Subscribe via feed.
Archive for August, 2017

Microsoft Edge Chakra Parser::ParseFncFormals Uninitialized Arguments

Posted by deepcore under exploit (No Respond)

Microsoft Edge Chakra suffers from an uninitialized arguments vulnerability in Parser::ParseFncFormals with the “PNodeFlags::fpnArguments_overriddenInParam” flag.

Microsoft Edge Chakra EmitNew Integer Overflow

Posted by deepcore under exploit (No Respond)

Microsoft Edge Chakra suffers from an integer overflow vulnerability in EmitNew.

Microsoft Edge Chakra Incorrect Jit Optimization

Posted by deepcore under exploit (No Respond)

Yet another finding that the fix for an incorrect jit optimization with TypedArray setter in Microsoft Edge Chakra may not be sufficient.

Adobe Flash Invoke Accesses Trait Out-Of-Bounds

Posted by deepcore under exploit (No Respond)

The included proof of concept file causes the traits of an ActionScript object to be accessed out of bounds in Adobe Flash. This can probably lead to exploitable type confusion.

OSNEXUS QuantaStor 4 Information Disclosure

Posted by deepcore under exploit (No Respond)

OSNEXUS QuantaStor version 4 suffers from multiple information disclosure vulnerabilities including user enumeration.

Internet Download Manager 6.28 Build 17 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Internet Download Manager version 6.28 Build 17 SEH unicode buffer overflow exploit.

ClipBucket 2.8.3 SQL Injection / Arbitrary File Read / Write

Posted by deepcore under exploit (No Respond)

ClipBucket version2.8.3 suffers from remote SQL injection, arbitrary file read/write, and default credential vulnerabilities.

ALLPlayer 7.4 Buffer Overflow

Posted by deepcore under exploit (No Respond)

ALLPlayer version 7.4 SEH unicode buffer overflow exploit.

AdvanDate iCupid Dating Software 12.2 SQL Injection

Posted by deepcore under exploit (No Respond)

AdvanDate iCupid Dating software version 12.2 suffers from a remote SQL injection vulnerability.

FreeBSD 10.3 Jail SHM Issue

Posted by deepcore under exploit (No Respond)

FreeBSD jail incompletely protects the access to the IPC primitives. The ‘allow.sysvipc’ setting only affects IPC queues, leaving other IPC objects unprotected, making them reachable system-wide independently of the system configuration. Versions 7.0 through 10.3 are affected. Proof of concept included.