[FD] [SYSS-2016-063] VMware ESXi 6 - Improper Input Validation (CWE-20)

2016-08-05 Thread Matthias Deeg
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Advisory ID: SYSS-2016-063 Product: VMware vSphere Hypervisor (ESXi) Manufacturer: VMware, Inc. Affected Version(s): VMware ESXi 6.0.0 build 3380124 (Update 1) VMware vCenter Server 6.0 U2 Tested Version(s): VMware ESXi 6.0.0

Re: [FD] Multiple remote vulnerabilities (RCE, bof) in Nuuo NVR and NETGEAR Surveillance

2016-08-05 Thread Pedro Ribeiro
On 04/08/16 17:46, Pedro Ribeiro wrote: > tl;dr > > Lots of RCE, hardcoded credentials, stack buffer overflow and > information disclosure in the Nuuo NVRmini and other network video > recorders of the same vendor. > These vulnerabilities also affect the NETGEAR Surveillance app (which > can be

[FD] Multiple remote vulnerabilities (RCE, bof) in Nuuo NVR and NETGEAR Surveillance

2016-08-05 Thread Pedro Ribeiro
tl;dr Lots of RCE, hardcoded credentials, stack buffer overflow and information disclosure in the Nuuo NVRmini and other network video recorders of the same vendor. These vulnerabilities also affect the NETGEAR Surveillance app (which can be installed on the NETGEAR ReadyNAS). See the full

[FD] CVE-2016-6527 Possible Privilege Escalation in telecom of Samsung Mobile Phone

2016-08-05 Thread 0xr0ot
Hi, Description of the potential vulnerability: Severity: Medium Affected versions: L(5.0/5.1), M(6.0) Reported on: May 11, 2016 Disclosure status: Privately disclosed. The vulnerability in SmartCall Activity components of Telecom application can make crash and reboot a device when the malformed

[FD] CVE-2016-6526 Possible Privilege Escalation in telecom of Samsung Mobile Phone

2016-08-05 Thread 0xr0ot
Description of the potential vulnerability: Severity: Medium Affected versions: L(5.0/5.1), M(6.0) Reported on: May 11, 2016 Disclosure status: Privately disclosed. A vulnerability in SpamCall Activity components of Telecom application can make crash and reboot a device when the malformed

[FD] Kaspersky Safe Browser iOS Application - MITM SSL Certificate Vulnerability (CVE-2016-6231)

2016-08-05 Thread David Coomber
Kaspersky Safe Browser iOS Application - MITM SSL Certificate Vulnerability (CVE-2016-6231) -- http://www.info-sec.ca/advisories/Kaspersky-Safe-Browser.html Overview "Stay safe from malicious links, suspicious content and identity theft while you surfing the Internet." "Our Safe Browser covers

[FD] Ecwid Ecommerce Shopping Cart WordPress Plugin unauthenticated PHP Object injection vulnerability

2016-08-05 Thread Summer of Pwnage
Ecwid Ecommerce Shopping Cart WordPress Plugin unauthenticated PHP Object injection vulnerability Yorick Koster, June 2016

[FD] DLL side loading vulnerability in VMware Host Guest Client Redirector

2016-08-05 Thread Securify B.V.
DLL side loading vulnerability in VMware Host Guest Client Redirector Yorick Koster, December 2015

[FD] FortiCloud - (Reports Summary) Multiple Persistent Vulnerabilities

2016-08-05 Thread Vulnerability Lab
Document Title: === FortiCloud - (Reports Summary) Multiple Persistent Vulnerabilities References (Source): http://www.vulnerability-lab.com/get_content.php?id=1735 Release Date: = 2016-08-05 Vulnerability Laboratory ID (VL-ID):

[FD] Subrion v4.0.5 CMS - SQL Injection Vulnerability

2016-08-05 Thread Vulnerability Lab
Document Title: === Subrion v4.0.5 CMS - SQL Injection Vulnerability References (Source): http://www.vulnerability-lab.com/get_content.php?id=1893 Release Date: = 2016-08-04 Vulnerability Laboratory ID (VL-ID):