Integer overflow in .NET Framework
System.DirectoryServices.Protocols.Utility class
Yorick Koster, May 2015
---
Insufficient certificate validation in EMC Secure Remote Services
Virtual Edition
Han Sahin, November 2014
Weak authentication in EMC Secure Remote Services Virtual Edition Web
Portal
Han Sahin, November 2014
-
Microsoft released MS15-101 that addresses this issue:
https://technet.microsoft.com/library/security/ms15-101
On 25-07-15 09:02, Securify B.V. wrote:
Integer overflow in .NET Framework
Synology Video Station command injection and multiple SQL injection
vulnerabilities
Han Sahin, September 2015
-
Multiple Cross-Site Scripting vulnerabilities in Synology Download
Station
Han Sahin, September 2015
--
Cisco AnyConnect elevation of privileges via DLL side loading
Yorick Koster, June 2015
Cisco AnyConnect elevation of privileges via DMG install script
Yorick Koster, July 2015
--
has released bug ID CSCuv01279 [5] for registered users, which
contains additional details and an up-to-date list of affected product
versions.
On 22-09-15 18:18, Securify B.V. wrote:
Cisco AnyConnect elevation of privileges
has released bug ID CSCuv11947 for registered users, which
contains additional details and an up-to-date list of affected product
versions.
On 23-09-15 19:14, Securify B.V. wrote:
Cisco AnyConnect elevation of privileges via
COM+ Services DLL side loading vulnerability
Yorick Koster, August 2015
Abstra
Event Viewer Snapin multiple DLL side loading vulnerabilities
Yorick Koster, August 2015
--
Windows Authentication UI DLL side loading vulnerability
Yorick Koster, August 2015
---
Shutdown UX DLL side loading vulnerability
Yorick Koster, November 2015
Abstra
Shockwave Flash Object DLL side loading vulnerability
Yorick Koster, August 2015
--
OLE DB Provider for Oracle multiple DLL side loading vulnerabilities
Yorick Koster, August 2015
---
LEADTOOLS ActiveX control multiple DLL side loading vulnerabilities
Yorick Koster, September 2015
-
HP ToComMsg DLL side loading vulnerability
Yorick Koster, September 2015
Abstr
HP LaserJet Fax Preview DLL side loading vulnerability
Yorick Koster, September 2015
--
NPS Datastore server DLL side loading vulnerability
Yorick Koster, September 2015
-
BDA MPEG2 Transport Information Filter DLL side loading vulnerability
Yorick Koster, September 2015
---
MapsUpdateTask Task DLL side loading vulnerability
Yorick Koster, November 2015
---
Fix
Microsoft released MS16-014 that fixes this vulnerability.
On 16-12-15 19:26, Securify B.V. wrote
Windows Mail Find People DLL side loading vulnerability
Yorick Koster, September 2015
-
Hi Stefan,
See below.
On 09-03-16 12:48, Stefan Kanthak wrote:
"Securify B.V." wrote:
Windows Mail Find People DLL side loading vul
.NET Framework 4.6 allows side loading of Windows API Set DLL
Yorick Koster, February 2016
EMC M&R (Watch4net) lacks Cross-Site Request Forgery protection
Han Sahin, November 2014
--
Microsoft Visio multiple DLL side loading vulnerabilities
Yorick Koster, August 2015
--
Craft CMS affected by server side template injection
Nelson Berg & Jurgen Kloosterman, June 2016
--
Persistent Cross-Site Scripting in WP Live Chat Support plugin
Han Sahin, July 2016
---
DLL side loading vulnerability in VMware Host Guest Client Redirector
Yorick Koster, December 2015
Internet Explorer iframe sandbox local file name disclosure
vulnerability
Yorick Koster, March 2016
---
Authentication bypass vulnerability in Western Digital My Cloud
Remco Vermeulen, Januari 2017
-
Multiple persistent Cross-Site Scripting vulnerabilities in osTicket
Han Sahin, July 2016
-
Adobe Reader for Android exposes insecure Javascript interfaces
Yorick Koster, April 2014
-
This issue was originally reported as CVE-2011-3426. We can confirm that
Mobile Safari on iOS 7.1.2 is still affected. We've reported this to
Apple on February 25, 2014. You can test is yourself at:
http://www.securify.nl/cve-2011-3426.html
This test page sets the following HTTP headers:
Conte
Attached is a screenshot that demonstrates this issue on Yahoo! Mail.
Despite the Content-Disposition header, (HTML) attachments are rendered
by Mobile Safari.
On 30-07-14 19:01, Securify B.V. wrote:
This issue was originally reported as CVE-2011-3426. We can confirm
that Mobile Safari on
Outlook.com for Android fails to validate server certificates
Yorick Koster, April 2014
---
Glype proxy cookie jar path traversal allows code execution
Securify, September 2014
--
Glype proxy privacy settings can be disabled via CSRF
Securify, September 2014
Glype proxy privacy settings can be disabled via CSRF
Securify, September 2014
Glype proxy local address filter bypass
Securify, September 2014
Abstract
Cisco RV Series multiple vulnerabilities
Yorick Koster, June 2013
Abstract
---
Websense Data Security DLP incident Forensics Preview is vulnerable to
Cross-Site Scripting
Han Sahin, September 2014
-
Websense Email Security vulnerable to persistent Cross-Site Scripting in
audit log details view
Han Sahin, September 2014
-
Command injection vulnerability in network diagnostics tool of Websense
Appliance Manager
Han Sahin, September 2014
---
Source code disclosure of Websense Triton JSP files via double quote
character
Han Sahin, September 2014
--
Missing access control on Websense Explorer web folder
Han Sahin, September 2014
--
Cross-Site Scripting vulnerability in Websense Data Security block page
Han Sahin, September 2014
-
Cross-Site Scripting vulnerability in Websense Explorer report scheduler
Han Sahin, September 2014
Multiple Cross-Site Scripting vulnerabilities in Websense Reporting
Han Sahin, September 2014
-
Error messages of Websense Content Gateway are vulnerable to Cross-Site
Scripting
Han Sahin, September 2014
---
EMC M&R (Watch4net) data storage collector credentials are not properly
protected
Han Sahin, November 2014
Cross-Site Scripting vulnerability in EMC M&R (Watch4net) Web Portal
Report Favorites
Han Sahin, November 2014
Cross-Site Scripting vulnerability in EMC M&R (Watch4net) Centralized
Management Console
Han Sahin, November 2014
-
Cross-Site Scripting vulnerability in EMC M&R (Watch4net) Alerting
Frontend
Han Sahin, November 2014
--
Path traversal vulnerability in EMC M&R (Watch4net) MIB Browser
Han Sahin, November 2014
--
Path traversal vulnerability in EMC M&R (Watch4net) Device Discovery
Han Sahin, November 2014
-
Command injection vulnerability in EMC Secure Remote Services Virtual
Edition
Han Sahin, November 2014
EMC Secure Remote Services Virtual Edition Provisioning component is
affected by SQL injection
Han Sahin, November 2014
---
Citrix Command Center allows downloading of configuration files
Han Sahin, August 2014
Advent JMX Servlet of Citrx Command Center is accessible to
unauthenticated users
Han Sahin, August 2014
--
Citrix NITRO SDK xen_hotfix page is vulnerable to Cross-Site Scripting
Han Sahin, August 2014
-
Command injection vulnerability in Citrix NITRO SDK xen_hotfix page
Han Sahin, August 2014
Citrix NetScaler VPX help pages are vulnerable to Cross-Site Scripting
Han Sahin, August 2014
-
Viber for Android exposes insecure Javascript interface
Yorick Koster, April 2014
-
Reflected Cross-Site Scripting vulnerability in asdoc generated
documentation
Radjnies Bhansingh, March 2014
--
Command injection vulnerability in Synology Photo Station
Han Sahin, May 2015
Reflected Cross-Site Scripting in Synology DiskStation Manager
Han Sahin, May 2015
Synology Photo Station multiple Cross-Site Scripting vulnerabilities
Han Sahin, May 2015
--
Western Digital My Cloud vulnerable to multiple command injection
vulnerabilities
Remco Vermeulen, January 2017
---
Western Digital My Cloud vulnerable to Cross-Site Request Forgery
vulnerability
Remco Vermeulen, January 2017
-
Stack-based buffer overflow in Western Digital My Cloud allows for
remote code execution
Remco Vermeulen, January 2017
Microsoft Edge Fetch API allows setting of arbitrary request headers
Yorick Koster, January 2017
--
Multiple local privilege escalation vulnerabilities in Proxifier for Mac
Yorick Koster, April 2017
Microsoft Office OneNote 2007 DLL side loading vulnerability
Yorick Koster, September 2015
Persistent Cross-Site Scripting in Scriptler Jenkins Plugin
Burak Kelebek, April 2017
-
Authentication bypass vulnerability in Western Digital My Cloud allows
escalation to admin privileges
Remco Vermeulen, April 2017
-
Multiple local privilege escalation vulnerabilities in HideMyAss Pro VPN
client v2.x for OS X
Han Sahin, April 2017
---
Local privilege escalation vulnerability in HideMyAss Pro VPN client
v3.x for macOS
Han Sahin, April 2017
-
SyntaxHighlight MediaWiki extension allows injection of arbitrary
Pygments options
Yorick Koster, February 2017
---
MediaWiki version 1.28.2 and version 1.27.3 were release that include a
fix for this issue.
https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000209.html
On 29-04-17 16:41, Securify B.V. wrote
InsomniaX loader allows loading of arbitrary Kernel Extensions
Yorick Koster, April 2017
--
Buffer over-read vulnerability in Virtuozzo Power Panel (VZPP) and
Automator
Sipke Mellema, July 2017
-
Xamarin Studio for Mac API documentation update affected by local
privilege escalation
Yorick Koster, April 2017
--
Clickjacking vulnerability in CSRF error page pfSense
Yorick Koster, November 2017
Clickjacking vulnerability in CSRF error page pfSense
Yorick Koster, November 2017
Arbitrary file read in Kaseya VSA
Kin Hung Cheng, Robert Hartshorn, May 2017
A
Code execution in Kaseya VSA
Kin Hung Cheng, Robert Hartshorn, May 2017
Abstra
Authentication bypass in Kaseya VSA
Kin Hung Cheng, Robert Hartshorn, May 2017
Cross-Site Scripting vulnerability in Zimbra Collaboration Suite due to
the way it handles attachment links
Stephan Kaag, January 2018
Authentication bypass vulnerability in Western Digital My Cloud allows
escalation to admin privileges
Remco Vermeulen, September 2018
-
Ivanti Workspace Control Application Whitelist bypass via PowerGrid /RWS
command line argument
Yorick Koster, August 2018
-
Ivanti Workspace Control local privilege escalation via Named Pipe
Yorick Koster, August 2018
-
Ivanti Workspace Control Data Security bypass via localhost UNC path
Yorick Koster, August 2018
---
Stored credentials Ivanti Workspace Control can be retrieved from
Registry
Yorick Koster, August 2018
-
Ivanti Workspace Control Application Whitelist bypass via PowerGrid /SEE
command line argument
Yorick Koster, August 2018
-
ZoneAlarm TrueVector Internet Monitor service insecure NTFS permissions
vulnerability
Yorick Koster, December 2019
-
Unauthorized access to QRadar configuration sets via default password
Yorick Koster, September 2019
QRadar RssFeedItem Server-Side Request Forgery vulnerability
Yorick Koster, September 2019
-
1 - 100 of 110 matches
Mail list logo