Subscribe via feed.
Archive for June, 2018

Microsoft Open Redirect

Posted by deepcore under exploit (No Respond)

dpa-fwl.microsoft.com suffers from an open redirection vulnerability.

10-Strike Network Inventory Explorer Standard 8.54 Registration Key Overflow

Posted by deepcore under exploit (No Respond)

10-Strike Network Inventory Explorer Standard version 8.54 suffers from a local buffer overflow vulnerability in the Enter Registration Key field.

Linux Kernel ext4_read_inline_data() Memory Corruption

Posted by deepcore under exploit (No Respond)

Linux Kernel versions prior to 4.16.11 suffer from an ext4_read_inline_data() memory corruption vulnerability.

MyBB Recent Threads 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

MyBB Recent Threads plugin version 1.0 suffer from a cross site scripting vulnerability.

Pagekit Cross Site Scripting Code Generator

Posted by deepcore under exploit (No Respond)

Pagekit versions prior to 1.0.13 suffer from a cross site scripting vulnerability.

Clone 2 GO Video Converter 2.8.2 Unicode Buffer Overflow

Posted by deepcore under exploit (No Respond)

Clone 2 GO Video Converter version 2.8.2 unicode buffer overflow remote code execution vulnerability.

Sint Wind PI 01.26.19 Authentication Bypass

Posted by deepcore under exploit (No Respond)

Sint Wind PI version 01.26.19 suffers from an authentication bypass vulnerability.

10-Strike Network Scanner 3.0 Local Buffer Overflow

Posted by deepcore under exploit (No Respond)

10-Strike Network Scanner version 3.0 suffers from a local buffer overflow vulnerability.

WebKitGTK+ 2.21.3 pageURL Mishandling Denial Of Service

Posted by deepcore under exploit (No Respond)

webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp in WebKit, as used in WebKitGTK+ through 2.21.3, mishandle an unset pageURL, leading to an application crash.

macOS Kernel Use-After-Free

Posted by deepcore under exploit (No Respond)

The macOS kernel suffers from a use-after-free vulnerability due to a lack of locking in the nvidia GeForce driver.