Full Disclosure: by author

54 messages starting Apr 14 22 and ending Apr 27 22
Date index | Thread index | Author index


Asterisk Security Team

AST-2022-003: func_odbc: Possible SQL Injection Asterisk Security Team (Apr 14)
AST-2022-002: res_stir_shaken: SSRF vulnerability with Identity header Asterisk Security Team (Apr 14)
AST-2022-001: res_stir_shaken: resource exhaustion with large files Asterisk Security Team (Apr 14)

Gionathan Reale via Fulldisclosure

Multiple Vulnerabilities in Reprise License Manager 14.2 Gionathan Reale via Fulldisclosure (Apr 07)

Heiko Feldhusen via Fulldisclosure

CVE-2021-40680: Artica Proxy VMWare Appliance 4.30.000000 <=[SP273] Rev.1 Heiko Feldhusen via Fulldisclosure (Apr 22)

malvuln

Backdoor.Win32.Jokerdoor / Weak Hardcoded Credentials malvuln (Apr 07)
Backdoor.Win32.Delf.ps / Information Disclosure malvuln (Apr 07)
Backdoor.Win32.Bifrose.uw / Insecure Permissions malvuln (Apr 07)
Backdoor.Win32.NetCat32.10 / Unauthenticated Remote Command Execution malvuln (Apr 14)
Backdoor.Win32.Wisell / Stack Buffer Overflow (SEH) malvuln (Apr 07)
Backdoor.Win32.Cafeini.b / Weak Hardcoded Credentials malvuln (Apr 27)
Trojan-Downloader.Win32.Small.ahlq / Insecure Permissions malvuln (Apr 27)
Net-Worm.Win32.Kibuv.c / Authentication Bypass malvuln (Apr 27)
HackTool.Win32.Delf.vs / Insecure Credential Storage malvuln (Apr 18)
Backdoor.Win32.GF.j / Unauthenticated Remote Command Execution malvuln (Apr 27)
Backdoor.Win32.Kilo.016 / Denial of Service (UDP Datagram) malvuln (Apr 14)
Backdoor.Win32.Delf.zn / Insecure Credential Storage malvuln (Apr 18)
Adversary3 v1.0 / Malware vulnerability intel tool for third-party attackers / updated malvuln (Apr 14)
Backdoor.Win32.Psychward.03.a / Weak Hardcoded Password malvuln (Apr 18)
Backdoor.Win32.MotivFTP.12 / Authentication Bypass malvuln (Apr 14)
Backdoor.Win32.Wollf.h / Unauthenticated Remote Command Execution malvuln (Apr 07)
Backdoor.Win32.Wollf.h / Unauthenticated Remote Command Execution malvuln (Apr 07)
Backdoor.Win32.Cafeini.b / Port Bounce Scan malvuln (Apr 27)
Backdoor.Win32.Prorat.cwx / Insecure Permissions malvuln (Apr 14)
Backdoor.Win32.GateHell.21 / Port Bounce Scan malvuln (Apr 18)
Backdoor.Win32.XLog.21 / Authentication Bypass Race Condition malvuln (Apr 07)
Backdoor.Win32.Agent.aegg / Weak Hardcoded Credentials malvuln (Apr 27)
Backdoor.Win32.Wisell / Unauthenticated Remote Command Execution malvuln (Apr 07)
Backdoor.Win32.Jokerdoor / Remote Stack Buffer Overflow malvuln (Apr 27)
Trojan.Win32.TScash.c / Insecure Permissions malvuln (Apr 18)
Backdoor.Win32.FTP.Lana.01.d / Port Bounce Scan malvuln (Apr 07)
Backdoor.Win32.NinjaSpy.c / Authentication Bypass malvuln (Apr 14)
Email-Worm.Win32.Sidex / Unauthenticated Remote Command Execution malvuln (Apr 27)
Backdoor.Win32.Psychward.03.a / Weak Hardcoded Password malvuln (Apr 14)
Backdoor.Win32.GateHell.21 / Authentication Bypass malvuln (Apr 18)
Virus.Win32.Qvod.b / Insecure Permissions malvuln (Apr 27)
Backdoor.Win32.Loselove / Denial of Service malvuln (Apr 18)
Backdoor.Win32.Ptakks.XP.a / Insecure Credential Storage malvuln (Apr 07)
Backdoor.Win32.Easyserv.11.c / Insecure Transit malvuln (Apr 07)
Backdoor.Win32.Tiny.a / Unauthenticated Remote Command Execution malvuln (Apr 07)
HackTool.Win32.IpcScan.c / Local Stack Buffer Overflow malvuln (Apr 14)
Backdoor.Win32.Verify.h / Unauthenticated Remote Command Execution malvuln (Apr 07)
Trojan-Downloader.Win32.Agent / Insecure Permissions malvuln (Apr 27)
Backdoor.Win32.Hupigon.haqj / Insecure Service Path malvuln (Apr 18)
Email-Worm.Win32.Pluto.b / Insecure Permissions malvuln (Apr 14)
Backdoor.Win32.Xingdoor / Denial of Service malvuln (Apr 07)
Trojan-Banker.Win32.Banker.heq / Insecure Permissions malvuln (Apr 27)
Backdoor.Win32.FTP.Lana.01.d / Weak Hardcoded Credentials malvuln (Apr 07)
Backdoor.Win32.NetSpy.10 / Unauthenticated Remote Command Execution malvuln (Apr 14)

Murat Aydemir

CVE-2022-26233: Barco Control Room Management Suite File Path Traversal Vulnerability Murat Aydemir (Apr 01)

sec-advisory

[AIT-SA-20220208-01] SexyPolling SQL Injection sec-advisory (Apr 22)

SEC Consult Vulnerability Lab, Research via Fulldisclosure

SEC Consult SA-20220413 :: Missing Authentication at File Download & Denial of Service in Siemens A8000 PLC SEC Consult Vulnerability Lab, Research via Fulldisclosure (Apr 14)
SEC Consult SA-20220427-0 :: Privilege Escalation in Miele Benchmark Programming Tool SEC Consult Vulnerability Lab, Research via Fulldisclosure (Apr 27)

Stefan Pietsch

Trovent Security Advisory 2108-02 / Zepp: User account enumeration in password reset function Stefan Pietsch (Apr 27)