Archive for October, 2020
Posted by deepcore under Security (No Respond)
Chrome MediaElementEventListener::UpdateSources Use-After-Free
Posted by deepcore under exploit (No Respond)
Chrome suffers from a MediaElementEventListener::UpdateSources use-after-free vulnerability.
TimeClock Software 1.01 SQL Injection
Posted by deepcore under exploit (No Respond)
TimeClock Software version 1.01 suffers from an authenticated time-based remote SQL injection vulnerability.
NodeBB Forum 1.14.2 Account Takeover
Posted by deepcore under exploit (No Respond)
NodeBB Forum versions 1.12.2 through 1.14.2 suffer from an account takeover vulnerability.
Guild Wars 2 Insecure Folder Permissions
Posted by deepcore under exploit (No Respond)
Guild Wars 2 suffers from an insecure folder permissions vulnerability.
[webapps] rConfig 3.9.5 – Remote Code Execution (Unauthenticated)
Posted by deepcore under Security (No Respond)
[webapps] Vehicle Parking Management System 1.0 – Authentication Bypass
Posted by deepcore under Security (No Respond)
berliCRM 1.0.24 SQL Injection
Posted by deepcore under exploit (No Respond)
berliCRM version 1.0.24 suffers from a remote SQL injection vulnerability.
Battle.Net 1.27.1.12428 Insecure File Permissions
Posted by deepcore under exploit (No Respond)
Battle.Net version 1.27.1.12428 suffers from a privilege escalation vulnerability due to insecure file permissions.
xls2csv 0.95 Overflow / Memory Leak
Posted by deepcore under exploit (No Respond)
xls2csv version 0.95 suffers from three overflow, one malloc fail, one memory leak, and two null pointer dereference vulnerabilities. Proof of concept code and ASAN analysis is included.