SUSE/Portus version 2.2 suffers from a persistent cross site scripting vulnerability.
45c4673d073bbdcf395b309bad7cd3d0
DlxSpot Player4 LED video wall has a hardcoded password that allows you to ssh in and escalate to root.
a8c160f05eb5b14922777c74c7455bf9
DlxSpot Player4 LED video wall suffers from a remote shell upload vulnerability. Versions greater than 1.5.10 are affected.
9af7a881088ecdf7ad4e03ae9466faeb
DlxSpot Player4 LED video wall suffers from a remote SQL injection vulnerability that allows for authentication bypass. Versions greater than 1.5.10 are affected.
2d94a5f031c7d5b9085cc566f159b20b
There is a security issue in Microsoft Edge related to how HTML documents are loaded. If Edge displays a HTML document from a slow HTTP server, it is possible that a part of the document is going to be rendered before the server has finished sending the document. It is also possible that some JavaScript code is going to trigger. By making DOM modifications before the document had a chance of fully loading, followed by another set of DOM modifications after the page has been loaded, it is possible to trigger memory corruption that could possibly lead to an exploitable condition.
38a51b456f8f99a75032e480ca87fb20
The Microsoft Windows kernel suffers from a stack memory disclosure vulnerability in win32k!NtQueryCompositionSurfaceBinding.
73d3685f1e900f98c6cd4f3a23681176
The Microsoft Windows kernel suffers from a stack memory disclosure vulnerability in win32k!NtGdiHLSurfGetInformation.
ea7057c9591140087eed136016fbcd5a
The Microsoft Windows kernel suffers from a stack memory disclosure vulnerability in win32k!NtGdiDoBanding.
fe4029deb9c5251a89ca66ad88be9adc
There is an out-of-bounds read issue in Microsoft Edge that could potentially be turned into remote code execution. The vulnerability has been confirmed on Microsoft Edge 38.14393.1066.0 (Microsoft EdgeHTML 14.14393) as well as Microsoft Edge 40.15063.0.0 (Microsoft EdgeHTML 15.15063).
f8f0367a62a7c9dadd43f0e6c52c13e5
The Microsoft Windows kernel suffers from a stack memory disclosure vulnerability in win32k!NtGdiEngCreatePalette.
83ee676927d72312fbb286ed64a835d8
The Microsoft Windows kernel suffers from a stack memory disclosure vulnerability in win32k!NtGdiGetFontResourceInfoInternalW.
61dc2229ecbf3b49ce1abc604e7d026d
The Microsoft Windows kernel win32k.sys TTF font processing suffers from an out-of-bounds read vulnerability with a malformed glyf table.
6641efba2930501968ff7f836aa362bc
The Microsoft Windows kernel win32k.sys TTF font procession functionality suffers from out-of-bounds read/write vulnerabilities.
aa8a1953e3c70722e1dd32b005aa020c
The Microsoft Windows kernel pool suffers from a memory disclosure vulnerability in nt!NtSetIoCompletion and nt!NtRemoveIoCompletion.
fd5025fc6a75cc5dbc1f54b354b0c2e7
The Microsoft Windows kernel suffers from a memory disclosure in win32k!NtGdiGetPhysicalMonitorDescription.
890bef0c1635255b9915dcca14ad5865
The Microsoft Windows kernel pool suffers from a memory disclosure vulnerability in win32k!NtGdiGetGlyphOutline.
5b64942e584a037e7e24695cad37a8d2
RECON Brussels has announced it's call for papers. The conference will take place January 29th through February 4th, 2018 in Brussels, Belgium.
b8cd79d146f9f4323ceb0141217dd86c
Watchguard's Firebox and XTM appliances suffer from an XML-RPC empty member denial of service vulnerability. Firmware versions below 12.0 were found to be vulnerable.
834b3f0a96297865381ef9778e35cd66
The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where the stack is mapped allowing attackers to more easily manipulate the stack. It was discovered that a buffer overflow existed in the Bluetooth stack of the Linux kernel when handling L2CAP configuration responses. A physically proximate attacker could use this to cause a denial of service (system crash). It was discovered that the Flash-Friendly File System (f2fs) implementation in the Linux kernel did not properly validate superblock metadata. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.
f0f811c3905f66d55df59c33e5694479
iBall ADSL2+ Home Router suffers from multiple authentication bypass vulnerabilities.
1d79305ff9e23d0f385e458888f5616f
UTStar WA3002G4 ADSL Broadband Modem suffers from multiple authentication bypass vulnerabilities.
76b06148bd896167e3da312b301ddd69
ZKTeco ZKTime Web version 2.0.1.12280 suffers from an information disclosure vulnerability.
6b7fa287e7bbc910a93f0b738525a4b8
ZKTeco ZKTime Web version 2.0.1.12280 suffers from a cross site request forgery vulnerability.
1ebd8d29476f9a7cfd4912a6b57b2711
This Microsoft bulletin summary lists a CVE that has undergone a major revision increment.
58d921ea9facc954f2381c1f5c171996
Red Hat Security Advisory 2017-2760-01 - The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix: It was found that stacking a file system over procfs in the Linux kernel could lead to a kernel stack overflow due to deep nesting, as demonstrated by mounting ecryptfs over procfs and creating a recursion by mapping /proc/environ. An unprivileged, local user could potentially use this flaw to escalate their privileges on the system.
b0026adac8be54ca2168544c7eceabc0