Subscribe via feed.
Archive for December, 2019

[dos] Adobe Acrobat Reader DC – Heap-Based Memory Corruption due to Malformed TTF Font

Posted by deepcore under Security (No Respond)

Adobe Acrobat Reader DC – Heap-Based Memory Corruption due to Malformed TTF Font

Tags: ,

[dos] AppXSvc 17763 – Arbitrary File Overwrite (DoS)

Posted by deepcore under Security (No Respond)

AppXSvc 17763 – Arbitrary File Overwrite (DoS)

Tags: ,

[dos] Product Key Explorer 4.2.0.0 – 'Key' Denial of Service (PoC)

Posted by deepcore under Security (No Respond)

Product Key Explorer 4.2.0.0 – ‘Key’ Denial of Service (PoC)

Tags: ,

[dos] Product Key Explorer 4.2.0.0 – 'Name' Denial of Service (POC)

Posted by deepcore under Security (No Respond)

Product Key Explorer 4.2.0.0 – ‘Name’ Denial of Service (POC)

Tags: ,

Mozilla Firefox Windows 64-Bit Chain Exploit

Posted by deepcore under exploit (No Respond)

This is a full browser compromise exploit chain targeting Mozilla Firefox on Windows 64-bit. It uses CVE-2019-9810 for getting code execution in both the content process as well as the parent process and CVE-2019-11708 to trick the parent process into browsing to an arbitrary URL.

Microsoft Windows Windows 10 UAC Bypass

Posted by deepcore under exploit (No Respond)

Proof of concept exploit that demonstrates a Microsoft Windows 10 UAC bypass for all executable files which are autoelevate true.

SpotAuditor 5.3.2 Local Buffer Overflow

Posted by deepcore under exploit (No Respond)

SpotAuditor version 5.3.2 Base64 local buffer overflow SEH exploit.

PRO-7070 Hazir Profesyonel Web Sitesi 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

PRO-7070 Hazir Profesyonel Web Sitesi version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Snipe-IT Open Source Asset Management 4.7.5 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Snipe-IT Open Source Asset Management version 4.7.5 suffers from a persistent cross site scripting vulnerability.

Alcatel-Lucent Omnivista 8770 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Alcatel-Lucent Omnivista 8770 suffers from a remote code execution vulnerability.