Re: Samsung TV - DoS vulnerability

2013-07-22 Thread malik
Assigned CVE number: CVE-2013-4890

Photo Server 2.0 iOS - Multiple Critical Vulnerabilities

2013-07-22 Thread Vulnerability Lab
Title: == Photo Server 2.0 iOS - Multiple Critical Vulnerabilities Date: = 2013-07-23 References: === http://www.vulnerability-lab.com/get_content.php?id=1029 VL-ID: = 1029 Common Vulnerability Scoring System: 8.6 Introduction:

Defense in depth -- the Microsoft way (part 4)

2013-07-22 Thread Stefan Kanthak
Hi, Microsoft distributes (security critical) updates for Windows components and Microsoft products installed on user systems via "Windows/Microsoft Update" and installs them automatically. Except in some VERY common cases... For the incorporation of redistributable components like the MSVCRT, M

SurgeFtp Server BufferOverflow Vulnerability

2013-07-22 Thread Anil Pazvant
--- | SurgeFtp Server BufferOverflow Vulnerability| Summary SurgeFTP Server has a buffer overflow vulnerability which

Juniper Secure Access XSS Vulnerability

2013-07-22 Thread Anil Pazvant
--- | Juniper Secure Access XSS Vulnerability| Summary === Juniper Secure Access software has reflected XSS vulnerability

Dell Kace 1000 SMA 5.4.742 - SQL Injection Vulnerabilities

2013-07-22 Thread Vulnerability Lab
Title: == Dell Kace 1000 SMA 5.4.742 - SQL Injection Vulnerabilities Date: = 2013-07-22 References: === http://www.vulnerability-lab.com/get_content.php?id=832 VL-ID: = 832 Common Vulnerability Scoring System: 7.5 Introduction:

Full Disclosure - WD My Net N600, N750, N900, N900C - Plain Text Disclosure of Admin Credentials

2013-07-22 Thread kyle Lovett
Vulnerable Products - WD My Net N600 HD Dual Band Router Wireless N WiFi Router Accelerate HD WD My Net N750 HD Dual Band Router Wireless N WiFi Router Accelerate HD Linux 2.6.3 Kernel Firmware Ver. 1.03.xx 1.04.xx Firmware unaffected Ver 1.01.xx WD My Net N900 HD Dual Band Router Wireless N WiFi

Barracuda CudaTel 2.6.02.040 - SQL Injection Vulnerability

2013-07-22 Thread Vulnerability Lab
Title: == Barracuda CudaTel 2.6.02.040 - SQL Injection Vulnerability Date: = 2013-07-20 References: === http://vulnerability-lab.com/get_content.php?id=775 BARRACUDA NETWORK SECURITY ID: BNSEC-723 VL-ID: = 775 Common Vulnerability Scoring System: ===

[CVE-2013-2137] Apache OFBiz XSS vulnerability in the "View Log" screen of the Webtools application

2013-07-22 Thread Jacopo Cappellato
CVE-2013-2137 - Apache OFBiz XSS vulnerability in the "View Log" screen of the Webtools application Vendor: The Apache Software Foundation Versions Affected: Apache OFBiz 10.04.01 to 10.04.05 Apache OFBiz 11.04.01 to 11.04.02 Apache OFBiz 12.04.01 Description: XSS vulnerability in the "View Lo

[CVE-2013-2250] Apache OFBiz Nested expression evaluation allows remote users to execute arbitrary UEL functions in OFBiz

2013-07-22 Thread Jacopo Cappellato
CVE-2013-2250 - Apache OFBiz Nested expression evaluation allows remote users to execute arbitrary UEL functions in OFBiz Vendor: The Apache Software Foundation Versions Affected: Apache OFBiz 10.04.01 to 10.04.05 Apache OFBiz 11.04.01 to 11.04.02 Apache OFBiz 12.04.01 Description: Parameter v