection

Sweepstakes Pro Software - SQL Injection

Appointment Script - SQL Injection

D-Link DIR-615 - Cross-Site Request Forgery

5.4.2017

Bugtraq

[security bulletin] HPESBGN03727 rev.1 - HPE Business Process Monitor, Remote Unauthorized Access to Data 2017-04-04
security-alert hpe com

DefenseCode ThunderScan SAST Advisory: Apache Tomcat Directory/Path Traversal 2017-04-04
DefenseCode (defensecode defensecode com)

[SECURITY] [DSA 3826-1] tryton-server security update 2017-04-04
Salvatore Bonaccorso (carnil debian org)

AST-2017-001: Buffer overflow in CDR's set user 2017-04-04
Asterisk Security Team (security asterisk org)

The password for the project protection of the Schneider Modicon TM221CE16R is hard-coded and cannot be changed. 2017-04-04
Ralf Spenneberg (info os-t de)

OS-S-2017-01: The password for the application protection of the Schneider Modicon TM221CE16R can be retrieved without authentication. Subsequently the application may be arbitrarily downloaded, uploaded and modified. CVSS 10. 2017-04-04
Ralf Spenneberg (info os-t de)

Moodle URL Manipulation Remote Account Information Disclosure 2017-04-04
Patrick Webster (patrick osisecurity com au)

iPlatinum iOneView Multiple Parameter Reflected XSS 2017-04-04
Patrick Webster (patrick osisecurity com au)

Kaseya information disclosure vulnerability 2017-04-04
Patrick Webster (patrick osisecurity com au)

AcoraCMS browser redirect and Cross-site scripting vulnerabilities 2017-04-04
Patrick Webster (patrick osisecurity com au)

SmartJobBoard - Cross-site scripting, personal information disclosure and PHPMailer package 2017-04-04
Patrick Webster (patrick osisecurity com au)

SilverStripe CMS - Path Disclosure 2017-04-04
Patrick Webster (patrick osisecurity com au)

Tweek!DM Document Management Authentication bypass, SQL injection 2017-04-04
Patrick Webster (patrick osisecurity com au)

Computer Associates API Gateway CRLF Response Splitting, Directory Traversal vulnerabilities 2017-04-04
Patrick Webster (patrick osisecurity com au)

CVE-2017-7185 - Mongoose OS - Use-after-free / Denial of Service 2017-04-04
Advisories (advisories compass-security com)

Lantern CMS Path Disclosure, SQL Injection, Reflected XSS 2017-04-04
Patrick Webster (patrick osisecurity com au)

Manhattan Software IWMS (Integrated Workplace Management System) XML External Entity (XXE) Injection File Disclosure 2017-04-04
Patrick Webster (patrick osisecurity com au)

AirWatch Self Service Portal Username Parameter LDAP Injection 2017-04-04
Patrick Webster (patrick osisecurity com au)

Avaya Radvision SCOPIA Desktop dlg_loginownerid.jsp ownerid SQL Injection 2017-04-04
Patrick Webster (patrick osisecurity com au)

Lotus Protector for Mail Security remote code execution 2017-04-04
Patrick Webster (patrick osisecurity com au)

Kaseya VSA 6.5 Parameter Reflected XSS, Enumeration and Bruteforce Weakness 2017-04-04
Patrick Webster (patrick osisecurity com au)

Malware

 

Phishing

moneygram office

4th April 2017

Money Transfer Control Number
(M.T.C.N):: #:94575379

Chase

3rd April 2017

Important Update

Economic and Financial Crimes

3rd April 2017

Dear Victim

Vulnerebility

WebORB for Java Remote Code Execution and XML External Entity Injection Vulnerabilities
2017-04-05
http://www.securityfocus.com/bid/97384

Apache Flex BlazeDS CVE-2017-5641 Remote Code Execution Vulnerability
2017-04-05
http://www.securityfocus.com/bid/97383

Atlassian JIRA CVE-2017-5983 Remote Code Execution Vulnerability
2017-04-05
http://www.securityfocus.com/bid/97379

GraniteDS Multiple Remote Code Execution Vulnerabilities
2017-04-05
http://www.securityfocus.com/bid/97382

Exadel Flamingo Multiple Remote Code Execution and XML External Entity Injection Vulnerabilities
2017-04-05
http://www.securityfocus.com/bid/97380

Pivotal Spring Flex CVE-2017-3203 Remote Code Execution Vulnerability
2017-04-05
http://www.securityfocus.com/bid/97376

Multiple Asterisk Products Remote Buffer Overflow Vulnerability
2017-04-05
http://www.securityfocus.com/bid/97377

Apache Geode CVE-2017-5649 Information Disclosure Vulnerability
2017-04-05
http://www.securityfocus.com/bid/97378

Google Pixel/Pixel XL Qualcomm Avtimer Driver CVE-2016-5346 Information Disclosure Vulnerability
2017-04-05
http://www.securityfocus.com/bid/97371

Avaya Radvision SCOPIA Desktop SQL Injection Vulnerability
2017-04-05
http://www.securityfocus.com/bid/97374

Xen 'memory_exchange()' Function Incomplete Fix Privilege Escalation Vulnerability
2017-04-05
http://www.securityfocus.com/bid/97375

Multiple Bluecoat Products CVE-2016-9091 Command Injection Vulnerability
2017-04-05
http://www.securityfocus.com/bid/97372

Multiple IBM Products CVE-2016-8987 Access Bypass Vulnerability
2017-04-05
http://www.securityfocus.com/bid/97369

Mongoose OS CVE-2017-7185 Use After Free Denial of Service Vulnerability
2017-04-05
http://www.securityfocus.com/bid/97370

IBM Lotus Protector for Mail Encryption Local File Include Vulnerability
2017-04-05
http://www.securityfocus.com/bid/97373

Google Nexus Broadcom Wi-Fi Driver CVE-2017-0585 Information Disclosure Vulnerability
2017-04-05
http://www.securityfocus.com/bid/97366

Google Android CVE-2017-0561 Remote Code Execution Vulnerability
2017-04-05
http://www.securityfocus.com/bid/97367

Google Android Qualcomm Wi-Fi Driver CVE-2016-10235 Denial of Service Vulnerability
2017-04-05
http://www.securityfocus.com/bid/97361

Google Nexus Qualcomm Qualcomm CP Access Driver CVE-2017-0583 Privilege Escalation Vulnerability
2017-04-05
http://www.securityfocus.com/bid/97368

Google Nexus Qualcomm TrustZone CVE-2016-5349 Information Disclosure Vulnerability
2017-04-05
http://www.securityfocus.com/bid/97364

Google Android Qualcomm Kyro L2 Driver CVE-2017-6423 Privilege Escalation Vulnerability
2017-04-05
http://www.securityfocus.com/bid/97387

Google Nexus Qualcomm IPA Driver CVE-2016-10234 Information Disclosure Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97365

Linux Kernel CVE-2017-2636 Local Privilege Escalation Vulnerability
2017-04-04
http://www.securityfocus.com/bid/96732

Linux Kernel CVE-2017-6214 Remote Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/96421

Linux Kernel CVE-2016-2117 Remote Buffer Overflow Vulnerability
2017-04-04
http://www.securityfocus.com/bid/84500

Linux Kernel CVE-2017-6353 Incomplete Fix Local Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/96473

Linux Kernel CVE-2017-7184 Local Privilege Escalation Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97018

Linux Kernel CVE-2017-6347 Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/96487

Linux kernel CVE-2017-6346 Use After Free Local Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/96508

Linux Kernel CVE-2017-2596 Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/95878

SANS News

Whitelists: The Holy Grail of Attackers

Threatpost

Lessons From Top-to-Bottom Compromise of Brazilian Bank

Details Around Romanian Phishing Kit Creator, Campaign Revealed

Android Variant of Notorious Pegasus Spyware Found

Exploit

Apple Webkit - Universal Cross-Site Scripting by Accessing a Named Property from an...

Apple WebKit 10.0.2(12602.3.12.0.1) - 'disconnectSubframes' Universal Cross-Site...

Apple WebKit 10.0.2(12602.3.12.0.1, r210800) -...

Apple WebKit 10.0.2(12602.3.12.0.1) - 'Frame::setDocument (1)' Universal Cross-Site...

Apple Webkit - 'JSCallbackData' Universal Cross-Site Scripting

macOS/iOS Kernel 10.12.3 (16D32) - Double-Free Due to Bad Locking in fsevents Device

macOS/iOS Kernel 10.12.3 (16D32) - 'bpf' Heap Overflow

macOS/iOS Kernel 10.12.3 (16D32) - SIOCGIFORDER Socket ioctl Off-by-One Memory...

macOS Kernel 10.12.2 (16C67) - Memory Disclosure Due to Lack of Bounds Checking in...

macOS Kernel 10.12.3 (16D32) - Use-After-Free Due to Double-Release in posix_spawn

macOS/iOS Kernel 10.12.3 (16D32) - SIOCSIFORDER Socket ioctl Memory Corruption Due...

macOS Kernel 10.12.3 (16D32) - 'audit_pipe_open' Off-by-One Memory Corruption

macOS/iOS Kernel 10.12.3 (16D32) - Bad Locking in necp_open Use-After-Free

macOS Kernel 10.12.2 (16C67) - 'AppleIntelCapriController::GetLinkConfig' Code Execution...

Apple WebKit 10.0.2 - HTMLInputElement Use-After-Free

Apple WebKit - 'RenderLayer' Use-After-Free

Apple WebKit - Negative-Size memmove in HTMLFormElement

Apple WebKit - 'FormSubmission::create' Use-After-Free

Apple WebKit - 'ComposedTreeIterator::traverseNextInShadowTree' Use-After-Free

Apple WebKit - 'table' Use-After-Free

Apple WebKit - 'WebCore::toJS' Use-After-Free

Bluecoat ASG 6.6/CAS 1.3 - OS Command Injection (Metasploit)

Broadcom Wi-Fi SoC - TDLS Teardown Request Remote Heap Overflow Exploit

SolarWinds LEM 6.3.1 - Remote Code Execution (Metasploit)

Broadcom Wi-Fi SoC - 'dhd_handle_swc_evt' Heap Overflow

Bluecoat ASG 6.6/CAS 1.3 - Privilege Escalation (Metasploit)

Pixie 1.0.4 - Arbitrary File Upload

4.4.2017

Bugtraq

The password for the project protection of the Schneider Modicon TM221CE16R is hard-coded and cannot be changed. 2017-04-04
Ralf Spenneberg (info os-t de)

OS-S-2017-01: The password for the application protection of the Schneider Modicon TM221CE16R can be retrieved without authentication. Subsequently the application may be arbitrarily downloaded, uploaded and modified. CVSS 10. 2017-04-04
Ralf Spenneberg (info os-t de)

Moodle URL Manipulation Remote Account Information Disclosure 2017-04-04
Patrick Webster (patrick osisecurity com au)

iPlatinum iOneView Multiple Parameter Reflected XSS 2017-04-04
Patrick Webster (patrick osisecurity com au)

Kaseya information disclosure vulnerability 2017-04-04
Patrick Webster (patrick osisecurity com au)

AcoraCMS browser redirect and Cross-site scripting vulnerabilities 2017-04-04
Patrick Webster (patrick osisecurity com au)

SmartJobBoard - Cross-site scripting, personal information disclosure and PHPMailer package 2017-04-04
Patrick Webster (patrick osisecurity com au)

SilverStripe CMS - Path Disclosure 2017-04-04
Patrick Webster (patrick osisecurity com au)

Tweek!DM Document Management Authentication bypass, SQL injection 2017-04-04
Patrick Webster (patrick osisecurity com au)

Computer Associates API Gateway CRLF Response Splitting, Directory Traversal vulnerabilities 2017-04-04
Patrick Webster (patrick osisecurity com au)

CVE-2017-7185 - Mongoose OS - Use-after-free / Denial of Service 2017-04-04
Advisories (advisories compass-security com)

Lantern CMS Path Disclosure, SQL Injection, Reflected XSS 2017-04-04
Patrick Webster (patrick osisecurity com au)

Manhattan Software IWMS (Integrated Workplace Management System) XML External Entity (XXE) Injection File Disclosure 2017-04-04
Patrick Webster (patrick osisecurity com au)

AirWatch Self Service Portal Username Parameter LDAP Injection 2017-04-04
Patrick Webster (patrick osisecurity com au)

Avaya Radvision SCOPIA Desktop dlg_loginownerid.jsp ownerid SQL Injection 2017-04-04
Patrick Webster (patrick osisecurity com au)

Lotus Protector for Mail Security remote code execution 2017-04-04
Patrick Webster (patrick osisecurity com au)

Kaseya VSA 6.5 Parameter Reflected XSS, Enumeration and Bruteforce Weakness 2017-04-04
Patrick Webster (patrick osisecurity com au)

[security bulletin] HPESBGN03721 rev.1 - HPE Operations Bridge Analytics, Remote Cross-Site Scripting (XSS) 2017-04-03
security-alert hpe com

SEC Consult SA-20170403-0 :: Misbehavior of PHP fsockopen function 2017-04-03
SEC Consult Vulnerability Lab (research sec-consult com)

Splunk Enterprise Information Theft CVE-2017-5607 2017-04-01
apparitionsec gmail com (hyp3rlinx)

Malware

 

Phishing

moneygram office

4th April 2017

Money Transfer Control Number
(M.T.C.N):: #:94575379

Chase

3rd April 2017

Important Update

Economic and Financial Crimes

3rd April 2017

Dear Victim

Platinum Indigo MasterCard

3rd April 2017

MasterCard for Less Than
Perfect Credit

Vulnerebility

Google Nexus Qualcomm IPA Driver CVE-2016-10234 Information Disclosure Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97365

Linux Kernel CVE-2017-2636 Local Privilege Escalation Vulnerability
2017-04-04
http://www.securityfocus.com/bid/96732

Linux Kernel CVE-2017-6214 Remote Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/96421

Linux Kernel CVE-2016-2117 Remote Buffer Overflow Vulnerability
2017-04-04
http://www.securityfocus.com/bid/84500

Linux Kernel CVE-2017-6353 Incomplete Fix Local Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/96473

Linux Kernel CVE-2017-7184 Local Privilege Escalation Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97018

Linux Kernel CVE-2017-6347 Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/96487

Linux kernel CVE-2017-6346 Use After Free Local Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/96508

Linux Kernel CVE-2017-2596 Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/95878

Linux kernel CVE-2017-6345 Local Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/96510

Google Nexus Qualcomm Wi-Fi Driver CVE-2017-0584 Information Disclosure Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97363

Linux Kernel CVE-2016-9191 Local Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/94129

Linux Kernel CVE-2017-2584 Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/95430

Linux Kernel CVE-2017-2583 Privilege Escalation Vulnerability
2017-04-04
http://www.securityfocus.com/bid/95673

Linux Kernel CVE-2017-5669 Local Security Bypass Vulnerability
2017-04-04
http://www.securityfocus.com/bid/96754

Google Android HTC Touchscreen Driver CVE-2017-0577 Privilege Escalation Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97348

Google Pixel/Pixel XL Qualcomm Video Driver CVE-2017-6425 Information Disclosure Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97362

Google Nexus Qualcomm Sound Driver CVE-2017-0586 Information Disclosure Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97357

Google Pixel/Pixel XL Qualcomm USB Driver CVE-2016-10236 Information Disclosure Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97359

Google Pixel C CVE-2017-0329 Privilege Escalation Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97353

Linux Kernel CVE-2017-6001 Incomplete Fix Local Privilege Escalation Vulnerability
2017-04-04
http://www.securityfocus.com/bid/96264

Linux Kernel CVE-2017-7187 Local Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/96989

Linux Kernel 'arch/x86/kvm/vmx.c' Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/94933

Linux Kernel 'crypto/mcryptd.c' Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/95677

Linux Kernel 'kvm/emulate.c' Information Disclosure Vulnerability
2017-04-04
http://www.securityfocus.com/bid/94615

Linux kernel 'ip6_gre.c' Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/96037

Google Android CVE-2016-8399 Remote Privilege Escalation Vulnerability
2017-04-04
http://www.securityfocus.com/bid/94708

Linux Kernel CVE-2016-10088 Incomplete Fix Multiple Local Memory Corruption Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/95169

Linux Kernel CVE-2016-3951 Null Pointer Deference Local Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/91028

Linux Kernel CVE-2016-8632 Local Heap Overflow Vulnerability
2017-04-04
http://www.securityfocus.com/bid/94211Google Android SurfaceFlinger CVE-2017-0546 Privilege Escalation Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97341

Google Android HTC Touchscreen Driver CVE-2017-0563 Privilege Escalation Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97342

Google Android NVIDIA Crypto Driver Multiple Information Disclosure Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97347

Google Android Qualcomm Video Driver Multiple Privilege Escalation Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97339

Google Android CameraBase CVE-2017-0544 Privilege Escalation Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97337

Google Android Mediaserver CVE-2017-0547 Information Disclosure Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97338

Google Android Mediaserver Multiple Denial of Service Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97336

Google Android Synaptics Touchscreen Driver Multiple Privilege Escalation Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97335

Google Android Mediaserver Multiple Information Disclosure Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97332

Google Android NVIDIA Crypto Driver Multiple Privilege Escalation Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97333

Google Android Qualcomm components Multiple Unspecified Security Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97334

Google Android Mediaserver Multiple Memory Corruption Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97330

Google Android Broadcom Wi-Fi Driver Multiple Privilege Escalation Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97331

Google Android Qualcomm components Multiple Unspecified Security Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97329

Apple iOS CVE-2017-6975 Arbitray Code Execution Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97328

libarchive CVE-2016-10209 Denial Of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97327

Multiple IBM Products CVE-2016-6100 Cross Site Request Forgery Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97326

collectd CVE-2017-7401 Multiple Denial of Service Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97321

IBM Business Process Manager CVE-2017-1140 Cross Site Scripting Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97322

Ninka CVE-2017-7239 Security Bypass Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97325

OpenStack Horizon CVE-2017-7400 Cross Site Scripting Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97324

Capstone 'winkernel_mm.c' Integer Overflow Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97323

CHICKEN CVE-2017-6949 Remote Buffer Overflow Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97317

Novell eDirectory CVE-2016-9168 Clickjacking Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97320

QEMU 'hw/9pfs/9p.c' Multiple Denial of Service Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97319

Multiple Symantec Products CVE-2016-6590 DLL Loading Local Privilege Escalation Vulnerability
2017-04-04
http://www.securityfocus.com/bid/94279

WallacePOS 'myaccount/resetpassword.php' Cross Site Scripting Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97316

Novell GroupWise CVE-2016-9169 Cross Site Scripting Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97318

Novell eDirectory CVE-2016-9167 Remote Privilege Escalation Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97315

audiofile CVE-2017-6837 Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97314Google Android Broadcom Wi-Fi Driver Multiple Privilege Escalation Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97331

Google Android Qualcomm components Multiple Unspecified Security Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97329

Apple iOS CVE-2017-6975 Arbitray Code Execution Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97328

libarchive CVE-2016-10209 Denial Of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97327

Multiple IBM Products CVE-2016-6100 Cross Site Request Forgery Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97326

collectd CVE-2017-7401 Multiple Denial of Service Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97321

IBM Business Process Manager CVE-2017-1140 Cross Site Scripting Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97322

Ninka CVE-2017-7239 Security Bypass Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97325

OpenStack Horizon CVE-2017-7400 Cross Site Scripting Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97324

Capstone 'winkernel_mm.c' Integer Overflow Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97323

CHICKEN CVE-2017-6949 Remote Buffer Overflow Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97317

Novell eDirectory CVE-2016-9168 Clickjacking Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97320

QEMU 'hw/9pfs/9p.c' Multiple Denial of Service Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97319

Multiple Symantec Products CVE-2016-6590 DLL Loading Local Privilege Escalation Vulnerability
2017-04-04
http://www.securityfocus.com/bid/94279

WallacePOS 'myaccount/resetpassword.php' Cross Site Scripting Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97316

Novell GroupWise CVE-2016-9169 Cross Site Scripting Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97318

Novell eDirectory CVE-2016-9167 Remote Privilege Escalation Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97315

audiofile CVE-2017-6837 Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97314

HelpMeWatchWho CVE-2017-7387 Cross Site Scripting Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97309

radare2 CVE-2017-6448 Stack Buffer Overflow Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97313

TigerVNC Multiple Security Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97305

Pixie CVE-2017-7361 Cross Site Scripting Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97274

SocialNetwork CVE-2017-7390 Cross Site Scripting Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97312

Openeclass 'webconf/webconf.php' Multiple Cross Site Scripting Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97310

Magmi 'magmi/web/ajax_gettime.php' Cross Site Scripting Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97311

Linux Kernel CVE-2017-7374 Local Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97308

Apple iOS/macOS/WatchOS/tvOS CVE-2017-2490 Memory Corruption Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97301

podofo Null Pointer Dereference Denial of Service and Heap Based Buffer Overflow Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97296

yaml-cpp CVE-2017-5950 Stack Buffer Overflow Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97307

Multiple Splunk Products Multiple Security Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97297Multiple IBM Products CVE-2016-6100 Cross Site Request Forgery Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97326

collectd CVE-2017-7401 Multiple Denial of Service Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97321

IBM Business Process Manager CVE-2017-1140 Cross Site Scripting Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97322

Ninka CVE-2017-7239 Security Bypass Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97325

OpenStack Horizon CVE-2017-7400 Cross Site Scripting Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97324

Capstone 'winkernel_mm.c' Integer Overflow Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97323

CHICKEN CVE-2017-6949 Remote Buffer Overflow Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97317

Novell eDirectory CVE-2016-9168 Clickjacking Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97320

QEMU 'hw/9pfs/9p.c' Multiple Denial of Service Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97319

Multiple Symantec Products CVE-2016-6590 DLL Loading Local Privilege Escalation Vulnerability
2017-04-04
http://www.securityfocus.com/bid/94279

WallacePOS 'myaccount/resetpassword.php' Cross Site Scripting Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97316

Novell GroupWise CVE-2016-9169 Cross Site Scripting Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97318

Novell eDirectory CVE-2016-9167 Remote Privilege Escalation Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97315

audiofile CVE-2017-6837 Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97314

HelpMeWatchWho CVE-2017-7387 Cross Site Scripting Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97309

radare2 CVE-2017-6448 Stack Buffer Overflow Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97313

TigerVNC Multiple Security Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97305

Pixie CVE-2017-7361 Cross Site Scripting Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97274

SocialNetwork CVE-2017-7390 Cross Site Scripting Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97312

Openeclass 'webconf/webconf.php' Multiple Cross Site Scripting Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97310

Magmi 'magmi/web/ajax_gettime.php' Cross Site Scripting Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97311

Linux Kernel CVE-2017-7374 Local Denial of Service Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97308

Apple iOS/macOS/WatchOS/tvOS CVE-2017-2490 Memory Corruption Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97301

podofo Null Pointer Dereference Denial of Service and Heap Based Buffer Overflow Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97296

yaml-cpp CVE-2017-5950 Stack Buffer Overflow Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97307

Multiple Splunk Products Multiple Security Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97297

Apple macOS CVE-2017-2477 Multiple Memory Corruption Vulnerabilities
2017-04-04
http://www.securityfocus.com/bid/97303

Adobe Acrobat and Reader CVE-2017-3010 Unspecified Memory Corruption Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97306

Adobe Acrobat and Reader CVE-2017-3009 Buffer Overflow Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97302

radare2 'libr/bin/p/bin_bflt.c' Remote Heap Buffer Overflow Vulnerability
2017-04-04
http://www.securityfocus.com/bid/97299

SANS News

A Practical Use for a SHA1 Collision

Threatpost

Fake SEO Plugin Used In WordPress Malware Attacks

Memory Corruption Mitigations Doing Their Job

Exploit

Apache Tomcat 6/7/8/9 - Information Disclosure

Maian Uploader 4.0 - 'user' Parameter SQL Injection

Maian Survey 1.1 - 'survey' Parameter SQL Injection

Maian Greetings 2.1 - 'cat' Parameter SQL Injection

Zyxel, EMG2926 < V1.00(AAQT.4)b8 - OS Command Injection

Bluecoat ASG 6.6/CAS 1.3 - OS Command Injection (Metasploit)

Pixie 1.0.4 - Arbitrary File Upload

Bluecoat ASG 6.6/CAS 1.3 - Privilege Escalation (Metasploit)

3.4.2017

Bugtraq

SEC Consult SA-20170403-0 :: Misbehavior of PHP fsockopen function 2017-04-03
SEC Consult Vulnerability Lab (research sec-consult com)

Splunk Enterprise Information Theft CVE-2017-5607 2017-04-01
apparitionsec gmail com (hyp3rlinx)

[security bulletin] HPESBGN03722 rev.1 - HPE Operations Agent, Local Escalation of Privilege 2017-03-31
security-alert hpe com

[security bulletin] HPESBHF03723 rev.1 - HPE Aruba ClearPass Policy Manager, using Apache Struts, Remote Code Execution 2017-03-29
security-alert hpe com

Malware

Trojan.Redleavy

Phishing

Platinum Indigo MasterCard

3rd April 2017

MasterCard for Less Than
Perfect Credit

AOL

2nd April 2017

Limit

Apple

1st April 2017

Important Security
Notification

Economic and Financial Crimes

1st April 2017

Dear Victim

Citi Alerts

1st April 2017

Personal Information Update

Vulnerebility

Adobe Acrobat and Reader CVE-2017-3010 Unspecified Memory Corruption Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97306

Adobe Acrobat and Reader CVE-2017-3009 Buffer Overflow Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97302

radare2 'libr/bin/p/bin_bflt.c' Remote Heap Buffer Overflow Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97299

Ruby CVE-2017-6181 Denial of Service Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97304

WebKit CVE-2017-5949 Denial of Service Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97298

Apple macOS CVE-2017-2489 Information Disclosure Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97300

LastPass Isolated World Global Properties Remote Code Execution Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97295

Ceragon FibeAir IP-10 Web Interface Authentication Bypass Vulnerability
2017-04-03
http://www.securityfocus.com/bid/91263

GNU glibc 'getaddrinfo()' Function Incomplete Fix Remote Denial of Service Vulnerability
2017-04-03
http://www.securityfocus.com/bid/88440

Multiple GIGABYTE Products VU#507496 Multiple Security Bypass Vulnerabilities
2017-04-03
http://www.securityfocus.com/bid/97294

CMS Made Simple CVE-2017-7255 Cross-Site Scripting Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97203

CHICKEN CVE-2015-4556 Denial of Service Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97293

libplist 'parse_string_node()' Function Local Denial of Service Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97290

libplist 'base64encode()' Function Local Denial of Service Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97291

Splunk Enterprise HTML Injection and Information Disclosure Vulnerabilities
2017-04-03
http://www.securityfocus.com/bid/97286

ownCloud and Nextcloud CVE-2016-9459 HTML Injection Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97284

Pitivi CVE-2015-0855 Arbitrary Code Execution Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97283

Nextcloud CVE-2016-9464 Unauthorized Access Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97287

ownCloud and Nextcloud CVE-2016-9462 Security Bypass Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97285

Multiple VMware Products CVE-2017-4902 Local Heap-Based Buffer Overflow Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97163

Multiple VMware Products CVE-2017-4904 Local Memory Corruption Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97165

Multiple VMware Products CVE-2017-4905 Local Information Disclosure Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97164

ownCloud and NextCloud CVE-2016-9460 Content Spoofing Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97282

Mozilla Firefox CVE-2017-5428 Integer Overflow Vulnerability
2017-04-03
http://www.securityfocus.com/bid/96959

GNU Binutils CVE-2017-7224 Remote Denial of Service Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97277

Multiple VMware Products CVE-2017-4903 Local Memory Corruption Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97160

Linux Kernel CVE-2017-7184 Local Privilege Escalation Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97018

Exponent CMS CVE-2016-9087 SQL Injection Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97271

libplist 'parse_string_node()' Function Local Heap Buffer Overflow Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97278

libplist 'parse_unicode_node()' Function Local Heap Buffer Overflow Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97281
libplist 'parse_string_node()' Function Local Denial of Service Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97290

libplist 'base64encode()' Function Local Denial of Service Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97291

Splunk Enterprise HTML Injection and Information Disclosure Vulnerabilities
2017-04-03
http://www.securityfocus.com/bid/97286

ownCloud and Nextcloud CVE-2016-9459 HTML Injection Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97284

Pitivi CVE-2015-0855 Arbitrary Code Execution Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97283

Nextcloud CVE-2016-9464 Unauthorized Access Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97287

ownCloud and Nextcloud CVE-2016-9462 Security Bypass Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97285

Multiple VMware Products CVE-2017-4902 Local Heap-Based Buffer Overflow Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97163

Multiple VMware Products CVE-2017-4904 Local Memory Corruption Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97165

Multiple VMware Products CVE-2017-4905 Local Information Disclosure Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97164

ownCloud and NextCloud CVE-2016-9460 Content Spoofing Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97282

Mozilla Firefox CVE-2017-5428 Integer Overflow Vulnerability
2017-04-03
http://www.securityfocus.com/bid/96959

GNU Binutils CVE-2017-7224 Remote Denial of Service Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97277

Multiple VMware Products CVE-2017-4903 Local Memory Corruption Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97160

Linux Kernel CVE-2017-7184 Local Privilege Escalation Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97018

Exponent CMS CVE-2016-9087 SQL Injection Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97271

libplist 'parse_string_node()' Function Local Heap Buffer Overflow Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97278

libplist 'parse_unicode_node()' Function Local Heap Buffer Overflow Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97281

Google Android CVE-2016-8399 Remote Privilege Escalation Vulnerability
2017-04-03
http://www.securityfocus.com/bid/94708

ownCloud and Nextcloud CVE-2016-9461 Unauthorized Access Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97276

Linux Kernel CVE-2016-2384 Local Denial of Service Vulnerability
2017-04-03
http://www.securityfocus.com/bid/83256

Quagga Routing Software Suite CVE-2016-4049 Denial Of Service Vulnerability
2017-04-03
http://www.securityfocus.com/bid/88561

IBM Cognos Analytics CVE-2016-3031 Cross Site Scripting Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97280

IBM Cognos Analytics CVE-2016-3015 Cross Site Scripting Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97279

GNU Binutils CVE-2017-7225 Remote Denial of Service Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97275

Exponent CMS CVE-2016-9020 SQL Injection Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97269

IBM TRIRIGA Application Platform CVE-2017-1180 Unspecified Remote Privilege Escalation Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97273

Pixie CVE-2017-7361 Cross Site Scripting Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97274

Trend Micro Mobile Security CVE-2016-9319 SSL Certificate Validation Security Bypass Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97272

Pixie CVE-2017-7362 Cross Site Scripting Vulnerability
2017-04-03
http://www.securityfocus.com/bid/97268

SANS News

IPFire - A Household Multipurpose Security Gateway

Threatpost

Fake SEO Plugin Used In WordPress Malware Attacks

Memory Corruption Mitigations Doing Their Job

Exploit

 

2.4.2017

Bugtraq

[security bulletin] HPESBGN03722 rev.1 - HPE Operations Agent, Local Escalation of Privilege 2017-03-31
security-alert hpe com

[security bulletin] HPESBHF03723 rev.1 - HPE Aruba ClearPass Policy Manager, using Apache Struts, Remote Code Execution 2017-03-29
security-alert hpe com

[security bulletin] HPESBUX03725 rev.1 - HPE HP-UX Web Server Suite running Apache, Multiple Vulnerabilities 2017-03-29
security-alert hpe com

ESA-2017-013: RSA Archer® GRC Security Operations Management Sensitive Information Disclosure Vulnerability 2017-03-29
EMC Product Security Response Center (Security_Alert emc com)

ESA-2017-028: EMC Isilon OneFS Path Traversal Vulnerability 2017-03-29
EMC Product Security Response Center (Security_Alert emc com)

[SECURITY] [DSA 3824-1] firebird2.5 security update 2017-03-29
Sebastien Delafond (seb debian org)

Malware

Worm:Win32/Bluber.A
BrowserModifier:Win32/ShopNav

Trojan:Win32/FakeSysdef

Adware:Win32/Peapoon

Trojan.Dimnie

Backdoor.Khrat

Trojan.Hirsdov

Phishing

Amazon Gift Cards

31st March 2017

🎁 Get a year of Amazon
Prime

Satellite Dealer

31st March 2017

FREE HBO SHOWTIME + $50 VISA
Gift Card

Apple ID

31st March 2017

Reminder: We have updates on
our Policy Update page,
service [246]

Vulnerebility

libplist 'parse_string_node()' Function Local Denial of Service Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97290

libplist 'base64encode()' Function Local Denial of Service Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97291

Splunk Enterprise HTML Injection and Information Disclosure Vulnerabilities
2017-04-02
http://www.securityfocus.com/bid/97286

ownCloud and Nextcloud CVE-2016-9459 HTML Injection Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97284

Pitivi CVE-2015-0855 Arbitrary Code Execution Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97283

Nextcloud CVE-2016-9464 Unauthorized Access Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97287

ownCloud and Nextcloud CVE-2016-9462 Security Bypass Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97285

Multiple VMware Products CVE-2017-4902 Local Heap-Based Buffer Overflow Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97163

Multiple VMware Products CVE-2017-4904 Local Memory Corruption Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97165

Multiple VMware Products CVE-2017-4905 Local Information Disclosure Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97164

ownCloud and NextCloud CVE-2016-9460 Content Spoofing Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97282

Mozilla Firefox CVE-2017-5428 Integer Overflow Vulnerability
2017-04-02
http://www.securityfocus.com/bid/96959

GNU Binutils CVE-2017-7224 Remote Denial of Service Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97277

Multiple VMware Products CVE-2017-4903 Local Memory Corruption Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97160

Linux Kernel CVE-2017-7184 Local Privilege Escalation Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97018

Exponent CMS CVE-2016-9087 SQL Injection Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97271

libplist 'parse_string_node()' Function Local Heap Buffer Overflow Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97278

libplist 'parse_unicode_node()' Function Local Heap Buffer Overflow Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97281

Google Android CVE-2016-8399 Remote Privilege Escalation Vulnerability
2017-04-02
http://www.securityfocus.com/bid/94708

ownCloud and Nextcloud CVE-2016-9461 Unauthorized Access Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97276

Linux Kernel CVE-2016-2384 Local Denial of Service Vulnerability
2017-04-02
http://www.securityfocus.com/bid/83256

Quagga Routing Software Suite CVE-2016-4049 Denial Of Service Vulnerability
2017-04-02
http://www.securityfocus.com/bid/88561

IBM Cognos Analytics CVE-2016-3031 Cross Site Scripting Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97280

IBM Cognos Analytics CVE-2016-3015 Cross Site Scripting Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97279

GNU Binutils CVE-2017-7225 Remote Denial of Service Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97275

Exponent CMS CVE-2016-9020 SQL Injection Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97269

IBM TRIRIGA Application Platform CVE-2017-1180 Unspecified Remote Privilege Escalation Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97273

Pixie CVE-2017-7361 Cross Site Scripting Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97274

Trend Micro Mobile Security CVE-2016-9319 SSL Certificate Validation Security Bypass Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97272

Pixie CVE-2017-7362 Cross Site Scripting Vulnerability
2017-04-02
http://www.securityfocus.com/bid/97268libplist 'parse_string_node()' Function Local Denial of Service Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97290

libplist 'base64encode()' Function Local Denial of Service Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97291

Splunk Enterprise HTML Injection and Information Disclosure Vulnerabilities
2017-04-01
http://www.securityfocus.com/bid/97286

ownCloud and Nextcloud CVE-2016-9459 HTML Injection Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97284

Pitivi CVE-2015-0855 Arbitrary Code Execution Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97283

Nextcloud CVE-2016-9464 Unauthorized Access Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97287

ownCloud and Nextcloud CVE-2016-9462 Security Bypass Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97285

Multiple VMware Products CVE-2017-4902 Local Heap-Based Buffer Overflow Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97163

Multiple VMware Products CVE-2017-4904 Local Memory Corruption Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97165

Multiple VMware Products CVE-2017-4905 Local Information Disclosure Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97164

ownCloud and NextCloud CVE-2016-9460 Content Spoofing Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97282

Mozilla Firefox CVE-2017-5428 Integer Overflow Vulnerability
2017-04-01
http://www.securityfocus.com/bid/96959

GNU Binutils CVE-2017-7224 Remote Denial of Service Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97277

Multiple VMware Products CVE-2017-4903 Local Memory Corruption Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97160

Linux Kernel CVE-2017-7184 Local Privilege Escalation Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97018

Exponent CMS CVE-2016-9087 SQL Injection Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97271

libplist 'parse_string_node()' Function Local Heap Buffer Overflow Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97278

libplist 'parse_unicode_node()' Function Local Heap Buffer Overflow Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97281

Google Android CVE-2016-8399 Remote Privilege Escalation Vulnerability
2017-04-01
http://www.securityfocus.com/bid/94708

ownCloud and Nextcloud CVE-2016-9461 Unauthorized Access Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97276

Linux Kernel CVE-2016-2384 Local Denial of Service Vulnerability
2017-04-01
http://www.securityfocus.com/bid/83256

Quagga Routing Software Suite CVE-2016-4049 Denial Of Service Vulnerability
2017-04-01
http://www.securityfocus.com/bid/88561

IBM Cognos Analytics CVE-2016-3031 Cross Site Scripting Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97280

IBM Cognos Analytics CVE-2016-3015 Cross Site Scripting Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97279

GNU Binutils CVE-2017-7225 Remote Denial of Service Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97275

Exponent CMS CVE-2016-9020 SQL Injection Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97269

IBM TRIRIGA Application Platform CVE-2017-1180 Unspecified Remote Privilege Escalation Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97273

Pixie CVE-2017-7361 Cross Site Scripting Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97274

Trend Micro Mobile Security CVE-2016-9319 SSL Certificate Validation Security Bypass Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97272

Pixie CVE-2017-7362 Cross Site Scripting Vulnerability
2017-04-01
http://www.securityfocus.com/bid/97268

SANS News

 

Threatpost

Aviation-Related Phishing Campaigns Seeking Credentials

Exploit

Splunk Enterprise - Information Disclosure

Membership Formula - 'order' Parameter SQL Injection

31.3.2017

Bugtraq

[security bulletin] HPESBHF03723 rev.1 - HPE Aruba ClearPass Policy Manager, using Apache Struts, Remote Code Execution 2017-03-29
security-alert hpe com

[security bulletin] HPESBUX03725 rev.1 - HPE HP-UX Web Server Suite running Apache, Multiple Vulnerabilities 2017-03-29
security-alert hpe com

ESA-2017-013: RSA Archer® GRC Security Operations Management Sensitive Information Disclosure Vulnerability 2017-03-29
EMC Product Security Response Center (Security_Alert emc com)

ESA-2017-028: EMC Isilon OneFS Path Traversal Vulnerability 2017-03-29
EMC Product Security Response Center (Security_Alert emc com)

[SECURITY] [DSA 3824-1] firebird2.5 security update 2017-03-29
Sebastien Delafond (seb debian org)

Malware

Backdoor.Khrat

Phishing

Yahoo UK

31st March 2017

Yahoo UK Security Issue

MR ANTHONY CHARLES

30th March 2017

UNITED BANK OF AFRICA
INTERNATIONAL

Vulnerebility

Pixie CVE-2017-7363 Cross Site Scripting Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97259

NetIQ Sentinel CVE-2017-5185 Denial of Service Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97267

Dahua IP Camera CVE-2017-7253 Privilege Escalation and Information Disclosure Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/97263

MikroTik RouterBoard CVE-2017-7285 Remote Denial of Service Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97266

NetIQ Sentinel CVE-2017-5184 Information Disclosure Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97262

Sophos Web Appliance Multiple Command Injection and Session Fixation Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/97261

Bubblewrap CVE-2017-5226 Security Bypass Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97260

Linux Kernel CVE-2017-2647 Null Pointer Deference Local Privilege Escalation Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97258

Linux Kernel CVE-2017-7346 Local Denial of Service Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97257

Wonderware InTouch Access Anywhere Multiple Security Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/97256

Multiple eMLi Products CVE-2017-7258 Directory Traversal Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97255

Multiple Schneider Electric Modicon Products Weak Cryptography Multiple Security Weaknesses
2017-03-31
http://www.securityfocus.com/bid/97254

MantisBT CVE-2017-7241 Cross Site Scripting Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97253

MantisBT CVE-2017-6973 Cross Site Scripting Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97252

MantisBT CVE-2017-7309 Cross Site Scripting Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97251

Mozilla Firefox CVE-2017-5426 Security Bypass Vulnerability
2017-03-31
http://www.securityfocus.com/bid/96694

Mozilla Firefox and Thunderbird Multiple Security Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/96693

Mozilla Firefox CVE-2017-5403 Denial of Service Vulnerability
2017-03-31
http://www.securityfocus.com/bid/96691

Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/96664

Mozilla Firefox MFSA 2017-05 Multiple Security Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/96692

Mozilla Firefox and Thunderbird CVE-2017-5401 Memory Corruption Vulnerability
2017-03-31
http://www.securityfocus.com/bid/96677

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/96651

Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/96654

IBM Algo One CVE-2017-1154 Unauthorized Access Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97248

Xen 'xenstore' Denial of Service Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97250

CentreCOM AR260S V2 CVE-2017-2125 Privilege Escalation Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97249

IBM TRIRIGA Application Platform CVE-2017-1171 Unspecified Remote Privilege Escalation Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97245

IBM Cúram Social Program Management CVE-2016-6111 XML External Entity Injection Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97244

Miele Professional PG 8528 CVE-2017-7240 Directory Traversal Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97080

Trango Altum AC600 Devices CVE-2016-10306 Insecure Default Password Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97241MantisBT CVE-2017-6973 Cross Site Scripting Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97252

MantisBT CVE-2017-7309 Cross Site Scripting Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97251

Mozilla Firefox CVE-2017-5426 Security Bypass Vulnerability
2017-03-31
http://www.securityfocus.com/bid/96694

Mozilla Firefox and Thunderbird Multiple Security Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/96693

Mozilla Firefox CVE-2017-5403 Denial of Service Vulnerability
2017-03-31
http://www.securityfocus.com/bid/96691

Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/96664

Mozilla Firefox MFSA 2017-05 Multiple Security Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/96692

Mozilla Firefox and Thunderbird CVE-2017-5401 Memory Corruption Vulnerability
2017-03-31
http://www.securityfocus.com/bid/96677

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/96651

Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-03-31
http://www.securityfocus.com/bid/96654

IBM Algo One CVE-2017-1154 Unauthorized Access Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97248

Xen 'xenstore' Denial of Service Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97250

CentreCOM AR260S V2 CVE-2017-2125 Privilege Escalation Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97249

IBM TRIRIGA Application Platform CVE-2017-1171 Unspecified Remote Privilege Escalation Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97245

IBM Cúram Social Program Management CVE-2016-6111 XML External Entity Injection Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97244

Miele Professional PG 8528 CVE-2017-7240 Directory Traversal Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97080

Trango Altum AC600 Devices CVE-2016-10306 Insecure Default Password Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97241

Multiple Trango devices CVE-2016-10307 Insecure Default Password Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97242

Siklu EtherHaul radios CVE-2016-10308 Insecure Default Password Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97243

Multiple IBM Products CVE-2017-1133 Cross Site Scripting Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97239

Exponent CMS CVE-2016-9019 SQL Injection Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97240

Multiple VMware Products CVE-2017-4902 Heap-Based Buffer Overflow Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97163

Multiple VMware Products CVE-2017-4904 Memory Corruption Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97165

Multiple VMware Products CVE-2017-4903 Memory Corruption Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97160

Multiple VMware Products CVE-2017-4905 Information Disclosure Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97164

Honeywell Intermec Industrial Printers CVE-2017-5671 Local Privilege Escalation Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97236

Exponent CMS CVE-2016-7789 SQL Injection Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97235

Exponent CMS CVE-2016-7788 SQL Injection Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97233

Wordpress BuddyPress Plugin CVE-2017-6954 Security Bypass Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97238

Multiple Flexense Products CVE-2017-7310 Buffer Overflow Vulnerability
2017-03-31
http://www.securityfocus.com/bid/97237

SANS News

Pro & Con of Outsourcing your SOC

Threatpost

NukeBot Banking Trojan Source Code Leaked Online by Author

Industry Braces for Repeal of ISP Privacy Rules

Github Repository Owners Targeted by Data-Stealing Malware

New Mirai Variant Carries Out 54-Hour DDoS Attacks

Exploit

Apple macOS/IOS 10.12.2(16C67) - mach_msg Heap Overflow

30.3.2017

Bugtraq

[security bulletin] HPESBHF03723 rev.1 - HPE Aruba ClearPass Policy Manager, using Apache Struts, Remote Code Execution 2017-03-29
security-alert hpe com

[security bulletin] HPESBUX03725 rev.1 - HPE HP-UX Web Server Suite running Apache, Multiple Vulnerabilities 2017-03-29
security-alert hpe com

ESA-2017-013: RSA Archer® GRC Security Operations Management Sensitive Information Disclosure Vulnerability 2017-03-29
EMC Product Security Response Center (Security_Alert emc com)

ESA-2017-028: EMC Isilon OneFS Path Traversal Vulnerability 2017-03-29
EMC Product Security Response Center (Security_Alert emc com)

[SECURITY] [DSA 3824-1] firebird2.5 security update 2017-03-29
Sebastien Delafond (seb debian org)

[SECURITY] [DSA 3798-2] tnef regression update 2017-03-29
Sebastien Delafond (seb debian org)

[slackware-security] mariadb (SSA:2017-087-01) 2017-03-28
Slackware Security Team (security slackware com)

Malware

Trojan.Dimnie

Backdoor.Khrat

Phishing

MR ANTHONY CHARLES

30th March 2017

UNITED BANK OF AFRICA
INTERNATIONAL

CTTExpresso

29th March 2017

=?UTF-8?Q?Erro_no_endere=C3=A7
o_de_entrega.?=

Credit One Platinum Visa Credi

28th March 2017

Earn cash back on
purchases—See if you
Pre-Qualify

Vulnerebility

Multiple Siklu EtherHaul Devices CVE-2017-7318 Remote Command Execution Vulnerability
2017-12-29
http://www.securityfocus.com/bid/97227

MODX Revolution CMS Multiple Security Vulnerabilities
2017-03-30
http://www.securityfocus.com/bid/97228

Apache Ambari CVE-2016-4976 Local Information Disclosure Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97229

XOOPS CVE-2017-7290 SQL Injection Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97230

cURL/libcURL Incomplete Fix CVE-2017-2628 Remote Security Bypass Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97187

Firebird CVE-2017-6369 Remote Code Execution Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97070

RSA Archer Security Operations Management with RSA UCF Local Information Disclosure Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97225

Apache Camel CVE-2017-5643 Server Side Request Forgery Security Bypass Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97226

Linux Kernel CVE-2017-2636 Local Privilege Escalation Vulnerability
2017-03-30
http://www.securityfocus.com/bid/96732

Linux Kernel CVE-2017-7184 Local Privilege Escalation Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97018

Samba CVE-2017-2619 Symlink Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97033

Huawei TIT-AL00 CVE-2017-2735 Local Security Bypass Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97224

Ubuntu AppArmor CVE-2017-6507 Security Bypass Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97223

EMC Isilon OneFS CVE-2017-4980 Directory Traversal Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97222

Google Chrome CVE-2017-5055 Use After Free Memory Corruption Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97221

Google Chrome and Chrome OS Multiple Security Vulnerabilities
2017-03-30
http://www.securityfocus.com/bid/97220

GNU Binutils CVE-2017-7300 Remote Heap Buffer Overflow Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97219

GNU Binutils 'aout_link_add_symbols()' Function Remote Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97218

Exponent CMS CVE-2016-7783 SQL Injection Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97212

GNU Binutils CVE-2017-7299 Remote Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97217

GNU Binutils 'swap_std_reloc_out()' Function Remote Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97216

Exponent CMS CVE-2016-7782 SQL Injection Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97210

GNU Binutils CVE-2017-7304 Remote Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97215

phpMyAdmin PMASA-2017-8 Security Bypass Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97211

HP Intelligent Management Center CVE-2017-5797 Information Disclosure Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97214

Exponent CMS CVE-2016-7780 SQL Injection Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97208

GNU Binutils CVE-2017-7303 Remote Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97213

Samsung Account CVE-2015-0864 Information Disclosure Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97207

Exponent CMS CVE-2016-7781 SQL Injection Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97206

GNU Binutils CVE-2017-7227 Remote Heap Buffer Overflow Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97209
GNU Binutils CVE-2017-7300 Remote Heap Buffer Overflow Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97219

GNU Binutils 'aout_link_add_symbols()' Function Remote Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97218

Exponent CMS CVE-2016-7783 SQL Injection Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97212

GNU Binutils CVE-2017-7299 Remote Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97217

GNU Binutils 'swap_std_reloc_out()' Function Remote Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97216

Exponent CMS CVE-2016-7782 SQL Injection Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97210

GNU Binutils CVE-2017-7304 Remote Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97215

phpMyAdmin PMASA-2017-8 Security Bypass Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97211

HP Intelligent Management Center CVE-2017-5797 Information Disclosure Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97214

Exponent CMS CVE-2016-7780 SQL Injection Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97208

GNU Binutils CVE-2017-7303 Remote Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97213

Samsung Account CVE-2015-0864 Information Disclosure Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97207

Exponent CMS CVE-2016-7781 SQL Injection Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97206

GNU Binutils CVE-2017-7227 Remote Heap Buffer Overflow Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97209

CMS Made Simple CVE-2017-7257 Cross-Site Scripting Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97205

CMS Made Simple CVE-2017-7256 Cross-Site Scripting Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97204

Allwinner Linux kernel 'sunxi-debug.c' Local Privilege Escalation Vulnerability
2017-03-30
http://www.securityfocus.com/bid/93442

Multiple F5 BIG-IP CVE-2016-7474 Local Information Disclosure Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97198

LibTIFF CVE-2016-10269 Heap Based Buffer Overflow Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97201

LibTIFF CVE-2016-10268 Heap Based Buffer Overflow Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97202

LibTIFF CVE-2016-10271 Heap Based Buffer Overflow Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97199

Wonder CMS CVE-2014-8702 Information Disclosure Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97192

LibTIFF CVE-2016-10270 Heap Based Buffer Overflow Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97200

LibTIFF CVE-2016-10272 Heap Based Buffer Overflow Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97197

Disk Sorter Enterprise CVE-2017-7230 Buffer Overflow Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97195

cloudflare-scrape CVE-2017-7235 Remote Code Execution Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97191

Eclipse tinydtls CVE-2017-7243 Denial of Service Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97193

Subrion CMS CVE-2017-6069 Cross Site Request Forgery Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97196

cURL/libcURL Incomplete Fix CVE-2017-2628 Remote Security Bypass Vulnerability
2017-03-30
http://www.securityfocus.com/bid/97187

Eview EV-07S GPS Tracker Buffer Overflow and Information Disclosure Vulnerabilities
2017-03-30
http://www.securityfocus.com/bid/97194

SANS News

Critical VMware vulnerabilities disclosed

Diverting built-in features for the bad

Threatpost

Workarounds Available for Flaws in Siemens RUGGEDCOM Gear

Publicly Attacked Microsoft IIS Zero Day Unlikely to be Patched

Industry Braces for Repeal of ISP Privacy Rules

Exploit

Sync Breeze Enterprise 9.5.16 - 'GET' Buffer Overflow (SEH)

Opensource Classified Ads Script - 'keyword' Parameter SQL Injection

EyesOfNetwork (EON) 5.1 - SQL Injection

AUFS (Ubuntu 15.10) - 'allow_userns' Fuse/Xattr User Namespaces Privilege Escalation

DiskBoss Enterprise 7.8.16 - 'Import Command' Buffer Overflow

DiskBoss Enterprise 7.8.16 - 'Import Command' Buffer Overflow

29.3.2017

Bugtraq

[SECURITY] [DSA 3798-2] tnef regression update 2017-03-29
Sebastien Delafond (seb debian org)

[slackware-security] mariadb (SSA:2017-087-01) 2017-03-28
Slackware Security Team (security slackware com)

APPLE-SA-2017-03-28-1 iCloud for Windows 6.2 2017-03-28
Apple Product Security (product-security-noreply lists apple com)

[SECURITY] [DSA 3823-1] eject security update 2017-03-28
Salvatore Bonaccorso (carnil debian org)

APPLE-SA-2017-03-27-7 macOS Server 5.3 2017-03-27
Apple Product Security (product-security-noreply lists apple com)

[SECURITY] [DSA 3821-1] gst-plugins-ugly1.0 security update 2017-03-27
Moritz Muehlenhoff (jmm debian org)

Malware

Trojan.Dimnie

Phishing

Credit One Platinum Visa Credi

28th March 2017

Earn cash back on
purchases—See if you
Pre-Qualify

Bank of America

28th March 2017

Bank of America Alert: Your
Online Access is Temporarily
Locked

CardApprovalUSA

27th March 2017

Open a new credit account

Vulnerebility

Disk Sorter Enterprise CVE-2017-7230 Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97195

cloudflare-scrape CVE-2017-7235 Remote Code Execution Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97191

Eclipse tinydtls CVE-2017-7243 Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97193

Subrion CMS CVE-2017-6069 Cross Site Request Forgery Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97196

cURL/libcURL Incomplete Fix CVE-2017-2628 Remote Security Bypass Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97187

Eview EV-07S GPS Tracker Buffer Overflow and Information Disclosure Vulnerabilities
2017-03-29
http://www.securityfocus.com/bid/97194

audiofile CVE-2017-6829 Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97189

Symphony CMS CVE-2017-6006 Cross Site Scripting Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97188

Linux Kernel CVE-2017-7273 Local Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97190

Irssi CVE-2017-7191 Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97185

Eview EV-07S GPS Tracker CVE-2017-5237 Security Bypass Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97186

Apache Ambari CVE-2016-6807 Remote Command Execution Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97184

Moodle CVE-2017-7298 Cross Site Scripting Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97182

audiofile CVE-2017-6828 Heap Based Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97183

radare2 'libr/util/r_pkcs7.c' Remote Denial Of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97181

icoutils 'decode_ne_resource_id()' Function Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/96292

icoutils 'simple_vec()' Function Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/96267

icoutils CVE-2017-5332 Local Code Execution Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95380

icoutils CVE-2017-5333 Local Integer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95678

icoutils 'extract_icons()' Function Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/96288

icoutils CVE-2017-5208 Local Integer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95315

Apache Camel CVE-2016-8749 Java Deserialization Multiple Remote Code Execution Vulnerabilities
2017-03-29
http://www.securityfocus.com/bid/97179

Rancher Server CVE-2017-7297 Security Bypass Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97180

Revive Adserver Multiple Security Vulnerabilities
2017-03-29
http://www.securityfocus.com/bid/83964

PHP CVE-2017-7272 Server Side Request Forgery Security Bypass Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97178

Yii framework CVE-2017-7271 Cross Site Scripting Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97167

Deluge CVE-2017-7178 Cross Site Request Forgery Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97041

Eject dmcrypt-get-device CVE-2017-6964 Local Code Execution Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97154

Linux Kernel CVE-2017-7294 Local Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97177

OCaml CVE-2015-8869 Multiple Security Vulnerabilities
2017-03-29
http://www.securityfocus.com/bid/89318IBM Rational Quality Manager CVE-2016-6031 Cross Site Scripting Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97169

F5 BIG-IP APM CVE-2016-7472 Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97168

LibTIFF CVE-2016-9533 Heap Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94742

Ruby on Rails Action Pack CVE-2016-0751 Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/81800

Apache And Microsoft IIS Range Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/21865

ImageMagick Incomplete Fix CVE-2017-7275 Memory Corruption Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97166

OpenSSH CVE-2016-10011 Local Information Disclosure Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94977

Python CVE-2016-5636 Heap Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/91247

tcpdump Multiple Buffer Overflow Vulnerabilities
2017-03-29
http://www.securityfocus.com/bid/95852

OpenSSH CVE-2016-10010 Privilege Escalation Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94972

OpenSSH CVE-2016-10012 Security Bypass Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94975

PHP 'ext/wddx/wddx.c' Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94846

LibTIFF CVE-2016-3619 Out Of Bounds Read Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/85919

OpenSSH CVE-2016-10009 Remote Code Execution Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94968

OpenSSL CVE-2016-7056 Local Information Disclosure Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95375

cURL/libcURL CVE-2016-9586 Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95019

PHP CVE-2016-10161 Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95768

PHP CVE-2016-10159 Integer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95774

Apache HTTP Server CVE-2016-8743 Security Bypass Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95077

PHP CVE-2016-10158 Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95764

PHP CVE-2016-10160 Remote Code Execution Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95783

Apache HTTP Server CVE-2016-0736 Remote Security Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95078

Apache HTTP Server CVE-2016-2161 Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/95076

Apache HTTP Server CVE-2016-8740 Denial of Service Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94650

Brave Browsers CVE-2016-9473 Address Bar Spoofing Vulnerability
2017-03-29
http://www.securityfocus.com/bid/97155

Apache HTTP Server CVE-2016-5387 Security Bypass Vulnerability
2017-03-29
http://www.securityfocus.com/bid/91816

LibTIFF CVE-2016-9539 Memory Corruption Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94754

LibTIFF CVE-2016-9540 Heap Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94747

LibTIFF CVE-2016-9536 Heap Buffer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94745

LibTIFF CVE-2016-9538 Integer Overflow Vulnerability
2017-03-29
http://www.securityfocus.com/bid/94753

SANS News

Logical & Physical Security Correlation

Critical VMware vulnerabilities disclosed

Threatpost

Apple Fixes 223 Vulnerabilities Across macOS, iOS, Safari

Microsoft Offers Analysis of Zero-Day Exploited By Zirconium Group

Harley Geiger on Cybersecurity Policy

‘Anonymous’ FTP Servers Leaving Healthcare Data Exposed

Exploit

Vm86 - Syscall Task Switch Kernel Panic / Privilege Escalation

Ubuntu 15.10 - 'USERNS ' Overlayfs Over Fuse Privilege Escalation

Ubuntu < 15.10 - PT Chown Arbitrary PTs Access Via UserNamespace Privilege...

Disk Sorter Enterprise 9.5.12 - 'Import Command' Buffer Overflow

NTP - Privilege Escalation

AUFS (Ubuntu 15.10) - 'allow_userns' Fuse/Xattr User Namespaces Privilege Escalation

DiskBoss Enterprise 7.8.16 - 'Import Command' Buffer Overflow

Apache 2.2 - Scoreboard Invalid Free On Shutdown

Apache < 2.0.64 / < 2.2.21 mod_setenvif - Integer Overflow

Linux Kernel (Ubuntu 11.10/12.04) - binfmt_script Stack Data Disclosure

DzSoft PHP Editor 4.2.7 - File Enumeration

Intermec PM43 Industrial Printer - Privilege Escalation

MikroTik RouterBoard 6.38.5 - Denial of Service

VX Search Enterprise 9.5.12 - 'Verify Email' Buffer Overflow

Microsoft Outlook - HTML Email Denial of Service

28.3.2017

Bugtraq

APPLE-SA-2017-03-27-7 macOS Server 5.3 2017-03-27
Apple Product Security (product-security-noreply lists apple com)

[SECURITY] [DSA 3821-1] gst-plugins-ugly1.0 security update 2017-03-27
Moritz Muehlenhoff (jmm debian org)

APPLE-SA-2017-03-27-1 Pages 6.1, Numbers 4.1, and Keynote 7.1 for Mac; Pages 3.1, Numbers 3.1, and Keynote 3.1 for iOS 2017-03-27
Apple Product Security (product-security-noreply lists apple com)

[SECURITY] [DSA 3817-1] jbig2dec security update 2017-03-24
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 3816-1] samba security update 2017-03-23
Salvatore Bonaccorso (carnil debian org)

Malware

Trojan.Aczibo

Phishing

Bank of America

28th March 2017

Bank of America Alert: Your
Online Access is Temporarily
Locked

CardApprovalUSA

27th March 2017

Open a new credit account

Cheap Auto Insurance Today

27th March 2017

New Auto Insurance Rates for
2017

LifeLock

26th March 2017

Your W-2 can be a 1-stop shop
for identity thieves

Vulnerebility

Cherry­Music CVE-2015-8309 Directory Traversal Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97149

Cherry­Music CVE-2015-8310 Cross Site Scripting Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97148

Icinga CVE-2015-8010 Cross Site Scripting Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97145

Revive Adserver Multiple Security Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/83964

Nghttp2 CVE-2017-2428 Multiple Remote Security Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97146

Apple iOS/tvOS/macOS/watchOS Multiple Security Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97137

Apple iOS APPLE-SA-2017-03-27-4 Multiple Security Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97138

McAfee Anti-Malware Scan CVE-2016-8031 Engine Multiple Local Security Bypass Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97142

McAfee Anti-Malware Scan Engine CVE-2016-8032 Multiple Local Security Bypass Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97144

Apple macOS APPLE-SA-2017-03-27-3 Multiple Security Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97140

WebKit CVE-2017-2415 Remote Code Execution Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97143

Pivotal Cloud Foundry Elastic Runtime CVE-2017-2773 Security Bypass Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97135

Apple Safari CVE-2017-2385 Local Security Bypass Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97136

Linux Kernel CVE-2017-7277 Multiple Local Memory Corruption Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97141

Apple macOS, iOS and tvOS CVE-2017-2448 Security Bypass Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97134

Apple iOS/WatchOS/tvOS/Safari CVE-2017-2444 Multiple Memory Corruption Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97131

WebKit CVE-2017-2471 Remote Code Execution Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97133

Apple iOS/macOS/WatchOS/tvOS CVE-2017-2485 Memory Corruption Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97132

WebKit Multiple Security Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97130

Apple iOS and Safari Multiple Security Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97129

pngdefry CVE-2017-7231 Heap Based Buffer Overflow Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97037

Apple macOS Server CVE-2017-2382 User Enumeration Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97128

Microsoft Internet Information Services CVE-2017-7269 Buffer Overflow Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97127

Apple iOS/Mac CVE-2017-2391 Information Disclosure Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97126

Schneider Electric VAMPSET Local Memory Corruption Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97124

WordPress recent-backups Plugin 'download-file.php' Arbitrary File Download Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97125

ZoneMinder CVE-2016-10203 Cross Site Scripting Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97122

Zimbra Collaboration Suite CVE-2016-9924 XML External Entity Injection Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97121

Multiple F5 BIG-IP Products CVE-2016-7468 Denial of Service Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97119

Firejail CVE-2017-5206 Security Bypass Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97120Microsoft Internet Information Services CVE-2017-7269 Buffer Overflow Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97127

Apple iOS/Mac CVE-2017-2391 Information Disclosure Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97126

Schneider Electric VAMPSET Local Memory Corruption Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97124

WordPress recent-backups Plugin 'download-file.php' Arbitrary File Download Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97125

ZoneMinder CVE-2016-10203 Cross Site Scripting Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97122

Zimbra Collaboration Suite CVE-2016-9924 XML External Entity Injection Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97121

Multiple F5 BIG-IP Products CVE-2016-7468 Denial of Service Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97119

Firejail CVE-2017-5206 Security Bypass Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97120

ZoneMinder CVE-2016-10206 Cross Site Request Forgery Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97114

PhishWall Client CVE-2017-2130 DLL Loading Remote Code Execution Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97113

ZoneMinder CVE-2016-10205 Session Fixation Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97116

WordPress YOP Poll Plugin CVE-2017-2127 Unspecified Cross Site Scripting Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97118

LibTIFF 'libtiff/tif_ojpeg.c' Divide By Zero Denial of Service Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97117

LibTIFF 'libtiff/tif_read.c' Divide By Zero Denial of Service Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97115

EyesOfNetwork CVE-2017-6087 Multiple Arbitrary Code Execution Vulnerabilities
2017-03-28
http://www.securityfocus.com/bid/97109

Nessus CVE-2017-7199 Local Privilege Escalation Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97110

Potrace CVE-2017-7263 Incomplete Fix Heap Buffer Overflow Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97112

MuPDF CVE-2017-7264 Use After Free Denial of Service Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97111

Multiple Zyxel Products CVE-2016-10227 Remote Denial of Service Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97105

WordPress Filedownload Plugin CVE-2015-1000004 Cross-Site Scripting Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97107

candidate-application-form Wordpress Plugin CVE-2015-1000005 Arbitrary File Download Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97108

WordPress Filedownload Plugin CVE-2015-1000003 SQL Injection Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97106

Linux Kernel CVE-2010-5328 Local Denial of Service Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97103

GOsa CVE-2014-9760 Cross Site Scripting Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97104

Node.js CVE-2014-9772 Cross Site Scripting Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97102

AMD Ryzen Processor CVE-2017-7262 Local Denial of Service Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97098

Artifex MuPDF CVE-2016-10247 Denial of Service Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97099

Symphony CMS CVE-2017-6067 Cross Site Scripting Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97101

Trend Micro InterScan Messaging Security Suite Directory Traversal Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97097

Linux Kernel CVE-2017-7261 Local Denial of Service Vulnerability
2017-03-28
http://www.securityfocus.com/bid/97096

SANS News

 

Threatpost

Fileless UAC Bypass Uses Windows Backup and Restore Utility

APT29 Used Domain Fronting, Tor to Execute Backdoor

New Clues Surface on Shamoon 2’s Destructive Behavior

Exploit

Microsoft Visual Studio 2015 update 3 - Denial of Service

Apple Safari - 'DateTimeFormat.format' Type Confusion

Apple Safari - Builtin JavaScript Allows Function.caller to be Used in Strict Mode

Apple Safari - Out-of-Bounds Read when Calling Bound Function

Internet Information Services (IIS) 6.0 WebDAV - 'ScStoragePathFromUrl' Buffer...

Samba 4.5.2 - Symlink Race Permits Opening Files Outside Share Directory

Github Enterprise - Default Session Secret And Deserialization (Metasploit)

Professional Bus Booking Script - 'hid_Busid' Parameter SQL Injection

CouponPHP CMS 3.1 - 'code' Parameter SQL Injection

EyesOfNetwork (EON) 5.0 - Remote Code Execution

EyesOfNetwork (EON) 5.0 - SQL Injection

Nuxeo 6.0 / 7.1 / 7.2 / 7.3 - Remote Code Execution (Metasploit)

inoERP 0.6.1 - Cross-Site Scripting / Cross-Site Request Forgery / SQL Injection /...

QNAP QTS < 4.2.4 - Domain Privilege Escalation

Disk Sorter Enterprise 9.5.12 - Local Buffer Overflow

27.3.2017

Bugtraq

[SECURITY] [DSA 3817-1] jbig2dec security update 2017-03-24
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 3816-1] samba security update 2017-03-23
Salvatore Bonaccorso (carnil debian org)

APPLE-SA-2017-03-22-1 iTunes for Windows 12.6 2017-03-22
Apple Product Security (product-security-noreply lists apple com)

SEC Consult SA-20170322-0 :: Multiple vulnerabilities in Solare Datensysteme Solar-Log devices 2017-03-22
SEC Consult Vulnerability Lab (research sec-consult com)

Defense in depth -- the Microsoft way (part 47): "AppLocker bypasses are not serviced via monthly security roll-ups" 2017-03-21
Stefan Kanthak (stefan kanthak nexgo de)

Malware

Backdoor:PowerShell/Tarpeg.D
Backdoor:PowerShell/Tarpeg.C

Backdoor:PowerShell/Tarpeg.B

Backdoor:PowerShell/Tarpeg.A

Phishing

LifeLock

26th March 2017

Your W-2 can be a 1-stop shop
for identity thieves

amazon

26th March 2017

[IMPORTANT]:UPDATE YOUR
ACCOUNT INFORMATION NOW

CardApprovalUSA

26th March 2017

Open a new credit account

Lexington Law Credit Repair

25th March 2017

FREE Credit Score Analysis

Indigo Platinum MasterCard

25th March 2017

A Platinum MasterCard for Less
Than Perfect Credit

Vulnerebility

Linux Kernel CVE-2010-5328 Local Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97103

GOsa CVE-2014-9760 Cross Site Scripting Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97104

Node.js CVE-2014-9772 Cross Site Scripting Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97102

AMD Ryzen Processor CVE-2017-7262 Local Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97098

Artifex MuPDF CVE-2016-10247 Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97099

Symphony CMS CVE-2017-6067 Cross Site Scripting Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97101

Trend Micro InterScan Messaging Security Suite Directory Traversal Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97097

Linux Kernel CVE-2017-7261 Local Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97096

Wordpress Filedownload Plugin CVE-2015-1000002 Security Bypass Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97100

Ghostscript CVE-2016-9601 Local Integer Overflow Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97095

SolarWinds Log and Event Manager CVE-2017-5198 Local Privilege Escalation Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97094

Subrion CMS CVE-2017-6068 Cross Site Request Forgery Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97091

OnePlus OxygenOS CVE-2017-5622 Local Code Execution Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97092

Netflix Security Monkey CVE-2017-7266 Open Redirection Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97088

SolarWinds Log and Event Manager CVE-2017-5199 Remote Code Execution Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97090

Subrion CMS 'admin/database' SQL Injection Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97093

Subrion CMS CVE-2017-6066 Cross Site Request Forgery Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97087

dotCMS CVE-2017-6003 Cross Site Scripting Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97089

Trend Micro Control Manager Multiple SQL Injection Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/97086

Logsign Remote Command Injection Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97038

EyesOfNetwork CVE-2017-6088 Multiple SQL Injection Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/97084

HexChat CVE-2016-2233 Stack-Based Buffer Overflow Vulnerability
2017-03-27
http://www.securityfocus.com/bid/95920

Google Android NFC CVE-2017-0481 Remote Privilege Escalation Vulnerability
2017-03-27
http://www.securityfocus.com/bid/96765

Apple macOS CVE-2016-4617 Multiple Security Bypass Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/96329

Python 'urrlib2/urllib/httplib/http.client' HTTP Header Injection Vulnerability
2017-03-27
http://www.securityfocus.com/bid/91226

Python CVE-2016-5636 Heap Buffer Overflow Vulnerability
2017-03-27
http://www.securityfocus.com/bid/91247

Pivotal Cloud Foundry Elastic Runtime CVE-2017-4955 Information Disclosure Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97082

Nuxeo Platform CVE-2017-5869 Arbitrary File Upload Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97083

Miele Professional PG 8528 CVE-2017-7240 Directory Traversal Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97080

IBM Kenexa LCMS Premier CVE-2017-1142 Man in the Middle Information Disclosure Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97081
Mozilla Firefox and Thunderbird Multiple Security Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/96693

Mozilla Firefox and Thunderbird CVE-2017-5401 Memory Corruption Vulnerability
2017-03-27
http://www.securityfocus.com/bid/96677

Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/96664

Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/96654

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/96651

Samba CVE-2017-2619 Symlink Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97033

IBM Kenexa LMS on Cloud CVE-2016-8935 Cross-Site Scripting Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97077

NTP CVE-2017-6452 Local Stack Based Buffer Overflow Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97078

NTP CVE-2017-6459 Local Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97076

IBM WebSphere Portal CVE-2017-1120 Cross Site Scripting Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97075

NTP CVE-2017-6455 Local Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97074

QNAP QTAP Qualcomm components Multiple Unspecified Security Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/97072

OpenJPEG CVE-2016-9573 Out of Bounds Read Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97073

TYPO3 CVE-2017-6370 Information Disclosure Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97071

Firebird CVE-2017-6369 Remote Code Execution Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97070

Chef Manage CVE-2017-7174 Remote Code Execution Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97069

GNU BinUtils CVE-2017-6969 Remote Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97065

libpcre Multiple Security Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/97067

Cloudera CDH CVE-2013-6446 Information Disclosure Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97068

SLiMS 7 Cendana CVE-2017-7242 Multiple Cross Site Scripting Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/97062

IBM TRIRIGA Application Platform CVE-2016-9737 Unspecified Cross Site Scripting Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97064

Redhat Wildfly CVE-2016-9589 Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97060

Gazelle Multiple Cross Site Scripting Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/97063

IBM TRIRIGA Applications CVE-2017-1153 Unspecified Remote Privilege Escalation Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97066

Pi Engine CVE-2017-7251 Cross Site Scripting Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97061

QNAP QTS Multiple Arbitrary Command Execution Vulnerabilities
2017-03-27
http://www.securityfocus.com/bid/97059

NTP CVE-2017-6451 Local Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97058

Multiple BD Products CVE-2017-6022 Hardcoded Credentials Information Disclosure Vulnerability
2017-03-27
http://www.securityfocus.com/bid/97057

GNU glibc '__res_vinit()' Function Information Disclosure Vulnerability
2017-03-27
http://www.securityfocus.com/bid/92257

GNU glibc CVE-2016-6323 Infinite Loop Denial of Service Vulnerability
2017-03-27
http://www.securityfocus.com/bid/92532

SANS News

Symantec vs. Google: The CA Fight Continues. What do you need to know?

Threatpost

 

Exploit

Linux/x86 - Reverse /bin/bash Shellcode (110 bytes)

Php Real Estate Property Script - SQL Injection

Php Real Estate Property Script - SQL Injection

Alibaba Clone Script - SQL Injection

Adult Tube Video Script - SQL Injection

Just Another Video Script 1.4.3 - SQL Injection

CouponPHP CMS 3.1 - 'code' Parameter SQL Injection

Professional Bus Booking Script - 'hid_Busid' Parameter SQL Injection

26.3.2017

Bugtraq

[SECURITY] [DSA 3816-1] samba security update 2017-03-23
Salvatore Bonaccorso (carnil debian org)

APPLE-SA-2017-03-22-1 iTunes for Windows 12.6 2017-03-22
Apple Product Security (product-security-noreply lists apple com)

SEC Consult SA-20170322-0 :: Multiple vulnerabilities in Solare Datensysteme Solar-Log devices 2017-03-22
SEC Consult Vulnerability Lab (research sec-consult com)

Defense in depth -- the Microsoft way (part 47): "AppLocker bypasses are not serviced via monthly security roll-ups" 2017-03-21
Stefan Kanthak (stefan kanthak nexgo de)

Malware

Trojan.Cadanif

Exp.CVE-2017-0015

Exp.CVE-2017-0018

Exp.CVE-2017-0154

Exp.CVE-2017-0050

Exp.CVE-2017-0149

Exp.CVE-2017-0067

Exp.CVE-2017-0141

Exp.CVE-2017-0010

Phishing

Indigo Platinum MasterCard

25th March 2017

A Platinum MasterCard for Less
Than Perfect Credit

 

Bank of America

24th March 2017

Bank of America Alert: Your
Online Access is Temporarily
Locked

LawsuitWinning

24th March 2017

You may qualify for
compensation for your personal
injuries!

Apple

23rd March 2017

YOUR APPLE ID HAS BEEN
DISABLED FOR SECURITY REASONS
YEEBDSPVRK

Yes BlueSky Auto Finance

23rd March 2017

Finance your new or used car
purchase. Fast App Response

Vulnerebility

Samba CVE-2017-2619 Symlink Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97033

IBM Kenexa LMS on Cloud CVE-2016-8935 Cross-Site Scripting Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97077

NTP CVE-2017-6452 Local Stack Based Buffer Overflow Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97078

NTP CVE-2017-6459 Local Denial of Service Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97076

IBM WebSphere Portal CVE-2017-1120 Cross Site Scripting Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97075

NTP CVE-2017-6455 Local Denial of Service Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97074

QNAP QTAP Qualcomm components Multiple Unspecified Security Vulnerabilities
2017-03-26
http://www.securityfocus.com/bid/97072

OpenJPEG CVE-2016-9573 Out of Bounds Read Denial of Service Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97073

TYPO3 CVE-2017-6370 Information Disclosure Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97071

Firebird CVE-2017-6369 Remote Code Execution Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97070

Chef Manage CVE-2017-7174 Remote Code Execution Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97069

GNU BinUtils CVE-2017-6969 Remote Denial of Service Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97065

libpcre Multiple Security Vulnerabilities
2017-03-26
http://www.securityfocus.com/bid/97067

Cloudera CDH CVE-2013-6446 Information Disclosure Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97068

SLiMS 7 Cendana CVE-2017-7242 Multiple Cross Site Scripting Vulnerabilities
2017-03-26
http://www.securityfocus.com/bid/97062

IBM TRIRIGA Application Platform CVE-2016-9737 Unspecified Cross Site Scripting Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97064

Redhat Wildfly CVE-2016-9589 Denial of Service Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97060

Gazelle Multiple Cross Site Scripting Vulnerabilities
2017-03-26
http://www.securityfocus.com/bid/97063

IBM TRIRIGA Applications CVE-2017-1153 Unspecified Remote Privilege Escalation Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97066

Pi Engine CVE-2017-7251 Cross Site Scripting Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97061

QNAP QTS Multiple Arbitrary Command Execution Vulnerabilities
2017-03-26
http://www.securityfocus.com/bid/97059

NTP CVE-2017-6451 Local Denial of Service Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97058

Multiple BD Products CVE-2017-6022 Hardcoded Credentials Information Disclosure Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97057

GNU glibc '__res_vinit()' Function Information Disclosure Vulnerability
2017-03-26
http://www.securityfocus.com/bid/92257

GNU glibc CVE-2016-6323 Infinite Loop Denial of Service Vulnerability
2017-03-26
http://www.securityfocus.com/bid/92532

GNU glibc 'libio/wstrops.c' Local Integer Overflow Vulnerability
2017-03-26
http://www.securityfocus.com/bid/72740

GNU glibc CVE-2016-1234 Local Buffer Overflow Vulnerability
2017-03-26
http://www.securityfocus.com/bid/84204

GNU glibc 'strxfrm()' Function Local Integer Overflow and Stack Overflow Vulnerabilities
2017-03-26
http://www.securityfocus.com/bid/72602

GNU glibc 'fnmatch_loop.c' Local Buffer Overflow Vulnerability
2017-03-26
http://www.securityfocus.com/bid/72789

QNAP QTS CVE-2017-5227 Local Information Disclosure Vulnerability
2017-03-26
http://www.securityfocus.com/bid/97056IBM Kenexa LMS on Cloud CVE-2016-8935 Cross-Site Scripting Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97077

NTP CVE-2017-6452 Local Stack Based Buffer Overflow Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97078

NTP CVE-2017-6459 Local Denial of Service Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97076

IBM WebSphere Portal CVE-2017-1120 Cross Site Scripting Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97075

NTP CVE-2017-6455 Local Denial of Service Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97074

QNAP QTAP Qualcomm components Multiple Unspecified Security Vulnerabilities
2017-03-25
http://www.securityfocus.com/bid/97072

OpenJPEG CVE-2016-9573 Out of Bounds Read Denial of Service Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97073

TYPO3 CVE-2017-6370 Information Disclosure Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97071

Firebird CVE-2017-6369 Remote Code Execution Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97070

Chef Manage CVE-2017-7174 Remote Code Execution Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97069

GNU BinUtils CVE-2017-6969 Remote Denial of Service Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97065

libpcre Multiple Security Vulnerabilities
2017-03-25
http://www.securityfocus.com/bid/97067

Cloudera CDH CVE-2013-6446 Information Disclosure Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97068

SLiMS 7 Cendana CVE-2017-7242 Multiple Cross Site Scripting Vulnerabilities
2017-03-25
http://www.securityfocus.com/bid/97062

IBM TRIRIGA Application Platform CVE-2016-9737 Unspecified Cross Site Scripting Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97064

Redhat Wildfly CVE-2016-9589 Denial of Service Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97060

Gazelle Multiple Cross Site Scripting Vulnerabilities
2017-03-25
http://www.securityfocus.com/bid/97063

IBM TRIRIGA Applications CVE-2017-1153 Unspecified Remote Privilege Escalation Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97066

Pi Engine CVE-2017-7251 Cross Site Scripting Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97061

Samba CVE-2017-2619 Symlink Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97033

QNAP QTS Multiple Arbitrary Command Execution Vulnerabilities
2017-03-25
http://www.securityfocus.com/bid/97059

NTP CVE-2017-6451 Local Denial of Service Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97058

Multiple BD Products CVE-2017-6022 Hardcoded Credentials Information Disclosure Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97057

GNU glibc '__res_vinit()' Function Information Disclosure Vulnerability
2017-03-25
http://www.securityfocus.com/bid/92257

GNU glibc CVE-2016-6323 Infinite Loop Denial of Service Vulnerability
2017-03-25
http://www.securityfocus.com/bid/92532

GNU glibc 'libio/wstrops.c' Local Integer Overflow Vulnerability
2017-03-25
http://www.securityfocus.com/bid/72740

GNU glibc CVE-2016-1234 Local Buffer Overflow Vulnerability
2017-03-25
http://www.securityfocus.com/bid/84204

GNU glibc 'strxfrm()' Function Local Integer Overflow and Stack Overflow Vulnerabilities
2017-03-25
http://www.securityfocus.com/bid/72602

GNU glibc 'fnmatch_loop.c' Local Buffer Overflow Vulnerability
2017-03-25
http://www.securityfocus.com/bid/72789

QNAP QTS CVE-2017-5227 Local Information Disclosure Vulnerability
2017-03-25
http://www.securityfocus.com/bid/97056

SANS News

Nicely Obfuscated JavaScript Sample

Distraction as a Service

Threatpost

Adware Apps Booted from Google Play

Instagram Adds Two-Factor Authentication

Privacy Advocates Vow to Fight Rollback of Broadband Privacy Rules

Experts Doubt Hackers’ Claim Of Millions Of Breached Apple Credentials

Exploit

Forticlient 5.2.3 Windows 10 x64 (Pre Anniversary) - Privilege Escalation

Forticlient 5.2.3 Windows 10 x64 (Post Anniversary) - Privilege Escalation

Miele Professional PG 8528 - Directory Traversal

NETGEAR WNR2000v5 - (Un)authenticated hidden_lang_avi Stack Overflow (Metasploit)

Logsign 4.4.2 / 4.4.137 - Remote Command Injection (Metasploit)

Gr8 Gallery Script - SQL Injection

wifirxpower - Local Buffer Overflow

Gr8 Tutorial Script - SQL Injection

24.3.2017

Bugtraq

[SECURITY] [DSA 3816-1] samba security update 2017-03-23
Salvatore Bonaccorso (carnil debian org)

APPLE-SA-2017-03-22-1 iTunes for Windows 12.6 2017-03-22
Apple Product Security (product-security-noreply lists apple com)

SEC Consult SA-20170322-0 :: Multiple vulnerabilities in Solare Datensysteme Solar-Log devices 2017-03-22
SEC Consult Vulnerability Lab (research sec-consult com)

Defense in depth -- the Microsoft way (part 47): "AppLocker bypasses are not serviced via monthly security roll-ups" 2017-03-21
Stefan Kanthak (stefan kanthak nexgo de)

[ERPSCAN-16-041] SAP NETWEAVER DIRECTORY CREATION OUTSIDE OF THE JVM 2017-03-21
ERPScan inc (erpscan online gmail com)

ESA-2017-010: EMC RecoverPoint SSL Stripping Vulnerability 2017-03-20
EMC Product Security Response Center (Security_Alert emc com)

[SECURITY] [DSA 3796-2] sitesummary regression update 2017-03-20
Sebastien Delafond (seb debian org)

[security bulletin] HPSBUX03596 rev.2 - HPE HP-UX running CIFS Server (Samba), Remote Access Restriction Bypass, Unauthorized Access 2017-03-20
security-alert hpe com

Malware

SupportScam:Win32/Monitnev.A

Infostealer.Bitral

Phishing

Apple

23rd March 2017

YOUR APPLE ID HAS BEEN
DISABLED FOR SECURITY REASONS
YEEBDSPVRK

Yes BlueSky Auto Finance

23rd March 2017

Finance your new or used car
purchase. Fast App Response

IT Cosmetics

23rd March 2017

Special Offer! Get Bye Bye
Foundation & 4 other beauty
favorites for just $39.95

VeteransVALoans

23rd March 2017

Did you serve? New VA Loan
Program

Vulnerebility

Cloudera CDH CVE-2013-6446 Information Disclosure Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97068

SLiMS 7 Cendana CVE-2017-7242 Multiple Cross Site Scripting Vulnerabilities
2017-03-24
http://www.securityfocus.com/bid/97062

IBM TRIRIGA Application Platform CVE-2016-9737 Unspecified Cross Site Scripting Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97064

Redhat Wildfly CVE-2016-9589 Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97060

Gazelle Multiple Cross Site Scripting Vulnerabilities
2017-03-24
http://www.securityfocus.com/bid/97063

IBM TRIRIGA Applications CVE-2017-1153 Unspecified Remote Privilege Escalation Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97066

Pi Engine CVE-2017-7251 Cross Site Scripting Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97061

Samba CVE-2017-2619 Symlink Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97033

QNAP QTS Multiple Arbitrary Command Execution Vulnerabilities
2017-03-24
http://www.securityfocus.com/bid/97059

NTP CVE-2017-6451 Local Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97058

Multiple BD Products CVE-2017-6022 Hardcoded Credentials Information Disclosure Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97057

GNU glibc '__res_vinit()' Function Information Disclosure Vulnerability
2017-03-24
http://www.securityfocus.com/bid/92257

GNU glibc CVE-2016-6323 Infinite Loop Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/92532

GNU glibc 'libio/wstrops.c' Local Integer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/72740

GNU glibc CVE-2016-1234 Local Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/84204

GNU glibc 'strxfrm()' Function Local Integer Overflow and Stack Overflow Vulnerabilities
2017-03-24
http://www.securityfocus.com/bid/72602

GNU glibc 'fnmatch_loop.c' Local Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/72789

QNAP QTS CVE-2017-5227 Local Information Disclosure Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97056

LAquis SCADA Software CVE-2017-6020 Directory Traversal Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97055

APNGDis Multiple Buffer Overflow Vulnerabilities
2017-03-24
http://www.securityfocus.com/bid/97053

Broadcom BCM4339 SoC CVE-2017-6957 Stack-Based Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97054

NTP CVE-2017-6458 Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97051

NTP CVE-2017-6460 Stack Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97052

NTP CVE-2017-6462 Local Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97045

NTP CVE-2017-6464 Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97050

NTP CVE-2016-9042 Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97046

NTP CVE-2017-6463 Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97049

Suricata CVE-2017-7177 Security Bypass Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97047

OnePlus OxygenOS CVE-2017-5623 Local Security Bypass Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97048

Pidgin CVE 2017-2640 Out of Bounds Write Security Vulnerability
2017-03-24
http://www.securityfocus.com/bid/96775APNGDis Multiple Buffer Overflow Vulnerabilities
2017-03-24
http://www.securityfocus.com/bid/97053

Broadcom BCM4339 SoC CVE-2017-6957 Stack-Based Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97054

NTP CVE-2017-6458 Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97051

NTP CVE-2017-6460 Stack Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97052

NTP CVE-2017-6462 Local Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97045

NTP CVE-2017-6464 Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97050

NTP CVE-2016-9042 Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97046

NTP CVE-2017-6463 Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97049

Suricata CVE-2017-7177 Security Bypass Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97047

OnePlus OxygenOS CVE-2017-5623 Local Security Bypass Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97048

Pidgin CVE 2017-2640 Out of Bounds Write Security Vulnerability
2017-03-24
http://www.securityfocus.com/bid/96775

Multiple Huawei Honor CVE-2017-2728 Local Security Bypass Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97042

GnuTLS GNUTLS-SA-2017-3 Multiple Security Vulnerabilities
2017-03-24
http://www.securityfocus.com/bid/97040

Deluge CVE-2017-7178 Cross Site Request Forgery Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97041

LastPass for Firefox Security Bypass Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97043

LastPass 'websiteConnector.js' Remote Code Execution Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97039

SAP GUI CVE-2017-6950 Remote Code Execution Vulnerability
2017-03-24
http://www.securityfocus.com/bid/96872

NetIQ Access Manager CVE-2016-5758 Cross Site Request Forgery Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97035

pngdefry 'pngdefry.c' Heap Based Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97037

W3C High Resolution Time API CVE-2017-5928 Security Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97036

Expat CVE-2016-5300 Incomplete Fix Remote Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/91159

Expat CVE-2016-4472 Incomplete Fix Remote Code Execution Vulnerability
2017-03-24
http://www.securityfocus.com/bid/91528

Admidio 'dates_function.php' SQL Injection Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97034

Google Chrome Prior to 44.0.2403.89 Multiple Security Vulnerabilities
2017-03-24
http://www.securityfocus.com/bid/75973

Expat XML Parsing Multiple Remote Denial of Service Vulnerabilities
2017-03-24
http://www.securityfocus.com/bid/52379

Libexpat Expat CVE-2012-6702 Predictable Random Number Generator Weakness
2017-03-24
http://www.securityfocus.com/bid/91483

Expat UTF-8 Character XML Parsing Remote Denial of Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/36097

Internet Explorer CVE-2009-3270 Denial-Of-Service Vulnerability
2017-03-24
http://www.securityfocus.com/bid/79354

Expat CVE-2016-0718 Buffer Overflow Vulnerability
2017-03-24
http://www.securityfocus.com/bid/90729

Drupal Linkit Module Access Bypass Vulnerability
2017-03-24
http://www.securityfocus.com/bid/97029

SANS News

Nicely Obfuscated JavaScript Sample

Threatpost

Half of Android Devices Unpatched Last Year

Malware That Targets Both Microsoft, Apple Operating Systems Found

Cisco Patches Critical IOx Vulnerability

Exploit

Miele Professional PG 8528 - Directory Traversal

Gr8 Tutorial Script - SQL Injection

Gr8 Gallery Script - SQL Injection

Sun Java Web Start Plugin - Command Line Argument Injection (Metasploit)

Adobe Flash Player - Nellymoser Audio Decoding Buffer Overflow (Metasploit)

VMware Host Guest Client Redirector - DLL Side Loading (Metasploit)

23.3.2017

Bugtraq

[SECURITY] [DSA 3816-1] samba security update 2017-03-23
Salvatore Bonaccorso (carnil debian org)

APPLE-SA-2017-03-22-1 iTunes for Windows 12.6 2017-03-22
Apple Product Security (product-security-noreply lists apple com)

SEC Consult SA-20170322-0 :: Multiple vulnerabilities in Solare Datensysteme Solar-Log devices 2017-03-22
SEC Consult Vulnerability Lab (research sec-consult com)

Defense in depth -- the Microsoft way (part 47): "AppLocker bypasses are not serviced via monthly security roll-ups" 2017-03-21
Stefan Kanthak (stefan kanthak nexgo de)

[ERPSCAN-16-041] SAP NETWEAVER DIRECTORY CREATION OUTSIDE OF THE JVM 2017-03-21
ERPScan inc (erpscan online gmail com)

ESA-2017-010: EMC RecoverPoint SSL Stripping Vulnerability 2017-03-20
EMC Product Security Response Center (Security_Alert emc com)

[SECURITY] [DSA 3796-2] sitesummary regression update 2017-03-20
Sebastien Delafond (seb debian org)

[security bulletin] HPSBUX03596 rev.2 - HPE HP-UX running CIFS Server (Samba), Remote Access Restriction Bypass, Unauthorized Access 2017-03-20
security-alert hpe com

Malware

Ransom.Vortex

JS.Vajawom

Phishing

IT Cosmetics

23rd March 2017

Special Offer! Get Bye Bye
Foundation & 4 other beauty
favorites for just $39.95

VeteransVALoans

23rd March 2017

Did you serve? New VA Loan
Program

Bank of America

22nd March 2017

Bank of America Alert: Your
Online Access is Temporarily
Locked

Vulnerebility

pngdefry 'pngdefry.c' Heap Based Buffer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97037

W3C High Resolution Time API CVE-2017-5928 Security Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97036

Expat CVE-2016-5300 Incomplete Fix Remote Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/91159

Expat CVE-2016-4472 Incomplete Fix Remote Code Execution Vulnerability
2017-03-23
http://www.securityfocus.com/bid/91528

Admidio 'dates_function.php' SQL Injection Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97034

Google Chrome Prior to 44.0.2403.89 Multiple Security Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/75973

Expat XML Parsing Multiple Remote Denial of Service Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/52379

Libexpat Expat CVE-2012-6702 Predictable Random Number Generator Weakness
2017-03-23
http://www.securityfocus.com/bid/91483

Expat UTF-8 Character XML Parsing Remote Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/36097

Internet Explorer CVE-2009-3270 Denial-Of-Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/79354

Expat CVE-2016-0718 Buffer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/90729

Drupal Linkit Module Access Bypass Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97029

SQLite CVE-2016-6153 Insecure Temporary File Creation Vulnerability
2017-03-23
http://www.securityfocus.com/bid/91546

SQLite CVE-2015-6607 Multiple Local Privilege Escalation Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/76970

Apple Mac OS X and iOS Multiple Security Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/75491

SQLite CVE-2013-7443 Local Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/76089

SQLite Versions Prior to 3.8.9 Multiple Security Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/74228

Samba CVE-2017-2619 Symlink Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97033

podofo CVE-2017-5852 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97032

PCRE CVE-2017-7186 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97030

sane-backends CVE-2017-6318 Information Disclosure Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97028

USBPcap CVE-2017-6178 Local Privilege Escalation Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97026

Drupal Office Hours Module Cross Site Scripting Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97027

Multiple Trend Micro Products CVE-2017-5565 DLL Loading Local Code Injection Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97031

WordPress Prior to 4.7.3 Multiple Cross Site Scripting Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/96601

WordPress Prior to 4.7.3 Security Bypass Vulnerability
2017-03-23
http://www.securityfocus.com/bid/96598

WordPress Prior to 4.7.3 URL Redirection Vulnerability
2017-03-23
http://www.securityfocus.com/bid/96600

Red Hat Dashbuilder CVE-2017-2658 Clickjacking Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97025

Multiple Bitdefender Products CVE-2017-6186 DLL Loading Local Code Injection Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97024

GNU Bash CVE-2016-0634 Local Code Execution Vulnerability
2017-03-23
http://www.securityfocus.com/bid/92999GNU Bash CVE-2016-0634 Local Code Execution Vulnerability
2017-03-23
http://www.securityfocus.com/bid/92999

GNU Bash CVE-2016-9401 Local Security Bypass Vulnerability
2017-03-23
http://www.securityfocus.com/bid/94398

GNU Bash CVE-2016-7543 Local Command Execution Vulnerability
2017-03-23
http://www.securityfocus.com/bid/93183

Samba CVE-2016-2125 User Impersonation Vulnerability
2017-03-23
http://www.securityfocus.com/bid/94988

Samba CVE-2016-2126 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/94994

Multiple AVG Products CVE-2017-5566 DLL Loading Local Code Injection Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97022

Linux kernel 'ip_sockglue.c' Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/96233

Ni LabVIEW CVE-2017-2775 Memory Corruption Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97020

Multiple Avira Products CVE-2017-6417 DLL Loading Local Code Injection Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97021

NfSen CVE-2017-6972 Unspecified Security Bypass Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97016

Linux Kernel CVE-2017-7184 Local Privilege Escalation Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97018

Multiple Avast Products CVE-2017-5567 DLL Loading Local Code Injection Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97017

icoutils 'simple_vec()' Function Buffer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/96267

icoutils CVE-2017-5332 Local Code Execution Vulnerability
2017-03-23
http://www.securityfocus.com/bid/95380

icoutils CVE-2017-5333 Local Integer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/95678

icoutils CVE-2017-5208 Local Integer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/95315

icoutils 'extract_icons()' Function Buffer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/96288

icoutils 'decode_ne_resource_id()' Function Buffer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/96292

OpenJPEG CVE-2016-9675 Incomplete Fix Multiple Remote Heap Based Buffer Overflow Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/94589

OpenJPEG CVE-2016-7163 Integer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/92897

Google Chrome Prior to 53.0.2785.89 Multiple Security Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/92717

Google Chrome Prior to 52.0.2743.116 Multiple Security Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/92276

Candlepin subscription-manager CVE-2017-2663 Multiple Local Privilege Escalation Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/97015

Cisco Application-Hosting Framework CVE-2017-3852 Arbitrary File Creation Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97014

Cisco Application-Hosting Framework CVE-2017-3851 Directory Traversal Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97013

Multiple Cisco Products CVE-2017-3853 Stack Buffer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97011

Cisco IOS and IOS XE Software CVE-2017-3864 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97012

libavcodec CVE-2017-7206 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97006

Cisco IOS and IOS XE Software CVE-2017-3857 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97010

Cisco IOS XE Software CVE-2017-3859 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97008
Linux Kernel CVE-2017-7184 Local Privilege Escalation Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97018

Multiple Avast Products CVE-2017-5567 DLL Loading Local Code Injection Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97017

icoutils 'simple_vec()' Function Buffer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/96267

icoutils CVE-2017-5332 Local Code Execution Vulnerability
2017-03-23
http://www.securityfocus.com/bid/95380

icoutils CVE-2017-5333 Local Integer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/95678

icoutils CVE-2017-5208 Local Integer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/95315

icoutils 'extract_icons()' Function Buffer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/96288

icoutils 'decode_ne_resource_id()' Function Buffer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/96292

OpenJPEG CVE-2016-9675 Incomplete Fix Multiple Remote Heap Based Buffer Overflow Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/94589

OpenJPEG CVE-2016-7163 Integer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/92897

Google Chrome Prior to 53.0.2785.89 Multiple Security Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/92717

Google Chrome Prior to 52.0.2743.116 Multiple Security Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/92276

Candlepin subscription-manager CVE-2017-2663 Multiple Local Privilege Escalation Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/97015

Cisco Application-Hosting Framework CVE-2017-3852 Arbitrary File Creation Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97014

Cisco Application-Hosting Framework CVE-2017-3851 Directory Traversal Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97013

Multiple Cisco Products CVE-2017-3853 Stack Buffer Overflow Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97011

Cisco IOS and IOS XE Software CVE-2017-3864 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97012

libavcodec CVE-2017-7206 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97006

Cisco IOS and IOS XE Software CVE-2017-3857 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97010

Cisco IOS XE Software CVE-2017-3859 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97008

Cisco IOS XE Software CVE-2017-3858 Command Injection Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97009

Cisco IOS XE Software CVE-2017-3856 Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97007

libavcodec CVE-2017-7208 Out of Bounds Read Denial of Service Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97005

Rockwell Automation Connected Components Workbench DLL Loading Local Code Execution Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97000

imdbphp CVE-2017-7204 Cross Site Scripting Vulnerability
2017-03-23
http://www.securityfocus.com/bid/97002

Microsoft Internet Explorer CVE-2016-0162 Information Disclosure Vulnerability
2017-03-23
http://www.securityfocus.com/bid/85939

Microsoft Internet Explorer CVE-2016-0164 Remote Memory Corruption Vulnerability
2017-03-23
http://www.securityfocus.com/bid/85922

Apple Safari APPLE-SA-2016-03-21-6 Multiple Security Vulnerabilities
2017-03-23
http://www.securityfocus.com/bid/85055

Symantec Endpoint Protection Manager and Client CVE-2015-8154 Security Bypass Vulnerability
2017-03-23
http://www.securityfocus.com/bid/84344

Symantec Endpoint Protection Manager CVE-2015-8152 Cross Site Request Forgery Vulnerability
2017-03-23
http://www.securityfocus.com/bid/84343

SANS News

SSMA Usage

Threatpost

Blank Slate Spam Campaign Spreads Cerber Ransomware

Google, Jigsaw Partner on Free Tools to Secure Elections

Exploit

Ceragon FibeAir IP-10 - SSH Private Key Exposure (Metasploit)

ExaGrid - Known SSH Key and Default Password (Metasploit)

GIT 1.8.5.6 / 1.9.5 / 2.0.5 / 2.1.4/ 2.2.1 & Mercurial < 3.2.3 - Multiple...

Ruby on Rails 4.0.x / 4.1.x / 4.2.x (Web Console v2) - Whitelist Bypass Code...

Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code...

Samba 2.2.2 < 2.2.6 - 'nttrans' Buffer Overflow (Metasploit)

SSH - User Code Execution (Metasploit)

Joomla! Component Modern Booking 1.0 - 'coupon' Parameter SQL Injection

Flippa Clone - SQL Injection

Centreon < 2.5.1 / Centreon Enterprise Server < 2.2 - SQL Injection / Command...

D-Link/TRENDnet - NCC Service Command Injection (Metasploit)

Seagate Business NAS - Unauthenticated Remote Command Execution (Metasploit)

MantisBT 1.2.0a3 < 1.2.17 - XmlImportExport Plugin PHP Code Injection (Metasploit)

OP5 5.3.5 / 5.4.0 / 5.4.2 / 5.5.0 / 5.5.1 - 'license.php' Remote Command Execution...

Lenovo System Update - Privilege Escalation (Metasploit)

MOXA MediaDBPlayback - ActiveX Control Buffer Overflow (Metasploit)

Malwarebytes Anti-Malware < 2.0.3 / Anti-Exploit < 1.03.1.1220 - Update Remote Code...

CADA 3S CoDeSys Gateway Server - Directory Traversal (Metasploit)

Mozilla Firefox 5.0 < 15.0.1 - __exposedProps__ XCS Code Execution (Metasploit)

Firebird - Relational Database CNCT Group Number Buffer Overflow (Metasploit)

Microsoft Silverlight - ScriptObject Unsafe Memory Access (MS13-022/MS13-087)...

Disk Sorter Enterprise 9.5.12 - 'GET' Buffer Overflow (SEH)

SysGauge 1.5.18 - SMTP Validation Buffer Overflow (Metasploit)

GLink Word Link Script 1.2.3 - SQL Injection

Solare Datensysteme Solar-Log Devices 2.8.4-56 / 3.5.2-85 - Multiple Vulnerabilities

SpyCamLizard 1.230 - Denial of Service

APNGDis 2.8 - 'chunk size descriptor' Heap Buffer Overflow

APNGDis 2.8 - 'image width / height chunk' Heap Buffer Overflow

APNGDis 2.8 - 'filename' Stack Buffer Overflow

22.3.2017

Bugtraq

SEC Consult SA-20170322-0 :: Multiple vulnerabilities in Solare Datensysteme Solar-Log devices 2017-03-22
SEC Consult Vulnerability Lab (research sec-consult com)

Defense in depth -- the Microsoft way (part 47): "AppLocker bypasses are not serviced via monthly security roll-ups" 2017-03-21
Stefan Kanthak (stefan kanthak nexgo de)

[ERPSCAN-16-041] SAP NETWEAVER DIRECTORY CREATION OUTSIDE OF THE JVM 2017-03-21
ERPScan inc (erpscan online gmail com)

ESA-2017-010: EMC RecoverPoint SSL Stripping Vulnerability 2017-03-20
EMC Product Security Response Center (Security_Alert emc com)

[SECURITY] [DSA 3796-2] sitesummary regression update 2017-03-20
Sebastien Delafond (seb debian org)

[security bulletin] HPSBUX03596 rev.2 - HPE HP-UX running CIFS Server (Samba), Remote Access Restriction Bypass, Unauthorized Access 2017-03-20
security-alert hpe com

CVE-2017-7183 ExtraPuTTY v029_RC2 TFTP Denial Of Service 2017-03-20
apparitionsec gmail com (hyp3rlinx)

[SECURITY] [DSA 3813-1] r-base security update 2017-03-19
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 3812-1] ioquake3 security update 2017-03-18
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 3811-1] wireshark security update 2017-03-18
Moritz Muehlenhoff (jmm debian org)

Malware

Exploit:HTML/Meadgive.AC

Trojan:Win32/Fuery.B!cl 

Trojan:PDF/Phish

Phishing

Getit-Free

21st March 2017

Congrats! Youve Been Selected
for FREE -- Dewalt -- Samples.

Bank of America

21st March 2017

Bank of America Alert: Your
Online Access is Temporarily
Locked

Amazon.com

21st March 2017

ACCOUNT AMAZON : Failed to
verify your account Amazon
-4:00:00 - 3/21/2017-

Royal Bank of Scotland

21st March 2017

PAYMENT PENDING

Vulnerebility

D-Link DIR-600M CVE-2017-5874 Cross Site Request Forgery Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96999

OpenStack Nova CVE-2017-7214 Information Disclosure Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96998

Malware Information Sharing Platform CVE-2017-7215 Multiple Cross Site Scripting Vulnerabilities
2017-03-22
http://www.securityfocus.com/bid/96997

Ghostscript CVE-2017-7207 Denial of Service Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96995

Rockwell Automation FactoryTalk Activation CVE-2017-6015 Local Privilege Escalation Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96996

Printing Communications Association Rawether CVE-2017-3196 Local Privilege Escalation Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96993

Binutils CVE-2017-7209 Remote Denial of Service Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96994

Binutils CVE-2017-7210 Multiple Remote Denial of Service Vulnerabilities
2017-03-22
http://www.securityfocus.com/bid/96992

AppSamvid DLL Loading Local Code Execution Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96990

Linux Kernel CVE-2017-7187 Local Denial of Service Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96989

OpenStack Glance CVE-2017-7200 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96988

Red Hat JBoss BPMS CVE-2016-6343 Cross Site Scripting Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96987

Mozilla Firefox CVE-2017-5428 Integer Overflow Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96959

IBM PowerKVM CVE-2016-7076 Local Command Execution Vulnerability
2017-03-22
http://www.securityfocus.com/bid/95778

IBM PowerKVM CVE-2016-7032 Multiple Local Command Execution Vulnerabilities
2017-03-22
http://www.securityfocus.com/bid/95776

GnuPG and Libgcrypt CVE-2016-6313 Local Predictable Random Number Generator Weakness
2017-03-22
http://www.securityfocus.com/bid/92527

policycoreutils CVE-2016-7545 Remote Privilege Escalation Vulnerability
2017-03-22
http://www.securityfocus.com/bid/93156

Microsoft Internet Explorer and Edge CVE-2016-7282 Information Disclosure Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94724

Microsoft Office CVE-2016-7298 Memory Corruption Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94720

Microsoft Auto Updater for Mac CVE-2016-7300 Local Privilege Escalation Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94784

Microsoft Windows Graphics Component CVE-2016-7272 Remote Code Execution Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94739

Microsoft Windows Graphics Component CVE-2016-7273 Remote Code Execution Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94752

Microsoft Windows Kernel 'Win32k.sys' CVE-2016-7260 Local Privilege Escalation Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94785

Microsoft Internet Explorer and Edge CVE-2016-7287 Remote Memory Corruption Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94722

Jenkins SSH Slaves Plugin CVE-2017-2648 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96985

Jenkins Active Directory Plugin CVE-2017-2649 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96986

Jenkins Mailer Plugin CVE-2017-2651 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96984

Jenkins CVE-2017-2650 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96981

Apache POI CVE-2017-5644 Denial Of Service Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96983

Moodle CVE-2017-2645 HTML Injection Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96982Malware Information Sharing Platform CVE-2017-7215 Multiple Cross Site Scripting Vulnerabilities
2017-03-22
http://www.securityfocus.com/bid/96997

Ghostscript CVE-2017-7207 Denial of Service Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96995

Rockwell Automation FactoryTalk Activation CVE-2017-6015 Local Privilege Escalation Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96996

Printing Communications Association Rawether CVE-2017-3196 Local Privilege Escalation Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96993

Binutils CVE-2017-7209 Remote Denial of Service Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96994

Binutils CVE-2017-7210 Multiple Remote Denial of Service Vulnerabilities
2017-03-22
http://www.securityfocus.com/bid/96992

AppSamvid DLL Loading Local Code Execution Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96990

Linux Kernel CVE-2017-7187 Local Denial of Service Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96989

OpenStack Glance CVE-2017-7200 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96988

Red Hat JBoss BPMS CVE-2016-6343 Cross Site Scripting Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96987

Mozilla Firefox CVE-2017-5428 Integer Overflow Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96959

IBM PowerKVM CVE-2016-7076 Local Command Execution Vulnerability
2017-03-22
http://www.securityfocus.com/bid/95778

IBM PowerKVM CVE-2016-7032 Multiple Local Command Execution Vulnerabilities
2017-03-22
http://www.securityfocus.com/bid/95776

GnuPG and Libgcrypt CVE-2016-6313 Local Predictable Random Number Generator Weakness
2017-03-22
http://www.securityfocus.com/bid/92527

policycoreutils CVE-2016-7545 Remote Privilege Escalation Vulnerability
2017-03-22
http://www.securityfocus.com/bid/93156

Microsoft Internet Explorer and Edge CVE-2016-7282 Information Disclosure Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94724

Microsoft Office CVE-2016-7298 Memory Corruption Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94720

Microsoft Auto Updater for Mac CVE-2016-7300 Local Privilege Escalation Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94784

Microsoft Windows Graphics Component CVE-2016-7272 Remote Code Execution Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94739

Microsoft Windows Graphics Component CVE-2016-7273 Remote Code Execution Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94752

Microsoft Windows Kernel 'Win32k.sys' CVE-2016-7260 Local Privilege Escalation Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94785

Microsoft Internet Explorer and Edge CVE-2016-7287 Remote Memory Corruption Vulnerability
2017-03-22
http://www.securityfocus.com/bid/94722

Jenkins SSH Slaves Plugin CVE-2017-2648 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96985

Jenkins Active Directory Plugin CVE-2017-2649 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96986

Jenkins Mailer Plugin CVE-2017-2651 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96984

Jenkins CVE-2017-2650 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96981

Apache POI CVE-2017-5644 Denial Of Service Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96983

Moodle CVE-2017-2645 HTML Injection Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96982

Jenkins Distributed Fork Plugin CVE-2017-2652 Security Bypass Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96980

Moodle CVE-2017-2644 HTML Injection Vulnerability
2017-03-22
http://www.securityfocus.com/bid/96979

SANS News

"Blank Slate" campaign still pushing Cerber ransomware

Threatpost

Locky, Cerber Ransomware Skilled at Hiding

Code Execution Vulnerability Found in Libpurple IM Library

Critical Moodle Vulnerability Could Lead to Server Compromise

SAP Vulnerability Puts Business Data at Risk for Thousands of Companies

Exploit

Joomla! Component Extra Search 2.2.8 - 'establename' Parameter SQL Injection

Disk Sorter Enterprise 9.5.12 - 'GET' Buffer Overflow (SEH)

GLink Word Link Script 1.2.3 - SQL Injection

22.3.2017

Bugtraq

Defense in depth -- the Microsoft way (part 47): "AppLocker bypasses are not serviced via monthly security roll-ups" 2017-03-21
Stefan Kanthak (stefan kanthak nexgo de)

[ERPSCAN-16-041] SAP NETWEAVER DIRECTORY CREATION OUTSIDE OF THE JVM 2017-03-21
ERPScan inc (erpscan online gmail com)

ESA-2017-010: EMC RecoverPoint SSL Stripping Vulnerability 2017-03-20
EMC Product Security Response Center (Security_Alert emc com)

[SECURITY] [DSA 3796-2] sitesummary regression update 2017-03-20
Sebastien Delafond (seb debian org)

[security bulletin] HPSBUX03596 rev.2 - HPE HP-UX running CIFS Server (Samba), Remote Access Restriction Bypass, Unauthorized Access 2017-03-20
security-alert hpe com

CVE-2017-7183 ExtraPuTTY v029_RC2 TFTP Denial Of Service 2017-03-20
apparitionsec gmail com (hyp3rlinx)

[SECURITY] [DSA 3813-1] r-base security update 2017-03-19
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 3812-1] ioquake3 security update 2017-03-18
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 3811-1] wireshark security update 2017-03-18
Moritz Muehlenhoff (jmm debian org)

Malware

TrojanSpy:MSIL/Omaneat
TrojanDownloader:Win32/Zdowbot.C

TrojanSpy:Win32/Bancos.XN

Trojan.Vanatmox

Trojan.Nexlogger

Phishing

Lloyds Bank

20th March 2017

Telephone Banking Verification

service@uk.paypal.com

19th March 2017

Your recent PayPal transfer is
under review

Vulnerebility

Microsoft Internet Explorer and Edge CVE-2016-7282 Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94724

Microsoft Office CVE-2016-7298 Memory Corruption Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94720

Microsoft Auto Updater for Mac CVE-2016-7300 Local Privilege Escalation Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94784

Microsoft Windows Graphics Component CVE-2016-7272 Remote Code Execution Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94739

Microsoft Windows Graphics Component CVE-2016-7273 Remote Code Execution Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94752

Microsoft Windows Kernel 'Win32k.sys' CVE-2016-7260 Local Privilege Escalation Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94785

Microsoft Internet Explorer and Edge CVE-2016-7287 Remote Memory Corruption Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94722

Jenkins SSH Slaves Plugin CVE-2017-2648 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96985

Jenkins Active Directory Plugin CVE-2017-2649 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96986

Jenkins Mailer Plugin CVE-2017-2651 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96984

Jenkins CVE-2017-2650 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96981

Apache POI CVE-2017-5644 Denial Of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96983

Moodle CVE-2017-2645 HTML Injection Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96982

Jenkins Distributed Fork Plugin CVE-2017-2652 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96980

Moodle CVE-2017-2644 HTML Injection Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96979

Quagga CVE-2017-5495 Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/95745

Quagga CVE-2016-1245 Buffer Overflow Vulnerability
2017-03-21
http://www.securityfocus.com/bid/93775

Quagga CVE-2016-2342 Stack Buffer Overflow Vulnerability
2017-03-21
http://www.securityfocus.com/bid/84318

Quagga CVE-2013-2236 Stack Buffer Overflow Vulnerability
2017-03-21
http://www.securityfocus.com/bid/60955

Moodle CVE-2017-2643 Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96978

Linux Kernel CVE-2016-10088 Incomplete Fix Multiple Local Memory Corruption Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/95169

Linux Kernel CVE-2016-9576 Use After Free Memory Corruption Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94821

Linux Kernel CVE-2016-2069 TLB Flush Local Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/81809

Linux Kernel CVE-2016-6480 Local Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/92214

Linux Kernel Local Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/92659

IETF IPv6 Protocol CVE-2016-10142 Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/95797

Linux Kernel CVE-2016-7042 Local Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/93544

Moodle CVE-2017-2641 SQL Injection Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96977

IBM Call Center for Commerce CVE-2016-6056 Cross Site Scripting Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96975

IBM Security Key Lifecycle Manager CVE-2016-6102 Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96976ExtraPuTTY CVE-2017-7183 Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96973

Cisco IOS and IOS XE Software CVE-2017-3849 Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96972

Cisco IOS and IOS XE Software CVE-2017-3850 Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96971

Skype CVE-2017-6517 DLL Loading Local Code Execution Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96969

USB Pratirodh CVE-2017-6911 Insecure Password Storage Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96970

Ubiquiti Networking Products Multiple Command Injection Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96967

IBM Algorithmics One-Algo Risk Application CVE-2017-1155 Unauthorized Access Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96968

Red Hat CloudForms Management App CVE-2017-2653 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96964

Microsoft Windows Local Privilege Escalation Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96966

Wordpress Anyone Plugin 'by-email.php' Session Management Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96965

IBM Cognos Business Intelligence CVE-2016-8960 Privilege Escalation Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96963

IBM Cognos Business Intelligence Server CVE-2016-9985 Local Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96962

Trend Micro ServerProtect for Linux Unspecified Cross Site Scripting Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96961

Cisco IOS and IOS XE Software CVE-2017-3881 Remote Code Execution Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96960

Mozilla Firefox CVE-2017-5428 Integer Overflow Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96959

Google Android Qualcomm Fingerprint Sensor Driver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96950

Google Android Audioserver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96958

Nexpose Information Disclosure and DLL Loading Remote Code Execution Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96956

Metasploit Multiple Directory Traversal Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96954

Google Android NFC CVE-2017-0481 Privilege Escalation Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96953

Rapid7 AppSpider CVE-2017-5233 DLL Loading Remote Code Execution Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96957

EPESI Multiple Cross Site Scripting Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96955

Google Android Kernel ION Subsystem Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96952

Google Android Networking Driver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96948

Google Android Qualcomm IPA Driver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96947

Google Android Qualcomm Camera Driver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96951

Google Android HTC Sensor Hub Driver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96949

django-epiceditor CVE-2017-6591 Cross Site Scripting Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96946

b2evolution CVE-2017-6902 Arbitrary File Upload Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96945

Easy File Sharing FTP Server CVE-2017-6510 Directory Traversal Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96944

SANS News

Malspam with password-protected Word documents

Threatpost

Local Windows Admins Can Hijack Sessions Without Credentials

Latest Tax Scams Include Phishing Lures, Malware

Exploit

Microsoft Windows - Uniscribe Font Processing Out-of-Bounds Read in...

Microsoft Windows - 'USP10!otlList::insertAt' Uniscribe Font Processing Heap-Based Buffer...

Microsoft Windows Kernel - Registry Hive Loading Crashes in nt!nt!HvpGetBinMemAlloc and...

Microsoft Windows - Uniscribe Font Processing Heap-Based Out-of-Bounds Read/Write in...

Microsoft Windows - Uniscribe Font Processing Heap-Based Memory Corruption in...

Microsoft Windows - Uniscribe Font Processing Heap-Based Memory Corruption in...

Microsoft Windows - Uniscribe Font Processing Heap-Based Buffer Overflow in...

Microsoft Windows - Uniscribe Font Processing Heap-Based Out-of-Bounds Write in...

Microsoft Windows - Uniscribe Font Processing Heap-Based Memory Corruption Around...

Microsoft Windows - Uniscribe Font Processing Buffer Overflow in...

Microsoft Windows - Uniscribe Font Processing Multiple Heap-Based Out-of-Bounds and Wild...

Microsoft GDI+ - 'gdiplus!GetRECTSForPlayback' Out-of-Bounds Read (MS17-013)

Microsoft Color Management Module 'icm32.dll' - 'icm32!Fill_ushort_ELUTs_from_lut16Tag'...

Microsoft Windows - Uniscribe Heap-Based Out-of-Bounds Read in...

Microsoft Color Management Module 'icm32.dll' - 'icm32!LHCalc3toX_Di16_Do16_Lut8_G32'...

Microsoft Internet Explorer - 'textarea.defaultValue' Memory Disclosure (MS17-006)

Mozilla Firefox - 'table' Use-After-Free

D-Link DGS-1510 - Multiple Vulnerabilities

Google Nest Cam 5.2.1
 - Buffer Overflow Conditions Over Bluetooth LE

ExtraPuTTY 0.29-RC2 - Denial of Service

21.3.2017

Bugtraq

Defense in depth -- the Microsoft way (part 47): "AppLocker bypasses are not serviced via monthly security roll-ups" 2017-03-21
Stefan Kanthak (stefan kanthak nexgo de)

[ERPSCAN-16-041] SAP NETWEAVER DIRECTORY CREATION OUTSIDE OF THE JVM 2017-03-21
ERPScan inc (erpscan online gmail com)

ESA-2017-010: EMC RecoverPoint SSL Stripping Vulnerability 2017-03-20
EMC Product Security Response Center (Security_Alert emc com)

[SECURITY] [DSA 3796-2] sitesummary regression update 2017-03-20
Sebastien Delafond (seb debian org)

[security bulletin] HPSBUX03596 rev.2 - HPE HP-UX running CIFS Server (Samba), Remote Access Restriction Bypass, Unauthorized Access 2017-03-20
security-alert hpe com

CVE-2017-7183 ExtraPuTTY v029_RC2 TFTP Denial Of Service 2017-03-20
apparitionsec gmail com (hyp3rlinx)

[SECURITY] [DSA 3813-1] r-base security update 2017-03-19
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 3812-1] ioquake3 security update 2017-03-18
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 3811-1] wireshark security update 2017-03-18
Moritz Muehlenhoff (jmm debian org)

Malware

TrojanSpy:MSIL/Omaneat
TrojanDownloader:Win32/Zdowbot.C

TrojanSpy:Win32/Bancos.XN

Trojan.Vanatmox

Trojan.Nexlogger

Phishing

Lloyds Bank

20th March 2017

Telephone Banking Verification

service@uk.paypal.com

19th March 2017

Your recent PayPal transfer is
under review

Vulnerebility

Microsoft Internet Explorer and Edge CVE-2016-7282 Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94724

Microsoft Office CVE-2016-7298 Memory Corruption Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94720

Microsoft Auto Updater for Mac CVE-2016-7300 Local Privilege Escalation Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94784

Microsoft Windows Graphics Component CVE-2016-7272 Remote Code Execution Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94739

Microsoft Windows Graphics Component CVE-2016-7273 Remote Code Execution Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94752

Microsoft Windows Kernel 'Win32k.sys' CVE-2016-7260 Local Privilege Escalation Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94785

Microsoft Internet Explorer and Edge CVE-2016-7287 Remote Memory Corruption Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94722

Jenkins SSH Slaves Plugin CVE-2017-2648 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96985

Jenkins Active Directory Plugin CVE-2017-2649 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96986

Jenkins Mailer Plugin CVE-2017-2651 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96984

Jenkins CVE-2017-2650 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96981

Apache POI CVE-2017-5644 Denial Of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96983

Moodle CVE-2017-2645 HTML Injection Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96982

Jenkins Distributed Fork Plugin CVE-2017-2652 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96980

Moodle CVE-2017-2644 HTML Injection Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96979

Quagga CVE-2017-5495 Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/95745

Quagga CVE-2016-1245 Buffer Overflow Vulnerability
2017-03-21
http://www.securityfocus.com/bid/93775

Quagga CVE-2016-2342 Stack Buffer Overflow Vulnerability
2017-03-21
http://www.securityfocus.com/bid/84318

Quagga CVE-2013-2236 Stack Buffer Overflow Vulnerability
2017-03-21
http://www.securityfocus.com/bid/60955

Moodle CVE-2017-2643 Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96978

Linux Kernel CVE-2016-10088 Incomplete Fix Multiple Local Memory Corruption Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/95169

Linux Kernel CVE-2016-9576 Use After Free Memory Corruption Vulnerability
2017-03-21
http://www.securityfocus.com/bid/94821

Linux Kernel CVE-2016-2069 TLB Flush Local Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/81809

Linux Kernel CVE-2016-6480 Local Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/92214

Linux Kernel Local Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/92659

IETF IPv6 Protocol CVE-2016-10142 Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/95797

Linux Kernel CVE-2016-7042 Local Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/93544

Moodle CVE-2017-2641 SQL Injection Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96977

IBM Call Center for Commerce CVE-2016-6056 Cross Site Scripting Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96975

IBM Security Key Lifecycle Manager CVE-2016-6102 Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96976ExtraPuTTY CVE-2017-7183 Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96973

Cisco IOS and IOS XE Software CVE-2017-3849 Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96972

Cisco IOS and IOS XE Software CVE-2017-3850 Denial of Service Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96971

Skype CVE-2017-6517 DLL Loading Local Code Execution Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96969

USB Pratirodh CVE-2017-6911 Insecure Password Storage Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96970

Ubiquiti Networking Products Multiple Command Injection Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96967

IBM Algorithmics One-Algo Risk Application CVE-2017-1155 Unauthorized Access Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96968

Red Hat CloudForms Management App CVE-2017-2653 Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96964

Microsoft Windows Local Privilege Escalation Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96966

Wordpress Anyone Plugin 'by-email.php' Session Management Security Bypass Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96965

IBM Cognos Business Intelligence CVE-2016-8960 Privilege Escalation Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96963

IBM Cognos Business Intelligence Server CVE-2016-9985 Local Information Disclosure Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96962

Trend Micro ServerProtect for Linux Unspecified Cross Site Scripting Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96961

Cisco IOS and IOS XE Software CVE-2017-3881 Remote Code Execution Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96960

Mozilla Firefox CVE-2017-5428 Integer Overflow Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96959

Google Android Qualcomm Fingerprint Sensor Driver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96950

Google Android Audioserver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96958

Nexpose Information Disclosure and DLL Loading Remote Code Execution Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96956

Metasploit Multiple Directory Traversal Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96954

Google Android NFC CVE-2017-0481 Privilege Escalation Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96953

Rapid7 AppSpider CVE-2017-5233 DLL Loading Remote Code Execution Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96957

EPESI Multiple Cross Site Scripting Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96955

Google Android Kernel ION Subsystem Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96952

Google Android Networking Driver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96948

Google Android Qualcomm IPA Driver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96947

Google Android Qualcomm Camera Driver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96951

Google Android HTC Sensor Hub Driver Multiple Privilege Escalation Vulnerabilities
2017-03-21
http://www.securityfocus.com/bid/96949

django-epiceditor CVE-2017-6591 Cross Site Scripting Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96946

b2evolution CVE-2017-6902 Arbitrary File Upload Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96945

Easy File Sharing FTP Server CVE-2017-6510 Directory Traversal Vulnerability
2017-03-21
http://www.securityfocus.com/bid/96944
 

SANS News

 

Threatpost

 

Exploit

 

21.3.2017

Bugtraq

CVE-2017-7183 ExtraPuTTY v029_RC2 TFTP Denial Of Service 2017-03-20
apparitionsec gmail com (hyp3rlinx)

[SECURITY] [DSA 3813-1] r-base security update 2017-03-19
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 3812-1] ioquake3 security update 2017-03-18
Moritz Muehlenhoff (jmm debian org)

[SECURITY] [DSA 3811-1] wireshark security update 2017-03-18
Moritz Muehlenhoff (jmm debian org)

MS Internet Information Services XSS / HTML Injection vulnerability 2017-03-16
David FM (david fdmv gmail com)

Malware

 

Phishing

Lloyds Bank

20th March 2017

Telephone Banking Verification

service@uk.paypal.com

19th March 2017

Your recent PayPal transfer is
under review

service@paypal.com

19th March 2017

You have added
richie.005@yahoo.com as a new
email address for your Paypal
account.

Vulnerebility

Red Hat CloudForms Management App CVE-2017-2653 Security Bypass Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96964

Microsoft Windows Local Privilege Escalation Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96966

Wordpress Anyone Plugin 'by-email.php' Session Management Security Bypass Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96965

IBM Cognos Business Intelligence CVE-2016-8960 Privilege Escalation Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96963

IBM Cognos Business Intelligence Server CVE-2016-9985 Local Information Disclosure Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96962

Trend Micro ServerProtect for Linux Unspecified Cross Site Scripting Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96961

Cisco IOS and IOS XE Software CVE-2017-3881 Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96960

Mozilla Firefox CVE-2017-5428 Integer Overflow Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96959

Google Android Qualcomm Fingerprint Sensor Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96950

Google Android Audioserver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96958

Nexpose Information Disclosure and DLL Loading Remote Code Execution Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96956

Metasploit Multiple Directory Traversal Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96954

Google Android NFC CVE-2017-0481 Privilege Escalation Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96953

Rapid7 AppSpider CVE-2017-5233 DLL Loading Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96957

EPESI Multiple Cross Site Scripting Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96955

Google Android Kernel ION Subsystem Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96952

Google Android Networking Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96948

Google Android Qualcomm IPA Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96947

Google Android Qualcomm Camera Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96951

Google Android HTC Sensor Hub Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96949

django-epiceditor CVE-2017-6591 Cross Site Scripting Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96946

b2evolution CVE-2017-6902 Arbitrary File Upload Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96945

Easy File Sharing FTP Server CVE-2017-6510 Directory Traversal Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96944

Linux Kernel CVE-2017-6951 Local Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96943

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96378

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95993

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95990

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96112

QEMU 'sdhci.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95885

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95999
Trend Micro ServerProtect for Linux Unspecified Cross Site Scripting Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96961

Cisco IOS and IOS XE Software CVE-2017-3881 Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96960

Mozilla Firefox CVE-2017-5428 Integer Overflow Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96959

Google Android Qualcomm Fingerprint Sensor Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96950

Google Android Audioserver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96958

Nexpose Information Disclosure and DLL Loading Remote Code Execution Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96956

Metasploit Multiple Directory Traversal Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96954

Google Android NFC CVE-2017-0481 Privilege Escalation Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96953

Rapid7 AppSpider CVE-2017-5233 DLL Loading Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96957

EPESI Multiple Cross Site Scripting Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96955

Google Android Kernel ION Subsystem Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96952

Google Android Networking Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96948

Google Android Qualcomm IPA Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96947

Google Android Qualcomm Camera Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96951

Google Android HTC Sensor Hub Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96949

django-epiceditor CVE-2017-6591 Cross Site Scripting Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96946

b2evolution CVE-2017-6902 Arbitrary File Upload Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96945

Easy File Sharing FTP Server CVE-2017-6510 Directory Traversal Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96944

Linux Kernel CVE-2017-6951 Local Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96943

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96378

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95993

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95990

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96112

QEMU 'sdhci.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95885

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95999

QEMU 'ac97.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95671

QEMU 'virtio-gpu.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95781

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/94803

QEMU 'es1370.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95669

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95773Google Android Audioserver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96958

Nexpose Information Disclosure and DLL Loading Remote Code Execution Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96956

Metasploit Multiple Directory Traversal Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96954

Google Android NFC CVE-2017-0481 Privilege Escalation Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96953

Rapid7 AppSpider CVE-2017-5233 DLL Loading Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96957

EPESI Multiple Cross Site Scripting Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96955

Google Android Kernel ION Subsystem Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96952

Google Android Networking Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96948

Google Android Qualcomm IPA Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96947

Google Android Qualcomm Camera Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96951

Google Android HTC Sensor Hub Driver Multiple Privilege Escalation Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/96949

django-epiceditor CVE-2017-6591 Cross Site Scripting Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96946

b2evolution CVE-2017-6902 Arbitrary File Upload Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96945

Easy File Sharing FTP Server CVE-2017-6510 Directory Traversal Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96944

Linux Kernel CVE-2017-6951 Local Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96943

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96378

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95993

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95990

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96112

QEMU 'sdhci.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95885

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95999

QEMU 'ac97.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95671

QEMU 'virtio-gpu.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95781

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/94803

QEMU 'es1370.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95669

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-20
http://www.securityfocus.com/bid/95773

LAquis SCADA CVE-2017-6016 Local Access Bypass Vulnerability
2017-03-20
http://www.securityfocus.com/bid/96942

Google Chrome Prior to 52.0.2743.82 Multiple Security Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/92053

Apple iOS/tvOS/MacOS/watchOS Multiple Security Vulnerabilities
2017-03-20
http://www.securityfocus.com/bid/93054

Microsoft Windows Uniscribe CVE-2016-7274 Remote Code Execution Vulnerability
2017-03-20
http://www.securityfocus.com/bid/94758

SANS News

Searching for Base64-encoded PE Files

Threatpost

Jon Oberheide on Perimeter Security

Exploit

HttpServer 1.0 - Directory Traversal

FTPShell Server 6.56 - 'ChangePassword' Buffer Overflow

ExtraPuTTY 0.29-RC2 - Denial of Service

Joomla! Component JooCart 2.x - 'product_id' Parameter SQL Injection

19.3.2017

Bugtraq

 

Malware

 

Phishing

Apple

17th March 2017

ALERT: We have updates on our
Policy Update Page.[521510]

Account Support

17th March 2017

Please check your account
information

Mea

17th March 2017

Mea just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Anamaria

17th March 2017

Anamaria just sent you
$3,182.00 USD with Paypal.
Paypal recommends to withdraw
it now.

Vulnerebility

Google Android Audioserver Multiple Privilege Escalation Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/96958

Nexpose Information Disclosure and DLL Loading Remote Code Execution Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/96956

Metasploit Multiple Directory Traversal Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/96954

Google Android NFC CVE-2017-0481 Privilege Escalation Vulnerability
2017-03-19
http://www.securityfocus.com/bid/96953

Rapid7 AppSpider CVE-2017-5233 DLL Loading Remote Code Execution Vulnerability
2017-03-19
http://www.securityfocus.com/bid/96957

EPESI Multiple Cross Site Scripting Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/96955

Google Android Kernel ION Subsystem Multiple Privilege Escalation Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/96952

Google Android Networking Driver Multiple Privilege Escalation Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/96948

Google Android Qualcomm IPA Driver Multiple Privilege Escalation Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/96947

Google Android Qualcomm Camera Driver Multiple Privilege Escalation Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/96951

Google Android HTC Sensor Hub Driver Multiple Privilege Escalation Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/96949

django-epiceditor CVE-2017-6591 Cross Site Scripting Vulnerability
2017-03-19
http://www.securityfocus.com/bid/96946

b2evolution CVE-2017-6902 Arbitrary File Upload Vulnerability
2017-03-19
http://www.securityfocus.com/bid/96945

Easy File Sharing FTP Server CVE-2017-6510 Directory Traversal Vulnerability
2017-03-19
http://www.securityfocus.com/bid/96944

Linux Kernel CVE-2017-6951 Local Denial of Service Vulnerability
2017-03-19
http://www.securityfocus.com/bid/96943

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-03-19
http://www.securityfocus.com/bid/96378

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-19
http://www.securityfocus.com/bid/95993

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-19
http://www.securityfocus.com/bid/95990

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-19
http://www.securityfocus.com/bid/96112

QEMU 'sdhci.c' Denial of Service Vulnerability
2017-03-19
http://www.securityfocus.com/bid/95885

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-19
http://www.securityfocus.com/bid/95999

QEMU 'ac97.c' Denial of Service Vulnerability
2017-03-19
http://www.securityfocus.com/bid/95671

QEMU 'virtio-gpu.c' Denial of Service Vulnerability
2017-03-19
http://www.securityfocus.com/bid/95781

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/94803

QEMU 'es1370.c' Denial of Service Vulnerability
2017-03-19
http://www.securityfocus.com/bid/95669

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-19
http://www.securityfocus.com/bid/95773

LAquis SCADA CVE-2017-6016 Local Access Bypass Vulnerability
2017-03-19
http://www.securityfocus.com/bid/96942

Google Chrome Prior to 52.0.2743.82 Multiple Security Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/92053

Apple iOS/tvOS/MacOS/watchOS Multiple Security Vulnerabilities
2017-03-19
http://www.securityfocus.com/bid/93054

Microsoft Windows Uniscribe CVE-2016-7274 Remote Code Execution Vulnerability
2017-03-19
http://www.securityfocus.com/bid/94758Google Android Audioserver Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96958

Nexpose Information Disclosure and DLL Loading Remote Code Execution Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96956

Metasploit Multiple Directory Traversal Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96954

Google Android NFC CVE-2017-0481 Privilege Escalation Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96953

Rapid7 AppSpider CVE-2017-5233 DLL Loading Remote Code Execution Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96957

EPESI Multiple Cross Site Scripting Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96955

Google Android Kernel ION Subsystem Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96952

Google Android Networking Driver Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96948

Google Android Qualcomm IPA Driver Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96947

Google Android Qualcomm Camera Driver Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96951

Google Android HTC Sensor Hub Driver Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96949

django-epiceditor CVE-2017-6591 Cross Site Scripting Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96946

b2evolution CVE-2017-6902 Arbitrary File Upload Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96945

Easy File Sharing FTP Server CVE-2017-6510 Directory Traversal Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96944

Linux Kernel CVE-2017-6951 Local Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96943

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96378

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95993

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95990

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96112

QEMU 'sdhci.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95885

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95999

QEMU 'ac97.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95671

QEMU 'virtio-gpu.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95781

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/94803

QEMU 'es1370.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95669

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95773

LAquis SCADA CVE-2017-6016 Local Access Bypass Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96942

Google Chrome Prior to 52.0.2743.82 Multiple Security Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/92053

Apple iOS/tvOS/MacOS/watchOS Multiple Security Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/93054

Microsoft Windows Uniscribe CVE-2016-7274 Remote Code Execution Vulnerability
2017-03-18
http://www.securityfocus.com/bid/94758Google Android Audioserver Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96958

Nexpose Information Disclosure and DLL Loading Remote Code Execution Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96956

Metasploit Multiple Directory Traversal Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96954

Google Android NFC CVE-2017-0481 Privilege Escalation Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96953

Rapid7 AppSpider CVE-2017-5233 DLL Loading Remote Code Execution Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96957

EPESI Multiple Cross Site Scripting Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96955

Google Android Kernel ION Subsystem Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96952

Google Android Networking Driver Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96948

Google Android Qualcomm IPA Driver Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96947

Google Android Qualcomm Camera Driver Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96951

Google Android HTC Sensor Hub Driver Multiple Privilege Escalation Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/96949

django-epiceditor CVE-2017-6591 Cross Site Scripting Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96946

b2evolution CVE-2017-6902 Arbitrary File Upload Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96945

Easy File Sharing FTP Server CVE-2017-6510 Directory Traversal Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96944

Linux Kernel CVE-2017-6951 Local Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96943

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96378

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95993

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95990

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96112

QEMU 'sdhci.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95885

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95999

QEMU 'ac97.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95671

QEMU 'virtio-gpu.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95781

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/94803

QEMU 'es1370.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95669

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-18
http://www.securityfocus.com/bid/95773

LAquis SCADA CVE-2017-6016 Local Access Bypass Vulnerability
2017-03-18
http://www.securityfocus.com/bid/96942

Google Chrome Prior to 52.0.2743.82 Multiple Security Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/92053

Apple iOS/tvOS/MacOS/watchOS Multiple Security Vulnerabilities
2017-03-18
http://www.securityfocus.com/bid/93054

Microsoft Windows Uniscribe CVE-2016-7274 Remote Code Execution Vulnerability
2017-03-18
http://www.securityfocus.com/bid/94758

SANS News

Example of Multiple Stages Dropper

Threatpost

Vulnerability Disclosed in Ubquiti Networks Admin Interface

VM Escape Earns Hackers $105K at Pwn2Own

Exploit

Linux/x86 - Encoded exceve("/bin/sh") Shellcode (44 Bytes)

Linux/x86 - Bind Shell Shellcode (51 bytes)

iFdate Social Dating Script 2.0 - SQL Injection

DIGISOL DG-HR1400 1.00.02 Wireless Router - Privilege Escalation

Omegle Clone - SQL Injection

Secure Download Links - 'dc' Parameter SQL Injection

17.3.2017

Bugtraq

MS Internet Information Services XSS / HTML Injection vulnerability 2017-03-16
David FM (david fdmv gmail com)

CVE-2017-6805 MobaXterm Personal Edition v9.4 Path Traversal Remote File Disclosure 2017-03-16
apparitionsec gmail com (hyp3rlinx)

SEC Consult SA-20170316-0 :: Authenticated command injection in multiple Ubiquiti Networks products 2017-03-16
SEC Consult Vulnerability Lab (research sec-consult com)

CVE-2017-6911: USB Pratirodh Insecure Password Storage Information Disclosure Vulnerability 2017-03-16
wsachin092 gmail com

[slackware-security] pidgin (SSA:2017-074-01) 2017-03-16
Slackware Security Team (security slackware com)

Path Traversal Remote File Disclosure 2017-03-16
apparitionsec gmail com (hyp3rlinx)

Malware

Trojan.Majikpos

Phishing

Mea

17th March 2017

Mea just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Anamaria

17th March 2017

Anamaria just sent you
$3,182.00 USD with Paypal.
Paypal recommends to withdraw
it now.

Kelly

17th March 2017

Kelly just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Vulnerebility

Google Android HTC Sensor Hub Driver Multiple Privilege Escalation Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96949

django-epiceditor CVE-2017-6591 Cross Site Scripting Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96946

b2evolution CVE-2017-6902 Arbitrary File Upload Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96945

Easy File Sharing FTP Server CVE-2017-6510 Directory Traversal Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96944

Linux Kernel CVE-2017-6951 Local Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96943

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96378

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95993

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95990

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96112

QEMU 'sdhci.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95885

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95999

QEMU 'ac97.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95671

QEMU 'virtio-gpu.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95781

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/94803

QEMU 'es1370.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95669

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95773

LAquis SCADA CVE-2017-6016 Local Access Bypass Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96942

Google Chrome Prior to 52.0.2743.82 Multiple Security Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/92053

Apple iOS/tvOS/MacOS/watchOS Multiple Security Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/93054

Microsoft Windows Uniscribe CVE-2016-7274 Remote Code Execution Vulnerability
2017-03-17
http://www.securityfocus.com/bid/94758

Libxml2 CVE-2016-4448 Remote Format String Vulnerability
2017-03-17
http://www.securityfocus.com/bid/90856

Commvault Edge CVE-2017-3195 Stack Buffer Overflow Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96941

Agora-Project Multiple Cross Site Scripting Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96940

Asus ASUSWRT Multiple Security Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96938

MaNGOSWebV4 Multiple Cross Site Scripting Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96939

Zammad Multiple Security Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96937

CMS Made Simple Multiple Cross Site Scripting Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96933

MagniComp Sysinfo CVE-2017-6516 Local Privilege Escalation Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96934

USB Pratirodh CVE-2017-6895 XML External Entity Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96936

IBM WebSphere Application Server CVE-2015-7450 Remote Code Execution Vulnerability
2017-03-17
http://www.securityfocus.com/bid/77653QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95993

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95990

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96112

QEMU 'sdhci.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95885

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95999

QEMU 'ac97.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95671

QEMU 'virtio-gpu.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95781

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/94803

QEMU 'es1370.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95669

QEMU 'virtio-gpu-3d.c' Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/95773

Google Chrome Prior to 52.0.2743.82 Multiple Security Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/92053

Apple iOS/tvOS/MacOS/watchOS Multiple Security Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/93054

Microsoft Windows Uniscribe CVE-2016-7274 Remote Code Execution Vulnerability
2017-03-17
http://www.securityfocus.com/bid/94758

Libxml2 CVE-2016-4448 Remote Format String Vulnerability
2017-03-17
http://www.securityfocus.com/bid/90856

Commvault Edge CVE-2017-3195 Stack Buffer Overflow Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96941

Agora-Project Multiple Cross Site Scripting Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96940

Asus ASUSWRT Multiple Security Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96938

MaNGOSWebV4 Multiple Cross Site Scripting Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96939

Zammad Multiple Security Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96937

CMS Made Simple Multiple Cross Site Scripting Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96933

MagniComp Sysinfo CVE-2017-6516 Local Privilege Escalation Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96934

USB Pratirodh CVE-2017-6895 XML External Entity Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96936

IBM WebSphere Application Server CVE-2015-7450 Remote Code Execution Vulnerability
2017-03-17
http://www.securityfocus.com/bid/77653

Shimmie CVE-2017-6909 Cross Site Scripting Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96932

webpagetest Multiple Cross Site Scripting Vulnerabilities
2017-03-17
http://www.securityfocus.com/bid/96935

ImageMagick CVE-2017-6498 Local Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96591

ImageMagick 'coders/sun.c' Local Heap Buffer Overflow Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96592

ImageMagick CVE-2017-6499 Local Denial of Service Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96590

McAfee Advanced Threat Defense CVE-2017-3899 SQL Injection Vulnerabilitiy
2017-03-17
http://www.securityfocus.com/bid/96929

Cisco Prime Infrastructure CVE-2017-3869 Security Bypass Vulnerability
2017-03-17
http://www.securityfocus.com/bid/96931

SANS News

 

Threatpost

GitHub Code Execution Bug Fetches $18,000 Bounty

US-CERT Warns HTTPS Inspection May Degrade TLS Security

Exploit

Microsoft Edge 38.14393.0.0 - JavaScript Engine Use-After-Free

AXIS Communications - Cross-Site Scripting / Content Injection

AXIS Multiple Products - Cross-Site Request Forgery

Wordpress Plugin Membership Simplified 1.58 - Arbitrary File Download

16.3.2017

Bugtraq

MS Internet Information Services XSS / HTML Injection vulnerability 2017-03-16
David FM (david fdmv gmail com)

CVE-2017-6805 MobaXterm Personal Edition v9.4 Path Traversal Remote File Disclosure 2017-03-16
apparitionsec gmail com (hyp3rlinx)

SEC Consult SA-20170316-0 :: Authenticated command injection in multiple Ubiquiti Networks products 2017-03-16
SEC Consult Vulnerability Lab (research sec-consult com)

CVE-2017-6911: USB Pratirodh Insecure Password Storage Information Disclosure Vulnerability 2017-03-16
wsachin092 gmail com

[slackware-security] pidgin (SSA:2017-074-01) 2017-03-16
Slackware Security Team (security slackware com)

Path Traversal Remote File Disclosure 2017-03-16
apparitionsec gmail com (hyp3rlinx)

CVE-2017-0045 Windows DVD Maker XML External Entity File Disclosure 2017-03-16
apparitionsec gmail com (hyp3rlinx)

Microsoft Edge Fetch API allows setting of arbitrary request headers 2017-03-14
Securify B.V. (lists securify nl)

Joomla com_virtuemart Component - 'id' Parameter Sql Injection Vulnerability 2017-03-14
iedb team gmail com

Malware

Backdoor.Actoin

JS.Adashic!inf

Trojan.Modruner

Phishing

Card Services Online

15th March 2017

Natwest Card Services.

service@paypal.com

15th March 2017

Receipt for Your Payment to
cleverbridge, Inc

Account Amazon UK

14th March 2017

Your Amazon.co.uk Account
Updates

Vulnerebility

CMS Made Simple Multiple Cross Site Scripting Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96933

MagniComp Sysinfo CVE-2017-6516 Local Privilege Escalation Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96934

USB Pratirodh CVE-2017-6895 XML External Entity Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96936

IBM WebSphere Application Server CVE-2015-7450 Remote Code Execution Vulnerability
2017-03-16
http://www.securityfocus.com/bid/77653

Shimmie CVE-2017-6909 Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96932

webpagetest Multiple Cross Site Scripting Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96935

ImageMagick CVE-2017-6498 Local Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96591

ImageMagick 'coders/sun.c' Local Heap Buffer Overflow Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96592

ImageMagick CVE-2017-6499 Local Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96590

McAfee Advanced Threat Defense CVE-2017-3899 SQL Injection Vulnerabilitiy
2017-03-16
http://www.securityfocus.com/bid/96929

Cisco Prime Infrastructure CVE-2017-3869 Security Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96931

Cisco Prime Optical for Service Providers CVE-2017-3871 Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96928

Cisco Nexus 7000 Series Switches CVE-2017-3875 Security Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96930

Cisco Adaptive Security Appliance Software CVE-2017-3867 Security Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96926

Cisco NX-OS Software CVE-2017-3878 Remote Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96927

Palo Alto Networks Terminal Services CVE-2017-6356 Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96925

Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96654

Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96664

Mozilla Firefox and Thunderbird CVE-2017-5401 Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96677

Mozilla Firefox and Thunderbird Multiple Security Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96693

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96651

netpbm CVE-2017-5849 Multiple Denial of Service Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96011

Apache Tomcat CVE-2016-8745 Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/94828

RabbitMQ CVE-2015-8786 Multiple Denial of Service Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/91508

Linux Kernel CVE-2017-5551 Local Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/95717

Linux Kernel 'EXT4 image' Local Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/94354

Oracle MySQL Server CVE-2017-3313 Local Security Vulnerability
2017-03-16
http://www.securityfocus.com/bid/95527

MariaDB and MySQL CVE-2017-3302 Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96162

Adobe Flash Player APSB17-07 Multiple Memory Corruption Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96866

Adobe Flash Player CVE-2017-2997 Buffer Overflow Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96860Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96654

Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96664

Mozilla Firefox and Thunderbird CVE-2017-5401 Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96677

Mozilla Firefox and Thunderbird Multiple Security Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96693

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96651

netpbm CVE-2017-5849 Multiple Denial of Service Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96011

Apache Tomcat CVE-2016-8745 Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/94828

RabbitMQ CVE-2015-8786 Multiple Denial of Service Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/91508

Linux Kernel CVE-2017-5551 Local Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/95717

Linux Kernel 'EXT4 image' Local Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/94354

Oracle MySQL Server CVE-2017-3313 Local Security Vulnerability
2017-03-16
http://www.securityfocus.com/bid/95527

MariaDB and MySQL CVE-2017-3302 Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96162

Adobe Flash Player APSB17-07 Multiple Memory Corruption Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96866

Adobe Flash Player CVE-2017-2997 Buffer Overflow Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96860

Adobe Flash Player CVE-2017-3000 Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96862

Adobe Flash Player APSB17-07 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96861

Drupal Private Module Access Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96924

Apache Tomcat CVE-2016-6816 Security Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/94461

Security guide for website operators CVE-2017-2128 OS Command Injection Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96923

Cisco NX-OS Software CVE-2017-3879 Remote Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96920

Cisco TelePresence Server Software CVE-2017-3815 Privilege Escalation Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96922

Cisco UCS Director CVE-2017-3868 Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96921

Drupal Core DRUPAL-SA-CORE-2017-001 Multiple Security Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96919

Cisco WebEx Meetings Server CVE-2017-3880 Authentication Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96918

Microsoft Windows Graphics Component CVE-2017-0108 Remote Code Execution Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96722

Cisco Prime Service Catalog CVE-2017-3866 Multiple Cross Site Scripting Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96917

Cisco Unified Communications Manager CVE-2017-3874 Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96914

Cisco Unified Communications Manager CVE-2017-3872 Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96916

Cisco StarOS CVE-2017-3819 Privilege Escalation Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96913

Cisco Unified Communications Manager CVE-2017-3877 Cross Site Request Forgery Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96915Microsoft Office CVE-2017-0020 Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96050

Microsoft Office CVE-2017-0027 Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96043

Microsoft Windows CVE-2017-0055 Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96622

Foxit Reader and Foxit PhantomPDF CVE-2017-6883 Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96870

Microsoft Edge CVE-2017-0151 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96727

Microsoft Edge CVE-2017-0150 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96725

Microsoft Edge CVE-2017-0070 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96690

Microsoft Edge CVE-2017-0137 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96689

Microsoft Edge CVE-2017-0136 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96688

Microsoft Edge CVE-2017-0134 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96687

Microsoft Edge CVE-2017-0132 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96686

Microsoft Edge CVE-2017-0141 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96685

Microsoft Edge CVE-2017-0138 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96684

Microsoft Edge CVE-2017-0133 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96683

Microsoft Edge CVE-2017-0094 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96682

Microsoft Edge CVE-2017-0071 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96681

Microsoft Edge CVE-2017-0131 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96671

Microsoft Edge CVE-2017-0067 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96662

Microsoft Edge CVE-2017-0135 Security Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96656

Microsoft Edge CVE-2017-0140 Security Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96653

Microsoft Edge CVE-2017-0066 Security Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96655

Microsoft Edge CVE-2017-0069 Spoofing Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96650

Microsoft Edge CVE-2017-0068 Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96649

Microsoft Edge CVE-2017-0065 Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96648

Microsoft Windows CVE-2017-0043 XML External Entity Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96628

Microsoft Windows CVE-2017-0102 Local Privilege Escalation Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96627

Microsoft Windows CVE-2017-0101 Local Privilege Escalation Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96625

Microsoft Windows Kernel CVE-2017-0103 Local Privilege Escalation Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96623

Microsoft Windows Kernel CVE-2017-0050 Local Privilege Escalation Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96025

Microsoft Windows Kernel 'Win32k.sys' CVE-2017-0081 Local Privilege Escalation Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96634Cisco UCS Director CVE-2017-3868 Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96921

Drupal Core DRUPAL-SA-CORE-2017-001 Multiple Security Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96919

Cisco WebEx Meetings Server CVE-2017-3880 Authentication Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96918

Microsoft Windows Graphics Component CVE-2017-0108 Remote Code Execution Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96722

Cisco Prime Service Catalog CVE-2017-3866 Multiple Cross Site Scripting Vulnerabilities
2017-03-16
http://www.securityfocus.com/bid/96917

Cisco Unified Communications Manager CVE-2017-3874 Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96914

Cisco Unified Communications Manager CVE-2017-3872 Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96916

Cisco StarOS CVE-2017-3819 Privilege Escalation Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96913

Cisco Unified Communications Manager CVE-2017-3877 Cross Site Request Forgery Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96915

Cisco WebEx Meetings Server CVE-2017-3811 XML External Entity Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96912

Cisco Wireless LAN Controller CVE-2017-3854 Remote Security Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96911

Cisco AsyncOS CVE-2017-3870 Remote Security Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96907

Multiple Cisco Products CVE-2017-3846 Arbitrary File Read Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96910

Cisco Mobility Express 1800 Access Point Series CVE-2017-3831 Authentication Bypass Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96909

WordPress Wp2android Plugin CVE-2017-1002003 Arbitrary File Upload Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96908

WordPress Webapp-Builder Plugin CVE-2017-1002002 Arbitrary File Upload Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96906

WordPress Mobile App Builder By Wappress Plugin Arbitrary File Upload Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96905

SAP Travel Management Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96904

SAP NetWeaver Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96903

SAP HANA Unspecified Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96900

WordPress Mobile Friendly App Builder By Easytouch Plugin Arbitrary File Upload Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96899

SiberianCMS CVE-2017-6906 Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96898

SAP Security Diagnostic Tool Unspecified Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96901

SAP Enterprise Portal 'styleservice' Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96902

Open.GL CVE-2017-6907 Cross Site Scripting Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96897

Apache Tomcat CVE-2016-8747 Information Disclosure Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96895

Red Hat JBoss Enterprise Application Platform CVE-2016-8657 Local Privilege Escalation Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96896

Microsoft Windows Hyper-V CVE-2017-0098 Remote Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96642

Microsoft Windows Hyper-V CVE-2017-0076 Remote Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96636

Microsoft Windows Hyper-V CVE-2017-0097 Remote Denial of Service Vulnerability
2017-03-16
http://www.securityfocus.com/bid/96639

SANS News

 

Threatpost

Intel, Microsoft Announce New Bug Bounties

Hackers Take Down Reader, Safari, Edge, Ubuntu Linux at Pwn2Own 2017

Fileless Malware Campaigns Tied to Same Attacker

Exploit

Microsoft Windows - COM Session Moniker Privilege Escalation (MS17-012)

Microsoft Windows - 'LoadUvsTable()' Heap-based Buffer Overflow

Adobe Flash - Metadata Parsing Out-of-Bounds Read

Adobe Flash - MovieClip Attach init Object Use-After-Free

Adobe Flash - ATF Thumbnailing Heap Overflow

Adobe Flash - ATF Planar Decompression Heap Overflow

Adobe Flash - AVC Header Slicing Heap Overflow

IBM WebSphere - RCE Java Deserialization (Metasploit)

Apache Struts Jakarta - Multipart Parser OGNL Injection (Metasploit)

Joomla! Component Vik Appointments 1.5 - SQL Injection

Joomla! Component Vik Rent Items 1.3 - SQL Injection

Joomla! Component Vik Rent Car 1.11 - SQL Injection

GitHub Enterprise 2.8.0 < 2.8.6 - Remote Code Execution

Steam Profile Integration 2.0.11 - SQL injection

Sitecore CMS 8.1 Update-3 - Cross-Site Scripting

Windows DVD Maker 6.1.7 - XML External Entity Injection

PCAUSA Rawether (ASUS PCE-AC56 WLAN Card Utilities Windows 10 x64) - Local...

15.3.2017

Bugtraq

Microsoft Edge Fetch API allows setting of arbitrary request headers 2017-03-14
Securify B.V. (lists securify nl)

Joomla com_virtuemart Component - 'id' Parameter Sql Injection Vulnerability 2017-03-14
iedb team gmail com

Joomla com_kunena Component - 'id' Parameter Sql Injection Vulnerability 2017-03-14
iedb team gmail com

Joomla com_sngevents Component - 'id' Parameter Sql Injection Vulnerability 2017-03-14
iedb team gmail com

Joomla com_fidecalendar Component - 'aid' Parameter Sql Injection Vulnerability 2017-03-14
iedb team gmail com

Malware

TrojanDownloader:Win32/Zdowbot.C
TrojanSpy:Win32/Bancos.XN

Phishing

Account Amazon UK

14th March 2017

Your Amazon.co.uk Account
Updates

Chantal

14th March 2017

Chantal just sent you
$3,182.00 USD with Paypal.
Paypal recommends to withdraw
it now.

Bank of America

14th March 2017

Bank of America Alert: Your
Online Access is Temporarily
Locked

Vulnerebility

Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96729

JIRA Server XML External Entity Injection and Arbitrary Code Execution Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96894

concrete5 Multiple Cross Site Scripting Vulnerabilities
2017-03-15
http://www.securityfocus.com/bid/96891

Fatek Automation PLC Ethernet Module CVE-2017-6023 Stack Based Buffer Overflow Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96892

WordPress DTracker Plugin Multiple Content Injection Vulnerabilities
2017-03-15
http://www.securityfocus.com/bid/96890

FIYO CMS CVE-2017-6823 Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96889

SAP NetWeaver Log Viewer Security Bypass Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96888

Cerberus FTP CVE-2017-6367 Denial of Service Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96887

MobaXterm Personal Edition CVE-2017-6805 Directory Traversal Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96886

SAP Cross Site Scripting Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96884

SAP BusinessObjects Unspecified Cross Site Scripting Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96885

keycloak CVE-2017-2646 Denial of Service Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96882

SAP 3D Visual Enterprise Author, Generator and Viewer Unspecified Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96883

SAP NetWeaver Visual Composer Denial of Service Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96865

SAP NetWeaver Monitoring Application Unspecified Cross Site Scripting Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96878

SAP Web Dynpro ABAP Unspecified Cross Site Scripting Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96879

Multiple VMware Products CVE-2017-4901 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96881

SAP Enterprise Portal 'GenericSemanticTest' Component Cross Site Scripting Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96880

GNU Wget CVE-2017-6508 CRLF Injection Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96877

Microsoft Windows SMB Server CVE-2017-0147 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96709

Microsoft Windows SMB Server CVE-2017-0145 Remote Code Execution Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96705

Microsoft Windows SMB Server CVE-2017-0146 Remote Code Execution Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96707

Microsoft Windows SMB Server CVE-2017-0143 Remote Code Execution Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96703

Microsoft Windows SMB Server CVE-2017-0148 Remote Code Execution Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96706

Microsoft Windows SMB Server CVE-2017-0144 Remote Code Execution Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96704

Microsoft Office CVE-2017-0029 Denial of Service Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96045

Microsoft Windows Hyper-V CVE-2017-0096 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96701

Microsoft Windows DirectShow CVE-2017-0042 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96098

Microsoft Windows Hyper-V CVE-2017-0075 Remote Code Execution Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96698

Microsoft Windows Hyper-V CVE-2017-0109 Remote Code Execution Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96644
Microsoft Windows Hyper-V CVE-2017-0021 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96020

Adobe Flash Player APSB17-07 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-03-15
http://www.securityfocus.com/bid/96861

Adobe Flash Player CVE-2017-3000 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96862

Adobe Flash Player APSB17-07 Multiple Memory Corruption Vulnerabilities
2017-03-15
http://www.securityfocus.com/bid/96866

Microsoft Internet Explorer CVE-2017-0049 Scripting Engine Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96095

Adobe Flash Player CVE-2017-2997 Buffer Overflow Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96860

Microsoft Windows Kernel 'Win32k.sys' CVE-2017-0082 Local Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96635

Microsoft Office CVE-2017-0105 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96746

Microsoft Office CVE-2017-0019 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96042

Microsoft Internet Explorer CVE-2017-0018 Remote Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96086

Microsoft Internet Explorer CVE-2017-0040 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96094

Microsoft Internet Explorer and Edge CVE-2017-0033 Spoofing Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96087

Microsoft Internet Explorer and Edge CVE-2017-0012 Spoofing Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96085

Microsoft Internet Explorer and Edge CVE-2017-0009 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96077

Microsoft Internet Explorer CVE-2017-0008 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96073

Microsoft Windows Graphics CVE-2017-0001 Local Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96057

Microsoft Internet Explorer and Edge CVE-2017-0037 Remote Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96088

Microsoft Windows Graphics CVE-2017-0047 Local Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96034

Microsoft Windows Graphics CVE-2017-0005 Local Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96033

Microsoft Windows CVE-2017-0038 Incomplete Fix Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96023

Microsoft Exchange Server CVE-2017-0110 Remote Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96621

SAP NetWeaver Visual Composer Denial of Service Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96865

Microsoft Office CVE-2017-0031 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96052

Microsoft Office CVE-2017-0030 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96051

Microsoft Office CVE-2017-0029 Denial of Service Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96045

Microsoft Office CVE-2017-0020 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96050

Microsoft Office CVE-2017-0027 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96043

Microsoft Windows CVE-2017-0055 Cross Site Scripting Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96622

Foxit Reader and Foxit PhantomPDF CVE-2017-6883 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96870

Microsoft Edge CVE-2017-0151 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96727Microsoft Windows Hyper-V CVE-2017-0021 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96020

Adobe Flash Player APSB17-07 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-03-15
http://www.securityfocus.com/bid/96861

Adobe Flash Player CVE-2017-3000 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96862

Adobe Flash Player APSB17-07 Multiple Memory Corruption Vulnerabilities
2017-03-15
http://www.securityfocus.com/bid/96866

Microsoft Internet Explorer CVE-2017-0049 Scripting Engine Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96095

Adobe Flash Player CVE-2017-2997 Buffer Overflow Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96860

Microsoft Windows Kernel 'Win32k.sys' CVE-2017-0082 Local Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96635

Microsoft Office CVE-2017-0105 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96746

Microsoft Office CVE-2017-0019 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96042

Microsoft Internet Explorer CVE-2017-0018 Remote Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96086

Microsoft Internet Explorer CVE-2017-0040 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96094

Microsoft Internet Explorer and Edge CVE-2017-0033 Spoofing Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96087

Microsoft Internet Explorer and Edge CVE-2017-0012 Spoofing Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96085

Microsoft Internet Explorer and Edge CVE-2017-0009 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96077

Microsoft Internet Explorer CVE-2017-0008 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96073

Microsoft Windows Graphics CVE-2017-0001 Local Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96057

Microsoft Internet Explorer and Edge CVE-2017-0037 Remote Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96088

Microsoft Windows Graphics CVE-2017-0047 Local Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96034

Microsoft Windows Graphics CVE-2017-0005 Local Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96033

Microsoft Windows CVE-2017-0038 Incomplete Fix Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96023

Microsoft Exchange Server CVE-2017-0110 Remote Privilege Escalation Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96621

SAP NetWeaver Visual Composer Denial of Service Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96865

Microsoft Office CVE-2017-0031 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96052

Microsoft Office CVE-2017-0030 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96051

Microsoft Office CVE-2017-0029 Denial of Service Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96045

Microsoft Office CVE-2017-0020 Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96050

Microsoft Office CVE-2017-0027 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96043

Microsoft Windows CVE-2017-0055 Cross Site Scripting Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96622

Foxit Reader and Foxit PhantomPDF CVE-2017-6883 Information Disclosure Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96870

Microsoft Edge CVE-2017-0151 Scripting Engine Remote Memory Corruption Vulnerability
2017-03-15
http://www.securityfocus.com/bid/96727

SANS News

Retro Hunting!

Threatpost

Google Eliminates Android Adfraud Botnet Chamois

JSON Libraries Patched Against Invalid Curve Crypto Attack

FSB Officers, Criminal Hackers Indicted in Yahoo Breach

WhatsApp, Telegram Vulnerabilities Exposed Users to Account Takeover

Patch Tuesday Returns; Microsoft Quiet on Postponement

Google Eliminates Android Adfraud Botnet Chamois

Exploit

Rawether for Windows - Privilege Escalation

ASUS PCE-AC56 WLAN Card Utilities (PCAUSA Rawether Windows 10 x64) - Local...

MikroTik Router - ARP Table OverFlow Denial Of Service

Joomla! Component Vik Appointments 1.5 - SQL Injection

Joomla! Component Vik Rent Items 1.3 - SQL Injection

Joomla! Component Vik Rent Car 1.11 - SQL Injection

Joomla! Component Advertisement Board 3.0.4 - 'id' Parameter SQL Injection

Joomla! Component Simple Membership 3.3.3 - 'userId' Parameter SQL Injection

14.3.2017

Bugtraq

Joomla com_kunena Component - 'id' Parameter Sql Injection Vulnerability 2017-03-14
iedb team gmail com

Joomla com_sngevents Component - 'id' Parameter Sql Injection Vulnerability 2017-03-14
iedb team gmail com

Joomla com_fidecalendar Component - 'aid' Parameter Sql Injection Vulnerability 2017-03-14
iedb team gmail com

Joomla com_registrationpro Component - 'did' Parameter Sql Injection Vulnerability 2017-03-14
iedb team gmail com

Joomla com_easyblog Component - 'id' Parameter Sql Injection Vulnerability 2017-03-14
iedb team gmail com

Atlassian - March 2017 - Bamboo, Crowd and HipChat Server - Critical Security Advisory 2017-03-14
David Black (dblack atlassian com)

[SECURITY] [DSA 3808-1] imagemagick security update 2017-03-13
Moritz Muehlenhoff (jmm debian org)

Malware

TrojanSpy:MSIL/Omaneat

Exp.CVE-2017-2984

Exp.CVE-2017-2982

Phishing

Bank of America

14th March 2017

Bank of America Alert: Your
Online Access is Temporarily
Locked

Card Services Online

14th March 2017

NATWEST CARD SERVICES.

Vulnerebility

SAP ERP Remote Authorization Bypass Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96871

Adobe Flash Player CVE-2017-3000 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96862

Adobe Flash Player CVE-2017-2997 Buffer Overflow Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96860

Trend Micro InterScan Messaging Security CVE-2017-6398 Remote Code Execution Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96859

SAP HANA Cockpit for Offline Administration Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96869

SAP ERP Remote Authorization Bypass Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96867

SAP HANA Unspecified Session Fixation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96864

Adobe Shockwave Player CVE-2017-2983 Local Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96863

Adobe Flash Player APSB17-07 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-03-14
http://www.securityfocus.com/bid/96861

Adobe Flash Player APSB17-07 Multiple Memory Corruption Vulnerabilities
2017-03-14
http://www.securityfocus.com/bid/96866

Adups CVE-2016-10139 Multiple Local Privilege Escalation Vulnerabilities
2017-03-14
http://www.securityfocus.com/bid/96858

Lutim CVE-2017-6877 Cross Site Scripting Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96855

Adups Fota CVE-2016-10138 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96853

Trend Micro Endpoint Sensor CVE-2017-6798 DLL Loading Remote Code Execution Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96857

Pidgin CVE 2017-2640 Out of Bounds Write Security Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96775

Linux kernel CVE-2017-6874 Use After Free Local Denial of Service Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96856

ZoneMinder CVE-2016-10140 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96849

Adups CVE-2016-10136 Local Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96854

Adups CVE-2016-10137 Local Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96852

CodeIgniter 'system/libraries/Email.php' Remote Code Execution Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96851

Multiple LG Android Mobile Devices CVE-2016-10135 Multiple Security Bypass Vulnerabilities
2017-03-14
http://www.securityfocus.com/bid/96846

Hitek Software Automize CVE-2016-10103 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96850

WordPress 'wp_ajax_update_plugin()' Function Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96847

Hitek Software Automize CVE-2016-10104 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96845

Hitek Software Automize CVE-2016-10102 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96848

Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96729

Hitek Software Automize CVE-2016-10101 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96840

Multiple F5 BIG-IP Products CVE-2016-7469 HTML Injection Vulnerability
2017-03-14
http://www.securityfocus.com/bid/95320

Symantec Web Gateway CVE-2016-9096 Multiple Cross Site Scripting Vulnerabilities
2017-03-14
http://www.securityfocus.com/bid/96297

IBM WebSphere Application Server CVE-2017-1151 Remote Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96841Pidgin CVE 2017-2640 Out of Bounds Write Security Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96775

Adups CVE-2016-10136 Local Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96854

Adups CVE-2016-10137 Local Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96852

CodeIgniter 'system/libraries/Email.php' Remote Code Execution Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96851

Multiple LG Android Mobile Devices CVE-2016-10135 Multiple Security Bypass Vulnerabilities
2017-03-14
http://www.securityfocus.com/bid/96846

Hitek Software Automize CVE-2016-10103 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96850

WordPress 'wp_ajax_update_plugin()' Function Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96847

Hitek Software Automize CVE-2016-10104 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96845

Hitek Software Automize CVE-2016-10102 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96848

Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96729

Hitek Software Automize CVE-2016-10101 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96840

Multiple F5 BIG-IP Products CVE-2016-7469 HTML Injection Vulnerability
2017-03-14
http://www.securityfocus.com/bid/95320

Symantec Web Gateway CVE-2016-9096 Multiple Cross Site Scripting Vulnerabilities
2017-03-14
http://www.securityfocus.com/bid/96297

IBM WebSphere Application Server CVE-2017-1151 Remote Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96841

Cybozu KUNAI CVE-2017-2109 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96844

Linux Kernel CVE-2016-8650 Null Pointer Deference Local Denial of Service Vulnerability
2017-03-14
http://www.securityfocus.com/bid/94532

Uninett mod_auth_mellon Module CVE-2017-6807 Authentication Bypass Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96843

Linux Kernel 'net/mac80211/tx.c' Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/70965

ISC BIND CVE-2016-9131 Remote Denial of Service Vulnerability
2017-03-14
http://www.securityfocus.com/bid/95386

Cybozu Kintone App CVE-2016-1185 Unspecified Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96842

NetIQ Self Service Password Reset CVE-2016-1599 Cross Site Scripting Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96837

Linux Kernel CVE-2016-2853 Local Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96839

Linux Kernel CVE-2016-2854 Local Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96838

Google Android MediaTek Video Codec Driver CVE-2017-0532 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96834

Google Nexus Qualcomm Camera Driver CVE-2017-0452 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96836

Google Nexus HTC Sound Codec Driver CVE-2017-0535 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96833

Google Android Kernel USB Gadget Driver CVE-2017-0537 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96831

Google Nexus Qualcomm Camera Driver CVE-2016-8417 Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96832

Google Nexus Synaptics Touchscreen Driver CVE-2017-0536 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96835

IBM Rational Rhapsody Design Manager CVE-2016-9698 XML External Entity Injection Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96829Multiple F5 BIG-IP Products CVE-2016-7469 HTML Injection Vulnerability
2017-03-14
http://www.securityfocus.com/bid/95320

Symantec Web Gateway CVE-2016-9096 Multiple Cross Site Scripting Vulnerabilities
2017-03-14
http://www.securityfocus.com/bid/96297

IBM WebSphere Application Server CVE-2017-1151 Remote Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96841

Cybozu KUNAI CVE-2017-2109 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96844

Linux Kernel CVE-2016-8650 Null Pointer Deference Local Denial of Service Vulnerability
2017-03-14
http://www.securityfocus.com/bid/94532

Uninett mod_auth_mellon Module CVE-2017-6807 Authentication Bypass Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96843

Linux Kernel 'net/mac80211/tx.c' Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/70965

Hitek Software Automize CVE-2016-10101 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96840

ISC BIND CVE-2016-9131 Remote Denial of Service Vulnerability
2017-03-14
http://www.securityfocus.com/bid/95386

Cybozu Kintone App CVE-2016-1185 Unspecified Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96842

NetIQ Self Service Password Reset CVE-2016-1599 Cross Site Scripting Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96837

Linux Kernel CVE-2016-2853 Local Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96839

Linux Kernel CVE-2016-2854 Local Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96838

Google Android MediaTek Video Codec Driver CVE-2017-0532 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96834

Google Nexus Qualcomm Camera Driver CVE-2017-0452 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96836

Google Nexus HTC Sound Codec Driver CVE-2017-0535 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96833

Google Android Kernel USB Gadget Driver CVE-2017-0537 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96831

Google Nexus Qualcomm Camera Driver CVE-2016-8417 Privilege Escalation Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96832

Google Nexus Synaptics Touchscreen Driver CVE-2017-0536 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96835

IBM Rational Rhapsody Design Manager CVE-2016-9698 XML External Entity Injection Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96829

IBM Rational Rhapsody Design Manager CVE-2016-9696 HTML Injection Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96830

IBM Rational Rhapsody Design Manager CVE-2016-8973 Arbitrary File Upload Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96826

IBM Rational Rhapsody Design Manager CVE-2016-9697 Information Disclosure Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96828

Livebox 3 Sagemcom CVE-2017-6552 Local Denial of Service Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96827

Azure Data Expert Ultimate CVE-2017-6506 Buffer Overflow Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96824

IBM Rational Rhapsody Design Manager CVE-2016-9694 Cross Site Scripting Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96825

dnaLIMS Multiple Security Vulnerabilities
2017-03-14
http://www.securityfocus.com/bid/96823

Wireshark 'wiretap/netscaler.c' Denial of Service Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96566

Wireshark WSP Dissector 'tcp_graph.c' Denial of Service Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96564

Wireshark LDSS Dissector 'epan/dissectors/packet-ldss.c' Denial of Service Vulnerability
2017-03-14
http://www.securityfocus.com/bid/96577

SANS News

February and March Microsoft Patch Tuesday

Threatpost

Adobe Fixes Six Code Execution Bugs in Flash

Credit Card Scrapers Continue to Target Magento

38 Android Devices Infected with Malware Preinstalled in Supply Chain

WordPress REST API Bug Could Be Used in Stored XSS Attacks

Exploit

MikroTik Router - ARP Table OverFlow Denial Of Service

VirtualBox - Cooperating VMs can Escape from Shared Folder

Joomla! Component Simple Membership 3.3.3 - 'userId' Parameter SQL Injection

Joomla! Component Advertisement Board 3.0.4 - 'id' Parameter SQL Injection

Car Workshop System - SQL Injection

Fiyo CMS 2.0.6.1 - Privilege Escalation

Cerberus FTP Server 8.0.10.1 - Denial of Service

13.3.2017

Bugtraq

Joomla com_carocci Component - 'isbn' Parameter Sql Injection Vulnerability 2017-03-12
iedb team gmail com

Joomla com_kide Component - 'view' Parameter Sql Injection Vulnerability 2017-03-12
iedb team gmail com

Joomla com_eventlist Component - 'id' Parameter Sql Injection Vulnerability 2017-03-12
iedb team gmail com

[security bulletin] HPESBUX03706 rev.1 - HP-UX NTP service running ntpd, Multiple Vulnerabilities 2017-03-10
security-alert hpe com

[security bulletin] HPESBHF03711 rev.1 - HPE 2620 Series Network Switches, Remote Cross Site Request Forgery (CSRF) 2017-03-10
security-alert hpe com

[security bulletin] HPESBGN03707 rev.1 - HPE ConvergedSystem 700 2.0 VMware Kit, Remote Increase of Privilege 2017-03-10
security-alert hpe com

[security bulletin] HPESBHF03716 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Remote Authentication Bypass 2017-03-10
security-alert hpe com

CVE-2016-10143: Vulnerability to read arbitrary files in "Tiki Wiki" 2017-03-10
Leon Zhao 7 gmail com

Malware

Trojan.Powire

Phishing

Tesco Bank

12th March 2017

TESCO BANK - WAS SUSPENDED DUE
TO A VIOLATION

PayPal

12th March 2017

Your account has been limited
until we hear from you

=?iso-8859-1?Q?R=E9seau_Paix_e

12th March 2017

TR: Nila just sent you
$3,182.00 USD with Paypal.
Paypal recommends to withdraw
it now.

Vulnerebility

Google Android MediaTek Video Codec Driver CVE-2017-0532 Information Disclosure Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96834

Google Nexus Qualcomm Camera Driver CVE-2017-0452 Information Disclosure Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96836

Google Nexus HTC Sound Codec Driver CVE-2017-0535 Information Disclosure Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96833

Google Android Kernel USB Gadget Driver CVE-2017-0537 Information Disclosure Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96831

Google Nexus Qualcomm Camera Driver CVE-2016-8417 Privilege Escalation Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96832

Google Nexus Synaptics Touchscreen Driver CVE-2017-0536 Information Disclosure Vulnerability

IBM Rational Rhapsody Design Manager CVE-2016-9698 XML External Entity Injection Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96829

IBM Rational Rhapsody Design Manager CVE-2016-9696 HTML Injection Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96830

IBM Rational Rhapsody Design Manager CVE-2016-8973 Arbitrary File Upload Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96826

IBM Rational Rhapsody Design Manager CVE-2016-9697 Information Disclosure Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96828

Livebox 3 Sagemcom CVE-2017-6552 Local Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96827

Azure Data Expert Ultimate CVE-2017-6506 Buffer Overflow Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96824

IBM Rational Rhapsody Design Manager CVE-2016-9694 Cross Site Scripting Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96825

dnaLIMS Multiple Security Vulnerabilities
2017-03-13
http://www.securityfocus.com/bid/96823

Wireshark 'wiretap/netscaler.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96566

Wireshark WSP Dissector 'tcp_graph.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96564

Wireshark LDSS Dissector 'epan/dissectors/packet-ldss.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96577

Wireshark NetScaler File Parser 'wiretap/netscaler.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96569

Wireshark IAX2 Dissector 'packet-iax2.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96563

Wireshark RTMPT Dissector 'dissectors/packet-rtmpt.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96571

Wireshark Netscaler File Parser 'netscaler.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96561

Wireshark 'k12.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96565

iBall Baton 150M Wireless Router CVE-2017-6558 Authentication Bypass Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96822

Kinsey Infor-Lawson CVE-2017-6550 Multiple SQL Injection Vulnerabilities
2017-03-13
http://www.securityfocus.com/bid/96821

Evostream Media Server CVE-2017-6427 Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96820

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96378

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96112

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/95999

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-13
http://www.securityfocus.com/bid/95990

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-13
http://www.securityfocus.com/bid/94803

QEMU 'sdhci.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/95885

QEMU 'ehci_init_transfer()' Function Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/94762

QEMU '/hw/usb/redirect.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/94759

QEMU '/hw/net/mcf_fec.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/94638

MantisBT 'view_filters_page.php' Cross Site Scripting Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96819

MantisBT 'bug_change_status_page.php' Cross Site Scripting Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96818

Evostream Media Server CVE-2017-6427 Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96820

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96378

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96112

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/95999

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-13
http://www.securityfocus.com/bid/95990

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-13
http://www.securityfocus.com/bid/94803

QEMU 'sdhci.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/95885

QEMU 'ehci_init_transfer()' Function Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/94762

QEMU '/hw/usb/redirect.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/94759

QEMU '/hw/net/mcf_fec.c' Denial of Service Vulnerability
2017-03-13
http://www.securityfocus.com/bid/94638

MantisBT 'view_filters_page.php' Cross Site Scripting Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96819

MantisBT 'bug_change_status_page.php' Cross Site Scripting Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96818

Roundcube CVE-2017-6820 Cross Site Scripting Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96817

Apache Struts CVE-2017-5638 Remote Code Execution Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96729

icoutils 'extract_icons()' Function Buffer Overflow Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96288

icoutils 'decode_ne_resource_id()' Function Buffer Overflow Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96292

icoutils 'simple_vec()' Function Buffer Overflow Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96267

Juniper Networks IDP Appliance Configuration Manager Cross Site Scripting Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96816

HP Intelligent Management Center CVE-2017-5791 Authentication Bypass Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96815

WordPress Prior to 4.7.3 Cross Site Request Forgery Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96602

WordPress Prior to 4.7.3 Security Bypass Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96598

WordPress Prior to 4.7.3 URL Redirection Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96600

WordPress Prior to 4.7.3 Multiple Cross Site Scripting Vulnerabilities
2017-03-13
http://www.securityfocus.com/bid/96601

FTP Voyager Scheduler CVE-2017-6803 Multiple Cross Site Request Forgery Vulnerabilities
2017-03-13
http://www.securityfocus.com/bid/96814

HP 2620 Series Network Switches CVE-2017-5796 Cross Site Request Forgery Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96813

Symantec Endpoint Protection CVE-2016-9094 Local Command Injection Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96298

Symantec Endpoint Protection Client CVE-2016-9093 Local Privilege Escalation Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96294

Google Pixel Qualcomm Bootloader CVE-2017-0455 Information Disclosure Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96812

Google Android MediaTek Driver CVE-2017-0529 Information Disclosure Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96810

Google Nexus Kernel Security Subsystem CVE-2017-0528 Privilege Escalation Vulnerability
2017-03-13
http://www.securityfocus.com/bid/96807

SANS News

New tool: sigs.py

Honeypot Logs and Tracking a VBE Script

Threatpost

Cody Pierce on the Future of Exploit Development

Telepresence Robots Patched Against Data Leaks

March Android Security Update Breaks SafetyNet, Android Pay

Exploit

Netgear R7000 and R6400 - cgi-bin Command Injection (Metasploit)

Cerberus FTP Server 8.0.10.1 - Denial of Service

Car Workshop System - SQL Injection

Fiyo CMS 2.0.6.1 - Privilege Escalation

11.3.2017

Bugtraq

[security bulletin] HPESBUX03706 rev.1 - HP-UX NTP service running ntpd, Multiple Vulnerabilities 2017-03-10
security-alert hpe com

[security bulletin] HPESBHF03711 rev.1 - HPE 2620 Series Network Switches, Remote Cross Site Request Forgery (CSRF) 2017-03-10
security-alert hpe com

[security bulletin] HPESBGN03707 rev.1 - HPE ConvergedSystem 700 2.0 VMware Kit, Remote Increase of Privilege 2017-03-10
security-alert hpe com

[security bulletin] HPESBHF03716 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Remote Authentication Bypass 2017-03-10
security-alert hpe com

CVE-2016-10143: Vulnerability to read arbitrary files in "Tiki Wiki" 2017-03-10
Leon Zhao 7 gmail com

[SECURITY] [DSA 3805-1] firefox-esr security update 2017-03-09
Moritz Muehlenhoff (jmm debian org)

[security bulletin] HPESBHF03714 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Local Arbitrary File Download 2017-03-08
security-alert hpe com

[SECURITY] [DSA 3804-1] linux security update 2017-03-08
Salvatore Bonaccorso (carnil debian org)

[security bulletin] HPESBHF03713 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Deserialization of Untrusted Data, Remote Code Execution 2017-03-08
security-alert hpe com

Malware

 

Phishing

Gwyneth

11th March 2017

Gwyneth just sent you
$3,182.00 USD with Paypal.
Paypal recommends to withdraw
it now.

Clare

11th March 2017

Clare just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Marsha

11th March 2017

Marsha just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

service@apple.com

11th March 2017

URGENT! Your Apple ID (
howiem@bigfoot.com ) was used
to sign in to iCloud

Vulnerebility

Symantec Endpoint Protection CVE-2016-9094 Local Command Injection Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96298

Symantec Endpoint Protection Client CVE-2016-9093 Local Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96294

Google Pixel Qualcomm Bootloader CVE-2017-0455 Information Disclosure Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96812

Google Android MediaTek Driver CVE-2017-0529 Information Disclosure Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96810

Google Nexus Kernel Security Subsystem CVE-2017-0528 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96807

Google Android Synaptics Touchscreen Driver CVE-2017-0524 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96808

Google Android NVIDIA GPU Driver CVE-2017-0307 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96809

Google Nexus Qualcomm Power Driver CVE-2016-8483 Information Disclosure Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96805

Google Android Audioserver CVE-2017-0499 Denial of Service Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96806

Google Android MediaTek Hardware Sensor Driver CVE-2017-0517 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96799

Google Nexus Kernel FIQ Debugger CVE-2017-0510 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96800

Google Nexus Qualcomm Crypto Engine Driver CVE-2017-0520 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96804

Google Android MediaTek APK CVE-2017-0522 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96798

Google Nexus Qualcomm Input Hardware Driver CVE-2017-0516 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96802

Google Nexus Qualcomm ADSPRPC Driver CVE-2017-0457 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96803

Google Android Mediaserver CVE-2017-0495 Information Disclosure Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96796

Google Nexus Qualcomm GPU Driver CVE-2016-8479 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96801

Google Android Broadcom Wi-Fi Driver CVE-2017-0509 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96797

Google Android Mediaserver CVE-2017-0497 Denial of Service Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96795

Google Android AOSP Messaging CVE-2017-0494 Information Disclosure Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96789

Google Android Setup Wizard CVE-2017-0498 Denial of Service Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96793

Google Android System UI CVE-2017-0492 Remote Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96794

Google Android Location Manager CVE-2017-0489 Remote Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96792

Google Android Package Manager CVE-2017-0491 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96791

Google Android Wi-Fi CVE-2017-0490 Privilege Escalation Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96790

Google Android Setup Wizard CVE-2017-0496 Denial of Service Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96788

Tiki Wiki CMS CVE-2016-10143 Arbitrary File Disclosure Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96787

R Programming Language CVE-2016-8714 Buffer Overflow Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96785

F-Secure Anti-Virus CVE-2017-6466 Remote Code Execution Vulnerability
2017-03-12
http://www.securityfocus.com/bid/96784

WordPress Mail Masta Plugin Multiple SQL Injection Vulnerabilities
2017-03-12
http://www.securityfocus.com/bid/96783Symantec Endpoint Protection CVE-2016-9094 Local Command Injection Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96298

Symantec Endpoint Protection Client CVE-2016-9093 Local Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96294

Google Pixel Qualcomm Bootloader CVE-2017-0455 Information Disclosure Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96812

Google Android MediaTek Driver CVE-2017-0529 Information Disclosure Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96810

Google Nexus Kernel Security Subsystem CVE-2017-0528 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96807

Google Android Synaptics Touchscreen Driver CVE-2017-0524 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96808

Google Android NVIDIA GPU Driver CVE-2017-0307 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96809

Google Nexus Qualcomm Power Driver CVE-2016-8483 Information Disclosure Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96805

Google Android Audioserver CVE-2017-0499 Denial of Service Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96806

Google Android MediaTek Hardware Sensor Driver CVE-2017-0517 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96799

Google Nexus Kernel FIQ Debugger CVE-2017-0510 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96800

Google Nexus Qualcomm Crypto Engine Driver CVE-2017-0520 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96804

Google Android MediaTek APK CVE-2017-0522 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96798

Google Nexus Qualcomm Input Hardware Driver CVE-2017-0516 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96802

Google Nexus Qualcomm ADSPRPC Driver CVE-2017-0457 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96803

Google Android Mediaserver CVE-2017-0495 Information Disclosure Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96796

Google Nexus Qualcomm GPU Driver CVE-2016-8479 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96801

Google Android Broadcom Wi-Fi Driver CVE-2017-0509 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96797

Google Android Mediaserver CVE-2017-0497 Denial of Service Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96795

Google Android AOSP Messaging CVE-2017-0494 Information Disclosure Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96789

Google Android Setup Wizard CVE-2017-0498 Denial of Service Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96793

Google Android System UI CVE-2017-0492 Remote Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96794

Google Android Location Manager CVE-2017-0489 Remote Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96792

Google Android Package Manager CVE-2017-0491 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96791

Google Android Wi-Fi CVE-2017-0490 Privilege Escalation Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96790

Google Android Setup Wizard CVE-2017-0496 Denial of Service Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96788

Tiki Wiki CMS CVE-2016-10143 Arbitrary File Disclosure Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96787

R Programming Language CVE-2016-8714 Buffer Overflow Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96785

F-Secure Anti-Virus CVE-2017-6466 Remote Code Execution Vulnerability
2017-03-11
http://www.securityfocus.com/bid/96784

WordPress Mail Masta Plugin Multiple SQL Injection Vulnerabilities
2017-03-11
http://www.securityfocus.com/bid/96783

SANS News

What's On Your Not To Do List?

Threatpost

 

Exploit

Windows x86 - Hide Console Window Shellcode (182 bytes)

Domain Marketplace Script - SQL Injection

Global In - SQL Injection

Global In - Arbitrary File Upload

Pet Listing Script 3.0 - SQL Injection

10.3.2017

Bugtraq

CVE-2016-10143: Vulnerability to read arbitrary files in "Tiki Wiki" 2017-03-10
Leon Zhao 7 gmail com

[SECURITY] [DSA 3805-1] firefox-esr security update 2017-03-09
Moritz Muehlenhoff (jmm debian org)

[security bulletin] HPESBHF03714 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Local Arbitrary File Download 2017-03-08
security-alert hpe com

[SECURITY] [DSA 3804-1] linux security update 2017-03-08
Salvatore Bonaccorso (carnil debian org)

[security bulletin] HPESBHF03713 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Deserialization of Untrusted Data, Remote Code Execution 2017-03-08
security-alert hpe com

Malware

 

Phishing

Lorrie

10th March 2017

Lorrie just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Bank of America

10th March 2017

Bank of America Alert: Your
Online Access is Temporarily
Locked

Mrs.Helen Smith Shabangu

9th March 2017

PICK UP YOUR FIRST PAYMENT OF
$4,500 USD IN MONEY GRAM

Westpac Bank

9th March 2017

Online Verification

Vulnerebility

Google Android Package Manager CVE-2017-0491 Privilege Escalation Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96791

Google Android Wi-Fi CVE-2017-0490 Privilege Escalation Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96790

Google Android Setup Wizard CVE-2017-0496 Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96788

Tiki Wiki CMS CVE-2016-10143 Arbitrary File Disclosure Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96787

R Programming Language CVE-2016-8714 Buffer Overflow Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96785

F-Secure Anti-Virus CVE-2017-6466 Remote Code Execution Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96784

WordPress Mail Masta Plugin Multiple SQL Injection Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96783

WordPress DTracker Plugin Multiple SQL Injection Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96781

Multiple Cloud Foundry Products CVE-2017-4960 Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96780

Unisys ClearPath MCP CVE-2017-5872 Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96782

gdk-pixbuf Integer Overflow and Denial of Service Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96779

Multiple KDE Products Products Information Disclosure Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96515

LXC 'lxc/lxc_user_nic.c' Remote Privilege Escalation Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96777

ImageMagick CVE-2017-6502 Local Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96763

Linux Kernel 'x86/mm/gup.c' Local Security Bypass Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96776

Pidgin CVE 2017-2640 Out of Bounds Write Security Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96775

HP LoadRunner and Performance Center CVE-2017-5789 Remote Heap Buffer Overflow Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96774

libarchive 'archive_write_set_format_iso9660.c' Integer Overflow Vulnerability
2017-03-10
http://www.securityfocus.com/bid/92036

libarchive Multiple Security Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/93781

libarchive 'lha_read_file_header_1()' Function Memory Corruption Vulnerability
2017-03-10
http://www.securityfocus.com/bid/95837

libarchive CVE-2016-7166 Denial Of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/92901

libarchive CVE-2016-5418 Arbitrary File Write Vulnerability
2017-03-10
http://www.securityfocus.com/bid/93165

Multiple VMware Workstation Products CVE-2017-4900 Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96770

HP Intelligent Management Center CVE-2017-5795 Arbitrary File Download Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96773

Mozilla Firefox and Thunderbird CVE-2017-5401 Memory Corruption Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96677

Multiple VMware Workstation Products CVE-2017-4898 DLL Loading Remote Code Execution Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96772

Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96664

Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96654

Mozilla Firefox and Thunderbird Multiple Security Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96693

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96651Multiple Cloud Foundry Products CVE-2017-4960 Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96780

Unisys ClearPath MCP CVE-2017-5872 Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96782

gdk-pixbuf Integer Overflow and Denial of Service Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96779

Multiple KDE Products Products Information Disclosure Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96515

LXC 'lxc/lxc_user_nic.c' Remote Privilege Escalation Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96777

ImageMagick CVE-2017-6502 Local Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96763

Linux Kernel 'x86/mm/gup.c' Local Security Bypass Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96776

Pidgin CVE 2017-2640 Out of Bounds Write Security Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96775

HP LoadRunner and Performance Center CVE-2017-5789 Remote Heap Buffer Overflow Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96774

libarchive 'archive_write_set_format_iso9660.c' Integer Overflow Vulnerability
2017-03-10
http://www.securityfocus.com/bid/92036

libarchive Multiple Security Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/93781

libarchive 'lha_read_file_header_1()' Function Memory Corruption Vulnerability
2017-03-10
http://www.securityfocus.com/bid/95837

libarchive CVE-2016-7166 Denial Of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/92901

libarchive CVE-2016-5418 Arbitrary File Write Vulnerability
2017-03-10
http://www.securityfocus.com/bid/93165

Multiple VMware Workstation Products CVE-2017-4900 Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96770

HP Intelligent Management Center CVE-2017-5795 Arbitrary File Download Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96773

Mozilla Firefox and Thunderbird CVE-2017-5401 Memory Corruption Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96677

Multiple VMware Workstation Products CVE-2017-4898 DLL Loading Remote Code Execution Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96772

Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96664

Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96654

Mozilla Firefox and Thunderbird Multiple Security Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96693

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96651

Multiple VMware Workstation Products CVE-2017-4899 Out of Bound Read Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96771

HP Intelligent Management Center CVE-2017-5792 Remote Code Execution Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96769

Schneider Electric ClearSCADA CVE-2017-6021 Remote Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96768

Google Chrome Prior to 57.0.2987.98 Multiple Security Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96767

IBM Tivoli System Automation for Multiplatforms Local Privilege Escalation Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96764

IBM Content Navigator CVE-2017-1146 Cross Site Scripting Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96761

Google Android Framesequence Library CVE-2017-0478 Remote Code Execution Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96762

Google Android libgdx CVE-2017-0477 Remote Code Execution Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96760Schneider Electric ClearSCADA CVE-2017-6021 Remote Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96768

Google Chrome Prior to 57.0.2987.98 Multiple Security Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96767

IBM Tivoli System Automation for Multiplatforms Local Privilege Escalation Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96764

IBM Content Navigator CVE-2017-1146 Cross Site Scripting Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96761

Google Android Framesequence Library CVE-2017-0478 Remote Code Execution Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96762

Google Android libgdx CVE-2017-0477 Remote Code Execution Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96760

qBittorrent CVE-2017-6503 Cross Site Scripting Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96758

Linux Kernel CVE-2017-5669 Local Security Bypass Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96754

IBM WebSphere MQ CVE-2017-1145 Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96759

IBM UrbanCode Deploy CVE-2016-9006 Multiple Cross Site Scripting Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96757

Google Android AOSP Messaging CVE-2017-0476 Memory Corruption Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96756

libevent Multiple Security Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96014

HP Intelligent Management Center CVE-2017-5790 Remote Code Execution Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96755

wuhu CVE-2017-6544 Cross Site Scripting Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96751

Multiple D-Link Routers CVE-2017-3193 Stack Buffer Overflow Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96747

Linux Kernel CVE-2017-2636 Local Privilege Escalation Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96732

Linux kernel CVE-2017-6345 Local Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96510

Linux kernel CVE-2017-6346 Use After Free Local Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96508

Linux Kernel CVE-2017-6353 Incomplete Fix Local Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96473

Linux Kernel CVE-2017-6348 Local Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96483

Linux Kernel CVE-2017-6214 Remote Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96421

Linux Kernel 'net/sctp/socket.c' Local Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96222

Linux Kernel 'arch/x86/kvm/vmx.c' Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/94933

Nessus Arbitrary File Upload Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96418

Pharos PopUp Printer Client Multiple Heap Based Buffer Overflow Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96742

IBM Jazz Reporting Service CVE-2015-7464 Denial of Service Vulnerability
2017-03-10
http://www.securityfocus.com/bid/96750

HP Operations Manager CVE-2016-1985 Remote Code Execution Vulnerability
2017-03-10
http://www.securityfocus.com/bid/82259

Google Android Qualcomm Wi-Fi Driver Multiple Information Disclosure Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96743

Google Android Qualcomm Camera Driver Multiple Information Disclosure Vulnerabilities
2017-03-10
http://www.securityfocus.com/bid/96749

Oracle Java SE and JRockit CVE-2017-3252 Remote Security Vulnerability
2017-03-10
http://www.securityfocus.com/bid/95509

SANS News

The Side Effect of GeoIP Filters

Threatpost

Google Chrome 57 Browser Update Patches ‘High’ Severity Flaws

Hundreds of Thousands of Vulnerable IP Cameras Easy Target for Botnet, Researcher Says

Zero Days Have Staying Power

Privilege Escalation Flaw Patched in Schneider Wonderware

Exploit

ASUSWRT RT-AC53 (3.0.0.4.380.6038) - Cross-Site Scripting

ASUSWRT RT-AC53 (3.0.0.4.380.6038) - Session Stealing

ASUSWRT RT-AC53 (3.0.0.4.380.6038) - Remote Code Execution

FTP Voyager Scheduler 16.2.0 - Cross-Site Request Forgery

Country on Sale Script - SQL Injection

Media Search Engine Script - 'search' Parameter SQL Injection

Soundify 1.1 - 'tid' Parameter SQL Injection

9.3.2017

Bugtraq

[security bulletin] HPESBHF03714 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Local Arbitrary File Download 2017-03-08
security-alert hpe com

[SECURITY] [DSA 3804-1] linux security update 2017-03-08
Salvatore Bonaccorso (carnil debian org)

[security bulletin] HPESBHF03713 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Deserialization of Untrusted Data, Remote Code Execution 2017-03-08
security-alert hpe com

[security bulletin] HPESBGN03712 rev.1 - HPE LoadRunner and Performance Center, Remote Code Execution 2017-03-08
security-alert hpe com

SEC Consult SA-20170308-0 :: Multiple vulnerabilities in Navetti PricePoint 2017-03-08
SEC Consult Vulnerability Lab (research sec-consult com)

[slackware-security] mozilla-firefox (SSA:2017-066-01) 2017-03-08
Slackware Security Team (security slackware com)

Malware

Misleading:Win32/Vigorf.A

Trojan.Stonedrill

Trojan.Powire

Phishing

Westpac Bank

9th March 2017

Online Verification

Online® ID Team

8th March 2017

Mail Suspended!

Support

8th March 2017

UPDATE YOUR ACCOUNT
INFORMATION

Farah

7th March 2017

Farah just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Vulnerebility

Google Android AOSP Messaging CVE-2017-0476 Memory Corruption Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96756

libevent Multiple Security Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96014

HP Intelligent Management Center CVE-2017-5790 Remote Code Execution Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96755

wuhu CVE-2017-6544 Cross Site Scripting Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96751

Multiple D-Link Routers CVE-2017-3193 Stack Buffer Overflow Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96747

Linux Kernel CVE-2017-2636 Local Privilege Escalation Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96732

Linux kernel CVE-2017-6345 Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96510

Linux kernel CVE-2017-6346 Use After Free Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96508

Linux Kernel CVE-2017-6353 Incomplete Fix Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96473

Linux Kernel CVE-2017-6348 Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96483

Linux Kernel CVE-2017-6214 Remote Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96421

Linux Kernel 'net/sctp/socket.c' Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96222

Linux Kernel 'arch/x86/kvm/vmx.c' Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/94933

Nessus Arbitrary File Upload Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96418

Pharos PopUp Printer Client Multiple Heap Based Buffer Overflow Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96742

IBM Jazz Reporting Service CVE-2015-7464 Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96750

HP Operations Manager CVE-2016-1985 Remote Code Execution Vulnerability
2017-03-09
http://www.securityfocus.com/bid/82259

Google Android Qualcomm Wi-Fi Driver Multiple Information Disclosure Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96743

Google Android Qualcomm Camera Driver Multiple Information Disclosure Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96749

Oracle Java SE and JRockit CVE-2017-3252 Remote Security Vulnerability
2017-03-09
http://www.securityfocus.com/bid/95509

Pharos PopUp Printer Client CVE-2017-2787 Heap Based Buffer Overflow Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96738

Drupal Services Module Remote Code Execution Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96744

Drupal Password Reset Landing Page Module Access Bypass Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96739

Netpbm CVE-2017-2587 Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96702

Netpbm CVE-2017-2586 Null Pointer Dereference Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96708

Netpbm CVE-2017-2579 Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96714

Netpbm CVE-2017-2581 Local Integer Overflow Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96710

Netpbm CVE-2017-2580 Local Heap Buffer Overflow Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96712

Pharos PopUp Printer Client CVE-2017-2786 Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96736

Oracle Java SE CVE-2017-3259 Remote Security Vulnerability
2017-03-09
http://www.securityfocus.com/bid/95570Google Android NVIDIA GPU Driver Multiple Privilege Escalation Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96723

Google Android MediaTek Components Multiple Privilege Escalation Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96726

Schneider Electric Wonderware Intelligence Default Credentials Security Bypass Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96721

Flash Seats for iOS CVE-2017-3190 SSL Certificate Validation Security Bypass Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96719

Google Android Recovery Verifier CVE-2017-0475 Privilege Escalation Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96716

ACTi Cameras Models Multiple Security Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96720

PHP FormMail Generator Cross Site Scripting and Arbitrary File Upload Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96718

OpenSSL 'BN_bn2dec()' Function Out of Bounds Write Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/92557

Google Android Mediaserver Multiple Remote Code Execution Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96717

Netpbm CVE-2017-2579 Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96714

Netpbm CVE-2017-2581 Local Integer Overflow Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96710

Netpbm CVE-2017-2580 Local Heap Buffer Overflow Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96712

Netpbm CVE-2017-2586 Null Pointer Dereference Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96708

Netpbm CVE-2017-2587 Local Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96702

Mozilla Firefox CVE-2017-5409 Arbitrary File Deletion Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96696

Mozilla Firefox and Thunderbird Multiple Security Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96693

Mozilla Firefox CVE-2017-5426 Security Bypass Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96694

Mozilla Firefox MFSA 2017-05 Multiple Security Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96692

Mozilla Firefox CVE-2017-5403 Denial of Service Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96691

Mozilla Firefox and Thunderbird CVE-2017-5401 Memory Corruption Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96677

Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96664

Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96654

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96651

BlackBerry Good Control Server CVE-2016-3127 Information Disclosure Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96629

IBM WebSphere Commerce CVE-2016-5894 Local Information Disclosure Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96624

Multiple IBM DB2 Products CVE-2017-1150 Information Disclosure Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96597

Multiple I-O DATA Network Camera Products Multiple Security Vulnerabilities
2017-03-09
http://www.securityfocus.com/bid/96620

CloudFlare Information Disclosure Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96617

Access CX App CVE-2017-2110 SSL Certificate Validation Security Bypass Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96615

OneThird CMS CVE-2017-2123 Cross Site Scripting Vulnerability
2017-03-09
http://www.securityfocus.com/bid/96613

SANS News

Critical Apache Struts 2 Vulnerability (Patch Now!)

Threatpost

Firefox 52 Expands Non-Secure HTTP Warnings, Enables SHA-1 Deprecation

Confide Updates App After Critical Security Issues Are Raised

Senator Demands Answers About CloudPets Breach

Attacks Heating Up Against Apache Struts 2 Vulnerability

Exploit

Country on Sale Script - SQL Injection

Media Search Engine Script - 'search' Parameter SQL Injection

Soundify 1.1 - 'tid' Parameter SQL Injection

BistroStays 3.0 - 'guests' Parameter SQL Injection

Nlance 2.2 - SQL Injection

Busewe 1.2 - SQL Injection

Fashmark 1.2 - 'category' Parameter SQL Injection

8.3.2017

Bugtraq

[security bulletin] HPESBHF03713 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Deserialization of Untrusted Data, Remote Code Execution 2017-03-08
security-alert hpe com

[security bulletin] HPESBGN03712 rev.1 - HPE LoadRunner and Performance Center, Remote Code Execution 2017-03-08
security-alert hpe com

SEC Consult SA-20170308-0 :: Multiple vulnerabilities in Navetti PricePoint 2017-03-08
SEC Consult Vulnerability Lab (research sec-consult com)

[slackware-security] mozilla-firefox (SSA:2017-066-01) 2017-03-08
Slackware Security Team (security slackware com)

Multiple vulnerabilities found in Wireless IP Camera (P2P) WIFICAM cameras and vulnerabilities in GoAhead 2017-03-08
Pierre Kim (pierre kim sec gmail com)

[security bulletin] HPESBHF03710 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Multiple Remote Vulnerabilities 2017-03-07
security-alert hpe com

Stack-based buffer overflow in Western Digital My Cloud allows for remote code execution 2017-03-07
Securify B.V. (lists securify nl)

SEC Consult SA-20170307-0 :: Unauthenticated OS command injection & arbitrary file upload in Western Digital WD My Cloud 2017-03-07
SEC Consult Vulnerability Lab (research sec-consult com)

Malware

 

Phishing

Farah

7th March 2017

Farah just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Audrina

7th March 2017

Audrina just sent you
$3,182.00 USD with Paypal.
Paypal recommends to withdraw
it now.

Vulnerebility

Mozilla Firefox MFSA 2017-05 Multiple Security Vulnerabilities
2017-03-08
http://www.securityfocus.com/bid/96692

Mozilla Firefox CVE-2017-5403 Denial of Service Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96691

Mozilla Firefox and Thunderbird CVE-2017-5401 Memory Corruption Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96677

Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-03-08
http://www.securityfocus.com/bid/96664

Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-03-08
http://www.securityfocus.com/bid/96654

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-03-08
http://www.securityfocus.com/bid/96651

BlackBerry Good Control Server CVE-2016-3127 Information Disclosure Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96629

IBM WebSphere Commerce CVE-2016-5894 Local Information Disclosure Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96624

Multiple IBM DB2 Products CVE-2017-1150 Information Disclosure Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96597

Multiple I-O DATA Network Camera Products Multiple Security Vulnerabilities
2017-03-08
http://www.securityfocus.com/bid/96620

CloudFlare Information Disclosure Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96617

Access CX App CVE-2017-2110 SSL Certificate Validation Security Bypass Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96615

OneThird CMS CVE-2017-2123 Cross Site Scripting Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96613

Trend Micro SafeSync for Enterprise Multiple Security Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96612

PrimeDrive Desktop Application Installer DLL Loading Remote Code Execution Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96619

dotCMS VU#168699 Multiple Security Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96616

IBM QRadar SIEM CVE-2016-2880 Local Hardcoded Credentials Information Disclosure Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96614

QEMU 'hw/usb/hcd-ohci.c' Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96611

Ansible CVE-2016-9587 Arbitrary Command Execution Vulnerability
2017-03-07
http://www.securityfocus.com/bid/95352

Multiple AlienVault Products Authentication Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93043

WordPress Prior to 4.7.3 Cross Site Request Forgery Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96602

WordPress Prior to 4.7.3 Multiple Cross Site Scripting Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96601

Linux Kernel CVE-2016-9083 Local Integer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93929

Linux Kernel CVE-2016-8655 Local Race Condition Vulnerability
2017-03-07
http://www.securityfocus.com/bid/94692

Linux Kernel 'kvm/emulate.c' Null Pointer Dereference Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/94459

Linux Kernel Vfio Driver CVE-2016-9084 Integer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93930

WordPress Prior to 4.7.3 URL Redirection Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96600

WordPress Prior to 4.7.3 Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96598

Symantec Endpoint Protection CVE-2016-9094 Local Command Injection Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96298

Symantec Endpoint Protection Client CVE-2016-9093 Local Privilege Escalation Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96294
Mozilla Firefox and Thunderbird Multiple Use After Free Denial of Service Vulnerabilities
2017-03-08
http://www.securityfocus.com/bid/96664

Mozilla Firefox and Thunderbird CVE-2017-5400 Multiple Memory-Corruption Vulnerabilities
2017-03-08
http://www.securityfocus.com/bid/96654

Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities
2017-03-08
http://www.securityfocus.com/bid/96651

BlackBerry Good Control Server CVE-2016-3127 Information Disclosure Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96629

IBM WebSphere Commerce CVE-2016-5894 Local Information Disclosure Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96624

Multiple IBM DB2 Products CVE-2017-1150 Information Disclosure Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96597

Multiple I-O DATA Network Camera Products Multiple Security Vulnerabilities
2017-03-08
http://www.securityfocus.com/bid/96620

CloudFlare Information Disclosure Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96617

Access CX App CVE-2017-2110 SSL Certificate Validation Security Bypass Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96615

OneThird CMS CVE-2017-2123 Cross Site Scripting Vulnerability
2017-03-08
http://www.securityfocus.com/bid/96613

Trend Micro SafeSync for Enterprise Multiple Security Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96612

PrimeDrive Desktop Application Installer DLL Loading Remote Code Execution Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96619

dotCMS VU#168699 Multiple Security Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96616

IBM QRadar SIEM CVE-2016-2880 Local Hardcoded Credentials Information Disclosure Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96614

QEMU 'hw/usb/hcd-ohci.c' Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96611

Ansible CVE-2016-9587 Arbitrary Command Execution Vulnerability
2017-03-07
http://www.securityfocus.com/bid/95352

Multiple AlienVault Products Authentication Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93043

WordPress Prior to 4.7.3 Cross Site Request Forgery Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96602

WordPress Prior to 4.7.3 Multiple Cross Site Scripting Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96601

Linux Kernel CVE-2016-9083 Local Integer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93929

Linux Kernel CVE-2016-8655 Local Race Condition Vulnerability
2017-03-07
http://www.securityfocus.com/bid/94692

Linux Kernel 'kvm/emulate.c' Null Pointer Dereference Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/94459

Linux Kernel Vfio Driver CVE-2016-9084 Integer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93930

WordPress Prior to 4.7.3 URL Redirection Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96600

WordPress Prior to 4.7.3 Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96598

Symantec Endpoint Protection CVE-2016-9094 Local Command Injection Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96298

Symantec Endpoint Protection Client CVE-2016-9093 Local Privilege Escalation Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96294

OpenBSD Man in the Middle Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96596

JasPer 'jpc_dec.c' Null Pointer Dereference Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96595

TeX Live CVE-2016-10243 Remote Code Execution Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96593

SANS News

Not All Malware Samples Are Complex

Threatpost

Dahua Patching Backdoor in DVRs, IP Cameras

Unpatched Western Digital Bugs Leave NAS Boxes Open to Attack

WordPress 4.7.3 Patches Half-Dozen Vulnerabilities

Exploit

USBPcap - Privilege Escalation

Themeforest Clone Script - SQL Injection

Graphicriver Clone Script - SQL Injection

Codecanyon Clone Script - SQL Injection

Audiojungle Clone Script - SQL Injection

Videohive Clone Script - SQL Injection

Azure Data Expert Ultimate 2.2.16 - Buffer Overflow

Themeforest Clone Script - SQL Injection

Graphicriver Clone Script - SQL Injection

Mini CMS 1.1 - 'name' Parameter SQL Injection

Daily Deals Script 1.0 - 'id' Parameter SQL Injection

Bull/IBM AIX Clusterwatch/Watchware - Multiple Vulnerabilities

Evostream Media Server 1.7.1 (x64) - Denial of Service

7.3.2017

Bugtraq

Stack-based buffer overflow in Western Digital My Cloud allows for remote code execution 2017-03-07
Securify B.V. (lists securify nl)

SEC Consult SA-20170307-0 :: Unauthenticated OS command injection & arbitrary file upload in Western Digital WD My Cloud 2017-03-07
SEC Consult Vulnerability Lab (research sec-consult com)

WordPress audio playlist functionality is affected by Cross-Site Scripting 2017-03-06
Summer of Pwnage (lists securify nl)

EasyCom PHP API Stack Buffer Overflow 2017-03-06
apparitionsec gmail securityfocus com (hyp3rlinx)

Sawmill Enterprise v8.7.9 Pass The Hash Authentication Bypass 2017-03-06
apparitionsec gmail securityfocus com (hyp3rlinx)

Malware

W32.Disttrack.C

Phishing

Audrina

7th March 2017

Audrina just sent you
$3,182.00 USD with Paypal.
Paypal recommends to withdraw
it now.

Louise

6th March 2017

Louise just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Lara

6th March 2017

Lara just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Vulnerebility

Linux Kernel Local Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/92659

Linux Kernel 'kernel/process.c' Local Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/91415

Linux Kernel CVE-2016-6480 Local Information Disclosure Vulnerability
2017-03-07
http://www.securityfocus.com/bid/92214

Linux Kernel CVE-2016-6130 Local Information Disclosure Vulnerability
2017-03-07
http://www.securityfocus.com/bid/91540

Linux Kernel 'tcp_xmit_retransmit_queue()' Function Use After Free Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/92452

Linux Kernel 'usbhid/hiddev.c' Local Heap Buffer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/91450

Linux Kernel Multiple Local Memory Corruption Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/91451

Linux kernel 'key_reject_and_link()' Function Local Use After Free Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/91211

Cisco Prime Collaboration Assurance CVE-2017-3844 Information Disclosure Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96247

OpenStack qemu-imge CVE-2015-5162 Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/76849

ISC BIND CVE-2017-3135 Remote Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96150

w3m Multiple Security Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/94407

Cisco Unified Communications Manager CVE-2017-3833 Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96246

Cisco Prime Collaboration Assurance CVE-2017-3845 Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96245

libevent Multiple Security Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96014

Multiple Hughes Satellite Modems VU#614751 Multiple Security Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96244

Adobe Flash Player APSB17-04 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96199

Adobe Flash Player APSB17-04 Multiple Heap Buffer Overflow Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96193

Adobe Flash Player APSB17-04 Multiple Unspecified Memory Corruption Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96190

Adobe Flash Player CVE-2017-2995 Type Confusion Remote Code Execution Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96191

Adobe Flash Player CVE-2017-2987 Unspecified Integer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96194

Cisco Meeting Server CVE-2017-3837 Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96243

Cisco Unified Communications Manager CVE-2017-3821 Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96241

Cisco AsyncOS for Email and Web Security Appliances Remote Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96239

Cisco Meeting Server CVE-2017-3830 Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96242

Cisco Secure Access Control System CVE-2017-3841 Information Disclosure Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96237

Cisco Unified Communications Manager CVE-2017-3828 Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96240

Cisco Secure Access Control System CVE-2017-3840 Open Redirection Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96238

Cisco Secure Access Control System XML External Entity Information Disclosure Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96236

Cisco Secure Access Control System CVE-2017-3838 Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96234Ansible CVE-2016-9587 Arbitrary Command Execution Vulnerability
2017-03-07
http://www.securityfocus.com/bid/95352

Multiple AlienVault Products Authentication Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93043

WordPress Prior to 4.7.3 Multiple Cross Site Scripting Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96601

Linux Kernel CVE-2016-9083 Local Integer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93929

Linux Kernel CVE-2016-8655 Local Race Condition Vulnerability
2017-03-07
http://www.securityfocus.com/bid/94692

Linux Kernel 'kvm/emulate.c' Null Pointer Dereference Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/94459

Linux Kernel Vfio Driver CVE-2016-9084 Integer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93930

WordPress Prior to 4.7.3 URL Redirection Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96600

WordPress Prior to 4.7.3 Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96598

Symantec Endpoint Protection CVE-2016-9094 Local Command Injection Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96298

Symantec Endpoint Protection Client CVE-2016-9093 Local Privilege Escalation Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96294

Multiple IBM DB2 Products CVE-2017-1150 Information Disclosure Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96597

OpenBSD Man in the Middle Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96596

JasPer 'jpc_dec.c' Null Pointer Dereference Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96595

TeX Live CVE-2016-10243 Remote Code Execution Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96593

ImageMagick 'coders/psd.c' Local Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96594

ImageMagick 'coders/sun.c' Local Heap Buffer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96592

FenixHosting fenix-open-source 'forums/search.php' Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96587

ImageMagick CVE-2017-6499 Local Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96590

WePresent WiPG-1500 Device CVE-2017-6351 Hardcoded Password Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96588

ImageMagick CVE-2017-6498 Local Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96591

ImageMagick CVE-2017-6501 Local Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96589

OpenElec CVE-2017-6445 Man in the Middle Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96580

Wireshark LDSS Dissector 'epan/dissectors/packet-ldss.c' Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96577

EPESI CVE-2017-6487 Multiple Cross Site Scripting Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96586

MaNGOSWebV4 CVE-2017-6478 Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96584

Groovel CVE-2017-6480 Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96585

Dotclear CVE-2017-6446 Multiple Cross Site Scripting Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96575

mcollective-puppet-agent CVE-2017-2290 Privilege Escalation Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96583

Ettercap CVE-2017-6430 Out of Bounds Read Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96582

Linux Kernel CVE-2016-9083 Local Integer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93929

Linux Kernel CVE-2016-8655 Local Race Condition Vulnerability
2017-03-07
http://www.securityfocus.com/bid/94692

Linux Kernel 'kvm/emulate.c' Null Pointer Dereference Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/94459

Linux Kernel Vfio Driver CVE-2016-9084 Integer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/93930

Symantec Endpoint Protection CVE-2016-9094 Local Command Injection Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96298

Symantec Endpoint Protection Client CVE-2016-9093 Local Privilege Escalation Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96294

Multiple IBM DB2 Products CVE-2017-1150 Information Disclosure Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96597

OpenBSD Man in the Middle Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96596

JasPer 'jpc_dec.c' Null Pointer Dereference Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96595

TeX Live CVE-2016-10243 Remote Code Execution Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96593

ImageMagick 'coders/psd.c' Local Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96594

ImageMagick 'coders/sun.c' Local Heap Buffer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96592

FenixHosting fenix-open-source 'forums/search.php' Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96587

ImageMagick CVE-2017-6499 Local Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96590

WePresent WiPG-1500 Device CVE-2017-6351 Hardcoded Password Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96588

ImageMagick CVE-2017-6498 Local Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96591

ImageMagick CVE-2017-6501 Local Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96589

OpenElec CVE-2017-6445 Man in the Middle Security Bypass Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96580

Wireshark LDSS Dissector 'epan/dissectors/packet-ldss.c' Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96577

EPESI CVE-2017-6487 Multiple Cross Site Scripting Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96586

MaNGOSWebV4 CVE-2017-6478 Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96584

Groovel CVE-2017-6480 Cross Site Scripting Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96585

Dotclear CVE-2017-6446 Multiple Cross Site Scripting Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96575

mcollective-puppet-agent CVE-2017-2290 Privilege Escalation Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96583

Ettercap CVE-2017-6430 Out of Bounds Read Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96582

Irssi CVE-2017-5356 Denial of Service Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96581

ATutor CVE-2017-6483 Multiple Cross Site Scripting Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96578

Tcpreplay 'Tcpcapinfo' Utility CVE-2017-6429 Buffer Overflow Vulnerability
2017-03-07
http://www.securityfocus.com/bid/96579

OpenEMR CVE-2017-6482 Multiple Cross Site Scripting Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96576

phpipam CVE-2017-6481 Multiple Cross Site Scripting Vulnerabilities
2017-03-07
http://www.securityfocus.com/bid/96573

SANS News

A very convincing Typosquatting + Social Engineering campaign is targeting Santander corporate customers in Brazil

Threatpost

Spammer’s Leaky Backup Exposes Massive Empire

DOJ Dismisses Playpen Case to Keep Tor Hack Private

Active Defense Bill Raises Concerns Of Potential Consequences

Exploit

Mini CMS 1.1 - 'name' Parameter SQL Injection

Daily Deals Script 1.0 - 'id' Parameter SQL Injection

6.3.2017

Bugtraq

EasyCom PHP API Stack Buffer Overflow 2017-03-06
apparitionsec gmail securityfocus com (hyp3rlinx)

Sawmill Enterprise v8.7.9 Pass The Hash Authentication Bypass 2017-03-06
apparitionsec gmail securityfocus com (hyp3rlinx)

CVE-2016-7955 - Alienvault OSSIM/USM Authentication Bypass 2017-03-06
Peter Lapp (lappsec gmail com)

CVE-2017-6430: Out-of-Bounds Read (DOS) Vulnerability in Ettercap Etterfilter utility 2017-03-06
ddos2me gmail com

OpenElec: Remote Code Execution Vulnerability through Man-In-The-Middle(CVE-2017-6445) 2017-03-06
Wolfgang (lister feedyourhead at)

CVE-2017-6429: Buffer overflow vulnerability in Tcpreplay tcpcapinfo utility 2017-03-06
ddos2me gmail com

EasyCom SQL iPlug Denial Of Service 2017-03-04
apparitionsec gmail com (hyp3rlinx)

Malware

 

Phishing

support

6th March 2017

your account will be limited
please update your information

CableTV

6th March 2017

Get more channels than ever
before with cable.

Katharine

5th March 2017

Katharine just sent you
$3,182.00 USD with Paypal.
Paypal recommends to withdraw
it now.

Vulnerebility

EPESI CVE-2017-6487 Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96586

MaNGOSWebV4 CVE-2017-6478 Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96584

Groovel CVE-2017-6480 Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96585

Dotclear CVE-2017-6446 Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96575

mcollective-puppet-agent CVE-2017-2290 Privilege Escalation Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96583

Ettercap CVE-2017-6430 Out of Bounds Read Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96582

Irssi CVE-2017-5356 Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96581

ATutor CVE-2017-6483 Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96578

Tcpreplay 'Tcpcapinfo' Utility CVE-2017-6429 Buffer Overflow Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96579

OpenEMR CVE-2017-6482 Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96576

phpipam CVE-2017-6481 Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96573

SilverStripe CMS CVE-2017-5197 Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96572

FTPShell Client CVE-2017-6465 Buffer Overflow Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96570

SysGauge CVE-2017-6416 Buffer Overflow Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96568

Wireshark NetScaler File Parser 'wiretap/netscaler.c' Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96569

Wireshark RTMPT Dissector 'dissectors/packet-rtmpt.c' Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96571

Wireshark 'wiretap/netscaler.c' Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96566

Piwik Remote Code Execution Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96567

Wireshark WSP Dissector 'tcp_graph.c' Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96564

sysPass CVE-2017-5999 Cryptographic Security Bypass Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96562

Wireshark 'k12.c' Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96565

Wireshark IAX2 Dissector 'packet-iax2.c' Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96563

Wireshark Netscaler File Parser 'netscaler.c' Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96561

rubyzip CVE-2017-5946 Directory Traversal Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96445

Linux Kernel CVE-2016-8655 Local Race Condition Vulnerability
2017-03-06
http://www.securityfocus.com/bid/94692

Linux Kernel CVE-2016-9083 Local Integer Overflow Vulnerability
2017-03-06
http://www.securityfocus.com/bid/93929

Linux Kernel Vfio Driver CVE-2016-9084 Integer Overflow Vulnerability
2017-03-06
http://www.securityfocus.com/bid/93930

Linux Kernel 'kvm/emulate.c' Null Pointer Dereference Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/94459

D-Link DSL-2730U CVE-2017-6411 Cross Site Request Forgery Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96560

VMware Horizon DaaS CVE-2017-4897 Security Bypass Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96559Zabbix CVE-2016-10134 SQL Injection Vulnerability
2017-03-06
http://www.securityfocus.com/bid/95423

EPSON TMNet WebConfig CVE-2017-6443 Multiple HTML Injection Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96556

FreeIPA CVE-2017-2590 Multiple Security Bypass Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96557

WordPress fast-image-adder Plugin CVE-2015-1000001 Arbitrary File Upload Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96554

Soruly whatanime.ga CVE-2017-6390 Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96555

Atheme IRC Services CVE-2017-6384 Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96552

FlightAirMap CVE-2017-6397 Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96551

WPO-Foundation WebPageTest CVE-2017-6396 Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96553

Remember Me Module DRUPAL-SA-CONTRIB-2017-025 Unspecified Security Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96546

Ping Identity 'mod_auth_openidc' Module CVE-2017-6413 Authentication Bypass Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96549

Rapid7 Metasploit Pro CVE-2017-5235 DLL Loading Remote Code Execution Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96548

HashOver CVE-2017-6395 Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96550

Rapid7 Insight Collector CVE-2017-5234 DLL Loading Remote Code Execution Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96545

WordPress Mobile App Plugin CVE-2017-6104 Arbitrary File Upload Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96547

Multiple KDE Products Products Information Disclosure Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96515

ImageMagick CVE-2017-6335 Local Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96544

Eaton xComfort Ethernet Communication Interface CVE-2017-9368 Information Disclosure Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96542

IBM Development Package for Apache Spark CVE-2016-4970 Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96540

Schneider Electric Conext ComBox CVE-2017-6019 Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96543

NagVis 'share/userfiles/gadgets/std_table.php' Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96537

Multiple Siemens Products CVE-2017-2685 Man in the Middle Security Bypass Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96519

OpenEMR CVE-2017-6394 Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96539

Multiple IBM Products CVE-2017-1124 Local Information Disclosure Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96536

QEMU '/src/card_7816.c' Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96541

w3m Multiple Security Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/94407

w3m Multiple Security Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/94464

WordPress AnyVar Plugin CVE-2017-6103 Multiple HTML Injection Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96532

IBM QRadar SIEM CVE-2016-9729 Authentication Bypass Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96538

WordPress rockhoist-badges Plugin CVE-2017-6102 HTML Injection Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96533

Kaltura server Lynx Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96534WordPress fast-image-adder Plugin CVE-2015-1000001 Arbitrary File Upload Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96554

Soruly whatanime.ga CVE-2017-6390 Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96555

Atheme IRC Services CVE-2017-6384 Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96552

FlightAirMap CVE-2017-6397 Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96551

WPO-Foundation WebPageTest CVE-2017-6396 Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96553

Remember Me Module DRUPAL-SA-CONTRIB-2017-025 Unspecified Security Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96546

Ping Identity 'mod_auth_openidc' Module CVE-2017-6413 Authentication Bypass Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96549

Rapid7 Metasploit Pro CVE-2017-5235 DLL Loading Remote Code Execution Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96548

HashOver CVE-2017-6395 Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96550

Rapid7 Insight Collector CVE-2017-5234 DLL Loading Remote Code Execution Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96545

WordPress Mobile App Plugin CVE-2017-6104 Arbitrary File Upload Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96547

Multiple KDE Products Products Information Disclosure Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96515

ImageMagick CVE-2017-6335 Local Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96544

Eaton xComfort Ethernet Communication Interface CVE-2017-9368 Information Disclosure Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96542

IBM Development Package for Apache Spark CVE-2016-4970 Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96540

Schneider Electric Conext ComBox CVE-2017-6019 Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96543

NagVis 'share/userfiles/gadgets/std_table.php' Cross Site Scripting Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96537

Multiple Siemens Products CVE-2017-2685 Man in the Middle Security Bypass Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96519

OpenEMR CVE-2017-6394 Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96539

Multiple IBM Products CVE-2017-1124 Local Information Disclosure Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96536

QEMU '/src/card_7816.c' Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96541

w3m Multiple Security Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/94407

w3m Multiple Security Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/94464

WordPress AnyVar Plugin CVE-2017-6103 Multiple HTML Injection Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96532

IBM QRadar SIEM CVE-2016-9729 Authentication Bypass Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96538

WordPress rockhoist-badges Plugin CVE-2017-6102 HTML Injection Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96533

Kaltura server Lynx Multiple Cross Site Scripting Vulnerabilities
2017-03-06
http://www.securityfocus.com/bid/96534

IBM QRadar SIEM CVE-2016-9740 Denial of Service Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96535

IBM QRadar SIEM CVE-2016-9725 Information Disclosure Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96530

IBM QRadar SIEM and Incident Forensics CVE-2016-9720 Information Disclosure Vulnerability
2017-03-06
http://www.securityfocus.com/bid/96531

SANS News

Another example of maldoc string obfuscation, with extra bonus: UAC bypass

A very convincing Typosquatting + Social Engineering campaign is targeting Santander corporate customers in Brazil

Threatpost

Bruce Schneier on IoT Regulation

Exploit

Conext ComBox 865-1058 - Denial of Service

CyberGhost 6.0.4.2205 - Privilege Escalation

FTPShell Client 6.53 - Buffer Overflow

Advanced Bus Booking Script 2.04 - SQL Injection

Entrepreneur Bus Booking Script 3.03 - 'hid_Busid' Parameter SQL Injection

Single Theater Booking Script - 'newsid' Parameter SQL Injection

Responsive Events & Movie Ticket Booking Script - SQL Injection

Online Cinema and Event Booking Script 2.01 - 'newsid' Parameter SQL Injection

Redbus Clone Script 3.05 - 'hid_Busid' Parameter SQL Injection

Groupon Clone Script 3.01 - 'catid' Parameter SQL Injection

Naukri Clone Script 3.02 - 'type' Parameter SQL Injection

Yellow Pages Clone Script 1.3.4 - SQL Injection

Advanced Matrimonial Script 2.0.3 - SQL Injection

Advanced Real Estate Script 4.0.6 - SQL Injection

PHP Classifieds Rental Script 3.6.0 - 'scatid' Parameter SQL Injection

Entrepreneur B2B Script 2.0.4 - 'id' Parameter SQL Injection

PHP Matrimonial Script 3.0 - SQL Injection

MLM Binary Plan Script 2.0.5 - SQL Injection

MLM Forced Matrix 2.0.7 - SQL Injection

MLM Forex Market Plan Script 2.0.1 - SQL Injection

MLM Membership Plan Script 2.0.5 - SQL Injection

Multireligion Responsive Matrimonial Script 4.7.1 - SQL Injection

Network Community Script 3.0.2 - SQL Injection

PHP B2B Script 3.05 - SQL Injection

Responsive Matrimonial Script 4.0.1 - SQL Injection

Schools Alert Management Script 2.01 - 'list_id' Parameter SQL Injection

Select Your College Script 2.01 - SQL Injection

Social Network Script 3.01 - 'id' Parameter SQL Injection

Website Broker Script 3.02 - 'view' Parameter SQL Injection

Linux/x86-64 - Polymorphic Flush IPTables Shellcode (47 bytes)

Linux/x86-64 - NetCat Reverse Shell Shellcode (72 bytes)

Linux/x86-64 - Polymorphic NetCat Reverse Shell Shellcode (106 bytes)

EPSON TMNet WebConfig 1.00 - Cross-Site Scripting

Joomla! Component JUX EventOn 1.0.1 - 'id' Parameter SQL Injection

Joomla! Component Monthly Archive 3.6.4 - 'author_form' Parameter SQL Injection

Joomla! Component AltaUserPoints 1.1 - 'userid' Parameter SQL Injection

Joomla! Component Content ConstructionKit 1.1 - SQL Injection

Joomla! Component AYS Quiz 1.0 - 'id' Parameter SQL Injection

4.3.2017

Bugtraq

 

Malware

SupportScam:JS/TechBrolo
SupportScam:JS/TechBrolo.A

JS/TechBrolo

Backdoor.Oliner

Phishing

auto-confirm-amazon.co.uk

3rd March 2017

Your Amazon.co.uk order
"Online Rental Movies.."

Tesco

3rd March 2017

BAG YOURSELF £300 OF TESCO
VOUCHERS!

Amazon

3rd March 2017

Customer Service: Important
account information

Chase

3rd March 2017

Irregular Activity

Apple Service

2nd March 2017

YOUR RECEIPT FROM APPLE STORE

Paypal inc

2nd March 2017

TEMPORARILY UNABLE TO LOAD
YOUR ACCOUNT

Vulnerebility

Linux Kernel Multiple Information Disclosure Vulnerabilities
2017-03-05
http://www.securityfocus.com/bid/94138

Linux Kernel CVE-2016-9083 Local Integer Overflow Vulnerability
2017-03-05
http://www.securityfocus.com/bid/93929

Broadcom Wifi Driver 'brcmf_cfg80211_start_ap()' Function Stack Buffer Overflow Vulnerability
2017-03-05
http://www.securityfocus.com/bid/93541

Linux Kernel CVE-2016-7042 Local Denial of Service Vulnerability
2017-03-05
http://www.securityfocus.com/bid/93544

Google Android Multiple Kernel Components Multiple Information Disclosure Vulnerabilites
2017-03-05
http://www.securityfocus.com/bid/93326

Linux Kernel Vfio Driver CVE-2016-9084 Integer Overflow Vulnerability
2017-03-05
http://www.securityfocus.com/bid/93930

Linux Kernel SCSI arcmsr Driver CVE-2016-7425 Local Heap Buffer Overflow Vulnerability
2017-03-05
http://www.securityfocus.com/bid/93037

Linux Kernel Local Security Bypass Vulnerability
2017-03-05
http://www.securityfocus.com/bid/92659

Linux Kernel 'kernel/process.c' Local Denial of Service Vulnerability
2017-03-05
http://www.securityfocus.com/bid/91415

Linux Kernel CVE-2016-6480 Local Information Disclosure Vulnerability
2017-03-05
http://www.securityfocus.com/bid/92214

Linux Kernel CVE-2016-6130 Local Information Disclosure Vulnerability
2017-03-05
http://www.securityfocus.com/bid/91540

Linux Kernel 'tcp_xmit_retransmit_queue()' Function Use After Free Denial of Service Vulnerability
2017-03-05
http://www.securityfocus.com/bid/92452

Linux Kernel 'usbhid/hiddev.c' Local Heap Buffer Overflow Vulnerability
2017-03-05
http://www.securityfocus.com/bid/91450

Linux Kernel Multiple Local Memory Corruption Vulnerabilities
2017-03-05
http://www.securityfocus.com/bid/91451

Linux kernel 'key_reject_and_link()' Function Local Use After Free Denial of Service Vulnerability
2017-03-05
http://www.securityfocus.com/bid/91211

Cisco Prime Collaboration Assurance CVE-2017-3844 Information Disclosure Vulnerability
2017-03-05
http://www.securityfocus.com/bid/96247

OpenStack qemu-imge CVE-2015-5162 Security Bypass Vulnerability
2017-03-05
http://www.securityfocus.com/bid/76849

ISC BIND CVE-2017-3135 Remote Denial of Service Vulnerability
2017-03-05
http://www.securityfocus.com/bid/96150

w3m Multiple Security Vulnerabilities
2017-03-05
http://www.securityfocus.com/bid/94407

Cisco Unified Communications Manager CVE-2017-3833 Cross Site Scripting Vulnerability
2017-03-05
http://www.securityfocus.com/bid/96246

Cisco Prime Collaboration Assurance CVE-2017-3845 Cross Site Scripting Vulnerability
2017-03-05
http://www.securityfocus.com/bid/96245

libevent Multiple Security Vulnerabilities
2017-03-05
http://www.securityfocus.com/bid/96014

Multiple Hughes Satellite Modems VU#614751 Multiple Security Vulnerabilities
2017-03-05
http://www.securityfocus.com/bid/96244

Adobe Flash Player APSB17-04 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-03-05
http://www.securityfocus.com/bid/96199

Adobe Flash Player APSB17-04 Multiple Heap Buffer Overflow Vulnerabilities
2017-03-05
http://www.securityfocus.com/bid/96193

Adobe Flash Player APSB17-04 Multiple Unspecified Memory Corruption Vulnerabilities
2017-03-05
http://www.securityfocus.com/bid/96190

Adobe Flash Player CVE-2017-2995 Type Confusion Remote Code Execution Vulnerability
2017-03-05
http://www.securityfocus.com/bid/96191

Adobe Flash Player CVE-2017-2987 Unspecified Integer Overflow Vulnerability
2017-03-05
http://www.securityfocus.com/bid/96194

Cisco Meeting Server CVE-2017-3837 Denial of Service Vulnerability
2017-03-05
http://www.securityfocus.com/bid/96243

Cisco Unified Communications Manager CVE-2017-3821 Cross Site Scripting Vulnerability
2017-03-05
http://www.securityfocus.com/bid/96241Linux Kernel 'net/llc/af_llc.c' Local Information Disclosure Vulnerability
2017-03-04
http://www.securityfocus.com/bid/90015

Linux Kernel CVE-2016-4482 Local Information Disclosure Vulnerability
2017-03-04
http://www.securityfocus.com/bid/90029

Graphviz 'yyerror()' Function Incomplete Fix Stack Buffer Overflow Vulnerability
2017-03-04
http://www.securityfocus.com/bid/64736

Graphviz 'yyerror()' Function Stack Buffer Overflow Vulnerability
2017-03-04
http://www.securityfocus.com/bid/64674

Graphviz 'chkNum()' Function Stack Buffer Overflow Vulnerability
2017-03-04
http://www.securityfocus.com/bid/64737

Lsyncd 'default-rsyncssh.lua' Remote Command Injection Vulnerability
2017-03-04
http://www.securityfocus.com/bid/71179

GnuTLS CVE-2017-5335 Multiple Buffer Overflow Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/95374

GnuTLS CVE-2017-5334 Security Bypass Vulnerability
2017-03-04
http://www.securityfocus.com/bid/95370

GnuTLS CVE-2017-5336 Stack Buffer Overflow Vulnerability
2017-03-04
http://www.securityfocus.com/bid/95377

GnuTLS 'lib/opencdk/read-packet.c' Multiple Heap Buffer Overflow Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/95372

OpenSSL CVE-2016-8610 Denial of Service Vulnerability
2017-03-04
http://www.securityfocus.com/bid/93841

MIT Kerberos KDC CVE-2016-3120 NULL Pointer Dereference Denial Of Service Vulnerability
2017-03-04
http://www.securityfocus.com/bid/92132

util-linux CVE-2016-5011 Local Denial of Service Vulnerability
2017-03-04
http://www.securityfocus.com/bid/91683

MuPDF 'fitz/pixmap.c' Heap Based Buffer Overflow Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96139

OpenSSH CVE-2016-10009 Remote Code Execution Vulnerability
2017-03-04
http://www.securityfocus.com/bid/94968

OpenSSH 'ssh/kex.c' Denial of Service Vulnerability
2017-03-04
http://www.securityfocus.com/bid/93776

OpenSSH CVE-2016-10012 Security Bypass Vulnerability
2017-03-04
http://www.securityfocus.com/bid/94975

S-nail CVE-2017-5899 Local Privilege Escalation Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96138

OpenSSH CVE-2016-10011 Local Information Disclosure Vulnerability
2017-03-04
http://www.securityfocus.com/bid/94977

PostfixAdmin CVE-2017-5930 Session Management Security Bypass Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96142

Tor Browser Launcher CVE-2016-3180 Arbitrary Code Execution Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96140

QEMU 'virtio-crypto.c' Integer Overflow Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96141

Symfony CVE-2016-2403 Authentication Bypass Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96137

GNU Bash CVE-2017-5932 Multiple Arbitrary Code Execution Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/96136

SimpleSAMLphp CVE-2016-3124 Information Disclosure Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96134

GraphicsMagick CVE-2016-7800 Remote Integer Underflow Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96135

Trend Micro Control Manager Multiple Directory Traversal Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/96131

Trend Micro Control Manager Multiple Information Disclosure Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/95972

IBM Security Access Manager Products CVE-2016-3029 Cross Site Request Forgery Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96133

SendQuick Entera and Avera SMS Gateway Appliances Remote Command Injection Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96129WordPress fast-image-adder Plugin CVE-2015-1000001 Arbitrary File Upload Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96554

Soruly whatanime.ga CVE-2017-6390 Cross Site Scripting Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96555

Atheme IRC Services CVE-2017-6384 Denial of Service Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96552

FlightAirMap CVE-2017-6397 Multiple Cross Site Scripting Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/96551

WPO-Foundation WebPageTest CVE-2017-6396 Cross Site Scripting Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96553

Remember Me Module DRUPAL-SA-CONTRIB-2017-025 Unspecified Security Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96546

Ping Identity 'mod_auth_openidc' Module CVE-2017-6413 Authentication Bypass Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96549

Rapid7 Metasploit Pro CVE-2017-5235 DLL Loading Remote Code Execution Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96548

HashOver CVE-2017-6395 Cross Site Scripting Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96550

Rapid7 Insight Collector CVE-2017-5234 DLL Loading Remote Code Execution Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96545

WordPress Mobile App Plugin CVE-2017-6104 Arbitrary File Upload Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96547

Multiple KDE Products Products Information Disclosure Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96515

ImageMagick CVE-2017-6335 Local Denial of Service Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96544

Eaton xComfort Ethernet Communication Interface CVE-2017-9368 Information Disclosure Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96542

IBM Development Package for Apache Spark CVE-2016-4970 Denial of Service Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96540

Schneider Electric Conext ComBox CVE-2017-6019 Denial of Service Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96543

NagVis 'share/userfiles/gadgets/std_table.php' Cross Site Scripting Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96537

Multiple Siemens Products CVE-2017-2685 Man in the Middle Security Bypass Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96519

OpenEMR CVE-2017-6394 Multiple Cross Site Scripting Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/96539

Multiple IBM Products CVE-2017-1124 Local Information Disclosure Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96536

QEMU '/src/card_7816.c' Denial of Service Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96541

w3m Multiple Security Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/94407

w3m Multiple Security Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/94464

WordPress AnyVar Plugin CVE-2017-6103 Multiple HTML Injection Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/96532

IBM QRadar SIEM CVE-2016-9729 Authentication Bypass Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96538

WordPress rockhoist-badges Plugin CVE-2017-6102 HTML Injection Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96533

Kaltura server Lynx Multiple Cross Site Scripting Vulnerabilities
2017-03-04
http://www.securityfocus.com/bid/96534

IBM QRadar SIEM CVE-2016-9740 Denial of Service Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96535

IBM QRadar SIEM CVE-2016-9725 Information Disclosure Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96530

IBM QRadar SIEM and Incident Forensics CVE-2016-9720 Information Disclosure Vulnerability
2017-03-04
http://www.securityfocus.com/bid/96531

SANS News

How your pictures may affect your website reputation

Threatpost

New Fileless Attack Using DNS Queries to Carry Out PowerShell Commands

Exploit

Linux/x86-64 - Polymorphic Setuid(0) & Execve(/bin/sh) Shellcode (31 bytes)

Wordpress < 4.7.1 - Username Enumeration

NetGain Enterprise Manager 7.2.562 - 'Ping' Command Injection

Joomla! Component Coupon 3.5 - SQL Injection

pfSense 2.3.2 - Cross-Site Scripting / Cross-Site Request Forgery

3.3.2017

Bugtraq

Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0 2017-03-02
Larry W. Cashdollar (larry0 me com)

[SECURITY] [DSA 3794-2] munin regression update 2017-03-02
Salvatore Bonaccorso (carnil debian org)

Joomla com_publication Component - 'sid' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_news Component - 'id' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_filecabinet Component - 'id' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_frontpage Component - 'Itemid' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Malware

Ransom:Win32/Ergop.A

Trojan.Bachosens

Exp.CVE-2017-0037

Phishing

Chase

3rd March 2017

Irregular Activity

Apple Service

2nd March 2017

YOUR RECEIPT FROM APPLE STORE

Paypal inc

2nd March 2017

TEMPORARILY UNABLE TO LOAD
YOUR ACCOUNT

Shawna

2nd March 2017

Shawna just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Amazon

1st March 2017

ABOUT YOUR ACCOUNT!

Vulnerebility

HashOver CVE-2017-6395 Cross Site Scripting Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96550

Rapid7 Insight Collector CVE-2017-5234 DLL Loading Remote Code Execution Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96545

WordPress Mobile App Plugin CVE-2017-6104 Arbitrary File Upload Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96547

Multiple KDE Products Products Information Disclosure Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96515

ImageMagick CVE-2017-6335 Local Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96544

Eaton xComfort Ethernet Communication Interface CVE-2017-9368 Information Disclosure Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96542

IBM Development Package for Apache Spark CVE-2016-4970 Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96540

Schneider Electric Conext ComBox CVE-2017-6019 Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96543

NagVis 'share/userfiles/gadgets/std_table.php' Cross Site Scripting Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96537

Multiple Siemens Products CVE-2017-2685 Man in the Middle Security Bypass Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96519

OpenEMR CVE-2017-6394 Multiple Cross Site Scripting Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/96539

Multiple IBM Products CVE-2017-1124 Local Information Disclosure Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96536

QEMU '/src/card_7816.c' Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96541

w3m Multiple Security Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/94407

w3m Multiple Security Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/94464

WordPress AnyVar Plugin CVE-2017-6103 Multiple HTML Injection Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/96532

IBM QRadar SIEM CVE-2016-9729 Authentication Bypass Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96538

WordPress rockhoist-badges Plugin CVE-2017-6102 HTML Injection Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96533

Kaltura server Lynx Multiple Cross Site Scripting Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/96534

IBM QRadar SIEM CVE-2016-9740 Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96535

IBM QRadar SIEM CVE-2016-9725 Information Disclosure Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96530

IBM QRadar SIEM and Incident Forensics CVE-2016-9720 Information Disclosure Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96531

Linux kernel CVE-2017-2634 Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96529

Hesiod Security Bypass and Privilege Escalation Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/90952

PHP CVE-2016-7479 Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/95151

PHP CVE-2016-7478 Remote Denial Of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/95150

PHP CVE-2016-7480 Remote Code Execution Vulnerability
2017-03-03
http://www.securityfocus.com/bid/95152

PHP CVE-2016-9138 Remote Code Execution Vulnerability
2017-03-03
http://www.securityfocus.com/bid/95268

PHP CVE-2017-5340 Remote Code Execution Vulnerability
2017-03-03
http://www.securityfocus.com/bid/95371

GNU glibc CVE-2016-10228 Infinite Loop Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96525
Linux Kernel 'tcp_xmit_retransmit_queue()' Function Use After Free Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/92452

Linux Kernel 'usbhid/hiddev.c' Local Heap Buffer Overflow Vulnerability
2017-03-03
http://www.securityfocus.com/bid/91450

Linux Kernel Multiple Local Memory Corruption Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/91451

Linux kernel 'key_reject_and_link()' Function Local Use After Free Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/91211

Cisco Prime Collaboration Assurance CVE-2017-3844 Information Disclosure Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96247

OpenStack qemu-imge CVE-2015-5162 Security Bypass Vulnerability
2017-03-03
http://www.securityfocus.com/bid/76849

ISC BIND CVE-2017-3135 Remote Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96150

w3m Multiple Security Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/94407

Cisco Unified Communications Manager CVE-2017-3833 Cross Site Scripting Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96246

Cisco Prime Collaboration Assurance CVE-2017-3845 Cross Site Scripting Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96245

libevent Multiple Security Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/96014

Multiple Hughes Satellite Modems VU#614751 Multiple Security Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/96244

Adobe Flash Player APSB17-04 Multiple Use After Free Remote Code Execution Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/96199

Adobe Flash Player APSB17-04 Multiple Heap Buffer Overflow Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/96193

Adobe Flash Player APSB17-04 Multiple Unspecified Memory Corruption Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/96190

Adobe Flash Player CVE-2017-2995 Type Confusion Remote Code Execution Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96191

Adobe Flash Player CVE-2017-2987 Unspecified Integer Overflow Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96194

Cisco Meeting Server CVE-2017-3837 Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96243

Cisco Unified Communications Manager CVE-2017-3821 Cross Site Scripting Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96241

Cisco AsyncOS for Email and Web Security Appliances Remote Security Bypass Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96239

Cisco Meeting Server CVE-2017-3830 Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96242

Cisco Secure Access Control System CVE-2017-3841 Information Disclosure Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96237

Cisco Unified Communications Manager CVE-2017-3828 Cross Site Scripting Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96240

Cisco Secure Access Control System CVE-2017-3840 Open Redirection Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96238

Cisco Secure Access Control System XML External Entity Information Disclosure Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96236

Cisco Secure Access Control System CVE-2017-3838 Cross Site Scripting Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96234

Cisco UCS Director CVE-2017-3801 Local Privilege Escalation Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96235

TVer App CVE-2017-2105 SSL Certificate Validation Security Bypass Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96232

Linux kernel 'ip_sockglue.c' Denial of Service Vulnerability
2017-03-03
http://www.securityfocus.com/bid/96233

Apache Brooklyn Cross Site Request Forgery and Multiple Cross Site Scripting Vulnerabilities
2017-03-03
http://www.securityfocus.com/bid/96228

SANS News

BitTorrent or Something Else?

Threatpost

Cisco Warns of High Severity Bug in NetFlow Appliance

Howard Schmidt’s Legacy of Service Remembered

HackerOne Offers Open Source Projects Free Access to Platform

Exploit

Php Classified OLX Clone Script - 'category' Parameter SQL Injection

Joomla! Component Abstract 2.1 - SQL Injection

Joomla! Component StreetGuessr Game 1.0 - SQL Injection

Joomla! Component Guesser 1.0.4 - 'type' Parameter SQL Injection

Joomla! Component Recipe Manager 2.2 - 'id' Parameter SQL Injection

2.3.2017

Bugtraq

Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0 2017-03-02
Larry W. Cashdollar (larry0 me com)

[SECURITY] [DSA 3794-2] munin regression update 2017-03-02
Salvatore Bonaccorso (carnil debian org)

Joomla com_publication Component - 'sid' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_news Component - 'id' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_filecabinet Component - 'id' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_frontpage Component - 'Itemid' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_phocadownload Component - 'id' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Malware

 

Phishing

Shawna

2nd March 2017

Shawna just sent you $3,182.00
USD with Paypal. Paypal
recommends to withdraw it now.

Amazon

1st March 2017

ABOUT YOUR ACCOUNT!

Paypal inc

1st March 2017

TEMPORARILY UNABLE TO LOAD
YOUR ACCOUNT

Vulnerebility

ImageMagick CVE-2016-10062 Security Bypass Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95209

ImageMagick CVE-2016-10144 Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95750

ImageMagick CVE-2016-10145 Local Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95749

Drupal AES encryption Module Security Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96507

podofo CVE-2017-5886 Heap Overflow Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96512

Virglrenderer CVE-2017-6386 Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96506

Multiple Cisco NetFlow Generation Appliances CVE-2017-3826 Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96509

Drupal RESTful Web Services Information Disclosure Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96511

Linux kernel CVE-2017-6345 Local Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96510

Imagemagick CVE-2017-5506 Local Memory Corruption Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95753

ImageMagick CVE-2017-5507 Local Information Disclosure Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95752

ImageMagick CVE-2017-5510 Local Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95755

ImageMagick 'coders/tiff.c' Remote Buffer Overflow Vulnerability
2017-03-02
http://www.securityfocus.com/bid/94727

ImageMagick CVE-2017-5508 Local Heap Buffer Overflow Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95748

ImageMagick CVE-2016-10146 Local Information Disclosure Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95744

ImageMagick CVE-2017-5511 Local Heap Buffer Overflow Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95746

libgd CVE-2016-6906 Buffer Overflow Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96503

OpenStack Swift CVE-2016-9590 Information Disclosure Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95448

Linux kernel CVE-2017-6346 Use After Free Local Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96508

Cisco Prime Infrastructure CVE-2017-3848 Cross Site Scripting Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96505

Veritas NetBackup Server and Client/NetBackup Appliance Authentication Bypass Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96504

TYPO3 Frontend Authentication Bypass Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96501

IBM QRadar Security Information and Event Manager Local Information Disclosure Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96502

Veritas NetBackup Server and Client/ NetBackup Appliance Hardcoded Credentials Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96500

Linux Kernel CVE-2017-2583 Privilege Escalation Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95673

Linux Kernel CVE-2017-2584 Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95430

Linux Kernel CVE-2016-9806 Local Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/94653

Libgd CVE-2016-6912 Security Bypass Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95843

Linux Kernel CVE-2016-7117 Use-After-Free Remote Code Execution Vulnerability
2017-03-02
http://www.securityfocus.com/bid/93304

Veritas NetBackup and NetBackup Appliance Local Insecure File Permissions Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96494TYPO3 Frontend Authentication Bypass Vulnerability
2017-03-28
http://www.securityfocus.com/bid/96501

Veritas NetBackup Server and Client/ NetBackup Appliance Hardcoded Credentials Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96500

Linux Kernel CVE-2017-2583 Privilege Escalation Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95673

Linux Kernel CVE-2017-2584 Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95430

Linux Kernel CVE-2016-9806 Local Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/94653

Libgd CVE-2016-6912 Security Bypass Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95843

Linux Kernel CVE-2016-7117 Use-After-Free Remote Code Execution Vulnerability
2017-03-02
http://www.securityfocus.com/bid/93304

Veritas NetBackup and NetBackup Appliance Local Insecure File Permissions Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96494

Veritas NetBackup Server and Client/ NetBackup Appliance Local Privilege Escalation Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96491

Veritas NetBackup Server and Client/NetBackup Appliance Local Command Execution Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96493

Ghostscript CVE-2013-5653 Multiple Information Disclosure Vulnerabilities
2017-03-02
http://www.securityfocus.com/bid/96497

AirWave Management Platform Multiple Security Vulnerabilities
2017-03-02
http://www.securityfocus.com/bid/96495

Node.js Minimatch Package 'pattern' Parameter Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96496

Linux kernel 'ip_sockglue.c' Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96233

Veritas NetBackup Server and Client/ NetBackup Appliance Arbitrary Command Execution Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96490

Linux Kernel CVE-2017-5577 Remote Buffer Overflow Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95765

Linux kernel 'ip6_gre.c' Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96037

Linux Kernel 'kernel/ptrace.c' Local Privilege Escalation Vulnerability
2017-03-02
http://www.securityfocus.com/bid/79899

Linux Kernel 'net/sctp/socket.c' Local Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96222

Linux Kernel CVE-2017-5576 Integer Overflow Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95767

Linux Kernel CVE-2017-5551 Local Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95717

Veritas NetBackup Server and Client/ NetBackup Appliance Arbitrary Command Execution Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96489

Veritas NetBackup Server and Client/NetBackup Appliance DNS Spoofing Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96488

Veritas NetBackup Server and Client/ NetBackup Appliance Denial-of-Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96485

Linux Kernel CVE-2017-6347 Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96487

Veritas NetBackup Server and Client/NetBackup Appliance Multiple Directory Traversal Vulnerabilities
2017-03-02
http://www.securityfocus.com/bid/96486

QEMU 'ehci_init_transfer()' Function Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/94762

Linux Kernel CVE-2017-6348 Local Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/96483

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-02
http://www.securityfocus.com/bid/95999

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-02
http://www.securityfocus.com/bid/94803

SANS News

SSL/TLS on port 389. Say what?

Phishing for Big Money Wire Transfers is Still Alive and Well (or: For Want of Good Punctuation, all was Lost)

Infected Apps in Google Play Store (it's not what you think)

Threatpost

Slack Fixes Cross-Origin Token Theft Bug

CloudPets Notifies California AG of Data Breach

Google reCaptcha Bypass Technique Uses Google’s Own Tools

Yahoo Tells SEC Executives Failed to Act on Breach

Keys for Dharma Ransomware Released

132 Google Play Apps Booted For Malicious IFrames

Exploit

Php Classified OLX Clone Script - 'category' Parameter SQL Injection

DLink DSL-2730U Wireless N 150 - Cross-Site Request Forgery

Aruba AirWave 8.2.3 - XML External Entity Injection / Cross-Site Scripting

WordPress Plugin Contact Form Manager - Cross-Site Request Forgery / Cross-Site Scripting

WordPress Plugin User Login Log 2.2.1 - Cross-Site Scripting

WordPress Plugin Popup by Supsystic 1.7.6 - Cross-Site Request Forgery

WordPress Plugin Global Content Blocks 2.1.5 - Cross-Site Request Forgery

WordPress Plugin File Manager 3.0.1 - Cross-Site Request Forgery

SchoolDir - SQL Injection

Rage Faces Script 1.3 - SQL Injection

Meme Maker Script 2.1 - 'user' Parameter SQL Injection

WordPress Plugin NewStatPress 1.2.4 - Cross-Site Scripting

SysGauge 1.5.18 - Buffer Overflow

WePresent WiPG-1500 - Backdoor Account

Windows x86 - Reverse TCP Staged Alphanumeric Shellcode (332 Bytes)

1.3.2017

Bugtraq

Joomla com_publication Component - 'sid' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_news Component - 'id' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_filecabinet Component - 'id' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_frontpage Component - 'Itemid' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_phocadownload Component - 'id' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

[SECURITY] [DSA 3798-1] tnef security update 2017-03-01
Sebastien Delafond (seb debian org)

Joomla com_jdownloads Component - 'cid' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Joomla com_webgrouper Component - 'Itemid' Parameter Sql Injection Vulnerability 2017-03-01
iedb team gmail com

Stored Cross-Site Scripting vulnerability in Contact Form WordPress Plugin 2017-03-01
Summer of Pwnage (lists securify nl)

Cross-Site Request Forgery & Cross-Site Scripting in Contact Form Manager WordPress Plugin 2017-03-01
Summer of Pwnage (lists securify nl)

Stored Cross-Site Scripting vulnerability in User Login Log WordPress Plugin 2017-03-01
Summer of Pwnage (lists securify nl)

Cross-Site Scripting in Magic Fields 1 WordPress Plugin 2017-03-01
Summer of Pwnage (lists securify nl)

Cross-Site Request Forgery in Atahualpa WordPress Theme 2017-03-01
Summer of Pwnage (lists securify nl)

Gwolle Guestbook mass action vulnerable for Cross-Site Request Forgery 2017-03-01
Summer of Pwnage (lists securify nl)

Cross-Site Request Forgery in WordPress Download Manager Plugin 2017-03-01
Summer of Pwnage (lists securify nl)

Persistent Cross-Site Scripting in the WordPress NewStatPress plugin 2017-03-01
Summer of Pwnage (lists securify nl)

Cross-Site Scripting vulnerability in Gwolle Guestbook WordPress Plugin 2017-03-01
Summer of Pwnage (lists securify nl)

Cross-Site Request Forgery in Global Content Blocks WordPress Plugin 2017-03-01
Summer of Pwnage (lists securify nl)

Cross-Site Request Forgery in File Manager WordPress plugin 2017-03-01
Summer of Pwnage (lists securify nl)

Admin Custom Login WordPress plugin custom login page affected by persistent Cross-Site Scripting 2017-03-01
Summer of Pwnage (lists securify nl)

Admin Custom Login WordPress plugin affected by persistent Cross-Site Scripting via Logo URL field 2017-03-01
Summer of Pwnage (lists securify nl)

Analytics Stats Counter Statistics WordPress Plugin unauthenticated PHP Object injection vulnerability 2017-03-01
Summer of Pwnage (lists securify nl)

Malware

Trojan:Win32/Fuery.B!cl

Trojan:Win32/Rundas.A
Ransom:Win32/Lamdelim.A

Phishing

PayPal Notice

1st March 2017

[Security] Please check the
information associated with
your account

KohlsGiftCards

28th February 2017

Hi (Customer ID: birdwell269)
$50_KOHLs-Gift-card expires
soon, ClaimNow

Capital One

28th February 2017

Capital One: Update Your
Account

CHASE BANK

28th February 2017

Verify Your Chase Account
Information
 

Vulnerebility

Veritas NetBackup Server and Client/NetBackup Appliance Multiple Directory Traversal Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/96486

QEMU 'ehci_init_transfer()' Function Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/94762

Linux Kernel CVE-2017-6348 Local Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96483

QEMU 'hw/scsi/megasas.c' Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/95999

QEMU Divide By Zero Multiple Denial of Service Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/94803

QEMU 'hw/usb/hcd-xhci.c' Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96220

QEMU 'hw/net/eepro100.c' Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/93957

QEMU 'hw/usb/dev-smartcard-reader.c' Integer Overflow Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96112

QEMU 'hw/display/cirrus_vga.c' Remote Code Execution Vulnerability
2017-03-01
http://www.securityfocus.com/bid/95990

QEMU CVE-2017-5579 Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/95780

Qemu CVE-2017-2620 Remote Code Execution Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96378

QEMU '/hw/usb/redirect.c' Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/94759

QEMU '/hw/net/mcf_fec.c' Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/94638

QEMU 'cirrus_vga.c' Security Bypass Vulnerability
2017-03-01
http://www.securityfocus.com/bid/71477

Siemens RUGGEDCOM NMS CVE-2017-2682 Cross Site Request Forgery Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96458

Siemens RUGGEDCOM NMS CVE-2017-2683 HTML Injection Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96455

Veritas NetBackup Server and Client/ NetBackup Appliance Arbitrary Command Execution Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96484

Multiple Intel Products CVE-2017-5682 Local Privilege Escalation Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96482

MuPDF 'pdf-object.c' Use After Free Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/93127

Artifex MuPDF CVE-2017-5991 Null Pointer Dereference Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96213

MuPDF 'fitz/pixmap.c' Heap Based Buffer Overflow Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96139

X.org X Server Local Multiple Security Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/96480

libgd Multiple Security Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/95869

libgd 'gdImageCreate()' Function Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/95841

PHP 'src/gd.c' Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/94865

Kodi Chorus2 CVE-2017-5982 Directory Traversal Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96481

tnef Multiple Integer Overflow, Type Confusion and Out of Bounds Write Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/96427

TYPO3 CMS Unspecified Multiple Cross Site Scripting Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/96479

Red Hat CloudForms Management Engine CVE-2017-2632 Privilege Escalation Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96478

D-link DI-524 CVE-2017-5633 Multiple Cross Site Request Forgery Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/96475tnef Multiple Integer Overflow, Type Confusion and Out of Bounds Write Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/96427

D-link DI-524 CVE-2017-5633 Multiple Cross Site Request Forgery Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/96475

Sage XRT Treasury CVE-2017-3183 SQL Injection Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96477

Amazon Kindle Setup CVE-2017-6189 DLL Loading Local Code Execution Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96476

Multiple Intel Ethernet Controller CVE-2016-8105 Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96474

Iceni Argus Multiple Security Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/96472

Linux Kernel CVE-2017-6353 Incomplete Fix Local Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96473

Multiple F5 BIG-IP Products CVE-2016-9245 Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96471

Linux Kernel CVE-2017-6074 Local Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96310

Iceni Argus CVE-2016-8715 Remote Code Execution Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96470

Iceni Argus CVE-2016-8389 Remote Integer Overflow Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96469

Iceni Argus CVE-2016-8387 Remote Heap Buffer Overflow Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96468

WBCE CMS Multiple Remote Vulnerabilities
2017-03-01
http://www.securityfocus.com/bid/96467

CubeCart CVE-2017-2117 Directory Traversal Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96466

Multiple F5 BIG-IP Products CVE-2016-9256 Privilege Escalation Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96464

McAfee ePolicy Orchestrator CVE-2017-3902 Cross Site Scripting Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96465

NETGEAR DGN2200 CVE-2017-6334 Remote Code Execution Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96463

ESET Endpoint Antivirus CVE-2016-9892 Remote Code Execution Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96462

SAP BusinessObjects Financial Consolidation CVE-2017-6061 Cross Site Scripting Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96461

Linux Kernel CVE-2017-6214 Remote Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96421

Virglrenderer CVE-2017-6355 Integer Overflow Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96460

Multiple ARM Processor CVE-2017-5927 Local Security Bypass Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96459

Dahua Security Multiple Products CVE-2017-6342 Information Disclosure Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96454

Multiple Intel Processor CVE-2017-5925 Local Security Bypass Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96452

Dahua Security Multiple Products CVE-2017-6341 Information Disclosure Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96456

Siemens RUGGEDCOM NMS CVE-2017-2682 Cross Site Request Forgery Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96458

Multiple AMD Processor CVE-2017-5926 Local Security Bypass Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96457

Siemens RUGGEDCOM NMS CVE-2017-2683 HTML Injection Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96455

IBM Connections CVE-2016-5932 Cross Site Scripting Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96453

Virglrenderer CVE-2017-6317 Denial of Service Vulnerability
2017-03-01
http://www.securityfocus.com/bid/96450

SANS News

Amazon S3 Outage

My Catch Of 4 Months In The Amazon IP Address Space

Threatpost

Dridex Trojan Gets A Major ‘AtomBombing’ Update

Siemens RUGGEDCOM NMS Equipment Vulnerable to CSRF, XSS

Million-Plus WordPress Sites Exposed by Vulnerable Plugin

Exploit

NETGEAR DGN2200v1/v2/v3/v4 - Cross-Site Request Forgery

Cisco AnyConnect Secure Mobility Client 4.3.04027 - Privilege Escalation

BlueIris 4.5.1.4 - Denial of Service

Synchronet BBS 3.16c - Denial of Service

Linux/x86-64 - Reverse Shell Shellcode (84 bytes)

28.2.2017

Bugtraq

Advisory X41-2017-001: Multiple Vulnerabilities in X.org 2017-02-28
X41 D-Sec GmbH Advisories (advisories x41-dsec de)

[SECURITY] [DSA 3788-2] tomcat8 regression update 2017-02-22
Salvatore Bonaccorso (carnil debian org)

[security bulletin] HPESBHF03709 rev.1 - HPE Network products including Comware, IMC, and VCX running OpenSSL, Remote Denial of Service (DoS), Disclosure of Sensitive Information 2017-02-21
security-alert hpe com

APPLE-SA-2017-02-21-2 Logic Pro X 10.3.1 2017-02-21
Apple Product Security (product-security-noreply lists apple com)

PDFMate PDF Converter Pro 1.7.5.0 - Buffer Overflow Vulnerability 2017-02-20
Vulnerability Lab (research vulnerability-lab com)

[SECURITY] [DSA 3790-1] spice security update 2017-02-16
Salvatore Bonaccorso (carnil debian org)

Malware

Ransom:Win64/Braincrypt.A
HackTool:Win32/Vigorf.A

Trojan:DOS/Vigorf.A

Trojan:SWF/Vigorf.A

Trojan:MSIL/Vigorf.A

Ransom:Win32/Pulobe.A

Phishing

Capital One

28th February 2017

Capital One: Update Your
Account

CHASE BANK

28th February 2017

Verify Your Chase Account
Information

Economic and Financial Crimes

27th February 2017

Dear Victim

AOL

27th February 2017

An individual has already
marked your current personal
profile

Vulnerebility

Linux kernel 'ip_sockglue.c' Denial of Service Vulnerability
2017-02-28
http://www.securityfocus.com/bid/96233

gtk-vnc Remote Code Execution Vulnerability and Multiple Integer Overflow Vulnerabilities
2017-02-28
http://www.securityfocus.com/bid/96016

SOGo Multiple Information Disclosure Vulnerabilities
2017-02-28
http://www.securityfocus.com/bid/96338

Apache Tomcat 'http11/AbstractInputBuffer.java' Denial of Service Vulnerability
2017-02-28
http://www.securityfocus.com/bid/96293

OpenSSL CVE-2017-3731 Denial of Service Vulnerability
2017-02-28
http://www.securityfocus.com/bid/95813

OpenSSL CVE-2016-8610 Denial of Service Vulnerability
2017-02-28
http://www.securityfocus.com/bid/93841

Mozilla Firefox CVE-2017-5373 Multiple Unspecified Memory Corruption Vulnerabilities
2017-02-28
http://www.securityfocus.com/bid/95762

WebKit CVE-2016-7762 Cross Site Scripting Vulnerability
2017-02-28
http://www.securityfocus.com/bid/96337

Mozilla Firefox Multiple Security Vulnerabilities
2017-02-28
http://www.securityfocus.com/bid/95769

Mozilla Firefox CVE-2017-5376 Denial of Service Vulnerability
2017-02-28
http://www.securityfocus.com/bid/95758

Mozilla Firefox CVE-2017-5375 ASLR and DEP Security Bypass Vulnerability
2017-02-28
http://www.securityfocus.com/bid/95757

Apple macOS CVE-2016-7761 Local Information Disclosure Vulnerability
2017-02-28
http://www.securityfocus.com/bid/96336

Microsoft Windows CVE-2017-0038 Incomplete Fix Information Disclosure Vulnerability
2017-02-28
http://www.securityfocus.com/bid/96023

Microsoft Windows Graphic Component CVE-2016-3219 Local Privilege Escalation Vulnerability
2017-02-28
http://www.securityfocus.com/bid/91085

Microsoft Windows Graphics Component CVE-2016-3216 Information Disclosure Vulnerability
2017-02-28
http://www.securityfocus.com/bid/91084

Webkit CVE-2017-2371 Security Bypass Vulnerability
2017-02-28
http://www.securityfocus.com/bid/95735

GNU glibc 'misc/hsearch_r.c' Integer Overflow Vulnerability
2017-02-28
http://www.securityfocus.com/bid/83275

GNU glibc 'strftime()' Function Memory Corruption Vulnerability
2017-02-28
http://www.securityfocus.com/bid/83277

Apple iOS CVE-2016-7759 Information Disclosure Vulnerability
2017-02-28
http://www.securityfocus.com/bid/96335

Apple macOS CVE-2016-7742 Arbitray Code Execution Vulnerability
2017-02-28
http://www.securityfocus.com/bid/96331

Apple iOS/macOS CVE-2016-7667 Denial of Service Vulnerability
2017-02-28
http://www.securityfocus.com/bid/96333

Apple iOS/macOS/watchOS CVE-2016-7714 Local Information Disclosure Vulnerability
2017-02-28
http://www.securityfocus.com/bid/96334

Apple macOS CVE-2016-4780 Arbitray Code Execution Vulnerability
2017-02-28
http://www.securityfocus.com/bid/96332

Apple iOS CVE-2016-7630 Security Bypass Vulnerability
2017-02-28
http://www.securityfocus.com/bid/96330

Multiple F5 BIG-IP Products CVE-2016-6249 Information Disclosure Vulnerability
2017-02-28
http://www.securityfocus.com/bid/96328

TCPDF CVE-2017-6100 Local File Include Vulnerability
2017-02-28
http://www.securityfocus.com/bid/96326

MuPDF 'jstest_main.c' Stack Buffer Overflow Vulnerability
2017-02-28
http://www.securityfocus.com/bid/96266

IBM Rational DOORS Next Generation CVE-2016-6055 Unspecified Cross Site Scripting Vulnerability
2017-02-28
http://www.securityfocus.com/bid/96327

Apache Camel CVE-2017-3159 Remote Code Execution Vulnerability
2017-02-28
http://www.securityfocus.com/bid/96321

BusyBox 'udhcp/domain_codec.c' Integer Overflow Vulnerability
2017-02-28
http://www.securityfocus.com/bid/96325

SANS News

My Catch Of 4 Months In The Amazon IP Address Space

Threatpost

Google Discloses Another ‘High Severity’ Microsoft Bug

Boeing Notifies 36,000 Employees Following Breach

Torvalds Downplays SHA-1 Threat to Git

Exploit

MVPower DVR TV-7104HE 1.8.4 115215B9 - Shell Unauthenticated Command Execution...

NETGEAR DGN2200v1/v2/v3/v4 - 'dnslookup.cgi' Remote Command Execution

27.2.2017

Bugtraq

 

Malware

 

Phishing

Congratulation s

27th February 2017

You've won Steve Scott. Please
confirm receipt

KohlsGiftCards

26th February 2017

Hi (Customer ID: birdwell269)
$50_KOHLs-Gift-card expires
soon, ClaimNow

PayPal Service

26th February 2017

You just need to confirm your
billing address.

Microsoft

25th February 2017

You have unread SECURITY
message

Vulnerebility

2017-0037
2017-2682
2017-2683
2017-5925
2017-5926
2017-5927
2017-5928
2017-5946
2017-6297
2017-6341
2017-6342
2017-6343
2017-6344
2017-6349
2017-6350
2017-6127
2017-6188

SANS News

Dynamite Phishing

Threatpost

Necurs Botnet Learns New DDoS Trick

Google Releases E2EMail to Open Source

Katie Moussouris on Bug Bounty Programs, Hack the Army, and Wassenaar

Exploit

MVPower DVR TV-7104HE 1.8.4 115215B9 - Shell Unauthenticated Command Execution...

Windows x86 - Executable Directory Search Shellcode (130 bytes)

Joomla! Component Gnosis 1.1.2 - 'id' Parameter SQL Injection

Joomla! Component Appointments for JomSocial 3.8.1 - SQL Injection

Joomla! Component My MSG 3.2.1 - SQL Injection

Joomla! Component Spinner 360 1.3.0 - SQL Injection

Joomla! Component JomSocial - SQL Injection

NETGEAR DGN2200v1/v2/v3/v4 - 'dnslookup.cgi' Remote Command Execution

Trend Micro InterScan Messaging Security (Virtual Appliance) - Remote Code...

Grails PDF Plugin 0.6 - XML External Entity Injection

Linux Kernel 4.4.0 (Ubuntu) - DCCP Double-Free Privilege Escalation

Linux Kernel 4.4.0 (Ubuntu) - DCCP Double-Free PoC

26.2.2017

Bugtraq

 

Malware

 

Phishing

KohlsGiftCards

24th February 2017

Hi (Customer ID: birdwell269)
$50_KOHLs-Gift-card expires
soon, ClaimNow

Lidl

24th February 2017

AT LIDL LUCKY CUSTOMERS LIKE
YOU CAN GET A CASH BACK

Apple ID

24th February 2017

Your Apple ID information has
been updated.

Mrs.Helen Smith Shabangu

24th February 2017

PICK UP YOUR FIRST PAYMENT OF
$4,500 USD IN MONEY GRAM

Vulnerebility

2016-2226
2016-4041
2016-4042
2016-4043
2016-4487
2016-4488
2016-4489
2016-4490
2016-4491
2016-4492
2016-4493
2016-5027
2016-8998
2016-9009
2016-9975
2017-2789
2017-2790
2017-2791
2017-5669
2016-10109

SANS News

Unpatched Microsoft Edge and IE Bug

It is Tax Season - Watch out for Suspicious Attachment

Threatpost

Researchers Uncover New Leads Behind Shamoon2

Exploit

Joomla! Component JooDatabase 3.1.0 - SQL Injection

Joomla! Component JO Facebook Gallery 4.5 - SQL Injection

Joomla! Component Intranet Attendance Track 2.6.5 - SQL Injection

24.2.2017

Bugtraq

 

Malware

Trojan.Bachosens

Phishing

Apple ID

24th February 2017

Your Apple ID information has
been updated.

Mrs.Helen Smith Shabangu

24th February 2017

PICK UP YOUR FIRST PAYMENT OF
$4,500 USD IN MONEY GRAM

Microsoft

23rd February 2017

Alert Notice

Support PayPal

23rd February 2017

You sent a payment of
$1,324.74 USD to Ebay

Vulnerebility

2014-4677
2016-1245
2016-3013
2016-3052
2016-8536
2016-8537
2016-8538
2016-8539
2016-8540
2016-8541
2016-8542
2016-8543
2016-8544
2016-8545
2016-8546
2016-8547
2016-8548
2016-8549
2016-8550
2016-8551
2016-8552
2016-8553
2016-8554
2016-8555
2016-8556
2016-8557
2016-8558
2016-8559
2016-8560
2016-8636
2016-8915
2016-8986
2016-9377
2016-9378
2016-9384
2016-9400
2016-9909
2016-9910
2016-9956
2017-5585
2017-5586
2017-6077
2017-6187
2017-6188
2017-6205
2017-6206
2012-0158
2014-1903
2015-1158
2016-0189
2016-1247
2016-9244
2016-9553
2016-9554
2016-9683
2016-9684
2017-2370
2017-6074
2017-6127

SANS News

Cloudflare data leak...what does it mean to me?

Threatpost

Java, Python FTP Injection Attacks Bypass Firewalls

Impact of New Linux Kernel DCCP Vulnerability Limited

Policy Experts Push To Make Vulnerability Equities Process Law

Exploit

Microsoft Edge and Internet Explorer - 'HandleColumnBreakOnColumnSpanningElement'...

Apple WebKit 10.0.2 - 'FrameLoader::clear' Universal Cross-Site Scripting

Apple WebKit 10.0.2 - Cross-Origin or Sandboxed IFRAME Pop-up Blocker Bypass

Apple WebKit 10.0.2 - 'Frame::setDocument' Universal Cross-Site Scripting

macOS HelpViewer 10.12.1 - XSS Leads to Arbitrary File Execution and Arbitrary File...

WordPress Plugin Mail Masta 1.0 - SQL Injection

Joomla! Component Store for K2 3.8.2 - SQL Injection

Joomla! Component UserExtranet 1.3.1 - SQL Injection

Joomla! Component MultiTier 3.1 - SQL Injection

23.2.2017

Bugtraq

 

Malware

Trojan:Win32/Chuckenit.A

Ransom.Trashi

OSX.Ransom

Trojan.Bachosens

Phishing

Chase

22nd February 2017

|CHASE BANK| IMPORTANT
NOTlFlCATlON!

Customer Support

22nd February 2017

Secure your rgwalker99@aol.com
mail account.

PayPal

22nd February 2017

PAYPAL : YOUR ACCOUNT HAS BEEN
LIMITED UNTIL WE HEAR FROM YOU

Vulnerebility

 

SANS News

Practical collision attack against SHA-1

Threatpost

Criminals Monetizing Attacks Against Unpatched WordPress Sites

Publicly Disclosed Windows Vulnerabilities Await Patches

Java, Python FTP Injection Attacks Bypass Firewalls

Exploit

Google Chrome - 'layout' Out-of-Bounds Read

Linux/x86-64 - Egghunter Shellcode (38 bytes)

Disk Savvy Enterprise 9.4.18 - Buffer Overflow (SEH)

WordPress Plugin Mail Masta 1.0 - SQL Injection

Joomla! Component Store for K2 3.8.2 - SQL Injection

Joomla! Component UserExtranet 1.3.1 - SQL Injection

Joomla! Component MultiTier 3.1 - SQL Injection

Shutter 0.93.1 - Code Execution

EasyCom For PHP 4.0.0 - Buffer Overflow (PoC)

EasyCom For PHP 4.0.0 - Denial of Service

22.2.2017

Bugtraq

 

Malware

Trojan.Redaman

Phishing

PayPal

22nd February 2017

PAYPAL : YOUR ACCOUNT HAS BEEN
LIMITED UNTIL WE HEAR FROM YOU

USAA Bank.

21st February 2017

USAA: SYSTEM SECURITY SERVICE.

AOL

21st February 2017

incoming friend request

Vulnerebility

2016-4613
2016-4617
2016-4660
2016-4661
2016-4662
2016-4663
2016-4664
2016-4665
2016-4666
2016-4667
2016-4669
2016-4670
2016-4671
2016-4673
2016-4674
2016-4675
2016-4677
2016-4678
2016-4679
2016-4680
2016-4681
2016-4682
2016-4683
2016-4685
2016-4686
2016-4688
2016-4689
2016-4690
2016-4691
2016-4692
2016-4693
2016-4721
2016-4743
2016-4764
2016-4780
2016-4781
2016-7577
2016-7578
2016-7579
2016-7580
2016-7581
2016-7582
2016-7583
2016-7584
2016-7586
2016-7587
2016-7588
2016-7589
2016-7591
2016-7592
2016-7594
2016-7595
2016-7596
2016-7597
2016-7598
2016-7599
2016-7600
2016-7601
2016-7602
2016-7603
2016-7604
2016-7605
2016-7606
2016-7607
2016-7608
2016-7609
2016-7610
2016-7611
2016-7612
2016-7613
2016-7614
2016-7615
2016-7616
2016-7617
2016-7618
2016-7619
2016-7620
2016-7621
2016-7622
2016-7623
2016-7624
2016-7625
2016-7626
2016-7627
2016-7628
2016-7629
2016-7630
2016-7632
2016-7633
2016-7634
2016-7635
2016-7636
2016-7637
2016-7638
2016-7639
2016-7640
2016-7641
2016-7642
2016-7643
2016-7644
2016-7645
2016-7646
2016-7648
2016-7649
2016-7650
2016-7651
2016-7652
2016-7653
2016-7654
2016-7655
2016-7656
2016-7657
2016-7658
2016-7659
2016-7660
2016-7661
2016-7662
2016-7663
2016-7664
2016-7665
2016-7666
2016-7667
2016-7714
2016-7742
2016-7759
2016-7761
2016-7762
2016-7765
2017-2350
2017-2351
2017-2352
2017-2353
2017-2354
2017-2355
2017-2356
2017-2357
2017-2358
2017-2359
2017-2360
2017-2361
2017-2362
2017-2363
2017-2364
2017-2365
2017-2366
2017-2368
2017-2369
2017-2370
2017-2371
2017-2372
2017-2373
2017-2374

SANS News

2 Apple Updates Today as Well - GarageBand and Logic Pro X

Microsoft Patch Tuesday, or is that "Patch Next Tuesday"? - Flash Player RCE patched today

Quick and dirty generic listener

Threatpost

OpenSSL Update Fixes High-Severity DoS Vulnerability

Data Stealing Malware TeamSpy Resurfaces in Spam Campaign

Google Upspin Secure File-Sharing Released to Open Source

Exploit

Joomla! Component ContentMap 1.3.8 - 'contentid' Parameter SQL Injection

Joomla! Component VehicleManager 3.9 - SQL Injection

Joomla! Component RealEstateManager 3.9 - SQL Injection

Joomla! Component BookLibrary 3.6.1 - SQL Injection

Joomla! Component MediaLibrary Basic 3.5 - SQL Injection

EasyCom For PHP 4.0.0 - Buffer Overflow (PoC)

EasyCom For PHP 4.0.0 - Denial of Service

Microsoft Office PowerPoint 2010 - 'MSO!Ordinal5429' Missing Length Check Heap Corruption

Microsoft Office PowerPoint 2010 - MSO/OART Heap Out-of-Bounds Access

Microsoft Office PowerPoint 2010 GDI - 'GDI32!ConvertDxArray' Insufficient Bounds Check

Adobe Flash - MP4 AMF Parsing Overflow

Adobe Flash - SWF Stack Corruption

Adobe Flash - Use-After-Free in Applying Bitmap Filter

Adobe Flash - YUVPlane Decoding Heap Overflow

21.2.2017

Bugtraq

 

Malware

TrojanDownloader:Win32/Pockershecv.A

Phishing

 

Vulnerebility

2016-10227
2016-6249
2016-9269
2016-9314
2016-9315
2016-9316
2017-0038
2017-5881
2017-5959
2017-6070
2017-6071
2017-6072
2017-6078
2017-6095
2017-6096
2017-6097
2017-6098
2016-4613
2016-4660
2016-4661
2016-4662
2016-4663
2016-4664
2016-4665
2016-4666
2016-4667
2016-4669
2016-4670
2016-4671
2016-4673
2016-4674
2016-4675
2016-4677
2016-4678
2016-4679
2016-4680
2016-4681
2016-4682
2016-4683
2016-4685
2016-4686
2016-4688
2016-4689
2016-4690
2016-4691
2016-4692
2016-4693
2016-4721
2016-4743
2016-4764
2016-4781
2016-6252
2016-7577
2016-7578
2016-7579
2016-7580
2016-7581
2016-7582
2016-7583
2016-7584
2016-7586
2016-7587
2016-7588
2016-7589
2016-7591
2016-7592
2016-7594
2016-7595
2016-7596
2016-7597
2016-7598
2016-7599
2016-7600
2016-7601
2016-7602
2016-7603
2016-7604
2016-7605
2016-7606
2016-7607
2016-7608
2016-7609
2016-7610
2016-7611
2016-7612
2016-7613
2016-7614
2016-7615
2016-7616
2016-7617
2016-7618
2016-7619
2016-7620
2016-7621
2016-7622
2016-7623
2016-7624
2016-7625
2016-7626
2016-7627
2016-7628
2016-7629
2016-7632
2016-7633
2016-7634
2016-7635
2016-7636
2016-7637
2016-7638
2016-7639
2016-7640
2016-7641
2016-7642
2016-7643
2016-7644
2016-7645
2016-7646
2016-7648
2016-7649
2016-7650
2016-7651
2016-7652
2016-7653
2016-7654
2016-7655
2016-7656
2016-7657
2016-7658
2016-7659
2016-7660
2016-7661
2016-7662
2016-7663
2016-7664
2016-7665
2016-7666
2017-2350
2017-2351
2017-2352
2017-2353
2017-2354
2017-2355
2017-2356
2017-2357
2017-2358
2017-2359
2017-2360
2017-2361
2017-2362
2017-2363
2017-2364
2017-2365
2017-2366
2017-2368
2017-2369
2017-2370
2017-2371
2017-2372
2017-2373

SANS News

Hardening Postfix Against FTP Relay Attacks

Investigating Off-Premise Wireless Behaviour (or, "I Know What You Connected To")

Threatpost

Windows Botnet Spreading Mirai Variant

Rook Security on Online Extortion

Exploit

Joomla! Component Eventix Events Calendar 1.0 - SQL Injection

Joomla! Component J-CruiseReservation Standard 3.0 - 'city' Parameter SQL Injection

Joomla! Component Eventix Events Calendar 1.0 - SQL Injection

DIGISOL DG-HR1400 Wireless Router - Cross-Site Request Forgery

Joomla! Component MaQma Helpdesk 4.2.7 - 'id' Parameter SQL Injection

Joomla! Component PayPal IPN for DOCman 3.1 - 'id' Parameter SQL Injection

Album Lock 4.0 iOS - Directory Traversal

Tenda N3 Wireless N150 Home Router - Authentication Bypass

20.2.2017

Bugtraq

 

Malware

TrojanDownloader:MSIL/Gendwnurl.AB!bit
TrojanDownloader:Win32/Farfli.K!bit

TrojanSpy:MSIL/Wuvsked.A

TrojanDownloader:MSIL/Efliot.A

HackTool:Win32/WinActivator

Backdoor:Win32/Rescoms.A

Backdoor:MSIL/IRCBot.L

TrojanDropper:Win32/Nabucur.D

TrojanDownloader:O97M/Powmet.A

Trojan:X97M/ShellHide.C

Exp.CVE-2017-0038

Ransom.Hermes

Phishing

PayPal Service

20th February 2017

You just need to confirm your
billing address.

N o t i c e

20th February 2017

DEAR CUSTOMER

Apple lD

20th February 2017

Your Apple lD information has
been updated

Vulnerebility

2014-9905
2016-5028
2016-5029
2016-5030
2016-5031
2016-5032
2016-5033
2016-5034
2016-5035
2016-5036
2016-5037
2016-5038
2016-5039
2016-5040
2016-5042
2016-5043
2016-5044
2016-5364
2016-6189
2016-6190
2016-6191
2016-6251
2016-6252
2016-6870
2016-6871
2016-6872
2016-6873
2016-6874
2016-6875
2016-7111
2016-7510
2016-7511
2017-6055
2017-6065
2016-6062 
2016-8495 
2016-9139 
2016-9637 
2016-9827 
2016-9828 
2016-9829 
2016-9831 
2017-5006 
2017-5007 
2017-5008 
2017-5009 
2017-5010 
2017-5011 
2017-5012 
2017-5013 
2017-5014 
2017-5015 
2017-5016 
2017-5017 
2017-5018 
2017-5019 
2017-5020 
2017-5021 
2017-5022 
2017-5023 
2017-5024 
2017-5025 
2017-5026 

SANS News

 

Threatpost

 

Exploit

Linux - Reverse Shell Shellcode (66 bytes)

Album Lock 4.0 iOS - Directory Traversal

Joomla! Component MaQma Helpdesk 4.2.7 - 'id' Parameter SQL Injection

Joomla! Component PayPal IPN for DOCman 3.1 - 'id' Parameter SQL Injection

18.2.2017

Bugtraq

 

Malware

TrojanDownloader:O97M/Powmet.A

Phishing

PayPal Service

18th February 2017

You just need to confirm your
billing address..

Amazon.com

17th February 2017

Your Amazon Account has been
Locked

sfitzgerald002

17th February 2017

Get the medication you need

Vulnerebility

2016-10134
2016-1249
2016-4311
2016-4312
2016-4314
2016-4315
2016-4316
2016-4327
2016-4861
2016-5417
2016-5919
2016-6062
2016-6233
2016-7293
2016-8652
2016-9139
2016-9637
2016-9773
2016-9814
2016-9827
2016-9828
2016-9829
2016-9831
2016-9955
2017-5006
2017-5007
2017-5008
2017-5009
2017-5010
2017-5011
2017-5012
2017-5013
2017-5014
2017-5015
2017-5016
2017-5017
2017-5018
2017-5019
2017-5020
2017-5021
2017-5022
2017-5023
2017-5024
2017-5025
2017-5026
2017-5027
2017-5344
2017-5357
2017-5998
2017-6000
2017-6014
2017-6056
2009-5028 
2011-4345 
2014-0050 
2014-4877 
2015-5125 
2015-5127 
2015-5129 
2015-5130 
2015-5131 
2015-5132 
2015-5133 
2015-5134 
2015-5539 
2015-5540 
2015-5541 
2015-5544 
2015-5545 
2015-5546 
2015-5547 
2015-5548 
2015-5549 
2015-5550 
2015-5551 
2015-5552 
2015-5553 
2015-5554 
2015-5555 
2015-5556 
2015-5557 
2015-5558 
2015-5559 
2015-5560 
2015-5561 
2015-5562 
2015-5563 
2015-5564 
2015-5565 
2015-5566 
2015-5567 
2015-5568 
2015-5570 
2015-5571 
2015-5572 
2015-5573 
2015-5574 
2015-5575 
2015-5576 
2015-5577 
2015-5578 
2015-5579 
2015-5580 
2015-5581 
2015-5582 
2015-5584 
2015-5587 
2015-5588 
2015-6420 
2015-6676 
2015-6677 
2015-6678 
2015-6679 
2015-6682 
2015-7547 
2015-8044 
2015-8415 
2015-8416 
2015-8417 
2015-8418 
2015-8419 
2015-8420 
2015-8421 
2015-8422 
2015-8423 
2015-8424 
2015-8425 
2015-8426 
2015-8427 
2015-8428 
2015-8429 
2015-8430 
2015-8431 
2015-8432 
2015-8433 
2015-8434 
2015-8435 
2015-8436 
2015-8437 
2015-8438 
2015-8439 
2015-8440 
2015-8441 
2015-8442 
2015-8443 
2015-8444 
2015-8445 
2015-8446 
2015-8447 
2015-8448 
2015-8449 
2015-8450 
2015-8451 
2015-8452 
2015-8453 
2015-8454 
2015-8455 
2015-8456 
2015-8457 
2015-8459 
2015-8460 
2015-8634 
2015-8635 
2015-8636 
2015-8638 
2015-8639 
2015-8640 
2015-8641 
2015-8642 
2015-8643 
2015-8644 
2015-8645 
2015-8646 
2015-8647 
2015-8648 
2015-8649 
2015-8650 
2015-8651 
2016-0360 
2016-0702 
2016-0705 
2016-0777 
2016-0778 
2016-0797 
2016-0799 
2016-1247 
2016-1521 
2016-1907 
2016-2105 
2016-2106 
2016-2107 
2016-2109 
2016-2183 
2016-2842 
2016-3739 
2016-4070 
2016-4071 
2016-4072 
2016-4342 
2016-4343 
2016-4393 
2016-4394 
2016-4395 
2016-4396 
2016-4537 
2016-4538 
2016-4539 
2016-4540 
2016-4541 
2016-4542 
2016-4543 
2016-5385 
2016-5387 
2016-5388 
2016-6033 
2016-6077 
2016-6079 
2016-8676 
2016-8691 
2016-8692 
2016-8693 
2016-8944 
2016-8972 
2016-9244 

SANS News

Brazilian malspam sends Autoit-based malware

Threatpost

 

Exploit

Joomla! Component Joomloc-CAT 4.1.3 - 'ville' Parameter SQL Injection

Joomla! Component Joomloc-Lite 1.3.2 - 'site_id' Parameter SQL Injection

Joomla! Component JomWALL 4.0 - 'wuid' Parameter SQL Injection

Joomla! Component OS Property 3.0.8 - SQL Injection

Joomla! Component EShop 2.5.1 - 'id' Parameter SQL Injection

Joomla! Component OS Services Booking 2.5.1 - SQL Injection

Joomla! Component Room Management 1.0 - SQL Injection

17.2.2017

Bugtraq

 

Malware

SupportScam:JS/TechBrolo.A 
BrowserModifier:Win32/Foxiebro 

Trojan.Kulekmoko

Phishing

Amazon.com

17th February 2017

Your Amazon Account has been
Locked

sfitzgerald002

17th February 2017

Get the medication you need

USAA

16th February 2017

Credit Alert Notification

Amazon.com

16th February 2017

Your Amazon Account has been
Locked

Westpac Bank

16th February 2017

Account Verifications Update

Vulnerebility

 

SANS News

AVM Private Key Leak Puts Cable Modems Worldwide At Risk

RTRBK - Router / Switch / Firewall Backups in PowerShell (tool drop)

Threatpost

Cris Thomas on Cyberwar Rhetoric

Divide Between Work, Personal Data on Android Breached

Exploit

Windows x86 - Protect Process Shellcode (229 bytes)

Linux - Dual/Multi mode

Bind Shell Shellcode (156 bytes)

Joomla! Component Team Display 1.2.1 - 'filter_category' Parameter SQL Injection

Joomla! Component Groovy Gallery 1.0.0 - SQL Injection

Joomla! Component WMT Content Timeline 1.0 - 'id' Parameter SQL Injection

16.2.2017

Bugtraq

 

Malware

SupportScam:JS/TechBrolo.A
JS/TechBrolo

SupportScam:JS/TechBrolo

Phishing

Amazon.com

16th February 2017

Your Amazon Account has been
Locked

Westpac Bank

16th February 2017

Account Verifications Update

USAA

16th February 2017

Incoming Payment Awaiting Your
Approval

PayPal Notice

15th February 2017

REMINDER : UNAUTHORIZED LOGIN
ACTIVITY

PayPal

15th February 2017

The password for your PayPal
has been successfully reset.

PayPal

15th February 2017

DEAR USER PAYPAL, YOU HAVE A
UPDATE TODAY

Vulnerebility

2013-7459
2015-8979
2016-0360
2016-10089
2016-1880
2016-1881
2016-1883
2016-1888
2016-1889
2016-3694
2016-6033
2016-6060
2016-6077
2016-6079
2016-6832
2016-6866
2016-7392
2016-7393
2016-7477
2016-7499
2016-8674
2016-8675
2016-8676
2016-8677
2016-8678
2016-8679
2016-8680
2016-8681
2016-8682
2016-8683
2016-8684
2016-8687
2016-8688
2016-8689
2016-8690
2016-8691
2016-8692
2016-8693
2016-8862
2016-8866
2016-8944
2016-8968
2016-8972
2016-9010
2016-9560
2016-9706
2017-0308
2017-0309
2017-0310
2017-0311
2017-0312
2017-0313
2017-0314
2017-0315
2017-0317
2017-0318
2017-0319
2017-0320
2017-0321
2017-0322
2017-0323
2017-0324
2017-3801
2017-5896
2017-5992
2017-5997
2017-6004
2017-6009
2017-6010
2017-6011

1999-1548
1999-1577
2000-0270
2000-1220
2000-1221
2002-2005
2017-5933 

SANS News

Microsoft February Patch Tuesday Now Rolled into March Update

Threatpost

 

Exploit

Joomla! Component Spider Calendar Lite 3.2.16 - SQL Injection

Joomla! Component Spider Catalog Lite 1.8.10 - SQL Injection

Joomla! Component Spider Facebook 1.6.1 - SQL Injection

Joomla! Component Spider FAQ Lite 1.3.1 - SQL Injection

WordPress Plugin Corner Ad 1.0.7 - Cross-Site Scripting

Microsoft Windows gdi32.dll - EMR_SETDIBITSTODEVICE Heap-Based Out-of-Bounds Reads...

NVIDIA Driver 375.70 - DxgkDdiEscape 0x100008b Out-of-Bounds Read/Write

NVIDIA Driver 375.70 - Buffer Overflow in Command Buffer Submission

GOM Player 2.3.10.5266 - '.fpx' Denial of Service

Cisco ASA - WebVPN CIFS Handling Buffer Overflow

OpenText Documentum D2 - Remote Code Execution

Geutebruck 5.02024 G-Cam/EFD-2250 - Remote Command Execution (Metasploit)

15.2.2017

Bugtraq

 

Malware

EUS:Win32/CustomEnterpriseBlock!cl 

Phishing

PayPal

15th February 2017

DEAR USER PAYPAL, YOU HAVE A
UPDATE TODAY

Apple

13th February 2017

YOUR APPLE-ID WAS USED TO SIGN
IN TO ICLOUD VIA NEW DEVICE.

Vulnerebility

2017-2968
2017-2969
2017-2973
2017-2974
2017-2975
2017-2976
2017-2977
2017-2978
2017-2979
2017-2980
2017-2981
2017-2982
2017-2984
2017-2985
2017-2986
2017-2987
2017-2988
2017-2990
2017-2991
2017-2992
2017-2993
2017-2994
2017-2995
2017-2996
2017-5990
2017-5991

2016-2274
2016-3995
2016-5782
2016-5786
2016-5796
2016-5798
2016-5801
2016-5802
2016-5803
2016-5805
2016-5809
2016-5811
2016-5813
2016-5815
2016-5818
2016-6210
2016-7987
2016-8341
2016-8344
2016-8346
2016-8347
2016-8348
2016-8350
2016-8352
2016-8353
2016-8354
2016-8355
2016-8356
2016-8357
2016-8358
2016-8359
2016-8360
2016-8361
2016-8362
2016-8363
2016-8364
2016-8367
2016-8368
2016-8369
2016-8370
2016-8372
2016-8374
2016-8375
2016-8376
2016-8377
2016-8378
2016-8379
2016-8566
2016-8567
2016-8659
2016-8859
2016-9332
2016-9333
2016-9334
2016-9337
2016-9338
2016-9339
2016-9343
2016-9344
2016-9345
2016-9346
2016-9347
2016-9348
2016-9349
2016-9351
2016-9353
2016-9354
2016-9355
2016-9356
2016-9357
2016-9360
2016-9361
2016-9362
2016-9363
2016-9364
2016-9365
2016-9366
2016-9367
2016-9369
2016-9371
2017-3896
2017-5139
2017-5140
2017-5141
2017-5142
2017-5143
2017-5144
2017-5145
2017-5146
2017-5149
2017-5151
2017-5152
2017-5153
2017-5154
2017-5155
2017-5157
2017-5159
2017-5161
2017-5162
2017-5163
2017-5164
2017-5165
2017-5166
2017-5167

SANS News

How was your stay at the Hotel La Playa?

Threatpost

Adobe Patches 13 Code Execution Vulnerabilities in Flash

Schneier Brings Campaign for IoT Regulation to RSA

DHS Chairman Paints Bleak US Cybersecurity Picture

Turning Tables on Nigerian Business Email Scammers

Exploit

Geutebruck 5.02024 G-Cam/EFD-2250 - Remote Command Execution (Metasploit)

Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 - Multiple...

Joomla! Component JoomBlog 1.3.1 - SQL Injection

13.2.2017

Bugtraq

 

Malware

Spammer:Win32/Junintian.A 

Phishing

 

Vulnerebility

2017-3302
2017-5960
2017-5961
2017-5962
2017-5963
2017-5964

SANS News

Microsoft Patch Tuesday Delayed

Threatpost

Nation States Distancing Themselves from APTs

Adobe Patches 13 Code Execution Vulnerabilities in Flash

Exploit

Google Android - Inter-process munmap in android.util.MemoryIntArray

Google Android - android.util.MemoryIntArray Ashmem Race Conditions

Microsoft Edge - TypedArray.sort Use-After-Free (MS16-145)

Piwik 2.14.0 / 2.16.0 / 2.17.1 / 3.0.1 - Superuser Plugin Upload (Metasploit)

ShadeYouVPN Client 2.0.1.11 - Privilege Escalation

ntfs-3g - Unsanitized modprobe Environment Privilege Escalation

LG G4 - lgdrmserver Binder Service Multiple Race Conditions

LG G4 - lghashstorageserver Directory Traversal

LG G4 - Touchscreen Driver write_log Kernel Read/Write

Linux Kernel 3.10.0 (CentOS7) - Denial of Service

Joomla! Component Soccer Bet 4.1.5 - 'userid' Parameter SQL Injection

PHP Marketplace Script - SQL Injection

Joomla! Component JE Classify Ads 1.2 - 'pro_id' Parameter SQL Injection

Joomla! Component JE Gallery 1.3 - 'photo_id' Parameter SQL Injection

Joomla! Component JE Directory 1.7 - 'ditemid' Parameter SQL Injection

Joomla! Component JE QuoteForm - 'Itemid' Parameter SQL Injection

12.2.2017

Bugtraq

 

Malware

Ransom:Win32/Wadhrama 
Ransom:Win32/Haknata.A!rsm 

Phishing

IRS

13th February 2017

Immediate re-confirmation of
your details required

Bank of America... Alert

12th February 2017

.Bank.Of.America: Security
Update Required.....

No@reply

12th February 2017

account verification

Vulnerebility

 

SANS News

Stuff I Learned Decrypting

Do You Use VirusTotal? Give PacketTotal a Spin!

Threatpost

Updated Firmware Due for Serious TP-Link Router Vulnerabilities

Exploit

Joomla! Component Soccer Bet 4.1.5 - 'userid' Parameter SQL Injection

SonicDICOM PACS 2.3.2 - Cross-Site Scripting

SonicDICOM PACS 2.3.2 - Cross-Site Request Forgery (Add Admin)

SonicDICOM PACS 2.3.2 - Privilege Escalation

Kodi 17.1 - Arbitrary File Disclosure

WhizBiz 1.9 - SQL Injection

TI Online Examination System 2.0 - SQL Injection

Viavi Real Estate - SQL Injection

Viavi Movie Review - 'id' Parameter SQL Injection

Viavi Product Review - 'id' Parameter SQL Injection

Quadz School Management System 3.1 - 'uisd' Parameter SQL Injection

Domains & Hostings Manager PRO 3.0 - 'entries' Parameter SQL Injection

Cimetrics BACstac 6.2f - Privilege Escalation

Cimetrics BACnet Explorer 4.0 - XML External Entity Injection

11.2.2017

Bugtraq

ESA-2017-001: EMC Isilon InsightIQ Authentication Bypass Vulnerability 2017-02-07
EMC Product Security Response Center (Security_Alert emc com)

Malware

Backdoor.Streamex

Phishing

Bank of America

11th February 2017

ACCOUNT REQUIRED ATTENTION

Federal Bureau of Investigatio

10th February 2017

Executive Director FBI

Vulnerebility

 

OpenSSL CVE-2016-8610 Denial of Service Vulnerability
2017-02-11
http://www.securityfocus.com/bid/93841

MIT Kerberos KDC CVE-2016-3120 NULL Pointer Dereference Denial Of Service Vulnerability
2017-02-11
http://www.securityfocus.com/bid/92132

util-linux CVE-2016-5011 Local Denial of Service Vulnerability
2017-02-11
http://www.securityfocus.com/bid/91683

MuPDF 'fitz/pixmap.c' Heap Based Buffer Overflow Vulnerability
2017-02-11
http://www.securityfocus.com/bid/96139

OpenSSH CVE-2016-10009 Remote Code Execution Vulnerability
2017-02-11
http://www.securityfocus.com/bid/94968

OpenSSH 'ssh/kex.c' Denial of Service Vulnerability
2017-02-11
http://www.securityfocus.com/bid/93776

OpenSSH CVE-2016-10012 Security Bypass Vulnerability
2017-02-11
http://www.securityfocus.com/bid/94975

S-nail CVE-2017-5899 Local Privilege Escalation Vulnerability
2017-02-11
http://www.securityfocus.com/bid/96138

OpenSSH CVE-2016-10011 Local Information Disclosure Vulnerability
2017-02-11
http://www.securityfocus.com/bid/94977

PostfixAdmin CVE-2017-5930 Session Management Security Bypass Vulnerability
2017-02-11
http://www.securityfocus.com/bid/96142

Tor Browser Launcher CVE-2016-3180 Arbitrary Code Execution Vulnerability
2017-02-11
http://www.securityfocus.com/bid/96140

QEMU 'virtio-crypto.c' Integer Overflow Vulnerability
2017-02-11
http://www.securityfocus.com/bid/96141

Symfony CVE-2016-2403 Authentication Bypass Vulnerability
2017-02-11
http://www.securityfocus.com/bid/96137

GNU Bash CVE-2017-5932 Multiple Arbitrary Code Execution Vulnerabilities
2017-02-11
http://www.securityfocus.com/bid/96136

SimpleSAMLphp CVE-2016-3124 Information Disclosure Vulnerability
2017-02-11
http://www.securityfocus.com/bid/96134

GraphicsMagick CVE-2016-7800 Remote Integer Underflow Vulnerability
2017-02-11
http://www.securityfocus.com/bid/96135

Trend Micro Control Manager Multiple Directory Traversal Vulnerabilities
2017-02-11
http://www.securityfocus.com/bid/96131

Trend Micro Control Manager Multiple Information Disclosure Vulnerabilities
2017-02-11
http://www.securityfocus.com/bid/95972

IBM Security Access Manager Products CVE-2016-3029 Cross Site Request Forgery Vulnerability
2017-02-11
http://www.securityfocus.com/bid/96133

SendQuick Entera and Avera SMS Gateway Appliances Remote Command Injection Vulnerability
2017-02-11
http://www.securityfocus.com/bid/96129

ZoneMinder CVE-2017-5368 Cross Site Request Forgery Vulnerability
2017-02-11
http://www.securityfocus.com/bid/96126

IBM Security Access Manager CVE-2016-3024 Local Information Disclosure Vulnerability
2017-02-11
http://www.securityfocus.com/bid/96132

IBM Security Access Manager Products CVE-2016-3027 XML External Entity Injection Vulnerability
2017-02-11
http://www.securityfocus.com/bid/96127

IBM Security Access Manager Products CVE-2016-3022 Information Disclosure Vulnerability
2017-02-11
http://www.securityfocus.com/bid/96130

Multiple Samsung Android Mobile Devices InputMethod Application Denial of Service Vulnerability
2017-02-11
http://www.securityfocus.com/bid/96128

Trend Micro Control Manager Multiple SQL Injection Vulnerabilities
2017-02-11
http://www.securityfocus.com/bid/96123

Alaris 8015 PC unit CVE-2016-9355 Information Disclosure Vulnerability
2017-02-11
http://www.securityfocus.com/bid/96116

Sielco Sistemi Winlog Pro/ Winlog Lite CVE-2017-5161 DLL Loading Local Code Execution Vulnerability
2017-02-11
http://www.securityfocus.com/bid/96119

Linux Kernel CVE-2016-10150 Denial of Service Vulnerability
2017-02-11
http://www.securityfocus.com/bid/95672

dotCMS Multiple Cross Site Scripting Vulnerabilities
2017-02-11
http://www.securityfocus.com/bid/96115

SANS News

 

Threatpost

 

Exploit

F5 BIG-IP SSL Virtual Server - Memory Disclosure

WordPress 4.7.0/4.7.1 Plugin Insert PHP - PHP Code Injection

10.2.2017

Bugtraq

 

Malware

Ransom:Win32/Haknata.A!rsm

Trojan.Mdropper.AE

Backdoor.Athenrat

Downloader.Ratankba

Trojan.Mirai

Phishing

Federal Bureau of Investigatio

10th February 2017

Executive Director FBI

BANK OF AMERICA

10th February 2017

PLEASE UPDATE YOUR ACCOUNT
INFORMATION

USAA

9th February 2017

Incoming Payment Awaiting Your
Approval

Woolworths Rewards

9th February 2017

CUSTOMER SATISFACTION SURVEY!

Vulnerebility

OpenSSL CVE-2016-8610 Denial of Service Vulnerability
2017-02-10
http://www.securityfocus.com/bid/93841

MIT Kerberos KDC CVE-2016-3120 NULL Pointer Dereference Denial Of Service Vulnerability
2017-02-10
http://www.securityfocus.com/bid/92132

util-linux CVE-2016-5011 Local Denial of Service Vulnerability
2017-02-10
http://www.securityfocus.com/bid/91683

MuPDF 'fitz/pixmap.c' Heap Based Buffer Overflow Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96139

OpenSSH CVE-2016-10009 Remote Code Execution Vulnerability
2017-02-10
http://www.securityfocus.com/bid/94968

OpenSSH 'ssh/kex.c' Denial of Service Vulnerability
2017-02-10
http://www.securityfocus.com/bid/93776

OpenSSH CVE-2016-10012 Security Bypass Vulnerability
2017-02-10
http://www.securityfocus.com/bid/94975

S-nail CVE-2017-5899 Local Privilege Escalation Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96138

OpenSSH CVE-2016-10011 Local Information Disclosure Vulnerability
2017-02-10
http://www.securityfocus.com/bid/94977

PostfixAdmin CVE-2017-5930 Session Management Security Bypass Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96142

Tor Browser Launcher CVE-2016-3180 Arbitrary Code Execution Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96140

QEMU 'virtio-crypto.c' Integer Overflow Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96141

Symfony CVE-2016-2403 Authentication Bypass Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96137

GNU Bash CVE-2017-5932 Multiple Arbitrary Code Execution Vulnerabilities
2017-02-10
http://www.securityfocus.com/bid/96136

SimpleSAMLphp CVE-2016-3124 Information Disclosure Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96134

GraphicsMagick CVE-2016-7800 Remote Integer Underflow Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96135

Trend Micro Control Manager Multiple Directory Traversal Vulnerabilities
2017-02-10
http://www.securityfocus.com/bid/96131

Trend Micro Control Manager Multiple Information Disclosure Vulnerabilities
2017-02-10
http://www.securityfocus.com/bid/95972

IBM Security Access Manager Products CVE-2016-3029 Cross Site Request Forgery Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96133

SendQuick Entera and Avera SMS Gateway Appliances Remote Command Injection Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96129

ZoneMinder CVE-2017-5368 Cross Site Request Forgery Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96126

IBM Security Access Manager CVE-2016-3024 Local Information Disclosure Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96132

IBM Security Access Manager Products CVE-2016-3027 XML External Entity Injection Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96127

IBM Security Access Manager Products CVE-2016-3022 Information Disclosure Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96130

Multiple Samsung Android Mobile Devices InputMethod Application Denial of Service Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96128

Trend Micro Control Manager Multiple SQL Injection Vulnerabilities
2017-02-10
http://www.securityfocus.com/bid/96123

Alaris 8015 PC unit CVE-2016-9355 Information Disclosure Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96116

Sielco Sistemi Winlog Pro/ Winlog Lite CVE-2017-5161 DLL Loading Local Code Execution Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96119

Linux Kernel CVE-2016-10150 Denial of Service Vulnerability
2017-02-10
http://www.securityfocus.com/bid/95672

dotCMS Multiple Cross Site Scripting Vulnerabilities
2017-02-10
http://www.securityfocus.com/bid/96115OpenSSL CVE-2016-8610 Denial of Service Vulnerability
2017-02-10
http://www.securityfocus.com/bid/93841

MIT Kerberos KDC CVE-2016-3120 NULL Pointer Dereference Denial Of Service Vulnerability
2017-02-10
http://www.securityfocus.com/bid/92132

util-linux CVE-2016-5011 Local Denial of Service Vulnerability
2017-02-10
http://www.securityfocus.com/bid/91683

MuPDF 'fitz/pixmap.c' Heap Based Buffer Overflow Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96139

OpenSSH CVE-2016-10009 Remote Code Execution Vulnerability
2017-02-10
http://www.securityfocus.com/bid/94968

OpenSSH 'ssh/kex.c' Denial of Service Vulnerability
2017-02-10
http://www.securityfocus.com/bid/93776

OpenSSH CVE-2016-10012 Security Bypass Vulnerability
2017-02-10
http://www.securityfocus.com/bid/94975

S-nail CVE-2017-5899 Local Privilege Escalation Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96138

OpenSSH CVE-2016-10011 Local Information Disclosure Vulnerability
2017-02-10
http://www.securityfocus.com/bid/94977

PostfixAdmin CVE-2017-5930 Session Management Security Bypass Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96142

Tor Browser Launcher CVE-2016-3180 Arbitrary Code Execution Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96140

QEMU 'virtio-crypto.c' Integer Overflow Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96141

Symfony CVE-2016-2403 Authentication Bypass Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96137

GNU Bash CVE-2017-5932 Multiple Arbitrary Code Execution Vulnerabilities
2017-02-10
http://www.securityfocus.com/bid/96136

SimpleSAMLphp CVE-2016-3124 Information Disclosure Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96134

GraphicsMagick CVE-2016-7800 Remote Integer Underflow Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96135

Trend Micro Control Manager Multiple Directory Traversal Vulnerabilities
2017-02-10
http://www.securityfocus.com/bid/96131

Trend Micro Control Manager Multiple Information Disclosure Vulnerabilities
2017-02-10
http://www.securityfocus.com/bid/95972

IBM Security Access Manager Products CVE-2016-3029 Cross Site Request Forgery Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96133

SendQuick Entera and Avera SMS Gateway Appliances Remote Command Injection Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96129

ZoneMinder CVE-2017-5368 Cross Site Request Forgery Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96126

IBM Security Access Manager CVE-2016-3024 Local Information Disclosure Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96132

IBM Security Access Manager Products CVE-2016-3027 XML External Entity Injection Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96127

IBM Security Access Manager Products CVE-2016-3022 Information Disclosure Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96130

Multiple Samsung Android Mobile Devices InputMethod Application Denial of Service Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96128

Trend Micro Control Manager Multiple SQL Injection Vulnerabilities
2017-02-10
http://www.securityfocus.com/bid/96123

Alaris 8015 PC unit CVE-2016-9355 Information Disclosure Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96116

Sielco Sistemi Winlog Pro/ Winlog Lite CVE-2017-5161 DLL Loading Local Code Execution Vulnerability
2017-02-10
http://www.securityfocus.com/bid/96119

Linux Kernel CVE-2016-10150 Denial of Service Vulnerability
2017-02-10
http://www.securityfocus.com/bid/95672

dotCMS Multiple Cross Site Scripting Vulnerabilities
2017-02-10
http://www.securityfocus.com/bid/96115

SANS News

Hancitor/Pony malspam

Threatpost

High Severity BIND Vulnerability Can Lead to A Crash
CryptoShield Infections from RIG EK Picking Up

Exploit

HP Smart Storage Administrator 2.30.6.0 - Remote Command Injection (Metasploit)

CMS Lite 1.3.1 - SQL Injection

Tiger Post 3.0.1 - SQL Injection

Gram Post 1.0 - SQL Injection

Youtube Analytics Multi Channel 3.0 - SQL Injection

Collabo - Arbitrary File Download

Takas Classified 1.1 - SQL Injection

Zigaform - SQL Injection

9.2.2017

Bugtraq

 

Malware

 

Phishing

USAA

9th February 2017

Incoming Payment Awaiting Your
Approval

Woolworths Rewards

9th February 2017

CUSTOMER SATISFACTION SURVEY!

Apple

7th February 2017

YOUR APPIE LD IS AUTOMATICALLY
LOCKED.

Vulnerebility

OpenSSL CVE-2016-8610 Denial of Service Vulnerability
2017-02-09
http://www.securityfocus.com/bid/93841

MIT Kerberos KDC CVE-2016-3120 NULL Pointer Dereference Denial Of Service Vulnerability
2017-02-09
http://www.securityfocus.com/bid/92132

util-linux CVE-2016-5011 Local Denial of Service Vulnerability
2017-02-09
http://www.securityfocus.com/bid/91683

MuPDF 'fitz/pixmap.c' Heap Based Buffer Overflow Vulnerability
2017-02-09
http://www.securityfocus.com/bid/96139

OpenSSH CVE-2016-10009 Remote Code Execution Vulnerability
2017-02-09
http://www.securityfocus.com/bid/94968

OpenSSH 'ssh/kex.c' Denial of Service Vulnerability
2017-02-09
http://www.securityfocus.com/bid/93776

OpenSSH CVE-2016-10012 Security Bypass Vulnerability
2017-02-09
http://www.securityfocus.com/bid/94975

S-nail CVE-2017-5899 Local Privilege Escalation Vulnerability
2017-02-09
http://www.securityfocus.com/bid/96138

OpenSSH CVE-2016-10011 Local Information Disclosure Vulnerability
2017-02-09
http://www.securityfocus.com/bid/94977

PostfixAdmin CVE-2017-5930 Session Management Security Bypass Vulnerability
2017-02-09
http://www.securityfocus.com/bid/96142

Tor Browser Launcher CVE-2016-3180 Arbitrary Code Execution Vulnerability
2017-02-09
http://www.securityfocus.com/bid/96140

QEMU 'virtio-crypto.c' Integer Overflow Vulnerability
2017-02-09
http://www.securityfocus.com/bid/96141

Symfony CVE-2016-2403 Authentication Bypass Vulnerability
2017-02-09
http://www.securityfocus.com/bid/96137

GNU Bash CVE-2017-5932 Multiple Arbitrary Code Execution Vulnerabilities
2017-02-09
http://www.securityfocus.com/bid/96136

SimpleSAMLphp CVE-2016-3124 Information Disclosure Vulnerability
2017-02-09
http://www.securityfocus.com/bid/96134

GraphicsMagick CVE-2016-7800 Remote Integer Underflow Vulnerability
2017-02-09
http://www.securityfocus.com/bid/96135

Trend Micro Control Manager Multiple Directory Traversal Vulnerabilities
2017-02-09
http://www.securityfocus.com/bid/96131

Trend Micro Control Manager Multiple Information Disclosure Vulnerabilities
2017-02-09
http://www.securityfocus.com/bid/95972

IBM Security Access Manager Products CVE-2016-3029 Cross Site Request Forgery Vulnerability
2017-02-09
http://www.securityfocus.com/bid/96133

SendQuick Entera and Avera SMS Gateway Appliances Remote Command Injection Vulnerability
2017-02-09
http://www.securityfocus.com/bid/96129

ZoneMinder CVE-2017-5368 Cross Site Request Forgery Vulnerability
2017-02-09
http://www.securityfocus.com/bid/96126

IBM Security Access Manager CVE-2016-3024 Local Information Disclosure Vulnerability
2017-02-09
http://www.securityfocus.com/bid/96132

IBM Security Access Manager Products CVE-2016-3027 XML External Entity Injection Vulnerability
2017-02-09
http://www.securityfocus.com/bid/96127

IBM Security Access Manager Products CVE-2016-3022 Information Disclosure Vulnerability
2017-02-09
http://www.securityfocus.com/bid/96130

Multiple Samsung Android Mobile Devices InputMethod Application Denial of Service Vulnerability
2017-02-09
http://www.securityfocus.com/bid/96128

Trend Micro Control Manager Multiple SQL Injection Vulnerabilities
2017-02-09
http://www.securityfocus.com/bid/96123

Alaris 8015 PC unit CVE-2016-9355 Information Disclosure Vulnerability
2017-02-09
http://www.securityfocus.com/bid/96116

Sielco Sistemi Winlog Pro/ Winlog Lite CVE-2017-5161 DLL Loading Local Code Execution Vulnerability
2017-02-09
http://www.securityfocus.com/bid/96119

Linux Kernel CVE-2016-10150 Denial of Service Vulnerability
2017-02-09
http://www.securityfocus.com/bid/95672

dotCMS Multiple Cross Site Scripting Vulnerabilities
2017-02-09
http://www.securityfocus.com/bid/96115

SANS News

CryptoShield Ransomware from Rig EK

Ticketbleed vulnerability affects some f5 appliances

Threatpost

Fileless Memory-Based Malware Plagues 140 Banks, Enterprises

Dino Dai Zovi on Securing Linux in Modern Workloads

Exploit

Mobiketa 3.5 - SQL Injection

Sendroid 5.2 - SQL Injection

Fome SMS Portal 2.0 - SQL Injection

SOA School Management - SQL Injection

Client Expert 1.0.1 - SQL Injection