TTCSIRT-162.090718: TT-CSIRT Advisory – Cisco Security Updates

TTCSIRT-160.090318: TT-CSIRT Advisory – Joomla Security Updates

Joomla has released a security update stating that the following vulnerabilities have been found in its Joomla Content Management System (CMS) – a) Inadequate checks regarding disabled fields can lead to an ACL violation – (CVE-2018-15881). b) Inadequate output filtering on the user profile page could lead to a stored XSS attack – (CVE-2018-15880). c) […]

TTCSIRT-158.081718: TT-CSIRT Advisory – Adobe Security Updates

Adobe has released a security update stating that the following issues have been discovered in Adobe Acrobat & Reader: a) One out-of-bounds vulnerability that could allow for arbitrary code execution – (CVE-2018-12808). b) One untrusted pointer deference vulnerability that could allow for arbitrary code execution – (CVE-2018-12799). Successful exploitation of these vulnerabilities could result in […]

TTCSIRT-157.081718: TT-CSIRT Advisory – Oracle Security Updates

Oracle has released a security update stating that a vulnerability has been discovered in Oracle Database Server that could allow for complete compromise of the database. The issue resides in the Oracle Database Server where low-privileged attackers that have Create Session privileges can compromise the Java Virtual Machine component and take complete control of the […]

TTCSIRT-156.081318: TT-CSIRT Advisory – NetComm Security Updates

ICS-CERT has released a security update stating that the NetComm’s Wireless 4G LTE Light Industrial M2M Router is vulnerable to: a) Information Exposure b) Cross-site Request Forgery c) Cross-site Scripting The flaws can be exploited remotely from the Internet and have been classified by ICS-CERT as “critical” while the information disclosure issues are said to […]

TTCSIRT-155.081318: TT-CSIRT Advisory – VMware Security Updates

VMware has released a security update stating that Horizon ver 6.0 – 7.0 for Windows contains an out-of-bounds read vulnerability in the Message Framework library. This issue may allow a less-privileged user to leak information from a privileged process running on a system where Horizon Connection Server, Horizon Agent or Horizon Client are installed. Further […]

TTCSIRT-154.080718: TT-CSIRT Advisory – Mozilla Security Updates

Mozilla has released a security update stating that it has found the following critical vulnerabilities within Mozilla Thunderbird ver 60.0: a) Bug #1459162 – a buffer overflow can occur when rendering canvas content while adjusting the height and width of the canvas element dynamically, causing data to be written outside of the currently computed boundaries. […]