Adminer <= v4.3.1 Server Side Request Forgery

2018-01-15 Thread apparitionsec
[+] Credits: John Page (aka hyp3rlinx) [+] Website: hyp3rlinx.altervista.org [+] Source: http://hyp3rlinx.altervista.org/advisories/ADMINER-UNAUTHENTICATED-SERVER-SIDE-REQUEST-FORGERY.txt [+] ISR: apparition security Vendor: == www.adminer.org Product:

Authentication bypass in Kaseya VSA

2018-01-15 Thread Securify B.V.
Authentication bypass in Kaseya VSA Kin Hung Cheng, Robert Hartshorn, May 2017

[SECURITY] [DSA 4087-1] transmission security update

2018-01-15 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-4087-1 secur...@debian.org https://www.debian.org/security/ Moritz Muehlenhoff January 14, 2018

Seagate Media Server allows deleting of arbitrary files and folders

2018-01-15 Thread Summer of Pwnage
Seagate Media Server allows deleting of arbitrary files and folders Yorick Koster, September 2017

Broken TLS certificate validation in VTech DigiGo browser

2018-01-15 Thread Summer of Pwnage
Broken TLS certificate validation in VTech DigiGo browser Sipke Mellema, September 2017

Arbitrary file read in Kaseya VSA

2018-01-15 Thread Securify B.V.
Arbitrary file read in Kaseya VSA Kin Hung Cheng, Robert Hartshorn, May 2017

Broken TLS certificate pinning in VTech DigiGo Kid Connect app

2018-01-15 Thread Summer of Pwnage
Broken TLS certificate pinning in VTech DigiGo Kid Connect app Sipke Mellema, September 2017

[SECURITY] [DSA 4086-1] libxml2 security update

2018-01-15 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-4086-1 secur...@debian.org https://www.debian.org/security/ Salvatore Bonaccorso January 13, 2018

Multiple vulnerabilities in VTech DigiGo allow browser overlay attack

2018-01-15 Thread Summer of Pwnage
Multiple vulnerabilities in VTech DigiGo allow browser overlay attack Sipke Mellema, September 2017

Code execution in Kaseya VSA

2018-01-15 Thread Securify B.V.
Code execution in Kaseya VSA Kin Hung Cheng, Robert Hartshorn, May 2017

[security bulletin] HPESBHF03800 rev.1 - HPE Comware 7 MSR Routers, Remote Denial of Service and Local Elevation or Privilege

2018-01-15 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Note: the current version of the following document is available here: https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03800en_us SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: hpesbhf03800en_us Version: 1

[SECURITY] [DSA 4085-1] xmltooling security update

2018-01-15 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-4085-1 secur...@debian.org https://www.debian.org/security/ Moritz Muehlenhoff January 12, 2018

[security bulletin] HPESBNS03804 rev.1 - HPE NonStop Server, Local Authentication Restriction Bypass

2018-01-15 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Note: the current version of the following document is available here: https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbns03804en_us SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: hpesbns03804en_us Version: 1