Bugtraq: by date

43 messages starting Oct 02 17 and ending Oct 31 17
Date index | Thread index | Author index


Monday, 02 October

Mac OS X Local Javascript Quarantine Bypass Filippo Cavallarin
Trend Micro OfficeScan v11.0 and XG (12.0)* Unauthorized Remote Memory Corruption CVE-2017-14089 (apparitionsec / hyp3rlinx) apparitionsec
Trend Micro OfficeScan v11.0 and XG (12.0)* Unauthorized Change Prevention Image File Execution Bypass (apparitionsec / hyp3rlinx) apparitionsec
Trend Micro OfficeScan v11.0 and XG (12.0)* Unauthorized Remote Encryption Key Disclosure CVE-2017-14083 (apparitionsec / hyp3rlinx) apparitionsec
Trend Micro OfficeScan v11.0 and XG (12.0)* Unauthorized Start Remote Process Code Execution / DOS - INI Corruption CVE-2017-14086 (apparitionsec / hyp3rlinx) apparitionsec
Trend Micro OfficeScan v11.0 and XG (12.0)* CURL (MITM) Remote Code Execution CVE-2017-14084 (apparitionsec / hyp3rlinx) apparitionsec
[SECURITY] [DSA 3986-1] ghostscript security update Salvatore Bonaccorso
[SECURITY] [DSA 3987-1] firefox-esr security update Moritz Muehlenhoff
Mac OS X Local Javascript Quarantine Bypass filippo . cavallarin
Trend Micro OfficeScan v11.0 and XG (12.0)* Unauthorized Server Side Request Forgery (apparitionsec / hyp3rlinx) apparitionsec
Trend Micro OfficeScan v11.0 and XG (12.0)* Unauthorized NT Domain / PHP Information Disclosures CVE-2017-14085 (apparitionsec / hyp3rlinx) apparitionsec
[SECURITY] [DSA 3988-1] libidn2-0 security update Salvatore Bonaccorso

Tuesday, 03 October

HPESBMU03753 rev.1 - HPE System Management Homepage, Multiple Remote Vulnerabilities HPE Product Security Response Team
[security bulletin] HPESBHF03776 rev.1 - HPE Intelligent Management Center (iMC) Service Operation Management (SOM), Remote Arbitrary File Download security-alert

Thursday, 05 October

DefenseCode Security Advisory: Magento Commerce CSRF, Stored Cross Site Scripting #1 DefenseCode

Friday, 06 October

[slackware-security] xorg-server (SSA:2017-279-03) Slackware Security Team

Monday, 09 October

[SECURITY] [DSA 3993-1] tor security update Moritz Muehlenhoff
[SECURITY] [DSA 3994-1] nautilus security update Yves-Alexis Perez

Wednesday, 11 October

[SECURITY] [DSA 3995-1] libxfont security update Moritz Muehlenhoff

Friday, 13 October

Multiple vulnerabilities in OpenText Documentum Content Server Andrey B. Panfilov

Sunday, 15 October

[RCESEC-2017-002][CVE-2017-14956] AlienVault USM v5.4.2 "/ossim/report/wizard_email.php" Cross-Site Request Forgery leading to Sensitive Information Disclosure Julien Ahrens
Advisory X41-2017-008: Multiple Vulnerabilities in Shadowsocks X41 D-Sec GmbH Advisories
Advisory X41-2017-010: Command Execution in Shadowsocks-libev X41 D-Sec GmbH Advisories
[security bulletin] MFSBGN03786 rev.1 - HPE Connected Backup, Local Escalation of Privilege swpmb . cyber-psrt

Monday, 16 October

SEC Consult SA-20171016-0 :: Multiple vulnerabilities in Micro Focus VisiBroker C++ SEC Consult Vulnerability Lab
[SECURITY] [DSA 3999-1] wpa security update Yves-Alexis Perez

Wednesday, 18 October

[security bulletin] HPESBHF03789 rev.2 - Certain HPE Gen9 Systems with HP Trusted Platform Module v2.0 Option, Unauthorized Access to Data security-alert
SEC Consult SA-20171018-1 :: Multiple vulnerabilities in Linksys E-series products SEC Consult Vulnerability Lab
WebKitGTK+ Security Advisory WSA-2017-0008 Carlos Alberto Lopez Perez
[slackware-security] libXres (SSA:2017-291-01) Slackware Security Team
[slackware-security] wpa_supplicant (SSA:2017-291-02) Slackware Security Team
[slackware-security] xorg-server (SSA:2017-291-03) Slackware Security Team
FreeBSD Security Advisory FreeBSD-SA-17:07.wpa [REVISED] FreeBSD Security Advisories

Thursday, 19 October

[SECURITY] [DSA 4002-1] mysql-5.5 security update Salvatore Bonaccorso
[SECURITY] [DSA 4003-1] libvirt security update Salvatore Bonaccorso

Tuesday, 24 October

[security bulletin] HPESBHF03779 rev.1 - HPE Fabric OS using OpenSSH, Denial of Service HPE Product Security Response Team
[SECURITY] [DSA 4006-1] mupdf security update Luciano Bello
KL-001-2017-017 : Infoblox NetMRI Administration Shell Escape and Privilege Escalation KoreLogic Disclosures

Wednesday, 25 October

KL-001-2017-020 : Sophos UTM 9 loginuser Privilege Escalation via Insecure Directory Permissions KoreLogic Disclosures

Thursday, 26 October

October 2017 - Bamboo - Critical Security Advisory Atlassian
Bomgar Remote Support - Local Privilege Escalation (CVE-2017-5996) VSR Advisories

Friday, 27 October

[VulnWatch] Advisory 02/2002: PHP remote vulnerability e-matters Security

Tuesday, 31 October

[security bulletin] HPESBHF03787 rev.1 - Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT, Deserialization of Untrusted Data, Remote Code Execution security-alert