Subscribe via feed.
Archive for May, 2019

Spidermonkey IonMonkey JS_OPTIMIZED_OUT Value Leak

Posted by deepcore under exploit (No Respond)

Spidermonkey IonMonkey can, during a bailout, leak an internal JS_OPTIMIZED_OUT magic value to the running script. This magic value can then be used to achieve memory corruption.

EquityPandit 1.0 Password Disclosure

Posted by deepcore under exploit (No Respond)

EquityPandit version 1.0 suffers from a password disclosure vulnerability.

Petraware pTransformer ADC SQL Injection

Posted by deepcore under exploit (No Respond)

Petraware pTransformer ADC versions prior to 2.1.7.22827 suffer from a remote SQL injection vulnerability that allows for login bypass.

Phraseanet DAM Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Phraseanet DAM versions prior to 4.0.7 suffer from a cross site scripting vulnerability.

VFront 0.99.5 Reflective Cross Site Scripting

Posted by deepcore under exploit (No Respond)

VFront version 0.99.5 suffers from multiple reflective cross site scripting vulnerabilities.

VFront 0.99.5 Persistent Cross Site Scripting

Posted by deepcore under exploit (No Respond)

VFront version 0.99.5 suffers from a persistent cross site scripting vulnerability.

[remote] Oracle Application Testing Suite – WebLogic Server Administration Console War Deployment (Metasploit)

Posted by deepcore under Security (No Respond)

Oracle Application Testing Suite – WebLogic Server Administration Console War Deployment (Metasploit)

Tags: ,

[dos] Spidermonkey – IonMonkey Unexpected ObjectGroup in ObjectGroupDispatch Operation

Posted by deepcore under Security (No Respond)

Spidermonkey – IonMonkey Unexpected ObjectGroup in ObjectGroupDispatch Operation

Tags: ,

[dos] Spidermonkey – IonMonkey Leaks JS_OPTIMIZED_OUT Magic Value to Script

Posted by deepcore under Security (No Respond)

Spidermonkey – IonMonkey Leaks JS_OPTIMIZED_OUT Magic Value to Script

Tags: ,

[dos] Qualcomm Android – Kernel Use-After-Free via Incorrect set_page_dirty() in KGSL

Posted by deepcore under Security (No Respond)

Qualcomm Android – Kernel Use-After-Free via Incorrect set_page_dirty() in KGSL

Tags: ,