WordPress Emag Marketplace Connector 1.0 Cross Site Scripting
WordPress Emag Marketplace Connector plugin version 1.0 suffers from a cross site scripting vulnerability.
WordPress Emag Marketplace Connector plugin version 1.0 suffers from a cross site scripting vulnerability.
It is possible to add a cached signing level to an unsigned file by exploiting a TOCTOU in CI leading to circumvention of Device Guard policies and possibly PPL signing levels.
It was discovered that the nt!NtQueryDirectoryFile system call discloses portions of uninitialized pool memory to user-mode clients on Windows 10, due to uninitialized fields in the output structure being copied to the application.
WebKit – ‘WebCore::AXObjectCache::performDeferredCacheUpdate’ Use-After-Free
Tags: 0day, remote exploitWebKit – ‘WebCore::SimpleLineLayout::RunResolver::runForPoint’ Out-of-Bounds Read
Tags: 0day, remote exploitWebKit – ‘WebCore::SVGPatternElement::collectPatternAttributes’ Out-of-Bounds Read
Tags: 0day, remote exploit