All Vulnerabilities
Microsoft Internet Explorer And Edge Elevation Of Privilege Vulnerability (CVE-20...
Severity:
Date Published:  26 Oct 2016
A privilege escalation vulnerability exists when Microsoft Internet Explorer or Edge fails to properly secure private namespace. An attacker who successfully exploited this vulnerability could gain elevated permissions on the namespace directory of a vulnerable system and gain elevated privileges.
Microsoft Windows True Type Font Parsing Elevation Of Privilege Vulnerability (CV...
Severity:
Date Published:  26 Oct 2016
An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploits this vulnerability could run arbitrary code in kernel mode.
Microsoft Windows Kernel Local Elevation Of Privilege Vulnerability (CVE-2016-007...
Severity:
Date Published:  26 Oct 2016
A local privilege escalation vulnerability was discovered within Microsoft Windows. It abuses the issue that a registry hive file will be opened in write mode if opening it in read mode fails. This, combined with the fact that the log files created when opening a hive in write mode are effectively owned by the system yet can also be modified by a user, allows normal users to overwrite critical system files. Successful exploitation of this issue may lead to local privilege escalation.
Microsoft Windows Kernel Local Elevation Of Privilege Vulnerability (CVE-2016-007...
Severity:
Date Published:  26 Oct 2016
A vulnerability was discovered within Microsoft Windows 10 that could lead to an arbitrary registry key access. The root cause of this vulnerability comes from kernel not checking for user while creating hardware profile subkeys in HKLM, which are created with full permission to the owner which is the user and also inherits the parent ACLs. A successfully exploitation of this issue could allow an attacker to elevate privileges when used for SymLink.
Microsoft Windows Kernel Local Elevation Of Privilege Vulnerability (CVE-2016-007...
Severity:
Date Published:  26 Oct 2016
A token impersonation vulnerability was discovered within Microsoft Windows. Successful exploitation of this issue might lead to a normal user process easily obtain a LocalSystem or any other user identity level token and further use it for impersonating a thread.
Microsoft Internet Explorer And Edge Memory Corruption Vulnerability (CVE-2016-33...
Severity:
Date Published:  26 Oct 2016
Microsoft Internet Explorer and Edge are prone to a memory corruption vulnerability. Attackers can exploit this issue to execute arbitrary code in the context of the user running the application.
Joomla Huge-IT Video Gallery SQL Injection Vulnerability (CVE-2016-1000123)
Severity:
Date Published:  26 Oct 2016
SQL injection vulnerability in Joomla! allows attackers to execute arbitrary SQL commands via unspecified vectors.
The Asterisk HTTP server currently has a default configuration which allows the BEAST vulnerability to be exploited if the TLS functionality is enabled. This can allow a man-in-the-middle attack to decrypt data passing through it.
Microsoft Internet Explorer And Edge Information Disclosure Vulnerability (CVE-20...
Severity:
Date Published:  26 Oct 2016
An information disclosure vulnerability exists in Internet Explorer and Edge in a way that the Res protocol manages the existence of files on the system. An attacker who successfully exploited this vulnerability could obtain information to further compromise the system.
Microsoft Windows Kernel Driver Local Elevation Of Privilege (CVE-2016-7185)
Severity:
Date Published:  26 Oct 2016
A privileges and access control vulnerability was discovered within Microsoft Windows. Successful exploitation of this issue might lead to an elevation of privileges.
Featured Stories
- The Mirage of AI Programming: Hallucinations and Code IntegrityThe adoption of large language models (LLMs) and Generative Pre-trained Transformers (GPTs), such as ChatGPT, by leading firms like Microsoft, Nuance, Mix and Google CCAI Insights, drives the industry towards a series of transformative changes. As the use of these new technologies becomes prevalent, it is important to understand their key behavior, advantages, and the risks they present.Read more
- Open RAN: Attack of the xAppsThis article discusses two O-RAN vulnerabilities that attackers can exploit. One vulnerability stems from insufficient access control, and the other arises from faulty message handlingRead more
- A Closer Exploration of Residential Proxies and CAPTCHA-Breaking ServicesThis article, the final part of a two-part series, focuses on the details of our technical findings and analyses of select residential proxies and CAPTCHA-solving services.Read more
- How Residential Proxies and CAPTCHA-Solving Services Become Agents of AbuseThis article, the first of a two-part series, provides insights on how abusers and cybercriminals use residential proxies and CAPTCHA-solving services to enable bots, scrapers, and stuffers, and proposes security countermeasures for organizations.Read more