Re: [FD] Netgear GS105Ev2 - Multiple Vulnerabilities

2016-03-04 Thread Nick Boyce
On 8 February 2016 at 21:23, I wrote: > > On 27 January 2016 at 15:56, Benedikt Westermann > wrote: > > > # Multiple Vulnerabilities - Netgear GS105Ev2 > [...] > > Firmware version: 1.3.0.3,1.4.0.2 > [...] > > Status: unfixed > > The Netgear website [1] shows that a new version of the firmware was

[FD] McAfee VirusScan Enterprise security restrictions bypass

2016-03-04 Thread Agazzini Maurizio
Security Advisory @ Mediaservice.net Srl (#01, 13/04/2016) Data Security Division Title: McAfee VirusScan Enterprise security restrictions bypass Application: McAfee VirusScan Enterprise 8.8 and prior versions Platform: Microsoft Window

[FD] Executable installers are vulnerable^WEVIL (case 29): putty-0.66-installer.exe allowa arbitrary (remote) code execution WITH escalation of privilege

2016-03-04 Thread Stefan Kanthak
Hi, putty-0.66-installer.exe loads and executes DWMAPI.dll or UXTheme.dll from its "application directory". For software downloaded with a web browser the application directory is typically the user's "Downloads" directory: see