Security News

Bugtraq: Wireless Photo Access 1.0.10 iOS - Multiple Vulnerabilities

Security Focus Vulnerabilities - 13 May, 2013 - 12:00
Wireless Photo Access 1.0.10 iOS - Multiple Vulnerabilities

File Lite 3.3 & 3.5 PRO iOS - Multiple Web Vulnerabilities

Bug Traq - 13 May, 2013 - 11:58

Posted by Vulnerability Lab on May 13

======
File Lite 3.3 & 3.5 PRO iOS - Multiple Web Vulnerabilities

Date:
=====
2013-05-04

References:
===========
http://www.vulnerability-lab.com/get_content.php?id=939

VL-ID:
=====
939

Common Vulnerability Scoring System:
====================================
5.9

Introduction:
=============
You have tons of files you need to get from one device to another, so what do you do? You use File Pro, that’s what you
do.
App Chronicles!...

SimpleTransfer 2.2.1 - Command Injection Vulnerabilities

Bug Traq - 13 May, 2013 - 11:46

Posted by Vulnerability Lab on May 13

Title:
======
SimpleTransfer 2.2.1 - Command Injection Vulnerabilities

Date:
=====
2013-05-03

References:
===========
http://www.vulnerability-lab.com/get_content.php?id=937

VL-ID:
=====
937

Common Vulnerability Scoring System:
====================================
5.6

Introduction:
=============
Simple Transfer is the easiest way of transferring your Photos and Videos to computer and other iOS devices via WiFi.
No need for cable, iTunes or...

Wireless Photo Access 1.0.10 iOS - Multiple Vulnerabilities

Bug Traq - 13 May, 2013 - 11:33

Posted by Vulnerability Lab on May 13

Title:
======
Wireless Photo Access 1.0.10 iOS - Multiple Vulnerabilities

Date:
=====
2013-04-27

References:
===========
http://www.vulnerability-lab.com/get_content.php?id=934

VL-ID:
=====
934

Common Vulnerability Scoring System:
====================================
5.6

Introduction:
=============
Is it too difficult to get your photos and videos in original quality from your iPhone or iPad? Simply access them
from any nearby computer or...

Wifi Album v1.47 iOS - Command Injection Vulnerability

Bug Traq - 13 May, 2013 - 11:19

Posted by Vulnerability Lab on May 13

Title:
======
Wifi Album v1.47 iOS - Command Injection Vulnerability

Date:
=====
2013-04-25

References:
===========
http://www.vulnerability-lab.com/get_content.php?id=935

VL-ID:
=====
935

Common Vulnerability Scoring System:
====================================
5.6

Introduction:
=============
WiFi Album allows you to easily transfer photos and videos between iPhone,iPad,iTouch,iMac and PC. Transfer photos and
videos
over WiFi, no cables...

Wifi Photo Transfer 2.1 & 1.1 PRO - Multiple Vulnerabilities

Bug Traq - 13 May, 2013 - 11:05

Posted by Vulnerability Lab on May 13

Title:
======
Wifi Photo Transfer 2.1 & 1.1 PRO - Multiple Vulnerabilities

Date:
=====
2013-04-21

References:
===========
http://www.vulnerability-lab.com/get_content.php?id=932

VL-ID:
=====
932

Common Vulnerability Scoring System:
====================================
6.1

Introduction:
=============
Easily access your photo libraries via wifi from any computer with a web browser! Just start the app and enter the
displayed address into...

Bugtraq: [SECURITY] [DSA 2667-1] mysql-5.5 security update

Security Focus Vulnerabilities - 13 May, 2013 - 11:00
[SECURITY] [DSA 2667-1] mysql-5.5 security update

Bugtraq: [SECURITY] [DSA 2666-1] xen security update

Security Focus Vulnerabilities - 13 May, 2013 - 11:00
[SECURITY] [DSA 2666-1] xen security update

Wireless Disk PRO v2.3 iOS - Multiple Web Vulnerabilities

Bug Traq - 13 May, 2013 - 10:52

Posted by Vulnerability Lab on May 13

Title:
======
Wireless Disk PRO v2.3 iOS - Multiple Web Vulnerabilities

Date:
=====
2013-02-26

References:
===========
http://www.vulnerability-lab.com/get_content.php?id=883

VL-ID:
=====
883

Common Vulnerability Scoring System:
====================================
6.2

Introduction:
=============
AirDisk Pro allows you to store, view and manage files on your iPhone, iPad or iPod touch. You can connect to AirDisk
Pro from any Mac or
PC over...

[RT-SA-2013-001] Advisory: Exim with Dovecot: Typical Misconfiguration Leads to Remote Command Execution

Bug Traq - 13 May, 2013 - 10:38

Posted by RedTeam Pentesting GmbH on May 13

Advisory: Exim with Dovecot: Typical Misconfiguration Leads to Remote
Command Execution

During a penetration test a typical misconfiguration was found in the
way Dovecot is used as a local delivery agent by Exim. A common use
case for the Dovecot IMAP and POP3 server is the use of Dovecot as a
local delivery agent for Exim. The Dovecot documentation contains an example
using a dangerous configuration option for Exim, which leads to a...

[ MDVSA-2013:164 ] mesa

Bug Traq - 13 May, 2013 - 10:22

Posted by security on May 13

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2013:164
http://www.mandriva.com/en/support/security/
_______________________________________________________________________

Package : mesa
Date : May 13, 2013
Affected: Business Server 1.0
_______________________________________________________________________

Problem Description:

Updated mesa...

[SECURITY] [DSA 2667-1] mysql-5.5 security update

Bug Traq - 13 May, 2013 - 10:05

Posted by Moritz Muehlenhoff on May 13

-------------------------------------------------------------------------
Debian Security Advisory DSA-2667-1 security () debian org
http://www.debian.org/security/ Moritz Muehlenhoff
May 12, 2013 http://www.debian.org/security/faq
-------------------------------------------------------------------------

Package : mysql-5.5
Vulnerability : several
Problem type : remote...

[SECURITY] [DSA 2666-1] xen security update

Bug Traq - 13 May, 2013 - 09:53

Posted by Salvatore Bonaccorso on May 13

-------------------------------------------------------------------------
Debian Security Advisory DSA-2666-1 security () debian org
http://www.debian.org/security/ Salvatore Bonaccorso
May 12, 2013 http://www.debian.org/security/faq
-------------------------------------------------------------------------

Package : xen
Vulnerability : several
Problem type : remote...

[ MDVSA-2013:164 ] mesa

Full Disclosure - 13 May, 2013 - 09:40

Posted by security on May 13

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2013:164
http://www.mandriva.com/en/support/security/
_______________________________________________________________________

Package : mesa
Date : May 13, 2013
Affected: Business Server 1.0
_______________________________________________________________________

Problem Description:

Updated mesa...

WASC Announcement: Static Analysis Technologies Evaluation Criteria Published

Bug Traq - 13 May, 2013 - 09:35

Posted by announcements on May 13

The Web Application Security Consortium (WASC) is pleased to announce the
Static Analysis Technologies Evaluation Criteria. The goal of the SATEC
project is to create a vendor-neutral set of criteria to help guide
application security professionals during the process of acquiring a
static code analysis technology that is intended to be used during
source-code driven security programs. This document provides a
comprehensive list of criteria that...

Bugtraq: ESA-2013-031: RSA® Authentication Agent Cross-Site Scripting (XSS) Vulnerability

Security Focus Vulnerabilities - 13 May, 2013 - 09:15
ESA-2013-031: RSA® Authentication Agent Cross-Site Scripting (XSS) Vulnerability

Bugtraq: [SECURITY] CVE-2012-3544 Chunked transfer encoding extension size is not limited

Security Focus Vulnerabilities - 13 May, 2013 - 09:15
[SECURITY] CVE-2012-3544 Chunked transfer encoding extension size is not limited

Bugtraq: [SECURITY] CVE-2013-2067 Session fixation with FORM authenticator

Security Focus Vulnerabilities - 13 May, 2013 - 09:15
[SECURITY] CVE-2013-2067 Session fixation with FORM authenticator

Bugtraq: CVE-2013-2071 Request mix-up if AsyncListener method throws RuntimeException

Security Focus Vulnerabilities - 13 May, 2013 - 09:15
CVE-2013-2071 Request mix-up if AsyncListener method throws RuntimeException

Vuln: Invision Power Board IP.Board Administrator Account Security Bypass Vulnerability

Security Focus Vulnerabilities - 12 May, 2013 - 23:00
Invision Power Board IP.Board Administrator Account Security Bypass Vulnerability
Syndicate content