Full Disclosure: by author

24 messages starting Jan 27 25 and ending Jan 15 25
Date index | Thread index | Author index


Andrey Stoykov

Host Header Injection - atutorv2.2.4 Andrey Stoykov (Jan 27)
Reflected XSS - atutorv2.2.4 Andrey Stoykov (Jan 27)

Apple Product Security via Fulldisclosure

APPLE-SA-01-27-2025-2 iOS 18.3 and iPadOS 18.3 Apple Product Security via Fulldisclosure (Jan 27)
APPLE-SA-01-27-2025-3 iPadOS 17.7.4 Apple Product Security via Fulldisclosure (Jan 27)
APPLE-SA-01-27-2025-9 Safari 18.3 Apple Product Security via Fulldisclosure (Jan 27)
APPLE-SA-01-27-2025-1 visionOS 2.3 Apple Product Security via Fulldisclosure (Jan 27)
APPLE-SA-01-27-2025-7 watchOS 11.3 Apple Product Security via Fulldisclosure (Jan 27)
APPLE-SA-01-27-2025-4 macOS Sequoia 15.3 Apple Product Security via Fulldisclosure (Jan 27)
APPLE-SA-01-27-2025-8 tvOS 18.3 Apple Product Security via Fulldisclosure (Jan 27)
APPLE-SA-01-27-2025-5 macOS Sonoma 14.7.3 Apple Product Security via Fulldisclosure (Jan 27)
APPLE-SA-01-27-2025-6 macOS Ventura 13.7.3 Apple Product Security via Fulldisclosure (Jan 27)

Asterisk Development Team

[asterisk-dev] Asterisk Security Release 21.6.1 Asterisk Development Team (Jan 15)
[asterisk-dev] Asterisk Security Release 20.11.1 Asterisk Development Team (Jan 15)

Asterisk Development Team via Fulldisclosure

Asterisk Security Release 18.26.1 Asterisk Development Team via Fulldisclosure (Jan 15)
Certified Asterisk Security Release certified-20.7-cert4 Asterisk Development Team via Fulldisclosure (Jan 15)
Certified Asterisk Security Release certified-18.9-cert13 Asterisk Development Team via Fulldisclosure (Jan 15)
Asterisk Security Release 22.1.1 Asterisk Development Team via Fulldisclosure (Jan 15)

David Fifield

Text injection on https://www.google.com/sorry/index via ?q parameter (no XSS) David Fifield (Jan 29)

Georgi Guninski

Deepseek writes textbook insecure code in 2025-01-28 Georgi Guninski (Jan 29)

Rodolfo Tavares via Fulldisclosure

CVE-2024-48463 Rodolfo Tavares via Fulldisclosure (Jan 15)

SEC Consult Vulnerability Lab via Fulldisclosure

SEC Consult SA-20250127-0 :: Weak Password Hashing Algorithms in Wind River Software VxWorks RTOS SEC Consult Vulnerability Lab via Fulldisclosure (Jan 27)

Shaikh Shahnawaz

AutoLib Software Systems OPAC Version.20.10 | Exposure of Sensitive Information | CVE-2024-48310 Shaikh Shahnawaz (Jan 27)
Quorum onQ OS - 6.0.0.5.2064 | Reflected Cross Site Scripting (XSS) | CVE-2024-44449 Shaikh Shahnawaz (Jan 29)

Thomas Weber | CyberDanube via Fulldisclosure

CyberDanube Security Research 20250107-0 | Multiple Vulnerabilities in ABB AC500v3 Thomas Weber | CyberDanube via Fulldisclosure (Jan 15)