Full Disclosure: by author

37 messages starting May 23 24 and ending May 29 24
Date index | Thread index | Author index


Andraz Sraka

[CFP] Security BSides Ljubljana 0x7E8 | September 27, 2024 Andraz Sraka (May 23)

Andrea Intilangelo

CVE-2024-34058: Nethserver 7 & 8 stored cross-site scripting (XSS) in WebTop package Andrea Intilangelo (May 20)

Apple Product Security via Fulldisclosure

APPLE-SA-05-13-2024-2 iOS 17.5 and iPadOS 17.5 Apple Product Security via Fulldisclosure (May 14)
APPLE-SA-05-13-2024-7 watchOS 10.5 Apple Product Security via Fulldisclosure (May 14)
APPLE-SA-05-08-2024-1 iTunes 12.13.2 for Windows Apple Product Security via Fulldisclosure (May 14)
APPLE-SA-05-13-2024-1 Safari 17.5 Apple Product Security via Fulldisclosure (May 14)
APPLE-SA-05-13-2024-4 macOS Sonoma 14.5 Apple Product Security via Fulldisclosure (May 14)
APPLE-SA-05-13-2024-5 macOS Ventura 13.6.7 Apple Product Security via Fulldisclosure (May 14)
APPLE-SA-05-13-2024-8 tvOS 17.5 Apple Product Security via Fulldisclosure (May 14)
APPLE-SA-05-13-2024-6 macOS Monterey 12.7.5 Apple Product Security via Fulldisclosure (May 14)
APPLE-SA-05-13-2024-3 iOS 16.7.8 and iPadOS 16.7.8 Apple Product Security via Fulldisclosure (May 14)

Asterisk Development Team via Fulldisclosure

asterisk release 20.8.1 Asterisk Development Team via Fulldisclosure (May 20)
asterisk release 18.23.1 Asterisk Development Team via Fulldisclosure (May 20)
asterisk release 21.3.1 Asterisk Development Team via Fulldisclosure (May 20)

Egidio Romano

[KIS-2024-04] Cacti <= 1.2.26 (import.php) Remote Code Execution Vulnerability Egidio Romano (May 14)

Julia Wunder

Research about consistency of CVSSv4 Julia Wunder (May 14)

malvuln

Panel.SmokeLoader / Cross Site Request Forgery (CSRF) malvuln (May 14)
TROJANSPY.WIN64.EMOTET.A / Arbitrary Code Execution malvuln (May 14)
Panel.SmokeLoader C2 / Cross Site Scripting (XSS) malvuln (May 14)
Panel.Amadey.d.c C2 / Cross Site Scripting (XSS) malvuln (May 14)
RansomLord v3 / Anti-Ransomware Exploit Tool Released malvuln (May 14)
Re: Panel.SmokeLoader / Cross Site Request Forgery (CSRF) malvuln (May 14)
Re: RansomLord v3 / Anti-Ransomware Exploit Tool Released malvuln (May 14)
BACKDOOR.WIN32.ASYNCRAT / Arbitrary Code Execution malvuln (May 14)

Marco Ivaldi

HNS-2024-06 - HN Security Advisory - Multiple vulnerabilities in Eclipse ThreadX Marco Ivaldi (May 29)
HNS-2024-07 - HN Security Advisory - Multiple vulnerabilities in RIOT OS Marco Ivaldi (May 14)

Martin Heiland via Fulldisclosure

OXAS-ADV-2024-0002: OX App Suite Security Advisory Martin Heiland via Fulldisclosure (May 06)

PT via Fulldisclosure

Live2D Cubism refusing to fix validation issue leading to heap corruption. PT via Fulldisclosure (May 03)

SEC Consult Vulnerability Lab via Fulldisclosure

SEC Consult SA-20240522-0 :: Broken access control & API Information Exposure in 4BRO App SEC Consult Vulnerability Lab via Fulldisclosure (May 23)
SEC Consult SA-20240524-0 :: Exposed Serial Shell on multiple PLCs in Siemens CP-XXXX Series SEC Consult Vulnerability Lab via Fulldisclosure (May 27)
SEC Consult SA-20240513-0 :: Tolerating Self-Signed Certificates in SAPĀ® Cloud Connector SEC Consult Vulnerability Lab via Fulldisclosure (May 14)
SEC Consult SA-20240527-0 :: Multiple vulnerabilities in HAWKI didactic interface SEC Consult Vulnerability Lab via Fulldisclosure (May 27)

Security Explorations

Microsoft PlayReady toolkit - codes release Security Explorations (May 06)
Microsoft PlayReady white-box cryptography weakness Security Explorations (May 01)
Microsoft PlayReady - complete client identity compromise Security Explorations (May 09)

Simon Bieber via Fulldisclosure

secuvera-SA-2024-02: Multiple Persistent Cross-Site Scritping (XSS) flaws in Drupal-Wiki Simon Bieber via Fulldisclosure (May 06)

Thomas Weber via Fulldisclosure

CyberDanube Security Research 20240528-0 | Multiple Vulnerabilities in ORing IAP-420 Thomas Weber via Fulldisclosure (May 29)