Slackware Security Advisory - New mozilla-nss packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.
8f68939f6ea6bc41b5d88e5c6f9512f0b524cfbf8bf623647dc7314c29fac479
Typesetter version 5.1 suffers from a cross site scripting vulnerability.
28278b39532299c48ed1dba24aea5fd1630a62e4e9fc86a6e90f7266db4be524
Chrome V8 sets incorrect type information on Math.expm1.
b5051eaa807edf87306ff4070c05b871431b0ebddc1af133eba30594e5419590
Wireshark suffers from a heap out-of-bounds read in find_signature.
41bc98d3cbc6e5394de02b36384419b632fa175b3e95c6ff855f2a6e83b86a5c
NUUO NVRMini2 version 3.9.1 suffers from an authenticated command injection vulnerability.
0a8f59d008e5177252566cbb4b4fa52dce1b3abdc7f39ddee6cbbfc1175b0861
Dolibarr ERP / CRM version 8.0.3 suffers from a cross site scripting vulnerability.
93a597392584cf3b5e1ab2271d1890060f352e5b06b9fab46d705c70d7f46e0d
DomainMOD version 4.11.01 suffers from multiple cross site scripting vulnerabilities.
57e88a02202c06f15254438a490e8cf8d4636e6dd56ef3c4e5ee97a73a46f6f5
OpenSSH versions prior to 7.7 suffer from a user enumeration vulnerability.
4859577142cc1049d3959af66839a236a04781ada4ed91ed9ebe565b43f98029
In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts. This also grants the attacker an ability to backdoor the server. SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to exfiltrate data. These vulnerabilities affect versions prior to November 2018 release.
7df4b2e0ea39929c4fb143059747f1dc9dfd9fc95b1686beaa11991e57523e2b
Xorg X11 server on AIX local privilege escalation exploit.
fdeb1b36f96691504fb5e84f75c6cdb5cd0544822f4eee060f585ebb37ee6e2d
Seopanel version 3.13.0 suffers from multiple cross site scripting vulnerabilities.
b03935fa62fe7d64672a36bbe4a1643a799fc8f3bbd3bbe83eb9a94e6c3bc726
Rockwell Automation Allen-Bradley PowerMonitor 1000 suffers from an incorrect access control that can allow for authentication bypass.
2e61ab14354c28992b4d911cdcf2e650d1988c2982dc51fc9f3976099bb6c776
Google Allo suffers from a denial of service vulnerability.
3a200cdec9078f15d49a2370f6fdbfe05a30a0b2ea3438a29940983025506470
Microsoft Lync for Mac 2011 suffers from a forced browsing / download injection vulnerability.
c1748eb14db54b7cb8de1f8cb17cbde9c33ef7291eedf99646039fa3fee586b8
119 bytes small Linux/x64 reverse (0.0.0.0:1907/TCP) shell shellcode.
e0e74d40c3e636f312b82579e463a18531fc4a43f62d0f957640bba6a354a1eb
61 bytes small Linux/x86 /usr/bin/head -n99 cat etc/passwd shellcode.
d599a6170b8fc6c0a18d02af4dd4a98f98fcaf1d305382d56cba5cd145a3adb3