Subscribe via feed.
Archive for July, 2016

Adobe Flash ATF Processing Overflow

Posted by deepcore under exploit (No Respond)

This ATF file causes a heap overflow in ATF processing in Adobe Flash.

Adobe Flash JXR Processing Double Free

Posted by deepcore under exploit (No Respond)

This JXR file causes a heap overflow when loaded in Adobe Flash.

Adobe Flash ATF Image Packing Overflow

Posted by deepcore under exploit (No Respond)

There is a heap overflow in ATF image packing. The file included in this archive demonstrates the vulnerability.

BMW Client-Side Cross Site Scripting

Posted by deepcore under exploit (No Respond)

The BMW online web application suffers from a cross site scripting vulnerability.

Notepad++ 6.9.2 DLL Hijacking

Posted by deepcore under exploit (No Respond)

The installer for Notepad++ version 6.9.2 suffers from a dll hijacking vulnerability.

JetBrains PyCharm Professional 2016.1.4 DLL Hijacking

Posted by deepcore under exploit (No Respond)

JetBrains PyCharm Professional 2016.1.4 suffers from a dll hijacking vulnerability.

PaX Reference Count Overflow Mitigation Bypass

Posted by deepcore under exploit (No Respond)

PaX contains a mitigation for reference count overflows that is intended to prevent atomic_t variables from reaching 0x80000000 and, more importantly, wrapping around to zero. A documented special case on x86 is that, because “atomically increment unless current value is X” cannot be implemented without a cmpxchg loop, the code instead increments the counter, checks […]

BMW ConnectedDrive Session Validation

Posted by deepcore under exploit (No Respond)

A session validation approval web vulnerability has been discovered in the official BMW ConnectedDrive online service web application. The vulnerability allows remote attackers to manipulate specific configured parameters to compromise the affected web application service.

PHP Real Estate Script 3 Arbitrary File Disclosure

Posted by deepcore under exploit (No Respond)

PHP Real Estate Script version 3 suffers from a file disclosure vulnerability.

Adobe Flash LMZA Property Decoding Heap Corruption

Posted by deepcore under exploit (No Respond)

This archive contains an images that causes heap corruption in Adobe Flash due to LMZA property decoding.