Subscribe via feed.
Archive for March, 2016

PivotX 2.3.11 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

PivotX version 2.3.11 suffers from a reflective cross site scripting vulnerability.

PivotX 2.3.11 Directory Traversal

Posted by deepcore under exploit (No Respond)

PivotX version 2.3.11 suffers from a directory traversal vulnerability.

PivotX 2.3.11 Shell Upload

Posted by deepcore under exploit (No Respond)

PivotX version 2.3.11 suffers from a remote shell upload vulnerability.

BigTree 4.2.8 Object Injection / Improper Filename Sanitization

Posted by deepcore under exploit (No Respond)

BigTree version 4.2.8 suffers from object injection and improper filename sanitization.

Grandstream Wave 1.0.1.26 Update Redirection

Posted by deepcore under exploit (No Respond)

The Grandstream Wave application version 1.0.1.26 periodically queries the Grandstream server for app updates. If a new update is found, the app shows a notification to the user that either opens the app’s Google Play page or auto-downloads the APK file and opens it for installation. The update information is downloaded over an insecure connection […]

Microsoft Internet Explorer Read AV In MSHTML!Layout::LayoutBuilderDivider::BuildPageLayout

Posted by deepcore under exploit (No Respond)

Microsoft Internet Explorer has a read AV in MSHTML!Layout::LayoutBuilderDivider::BuildPageLayout issue.

Adobe Flash op_pushwith Incorrect Jit Optimization

Posted by deepcore under exploit (No Respond)

The avmplus bytecode verifier misses a control-flow path via op_pushwith throwing an exception allowing crafted bytecode to be incorrectly optimized which can trivially be abused to get code execution.

Windows Kernel ATMFD.DLL OTF Font Processing Stack Corruption

Posted by deepcore under exploit (No Respond)

There is a Windows kernel crash in the ATMFD.DLL OpenType driver while processing a corrupted OTF font file.

Windows Kernel ATMFD.DLL OTF Font Processing Stack Crash

Posted by deepcore under exploit (No Respond)

There is a Windows kernel crash in the ATMFD.DLL OpenType driver while processing a corrupted OTF font file.

Window Secondary Login Failed Sanitization

Posted by deepcore under exploit (No Respond)

The SecLogon service does not sanitize standard handles when creating a new process leading to duplicating a system service thread pool handle into a user accessible process. This can be used to elevate privileges to Local System.