Subscribe via feed.
Archive for December, 2016

WordPress Google Analytics Counter Tracker 3.1.5 PHP Object Injection

Posted by deepcore under exploit (No Respond)

WordPress Google Analytics Counter Tracker plugin version 3.1.5 suffers from an unauthenticated PHP object injection vulnerability.

10-Strike Network File Search Pro 2.3 Buffer Overflow

Posted by deepcore under exploit (No Respond)

10-Strike Network File Search Pro version 2.3 SEH local buffer overflow exploit.

iOS 10.1.x Certificate File Memory Corruption

Posted by deepcore under exploit (No Respond)

iOS version 10.1.x suffers from certificate file memory corruption vulnerability.

Serva 3.0.0 HTTP Server Denial Of Service

Posted by deepcore under exploit (No Respond)

Serva 3.0.0 HTTP server suffers from a denial of service vulnerability.

XFINITY Gateway Technicolor DPC3941T Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

XFINITY Gateway Technicolor DPC3941T wifi password changing cross site request forgery proof of concept code.

Microsoft Internet Explorer 9 IEFRAME CSelectionInteractButtonBehavior::_UpdateButtonLocation Use-After-Free

Posted by deepcore under exploit (No Respond)

A specially crafted web-page can trigger a use-after-free vulnerability in Microsoft Internet Explorer 9.

TP-LINK TD-W8151N Denial Of Service

Posted by deepcore under exploit (No Respond)

TP-LINK TD-W8151N suffers from a denial of service vulnerability.

Joomla DT Register SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla DT Register component versions prior to 3.1.12 in Joomla 3.x and version 2.8.18 in Joomla 2.5 suffer from a remote SQL injection vulnerability.

apt Repository Signing Bypass

Posted by deepcore under exploit (No Respond)

apt suffers from a repository signing bypass via memory allocation failure.

Samsung Devices KNOX Extensions OTP TrustZone Trustlet Stack Buffer Overflow

Posted by deepcore under exploit (No Respond)

As a part of the KNOX extensions available on Samsung devices, Samsung provides a TrustZone trustlet which allows the generation of OTP tokens. The tokens themselves are generated in a TrustZone application within the TEE (UID: fffffffff0000000000000000000001e), which can be communicated with using the “OTP” service, published by “otp_server”. Many of the internal commands supported […]