VU#573168: Microsoft Internet Explorer scripting engine JScript memory corruption vulnerability

Microsoft Internet Explorer contains a scripting engine,which handles execution of scripting languages such as VBScript and JScript. The scripting engine JScript component contains an unspecified memory corruption vulnerability. Any application that su… Continue reading VU#573168: Microsoft Internet Explorer scripting engine JScript memory corruption vulnerability

Posted in Uncategorized

VU#317277: Texas Instruments CC2640 and CC2650 microcontrollers vulnerable to heap overflow and insecure update

CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer CVE-2018-16986 – also known as BLEEDINGBIT The following Texas Instrument chips are affected: CC2640(non-R2)with BLE-STACK version 2.2.1 or an earlier version CC2650 with B… Continue reading VU#317277: Texas Instruments CC2640 and CC2650 microcontrollers vulnerable to heap overflow and insecure update

Posted in Uncategorized

VU#581311: TP-Link EAP Controller lacks RMI authentication and is vulnerable to deserialization attacks

CWE-306:Missing Authentication for Critical Function – CVE-2018-5393 EAP Controller for Linux utilizes a Java remote method invocation(RMI)service for remote control. The RMI interface does not require any authentication before use. Remote attackers ca… Continue reading VU#581311: TP-Link EAP Controller lacks RMI authentication and is vulnerable to deserialization attacks

Posted in Uncategorized

VU#598349: Automatic DNS registration and proxy autodiscovery allow spoofing of network services

The Web Proxy Automatic Discovery(WPAD)protocol is used to automatically provide proxy configuration information to devices on a network. Clients issue a special DHCP request to obtain the information for the proxy configuration,but will fall back on a… Continue reading VU#598349: Automatic DNS registration and proxy autodiscovery allow spoofing of network services

Posted in Uncategorized