vendredi 19 juillet 2019    || Inscription
BanniereAlertes
 
 

Notre sélection d'alertes et avis SSI.
Sources : US Cert, Cert EU, Cert FR, Cnil, VulDB.

AudioCodes Mediant 500L-MSBR prior 7.20A.202.307 Management Web Interface CSRFProtection cross site request forgery

A vulnerability was found in AudioCodes Mediant 500L-MSBR, Mediant 500-MBSR, Mediant M800B-MSBR and Mediant 800C-MSBR. It has been declared as problematic. Affected by this vulnerability is an unknown part of the component Management Web...
Auteur: VulDB

AudioCodes Mediant 500L-MSBR F7.20A.25 Management Web Interface keyword cross site scripting

A vulnerability was found in AudioCodes Mediant 500L-MSBR, Mediant 500-MBSR, Mediant M800B-MSBR and Mediant 800C-MSBR F7.20A.25. It has been classified as problematic. Affected is some unknown functionality of the component Management Web...
Auteur: VulDB

Kaspersky Anti-Virus/Internet Security/Total Security up to 2019 Product ID information disclosure

A vulnerability was found in Kaspersky Anti-Virus, Internet Security and Total Security up to 2019 (Anti-Malware Software) and classified as problematic. This issue affects an unknown functionality of the component Product ID Handler. The...
Auteur: VulDB

Adobe Bridge CC up to 9.0.2 Out-of-Bounds memory corruption

A vulnerability has been found in Adobe Bridge CC up to 9.0.2 and classified as critical. This vulnerability affects an unknown function. The manipulation with an unknown input leads to a memory corruption vulnerability (Out-of-Bounds). The CWE...
Auteur: VulDB

Adobe Dreamweaver up to 18.0 Direct Download Installer privilege escalation

A vulnerability, which was classified as critical, was found in Adobe Dreamweaver up to 18.0. This affects some unknown processing of the component Direct Download Installer. The manipulation with an unknown input leads to a privilege escalation...
Auteur: VulDB

Adobe Experience Manager up to 6.4 Reflected cross site scripting

A vulnerability, which was classified as problematic, has been found in Adobe Experience Manager up to 6.4 (Content Management System). Affected by this issue is an unknown code block. The manipulation with an unknown input leads to a cross site...
Auteur: VulDB

Adobe Experience Manager up to 6.4 Stored cross site scripting

A vulnerability classified as problematic was found in Adobe Experience Manager up to 6.4 (Content Management System). Affected by this vulnerability is an unknown code. The manipulation with an unknown input leads to a cross site scripting...
Auteur: VulDB

Adobe Experience Manager up to 6.4 cross site request forgery

A vulnerability classified as problematic has been found in Adobe Experience Manager up to 6.4 (Content Management System). Affected is an unknown part. The manipulation with an unknown input leads to a cross site request forgery vulnerability....
Auteur: VulDB

Cloud Foundry UAA prior 73.4.0 X-Frame-Options Clickjacking privilege escalation

A vulnerability was found in Cloud Foundry UAA (Cloud Software). It has been rated as problematic. This issue affects some unknown functionality of the component X-Frame-Options Handler. The manipulation with an unknown input leads to a...
Auteur: VulDB

Dell EMC Unity/UnityVSA up to 5.0.0.0.5 Password Storage weak encryption

A vulnerability was found in Dell EMC Unity and UnityVSA up to 5.0.0.0.5. It has been declared as critical. This vulnerability affects an unknown functionality of the component Password Storage. The manipulation with an unknown input leads to a...
Auteur: VulDB

Dell EMC Unity/UnityVSA up to 5.0.0.0.5 Authorization privilege escalation

A vulnerability was found in Dell EMC Unity and UnityVSA up to 5.0.0.0.5. It has been classified as critical. This affects an unknown function of the component Authorization. The manipulation with an unknown input leads to a privilege escalation...
Auteur: VulDB

McAfee Agent up to 5.6.1 HF2 privilege escalation [CVE-2019-3592]

A vulnerability was found in McAfee Agent up to 5.6.1 HF2 and classified as critical. Affected by this issue is some unknown processing. The manipulation with an unknown input leads to a privilege escalation vulnerability. Using CWE to declare...
Auteur: VulDB

HHVM up to 4.3.0 scrypt_enc() N/r/p memory corruption

A vulnerability has been found in HHVM up to 4.3.0 and classified as critical. Affected by this vulnerability is the function scrypt_enc(). The manipulation of the argument N/r/p as part of a Parameter leads to a memory corruption vulnerability...
Auteur: VulDB

VideoLAN VLC Media Player up to 3.0.7 video.c lavc_CopyPicture width/height memory corruption

A vulnerability, which was classified as critical, was found in VideoLAN VLC Media Player up to 3.0.7 (Multimedia Player Software). Affected is the function lavc_CopyPicture of the file modules/codec/avcodec/video.c. The manipulation of the...
Auteur: VulDB

flatCore up to 1.4 files.upload-script.php cross site request forgery

A vulnerability, which was classified as problematic, has been found in flatCore up to 1.4. This issue affects an unknown part of the file acp/core/files.upload-script.php. The manipulation with an unknown input leads to a cross site request...
Auteur: VulDB

libjpeg-turbo 2.0.2 JPEG Image width/height denial of service [Disputed]

A vulnerability classified as problematic was found in libjpeg-turbo 2.0.2. This vulnerability affects some unknown functionality of the component JPEG Image Handler. The manipulation of the argument width/height with an unknown input leads to a...
Auteur: VulDB

Bento4 1.5.1-627 SetDataSize denial of service

A vulnerability classified as problematic has been found in Bento4 1.5.1-627 (Multimedia Player Software). This affects the function AP4_DataBuffer::SetDataSize. The manipulation with an unknown input leads to a denial of service vulnerability...
Auteur: VulDB

Discuz!ML 3.2/3.3/3.4 Cookie PHP Code Execution privilege escalation

A vulnerability was found in Discuz!ML 3.2/3.3/3.4. It has been rated as critical. Affected by this issue is an unknown function of the component Cookie Handler. The manipulation with an unknown input leads to a privilege escalation...
Auteur: VulDB

gdnsd 3.2.0 zscan_rfc1035.rl set_ipv6() memory corruption

A vulnerability was found in gdnsd 3.2.0. It has been declared as critical. Affected by this vulnerability is the function set_ipv6() of the file zscan_rfc1035.rl. The manipulation with an unknown input leads to a memory corruption vulnerability...
Auteur: VulDB

gdnsd 3.2.0 zscan_rfc1035.rl set_ipv4() memory corruption

A vulnerability was found in gdnsd 3.2.0. It has been classified as critical. Affected is the function set_ipv4() of the file zscan_rfc1035.rl. The manipulation with an unknown input leads to a memory corruption vulnerability (Stack-based). CWE...
Auteur: VulDB

SyGuestBook A5 1.2 Comment Reply index.php cross site scripting

A vulnerability was found in SyGuestBook A5 1.2 and classified as problematic. This issue affects an unknown code of the file index.php?c=admin&a=index of the component Comment Reply Handler. The manipulation with an unknown input leads to a...
Auteur: VulDB

SyGuestBook A5 1.2 index.php cross site request forgery

A vulnerability has been found in SyGuestBook A5 1.2 and classified as critical. This vulnerability affects an unknown part of the file index.php?c=Administrator&a=update. The manipulation with an unknown input leads to a cross site request...
Auteur: VulDB

SyGuestBook A5 1.2 include/functions.php isValidData IMG Element cross site scripting

A vulnerability, which was classified as problematic, was found in SyGuestBook A5 1.2. This affects the function isValidData of the file include/functions.php. The manipulation as part of a IMG Element leads to a cross site scripting...
Auteur: VulDB

b3log Wide up to 1.5.x privilege escalation [CVE-2019-13915]

A vulnerability, which was classified as critical, has been found in b3log Wide up to 1.5.x. Affected by this issue is an unknown functionality. The manipulation with an unknown input leads to a privilege escalation vulnerability. Using CWE to...
Auteur: VulDB

Opera Mini up to 16.0.14 on iOS javascript: URL Universal cross site scripting

A vulnerability classified as critical was found in Opera Mini up to 16.0.14 on iOS (iOS App Software). Affected by this vulnerability is an unknown function. The manipulation as part of a javascript: URL leads to a cross site scripting...
Auteur: VulDB
12345678910Last

Événements SSI

BLACK HAT

Événement majeur mondial sur la sécurité de l'information la conférence Black Hat USA a lieu du 3 au 8 août 2019 à Las Vegas (Mandalay Bay). Organisé par UBM.


Présentation par l'organisateur

Now in its 22nd year, Black Hat USA is the world's leading information security event, providing attendees with the very latest in research, development and trends. Black Hat USA 2019 opens with four days of technical Trainings (August 3-6) followed by the two-day main conference (August 7-8) featuring Briefings, Arsenal, Business Hall, and more.

 Plus d'infos sur le site dédié à l'événement.

LES ASSISES

Grand rendez-vous annuel des RSSI, les Assises de la sécurité des systèmes d'information se tiennent à Monaco (Grimaldi Forum) du 9 au 12 octobre 2019. Organisées par DG Consultants.

Présentation par l'organisateur



Retour sur Les Assises 2018

La 18ème édition des Assises de la Sécurité à Monaco, c’est terminé ! Encore merci aux 2800 participants dont les 160 partenaires qui pendant trois jours se sont retrouvés pour faire vivre cet événement unique en France. Conférences, one-to-one, tables-rondes, ateliers, moments de networking… Par leur contenu, par la qualité des visiteurs et par la richesse des échanges, les Assises se positionnent plus que jamais comme le rendez-vous incontournable de tous les professionnels de la cybersécurité. A l’image du marché qui ne cesse d’évoluer, les Assises savent adapter leur offre afin de répondre au mieux aux attentes du secteur. Ainsi cette édition a-t-elle voulu mettre en avant les grands enjeux du moment en multipliant les prises de parole, les démonstrations et les retours d’expérience.

Rendez-vous maintenant pour la prochaine édition qui aura lieu du 9 au 12 octobre 2019

Plus d'informations sur le site dédié à l'événement.

RSS