Full Disclosure: by date

32 messages starting Oct 02 23 and ending Oct 27 23
Date index | Thread index | Author index


Monday, 02 October

SEC Consult SA-20230925-0 :: Stored Cross-Site Scripting in mb Support broker management solution openVIVA c2 SEC Consult Vulnerability Lab, Research via Fulldisclosure
SEC Consult SA-20230927-0 :: Multiple Vulnerabilities in SAPĀ® Enable Now Manager SEC Consult Vulnerability Lab, Research via Fulldisclosure
APPLE-SA-09-26-2023-1 Safari 17 Apple Product Security via Fulldisclosure
APPLE-SA-09-26-2023-2 macOS Sonoma 14 Apple Product Security via Fulldisclosure
APPLE-SA-09-26-2023-3 Additional information for APPLE-SA-2023-09-21-3 iOS 16.7 and iPadOS 16.7 Apple Product Security via Fulldisclosure
APPLE-SA-09-26-2023-4 Additional information for APPLE-SA-2023-09-21-6 macOS Ventura 13.6 Apple Product Security via Fulldisclosure
APPLE-SA-09-26-2023-5 Additional information for APPLE-SA-2023-09-21-7 macOS Monterey 12.7 Apple Product Security via Fulldisclosure
APPLE-SA-09-26-2023-6 Xcode 15 Apple Product Security via Fulldisclosure
APPLE-SA-09-26-2023-7 iOS 17 and iPadOS 17 Apple Product Security via Fulldisclosure
APPLE-SA-09-26-2023-8 watchOS 10 Apple Product Security via Fulldisclosure
APPLE-SA-09-26-2023-9 tvOS 17 Apple Product Security via Fulldisclosure

Thursday, 05 October

CVE-2023-4911: Local Privilege Escalation in the glibc's ld.so Qualys Security Advisory via Fulldisclosure
APPLE-SA-2023-10-04-1 iOS 17.0.3 and iPadOS 17.0.3 Apple Product Security via Fulldisclosure
SEC Consult SA-20231005 :: Open Redirect in SAPĀ® BSP Test Application it00 (Bypass for CVE-2020-6215 Patch) SEC Consult Vulnerability Lab, Research via Fulldisclosure

Monday, 16 October

Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days. Joshua Rogers
XNSoft Nconvert 7.136 - Multiple Vulnerabilities michele
APPLE-SA-10-10-2023-1 iOS 16.7.1 and iPadOS 16.7.1 Apple Product Security via Fulldisclosure
Defense in depth -- the Microsoft way (part 86): shipping rotten software to billions of unsuspecting customers Stefan Kanthak

Wednesday, 25 October

Ringzer0 Bootstrap24 CFP Now Open Steve Lord
APPLE-SA-10-25-2023-1 iOS 17.1 and iPadOS 17.1 Apple Product Security via Fulldisclosure
APPLE-SA-10-25-2023-3 iOS 15.8 and iPadOS 15.8 Apple Product Security via Fulldisclosure
APPLE-SA-10-25-2023-6 macOS Monterey 12.7.1 Apple Product Security via Fulldisclosure
APPLE-SA-10-25-2023-7 tvOS 17.1 Apple Product Security via Fulldisclosure
APPLE-SA-10-25-2023-2 iOS 16.7.2 and iPadOS 16.7.2 Apple Product Security via Fulldisclosure
APPLE-SA-10-25-2023-4 macOS Sonoma 14.1 Apple Product Security via Fulldisclosure
APPLE-SA-10-25-2023-8 watchOS 10.1 Apple Product Security via Fulldisclosure
APPLE-SA-10-25-2023-5 macOS Ventura 13.6.1 Apple Product Security via Fulldisclosure
APPLE-SA-10-25-2023-9 Safari 17.1 Apple Product Security via Fulldisclosure

Thursday, 26 October

[KIS-2023-10] SugarCRM <= 13.0.1 (GetControl) Server-Side Template Injection Vulnerability Egidio Romano
[KIS-2023-11] SugarCRM <= 13.0.1 (set_note_attachment) Unrestricted File Upload Vulnerability Egidio Romano

Friday, 27 October

[KIS-2023-12] phpFox <= 4.8.13 (redirect) PHP Object Injection Vulnerability Egidio Romano
LKX-2023-001 VinChin VMWare Backup Gregory Boddin via Fulldisclosure