Subscribe via feed.
Archive for November, 2020

DiskBoss 11.7.28 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

DiskBoss version 11.7.28 suffers from an unquoted service path vulnerability.

Canon Inkjet Extended Survey Program 5.1.0.8 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

Canon Inkjet Extended Survey Program version 5.1.0.8 suffers from an unquoted service path vulnerability.

SunSSH Solaris 10 x86 Remote Root

Posted by deepcore under exploit (No Respond)

A trivial to reach stack-based buffer overflow is present in libpam on Solaris. The vulnerable code exists in pam_framework.c parse_user_name() which allocates a fixed size buffer of 512 bytes on the stack and parses a username supplied to PAM modules (such as authtok_get used by SunSSH). This issue can be reached remotely pre-authentication via SunSSH […]

Windows File Enumeration Intel Gathering Tool 2.2

Posted by deepcore under exploit (No Respond)

NtFileSins.py is a Windows file enumeration intel gathering tool.

Online Book Store 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Book Store version 1.0 suffers from a remote SQL injection vulnerability. This is a variant of the original vulnerability discovered in August of 2020 by Moaaz Taha.

Deep Instinct Windows Agent 1.2.24.0 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

Deep Instinct Windows Agent version 1.2.24.0 suffers from an unquoted service path vulnerability.

Privacy Drive 3.17.0 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

Privacy Drive version 3.17.0 suffers from an unquoted service path vulnerability.

Joplin 1.2.6 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Joplin version 1.2.6 suffers from a cross site scripting vulnerability.

Chrome V8 Turbofan Type Confusion

Posted by deepcore under exploit (No Respond)

Turbofan fails to deoptimize code after map deprecation, leading to a type confusion vulnerability.

Chrome ConvertToJavaBitmap Heap Buffer Overflow

Posted by deepcore under exploit (No Respond)

Chrome on Android suffers from a ConvertToJavaBitmap heap buffer overflow vulnerability.