[FD] HP ThinPro - Privileged command injection

2020-03-24 Thread Eldar Marcussen
HP ThinPro - Privileged command injection === Identifiers - * CVE-2019-18910 CVSSv3 score - 7.6 (AV:A/AC:L/PR:L/UI:N/S:U/C:H/

[FD] HP ThinPro - Citrix command injection

2020-03-24 Thread Eldar Marcussen
HP ThinPro - Citrix command injection === Identifiers - * CVE-2019-18909 CVSSv3 score - 6.1 (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/

[FD] HP ThinPro - Privilege escalation

2020-03-24 Thread Eldar Marcussen
HP ThinPro - Privilege escalation === Identifiers - * CVE-2019-16287 CVSSv3 score - 6.1 (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)

[FD] HP ThinPro - Application filter bypass

2020-03-24 Thread Eldar Marcussen
HP ThinPro - Application filter bypass === Identifiers - * CVE-2019-16286 CVSSv3 score - 6.1 (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H

[FD] HP ThinPro - Information disclosure

2020-03-24 Thread Eldar Marcussen
HP ThinPro - Information disclosure === Identifiers - * CVE-2019-16285 CVSSv3 score - 6.1 (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:

[FD] Hackers 2 Hackers Conference 17th Edition Call For Papers

2020-03-24 Thread Rodrigo Rubira Branco (BSDaemon)
CALL FOR PAPERS - Hackers 2 Hackers Conference 17th edition The call for papers for H2HC 17th edition is now open.  H2HC is a hacker conference taking place in Sao Paulo, Brazil, on 24th and 25th of October 2020. [ - INTRODUCTION - ] For another consecutive year and past success we have been ha

[FD] APPLE-SA-2020-03-24-5 Safari 13.1

2020-03-24 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-2020-03-24-5 Safari 13.1 Safari 13.1 is now available and addresses the following: Safari Downloads Available for: macOS Mojave and macOS High Sierra, and included in macOS Catalina Impact: A malicious iframe may use another website’s down

[FD] APPLE-SA-2020-03-24-6 iTunes for Windows 12.10.5

2020-03-24 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-2020-03-24-6 iTunes for Windows 12.10.5 iTunes for Windows 12.10.5 is now available and addresses the following: libxml2 Available for: Windows 7 and later Impact: Multiple issues in libxml2 Description: A buffer overflow was addressed wit

[FD] APPLE-SA-2020-03-24-4 watchOS 6.2

2020-03-24 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-2020-03-24-4 watchOS 6.2 watchOS 6.2 is now available and addresses the following: ActionKit Available for: Apple Watch Series 1 and later Impact: An application may be able to use an SSH client provided by private frameworks Description:

[FD] APPLE-SA-2020-03-24-7 Xcode 11.4

2020-03-24 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-2020-03-24-7 Xcode 11.4 Xcode 11.4 is now available and contains security improvements. Additional recognition ld64 We would like to acknowledge an anonymous researcher for their assistance. Installation note: Xcode 11.4 may be obtained

[FD] APPLE-SA-2020-03-24-2 macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra

2020-03-24 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-2020-03-24-2 macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra are now available and address the follo

[FD] APPLE-SA-2020-03-24-3 tvOS 13.4

2020-03-24 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-2020-03-24-3 tvOS 13.4 tvOS 13.4 is now available and addresses the following: ActionKit Available for: Apple TV 4K and Apple TV HD Impact: An application may be able to use an SSH client provided by private frameworks Description: This is

[FD] APPLE-SA-2020-03-24-1 iOS 13.4 and iPadOS 13.4

2020-03-24 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-2020-03-24-1 iOS 13.4 and iPadOS 13.4 iOS 13.4 and iPadOS 13.4 are now available and address the following: ActionKit Available for: iPhone 6s and later, iPad Air 2 and later, iPad mini 4 and later, and iPod touch 7th generation Impact: An

[FD] New version of Hyperion PE runtime crypter

2020-03-24 Thread Levon Kayan
Hi, We've just released version 2.3 of our PE runtime crypter, hyperion. [ CHANGELOG ] - rejects unsupported .NET executables - preserves GUI/Commandline PE flag - has a lower AV detection because static stuff was removed and 64 bit output file size was reduced by 4 kilo bytes [ DESCR ] Hyp

[FD] Authentication Bypass in Tribal SITS:Vision

2020-03-24 Thread Callum Murphy
SITS:Vision 9.7.0 Authentication Bypass [-] Software Link: https://www.tribalgroup.com/software-and-services/student-information-systems/sitsvision [-] Affected Vers