Full Disclosure: by date

84 messages starting Jan 03 21 and ending Jan 26 21
Date index | Thread index | Author index


Sunday, 03 January

Multiple vulnerabilities in Gotenberg <= 6.2.0 Błażej Adamczyk
Multiple vulnerabilities found in Rock RMS including RCE and account takeover Cyber Security Research Group via Fulldisclosure
Stored XSS In Hyland's Enterprise Search johnkennedy
BACKDOOR.WIN32.BNLITE / Remote Heap Corruption malvuln
Phorpiex / Insecure permissions EoP malvuln
TROJAN.WIN32.JORIK.DMSPAMMER.SZ / Remote Memory Corruption malvuln
HEUR.RISKTOOL.WIN32.BITMINER.GEN / Remote Memory Corruption malvuln
Backdoor.Win32.Zombam.j / Remote Stack Buffer Overflow malvuln
BACKDOOR.WIN32.REMOTEMANIPULATOR / Insecure Permissions malvuln
BACKDOOR.WIN32.ADVERBOT / Remote Stack Corruption malvuln
[KIS-2020-11] qdPM <= 9.1 (executeExport) PHP Object Injection Vulnerability Egidio Romano
Trojan:Win32/Alyak.B / Remote Stack Corruption malvuln
Email-Worm.Win32.Zhelatin.ago / Remote Stack Buffer Overflow malvuln
Trojan.Win32.Bayrob.cgau / Insecure Permissions EoP (SYSTEM) malvuln
Trojan.Win32.Barjac / Remote Stack Buffer Overflow. malvuln
Backdoor.Win32.Infexor.b / Remote Buffer Overflow malvuln
WIN32 BACKDOOR - 2019-02-ARTRADOWNLOADER / Remote SEH Buffer Overflow and Insecure Permissions malvuln
Threat: Trojan.Win32.Antavka.bz / Insecure Permissions EoP malvuln

Wednesday, 06 January

CVE-2020-24386: IMAP hibernation allows accessing other peoples mail Aki Tuomi
CVE-2020-24386: IMAP hibernation allows accessing other peoples mail Aki Tuomi
Files.com - Auth Bypass (Fat Client) Balázs Hambalkó
Backdoor.Win32.Zombam.k / Remote Stack Buffer Overflow malvuln
[KIS-2021-01] IPS Community Suite <= 4.5.4 (Downloads REST API) SQL Injection Vulnerability Egidio Romano
Re: [SECURITY] CVE-2013-4444 Remote Code Execution in Apache Tomcat Mark Thomas

Thursday, 07 January

Backdoor.Win32.Agent.dcbh / Insecure Permissions EoP malvuln
Backdoor.Win32.Xtreme.yvp / Insecure Permissions EoP malvuln
Backdoor.Win32.NinjaSpy.c / Remote Stack Buffer Overflow malvuln
Open-Xchange Security Advisory 2021-01-07 Martin Heiland via Fulldisclosure
Trovent Security Advisory 2010-01 / CVE-2020-28208: Rocket.Chat email address enumeration vulnerability Stefan Pietsch

Tuesday, 12 January

Re: Backdoor.Win32.NinjaSpy.c / Remote Stack Buffer Overflow Matthew Fernandez
Multiple vulnerabilities found in FiberHome HG6245D routers Pierre Kim
Envira Gallery - Lite Edition - Version 1.8.3.2 CVE-2020-35581 CVE-2020-35582 Rodolfo Augusto do Nascimento Tavares
Re: Trovent Security Advisory 2010-01 [updated] / CVE-2020-28208: Rocket.Chat email address enumeration vulnerability Stefan Pietsch
Advisory: ES2021-01 - Loopback access control bypass in coturn by using 0.0.0.0, [::1] or [::] as the peer address Sandro Gauci
Re: Backdoor.Win32.Xtreme.yvp / Insecure Permissions EoP bo0od
Backdoor.Win32.Ketch.b / Remote Stack Buffer Overflow malvuln
Backdoor.Win32.Levelone.a / Remote Stack Buffer Overflow malvuln
Backdoor.Win32.Levelone.b / Remote Stack Buffer Overflow malvuln
Backdoor.Win32.Zombam.a / Remote Stack Buffer Overflow malvuln

Wednesday, 13 January

SEC Consult SA-20210113-0 :: Multiple vulnerabilities in Pepperl+Fuchs IO-Link Master Series SEC Consult Vulnerability Lab
SEC Consult SA-20210113-1 :: Multiple vulnerabilities in flatCore CMS SEC Consult Vulnerability Lab

Tuesday, 19 January

Re: Backdoor.Win32.Xtreme.yvp / Insecure Permissions EoP network.mp4 via Fulldisclosure
Re: Backdoor.Win32.NinjaSpy.c / Remote Stack Buffer Overflow network.mp4 via Fulldisclosure
Re: Trovent Security Advisory 2010-01 [updated] / CVE-2020-28208: Rocket.Chat email address enumeration vulnerability Stefan Pietsch
BACKDOOR.WIN32.KURBADUR.A / Remote Stack Buffer Overflow malvuln
Backdoor.Win32.Ketch.i / SEH Remote Stack Buffer Overflow malvuln
BACKDOOR.WIN32.KETCH.A / Remote SEH Stack Buffer Overflow malvuln
Backdoor.Win32.Ncx.bt / Remote Stack Buffer Overflow malvuln
Backdoor.Win32.Nucleroot.bi - MaskPE 2.0 / File Based Buffer Overflow malvuln
Backdoor.Win32.Nucleroot.t - MaskPE 1.6 / File Based Buffer Overflow malvuln
Backdoor.Win32.Latinus.b / Remote Buffer Overflow malvuln
Backdoor.Win32.Whgrx / Remote Host Header Stack Buffer Overflow malvuln
Backdoor.Win32.Mnets / Remote Stack Buffer Overflow - (UDP Datagram Proto) malvuln
Newfuture Trojan V.1.0 BETA 1 / Insecure Permissions malvuln
Constructor.Win32.SMWG.a / Insecure Permissions malvuln
Constructor.Win32.SMWG.c / Insecure Permissions malvuln
Email-Worm.Win32.Agent.gi / Remote Stack Buffer Overflow - (UDP Datagram) malvuln
Backdoor.Win32.NetBull.11.a / Remote Buffer Overflow malvuln

Friday, 22 January

Re: Constructor.Win32.SMWG.a / Insecure Permissions Garrett Skjelstad
CVE-2020-20269 - Caret Editor v4.0.0-rc21 Remote Code Execution Manuel Bua
[REVIVE-SA-2021-001] Revive Adserver Vulnerabilities Matteo Beccati via Fulldisclosure
Backdoor.Win32.Zombam.geq / Remote Buffer Overflow malvuln
Backdoor.Win32.Whirlpool.10 / Remote Stack Buffer Overflow malvuln
Backdoor.Win32.Whisper.b / Remote Stack Corruption malvuln
Backdoor.Win32.Zxman / Missing Authentication malvuln
Backdoor.Win32.WinShell.30 / Remote Stack Buffer Overflow / Missing Authentication malvuln
Backdoor.Win32.Onalf / Missing Authentication malvuln
Backdoor.Win32.Verify.f / Missing Authentication malvuln
Backdoor.Win32.Xel / Remote Authentication Buffer Overflow malvuln
Backdoor.Win32.Hupigon.adef / Remote Stack Buffer Overflow malvuln

Monday, 25 January

Backdoor.Win32.Kraimer.11 / Missing Authentication malvuln
Backdoor.Win32.Noknok.60 / Insecure Permissions malvuln
Backdoor.Win32.Noknok.50 / Insecure Permissions malvuln
Backdoor.Win32.Jokerdoor (TDC Mail Spy 1.0) / Insecure Permissions malvuln
Trojan.Win32.Xocry.ff / Insecure Permissions malvuln
Backdoor.Win32.Wollf.16 / Weak Hardcoded Password malvuln
Backdoor.Win32.DarkKomet.bhfh / Insecure Permissions malvuln
Backdoor.Win32.Wollf.c / Hardcoded Backdoor Password malvuln

Tuesday, 26 January

[REVIVE-SA-2021-002] Revive Adserver Vulnerabilities Matteo Beccati via Fulldisclosure
Baron Samedit: Heap-based buffer overflow in Sudo (CVE-2021-3156) Qualys Security Advisory
APPLE-SA-2021-01-26-1 iOS 14.4 and iPadOS 14.4 Apple Product Security via Fulldisclosure
APPLE-SA-2021-01-26-2 tvOS 14.4 Apple Product Security via Fulldisclosure
APPLE-SA-2021-01-26-3 watchOS 7.3 Apple Product Security via Fulldisclosure
APPLE-SA-2021-01-26-4 Xcode 12.4 Apple Product Security via Fulldisclosure