Linux kernel vulnerability CVE-2019-12456 Security Advisory Security Advisory Description ** DISPUTED ** An issue was discovered in the MPT3COMMAND case in _ctl_ioctl_main in drivers/scsi/mpt3sas/ ...
More info:
https://support.f5.com/csp/article/K84310302
http://feedproxy.google.com/~r/sucuri/blog/~3/C0lXQcD0tyc/zero-day-rce-in-vbulletin-v5-0-0-v5-5-4.html A new remote code execution (RCE) zero-day vulnerability has been disclosed by an anonymous researcher on the Full Disclosure mailing list this past Monday. This vulnerability is extremely severe. It allows any website visitors to run PHP code and shell commands on the site’s underlying server. Am I At Risk? At the time of writing […]
More info:
http://feedproxy.google.com/~r/sucuri/blog/~3/C0lXQcD0tyc/zero-day-rce-in-vbulletin-v5-0-0-v5-5-4.html
Several vulnerabilities have been discovered in the Linux kernel thatmay lead to a privilege escalation, denial of service or informationleaks.
More info:
https://www.debian.org/security/2019/dsa-4531
Apache Traffic Control vulnerability CVE-2019-12405 Security Advisory Security Advisory Description Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP ...
More info:
https://support.f5.com/csp/article/K84141859
https://ithemes.com/wordpress-security-infographics/Love infographics? We do, too! From WordPress security basics to how to secure your website, we have 8 WordPress security infographics for you to download and share. 1. Five Ways to Secure Your WordPress Website It feels like every week there’s another security breach in the news. It can cause panic, especially when we think […]
More info:
https://ithemes.com/wordpress-security-infographics/
Linux kernel vulnerability CVE-2011-5327 Security Advisory Security Advisory Description In the Linux kernel before 3.1, an off by one in the drivers/target/loopback/tcm_loop.c tcm_loop_make_naa_ ...
More info:
https://support.f5.com/csp/article/K42315210
It was discovered that SPIP, a website engine for publishing, wouldallow unauthenticated users to modify published content and write tothe database, perform cross-site request forgeries, and enumerateregistered users.
More info:
https://www.debian.org/security/2019/dsa-4532
Samba vulnerability CVE-2019-10197 Security Advisory Security Advisory Description A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3 ...
More info:
https://support.f5.com/csp/article/K69511801
Linux kernel vulnerability CVE-2017-18509 Security Advisory Security Advisory Description An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket ...
More info:
https://support.f5.com/csp/article/K41582535
https://www.wordfence.com/blog/2019/09/podcast-episode-46-zero-day-vulnerability-in-rich-reviews-plugin-exploited-in-the-wild/ We chat with Mikey Veenstra to talk about the Wordfence Threat Intelligence team’s work tracking a series of active attacks on an unpatched vulnerability in the Rich Reviews plugin for WordPress. With an estimated 16,000 installations, attackers are targeting unauthenticated plugin option updates, which can be used to deliver stored cross-site scripting (XSS)
More info:
https://www.wordfence.com/blog/2019/09/podcast-episode-46-zero-day-vulnerability-in-rich-reviews-plugin-exploited-in-the-wild/