Subscribe via feed.
Archive for January, 2017

Microsoft Power Point Java Payload Code Execution

Posted by deepcore under exploit (No Respond)

Microsoft power point allows users to insert objects of arbitrary file types. At presentation time these objects can be activated by mouse movement or clicking.

PageKit 1.0.10 Password Reset

Posted by deepcore under exploit (No Respond)

PageKit version 1.0.10 suffers from a password reset vulnerability.

Oracle E-Business Suite 12.x Unconstrainted File Download

Posted by deepcore under exploit (No Respond)

Oracle E-Business Suite versions 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6 suffer from an unconstrained file download vulnerability.

Python 2.x Buffer Overflow

Posted by deepcore under exploit (No Respond)

Python version 2.x suffers from a buffer overflow in the DecodeAdpcmImaQT function in the ctypes module.

Microsoft Remote Desktop Client For Mac 8.0.36 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Microsoft Remote Desktop Client for Mac version 8.0.36 suffers from a remote code execution vulnerability.

Oracle PeopleSoft HCM 9.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Oracle PeopleSoft HCM version 9.2 suffers from a cross site scripting vulnerability.

Oracle OpenJDK Runtime Environment Build 1.8.0_112-b15 Denial Of Service

Posted by deepcore under exploit (No Respond)

Oracle OpenJDK Runtime Environment build 1.8.0_112-b15 suffers from a java serialization denial of service vulnerability.

CUPS DNS Rebinding Via Incorrect Whitelist

Posted by deepcore under exploit (No Respond)

CUPS suffers from an incorrect whitelist that permits DNS rebinding attacks.

Cisco Magic WebEx URL Remote Command Execution

Posted by deepcore under exploit (No Respond)

Cisco’s WebEx extension has a URL that allows for arbitrary remote command execution.

Firefox nsSMILTimeContainer::NotifyTimeChange() Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an out-of-bounds indexing/use-after-free condition present in nsSMILTimeContainer::NotifyTimeChange() across numerous versions of Mozilla Firefox on Microsoft Windows.