Subscribe via feed.
Archive for April, 2019

Linux Siemens R3964 Line Discipline Missing Lock

Posted by deepcore under exploit (No Respond)

The Siemens R3964 line discipline code in drivers/tty/n_r3964.c has a few races around its ioctl handler; for example, the handler for R3964_ENABLE_SIGNALS just allocates and deletes elements in a linked list with zero locking. This code is reachable by an unprivileged user if the line discipline is enabled in the kernel config; Ubuntu 18.04, for […]

Sony Smart TV Information Disclosure / File Read

Posted by deepcore under exploit (No Respond)

Sony Smart TVs suffer from information disclosure and arbitrary file read vulnerabilities.

VirtualBox COM RPC Interface Code Injection / Privilege Escalation

Posted by deepcore under exploit (No Respond)

The hardened VirtualBox process on a Windows host does not secure its COM interface leading to arbitrary code injection and elevation of privilege.

RARLAB WinRAR ACE Format Input Validation Remote Code Execution

Posted by deepcore under exploit (No Respond)

In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path. This module will attempt to extract a payload […]

https://envocc.ddc.moph.go.th//xampp/lang.tmp

Posted by deepcore under defacement (No Respond)

https://envocc.ddc.moph.go.th//xampp/lang.tmp notified by ATSIZ

Tags:

[local] RARLAB WinRAR 5.61 – ACE Format Input Validation Remote Code Execution (Metasploit)

Posted by deepcore under Security (No Respond)

RARLAB WinRAR 5.61 – ACE Format Input Validation Remote Code Execution (Metasploit)

Tags: ,

[local] Lavavo CD Ripper 4.20 – 'License Activation Name' Buffer Overflow (SEH)

Posted by deepcore under Security (No Respond)

Lavavo CD Ripper 4.20 – ‘License Activation Name’ Buffer Overflow (SEH)

Tags: ,

[dos] AnMing MP3 CD Burner 2.0 – Denial of Service (PoC)

Posted by deepcore under Security (No Respond)

AnMing MP3 CD Burner 2.0 – Denial of Service (PoC)

Tags: ,

[webapps] osTicket 1.11 – Cross-Site Scripting / Local File Inclusion

Posted by deepcore under Security (No Respond)

osTicket 1.11 – Cross-Site Scripting / Local File Inclusion

Tags: ,

[dos] JioFi 4G M2S 1.0.2 – Denial of Service

Posted by deepcore under Security (No Respond)

JioFi 4G M2S 1.0.2 – Denial of Service

Tags: ,