Full Disclosure: by date

36 messages starting Feb 07 20 and ending Feb 27 20
Date index | Thread index | Author index


Friday, 07 February

New Release: UFONet v1.4 - "T|M3WaRS!"... psy
xglance-bin exploit (CVE-2014-2630) redazione

Tuesday, 11 February

Critical Bluetooth Vulnerability in Android (CVE-2020-0022) – BlueFrag Marcin Kozlowski

Wednesday, 12 February

[KIS-2020-01] SuiteCRM <= 7.11.11 Second-Order PHP Object Injection Vulnerabilities Egidio Romano
[KIS-2020-02] SuiteCRM <= 7.11.11 Multiple Phar Deserialization Vulnerabilities Egidio Romano
[KIS-2020-03] SuiteCRM <= 7.11.11 (action_saveHTMLField) Bean Manipulation Vulnerability Egidio Romano
[KIS-2020-04] SuiteCRM <= 7.11.11 (add_to_prospect_list) Broken Access Control Vulnerability Egidio Romano
[KIS-2020-05] SuiteCRM <= 7.11.10 Multiple SQL Injection Vulnerabilities Egidio Romano

Friday, 14 February

CVE-2019-18915 HP System Event Utility / Privilege Escalation Vulnerability hyp3rlinx
CA20200205-01: Security Notice for CA Unified Infrastructure Management Ken Williams via Fulldisclosure
Re: [FD] Critical Bluetooth Vulnerability in Android (CVE-2020-0022) – BlueFrag Marcin Kozlowski
RootedCON 2020 - Registration, Trainings, Speakers and Hacker Night omarbv
[EnumJavaLibs]_ Remote Java classpath enumerator RedTimmy Security
[TZO-11-2020] - ESET Generic Malformed Archive Bypass (BZ2 Checksum) Thierry Zoller
[TZO-13-2020] - AVIRA Generic AV Bypass (ZIP GPFLAG) Thierry Zoller
[TZO-15-2020] - F-SECURE Generic Malformed Container bypass (RAR) Thierry Zoller

Tuesday, 18 February

CVE-2020-0728: Windows Modules Installer Service Information Disclosure Vulnerability Imre Rad
Web Application Firewall bypass via Bluecoat device RedTimmy Security
Multiple vulnerabilities in SmartClient_v12 Red Team
[TZO-17-2020] - Kaspersky Generic Archive Bypass (ZIP FLNMLEN) Thierry Zoller
[TZO-18-2020] - Bitdefender Malformed Archive bypass (GZIP) Thierry Zoller
Re: [TZO-03-2020] ESET Generic Malformed Archive Bypass (ZIP Compression Information) Thierry Zoller

Thursday, 20 February

D-Link DGS-1250 header injection vulnerability Harry Sintonen via Fulldisclosure
Open-Xchange Security Advisory 2020-02-19 Open-Xchange GmbH via Fulldisclosure

Tuesday, 25 February

SEC Consult SA-20200225-0 :: Multiple Cross-site Scripting (XSS) Vulnerabilities in PHP-Fusion CMS SEC Consult Vulnerability Lab

Thursday, 27 February

CVE-2020-5497 - MITREid Connect XSS aaron bishop
Hostapd fails at seeding PRNGS, leading to insufficient entropy (CVE-2016-10743 and CVE-2019-10064) Jonathan Brossard
[SerialTweaker] Interactive modification of Java Serialized Objects Red Timmy Security
Local information disclosure in OpenSMTPD (CVE-2020-8793) Qualys Security Advisory
LPE and RCE in OpenSMTPD's default install (CVE-2020-8794) Qualys Security Advisory
Comtrend VR-3033 Multiple Command Injection vulnerability raki ben hamouda
Defense in depth -- the Microsoft way (part 62): Windows shipped with end-of-life components Stefan Kanthak
[TZO-19-2020] - AVIRA Generic AV Bypass (ISO Container) - CVE-2020-9320 Thierry Zoller
[TZO-16-2020] - F-SECURE Generic Malformed Container bypass (GZIP) Thierry Zoller
[TZO-22-2020] Qihoo360 | GDATA | Rising | Command Generic Malformed Archive Bypass Thierry Zoller
[TZO-23-2020] - AVAST Generic Archive Bypass (ZIP) Thierry Zoller