Microsoft Windows kernel suffers from a use-after-free of the PDEVOBJ object via a race condition vulnerability in NtGdiGetDeviceCapsAll.
This Metasploit module exploits a Java deserialization vulnerability in Apache OFBiz’s unauthenticated XML-RPC endpoint /webtools/control/xmlrpc for versions prior to 17.12.04.
MyBB OUGC Feedback plugin version 1.8.22 suffers from a cross site scripting vulnerability.
Trojan-Spy.Win32.KeyLogger.qt malware suffers from an insecure permissions vulnerability.
Nsasoft Hardware Software Inventory version 1.6.4.0 suffers from a denial of service vulnerability.
Trojan-Dropper.Win32.Hamer.10 malware suffers from a denial of service vulnerability.
Big IP’s Traffic Management Microkernels (TMM) URI normalization incorrectly handles invalid IPv6 hostnames allowing for information disclosure and an out-of-bounds write condition.
The bd daemon, which runs as part of the F5 BIG-IP Application Security Manager (ASM), is vulnerable to a stack-based buffer overflow when processing overlong HTTP response headers in the…
Vembu BDR 4.2.0.1 U1 – Multiple Unquoted Service Paths
Monitoring System (Dashboard) 1.0 – File Upload RCE (Authenticated)