pti macOS/iOS ImageIO PVR Image Processing Heap Corruption By packetstormsecurity.com Published On :: Fri, 07 Feb 2020 16:07:56 GMT macOS and iOS have an ImageIO heap corruption issue when processing malformed PVR images. Full Article
pti macOS / iOS launchd XPC Message Parsing Memory Corruption By packetstormsecurity.com Published On :: Thu, 13 Feb 2020 15:53:01 GMT launchd on macOS and iOS suffer from a memory corruption issue due to a lack of bounds checking when parsing XPC messages. Full Article
pti iOS / macOS AWDL Heap Corruption / Bounds Checking By packetstormsecurity.com Published On :: Mon, 09 Mar 2020 10:11:11 GMT A remote iOS / macOS heap corruption issue exists due to insufficient bounds checking in AWDL. Full Article
pti SuperBackup 2.0.5 Persistent Cross Site Scripting By packetstormsecurity.com Published On :: Wed, 15 Apr 2020 18:29:35 GMT SuperBackup version 2.0.5 for iOS suffers from a persistent cross site scripting vulnerability. Full Article
pti AirDisk Pro 5.5.3 Persistent Cross Site Scripting By packetstormsecurity.com Published On :: Wed, 15 Apr 2020 18:39:20 GMT AirDisk Pro version 5.5.3 for iOS suffers from multiple persistent cross site scripting vulnerabilities. Full Article
pti Folder Lock 3.4.5 Cross Site Scripting By packetstormsecurity.com Published On :: Mon, 20 Apr 2020 18:44:44 GMT Folder Lock version 3.4.5 for iOS suffers from multiple cross site scripting vulnerabilities. Full Article
pti Sky File 2.1.0 Cross Site Scripting / Directory Traversal By packetstormsecurity.com Published On :: Tue, 21 Apr 2020 14:33:56 GMT Sky File version 2.1.0 for iOS suffers from cross site scripting and directory traversal vulnerabilities. Full Article
pti RSA Warns Over NSA Link To Encryption Algorithm By packetstormsecurity.com Published On :: Fri, 20 Sep 2013 15:16:59 GMT Full Article headline government privacy flaw nsa cryptography rsa
pti Hollywood Takes The Bait, Options McAfee Movie By packetstormsecurity.com Published On :: Tue, 15 Jan 2013 05:10:35 GMT Full Article headline mcafee
pti CloudFlare Probes Mystery Interception Of Site Traffic Across India By packetstormsecurity.com Published On :: Thu, 14 Jul 2016 14:30:56 GMT Full Article headline privacy india
pti Ac4p.com Gallery 1.0 Cross Site Scripting / Shell Upload / Bypass / Disclosure By packetstormsecurity.com Published On :: Tue, 23 Feb 2010 07:00:24 GMT Ac4p.com Gallery version 1.0 suffers from cross site scripting, phpinfo disclosure, shell upload, and insecure cookie handling vulnerabilities. Full Article
pti P5 FNIP-8x16A/FNIP-4xSH CSRF / Cross Site Scripting By packetstormsecurity.com Published On :: Tue, 21 Apr 2020 14:15:30 GMT P5 FNIP-8x16A / FNIP-4xSH versions 1.0.20 and 1.0.11 suffer from cross site request forgery and cross site scripting vulnerabilities. Full Article
pti osTicket 1.12 File Upload Cross Site Scripting By packetstormsecurity.com Published On :: Sun, 11 Aug 2019 17:54:59 GMT An issue was discovered in osTicket versions before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no) mitigations implemented for file content checks; also, the output is not handled properly, causing persistent XSS that leads to cookie stealing or malicious actions. Full Article
pti Without Encryption We Will Lose All Privacy. This Is Our New Battleground. By packetstormsecurity.com Published On :: Tue, 15 Oct 2019 13:49:15 GMT Full Article headline government privacy usa spyware nsa cryptography
pti Option Way Exposed Personal Info On Customers By packetstormsecurity.com Published On :: Wed, 04 Sep 2019 13:52:48 GMT Full Article headline privacy data loss identity theft
pti PHP-Fusion CMS 9.03 Cross Site Scripting By packetstormsecurity.com Published On :: Wed, 26 Feb 2020 19:33:33 GMT PHP-Fusion CMS versions 9 through 9.03 suffer from multiple cross site scripting vulnerabilities. Full Article
pti Neowise CarbonFTP 1.4 Insecure Proprietary Password Encryption By packetstormsecurity.com Published On :: Tue, 21 Apr 2020 14:18:20 GMT Neowise CarbonFTP version 1.4 suffers from an insecure proprietary password encryption implementation. Second version of this exploit that is updated to work with Python 3. Full Article
pti CentOS-WebPanel.com Control Web Panel 0.9.8.846 Cross Site Scripting By packetstormsecurity.com Published On :: Mon, 05 Aug 2019 20:55:44 GMT CentOS-WebPanel.com Control Web Panel (CWP) version 0.9.8.846 suffers from a reflective cross site scripting vulnerability. Full Article
pti CentOS 7.6.1810 Control Web Panel 0.9.8.837 Cross Site Scripting By packetstormsecurity.com Published On :: Mon, 26 Aug 2019 15:59:03 GMT CentOS version 7.6.1810 with Control Web Panel version 0.9.8.837 suffers from a persistent cross site scripting vulnerability. Full Article
pti User Management System 2.0 Cross Site Scripting By packetstormsecurity.com Published On :: Thu, 23 Apr 2020 19:19:35 GMT User Management System version 2.0 suffers from a persistent cross site scripting vulnerability. Full Article
pti Complaint Management System 4.2 Cross Site Scripting By packetstormsecurity.com Published On :: Thu, 23 Apr 2020 19:24:07 GMT Complaint Management System version 4.2 suffers from a persistent cross site scripting vulnerability. Full Article
pti jQuery html() Cross Site Scripting By packetstormsecurity.com Published On :: Sat, 25 Apr 2020 12:23:23 GMT jQuery versions prior to 3.5 suffer from an html() cross site scripting vulnerability. Full Article
pti Open-AudIT 3.3.0 Cross Site Scripting By packetstormsecurity.com Published On :: Sun, 26 Apr 2020 19:22:22 GMT Open-AudIT version 3.3.0 suffers from a cross site scripting vulnerability. Full Article
pti Geeklog 2.2.1 Cross Site Scripting By packetstormsecurity.com Published On :: Mon, 27 Apr 2020 14:55:02 GMT Geeklog version 2.2.1 suffers from a cross site scripting vulnerability. Full Article
pti POS PHP 17.5 Cross Site Scripting By packetstormsecurity.com Published On :: Tue, 28 Apr 2020 14:50:09 GMT POS PHP version 17.5 suffers from a persistent cross site scripting vulnerability. Full Article
pti Easy Transfer 1.7 Cross Site Scripting / Directory Traversal By packetstormsecurity.com Published On :: Tue, 28 Apr 2020 14:52:49 GMT Easy Transfer version 1.7 for iOS suffers from cross site scripting and directory traversal vulnerabilities. Full Article
pti ChemInv 1 Cross Site Scripting By packetstormsecurity.com Published On :: Thu, 30 Apr 2020 14:52:47 GMT ChemInv version 1 suffers from a persistent cross site scripting vulnerability. Full Article
pti Online Scheduling System 1.0 Cross Site Scripting By packetstormsecurity.com Published On :: Thu, 30 Apr 2020 19:22:22 GMT Online Scheduling System version 1.0 suffers from a persistent cross site scripting vulnerability. Full Article
pti PHP-Fusion 9.03.50 Cross Site Scripting By packetstormsecurity.com Published On :: Thu, 30 Apr 2020 23:03:33 GMT PHP-Fusion version 9.03.50 suffers from a persistent cross site scripting vulnerability. Full Article
pti osTicket 1.14.1 Cross Site Scripting By packetstormsecurity.com Published On :: Sun, 03 May 2020 18:22:11 GMT osTicket version 1.14.1 suffers from a persistent cross site scripting vulnerability. Full Article
pti WordPress WooCommerce Advanced Order Export 3.1.3 Cross Site Scripting By packetstormsecurity.com Published On :: Tue, 05 May 2020 20:51:15 GMT WordPress WooCommerce Advanced Order Export plugin version 3.1.3 suffers from a cross site scripting vulnerability. Full Article
pti Online Clothing Store 1.0 Cross Site Scripting By packetstormsecurity.com Published On :: Wed, 06 May 2020 14:53:08 GMT Online Clothing Store version 1.0 suffers from a persistent cross site scripting vulnerability. Full Article
pti Sentrifugo CMS 3.2 Cross Site Scripting By packetstormsecurity.com Published On :: Thu, 07 May 2020 15:19:23 GMT Sentrifugo CMS version 3.2 suffers from a persistent cross site scripting vulnerability. Full Article
pti iChat 1.6 Cross Site Scripting By packetstormsecurity.com Published On :: Thu, 07 May 2020 15:21:46 GMT iChat version 1.6 suffers from a cross site scripting vulnerability. Full Article
pti OpenZ ERP 3.6.60 Cross Site Scripting By packetstormsecurity.com Published On :: Thu, 07 May 2020 15:25:10 GMT OpenZ ERP version 3.6.60 suffers from a persistent cross site scripting vulnerability. Full Article
pti Draytek VigorAP Cross Site Scripting By packetstormsecurity.com Published On :: Thu, 07 May 2020 15:32:09 GMT Draytek VigorAP suffers from a persistent cross site scripting vulnerability. Multiple different versions are affected. Full Article
pti Tiny MySQL Cross Site Scripting By packetstormsecurity.com Published On :: Fri, 08 May 2020 19:44:36 GMT Tiny MySQL suffers from a cross site scripting vulnerability. Full Article
pti WebTareas 2.0p8 Cross Site Scripting By packetstormsecurity.com Published On :: Fri, 08 May 2020 19:48:57 GMT WebTareas version 2.0p8 suffers from a cross site scripting vulnerability. Full Article
pti WordPress Dosimple Theme 2.0 Cross Site Scripting By packetstormsecurity.com Published On :: Fri, 08 May 2020 19:52:13 GMT WordPress Dosimple theme version 2.0 suffers from a cross site scripting vulnerability. Full Article
pti Grub2 grub2-set-bootflag Environment Corruption By packetstormsecurity.com Published On :: Wed, 27 Nov 2019 23:02:22 GMT Grub2 has grub2-set-bootflag setuid in the new Fedora release and has the ability to corrupt the environment. Full Article
pti Accepting Network Update Texts Could Have Pwned Your Mobe By packetstormsecurity.com Published On :: Thu, 05 Sep 2019 13:39:40 GMT Full Article headline hacker phone flaw israel google
pti Brazilian Judge Orders Another WhatsApp Block Over Message Encryption By packetstormsecurity.com Published On :: Wed, 20 Jul 2016 00:57:38 GMT Full Article headline government privacy spyware facebook brazil cryptography
pti CHIYU BF430 TCP IP Converter Cross Site Scripting By packetstormsecurity.com Published On :: Tue, 11 Feb 2020 15:44:17 GMT CHIYU BF430 TCP IP Converter suffers from a persistent cross site scripting vulnerability. Full Article
pti Design And Implementation Of A Voice Encryption System For Telephone Networks By packetstormsecurity.com Published On :: Mon, 01 Sep 2014 14:02:22 GMT This whitepaper goes into detail on design and implementation details for performing voice encryption on telephone networks. Written in Spanish. Full Article
pti Juniper Secure Access Cross Site Scripting By packetstormsecurity.com Published On :: Sat, 06 Mar 2010 15:42:52 GMT Juniper Secure Access suffers from a cross site scripting vulnerability. SA Appliances running Juniper IVE OS 6.0 or higher are affected. Full Article
pti Juniper SSL VPN Bypass / Cross Site Scripting By packetstormsecurity.com Published On :: Tue, 09 Nov 2010 01:05:48 GMT This is a list of older cross site scripting and bypass vulnerabilities associated with older Juniper IVE releases. Full Article
pti Juniper Secure Access Cross Site Scripting By packetstormsecurity.com Published On :: Tue, 23 Jul 2013 14:44:44 GMT Juniper Secure Access software suffers from a reflective cross site scripting vulnerability. Full Article
pti Juniper JunOS 9.x Cross Site Scripting By packetstormsecurity.com Published On :: Wed, 24 Jul 2013 17:01:11 GMT Juniper JunOS version 9.x suffers from a html injection vulnerability that allows for cross site scripting attacks. Full Article
pti Packet Storm Exploit 2013-0827-1 - Oracle Java ByteComponentRaster.verify() Memory Corruption By packetstormsecurity.com Published On :: Tue, 27 Aug 2013 23:58:22 GMT The ByteComponentRaster.verify() method in Oracle Java versions prior to 7u25 is vulnerable to a memory corruption vulnerability that allows bypassing of "dataOffsets[]" boundary checks. This exploit code demonstrates remote code execution by popping calc.exe. It was obtained through the Packet Storm Bug Bounty program. Full Article
pti Packet Storm Exploit 2013-0917-1 - Oracle Java ShortComponentRaster.verify() Memory Corruption By packetstormsecurity.com Published On :: Tue, 17 Sep 2013 04:45:32 GMT The ShortComponentRaster.verify() method in Oracle Java versions prior to 7u25 is vulnerable to a memory corruption vulnerability that allows bypassing of "dataOffsets[]" boundary checks when the "numDataElements" field is 0. This exploit code demonstrates remote code execution by popping calc.exe. It was obtained through the Packet Storm Bug Bounty program. Full Article