Exploit
- Tue, 04 Mar 2014 00:00:00 +0000: [local] - Calavera UpLoader 3.5 - SEH Buffer Overflow - Exploit-DB updates
Calavera UpLoader 3.5 - SEH Buffer Overflow - Mon, 03 Mar 2014 00:00:00 +0000: [webapps] - SpagoBI 4.0 - Persistent XSS Vulnerability - Exploit-DB updates
SpagoBI 4.0 - Persistent XSS Vulnerability - Mon, 03 Mar 2014 00:00:00 +0000: [webapps] - couponPHP CMS 1.0 - Multiple Stored XSS and SQL Injection Vulnerabilities - Exploit-DB updates
couponPHP CMS 1.0 - Multiple Stored XSS and SQL Injection Vulnerabilities - Mon, 03 Mar 2014 00:00:00 +0000: [webapps] - SpagoBI 4.0 - Persistent HTML Script Insertion - Exploit-DB updates
SpagoBI 4.0 - Persistent HTML Script Insertion - Mon, 03 Mar 2014 00:00:00 +0000: [local] - ALLPlayer 5.8.1 - (.m3u file) Buffer Overflow (SEH) - Exploit-DB updates
ALLPlayer 5.8.1 - (.m3u file) Buffer Overflow (SEH) - Mon, 03 Mar 2014 00:00:00 +0000: [webapps] - SpagoBI 4.0 - Arbitrary XSS File Upload - Exploit-DB updates
SpagoBI 4.0 - Arbitrary XSS File Upload - Sat, 01 Mar 2014 00:00:00 +0000: [webapps] - Oracle Demantra 12.2.1 - Stored XSS Vulnerability - Exploit-DB updates
Oracle Demantra 12.2.1 - Stored XSS Vulnerability - Sat, 01 Mar 2014 00:00:00 +0000: [webapps] - Oracle Demantra 12.2.1 - SQL Injection Vulnerability - Exploit-DB updates
Oracle Demantra 12.2.1 - SQL Injection Vulnerability - Sat, 01 Mar 2014 00:00:00 +0000: [webapps] - Oracle Demantra 12.2.1 - Database Credentials Disclosure - Exploit-DB updates
Oracle Demantra 12.2.1 - Database Credentials Disclosure - Sat, 01 Mar 2014 00:00:00 +0000: [webapps] - Oracle Demantra 12.2.1 - Arbitrary File Disclosure - Exploit-DB updates
Oracle Demantra 12.2.1 - Arbitrary File Disclosure
PACKETSTORM DATABASE
- 5 March 2014: Windows Escalate UAC Protection Bypass (In Memory Injection) - Files ≈ Packet Storm
This Metasploit module will bypass Windows UAC by utilizing the trusted publisher certificate through process injection. It will spawn a second shell that has the UAC flag turned off. This Metasploit module uses the Reflective DLL Injection technique to drop only the DLL payload binary instead of three separate binaries in the standard technique. However, it requires the correct architecture to be selected, (use x64 for SYSWOW64 systems also). - 5 March 2014: ALLPlayer M3U Buffer Overflow - Files ≈ Packet Storm
This Metasploit module exploits a stack-based buffer overflow vulnerability in ALLPlayer 2.8.1, caused by a long string in a playlist entry. By persuading the victim to open a specially-crafted .M3U file, a remote attacker could execute arbitrary code on the system or cause the application to crash. This Metasploit module has been tested successfully on Windows 7 SP1. - 5 March 2014: Red Hat Security Advisory 2014-0249-01 - Files ≈ Packet Storm
Red Hat Security Advisory 2014-0249-01 - PostgreSQL is an advanced object-relational database management system. Multiple stack-based buffer overflow flaws were found in the date/time implementation of PostgreSQL. An authenticated database user could provide a specially crafted date/time value that, when processed, could cause PostgreSQL to crash or, potentially, execute arbitrary code with the permissions of the user running PostgreSQL. Multiple integer overflow flaws, leading to heap-based buffer overflows, were found in various type input functions in PostgreSQL. An authenticated database user could possibly use these flaws to crash PostgreSQL or, potentially, execute arbitrary code with the permissions of the user running PostgreSQL. - 5 March 2014: Ubuntu Security Notice USN-2127-1 - Files ≈ Packet Storm
Ubuntu Security Notice 2127-1 - Nikos Mavrogiannopoulos discovered that GnuTLS incorrectly handled certificate verification functions. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited with specially crafted certificates to view sensitive information. - 5 March 2014: Apache Cordova 2.9.0 File-Transfer Insecure Defaults - Files ≈ Packet Storm
Cordova File-Transfer iOS plugin from Cordova versions 2.4.0 to 2.9.0 and Cordova File-Transfer iOS standalone plugin (org.apache.cordova.file-transfer) versions 0.1.0 to 0.4.1 suffers from file-transfer insecure default settings. - 4 March 2014: Java OpenID Server 1.2.1 XSS / Session Fixation - Files ≈ Packet Storm
JOIDS (Java OpenID Server) version 1.2.1 suffers from reflected cross site scripting and session fixation vulnerabilities. - 4 March 2014: ClickDesk 4.3 Cross Site Scripting - Files ≈ Packet Storm
ClickDesk versions 4.3 and below suffer from multiple persistent cross site scripting vulnerabilities. - 4 March 2014: Google Youtube Arbitrary File Upload - Files ≈ Packet Storm
Youtube.com suffered from an arbitrary file upload vulnerability when headers were manipulated. - 4 March 2014: Ganib 2.3 SQL Injection - Files ≈ Packet Storm
Ganib versions 2.3 and below suffer from a remote SQL injection vulnerability. - 4 March 2014: Red Hat Security Advisory 2014-0233-01 - Files ≈ Packet Storm
Red Hat Security Advisory 2014-0233-01 - PackStack is a command-line utility that uses Puppet modules to support rapid deployment of OpenStack on existing servers over an SSH connection. PackStack is suitable for deploying both single node proof-of-concept installations and more complex multi-node installations. It was found that PackStack did not correctly install the rules defined in the default security groups when deployed on OpenStack Networking, allowing network connections to be made to systems that should not have been accessible. - 4 March 2014: Red Hat Security Advisory 2014-0232-01 - Files ≈ Packet Storm
Red Hat Security Advisory 2014-0232-01 - OpenStack Object Storage provides object storage in virtual containers, which allows users to store and retrieve files. The service's distributed architecture supports horizontal scaling; redundancy as failure-proofing is provided through software-based data replication. Because Object Storage supports asynchronous eventual consistency replication, it is well suited to multiple data-center deployment. A timing attack flaw was found in the way the swift TempURL middleware responded to arbitrary TempURL requests. An attacker with knowledge of an object's name could use this flaw to obtain a secret URL to this object, which was intended to be publicly shared only with specific recipients, if the object had the TempURL key set. Note that only setups using the TempURL middleware were affected. - 4 March 2014: Apache Cordova 2.9.0 Privilege Escalation - Files ≈ Packet Storm
Cordova In-App-Browser iOS plugin from Cordova versions 2.6.0 to 2.9.0 and Cordova In-App-Browser iOS standalone plugin (org.apache.cordova.inappbrowser) versions 0.1.0 to 0.3.1 suffer from a privilege escalation vulnerability. - 4 March 2014: Apache Shiro 1.2.2 LDAP Authentication Bypass - Files ≈ Packet Storm
Apache Shiro versions 1.0.0-incubating through 1.2.2 suffer from an LDAP authentication bypass vulnerability. - 4 March 2014: Ipdecap 0.7 - Files ≈ Packet Storm
Ipdecap can decapsulate traffic encapsulated within GRE, IPIP, 6in4, and ESP (IPSEC) protocols, and can also remove IEEE 802.1Q (virtual LAN) headers. It reads packets from a pcap file, removes the encapsulation protocol, and writes them in another pcap file. - 4 March 2014: Red Hat Security Advisory 2014-0229-01 - Files ≈ Packet Storm
Red Hat Security Advisory 2014-0229-01 - OpenStack Image service provides discovery, registration, and delivery services for disk and server images. It provides the ability to copy or snapshot a server image, and immediately store it away. Stored images can be used as a template to get new servers up and running quickly and more consistently than installing a server operating system and individually configuring additional services. An information leak flaw was found in the way glance stored certain logging information. An attacker with access to the glance log files could use this flaw to obtain authentication credentials to the OpenStack Object Storage back end. Note that only setups using the swift back end were affected.
CERT VULNERABILITY DATABASE
- Tue, 04 Mar 2014 19:02:36 +0000: VU#600724: ZTE F460/F660 cable modems contain an unauthenticated backdoor - CERT Recently Published Vulnerability Notes
ZTE F460/F660 cable modems contain an unauthenticated backdoor. - Mon, 03 Mar 2014 18:27:36 +0000: VU#525132: Foscam IP camera authentication bypass vulnerability - CERT Recently Published Vulnerability Notes
The FI8910W Foscam IP camera running firmware version 11.37.2.54 fails to properly authenticate users. - Fri, 28 Feb 2014 18:09:36 +0000: VU#221620: Blue Coat ProxySG local user changes contain a time and state vulnerability - CERT Recently Published Vulnerability Notes
Changes to Blue Coat ProxySG local users do not take effect immediately,giving an attacker with known credentials a window of opportunity to use those credentials even if the user was deleted or the password was changed. (CWE-361) - Fri, 28 Feb 2014 14:07:36 +0000: VU#526062: CMS Made Simple contains multiple cross-site scripting vulnerabilities - CERT Recently Published Vulnerability Notes
CMS Made Simple contains multiple cross-site scripting vulnerabilities - Thu, 27 Feb 2014 11:42:37 +0000: VU#534284: Synology DiskStation Manager VPN module hard-coded password vulnerability - CERT Recently Published Vulnerability Notes
Synology DiskStation Manager VPN module contains a hard-coded password which cannot be changed. - Tue, 25 Feb 2014 16:46:37 +0000: VU#684412: libpng denial-of-service vulnerability - CERT Recently Published Vulnerability Notes
libpng versions 1.6.0 through 1.6.9 contain a denial-of-service vulnerability. - Tue, 18 Feb 2014 11:21:36 +0000: VU#656302: Belkin Wemo Home Automation devices contain multiple vulnerabilities - CERT Recently Published Vulnerability Notes
Belkin Wemo Home Automation devices contain multiple vulnerabilities. - Mon, 17 Feb 2014 14:37:36 +0000: VU#539289: Microsoft XMLDOM ActiveX control information disclosure vulnerability - CERT Recently Published Vulnerability Notes
The Microsoft XMLDOM ActiveX control can be used to check for the presence of multiple resources,which can result in unintended information disclosure. - Sat, 15 Feb 2014 00:50:36 +0000: VU#732479: Internet Explorer CMarkup use-after-free vulnerability - CERT Recently Published Vulnerability Notes
Microsoft Internet Explorer contains a use-after-free vulnerability in the MSHTML CMarkup component,which can allow a remote,unauthenticated attacker to execute arbitrary code on a vulnerable system. - Tue, 11 Feb 2014 20:48:05 +0000: VU#727318: DELL SonicWALL GMS/Analyzer/UMA contains a cross-site scripting (XSS) vulnerability - CERT Recently Published Vulnerability Notes
DELL SonicWALL GMS/Analyzer/UMA version 7.1,and possibly earlier versions,contains a cross-site scripting(XSS)vulnerability. (CWE-79) - Thu, 06 Feb 2014 18:05:05 +0000: VU#146430: F5 Networks BIG-IP Edge Client information leakage vulnerability - CERT Recently Published Vulnerability Notes
F5 Networks has reported a flaw in the BIG-IP APM and the FirePass client-side F5-signed Edge Client components. The components may leak information from memory. (CWE-200) - Tue, 04 Feb 2014 19:47:05 +0000: VU#813382: Dell KACE K1000 management appliance contains a cross-site scripting vulnerability - CERT Recently Published Vulnerability Notes
Dell KACE K1000 management appliance version 5.5.90545,and possibly earlier versions,contains a cross-site scripting(XSS)vulnerability. (CWE-79) - Mon, 03 Feb 2014 20:07:05 +0000: VU#431726: Seowon Intech WiMAX SWU-9100 mobile router contains multiple vulnerabilities - CERT Recently Published Vulnerability Notes
Seowon Intech WiMAX SWU-9100 mobile routers contain command injection(CWE-77)and direct request(CWE-425)vulnerabilities. - Mon, 03 Feb 2014 12:09:10 +0000: VU#593118: Fortinet Fortiweb 5.0.3 contains a reflected cross-site scripting vulnerability - CERT Recently Published Vulnerability Notes
Fortinet Fortiweb 5.0.3,and possibly earlier versions,contains a cross-site scripting vulnerability. (CWE-79) - Mon, 03 Feb 2014 12:09:10 +0000: VU#728638: Fortinet FortiOS 5.0.5 contains a reflected cross-site scripting (XSS) vulnerability - CERT Recently Published Vulnerability Notes
Fortinet FortiOS 5.0.5,and possibly earlier versions,contains a cross-site scripting vulnerability. (CWE-79)
SECURITYFOCUS DATABASE
- Wed, 05 Mar 2014 00:00:00 +0000: Vuln: GnuTLS CVE-2014-0092 Certificate Validation Security Bypass Vulnerability - SecurityFocus Vulnerabilities
GnuTLS CVE-2014-0092 Certificate Validation Security Bypass Vulnerability - Wed, 05 Mar 2014 00:00:00 +0000: Vuln: PostgreSQL CVE-2014-0063 Remote Stack Buffer Overflow Vulnerability - SecurityFocus Vulnerabilities
PostgreSQL CVE-2014-0063 Remote Stack Buffer Overflow Vulnerability - Wed, 05 Mar 2014 00:00:00 +0000: Vuln: PostgreSQL CVE-2014-0064 Multiple Remote Buffer Overflow Vulnerabilities - SecurityFocus Vulnerabilities
PostgreSQL CVE-2014-0064 Multiple Remote Buffer Overflow Vulnerabilities - Wed, 05 Mar 2014 00:00:00 +0000: Vuln: PostgreSQL CVE-2014-0066 Remote Denial Of Service Vulnerability - SecurityFocus Vulnerabilities
PostgreSQL CVE-2014-0066 Remote Denial Of Service Vulnerability - : Bugtraq: [CVE-2014-0072] Apache Cordova File-Transfer insecure defaults - SecurityFocus Vulnerabilities
[CVE-2014-0072] Apache Cordova File-Transfer insecure defaults - : Bugtraq: [CVE-2014-0073] Apache Cordova In-App-Browser privilege escalation - SecurityFocus Vulnerabilities
[CVE-2014-0073] Apache Cordova In-App-Browser privilege escalation - : Bugtraq: JOIDS (Java OpenID Server) multiple vulnerabilities - SecurityFocus Vulnerabilities
JOIDS (Java OpenID Server) multiple vulnerabilities - : Bugtraq: [slackware-security] gnutls (SSA:2014-062-01) - SecurityFocus Vulnerabilities
[slackware-security] gnutls (SSA:2014-062-01) - : More rss feeds from SecurityFocus - SecurityFocus Vulnerabilities
News, Infocus, Columns, Vulnerabilities, Bugtraq ...
Tidak ada komentar:
Posting Komentar