low Microsoft Windows OpenType CFF Driver Stack Overflow By packetstormsecurity.com Published On :: Fri, 15 Apr 2011 14:28:37 GMT The VUPEN Vulnerability Research Team discovered a critical vulnerability in Microsoft Windows. The vulnerability is caused by a stack overflow error in the OpenType Compact Font Format (CFF) driver "ATMFD.dll" when processing certain operands within an OpenType font, which could be exploited by remote attackers to execute arbitrary code on a vulnerable Windows 7, Windows Server 2008, Windows Server 2008 R2, and Windows Vista systems via a malicious font, or by local attackers to gain elevated privileges on Windows XP and Windows Server 2003 systems via a malicious application. Full Article
low DVD X Player 5.5 .plf PlayList Buffer Overflow By packetstormsecurity.com Published On :: Fri, 02 Sep 2011 15:22:44 GMT This Metasploit module exploits a stack-based buffer overflow on DVD X Player 5.5 Pro and Standard. By supplying a long string of data in a plf file (playlist), the MediaPlayerCtrl.dll component will attempt to extract a filename out of the string, and then copy it on the stack without any proper bounds checking, which causes a buffer overflow, and results arbitrary code execution under the context of the user. This Metasploit module has been designed to target common Windows systems such as: Windows XP SP2/SP3, Windows Vista, and Windows 7. Full Article
low ACDSee FotoSlate PLP File id Parameter Overflow By packetstormsecurity.com Published On :: Mon, 10 Oct 2011 22:35:13 GMT This Metasploit module exploits a buffer overflow in ACDSee FotoSlate 4.0 Build 146 via a specially crafted id parameter in a String element. When viewing a malicious PLP file with the ACDSee FotoSlate product, a remote attacker could overflow a buffer and execute arbitrary code. This exploit has been tested on systems such as Windows XP SP3, Windows Vista, and Windows 7. Full Article
low CCMPlayer 1.5 Stack Buffer Overflow By packetstormsecurity.com Published On :: Sat, 03 Dec 2011 18:32:22 GMT This Metasploit module exploits a stack based buffer overflow in CCMPlayer 1.5. Opening a m3u playlist with a long track name, a SEH exception record can be overwritten with parts of the controllable buffer. SEH execution is triggered after an invalid read of an injectable address, thus allowing arbitrary code execution. This Metasploit module works on multiple Windows platforms including: Windows XP SP3, Windows Vista, and Windows 7. Full Article
low NTR ActiveX Control Check() Method Buffer Overflow By packetstormsecurity.com Published On :: Sat, 22 Sep 2012 06:44:12 GMT This Metasploit module exploits a vulnerability found in NTR ActiveX 1.1.8. The vulnerability exists in the Check() method, due to the insecure usage of strcat to build a URL using the bstrParams parameter contents, which leads to code execution under the context of the user visiting a malicious web page. In order to bypass DEP and ASLR on Windows Vista and Windows 7 JRE 6 is needed. Full Article
low MS13-005 HWND_BROADCAST Low to Medium Integrity Privilege Escalation By packetstormsecurity.com Published On :: Mon, 29 Jul 2013 22:14:06 GMT The Windows kernel does not properly isolate broadcast messages from low integrity applications from medium or high integrity applications. This allows commands to be broadcasted to an open medium or high integrity command prompts allowing escalation of privileges. We can spawn a medium integrity command prompt, after spawning a low integrity command prompt, by using the Win+Shift+# combination to specify the position of the command prompt on the taskbar. We can then broadcast our command and hope that the user is away and doesn't corrupt it by interacting with the UI. Broadcast issue affects versions Windows Vista, 7, 8, Server 2008, Server 2008 R2, Server 2012, RT. But Spawning a command prompt with the shortcut key does not work in Vista so you will have to check if the user is already running a command prompt and set SPAWN_PROMPT false. The WEB technique will execute a powershell encoded payload from a Web location. The FILE technique will drop an executable to the file system, set it to medium integrity and execute it. The TYPE technique will attempt to execute a powershell encoded payload directly from the command line but it may take some time to complete. Full Article
low Google Android RCE Bug Allows Attacker Full Device Access By packetstormsecurity.com Published On :: Tue, 05 May 2020 16:03:04 GMT Full Article headline privacy phone data loss flaw google
low Common Desktop Environment 2.3.1 Buffer Overflow By packetstormsecurity.com Published On :: Fri, 17 Jan 2020 16:40:08 GMT A buffer overflow in the CheckMonitor() function in the Common Desktop Environment 2.3.1 and earlier and 1.6 and earlier, as distributed with Oracle Solaris 10 1/13 (Update 11) and earlier, allows local users to gain root privileges via a long palette name passed to dtsession in a malicious .Xdefaults file. Note that Oracle Solaris CDE is based on the original CDE 1.x train, which is different from the CDE 2.x codebase that was later open sourced. Most notably, the vulnerable buffer in the Oracle Solaris CDE is stack-based, while in the open source version it is heap-based. Full Article
low Common Desktop Environment 2.3.1 / 1.6 libDtSvc Buffer Overflow By packetstormsecurity.com Published On :: Fri, 17 Apr 2020 22:37:07 GMT A difficult to exploit stack-based buffer overflow in the _DtCreateDtDirs() function in the Common Desktop Environment version distributed with Oracle Solaris 10 1/13 (Update 11) and earlier may allow local users to corrupt memory and potentially execute arbitrary code in order to escalate privileges via a long X11 display name. The vulnerable function is located in the libDtSvc library and can be reached by executing the setuid program dtsession. Versions 2.3.1 and below as well as 1.6 and earlier are affected. Full Article
low Oracle Solaris 11.x / 10 whodo / w Buffer Overflow By packetstormsecurity.com Published On :: Fri, 17 Apr 2020 22:38:30 GMT A difficult to exploit heap-based buffer overflow in setuid root whodo and w binaries distributed with Solaris allows local users to corrupt memory and potentially execute arbitrary code in order to escalate privileges. Full Article
low SMBv3 Compression Buffer Overflow By packetstormsecurity.com Published On :: Mon, 06 Apr 2020 19:01:13 GMT A vulnerability exists within the Microsoft Server Message Block 3.1.1 (SMBv3) protocol that can be leveraged to execute code on a vulnerable server. This local exploit implementation leverages this flaw to elevate itself before injecting a payload into winlogon.exe. Full Article
low Delta Industrial Automation DCISoft 1.12.09 Stack Buffer Overflow By packetstormsecurity.com Published On :: Sun, 14 Feb 2016 01:26:22 GMT Delta Industrial Automation DCISoft version 1.12.09 suffers from a stack buffer overflow vulnerability. Full Article
low Packet Storm Exploit 2013-0903-1 - Apple Safari Heap Buffer Overflow By packetstormsecurity.com Published On :: Wed, 04 Sep 2013 03:37:10 GMT A heap memory buffer overflow vulnerability exists within the WebKit's JavaScriptCore JSArray::sort(...) method. The exploit for this vulnerability is javascript code which shows how to use it for memory corruption of internal JS objects (Unit32Array and etc.) and subsequent arbitrary code execution (custom ARM/x64 payloads can be pasted into the JS code). This exploit affects Apple Safari version 6.0.1 for iOS 6.0 and OS X 10.7/8. Earlier versions may also be affected. It was obtained through the Packet Storm Bug Bounty program. Full Article
low Packet Storm Advisory 2013-0903-1 - Apple Safari Heap Buffer Overflow By packetstormsecurity.com Published On :: Wed, 04 Sep 2013 03:55:53 GMT A heap memory buffer overflow vulnerability exists within the WebKit's JavaScriptCore JSArray::sort(...) method. This method accepts the user-defined JavaScript function and calls it from the native code to compare array items. If this compare function reduces array length, then the trailing array items will be written outside the "m_storage->m_vector[]" buffer, which leads to the heap memory corruption. This finding was purchased through the Packet Storm Bug Bounty program. Full Article
low Linux Kernel Spectre V2 Defense Caused Massive Slowdown By packetstormsecurity.com Published On :: Tue, 20 Nov 2018 15:06:31 GMT Full Article headline linux flaw patch intel
low Critical Linux Wi-Fi Bug Allows System Compromise By packetstormsecurity.com Published On :: Sat, 19 Oct 2019 15:36:59 GMT Full Article headline linux wireless flaw
low Low-Orbit Internet Banking Fraud Claim Alleged To Be Space Junk By packetstormsecurity.com Published On :: Thu, 09 Apr 2020 14:33:35 GMT Full Article headline bank space fraud
low Global FDI flows stable in 2019, reports Unctad By www.fdiintelligence.com Published On :: Wed, 22 Jan 2020 10:52:15 +0000 Global FDI flows recorded a marginal 1% fall in 2019, but the value of announced greenfield investment projects plummets by 22%. Full Article
low Developing nations dominate free zone investment flows By www.fdiintelligence.com Published On :: Wed, 20 Nov 2019 13:01:43 +0000 Global free zones may be spurring development in less economically developed countries Full Article
low New Remote Bug in OpenSSH v3.3 and Below By packetstormsecurity.com Published On :: Mon, 24 Jun 2002 08:34:07 GMT Full Article ssh
low NV Energy's new 540-MWh storage and 475-MW solar project comes at a very low price By feedproxy.google.com Published On :: 2019-06-25T13:39:39Z 8minute Solar Energy, NV Energy and the Moapa Band of Paiutes announced that NV Energy selected 8minute to develop the largest solar plus storage project ever built in Nevada and one of the largest in the world. Full Article Editor's Pick News Utility Scale Grid Scale Solar Storage
low Fantasy Energy League Draft follow-up: breaking down the first round By feedproxy.google.com Published On :: 2019-07-18T14:15:27Z In late 2018, I put out the call to see how many fellow energy nerds I could gather to indulge me in combining my passion for energy analysis and clean power policy with my love of fantasy sports. By the end of January 2019, I had my cast of characters who somehow thought this idea was as fun as I did (isn’t the Internet the greatest tool for finding people who share your interests?) and I released my Draft Preview. Coordinating this draft among 14 different teams with different time zones and schedules chock-full of actually helping to save the planet proved no easy task, but by the end of March we had conducted 5 rounds of picks for a total of 70 selections in this Inaugural Fantasy Energy League! Full Article Hydropower Storage DER Bioenergy Wind Power Opinion & Commentary Geothermal
low LIHI certifies two low-impact hydroelectric facilities By feedproxy.google.com Published On :: 2019-07-19T14:39:00Z The Low Impact Hydropower Institute recently announced it had awarded low-impact certification status to two hydroelectric facilities: Full Article Environmental North America News Hydropower Generators and Electrical Components
low U.S. wind energy prices are at historical lows, DOE report says By feedproxy.google.com Published On :: 2019-08-13T18:24:00Z The national average price of wind power purchase agreements dropped to below 2 cents/kWh in 2018, according to the annual Wind Technologies Market Report released by the U.S. Department of Energy. Full Article Wind Power News
low California aims to fix low-income storage program and deliver new resilience incentives By feedproxy.google.com Published On :: 2019-09-06T13:11:51Z California’s energy storage incentive program has been a great success, with more than 11,000 battery storage systems installed to-date. The problem is, it’s not reaching the state’s most vulnerable communities. A new proposal from the California Public Utilities Commission (CPUC) aims to fix some of the barriers preventing disadvantaged communities from participating in the program, and it allocates $100 million to a new program designed to offset the cost of battery storage systems for populations threatened by wildfires and related utility power shutoffs. Full Article Energy Efficiency Microgrids News DER
low Lower than average wind speeds are hurting US wind power producers By feedproxy.google.com Published On :: 2019-02-25T14:11:58Z Unusually still weather in the upper Midwest and Great Plains in late 2018 has already taken a bite out of earnings at NextEra Energy Inc. and Avangrid Inc., which both operate large wind farms. Other wind generators have yet to report fourth-quarter results, including Pattern Energy Group Inc., TerraForm Power Inc. and Clearway Energy Inc. Full Article News Wind Power O&M Solar Utility Integration
low Idaho Power sets goal for 100-percent clean energy by 2045; signs record-low solar PPA By feedproxy.google.com Published On :: 2019-03-29T14:33:00Z Idaho Power unveiled a goal Tuesday to provide 100-percent clean energy by 2045 on the heels of an announcement that it will purchase 120-MW of solar energy through a PPA with Jackpot Holdings at a price of less than US $0.022 cents per kWh. Full Article News Editor's Pick Hydropower Storage Bioenergy Wind Power Solar Geothermal
low NV Energy's new 540-MWh storage and 475-MW solar project comes at a very low price By feedproxy.google.com Published On :: 2019-06-25T13:39:39Z 8minute Solar Energy, NV Energy and the Moapa Band of Paiutes announced that NV Energy selected 8minute to develop the largest solar plus storage project ever built in Nevada and one of the largest in the world. Full Article Editor's Pick News Utility Scale Grid Scale Solar Storage
low Delaware Joins 34 States in Passing C-PACE Legislation; A Cleaner Energy Supply to Follow By feedproxy.google.com Published On :: 2018-09-10T16:49:41Z Last month, Delaware Governor John Carney signed Senate Bill 113 into law, enabling Commercial Property Assessed Clean Energy (C-PACE) financing in Delaware. Once implemented, PACE will offer a new method for financing commercial energy efficiency and renewable energy projects. Full Article Energy Efficiency DER Rooftop News C&I DER
low Crowdfunding Sites That Allow True Investment in Renewable Energy and Sustainability: Alternatives to Kickstarter & Indiegogo By feedproxy.google.com Published On :: 2019-01-11T15:41:41Z Crowdfunding has become a popular tool for people and organizations to use to test out their new ideas for green products while securing funds to begin operations. The most well-known crowdfunding websites, Kickstarter and Indiegogo, have helped a significant amount of projects in renewable energy and sustainability get off the ground, projects that have been the focus of previous installments in my ongoing articles series about crowdfunding in energy. Full Article Energy Efficiency DER Onshore Bioenergy Opinion & Commentary Utility Integration
low Global Clean Energy Spending Dips in 2018 But Installations Rise on Lower Prices By feedproxy.google.com Published On :: 2019-01-18T17:35:05Z Global funding for clean-energy projects sagged in 2018 after China’s decision to curb subsidies dragged down installations in the world’s biggest solar market. Full Article News Hydropower Storage Energy Efficiency Bioenergy Wind Power Solar
low California aims to fix low-income storage program and deliver new resilience incentives By feedproxy.google.com Published On :: 2019-09-06T13:11:51Z California’s energy storage incentive program has been a great success, with more than 11,000 battery storage systems installed to-date. The problem is, it’s not reaching the state’s most vulnerable communities. A new proposal from the California Public Utilities Commission (CPUC) aims to fix some of the barriers preventing disadvantaged communities from participating in the program, and it allocates $100 million to a new program designed to offset the cost of battery storage systems for populations threatened by wildfires and related utility power shutoffs. Full Article Energy Efficiency Microgrids News DER
low Clean Energy Spending Drops 15 Percent to Reach Lowest Level Since 2013 By feedproxy.google.com Published On :: 2015-04-10T14:16:00Z Global investment in clean energy slumped 15 percent in the first quarter to the lowest level in two years because of a decline in wind and utility-scale projects. Full Article Storage Energy Efficiency Wind Power Solar
low Work stoppage ends at 20-MW Lower Modi Khola hydropower facility By feedproxy.google.com Published On :: 2016-10-05T20:46:00Z Construction resumed Oct. 4 on tunnel works after a brief work stoppage that began on Sept. 28 at the 20-MW Lower Modi Khola run-of-river hydropower facility. Full Article Baseload
low Idaho Power sets goal for 100-percent clean energy by 2045; signs record-low solar PPA By feedproxy.google.com Published On :: 2019-03-29T14:33:00Z Idaho Power unveiled a goal Tuesday to provide 100-percent clean energy by 2045 on the heels of an announcement that it will purchase 120-MW of solar energy through a PPA with Jackpot Holdings at a price of less than US $0.022 cents per kWh. Full Article News Editor's Pick Hydropower Storage Bioenergy Wind Power Solar Geothermal
low Microgrid with long-duration flow battery installed at U.S. Marine Corps Base Camp Pendleton By feedproxy.google.com Published On :: 2019-05-14T15:48:39Z This week energy storage maker ESS Inc said that it had deployed an Energy Warehouse (EW) long-duration flow battery system at Marine Corps Base Camp Pendleton in San Diego, California. Full Article Microgrids DER Microgrids News DER
low Flow battery company joins Power Africa to help power renewable microgrids By feedproxy.google.com Published On :: 2019-05-20T17:04:28Z On Monday, Portland-Oregon-based flow battery manufacturer ESS announced that it has joined Power Africa, a U.S. government-led partnership coordinated by the U.S. Agency for International Development (USAID), as a private sector partner. ESS is the program’s first flow battery partner. Full Article Microgrids Microgrids News Grid Scale DER DER Off-Grid
low NV Energy's new 540-MWh storage and 475-MW solar project comes at a very low price By feedproxy.google.com Published On :: 2019-06-25T13:39:39Z 8minute Solar Energy, NV Energy and the Moapa Band of Paiutes announced that NV Energy selected 8minute to develop the largest solar plus storage project ever built in Nevada and one of the largest in the world. Full Article Editor's Pick News Utility Scale Grid Scale Solar Storage
low Fantasy Energy League Draft follow-up: breaking down the first round By feedproxy.google.com Published On :: 2019-07-18T14:15:27Z In late 2018, I put out the call to see how many fellow energy nerds I could gather to indulge me in combining my passion for energy analysis and clean power policy with my love of fantasy sports. By the end of January 2019, I had my cast of characters who somehow thought this idea was as fun as I did (isn’t the Internet the greatest tool for finding people who share your interests?) and I released my Draft Preview. Coordinating this draft among 14 different teams with different time zones and schedules chock-full of actually helping to save the planet proved no easy task, but by the end of March we had conducted 5 rounds of picks for a total of 70 selections in this Inaugural Fantasy Energy League! Full Article Hydropower Storage DER Bioenergy Wind Power Opinion & Commentary Geothermal
low California aims to fix low-income storage program and deliver new resilience incentives By feedproxy.google.com Published On :: 2019-09-06T13:11:51Z California’s energy storage incentive program has been a great success, with more than 11,000 battery storage systems installed to-date. The problem is, it’s not reaching the state’s most vulnerable communities. A new proposal from the California Public Utilities Commission (CPUC) aims to fix some of the barriers preventing disadvantaged communities from participating in the program, and it allocates $100 million to a new program designed to offset the cost of battery storage systems for populations threatened by wildfires and related utility power shutoffs. Full Article Energy Efficiency Microgrids News DER
low Telecommunications Case Studies Address Head-in-Pillow (HnP) Defects and Mitigation through Assembly Process Modification and Control By www.ipc.org Published On :: Presentation by Russell Nowland of CommScope Full Article
low BGA Processing for Reliability: Dealing with Dissimilar Alloys and Avoiding Head on Pillow By www.ipc.org Published On :: Presentation by Jason Fullerton of ACI Technologies, Inc. Full Article
low An Investigation into Low Temperature Tin-bismuth and Tin-bismuth-silver Lead-free Alloy Solder Pastes By www.ipc.org Published On :: Presentation by Jasbir Bath of Christopher Associates. Full Article
low EU Needs Low-Carbon Energy Union, Ministers’ Advisory Panel Says By feedproxy.google.com Published On :: 2014-06-19T13:52:00Z The European Union needs an ambitious emissions-reduction goal, targets for energy- efficiency and renewables as well as tools to foster investment under its planned 2030 policies, an advisory panel to 14 ministers said. Full Article Storage Energy Efficiency Wind Power Solar
low Gas and Coal To Replace Hydropower in Brazil, Pollution to Follow By feedproxy.google.com Published On :: 2014-12-01T16:57:00Z The Brazilian government is seeking to award contracts in an auction tomorrow for natural gas- and coal-fueled power plants, reversing a drive that previously favored renewable-energy projects. It would lead to the first new thermal plants in three years, after the government scaled back such projects and awarded wind contracts starting in 2009 and solar energy earlier this year. Full Article Storage Energy Efficiency Wind Power Solar
low Energy Efficiency and Renewables Are Lowest Risk/Cost Investments for Utilities By feedproxy.google.com Published On :: 2014-12-02T13:27:00Z A new report by utility and finance experts contains positive news for the environment, our air and our (and our utilities’) pocketbooks — the economics of electric power resources have made zero-emissions energy efficiency and renewable energy technologies the most financially attractive options to meet the nation’s future energy demands. Full Article Energy Efficiency Hydropower Utility Scale Baseload Storage Energy Efficiency Bioenergy Policy Wind Power Opinion & Commentary Solar Geothermal
low New Navy Smart Microgrid Project Will Test Vanadium Flow Battery Storage By feedproxy.google.com Published On :: 2014-12-02T14:16:00Z The California Energy Commission (CEC) and U.S. Navy (USN) are teaming up to spur deployment of grid-integrated local renewable energy resources and advanced energy storage solutions. On December 1, Imergy Power Systems announced that its ESP30 series vanadium-flow batteries will be used in a CEC-sponsored Smart Microgrid project hosted by the Navy at its Mobile Utilities Support Equipment (MUSE) Facility in Port Hueneme, California. Full Article Microgrids Microgrids Hydropower Baseload Solar Storage
low Carpe Diem: Low Oil and Gas Prices Could Be a Clean-Energy Opportunity By feedproxy.google.com Published On :: 2015-02-05T12:03:00Z The recent dramatic plunge in oil and natural gas prices, to their lowest level since the global recession in 2009, has some observers worried about the effect on clean tech. Conventional wisdom has it that renewables have a tougher time competing when fossil fuels are cheap, making grid parity (in the case of natural gas-fired electricity) more elusive for solar and wind power. Full Article Energy Efficiency Hydropower Baseload Storage Energy Efficiency Bioenergy Policy Wind Power Opinion & Commentary Solar Project Development Geothermal
low Will Lower Oil Prices Dampen the Mining Industry’s Appetite for Renewables? By feedproxy.google.com Published On :: 2015-02-16T15:09:00Z For many mining companies, the rallying cry for investigating solar or wind energy options has been that the price of oil and other conventional fuels is too high — and will almost certainly rise over time. Now, though, with oil prices having taken a dramatic nosedive, this argument no longer packs quite the same punch that it once did. Full Article Energy Efficiency Hydropower Baseload Storage Energy Efficiency Bioenergy Wind Power Solar Project Development Geothermal
low UK Low-Carbon Contract Winners Revealed: Wind Scores, Solar Disappoints By feedproxy.google.com Published On :: 2015-02-27T16:38:00Z The first round of the Contracts for Difference (CfD) programme — the UK scheme that is designed to support low-carbon generation and a capacity margin in the energy sector — has concluded. Contracts were offered to 27 renewable electricity projects with a total value of some £315 million (US$500 million), which include two offshore wind farms with a total planned capacity of more than 1.1 GW, 15 onshore wind projects and five solar projects. In total, more 2 GW of new low-carbon capacity (including renewables, nuclear and carbon capture and storage) could be built under the CfD scheme. Full Article Baseload Onshore Bioenergy Wind Power Solar Project Development Offshore