XnView 2.49.1 Denial Of Service
XnView version 2.49.1 suffers from a denial of service vulnerability.
AVS Audio Converter 9.1 Buffer Overflow
AVS Audio Converter version 9.1 suffers from a buffer overflow vulnerability.
Rumpus FTP Web File Manager 8.2.9.1 Cross Site Scripting
Rumpus FTP Web File Manager version 8.2.9.1 suffers from a cross site scripting vulnerability.
Telerik UI Remote Code Execution
The Telerik UI for ASP.NET AJAX insecurely deserializes JSON objects in a manner that results in arbitrary remote code execution on the software’s underlying host.
macOS Kernel wait_for_namespace_event() Race Condition / Use-After-Free
In the macOS kernel, the XNU function wait_for_namespace_event() in bsd/vfs/vfs_syscalls.c releases a file descriptor for use by userspace but may then subsequently destroy that file descriptor using fp_free(), which unconditionally frees the fileproc and fileglob. This opens up a race window during which the process could manipulate those objects while they’re being freed. Exploitation requires […]
Microsoft UPnP Local Privilege Elevation
This Metasploit module exploits two vulnerabilities to execute a command as an elevated user. The first (CVE-2019-1405) uses the UPnP Device Host Service to elevate to NT AUTHORITYLOCAL SERVICE. The second (CVE-2019-1322) leverages the Update Orchestrator Service to elevate from NT AUTHORITYLOCAL SERVICE to NT AUTHORITYSYSTEM.
[dos] FTP Navigator 8.03 – 'Custom Command' Denial of Service (SEH)
[webapps] Deutsche Bahn Ticket Vending Machine Local Kiosk – Privilege Escalation
Metasploit Sample Linux Privilege Escalation Exploit
This Metasploit exploit module illustrates how a vulnerability could be exploited in a linux command for privilege escalation.