Subscribe via feed.
Archive for May, 2016

Teampass v2.1.25 – Unauthenticated Access Vulnerability

Posted by deepcore under exploit (No Respond)

An independent vulnerability laboratory researcher discovered multiple vulnerabilities in the official Teampass v2.1.25 application.

Peplink InControl 2 CDM – (API) Persistent Vulnerability

Posted by deepcore under exploit (No Respond)

The vulnerability lab core team discovered an application-side web vulnerability in the official Peplink InControl 2 cloud based device managemet web-application.

AutoIT 3 DLL Hijacking

Posted by deepcore under exploit (No Respond)

AutoIT version 3 suffers from a dll hijacking vulnerability.

Microsoft Visual C++ DLL Hijacking

Posted by deepcore under exploit (No Respond)

Microsoft Visual C++ 2010 Redistributable Package and Visual C++ Redistributable for Visual Studio 2015 suffer from multiple dll hijacking vulnerabilities.

Microsoft Windows gdi32.dll ExtEscape() Buffer Overflow

Posted by deepcore under exploit (No Respond)

gdi32.dll in Microsoft Windows suffers from a heap-based buffer overflow in ExtEscape().

Symantec / Norton Antivirus Memory Corruption

Posted by deepcore under exploit (No Respond)

Symantec / Norton Antivirus suffers from a remote ring0 memory corruption vulnerability.

Microsoft Windows gdi32.dll Information Disclosure

Posted by deepcore under exploit (No Respond)

gdi32.dll in Microsoft Windows suffers from information disclosure issues via the EMF CREATECOLORSPACEW record handling.

Microsoft Windows gdi32.dll Data Copy

Posted by deepcore under exploit (No Respond)

gdi32.dll in Microsoft Windows suffers from a denial of service issue due to an attacker controlling the Size argument in the gdi32!GdiComment() function.

WSO2 SOA Enablement Server Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WSO2 SOA Enablement server suffers from a cross site scripting vulnerability.

Dell SonicWALL Scrutinizer 11.01 methodDetail SQL Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a vulnerability found in Dell SonicWALL Scrutinizer. The methodDetail parameter in exporters.php allows an attacker to write arbitrary files to the file system with an SQL Injection attack, and gain remote code execution under the context of SYSTEM for Windows, or as Apache for Linux. Authentication is required to exploit this […]