CVE-2019-16993 In phpBB, includes/acp/acp_bbcodes.php had improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An
An update that solves two vulnerabilities and has one errata is now available.
– Update to 2.16.3 – Side channel attack on deterministic ECDSA (CVE-2019-16910) Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.16.3-and-2.7.12-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2019-10
– Update to 2.16.3 – Side channel attack on deterministic ECDSA (CVE-2019-16910) Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.16.3-and-2.7.12-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2019-10
This is an update fixing CVE-2019-16928.
Update to 1.7.5 —- Fixes CVE-2019-12816
security update
security update
1.6.7 Fix potential crash when reloading config. Client library: * Don’t use / in autogenerated client ids, to avoid confusing with topics. * Fix mosquitto_max_inflight_messages_set() and mosquitto_int_option(…, MOSQ_OPT_*_MAX, …) behaviour. * Fix regression on use of
Max Kellermann reported a NULL pointer dereference flaw in libapreq2, a generic Apache request library, allowing a remote attacker to cause a denial of service against an application using the library (application crash) if an invalid nested “multipart” body is processed.
1.6.7 Fix potential crash when reloading config. Client library: * Don’t use / in autogenerated client ids, to avoid confusing with topics. * Fix mosquitto_max_inflight_messages_set() and mosquitto_int_option(…, MOSQ_OPT_*_MAX, …) behaviour. * Fix regression on use of
1.6.7 Fix potential crash when reloading config. Client library: * Don’t use / in autogenerated client ids, to avoid confusing with topics. * Fix mosquitto_max_inflight_messages_set() and mosquitto_int_option(…, MOSQ_OPT_*_MAX, …) behaviour. * Fix regression on use of
An XSS vulnerability was discovered in noVNC in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
An update that fixes 29 vulnerabilities is now available.
Type: Vulnerability. Linux Kernel is prone to multiple local privilege-escalation vulnerabilities; fixes are available.
Type: Vulnerability. Cisco Unified Communications Manager is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Cisco Unified Communications Manager is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Cisco Unified Contact Center Express is prone to an HTTP response-splitting vulnerability; fixes are available.
Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Cisco Adaptive Security Appliance is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Moxa EDR 810 Series is prone to multiple security vulnerabilities; fixes are available.
Type: Vulnerability. Cisco Prime Infrastructure is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Cisco Prime Infrastructure is prone to a cross-site scripting vulnerability; fixes are available.
The package ruby2.5 before version 2.5.7-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing, cross-site scripting, denial of service and insufficient validation.
The package ruby-rdoc before version 6.1.2-1 is vulnerable to cross- site scripting.
An update that fixes 27 vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes 27 vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that solves one vulnerability and has two fixes is now available.
Reading Time: ~ 2 min. DoorDash Data Breach Nearly five months after a breach, DoorDash has just now discovered that unauthorized access to sensitive customer information has taken place. Among the stolen data were customer names, payment history, and contact info, as well as the last four digits of both customer payment cards and employee […]
Several security issues were fixed in the Linux kernel.
A vulnerability was discovered by Lukas Kupczyk of the Advanced Research Team at CrowdStrike Intelligence in OpenConnect, an open client for Cisco AnyConnect, Pulse, GlobalProtect VPN. A malicious HTTP server
An update that fixes one vulnerability is now available.
Type: Vulnerability. Cisco Firepower Management Center is prone to multiple remote code-execution vulnerabilities; fixes are available.
Type: Vulnerability. Cisco FXOS and Firepower Threat Defense Software are prone to multiple local command-injection vulnerabilities; fixes are available.
Type: Vulnerability. Cisco Firepower Threat Defense Software is prone to multiple security-bypass vulnerabilities; fixes are available.
Type: Vulnerability. Multiple Cisco Unified Communications Products are prone to a cross-site request-forgery vulnerability.
Type: Vulnerability. Cisco Firepower Management Center is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Cisco Firepower Management Center is prone to multiple SQL-injection vulnerabilities; fixes are available.
Type: Vulnerability. Cisco Firepower Management Center is prone to a command-injection vulnerability; fixes are available
Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Google Chrome OS is prone to a remote integer-overflow vulnerability; fixes are available.
Type: Vulnerability. WhatsApp is prone to an integer overflow vulnerability.
Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a remote command-injection vulnerability; fixes are available.
Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a command-injection vulnerability; fixes are available.
Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a hard-coded credentials vulnerability; fixes are available.
Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a security vulnerability; fixes are available.
Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to an SQL-injection vulnerability; fixes are available.
Type: Vulnerability. Linux Kernel is prone to a denial-of-service vulnerability; fixes are available.
Updated thunderbird packages fix security vulnerability: Spoofing a message author via a crafted S/MIME message (CVE-2019-11755) It also fixes various other bugs, as listed in the releasenotes.
The incidents send medical staff back to the days of pen and paper The post Hospitals in US, Australia hobbled by ransomware appeared first on WeLiveSecurity
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
patch: do_ed_script in pch.c does not block strings beginning with a ! character (CVE-2018-20969) * patch: OS shell command injection when processing crafted patch files (CVE-2019-13638) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. SL7 […]
An update that solves two vulnerabilities and has two fixes is now available.
An update that fixes one vulnerability is now available.
