[FD] Mozilla's MSI installers: FUBAR (that's spelled "fucked-up beyond all repair")

2019-07-09 Thread Stefan Kanthak
Hi @ll, Mozilla finally provides MSI installers for their just released Firefox 68 and Firefox 68 ESR for Windows:

[FD] PowerPanel Business Edition 3.4.0 - Cross Site Request Forgery

2019-07-09 Thread Joey Lane via Fulldisclosure
# Exploit Title: PowerPanel Business Edition 3.4.0 - Cross Site Request Forgery # Date: 7/9/2019 # Exploit Author: Joey Lane # Vendor Homepage: https://www.cyberpowersystems.com # Version: 3.4.0 # Tested on: Ubuntu 16.04 # CVE : CVE-2019-13071 # Reported to vendor on 5/25/2019, no acknowledgement.

[FD] Two vulnerabilities found in Sony BRAVIA Smart TVs

2019-07-09 Thread xen1thLabs
## ADVISORY INFORMATION TITLE: Two vulnerabilities found in Sony BRAVIA Smart TVs ADVISORY URL: CVE-2019-11889 https://www.darkmatter.ae/xen1thlabs/sony-remote-denial-of-service-triggered-over-vulnerability-hbbtv-xl-19-014/ CVE-2019-11890

[FD] Vulnerabilities in TP-Link TL-WR940N and TL-WR941ND

2019-07-09 Thread MustLive
Hello list! There are Brute Force and Cross-Site Request Forgery vulnerabilities in TP-Link TL-WR940N and TL-WR941ND. After my advisory about vulnerabilities in TP-Link TL-WR841N and TL-WR841ND in 2017. - Affected products: - Vulnerable are the

[FD] UPDATE: [SYSS-2019-021]: WolfVision Cynap - Use of Hard-coded Cryptographic Key (CWE-321) [CVE-2019-13352]

2019-07-09 Thread Matthias Deeg
Advisory ID: SYSS-2019-021 Product: Cynap Manufacturer: WolfVision Affected Version(s): 1.18g, 1.28j Tested Version(s): 1.18g, 1.28j Vulnerability Type: Use of Hard-coded Cryptographic Key (CWE-321) Risk Level: High Solution Status: Fixed Manufacturer Notification: 2019-05-03 Solution Date:

[FD] Polycom RealPresence Touch device vulnerable to Slowloris attack (hardware version 7; OS version 2.1.2-255)

2019-07-09 Thread Eitan shav
[Description] Polycom RealPresence Touch devices (hardware version 7; operating system version 2.1.2-255) allow remote attackers to cause a denial of service (networking outage) by sending "Slowloris" packet data to the login interface. [VulnerabilityType] Slowloris DoS [Vendor of

[FD] Razer Synapse 3, Laptops Ship with Re-used Root Certificate with Private Key

2019-07-09 Thread No One
Razer is a company that produces gaming-centric computer peripherals, laptops, desktops, and mobile phones. Many of their products allow for rich customization of device lighting effects. These features are managed by a client application called Synapse. On Windows, Razer Synapse 3 installs an