Stored Cross-Site Scripting vulnerability in Count per Day WordPress Plugin

2016-08-04 Thread Summer of Pwnage
Stored Cross-Site Scripting vulnerability in Count per Day WordPress Plugin Julien Rentrop, July 2016 -

Cross-Site Scripting in Count per Day WordPress Plugin

2016-08-04 Thread Summer of Pwnage
Cross-Site Scripting in Count per Day WordPress Plugin Yorick Koster, July 2016 ---

Cross-Site Scripting in FormBuilder WordPress Plugin

2016-08-04 Thread Summer of Pwnage
Cross-Site Scripting in FormBuilder WordPress Plugin Peter Ganzevles, July 2016 ---

Cross-Site Scripting vulnerability in Events Made Easy WordPress plugin

2016-08-04 Thread Summer of Pwnage
Cross-Site Scripting vulnerability in Events Made Easy WordPress plugin Job Diesveld, July 2016 ---

Re: Multiple remote vulnerabilities (RCE, bof) in Nuuo NVR and NETGEAR Surveillance

2016-08-04 Thread Pedro Ribeiro
On 04/08/16 17:46, Pedro Ribeiro wrote: > tl;dr > > Lots of RCE, hardcoded credentials, stack buffer overflow and > information disclosure in the Nuuo NVRmini and other network video > recorders of the same vendor. > These vulnerabilities also affect the NETGEAR Surveillance app (which > can be in

Multiple remote vulnerabilities (RCE, bof) in Nuuo NVR and NETGEAR Surveillance

2016-08-04 Thread Pedro Ribeiro
tl;dr Lots of RCE, hardcoded credentials, stack buffer overflow and information disclosure in the Nuuo NVRmini and other network video recorders of the same vendor. These vulnerabilities also affect the NETGEAR Surveillance app (which can be installed on the NETGEAR ReadyNAS). See the full adviso

Cisco Security Advisory: Cisco IOS Software Crafted Network Time Protocol Packets Denial of Service Vulnerability

2016-08-04 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Cisco Security Advisory: Cisco IOS Software Crafted Network Time Protocol Packets Denial of Service Vulnerability Advisory ID: cisco-sa-20160804-wedge Revision 1.0 For Public Release 2016 August 4 16:00 GMT

[SECURITY] [DSA 3641-1] openjdk-7 security update

2016-08-04 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-3641-1 secur...@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 04, 2016

[SYSS-2016-065] NASdeluxe NDL-2400r: OS Command Injection

2016-08-04 Thread klaus . eisentraut
Advisory ID: SYSS-2016-065 Product: NASdeluxe NDL-2400r Vendor: Starline Computer GmbH Affected Version(s): 2.01.10 Tested Version(s): 2.01.09 Vulnerability Type: OS Command Injection (CWE-78) Risk Level: High Solution Status: no fix (product has reached EOL since 3 years) Vendor Notification: 201

FortiManager (Series) - (Bookmark) Persistent Vulnerability

2016-08-04 Thread Vulnerability Lab
Document Title: === FortiManager (Series) - (Bookmark) Persistent Vulnerability References (Source): http://www.vulnerability-lab.com/get_content.php?id=1685 Fortinet PSIRT ID: 1624461 Release Notes 1: http://docs.fortinet.com/uploaded/files/2499/fortios-5.0.12

FortiAnalyzer & FortiManager - Client Side Cross Site Scripting Web Vulnerability

2016-08-04 Thread Vulnerability Lab
Document Title: === FortiAnalyzer & FortiManager - Client Side Cross Site Scripting Web Vulnerability References (Source): http://www.vulnerability-lab.com/get_content.php?id=1686 Fortinet PSIRT ID: 1624489 Release Notes 1: http://docs.fortinet.com/uploaded/fi

Cross-Site Scripting in WordPress Landing Pages Plugin

2016-08-04 Thread Summer of Pwnage
Cross-Site Scripting in WordPress Landing Pages Plugin Burak Kelebek, July 2016 ---

Cross-Site Scripting in Activity Log WordPress Plugin

2016-08-04 Thread Summer of Pwnage
Cross-Site Scripting in Activity Log WordPress Plugin Yorick Koster, July 2016

Cross-Site Scripting vulnerability in search function Activity Log WordPress Plugin

2016-08-04 Thread Summer of Pwnage
Cross-Site Scripting vulnerability in search function Activity Log WordPress Plugin Edwin Molenaar, July 2016 -

[SECURITY] [DSA 3640-1] firefox-esr security update

2016-08-04 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-3640-1 secur...@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 03, 2016