Cisco Security Advisory: Cisco Security Advisory Cisco WebEx Meetings Server Command Injection Vulnerability

2015-02-04 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory Cisco WebEx Meetings Server Command Injection Vulnerability Advisory ID: cisco-sa-20150204-wbx Revision 1.0 For Public Release 2015 February 4 16:00 UTC (GMT

Re: Re: CVE-2015-1437 XSS In ASUS Router.

2015-02-04 Thread kingkaustubh
Here is the exact conversation ASUS CASEID=RTM20150115204498-295 Please click here if you wish to reply this mail! Dear Kaustubh, Thank you for the information, we really appreciate your feedback. To improve our customers experience we have forwarded your information to related

ESA-2015-010: EMC Documentum D2 Multiple Vulnerabilities

2015-02-04 Thread Security Alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ESA-2015-010: EMC Documentum D2 Multiple Vulnerabilities EMC Identifier: ESA-2015-010 CVE Identifier: CVE-2015-0517, CVE-2015-0518 Affected products: • EMC Documentum D2 3.1 and all patch versions • EMC Documentum D2 3.1 SP1 and all

Re: CVE-2015-1437 XSS In ASUS Router.

2015-02-04 Thread Darko Vršič
On 02/04/2015 02:44 PM, Michael Meyer wrote: *** kingkaust...@me.com wrote: # Title:- Reflected XSS vulnarbility in Asus RT-N10 Plus router Author: Kaustubh G. Padwad Product: ASUS Router RT-N10 Plus Firmware: 2.1.1.1.70 Severity: HIGH Auth: Not

Re: [FD] Major Internet Explorer Vulnerability - NOT Patched

2015-02-04 Thread David Leo
Microsoft was notified on Oct 13, 2014. Joey thank you very much for your words. Kind Regards, On 2015/2/3 4:53, Joey Fowler wrote: Hi David, nice is an understatement here. I've done some testing with this one and, while there /are/ quirks, it most definitely works. It even bypasses

Re: CVE-2015-1437 XSS In ASUS Router.

2015-02-04 Thread Michael Meyer
*** kingkaust...@me.com wrote: # Title:- Reflected XSS vulnarbility in Asus RT-N10 Plus router Author: Kaustubh G. Padwad Product: ASUS Router RT-N10 Plus Firmware: 2.1.1.1.70 Severity: HIGH Auth: Not requierd CVE ID: CVE-2015-1437 #

ESA-2014-158: RSA BSAFE® Micro Edition Suite, SSL-J and SSL-C Triple Handshake Vulnerability

2015-02-04 Thread Security Alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ESA-2014-158: RSA BSAFE® Micro Edition Suite, SSL-J and SSL-C Triple Handshake Vulnerability EMC Identifier: ESA-2014-158 CVE Identifier: CVE-2014-4630 Severity Rating: CVSS v2 Base Score: 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P) Affected

Bitdefender Internet Security -

2015-02-04 Thread jerold
There seems to be some security issues with the way Bitdefender Internet Security 2015 software (Build 18.20.0.1429) interacts with its myBitdefender online portal. Issues: 1) Possible partial information disclosure privacy issue of users' myBitdefender account credentials when using the

[SECURITY] [DSA 3153-1] krb5 security update

2015-02-04 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-3153-1 secur...@debian.org http://www.debian.org/security/Moritz Muehlenhoff February 03, 2015

[CVE-2015-1467] Fork CMS - SQL Injection in Version 3.8.5

2015-02-04 Thread sven
[CVE-2015-1467] Fork CMS - SQL Injection in Version 3.8.5 Product Information: Software: Fork CMS Tested Version: 3.8.5, released on Wednesday 14 January 2015 Vulnerability Type: SQL Injection (CWE-89) Download link to tested

Re: CVE-2015-1437 XSS In ASUS Router.

2015-02-04 Thread Henri Salo
On Tue, Feb 03, 2015 at 04:54:26PM +, kingkaust...@me.com wrote: 8-jan-2015 Repoerted to ASUS 9-jan-2015 Asus confirm that they reported to concern department 15-jan-2015 Ask for update from asus asus says reported to HQ 28-jan-2015 Ask asus about reporting security foucus No reply from