Executable installers are vulnerable^WEVIL (case 46): Pelles C allows arbitrary code execution

2017-01-22 Thread Stefan Kanthak
Hi @ll, the executable installers of "Pelle's C", and, , available from , are vulnerable to DLL hijacking: they load (tested on Windows 7) at least the

[SECURITY] [DSA 3770-1] mariadb-10.0 security update

2017-01-22 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-3770-1 secur...@debian.org https://www.debian.org/security/ Salvatore Bonaccorso January 22, 2017

[SECURITY] [DSA 3769-1] libphp-swiftmailer security update

2017-01-22 Thread Sebastien Delafond
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-3769-1 secur...@debian.org https://www.debian.org/security/ Sebastien Delafond January 22, 2017

NTOPNG Web Interface v2.4 CSRF Token Bypass

2017-01-22 Thread hyp3rlinx
[+]# [+] Credits / Discovery: John Page AKA Hyp3rlinX [+] Website: hyp3rlinx.altervista.org [+] Source: http://hyp3rlinx.altervista.org/advisories/NTOPNG-CSRF-TOKEN-BYPASS.txt [+] ISR: ApparitionSEC