Full Disclosure: by author

31 messages starting Jan 05 26 and ending Jan 05 26
Date index | Thread index | Author index


Agent Spooky's Fun Parade via Fulldisclosure

Linux Kernel Block Subsystem Vulnerabilities Agent Spooky's Fun Parade via Fulldisclosure (Jan 05)

Andrey Stoykov

Weak Password Complexity - elggv6.3.3 Andrey Stoykov (Jan 29)
Username Enumeration - elggv6.3.3 Andrey Stoykov (Jan 29)
Paper-Exploiting XAMPP Installations Andrey Stoykov (Jan 29)

Art Manion via Fulldisclosure

Re: Multiple Security Misconfigurations and Customer Enumeration Exposure in Convercent Whistleblowing Platform (EQS Group) Art Manion via Fulldisclosure (Jan 10)

BUG

OpenMetadata <= 1.11.3 Authenticated SQL Injection BUG (Jan 21)

duykham

Security Vulnerability in Koller Secret: Real Hidden App (com.koller.secret.hidemyphoto) duykham (Jan 05)

Karol Wrótniak

CVE-2025-12758: Unicode Variation Selectors Bypass in 'validator' library (isLength) Karol Wrótniak (Jan 29)

KoreLogic Disclosures via Fulldisclosure

KL-001-2026-01: yintibao Fun Print Mobile Unauthorized Access via Context Hijacking KoreLogic Disclosures via Fulldisclosure (Jan 08)

malvuln

SigInt-Hombre v1 / dynamic Suricata detection rules from real-time threat feeds malvuln (Jan 05)

Marco Ermini via Fulldisclosure

Re: Multiple Security Misconfigurations and Customer Enumeration Exposure in Convercent Whistleblowing Platform (EQS Group) Marco Ermini via Fulldisclosure (Jan 26)

Matteo Beccati

[REVIVE-SA-2026-001] Revive Adserver Vulnerabilities Matteo Beccati (Jan 14)

Ron E

RIOT OS 2026.01-devel-317 Stack-Based Buffer Overflow in tapslip6 Utility via Unbounded Device Path Construction Ron E (Jan 10)
TinyOS 2.1.2 printfUART Global Buffer Overflow via Unbounded Format Expansion Ron E (Jan 10)
Panda3d v1.10.16 egg-mkfont Stack Buffer Overflow Ron E (Jan 05)
TinyOS 2.1.2 Stack-Based Buffer Overflow in mcp2200gpio Ron E (Jan 10)
Bioformats v8.3.0 Improper Restriction of XML External Entity Reference in Bio-Formats Leica Microsystems XML Parser Ron E (Jan 05)
zlib v1.3.1.2 Global Buffer Overflow in TGZfname() of zlib untgz Utility via Unbounded strcpy() on User-Supplied Archive Name Ron E (Jan 05)
Bioformats v8.3.0 Untrusted Deserialization of Bio-Formats Memoizer Cache Files Ron E (Jan 05)
Panda3d v1.10.16 deploy-stub Unbounded Stack Allocation Leading to Uninitialized Memory Ron E (Jan 05)
RIOT OS 2026.01-devel-317 Stack-Based Buffer Overflow in RIOT ethos Serial Frame Parser Ron E (Jan 10)
MongoDB v8.3.0 Heap Buffer Underflow in OpenLDAP LMDB mdb_load Ron E (Jan 05)
Panda3d v1.10.16 Uncontrolled Format String in Panda3D egg-mkfont Allows Stack Memory Disclosure Ron E (Jan 05)
MongoDB v8.3.0 Integer Underflow in LMDB mdb_load Ron E (Jan 05)

SEC Consult Vulnerability Lab via Fulldisclosure

SEC Consult SA-20260126-2 :: UART Leaking Sensitive Data in dormakaba registration unit 9002 (PIN pad) SEC Consult Vulnerability Lab via Fulldisclosure (Jan 26)
SEC Consult SA-20260126-1 :: Multiple Critical Vulnerabilities in dormakaba Access Manager SEC Consult Vulnerability Lab via Fulldisclosure (Jan 26)
SEC Consult SA-20260126-0 :: Multiple Critical Vulnerabilities in dormakaba Kaba exos 9300 SEC Consult Vulnerability Lab via Fulldisclosure (Jan 26)

Stefan Kanthak via Fulldisclosure

Defense in depth -- the Microsoft way (part 95): the (shared) "Start Menu" is dispensable Stefan Kanthak via Fulldisclosure (Jan 10)

Wade Sparks

Re: Multiple Security Misconfigurations and Customer Enumeration Exposure in Convercent Whistleblowing Platform (EQS Group) Wade Sparks (Jan 21)

Yuffie Kisaragi via Fulldisclosure

Re: Multiple Security Misconfigurations and Customer Enumeration Exposure in Convercent Whistleblowing Platform (EQS Group) Yuffie Kisaragi via Fulldisclosure (Jan 26)
Multiple Security Misconfigurations and Customer Enumeration Exposure in Convercent Whistleblowing Platform (EQS Group) Yuffie Kisaragi via Fulldisclosure (Jan 05)