vendredi 19 juillet 2019    || Inscription
BanniereAlertes
 
 

Notre sélection d'alertes et avis SSI.
Sources : US Cert, Cert EU, Cert FR, Cnil, VulDB.

Oracle Releases July 2019 Security Bulletin

Original release date: July 16, 2019Oracle has released its Critical Patch Update for July 2019 to address 319 vulnerabilities across multiple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected...
Auteur: US Cert

DHS Webinar: Cybersecurity Threats to the Healthcare Sector

Original release date: July 16, 2019The Department of Homeland Security (DHS) and the American Hospital Association (AHA) are conducting a webinar focused on current cybersecurity threats to the healthcare sector. The webinar will be held on...
Auteur: US Cert

IRS Releases Six Cybersecurity Safeguards

Original release date: July 16, 2019The Internal Revenue Service (IRS) has issued a news release outlining six cybersecurity safeguards to protect computers, email, and sensitive data. The recommendations are part of the Taxes. Security....
Auteur: US Cert

Alt-N MDaemon 19 Spam Messages privilege escalation

A vulnerability was found in Alt-N MDaemon 19 (Mail Server Software). It has been rated as critical. This issue affects an unknown part of the component Spam Handler. The manipulation as part of a Messages leads to a privilege escalation...
Auteur: VulDB

PluckCMS up to 4.7.4 File Upload data/inc/images.php HTTP Request privilege escalation

A vulnerability was found in PluckCMS up to 4.7.4. It has been declared as critical. This vulnerability affects some unknown functionality of the file data/inc/images.php of the component File Upload. The manipulation as part of a HTTP Request...
Auteur: VulDB

BigTree CMS Users Management Page cross site scripting [CVE-2019-1010061]

A vulnerability was found in BigTree CMS (Content Management System) (the affected version unknown). It has been classified as problematic. This affects an unknown functionality of the component Users Management Page. The manipulation with an...
Auteur: VulDB

NASA CFITSIO up to 3.42 Code Execution memory corruption

A vulnerability was found in NASA CFITSIO up to 3.42 and classified as critical. Affected by this issue is an unknown function. The manipulation with an unknown input leads to a memory corruption vulnerability (Code Execution). Using CWE to...
Auteur: VulDB

nfdump up to 1.6.16 nfx.c memory corruption

A vulnerability has been found in nfdump up to 1.6.16 and classified as critical. Affected by this vulnerability is some unknown processing of the file nfx.c. The manipulation with an unknown input leads to a memory corruption vulnerability...
Auteur: VulDB

Zammad up to 2.3.0 cross site scripting [CVE-2019-1010018]

A vulnerability, which was classified as problematic, was found in Zammad up to 2.3.0. Affected is an unknown code block. The manipulation with an unknown input leads to a cross site scripting vulnerability. CWE is classifying the issue as...
Auteur: VulDB

CERTFR-2019-AVI-337 : Multiples vulnérabilités dans le noyau Linux de SUSE (16 juillet 2019)

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, un déni de service et un contournement de la politique...
Auteur: Cert FR

CERTFR-2019-AVI-336 : Multiples vulnérabilités dans Google Chrome (16 juillet 2019)

De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un déni de service à distance et une atteinte à la confidentialité des données.

Auteur: Cert FR

CERTFR-2019-AVI-335 : Multiples vulnérabilités dans Palo Alto PAN-OS (16 juillet 2019)

De multiples vulnérabilités ont été découvertes dans Palo Alto PAN-OS. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une élévation de privilèges.

Auteur: Cert FR

CERTFR-2019-AVI-334 : Multiples vulnérabilités dans Moodle (16 juillet 2019)

De multiples vulnérabilités ont été découvertes dans Moodle. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité et une atteinte à l'intégrité des données.

Auteur: Cert FR

Schneider Electric Interactive Graphical SCADA System up to 14 MDB Database Out-of-Bounds memory corruption

A vulnerability, which was classified as critical, has been found in Schneider Electric Interactive Graphical SCADA System up to 14 (SCADA Software). This issue affects an unknown code of the component MDB Database Handler. The manipulation with...
Auteur: VulDB

ProClima up to 7.x DLL Search Path privilege escalation

A vulnerability classified as critical was found in ProClima up to 7.x. This vulnerability affects an unknown part of the component DLL Handler. The manipulation as part of a Search Path leads to a privilege escalation vulnerability. The CWE...
Auteur: VulDB

ProClima up to 7.x Code Execution memory corruption

A vulnerability classified as critical has been found in ProClima up to 7.x. This affects some unknown functionality. The manipulation with an unknown input leads to a memory corruption vulnerability (Code Execution). CWE is classifying the...
Auteur: VulDB

ProClima up to 7.x Remote Code Execution [CVE-2019-6823]

A vulnerability was found in ProClima up to 7.x. It has been rated as critical. Affected by this issue is an unknown functionality. The manipulation with an unknown input leads to a privilege escalation vulnerability (Code Execution). Using CWE...
Auteur: VulDB

Schneider Electric ZelioSoft2 up to 5.2 Project File Use-After-Free memory corruption

A vulnerability was found in Schneider Electric ZelioSoft2 up to 5.2. It has been declared as critical. Affected by this vulnerability is an unknown function. The manipulation as part of a Project File leads to a memory corruption vulnerability...
Auteur: VulDB

http-file-server up to 0.2.6 on NPM directory traversal [CVE-2019-5447]

A vulnerability was found in http-file-server up to 0.2.6 on NPM. It has been classified as problematic. Affected is some unknown processing. The manipulation with an unknown input leads to a directory traversal vulnerability. CWE is classifying...
Auteur: VulDB

python-engineio up to 3.8.2 Websocket privilege escalation

A vulnerability was found in python-engineio up to 3.8.2 (Programming Language Software) and classified as critical. This issue affects an unknown code block of the component Websocket Handler. The manipulation with an unknown input leads to a...
Auteur: VulDB

HID Global DigitalPersona U.are.U 4500 v24 Key weak encryption

A vulnerability has been found in HID Global DigitalPersona U.are.U 4500 v24 and classified as critical. This vulnerability affects an unknown code. The manipulation with an unknown input leads to a weak encryption vulnerability (Key). The CWE...
Auteur: VulDB

Aquaverde Aquarius CMS up to 4.1.0 Log File Password information disclosure

A vulnerability, which was classified as problematic, was found in Aquaverde Aquarius CMS up to 4.1.0 (Content Management System). This affects an unknown part of the component Log File Handler. The manipulation with an unknown input leads to a...
Auteur: VulDB

GLPI 9.3.1 getDropDownValue.php Request cross site scripting

A vulnerability, which was classified as problematic, has been found in GLPI 9.3.1 (Asset Management Software). Affected by this issue is some unknown functionality of the file /glpi/ajax/getDropDownValue.php. The manipulation as part of a...
Auteur: VulDB

Slanger 0.6.0 Message Remote Code Execution

A vulnerability classified as critical was found in Slanger 0.6.0. Affected by this vulnerability is an unknown functionality of the component Message Handler. The manipulation with an unknown input leads to a privilege escalation vulnerability...
Auteur: VulDB

libmspack 0.9.1alpha libmspack/mspack/chmd.c) chmd_read_headers() CHM File memory corruption

A vulnerability classified as critical has been found in libmspack 0.9.1alpha. Affected is the function chmd_read_headers() of the file libmspack/mspack/chmd.c). The manipulation as part of a CHM File leads to a memory corruption vulnerability....
Auteur: VulDB
First567891011121314Last

Événements SSI

BLACK HAT

Événement majeur mondial sur la sécurité de l'information la conférence Black Hat USA a lieu du 3 au 8 août 2019 à Las Vegas (Mandalay Bay). Organisé par UBM.


Présentation par l'organisateur

Now in its 22nd year, Black Hat USA is the world's leading information security event, providing attendees with the very latest in research, development and trends. Black Hat USA 2019 opens with four days of technical Trainings (August 3-6) followed by the two-day main conference (August 7-8) featuring Briefings, Arsenal, Business Hall, and more.

 Plus d'infos sur le site dédié à l'événement.

LES ASSISES

Grand rendez-vous annuel des RSSI, les Assises de la sécurité des systèmes d'information se tiennent à Monaco (Grimaldi Forum) du 9 au 12 octobre 2019. Organisées par DG Consultants.

Présentation par l'organisateur



Retour sur Les Assises 2018

La 18ème édition des Assises de la Sécurité à Monaco, c’est terminé ! Encore merci aux 2800 participants dont les 160 partenaires qui pendant trois jours se sont retrouvés pour faire vivre cet événement unique en France. Conférences, one-to-one, tables-rondes, ateliers, moments de networking… Par leur contenu, par la qualité des visiteurs et par la richesse des échanges, les Assises se positionnent plus que jamais comme le rendez-vous incontournable de tous les professionnels de la cybersécurité. A l’image du marché qui ne cesse d’évoluer, les Assises savent adapter leur offre afin de répondre au mieux aux attentes du secteur. Ainsi cette édition a-t-elle voulu mettre en avant les grands enjeux du moment en multipliant les prises de parole, les démonstrations et les retours d’expérience.

Rendez-vous maintenant pour la prochaine édition qui aura lieu du 9 au 12 octobre 2019

Plus d'informations sur le site dédié à l'événement.

RSS