|
Colapse all |
Post message
[slackware-security] mozilla-firefox (SSA:2016-219-02) 2016-08-06 Slackware Security Team (security slackware com) [SECURITY] [DSA 3643-1] kde4libs security update 2016-08-06 Salvatore Bonaccorso (carnil debian org) Ecwid Ecommerce Shopping Cart WordPress Plugin unauthenticated PHP Object injection vulnerability 2016-08-05 Summer of Pwnage (lists securify nl) ------------------------------------------------------------------------ Ecwid Ecommerce Shopping Cart WordPress Plugin unauthenticated PHP Object injection vulnerability ------------------------------------------------------------------------ Yorick Koster, June 2016 ------------------------------ [ more ] [ reply ] DLL side loading vulnerability in VMware Host Guest Client Redirector 2016-08-05 Securify B.V. (lists securify nl) ------------------------------------------------------------------------ DLL side loading vulnerability in VMware Host Guest Client Redirector ------------------------------------------------------------------------ Yorick Koster, December 2015 ------------------------------------------------------ [ more ] [ reply ] Sophos Mobile Control EAS Proxy Open Reverse Proxy vulnerability (CVE-2016-6597) 2016-08-05 Tim Kretschmann (tim kretschmann pallas com) Application: Sophos Mobile Control EAS Proxy Versions Affected: 3.5.0.3 Vendor URL: https://www.sophos.com/ Bugs: Open Reverse Proxy Sent: 30.06.2016 Reported: 05.07.2016 Vendor response: 13.07.2016 Published BugFix by vendor: 28.07.2016 Date of Public Advisory: 05.08.2016 Reference: Sophos Case #6 [ more ] [ reply ] Sophos Mobile Control EAS Proxy Open Reverse Proxy vulnerability (CVE-2016-6597) 2016-08-05 Tim Kretschmann (tim kretschmann pallas com) Application: Sophos Mobile Control EAS Proxy Versions Affected: 3.5.0.3 Vendor URL: https://www.sophos.com/ Bugs: Open Reverse Proxy Sent: 30.06.2016 Reported: 05.07.2016 Vendor response: 13.07.2016 Published BugFix by vendor: 28.07.2016 Date of Public Advisory: 05.08.2016 Reference: Sophos Case #6 [ more ] [ reply ] Subrion v4.0.5 CMS - SQL Injection Vulnerability 2016-08-05 Vulnerability Lab (research vulnerability-lab com) Document Title: =============== Subrion v4.0.5 CMS - SQL Injection Vulnerability References (Source): ==================== http://www.vulnerability-lab.com/get_content.php?id=1893 Release Date: ============= 2016-08-04 Vulnerability Laboratory ID (VL-ID): ==================================== 1 [ more ] [ reply ] FortiCloud - (Reports Summary) Multiple Persistent Vulnerabilities 2016-08-05 Vulnerability Lab (research vulnerability-lab com) Document Title: =============== FortiCloud - (Reports Summary) Multiple Persistent Vulnerabilities References (Source): ==================== http://www.vulnerability-lab.com/get_content.php?id=1735 Release Date: ============= 2016-08-05 Vulnerability Laboratory ID (VL-ID): ==================== [ more ] [ reply ] Typesettercms v5.0.1 - (Delete Files) CSRF Vulnerability 2016-08-05 Vulnerability Lab (research vulnerability-lab com) Document Title: =============== Typesettercms v5.0.1 - (Delete Files) CSRF Vulnerability References (Source): ==================== http://www.vulnerability-lab.com/get_content.php?id=1889 Release Date: ============= 2016-08-03 Vulnerability Laboratory ID (VL-ID): ============================= [ more ] [ reply ] [0day] net2ftp multiple XSS on unauthenticated users 2016-08-05 Jacobo Avariento (jacobo sofistic com) *Summary* Subject: net2ftp XSS in "command" and "url_withpw" parameters Versions vulnerable: ALL (Tested on latest, version 1.0) Category: 0-day Impact: Medium *Description of the product* net2ftp is a web based FTP client (_http://www.net2ftp.com/index.php_ <http://www.net2ftp.com/index.php>) [ more ] [ reply ] Stored Cross-Site Scripting vulnerability in Count per Day WordPress Plugin 2016-08-04 Summer of Pwnage (lists securify nl) ------------------------------------------------------------------------ Stored Cross-Site Scripting vulnerability in Count per Day WordPress Plugin ------------------------------------------------------------------------ Julien Rentrop, July 2016 --------------------------------------------------- [ more ] [ reply ] Cross-Site Scripting in Count per Day WordPress Plugin 2016-08-04 Summer of Pwnage (lists securify nl) ------------------------------------------------------------------------ Cross-Site Scripting in Count per Day WordPress Plugin ------------------------------------------------------------------------ Yorick Koster, July 2016 ------------------------------------------------------------------------ [ more ] [ reply ] Cross-Site Scripting in FormBuilder WordPress Plugin 2016-08-04 Summer of Pwnage (lists securify nl) ------------------------------------------------------------------------ Cross-Site Scripting in FormBuilder WordPress Plugin ------------------------------------------------------------------------ Peter Ganzevles, July 2016 ------------------------------------------------------------------------ [ more ] [ reply ] Cross-Site Scripting vulnerability in Events Made Easy WordPress plugin 2016-08-04 Summer of Pwnage (lists securify nl) ------------------------------------------------------------------------ Cross-Site Scripting vulnerability in Events Made Easy WordPress plugin ------------------------------------------------------------------------ Job Diesveld, July 2016 --------------------------------------------------------- [ more ] [ reply ] Multiple remote vulnerabilities (RCE, bof) in Nuuo NVR and NETGEAR Surveillance 2016-08-04 Pedro Ribeiro (pedrib gmail com) (1 replies) tl;dr Lots of RCE, hardcoded credentials, stack buffer overflow and information disclosure in the Nuuo NVRmini and other network video recorders of the same vendor. These vulnerabilities also affect the NETGEAR Surveillance app (which can be installed on the NETGEAR ReadyNAS). See the full [ more ] [ reply ] Re: Multiple remote vulnerabilities (RCE, bof) in Nuuo NVR and NETGEAR Surveillance 2016-08-04 Pedro Ribeiro (pedrib gmail com) Cisco Security Advisory: Cisco IOS Software Crafted Network Time Protocol Packets Denial of Service Vulnerability 2016-08-04 Cisco Systems Product Security Incident Response Team (psirt cisco com) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Cisco Security Advisory: Cisco IOS Software Crafted Network Time Protocol Packets Denial of Service Vulnerability Advisory ID: cisco-sa-20160804-wedge Revision 1.0 For Public Release 2016 August 4 16:00 GMT +-------------------------------------- [ more ] [ reply ] [SYSS-2016-065] NASdeluxe NDL-2400r: OS Command Injection 2016-08-04 klaus eisentraut syss de Advisory ID: SYSS-2016-065 Product: NASdeluxe NDL-2400r Vendor: Starline Computer GmbH Affected Version(s): 2.01.10 Tested Version(s): 2.01.09 Vulnerability Type: OS Command Injection (CWE-78) Risk Level: High Solution Status: no fix (product has reached EOL since 3 years) Vendor Notification: 2016 [ more ] [ reply ] FortiManager (Series) - (Bookmark) Persistent Vulnerability 2016-08-04 Vulnerability Lab (research vulnerability-lab com) Document Title: =============== FortiManager (Series) - (Bookmark) Persistent Vulnerability References (Source): ==================== http://www.vulnerability-lab.com/get_content.php?id=1685 Fortinet PSIRT ID: 1624461 Release Notes 1: http://docs.fortinet.com/uploaded/files/2499/fortios-5.0.12-r [ more ] [ reply ] FortiAnalyzer & FortiManager - Client Side Cross Site Scripting Web Vulnerability 2016-08-04 Vulnerability Lab (research vulnerability-lab com) Document Title: =============== FortiAnalyzer & FortiManager - Client Side Cross Site Scripting Web Vulnerability References (Source): ==================== http://www.vulnerability-lab.com/get_content.php?id=1686 Fortinet PSIRT ID: 1624489 Release Notes 1: http://docs.fortinet.com/uploaded/files [ more ] [ reply ] Cross-Site Scripting in WordPress Landing Pages Plugin 2016-08-03 Summer of Pwnage (lists securify nl) ------------------------------------------------------------------------ Cross-Site Scripting in WordPress Landing Pages Plugin ------------------------------------------------------------------------ Burak Kelebek, July 2016 ------------------------------------------------------------------------ [ more ] [ reply ] Cross-Site Scripting in Activity Log WordPress Plugin 2016-08-03 Summer of Pwnage (lists securify nl) ------------------------------------------------------------------------ Cross-Site Scripting in Activity Log WordPress Plugin ------------------------------------------------------------------------ Yorick Koster, July 2016 ------------------------------------------------------------------------ A [ more ] [ reply ] Cross-Site Scripting vulnerability in search function Activity Log WordPress Plugin 2016-08-03 Summer of Pwnage (lists securify nl) ------------------------------------------------------------------------ Cross-Site Scripting vulnerability in search function Activity Log WordPress Plugin ------------------------------------------------------------------------ Edwin Molenaar, July 2016 ------------------------------------------- [ more ] [ reply ] Secunia Research: LibGD "_gdContributionsAlloc()" Integer Overflow Denial of Service Vulnerability 2016-08-03 Secunia Research (remove-vuln secunia com) |
|
Privacy Statement |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
[slackware-security] mozilla-firefox (SSA:2016-219-02)
New mozilla-firefox packages are available for Slackware 14.1 and 14.2 to
fix security issues.
Here are the details from the Slackware 14.2 ChangeLog:
+--------------------------+
patches/packa
[ more ] [ reply ]