Subscribe via feed.
Archive for May, 2018

Nanopool Claymore Dual Miner 7.3 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Nanopool Claymore Dual Miner version 7.3 suffers from a remote code execution vulnerability.

Intelbras NCLOUD 300 1.0 Authentication Bypass

Posted by deepcore under exploit (No Respond)

Intelbras NCLOUD 300 version 1.0 suffers from an authentication bypass vulnerability.

AF_PACKET packet_set_ring Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a heap-out-of-bounds write in the packet_set_ring function in net/packet/af_packet.c (AF_PACKET) in the Linux kernel to execute code as root (CVE-2017-7308). The bug was initially introduced in 2011 and patched in version 4.10.6, potentially affecting a large number of kernels; however this exploit targets only systems using Ubuntu Xenial kernels 4.8.0 < […]

[local] Prime95 29.4b8 – Stack Buffer Overflow (SEH)

Posted by deepcore under Security (No Respond)

Prime95 29.4b8 – Stack Buffer Overflow (SEH)

Tags: ,

[dos] Microsoft Edge Chakra JIT – Bound Check Elimination Bug

Posted by deepcore under Security (No Respond)

Microsoft Edge Chakra JIT – Bound Check Elimination Bug

Tags: ,

[webapps] SAP B2B / B2C CRM 2.x < 4.x – Local File Inclusion

Posted by deepcore under Security (No Respond)

SAP B2B / B2C CRM 2.x < 4.x – Local File Inclusion

Tags: ,

[local] Linux 4.8.0 < 4.8.0-46 – AF_PACKET packet_set_ring Privilege Escalation (Metasploit)

Posted by deepcore under Security (No Respond)

Linux 4.8.0 < 4.8.0-46 – AF_PACKET packet_set_ring Privilege Escalation (Metasploit)

Tags: ,

[remote] HPE iMC 7.3 – Remote Code Execution (Metasploit)

Posted by deepcore under Security (No Respond)

HPE iMC 7.3 – Remote Code Execution (Metasploit)

Tags: ,

[webapps] SAP NetWeaver Web Dynpro 6.4 to 7.5 – Information disclosure

Posted by deepcore under Security (No Respond)

SAP NetWeaver Web Dynpro 6.4 to 7.5 – Information disclosure

Tags: ,

[webapps] Monstra CMS before 3.0.4 – Cross-Site Scripting

Posted by deepcore under Security (No Respond)

Monstra CMS before 3.0.4 – Cross-Site Scripting

Tags: ,