Security
Headlines
HeadlinesLatestCVEs

Source

Packet Storm

Impress CMS 1.3.9 Open Redirection

Impress CMS version 1.3.9 suffers from an open redirection vulnerability.

Packet Storm
#vulnerability#windows#google#php#auth#firefox
ImgHosting 1.3 HTML Injection

ImgHosting version 1.3 suffers from a html injection vulnerability.

Humhub 1.3.13 Shell Upload

Humhub version 1.3.13 suffers from a remote shell upload vulnerability.

Packet Storm New Exploits For August, 2023

This archive contains all of the 305 exploits added to Packet Storm in August, 2023.

Tinycontrol LAN Controller 3 Remote Admin Password Change

Tinycontrol LAN Controller version 3 suffers from an insecure access control allowing an unauthenticated attacker to change accounts passwords and bypass authentication gaining panel control access.

Tinycontrol LAN Controller 3 Remote Credential Extraction

Tinycontrol LAN Controller version 3 suffers from an issue where an unauthenticated attacker can retrieve the controller's configuration backup file and extract sensitive information that can allow him/her/them to bypass security controls and penetrate the system in its entirety.

Tinycontrol LAN Controller 3 Denial Of Service

Tinycontrol LAN Controller version 3 suffers from an unauthenticated remote denial of service vulnerability. An attacker can issue direct requests to the stm.cgi page to reboot and also reset factory settings on the device.

Debian Security Advisory 5487-1

Debian Linux Security Advisory 5487-1 - A security issue was discovered in Chromium, which could result in the execution of arbitrary code.

Ubuntu Security Notice USN-6332-1

Ubuntu Security Notice 6332-1 - Daniel Moghimi discovered that some Intel Processors did not properly clear microarchitectural state after speculative execution of various instructions. A local unprivileged user could use this to obtain to sensitive information. William Zhao discovered that the Traffic Control subsystem in the Linux kernel did not properly handle network packet retransmission in certain situations. A local attacker could use this to cause a denial of service.

VMWare Aria Operations For Networks Remote Code Execution

VMWare Aria Operations for Networks (vRealize Network Insight) static SSH key remote code execution proof of concept exploit.