Subscribe via feed.
Archive for November, 2019

[dos] Adobe Acrobat Reader DC for Windows – Use of Uninitialized Pointer due to Malformed JBIG2Globals Stream

Posted by deepcore under Security (No Respond)

Adobe Acrobat Reader DC for Windows – Use of Uninitialized Pointer due to Malformed JBIG2Globals Stream

Tags: ,

[dos] iMessage – Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address

Posted by deepcore under Security (No Respond)

iMessage – Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address

Tags: ,

[local] XML Notepad 2.8.0.4 – XML External Entity Injection

Posted by deepcore under Security (No Respond)

XML Notepad 2.8.0.4 – XML External Entity Injection

Tags: ,

[local] Alps HID Monitor Service 8.1.0.10 – 'ApHidMonitorService' Unquote Service Path

Posted by deepcore under Security (No Respond)

Alps HID Monitor Service 8.1.0.10 – ‘ApHidMonitorService’ Unquote Service Path

Tags: ,

Jenkins Build-Metrics 1.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Jenkins Build-Metrics plugin version 1.3 suffers from a cross site scripting vulnerability.

SolarWinds Kiwi Syslog Server 8.3.52 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

SolarWinds Kiwi Syslog Server version 8.3.52 suffers from a Kiwi Syslog Service unquoted service path vulnerability.

Adive Framework 2.0.7 Privilege Escalation

Posted by deepcore under exploit (No Respond)

Adive Framework version 2.0.7 suffers from a privilege escalation vulnerability.

Nextcloud 17 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Nextcloud 17 suffers from multiple cross site request forgery vulnerabilities.

Chrome Site Isolation Bypass / File Disclosure

Posted by deepcore under exploit (No Respond)

The Chrome Payment Handler API suffers from site isolation bypass and local file disclosure vulnerabilities.

Adaware Web Companion 4.8.2078.3950 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

Adaware Web Companion version 4.8.2078.3950 suffers from an unquoted service path vulnerability.