Subscribe via feed.
Archive for January, 2016

WiX Toolset DLL Hijacking

Posted by deepcore under exploit (No Respond)

WiX Toolset installers suffer from a DLL hijacking vulnerability.

xwpe 1.5.30a-2.1 Buffer Overflow

Posted by deepcore under exploit (No Respond)

xwpe versions 1.5.30a-2.1 and below are prone to a stack-based buffer overflow vulnerability because the application fails to perform adequate boundary-checks on user-supplied input.

Avast Sandbox/Autosandbox Message Filtering Vulnerable To MS13-005

Posted by deepcore under exploit (No Respond)

Avast Sandbox/Autosandbox message filtering suffers from a flaw that allows for privilege escalation.

Apple Security Advisory 2016-01-19-1

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2016-01-19-1 – iOS 9.2.1 is now available and addresses memory corruption and privacy issues.

Tags: , ,

Apple Security Advisory 2016-01-19-2

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2016-01-19-2 – OS X El Capitan 10.11.3 and Security Update 2016-001 are now available and address memory corruption, code execution, and privilege escalation vulnerabilities.

Tags: , ,

Apple Security Advisory 2016-01-19-3

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2016-01-19-3 – Safari 9.0.3 is now available and addresses privacy and multiple memory corruption vulnerabilities.

Tags: , ,

Python 3.5.1 DLL Hijacking

Posted by deepcore under exploit (No Respond)

Python version 3.5.1 installers suffer from a DLL hijacking vulnerability.

FreeBSD bsnmpd Information Disclosure

Posted by deepcore under exploit (No Respond)

FreeBSD suffers from a bsnmpd information disclosure vulnerability.

Amanda 3.3.1 amstar Command Injection

Posted by deepcore under exploit (No Respond)

Amanda versions 3.3.1 and below amstar command injection local root exploit #2.

TCExam 12.2.5 Information Disclosure

Posted by deepcore under exploit (No Respond)

TCExam versions 12.2.5 and below suffer from a correct answer information disclosure vulnerability.