Node.JS node-serialize remote code execution exploit.
d4cff9dd6bf638bfad6430e7fdb98e3c41364d4bb5ae4c0a84b242ba5a992b80
Trojan-Dropper.Win32.Googite.b malware suffers from a code execution vulnerability.
c4c296961dc8e41f5d8e2fa7da763ac7a25c7f829d63b24f5a6ec102681a9a47
Ubuntu Security Notice 4992-1 - Máté Kukri discovered that the acpi command in GRUB 2 allowed privileged users to load crafted ACPI tables when secure boot is enabled. An attacker could use this to bypass UEFI Secure Boot restrictions. Chris Coulson discovered that the rmmod command in GRUB 2 contained a use- after-free vulnerability. A local attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. Chris Coulson discovered that a buffer overflow existed in the command line parser in GRUB 2. A local attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. Various other issues were also addressed.
1f9aec408e5162b86a8b71d82cc6be6d6601a5a4992dbb961c31198f605ea5bf
When analyzing the Protectimus SLIM TOTP hardware token, Matthias Deeg found out that the time used by the Protectimus SLIM TOTP hardware token can be set independently from the used seed value for generating time-based one-time passwords without requiring any authentication.
18da959eb49ff3d5b8d29ab92f7247fff8490774b451cce50831a03dc291d6c0
iFunbox version 4.2 suffers from an unquoted service path vulnerability.
282e697b6a984a007573280661f5c019cc2693b207326f3ff06fccb8c4ed6942
OpenEMR version 5.0.1.7 suffers from a path traversal vulnerability.
4137f1bcde3ba0b062231c438d7bd1885e04568f8cb1e019f5635288f2560b7d
ICE Hrm version 29.0.0.OS suffers from a persistent cross site scripting vulnerability.
81351aa19a519f6d67a50fa7c5f0e01f5776fd2f342d0cfce2bff3a6327604ca
Brief whitepaper that goes through proxy, ssh, and vpn pivoting during an attack. Written in Arabic.
a1e855c508e17641d2eb114eced9cbb69be22f676f04484aaf30c490b078784e
ICE Hrm version 29.0.0.OS suffers from a cross site request forgery vulnerability.
428307418f215e41128b67466956ad0750203da95db327aba348d9c16fad1e1d
ICE Hrm version 29.0.0.OS suffers from cross site scripting and session fixation vulnerabilities.
4f2a125bcf3c1919dd62b032560e0645fab870d5f7925db93ca9c712c8661782
Whitepaper called 'node-serialize' Remote Code Execution - Web Shell. Written in Turkish.
5258591e002e919f55d52d14edd0cf8d6b32488ebf99fbf4b7583e1a674d53bb