#Xiaomi advisories by Taszk
labs.taszk.io ->
labs.taszk.io ->
labs.taszk.io ->
It seems there is some exceptionally dump vendor policy is in the works so #NoCVE
Original->
Remote Pre-Auth Buffer Overflow in GNU Inetutils telnetd (LINEMODE SLC)
seclists.org ->
#NoCVE yet?
Original->
[RSS] When NAS Vendors Forget How TLS Works
www.interruptlabs.co.uk ->
#QNAP #Synology #Pwn2Own #NoCVE
Original->
[RSS] Python - Zip64 Locator Offset Vulnerability
github.com ->
#NoCVE
Original->
[RSS] Keiro Control authentication bypass (0-day?) #NoCVE
ssd-disclosure.com ->
Original->
[oss-security] Roundcube webmail: Post-Auth RCE via PHP Object Deserialization reported by firs0v /by @hanno
www.openwall.com ->
#NoCVE
Original->
[RSS] Protecting Windows users from Janet Jackson's Rhythm Nation
devblogs.microsoft.com ->
#NoCVE
Original->
[RSS] Finding an Unauthenticated RCE nday in Zendto, patched quietly in 2021. Lots of vulnerable instances exposed to the internet.
projectblack.io ->
#NoCVE
Original->
This is the out-of-bands read, that didn't get a CVE apparently:
github.com ->
#PHP #NoCVE
Original->
[RSS] Pwn everything Bounce everywhere all at once (part 2)
blog.quarkslab.com ->
New pre-auth RCE exploit chains for old SOPlanning bugs #NoCVE
Original->