Full Disclosure: by author

36 messages starting Feb 27 20 and ending Feb 14 20
Date index | Thread index | Author index


aaron bishop

CVE-2020-5497 - MITREid Connect XSS aaron bishop (Feb 27)

Egidio Romano

[KIS-2020-05] SuiteCRM <= 7.11.10 Multiple SQL Injection Vulnerabilities Egidio Romano (Feb 12)
[KIS-2020-02] SuiteCRM <= 7.11.11 Multiple Phar Deserialization Vulnerabilities Egidio Romano (Feb 12)
[KIS-2020-01] SuiteCRM <= 7.11.11 Second-Order PHP Object Injection Vulnerabilities Egidio Romano (Feb 12)
[KIS-2020-04] SuiteCRM <= 7.11.11 (add_to_prospect_list) Broken Access Control Vulnerability Egidio Romano (Feb 12)
[KIS-2020-03] SuiteCRM <= 7.11.11 (action_saveHTMLField) Bean Manipulation Vulnerability Egidio Romano (Feb 12)

Harry Sintonen via Fulldisclosure

D-Link DGS-1250 header injection vulnerability Harry Sintonen via Fulldisclosure (Feb 20)

hyp3rlinx

CVE-2019-18915 HP System Event Utility / Privilege Escalation Vulnerability hyp3rlinx (Feb 14)

Imre Rad

CVE-2020-0728: Windows Modules Installer Service Information Disclosure Vulnerability Imre Rad (Feb 18)

Jonathan Brossard

Hostapd fails at seeding PRNGS, leading to insufficient entropy (CVE-2016-10743 and CVE-2019-10064) Jonathan Brossard (Feb 27)

Ken Williams via Fulldisclosure

CA20200205-01: Security Notice for CA Unified Infrastructure Management Ken Williams via Fulldisclosure (Feb 14)

Marcin Kozlowski

Re: [FD] Critical Bluetooth Vulnerability in Android (CVE-2020-0022) – BlueFrag Marcin Kozlowski (Feb 14)
Critical Bluetooth Vulnerability in Android (CVE-2020-0022) – BlueFrag Marcin Kozlowski (Feb 11)

omarbv

RootedCON 2020 - Registration, Trainings, Speakers and Hacker Night omarbv (Feb 14)

Open-Xchange GmbH via Fulldisclosure

Open-Xchange Security Advisory 2020-02-19 Open-Xchange GmbH via Fulldisclosure (Feb 20)

psy

New Release: UFONet v1.4 - "T|M3WaRS!"... psy (Feb 07)

Qualys Security Advisory

Local information disclosure in OpenSMTPD (CVE-2020-8793) Qualys Security Advisory (Feb 27)
LPE and RCE in OpenSMTPD's default install (CVE-2020-8794) Qualys Security Advisory (Feb 27)

raki ben hamouda

Comtrend VR-3033 Multiple Command Injection vulnerability raki ben hamouda (Feb 27)

redazione

xglance-bin exploit (CVE-2014-2630) redazione (Feb 07)

Red Team

Multiple vulnerabilities in SmartClient_v12 Red Team (Feb 18)

Red Timmy Security

[SerialTweaker] Interactive modification of Java Serialized Objects Red Timmy Security (Feb 27)

RedTimmy Security

[EnumJavaLibs]_ Remote Java classpath enumerator RedTimmy Security (Feb 14)
Web Application Firewall bypass via Bluecoat device RedTimmy Security (Feb 18)

SEC Consult Vulnerability Lab

SEC Consult SA-20200225-0 :: Multiple Cross-site Scripting (XSS) Vulnerabilities in PHP-Fusion CMS SEC Consult Vulnerability Lab (Feb 25)

Stefan Kanthak

Defense in depth -- the Microsoft way (part 62): Windows shipped with end-of-life components Stefan Kanthak (Feb 27)

Thierry Zoller

[TZO-19-2020] - AVIRA Generic AV Bypass (ISO Container) - CVE-2020-9320 Thierry Zoller (Feb 27)
[TZO-15-2020] - F-SECURE Generic Malformed Container bypass (RAR) Thierry Zoller (Feb 14)
[TZO-17-2020] - Kaspersky Generic Archive Bypass (ZIP FLNMLEN) Thierry Zoller (Feb 18)
Re: [TZO-03-2020] ESET Generic Malformed Archive Bypass (ZIP Compression Information) Thierry Zoller (Feb 18)
[TZO-22-2020] Qihoo360 | GDATA | Rising | Command Generic Malformed Archive Bypass Thierry Zoller (Feb 27)
[TZO-18-2020] - Bitdefender Malformed Archive bypass (GZIP) Thierry Zoller (Feb 18)
[TZO-16-2020] - F-SECURE Generic Malformed Container bypass (GZIP) Thierry Zoller (Feb 27)
[TZO-23-2020] - AVAST Generic Archive Bypass (ZIP) Thierry Zoller (Feb 27)
[TZO-13-2020] - AVIRA Generic AV Bypass (ZIP GPFLAG) Thierry Zoller (Feb 14)
[TZO-11-2020] - ESET Generic Malformed Archive Bypass (BZ2 Checksum) Thierry Zoller (Feb 14)