[FD] [SBA-ADV-20200707-01] CVE-2020-36771: CloudLinux CageFS 7.1.1-1 or below Token Disclosure

2024-01-26 Thread SBA - Advisory via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 # CloudLinux CageFS Token Disclosure # Link: https://github.com/sbaresearch/advisories/tree/public/2020/SBA-ADV-20200707-01_CloudLinux_CageFS_Token_Disclosure ## Vulnerability Overview ## CloudLinux CageFS 7.1.1-1 or below passes the authenticati

[FD] [SBA-ADV-20200707-02] CVE-2020-36772: CloudLinux CageFS 7.0.8-2 or below Insufficiently Restricted Proxy Command

2024-01-26 Thread SBA - Advisory via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 # CloudLinux CageFS Insufficiently Restricted Proxy Command # Link: https://github.com/sbaresearch/advisories/tree/public/2020/SBA-ADV-20200707-02_CloudLinux_CageFS_Insufficiently_Restricted_Proxy_Commands ## Vulnerability Overview ## CloudLinux

[FD] [Full Disclosure] CVE-2024-22900: Unpatched Command Injection in Vinchin Backup and Recovery Versions 7.2 and Earlier

2024-01-26 Thread Balgogan via Fulldisclosure
CVE ID: CVE-2024-22900 Title: Command Injection Vulnerability in Vinchin Backup and Recovery Versions 7.2 and Earlier Description: A critical security vulnerability, identified as CVE-2024-22900, has been discovered in Vinchin Backup and Recovery software, affecting versions 7.2 and earlier. T

[FD] [Full Disclosure] CVE-2024-22899: Unpatched Command Injection in Vinchin Backup and Recovery Versions 7.2 and Earlier

2024-01-26 Thread Valentin Lobstein via Fulldisclosure
CVE ID: CVE-2024-22899 Title: Command Injection Vulnerability in Vinchin Backup and Recovery's syncNtpTime Function in Versions 7.2 and Earlier Description: A critical security vulnerability, identified as CVE-2024-22899, has been discovered in the `syncNtpTime` function of Vinchin Backup and R

[FD] [Full Disclosure] CVE-2024-22901: Default MYSQL Credentials in Vinchin Backup & Recovery v7.2 and Earlier

2024-01-26 Thread Valentin Lobstein via Fulldisclosure
CVE ID: CVE-2024-22901 Title: Default MYSQL Credentials Vulnerability in Vinchin Backup & Recovery v7.2 Description: A critical security issue, identified as CVE-2024-22901, has been discovered in Vinchin Backup & Recovery version 7.2. The software has been found to use default MYSQL credential

[FD] [Full Disclosure] CVE-2024-22902: Default Root Credentials in Vinchin Backup & Recovery v7.2 and Earlier

2024-01-26 Thread Valentin Lobstein via Fulldisclosure
CVE ID: CVE-2024-22902 Title: Default Root Credentials Vulnerability in Vinchin Backup & Recovery v7.2 Suggested Description: Vinchin Backup & Recovery version 7.2 has been identified as being configured with default root credentials, posing a significant security vulnerability. Additional Info

[FD] [Full Disclosure] CVE-2024-22903: Unpatched Command Injection in Vinchin Backup & Recovery Versions 7.2 and Earlier

2024-01-26 Thread Valentin Lobstein via Fulldisclosure
CVE ID: CVE-2024-22903 Title: Command Injection Vulnerability in SystemHandler.class.php of Vinchin Backup & Recovery Versions 7.2 and Earlier Description: A significant security vulnerability, CVE-2024-22903, has been identified in the `deleteUpdateAPK` function within the `SystemHandler.class

[FD] APPLE-SA-01-22-2024-1 Safari 17.3

2024-01-26 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-01-22-2024-1 Safari 17.3 Safari 17.3 addresses the following issues. Information about the security content is also available at https://support.apple.com/kb/HT214056. Apple maintains a Security Updates page at https://support.apple.com/HT

[FD] APPLE-SA-01-22-2024-2 iOS 17.3 and iPadOS 17.3

2024-01-26 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-01-22-2024-2 iOS 17.3 and iPadOS 17.3 iOS 17.3 and iPadOS 17.3 addresses the following issues. Information about the security content is also available at https://support.apple.com/kb/HT214059. Apple maintains a Security Updates page at ht

[FD] APPLE-SA-01-22-2024-3 iOS 16.7.5 and iPadOS 16.7.5

2024-01-26 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-01-22-2024-3 iOS 16.7.5 and iPadOS 16.7.5 iOS 16.7.5 and iPadOS 16.7.5 addresses the following issues. Information about the security content is also available at https://support.apple.com/kb/HT214063. Apple maintains a Security Updates pa

[FD] APPLE-SA-01-22-2024-4 iOS 15.8.1 and iPadOS 15.8.1

2024-01-26 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-01-22-2024-4 iOS 15.8.1 and iPadOS 15.8.1 iOS 15.8.1 and iPadOS 15.8.1 addresses the following issues. Information about the security content is also available at https://support.apple.com/kb/HT214062. Apple maintains a Security Updates pa

[FD] APPLE-SA-01-22-2024-5 macOS Sonoma 14.3

2024-01-26 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-01-22-2024-5 macOS Sonoma 14.3 macOS Sonoma 14.3 addresses the following issues. Information about the security content is also available at https://support.apple.com/kb/HT214061. Apple maintains a Security Updates page at https://support.

[FD] APPLE-SA-01-22-2024-6 macOS Ventura 13.6.4

2024-01-26 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-01-22-2024-6 macOS Ventura 13.6.4 macOS Ventura 13.6.4 addresses the following issues. Information about the security content is also available at https://support.apple.com/kb/HT214058. Apple maintains a Security Updates page at https://su

[FD] APPLE-SA-01-22-2024-7 macOS Monterey 12.7.3

2024-01-26 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-01-22-2024-7 macOS Monterey 12.7.3 macOS Monterey 12.7.3 addresses the following issues. Information about the security content is also available at https://support.apple.com/kb/HT214057. Apple maintains a Security Updates page at https://

[FD] APPLE-SA-01-22-2024-8 watchOS 10.3

2024-01-26 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-01-22-2024-8 watchOS 10.3 watchOS 10.3 addresses the following issues. Information about the security content is also available at https://support.apple.com/kb/HT214060. Apple maintains a Security Updates page at https://support.apple.com/

[FD] APPLE-SA-01-22-2024-9 tvOS 17.3

2024-01-26 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-01-22-2024-9 tvOS 17.3 tvOS 17.3 addresses the following issues. Information about the security content is also available at https://support.apple.com/kb/HT214055. Apple maintains a Security Updates page at https://support.apple.com/HT2012

[FD] TrojanSpy Win32 Nivdort / Insecure Permissions - EoP (SYSTEM)

2024-01-26 Thread malvuln
Discovery / credits: Malvuln (John Page aka hyp3rlinx) (c) 2024 Original source: https://malvuln.com/advisory/15bda00b57e2ed729a45f7cfa62165da.txt Contact: malvul...@gmail.com Media: twitter.com/malvuln Threat: TrojanSpy Win32 Nivdort Vulnerability: Insecure Permissions - EoP (SYSTEM) Family: Nivd

[FD] Yet another fork()/malloc() bomb in javascript + SIGILL in Chrome

2024-01-26 Thread Georgi Guninski
Searching the web for `javascript fork malloc bomb` returns results, e.g. [here][1]: and [here][2]: We got a javascript fork malloc bomb which crashed Chrome 121 on linux with SIGILL and about one in five runs the virtual machine freezes. SIGILL almost always is a sign of memory corruption :) On a

[FD] Multiple Vulnerabilities in Reprise License Manager 15.1 (CVE-2023-43183, CVE-2023-44031)

2024-01-26 Thread Rahim, Mohaiman via Fulldisclosure
Multiple Vulnerabilities in Reprise License Manager 15.1 (CVE-2023-43183, CVE-2023-44031) Credit: Mohaiman Rahim ///

[FD] Null pointer deference in freedesktop mesa

2024-01-26 Thread Meng Ruijie
[Vulnerability description] freedesktop Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete event unexpectedly when the application is using DR

[FD] Null pointer dereference in Xedit

2024-01-26 Thread Meng Ruijie
[Vulnerability description] A NULL pointer dereference in the component /X11/xedit/lisp of Xedit v1.2.3 allows attackers to cause a Denial of Service (DoS) via a crafted lisp.lsp file. [VulnerabilityType Other] null pointer deference [Vendor of Product] Xedit [Affected Product Code Base] Xedit

[FD] NULL pointer dereference in tgetstr() of ncurses

2024-01-26 Thread Meng Ruijie
[Vulnerability description] ncurses v6.4-20230610 was discovered to contain a NULL pointer dereference via the function tgetstr(). [VulnerabilityType Other] null pointer deference [Vendor of Product] ncurses [Affected Product Code Base] ncurses - 6.4-20230610 [Reference] https://lists.gnu.org/

[FD] Buffer Overflow in glXQueryServerString() of mesa

2024-01-26 Thread Meng Ruijie
[Vulnerability description] freedesktop Mesa v23.0.4 was discovered to contain a segmentation violation via the function glXQueryServerString(). [Vulnerability Type] Buffer Overflow [Vendor of Product] freedesktop [Affected Product Code Base] Mesa - 23.0.4 [Reference] https://gitlab.freedeskto

[FD] Null pointer deference in XGetWMHints() of Xfig

2024-01-26 Thread Meng Ruijie
[Vulnerability description] Xfig v3.2.8 was discovered to contain a segmentation violation via the function XGetWMHints(). [VulnerabilityType Other] null pointer deference [Vendor of Product] SourceForge [Affected Product Code Base] Xfig - 3.2.8 [Reference] https://sourceforge.net/p/mcj/ticket

[FD] NULL pointer dereference in the function handle_viminfo_register() of vim

2024-01-26 Thread Meng Ruijie
[Vulnerability description] A NULL pointer dereference in the function handle_viminfo_register() of vim v9.0 allows attackers to cause a Denial of Service (DoS) via crafted file. [VulnerabilityType Other] null pointer deference [Vendor of Product] vim [Affected Product Code Base] vim - 9.0 [Re

[FD] NULL pointer dereference in __glXGetDrawableAttribute() of Mesa

2024-01-26 Thread Meng Ruijie
[Vulnerability description] freedesktop Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function __glXGetDrawableAttribute(). [Vulnerability Type] Buffer Overflow [Vendor of Product] freedesktop [Affected Product Code Base] Mesa - 23.0.4 [Reference] https://gitlab.fre

[FD] NULL pointer dereference in XIQueryDevice() of gnome gtk

2024-01-26 Thread Meng Ruijie
[Vulnerability description] gnome gtk 824e9833 was discovered to contain a NULL pointer dereference via the function XIQueryDevice(). [VulnerabilityType Other] null pointer deference [Vendor of Product] gnome [Affected Product Code Base] gtk - 824e9833 [Reference] https://gitlab.gnome.org/GNOM

[FD] NULL pointer dereference in glXGetDrawableScreen() of OpenGL libglvnd

2024-01-26 Thread Meng Ruijie
[Vulnerability description] OpenGL libglvnd bb06db5a was discovered to contain a NULL pointer dereference via the function glXGetDrawableScreen(). [Vulnerability Type] Buffer Overflow [Vendor of Product] OpenGL [Affected Product Code Base] libglvnd - bb06db5a [Reference] https://gitlab.freedes

[FD] null pointer deference in GNU Midnight at /tty/x11conn.c

2024-01-26 Thread Meng Ruijie
[Vulnerability description] GNU Midnight Commander v4.8.29-146-g299d9a2fb was discovered to contain a segmentation violation via the function x_error_handler() at /tty/x11conn.c. [VulnerabilityType Other] null pointer deference [Vendor of Product] GNU [Affected Product Code Base] Midnight Comma

[FD] null pointer deference in gnome gdk-pixbuf

2024-01-26 Thread Meng Ruijie
[Vulnerability description] gnome gdk-pixbuf 4fc028aa was discovered to contain a segmentation violation via the function gdk_pixbuf_io_init_modules(). [VulnerabilityType Other] null pointer deference [Vendor of Product] gnome [Affected Product Code Base] gdk-pixbuf - 4fc028aa [Reference] http

[FD] arithmetic exception in S-lang via the function tt_sprintf()

2024-01-26 Thread Meng Ruijie
[Vulnerability description] S-Lang v2.3.2 was discovered to contain an arithmetic exception via the function tt_sprintf(). [VulnerabilityType Other] FPE [Vendor of Product] S-Lang [Affected Product Code Base] S-Lang - 2.3.2 [Reference] http://lists.jedsoft.org/lists/slang-users/2023/003.ht

[FD] null pointer deference in gnome gtk via init_randr15() at gdkscreen-x11.c

2024-01-26 Thread Meng Ruijie
[Vulnerability description] gnome gtk f2a28891 was discovered to contain a segmentation violation via the function init_randr15() at gdkscreen-x11.c. [VulnerabilityType Other] null pointer deference [Vendor of Product] gnome [Affected Product Code Base] gtk - f2a28891 [Reference] https://gitla

[FD] SEGV in S-Lang via fixup_tgetstr()

2024-01-26 Thread Meng Ruijie
[Vulnerability description] S-Lang v2.3.2 was discovered to contain a SEGV via the function fixup_tgetstr(). [VulnerabilityType Other] SEGV [Vendor of Product] S-Lang [Affected Product Code Base] S-Lang - 2.3.2 [Reference] http://lists.jedsoft.org/lists/slang-users/2023/002.html [CVE Refer

[FD] null pointer deference in gnome gtk via parse_settings() at xsettings-client.c

2024-01-26 Thread Meng Ruijie
[Vulnerability description] gnome gtk ac60bc60 was discovered to contain a segmentation violation via the function parse_settings() at xsettings-client.c. [VulnerabilityType Other] null pointer deference [Vendor of Product] gnome [Affected Product Code Base] gtk - ac60bc60 [Reference] https://

[FD] NULL pointer dereference in freedesktop Mesa via check_xshm()

2024-01-26 Thread Meng Ruijie
[Vulnerability description] freedesktop Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function check_xshm(). [Vulnerability Type] NULL pointer dereference [Vendor of Product] freedesktop [Affected Product Code Base] Mesa - 23.0.4 [Reference] https://gitlab.freedeskt

[FD] null pointer deference in nano via read_the_list()

2024-01-26 Thread Meng Ruijie
[Vulnerability description] Nano v6.2 was discovered to contain a segmentation violation via the function read_the_list(). [VulnerabilityType Other] null pointer deference [Vendor of Product] nano [Affected Product Code Base] nano - 6.2 [Reference] https://savannah.gnu.org/bugs/index.php?64465

[FD] NULL pointer dereference in QT via the function QXcbConnection::initializeAllAtoms()

2024-01-26 Thread Meng Ruijie
[Vulnerability description] QT v6.2, v6.5, and v6.6 was discovered to contain a NULL pointer dereference via the function QXcbConnection::initializeAllAtoms(). [VulnerabilityType Other] null pointer deference [Vendor of Product] qt [Affected Product Code Base] qt - 6.6, 6.5, 6.2 [Reference] ht

[FD] Buffer Overflow in graphviz via via a crafted config6a file

2024-01-26 Thread Meng Ruijie
[Vulnerability description] Buffer Overflow vulnerability in graphviz v.2.43.0 allows a remote attacker to execute arbitrary code via a crafted config6a file. [Vulnerability Type] Buffer Overflow [Vendor of Product] graphviz [Affected Product Code Base] graphviz - 2.43.0 [Reference] https://gi

[FD] null pointer deference in MiniZinc via a crafted .mzn file

2024-01-26 Thread Meng Ruijie
[Vulnerability description] Null pointer deference happens in MiniZinc v.2.7.6 via a crafted .mzn file. [VulnerabilityType Other] null pointer deference [Vendor of Product] MiniZinc [Affected Product Code Base] MiniZinc - 2.7.6 [Reference] https://github.com/MiniZinc/libminizinc/issues/730 [CV

[FD] null pointer deference in Sane via a crafted config file

2024-01-26 Thread Meng Ruijie
[Vulnerability description] A null pointer deference occurred in Sane v.1.2.1 via a crafted config file to the sanei_configure_attach() function. [VulnerabilityType Other] null pointer deference [Vendor of Product] sane [Affected Product Code Base] sane - 1.2.1 [Reference] https://gitlab.com/s

[FD] null pointer deference in tex-live via a crafted cmr10.pfb

2024-01-26 Thread Meng Ruijie
[Vulnerability description] A null pointer deference occurred in tex-live 944e257 via a crafted cmr10.pfb config file. [VulnerabilityType Other] null pointer deference [Vendor of Product] tex-live [Affected Product Code Base] tex-live - 944e257 [Reference] https://tug.org/pipermail/tex-live/20

[FD] null pointer deference in LLVM

2024-01-26 Thread Meng Ruijie
[Vulnerability description] A null pointer deference existed in LLVM v.15.0.0 via a crafted pdflatex.fmt file. [VulnerabilityType Other] null pointer deference [Vendor of Product] llvm [Affected Product Code Base] llvm - LLVM-15 [Reference] https://github.com/llvm/llvm-project/issues/67388 [C

[FD] null pointer deference in MiniZinc via a crafted Preferences.json file

2024-01-26 Thread Meng Ruijie
[Vulnerability description] A null pointer deference existed in MiniZinc v.2.7.6 via a crafted Preferences.json file. [VulnerabilityType Other] null pointer deference [Vendor of Product] MiniZinc [Affected Product Code Base] MiniZinc - 2.7.6 [Reference] https://github.com/MiniZinc/libminizinc/

[FD] null pointer deference in tex-live

2024-01-26 Thread Meng Ruijie
[Vulnerability description] A null pointer deference existed in tex-live v.944e257 via a crafted file to the texk/web2c/pdftexdir/tounicode.c function. [VulnerabilityType Other] null pointer deference [Vendor of Product] tex-live [Affected Product Code Base] tex-live - 944e257 [Reference] http

[FD] Buffer overflow in Sane

2024-01-26 Thread Meng Ruijie
[Vulnerability description] A buffer overflow existed in Sane v.1.2.1 via a crafted config file to the init_options() function. [Vulnerability Type] Buffer Overflow [Vendor of Product] sane [Affected Product Code Base] sane - 1.2.1 [Reference] https://gitlab.com/sane-project/backends/-/issues/