from ZDI: Published Advisories https://ift.tt/2G1RApW
Showing posts with label ZDI: Published Advisories. Show all posts
Showing posts with label ZDI: Published Advisories. Show all posts
ZDI-17-1015: Microsoft Windows JavaScript Typed Array JIT Optimization Use-After-Free Remote Code Execution Vulnerability
from ZDI: Published Advisories https://ift.tt/2G1RApW
ZDI-17-1014: Microsoft Windows Font Embedding Out-Of-Bounds Read Information Disclosure Vulnerability
from ZDI: Published Advisories http://ift.tt/2G1ckKV
ZDI-17-1013: Adobe Acrobat Pro DC ImageConversion EMF BMP Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
from ZDI: Published Advisories http://ift.tt/2Fo5HBv
ZDI-17-1012: Adobe Acrobat Pro DC ImageConversion EMF JPEG Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
from ZDI: Published Advisories http://ift.tt/2FgyEmO
ZDI-17-1011: Adobe Acrobat Pro DC ImageConversion EMF GIF Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
from ZDI: Published Advisories http://ift.tt/2FlOQyY
ZDI-17-1010: Microsoft Windows Font Embedding Out-Of-Bounds Read Information Disclosure Vulnerability
from ZDI: Published Advisories http://ift.tt/2Fk8LhR
ZDI-17-1009: Symantec Messaging Gateway Export Servlet snmpFileName Directory Traversal Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Symantec Messaging Gateway. Authentication is required to exploit this vulnerability.
from ZDI: Published Advisories http://ift.tt/2BnWoDq
from ZDI: Published Advisories http://ift.tt/2BnWoDq
ZDI-17-1008: QNAP QTS Web change_password Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of QNAP QTS. Authentication is not required to exploit this vulnerability.
from ZDI: Published Advisories http://ift.tt/2z6jit8
from ZDI: Published Advisories http://ift.tt/2z6jit8
ZDI-17-1007: QNAP QTS Web sysinfoReq Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of QNAP QTS. Authentication is not required to exploit this vulnerability.
from ZDI: Published Advisories http://ift.tt/2Bn30Sv
from ZDI: Published Advisories http://ift.tt/2Bn30Sv
ZDI-17-1006: QNAP QTS Web change_password Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of QNAP QTS. Authentication is not required to exploit this vulnerability.
from ZDI: Published Advisories http://ift.tt/2z5zYRi
from ZDI: Published Advisories http://ift.tt/2z5zYRi
ZDI-17-1005: QNAP QTS authLogin Host Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of QNAP QTS. Authentication is not required to exploit this vulnerability.
from ZDI: Published Advisories http://ift.tt/2Bn1e46
from ZDI: Published Advisories http://ift.tt/2Bn1e46
ZDI-17-1004: QNAP QTS authLogin Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of QNAP QTS. Authentication is not required to exploit this vulnerability.
from ZDI: Published Advisories http://ift.tt/2z62D94
from ZDI: Published Advisories http://ift.tt/2z62D94
ZDI-17-1003: QNAP QTS Web devRequest Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of QNAP QTS. Authentication is not required to exploit this vulnerability.
from ZDI: Published Advisories http://ift.tt/2Bq55gz
from ZDI: Published Advisories http://ift.tt/2Bq55gz
ZDI-17-1002: QNAP QTS NASFTPD USER Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of QNAP QTS NASFTPD. Authentication is not required to exploit this vulnerability.
from ZDI: Published Advisories http://ift.tt/2z4XZbt
from ZDI: Published Advisories http://ift.tt/2z4XZbt
ZDI-17-1001: WECON LeviStudio PLC Driver Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of WECON LeviStudio. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
from ZDI: Published Advisories http://ift.tt/2BnecyH
from ZDI: Published Advisories http://ift.tt/2BnecyH
ZDI-17-1000: Ecava IntegraXor Report getdata name SQL Injection Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Ecava IntegraXor. Authentication is not required to exploit this vulnerability.
from ZDI: Published Advisories http://ift.tt/2z5HYSx
from ZDI: Published Advisories http://ift.tt/2z5HYSx
ZDI-17-999: Ecava IntegraXor Report batchlist SQL Injection Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Ecava IntegraXor. Authentication is not required to exploit this vulnerability.
from ZDI: Published Advisories http://ift.tt/2z4rbPV
from ZDI: Published Advisories http://ift.tt/2z4rbPV
ZDI-17-998: Adobe Flash Player BitmapData hitTest Out-Of-Bounds Access Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
from ZDI: Published Advisories http://ift.tt/2z5Dk73
from ZDI: Published Advisories http://ift.tt/2z5Dk73
ZDI-17-997: Adobe Flash LocaleID determinePreferredLocales Out-Of-Bounds Read Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
from ZDI: Published Advisories http://ift.tt/2z5VkhI
from ZDI: Published Advisories http://ift.tt/2z5VkhI
ZDI-17-996: Adobe Flash NetworkConfiguration addCustomHeader Out-Of-Bounds Read Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
from ZDI: Published Advisories http://ift.tt/2z5hL6A
from ZDI: Published Advisories http://ift.tt/2z5hL6A
Subscribe to:
Posts (Atom)
Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading
Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads...
-
Original release date: November 08, 2018 Summary JBoss Verify and EXploitation tool (JexBoss) is an open-source tool used by cybersecurity...
-
Original release date: May 21, 2018 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded b...
-
Original release date: January 29, 2018 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been record...
-
It's no secret that learning how to code is one of the most important things you can do when it comes to the beginning or furthering pra...
-
Original release date: February 12, 2018 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recor...
-
Original release date: February 26, 2018 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recor...
-
Os estragos causados pelo ataque com ransomware ao Superior Tribunal de Justiça (STJ) ainda não são totalmente conhecidos. A Polícia Federa...
-
Original release date: March 9, 2020 The CISA Weekly Vulnerability Summary Bulletin is created using information from the NIST NVD . In som...
-
Original release date: October 26, 2020 The CISA Weekly Vulnerability Summary Bulletin is created using information from the NIST NVD . In...
-
Original release date: January 08, 2018 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been record...