Subscribe via feed.
Archive for April, 2021

Google Chrome SimplfiedLowering Integer Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an issue in Google Chrome versions before 87.0.4280.88 (64 bit). The exploit makes use of an integer overflow in the SimplifiedLowering phase in turbofan. It is used along with a typer hardening bypass using ArrayPrototypeShift to create a JSArray with a length of -1. This is abused to gain arbitrary read/write […]

CMSimple 5.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

CMSimple version 5.2 suffers from a persistent cross site scripting vulnerability.

Trojan.Win32.Hosts2.yqf Insecure Permissions

Posted by deepcore under exploit (No Respond)

Trojan.Win32.Hosts2.yqf malware suffers from an insecure permissions vulnerability.

Trojan-Downloader.Win32.Genome.omht Insecure Permissions

Posted by deepcore under exploit (No Respond)

Trojan-Downloader.Win32.Genome.omht malware suffers from an insecure permissions vulnerability.

Trojan-Downloader.Win32.Genome.qiw Insecure Permissions

Posted by deepcore under exploit (No Respond)

Trojan-Downloader.Win32.Genome.qiw malware suffers from an insecure permissions vulnerability.

Composr 10.0.36 Shell Upload

Posted by deepcore under exploit (No Respond)

Composr version 10.0.36 suffers from a remote shell upload vulnerability.

Trojan.Win32.Hotkeychick.d Insecure Permissions

Posted by deepcore under exploit (No Respond)

Trojan.Win32.Hotkeychick.d malware suffers from an insecure permissions vulnerability.

Linux Kernel 5.4 BleedingTooth Remote Code Execution

Posted by deepcore under exploit (No Respond)

Linux kernel version 5.4 BleedingTooth bluetooth zero-click proof of concept remote code execution exploit.

Backdoor.Win32.Hupigon.das Unauthenticated Open Proxy

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Hupigon.das malware has an unauthenticated open proxy functionality.

D-Link DSL-320B-D1 Pre-Authentication Buffer Overflow

Posted by deepcore under exploit (No Respond)

The D-Link DSL-320B-D1 ADSL modem suffers from multiple pre-authentication stack buffer overflow vulnerabilities.