[FD] Java deserialization vulnerability in QRadar RemoteJavaScript Servlet

2020-10-16 Thread Securify B.V. via Fulldisclosure
Java deserialization vulnerability in QRadar RemoteJavaScript Servlet Abstract A

[FD] Microsoft OneDrive client for Windows Qt QML module hijack

2020-07-09 Thread Securify B.V. via Fulldisclosure
Microsoft OneDrive client for Windows Qt QML module hijack Yorick Koster, July 2020

[FD] Cisco AnyConnect elevation of privileges due to insecure handling of path names

2020-04-21 Thread Securify B.V. via Fulldisclosure
Cisco AnyConnect elevation of privileges due to insecure handling of path names Yorick Koster, December 2019 ---

[FD] QRadar session manager path traversal vulnerability

2020-04-21 Thread Securify B.V. via Fulldisclosure
QRadar session manager path traversal vulnerability Yorick Koster, September 2019 --

[FD] Authorization bypass in QRadar Forensics web application

2020-04-21 Thread Securify B.V. via Fulldisclosure
Authorization bypass in QRadar Forensics web application Yorick Koster, September 2019 -

[FD] Arbitrary class instantiation & local file inclusion vulnerability in QRadar Forensics web application

2020-04-21 Thread Securify B.V. via Fulldisclosure
Arbitrary class instantiation & local file inclusion vulnerability in QRadar Forensics web application Yorick Koster, September 2019 ---

[FD] PHP object injection vulnerability in QRadar Forensics web application

2020-04-21 Thread Securify B.V. via Fulldisclosure
PHP object injection vulnerability in QRadar Forensics web application Yorick Koster, September 2019 ---

[FD] Local privilege escalation in QRadar due to run-result-reader.sh insecure file permissions

2020-04-21 Thread Securify B.V. via Fulldisclosure
Local privilege escalation in QRadar due to run-result-reader.sh insecure file permissions Yorick Koster, September 2019 ---

[FD] Reflected Cross-Site Scripting in QRadar Forensics link analysis page

2020-04-21 Thread Securify B.V. via Fulldisclosure
Reflected Cross-Site Scripting in QRadar Forensics link analysis page Yorick Koster, September 2019

[FD] Cross-Site Request Forgery & weak access control in QRadar ConfigServices webservice

2020-04-21 Thread Securify B.V. via Fulldisclosure
Cross-Site Request Forgery & weak access control in QRadar ConfigServices webservice Yorick Koster, September 2019 -

[FD] QRadar RssFeedItem Server-Side Request Forgery vulnerability

2020-04-21 Thread Securify B.V. via Fulldisclosure
QRadar RssFeedItem Server-Side Request Forgery vulnerability Yorick Koster, September 2019 -

[FD] Unauthorized access to QRadar configuration sets via default password

2020-04-21 Thread Securify B.V. via Fulldisclosure
Unauthorized access to QRadar configuration sets via default password Yorick Koster, September 2019

[FD] ZoneAlarm TrueVector Internet Monitor service insecure NTFS permissions vulnerability

2020-03-17 Thread Securify B.V. via Fulldisclosure
ZoneAlarm TrueVector Internet Monitor service insecure NTFS permissions vulnerability Yorick Koster, December 2019 -

[FD] Ivanti Workspace Control Application Whitelist bypass via PowerGrid /SEE command line argument

2018-10-01 Thread Securify B.V. via Fulldisclosure
Ivanti Workspace Control Application Whitelist bypass via PowerGrid /SEE command line argument Yorick Koster, August 2018 -

[FD] Stored credentials Ivanti Workspace Control can be retrieved from Registry

2018-10-01 Thread Securify B.V. via Fulldisclosure
Stored credentials Ivanti Workspace Control can be retrieved from Registry Yorick Koster, August 2018 -

[FD] Ivanti Workspace Control Data Security bypass via localhost UNC path

2018-10-01 Thread Securify B.V. via Fulldisclosure
Ivanti Workspace Control Data Security bypass via localhost UNC path Yorick Koster, August 2018 ---

[FD] Ivanti Workspace Control local privilege escalation via Named Pipe

2018-10-01 Thread Securify B.V. via Fulldisclosure
Ivanti Workspace Control local privilege escalation via Named Pipe Yorick Koster, August 2018 -

[FD] Ivanti Workspace Control Application Whitelist bypass via PowerGrid /RWS command line argument

2018-10-01 Thread Securify B.V. via Fulldisclosure
Ivanti Workspace Control Application Whitelist bypass via PowerGrid /RWS command line argument Yorick Koster, August 2018 -

[FD] Authentication bypass vulnerability in Western Digital My Cloud allows escalation to admin privileges

2018-09-18 Thread Securify B.V. via Fulldisclosure
Authentication bypass vulnerability in Western Digital My Cloud allows escalation to admin privileges Remco Vermeulen, September 2018 -

[FD] Cross-Site Scripting vulnerability in Zimbra Collaboration Suite due to the way it handles attachment links

2018-03-24 Thread Securify B.V. via Fulldisclosure
Cross-Site Scripting vulnerability in Zimbra Collaboration Suite due to the way it handles attachment links Stephan Kaag, January 2018

[FD] Authentication bypass in Kaseya VSA

2018-01-13 Thread Securify B.V. via Fulldisclosure
Authentication bypass in Kaseya VSA Kin Hung Cheng, Robert Hartshorn, May 2017

[FD] Code execution in Kaseya VSA

2018-01-13 Thread Securify B.V. via Fulldisclosure
Code execution in Kaseya VSA Kin Hung Cheng, Robert Hartshorn, May 2017 Abstra

[FD] Arbitrary file read in Kaseya VSA

2018-01-13 Thread Securify B.V. via Fulldisclosure
Arbitrary file read in Kaseya VSA Kin Hung Cheng, Robert Hartshorn, May 2017 A

[FD] bugt...@securityfocus.com

2017-11-22 Thread Securify B.V. via Fulldisclosure
Clickjacking vulnerability in CSRF error page pfSense Yorick Koster, November 2017

[FD] Clickjacking vulnerability in CSRF error page pfSense

2017-11-22 Thread Securify B.V. via Fulldisclosure
Clickjacking vulnerability in CSRF error page pfSense Yorick Koster, November 2017

[FD] Xamarin Studio for Mac API documentation update affected by local privilege escalation

2017-08-14 Thread Securify B.V. via Fulldisclosure
Xamarin Studio for Mac API documentation update affected by local privilege escalation Yorick Koster, April 2017 --

[FD] Buffer over-read vulnerability in Virtuozzo Power Panel (VZPP) and Automator

2017-07-05 Thread Securify B.V. via Fulldisclosure
Buffer over-read vulnerability in Virtuozzo Power Panel (VZPP) and Automator Sipke Mellema, July 2017 -

[FD] InsomniaX loader allows loading of arbitrary Kernel Extensions

2017-07-02 Thread Securify B.V. via Fulldisclosure
InsomniaX loader allows loading of arbitrary Kernel Extensions Yorick Koster, April 2017 --