ZenPhoto version 1.4.14 suffers from multiple cross site scripting vulnerabilities.
Microsoft Windows suffers from a privilege escalation vulnerability. The Data Sharing Service does not has a TOCTOU in PolicyChecker::CheckFilePermission resulting in an arbitrary file deletion.
Polkit suffers from a temporary auth hijacking vulnerability via PID reuse and a non-atomic fork.
Wireshark suffers from a get_t61_string heap out-of-bounds read vulnerability.
This Metasploit module exploits the command injection vulnerability of MailCleaner Community Edition product. An authenticated user can execute an operating system command under the context of the web server user…
http://www.pnbpeo.go.th/hey.htm notified by /MrAxxCT-
polkit – Temporary auth Hijacking via PID Reuse and Non-atomic Fork
Linux/x86 – wget chmod execute over execve /bin/sh -c Shellcode (119 bytes)
ZTE MF65 BD_HDV6MF65V1.0.0B05 – Cross-Site Scripting
Microsoft Office SharePoint Server 2016 – Denial of Service (Metasploit)