Subscribe via feed.
Archive for October, 2022

Windows Kernel Registry Subkey Lists Integer Overflow

Posted by deepcore under exploit (No Respond)

The Windows Kernel suffers from integer overflow vulnerabilities in its registry subkey lists leading to memory corruption.

MapTool 1.11.5 Denial Of Service

Posted by deepcore under exploit (No Respond)

MapTool version 1.11.5 suffers from a denial of service vulnerability.

MapTool 1.11.5 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

MapTool version 1.11.5 suffers from a cross site scripting vulnerability.

Joomla Vik Appointments 1.7.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Joomla Vik Appointments extension version 1.7.3 suffers from a cross site scripting vulnerability.

MiniDVBLinux 5.4 Configuration Download

Posted by deepcore under exploit (No Respond)

MiniDVBLinux versions 5.4 and below are vulnerable to an unauthenticated configuration download when a direct object reference is made to the backup function using an HTTP GET request.

MiniDVBLinux 5.4 SVDRP Control

Posted by deepcore under exploit (No Respond)

MiniDVBLinux versions 5.4 and below allows the usage of the SVDRP protocol/commands to be sent by a remote attacker to manipulate and/or remotely control the TV.

MiniDVBLinux 5.4 Change Root Password

Posted by deepcore under exploit (No Respond)

MiniDVBLinux versions 5.4 and below root password changing proof of concept exploit.

Backdoor.Win32.DarkSky.23 MVID-2022-0648 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.DarkSky.23 malware suffers from a buffer overflow vulnerability.

MiniDVBLinux 5.4 Unauthenticated Stream Disclosure

Posted by deepcore under exploit (No Respond)

MiniDVBLinux versions 5.4 and below suffer from an unauthenticated live stream disclosure when /tpl/tv_action.sh is called and generates a snapshot in /var/www/images/tv.jpg through the Simple VDR Protocol (SVDRP).

Webile 1.0.1 Directory Traversal

Posted by deepcore under exploit (No Respond)

Webile version 1.0.1 suffers from a directory traversal vulnerability.