Subscribe via feed.
Archive for February, 2020

HP System Event Utility Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

The HP System Event service “HPMSGSVC.exe” will load an arbitrary EXE and execute it with SYSTEM integrity. HPMSGSVC.exe runs a background process that delivers push notifications. The problem is that the HP Message Service will load and execute any arbitrary executable named “Program.exe” if it is found in the user’s c: drive.

WordPress Wordfence 7.4.5 Local File Disclosure

Posted by deepcore under exploit (No Respond)

WordPress Wordfence plugin version 7.4.5 suffers from a file disclosure vulnerability.

WordPress Tutor 1.5.3 Local File Inclusion

Posted by deepcore under exploit (No Respond)

WordPress Tutor plugin version 1.5.3 suffers from a local file inclusion vulnerability.

Samsung Kernel PROCA Use-After-Free / Double-Free

Posted by deepcore under exploit (No Respond)

The Samsung kernel has logic bug and locking issues in PROCA that can lead to use-after-free and double-free issues from an application’s context.

Samsung SEND_FILE_WITH_HEADER Use-After-Free

Posted by deepcore under exploit (No Respond)

Samsung suffers from a use-after-free vulnerability due to a missing lock in the SEND_FILE_WITH_HEADER handler in f_mtp_samsung.c.

[webapps] PANDORAFMS 7.0 – Authenticated Remote Code Execution

Posted by deepcore under Security (No Respond)

PANDORAFMS 7.0 – Authenticated Remote Code Execution

Tags: ,

[local] OpenTFTP 1.66 – Local Privilege Escalation

Posted by deepcore under Security (No Respond)

OpenTFTP 1.66 – Local Privilege Escalation

Tags: ,

[webapps] WordPress Plugin tutor.1.5.3 – Local File Inclusion

Posted by deepcore under Security (No Respond)

WordPress Plugin tutor.1.5.3 – Local File Inclusion

Tags: ,

[webapps] WordPress Plugin tutor.1.5.3 – Persistent Cross-Site Scripting

Posted by deepcore under Security (No Respond)

WordPress Plugin tutor.1.5.3 – Persistent Cross-Site Scripting

Tags: ,

Torrent iPod Video Converter 1.51 Stack Overflow

Posted by deepcore under exploit (No Respond)

Torrent iPod Video Converter version 1.51 suffers from a stack overflow vulnerability.