CVE-2016-4865
Cross-site scripting (XSS) vulnerability in the “Customapp” function in Cybozu Office 9.0.0 through 10.4.0.
Cross-site scripting (XSS) vulnerability in the “Customapp” function in Cybozu Office 9.0.0 through 10.4.0.
Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to conduct a “reflected file download” attack.
[This is a guest diary contributed by Remco Verhoef. If you would like to contribute a guest post, please let us know via our contact page] Currently there is a campaign going on where phishing attacks will use domains that lookexactly like safe domainsby using Punycode domains. (https://www.wordfence.com/blog/2017/04/chrome-firefox-unicode-phishing/) This is called a homograph attack. The …
Read more “Tool to Detect Active Phishing Attacks Using Unicode Look-Alike Domains, (Sun, Apr 16th)”
Artifex jbig2dec 0.13 has a heap-based buffer over-read leading to denial of service (application crash) or disclosure of sensitive information from process memory, because of an integer overflow in the jbig2_decode_symbol_dict function in jbig2_symbol_dict.c in libjbig2dec.a during operation on a crafted .jb2 file.
The mm subsystem in the Linux kernel through 4.10.10 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism, which allows local users to read or write to kernel memory locations in the first megabyte (and bypass slab-allocation access restrictions) via an application that opens the /dev/mem file, related to arch/x86/mm/init.c and drivers/char/mem.c.
With Fridays release of additional Shadowbroker tools, a lot of attention was spent on exploits with names like Eternalblue, which exploited only recently patched vulnerabilities. Another item of interesthowever, is the command and control channel used to communicate with systems post exploitation. One covert channel, double pulsar, is designed to particular for systems that are …
Read more “Detecting SMB Covert Channel ("Double Pulsar"), (Sun, Apr 16th)”
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a query string in an HTTP Referer header. This was found in core/admin/modules/developer/_header.php and patched in core/inc/bigtree/admin.php on 2017-04-14.
udevd in udev 232, when the Linux kernel 4.8.0 is used, does not properly verify the source of a Netlink message, which allows local users to execute arbitrary commands by leveraging access to the NETLINK_KOBJECT_UEVENT family, and the presence of the /lib/udev/rules.d/50-udev-default.rules file, to provide a crafted REMOVE_CMD value.
LibreOffice before 2017-03-14 has an out-of-bounds write related to the HWPFile::TagsRead function in hwpfilter/source/hwpfile.cxx.