This Metasploit module triggers a stack buffer overflow in Wireshark versions 1.8.12/1.10.5 and below by generating an malicious file.
9a0517e6d1e5163de35e4817296671008162392223a5c12c8ee4a7970047e1f9
This exploit leverage a stack overflow vulnerability to escalate privileges. The vulnerable function nfs_convert_old_nfs_args does not verify the size of a user-provided argument before copying it to the stack. As a result by passing a large size, a local user can overwrite the stack with arbitrary content. Mac OS X Lion Kernel versions equal to and below xnu-1699.32.7 except xnu-1699.24.8 are affected.
7dda844fc6c2159587750ff9bbb7d5956502e05e69840baeb969d48120b1443f
HP Security Bulletin HPSBMU03017 2 - A potential security vulnerability has been identified with HP Software Connect-IT running OpenSSL. The Heartbleed vulnerability was detected in specific OpenSSL versions. OpenSSL is a 3rd party product that is embedded with some of HP Software products. This bulletin objective is to notify HP Software customers about products affected by the Heartbleed vulnerability. Note: The Heartbleed vulnerability (CVE-2014-0160) is a vulnerability found in the OpenSSL product cryptographic software library product. This weakness potentially allows disclosure of information protected, under normal conditions, by the SSL/TLS protocol. Revision 2 of this advisory.
e9a78459f7e987b83bf4af8f0957d2dda3712e58121f226f6f32537579683a93
VideoWhisper version 7 for Drupal suffers from a cross site scripting vulnerability.
3cb36f0f355441197eacc71c9ca9d019691be0cbec19e7c31df8fb082d3eb583
Depot WiFi version 1.0.0 for iOS suffers from code execution and local file inclusion vulnerabilities.
239876a4258fa1ffcf2718fcb13020b5cd7008ce28f17eef80d30d9eaea994bd
GeoCore MAX DB version 7.3.3 suffers from a time-based remote blind SQL injection vulnerability.
64ba7edde32456837b3726c9218f6cbada0d228c7d4a3ff8408e3d7216df33dc
HP Security Bulletin HPSBMU03023 - A potential security vulnerability has been identified in HP BladeSystem c-Class Virtual Connect Support Utility (VCSU) running OpenSSL on Linux and Windows. This is the OpenSSL vulnerability known as "Heartbleed" which could be exploited remotely resulting in disclosure of information. The Virtual Connect firmware itself is not vulnerable to CVE-2014-0160 (Heartbleed), however, the installer component in versions 4.10 and 4.20 of Virtual Connect does have the vulnerability, and should be replaced with versions 4.10b or 4.20b, or the latest version of Virtual Connect Support Utility referenced below. The VCSU vulnerability is only present during the firmware upgrade process. Revision 1 of this advisory.
265d34dec60e1f903018c216fd1d7594a225c2b117f6462facc19c5c9c6b82cc
WordPress iMember360is plugin versions 3.8.012 through 3.9.001 suffers from arbitrary code execution, database credential disclosure, arbitrary user deletion, and cross site scripting vulnerabilities.
4d85f0311356c907bff3b2196646e771d62abcd6b04f759570f4f0300a39cb77
HP Security Bulletin HPSBST03016 - A potential security vulnerability has been identified in HP P2000 G3 MSA Array Systems, HP MSA 2040 Storage, and HP MSA 1040 Storage running OpenSSL.This is the OpenSSL vulnerability known as "Heartbleed" which could be exploited remotely resulting in disclosure of information. Revision 1 of this advisory.
cc603d74519194ed684085382b3f25f8e81c35c6cb29ed84719965071aec239b
HP Security Bulletin HPSBMU02895 SSRT101253 2 - Potential security vulnerabilities have been identified with HP Data Protector. These vulnerabilities could be remotely exploited to allow an increase of privilege, create a Denial of Service (DoS), or execute arbitrary code. Revision 2 of this advisory.
0a07ff8e1b3e2972b6af5cc5d704474d68bf9a9d401e1cdab7ed39724fa01539
Debian Linux Security Advisory 2906-1 - Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service, information leak or privilege escalation.
336839d986f877d0c9633d42e6961fa76ae807751676c40199ee1f7de18091c3
Debian Linux Security Advisory 2912-1 - Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in the execution of arbitrary code, breakouts of the Java sandbox, information disclosure or denial of service.
79dfda837e78d1e5259e544223cb2c97b5077035eab63af2590729a5832b5f12
WordPress Work-The-Flow plugin version 1.2.1 suffers from a remote shell upload vulnerability.
81151a69aad7d23a4b3ad3b647d219987ca81d347d7e6393e87eb89ac65182da
Kolibri version 2.0 GET request stack buffer overflow exploit that spawns a bindshell on TCP/4444.
329f1e7a41c16584e5af9f1499b811f888b81bccdba1aee77683cad9955bd7b6
InfraRecorder version 0.53 suffers from a unicode buffer overflow vulnerability.
0b8679268a6b10a4b2a1deab7b8b065f4eb7d1e739f4942337e4e38231c083d0
The WordPress Echelon theme suffers from a remote shell upload vulnerability.
c33b258feee36d875dc4c0082563970e58db338744d94505982121e9877a3449
xnews version 3-0-0 suffers from a cross site scripting vulnerability.
cb801e3e008731eae78be6fac9fbc8ace62b194df563ec4abc47db0f3fbefd09
Live.com suffered from a UI redressing attack.
225b94c84cff17ea94e1fb2b927ea713b15076fee01dcd5ee0b5645ae0ed3abf