exploit the possibilities
Showing 1 - 16 of 16 RSS Feed

Files Date: 2019-07-12

Linux/x86 chmod 666 /etc/passwd / /etc/shadow Shellcode
Posted Jul 12, 2019
Authored by Xavier Invers Fornells

61 bytes small Linux/x86 chmod 666 /etc/passwd and chmod 666 /etc/shadow shellcode.

tags | x86, shellcode
systems | linux
MD5 | 1d275af34ac3eb4e6782353a61ffbebe
Ubuntu Security Notice USN-4054-1
Posted Jul 12, 2019
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 4054-1 - A sandbox escape was discovered in Firefox. If a user were tricked in to installing a malicious language pack, an attacker could exploit this to gain additional privileges. Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information, bypass same origin restrictions, conduct cross-site scripting attacks, conduct cross-site request forgery attacks, spoof origin attributes, spoof the addressbar contents, bypass safebrowsing protections, or execute arbitrary code. Various other issues were also addressed.

tags | advisory, denial of service, arbitrary, spoof, xss, csrf
systems | linux, ubuntu
advisories | CVE-2019-11709, CVE-2019-11711, CVE-2019-11712, CVE-2019-11713, CVE-2019-11715, CVE-2019-11716, CVE-2019-11717, CVE-2019-11719, CVE-2019-11720, CVE-2019-11721, CVE-2019-11724, CVE-2019-11725, CVE-2019-11727, CVE-2019-11729, CVE-2019-11730, CVE-2019-9811
MD5 | 8ea6959ed7ac020d5ddd786544d68258
Debian Security Advisory 4480-1
Posted Jul 12, 2019
Site debian.org

Debian Linux Security Advisory 4480-1 - Multiple vulnerabilities were discovered in the HyperLogLog implementation of Redis, a persistent key-value database, which could result in denial of service or potentially the execution of arbitrary code.

advisories | CVE-2019-10192, CVE-2019-10193
MD5 | e5f6048460ebffda11af0a60dbde63a3
Xymon useradm Command Execution
Posted Jul 12, 2019
Authored by Brendan Coles, Markus Krell | Site metasploit.com

This Metasploit module exploits a command injection vulnerability in Xymon versions before 4.3.25 which allows authenticated users to execute arbitrary operating system commands as the web server user. When adding a new user to the system via the web interface with useradm.sh, the user's username and password are passed to htpasswd in a call to system() without validation. This module has been tested successfully on Xymon version 4.3.10 on Debian 6.

tags | exploit, web, arbitrary
systems | linux, debian
advisories | CVE-2016-2056
MD5 | 5d1fdb4c7a1abc1fbc3c13a84a4a2eef
Debian Security Advisory 4480-1
Posted Jul 12, 2019
Authored by Debian | Site debian.org

Debian Linux Security Advisory 4480-1 - Multiple vulnerabilities were discovered in the HyperLogLog implementation of Redis, a persistent key-value database, which could result in denial of service or potentially the execution of arbitrary code.

tags | advisory, denial of service, arbitrary, vulnerability
systems | linux, debian
advisories | CVE-2019-10192, CVE-2019-10193
MD5 | e5f6048460ebffda11af0a60dbde63a3
Debian Security Advisory 4479-1
Posted Jul 12, 2019
Authored by Debian | Site debian.org

Debian Linux Security Advisory 4479-1 - Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, cross-site scripting, spoofing, information disclosure, denial of service or cross-site request forgery.

tags | advisory, web, denial of service, arbitrary, spoof, xss, info disclosure, csrf
systems | linux, debian
advisories | CVE-2019-11709, CVE-2019-11711, CVE-2019-11712, CVE-2019-11713, CVE-2019-11715, CVE-2019-11717, CVE-2019-11719, CVE-2019-11729, CVE-2019-11730, CVE-2019-9811
MD5 | 1e90e6a1c90fc8275f2fadb11f5d1fc8
Red Hat Security Advisory 2019-1763-01
Posted Jul 12, 2019
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2019-1763-01 - Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 60.8.0 ESR. Issues addressed include cross site scripting and use-after-free vulnerabilities.

tags | advisory, web, vulnerability, xss
systems | linux, redhat
advisories | CVE-2019-11709, CVE-2019-11711, CVE-2019-11712, CVE-2019-11713, CVE-2019-11715, CVE-2019-11717, CVE-2019-11730, CVE-2019-9811
MD5 | 4d0b8355d6f907b18f24fcab1f430520
Asterisk Project Security Advisory - AST-2019-003
Posted Jul 12, 2019
Authored by Joshua Colp, Francesco Castellano | Site asterisk.org

Asterisk Project Security Advisory - When T.38 faxing is done in Asterisk a T.38 reinvite may be sent to an endpoint to switch it to T.38. If the endpoint responds with an improperly formatted SDP answer including both a T.38 UDPTL stream and an audio or video stream containing only codecs not allowed on the SIP peer or user a crash will occur. The code incorrectly assumes that there will be at least one common codec when T.38 is also in the SDP answer.

tags | advisory
advisories | CVE-2019-13161
MD5 | d09b1ff158348303d04ff506414c1e3e
Asterisk Project Security Advisory - AST-2019-002
Posted Jul 12, 2019
Authored by George Joseph, Gil Richard | Site asterisk.org

Asterisk Project Security Advisory - A specially crafted SIP in-dialog MESSAGE message can cause Asterisk to crash.

tags | advisory
advisories | CVE-2019-12827
MD5 | 7da13e55cd8ce9754ba01c6e12efdff4
Sitecore 9.0 Rev 171002 Cross Site Scripting
Posted Jul 12, 2019
Authored by Owais Mehtab

Sitecore version 9.0 rev 171002 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2019-13493
MD5 | 39d6c982acaa37a46cb0a8d2e1d7da4c
SNMPc Enterprise Edition 9 / 10 Mapping Filename Buffer Overflow
Posted Jul 12, 2019
Authored by xerubus

SNMPc Enterprise Edition versions 9 and 10 suffer from a mapping filename buffer overflow vulnerability.

tags | exploit, overflow
advisories | CVE-2019-13494
MD5 | 109af1e27d2b7507c41e3905ac72c086
Scapy Packet Manipulation Tool 2.4.3rc3
Posted Jul 12, 2019
Authored by Philippe Biondi | Site secdev.org

Scapy is a powerful interactive packet manipulation tool, packet generator, network scanner, network discovery tool, and packet sniffer. It provides classes to interactively create packets or sets of packets, manipulate them, send them over the wire, sniff other packets from the wire, match answers and replies, and more. Interaction is provided by the Python interpreter, so Python programming structures can be used (such as variables, loops, and functions). Report modules are possible and easy to make. It is intended to do the same things as ttlscan, nmap, hping, queso, p0f, xprobe, arping, arp-sk, arpspoof, firewalk, irpas, tethereal, tcpdump, etc.

Changes: Release candidate 3 for 2.4.3. Various updates.
tags | tool, scanner, python
systems | unix
MD5 | 5126a95a48d9875ba8af97961b579330
Jenkins Dependency Graph View 0.13 Cross Site Scripting
Posted Jul 12, 2019
Authored by Ishaq Mohammed

Jenkins Dependency Graph View plugin version 0.13 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2019-10349
MD5 | c1ce6b865eb9188b93661b01f4e2d546
Microsoft Font Subsetting DLL ComputeFormat4CmapData Heap Corruption
Posted Jul 12, 2019
Authored by Google Security Research, mjurczyk

There is a Microsoft Font Subsetting DLL heap corruption vulnerability in ComputeFormat4CmapData.

tags | exploit
MD5 | 1e6e251496d7be9a3bc32fd32fae64ff
WorldClient 14 Cross Site Request Forgery
Posted Jul 12, 2019
Authored by Prithwish Pal

WorldClient version 14 suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
advisories | CVE-2018-17792
MD5 | 709b955d4f8bddb74c3308c677792d0f
Microsoft DirectWrite / AFDKO OpenType Stack Corruption
Posted Jul 12, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from a stack corruption vulnerability in OpenType font handling while processing CFF blend DICT operator.

tags | exploit
advisories | CVE-2019-1123
MD5 | 743e9318dc7ba438e2b58cc2c6bfdc2f
Page 1 of 1
Back1Next

File Archive:

July 2019

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    34 Files
  • 2
    Jul 2nd
    15 Files
  • 3
    Jul 3rd
    9 Files
  • 4
    Jul 4th
    8 Files
  • 5
    Jul 5th
    2 Files
  • 6
    Jul 6th
    3 Files
  • 7
    Jul 7th
    1 Files
  • 8
    Jul 8th
    15 Files
  • 9
    Jul 9th
    15 Files
  • 10
    Jul 10th
    20 Files
  • 11
    Jul 11th
    17 Files
  • 12
    Jul 12th
    16 Files
  • 13
    Jul 13th
    2 Files
  • 14
    Jul 14th
    1 Files
  • 15
    Jul 15th
    20 Files
  • 16
    Jul 16th
    27 Files
  • 17
    Jul 17th
    7 Files
  • 18
    Jul 18th
    5 Files
  • 19
    Jul 19th
    12 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2019 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close