Debian Linux Security Advisory 4462-1 - Joe Vennix discovered an authentication bypass vulnerability in dbus, an asynchronous inter-process communication system. The implementation of the DBUS_COOKIE_SHA1 authentication mechanism was susceptible to a symbolic link attack. A local attacker could take advantage of this flaw to bypass authentication and connect to a DBusServer with elevated privileges.
47411081b5ba9236c68f5889f5610ac716223979531628db99760623a5d15f46
Slackware Security Advisory - New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.
b9072c20fb0032682c69575ad4bf45a9e8714f8de2a3e657d9f4d2e26acab4b9
The industrial managed switch series 852 from WAGO is affected by multiple vulnerabilities such as old software components embedded in the firmware. Furthermore, hardcoded password hashes and credentials were also found by doing an automated scan with IoT Inspector.
5c8f473ce950d3d7fc4a502cd31cbb68d69766f0ee3d50da6ac20921262a4c65
This script abuses an unauthenticated information leak in the apcupsd daemon.
fe02a8ec9b1f484fc42bf669835cd9ac2dea878f12704cd2b0a793fb56f4f139
Red Hat Security Advisory 2019-1467-01 - Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Issues addressed include an information leakage vulnerability.
6481e2c602b3983688e83997816abecdc65ae1240c842fcfa0dd8de039f4656a
Pronestor Health Monitoring versions prior to 8.1.12.0 suffer from a local privilege escalation vulnerability due to weak file permissions.
5fb108d74a47651cbd865931fade07060bf203cfadce38d2fcda5b7c3c61b908
Sitecore versions 8.x suffer from a deserialization vulnerability that allows for remote code execution.
2179f1c7a5bbe152a9845544b7783d499be690279ed565d9ba28e972c3f821d9
WebLord WL-Nuke Coppermine for PHP-Nuke version 1.3.1c suffers from a remote SQL injection vulnerability.
162d4b7164cbe6602c8f7019ca2e62a42902a68bb333f9eeb31dc073df4a498e