Ubuntu Security Notice 3628-2 - USN-3628-1 fixed a vulnerability in OpenSSL. This update provides the corresponding update for Ubuntu 12.04 ESM. Alejandro Cabrera Aldaya, Billy Brumley, Cesar Pereida Garcia and Luis Manuel Alvarez Tapia discovered that OpenSSL incorrectly handled RSA key generation. An attacker could possibly use this issue to perform a cache-timing attack and recover private RSA keys. Various other issues were also addressed.
b97eef64acda8f70ac874f053e082d5142efeacf22be47d9cfa82d52b78aea64
Ubuntu Security Notice 3628-1 - Alejandro Cabrera Aldaya, Billy Brumley, Cesar Pereida Garcia and Luis Manuel Alvarez Tapia discovered that OpenSSL incorrectly handled RSA key generation. An attacker could possibly use this issue to perform a cache-timing attack and recover private RSA keys.
2b906fe54f8dc8733e2e48459df788f7e92245ff6eede0444543bfe996334f6d
Ubuntu Security Notice 3627-1 - Alex Nichols and Jakob Hirsch discovered that the Apache HTTP Server mod_authnz_ldap module incorrectly handled missing charset encoding headers. A remote attacker could possibly use this issue to cause the server to crash, resulting in a denial of service. Elar Lang discovered that the Apache HTTP Server incorrectly handled certain characters specified in <FilesMatch>. A remote attacker could possibly use this issue to upload certain files, contrary to expectations. Various other issues were also addressed.
0003185aef4aed0ee0f79ef7b8f8e057cba6234b38944be6624baead979ec72e
Seagate Personal Cloud model SRN21C running firmware versions 4.3.16.0 and 4.3.18.0 suffers from a persistent cross site scripting vulnerabilities.
e781553767030bf98f0d576bce042a246fa79981a84c0cfb754a87a6669dfce7
Seagate Personal Cloud model SRN21C running firmware versions 4.3.16.0 and 4.3.18.0 suffer from a path traversal vulnerability.
5ef896e7b37cb5ccba017088977b813090cb4b99b1764b4ea351316ab3dd7a44
Seagate Personal Cloud model SRN21C running firmware versions 4.3.16.0 and 4.3.18.0 allows for moving of arbitrary files.
c10b30b886d514c80a6e95c583657ad577f538056af82102f47d7c966c1721fd
This Microsoft bulletin summary holds CVE revision updates for CVE-2018-1037.
67f82a1876aa156150a7467663f85a7653e7785886519ee8ad4d47577ccc56db
Stegano is a basic Python Steganography module. Stegano implements two methods of hiding: using the red portion of a pixel to hide ASCII messages, and using the Least Significant Bit (LSB) technique. It is possible to use a more advanced LSB method based on integers sets. The sets (Sieve of Eratosthenes, Fermat, Carmichael numbers, etc.) are used to select the pixels used to hide the information.
af26659ba175b39284a2e0bb8fbfd5989779445524ab6aef258ff7fb2ec0f2cb
Ansvif is "A Not So Very Intelligent Fuzzer". It feeds garbage arguments and data into programs trying to induce a fault.
11210463d7d354962165bf3887b2384b20d757d1e57785e6996cdb17c9a257d9
92 bytes small Linux x86 tcp/1337 bindshell shellcode.
835acf809be1380ac656b9b529139a3473867cc3cefdbf9059dc70bc2b6827d4
The enlightened Windows Lockdown Policy check for COM Class instantiation can be bypassed by using a bug in .NET leading to arbitrary code execution on a system with UMCI enabled (e.g. Device Guard).
6472ee6172948afddeda0672cf9b60975d9a244ee152920a06d2b4c956e58bbf
Slackware Security Advisory - New gd packages are available for Slackware 14.2 and -current to fix security issues.
86ee3d5531e8cde7c3307d3b31bdfee75b677158c29f40f0859bc58b0eee5eea
Digital Guardian Management Console version 7.1.2.0015 suffers from an XML external entity injection vulnerability.
7cec0fd3e8efd19ae243d045d84667f65746f0c3315377e8314d97b5817a1fc7
Digital Guardian Management Console version 7.1.2.0015 suffer from a server-side request forgery vulnerability.
f1b0b22b704b5604dddfeb0b710a6726a23262722923f328e058f820cb584add
Lutron Quantum versions 2.0 through 3.2.243 suffer from an information disclosure vulnerability.
6328339a48c0fa2a65575ff54b997e175b5acc99ddbc3b76945e34e07a2fad96
WordPress Caldera Forms plugin version 1.5.9.1 suffers from a cross site scripting vulnerability.
5ba544e8afc1bd3b2ce994ab5600e72cb1ca79a17152a722178a125e25528c4e
This Microsoft bulletin summary holds CVE revision updates for CVE-2018-1035.
f4acc3da4f77a4a78872a6c2a54dc7190ec69bda8788cb5eb7c8a24535d28999
Facebook Graph groups crosswalk user's metadata mapping weakness demo proof of concept script.
2fec004a3acc305a371175f91db5554d47f38b1459d46aea1e5a5eeda02760fb
Joomla JS Jobs component version 1.2.0 suffers from a cross site request forgery vulnerability.
7567b0061def93cea876d101656abf7f8c7e7f1e0377907414e206e95519fad6
Geist WatchDog Console version 3.2.2 suffers from cross site scripting, XML external entity injection, and insecure file permission vulnerabilities.
d918f241ee6c7025f29ccf1f1cb519560eb23c715777ff59995bc0cdf7a81280