[security bulletin] HPSBPV03516 rev.2 - HP VAN SDN Controller, Multiple Vulnerabilities

2016-10-11 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04819635 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c04819635 Version: 2 HPSBPV03516 rev.2 - HP

Contenido v4.9.11 CMS - (Backend) Multiple XSS Vulnerabilities

2016-10-11 Thread ad...@evolution-sec.com
Document Title: === Contenido v4.9.11 - (Backend) Multiple XSS Vulnerabilities References (Source): http://www.vulnerability-lab.com/get_content.php?id=1928 Release Date: = 2016-10-10 Vulnerability Laboratory ID (VL-ID):

Facebook API v2.1 - RFC6749 Open Redirect Vulnerability

2016-10-11 Thread Vulnerability Lab
Document Title: === Facebook API v2.1 - RFC6749 Open Redirect Vulnerability References (Source): https://www.vulnerability-lab.com/get_content.php?id=1972 Vulnerability Magazine:

[SYSS-2016-043] Microsoft Wireless Desktop 2000 - Cryptographic Issues (CWE-310), Insufficient Protection against Replay Attacks

2016-10-11 Thread matthias . deeg
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Advisory ID: SYSS-2016-043 Product: Microsoft Wireless Desktop 2000 Manufacturer: Microsoft Affected Version(s): Ver. A Tested Version(s): Ver. A Vulnerability Type: Cryptographic Issues (CWE-310) Insufficient Protection against

[SYSS-2016-043] Microsoft Wireless Desktop 2000 - Cryptographic Issues (CWE-310), Insufficient Protection against Replay Attacks

2016-10-11 Thread matthias . deeg
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Advisory ID: SYSS-2016-043 Product: Microsoft Wireless Desktop 2000 Manufacturer: Microsoft Affected Version(s): Ver. A Tested Version(s): Ver. A Vulnerability Type: Cryptographic Issues (CWE-310) Insufficient Protection against

SEC Consult SA-20161011-0 :: XXE vulnerability in RSA Enterprise Compromise Assessment Tool (ECAT)

2016-10-11 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory < 20161011-0 > === title: XML External Entity Injection (XXE) product: RSA Enterprise Compromise Assessment Tool (ECAT) vulnerable version: 4

[SEARCH-LAB advisory] AVTECH IP Camera, NVR, DVR multiple vulnerabilities

2016-10-11 Thread Gergely Eberhardt
Avtech devices multiple vulnerabilities -- Platforms / Firmware confirmed affected: - Every Avtech device (IP camera, NVR, DVR) and firmware version. [4] contains the list of confirmed firmware versions, which are affected. - Product page: