#漏洞 nginx DNS Resolver Off-by-One Heap Write Vulnerability - CVE-2021-23017
https://x41-dsec.de/lab/advisories/x41-2021-002-nginx-resolver-copy/
https://x41-dsec.de/lab/advisories/x41-2021-002-nginx-resolver-copy/
X41 D-Sec - Penetration Tests and Source Code Audits
nginx DNS Resolver Off-by-One Heap Write Vulnerability
An off-by-one error in ngx_resolver_copy() while processing DNS responses allows a network attacker to write a dot character (‘.’, 0x2E) out of bounds in a heap allocated buffer.
#漏洞 CVE-2021-33564 Argument Injection in Ruby Dragonfly
https://zxsecurity.co.nz/research/argunment-injection-ruby-dragonfly/
https://zxsecurity.co.nz/research/argunment-injection-ruby-dragonfly/
zxsecurity.co.nz
Ruby Dragonfly - ZX Security
Full spectrum IT security services
#漏洞 Pulse Connect Secure 任意代码执行漏洞(CVE-2021-22908)
https://github.com/CERTCC/PoC-Exploits/blob/master/cve-2021-22908/cve-2021-22908.py
https://github.com/CERTCC/PoC-Exploits/blob/master/cve-2021-22908/cve-2021-22908.py
GitHub
PoC-Exploits/cve-2021-22908/cve-2021-22908.py at master · CERTCC/PoC-Exploits
Select proof-of-concept exploits for software vulnerabilities to aid in identifying and testing vulnerable systems. - CERTCC/PoC-Exploits
#漏洞 Signedness issue in ClassInfo message handler leads to RCE on CS:GO client
https://hackerone.com/reports/876719
https://hackerone.com/reports/876719
HackerOne
Valve disclosed on HackerOne: Signedness issue in ClassInfo message...
Title: Signedness issue in ClassInfo message handler leads to RCE on CS:GO client
Scope: csgo.exe
Weakness: Array Index Underflow
Severity: Critical (9.6)
Link: ...
Scope: csgo.exe
Weakness: Array Index Underflow
Severity: Critical (9.6)
Link: ...
#漏洞 CVE-2021-31440: AN INCORRECT BOUNDS CALCULATION IN THE LINUX KERNEL EBPF VERIFIER
https://www.zerodayinitiative.com/blog/2021/5/26/cve-2021-31440-an-incorrect-bounds-calculation-in-the-linux-kernel-ebpf-verifier
https://www.zerodayinitiative.com/blog/2021/5/26/cve-2021-31440-an-incorrect-bounds-calculation-in-the-linux-kernel-ebpf-verifier
Zero Day Initiative
Zero Day Initiative — CVE-2021-31440: An Incorrect Bounds Calculation in the Linux Kernel eBPF Verifier
In April 2021, the ZDI received a Linux kernel submission that turned out to be an incorrect bounds calculation bug in the extended Berkeley Packet Filter (eBPF) verifier. This bug was submitted to the program by Manfred Paul ( @_manfp ) of the RedRocket…
#漏洞 QNAP MalwareRemover 命令注入漏洞(CVE-2020-36198)
https://www.shielder.it/advisories/qnap-musicstation-malwareremover-pre-auth-remote-code-execution/
https://www.shielder.it/advisories/qnap-musicstation-malwareremover-pre-auth-remote-code-execution/
Shielder
Shielder - QNAP MusicStation/MalwareRemover Pre-Auth Remote Code Execution
QNAP MusicStation and MalwareRemover pre-installed official apps are affected by an arbitrary file upload and a command injection, leading to pre-auth remote root command execution.
#漏洞 VMware vCenter Server 远程代码执行漏洞(CVE-2021-21985)
https://attackerkb.com/topics/X85GKjaVER/cve-2021-21985
https://attackerkb.com/topics/X85GKjaVER/cve-2021-21985
AttackerKB
CVE-2021-21985 | AttackerKB
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enab…
#漏洞 PLAYING WITH IMAGETRAGICK LIKE IT'S 2016
https://www.synacktiv.com/en/publications/playing-with-imagetragick-like-its-2016.html
https://www.synacktiv.com/en/publications/playing-with-imagetragick-like-its-2016.html
Synacktiv
Playing with ImageTragick like it's 2016
You probably already have encountered document converting features that deal with ImageMagick during engagements but for some reason you were not able to exploit them. This article will mention some t
#漏洞 CVE-2021-33216: CommScope Ruckus IoT 控制器存在隐藏账户
https://korelogic.com/Resources/Advisories/KL-001-2021-007.txt
https://korelogic.com/Resources/Advisories/KL-001-2021-007.txt
#漏洞 runc mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs (CVE-2021-30465)
http://blog.champtar.fr/runc-symlink-CVE-2021-30465/
http://blog.champtar.fr/runc-symlink-CVE-2021-30465/
#漏洞 Dubbo Consumer脚本注入RCE - CVE-2021-30181
https://threedr3am.github.io/2021/05/30/Dubbo%20Consumer%E8%84%9A%E6%9C%AC%E6%B3%A8%E5%85%A5RCE%20-%20CVE-2021-30181/#more
https://threedr3am.github.io/2021/05/30/Dubbo%20Consumer%E8%84%9A%E6%9C%AC%E6%B3%A8%E5%85%A5RCE%20-%20CVE-2021-30181/#more
大彩笔threedr3am
Dubbo Consumer脚本注入RCE - CVE-2021-30181
0x00 事情的由来昨天看到Dubbo公布了几个新的CVE,一个没有Credit的中危 CVE-2021-25641,一个有Credit(Github Security Lab)的低危 CVE-2021-30181,其中CVE-2021-30181漏洞邮件标题为“RCE on customers via Script route poisoning (Nashorn script injectio
#漏洞 \QNAP Music Station/Malware Remover未授权远程代码执行漏洞(CVE-2020-36197 CVE-2020-36198)
https://www.shielder.it/advisories/qnap-musicstation-malwareremover-pre-auth-remote-code-execution/
https://www.shielder.it/advisories/qnap-musicstation-malwareremover-pre-auth-remote-code-execution/
Shielder
Shielder - QNAP MusicStation/MalwareRemover Pre-Auth Remote Code Execution
QNAP MusicStation and MalwareRemover pre-installed official apps are affected by an arbitrary file upload and a command injection, leading to pre-auth remote root command execution.
#漏洞 Overwolf 1-Click Remote Code Execution - CVE-2021-33501
https://swordbytes.com/blog/security-advisory-overwolf-1-click-remote-code-execution-cve-2021-33501/
https://swordbytes.com/blog/security-advisory-overwolf-1-click-remote-code-execution-cve-2021-33501/
Overwolf 1-Click Remote Code Execution - CVE-2021-33501 | SwordBytes Security
SwordBytes researchers have identified an Unauthenticated Remote Code Execution (RCE) vulnerability in Overwolf’s Client Application by abusing a Reflected Cross-Site Scripting (XSS) issue present in the “overwolfstore://” URL handler. This vulnerability…