ag macOS / iOS launchd XPC Message Parsing Memory Corruption By packetstormsecurity.com Published On :: Thu, 13 Feb 2020 15:53:01 GMT launchd on macOS and iOS suffer from a memory corruption issue due to a lack of bounds checking when parsing XPC messages. Full Article
ag macOS / iOS ImageIO OpenEXR Image Processing Memory Issues By packetstormsecurity.com Published On :: Mon, 02 Mar 2020 19:19:48 GMT macOS and iOS have a vulnerability with ImageIO where memory safety issues occur when processing OpenEXR images. Full Article
ag Firefox Zero Day Was Used In Attack Against Coinbase Employees By packetstormsecurity.com Published On :: Thu, 20 Jun 2019 17:00:52 GMT Full Article headline hacker flaw mozilla firefox cryptography
ag RSA Conference Registration Page Collecting Twitter Credentials By packetstormsecurity.com Published On :: Fri, 22 Jan 2016 14:27:30 GMT Full Article headline data loss flaw password twitter conference rsa
ag Intel Finds Critical Holes In Secret Management Engine By packetstormsecurity.com Published On :: Tue, 21 Nov 2017 18:50:10 GMT Full Article headline flaw mcafee backdoor intel
ag XMB - eXtreme Message Board 1.9.11.13 Weak Crypto / Insecure Password Storage By packetstormsecurity.com Published On :: Sat, 23 Jan 2016 13:03:33 GMT XMB - eXtreme Message Board version 1.9.11.13 suffers from weak crypto and insecure password storage vulnerabilities. Full Article
ag Android Securty Research: Crypto Local Storage Attack By packetstormsecurity.com Published On :: Thu, 28 Feb 2019 20:22:22 GMT Whitepaper called Android Security Research: Crypto Wallet Local Storage Attack. Full Article
ag Facebook's New Privacy Tool Lets You Manage How You're Tracked By packetstormsecurity.com Published On :: Tue, 28 Jan 2020 15:39:48 GMT Full Article headline privacy facebook social
ag WhatsApp Axes COVID-19 Mass Message Forwarding By packetstormsecurity.com Published On :: Wed, 08 Apr 2020 15:36:16 GMT Full Article headline facebook
ag Dynamic MessageBoxA||W PEB And Import Table Method Shellcode By packetstormsecurity.com Published On :: Wed, 18 Mar 2020 15:10:48 GMT 232 bytes small Dynamic MessageBoxA||W PEB and Import Table Method shellcode. Full Article
ag PHPKB Multi-Language 9 Authenticated Directory Traversal By packetstormsecurity.com Published On :: Mon, 16 Mar 2020 13:56:01 GMT PHPKB Multi-Language 9 suffers from an authenticated directory traversal vulnerability. Full Article
ag 50 Arrested In Smartphone Spyware Dragnet By packetstormsecurity.com Published On :: Thu, 01 Jul 2010 11:35:47 GMT Full Article phone spyware romania
ag U.S. Agent Lures Romanian Hackers In Subway Data Heist By packetstormsecurity.com Published On :: Fri, 18 Apr 2014 15:09:59 GMT Full Article headline hacker government bank usa romania
ag Cisco Patches Router OS Against New Crypto Attack By packetstormsecurity.com Published On :: Wed, 15 Aug 2018 03:44:19 GMT Full Article headline flaw patch cisco cryptography
ag 88 Cisco Products Affected By FragmentSmack By packetstormsecurity.com Published On :: Wed, 26 Sep 2018 16:24:18 GMT Full Article headline linux denial of service flaw cisco
ag Cisco Warns Of Critical Flaws In Data Center Network Manager By packetstormsecurity.com Published On :: Thu, 27 Jun 2019 14:09:21 GMT Full Article headline flaw cisco
ag Planes, Gate, And Bags: How Hackers Can Hijack Your Local Airport By packetstormsecurity.com Published On :: Fri, 11 Oct 2019 14:57:26 GMT Full Article headline hacker terror
ag Feds Once Again Demand Apple Unlock Encrypted iPhones By packetstormsecurity.com Published On :: Wed, 08 Jan 2020 16:25:50 GMT Full Article headline government privacy usa phone apple terror fbi cryptography
ag Tesla Autopilot Duped By Phantom Images By packetstormsecurity.com Published On :: Wed, 05 Feb 2020 17:05:20 GMT Full Article headline flaw terror
ag Exagate Sysguard 6001 Cross Site Request Forgery By packetstormsecurity.com Published On :: Fri, 20 Mar 2020 14:45:22 GMT Exagate Sysguard 6001 suffers from a cross site request forgery vulnerability. Full Article
ag Complaint Management System 4.2 Cross Site Request Forgery By packetstormsecurity.com Published On :: Thu, 23 Apr 2020 19:31:05 GMT Complaint Management System version 4.2 suffers from a cross site request forgery vulnerability. Full Article
ag Cisco Data Center Network Manager Unauthenticated Remote Code Execution By packetstormsecurity.com Published On :: Mon, 02 Sep 2019 18:04:06 GMT DCNM exposes a file upload servlet (FileUploadServlet) at /fm/fileUpload. An authenticated user can abuse this servlet to upload a WAR to the Apache Tomcat webapps directory and achieve remote code execution as root. This module exploits two other vulnerabilities, CVE-2019-1619 for authentication bypass on versions 10.4(2) and below, and CVE-2019-1622 (information disclosure) to obtain the correct directory for the WAR file upload. This module was tested on the DCNM Linux virtual appliance 10.4(2), 11.0(1) and 11.1(1), and should work on a few versions below 10.4(2). Only version 11.0(1) requires authentication to exploit (see References to understand why). Full Article
ag Malicious SMS Messages Can Wipe A Galaxy By packetstormsecurity.com Published On :: Wed, 25 Jan 2017 15:17:50 GMT Full Article headline phone flaw samsung
ag Microsoft Windows NtUserMNDragOver Local Privilege Escalation By packetstormsecurity.com Published On :: Fri, 08 May 2020 20:05:13 GMT This Metasploit module exploits a NULL pointer dereference vulnerability in MNGetpItemFromIndex(), which is reachable via a NtUserMNDragOver() system call. The NULL pointer dereference occurs because the xxxMNFindWindowFromPoint() function does not effectively check the validity of the tagPOPUPMENU objects it processes before passing them on to MNGetpItemFromIndex(), where the NULL pointer dereference will occur. This module has been tested against Windows 7 x86 SP0 and SP1. Offsets within the solution may need to be adjusted to work with other versions of Windows, such as Windows Server 2008. Full Article
ag 4 US Agencies Don't Properly Verify Your Data Due To The Equifax Breach By packetstormsecurity.com Published On :: Fri, 14 Jun 2019 16:08:03 GMT Full Article headline government privacy usa data loss fraud identity theft
ag 200K Sign Petition Against Equifax Data Breach Settlement By packetstormsecurity.com Published On :: Mon, 23 Sep 2019 16:52:50 GMT Full Article headline privacy data loss identity theft
ag Facebook Agrees To Pay $550 Million To End Facial Recognition Tech Lawsuit By packetstormsecurity.com Published On :: Thu, 30 Jan 2020 15:06:03 GMT Full Article headline government privacy usa data loss identity theft facebook
ag PHPKB Multi-Language 9 image-upload.php Code Execution By packetstormsecurity.com Published On :: Mon, 16 Mar 2020 13:57:49 GMT PHPKB Multi-Language 9 suffers from an image-upload.php remote authenticated code execution vulnerability. Full Article
ag Megaupload Founder Can Sue New Zealand Spy Agency By packetstormsecurity.com Published On :: Thu, 07 Mar 2013 05:08:34 GMT Full Article headline government riaa mpaa pirate new zealand
ag Kimble's Extradition Hearing Delayed Again By packetstormsecurity.com Published On :: Mon, 07 Jul 2014 15:17:46 GMT Full Article headline government usa riaa mpaa new zealand
ag Win32/XP SP3 Windows Magnifier Shellcode By packetstormsecurity.com Published On :: Mon, 02 May 2011 23:43:16 GMT 52 bytes small Win32/XP SP3 windows magnifier shellcode. Full Article
ag Magento WooCommerce CardGate Payment Gateway 2.0.30 Bypass By packetstormsecurity.com Published On :: Tue, 25 Feb 2020 15:09:50 GMT Magento WooCommerce CardGate Payment Gateway version 2.0.30 suffers from a payment process bypass vulnerability. Full Article
ag Ivanti Workspace Manager Security Bypass By packetstormsecurity.com Published On :: Wed, 18 Mar 2020 14:54:31 GMT Ivanti Workspace Manager versions prior to 10.3.90 suffer from a bypass vulnerability. Full Article
ag ManageEngine DataSecurity Plus Authentication Bypass By packetstormsecurity.com Published On :: Fri, 08 May 2020 19:50:07 GMT ManageEngine DataSecurity Plus versions prior to 6.0.1 and ADAudit Plus versions prior to 6.0.3 suffer from an authentication bypass vulnerability. Full Article
ag IBM Data Risk Manager 2.0.3 Default Password By packetstormsecurity.com Published On :: Tue, 05 May 2020 21:10:41 GMT This Metasploit module abuses a known default password in IBM Data Risk Manager. The a3user has the default password idrm and allows an attacker to log in to the virtual appliance via SSH. This can be escalate to full root access, as a3user has sudo access with the default password. At the time of disclosure, this is a 0day. Versions 2.0.3 and below are confirmed to be affected, and the latest 2.0.6 is most likely affected too. Full Article
ag Nexus Repository Manager 3.21.1-01 Remote Code Execution By packetstormsecurity.com Published On :: Thu, 16 Apr 2020 15:37:25 GMT This Metasploit module exploits a Java Expression Language (EL) injection in Nexus Repository Manager versions up to and including 3.21.1 to execute code as the Nexus user. Tested against 3.21.1-01. Full Article
ag Spectre Chip Security Vulnerability Strikes Again By packetstormsecurity.com Published On :: Tue, 22 May 2018 06:36:24 GMT Full Article headline flaw intel
ag Intel's SGX Coughs Up Crypto Keys When Scientists Tweak CPU Voltage By packetstormsecurity.com Published On :: Wed, 11 Dec 2019 16:44:11 GMT Full Article headline flaw cryptography intel
ag RIAA Wants Infamous File-Sharer To Campaign Against Piracy By packetstormsecurity.com Published On :: Thu, 11 Jul 2013 14:51:08 GMT Full Article headline riaa mpaa pirate
ag User Management System 2.0 Cross Site Scripting By packetstormsecurity.com Published On :: Thu, 23 Apr 2020 19:19:35 GMT User Management System version 2.0 suffers from a persistent cross site scripting vulnerability. Full Article
ag Complaint Management System 4.2 Cross Site Scripting By packetstormsecurity.com Published On :: Thu, 23 Apr 2020 19:24:07 GMT Complaint Management System version 4.2 suffers from a persistent cross site scripting vulnerability. Full Article
ag Grub2 grub2-set-bootflag Environment Corruption By packetstormsecurity.com Published On :: Wed, 27 Nov 2019 23:02:22 GMT Grub2 has grub2-set-bootflag setuid in the new Fedora release and has the ability to corrupt the environment. Full Article
ag vReliable Datagram Sockets (RDS) rds_page_copy_user Privilege Escalation By packetstormsecurity.com Published On :: Mon, 23 Dec 2019 21:02:43 GMT This Metasploit module exploits a vulnerability in the rds_page_copy_user function in net/rds/page.c (RDS) in Linux kernel versions 2.6.30 to 2.6.36-rc8 to execute code as root (CVE-2010-3904). This module has been tested successfully on Fedora 13 (i686) kernel version 2.6.33.3-85.fc13.i686.PAE and Ubuntu 10.04 (x86_64) with kernel version 2.6.32-21-generic. Full Article
ag Brazilian Judge Orders Another WhatsApp Block Over Message Encryption By packetstormsecurity.com Published On :: Wed, 20 Jul 2016 00:57:38 GMT Full Article headline government privacy spyware facebook brazil cryptography
ag Telegram Voicemail Hack Used Against Brazil's President, Ministers By packetstormsecurity.com Published On :: Fri, 26 Jul 2019 15:54:32 GMT Full Article headline hacker government phone spyware brazil
ag Digital Whisper Electronic Magazine #87 By packetstormsecurity.com Published On :: Sun, 01 Oct 2017 23:08:47 GMT Digital Whisper Electronic Magazine issue 87. Written in Hebrew. Full Article
ag Digital Whisper Electronic Magazine #88 By packetstormsecurity.com Published On :: Sat, 18 Nov 2017 23:22:22 GMT Digital Whisper Electronic Magazine issue 88. Written in Hebrew. Full Article
ag Digital Whisper Electronic Magazine #89 By packetstormsecurity.com Published On :: Fri, 01 Dec 2017 03:33:33 GMT Digital Whisper Electronic Magazine issue 89. Written in Hebrew. Full Article
ag Digital Whisper Electronic Magazine #90 By packetstormsecurity.com Published On :: Tue, 02 Jan 2018 04:44:44 GMT Digital Whisper Electronic Magazine issue 90. Written in Hebrew. Full Article
ag Digital Whisper Electronic Magazine #92 By packetstormsecurity.com Published On :: Wed, 01 Aug 2018 01:11:11 GMT Digital Whisper Electronic Magazine issue 92. Written in Hebrew. Full Article