[FD] Integer overflow in .NET Framework System.DirectoryServices.Protocols.Utility class

2015-07-25 Thread Securify B.V.
Integer overflow in .NET Framework System.DirectoryServices.Protocols.Utility class Yorick Koster, May 2015 ---

[FD] Insufficient certificate validation in EMC Secure Remote Services Virtual Edition

2015-08-17 Thread Securify B.V.
Insufficient certificate validation in EMC Secure Remote Services Virtual Edition Han Sahin, November 2014

[FD] Weak authentication in EMC Secure Remote Services Virtual Edition Web Portal

2015-08-17 Thread Securify B.V.
Weak authentication in EMC Secure Remote Services Virtual Edition Web Portal Han Sahin, November 2014 -

Re: [FD] Integer overflow in .NET Framework System.DirectoryServices.Protocols.Utility class

2015-09-08 Thread Securify B.V.
Microsoft released MS15-101 that addresses this issue: https://technet.microsoft.com/library/security/ms15-101 On 25-07-15 09:02, Securify B.V. wrote: Integer overflow in .NET Framework

[FD] Synology Video Station command injection and multiple SQL injection vulnerabilities

2015-09-09 Thread Securify B.V.
Synology Video Station command injection and multiple SQL injection vulnerabilities Han Sahin, September 2015 -

[FD] Multiple Cross-Site Scripting vulnerabilities in Synology Download Station

2015-09-09 Thread Securify B.V.
Multiple Cross-Site Scripting vulnerabilities in Synology Download Station Han Sahin, September 2015 --

[FD] Cisco AnyConnect elevation of privileges via DLL side loading

2015-09-22 Thread Securify B.V.
Cisco AnyConnect elevation of privileges via DLL side loading Yorick Koster, June 2015

[FD] Cisco AnyConnect elevation of privileges via DMG install script

2015-09-23 Thread Securify B.V.
Cisco AnyConnect elevation of privileges via DMG install script Yorick Koster, July 2015 --

Re: [FD] Cisco AnyConnect elevation of privileges via DLL side loading

2015-09-30 Thread Securify B.V.
has released bug ID CSCuv01279 [5] for registered users, which contains additional details and an up-to-date list of affected product versions. On 22-09-15 18:18, Securify B.V. wrote: Cisco AnyConnect elevation of privileges

Re: [FD] Cisco AnyConnect elevation of privileges via DMG install script

2015-09-30 Thread Securify B.V.
has released bug ID CSCuv11947 for registered users, which contains additional details and an up-to-date list of affected product versions. On 23-09-15 19:14, Securify B.V. wrote: Cisco AnyConnect elevation of privileges via

[FD] COM+ Services DLL side loading vulnerability

2015-12-12 Thread Securify B.V.
COM+ Services DLL side loading vulnerability Yorick Koster, August 2015 Abstra

[FD] Event Viewer Snapin multiple DLL side loading vulnerabilities

2015-12-12 Thread Securify B.V.
Event Viewer Snapin multiple DLL side loading vulnerabilities Yorick Koster, August 2015 --

[FD] Windows Authentication UI DLL side loading vulnerability

2015-12-12 Thread Securify B.V.
Windows Authentication UI DLL side loading vulnerability Yorick Koster, August 2015 ---

[FD] Shutdown UX DLL side loading vulnerability

2015-12-16 Thread Securify B.V.
Shutdown UX DLL side loading vulnerability Yorick Koster, November 2015 Abstra

[FD] Shockwave Flash Object DLL side loading vulnerability

2015-12-16 Thread Securify B.V.
Shockwave Flash Object DLL side loading vulnerability Yorick Koster, August 2015 --

[FD] OLE DB Provider for Oracle multiple DLL side loading vulnerabilities

2015-12-16 Thread Securify B.V.
OLE DB Provider for Oracle multiple DLL side loading vulnerabilities Yorick Koster, August 2015 ---

[FD] LEADTOOLS ActiveX control multiple DLL side loading vulnerabilities

2016-01-23 Thread Securify B.V.
LEADTOOLS ActiveX control multiple DLL side loading vulnerabilities Yorick Koster, September 2015 -

[FD] HP ToComMsg DLL side loading vulnerability

2016-01-23 Thread Securify B.V.
HP ToComMsg DLL side loading vulnerability Yorick Koster, September 2015 Abstr

[FD] HP LaserJet Fax Preview DLL side loading vulnerability

2016-01-23 Thread Securify B.V.
HP LaserJet Fax Preview DLL side loading vulnerability Yorick Koster, September 2015 --

[FD] NPS Datastore server DLL side loading vulnerability

2016-02-10 Thread Securify B.V.
NPS Datastore server DLL side loading vulnerability Yorick Koster, September 2015 -

[FD] BDA MPEG2 Transport Information Filter DLL side loading vulnerability

2016-02-10 Thread Securify B.V.
BDA MPEG2 Transport Information Filter DLL side loading vulnerability Yorick Koster, September 2015 ---

[FD] MapsUpdateTask Task DLL side loading vulnerability

2016-02-10 Thread Securify B.V.
MapsUpdateTask Task DLL side loading vulnerability Yorick Koster, November 2015 ---

Re: [FD] OLE DB Provider for Oracle multiple DLL side loading vulnerabilities

2016-02-10 Thread Securify B.V.
Fix Microsoft released MS16-014 that fixes this vulnerability. On 16-12-15 19:26, Securify B.V. wrote

[FD] Windows Mail Find People DLL side loading vulnerability

2016-03-08 Thread Securify B.V.
Windows Mail Find People DLL side loading vulnerability Yorick Koster, September 2015 -

Re: [FD] Windows Mail Find People DLL side loading vulnerability

2016-03-09 Thread Securify B.V.
Hi Stefan, See below. On 09-03-16 12:48, Stefan Kanthak wrote: "Securify B.V." wrote: Windows Mail Find People DLL side loading vul

[FD] .NET Framework 4.6 allows side loading of Windows API Set DLL

2016-04-12 Thread Securify B.V.
.NET Framework 4.6 allows side loading of Windows API Set DLL Yorick Koster, February 2016

[FD] EMC M&R (Watch4net) lacks Cross-Site Request Forgery protection

2016-04-27 Thread Securify B.V.
EMC M&R (Watch4net) lacks Cross-Site Request Forgery protection Han Sahin, November 2014 --

[FD] Microsoft Visio multiple DLL side loading vulnerabilities

2016-06-15 Thread Securify B.V.
Microsoft Visio multiple DLL side loading vulnerabilities Yorick Koster, August 2015 --

[FD] Craft CMS affected by server side template injection

2016-06-27 Thread Securify B.V.
Craft CMS affected by server side template injection Nelson Berg & Jurgen Kloosterman, June 2016 --

[FD] Persistent Cross-Site Scripting in WP Live Chat Support plugin

2016-07-11 Thread Securify B.V.
Persistent Cross-Site Scripting in WP Live Chat Support plugin Han Sahin, July 2016 ---

[FD] DLL side loading vulnerability in VMware Host Guest Client Redirector

2016-08-05 Thread Securify B.V.
DLL side loading vulnerability in VMware Host Guest Client Redirector Yorick Koster, December 2015

[FD] Internet Explorer iframe sandbox local file name disclosure vulnerability

2016-08-09 Thread Securify B.V.
Internet Explorer iframe sandbox local file name disclosure vulnerability Yorick Koster, March 2016 ---

[FD] Authentication bypass vulnerability in Western Digital My Cloud

2017-02-08 Thread Securify B.V.
Authentication bypass vulnerability in Western Digital My Cloud Remco Vermeulen, Januari 2017 -

[FD] Multiple persistent Cross-Site Scripting vulnerabilities in osTicket

2017-02-28 Thread Securify B.V.
Multiple persistent Cross-Site Scripting vulnerabilities in osTicket Han Sahin, July 2016 -

[FD] Adobe Reader for Android exposes insecure Javascript interfaces

2014-04-13 Thread Securify B.V.
Adobe Reader for Android exposes insecure Javascript interfaces Yorick Koster, April 2014 -

Re: [FD] Bypassing Content-Disposition: attachment for XSS on Chrome/Safari(IOS 6.x)

2014-07-30 Thread Securify B.V.
This issue was originally reported as CVE-2011-3426. We can confirm that Mobile Safari on iOS 7.1.2 is still affected. We've reported this to Apple on February 25, 2014. You can test is yourself at: http://www.securify.nl/cve-2011-3426.html This test page sets the following HTTP headers: Conte

Re: [FD] Bypassing Content-Disposition: attachment for XSS on Chrome/Safari(IOS 6.x)

2014-07-30 Thread Securify B.V.
Attached is a screenshot that demonstrates this issue on Yahoo! Mail. Despite the Content-Disposition header, (HTML) attachments are rendered by Mobile Safari. On 30-07-14 19:01, Securify B.V. wrote: This issue was originally reported as CVE-2011-3426. We can confirm that Mobile Safari on

[FD] Outlook.com for Android fails to validate server certificates

2014-08-17 Thread Securify B.V.
Outlook.com for Android fails to validate server certificates Yorick Koster, April 2014 ---

[FD] Glype proxy cookie jar path traversal allows code execution

2014-09-22 Thread Securify B.V.
Glype proxy cookie jar path traversal allows code execution Securify, September 2014 --

[FD] Glype proxy privacy settings can be disabled via CSRF

2014-09-22 Thread Securify B.V.
Glype proxy privacy settings can be disabled via CSRF Securify, September 2014

[FD] Glype proxy privacy settings can be disabled via CSRF

2014-09-22 Thread Securify B.V.
Glype proxy privacy settings can be disabled via CSRF Securify, September 2014

[FD] Glype proxy local address filter bypass

2014-09-22 Thread Securify B.V.
Glype proxy local address filter bypass Securify, September 2014 Abstract

[FD] Cisco RV Series multiple vulnerabilities

2014-11-06 Thread Securify B.V.
Cisco RV Series multiple vulnerabilities Yorick Koster, June 2013 Abstract ---

[FD] Websense Data Security DLP incident Forensics Preview is vulnerable to Cross-Site Scripting

2015-03-18 Thread Securify B.V.
Websense Data Security DLP incident Forensics Preview is vulnerable to Cross-Site Scripting Han Sahin, September 2014 -

[FD] Websense Email Security vulnerable to persistent Cross-Site Scripting in audit log details view

2015-03-18 Thread Securify B.V.
Websense Email Security vulnerable to persistent Cross-Site Scripting in audit log details view Han Sahin, September 2014 -

[FD] Command injection vulnerability in network diagnostics tool of Websense Appliance Manager

2015-03-18 Thread Securify B.V.
Command injection vulnerability in network diagnostics tool of Websense Appliance Manager Han Sahin, September 2014 ---

[FD] Source code disclosure of Websense Triton JSP files via double quote character

2015-03-18 Thread Securify B.V.
Source code disclosure of Websense Triton JSP files via double quote character Han Sahin, September 2014 --

[FD] Missing access control on Websense Explorer web folder

2015-03-18 Thread Securify B.V.
Missing access control on Websense Explorer web folder Han Sahin, September 2014 --

[FD] Cross-Site Scripting vulnerability in Websense Data Security block page

2015-03-18 Thread Securify B.V.
Cross-Site Scripting vulnerability in Websense Data Security block page Han Sahin, September 2014 -

[FD] Cross-Site Scripting vulnerability in Websense Explorer report scheduler

2015-03-18 Thread Securify B.V.
Cross-Site Scripting vulnerability in Websense Explorer report scheduler Han Sahin, September 2014

[FD] Multiple Cross-Site Scripting vulnerabilities in Websense Reporting

2015-03-18 Thread Securify B.V.
Multiple Cross-Site Scripting vulnerabilities in Websense Reporting Han Sahin, September 2014 -

[FD] Error messages of Websense Content Gateway are vulnerable to Cross-Site Scripting

2015-03-18 Thread Securify B.V.
Error messages of Websense Content Gateway are vulnerable to Cross-Site Scripting Han Sahin, September 2014 ---

[FD] EMC M&R (Watch4net) data storage collector credentials are not properly protected

2015-03-18 Thread Securify B.V.
EMC M&R (Watch4net) data storage collector credentials are not properly protected Han Sahin, November 2014

[FD] Cross-Site Scripting vulnerability in EMC M&R (Watch4net) Web Portal Report Favorites

2015-03-18 Thread Securify B.V.
Cross-Site Scripting vulnerability in EMC M&R (Watch4net) Web Portal Report Favorites Han Sahin, November 2014

[FD] Cross-Site Scripting vulnerability in EMC M&R (Watch4net) Centralized Management Console

2015-03-18 Thread Securify B.V.
Cross-Site Scripting vulnerability in EMC M&R (Watch4net) Centralized Management Console Han Sahin, November 2014 -

[FD] Cross-Site Scripting vulnerability in EMC M&R (Watch4net) Alerting Frontend

2015-03-18 Thread Securify B.V.
Cross-Site Scripting vulnerability in EMC M&R (Watch4net) Alerting Frontend Han Sahin, November 2014 --

[FD] Path traversal vulnerability in EMC M&R (Watch4net) MIB Browser

2015-03-18 Thread Securify B.V.
Path traversal vulnerability in EMC M&R (Watch4net) MIB Browser Han Sahin, November 2014 --

[FD] Path traversal vulnerability in EMC M&R (Watch4net) Device Discovery

2015-03-18 Thread Securify B.V.
Path traversal vulnerability in EMC M&R (Watch4net) Device Discovery Han Sahin, November 2014 -

[FD] Command injection vulnerability in EMC Secure Remote Services Virtual Edition

2015-03-18 Thread Securify B.V.
Command injection vulnerability in EMC Secure Remote Services Virtual Edition Han Sahin, November 2014

[FD] EMC Secure Remote Services Virtual Edition Provisioning component is affected by SQL injection

2015-03-18 Thread Securify B.V.
EMC Secure Remote Services Virtual Edition Provisioning component is affected by SQL injection Han Sahin, November 2014 ---

[FD] Citrix Command Center allows downloading of configuration files

2015-03-19 Thread Securify B.V.
Citrix Command Center allows downloading of configuration files Han Sahin, August 2014

[FD] Advent JMX Servlet of Citrx Command Center is accessible to unauthenticated users

2015-03-19 Thread Securify B.V.
Advent JMX Servlet of Citrx Command Center is accessible to unauthenticated users Han Sahin, August 2014 --

[FD] Citrix NITRO SDK xen_hotfix page is vulnerable to Cross-Site Scripting

2015-03-19 Thread Securify B.V.
Citrix NITRO SDK xen_hotfix page is vulnerable to Cross-Site Scripting Han Sahin, August 2014 -

[FD] Command injection vulnerability in Citrix NITRO SDK xen_hotfix page

2015-03-19 Thread Securify B.V.
Command injection vulnerability in Citrix NITRO SDK xen_hotfix page Han Sahin, August 2014

[FD] Citrix NetScaler VPX help pages are vulnerable to Cross-Site Scripting

2015-03-19 Thread Securify B.V.
Citrix NetScaler VPX help pages are vulnerable to Cross-Site Scripting Han Sahin, August 2014 -

[FD] Viber for Android exposes insecure Javascript interface

2015-03-20 Thread Securify B.V.
Viber for Android exposes insecure Javascript interface Yorick Koster, April 2014 -

[FD] Reflected Cross-Site Scripting vulnerability in asdoc generated documentation

2015-04-07 Thread Securify B.V.
Reflected Cross-Site Scripting vulnerability in asdoc generated documentation Radjnies Bhansingh, March 2014 --

[FD] Command injection vulnerability in Synology Photo Station

2015-05-25 Thread Securify B.V.
Command injection vulnerability in Synology Photo Station Han Sahin, May 2015

[FD] Reflected Cross-Site Scripting in Synology DiskStation Manager

2015-05-25 Thread Securify B.V.
Reflected Cross-Site Scripting in Synology DiskStation Manager Han Sahin, May 2015

[FD] Synology Photo Station multiple Cross-Site Scripting vulnerabilities

2015-05-25 Thread Securify B.V.
Synology Photo Station multiple Cross-Site Scripting vulnerabilities Han Sahin, May 2015 --

[FD] Western Digital My Cloud vulnerable to multiple command injection vulnerabilities

2017-03-07 Thread Securify B.V.
Western Digital My Cloud vulnerable to multiple command injection vulnerabilities Remco Vermeulen, January 2017 ---

[FD] Western Digital My Cloud vulnerable to Cross-Site Request Forgery vulnerability

2017-03-07 Thread Securify B.V.
Western Digital My Cloud vulnerable to Cross-Site Request Forgery vulnerability Remco Vermeulen, January 2017 -

[FD] Stack-based buffer overflow in Western Digital My Cloud allows for remote code execution

2017-03-07 Thread Securify B.V.
Stack-based buffer overflow in Western Digital My Cloud allows for remote code execution Remco Vermeulen, January 2017

[FD] Microsoft Edge Fetch API allows setting of arbitrary request headers

2017-03-14 Thread Securify B.V.
Microsoft Edge Fetch API allows setting of arbitrary request headers Yorick Koster, January 2017 --

[FD] Multiple local privilege escalation vulnerabilities in Proxifier for Mac

2017-04-11 Thread Securify B.V.
Multiple local privilege escalation vulnerabilities in Proxifier for Mac Yorick Koster, April 2017

[FD] Microsoft Office OneNote 2007 DLL side loading vulnerability

2017-04-11 Thread Securify B.V.
Microsoft Office OneNote 2007 DLL side loading vulnerability Yorick Koster, September 2015

[FD] Persistent Cross-Site Scripting in Scriptler Jenkins Plugin

2017-04-14 Thread Securify B.V.
Persistent Cross-Site Scripting in Scriptler Jenkins Plugin Burak Kelebek, April 2017 -

[FD] Authentication bypass vulnerability in Western Digital My Cloud allows escalation to admin privileges

2017-04-22 Thread Securify B.V.
Authentication bypass vulnerability in Western Digital My Cloud allows escalation to admin privileges Remco Vermeulen, April 2017 -

[FD] Multiple local privilege escalation vulnerabilities in HideMyAss Pro VPN client v2.x for OS X

2017-04-29 Thread Securify B.V.
Multiple local privilege escalation vulnerabilities in HideMyAss Pro VPN client v2.x for OS X Han Sahin, April 2017 ---

[FD] Local privilege escalation vulnerability in HideMyAss Pro VPN client v3.x for macOS

2017-04-29 Thread Securify B.V.
Local privilege escalation vulnerability in HideMyAss Pro VPN client v3.x for macOS Han Sahin, April 2017 -

[FD] SyntaxHighlight MediaWiki extension allows injection of arbitrary Pygments options

2017-04-29 Thread Securify B.V.
SyntaxHighlight MediaWiki extension allows injection of arbitrary Pygments options Yorick Koster, February 2017 ---

Re: [FD] SyntaxHighlight MediaWiki extension allows injection of arbitrary Pygments options

2017-05-01 Thread Securify B.V.
MediaWiki version 1.28.2 and version 1.27.3 were release that include a fix for this issue. https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000209.html On 29-04-17 16:41, Securify B.V. wrote

[FD] InsomniaX loader allows loading of arbitrary Kernel Extensions

2017-07-02 Thread Securify B.V. via Fulldisclosure
InsomniaX loader allows loading of arbitrary Kernel Extensions Yorick Koster, April 2017 --

[FD] Buffer over-read vulnerability in Virtuozzo Power Panel (VZPP) and Automator

2017-07-05 Thread Securify B.V. via Fulldisclosure
Buffer over-read vulnerability in Virtuozzo Power Panel (VZPP) and Automator Sipke Mellema, July 2017 -

[FD] Xamarin Studio for Mac API documentation update affected by local privilege escalation

2017-08-14 Thread Securify B.V. via Fulldisclosure
Xamarin Studio for Mac API documentation update affected by local privilege escalation Yorick Koster, April 2017 --

[FD] Clickjacking vulnerability in CSRF error page pfSense

2017-11-22 Thread Securify B.V. via Fulldisclosure
Clickjacking vulnerability in CSRF error page pfSense Yorick Koster, November 2017

[FD] bugt...@securityfocus.com

2017-11-22 Thread Securify B.V. via Fulldisclosure
Clickjacking vulnerability in CSRF error page pfSense Yorick Koster, November 2017

[FD] Arbitrary file read in Kaseya VSA

2018-01-13 Thread Securify B.V. via Fulldisclosure
Arbitrary file read in Kaseya VSA Kin Hung Cheng, Robert Hartshorn, May 2017 A

[FD] Code execution in Kaseya VSA

2018-01-13 Thread Securify B.V. via Fulldisclosure
Code execution in Kaseya VSA Kin Hung Cheng, Robert Hartshorn, May 2017 Abstra

[FD] Authentication bypass in Kaseya VSA

2018-01-13 Thread Securify B.V. via Fulldisclosure
Authentication bypass in Kaseya VSA Kin Hung Cheng, Robert Hartshorn, May 2017

[FD] Cross-Site Scripting vulnerability in Zimbra Collaboration Suite due to the way it handles attachment links

2018-03-24 Thread Securify B.V. via Fulldisclosure
Cross-Site Scripting vulnerability in Zimbra Collaboration Suite due to the way it handles attachment links Stephan Kaag, January 2018

[FD] Authentication bypass vulnerability in Western Digital My Cloud allows escalation to admin privileges

2018-09-18 Thread Securify B.V. via Fulldisclosure
Authentication bypass vulnerability in Western Digital My Cloud allows escalation to admin privileges Remco Vermeulen, September 2018 -

[FD] Ivanti Workspace Control Application Whitelist bypass via PowerGrid /RWS command line argument

2018-10-01 Thread Securify B.V. via Fulldisclosure
Ivanti Workspace Control Application Whitelist bypass via PowerGrid /RWS command line argument Yorick Koster, August 2018 -

[FD] Ivanti Workspace Control local privilege escalation via Named Pipe

2018-10-01 Thread Securify B.V. via Fulldisclosure
Ivanti Workspace Control local privilege escalation via Named Pipe Yorick Koster, August 2018 -

[FD] Ivanti Workspace Control Data Security bypass via localhost UNC path

2018-10-01 Thread Securify B.V. via Fulldisclosure
Ivanti Workspace Control Data Security bypass via localhost UNC path Yorick Koster, August 2018 ---

[FD] Stored credentials Ivanti Workspace Control can be retrieved from Registry

2018-10-01 Thread Securify B.V. via Fulldisclosure
Stored credentials Ivanti Workspace Control can be retrieved from Registry Yorick Koster, August 2018 -

[FD] Ivanti Workspace Control Application Whitelist bypass via PowerGrid /SEE command line argument

2018-10-01 Thread Securify B.V. via Fulldisclosure
Ivanti Workspace Control Application Whitelist bypass via PowerGrid /SEE command line argument Yorick Koster, August 2018 -

[FD] ZoneAlarm TrueVector Internet Monitor service insecure NTFS permissions vulnerability

2020-03-17 Thread Securify B.V. via Fulldisclosure
ZoneAlarm TrueVector Internet Monitor service insecure NTFS permissions vulnerability Yorick Koster, December 2019 -

[FD] Unauthorized access to QRadar configuration sets via default password

2020-04-21 Thread Securify B.V. via Fulldisclosure
Unauthorized access to QRadar configuration sets via default password Yorick Koster, September 2019

[FD] QRadar RssFeedItem Server-Side Request Forgery vulnerability

2020-04-21 Thread Securify B.V. via Fulldisclosure
QRadar RssFeedItem Server-Side Request Forgery vulnerability Yorick Koster, September 2019 -

  1   2   >