Subscribe via feed.
Archive for September, 2015

WordPress Vertical Image Slider 1.0 CSRF / XSS

Posted by deepcore under exploit (No Respond)

WordPress Vertical Image Slider plugin version 1.0 suffers from cross site request forgery and cross site scripting vulnerabilities.

VBox Satellite Express Arbitrary Write Privilege Escalation

Posted by deepcore under exploit (No Respond)

A vulnerability within the ndvbs module allows an attacker to inject memory they control into an arbitrary location they define. This vulnerability can be used to overwrite function pointers in HalDispatchTable resulting in an elevation of privilege. suffers from code execution, and local file inclusion vulnerabilities.

Konica Minolta FTP Utility 1.00 Post Auth CWD Command SEH Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an SEH overflow in Konica Minolta FTP Server 1.00. Konica Minolta FTP fails to check input size when parsing ‘CWD’ commands, which leads to an SEH overflow. Konica FTP allows anonymous access by default; valid credentials are typically unnecessary to exploit this vulnerability.

OS X IOKit Kernel Memory Corruption

Posted by deepcore under Apple (No Respond)

An OS X IOKit kernel memory corruption issue occurs due to a bad bzero in IOBluetoothDevice.

Tags: , ,

Apple Security Advisory 2015-09-16-1

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2015-09-16-1 – iOS 9 is now available and addresses denial of service, information disclosure, and various other issues.

Tags: , ,

Apple Security Advisory 2015-09-16-2

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2015-09-16-2 – Xcode 7.0 is now available and addresses traffic inspection, access bypass, and various other vulnerabilities.

Tags: , ,

Apple Security Advisory 2015-09-16-3

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2015-09-16-3 – iTunes 12.3 is now available and addresses code execution, application termination, memory corruption, and various other vulnerabilities.

Tags: , ,

Apple Security Advisory 2015-09-16-4

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2015-09-16-4 – OS X Server 5.0.3 is now available and addresses denial of service, code execution, and various other vulnerabilities.

Tags: , ,

[webapps] – ADH-Web Server IP-Cameras – Multiple Vulnerabilities

Posted by deepcore under Security (No Respond)

ADH-Web Server IP-Cameras – Multiple Vulnerabilities

Tags: ,

[remote] – Thomson CableHome Gateway (DWG849) Cable Modem Gateway – Information Exposure

Posted by deepcore under Security (No Respond)

Thomson CableHome Gateway (DWG849) Cable Modem Gateway – Information Exposure

Tags: ,