Subscribe via feed.
Archive for December, 2021

Oracle Database Protection Mechanism Bypass

Posted by deepcore under exploit (No Respond)

Due to insecure fallback behavior, a man-in-the-middle attacker can bypass NNE’s protection against man-in-the-middle attacks and hijack authenticated connections. In some configurations, a full man-in-the-middle attack is possible. Oracle Database versions 19c, 12.2.0.1, and 12.1.0.2 are affected.

Backdoor.Win32.Phase.11 Code Execution

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Phase.11 malware suffers from a code execution vulnerability.

Oracle Database Weak NNE Integrity Key Derivation

Posted by deepcore under exploit (No Respond)

NNE’s integrity protection mechanism deliberately weakens the key used for computing per-packet message authentication codes (MACs). Oracle Database versions 19c, 12.2.0.1, and 12.1.0.2 are affected.

[local] Microsoft Internet Explorer / ActiveX Control – Security Bypass

Posted by deepcore under Security (No Respond)

Microsoft Internet Explorer / ActiveX Control – Security Bypass

Tags: ,

[webapps] WordPress Plugin Typebot 1.4.3 – Stored Cross Site Scripting (XSS) (Authenticated)

Posted by deepcore under Security (No Respond)

WordPress Plugin Typebot 1.4.3 – Stored Cross Site Scripting (XSS) (Authenticated)

Tags: ,

[remote] Apache Log4j 2 – Remote Code Execution (RCE)

Posted by deepcore under Security (No Respond)

Apache Log4j 2 – Remote Code Execution (RCE)

Tags: ,

[local] Laravel Valet 2.0.3 – Local Privilege Escalation (macOS)

Posted by deepcore under Security (No Respond)

Laravel Valet 2.0.3 – Local Privilege Escalation (macOS)

Tags: ,

[remote] Apache Log4j2 2.14.1 – Information Disclosure

Posted by deepcore under Security (No Respond)

Apache Log4j2 2.14.1 – Information Disclosure

Tags: ,

Log4j Zero Day Flaw: What You Need To Know And How To Protect Yourself

Posted by deepcore under exploit (No Respond)

[webapps] WebHMI 4.0 – Remote Code Execution (RCE) (Authenticated)

Posted by deepcore under Security (No Respond)

WebHMI 4.0 – Remote Code Execution (RCE) (Authenticated)

Tags: ,