Ping Identity Agentless Integration Kit versions prior to 1.5 suffer from a cross site scripting vulnerability.
9c150c77a9bce6accc3723843ec65700cdd8208915df10e20c19c5f97162c324
SSLsplit is a tool for man-in-the-middle attacks against SSL/TLS encrypted network connections. Connections are transparently intercepted through a network address translation engine and redirected to SSLsplit. SSLsplit terminates SSL/TLS and initiates a new SSL/TLS connection to the original destination address, while logging all data transmitted. SSLsplit is intended to be useful for network forensics and penetration testing.
ba0473fd01428439e0cf22fae80fdd26d08a0bcf85e17c82177cb0810b700faf
Zyxel USG/UAG/ATP/VPN/NXC series suffer from an issue where a DNS request can be made by an unauthenticated attacker to either spam a DNS service of a third party with requests that have a spoofed origin or probe whether domain names are present on the internal network behind the firewall.
d1f54ec01ba5b00cfa34a2d4469ebf60d85f134038071b4ccda0eb845965f314
An FTP service runs on the Zyxel wireless access point that contains the configuration file for the WiFi network. This FTP server can be accessed with hard-coded credentials that are embedded in the firmware of the AP. When the WiFi network is bound to another VLAN, an attacker can cross the network by fetching the credentials from the FTP server.
d8f9966f1cf6cfdad043939000c11dc5d57af44b55eeecde1c7d7957838c81b4
DomainMod versions 4.13 and below suffer from a cross site scripting vulnerability.
9a77f200dfd9284cde8bc12162d2ecae0bf890cf467a7745345eb70d55467bb6
Sentrifugo version 3.2 suffers from a persistent cross site scripting vulnerability.
8dea7b371326fb8468052218e1872aad7430951da5e6046ca8028361288c698b
Sentrifugo version 3.2 suffers from a file upload restriction bypass vulnerability.
b2ddc21cc34e199f03eedef6284b088fa2d72d49ab537de7e5b2543954cdb82f
Canon PRINT version 2.5.5 suffers from a content provider URI injection vulnerability.
dcee22bdc054fa25db75dc967498a61dd74c7c4e8473502f78c6cd765b702afe
VX Search Enterprise version 10.4.16 suffers from a User-Agent denial of service vulnerability.
60b99a7d14ce76ff859d716709231c8d1f25d64cb75f0399d5946a59cedde6f0
WordPress WooCommerce Product Feed plugin versions 2.2.18 and below suffer from a cross site scripting vulnerability.
7ee650f72feb594831ea81668b440c5432a38be763e03140bfab5492b60b0070
YouPHPTube version 7.4 suffers from a remote code execution vulnerability.
c852da415cdb99461bf905a3cb99585852af22f48fff8fe570f06294bdb68d86
Easy MP3 Downloader version 4.7.8.8 suffers from a denial of service vulnerability.
671ab08abaabae5d4f64ce0841a94831e10eaa969212276ba7a2338810f61664
SQL Server Password Changer version 1.90 suffers from a denial of service vulnerability.
bbc27cbf7d71b466a23989a55d074b52453f4374b992b76b635867bdad570c3c
Asus Precision TouchPad version 11.0.0.25 suffers from denial of service and privilege escalation via pool overflow vulnerabilities.
781fa5fb4c090fbf82b363a4a66c005d97b1e04a7867c3bca917aeebee30c6fa
This is a brief whitepaper on how to find savedata exploits on Sony PlayStation Vita (PS Vita).
188612d0c7a2539a8f339aa1aea144f2e79cae8e31e8f935cf054251a5ed4586
Ubuntu Security Notice 4113-1 - Stefan Eissing discovered that the HTTP/2 implementation in Apache did not properly handle upgrade requests from HTTP/1.1 to HTTP/2 in some situations. A remote attacker could use this to cause a denial of service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 19.04. Craig Young discovered that a memory overwrite error existed in Apache when performing HTTP/2 very early pushes in some situations. A remote attacker could use this to cause a denial of service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 19.04. Various other issues were also addressed.
fc01073e29fa98b6982a2c858a17b8ca2bb20084a922393ce6c10b57d28d56cf
This python script mints a .ps file with an exploitable semicolon condition that allows for command execution from Microsoft Windows PowerShell.
c030abc642a4fc06451a399c9721d06640d3154f8771ff2127c3bd516db33192
WebKitGTK+ and WPE WebKit suffer from code execution, universal cross site scripting, and memory corruption vulnerabilities. Multiple versions are affected.
717a870dd2bc0256ddcda1abe745089002e9d297d7a372d49f1407bce3834e9d
QEMU suffers from a denial of service vulnerability.
a7ace3948d40801e615564c65a1588dd104cf00c12897845832d6f387b26efdf
Red Hat Security Advisory 2019-2582-01 - Pango is a library for laying out and rendering of text, with an emphasis on internationalization. Pango forms the core of text and font handling for the GTK+ widget toolkit. Issues addressed include a buffer overflow vulnerability.
33c998429349460bae19a84051c87330740bd0e090eb14a23238b5ffc6016149
Ubuntu Security Notice 4112-1 - Abhishek Lekshmanan discovered that the RADOS gateway implementation in Ceph did not handle client disconnects properly in some situations. A remote attacker could use this to cause a denial of service.
6bdf721ecf66ba3944cc831f4f5afda69ab1538183c30580680e689e202d623a
Ubuntu Security Notice 4111-1 - Hiroki Matsukuma discovered that the PDF interpreter in Ghostscript did not properly restrict privileged calls when -dSAFER restrictions were in effect. If a user or automated system were tricked into processing a specially crafted file, a remote attacker could possibly use this issue to access arbitrary files.
1d8927fb5ab42e83bac5c9d5b553f9406fcbe964befd3851ce63f6117f2e091d
PilusCart versions 1.4.1 and below suffers from a file disclosure vulnerability.
f8908a36266e411cbdc113acc916de9d269db31ab793db6595c6e0bbb98e674b
Jobberbase version 2.0 suffers from a remote SQL injection vulnerability.
2b83d68859013bc6ed71c264b4a1f6e1105169783e4a3c067eb12b60f7b8572a
Webkit JSC JIT suffers from an uninitialized variable access vulnerability in ArgumentsEliminationPhase::transform.
13d8e2202cdebf7ff53e2e5906bdd6ba343e47a89003e53597579db4cb95bcdc