Subscribe via feed.
Archive for November, 2019

Microsoft Office365 Protection Bypass / Remote Code Execution

Posted by deepcore under exploit (No Respond)

Microsoft Office365 suffers from an improper integrity validation check that can allow for a protection bypass condition that will let docx documents become macro-enabled.

ilchCMS 2.1.23 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

ilchCMS version 2.1.23 suffers from multiple cross site scripting vulnerabilities.

BlueKeep Attacks Have Arrived, Are Initially Underwhelming

Posted by deepcore under exploit (No Respond)

Apple macOS 10.15.1 Denial Of Service

Posted by deepcore under Apple (No Respond)

Apple macOS version 10.15.1 denial of service proof of concept exploit.

Tags: , ,

Apple Security Advisory 2019-11-01-1

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2019-11-01-1 – Xcode 11.2 addresses code execution vulnerabilities.

Tags: , ,

[local] Blue Stacks App Player 2.4.44.62.57 – "BstHdLogRotatorSvc" Unquote Service Path

Posted by deepcore under Security (No Respond)

Blue Stacks App Player 2.4.44.62.57 – “BstHdLogRotatorSvc” Unquote Service Path

Tags: ,

[dos] macOS XNU – Missing Locking in checkdirs_callback() Enables Race with fchdir_common()

Posted by deepcore under Security (No Respond)

macOS XNU – Missing Locking in checkdirs_callback() Enables Race with fchdir_common()

Tags: ,

[dos] WebKit – Universal XSS in JSObject::putInlineSlow and JSValue::putToPrimitive

Posted by deepcore under Security (No Respond)

WebKit – Universal XSS in JSObject::putInlineSlow and JSValue::putToPrimitive

Tags: ,

[webapps] thrsrossi Millhouse-Project 1.414 – 'content' Persistent Cross-Site Scripting

Posted by deepcore under Security (No Respond)

thrsrossi Millhouse-Project 1.414 – ‘content’ Persistent Cross-Site Scripting

Tags: ,

[webapps] thejshen Globitek CMS 1.4 – 'id' SQL Injection

Posted by deepcore under Security (No Respond)

thejshen Globitek CMS 1.4 – ‘id’ SQL Injection

Tags: ,