what you don't know can hurt you
Showing 1 - 22 of 22 RSS Feed

Files Date: 2019-03-19

Microsoft Edge Flash click2play Bypass
Posted Mar 19, 2019
Authored by Ivan Fratric, Google Security Research

Microsoft Edge suffers from a Flash click2play bypass with CObjectElement::FinalCreateObject.

tags | exploit
advisories | CVE-2019-0612
MD5 | c94b41849f791f91a4e487bc8f455397
VBScript VbsErase Memory Corruption
Posted Mar 19, 2019
Authored by Ivan Fratric, Google Security Research

There is an issue in VBScript in the VbsErase function. In some cases, VbsErase fails to clear the argument variable properly, which can trivially lead to crafting a variable with the array type, but with a pointer controlled controlled by an attacker.

tags | exploit
advisories | CVE-2019-0667
MD5 | c197b2b4966090acde9b5638b0466c4a
GNU Privacy Guard 2.2.14
Posted Mar 19, 2019
Site gnupg.org

GnuPG (the GNU Privacy Guard or GPG) is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440. As such, it is meant to be compatible with PGP from NAI, Inc. Because it does not use any patented algorithms, it can be used without any restrictions.

Changes: Multiple code updates and an updated Russian translation.
tags | tool, encryption
MD5 | 96a21c6341b876d13ed66a9f270806bb
JFrog Artifactory Pro 6.5.9 Signature Validation
Posted Mar 19, 2019
Authored by Timo Juhani Lindfors

The SAML SSO addon in JFrog Artifactory version 6.5.9 does not properly validate the XML signature in the SAMLResponse field send to the URL /webapp/saml/loginResponse. An attacker can use this flaw to login as any user if they already can login as some user.

tags | exploit
advisories | CVE-2018-19971
MD5 | 286da37ca8a607162967886cc7683e3f
Slackware Security Advisory - libssh2 Updates
Posted Mar 19, 2019
Authored by Slackware Security Team | Site slackware.com

Slackware Security Advisory - New libssh2 packages are available for Slackware 14.2 and -current to fix security issues.

tags | advisory
systems | linux, slackware
advisories | CVE-2019-3855, CVE-2019-3856, CVE-2019-3857, CVE-2019-3858, CVE-2019-3859, CVE-2019-3860, CVE-2019-3861, CVE-2019-3862, CVE-2019-3863
MD5 | 75dc61143a842e32ab8500f75ed4d9ec
Debian Security Advisory 4409-1
Posted Mar 19, 2019
Authored by Debian | Site debian.org

Debian Linux Security Advisory 4409-1 - Erik Olof Gunnar Andersson discovered that incorrect validation of port settings in the iptables security group driver of Neutron, the OpenStack virtual network service, could result in denial of service in a multi tenant setup.

tags | advisory, denial of service
systems | linux, debian
advisories | CVE-2019-9735
MD5 | d3a948ca8507d7cb3d99637b37eb392b
Red Hat Security Advisory 2019-0600-01
Posted Mar 19, 2019
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2019-0600-01 - Red Hat CloudForms Management Engine delivers the insight, control, and automation needed to address the challenges of managing virtual environments. CloudForms Management Engine is built on Ruby on Rails, a model-view-controller framework for web application development. Action Pack implements the controller and the view components. Issues addressed include a deserialization vulnerability.

tags | advisory, web, ruby
systems | linux, redhat
advisories | CVE-2018-16476
MD5 | 1851ff3f967e78cafa8097e80c42894d
Gentoo Linux Security Advisory 201903-15
Posted Mar 19, 2019
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201903-15 - Multiple vulnerabilities have been found in NTP, the worst of which could result in the remote execution of arbitrary code. Versions less than 4.2.8_p13 are affected.

tags | advisory, remote, arbitrary, vulnerability
systems | linux, gentoo
advisories | CVE-2018-12327, CVE-2019-8936
MD5 | 8df860a16344eea891017b2ab32a71ef
Chrome StoragePartitionService Double-Destruction Race
Posted Mar 19, 2019
Authored by Google Security Research, Mark Brand

There's a race condition in the destruction of the BindingState for bindings to the StoragePartitionService in Chrome. It looks like the root cause of the issue is that since we can get two concurrent calls to callbacks returned from mojo::BindingSet::GetBadMessageCallback() from the same BindingSet, which results in a data race destroying the same BindingState.

tags | exploit, root
advisories | CVE-2019-5797
MD5 | 93fdcc784fafeb9f017d38fdf6497ad4
Microsoft Windows IE11 VBScript Execution Policy Bypass In MSHTML
Posted Mar 19, 2019
Authored by James Forshaw, Google Security Research

MSHTML only checks for the CLSID associated with VBScript when blocking in the Internet Zone, but doesn't check other VBScript CLSIDs which allow a web page to bypass the security zone policy.

tags | exploit, web
advisories | CVE-2019-0768
MD5 | 584cf23d79ac670ff438b7731597d0f4
Chrome MidiManagerWin Use-After-Free
Posted Mar 19, 2019
Authored by Google Security Research, Mark Brand

Chrome suffers from a use-after-free vulnerability in MidiManagerWin.

tags | exploit
advisories | CVE-2019-5789
MD5 | dc0f159730c40da031c0642b88e832b2
Chrome FileSystemOperationRunner Use-After-Free
Posted Mar 19, 2019
Authored by Google Security Research, Mark Brand

Chrome suffers from a use-after-free vulnerability in FileSystemOperationRunner.

tags | exploit
advisories | CVE-2019-5788
MD5 | 21b3aa46f914503f58e394a2ab04c463
Advanced Host Monitor 11.92 Beta Local Buffer Overflow
Posted Mar 19, 2019
Authored by Peyman Forouzan

Advanced Host Monitor version 11.92 Beta suffers from a buffer overflow vulnerability.

tags | exploit, overflow
MD5 | 6f1aa8cff7eb3c6149dd426e623ace6e
Chrome ExtensionsGuestViewMessageFilter Data Race
Posted Mar 19, 2019
Authored by Google Security Research, Mark Brand

There appears to be a race condition in the destruction of the ExtensionsGuestViewMessageFilter if the ProcessIdToFilterMap is modified concurrently in Chrome.

tags | exploit
advisories | CVE-2019-5796
MD5 | 443d417c18c99366a21ce4b7f33f13ab
Abine Blur 7.8.24x Authentication Bypass
Posted Mar 19, 2019
Authored by RS Tyler Schroder

The Password Manager Extension in Abine Blur versions 7.8.24x allows attackers to bypass the multi-factor authentication and macOS disk-encryption protection mechanisms, and consequently exfiltrate secured data, because the right-click context menu is not secured. NOTE: this vulnerability exists because of a CVE-2018-7213 regression.

tags | advisory, bypass
advisories | CVE-2018-7213, CVE-2019-6481
MD5 | 3f9130ef2411e972988a7ce52ef65e0b
eNdonesia Portal 8.7 Iframe Injection / SQL Injection
Posted Mar 19, 2019
Authored by Mehmet Emiroglu

eNdonesia Portal version 8.7 suffers from remote SQL injection and iframe injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
MD5 | b099a2b684a207b7fd0c44f79a71a037
Netartmedia PHP Mall 4.1 SQL Injection
Posted Mar 19, 2019
Authored by Ahmet Umit Bayram

Netartmedia PHP Mall version 4.1 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
MD5 | 137db9a66101e3096824f22d24d3c15c
Gila CMS 1.9.1 Cross Site Scripting
Posted Mar 19, 2019
Authored by Ahmet Umit Bayram

Gila CMS version 1.9.1 suffers from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2019-9647
MD5 | dd0d01b91e4b3fc6b3f822a48decd54a
Netartmedia Event Portal 2.0 SQL Injection
Posted Mar 19, 2019
Authored by Ahmet Umit Bayram

Netartmedia Event Portal version 2.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 7376fb572e9d675521a6918563b56747
Netartmedia Real Estate Portal 5.0 SQL Injection
Posted Mar 19, 2019
Authored by Ahmet Umit Bayram

Netartmedia Real Estate Portal version 5.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 3c11212afdb861fe4e2d3cc0f8e1218b
MyBB Upcoming Events 1.32 Cross Site Scripting
Posted Mar 19, 2019
Authored by 0xB9

MyBB Upcoming Events plugin version 1.32 suffers from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2019-9650
MD5 | 0bbd4c6a83d39c1d1f4a9817b88eca2a
Jenkins ACL Bypass / Metaprogramming Remote Code Execution
Posted Mar 19, 2019
Authored by Orange Tsai, wvu | Site metasploit.com

This Metasploit module exploits a vulnerability in Jenkins dynamic routing to bypass the Overall/Read ACL and leverage Groovy metaprogramming to download and execute a malicious JAR file. The ACL bypass gadget is specific to Jenkins versions 2.137 and below and will not work on later versions of Jenkins. Tested against Jenkins 2.137 and Pipeline: Groovy Plugin 2.61.

tags | exploit
advisories | CVE-2019-1003000, CVE-2019-1003001, CVE-2019-1003002
MD5 | ebc7d597076f043f7e2c68f773bfe3fb
Page 1 of 1
Back1Next

File Archive:

January 2020

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jan 1st
    8 Files
  • 2
    Jan 2nd
    11 Files
  • 3
    Jan 3rd
    11 Files
  • 4
    Jan 4th
    2 Files
  • 5
    Jan 5th
    2 Files
  • 6
    Jan 6th
    18 Files
  • 7
    Jan 7th
    15 Files
  • 8
    Jan 8th
    16 Files
  • 9
    Jan 9th
    10 Files
  • 10
    Jan 10th
    13 Files
  • 11
    Jan 11th
    2 Files
  • 12
    Jan 12th
    4 Files
  • 13
    Jan 13th
    21 Files
  • 14
    Jan 14th
    18 Files
  • 15
    Jan 15th
    12 Files
  • 16
    Jan 16th
    18 Files
  • 17
    Jan 17th
    11 Files
  • 18
    Jan 18th
    2 Files
  • 19
    Jan 19th
    0 Files
  • 20
    Jan 20th
    0 Files
  • 21
    Jan 21st
    0 Files
  • 22
    Jan 22nd
    0 Files
  • 23
    Jan 23rd
    0 Files
  • 24
    Jan 24th
    0 Files
  • 25
    Jan 25th
    0 Files
  • 26
    Jan 26th
    0 Files
  • 27
    Jan 27th
    0 Files
  • 28
    Jan 28th
    0 Files
  • 29
    Jan 29th
    0 Files
  • 30
    Jan 30th
    0 Files
  • 31
    Jan 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2016 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close