Subscribe via feed.
Archive for March, 2018

Contec Smart Home 4.15 Insecure Direct Object Reference

Posted by deepcore under exploit (No Respond)

Contec Smart Home version 4.15 suffers from insecure direct object reference vulnerabilities.

Linux Kernel Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

Linux Kernel versions prior to 4.4.0-116 (Ubuntu 16.04.4) local privilege escalation exploit.

WordPress Site Editor 1.1.1 Local File Inclusion

Posted by deepcore under exploit (No Respond)

WordPress Site Editor plugin version 1.1.1 suffers from a local file inclusion vulnerability.

Grav CMS 1.2.4 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Grav CMS version 1.2.4 suffers from a cross site scripting vulnerability.

Easy Chat Server 3.1 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Easy Chat Server version 3.1 remote buffer overflow exploit.

Kamailio 5.1.1 / 5.1.0 / 5.0.0 Heap Overflow

Posted by deepcore under exploit (No Respond)

Kamailio versions 5.1.1, 5.1.0, and 5.0.0 suffer from an off-by-one heap overflow vulnerability.

[papers] Windows Kernel Exploitation Tutorial Part 7: Uninitialized Heap Variable

Posted by deepcore under Security (No Respond)

Windows Kernel Exploitation Tutorial Part 7: Uninitialized Heap Variable

Tags: ,

Microsoft Intune Design Weakness

Posted by deepcore under Apple (No Respond)

Compass Security discovered a design weakness in Microsoft Intune’s iOS Keychain management. This allows users to access company data even after the device has been unenrolled.

Tags: , ,

[dos] Kamailio 5.1.1 / 5.1.0 / 5.0.0 – Off-by-One Heap Overflow

Posted by deepcore under Security (No Respond)

Kamailio 5.1.1 / 5.1.0 / 5.0.0 – Off-by-One Heap Overflow

Tags: ,

[local] Google Software Updater macOS – Unsafe use of Distributed Objects Privilege Escalation

Posted by deepcore under Security (No Respond)

Google Software Updater macOS – Unsafe use of Distributed Objects Privilege Escalation

Tags: ,