Subscribe via feed.
Archive for December, 2016

McAfee Virus Scan Enterprise For Linux Remote Code Execution

Posted by deepcore under exploit (No Respond)

McAfee Virus Scan Enterprise for Linux suffers from a remote code execution vulnerability.

Apple Security Advisory 2016-12-12-1

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2016-12-12-1 – iOS 10.2 is now available and addresses information disclosure, access bypass, and various other vulnerabilities.

Tags: , ,

Apple Security Advisory 2016-12-12-2

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2016-12-12-2 – watchOS 3.1.1 is now available and addresses code execution and authorization issues.

Tags: , ,

Apple Security Advisory 2016-12-12-3

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2016-12-12-3 – tvOS 10.1 is now available and addresses a memory corruption vulnerability.

Tags: , ,

Roundcube 1.2.2 Command Execution

Posted by deepcore under exploit (No Respond)

Roundcube version 1.2.2 suffers from a command execution vulnerability via email.

Microsoft Internet Explorer MSHTML CDispNode::InsertSiblingNode Use-After-Free

Posted by deepcore under exploit (No Respond)

A specially crafted web-page can trigger a memory corruption vulnerability in Microsoft Internet Explorer 9.

Bluemix Container Authorization Controls

Posted by deepcore under exploit (No Respond)

Bluemix containers have a broken access control that allows auditors to create and delete containers.

Microsoft Internet Explorer 9 MSHTML CElement::HasFlag Memory Corruption

Posted by deepcore under exploit (No Respond)

Microsoft Internet Explorer 9 suffers from an MSHTML CElement::HasFlag memory corruption vulnerability.

Splunk Enterprise 6.4.3 Server-Side Request Forgery

Posted by deepcore under exploit (No Respond)

Splunk Enterprise versions 6.4.3 and below suffer from a server-side request forgery vulnerability.

Symantec VIP Access Arbitrary DLL Execution

Posted by deepcore under exploit (No Respond)

Symantec VIP Access versions prior to 2.2.2 suffer from an arbitrary dll execution vulnerability.