Subscribe via feed.
Archive for February, 2017

Adobe Flash Bitmapfilter Use-After-Free

Posted by deepcore under exploit (No Respond)

Adobe Flash suffers from a use-after-free vulnerability in applying bitmapfilter.

Adobe Flash YUVPlane Decoding Heap Overflow

Posted by deepcore under exploit (No Respond)

Adobe Flash suffers from a heap overflow vulnerability during YUVPLane decoding.

Adobe Flash SWF Stack Corruption

Posted by deepcore under exploit (No Respond)

Adobe Flash suffers from a stack corruption vulnerability using a fuzzed SWF file.

Adobe Flash MP4 AMF Parsing Overflow

Posted by deepcore under exploit (No Respond)

Adobe Flash suffers from an overflow vulnerability during MP4 AMF parsing.

dotCMS 3.6.1 Blind Boolean SQL Injection

Posted by deepcore under exploit (No Respond)

dotCMS versions 3.6.1 and below suffer from a remote blind boolean SQL injection vulnerability.

QNAP QTS 4.2.x XSS / Command Injection / Transport Issues

Posted by deepcore under exploit (No Respond)

QNAP QTS firmware contain missing transport layer security, improper certificate validation, command injection, cross site scripting, and information disclosure vulnerabilities that can be exploited to gain remote command execution to the devices or to perform arbitrary administrative functions, and to gain unauthorized access to user’s myQNAPcloud credentials.

Trendmicro InterScan 6.5-SP2_Build_Linux_1548 Arbitrary File Write

Posted by deepcore under exploit (No Respond)

Trendmicro InterScan version 6.5-SP2_Build_Linux_1548 suffers from an arbitrary file write vulnerability that can lead to remote command execution.

Trendmicro InterScan 6.5-SP2_Build_Linux_1548 Privilege Escalation

Posted by deepcore under exploit (No Respond)

Trendmicro InterScan version 6.5-SP2_Build_Linux_1548 suffers from a privilege escalation vulnerability.

Trendmicro InterScan 6.5-SP2_Build_Linux_1548 Remote Root

Posted by deepcore under exploit (No Respond)

Trendmicro InterScan version 6.5-SP2_Build_Linux_1548 suffers from a remote root access vulnerability.

OpenText Documentum Content Server 7.3 SQL Injection

Posted by deepcore under exploit (No Respond)

OpenText Documentum Content Server version 7.3 suffers from a remote SQL injection vulnerability due to a previously announced fix being incomplete.