Subscribe via feed.
Archive for December, 2016

GNU Netcat 0.7.1 Out-Of-Bounds Write

Posted by deepcore under exploit (No Respond)

GNU Netcat version 0.7.1 suffers from an out-of-bounds array write.

Apache CouchDB 2.0.0 Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

Apache CouchDB sets weak file permissions potentially allowing ‘Standard’ Windows users to elevate privileges. The “nssm.exe” (Apache CouchDB) executable can be replaced by a ‘Standard’ non administrator user, allowing them to add a backdoor Administrator account once the “Apache CouchDB” service is restarted or system rebooted. As Apache CouchDB runs as LOCALSYSTEM, standard users can […]

Microsoft Event Viewer 1.0 XXE Injection

Posted by deepcore under exploit (No Respond)

Microsoft Event Viewer version 1.0 suffers from an XML external entity (XXE) injection vulnerability that allows for file exfiltration.

Alcatel Lucent Omnivista 8770 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Alcatel Lucent Omnivista 8770 suffers from a remote code execution vulnerability.

Microsoft Authorization Manager 6.1.7601 XXE Injection

Posted by deepcore under exploit (No Respond)

Microsoft Authorization Manager version 6.1.7601 suffers from an XML external entity (XXE) injection vulnerability that allows for file exfiltration.

BlackStratus LOGStorm 4.5.1.35 / 4.5.1.96 Remote Root

Posted by deepcore under exploit (No Respond)

BlackStratus LOGStorm has multiple vulnerabilities that allow a remote unauthenticated user, among other things, to assume complete control over the virtual appliance with root privileges. This is possible due to multiple network servers listening for network connections by default, allowing authorization with undocumented credentials supported by appliance’s OS, web interface and sql server. Versions 4.5.1.35 […]

http://www.namkeaw.go.th/index.php

Posted by deepcore under defacement (No Respond)

http://www.namkeaw.go.th/index.php notified by Tamil_Pasanga_Hackers

Tags:

Android IOMXNodeInstance::enableNativeBuffers Unchecked Index

Posted by deepcore under exploit (No Respond)

The code in IOMXNodeInstance.cpp that handles enableNativeBuffers uses port_index without validation, leading to writing the dword value 0 or 1 at an attacker controlled offset from the IOMXNodeInstance structure.

Xfinity Gateway Remote Code Execution

Posted by deepcore under exploit (No Respond)

Xfinity Gateway suffers from a remote code execution vulnerability.

Apache ActiveMQ 5.11.1 / 5.13.2 Directory Traversal / Command Execution

Posted by deepcore under exploit (No Respond)

Apache ActiveMQ versions 5.11.1 and 5.13.2 suffer from command execution and directory traversal vulnerabilities.