New User, Welcome!     Login

Next Page >>

Security vulnerabilities

Cisco Security Advisory: Cisco Show and Share Security Vulnerabilities

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Cisco Security Advisory: Cisco Show and Share Security Vulnerabilities

Advisory ID: cisco-sa-20111019-sns

Revision 1.0

For Public Release 2011 October 19 16:00  UTC (GMT)

[HITB-Announce] HITB2011AMS -- Call For Papers now Open

# Network Protocols, Analysis and Attacks
# Applications of Cryptographic Techniques
# Side Channel Analysis of Hardware Devices
# Data Recovery, Forensics and Incident Response
# Analysis of Malicious Code / Viruses / Malware
# Windows / Linux / OS X / *NIX Security Vulnerabilities
# Next Generation Exploit and Exploit Mitigation Techniques
# WLAN, GPS, HAM Radio, Satellite, RFID and Bluetooth Security

Each non-resident speaker will receive accommodation for 3 nights / 4
days. For each non-resident speaker, HITB will cover travel expenses up

VMSA-2010-0011 VMware Studio 2.1 addresses security vulnerabilities in virtual appliances created with Studio 2.0.

- ------------------------------------------------------------------------
                   VMware Security Advisory

Advisory ID:       VMSA-2010-0011
Synopsis:          VMware Studio 2.1 addresses security vulnerabilities
                   in virtual appliances created with Studio 2.0.
Issue date:        2010-07-13
Updated on:        2010-07-13 (initial release of advisory)
CVE numbers:       CVE-2010-2427 CVE-2010-2667
- ------------------------------------------------------------------------

Multiple Vulnerabilities in XOOPS 2.4.3 and earlier

== Overview ==

CodeScan Labs (www.codescan.com), has recently released a new source
code scanning tool, CodeScan. CodeScan is an advanced auditing tool
designed to check web application source code for security vulnerabilities.
CodeScan utilises an intelligent source code parsing engine, traversing
execution paths and tracking the flow of user supplied input.

During the ongoing testing of CodeScan ASP, Xoops was selected as one of
the test applications. We downloaded Xoops from the Xoops website

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Digital Media Manager

use of the vulnerability described in this advisory.

The privilege escalation and information leakage vulnerabilities were
reported to Cisco by the National Australia Bank's Security Assurance
team. Cisco PSIRT appreciates the opportunity to work with researchers
on security vulnerabilities and welcomes the opportunity to review and
assist in product reports.

The default credentials vulnerability was found during internal testing.

Status of this Notice: FINAL

Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances

The ACL bypass vulnerability was reported to Cisco by Jon Ramsey and
Jeff Jarmoc from SecureWorks.

The Cisco PSIRT greatly appreciates the opportunity to work with
researchers on security vulnerabilities, and welcomes the opportunity to
review and assist in product reports.

All other vulnerabilities were found during internal testing and during
the resolution of customer service requests.


[SE-2012-01] Security weakness in Apple Quicktime Java extensions

informing the company about a discovered vulnerability. Along with the
notice, the company also received our Proof of Concept code.

More technical details regarding the discovered security vulnerability
in Apple Quicktime will be disclosed at the time of the publication of
the SE-2012-01 project (Security Vulnerabilities in Java SE).

Thank you.

Best Regards
Adam Gowdiak

[HITB-Announce] Reminder: HITB2011AMS - Call for Papers closes on the 18th of Feb

# Network Protocols, Analysis and Attacks
# Applications of Cryptographic Techniques
# Side Channel Analysis of Hardware Devices
# Data Recovery, Forensics and Incident Response
# Analysis of Malicious Code / Viruses / Malware
# Windows / Linux / OS X / *NIX Security Vulnerabilities
# Next Generation Exploit and Exploit Mitigation Techniques
# WLAN, GPS, HAM Radio, Satellite, RFID and Bluetooth Security

Each non-resident speaker will receive accommodation for 3 nights / 4
days at the Krasnapolsky. For each non-resident speaker, HITB will cover

[SVRT-06-08] MULTI SECURITY VULNERABILITIES IN MVNFORUM

MULTI SECURITY VULNERABILITIES IN MVNFORUM

1. General Information
mvnForum is software used for creating forums on the Internet 
(http://www.mvnforum.com). This is an open source software making use of 
Java J2EE (ISP/Servlet) technology.

On September 6 2008, SVRT-Bkis found several CSRF and XSS vulnerabilities in 
some functions of mvnForum 1.2 GA. These are highly serious vulnerabilities 
allowing hackers to perform privilege escalation attack on the Forum.

[HITB-Announce] Reminder: HITB2012AMS Call For Papers Closing Soon

    Applications of Cryptographic Techniques
    Side Channel Analysis of Hardware Devices
    Analysis of Malicious Code / Viruses / Malware
    Data Recovery, Forensics and Incident Response
    Hardware based attacks and reverse engineering
    Windows / Linux / OS X / *NIX Security Vulnerabilities
    Next Generation Exploit and Exploit Mitigation Techniques
    NFC, WLAN, GPS, HAM Radio, Satellite, RFID and Bluetooth Security

Each accepted submission will entitle the speaker / speakers to
accommodation for 3 nights / 4 days and travel expense reimbursement up

[CORE-2010-0121] Multiple Vulnerabilities with 8.3 Filename Pseudonyms in Web Servers

. 2010-01-12:
Technical details sent to Cherokee and Mongoose teams by Core.

. 2010-01-12:
Cherokee team notifies Core that the issues have been evaluated and
considered security vulnerabilities. Cherokee team also informs us that
they are not currently shipping Windows binaries because they are aware
of all this sort of issues. The Windows port has not received much
attention for the last few years and it is far from being ready for
production. Cherokee team also states that they will link Core advisory
from their bug-tracker as soon as it is published. Currently the Windows

Insufficient User Input Validation in VP-ASP 6.50 Demo Code

 
== Overview ==

CodeScan Labs (http://www.codescan.com), has recently released a new source
code scanning tool, CodeScan. CodeScan is an advanced auditing tool
designed to check web application source code for security vulnerabilities.
CodeScan utilises an intelligent source code parsing engine, traversing
execution paths and tracking the flow of user supplied input.

During the ongoing testing of CodeScan ASP, VP-ASP was selected as one of 
the test applications. We downloaded a demo of VP-ASP from the VP-ASP

Cisco Security Advisory: Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability

The Cisco PSIRT is not aware of any public announcements or malicious
use of the vulnerability described in this advisory.

This vulnerability was reported to Cisco by the National Australia
Bank's Security Assurance team. Cisco PSIRT appreciates the opportunity
to work with researchers on security vulnerabilities and welcomes the
opportunity to review and assist in product reports.

Status of this Notice: FINAL
============================


[HITB-Announce] REMINDER: HITB2011 - Malaysia Call for Papers Closes on the 15th

# Network Protocols, Analysis and Attacks
# Applications of Cryptographic Techniques
# Side Channel Analysis of Hardware Devices
# Data Recovery, Forensics and Incident Response
# Analysis of Malicious Code / Viruses / Malware
# Windows / Linux / OS X / *NIX Security Vulnerabilities
# Next Generation Exploit and Exploit Mitigation Techniques
# WLAN, GPS, HAM Radio, Satellite, RFID and Bluetooth Security

Your submission will be reviewed by The HITB CFP Review Committee which
includes:

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Security Agent

use of the vulnerabilities described in this advisory.

The directory traversal and SQL injection vulnerabilities were
discovered and reported to Cisco by Gabriele Giuseppini from Cigital.
Cisco PSIRT appreciates the opportunity to work with researchers on
security vulnerabilities and welcomes the opportunity to review and
assist in product reports. The DoS vulnerability was found during
internal testing.

Status of this Notice: FINAL
============================

Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service and Authentication Bypass Vulnerabilities

The Cisco PSIRT is not aware of any public announcements or malicious
use of the vulnerability described in this advisory.

Cisco PSIRT greatly appreciates the opportunity to work with
researchers on security vulnerabilities and welcomes the opportunity
to review and assist in product reports. We would like to thank
VoIPshield for working with us towards the goal of keeping Cisco
networks and the Internet, as a whole, secure.

Status of this Notice: FINAL

PR06-12: XSS on BEA Plumtree Foundation and AquaLogic Interaction portals

Interaction.


References:

"ProCheckUp - Security Vulnerabilities"
http://www.procheckup.com/Vulnerabilities.php

BEA's BEA08-186.00 advisory:

"Security Advisories and Notifications"

Cisco Secure ACS Denial Of Service Vulnerability

The RADIUS shared secret and a valid known Network Access Server
(NAS) IP address must be known to carry out this exploit.

The Cisco PSIRT team greatly appreciates the opportunity to work with
researchers on security vulnerabilities, and we welcome the
opportunity to review and assist in product reports. We thank Laurent
Butti and Gabriel Campana of Orange Labs / France Telecom Group for
reporting this vulnerability to Cisco PSIRT.

Software patches are available for customers with support contracts

Cisco Security Advisory: CiscoWorks Common Services Arbitrary Code Execution Vulnerability

This vulnerability was reported to Cisco by Dave Lewis from
Liquidmatrix.org.

Cisco PSIRT greatly appreciates the opportunity to work with
researchers on security vulnerabilities, and we welcome the
opportunity to review and assist in product reports.

Status of this Notice: FINAL

THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY

VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues

~                   CVE-2008-1340
- -------------------------------------------------------------------

1. Summary:

~   Several critical security vulnerabilities have been addressed
~   in the newest releases of VMware's hosted product line.

2. Relevant releases:

~   VMware Workstation 6.0.2 and earlier

Cisco Security Advisory: SQL injection in Cisco Unified Communications Manager

This vulnerability was reported to Cisco by Nico Leidecker and Tracey
Parry at Portcullis Computer Security Limited. Cisco PSIRT would like
to thank these two individuals for bringing this issue to our
attention and for working with PSIRT toward coordinated disclosure of
the issue. Cisco PSIRT greatly appreciates the opportunity to work
with researchers on security vulnerabilities and welcomes the
opportunity to review and assist in product reports.

Status of this Notice: FINAL
============================


Assurent VR - Microsoft Agent Crafted URL Stack Buffer Overflow

  Vendor: MS07-051


10. About Assurent VRS

Assurent's Vulnerability Research Service (VRS) for security product vendors, and Threat Protection Programs (TPP) for MSPs and enterprise security teams, help to eliminate the significant costs incurred by security product vendors, MSPs, and enterprise security teams in responding to and managing critical new security vulnerabilities and other threats including worm & virus outbreaks and high-risk spyware. The VRS and TPP services are real-time feeds providing subscribers with detailed analysis of the top security vulnerabilities, focused on the specific needs of each group of customers. 

http://www.assurent.com/



VMSA-2010-0012 VMware vCenter Update Manager fix for Jetty Web server addresses important security vulnerabilities

- ------------------------------------------------------------------------
                   VMware Security Advisory

Advisory ID:       VMSA-2010-0012
Synopsis:          VMware vCenter Update Manager fix for Jetty Web
                   server addresses important security vulnerabilities
Issue date:        2010-07-19
Updated on:        2010-07-19 (initial release of advisory)
CVE numbers:       CVE-2009-1523 CVE-2009-1524
- ------------------------------------------------------------------------


Cisco Security Response: Multiple Vulnerabilities in Cisco Unified Videoconferencing Products

http://www.trustmatta.com/advisories/MATTA-2010-001.txt

Cisco would like to thank Florent Daigniere of Matta Consulting for
reporting these vulnerabilities to us. Cisco greatly appreciate the
opportunity to work with researchers on security vulnerabilities and
welcome the opportunity to review and assist in product reports.

Additional Information
======================


CORE-2011-0103 - ZOHO ManageEngine ADSelfService multiple vulnerabilities

6. *Vendor Information, Solutions and Workarounds*

Core would like to thanks Manikandan.T [2] for giving us the following
detailed information about the way Zoho team has addressed the security
vulnerabilities highlighted in this document.


6.1. *Solution to the Weak security question mechanism*

[CVE-2010-3272] In addition to the Security Questions, the latest

Cisco Security Advisory: Multiple Vulnerabilities in Cisco TelePresence Manager

the Cisco Technical Assistance Center (TAC) or your contracted
maintenance provider for assistance.

Each row of the following Cisco TelePresence System Software table
defines a specific defect, the first fixed release, and the
recommended release to resolve all the security vulnerabilities
identified in this advisory as well as other vulnerabilities that are
not security related. Cisco recommends upgrading to a release equal
to or later than the release in the Recommended Releases column of
the table.


AdaptCMS 2.0.1 Multiple security vulnerabilities

Advisory:               AdaptCMS 2.0.1 Multiple security vulnerabilities
Advisory ID:            SSCHADV2011-018
Author:                 Stefan Schurtz
Affected Software:      Successfully tested on AdaptCMS 2.0.1
Vendor URL:             http://www.adaptcms.com/
Vendor Status:          fixed
CVE-ID:                 -

==========================
Vulnerability Description:

Cisco Security Advisory: CiscoWorks Common Services Arbitrary Command Execution Vulnerability

Products and Services menu of the Cisco Security Intelligence
Operations (SIO) Portal. Following this transition, new Cisco Security
Advisories and Responses will be published to the new location.
Although the URL has changed, the content of security documents and
the vulnerability policy are not impacted. Cisco will continue to
disclose security vulnerabilities in accordance with the published
Security Vulnerability Policy.

Affected Products
=================


Cisco Security Advisory: Cisco Unified Communications Manager Directory Traversal Vulnerability

Services menu of the Cisco Security Intelligence Operations (SIO)
Portal. Following this transition, new Cisco Security Advisories and
Responses will be published to the new location. Although the URL has
changed, the content of security documents and the vulnerability
policy are not impacted. Cisco will continue to disclose security
vulnerabilities in accordance with the published Security
Vulnerability Policy.

Affected Products
=================


Cisco Security Advisory: Denial of Service Vulnerability in Cisco Video Surveillance IP Cameras

Services menu of the Cisco Security Intelligence Operations (SIO)
Portal. Following this transition, new Cisco Security Advisories and
Responses will be published to the new location. Although the URL has
changed, the content of security documents and the vulnerability
policy are not impacted. Cisco will continue to disclose security
vulnerabilities in accordance with the published Security
Vulnerability Policy.

Affected Products
=================


Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!