Deprecated: The each() function is deprecated. This message will be suppressed on further calls in /home/zhenxiangba/zhenxiangba.com/public_html/phproxy-improved-master/index.php on line 456
Mail Index
Mail Index
- Advisory - Bamboo - CVE-2017-14589 CVE-2017-14590
- b2evolution CMS 6.6.0 - 6.8.10 PHP code execution
- CVE-2017-6094 - Genexis GAPS Access Control Vulnerability
- From: Antoine Neuenschwander
- [security bulletin] MFSBGN03793 rev.2 - Project and Portfolio Management Center, Multiple vulnerabilities
- Intel CPU bug forcing page table switch during syscalls?
- Re "Intel responds to security research findings"
- [security bulletin] HPESBHF03803 rev.1 - Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance, Remote Denial of Service and Execution of Code
- [SECURITY] [DSA 4078-1] linux security update
- Icyphoenix 2.2.0.105 - Multiple SQL Injection Vulnerabilities
- SonicWall SonicOS NSA UTM Firewall - Bypass & Persistent Vulnerability
- iJoomla com_adagency 6.0.9 - SQL Injection Vulnerabilities
- Abyss Web Server < v2.11.6 Memory Heap Corruption (hyp3rlinx / apparitionsec)
- Wickr Inc - App Clock & Message Deletion Glitch - Bug Bounty
- WpJobBoard v4.4.4 - Multiple SQL Injection Vulnerabilities
- CVE-2017-17055 Artica Web Proxy v3.06 Remote Code Execution (hyp3rlinx / ApparitionSec)
- CVE-2017-16884 Mist Server v2.12 Unauthenticated Persistent XSS (hyp3rlinx / ApparitionSec)
- [SECURITY] [DSA 4079-1] poppler security update
- Social Media Widget by Acurax [CSRF]
- CMS Tree Page View [CSRF, Privilege Escalation]
- Admin Menu Tree Page View [CSRF, Privilege Escalation]
- SonicWall SonicOS NSA Web Firewall - Multiple Web Vulnerabilities
- APPLE-SA-2018-1-8-1 iOS 11.2.2
- From: Apple Product Security
- APPLE-SA-2018-1-8-2 macOS High Sierra 10.13.2 Supplemental Update
- From: Apple Product Security
- APPLE-SA-2018-1-8-3 Safari 11.0.2
- From: Apple Product Security
- Response to Meltdown and Spectre
- [SECURITY] [DSA 4081-1] php5 security update
- [SECURITY] [DSA 4080-1] php7.0 security update
- [slackware-security] irssi (SSA:2018-008-01)
- From: Slackware Security Team
- CVE-2017-17485: one more way of rce in jackson-databind when defaultTyping+objects are used
- [SECURITY] [DSA 4082-1] linux security update
- From: Salvatore Bonaccorso
- [security bulletin] HPESBHF03805 rev.4 - Certain HPE products using Microprocessors from Intel, AMD, and ARM, with Speculative Execution, Elevation of Privilege and Information Disclosure.
- Multiple vulnerabilities in TP-Link products(CVE-2017-15613 to CVE-2017-15637)
- DefenseCode ThunderScan SAST Advisory: WordPress Testimonial Slider Plugin SQL injection Security Vulnerability
- DefenseCode ThunderScan SAST Advisory: WordPress Smooth Slider Plugin SQL injection Security Vulnerability
- DefenseCode ThunderScan SAST Advisory: WordPress Dbox 3D Slider Lite Multiple SQL injection Security Vulnerabilities
- WebKitGTK+ Security Advisory WSA-2018-0001
- From: Carlos Alberto Lopez Perez
- [SECURITY] [DSA 4083-1] poco security update
- CVE-2017-8802 Zimbra Collaboration Suite - Stored Cross-Site Scripting
- Flash Operator Panel v2.31.03 - Command Execution Vulnerability
- [SECURITY] [DSA 4084-1] gifsicle security update
- Magento Commerce - SSRF & XSPA Web Vulnerability
- Piwigo v2.8.2 & 2.9.2 CMS - Multiple Cross Site Vulnerabilities
- MagicSpam 2.0.13 - Insecure File Permission Vulnerability
- Magento Connect T1 - (Claim) Persistent Vulnerability
- SonicWall GMS v8.1 - Filter Bypass & Persistent Vulnerability
- Microsoft Sharepoint 2013 - Limited Access Permission Bypass Vulnerability
- Kentico CMS v11.0 - Stack Buffer Overflow Vulnerability
- [security bulletin] HPESBNS03804 rev.1 - HPE NonStop Server, Local Authentication Restriction Bypass
- [SECURITY] [DSA 4085-1] xmltooling security update
- [security bulletin] HPESBHF03800 rev.1 - HPE Comware 7 MSR Routers, Remote Denial of Service and Local Elevation or Privilege
- Code execution in Kaseya VSA
- Arbitrary file read in Kaseya VSA
- Broken TLS certificate pinning in VTech DigiGo Kid Connect app
- [SECURITY] [DSA 4087-1] transmission security update
- Adminer <= v4.3.1 Server Side Request Forgery
- Broken TLS certificate validation in VTech DigiGo browser
- [SECURITY] [DSA 4086-1] libxml2 security update
- From: Salvatore Bonaccorso
- Seagate Media Server allows deleting of arbitrary files and folders
- Authentication bypass in Kaseya VSA
- Multiple vulnerabilities in VTech DigiGo allow browser overlay attack
- [RT-SA-2017-013] Truncation of SAML Attributes in Shibboleth 2
- From: RedTeam Pentesting GmbH
- Zenario v7.6 CMS - SQL Injection Web Vulnerability
- [SECURITY] [DSA 4088-1] gdk-pixbuf security update
- MagicSpam 2.0.13 - Insecure File Permission Vulnerability
- ADVISORY - LiveZilla - Cross-site scripting (XSS) vulnerability in knowledgebase.php - CVE-2017-15869
- [SECURITY] [DSA 4089-1] bind9 security update
- From: Salvatore Bonaccorso
- [SECURITY] [DSA 4090-1] wordpress security update
- [slackware-security] bind (SSA:2018-017-01)
- From: Slackware Security Team
- [security bulletin] HPSBGN02925 rev.3 - HP IceWall SSO, IceWall File Manager and IceWall Federation Agent, Multiple Remote Unauthorized Access Vulnerabilities
- [security bulletin] HPESBHF03805 rev.5 - Certain HPE products using Microprocessors from Intel, AMD, and ARM, with Speculative Execution, Elevation of Privilege and Information Disclosure.
- [security bulletin] HPESBMU03806 rev.1 - HPE IceWall Products, Multiple Remote Unauthorized Disclosure of Information, Unauthorized Modificiation
- [SECURITY] [DSA 4092-1] awstats security update
- CVE-2017-15713: Apache Hadoop MapReduce job history server vulnerability
- [SECURITY] [DSA 4093-1] openocd security update
- CentOS Web Panel v0.9.8.12 - Multiple Persistent Web Vulnerabilities
- Oracle JDeveloper IDE Directory Traversal CVE-2017-10273 (hyp3rlinx / apparition security)
- Photo Vault v1.2 iOS - Insecure Authentication Vulnerability
- Shopware 5.2.5 & v5.3 - Multiple Cross Site Scripting Web Vulnerabilities
- CentOS Web Panel v0.9.8.12 - Non-Persistent Cross Site Scripting Vulnerabilities
- Acadmic Microsoft - API Query Filter Cross Site Scripting Vulnerability
- CentOS Web Panel v0.9.8.12 - Remote SQL Injection Vulnerabilities
- [SECURITY] [DSA 4094-1] smarty3 security update
- [security bulletin] HPESBHF03805 rev.7 - Certain HPE products using Microprocessors from Intel, AMD, and ARM, with Speculative Execution, Elevation of Privilege and Information Disclosure.
- SEC Consult SA-20180123-0 :: XXE & Reflected XSS in Oracle Financial Services Analytical Applications
- From: SEC Consult Vulnerability Lab
- DefenseCode ThunderScan SAST Advisory: SugarCRM Community Edition Multiple SQL Injection Vulnerabilities
- APPLE-SA-2018-1-23-5 Safari 11.0.3
- From: Apple Product Security
- APPLE-SA-2018-1-23-6 iTunes 12.7.3 for Windows
- From: Apple Product Security
- APPLE-SA-2018-1-23-2 macOS High Sierra 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan
- From: Apple Product Security
- APPLE-SA-2018-1-23-1 iOS 11.2.5
- From: Apple Product Security
- APPLE-SA-2018-1-23-3 watchOS 4.2.2
- From: Apple Product Security
- APPLE-SA-2018-1-23-7 iCloud for Windows 7.3
- From: Apple Product Security
- APPLE-SA-2018-1-23-4 tvOS 11.2.5
- From: Apple Product Security
- CVE-2017-15718: Apache Hadoop YARN NodeManager vulnerability
- WebKitGTK+ Security Advisory WSA-2018-0002
- From: Carlos Alberto Lopez Perez
- [SECURITY] [DSA 4096-1] firefox-esr security update
- [SECURITY] [DSA 4095-1] gcab security update
- From: Salvatore Bonaccorso
- [slackware-security] curl (SSA:2018-024-01)
- From: Slackware Security Team
- [SECURITY] [DSA 4097-1] poppler security update
- [security bulletin] HPESBHF03809 rev.1 - HPE Intelligent Management Center (iMC) PLAT, Remote Authentication Restriction Bypass
- [security bulletin] HPESBHF03813 rev.1 - HPE Intelligent Management Center (iMC) PLAT, Remote Code Execution
- [security bulletin] HPESBHF03815 rev.1 - HPE Intelligent Management Center (iMC) PLAT, Remote Code Execution
- [security bulletin] HPESBHF03810 rev.1 - HPE Intelligent Management Center (iMC) PLAT, Remote Disclosure of Information
- [security bulletin] HPESBHF03808 rev.1 - HPE Intelligent Management Center (iMC) PLAT, Remote Code Execution
- KL-001-2018-001 : Sophos Web Gateway Persistent Cross Site Scripting Vulnerability
- From: KoreLogic Disclosures
- [security bulletin] HPESBHF03812 rev.1 - HPE Intelligent Management Center (iMC) PLAT, Remote Multiple Vulnerabilities
- [slackware-security] mozilla-thunderbird (SSA:2018-025-01)
- From: Slackware Security Team
- [security bulletin] HPESBHF03811 rev.1 - HPE Intelligent Management Center (iMC) PLAT, Remote Multiple Vulnerabilities
- [security bulletin] HPESBHF03814 rev.1 - HPE Intelligent Management Center (iMC) PLAT, Remote Unauthorized Modification
- [SECURITY] [DSA 4100-1] tiff security update
- [SECURITY] [DSA 4101-1] wireshark security update
- [SECURITY] [DSA 4099-1] ffmpeg security update
- [SECURITY] [DSA 4098-1] curl security update
- [SYSS-2017-026] Microsoft Surface Hub Keyboard - Cryptographic Issues (CWE-310), Insufficient Protection against Replay Attacks
- Secunia Research: LibRaw Multiple Denial of Service Vulnerabilities
- Defense in depth -- the Microsoft way (part 49): fun with application manifests
- [SECURITY] [DSA 4094-2] smarty3 security update
- SEC Consult SA-20180131-0 :: Multiple Vulnerabilities in Sprecher Automation SPRECON-E-C, PU-2433
- From: SEC Consult Vulnerability Lab
Mail converted by MHonArc