Advertisement
Top

Tag: bug


Application security, Security

Browser data leakage bug – Mozilla to delete info just in case

January 2, 2018

Via: Naked Security

Mozilla published an unexpected security patch this week, bumping Firefox up to version 57.0.3. (You probably weren’t expecting a browser update between Christmas and New Year, but it’s good to know that security fixes don’t take second place in holiday season.) […]


Vulnerabilities

Mozilla Patches Critical Bug in Thunderbird

December 27, 2017

Via: Threat Post

Mozilla issued a critical security update to its popular open-source Thunderbird email client. The patch was part of a December release of five fixes that included two bugs rated high and one rated moderate and another low. Mozilla said Thunderbird, […]


Vulnerabilities

Critical Apple Login Bug Puts macOS High Sierra Systems at Risk

November 29, 2017

Via: Threat Post

A major bug in Apple’s macOS gives anyone with physical access to a computer running the latest version of the High Sierra operating system admin access simply by putting “root” in the user name field. The bug was publicized Tuesday […]


Network security

Samsung’s Mobile Device Bug Bounty Program Gets a Boost

November 29, 2017

Via: Dark Reading

Samsung Electronics partners with Bugcrowd to deliver timely payments for its Mobile Security Rewards Program. Samsung Electronics is giving its newly minted two-month-old bug bounty program a boost by bringing in Bugcrowd to handle the payment processing, the companies announced […]


Vulnerabilities

Intel Patches CPU Bugs Impacting Millions of PCs, Servers

November 22, 2017

Via: Threat Post

Intel released patches on Monday to protect millions of PCs and servers from vulnerabilities found in its Management Engine, Trusted Execution Engine and Server Platform Services that could allow local attackers elevate privileges, run arbitrary code, crash systems and eavesdrop […]


Cloud security, Vulnerabilities

WordPress Delivers Second Patch For SQL Injection Bug

November 2, 2017

Via: Threat Post

A bug exploitable in WordPress 4.8.2 and earlier creates unexpected and unsafe conditions ripe for a SQL injection attack, exposing sites created on the content management system to takeover. WordPress released WordPress 4.8.3 Tuesday, which mitigates the vulnerability. “This is […]


Cloud security

Oracle Patches 250 Bugs in Quarterly Critical Patch Update

October 18, 2017

Via: Threat Post

Oracle patched 250 vulnerabilities across hundreds of different products as part of its quarterly Critical Patch Update released today. Rounding out the list of products with the most patches is Oracle Fusion Middleware with 38, Oracle Hospitality Applications with 37 […]


Vulnerabilities

Siemens Fixes Session Hijacking Bug in LOGO!, Warns of Man-in-the-Middle Attacks

August 31, 2017

Via: Threat Post

Administrators who have Siemens’ LOGO! logic module deployed in automation setups are being urged to update its firmware. The German industrial manufacturing giant pushed out an update for its LOGO! 8 BM devices Wednesday morning to fix a vulnerability (CVE-2017-12734) […]


Cloud security

Incident report on Cloudflare parser bug

February 28, 2017

Via: The Hacker News

Cloudflare reported last night a bug in their service which could have leaked information from the services using their edge cache servers. Feedly uses Cloudflare as a security shield which increases the reliability and performance of the Feedly web application. As […]


Vulnerabilities

Chrome bug triggered errors on websites using Symantec SSL certificates

December 6, 2016

Via: CSO Online

If you’ve encountered errors over the past month when trying to access HTTPS-enabled websites on your computer or Android phone, it might have been due to a bug in Chrome. The bug affected the validation for some SSL certificates issued […]


Access control, Mobile security

iPhone autodial bug parties like it’s 2008

November 14, 2016

Via: Naked Security

Eight years ago, security researcher Colin Mulliner found and reported an intriguing bug to Apple. Even though the bug was in Safari on iOS, the vulnerability involved unwanted telephone calls, thanks to a special sort of web link using URLs […]


Application security, Mobile security

Intel Crosswalk bug invalidates SSL protection

August 2, 2016

Via: Help Net Security

A bug in the Intel Crosswalk Project library for cross-platform mobile development can open users to man-in-the-middle attacks, researchers from Nightwatch Cybersecurity have found. “The Crosswalk Project, created by Intel’s Open Source Technology Center, allows mobile developers to use HTML, […]


Vulnerabilities

Critical bug in libotr could open users of ChatSecure, Adium, Pidgin to compromise

March 11, 2016

Via: Help Net Security

A vulnerability in “libotr,” the C code implementation of the Off-the-Record (OTR) protocol that is used in many secure instant messengers such as ChatSecure, Pidgin, Adium and Kopete, could be exploited by attackers to crash an app using libotr or […]


Application security

Twitter Patches Bug Exposing Details of 10,000 Users

February 23, 2016

Via: InfoSecurity Live

Twitter has addressed a privacy bug that exposed email addresses and phone numbers associated with roughly 10,000 user accounts. According to the social media company, the flaw affected its password recovery system for approximately 24 hours last week. Users whose […]


Application security

Twitter password recovery bug exposes 10,000 users’ personal information

February 19, 2016

Via: CSO Online

Twitter has notified 10,000 users that their email addresses and phone numbers may have been exposed due to a bug in the website’s password recovery feature. The incident happened over the course of 24 hours on an unspecified day last […]


Vulnerabilities

Use Linux? Stop what you’re doing and apply this patch

February 17, 2016

Via: CSO Online

A buffer-overflow vulnerability uncovered Tuesday in the GNU C Library poses a serious threat to countless Linux users. Dating back to the release of glibc 2.9 in 2008, CVE-2015-7547 is a stack-based buffer overflow bug in the glibc DNS client-side […]


Mobile security

LG patches data theft bug affecting millions of Android phones

January 29, 2016

Via: CIO

LG has patched a security flaw in an application preinstalled on millions of its Android G3 smartphones that researchers found could be used to steal a variety of data. The application, called Smart Notice, is a kind of multi-functional widget, […]


Vulnerabilities

Adobe Flash Bug Discovery Leads To New Attack Mitigation Method

November 11, 2015

Via: Dark Reading

Prototype aims to prevent exploits that employ ‘use after free’ bugs in Windows, Linux, OS X software. Another day, another Adobe Flash vulnerability: but this time, the researchers who found the bug are also building an attack-mitigation method that would […]


Mobile security

More than a billion Android devices vulnerable to new Stagefright bugs

October 1, 2015

Via: mobile-security

More than a billion mobile #devices are affected by a set of two new critical vulnerabilities in #android‘s #stagefright code that can be exploited by an attacker to take complete control of a device, and as of Thursday patches are […]


Network security

Firefox 42 beta launches with Tracking Protection in Private Browsing

September 28, 2015

Via: network-security

Hot on the heels of #firefox 41 – which saw the end of a 14-year-old #bug that sucked up memory for #adblock plus users – #mozilla announced a new beta of the popular web browser. Firefox 42 beta for Windows, […]