The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.
History of vulnerabilities analyzed by Vigil@nce:

computer vulnerability CVE-2018-10139

PAN-OS: Cross Site Scripting via GlobalProtect Response Page

Synthesis of the vulnerability

An attacker can trigger a Cross Site Scripting via GlobalProtect Response Page of PAN-OS, in order to run JavaScript code in the context of the web site.
Impacted products: Palo Alto Firewall PA***, PAN-OS.
Severity: 2/4.
Creation date: 16/08/2018.
Identifiers: CVE-2018-10139, PAN-84836, PAN-SA-2018-0009, VIGILANCE-VUL-27035.

Description of the vulnerability

The PAN-OS product offers a web service. However, it does not filter received...
Complete Vigil@nce bulletin.... (Free trial)

vulnerability alert 27031

Centreon Web: SQL injection via Metrics RPN

Synthesis of the vulnerability

An attacker can use a SQL injection via Metrics RPN of Centreon Web, in order to read or alter data.
Impacted products: Centreon.
Severity: 2/4.
Creation date: 16/08/2018.
Identifiers: VIGILANCE-VUL-27031.

Description of the vulnerability

The Centreon Web product uses a database. However, user's data are directly i...
Complete Vigil@nce bulletin.... (Free trial)

computer vulnerability CVE-2018-8360

Microsoft .NET: information disclosure

Synthesis of the vulnerability

An attacker can bypass access restrictions to data of Microsoft .NET, in order to obtain sensitive information.
Impacted products: .NET Framework.
Severity: 2/4.
Creation date: 16/08/2018.
Identifiers: CERTFR-2018-AVI-398, CVE-2018-8360, VIGILANCE-VUL-26985.

Description of the vulnerability

The Microsoft .NET product offers a web service. However, an attacker can byp...
Complete Vigil@nce bulletin.... (Free trial)

computer vulnerability alert 26946

TYPO3 Frontend Treeview: Cross Site Scripting

Synthesis of the vulnerability

An attacker can trigger a Cross Site Scripting of TYPO3 Frontend Treeview, in order to run JavaScript code in the context of the web site.
Impacted products: TYPO3 Extensions ~ not comprehensive.
Severity: 2/4.
Creation date: 09/08/2018.
Identifiers: TYPO3-EXT-SA-2018-008, VIGILANCE-VUL-26946.

Description of the vulnerability

The Frontend Treeview extension can be installed on TYPO3. However, it does n...
Complete Vigil@nce bulletin.... (Free trial)

vulnerability alert 26941

TYPO3 Powermail: Cross Site Scripting

Synthesis of the vulnerability

An attacker can trigger a Cross Site Scripting of TYPO3 Powermail, in order to run JavaScript code in the context of the web site.
Impacted products: TYPO3 Extensions ~ not comprehensive.
Severity: 2/4.
Creation date: 09/08/2018.
Identifiers: TYPO3-EXT-SA-2018-004, VIGILANCE-VUL-26941.

Description of the vulnerability

The Powermail extension can be installed on TYPO3. However, it does not filte...
Complete Vigil@nce bulletin.... (Free trial)

computer vulnerability bulletin 26938

TYPO3 Heise Shariff: Cross Site Scripting

Synthesis of the vulnerability

An attacker can trigger a Cross Site Scripting of TYPO3 Heise Shariff, in order to run JavaScript code in the context of the web site.
Impacted products: TYPO3 Extensions ~ not comprehensive.
Severity: 2/4.
Creation date: 09/08/2018.
Identifiers: TYPO3-EXT-SA-2018-001, VIGILANCE-VUL-26938.

Description of the vulnerability

The Heise Shariff extension can be installed on TYPO3. However, it does not f...
Complete Vigil@nce bulletin.... (Free trial)

computer vulnerability announce 26937

Joomla J-BusinessDirectory: SQL injection

Synthesis of the vulnerability

An attacker can use a SQL injection of Joomla J-BusinessDirectory, in order to read or alter data.
Impacted products: Joomla Extensions ~ not comprehensive.
Severity: 2/4.
Creation date: 09/08/2018.
Identifiers: VIGILANCE-VUL-26937.

Description of the vulnerability

The Joomla J-BusinessDirectory product uses a database. However, user's data ...
Complete Vigil@nce bulletin.... (Free trial)

vulnerability 26910

SUSE LE: security improvement via yast2-ftp-server

Synthesis of the vulnerability

The security of SUSE LE was improved via yast2-ftp-server.
Impacted products: SLES.
Severity: 1/4.
Creation date: 06/08/2018.
Identifiers: 921303, SUSE-SU-2018:2181-1, VIGILANCE-VUL-26910.

Description of the vulnerability

This bulletin is about a security improvement. It does not describe a vulnera...
Complete Vigil@nce bulletin.... (Free trial)

computer vulnerability bulletin 26908

XStatic-jquery-ui: Cross Site Scripting

Synthesis of the vulnerability

An attacker can trigger a Cross Site Scripting of XStatic-jquery-ui, in order to run JavaScript code in the context of the web site.
Impacted products: Fedora.
Severity: 2/4.
Creation date: 06/08/2018.
Identifiers: FEDORA-2018-2d2179e7d0, FEDORA-2018-f972c1b36e, VIGILANCE-VUL-26908.

Description of the vulnerability

The XStatic-jquery-ui product offers a web service. However, it does not filt...
Complete Vigil@nce bulletin.... (Free trial)

vulnerability note 26904

Node.js url-parse: open redirect

Synthesis of the vulnerability

An attacker can deceive the user of Node.js url-parse, in order to redirect him to a malicious site.
Impacted products: Nodejs Modules ~ not comprehensive.
Severity: 1/4.
Creation date: 03/08/2018.
Identifiers: VIGILANCE-VUL-26904.

Description of the vulnerability

The url-parse module can be installed on Node.js.

However, the web service accepts to redirect the victim with no warning, to an external site indicated by the attacker.

An attacker can therefore deceive the user of Node.js url-parse, in order to redirect him to a malicious site.
Complete Vigil@nce bulletin.... (Free trial)

   Next page

Direct access to page 1 21 41 61 81 101 121 141 161 181 201 221 241 261 281 301 321 341 361 381 401 421 441 461 481 501 521 541 561 581 601 621 641 661 681 701 721 741 761 781 801 821 841 861 881 901 921 941 961 981 1001 1021 1041 1061 1081 1101 1121 1141 1161 1181 1201 1221 1241 1261 1281 1301 1321 1341 1361 1381 1401 1421 1441 1461 1481 1501 1521 1541 1561 1581 1601 1621 1641 1661 1681 1701 1721 1741 1761 1781 1801 1821 1841 1861 1881 1901 1921 1941 1961 1981 2001 2021 2031 2032 2033 2034 2035 2036 2037 2038 2039 2040 2041