Re: [FD] LibTIFF 4.0.8 has multiple memory leak vulnerabilities (CVE-2017-16232)

2018-12-21 Thread Henri Salo
On Thu, Dec 20, 2018 at 09:03:08AM +0800, zzt0907 wrote: > # LibTIFF 4.0.8 has multiple memory leak vulnerabilities (CVE-2017-16232) > https://github.com/shelltdf/libtiff/commit/25f9ffa56548c1846c4a1f19308b7f561f7b1ab0 I'm curious why do you post about minor memory leak after over year from fix,

[FD] [CVE-2018-18009] dirary0.js on D-Link DIR-140L, DIR-640L devices allows remote unauthenticated attackers to discover admin credentials

2018-12-21 Thread Tyler Cui
[Vendor] us.dlink.com [Product] DIR-140L (version 1.02) DIR-640L (version 1.01RU) Other versions might also be affected. [Vulnerability Type] admin credentials disclosure [Affected Component] Web Interface [CVE Reference] CVE-2018-18009 [Security Issue] An authenticated user can visit

[FD] [CVE-2018-18008] spaces.htm on multiple D-Link devices (DSL, DIR, DWR) allows remote unauthenticated attackers to discover admin credentials

2018-12-21 Thread Tyler Cui
[Vendor] us.dlink.com [Product] D-Link DSL-2770L (version ME_1.01, ME_1.02, AU_1.06) D-Link DIR-140L, DIR-640L (version 1.00, 1.01RU, 1.02) D-Link DWR-116, DWR-512, DWR-555, DWR-921 (version V1.03, V1.05, V2.01, V2.02) [Vulnerability Type] admin credentials disclosure [Affected Component] Web

[FD] [CVE-2018-18007] atbox.htm on D-Link DSL-2770L devices allows remote unauthenticated attackers to discover admin credentials

2018-12-21 Thread Tyler Cui
[Vendor] us.dlink.com [Product] D-Link DSL-2770L (version ME_1.01, ME_1.02, AU_1.06) [Vulnerability Type] admin credentials disclosure [Affected Component] Web Interface [CVE Reference] CVE-2018-18007 [Security Issue] An authenticated user can visit the page atbox.htm, for example,

[FD] CVE-2018-20211 - DLL Hijacking in Exiftool v8.3.2.0

2018-12-21 Thread Rafael Pedrero
___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] CVE-2018-20193 - Privilege escalation in Juniper Secure Access SSL VPN - SA-4000, 5.1R5 (build 9627) 4.2 Release (build 7631)

2018-12-21 Thread Rafael Pedrero
In 2006... ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] DAVOSET v.1.3.7

2018-12-21 Thread MustLive
Hello participants of Mailing List. Since announcement of DAVOSET in 2010 and all releases, I've made next update of the software. Recently DAVOSET v.1.3.7 was released - DDoS attacks via other sites execution tool (http://websecurity.com.ua/davoset/). Video demonstration of DAVOSET:

[FD] New vulnerabilities in Transcend Wi-Fi SD Card

2018-12-21 Thread MustLive
Hello list! There are Directory Traversal and Cross-Site Request Forgery vulnerabilities in Transcend Wi-Fi SD Card. - Affected products: - Vulnerable is the next model: Transcend Wi-Fi SD Card 16 GB, Firmware v.1.8. This model with other

[FD] Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section

2018-12-21 Thread Murat Aydemir
I. VULNERABILITY - Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section II. CVE REFERENCE - CVE-2018-20339 III. VENDOR - https://www.manageengine.com IV. TIMELINE

[FD] Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section

2018-12-21 Thread Murat Aydemir
I. VULNERABILITY - Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section II. CVE REFERENCE - CVE-2018-20338 III. VENDOR - https://www.manageengine.com IV. TIMELINE

[FD] Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API

2018-12-21 Thread Murat Aydemir
I. VULNERABILITY - Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API. II. CVE REFERENCE - CVE-2018-20173 III. VENDOR - https://www.manageengine.com IV. TIMELINE

[FD] Capstone disassembler v4.0 is out!

2018-12-21 Thread Nguyen Anh Quynh
Greetings, We are super excited to announce version 4.0 of Capstone disassembler framework! Exactly 5 years ago, on December 18th of 2013, we published the first version. Today, this release 4.0 marks 5 years of our project! Such a long journey, which is impossible without huge community

[FD] [CORE-2018-0007] - GIGABYTE Driver Elevation of Privilege Vulnerabilities

2018-12-21 Thread advisories
SecureAuth - SecureAuth Labs Advisory http://www.secureauth.com/ GIGABYTE Drivers Elevation of Privilege Vulnerabilities *1. *Advisory Information** Title: GIGABYTE Drivers Elevation of Privilege Vulnerabilities Advisory ID: CORE-2018-0007 Advisory URL:

[FD] [CORE-2017-0012] - ASUS Drivers Elevation of Privilege Vulnerabilities

2018-12-21 Thread advisories
SecureAuth - SecureAuth Labs Advisory http://www.secureauth.com/ ASUS Drivers Elevation of Privilege Vulnerabilities *1. *Advisory Information** Title: ASUS Drivers Elevation of Privilege Vulnerabilities Advisory ID: CORE-2017-0012 Advisory URL:

[FD] Buffer Overflow in function match() PCRE 8.41 (CVE-2017-16231)

2018-12-21 Thread zzt0907
# Buffer Overflow in function match() PCRE 8.41 (CVE-2017-16231) ## Product Download: https://sourceforge.net/projects/pcre/files/pcre/ ## Vulnerability Type??Buffer Overflow ## Attack Type : local ## Vulnerability Description a pcretest load test PoC produces a crash overflow in the function

[FD] LibTIFF 4.0.8 has multiple memory leak vulnerabilities (CVE-2017-16232)

2018-12-21 Thread zzt0907
#CVE-2017-16232 # LibTIFF 4.0.8 has multiple memory leak vulnerabilities (CVE-2017-16232) ## Product Download: http://www.libtiff.org/ http://download.osgeo.org/libtiff/ ## Vulnerability Type??memory leak ## Attack Type : local ## Vulnerability Description LibTIFF 4.0.8 has multiple memory leak