Full Disclosure: by author

59 messages starting Sep 07 21 and ending Sep 01 21
Date index | Thread index | Author index


Advisories

CVE-2021-3145: Biometric Authentication Bypass in Ionic Identity Vault Advisories (Sep 07)
openvpn-monitor OpenVPN Management Socket Command Injection Advisories (Sep 24)
openvpn-monitor Cross-Site Request Forgery (CSRF) Advisories (Sep 24)
openvpn-monitor Authorization Bypass Advisories (Sep 24)

Antoine Martin

rencode 3-byte packet DoS Antoine Martin (Sep 07)

Apple Product Security via Fulldisclosure

APPLE-SA-2021-09-23-1 iOS 12.5.5 Apple Product Security via Fulldisclosure (Sep 24)
APPLE-SA-2021-09-13-2 watchOS 7.6.2 Apple Product Security via Fulldisclosure (Sep 17)
APPLE-SA-2021-09-23-2 Security Update 2021-006 Catalina Apple Product Security via Fulldisclosure (Sep 24)
APPLE-SA-2021-09-13-1 iOS 14.8 and iPadOS 14.8 Apple Product Security via Fulldisclosure (Sep 17)
APPLE-SA-2021-09-13-4 Security Update 2021-005 Catalina Apple Product Security via Fulldisclosure (Sep 17)
APPLE-SA-2021-09-13-5 Safari 14.1.2 Apple Product Security via Fulldisclosure (Sep 17)
APPLE-SA-2021-09-13-3 macOS Big Sur 11.6 Apple Product Security via Fulldisclosure (Sep 17)

bashis

Dahua CVE-2021-33044, CVE-2021-33045 bashis (Sep 07)

bo0od

Re: Mirror on the Fly Attack bo0od (Sep 07)

BSidesSF CFP via Fulldisclosure

BSides San Francisco – February 2022 BSidesSF CFP via Fulldisclosure (Sep 21)

disclosure

AMD Chipset Driver Information Disclosure Vulnerability [CVE-2021-26333] disclosure (Sep 17)

Gökhan Muharremoglu

Mirror on the Fly Attack Gökhan Muharremoglu (Sep 03)

Heiko Feldhusen via Fulldisclosure

Artica Proxy VMWare Appliance 4.30.000000 <=[SP273] Heiko Feldhusen via Fulldisclosure (Sep 03)

Henri Salo

Re: a xss vulnerability in Jforum 2.7.0 Henri Salo (Sep 07)

hyp3rlinx

Windows NT Command-line Interpreter "cmd.exe" / Stack Buffer Overflow hyp3rlinx (Sep 21)
Windows NT Command-line Interpreter "cmd.exe" - Stack Buffer Overflow / PoC Video hyp3rlinx (Sep 21)
Microsoft Windows Command-line Interpreter "cmd.exe" / Stack Buffer Overflow hyp3rlinx (Sep 17)

Imre Rad

Google Extensible Service Proxy v1 - CWE-287 Improper Authentication Imre Rad (Sep 28)

Jonathan Gregson via Fulldisclosure

Windows Defender Application Guard DoS via Long Hostname Jonathan Gregson via Fulldisclosure (Sep 03)

KoreLogic Disclosures via Fulldisclosure

KL-001-2021-009: CyberArk Credential Provider Race Condition And Authorization Bypass KoreLogic Disclosures via Fulldisclosure (Sep 01)
KL-001-2021-010:CyberArk Credential Provider Local Cache Can Be Decrypted KoreLogic Disclosures via Fulldisclosure (Sep 01)
KL-001-2021-008: CyberArk Credential File Insufficient Effective Key Space KoreLogic Disclosures via Fulldisclosure (Sep 01)

kun song

a xss vulnerability in Jforum 2.7.0 kun song (Sep 03)

malvuln

Trojan-Downloader.Win32.VB.abb / Insecure Permissions malvuln (Sep 28)
Backdoor.Win32.Agent.aer / Remote Denial of Service malvuln (Sep 28)
Backdoor.Win32.Small.gs / Unauthenticated Remote Command Execution malvuln (Sep 07)
Backdoor.Win32.RmtSvc.l / Remote Denial of Service malvuln (Sep 28)
Backdoor.Win32.Minilash.10.b / Remote Denial of Service (UDP Datagram) malvuln (Sep 21)
HEUR.Trojan.Win32.Generic / Insecure Permissions malvuln (Sep 14)
Backdoor.Win32.WinterLove.i / Hardcoded Weak Password malvuln (Sep 14)
Backdoor.Win32.Agent.aer / Insecure Transit Password Disclosure malvuln (Sep 28)
Backdoor.Win32.Small.vjt / Unauthenticated Remote Command Execution malvuln (Sep 07)
Backdoor.Win32.Wollf.h / Unauthenticated Remote Command Execution malvuln (Sep 14)
Backdoor.Win32.Hupigon.asqx / Unauthenticated Open Proxy malvuln (Sep 21)
Backdoor.Win32.Hupigon.fjcd / Unauthenticated Open Proxy malvuln (Sep 28)
Trojan.Win32.Agent.xaamkd / Insecure Permissions malvuln (Sep 21)
Backdoor.Win32.Nyara.aq / Insecure Permissions malvuln (Sep 07)
Backdoor.Win32.VB.awm / Authentication Bypass - Information Leakage malvuln (Sep 14)
Backdoor.Win32.MoonPie.40 / Port Bounce Scan malvuln (Sep 03)
Backdoor.Win32.Hupigon.afjk / Authentication Bypass RCE malvuln (Sep 28)
Backdoor.Win32.MoonPie.40 / Unauthenticated Remote Command Execution malvuln (Sep 03)
Backdoor.Win32.MoonPie.40 / Authentication Bypass RCE malvuln (Sep 03)
Backdoor.Win32.Hupigon.afjk / Directory Traversal malvuln (Sep 28)

product-security-noreply--- via Fulldisclosure

APPLE-SA-2021-09-20-7 Additional information for APPLE-SA-2021-09-13-3 macOS Big Sur 11.6 product-security-noreply--- via Fulldisclosure (Sep 21)
APPLE-SA-2021-09-20-2 watchOS 8 product-security-noreply--- via Fulldisclosure (Sep 21)
APPLE-SA-2021-09-20-4 Xcode 13 product-security-noreply--- via Fulldisclosure (Sep 21)
APPLE-SA-2021-09-20-10 iTunes 12.12 for Windows product-security-noreply--- via Fulldisclosure (Sep 21)
APPLE-SA-2021-09-20-6 Additional information for APPLE-SA-2021-09-13-1 iOS 14.8 and iPadOS 14.8 product-security-noreply--- via Fulldisclosure (Sep 21)
APPLE-SA-2021-09-20-9 iTunes U 3.8.3 product-security-noreply--- via Fulldisclosure (Sep 21)
APPLE-SA-2021-09-20-5 Safari 15 product-security-noreply--- via Fulldisclosure (Sep 21)
APPLE-SA-2021-09-20-3 tvOS 15 product-security-noreply--- via Fulldisclosure (Sep 21)
APPLE-SA-2021-09-20-8 Additional information for APPLE-SA-2021-09-13-4 Security Update 2021-005 Catalina product-security-noreply--- via Fulldisclosure (Sep 21)
APPLE-SA-2021-09-20-1 iOS 15 and iPadOS 15 product-security-noreply--- via Fulldisclosure (Sep 21)

SEC Consult Vulnerability Lab

SEC Consult SA-20210901-0 :: Multiple vulnerabilities in MOXA devices SEC Consult Vulnerability Lab (Sep 01)