Apple WebKit suffers from a type confusion vulnerability in RenderBox with accessibility enabled.
Monthly Archives: January 2017
Apple WebKit HTMLKeygenElement Type Confusion
Apple WebKit suffers from a HTMLKeygenElement type confusion vulnerability.
Google Chrome HTMLKeygenElement::shadowSelect() Type Confusion
Google Chrome suffers from a HTMLKeygenElement::shadowSelect() type confusion vulnerability.
Stegano 0.6.3
Stegano is a basic Python Steganography module. Stegano implements two methods of hiding: using the red portion of a pixel to hide ASCII messages, and using the Least Significant Bit (LSB) technique. It is possible to use a more advanced LSB method based on integers sets. The sets (Sieve of Eratosthenes, Fermat, Carmichael numbers, etc.) are used to select the pixels used to hide the information.
Android RKP Information Disclosure
Android suffers from an RKP information disclosure vulnerability via s2-remapping physical ranges.
Android RKP EL1 Code Loading Bypass
Android suffers from an RKP EL1 code loading bypass vulnerability.
Packet Fence 6.5.0
PacketFence is a network access control (NAC) system. It is actively maintained and has been deployed in numerous large-scale institutions. It can be used to effectively secure networks, from small to very large heterogeneous networks. PacketFence provides NAC-oriented features such as registration of new network devices, detection of abnormal network activities including from remote snort sensors, isolation of problematic devices, remediation through a captive portal, and registration-based and scheduled vulnerability scans.
Android RKP Privilege Escalation
Android suffers from an RKP privilege escalation via unprotected MSRs in EL1 to memory management control registers.
Android cfp_ropp_new_key_reenc / cfp_ropp_new_key RKP Memory Corruption
Android suffers from an RKP memory corruption vulnerability in “cfp_ropp_new_key_reenc” and “cfp_ropp_new_key”.
Vuln: EMC Smarts Network Configuration Manager CVE-2017-2767 Remote Code Execution Vulnerability
EMC Smarts Network Configuration Manager CVE-2017-2767 Remote Code Execution Vulnerability