Full Disclosure: by date

75 messages starting Jan 04 24 and ending Jan 27 24
Date index | Thread index | Author index


Thursday, 04 January

Windows PowerShell Single Quote Code Execution / Event Log Bypass hyp3rlinx
RansomLord v2 - Anti-Ransomware Exploitation Tool / New Release hyp3rlinx

Monday, 08 January

SSH-Snake: Automated SSH-Based Network Traversal Joshua Rogers
OXAS-ADV-2023-0005: OX App Suite Security Advisory Martin Heiland via Fulldisclosure
OXAS-ADV-2023-0006: OX App Suite Security Advisory Martin Heiland via Fulldisclosure
cpio privilege escalation vulnerability via setuid files in cpio archive Georgi Guninski

Sunday, 14 January

Re: [SBA-ADV-20220120-01] MOKOSmart MKGW1 Gateway Improper Session Management SBA - Advisory via Fulldisclosure
Re: cpio privilege escalation vulnerability via setuid files in cpio archive fulldisclosure
Re: cpio privilege escalation vulnerability via setuid files in cpio archive Georgi Guninski
Re: cpio privilege escalation vulnerability via setuid files in cpio archive Harry Sintonen via Fulldisclosure
Re: cpio privilege escalation vulnerability via setuid files in cpio archive Harry Sintonen via Fulldisclosure
CyberDanube Security Research 20240109-0 | Multiple Vulnerabilities in JetNet Series Thomas Weber via Fulldisclosure
Backdoor.Win32 Carbanak (Anunak) / Named Pipe Null DACL malvuln

Wednesday, 17 January

ODR violation in Redis Raft Meng Ruijie
Incorrect handshake in TinyDTLS Meng Ruijie
Mishandle epoch number in TinyDTLS servers Meng Ruijie
Infinite loop leading to buffer overflow in TinyDTLS Meng Ruijie
Buffer over-read in TinyDTLS Meng Ruijie
Assertion failure in check_certificate_request() of TinyDTLS Meng Ruijie
Misues same epoch number within TCP lifetime in TinyDTLS Meng Ruijie
Buffer over-read in dtls_sha256_update of TinyDTLS Meng Ruijie
Legends of IdleOn - I Reject Your RNG And Substitute My Own Soatok Dreamseeker

Thursday, 18 January

Minor firefox DoS - semi silently polluting ~/Downloads with files (part 2) Georgi Guninski
Re: ODR violation in Redis Raft Jeffrey Walton

Friday, 26 January

[SBA-ADV-20200707-01] CVE-2020-36771: CloudLinux CageFS 7.1.1-1 or below Token Disclosure SBA - Advisory via Fulldisclosure
[SBA-ADV-20200707-02] CVE-2020-36772: CloudLinux CageFS 7.0.8-2 or below Insufficiently Restricted Proxy Command SBA - Advisory via Fulldisclosure
[Full Disclosure] CVE-2024-22900: Unpatched Command Injection in Vinchin Backup and Recovery Versions 7.2 and Earlier Balgogan via Fulldisclosure
[Full Disclosure] CVE-2024-22899: Unpatched Command Injection in Vinchin Backup and Recovery Versions 7.2 and Earlier Valentin Lobstein via Fulldisclosure
[Full Disclosure] CVE-2024-22901: Default MYSQL Credentials in Vinchin Backup & Recovery v7.2 and Earlier Valentin Lobstein via Fulldisclosure
[Full Disclosure] CVE-2024-22902: Default Root Credentials in Vinchin Backup & Recovery v7.2 and Earlier Valentin Lobstein via Fulldisclosure
[Full Disclosure] CVE-2024-22903: Unpatched Command Injection in Vinchin Backup & Recovery Versions 7.2 and Earlier Valentin Lobstein via Fulldisclosure
APPLE-SA-01-22-2024-1 Safari 17.3 Apple Product Security via Fulldisclosure
APPLE-SA-01-22-2024-2 iOS 17.3 and iPadOS 17.3 Apple Product Security via Fulldisclosure
APPLE-SA-01-22-2024-3 iOS 16.7.5 and iPadOS 16.7.5 Apple Product Security via Fulldisclosure
APPLE-SA-01-22-2024-4 iOS 15.8.1 and iPadOS 15.8.1 Apple Product Security via Fulldisclosure
APPLE-SA-01-22-2024-5 macOS Sonoma 14.3 Apple Product Security via Fulldisclosure
APPLE-SA-01-22-2024-6 macOS Ventura 13.6.4 Apple Product Security via Fulldisclosure
APPLE-SA-01-22-2024-7 macOS Monterey 12.7.3 Apple Product Security via Fulldisclosure
APPLE-SA-01-22-2024-8 watchOS 10.3 Apple Product Security via Fulldisclosure
APPLE-SA-01-22-2024-9 tvOS 17.3 Apple Product Security via Fulldisclosure
TrojanSpy Win32 Nivdort / Insecure Permissions - EoP (SYSTEM) malvuln
Yet another fork()/malloc() bomb in javascript + SIGILL in Chrome Georgi Guninski
Multiple Vulnerabilities in Reprise License Manager 15.1 (CVE-2023-43183, CVE-2023-44031) Rahim, Mohaiman via Fulldisclosure
PrommetriX - (Prometheus Metrics Leaker) released! psy
Null pointer deference in freedesktop mesa Meng Ruijie
Null pointer dereference in Xedit Meng Ruijie
NULL pointer dereference in tgetstr() of ncurses Meng Ruijie
Buffer Overflow in glXQueryServerString() of mesa Meng Ruijie
Null pointer deference in XGetWMHints() of Xfig Meng Ruijie
NULL pointer dereference in the function handle_viminfo_register() of vim Meng Ruijie
NULL pointer dereference in __glXGetDrawableAttribute() of Mesa Meng Ruijie
NULL pointer dereference in XIQueryDevice() of gnome gtk Meng Ruijie
NULL pointer dereference in glXGetDrawableScreen() of OpenGL libglvnd Meng Ruijie
null pointer deference in GNU Midnight at /tty/x11conn.c Meng Ruijie
null pointer deference in gnome gdk-pixbuf Meng Ruijie
arithmetic exception in S-lang via the function tt_sprintf() Meng Ruijie
null pointer deference in gnome gtk via init_randr15() at gdkscreen-x11.c Meng Ruijie
SEGV in S-Lang via fixup_tgetstr() Meng Ruijie
null pointer deference in gnome gtk via parse_settings() at xsettings-client.c Meng Ruijie
NULL pointer dereference in freedesktop Mesa via check_xshm() Meng Ruijie
null pointer deference in nano via read_the_list() Meng Ruijie
NULL pointer dereference in QT via the function QXcbConnection::initializeAllAtoms() Meng Ruijie
Buffer Overflow in graphviz via via a crafted config6a file Meng Ruijie
null pointer deference in MiniZinc via a crafted .mzn file Meng Ruijie
null pointer deference in Sane via a crafted config file Meng Ruijie
null pointer deference in tex-live via a crafted cmr10.pfb Meng Ruijie
null pointer deference in LLVM Meng Ruijie
null pointer deference in MiniZinc via a crafted Preferences.json file Meng Ruijie
null pointer deference in tex-live Meng Ruijie
Buffer overflow in Sane Meng Ruijie

Saturday, 27 January

Re: Null pointer dereference in Xedit Alan Coopersmith
Re: NULL pointer dereference in freedesktop Mesa via check_xshm() Dan Cross
Re: null pointer deference in nano via read_the_list() Mark Esler
CVEs based on commit messages Mark Esler
Re: Buffer Overflow in graphviz via via a crafted config6a file Matthew Fernandez