Subscribe via feed.
Archive for February, 2021

Park Ticketing Management System 1 SQL Injection

Posted by deepcore under exploit (No Respond)

Park Ticketing Management System version 1 suffers from a remote SQL injection vulnerability.

Sudo Buffer Overflow / Privilege Escalation

Posted by deepcore under exploit (No Respond)

Sudo versions prior to 1.9.5p2 suffer from buffer overflow and privilege escalation vulnerabilities.

GPG libgcrypt Heap Buffer Overflow

Posted by deepcore under exploit (No Respond)

There is a heap buffer overflow in libgcrypt due to an incorrect assumption in the block buffer management code. Just decrypting some data can overflow a heap buffer with attacker controlled data and no verification or signature is validated before the vulnerability occurs.

Packet Storm New Exploits For January, 2021

Posted by deepcore under exploit (No Respond)

This archive contains all of the 231 exploits added to Packet Storm in January, 2021.

[local] Solaris 10 1/13 (SPARC) – 'dtprintinfo' Local Privilege Escalation (3)

Posted by deepcore under Security (No Respond)

Solaris 10 1/13 (SPARC) – ‘dtprintinfo’ Local Privilege Escalation (3)

Tags: ,

[local] Solaris 10 1/13 (SPARC) – 'dtprintinfo' Local Privilege Escalation (1)

Posted by deepcore under Security (No Respond)

Solaris 10 1/13 (SPARC) – ‘dtprintinfo’ Local Privilege Escalation (1)

Tags: ,

[local] Solaris 10 1/13 (Intel) – 'dtprintinfo' Local Privilege Escalation (3)

Posted by deepcore under Security (No Respond)

Solaris 10 1/13 (Intel) – ‘dtprintinfo’ Local Privilege Escalation (3)

Tags: ,

[local] Solaris 10 1/13 (Intel) – 'dtprintinfo' Local Privilege Escalation (2)

Posted by deepcore under Security (No Respond)

Solaris 10 1/13 (Intel) – ‘dtprintinfo’ Local Privilege Escalation (2)

Tags: ,

[local] Solaris 10 1/13 (SPARC) – 'dtprintinfo' Local Privilege Escalation (2)

Posted by deepcore under Security (No Respond)

Solaris 10 1/13 (SPARC) – ‘dtprintinfo’ Local Privilege Escalation (2)

Tags: ,

[webapps] Student Record System 4.0 – 'cid' SQL Injection

Posted by deepcore under Security (No Respond)

Student Record System 4.0 – ‘cid’ SQL Injection

Tags: ,