[FD] CVE-2018-11101: Signal-desktop HTML tag injection variant 2

2018-05-16 Thread Alfredo Ortega
Title: Signal-desktop HTML tag injection variant 2 Date Published: 2018-05-16 Last Update: 2018-05-16 CVE Name: CVE-2018-11101 Class: Code injection Remotely Exploitable: Yes Locally Exploitable: No Vendors contacted: Signal.org Vulnerability Description: Signal-desktop is the standalone

[FD] Privilege escalation on Windows10/x by shortcut alteration.

2018-05-16 Thread Davide Lombardo
According to Microsoft it is not a security concern: UAC is rendered useless by the possibility of an unprivileged session to modify shortcuts to point at an identical looking executable which can silently run malicious code with admin approval, Windows defender would not help much. I have

[FD] PDFParser vulnerability

2018-05-16 Thread bear.xiong
PDFParser vulnerability Author : Webin security lab - dbapp security Ltd === Introduction: = A tool to parse pdf file. Affected version: = lastest version Vulnerability Description: == 1. The ObjReader::ReadObj() function in

[FD] vcftools 0.1.15 vuln bugs

2018-05-16 Thread bear.xiong
vcftools multiple vulnerabilities Author : Webin security lab - dbapp security Ltd === Introduction: = A set of tools written in Perl and C++ for working with VCF files, such as those generated by the 1000 Genomes Project. Project website:

[FD] SEC Consult SA-20180516-0 :: XXE & XSS vulnerabilities in RSA Authentication Manager

2018-05-16 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory < 20180516-0 > === title: XXE & XSS vulnerabilities product: RSA Authentication Manager vulnerable version: 8.2.1.4.0-build1394922, < 8.3 P