BugTraq Mode:
(Page 5 of 1570)  < Prev  1 2 3 4 5 6 7 8 9 10 11  Next >
[Appcheck-NG] Unpatched Vulnerabilities in Magento E-Commerce Platform 2014-11-04
AppCheck_Advisories (advisories appcheck-ng com)
On April 8th 2014, AppCheck reported several Cross Site Scripting Vulnerabilities in the Magento e-commerce platform via the eBay bug bounty program. eBay responded to inform us that the vulnerabilities had already been reported.

However, since more than 6 months have passed and no fix is yet avail

[ more ]  [ reply ]
[slackware-security] php (SSA:2014-307-03) 2014-11-04
Slackware Security Team (security slackware com)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

[slackware-security] php (SSA:2014-307-03)

New php packages are available for Slackware 14.0, 14.1, and -current to
fix security issues.

Here are the details from the Slackware 14.1 ChangeLog:
+--------------------------+
patches/packages/php-5.4.3

[ more ]  [ reply ]
[slackware-security] mozilla-firefox (SSA:2014-307-02) 2014-11-04
Slackware Security Team (security slackware com)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

[slackware-security] mozilla-firefox (SSA:2014-307-02)

New mozilla-firefox packages are available for Slackware 14.1 and -current to
fix security issues.

Here are the details from the Slackware 14.1 ChangeLog:
+--------------------------+
patches/p

[ more ]  [ reply ]
[slackware-security] mariadb (SSA:2014-307-01) 2014-11-04
Slackware Security Team (security slackware com)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

[slackware-security] mariadb (SSA:2014-307-01)

New mariadb packages are available for Slackware 14.1 and -current to
fix security issues.

Here are the details from the Slackware 14.1 ChangeLog:
+--------------------------+
patches/packages/mariadb-

[ more ]  [ reply ]
[slackware-security] seamonkey (SSA:2014-307-04) 2014-11-04
Slackware Security Team (security slackware com)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

[slackware-security] seamonkey (SSA:2014-307-04)

New seamonkey packages are available for Slackware 14.0, 14.1, and -current to
fix security issues.

Here are the details from the Slackware 14.1 ChangeLog:
+--------------------------+
patches/packag

[ more ]  [ reply ]
Modx CMS CSRF Bypass & XSS Vulnerabilities 2014-11-03
bhati contact gmail com
Public Disclosure -
http://hacktivity.websecgeeks.com/modx-csrf-and-xss/
===========================================
Product: MODX Revolution
Severity: Critical
Versions: 2.0.0?2.2.14
Vulnerability type: CSRF & XSS
Report date: 2014-Jul-10
Fixed date: 2014-Jul-15

Description
A significant vulnerab

[ more ]  [ reply ]
Ahrareandeysheh CMS Cross-Site Scripting Vulnerability 2014-11-03
iedb team gmail com
Ahrareandeysheh CMS All version suffers from a Cross-Site Scripting Vulnerability

#################################

#
# @@@ @@@@@@@@@@@ @@@@@ @@@@@@@@@@ @@@ @@@@@@@
# @@@ @@@@@@@@@@@ @@@ @@ @@@ @@ @@@ @@@@@@@@
# @@@ @@@

[ more ]  [ reply ]
CFP: Fourth World Congress - SEMCMI2015 - Malaysia 2014-11-03
Conference Updates (jackie sdiwc info)
The International Conference on Software Engineering, Mobile Computing
and Media Informatics (SEMCMI2015)
- Part of The Fourth World Congress on Computing and Information
Technology (WCIT) -

Asia Pacific University of Technology and Innovation (APU)
Kuala Lumpur, Malaysia
September 29 - October 1

[ more ]  [ reply ]
[SECURITY] [DSA 3062-1] wget security update 2014-11-02
Luciano Bello (luciano debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- ------------------------------------------------------------------------
-
Debian Security Advisory DSA-3062-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Luciano Bello
November 01, 2014

[ more ]  [ reply ]
[SECURITY] [DSA 3063-1] quassel security update 2014-11-02
Luciano Bello (luciano debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- ------------------------------------------------------------------------
-
Debian Security Advisory DSA-3063-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Luciano Bello
November 02, 2014

[ more ]  [ reply ]
PARSADEV CMS Cross-Site Scripting Vulnerability 2014-11-01
iedb team gmail com
PARSADEV CMS All version suffers from a Cross-Site Scripting Vulnerability

#################################

#
# @@@ @@@@@@@@@@@ @@@@@ @@@@@@@@@@ @@@ @@@@@@@
# @@@ @@@@@@@@@@@ @@@ @@ @@@ @@ @@@ @@@@@@@@
# @@@ @@@

[ more ]  [ reply ]
"Aircrack-ng 1.2 Beta 3" multiple vulnerabilities 2014-11-01
n sampanis obrela com
"Aircrack-ng 1.2 Beta 3" multiple vulnerabilities

Description:
--------------------------------
Four vulnerabilities exist on aircrack-ng <= 1.2 Beta 3 which allow remote/local code execution, privilege escalation and denial of service. Specifically, the following vulnerabilities were identified

[ more ]  [ reply ]
[SECURITY] [DSA 3061-1] icedove security update 2014-10-31
Moritz Muehlenhoff (jmm debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
-
Debian Security Advisory DSA-3061-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Moritz Muehlenhoff
October 31, 2014

[ more ]  [ reply ]
[SECURITY] [DSA 3060-1] linux security update 2014-10-31
Salvatore Bonaccorso (carnil debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- ------------------------------------------------------------------------
-
Debian Security Advisory DSA-3060-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Salvatore Bonaccorso
October 31, 2014

[ more ]  [ reply ]
[SE-2014-01] Missing patches / inaccurate information regarding Oracle Oct CPU 2014-10-31
Security Explorations (contact security-explorations com)

Hello All,

We've been recently informed by a 3rd party that Oracle planned to release
fixes for the vulnerabilities covered by our SE-2014-01 [1] project in Nov
2014.

We initially thought that someone mistakenly took Oct for Nov (Oracle CPU
was released on Oct 14, 2014), but the credibility of th

[ more ]  [ reply ]
SEC Consult SA-20141031-0 :: XML External Entity Injection (XXE) and Reflected XSS in Scalix Web Access 2014-10-31
SEC Consult Vulnerability Lab (research sec-consult com)
SEC Consult Vulnerability Lab Security Advisory < 20141031-0 >
=======================================================================
title: XML External Entity Injection (XXE) and Reflected XSS
product: Scalix Web Access
vulnerable version: 11.4.6.12377 and 12.2.0.14697

[ more ]  [ reply ]
[SYSS-2014-008] McAfee File and Removable Media Protection (FRP/EEFF/EERM) - Use of a One-Way Hash with a Predictable Salt (CVE-2014-8565) 2014-10-31
matthias deeg syss de
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~

Advisory ID: SYSS-2014-008
Product(s): McAfee Endpoint Encryption for Files and Folders (EEFF)
McAfee File and Removable Media Protection (FRP)
Vendor: McAfe

[ more ]  [ reply ]
[security bulletin] HPSBUX03162 SSRT101767 rev.1 - HP-UX Running OpenSSL, Remote Denial of Service (DoS), Unauthorized Access, Man-in-the-Middle (MitM) Attack 2014-10-31
security-alert hp com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Note: the current version of the following document is available here:
https://h20564.www2.hp.com/portal/site/hpsc/public/kb/
docDisplay?docId=emr_na-c04492722

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c04492722
Version: 1

HPSBUX03162 SS

[ more ]  [ reply ]
[security bulletin] HPSBPI03147 rev.1 - Certain HP Color LaserJet Printers, Remote Unauthorized Access, Denial of Service (DoS) 2014-10-30
security-alert hp com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Note: the current version of the following document is available here:
https://h20564.www2.hp.com/portal/site/hpsc/public/kb/
docDisplay?docId=emr_na-c04483249

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c04483249
Version: 1

HPSBPI03147 re

[ more ]  [ reply ]
Call for Papers - WorldCIST'15 - Azores, Deadline: November 23 2014-10-30
ML (marialemos72 gmail com)
------
WorldCIST'15 - 3rd World Conference on Information Systems and Technologies
Ponta Delgada, Azores *, Portugal
1 - 3 April 2015
http://www.aisti.eu/worldcist15/
------
* Azores is ranked as the second most beautiful archipelago in the world by National Geographic.
------------

SCOPE

The Wo

[ more ]  [ reply ]
[slackware-security] wget (SSA:2014-302-01) 2014-10-29
Slackware Security Team (security slackware com)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

[slackware-security] wget (SSA:2014-302-01)

New wget packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1,
and -current to fix a security issue.

Here are the details from the Slackware 14.1 ChangeLog:
+--------------------------+
patc

[ more ]  [ reply ]
[security bulletin] HPSBUX03159 SSRT101785 rev.2 - HP-UX kernel, Local Denial of Service (DoS) 2014-10-29
security-alert hp com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Note: the current version of the following document is available here:
https://h20564.www2.hp.com/portal/site/hpsc/public/kb/
docDisplay?docId=emr_na-c04491186

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c04491186
Version: 2

HPSBUX03159 SS

[ more ]  [ reply ]
[SECURITY] [DSA 3059-1] dokuwiki security update 2014-10-29
Moritz Muehlenhoff (jmm debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
-
Debian Security Advisory DSA-3059-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Moritz Muehlenhoff
October 29, 2014

[ more ]  [ reply ]
CVE-2014-8399 SQL Injection in NuevoLabs flash player for clipshare 2014-10-29
research protectlogic com
Nuevolabs Nuevoplayer for clipshare SQL Injection
=======================================================================

:: ADVISORY SUMMARY ::
Title: Nuevolabs Nuevoplayer for clipshare Sql Injection
Vendor: NUEVOLABS (www.nuevolabs.com)
Product: NUEVOPLAYER for clipshare
Credits: Cory

[ more ]  [ reply ]
SEC Consult SA-20141029-1 :: Persistent cross site scripting in Confluence RefinedWiki Original Theme 2014-10-29
SEC Consult Vulnerability Lab (research sec-consult com)
SEC Consult Vulnerability Lab Security Advisory < 20141029-1 >
=======================================================================
title: Persistent cross site scripting
product: Confluence RefinedWiki Original Theme
vulnerable version: 3.x - 4.0.x
fixed version:

[ more ]  [ reply ]
Multiple vulnerabilities in EspoCRM 2014-10-29
High-Tech Bridge Security Research (advisory htbridge com)
Advisory ID: HTB23238
Product: EspoCRM
Vendor: http://www.espocrm.com
Vulnerable Version(s): 2.5.2 and probably prior
Tested Version: 2.5.2
Advisory Publication: October 8, 2014 [without technical details]
Vendor Notification: October 8, 2014
Vendor Patch: October 10, 2014
Public Disclosure: Oct

[ more ]  [ reply ]
[ MDVSA-2014:212 ] wget 2014-10-29
security mandriva com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2014:212
http://www.mandriva.com/en/support/security/
___________________________________________________________

[ more ]  [ reply ]
[ MDVSA-2014:211 ] wpa_supplicant 2014-10-29
security mandriva com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2014:211
http://www.mandriva.com/en/support/security/
___________________________________________________________

[ more ]  [ reply ]
SEC Consult SA-20141029-0 :: Multiple critical vulnerabilities in Vizensoft Admin Panel 2014-10-29
SEC Consult Vulnerability Lab (research sec-consult com)
SEC Consult Vulnerability Lab Security Advisory < 20141029-0 >
=======================================================================
title: Multiple critical vulnerabilities
product: Vizensoft Admin Panel
vulnerable version: 2014
fixed version: -
impac

[ more ]  [ reply ]
[security bulletin] HPSBUX03159 SSRT101785 rev.1 - HP-UX kernel, Local Denial of Service (DoS) 2014-10-28
security-alert hp com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Note: the current version of the following document is available here:
https://h20564.www2.hp.com/portal/site/hpsc/public/kb/
docDisplay?docId=emr_na-c04491186

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c04491186
Version: 1

HPSBUX03159 SS

[ more ]  [ reply ]
(Page 5 of 1570)  < Prev  1 2 3 4 5 6 7 8 9 10 11  Next >


 

Privacy Statement
Copyright 2010, SecurityFocus