BugTraq Mode:
(Page 15 of 1719)  < Prev  10 11 12 13 14 15 16 17 18 19 20  Next >
[SECURITY] [DSA 3779-1] wordpress security update 2017-02-01
Sebastien Delafond (seb debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- ------------------------------------------------------------------------
-
Debian Security Advisory DSA-3779-1 security (at) debian (dot) org [email concealed]
https://www.debian.org/security/ Sebastien Delafond
February 01, 2017

[ more ]  [ reply ]
[security bulletin] HPESBHF03700 rev.1 - HPE iMC PLAT, Remote Disclosure of Information, Denial of Service (DoS) 2017-01-31
security-alert hpe com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Note: the current version of the following document is available here:

https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c053824
18

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c05382418

Version: 1

HPESBHF03700 rev.1

[ more ]  [ reply ]
[SECURITY] [DSA 3778-1] ruby-archive-tar-minitar security update 2017-01-31
Salvatore Bonaccorso (carnil debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- ------------------------------------------------------------------------
-
Debian Security Advisory DSA-3778-1 security (at) debian (dot) org [email concealed]
https://www.debian.org/security/ Salvatore Bonaccorso
January 31, 2017

[ more ]  [ reply ]
[security bulletin] HPESBGN03696 rev.1 - HPE Helion Eucalyptus, Remote Escalation of Privilege 2017-01-31
security-alert hpe com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Note: the current version of the following document is available here:

https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c053828
68

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c05382868

Version: 1

HPESBGN03696 rev.1

[ more ]  [ reply ]
[security bulletin] HPSBHF03693 rev.1 - HPE iMC PLAT Network Products running Microsoft SQL Server, Remote Elevation of Privilege 2017-01-31
security-alert hpe com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Note: the current version of the following document is available here:

https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c053827
40

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c05382740

Version: 1

HPSBHF03693 rev.1

[ more ]  [ reply ]
ESA-2017-007: EMC Documentum eRoom Unverified Password Change Vulnerability 2017-01-31
EMC Product Security Response Center (Security_Alert emc com)

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA256

ESA-2017-007: EMC Documentum eRoom Unverified Password Change Vulnerability

EMC Identifier: ESA-2017-007

CVE Identifier: CVE-2017-2766

Severity Rating: CVSS v3 Base Score: 5.7 (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L)

Affected products:

EM

[ more ]  [ reply ]
ESA-2016-094: RSA BSAFE Micro Edition Suite Multiple Vulnerabilities 2017-01-31
EMC Product Security Response Center (Security_Alert emc com)

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA256

ESA-2016-094: RSA BSAFE® Micro Edition Suite Multiple Vulnerabilities

EMC Identifier: ESA-2016-094

CVE Identifier: CVE-2016-0923, CVE-2016-0924

Affected Products:

? RSA BSAFE Micro Edition Suite (MES) all 4.1.x versions prior to 4.1.5

[ more ]  [ reply ]
[REVIVE-SA-2017-001] Revive Adserver - Multiple vulnerabilities 2017-01-31
Matteo Beccati (matteo beccati com)
========================================================================

Revive Adserver Security Advisory REVIVE-SA-2017-001
========================================================================

http://www.revive-adserver.com/security/revive-sa-2017-001
======================

[ more ]  [ reply ]
[security bulletin] HPESBMU03701 rev.1 - HPE Smart Storage Administrator, Remote Arbitrary Code Execution 2017-01-30
security-alert hpe com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Note: the current version of the following document is available here:

https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c053823
49

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c05382349

Version: 1

HPESBMU03701 rev.1

[ more ]  [ reply ]
Secunia Research: libarchive "lha_read_file_header_1()" Out-Of-Bounds Memory Access Denial of Service Vulnerability 2017-01-30
Secunia Research (remove-vuln secunia com)
======================================================================

Secunia Research 2017/01/27

libarchive "lha_read_file_header_1()" Out-Of-Bounds Memory Access

Denial of Service Vulnerability

===============================================

[ more ]  [ reply ]
secuvera-SA-2017-01: Privilege escalation in an OPSI Managed Client environment ("rise of the machines") 2017-01-30
sbieber secuvera de
Affected Products
Tested with
OPSI Server 4.0.7.26
OPSI ClientAgent 4.0.7.10-1
(older releases have not been tested)
According to the vendor all server instances that use a python-opsi version lower
than 4.0.7.28-4 are affected

References
https://www.secuvera.de/advisori

[ more ]  [ reply ]
Persistent Cross-Site Scripting vulnerability in User Access Manager WordPress Plugin 2017-01-28
Summer of Pwnage (lists securify nl)
------------------------------------------------------------------------

Persistent Cross-Site Scripting vulnerability in User Access Manager
WordPress Plugin
------------------------------------------------------------------------

Burak Kelebek, July 2016

------------------------------------------

[ more ]  [ reply ]
Multiple blind SQL injection vulnerabilities in FormBuilder WordPress Plugin 2017-01-28
Summer of Pwnage (lists securify nl)
------------------------------------------------------------------------

Multiple blind SQL injection vulnerabilities in FormBuilder WordPress
Plugin
------------------------------------------------------------------------

Burak Kelebek, July 2016

---------------------------------------------------

[ more ]  [ reply ]
CVE-2017-3160: Gradle Distribution URL used by Cordova-Android does not use https by default 2017-01-27
bowserj gmail com
===================================================================
CVE-2017-3160: Gradle Distribution URL used by Cordova-Android does not use https by default

Severity: High

Vendor: The Apache Software Foundation

Versions Affected: Cordova Android (6.1.1 and below)

Description: After the Andro

[ more ]  [ reply ]
[SECURITY] [DSA 3773-1] openssl security update 2017-01-27
Moritz Muehlenhoff (jmm debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- ------------------------------------------------------------------------
-
Debian Security Advisory DSA-3773-1 security (at) debian (dot) org [email concealed]
https://www.debian.org/security/ Moritz Muehlenhoff
January 27, 2017

[ more ]  [ reply ]
ESA-2016-133: EMC Data Protection Advisor Path Traversal Vulnerability 2017-01-26
EMC Product Security Response Center (Security_Alert emc com)

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA256

ESA-2016-133: EMC Data Protection Advisor Path Traversal Vulnerability

EMC Identifier: ESA-2016-133

CVE Identifier: CVE-2016-8211

Severity Rating: CVSS v3 Base Score: 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected products:

EMC

[ more ]  [ reply ]
ESA-2016-154: RSA BSAFE® Crypto-J Multiple Security Vulnerabilities 2017-01-26
EMC Product Security Response Center (Security_Alert emc com)

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA256

ESA-2016-154: RSA BSAFE® Crypto-J Multiple Security Vulnerabilities

EMC Identifier: ESA-2016-154

CVE Identifier: CVE-2016-8212, CVE-2016-8217

Severity Rating: See below for scores for individual issues

Affected Products:

? RSA BSA

[ more ]  [ reply ]
ESA-2016-037: EMC PowerPath Management Appliance Information Disclosure Vulnerability 2017-01-26
EMC Product Security Response Center (Security_Alert emc com)

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA256

ESA-2016-037: EMC PowerPath Management Appliance Information Disclosure Vulnerability

EMC Identifier: ESA-2016-037

CVE Identifier: CVE-2016-0890

Severity Rating: CVSS v3 Base Score: 6.4 (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L)

Affected

[ more ]  [ reply ]
Secunia Research: Oracle Outside In VSDX Use-After-Free Vulnerability 2017-01-27
Secunia Research (remove-vuln secunia com)
======================================================================

Secunia Research 2016/01/18

Oracle Outside In VSDX Use-After-Free Vulnerability

======================================================================

Table of Contents

Affected Software...

[ more ]  [ reply ]
[slackware-security] mozilla-thunderbird (SSA:2017-026-01) 2017-01-27
Slackware Security Team (security slackware com)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

[slackware-security] mozilla-thunderbird (SSA:2017-026-01)

New mozilla-thunderbird packages are available for Slackware 14.1, 14.2,
and -current to fix security issues.

Here are the details from the Slackware 14.2 ChangeLog:
+----------------------

[ more ]  [ reply ]
CA20170126-01: Security Notice for CA Common Services casrvc 2017-01-26
Kotas, Kevin J (Kevin Kotas ca com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

CA20170126-01: Security Notice for CA Common Services casrvc

Issued: January 26, 2017
Last Updated: January 26, 2017

CA Technologies support is alerting customers about a medium risk
vulnerability that may allow a local attacker to gain additional
p

[ more ]  [ reply ]
[SECURITY] [DSA 3772-1] libxpm security update 2017-01-26
Salvatore Bonaccorso (carnil debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- ------------------------------------------------------------------------
-
Debian Security Advisory DSA-3772-1 security (at) debian (dot) org [email concealed]
https://www.debian.org/security/ Salvatore Bonaccorso
January 26, 2017

[ more ]  [ reply ]
ESA-2016-167: EMC Documentum D2 Multiple Vulnerabilities 2017-01-26
EMC Product Security Response Center (Security_Alert emc com)

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA256

ESA-2016-167: EMC Documentum D2 Multiple Vulnerabilities

EMC Identifier: ESA-2016-167

CVE Identifier: CVE-2016-9872, CVE-2016-9873

Severity Rating: CVSS v3 Base Score: See below for CVSSv3 score.

Affected products:

EMC Documentum D2

[ more ]  [ reply ]
ESA-2016-160: EMC Data Domain DD OS Command Injection Vulnerability 2017-01-26
EMC Product Security Response Center (Security_Alert emc com)

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA256

ESA-2016-160: EMC Data Domain DD OS Command Injection Vulnerability

EMC Identifier: ESA-2016-160

CVE Identifier: CVE-2016-8216

Severity Rating: CVSS v3 Base Score: 6.7 (AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)

Affected products:

EMC Data

[ more ]  [ reply ]
ESA-2016-132: EMC RecoverPoint Multiple Vulnerabilities 2017-01-26
EMC Product Security Response Center (Security_Alert emc com)

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA256

ESA-2016-132: EMC RecoverPoint Multiple Vulnerabilities

EMC Identifier: ESA-2016-132

CVE Identifiers: CVE-2016-6648, CVE-2016-6649

Severity Rating: CVSS v3 Base Score: See below for individual scores.

Affected products:

EMC Recove

[ more ]  [ reply ]
ESA-2016-092: RSA® Web Threat Detection Cross Site Scripting Vulnerability 2017-01-26
EMC Product Security Response Center (Security_Alert emc com)

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA256

ESA-2016-092: RSA® Web Threat Detection Cross Site Scripting Vulnerability

EMC Identifier: ESA-2016-092

CVE Identifier: CVE-2016-0919

Severity Rating: CVSS v3 Base Score: 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L)

Affected Products:

·

[ more ]  [ reply ]
PEAR HTTP_Upload v1.0.0b3 Arbitrary File Upload 2017-01-26
apparitionsec gmail com (hyp3rlinx)
[+]#####################################################################
###########################
[+] Credits: John Page AKA Hyp3rlinx
[+] Website: hyp3rlinx.altervista.org
[+] Source: http://hyp3rlinx.altervista.org/advisories/PEAR-HTTP_UPLOAD-ARBITRARY-FI
LE-UPLOAD.txt
[+] ISR: ApparitionSEC

[ more ]  [ reply ]
[SECURITY] [DSA 3771-1] firefox-esr security update 2017-01-25
Moritz Muehlenhoff (jmm debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- ------------------------------------------------------------------------
-
Debian Security Advisory DSA-3771-1 security (at) debian (dot) org [email concealed]
https://www.debian.org/security/ Moritz Muehlenhoff
January 25, 2017

[ more ]  [ reply ]
Google Forms WordPress Plugin unauthenticated PHP Object injection vulnerability 2017-01-25
Summer of Pwnage (lists securify nl)
------------------------------------------------------------------------

Google Forms WordPress Plugin unauthenticated PHP Object injection
vulnerability
------------------------------------------------------------------------

Yorick Koster, June 2016

-----------------------------------------------

[ more ]  [ reply ]
Cisco Security Advisory: Cisco TelePresence Multipoint Control Unit Remote Code Execution Vulnerability 2017-01-25
Cisco Systems Product Security Incident Response Team (psirt cisco com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Cisco Security Advisory: Cisco TelePresence Multipoint Control Unit Remote Code Execution Vulnerability

Advisory ID: cisco-sa-20170125-telepresence

Revision 1.0

For Public Release 2017 January 25 16:00 UTC (GMT)

+-----------------------------------

[ more ]  [ reply ]
(Page 15 of 1719)  < Prev  10 11 12 13 14 15 16 17 18 19 20  Next >


 

Privacy Statement
Copyright 2010, SecurityFocus