A buffer overflow vulnerability exists in AoA DVD Creator ActiveX 2.6.2. The vulnerability is caused due to a boundary error when handling a specially crafted SetImageData() method call. This can be exploited to cause a stack-based buffer overflow by e.g. passing an overly long string to the affected method. Successful exploitation may allow execution of arbitrary code.
A buffer overflow vulnerability exists in AoA Audio Extractor Basic ActiveX 2.3.7. The vulnerability is caused due to a boundary error when handling a specially crafted HTML page. This can be exploited to cause a stack-based buffer overflow by e.g. enticing a user to visit a malicious web site. Successful exploitation may allow execution of arbitrary code.
This vulnerability allows remote attackers to create an administrator account on the CMS without being authenticated. To exploit the flaw, a SMTP configuration has to be configured on SPIP because the password is sent by mail.
check_dhcp plugin that is a part of the official Nagios Plugins package contains a vulnerability that allows a malicious attacker to read parts of INI config files belonging to root on a local system. It could allow an attacker to obtain sensitive information like passwords that should only be accessible by root user. The vulnerability is due to check_dhcp plugin having Root SUID permissions and inappropriate access control when reading user provided files.
A null pointer dereference vulnerability exists in Mozilla Firefox prior to version 29.0. An attacker can exploit this vulnerability to cause a denial of service condition. The vulnerability is due to an error when handling a crafted HTML page. This can be exploited to cause a null pointer dereference in the function NS_NewLocalFile. This can be exploited to cause a denial of service condition.
The issue is with the cairo_image_surface_get_data() function in Cairo. These fields are vulnerable: Filter text box, Statistics -> IP DESTINATIONS, Statistics -> IP Addresses. Paste the generated text in any one of above fields and hit return.
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. Be aware this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.
By sending the following request to the BROADCOM PIPA C211 web interface it is possible to retrieve complete system configuration including administrative credentials, SMTP community strings, FTP upload credentials and all other system user credentials.
This proof of concept code will crash TFTPD32 and TFTPD64. By changing the $j and $i loop limits, the EIP can reach 0x2E373231 ("127.") or any string contained in TFTPD32 error logs, and sometimes EIP reaches addresses similar to 0x00013200, which may enable Remote Code Execution using some form of heap-spray.
This exploit is a proof-of-concept for CVE-2013-1763, a vulnerability in the Linux kernel that allows for privilege escalation. The bug was found by Spender and the proof-of-concept was written by SynQ. The exploit is hard-coded for kernel 3.5.0-17-generic #28-Ubuntu SMP Tue Oct 9 19:32:08 UTC 2012 i686 i686 i686 GNU/Linux and uses nl_table->hash.rehash_time, index 81. The exploit was updated in February 2013 to add support for Fedora 18.