Subscribe via feed.
Archive for July, 2021

[webapps] WordPress Plugin LearnPress 3.2.6.8 – Privilege Escalation

Posted by deepcore under Security (No Respond)

WordPress Plugin LearnPress 3.2.6.8 – Privilege Escalation

Tags: ,

VMware ThinApp DLL Hijacking

Posted by deepcore under exploit (No Respond)

VMware ThinApp suffered from a dll hijacking vulnerability.

Aruba Instant (IAP) Remote Code Execution

Posted by deepcore under exploit (No Respond)

Aruba Instant (IAP) remote code execution exploit.

Seagate BlackArmor NAS sg2000-2000.1331 Command Injection

Posted by deepcore under exploit (No Respond)

Seagate BlackArmor NAS version sg2000-2000.1331 remote command injection exploit.

Aruba Instant 8.7.1.0 Arbitrary File Modification

Posted by deepcore under exploit (No Respond)

Aruba Instant version 8.7.1.0 arbitrary file modification exploit.

ForgeRock Access Manager/OpenAM 14.6.3 Remote Code Execution

Posted by deepcore under exploit (No Respond)

ForgeRock Access Manager/OpenAM version 14.6.3 unauthenticated remote code execution exploit.

Argus Surveillance DVR 4.0 Weak Password Encryption

Posted by deepcore under exploit (No Respond)

Argus Surveillance DVR version 4.0 suffers from a weak password encryption vulnerability.

OX App Suite / OX Guard / OX Documents SSRF / Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Open-Xchange OX App Suite, OX Guard, and OX Documents suffer from server-side request forgery and cross site scripting vulnerabilities. Some of these issues only affect version 7.10.3 while some affect 7.10.4 and earlier.

Linux Kernel Netfilter Heap Out-Of-Bounds Write

Posted by deepcore under exploit (No Respond)

A heap out-of-bounds write affecting the Linux kernel since version 2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a denial of service condition (via heap memory corruption) through user name space.

Linux Kernel Netfilter Heap Out-Of-Bounds Write

Posted by deepcore under exploit (No Respond)

A heap out-of-bounds write affecting the Linux kernel since version 2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a denial of service condition (via heap memory corruption) through user name space.