This Metasploit module exploits a buffer overflow vulnerability on the UploadControl ActiveX. The vulnerability exists in the handling of the "Attachment_Times" property, due to the insecure usage of the _swscanf. The affected ActiveX is provided by the qp2.dll installed with the IBM Lotus Quickr product. This Metasploit module has been tested successfully on IE6-IE9 on Windows XP, Vista and 7, using the qp2.dll 8.1.0.1800. In order to bypass ASLR the no aslr compatible module msvcr71.dll is used. This one is installed with the qp2 ActiveX.
2570396e9a994f0f9128106991e69dcb968d0dde0fbe6d004afd9587713e5cbb
This Metasploit module exploits a buffer overflow vulnerability on the UploadControl ActiveX. The vulnerability exists in the handling of the "Attachment_Times" property, due to the insecure usage of the _swscanf. The affected ActiveX is provided by the dwa85W.dll installed with the IBM Lotus iNotes ActiveX installer. This Metasploit module has been tested successfully on IE6-IE9 on Windows XP, Vista and 7, using the dwa85W.dll 85.3.3.0 as installed with Lotus Domino 8.5.3. In order to bypass ASLR the no aslr compatible module dwabho.dll is used. This one is installed with the iNotes ActiveX.
a5379e9a43da683cd4806d1f1e1d548d9998b0760444a32f658bcd9210c0c210
Google Maps suffered from a cross site scripting vulnerability. This was patched the same day as it was publicly disclosed.
ceadd5d42578a51846404a083d2bc06590816e3f1e2797e178d4f40956bf0b98
SolarWinds TFTP Server versions 9.2.0.111 and below remote denial of service exploit.
cee50b517e8a70d45f5b63ded8e50ae0b5fb619c59073aeef77aec19d4f2c555
Grabit versions 1.7.2 Beta 3 and below SEH overwrite exploit that creates a malicious .nzb file.
ded4904079b67e471affc3ad4c0c01de4770c55493c703502b40bdf9fce76a37