[FD] Defense in depth -- the Microsoft way (part 60): same old sins and incompetence!

2019-02-26 Thread Stefan Kanthak
Hi @ll, Microsoft just announced the general availability of their "Windows Defender Advanced Threat Protection/Endpoint Protection & Response" for their "downlevel" operating systems Windows 7 and Windows 8.1: https://techcommunity.microsoft.com/t5/Windows-Defender-ATP/Windows-Defender-ATP-s-EDR-

[FD] [CVE-2019-9083] Blind SQL injection in SQLiteManager 1.2.0 (and 1.2.4)

2019-02-26 Thread Rafael Pedrero
___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] CVE-2019-1000032: Memory corruption / DoS in nanosvg

2019-02-26 Thread Sebastian Neef
The SVG library nanosvg [0] suffers from a memory corruption bug that can lead to at least DoS. The bug exists in the `nsvg__parseColorRGB` function, which can be reached by parsing a malicious SVG file through `nsvgParseFromFile` or `nsvgParse`. This should also affect libraries/packages tha