Subscribe via feed.
Archive for January, 2016

Symantec Endpoint Protection 12.1.4013 Denial Of Service

Posted by deepcore under exploit (No Respond)

Symantec Endpoint Protection version 12.1.4013 suffers from a denial of service vulnerability.

o2 DSL Auto Configuration Server Credential Disclosure

Posted by deepcore under exploit (No Respond)

The o2 Auto Configuration Server (ACS) discloses VoIP/SIP credentials of arbitrary customers when receiving manipulated CWMP packets. These credentials can then be used by an attacker to register any VoIP number of the victim. This enables the attacker to place and receive calls on behalf of the attacked user.

Barracuda #38 Message Archiver – Multiple Vulnerabilities

Posted by deepcore under exploit (No Respond)

The vulnerability Laboratory Research Team has discovered multiple web validation vulnerabilities in the barracuda Message Archiver v650 Product.

Apple Security Advisory 2016-01-07-1

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2016-01-07-1 – QuickTime 7.7.9 is now available and addresses multiple memory corruption issues.

Tags: , ,

ownCloud 8.2.1 / 8.1.4 / 8.0.9 Information Exposure

Posted by deepcore under exploit (No Respond)

ownCloud versions 8.2.1 and below, 8.1.4 and below, and 8.0.9 and below suffer from an information exposure vulnerability via directory listings.

Emsisoft Anti Malware DLL Hijacking

Posted by deepcore under exploit (No Respond)

Emsisoft Anti Malware suffers from a DLL hijacking vulnerability.

ZoneAlarm DLL Hijacking

Posted by deepcore under exploit (No Respond)

ZoneAlarm installers suffer from a DLL hijacking vulnerability.

AVM FRITZ!Box: Arbitrary Code Execution Via Firmware Images

Posted by deepcore under exploit (No Respond)

The firmware upgrade process of the FRITZ!Box 7490 is flawed. Specially crafted firmware images can overwrite critical files. Arbitrary code can get executed if an attempt is made to install such a manipulated firmware. Versions prior to 6.30 are affected.

AVM FRITZ!Box: Buffer Overflow

Posted by deepcore under exploit (No Respond)

RedTeam Pentesting discovered that several models of the AVM FRITZ!Box are vulnerable to a stack-based buffer overflow, which allows attackers to execute arbitrary code on the device. Versions prior to 6.30 are affected.

OpenCart 2.1.0.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

OpenCart version 2.1.0.1 suffers from a cross site scripting vulnerability.