Compass Security News

Here you will find reports, interviews and news. We give you an insight into our work and report on 0day (zero-day) vulnerabilities discovered by our staff on customer projects or in their research time.

 

Stephan Sekula identified vulnerabilities in the OfficeSpace facility management software.

Read more

Thierry Viaccoz identified an incorrectly designed access control in Homeputer CL Studio for HomeMatic.

Read more

Lukasz D. identified an HTTP header injection vulnerability in Vert.x Framework.

Read more

Nicolas Heiniger identified vulnerabilities in totemomail Encryption Gateway.

Read more

Stephan Sekula has identified a design vulnerability in Microsoft Intune that may allow getting access to confidential information.

Read more

Stephan Sukula identified a design vulnerability in Microsoft Intune that allows bypassing the app PIN protection.

Read more

Damian Pfammatter and Alessandro Zala identified an XSS vulnerability in Zimbra Collaboration Suite.

Read more

Sylvain Heiniger identified an XSS vulnerability in GitLab CE+EE

Read more

Nicolas Heiniger identified vulnerabilities in MyTy.

Read more

Benjamin Bruppbacher identified an XML External Entity Attack in the iText PDF Library.

Read more

In recent months, Compass Security has supervised two scientific projects by students at the University of Applied Sciences Rapperswil HSR.

Read more

Dobin Rutishauser identified a stack based buffer overflow in the Mongoose Embedded Web Server Library.

Read more