Tea LaTex 1.0 – Remote Code Execution (Unauthenticated)
>> AUTHOR: deepcore
Tea LaTex 1.0 – Remote Code Execution (Unauthenticated)
Internet Explorer 11 – Use-After-Free
Tiandy IPC and NVR 9.12.7 – Credential Disclosure
CuteNews 2.1.2 – Remote Code Execution
ZTE Router F602W – Captcha Bypass
The CloundExperienceHostBroker hosts unsafe COM objects accessible to a normal user leading to elevation of privilege.
Yaws versions 1.81 through 2.0.7 suffer from remote OS command injection and XML external entity injection vulnerabilities.
The Qualcomm Adreno GPU shares a global mapping called a “scratch” buffer with the Adreno KGSL kernel driver. The contents of the scratch buffer can be overwritten by untrusted GPU…
The StorageFolder class when used out of process can bypass security checks to read and write files not allowed to an AppContainer.
http://thepsathit.go.th/doc/ghi.html notified by Ghost Hunter Illusion