Subscribe via feed.
Archive for May, 2017

Apple iOS / OS X NSKeyedArchiver Memory Corruption

Posted by deepcore under Apple (No Respond)

Apple iOS / OS X suffer from a NSKeyedArchiver memory corruption vulnerability due to a lack of bounds checking in CAMediaTimingFunctionBuiltin.

Tags: , ,

Apple MacOS HIServices Privilege Escalation

Posted by deepcore under Apple (No Respond)

Apple MacOS suffers from a local elevation of privilege vulnerability due to a lack of bounds checking in HIServices custom CFObject serialization.

Tags: , ,

http://amnatpao.go.th

Posted by deepcore under defacement (No Respond)

http://amnatpao.go.th notified by Con7ext

Tags:

WordPress Contentive Theme – Cross Site Web Vulnerability

Posted by deepcore under exploit (No Respond)

An independent vulnerability laboratory researcher discovered a cross site scripting vulnerability in the official Conte…

Lufthansa AG – (Limbo) Open Redirect Web Vulnerability

Posted by deepcore under exploit (No Respond)

The vulnerability laboratory core research team discovered a open redirect vulnerability in the official Lufthansa Move …

MediaWiki SyntaxHighlight Extension Option Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an option injection vulnerability in the SyntaxHighlight extension of MediaWiki. It tries to create and execute a PHP file in the document root. The USERNAME and PASSWORD options are only needed if the Wiki is configured as private. This vulnerability affects any MediaWiki installation with SyntaxHighlight version 2.0 installed and enabled. […]

Sync Breeze Enterprise GET Buffer Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a stack-based buffer overflow vulnerability in the web interface of Sync Breeze Enterprise v9.4.28, caused by improper bounds checking of the request path in HTTP GET requests sent to the built-in web server. This Metasploit module has been tested successfully on Windows 7 SP1 x86.

HP SimplePass 8.x Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

HP SimplePass versions 8.00.49, 8.00.57, and 8.01.46 suffers from a local privilege escalation vulnerability.

VMWare Horizon 5.4 DLL Hijacking

Posted by deepcore under exploit (No Respond)

VMWare Horizon client version 5.4 suffers from a dll hijacking vulnerability.

Asterisk 14.4.0 PJSIP 2.6 Heap Overflow

Posted by deepcore under exploit (No Respond)

Asterisk version 14.4.0 with PJSIP version 2.6 suffers from a heap overflow vulnerability in CSEQ header parsing.