Full Disclosure: by date

39 messages starting Aug 03 21 and ending Aug 31 21
Date index | Thread index | Author index


Tuesday, 03 August

Spammers Using storage[.]googleapis[.]com ?!!? Nick Boyce
Stb_truetype library heap buffer overflows (many CVEs, no CVEs yet) Marcin Kozlowski
Backdoor.Win32.WinShell.40 / Unauthenticated Remote Command Execution malvuln

Friday, 06 August

Re: Spammers Using storage[.]googleapis[.]com ?!!? Adrien JOLIBERT
Connect-app (CDU) Version: 3.8 - Cross Site Scripting merion44 via Fulldisclosure
Constructor.Win32.SS.11.c / Unauthenticated Open Proxy malvuln
Trojan-Dropper.Win32.Small.fp / Unauthenticated Open Proxy malvuln
Backdoor.Win32.Zdemon.10 / Unauthenticated Remote Command Execution malvuln
Backdoor.Win32.Zdemon.126 / Unauthenticated Remote Command Execution malvuln
Backdoor.Win32.Zaratustra / Unauthenticated Remote File Write (Remote Code Exec) malvuln

Tuesday, 10 August

Accept Facebook friend requests without unlocking your Android [Unpatched] Sivanesh Ashok
Re: Spammers Using storage[.]googleapis[.]com ?!!? Jeffrey Walton
[RT-SA-2021-002] XML External Entity Expansion in MobileTogether Server RedTeam Pentesting GmbH

Friday, 13 August

[SYSS-2021-042] TJWS - Reflected Cross-Site Scripting (CVE-2021-37573) Maurizio Ruchay
firebase/php-jwt Algorithm Confusion with Key IDs Paragon Initiative Enterprises Security Team
Trojan-Proxy.Win32.Raznew.gen / Unauthenticated Open Proxy malvuln
Backdoor.Win32.IRCBot.gen / Hardcoded Weak Password malvuln
HackTool.Win32.Hidd.b / Remote Stack Buffer Overflow (UDP Datagram) malvuln
HackTool.Win32.HKit / Unauthenticated Remote Command Execution malvuln

Monday, 16 August

New BlackArch Linux ISOs + OVA Image released! Black Arch
Cyberoam NetGenie (C0101B1-20141120-NG11VO) - Cross Site Scripting (XSS) Gionathan Reale via Fulldisclosure

Thursday, 19 August

SEC Consult SA-20210819-0 :: Multiple critical vulnerabilities in Altus Nexto and Hadron series SEC Consult Vulnerability Lab

Friday, 20 August

SEC Consult SA-20210820-0 :: Multiple Vulnerabilities in NetModule Router Software SEC Consult Vulnerability Lab

Friday, 27 August

SEC Consult SA-20210827-1 :: XML Tag injection in BSCW Server SEC Consult Vulnerability Lab
SEC Consult SA-20210827-0 :: Authenticated RCE in BSCW Server SEC Consult Vulnerability Lab
XSS in Apple ID Server idmsa.apple.com Zemn mez

Tuesday, 31 August

LLVM based tool to audit Linux Kernel Modules Security Marcin Kozlowski
Backdoor.Win32.DarkKomet.aspl / Insecure Permissions malvuln
Trojan-Proxy.Win32.Raznew.gen / Unauthenticated Open Proxy malvuln
Backdoor.Win32.Hupigon.abe / Unauthenticated Open Proxy malvuln
HEUR.Trojan.Win32.Delf.gen / Insecure Permissions malvuln
Backdoor.Win32.Antilam.11 / Unauthenticated Remote Code Execution malvuln
Backdoor.Win32.Delf.um / Authentication Bypass RCE malvuln
Backdoor.Win32.Delf.wr / Authentication Bypass RCE malvuln
Backdoor.Win32.Delf.wr / Port Bounce Scan malvuln
Backdoor.Win32.BO2K.11.d (Back Orifice) / Local Stack Buffer Overflow malvuln
Backdoor.Win32.Hupigon.aejq / Authentication Bypass RCE malvuln
Backdoor.Win32.Hupigon.aejq / Port Bounce Scan malvuln
Backdoor.Win32.Hupigon.aejq / Directory Traversal malvuln