ESET research reveals notorious crime group also conducting espionage campaigns for the past five years The post Buhtrap group uses zero‑day in latest espionage campaigns appeared first on WeLiveSecurity
New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to an authentication-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Azure Automation is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Azure DevOps Server and Team Foundation Server are prone to an remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Visual Studio is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Visual Studio is prone to a local privilege-escalation vulnerability; fixes are available.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
An update that fixes two vulnerabilities is now available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes one vulnerability is now available.
dbus: DBusServer DBUS_COOKIE_SHA1 authentication bypass (CVE-2019-12749) SL6 x86_64 dbus-1.2.24-11.el6_10.x86_64.rpm dbus-debuginfo-1.2.24-11.el6_10.i686.rpm dbus-debuginfo-1.2.24-11.el6_10.x86_64.rpm dbus-libs-1.2.24-11.el6_10.i686.rpm dbus-libs-1.2.24-11.el6_10.x86_64.rpm dbus-x11-1.2.24-11.el6_10.x86_64.rpm dbus-devel-1.2.24-11.el6_10.i686.rpm dbus-devel-1 [More…]
An update that solves one vulnerability and has 8 fixes is now available.
An update that solves one vulnerability and has three fixes is now available.
An update that solves 21 vulnerabilities and has two fixes is now available.
An update that solves one vulnerability and has two fixes is now available.
It was discovered that there were two heap buffer overflows in the Hyperloglog functionality provided by the Redis in-memory key-value database.
ESET research discovers a zero-day exploit that takes advantage of a local privilege escalation vulnerability in Windows The post Windows zero‑day CVE‑2019‑1132 exploited in targeted attacks appeared first on WeLiveSecurity
An update for openstack-ironic-inspector is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for openstack-tripleo-common is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Risk Level: Very Low. Type: Trojan.
security update
The times they have a-changed since the ICO could only slap fines worth a fraction of the current amounts The post UK’s data watchdog hands out two mega‑fines for breaches appeared first on WeLiveSecurity
Apport could be made to expose sensitive information in crash reports.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update is now available for Red Hat JBoss Web Server 3.1. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update is now available for Red Hat JBoss Web Server 3.1 for RHEL 6 and Red Hat JBoss Web Server 3.1 for RHEL 7. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,
Several security issues were fixed in GVfs.
The package python2-django before version 1.11.22-1 is vulnerable to silent downgrade.
The package python-django before version 2.2.3-1 is vulnerable to silent downgrade.
The package irssi before version 1.2.1-1 is vulnerable to arbitrary code execution.
Spring Security support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user
Whoopsie could be made to crash or expose sensitive information if it processed a specially crafted crash report.
Apport could be made to expose sensitive information in crash reports.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Exchange Server is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.
Type: Vulnerability. Microsoft Team Foundation Server is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Microsoft Exchange Server is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
