Silver Peak VX virtual appliance running VXOA before version 6.2.11 contains a number of security vulnerabilities, including command injection, unauthenticated file read, mass assignment, shell upload, and hardcoded credentials. By…
OpenLDAP versions 2.4.42 and below suffer from a remote denial of service vulnerability.
Magento versions 1.9.2 and below suffer from an autoloaded file inclusion vulnerability.
IKEView.exe is vulnerable to local stack based buffer overflow when parsing an malicious (internet key exchange) “.elg” file.
Monsta FTP version 1.6.2 suffers from cross site request forgery and cross site scripting vulnerabilities.
Install.framework has a suid root binary at /System/Library/PrivateFrameworks/Install.framework/Resources/runner that allows for arbitrary mkdir, unlink, and chown.
The private Install.framework has a few helper executables in /System/Library/PrivateFrameworks/Install.framework/Resources, one of which is suid root and exploitable.
Typo3 CMS versions 6.2.14 and below and 4.5.40 and below suffer from a cross site scripting vulnerability.
The Install.framework runner suid root binary does not correctly account for the fact that Distributed Objects can be connected to by multiple clients at the same time. By connecting two…
Openfire version 3.10.2 suffers from a cross site request forgery vulnerability.