NCC Group Research Blog
Technical Advisory – play-pac4j Authentication rule bypass
4 months ago
Technical Advisory – OpenJDK – Weak Parsing Logic in java.net.InetAddress and Related Classes
4 months ago
Technical Advisory – OpenOffice.org Multiple Memory Corruption Vulnerabilities
4 months ago
Technical Advisory – NXP i.MX SDP_READ_DISABLE Fuse Bypass (CVE-2022-45163)
4 months ago
Technical Advisory – Open5GS Stack Buffer Overflow During PFCP Session Establishment on UPF (CVE-2021-41794)
4 months ago
Technical Advisory – New York State Excelsior Pass Vaccine Passport Scanner App Sends Data to a Third Party not Specified in Privacy Policy
4 months ago
Technical Advisory – Nullsoft Scriptable Installer System (NSIS) – Insecure Temporary Directory Usage
4 months ago
Technical Advisory – Multiple Vulnerabilities in the Galaxy App Store (CVE-2023-21433, CVE-2023-21434)
4 months ago
Technical Advisory – Multiple Vulnerabilities in U-Boot (CVE-2022-30790, CVE-2022-30552)
4 months ago
Technical Advisory – New York State Excelsior Pass Vaccine Passport Credential Forgery
4 months ago
Technical Advisory – Multiple Vulnerabilities in Connectize G6 AC2100 Dual Band Gigabit WiFi Router (CVE-2023-24046, CVE-2023-24047, CVE-2023-24048, CVE-2023-24049, CVE-2023-24050, CVE-2023-24051, CVE-2023-24052)
4 months ago
Technical Advisory – Multiple vulnerabilities in Nuki smart locks (CVE-2022-32509, CVE-2022-32504, CVE-2022-32502, CVE-2022-32507, CVE-2022-32503, CVE-2022-32510, CVE-2022-32506, CVE-2022-32508, CVE-2022-32505)
4 months ago
Technical Advisory – macOS Installer Local Root Privilege Escalation (CVE-2020-9817)
4 months ago
Technical Advisory – Multiple HTML Injection Vulnerabilities in KaiOS Pre-installed Mobile Applications
4 months ago
Technical Advisory – Linux RDS Protocol Local Privilege Escalation
4 months ago
Technical Advisory – Lenovo ImController Local Privilege Escalation (CVE-2021-3922, CVE-2021-3969)
4 months ago
Technical Advisory – libraptor – XXE in RDF/XML File Interpretation
4 months ago
Technical Advisory – Kwikset/Weiser BLE Proximity Authentication in Kevo Smart Locks Vulnerable to Relay Attacks
4 months ago
Technical Advisory – KwikTag Web Admin Authentication Bypass
4 months ago
Checked
2 hours 31 minutes ago