Security Advisories
The Qualys Vulnerability and Malware Research Labs (VMRL) is tasked with the investigation of software packages to find new flaws. Once found, we work with the software owner to get the flaw registered (CVEs), and then we assist with the quickest resolution possible by providing detailed technical information, including proof of concept code.
This list of advisories provides insight into the specific vulnerabilities reported.
-
Sudo's get_process_ttyname() for Linux (CVE-2017-1000367)
linux_sudo_cve-2017-1000367.c - accompanying Sudoer-to-root exploit
-
D-Link DIR-615 Router Multiple Vulnerabilities (CVE-2017-7404, CVE-2017-7405 and CVE-2017-7406)
-
Manage Engine OpManager Multiple Security Vulnerabilities
-
Session Fixation Vulnerability in Sophos Secure Web Appliance
-
Insecure CrossDomain.XML in D-Link DCS Series Cameras
-
Multiple Vulnerabilities in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) 6.5.x
-
Accellion FTP Multiple Security Vulnerabilities
-
Sensitive Information Disclosure Vulnerability in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) 6.5.x
-
Multiple Vulnerabilities in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) 6.5.x
-
Netgear D6000 and D3600 hard-coded cryptographic keys authentication bypass (CVE-2015-8288, CVE-2015-8289)
-
OpenSSH (CVE-2016-0777 and CVE-2016-0778)
-
LibreSSL (CVE-2015-5333 and CVE-2015-5334)
-
OpenSMTPD Audit Report (CVE TBA)
-
userhelper chfn() newline filtering and libuser passwd file handling (CVE-2015-3245 and CVE-2015-3246)
roothelper.c - an unusual local root exploit
-
GHOST: glibc gethostbyname buffer overflow vulnerability (CVE-2015-0235)
-
Foscam Dynamic DNS Predictable Credentials Vulnerability (CVE-2014-1849)
-
ModSecurity and ModSecurity Core Rule Set Multipart Bypasses
-
Memory Corruption when Apple Quicktime Parses .pct File (CVE-2012-0671)
-
Memory Corruption when Adobe Shockwave Player Parses .dir Media File (CVE-2012-2031)
-
Memory Corruption when Adobe Shockwave Player Parses .dir Media File (CVE-2012-2030)
-
Memory Corruption when Adobe Shockwave Player Parses .dir Media File (CVE-2012-2029)
-
Adobe Reader All Versions Memory Corruption - APB11-16 (CVE-2011-2098)
-
Apache Reverse Proxy Security Bypass Vulnerability (CVE-2011-4317)