Subscribe via feed.
Archive for July, 2021

Apple Security Advisory 2021-07-21-4

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2021-07-21-4 – Security Update 2021-005 Mojave addresses code execution, double free, information leakage, integer overflow, out of bounds read, and out of bounds write vulnerabilities.

Tags: , ,

Apple Security Advisory 2021-07-21-5

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2021-07-21-5 – watchOS 7.6 addresses buffer overflow, bypass, code execution, integer overflow, out of bounds read, out of bounds write, and use-after-free vulnerabilities.

Tags: , ,

Apple Security Advisory 2021-07-21-6

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2021-07-21-6 – tvOS 14.7 addresses buffer overflow, bypass, code execution, integer overflow, out of bounds read, out of bounds write, and use-after-free vulnerabilities.

Tags: , ,

Apple Security Advisory 2021-07-21-7

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2021-07-21-7 – Safari 14.1.2 addresses code execution and use-after-free vulnerabilities.

Tags: , ,

ElasticSearch 7.13.3 Memory Disclosure

Posted by deepcore under exploit (No Respond)

ElasticSearch version 7.13.3 memory disclosure exploit.

[webapps] ElasticSearch 7.13.3 – Memory disclosure

Posted by deepcore under Security (No Respond)

ElasticSearch 7.13.3 – Memory disclosure

Tags: ,

[webapps] WordPress Plugin Simple Post 1.1 – 'Text field' Stored Cross-Site Scripting (XSS)

Posted by deepcore under Security (No Respond)

WordPress Plugin Simple Post 1.1 – ‘Text field’ Stored Cross-Site Scripting (XSS)

Tags: ,

NSO Will No Longer Talk To The Press About Damning Reports

Posted by deepcore under exploit (No Respond)

Vehicle Parking Management System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Vehicle Parking Management System version 1.0 suffers from a persistent cross site scripting vulnerability. Original discovery of persistent cross site scripting in this version is attributed to Tushar Vaidya in February of 2021.

Vehicle Parking Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Vehicle Parking Management System version 1.0 suffers from a remote SQL injection vulnerability. Original discovery of SQL injection in this version is attributed to gh1mau in July of 2020.