Bugtraq: by author

61 messages starting Mar 17 19 and ending Mar 03 19
Date index | Thread index | Author index


Anti Räis

Gitea 1.7.3 stored HTML injection (XSS) Anti Räis (Mar 17)

apparitionsec

Microsoft Windows .Reg File Dialog Box Message Spoofing 0day apparitionsec (Mar 12)
[**UPDATED] Microsoft Windows .Reg File Dialog Box Message Spoofing 0day apparitionsec (Mar 12)

Apple Product Security

APPLE-SA-2019-3-27-1 watchOS 5.2 Apple Product Security (Mar 27)
APPLE-SA-2019-3-25-2 macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra Apple Product Security (Mar 26)
APPLE-SA-2019-3-25-6 iCloud for Windows 7.11 Apple Product Security (Mar 26)
APPLE-SA-2019-3-25-7 Xcode 10.2 Apple Product Security (Mar 26)
APPLE-SA-2019-3-25-5 iTunes 12.9.4 for Windows Apple Product Security (Mar 26)
APPLE-SA-2019-3-25-3 tvOS 12.2 Apple Product Security (Mar 26)
APPLE-SA-2019-3-25-4 Safari 12.1 Apple Product Security (Mar 26)
APPLE-SA-2019-3-25-1 iOS 12.2 Apple Product Security (Mar 26)

Atlassian

Atlassian - Confluence Security Advisory - 2019-03-20 Atlassian (Mar 25)

cfp

Recon 2019 Call For Papers - June 28 - 30, 2019 - Montreal, Canada cfp (Mar 26)

Christian Lerrahn

[article2pdf (Wordpress plug-in)] Multiple vulnerabilities (CVE-2019-1000031, CVE-2019-1010257) Christian Lerrahn (Mar 26)

David Coomber

Cisco Common Service Platform Collector - Hardcoded Credentials (CVE-2019-1723) David Coomber (Mar 13)

Ece örsel

SAP J2EE Engine/7.01/Fiori Reflected Cross Site Scripting (XSS) Ece örsel (Mar 04)
SAP J2EE Engine/7.01/Portal/EPP Reflected Cross Site Scripting (XSS) Ece örsel (Mar 04)
SAP J2EE Engine/7.01/Fiori Reflected Cross Site Scripting (XSS) Ece örsel (Mar 04)

Erin Jensby

March 2019 Sourcetree Advisory - Multiple Remote Code Execution Vulnerabilities Erin Jensby (Mar 20)

Fernando Gont

IPv6 Security for IPv4 Engineers Fernando Gont (Mar 13)

Krzysztof Burghardt

Multiple vulnerabilities in DASAN H660RM GPON router firmware Krzysztof Burghardt (Mar 26)

Luciano Bello

[SECURITY] [DSA 4405-1] openjpeg2 security update Luciano Bello (Mar 11)

matthias . deeg

[SYSS-2018-036]: ABUS Secvest Remote Control - Denial of Service - Uncontrolled Resource Consumption (CWE-400) matthias . deeg (Mar 25)
[SYSS-2018-033]: Fujitsu Wireless Keyboard Set LX901 - Keystroke Injection Vulnerability matthias . deeg (Mar 15)
[SYSS-2018-035]: ABUS Secvest Remote Control - Missing Encryption of Sensitive Data (CWE-311) matthias . deeg (Mar 25)
[SYSS-2018-034]: ABUS Secvest - Rolling Code - Predictable from Observable State (CWE-341) matthias . deeg (Mar 25)

Michael Gilbert

[SECURITY] [DSA 4404-1] chromium security update Michael Gilbert (Mar 11)

Moritz Muehlenhoff

[SECURITY] [DSA 4411-1] firefox-esr security update Moritz Muehlenhoff (Mar 20)
[SECURITY] [DSA 4417-1] firefox-esr security update Moritz Muehlenhoff (Mar 24)
[SECURITY] [DSA 4412-1] drupal7 security update Moritz Muehlenhoff (Mar 20)
[SECURITY] [DSA 4402-1] mumble security update Moritz Muehlenhoff (Mar 06)
[SECURITY] [DSA 4410-1] openjdk-8 security update Moritz Muehlenhoff (Mar 20)
[SECURITY] [DSA 4409-1] neutron security update Moritz Muehlenhoff (Mar 19)
[SECURITY] [DSA 4408-1] liblivemedia security update Moritz Muehlenhoff (Mar 17)
[SECURITY] [DSA 4403-1] php7.0 security update Moritz Muehlenhoff (Mar 11)
[SECURITY] [DSA 4407-1] xmltooling security update Moritz Muehlenhoff (Mar 13)
[SECURITY] [DSA 4406-1] waagent security update Moritz Muehlenhoff (Mar 13)

RedTeam Pentesting GmbH

[RT-SA-2019-003] Cisco RV320 Unauthenticated Configuration Export RedTeam Pentesting GmbH (Mar 27)
[RT-SA-2019-004] Cisco RV320 Unauthenticated Diagnostic Data Retrieval RedTeam Pentesting GmbH (Mar 27)
[RT-SA-2019-005] Cisco RV320 Command Injection Retrieval RedTeam Pentesting GmbH (Mar 27)
[RT-SA-2019-007] Code Execution via Insecure Shell Function getopt_simple RedTeam Pentesting GmbH (Mar 26)

Red Timmy Sec -

FlexPaper <= 2.3.6 Remote Command Execution Red Timmy Sec - (Mar 11)

Salvatore Bonaccorso

[SECURITY] [DSA 4415-1] passenger security update Salvatore Bonaccorso (Mar 24)
[SECURITY] [DSA 4418-1] dovecot security update Salvatore Bonaccorso (Mar 28)
[SECURITY] [DSA 4413-1] ntfs-3g security update Salvatore Bonaccorso (Mar 21)
[SECURITY] [DSA 4416-1] wireshark security update Salvatore Bonaccorso (Mar 24)

Sebastien Delafond

[SECURITY] [DSA 4419-1] twig security update Sebastien Delafond (Mar 31)
[SECURITY] [DSA 4401-1] wordpress security update Sebastien Delafond (Mar 01)

SecureAuth Advisories

[SAUTH-2019-0002] - Pydio 8 Multiple Vulnerabilities SecureAuth Advisories (Mar 28)

Security Explorations

[SE-2019-01] Java Card vulnerabilities Security Explorations (Mar 20)

Slackware Security Team

[slackware-security] gnutls (SSA:2019-086-01) Slackware Security Team (Mar 27)
[slackware-security] ntp (SSA:2019-067-01) Slackware Security Team (Mar 11)
[slackware-security] mozilla-thunderbird (SSA:2019-084-01) Slackware Security Team (Mar 26)
[slackware-security] mozilla-firefox (SSA:2019-081-01) Slackware Security Team (Mar 24)
[slackware-security] libssh2 (SSA:2019-077-01) Slackware Security Team (Mar 19)
[slackware-security] infozip (SSA:2019-060-01) Slackware Security Team (Mar 03)
[slackware-security] python (SSA:2019-062-01) Slackware Security Team (Mar 03)

Thijs Kinkhorst

[SECURITY] [DSA 4414-1] libapache2-mod-auth-mellon security update Thijs Kinkhorst (Mar 24)

VMware Security Response Center

NEW: VMSA-2019-0002 - VMware Workstation update addresses elevation of privilege issues. VMware Security Response Center (Mar 15)
NEW: VMSA-2019-0003 - VMware Horizon update addresses Connection Server information disclosure vulnerability VMware Security Response Center (Mar 15)

Yves-Alexis Perez

[SECURITY] [DSA 4387-2] openssh security update Yves-Alexis Perez (Mar 03)