Adobe Acrobat Reader DC for Windows – Use of Uninitialized Pointer due to Malformed JBIG2Globals Stream
We have observed the following access violation exception in the latest version of Adobe Acrobat Reader DC for Window...
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
We have observed the following access violation exception in the latest version of Adobe Acrobat Reader DC for Window...
We have observed the following access violation exception in the latest version of Adobe Acrobat Reader DC for Window...
# Exploit Title: Jenkins build-metrics plugin 1.3 - 'label' Cross-Site Scripting
# Exploit Title: SolarWinds Kiwi Syslog Server 8.3.52 - 'Kiwi Syslog Server' Unquoted Service Path
# Exploit Title: Adive Framework 2.0.7 - Privilege Escalation
# Exploit Title: Nextcloud 17 - Cross-Site Request Forgery
# Exploit Title: Adaware Web Companion version 4.8.2078.3950 - 'WCAssistantService' Unquoted Service Path
# Exploit Title: Wacom WTabletService 6.6.7-3 - 'WTabletServicePro' Unquoted Service Path
# Exploit Title: QNAP NetBak Replicator 4.5.6.0607 - 'QVssService' Unquoted Service Path
# Exploit Title: Smartwares HOME easy 1.0.9 - Client-Side Authentication Bypass
# Title: Smartwares HOME easy 1.0.9 - Database Backup Information Disclosure
# Exploit Title: thejshen Globitek CMS 1.4 - 'id' SQL Injection
# Exploit Title: Blue Stacks App Player 2.4.44.62.57 - "BstHdLogRotatorSvc" Unquote Service Path
# Exploit Title: thrsrossi Millhouse-Project 1.414 - 'content' Persistent Cross-Site Scripting
# Exploit Title: Network Inventory Advisor 5.0.26.0 - 'niaservice' Unquoted Service Path
# Exploit Title: rimbalinux AhadPOS 1.11 - 'alamatCustomer' SQL Injection
# Exploit Title: FileOptimizer 14.00.2524 - Denial of Service (PoC)
# Exploit Title: html5_snmp 1.11 - 'Remark' Persistent Cross-Site Scripting
# Exploit Title: html5_snmp 1.11 - 'Router_ID' SQL Injection
# Exploit Title: SD.NET RIM 4.7.3c - 'idtyp' SQL Injection
The following sample was found by Fuzzilli and then slightly modified. It crashes JSC in debug builds:
VULNERABILITY DETAILS
On macOS, when a new mount point is created, the kernel uses checkdirs() to, as
# Exploit Title: Aida64 6.10.5200 - Buffer Overflow (SEH)
# Exploit Title: OpenVPN Connect 3.0.0.272 - 'ovpnagent' Unquoted Service Path
# Exploit Title: Ayukov NFTP client 1.71 - 'SYST' Buffer Overflow
# Title: Launch Manager 6.1.7600.16385 'DsiWMIService' Unquoted Service Path
# Exploit Title: Apple macOS 10.15.1 - Denial of Service (PoC)
EDB Download ~ https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/47685.zip
#!/usr/bin/python
# Exploit Title: TheJshen contentManagementSystem 1.04 - 'id' SQL Injection
# Title: OpenVPN Private Tunnel 2.8.4 - 'ovpnagent' Unquoted Service Path
# Exploit Title: ownCloud 10.3.0 stable - Cross-Site Request Forgery
# Title: Apache Solr 8.2.0 - Remote Code Execution
# Exploit Title: MikroTik RouterOS 6.45.6 - DNS Cache Poisoning
# Exploit Title: Wordpress Plugin Google Review Slider 6.1 - 'tid' SQL Injection
# Exploit Title: WMV to AVI MPEG DVD WMV Convertor 4.6.1217 - Buffer OverFlow (SEH)
# Exploit Title: Ajenti 2.1.31 - Remote Code Exection (Metasploit)
# Exploit Title: Citrix StoreFront Server 7.15 - XML External Entity Injection
# Title: iSeeQ Hybrid DVR WH-H4 2.0.0.P - (get_jpeg) Stream Disclosure
# Exploit Title: WMV to AVI MPEG DVD WMV Convertor 4.6.1217 - Denial of Service
The following JavaScript program, found by Fuzzilli and slightly modified, crashes JavaScriptCore built from HEAD and...
# Exploit Title: Win10 MailCarrier 2.51 - 'POP3 User' Remote Buffer Overflow
# Exploit Title: rConfig 3.9.2 - Remote Code Execution
# Exploit Title: Intelligent Security System SecurOS Enterprise 10.2 - 'SecurosCtrlService' Unquoted Service Path
# Exploit Title: Wordpress 5.2.4 - Cross-Origin Resource Sharing