This Microsoft advisory notification includes advisories released or updated on August 15, 2018.
e1891489b4be96b57239849387f7e211ffa391cfb65751b826050c7496f89e11
This Microsoft bulletin summary holds CVE updates for CVE-2018-8202 and CVE-2018-8284.
be07de48f5737ecf4d07145dbf109296adb486ea3c1adb50f1a7aaaf02de9243
Red Hat Security Advisory 2018-2439-01 - MariaDB is a multi-user, multi-threaded SQL database server that is binary compatible with MySQL. Issues addressed include a silly amount of unspecified vulnerabilities.
00a0671d1d65d2911e8f22b332fc5a477655aa5fcbe5f132cee38f207705b81e
Red Hat Security Advisory 2018-2462-01 - Kernel-based Virtual Machine is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM. Issues addressed include a buffer overflow vulnerability.
d888f6c463bf4ebb8752fc93231cfe8f9188d40f7b96eb4a62e34c7bc02c8685
Red Hat Security Advisory 2018-2470-01 - Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache HTTP Server, the Apache Tomcat Servlet container, Apache Tomcat Connector, JBoss HTTP Connector, Hibernate, and the Tomcat Native library. This release of Red Hat JBoss Web Server 3.1 Service Pack 4 serves as a replacement for Red Hat JBoss Web Server 3.1, and includes bug fixes. Issues addressed include insecure defaults.
7c59532733c38f637d3997844cec73a4dbac335476a98bc66adf427a840b3d53
Central Management Software version 1.4.13 suffers from a denial of service vulnerability.
51bd8b9a36bafc19f5dc04da553197a42e653a850c46f7795290ce38561afeb4
ObserverIP Scan Tool version 1.4.0.1 denial of service proof of concept exploit.
e92c93798e179fda9b6fa435c89feee7b28dae4654b13829a9fcf94e8c35ef79
Pimcore versions 5.2.3 and below suffer from cross site request forgery, cross site scripting, and remote SQL injection vulnerabilities.
aba5d313c5fdfdbdc045ef60b644c928c5b431384880c30e65d8e7dc0393c95b
Red Hat Security Advisory 2018-2402-01 - The RHV-M Virtual Appliance automates the process of installing and configuring the Red Hat Virtualization Manager. The appliance is available to download as an OVA file from the Customer Portal. Issues addressed include a denial of service vulnerability.
255c58742e78f56152ffc709f8738c8457c04a31f66a87e2cc5738d46dea2b1a
Red Hat Security Advisory 2018-2435-01 - The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update upgrades Flash Player to version 30.0.0.154. Issues addressed include bypass and information leakage vulnerabilities.
5044b27ae451f9eae8e03ba312ca011d5ea7e5194a9ee06105a086f80ca1c509
Ubuntu Security Notice 3733-2 - USN-3733-1 fixed a vulnerability in GnuPG. This update provides the corresponding update for Ubuntu 12.04 ESM. Daniel J. Bernstein, Joachim Breitner, Daniel Genkin, Leon Groot Bruinderink, Nadia Heninger, Tanja Lange, Christine van Vredendaal, and Yuval Yarom discovered that GnuPG is vulnerable to a cache side- channel attack. A local attacker could use this attack to recover RSA private keys. Various other issues were also addressed.
817cfd19cf50cae7760c3417576d5726f44022f1b1c841a3e0a3e23a7fad11f8
WebkitGTK+ version 2.20.3 ImageBufferCairo::getImageData() buffer overflow proof of concept exploit.
c669f849911cb422bc27df76dde3df3109a5a561cedf811ec2f14604a0af2198
WordPress Export Users to CSV plugin version 1.1.1 suffers from a CSV injection vulnerability.
b300b31e2bd3c5ffcd8e03ac88eda85de9048362ed027cc29e08a93f254916ef
OpenEMR version 5.0.1.3 suffers from arbitrary file read, write, and delete vulnerabilities.
e3013113e1a75a23ff07ff104eebc4f7e15d6667699b3fcf0f7297c2ed4ea905
OpenSSH versions 2.3 up to 7.4 suffer from a username enumeration vulnerability.
5b89ae3c3cfc697123f753a66e100e36a1f19ae7a11ab2e0b7081e0e195522af
Easy RM to MP3 Converter version 2.6 stack buffer overflow exploit for Windows 7.
640e5c118d2687486902b39cdb4593aae91058ec637ac09ae2efb1cd2c648ddf