what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 51 - 75 of 923 RSS Feed

Files Date: 2024-09-01 to 2024-09-30

Ubuntu Security Notice USN-7037-1
Posted Sep 26, 2024
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 7037-1 - It was discovered that OpenJPEG could enter a large loop and continuously print warning messages when given specially crafted input. An attacker could potentially use this issue to cause a denial of service.

tags | advisory, denial of service
systems | linux, ubuntu
advisories | CVE-2023-39327
SHA-256 | 81b6eb730c0ee7967ac3037f5a6565c45a7035ff9d03a4513c0353b44a6b4a72
Red Hat Security Advisory 2024-7135-03
Posted Sep 26, 2024
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2024-7135-03 - An update for git-lfs is now available for Red Hat Enterprise Linux 8.

tags | advisory
systems | linux, redhat
advisories | CVE-2024-34156
SHA-256 | ac8ff5db3b68e1e549078a7f63ce692fda73d9577ac2a05cec5e7e0f8683243e
Ubuntu Security Notice USN-7038-1
Posted Sep 26, 2024
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 7038-1 - Thomas Stangner discovered a permission vulnerability in the Apache Portable Runtime library. A local attacker could possibly use this issue to read named shared memory segments, potentially exposing sensitive application data.

tags | advisory, local
systems | linux, ubuntu
advisories | CVE-2023-49582
SHA-256 | 4bc9ae4d066ade2386768445712f54f05bbaee490eb4829d2fe9fdbeacc1200d
Ubuntu Security Notice USN-7036-1
Posted Sep 26, 2024
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 7036-1 - It was discovered that Rack was not properly parsing data when processing multipart POST requests. If a user or automated system were tricked into sending a specially crafted multipart POST request to an application using Rack, a remote attacker could possibly use this issue to cause a denial of service. It was discovered that Rack was not properly escaping untrusted data when performing logging operations, which could cause shell escaped sequences to be written to a terminal. If a user or automated system were tricked into sending a specially crafted request to an application using Rack, a remote attacker could possibly use this issue to execute arbitrary code in the machine running the application.

tags | advisory, remote, denial of service, arbitrary, shell
systems | linux, ubuntu
advisories | CVE-2022-30122, CVE-2022-30123, CVE-2022-44572, CVE-2023-27530, CVE-2023-27539, CVE-2024-25126, CVE-2024-26141, CVE-2024-26146
SHA-256 | c4acd1ffc8ca871047fb8a39618d9c0b95465770474d22abee717b0b2de788ad
Ubuntu Security Notice USN-7035-1
Posted Sep 26, 2024
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 7035-1 - It was discovered that the AppArmor policy compiler incorrectly generated looser restrictions than expected for rules allowing mount operations. A local attacker could possibly use this to bypass AppArmor restrictions in applications where some mount operations were permitted.

tags | advisory, local
systems | linux, ubuntu
advisories | CVE-2016-1585
SHA-256 | 18e6675296e9bfadfac2c11a124d64d6e37cdc0a0120690b5b56b0de4b34dee9
SchoolPlus 1.0 SQL Injection
Posted Sep 26, 2024
Authored by indoushka

SchoolPlus version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection, bypass
SHA-256 | d2074cc8545a505ce1af1c27f59e640d90c6c616fbd247a73c1d9f5cea3d3385
School Log Management System 1.0 Code Injection
Posted Sep 26, 2024
Authored by indoushka

School Log Management System version 1.0 suffers from a PHP code injection vulnerability.

tags | exploit, php
SHA-256 | a34789327de460887266c735bef8f74228929d32d54ba320baa0cf19e9f7e3af
School Dormitory Management System 1.0 Insecure Settings
Posted Sep 26, 2024
Authored by indoushka

School Dormitory Management System version 1.0 suffers from an ignored default credential vulnerability.

tags | exploit
SHA-256 | 861e610b1a8c0b1120c4149e66a75572e6d4838142e38d7e89abb78b2b88e983
Sample Blog Site 1.0 SQL Injection
Posted Sep 26, 2024
Authored by indoushka

Sample Blog Site version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection, bypass
SHA-256 | 61eda3f220bcfb474e61a383d157f7559eaabd352c4d5b1a930e8077c163d977
Rupee Invoice System 1.0 Arbitrary File Upload
Posted Sep 26, 2024
Authored by indoushka

Rupee Invoice System version 1.0 suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
SHA-256 | 6fb3380fdbd9dc68d4cb8441ac475f25ac1ecd1029d07f228a330be33ec7258c
Restaurant POS 1.0 SQL Injection
Posted Sep 26, 2024
Authored by indoushka

Restaurant POS version 1.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 1efe1a827da05e9054d6424d0c6cbeffd061cb7a7b523985c9f815859c5ded7a
Responsive Binary mlm 3.2.0 SQL Injection
Posted Sep 26, 2024
Authored by indoushka

Responsive Binary mlm version 3.2.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection, bypass
SHA-256 | 7832158bdfb6f25736475de94f715b561965469ceb63c7f42c224430b50843df
Responsive Billing sw System 3.2.0 SQL Injection
Posted Sep 26, 2024
Authored by indoushka

Responsive Billing sw System version 3.2.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection, bypass
SHA-256 | a0219dae7fd1734f734512e67150e374366e1b2cf6be0d9351c5231f163d3f5a
PHP SPM 1.0 WYSIWYG Code Injection
Posted Sep 26, 2024
Authored by indoushka

PHP SPM version 1.0 suffers from a WYSIWYG code injection vulnerability.

tags | exploit, php
SHA-256 | 536b68dcbe9d4246c7b010d149de6d84d7dd1692847cf3ff869f37c679492ff7
PHP ACRSS 1.0 WYSIWYG Code Injection
Posted Sep 26, 2024
Authored by indoushka

PHP ACRSS version 1.0 suffers from a WYSIWYG code injection vulnerability.

tags | exploit, php
SHA-256 | 4007e9d326a3fe6cb1abc611dc7edabd1018b4749c72ecb7f637d013b3571243
ABB Cylon Aspect 3.07.00 Remote Code Execution
Posted Sep 25, 2024
Authored by LiquidWorm | Site zeroscience.mk

The ABB Cylon Aspect version 3.07.00 BMS/BAS controller suffers from an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through the host HTTP GET parameter called by networkDiagAjax.php script.

tags | exploit, web, arbitrary, shell, php
advisories | CVE-2023-0636
SHA-256 | 8123a5d0a4c6fa336d0b765079abb5168cf0f686b24baa715db1e55915f315fe
Gentoo Linux Security Advisory 202409-25
Posted Sep 25, 2024
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 202409-25 - Multiple vulnerabilities have been found in Xpdf, the worst of which could result in denial of service. Versions greater than or equal to 4.05 are affected.

tags | advisory, denial of service, vulnerability
systems | linux, gentoo
advisories | CVE-2018-16369, CVE-2018-7453, CVE-2022-30524, CVE-2022-30775, CVE-2022-33108, CVE-2022-36561, CVE-2022-38222, CVE-2022-38334, CVE-2022-38928, CVE-2022-41842, CVE-2022-41843, CVE-2022-41844, CVE-2022-43071, CVE-2022-43295
SHA-256 | fac11019c2046399ae717b97268560c482db032ca010a9a6d9a286947ef0235a
Ubuntu Security Notice USN-7034-1
Posted Sep 25, 2024
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 7034-1 - The ca-certificates package contained outdated CA certificates. This update refreshes the included certificates to those contained in the 2.64 version of the Mozilla certificate authority bundle.

tags | advisory
systems | linux, ubuntu
SHA-256 | 07051ae013dc2a27ea346908afccf5a1bad6728d7ac5c5a8b7c95220ee1faf34
Red Hat Security Advisory 2024-7103-03
Posted Sep 25, 2024
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2024-7103-03 - An update for grafana-pcp is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

tags | advisory
systems | linux, redhat
advisories | CVE-2024-34156
SHA-256 | 95813b2104bdc7d0b4d5656c87b1d08a95eb492573d9c521988dadea9af1c2df
Ubuntu Security Notice USN-7032-1
Posted Sep 25, 2024
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 7032-1 - It was discovered that Tomcat incorrectly handled HTTP trailer headers. A remote attacker could possibly use this issue to perform HTTP request smuggling.

tags | advisory, remote, web
systems | linux, ubuntu
advisories | CVE-2023-46589
SHA-256 | 19ad4cab25b37facba8c59f772004773b63724edac1ac9aadf381cd6bd195897
PHP SPM 1.0 Code Injection
Posted Sep 25, 2024
Authored by indoushka

PHP SPM version 1.0 suffers from a PHP code injection vulnerability.

tags | exploit, php
SHA-256 | 42eadddca12393ee271fabcce4e022f9356f7034e6fb3c8f39890de24c8c2b65
Red Hat Security Advisory 2024-7102-03
Posted Sep 25, 2024
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2024-7102-03 - An update for grafana is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

tags | advisory
systems | linux, redhat
advisories | CVE-2024-34156
SHA-256 | 932e594e58bd7c6b674ad73d959e34a51f6dcd3ad5862a855bbb608b0ebb54a2
Ubuntu Security Notice USN-7009-2
Posted Sep 25, 2024
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 7009-2 - Chenyuan Yang discovered that the CEC driver driver in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. Chenyuan Yang discovered that the USB Gadget subsystem in the Linux kernel did not properly check for the device to be enabled before writing. A local attacker could possibly use this to cause a denial of service.

tags | advisory, denial of service, arbitrary, kernel, local
systems | linux, ubuntu
advisories | CVE-2022-48772, CVE-2023-52887, CVE-2024-23848, CVE-2024-25741, CVE-2024-31076, CVE-2024-34027, CVE-2024-35247, CVE-2024-36015, CVE-2024-36032, CVE-2024-36489, CVE-2024-36894, CVE-2024-36972, CVE-2024-36974, CVE-2024-37356
SHA-256 | bc022d142c18a55625e63d62b56d8f76cf8e0a79f3f0ed802474777c8cbc4817
PHP ACRSS 1.0 Code Injection
Posted Sep 25, 2024
Authored by indoushka

PHP ACRSS version 1.0 suffers from a PHP code injection vulnerability.

tags | exploit, php
SHA-256 | 9a020e5f43760ba811c1702f617a4ccf04426dfe0e6f358f368a57c7bd6f3a92
Ubuntu Security Notice USN-7033-1
Posted Sep 25, 2024
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 7033-1 - It was discovered that some Intel Processors did not properly restrict access to the Running Average Power Limit interface. This may allow a local privileged attacker to obtain sensitive information. It was discovered that some Intel Processors did not properly implement finite state machines in hardware logic. This may allow a local privileged attacker to cause a denial of service.

tags | advisory, denial of service, local
systems | linux, ubuntu
advisories | CVE-2024-23984, CVE-2024-24968
SHA-256 | f8ba90a3153c8d619b3a6dea5959ad86e6310426029496d99414b1e5ad0e97b7
Page 3 of 37
Back12345Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close