header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Palo Alto Networks Terminal Services Agent Integer Overflow

An integer overflow vulnerability exists in the Palo Alto Networks Terminal Services Agent driver (panta.sys) version 6.0.7.0. The vulnerability is caused by a lack of proper validation of user-supplied input when allocating memory. An attacker can exploit this vulnerability by supplying a specially crafted input to the driver, resulting in an integer overflow, which can be used to execute arbitrary code in the context of the kernel.

Polycom VVX Web Interface – Change Admin Password as User

This module requires the user to have access to the 'User' account (Default User:123) in the Polycom VoIP phone's web interface. The user can use the following steps to escalate privileges and become the Admin user to reveal menu items internal IP addresses and account information. Login with the 'User' Account. Navigate to Settings > Change Password. Fill in 'Old Password' with the current 'User' password. Fill in 'New Password' with the new 'Admin' account password, and confirm. Using a live HTML editor, inspect the old password field. Change the name field to '120'. Click 'Save'. An error will be shown on screen but you can now log into the Admin account with the new password.

OpenSSH 6.8-6.9 local privilege escalation – CVE-2015-6565

OpenSSH 6.8-6.9 is vulnerable to a local privilege escalation vulnerability due to a race condition in the PTY allocation code. This vulnerability allows a local user to gain root privileges. The vulnerability was discovered by Jann Horn and was assigned CVE-2015-6565.

Systemd Local Root Exploit

This is a heads up for a trivial systemd local root exploit, that was silently fixed in the upstream git as: commit 06eeacb6fe029804f296b065b3ce91e796e1cd0e. The analysis says that is a 'possible DoS', but its a local root exploit indeed. Mode 07777 also contains the suid bit, so files created by touch() are world writable suids, root owned. Such as /var/lib/systemd/timers/stamp-fstrim.timer thats found on a non-nosuid mount. This is trivially exploited by something like: http://www.halfdog.net/Security/2015/SetgidDirectoryPrivilegeEscalation/CreateSetgidBinary.c with minimal changes, so no PoC is provided. The bug was possibly introduced via: commit ee735086f8670be1591fa9593e80dd60163a7a2f. We believe that this mostly affects v228 of systemd, but its recommended that distributors cross-check their systemd versions for vulnerable touch_*() functions.

TM RG4332 Wireless Router Traversal Arbitrary File Read

This exploit allows an attacker to read arbitrary files on the TM RG4332 Wireless Router. By sending a specially crafted HTTP request, an attacker can traverse the directory structure of the router and read any file on the system. This vulnerability is due to insufficient input validation of the 'getpage' parameter in the webproc CGI script.

Recent Exploits: