SEC Consult 20130417-0 :: Multiple vulnerabilities in Sosci Survey

2013-04-18 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory 20130417-0 === title: Multiple vulnerabilities in Sosci Survey product: Sosci Survey vulnerable version: 2.3.04a fixed version: 2.3.04a

SEC Consult SA-20130417-1 :: Java ActiveX Control Memory Corruption

2013-04-18 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory 20130417-1 === title: Java ActiveX Control Memory Corruption product: Java(TM) Web Start Launcher vulnerable version: Sun Java Version 7 Update 17 and

SEC Consult SA-20130417-2 :: HTTP header injection/Cache poisoning in Oracle WebCenter Sites Satellite Server

2013-04-18 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory 20130417-2 === title: HTTP header injection/Cache poisoning in Oracle WebCenter Sites Satellite Server product: Oracle WebCenter

Cisco Security Advisory: Cisco Network Admission Control Manager SQL Injection Vulnerability

2013-04-18 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Cisco Security Advisory: Cisco Network Admission Control Manager SQL Injection Vulnerability Advisory ID: cisco-sa-20130417-nac Revision 1.0 For Public Release 2013 April 17 16:00 UTC (GMT)

Cisco Security Advisory: Cisco TelePresence Infrastructure Denial of Service Vulnerability

2013-04-18 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Cisco Security Advisory: Cisco TelePresence Infrastructure Denial of Service Vulnerability Advisory ID: cisco-sa-20130417-tpi Revision 1.0 For Public Release 2013 April 17 16:00 UTC (GMT)

DC4420 - London DEFCON - April meet - Tuesday 23rd April 2013

2013-04-18 Thread Major Malfunction
Whether you're coming to town next week for London Infosec or BSides, or you're in the smoke anyway, come and join us for what is normally our busiest and most entertaining night of the year... This time should be no exception: we have managed to retain our normal venue - The Phoenix - and we

[SECURITY] [DSA 2662-1] xen security update

2013-04-18 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2662-1 secur...@debian.org http://www.debian.org/security/ Salvatore Bonaccorso April 18, 2013

CVE-2013-2504 : Matrix42 Service Desk XSS

2013-04-18 Thread 43z sec
* * * 43zsec SECURITY ADVISORY * * * * *