Subscribe via feed.
Archive for September, 2022

Blink1Control2 2.2.7 Weak Password Encryption

Posted by deepcore under exploit (No Respond)

Blink1Control2 version 2.2.7 suffers from a weak password encryption vulnerability.

Backdoor.Win32.Hellza.120 MVID-2022-0642 Authentication Bypass

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Hellza.120 malware suffers from an authentication bypass vulnerability.

Backdoor.Win32.Hellza.120 MVID-2022-0641 Remote Command Execution

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Hellza.120 malware suffers from a remote command execution vulnerability.

Arm Mali Released Buffer Use-After-Free

Posted by deepcore under exploit (No Respond)

On Mali devices without the new CSF interface, IMPORTED_USER_BUF is released without flushing host-side VMAs, leading to a page use-after-free vulnerability.

Arm Mali Physical Address Exposure

Posted by deepcore under exploit (No Respond)

Arm Mali has an issue where a driver exposes physical addresses to unprivileged userspace.

Arm Mali Race Condition

Posted by deepcore under exploit (No Respond)

The Mali driver frees GPU page tables before removing the higher-level PTEs pointing to those page tables (and, therefore, also before issuing the required flushes). This means a racing memory write instruction on the GPU can write to an attacker-controlled physical address.

Arm Mali CSF Missing Buffer Size Check

Posted by deepcore under exploit (No Respond)

In the Linux Mali driver, when building with MALI_USE_CSF, the VFS read handler of the main Mali file descriptor (kbase_read()) never looks at its “count” parameter. This means that a simple userspace program that sets up a Mali file descriptor, then calls read(mali_fd, buf, 1), will see read() returning a higher length than requested, and […]

[remote] Wifi HD Wireless Disk Drive 11 – Local File Inclusion

Posted by deepcore under Security (No Respond)

Wifi HD Wireless Disk Drive 11 – Local File Inclusion

Tags: ,

[remote] WiFiMouse 1.8.3.4 – Remote Code Execution (RCE)

Posted by deepcore under Security (No Respond)

WiFiMouse 1.8.3.4 – Remote Code Execution (RCE)

Tags: ,

Genesys PureConnect Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Genesys PureConnect as of their build on 08-October-2020 suffers from a cross site scripting vulnerability.