Posts
2352
Following
513
Followers
1232
A drunken debugger

Heretek of Silent Signal
Another batch of vulnerabilities released, by @TalosSecurity now for Foxit Reader:

- CVE-2024-25938 - Foxit Reader Barcode widget Calculate event use-after-free vulnerability
- CVE-2024-25648 - Foxit Reader ComboBox widget Format event use-after-free vulnerability
- CVE-2024-25575 - Foxit Reader Lock object fields property type confusion vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2024-1958
https://talosintelligence.com/vulnerability_reports/TALOS-2024-1959
https://talosintelligence.com/vulnerability_reports/TALOS-2024-1963

(I should create a bot for these already...)
0
0
2
The fact that this blows so many peoples minds (mine included) shows how awfully shit UI discoverability on mobile is.
0
1
4
Sooo...MS still doesn't like publishing mpengine PDB's?
0
0
0
[RSS] Local Privilege Escalation Vulnerability in Ant Media Server (CVE-2024-32656)

https://www.praetorian.com/blog/local-privilege-escalation-vulnerability-in-ant-media-server-cve-2024-32656/
0
0
0
[RSS] Judge0 Sandbox Escape - CVE-2024-29021, CVE-2024-28185 and CVE-2024-28189

https://tantosec.com/blog/judge0/
0
0
2
Edited 4 months ago
[RSS] Fuzzer Development 1: The Soul of a New Machine (2023.11.04)

https://h0mbre.github.io/New_Fuzzer_Project/

I wouldn't post the n+1. new fuzzer attempt, but h0mbre's works always worth checking out!
1
0
0
[RSS] Souls without bodies, phantom types shenanigans

https://www.synacktiv.com/en/publications/souls-without-bodies-phantom-types-shenanigans

"In this article, we will present strange data types that only exists in the realm of types, called phantom types. We will also briefly introduce GADTs, and how to emulate some of their safety guarantees in languages where they are not available."
0
0
1
[RSS] [PlayStation] high - Remote vulnerabilities in spp (12500.00USD)

https://hackerone.com/reports/2177925
0
1
0
Series of DICOM parser vulnerabilities disclosed by @TalosSecurity :

CVE-2024-22373 - Grassroot DICOM JPEG2000Codec::DecodeByStreamsCommon out-of-bounds write vulnerability

CVE-2024-22391 - Mathieu Malaterre Grassroot DICOM LookupTable::SetLUT out-of-bounds write vulnerability

CVE-2024-25569 - Grassroot DICOM RAWCodec::DecodeBytes out-of-bounds read vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2024-1935
https://talosintelligence.com/vulnerability_reports/TALOS-2024-1924
https://talosintelligence.com/vulnerability_reports/TALOS-2024-1944
0
0
1
[RSS] Micropatches Released for Windows MSHTML Platform Remote Code Execution Vulnerability (CVE-2023-35628)

https://blog.0patch.com/2024/04/micropatches-released-for-windows_25.html
0
0
0
[RSS] NodeZero: Testing for Exploitability of Palo Alto Networks CVE-2024-3400

https://www.horizon3.ai/insights/nodezero-testing-for-exploitability-of-palo-alto-networks-cve-2024-3400/
0
0
0
This reminds me of my days spent on AV vulnerability hunting :)

RE: https://social.linux.pizza/users/standaloneSA/statuses/112346503511568045
0
0
2
[oss-security] libksieve (used by kmail/kontact) sent password as username

https://seclists.org/oss-sec/2024/q2/174

#whoops
0
0
1
#deathmetal #vocals #music
Show content
This kid is simply incredible

https://www.youtube.com/watch?v=8B7M_wPMH_k
0
0
1
repeated
Behold: THE DEBUGGER PEDAL

Powered by Chiba City Runes and Hacker Stickers (also xremap).

With this technology, I'll be unstoppable!
3
3
6
repeated

Inspirational Skeletorđź’€

Edited 4 months ago
0
3
0
Show older