[FD] [SYSS-2017-027] Microsoft Windows Hello Face Authentication - Authentication Bypass by Spoofing (CWE-290)

2017-12-19 Thread Matthias Deeg
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Advisory ID: SYSS-2017-027 Product: Microsoft Windows Hello Face Authentication Manufacturer: Microsoft Affected Version(s): Windows 10 Pro (Version 1709, OS Build 16299.19) Windows 10 Pro (Version 1703, OS Build 15063.726)

[FD] ESA-2017-157: EMC Data Domain DD OS Memory Overflow Vulnerability

2017-12-19 Thread EMC Product Security Response Center
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 ESA-2017-157: EMC Data Domain DD OS Memory Overflow Vulnerability EMC Identifier: ESA-2017-157 CVE Identifier: CVE-2017-14385 Severity Rating: CVSS v3 Base Score: 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) Affected products: The following EMC

[FD] ESA-2017-161: EMC Isilon OneFS NFS Export Security Setting Fallback Vulnerability

2017-12-19 Thread EMC Product Security Response Center
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 ESA-2017-161: EMC Isilon OneFS NFS Export Security Setting Fallback Vulnerability EMC Identifier: ESA-2017-161 CVE Identifier: CVE-2017-14387 Severity Rating: CVSS v3 Base Score: 4.8 (AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N) Affected products:

[FD] [CVE-2017-17744] Cross-Site Scripting (XSS) vulnerability in Custom Map WordPress Plugin

2017-12-19 Thread nicolas.buzy-debat
Product: Custom Map WordPress Plugin - https://wordpress.org/plugins/custom-map/ Vendor: webdesi9 Tested version: 1.1 CVE ID: CVE-2017-17744 ** CVE description ** A cross-site scripting (XSS) vulnerability in the custom-map plugin through 1.1 for WordPress allows remote attackers to inject

[FD] [CVE-2017-17719] Cross-Site Scripting (XSS) vulnerability in WordPress Concours Plugin

2017-12-19 Thread nicolas.buzy-debat
Product: WordPress Concours Plugin - https://wordpress.org/plugins/wp-concours/ Vendor: Olyos Tested version: 1.1 CVE ID: CVE-2017-17719 ** CVE description ** A cross-site scripting (XSS) vulnerability in the wp-concours plugin through 1.1 for WordPress allows remote attackers to inject

Re: [FD] Google supported XSS kit aka AdExchange iframe buster kit

2017-12-19 Thread Zmx
Some more details: 1) The google article seems to link the problematic kit only in non-english local (check the french version or spanish one) 2) In order for predicta to work, you should host your javascript on a specific path: /mrm-ad/commons.js 2017-12-19 15:24 GMT+01:00 Zmx

Re: [FD] CVE-2017-15944: Palo Alto Networks firewalls remote root code execution

2017-12-19 Thread Fernando A. Lagos Berardi
We've developed a script that verify the first bug of CVE-2017-x to verify if the device is vulnerable or not. The script creates the fake custom cookie and then verify it. If the cookie exists the device is vulnerable. We've extracted more than 6000 Palo Alto Networks Firewall devices from

[FD] DefenseCode ThunderScan SAST Advisory: WordPress Clean Up Optimizer Plugin Security Vulnerability

2017-12-19 Thread DefenseCode
DefenseCode ThunderScan SAST Advisory: WordPress Clean Up Optimizer     Plugin Security Vulnerability Advisory ID:    DC-2017-12-004 Advisory Title: WordPress Clean Up Optimizer Plugin Security Vulnerability Advisory URL:   http://www.defensecode.com/advisories.php Software:  

[FD] DefenseCode ThunderScan SAST Advisory: WordPress Top-10 Plugin SQL Injection Security Vulnerability

2017-12-19 Thread DefenseCode
DefenseCode ThunderScan SAST Advisory: WordPress Top-10 Plugin    SQL Injection Security Vulnerability Advisory ID:    DC-2017-12-003 Advisory Title: WordPress Top-10 Plugin SQL Injection Security Vulnerability Advisory URL:   http://www.defensecode.com/advisories.php Software:  

[FD] [CVE-2017-17704] Broken Cryptography in iStar Ultra & IP ACM by Software House

2017-12-19 Thread David Tomaschik via Fulldisclosure
Introduction Vulnerabilities were identified in the iStar Ultra & IP-ACM boards offered by Software House. This system is used to control physical access to resources based on RFID-based badge readers. Badge readers interface with the IP-ACM board, which uses TCP/IP to communicate

[FD] CVE-2017-6094 - Genexis GAPS Access Control Vulnerability

2017-12-19 Thread Antoine Neuenschwander
# # # CVE-2017-6094 - Genexis GAPS Access Control Vulnerability# #

[FD] [CFP] Security BSides Ljubljana 0x7E2

2017-12-19 Thread Andraz Sraka
-=[ BSidesLjubljana Event info ]=-=-=-=-=-=-=-=-=-=-=-=-=-=-  BSidesLjubljana - https://bsidesljubljana.si   Date: March 10th, 2018 Venue: Poligon creative centre, Ljubljana, Slovenia, Europe   CFP URL: https://bsidesljubljana.si/cfp/ CFP Submit form: https://goo.gl/forms/JO4XCnMPGv6AAD2w2 Email: