Subscribe via feed.
Archive for June, 2016

[dos] – OS X Kernel – OOB Read of Object Pointer Due to Insufficient Checks in Raw Cast to enum Type

Posted by deepcore under Security (No Respond)

OS X Kernel – OOB Read of Object Pointer Due to Insufficient Checks in Raw Cast to enum Type

Tags: ,

[dos] – OS X Kernel – Exploitable NULL Dereference in CoreCaptureResponder Due to Unchecked Return Value

Posted by deepcore under Security (No Respond)

OS X Kernel – Exploitable NULL Dereference in CoreCaptureResponder Due to Unchecked Return Value

Tags: ,

[dos] – OS X Kernel – Use-After-Free Due to Bad Locking in IOAcceleratorFamily2

Posted by deepcore under Security (No Respond)

OS X Kernel – Use-After-Free Due to Bad Locking in IOAcceleratorFamily2

Tags: ,

[dos] – OS X Kernel – Exploitable NULL Pointer Dereference in AppleMuxControl.kext

Posted by deepcore under Security (No Respond)

OS X Kernel – Exploitable NULL Pointer Dereference in AppleMuxControl.kext

Tags: ,

[dos] – OS X/iOS Kernel – UAF Racing getProperty on IOHDIXController and testNetBootMethod on IOHDIXControllerUserClient

Posted by deepcore under Security (No Respond)

OS X/iOS Kernel – UAF Racing getProperty on IOHDIXController and testNetBootMethod on IOHDIXControllerUserClient

Tags: ,

[dos] – OS X Kernel – Stack Buffer Overflow in GeForce GPU Driver

Posted by deepcore under Security (No Respond)

OS X Kernel – Stack Buffer Overflow in GeForce GPU Driver

Tags: ,

[dos] – OS X Kernel – Exploitable NULL Dereference in IOAccelSharedUserClient2::page_off_resource

Posted by deepcore under Security (No Respond)

OS X Kernel – Exploitable NULL Dereference in IOAccelSharedUserClient2::page_off_resource

Tags: ,

http://cri1.go.th

Posted by deepcore under Security (No Respond)

http://cri1.go.th notified by Av3LoXiS

Tags:

[webapps] – Drale DBTableViewer 100123 – Blind SQL Injection

Posted by deepcore under Security (No Respond)

Drale DBTableViewer 100123 – Blind SQL Injection

Tags: ,

ManageEngine SelfService Plus Cross Site Scripting

Posted by deepcore under exploit (No Respond)

ManageEngine SelfService Plus build 5312 (Mar 2016) and prior suffer from a cross site scripting vulnerability.