[FD] Numerous FreeTDS crashes fixed on master

2017-05-09 Thread Brandon Perry
Attached is a zip file of reported TDS streams that cause segmentation faults in the FreeTDS library. The ‘tsql’ binary was used for the fuzzing, so these most likely only affect client-side functionality. These have been resolved on master and the 1.0 branch. Also included in the zip file is a

[FD] SEC Consult SA-20170509-0 :: Multiple vulnerabilities in I, Librarian PDF manager

2017-05-09 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory < 20170509-0 > === title: Multiple vulnerabilities product: I, Librarian PDF manager vulnerable version: <=4.6 & 4.7 fixed version: 4.8

[FD] Veritas Netbackup v8.0 - Multiple Vulnerabilities

2017-05-09 Thread Sven Blumenstein via Fulldisclosure
Veritas Netbackup 8.0 - Multiple Vulnerabilities - Introduction Multiple vulnerabilities were identified in Veritas Netbackup ( https://www.veritas.com/product/backup-and-recovery/netbackup-8). The vulnerabilities were discovered du

[FD] CSRF/Stored XSS in MSMC – Redirect After Comment could allow unauthenticated individuals to do almost anything (WordPress plugin)

2017-05-09 Thread dxw Security
Details Software: MSMC - Redirect After Comment Version: 2.1.2 Homepage: https://wordpress.org/plugins/msmc-redirect-after-comment/ Advisory report: https://security.dxw.com/advisories/csrf-stored-xss-in-msmc-redirect-after-comment/ CVE: Awaiting assignment CVSS: 5.8 (Medium; AV:N

[FD] Aleph Research: Google Nexus 9 SensorHub Firmware Downgrade Vulnerability (CVE-2017-0582)

2017-05-09 Thread Roee Hay
Title: Google Nexus 9 SensorHub Firmware Downgrade Vulnerability Identifier: CVE-2017-0582 Product: === Google Nexus 9 Vulnerable Version: Nexus 9 Android Builds before N4F27B - May 2017, i.e. before bootloader 3.50.0.0143. Mitigation: = Install N4F27

[FD] CSRF in wordpress plugin clean login allows remote attacker change wordpress login redirect url or logout redirect url to evil address

2017-05-09 Thread Zeng Wester
=== Software Description === Software:clean login version:<1.8 description:Responsive Frontend Login and Registration plugin. Details CSRF in wordpress plugin clean login allows remote attacker change wordpress login redirect url or logout redire