Subscribe via feed.
Archive for September, 2017

Microsoft Windows Kernel TTF Font Processing Out-Of-Bounds

Posted by deepcore under exploit (No Respond)

The Microsoft Windows kernel win32k.sys TTF font procession functionality suffers from out-of-bounds read/write vulnerabilities.

Microsoft Windows Kernel TTF Font Processing glyf Out-Of-Bounds Read

Posted by deepcore under exploit (No Respond)

The Microsoft Windows kernel win32k.sys TTF font processing suffers from an out-of-bounds read vulnerability with a malformed glyf table.

Microsoft Windows Kernel win32k!NtGdiGetFontResourceInfoInternalW Memory Disclosure

Posted by deepcore under exploit (No Respond)

The Microsoft Windows kernel suffers from a stack memory disclosure vulnerability in win32k!NtGdiGetFontResourceInfoInternalW.

Microsoft Windows Kernel win32k!NtGdiEngCreatePalette Memory Disclosure

Posted by deepcore under exploit (No Respond)

The Microsoft Windows kernel suffers from a stack memory disclosure vulnerability in win32k!NtGdiEngCreatePalette.

Microsoft Edge COptionsCollectionCacheItem::GetAt Out-Of-Bounds Read

Posted by deepcore under exploit (No Respond)

There is an out-of-bounds read issue in Microsoft Edge that could potentially be turned into remote code execution. The vulnerability has been confirmed on Microsoft Edge 38.14393.1066.0 (Microsoft EdgeHTML 14.14393) as well as Microsoft Edge 40.15063.0.0 (Microsoft EdgeHTML 15.15063).

Microsoft Windows Kernel win32k!NtGdiDoBanding Memory Disclosure

Posted by deepcore under exploit (No Respond)

The Microsoft Windows kernel suffers from a stack memory disclosure vulnerability in win32k!NtGdiDoBanding.

Microsoft Windows Kernel win32k!NtQueryCompositionSurfaceBinding Memory Disclosure

Posted by deepcore under exploit (No Respond)

The Microsoft Windows kernel suffers from a stack memory disclosure vulnerability in win32k!NtQueryCompositionSurfaceBinding.

Microsoft Edge Partial Page Loading Memory Corruption

Posted by deepcore under exploit (No Respond)

There is a security issue in Microsoft Edge related to how HTML documents are loaded. If Edge displays a HTML document from a slow HTTP server, it is possible that a part of the document is going to be rendered before the server has finished sending the document. It is also possible that some JavaScript […]

DlxSpot SQL Injection

Posted by deepcore under exploit (No Respond)

DlxSpot Player4 LED video wall suffers from a remote SQL injection vulnerability that allows for authentication bypass. Versions greater than 1.5.10 are affected.

DlxSpot Shell Upload

Posted by deepcore under exploit (No Respond)

DlxSpot Player4 LED video wall suffers from a remote shell upload vulnerability. Versions greater than 1.5.10 are affected.