Subscribe via feed.
Archive for March, 2016

Adobe (Edex) – Client Side Cross Site Scripting Vulnerability

Posted by deepcore under exploit (No Respond)

The Vulnerability Laboratory Core Research Team discovered a client-side cross site scripting web vulnerability in the official Adobe Edex online service web-application.

Coppermine 1.5.40 Weak Cryptography

Posted by deepcore under exploit (No Respond)

Coppermine version 1.5.40 uses straight MD5 without any salt for storage of passwords.

Libxml2 XmlParseEndTag2 Heap-Based Buffer Overread

Posted by deepcore under exploit (No Respond)

A crash due to a heap-based out-of-bounds memory read can be observed in an ASAN build of latest stable libxml2 (2.9.3, released 4 days ago), by feeding a malformed file to xmllint.

Libxml2 XmlDictAddString Heap-Based Buffer Overread

Posted by deepcore under exploit (No Respond)

A crash due to a heap-based out-of-bounds memory read can be observed in an ASAN build of latest stable libxml2 (2.9.3, released 4 days ago), by feeding a malformed file to xmllint.

Libxml2 XmlParserPrintFileContextInternal Heap-Based Buffer Overread

Posted by deepcore under exploit (No Respond)

A crash due to a heap-based out-of-bounds memory read can be observed in an ASAN build of latest stable libxml2 (2.9.3, released 4 days ago), by feeding a malformed file to xmllint.

Libxml2 HtmlCurrentChar Heap-Based Buffer Overread

Posted by deepcore under exploit (No Respond)

A crash due to a heap-based out-of-bounds memory read can be observed in an ASAN build of latest stable libxml2 (2.9.3, released 4 days ago), by feeding a malformed file to xmllint.

Comodo Anti-Virus GeekBuddy DLL Hijacking

Posted by deepcore under exploit (No Respond)

The Comodo Anti-Virus GeekBuddy component suffers from a dll hijacking vulnerability.

Pulse CMS 4.5.2 Local File Inclusion

Posted by deepcore under exploit (No Respond)

Pulse CMS version 4.5.2 suffers from a local file inclusion vulnerability.

WP Good News Themes Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WP Good News Themes suffers from a client-side cross site scripting vulnerability.

Fing 3.3.0 Persistent Mail Encoding

Posted by deepcore under exploit (No Respond)

Fing version 3.3.0 suffers from a persistent mail encoding vulnerability.