jeudi 18 juillet 2019    || Inscription
BanniereAlertes
 
 

Notre sélection d'alertes et avis SSI.
Sources : US Cert, Cert EU, Cert FR, Cnil, VulDB.

ThinkCMF 5.0.190111 addpost.html alias privilege escalation

A vulnerability was found in ThinkCMF 5.0.190111. It has been declared as critical. This vulnerability affects a code block of the file portal/admin_category/addpost.html. The manipulation of the argument alias as part of a Parameter leads to a...
Auteur: VulDB

Simple DirectMedia Layer up to 1.2.15/2.0.9 audio/SDL_wave.c InitIMA_ADPCM memory corruption

A vulnerability was found in Simple DirectMedia Layer up to 1.2.15/2.0.9. It has been classified as critical. This affects the function InitIMA_ADPCM of the file audio/SDL_wave.c. The manipulation with an unknown input leads to a memory...
Auteur: VulDB

Simple DirectMedia Layer up to 1.2.15/2.0.9 audio/SDL_wave.c SDL_LoadWAV_RW memory corruption

A vulnerability was found in Simple DirectMedia Layer up to 1.2.15/2.0.9 and classified as critical. Affected by this issue is the function SDL_LoadWAV_RW of the file audio/SDL_wave.c. The manipulation with an unknown input leads to a memory...
Auteur: VulDB

Simple DirectMedia Layer up to 1.2.15/2.0.9 audio/SDL_wave.c InitMS_ADPCM memory corruption

A vulnerability has been found in Simple DirectMedia Layer up to 1.2.15/2.0.9 and classified as critical. Affected by this vulnerability is the function InitMS_ADPCM of the file audio/SDL_wave.c. The manipulation with an unknown input leads to a...
Auteur: VulDB

Simple DirectMedia Layer up to 1.2.15/2.0.9 audio/SDL_wave.c MS_ADPCM_decode memory corruption

A vulnerability, which was classified as critical, was found in Simple DirectMedia Layer up to 1.2.15/2.0.9. Affected is the function MS_ADPCM_decode of the file audio/SDL_wave.c. The manipulation with an unknown input leads to a memory...
Auteur: VulDB

Simple DirectMedia Layer up to 1.2.15/2.0.9 audio/SDL_wave.c IMA_ADPCM_decode memory corruption

A vulnerability, which was classified as critical, has been found in Simple DirectMedia Layer up to 1.2.15/2.0.9. This issue affects the function IMA_ADPCM_decode of the file audio/SDL_wave.c. The manipulation with an unknown input leads to a...
Auteur: VulDB

Simple DirectMedia Layer up to 1.2.15/2.0.9 audio/SDL_wave.c InitMS_ADPCM memory corruption

A vulnerability classified as critical was found in Simple DirectMedia Layer up to 1.2.15/2.0.9. This vulnerability affects the function InitMS_ADPCM of the file audio/SDL_wave.c. The manipulation with an unknown input leads to a memory...
Auteur: VulDB

Simple DirectMedia Layer up to 1.2.15/2.0.9 audio/SDL_wave.c IMA_ADPCM_nibble memory corruption

A vulnerability classified as critical has been found in Simple DirectMedia Layer up to 1.2.15/2.0.9. This affects the function IMA_ADPCM_nibble of the file audio/SDL_wave.c. The manipulation with an unknown input leads to a memory corruption...
Auteur: VulDB

PbootCMS 1.3.6 cross site request forgery [CVE-2019-7570]

A vulnerability was found in PbootCMS 1.3.6 (Content Management System). It has been rated as critical. Affected by this issue is some processing of the file admin.php/User/del/ucode/. The manipulation with an unknown input leads to a cross site...
Auteur: VulDB

DOYO 2.3 admin.php cross site request forgery

A vulnerability was found in DOYO 2.3. It has been declared as critical. Affected by this vulnerability is a code block of the file admin.php?c=a_adminuser&a=add&run=1. The manipulation with an unknown input leads to a cross site request forgery...
Auteur: VulDB

baijiacms V4 index.php cate sql injection

A vulnerability was found in baijiacms V4 (Content Management System). It has been classified as critical. Affected is code of the file index.php?act=index. The manipulation of the argument cate as part of a Parameter leads to a sql injection...
Auteur: VulDB

Waimai Super CMS 20150505 admin.php username/password cross site scripting

A vulnerability was found in Waimai Super CMS 20150505 (Content Management System) and classified as problematic. This issue affects a part of the file admin.php?m=Member&a=adminaddsave. The manipulation of the argument username/password as part...
Auteur: VulDB

CSZ CMS 1.1.8 admin/users/new/add cross site request forgery

A vulnerability has been found in CSZ CMS 1.1.8 (Content Management System) and classified as critical. This vulnerability affects a functionality of the file admin/users/new/add. The manipulation with an unknown input leads to a cross site...
Auteur: VulDB

Boolector 3.0.0 parser/btorsmt2.c get_failed_assumptions/btor_delete memory corruption

A vulnerability, which was classified as critical, was found in Boolector 3.0.0 (Network Encryption Software). This affects the function get_failed_assumptions/btor_delete of the file parser/btorsmt2.c. The manipulation with an unknown input...
Auteur: VulDB

Boolector Btor2Tools prior 2019-01-15 btor2parser.c memory corruption

A vulnerability, which was classified as critical, has been found in Boolector Btor2Tools (Network Encryption Software). Affected by this issue is some functionality of the file btor2parser/btor2parser.c. The manipulation with an unknown input...
Auteur: VulDB

Gurock TestRail 5.3.0.3603 Backend index.php Request information disclosure

A vulnerability classified as problematic was found in Gurock TestRail 5.3.0.3603. Affected by this vulnerability is the functionality of the file index.php of the component Backend. The manipulation as part of a Request leads to a information...
Auteur: VulDB

Websense Forcepoint User ID up to 1.2 Service Port 5001 Remote Code Execution

A vulnerability was found in Websense Forcepoint User ID up to 1.2. It has been declared as critical. This vulnerability affects a code block of the component Service Port 5001. The manipulation with an unknown input leads to a privilege...
Auteur: VulDB

IBM API Connect up to V2018.4.1.1 Access Token Log information disclosure

A vulnerability was found in IBM API Connect up to V2018.4.1.1. It has been classified as problematic. This affects code of the component Access Token Handler. The manipulation with an unknown input leads to a information disclosure...
Auteur: VulDB

Dell EMC VNX2 OE for File prior 8.1.9.236 VNX Control Station OS Command Injection privilege escalation

A vulnerability was found in Dell EMC VNX2 OE for File and classified as critical. Affected by this issue is a part of the component VNX Control Station. The manipulation with an unknown input leads to a privilege escalation vulnerability (OS...
Auteur: VulDB

Cisco Webex Business Suite up to 3.0.8 spoofing [CVE-2019-1680]

A vulnerability has been found in Cisco Webex Business Suite up to 3.0.8 (Unified Communication Software) and classified as critical. Affected by this vulnerability is a functionality. The manipulation with an unknown input leads to a spoofing...
Auteur: VulDB

Cisco TelePresence Conductor up to XC4.3.3 Web Interface Server-Side Request Forgery

A vulnerability, which was classified as critical, was found in Cisco TelePresence Conductor, Expressway Series and TelePresence Video Communication Server up to XC4.3.3 (Unified Communication Software). Affected is a function of the component...
Auteur: VulDB

Cisco Meeting Server up to 2.4.2 Session Initiation Protocol denial of service

A vulnerability, which was classified as problematic, has been found in Cisco Meeting Server up to 2.4.2. This issue affects some functionality of the component Session Initiation Protocol. The manipulation with an unknown input leads to a...
Auteur: VulDB

Cisco WebEx Meetings Application prior 11.7.0.236 on Android cross site scripting

A vulnerability classified as problematic was found in Cisco WebEx Meetings Application on Android (Unified Communication Software). This vulnerability affects the functionality. The manipulation with an unknown input leads to a cross site...
Auteur: VulDB

Cisco Aironet Active Sensor prior DNAC1.2.8 Default Configuration Restart denial of service

A vulnerability classified as problematic has been found in Cisco Aironet Active Sensor (Wireless LAN Software). This affects an unknown function of the component Default Configuration. The manipulation with an unknown input leads to a denial of...
Auteur: VulDB

Cisco FirePOWER Management Center Web-based Management Interface cross site scripting

A vulnerability was found in Cisco FirePOWER Management Center (Firewall Software). It has been rated as problematic. Affected by this issue is some processing of the component Web-based Management Interface. The manipulation with an unknown...
Auteur: VulDB
First271272273274275276277278279280Last

Événements SSI

BLACK HAT

Événement majeur mondial sur la sécurité de l'information la conférence Black Hat USA a lieu du 3 au 8 août 2019 à Las Vegas (Mandalay Bay). Organisé par UBM.


Présentation par l'organisateur

Now in its 22nd year, Black Hat USA is the world's leading information security event, providing attendees with the very latest in research, development and trends. Black Hat USA 2019 opens with four days of technical Trainings (August 3-6) followed by the two-day main conference (August 7-8) featuring Briefings, Arsenal, Business Hall, and more.

 Plus d'infos sur le site dédié à l'événement.

LES ASSISES

Grand rendez-vous annuel des RSSI, les Assises de la sécurité des systèmes d'information se tiennent à Monaco (Grimaldi Forum) du 9 au 12 octobre 2019. Organisées par DG Consultants.

Présentation par l'organisateur



Retour sur Les Assises 2018

La 18ème édition des Assises de la Sécurité à Monaco, c’est terminé ! Encore merci aux 2800 participants dont les 160 partenaires qui pendant trois jours se sont retrouvés pour faire vivre cet événement unique en France. Conférences, one-to-one, tables-rondes, ateliers, moments de networking… Par leur contenu, par la qualité des visiteurs et par la richesse des échanges, les Assises se positionnent plus que jamais comme le rendez-vous incontournable de tous les professionnels de la cybersécurité. A l’image du marché qui ne cesse d’évoluer, les Assises savent adapter leur offre afin de répondre au mieux aux attentes du secteur. Ainsi cette édition a-t-elle voulu mettre en avant les grands enjeux du moment en multipliant les prises de parole, les démonstrations et les retours d’expérience.

Rendez-vous maintenant pour la prochaine édition qui aura lieu du 9 au 12 octobre 2019

Plus d'informations sur le site dédié à l'événement.

RSS