Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Outlook is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Outlook is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Outlook is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Outlook is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Dynamics 365 is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Microsoft Team Foundation Server is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.
LinuxSecurity.com: Several security issues were fixed in the kernel.
LinuxSecurity.com: Several security issues were fixed in Python.
Reading Time: ~2 min.Infowars Online Site Compromised by MageCart Attack Earlier this week, a security researcher found payment card-stealing scripts running on the Infowars online site. The scripts managed to stay active for nearly 24 hours. At least 1,600 users of the site may have been affected during this period, though many were returning customers […]
LinuxSecurity.com: Several security issues were fixed in OpenJDK 7.
LinuxSecurity.com: It was discovered that incorrect connection setup in the server for Teeworlds, an online multi-player platform 2D shooter, could result in denial of service via forged connection packets (rendering all game server slots occupied) (CVE-2018-18541). This update fixes it.
LinuxSecurity.com: Updated php-pear-CAS packages fix security vulnerabilities: An XSS vulnerabilities has been fixed for proxy mode. References: – https://bugs.mageia.org/show_bug.cgi?id=23833
LinuxSecurity.com: An important vulnerability in Adobe Flash Player 31.0.0.122 and earlier versions. Successful exploitation could lead to information disclosure. (CVE-2018-15978) References:
LinuxSecurity.com: There is a possible XSS vulnerability in Rack. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`.Applications that expect the scheme to be limited to “http” or “https” and do not escape the return value could be vulnerable to an XSS attack (CVE-2018-16471).
LinuxSecurity.com: A flaw was found in gdal up to version 2.3.0. A Heap-buffer-overflow in GTiffOddBitsBand::IReadBlock. A flaw was found in gdal. A Heap-buffer-overflow in NITFRasterBand::Unpack.
LinuxSecurity.com: It was discovered that Mutt incorrectly handled certain requests. An attacker could possibly use this to execute arbitrary code (CVE-2018-14350, CVE-2018-14352, CVE-2018-14354, CVE-2018-14359, CVE-2018-14358, CVE-2018-14353 ,CVE-2018-14357).
LinuxSecurity.com: A NULL pointer dereference flaw was found in the way patch processed patch files. An attacker could potentially use this flaw to crash patch by tricking it into processing crafted patches (CVE-2018-6951). A double-free flaw was found in the way the patch utility processed
LinuxSecurity.com: A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database (CVE-2018-1058).
Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Dynamics 365 is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Microsoft Exchange Server is prone to a remote privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Outlook is prone to an information-disclosure vulnerability; fixes are available.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan.
Industry standard specification does not guarantee the safety of the self-encrypting drives despite verification The post Security researchers bypass encryption on self-encrypting drives appeared first on WeLiveSecurity
Reading Time: ~3 min.What business owners and MSPs should know about the year’s biggest online retail holiday It’s no secret that Black Friday and Cyber Monday are marked by an uptick in online shopping. Cyber Monday 2017 marked the single largest day of online sales to date, with reported sales figures upwards of $6.5 billion. […]
Almost all young people recycle their passwords, often doing so across work and personal accounts The post Employees’ cybersecurity habits worsen, survey finds appeared first on WeLiveSecurity
LinuxSecurity.com: Several security issues were mitigated in the Linux kernel.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: The system could be made to crash or run programs as an administrator.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
security update
LinuxSecurity.com: PostgreSQL could be made to run SQL statements as the administrator.
LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Type: Vulnerability. Microsoft Dynamics 365 is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Skype for Business and Lync are prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Microsoft .NET Core is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, and Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions.
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Several security issues were fixed in Python.
Risk Level: Very Low. Type: Trojan.
