Category Archives: Full Disclosure

Full Disclosure

Hacktivity 2015 CFP

Posted by Ferenc Spala on May 22

Hi all,

Please find our CFP below – would be great to see many submissions from you
😉

[ == Hacktivity 2015 Call For Papers == ]

Conference: October 9-10, 2015

CFP closing date: June 30, 2015

CFP notification to authors: July 31, 2015

Venue: Budapest, Hungary

Web: https://hacktivity.com

Email: cfp _!{at}!_ hacktivity.com

Twitter: @hacktivityconf

Hacktivity is the leading hacking conference in Hungary. Hacktivity brings
together…

SAP Security Notes May 2015

Posted by Darya Maenkova on May 22

SAP <http://www.sap.com/>has released the monthly critical patch update
for May 2015. This patch update closes a lot of vulnerabilities in SAP
products, some of them belong in the SAP HANA security area. This month,
three critical vulnerabilities found by ERPScan researchers Dmitry
Chastukhin and Vahagn Vardanyan were closed.

*Issues that were patched with the help of ERPScan*

The detailed list of corrected vulnerabilities that were…

[CORE-2015-0010] – Sendio ESP Information Disclosure Vulnerability

Posted by CORE Advisories Team on May 22

1. Advisory Information

Title: Sendio ESP Information Disclosure Vulnerability
Advisory ID: CORE-2015-0010
Advisory URL: http://www.coresecurity.com/advisories/sendio-esp-information-disclosure-vulnerability
Date published: 2015-05-22
Date of last update: 2015-05-22
Vendors contacted: Sendio
Release mode: Coordinated release

2. Vulnerability Information

Class: OWASP Top Ten 2013 Category A2 – Broken Authentication and Session Management…

CVE for Apple's ECDHE-ECDSA SecureTransport bug?

Posted by Jeffrey Walton on May 20

Does anyone know if Apple’s ECDHE-ECDSA SecureTransport bug was
assigned a CVE? It affected OS X and iOS.

Effectively, the bug was an implementation error that cause
interoperability failures. To mostly counter it, the cipher suites had
to be disabled, which resulted in a loss of security. If the person
experiencing it did not know the cause, then they were left with a
Denial of Service (DoS).

To be clear, this was a different bug than…

CVE ID assignment – eZPublish vulnerability

Posted by us3r777 on May 20

Hi,

I’m trying to get a CVE-ID attributed to the issue discribed bellow.

I tried to contact cve-assign () mitre org two times, on March 31 and on
May 11, but I did not get any answer.

The issue is now public and described here :
http://share.ez.no/community-project/security-advisories/ezsa-2015-001-potential-vulnerability-in-ez-publish-password-recovery

May someone attribute a CVE-ID to this vulnerability please ?

Description…

hardwear.io – Hardware Security Conference Call for Papers

Posted by Hardwear Team on May 20

Dear Hackers and Security Gurus,

hardwear is seeking innovative research on hardware security. If you
have done interesting research on attacks or mitigation on any
Hardware and want to showcase it to the security community, just
submit your research paper. Please find all the relevant details for
the submission below.

About hardwear.io
—————————-
Somewhere in the mid of last year, amidst all the news and concerns
surrounding…

Eisbär SCADA (All Versions – iOS, Android & W8) – Persistent UI Vulnerability

Posted by Vulnerability Lab on May 20

Document Title:
===============
Eisbär SCADA (All Versions – iOS, Android & W8) – Persistent UI Vulnerability

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1456

Release Date:
=============
2015-05-19

Vulnerability Laboratory ID (VL-ID):
====================================
1456

Common Vulnerability Scoring System:
====================================
5.2

Product & Service Introduction:…

Staff FTP v3.04 Software – DLL Hijacking Vulnerability

Posted by Vulnerability Lab on May 20

Document Title:
===============
Staff FTP v3.04 Software – DLL Hijacking Vulnerability

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1499

Release Date:
=============
2015-05-19

Vulnerability Laboratory ID (VL-ID):
====================================
1499

Common Vulnerability Scoring System:
====================================
6

Product & Service Introduction:…

WISE-FTP Software v8.0.2 – DLL Hijacking Vulnerability

Posted by Vulnerability Lab on May 20

Document Title:
===============
WISE-FTP Software v8.0.2 – DLL Hijacking Vulnerability

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1498

Release Date:
=============
2015-05-18

Vulnerability Laboratory ID (VL-ID):
====================================
1498

Common Vulnerability Scoring System:
====================================
6

Product & Service Introduction:…

HiDisk 2.4 iOS – (currentFolderPath) Persistent Vulnerability

Posted by Vulnerability Lab on May 20

Document Title:
===============
HiDisk 2.4 iOS – (currentFolderPath) Persistent Vulnerability

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1496

Release Date:
=============
2015-05-19

Vulnerability Laboratory ID (VL-ID):
====================================
1496

Common Vulnerability Scoring System:
====================================
3.5

Product & Service Introduction:…