Type: Vulnerability. Cisco SPA122 ATA with Router Devices are prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Cisco Identity Services Engine is prone to an information disclosure vulnerability; fixes are available.
Type: Vulnerability. Multiple Sonatype Products are prone to an unspecified remote code execution vulnerability; fixes are available.
Type: Vulnerability. Cisco Identity Services Engine is prone to multiple HTML-injection vulnerabilities; fixes are available.
Type: Vulnerability. Cisco Firepower Management Center is prone to multiple cross-site scripting vulnerabilities; fixes are available.
Type: Vulnerability. Cisco SPA100 Series Analog Telephone Adapters are prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. CA Performance Management is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Broken Link Checker plugin for WordPress is prone to a cross-site scripting vulnerability.
Type: Vulnerability. Cisco SPA100 Series Analog Telephone Adapters are prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Cisco SPA100 Series Analog Telephone Adapters are prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Cisco Small Business Smart and Managed Switches are prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. TYPO3 freeCap CAPTCHA extension is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Cisco Firepower Management Center is prone to an HTML-injection vulnerability; fixes are available.
Type: Vulnerability. Cisco Aironet Access Points are prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Cisco Firepower Management Center is prone to an HTML-injection vulnerability; fixes are available.
Type: Vulnerability. Linux Kernel is prone to a buffer-overflow vulnerability; fixes are available.
Type: Vulnerability. Cisco SPA100 Series Analog Telephone Adapters are prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Cisco TelePresence CE Software is prone to a local command-injection vulnerability; fixes are available.
An update that fixes three vulnerabilities is now available.
An update that fixes one vulnerability is now available.
The company says that the incident, going back to March 2018, affected only 1 out of its 3,000 servers The post NordVPN reveals breach at datacenter provider appeared first on WeLiveSecurity
An update that solves 40 vulnerabilities and has 225 fixes is now available.
An update for qemu-kvm-rhev is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 and Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update that solves one vulnerability and has 21 fixes is now available.
An update that fixes one vulnerability is now available.
OpenJDK: Incorrect handling of nested jar: URLs in Jar URL handler (Networking, 8223892) (CVE-2019-2978) * OpenJDK: Incorrect handling of HTTP proxy responses in HttpURLConnection (Networking, 8225298) (CVE-2019-2989) * OpenJDK: Missing restrictions on use of custom SocketImpl (Networking, 8218573) (CVE-2019-2945) * OpenJDK: NULL pointer dereferen [More…]
An update is now available for Red Hat Satellite 6.6 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
OpenJDK: Incorrect handling of nested jar: URLs in Jar URL handler (Networking, 8223892) (CVE-2019-2978) * OpenJDK: Incorrect handling of HTTP proxy responses in HttpURLConnection (Networking, 8225298) (CVE-2019-2989) * OpenJDK: Missing restrictions on use of custom SocketImpl (Networking, 8218573) (CVE-2019-2945) * OpenJDK: NULL pointer dereference in DrawGlyphList (2D, 8222690) (CVE-2019- [More…]
An update for python is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.
An update for wget is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.
An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
security update
Type: Vulnerability. Cisco Expressway Series and Telepresence VCS are prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Cisco TelePresence Collaboration Endpoint Software is prone to multiple local arbitrary file-overwrite vulnerabilities; fixes are available.
Type: Vulnerability. Apache Thrift is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Cisco TelePresence Collaboration Endpoint Software is prone to a local arbitrary file-write vulnerability; fixes are available.
Type: Vulnerability. Cisco TelePresence Collaboration Endpoint Software is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Cisco Wireless LAN Controller Software is prone to a local directory-traversal vulnerability; fixes are available.
Type: Vulnerability. AVEVA IEC870IP Driver for Vijeo Citect and Citect SCADA is prone to a stack-based buffer-overflow vulnerability; fixes are available.
Type: Vulnerability. Apache Thrift is prone to a remote security vulnerability; fixes are available.
Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Cisco TelePresence Collaboration Endpoint Software is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Palo Alto Networks GlobalProtect Agent is prone to a local privilege-escalation vulnerability; fixes are available.
Notorious cyberespionage group debases MSSQL The post Winnti Group’s skip‑2.0: A Microsoft SQL Server backdoor appeared first on WeLiveSecurity
It was discovered that Aspell, the GNU spell checker, incorrectly handled certain inputs which leads to a stack-based buffer over-read. An attacker could potentially access sensitive information.
An update that solves one vulnerability and has two fixes is now available.
An update that solves one vulnerability and has two fixes is now available.
security update
An update that fixes four vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update for logging-elasticsearch5-container is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
It was discovered that the Special:Redirect functionality of MediaWiki, a website engine for collaborative work, could expose suppressed user names, resulting in an information leak.
New build after fixing BuildRequires —- – Rebase to upstream version 3.9.0 – fix CVE-2019-14745
In the nfs-utils package, providing support files for Network File System (NFS) including the rpc.statd daemon, the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files
* Rebase to 1.8.28 * Fixed CVE-2019-14287
Type: Vulnerability. Horner Automation Cscape is prone to multiple arbitrary code-execution vulnerabilities; fixes are available.
Type: Vulnerability. Cisco Aironet Access Points is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Cisco Wireless LAN Controller is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. ISC Kea is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Palo Alto Networks GlobalProtect Agent is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. ISC Kea is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. ISC Kea is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Cisco Aironet Access Points is prone to an unauthorized access vulnerability; fixes are available.
