Subscribe via feed.
Archive for November, 2022

Ecommerce CodeIgniter Bootstrap 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Ecommerce CodeIgniter Bootstrap version 1.0 suffers from a cross site scripting vulnerability.

wolfSSL Buffer Overflow

Posted by deepcore under exploit (No Respond)

In wolfSSL versions prior to 5.5.1, malicious clients can cause a buffer overflow during a resumed TLS 1.3 handshake. If an attacker resumes a previous TLS session by sending a maliciously crafted Client Hello, followed by another maliciously crafted Client Hello. In total 2 Client Hellos have to be sent. One which pretends to resume […]

Train Scheduler App 1.0 Insecure Direct Object Reference

Posted by deepcore under exploit (No Respond)

Train Scheduler App version 1.0 suffers from an insecure direct object reference vulnerability.

Simple Cold Storage Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Simple Cold Storage Management System version 1.0 suffers from a remote SQL injection vulnerability.

Leeloo Multipath Authorization Bypass / Symlink Attack

Posted by deepcore under exploit (No Respond)

The Qualys Research Team has discovered authorization bypass and symlink vulnerabilities in multipathd. The authorization bypass was introduced in version 0.7.0 and the symlink vulnerability was introduced in version 0.7.7.

Apple Security Advisory 2022-10-27-9

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2022-10-27-9 – macOS Big Sur 11.7 addresses buffer overflow, bypass, code execution, out of bounds write, and use-after-free vulnerabilities.

Tags: , ,

Apple Security Advisory 2022-10-27-10

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2022-10-27-10 – tvOS 16.1 addresses code execution, out of bounds write, and spoofing vulnerabilities.

Tags: , ,

Apple Security Advisory 2022-10-27-11

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2022-10-27-11 – tvOS 16 addresses buffer overflow, code execution, out of bounds read, out of bounds write, spoofing, and use-after-free vulnerabilities.

Tags: , ,

Apple Security Advisory 2022-10-27-12

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2022-10-27-12 – watchOS 9.1 addresses code execution, out of bounds write, and spoofing vulnerabilities.

Tags: , ,

Apple Security Advisory 2022-10-27-13

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2022-10-27-13 – watchOS 9 addresses buffer overflow, bypass, code execution, out of bounds read, out of bounds write, spoofing, and use-after-free vulnerabilities.

Tags: , ,