Subscribe via feed.
Archive for November, 2016

Adobe Connect / Desktop 9.5.7 Script Insertion

Posted by deepcore under exploit (No Respond)

Adobe Connect and Desktop version 9.5.7 suffers from malicious script insertion vulnerabilities.

Samsung SW Update Service Privilege Escalation

Posted by deepcore under exploit (No Respond)

Samsung Software Update Service, SWUpdateService (SWMAgent.exe), installs as a service with an unquoted service path running with SYSTEM privileges. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system.

Verint Impact 360 11.1 Open Redirect

Posted by deepcore under exploit (No Respond)

Verint Impact 360 version 11.1 suffers from an open redirection vulnerability.

Droid4X Privilege Escalation

Posted by deepcore under exploit (No Respond)

Droid4XService (Droid4XService.exe) installs as a service with an unquoted service path running with SYSTEM privileges. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system.

PCMan FTP Server 2.0.7 LIST Buffer Overflow

Posted by deepcore under exploit (No Respond)

PCMan FTP server version 2.0.7 LIST command buffer overflow exploit.

VBScript RegExpComp::PnodeParse Out-Of-Bounds Read

Posted by deepcore under exploit (No Respond)

A specially crafted script can cause the VBScript engine to read data beyond a memory block for use as a regular expression. An attacker that is able to run such a script in any application that embeds the VBScript engine may be able to disclose information stored after this memory block. This includes all versions […]

e107 CMS 2.1.2 Privilege Escalation

Posted by deepcore under exploit (No Respond)

e107 CMS version 2.1.2 suffers from a privilege escalation vulnerability.

Nero 7.10.1.0 Privilege Escalation

Posted by deepcore under exploit (No Respond)

Nero version 7.10.1.0 suffers from an unquoted service path privilege escalation vulnerability.

Microsoft Internet Explorer 9 / 10 / 11 PROPERTYDESC::HandleStyleComponentProperty Out-Of-Bounds

Posted by deepcore under exploit (No Respond)

Microsoft Internet Explorer versions 9, 10, and 11 suffer from an MSHTML PROPERTYDESC::HandleStyleComponentProperty out-of-bounds read.

Exponent CMS 2.4.0 Blind SQL Injection

Posted by deepcore under exploit (No Respond)

Exponent CMS version 2.4.0 suffers from a remote blind SQL injection vulnerability.