Subscribe via feed.
Archive for August, 2019

ManageEngine opManager 12.3.150 Remote Code Execution

Posted by deepcore under exploit (No Respond)

ManageEngine opManager version 12.3.150 suffers from an authenticated code execution vulnerability.

Tesla Agent Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a command injection vulnerability in the Tesla Agent botnet panel.

Adobe Acrobat CoolType (AFDKO) Type 1 Font Memory Corruption

Posted by deepcore under exploit (No Respond)

Adobe Acrobat CoolType (AFDKO) suffers from a memory corruption vulnerability in the handling of Type 1 font load/store operators.

Adobe Acrobat CoolType (AFDKO) Type 1 Font Uninitialized Memory Issue

Posted by deepcore under exploit (No Respond)

Adobe Acrobat CoolType (AFDKO) performs a call from uninitialized memory due to an empty FDArray in Type 1 fonts.

Microsoft Font Subsetting DLL MergeFontPackage Dangling Pointer

Posted by deepcore under exploit (No Respond)

The Microsoft Font Subsetting DLL (fontsub.dll) is a default Windows helper library for subsetting TTF fonts. It has an issue where it returns a dangling pointer via MergeFontPackage.

Microsoft Font Subsetting DLL GetGlyphId Out-Of-Bounds Read

Posted by deepcore under exploit (No Respond)

Microsoft Font Subsetting DLL suffers from a heap-based out-of-bounds read vulnerability in GetGlyphIdx.

Microsoft Font Subsetting DLL MergeFormat12Cmap / MakeFormat12MergedGlyphList Double-Free

Posted by deepcore under exploit (No Respond)

Microsoft Font Subsetting DLL suffers from a double free vulnerability in MergeFormat12Cmap / MakeFormat12MergedGlyphList.

Microsoft Font Subsetting DLL FixSbitSubTables Heap Corruption

Posted by deepcore under exploit (No Respond)

Microsoft Font Subsetting DLL suffers from a heap corruption vulnerability in FixSbitSubTables.

Microsoft Font Subsetting DLL ReadTableIntoStructure Heap Corruption

Posted by deepcore under exploit (No Respond)

Microsoft Font Subsetting DLL suffers from a heap corruption vulnerability in ReadTableIntoStructure.

Microsoft Font Subsetting DLL ReadAllocFormat12CharGlyphMapList Heap Corruption

Posted by deepcore under exploit (No Respond)

Microsoft Font Subsetting DLL suffers from a heap corruption vulnerability in ReadAllocFormat12CharGlyphMapList.