[ANNOUNCE] [SECURITY] CVE-2017-7660: Security Vulnerability in secure inter-node communication in Apache Solr

2017-07-07 Thread Shalin Shekhar Mangar
CVE-2017-7660: Security Vulnerability in secure inter-node communication in Apache Solr Severity: Important Vendor: The Apache Software Foundation Versions Affected: Solr 5.3 to 5.5.4 Solr 6.0 to 6.5.1 Description: Solr uses a PKI based mechanism to secure inter-node communication when securit

[SYSS-2017-011] Office 365: Insufficient Session Expiration (CWE-613)

2017-07-07 Thread Micha Borrmann
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Advisory ID: SYSS-2017-011 Product: Office 365 (Sharepoint) Manufacturer: Microsoft Affected Version(s): ? Tested Version(s): Office 365 Enterprise E3 (version from February 2017) Vulnerability Type: Insufficient Session Expiration (CWE-613) Risk Lev

KL-001-2017-014 : Barracuda WAF Support Tunnel Hijack

2017-07-07 Thread KoreLogic Disclosures
KL-001-2017-014 : Barracuda WAF Support Tunnel Hijack Title: Barracuda WAF Support Tunnel Hijack Advisory ID: KL-001-2017-014 Publication Date: 2017.07.06 Publication URL: https://www.korelogic.com/Resources/Advisories/KL-001-2017-014.txt 1. Vulnerability Details Affected Vendor: Barracud

Firefox v54.0.1 Denial Of Service

2017-07-07 Thread apparitionsec
[+] Credits: John Page aka hyp3rlinx [+] Website: hyp3rlinx.altervista.org [+] Source: http://hyp3rlinx.altervista.org/advisories/FIREFOX-v54.0.1-DENIAL-OF-SERVICE.txt [+] ISR: ApparitionSec Vendor: === www.mozilla.org Product: === Firefox v54.0.1

KL-001-2017-015 : Solarwinds LEM Hardcoded Credentials

2017-07-07 Thread KoreLogic Disclosures
KL-001-2017-015 : Solarwinds LEM Hardcoded Credentials Title: Solarwinds LEM Hardcoded Credentials Advisory ID: KL-001-2017-015 Publication Date: 2017.07.06 Publication URL: https://www.korelogic.com/Resources/Advisories/KL-001-2017-015.txt 1. Vulnerability Details Affected Vendor: Solarw

KL-001-2017-012 : Barracuda WAF Grub Password Complexity

2017-07-07 Thread KoreLogic Disclosures
KL-001-2017-012 : Barracuda WAF Grub Password Complexity Title: Barracuda WAF Grub Password Complexity Advisory ID: KL-001-2017-012 Publication Date: 2017.07.06 Publication URL: https://www.korelogic.com/Resources/Advisories/KL-001-2017-012.txt 1. Vulnerability Details Affected Vendor: Ba

KL-001-2017-011 : Barracuda WAF Internal Development Credential Disclosure

2017-07-07 Thread KoreLogic Disclosures
KL-001-2017-011 : Barracuda WAF Internal Development Credential Disclosure Title: Barracuda WAF Internal Development Credential Disclosure Advisory ID: KL-001-2017-011 Publication Date: 2017.07.06 Publication URL: https://www.korelogic.com/Resources/Advisories/KL-001-2017-011.txt 1. Vulnerabili