vendredi 19 juillet 2019    || Inscription
BanniereAlertes
 
 

Notre sélection d'alertes et avis SSI.
Sources : US Cert, Cert EU, Cert FR, Cnil, VulDB.

WPEverest Everest Forms Plugin up to 1.4.9 on WordPress evf-entry-functions.php sql injection

A vulnerability classified as critical has been found in WPEverest Everest Forms Plugin up to 1.4.9 on WordPress (WordPress Plugin). Affected is some unknown processing of the file includes/evf-entry-functions.php. The manipulation with an...
Auteur: VulDB

Docker Community Edition/Enterprise Edition Debug Mode Log information disclosure

A vulnerability was found in Docker Community Edition and Enterprise Edition (Virtualization Software) (unknown version). It has been rated as problematic. This issue affects an unknown code block of the component Debug Mode. The manipulation ...
Auteur: VulDB

Avast Antivirus up to 19.3 AvastSvc.exe privilege escalation

A vulnerability was found in Avast Antivirus up to 19.3 (Anti-Malware Software). It has been declared as problematic. This vulnerability affects an unknown code of the file AvastSvc.exe. The manipulation with an unknown input leads to a...
Auteur: VulDB

Open Information Security Foundation Suricata up to 4.1.2 HTTP Detection Network Packet denial of service

A vulnerability was found in Open Information Security Foundation Suricata up to 4.1.2. It has been classified as problematic. This affects an unknown part of the component HTTP Detection. The manipulation as part of a Network Packet leads to a...
Auteur: VulDB

Ladon 0.6.1 XML Data SOAP Request XML External Entity

A vulnerability was found in Ladon 0.6.1 and classified as critical. Affected by this issue is some unknown functionality of the component XML Data Handler. The manipulation as part of a SOAP Request leads to a privilege escalation vulnerability...
Auteur: VulDB

scapy up to 2.4.0 _RADIUSAttrPacketListField Packet denial of service

A vulnerability has been found in scapy up to 2.4.0 and classified as problematic. Affected by this vulnerability is the function _RADIUSAttrPacketListField. The manipulation as part of a Packet leads to a denial of service vulnerability (Loop)....
Auteur: VulDB

Gitea up to 1.7.0 cross site scripting [CVE-2019-1010261]

A vulnerability, which was classified as problematic, was found in Gitea up to 1.7.0. Affected is an unknown function. The manipulation with an unknown input leads to a cross site scripting vulnerability. CWE is classifying the issue as CWE-80....
Auteur: VulDB

SaltStack Salt 2018.3/2019.2 mysqluser_chpass sql injection

A vulnerability, which was classified as critical, has been found in SaltStack Salt 2018.3/2019.2. This issue affects the function mysqluser_chpass. The manipulation with an unknown input leads to a sql injection vulnerability. Using CWE to...
Auteur: VulDB

Linux Foundation ONOS up to 2.0.0 FlowRuleManager.java applyFlowRules/apply privilege escalation

A vulnerability classified as critical was found in Linux Foundation ONOS up to 2.0.0. This vulnerability affects the function applyFlowRules/apply of the file FlowRuleManager.java. The manipulation with an unknown input leads to a privilege...
Auteur: VulDB

Open Information Security Foundation Suricata up to 4.1.1 DNS Detection app-layer-detect-proto.c Network Request denial of service

A vulnerability classified as problematic has been found in Open Information Security Foundation Suricata up to 4.1.1. This affects an unknown code of the file app-layer-detect-proto.c of the component DNS Detection. The manipulation as part of...
Auteur: VulDB

Linux Foundation ONOS up to 2.0.0 FlowWebResource.java createFlow/createFlows privilege escalation

A vulnerability was found in Linux Foundation ONOS up to 2.0.0. It has been rated as critical. Affected by this issue is the function createFlow/createFlows of the file FlowWebResource.java. The manipulation with an unknown input leads to a...
Auteur: VulDB

Linux Foundation ONOS up to 2.0.0 FlowWebResource.java createFlow() memory corruption

A vulnerability was found in Linux Foundation ONOS up to 2.0.0. It has been declared as critical. Affected by this vulnerability is the function createFlow() of the file FlowWebResource.java. The manipulation with an unknown input leads to a...
Auteur: VulDB

Synetics i-doit up to 1.12 HTTP POST Request sql injection

A vulnerability was found in Synetics i-doit up to 1.12. It has been classified as critical. Affected is an unknown functionality. The manipulation as part of a HTTP POST Request leads to a sql injection vulnerability. CWE is classifying the...
Auteur: VulDB

MailCleaner NewslettersController.php allowAction() HTTP GET Request information disclosure

A vulnerability was found in MailCleaner (unknown version) and classified as problematic. This issue affects the function allowAction() of the file NewslettersController.php. The manipulation as part of a HTTP GET Request leads to a information...
Auteur: VulDB

Oecms 4.3.R60321 admincp.php cross site request forgery

A vulnerability has been found in Oecms 4.3.R60321 and classified as problematic. This vulnerability affects some unknown processing of the file admincp.php. The manipulation with an unknown input leads to a cross site request forgery...
Auteur: VulDB

TechyTalk Quick Chat Plugin on WordPress AJAX Request Quick-chat.php sql injection

A vulnerability, which was classified as critical, was found in TechyTalk Quick Chat Plugin on WordPress (the affected version unknown). This affects an unknown code block of the file Quick-chat.php of the component AJAX Request Handler. The...
Auteur: VulDB

BACnet Stack bacserv 0.8.5/0.9.1 bacserv BVLC forwarded NPDU bvlc_bdt_forward_npdu() memory corruption

A vulnerability, which was classified as problematic, has been found in BACnet Stack bacserv 0.8.5/0.9.1. Affected by this issue is the function bvlc_bdt_forward_npdu() of the component bacserv BVLC forwarded NPDU. The manipulation with an...
Auteur: VulDB

Moinejf abcm2ps 8.13.20 Access Control front.c txt_add Commit denial of service

A vulnerability classified as problematic was found in Moinejf abcm2ps 8.13.20. Affected by this vulnerability is the function txt_add of the file front.c of the component Access Control. The manipulation as part of a Commit leads to a denial of...
Auteur: VulDB

Lawrence Livermore National Laboratory msr-safe 1.1.0 Access Control privilege escalation

A vulnerability classified as critical has been found in Lawrence Livermore National Laboratory msr-safe 1.1.0. Affected is some unknown functionality of the component Access Control. The manipulation with an unknown input leads to a privilege...
Auteur: VulDB

The Sleuth Kit up to 4.6.0 fls Tool tsk/fs/hfs_dent.c hfs_cat_traverse() memory corruption

A vulnerability was found in The Sleuth Kit up to 4.6.0. It has been rated as critical. This issue affects the function hfs_cat_traverse() of the file tsk/fs/hfs_dent.c of the component fls Tool. The manipulation with an unknown input leads to a...
Auteur: VulDB

Canadian Centre for Cyber Security Releases Advisory on Fileless Malware

Original release date: July 18, 2019The Canadian Centre for Cyber Security (CCCS) has released an advisory on an Astaroth fileless malware campaign affecting Microsoft Windows. Astaroth resides solely in memory, and an attacker can use it and...
Auteur: US Cert

DomainMod 4.10.0 cross site request forgery [CVE-2019-1010096]

A vulnerability was found in DomainMod 4.10.0. It has been declared as problematic. This vulnerability affects an unknown function. The manipulation with an unknown input leads to a cross site request forgery vulnerability. The CWE definition...
Auteur: VulDB

DomainMod 4.10.0 cross site request forgery [CVE-2019-1010095]

A vulnerability was found in DomainMod 4.10.0. It has been classified as problematic. This affects some unknown processing. The manipulation with an unknown input leads to a cross site request forgery vulnerability. CWE is classifying the issue...
Auteur: VulDB

DomainMod 4.10.0 cross site request forgery [CVE-2019-1010094]

A vulnerability was found in DomainMod 4.10.0 and classified as problematic. Affected by this issue is an unknown code block. The manipulation with an unknown input leads to a cross site request forgery vulnerability. Using CWE to declare the...
Auteur: VulDB

Dolibarr 7.0.0 cross site request forgery [CVE-2019-1010054]

A vulnerability has been found in Dolibarr 7.0.0 (Enterprise Resource Planning Software) and classified as problematic. Affected by this vulnerability is an unknown code. The manipulation with an unknown input leads to a cross site request...
Auteur: VulDB
12345678910Last

Événements SSI

BLACK HAT

Événement majeur mondial sur la sécurité de l'information la conférence Black Hat USA a lieu du 3 au 8 août 2019 à Las Vegas (Mandalay Bay). Organisé par UBM.


Présentation par l'organisateur

Now in its 22nd year, Black Hat USA is the world's leading information security event, providing attendees with the very latest in research, development and trends. Black Hat USA 2019 opens with four days of technical Trainings (August 3-6) followed by the two-day main conference (August 7-8) featuring Briefings, Arsenal, Business Hall, and more.

 Plus d'infos sur le site dédié à l'événement.

LES ASSISES

Grand rendez-vous annuel des RSSI, les Assises de la sécurité des systèmes d'information se tiennent à Monaco (Grimaldi Forum) du 9 au 12 octobre 2019. Organisées par DG Consultants.

Présentation par l'organisateur



Retour sur Les Assises 2018

La 18ème édition des Assises de la Sécurité à Monaco, c’est terminé ! Encore merci aux 2800 participants dont les 160 partenaires qui pendant trois jours se sont retrouvés pour faire vivre cet événement unique en France. Conférences, one-to-one, tables-rondes, ateliers, moments de networking… Par leur contenu, par la qualité des visiteurs et par la richesse des échanges, les Assises se positionnent plus que jamais comme le rendez-vous incontournable de tous les professionnels de la cybersécurité. A l’image du marché qui ne cesse d’évoluer, les Assises savent adapter leur offre afin de répondre au mieux aux attentes du secteur. Ainsi cette édition a-t-elle voulu mettre en avant les grands enjeux du moment en multipliant les prises de parole, les démonstrations et les retours d’expérience.

Rendez-vous maintenant pour la prochaine édition qui aura lieu du 9 au 12 octobre 2019

Plus d'informations sur le site dédié à l'événement.

RSS