Subscribe via feed.
Archive for January, 2020

WeChat CAudioJBM::InputAudioFrameToJBM Memory Corruption

Posted by deepcore under exploit (No Respond)

There is a memory corruption vulnerability in audio processing during a voice call in WeChat. When an RTP packet is processed, there is a call to UnpacketRTP. This function decrements the length of the packet by 12 without checking that the packet has at least 12 bytes in it. This leads to a negative packet […]

Android ashmem Read-Only Bypasses

Posted by deepcore under exploit (No Respond)

Android suffers from ashmem read-only bypass vulnerabilities via remap_file_pages() and ASHMEM_UNPIN.

[webapps] Citrix Application Delivery Controller and Citrix Gateway – Remote Code Execution

Posted by deepcore under Security (No Respond)

Citrix Application Delivery Controller and Citrix Gateway – Remote Code Execution

Tags: ,

[webapps] Citrix Application Delivery Controller and Citrix Gateway – Remote Code Execution (PoC)

Posted by deepcore under Security (No Respond)

Citrix Application Delivery Controller and Citrix Gateway – Remote Code Execution (PoC)

Tags: ,

https://www.huaikrachaohospital.go.th/0day.html

Posted by deepcore under defacement (No Respond)

https://www.huaikrachaohospital.go.th/0day.html notified by exploit-0day

Tags:

[webapps] ASTPP 4.0.1 VoIP Billing – Database Backup Download

Posted by deepcore under Security (No Respond)

ASTPP 4.0.1 VoIP Billing – Database Backup Download

Tags: ,

[webapps] Pandora 7.0NG – Remote Code Execution

Posted by deepcore under Security (No Respond)

Pandora 7.0NG – Remote Code Execution

Tags: ,

[local] TotalAV 2020 4.14.31 – Privilege Escalation

Posted by deepcore under Security (No Respond)

TotalAV 2020 4.14.31 – Privilege Escalation

Tags: ,

[webapps] PixelStor 5000 K:4.0.1580-20150629 – Remote Code Execution

Posted by deepcore under Security (No Respond)

PixelStor 5000 K:4.0.1580-20150629 – Remote Code Execution

Tags: ,

Cisco DCNM JBoss 10.4 Credential Leakage

Posted by deepcore under exploit (No Respond)

Cisco DCNM JBoss version 10.4 suffers from a credential leakage vulnerability.