Subscribe via feed.
Archive for November, 2016

FreeFloat FTP Server 1.0 RENAME Buffer Overflow

Posted by deepcore under exploit (No Respond)

FreeFloat FTP server version 1.0 suffers from a RENAME command related buffer overflow vulnerability.

PCMan FTP Server 2.0.7 UMASK Buffer Overflow

Posted by deepcore under exploit (No Respond)

PCMan FTP server version 2.0.7 suffers from a UMASK command related buffer overflow vulnerability.

Caph 1.1 Local Denial Of Service

Posted by deepcore under exploit (No Respond)

Caph version 1.1 suffers from a local buffer overflow vulnerability that can cause a denial of service.

MySQL / MariaDB / PerconaDB Privilege Escalation / Race Condition

Posted by deepcore under exploit (No Respond)

An independent research has revealed a race condition vulnerability which affects MySQL, MariaDB and PerconaDB databases. The vulnerability can allow a local system user with access to the affected database in the context of a low-privileged account (CREATE/INSERT/SELECT grants) to escalate their privileges and execute arbitrary code as the database system user (typically ‘mysql’).

Mini Notice Board 1.1 SQL Injection

Posted by deepcore under exploit (No Respond)

Mini Notice Board version 1.1 suffers from a remote SQL injection vulnerability.

Mini Notice Board 1.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Mini Notice Board version 1.1 suffers from a cross site scripting vulnerability.

Microsoft Internet Explorer 11 MSHTML CView::CalculateImageImmunity Use-After-Free

Posted by deepcore under exploit (No Respond)

Setting the listStyleImage property of an Element object causes MSIE 11 to allocate 0x4C bytes for an “image context” structure, which contains a reference to the document object as well as a reference to the same CMarkup object as the document. When the element is removed from the document/document fragment, this image context is freed […]

Alienvault OSSIM/USM 5.3.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Alienvault OSSIM/USM versions 5.3.1 and below suffer from a cross site scripting vulnerability.

Alienvault OSSIM/USM 5.3.1 SQL Injection

Posted by deepcore under exploit (No Respond)

Alienvault OSSIM/USM versions 5.3.1 and below suffer from a remote SQL injection vulnerability.

Alienvault OSSIM/USM 5.3.1 Persistent Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Alienvault OSSIM/USM versions 5.3.1 and below suffer from a stored cross site scripting vulnerability.