Full Disclosure: by date

59 messages starting Sep 01 21 and ending Sep 28 21
Date index | Thread index | Author index


Wednesday, 01 September

SEC Consult SA-20210901-0 :: Multiple vulnerabilities in MOXA devices SEC Consult Vulnerability Lab
KL-001-2021-008: CyberArk Credential File Insufficient Effective Key Space KoreLogic Disclosures via Fulldisclosure
KL-001-2021-009: CyberArk Credential Provider Race Condition And Authorization Bypass KoreLogic Disclosures via Fulldisclosure
KL-001-2021-010:CyberArk Credential Provider Local Cache Can Be Decrypted KoreLogic Disclosures via Fulldisclosure

Friday, 03 September

Windows Defender Application Guard DoS via Long Hostname Jonathan Gregson via Fulldisclosure
Mirror on the Fly Attack Gökhan Muharremoglu
Artica Proxy VMWare Appliance 4.30.000000 <=[SP273] Heiko Feldhusen via Fulldisclosure
Backdoor.Win32.MoonPie.40 / Authentication Bypass RCE malvuln
Backdoor.Win32.MoonPie.40 / Port Bounce Scan malvuln
Backdoor.Win32.MoonPie.40 / Unauthenticated Remote Command Execution malvuln
a xss vulnerability in Jforum 2.7.0 kun song

Tuesday, 07 September

CVE-2021-3145: Biometric Authentication Bypass in Ionic Identity Vault Advisories
Re: Mirror on the Fly Attack bo0od
Re: a xss vulnerability in Jforum 2.7.0 Henri Salo
Backdoor.Win32.Nyara.aq / Insecure Permissions malvuln
Backdoor.Win32.Small.gs / Unauthenticated Remote Command Execution malvuln
Backdoor.Win32.Small.vjt / Unauthenticated Remote Command Execution malvuln
Dahua CVE-2021-33044, CVE-2021-33045 bashis
rencode 3-byte packet DoS Antoine Martin

Tuesday, 14 September

HEUR.Trojan.Win32.Generic / Insecure Permissions malvuln
Backdoor.Win32.VB.awm / Authentication Bypass - Information Leakage malvuln
Backdoor.Win32.Wollf.h / Unauthenticated Remote Command Execution malvuln
Backdoor.Win32.WinterLove.i / Hardcoded Weak Password malvuln

Friday, 17 September

Microsoft Windows Command-line Interpreter "cmd.exe" / Stack Buffer Overflow hyp3rlinx
AMD Chipset Driver Information Disclosure Vulnerability [CVE-2021-26333] disclosure
APPLE-SA-2021-09-13-1 iOS 14.8 and iPadOS 14.8 Apple Product Security via Fulldisclosure
APPLE-SA-2021-09-13-2 watchOS 7.6.2 Apple Product Security via Fulldisclosure
APPLE-SA-2021-09-13-3 macOS Big Sur 11.6 Apple Product Security via Fulldisclosure
APPLE-SA-2021-09-13-4 Security Update 2021-005 Catalina Apple Product Security via Fulldisclosure
APPLE-SA-2021-09-13-5 Safari 14.1.2 Apple Product Security via Fulldisclosure

Tuesday, 21 September

Windows NT Command-line Interpreter "cmd.exe" / Stack Buffer Overflow hyp3rlinx
Windows NT Command-line Interpreter "cmd.exe" - Stack Buffer Overflow / PoC Video hyp3rlinx
BSides San Francisco – February 2022 BSidesSF CFP via Fulldisclosure
APPLE-SA-2021-09-20-1 iOS 15 and iPadOS 15 product-security-noreply--- via Fulldisclosure
APPLE-SA-2021-09-20-2 watchOS 8 product-security-noreply--- via Fulldisclosure
APPLE-SA-2021-09-20-3 tvOS 15 product-security-noreply--- via Fulldisclosure
APPLE-SA-2021-09-20-4 Xcode 13 product-security-noreply--- via Fulldisclosure
APPLE-SA-2021-09-20-5 Safari 15 product-security-noreply--- via Fulldisclosure
APPLE-SA-2021-09-20-6 Additional information for APPLE-SA-2021-09-13-1 iOS 14.8 and iPadOS 14.8 product-security-noreply--- via Fulldisclosure
APPLE-SA-2021-09-20-7 Additional information for APPLE-SA-2021-09-13-3 macOS Big Sur 11.6 product-security-noreply--- via Fulldisclosure
APPLE-SA-2021-09-20-8 Additional information for APPLE-SA-2021-09-13-4 Security Update 2021-005 Catalina product-security-noreply--- via Fulldisclosure
APPLE-SA-2021-09-20-9 iTunes U 3.8.3 product-security-noreply--- via Fulldisclosure
APPLE-SA-2021-09-20-10 iTunes 12.12 for Windows product-security-noreply--- via Fulldisclosure
Trojan.Win32.Agent.xaamkd / Insecure Permissions malvuln
Backdoor.Win32.Hupigon.asqx / Unauthenticated Open Proxy malvuln
Backdoor.Win32.Minilash.10.b / Remote Denial of Service (UDP Datagram) malvuln

Friday, 24 September

openvpn-monitor Authorization Bypass Advisories
openvpn-monitor OpenVPN Management Socket Command Injection Advisories
openvpn-monitor Cross-Site Request Forgery (CSRF) Advisories
APPLE-SA-2021-09-23-2 Security Update 2021-006 Catalina Apple Product Security via Fulldisclosure
APPLE-SA-2021-09-23-1 iOS 12.5.5 Apple Product Security via Fulldisclosure

Tuesday, 28 September

Google Extensible Service Proxy v1 - CWE-287 Improper Authentication Imre Rad
Trojan-Downloader.Win32.VB.abb / Insecure Permissions malvuln
Backdoor.Win32.Agent.aer / Remote Denial of Service malvuln
Backdoor.Win32.Agent.aer / Insecure Transit Password Disclosure malvuln
Backdoor.Win32.RmtSvc.l / Remote Denial of Service malvuln
Backdoor.Win32.Hupigon.fjcd / Unauthenticated Open Proxy malvuln
Backdoor.Win32.Hupigon.afjk / Authentication Bypass RCE malvuln
Backdoor.Win32.Hupigon.afjk / Directory Traversal malvuln