Subscribe via feed.
Archive for November, 2015

Windows NtCreateLowBoxToken Handle Capture Local DoS/Elevation Of Privilege

Posted by deepcore under exploit (No Respond)

Last Updated on November 3, 2015 by deepcore The NtCreateLowBoxToken API allows the capture of arbitrary handles which can lead to to local denial of service or elevation of privilege.

Milton Webdav 2.7.0.1 XXE Injection

Posted by deepcore under exploit (No Respond)

Last Updated on November 3, 2015 by deepcore Milton Webdav version 2.7.0.1 suffers from an XXE injection vulnerability.

Python 2.7 strop.replace() Integer Overflow

Posted by deepcore under exploit (No Respond)

Last Updated on November 3, 2015 by deepcore Python version 2.7 strop.replace() method suffers from an integer overflow that can be exploited to write outside the bounds of the string buffer and potentially achieve code execution. The issue can be triggered by performing a large substitution that overflows the arithmetic used in mymemreplace() to calculate […]

Python 2.7 array.fromstring Use After Free

Posted by deepcore under exploit (No Respond)

Last Updated on November 3, 2015 by deepcore Python 2.7 array.fromstring() method suffers from a use after free caused by unsafe realloc use. The issue is triggered when an array is concatenated to itself via fromstring() call.

Python 2.7 Hotshot pack_string Heap Buffer Overflow

Posted by deepcore under exploit (No Respond)

Last Updated on November 3, 2015 by deepcore Python version 2.7 hotshot module suffers from a heap buffer overflow due to a memcpy in the pack_string function at line 633.

Spetnik TCPing Utility 2.1.0 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Last Updated on November 3, 2015 by deepcore If TCPing is called with an specially crafted CL argument it will cause an exception and overwrite the pointers to next SEH record and SEH handler with our buffer and malicious shellcode. Spetnik TCPing version 2.1.0 is affected.

actiTIME 2015.2 Privilege Escalation / Open Redirect

Posted by deepcore under exploit (No Respond)

Last Updated on November 3, 2015 by deepcore actiTIME 2015.2 suffers from multiple security vulnerabilities including open redirection, HTTP response splitting, and unquoted service path elevation of privilege.

Packet Storm New Exploits For October, 2015

Posted by deepcore under exploit (No Respond)

Last Updated on November 3, 2015 by deepcore This archive contains 166 exploits that were added to Packet Storm in October, 2015.

[dos] – Samsung libQjpeg Image Decoding Memory Corruption

Posted by deepcore under Security (No Respond)

Last Updated on November 3, 2015 by deepcore Samsung libQjpeg Image Decoding Memory Corruption

Tags: ,

[dos] – Samsung Galaxy S6 – android.media.process Face Recognition Memory Corruption

Posted by deepcore under Security (No Respond)

Last Updated on November 3, 2015 by deepcore Samsung Galaxy S6 – android.media.process Face Recognition Memory Corruption

Tags: ,