Posted by Apple Product Security via Fulldisclosure on Nov 21
APPLE-SA-11-19-2024-5 macOS Sequoia 15.1.1
macOS Sequoia 15.1.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/121753 .
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
JavaScriptCore
Available for: macOS Sequoia
Impact: Processing maliciously crafted web content may lead to arbitrary…
Posted by Qualys Security Advisory via Fulldisclosure on Nov 21
Qualys Security Advisory
LPEs in needrestart (CVE-2024-48990, CVE-2024-48991, CVE-2024-48992,
CVE-2024-10224, and CVE-2024-11003)
========================================================================
Contents
========================================================================
Summary
Background
CVE-2024-48990 (and CVE-2024-48992)
CVE-2024-48991
CVE-2024-10224 (and CVE-2024-11003)
Mitigation
Acknowledgments
Timeline
I got bugs…
Posted by Apple Product Security via Fulldisclosure on Nov 21
APPLE-SA-11-19-2024-4 iOS 17.7.2 and iPadOS 17.7.2
iOS 17.7.2 and iPadOS 17.7.2 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/121754 .
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
JavaScriptCore
Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch
2nd generation…
Posted by Apple Product Security via Fulldisclosure on Nov 21
APPLE-SA-11-19-2024-3 iOS 18.1.1 and iPadOS 18.1.1
iOS 18.1.1 and iPadOS 18.1.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/121752 .
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
JavaScriptCore
Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch
3rd generation…
Posted by Apple Product Security via Fulldisclosure on Nov 21
APPLE-SA-11-19-2024-2 visionOS 2.1.1
visionOS 2.1.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/121755 .
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
JavaScriptCore
Available for: Apple Vision Pro
Impact: Processing maliciously crafted web content may lead to arbitrary
code…
Posted by Apple Product Security via Fulldisclosure on Nov 21
APPLE-SA-11-19-2024-1 Safari 18.1.1
Safari 18.1.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/121756 .
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
JavaScriptCore
Available for: macOS Ventura and macOS Sonoma
Impact: Processing maliciously crafted web content may lead to…
Posted by Andrey Stoykov on Nov 21
# Exploit Title: Reflected XSS – fronsetiav1.1
# Date: 11/2024
# Exploit Author: Andrey Stoykov
# Version: 1.1
# Tested on: Debian 12
# Blog:
https://msecureltd.blogspot.com/2024/11/friday-fun-pentest-series-14-reflected.html
Reflected XSS #1 – “show_operations.jsp”
Steps to Reproduce:
1. Visit main page of the application.
2. In the input field of “WSDL Location” enter the following payload “><img
src=x…
Posted by Andrey Stoykov on Nov 21
# Exploit Title: XXE OOB – fronsetiav1.1
# Date: 11/2024
# Exploit Author: Andrey Stoykov
# Version: 1.1
# Tested on: Debian 12
# Blog:
https://msecureltd.blogspot.com/2024/11/friday-fun-pentest-series-15-oob-xxe.html
XXE OOB
Description:
– It was found that the application was vulnerable XXE (XML External Entity
Injection)
Steps to Reproduce:
1. Add Python3 server to serve malicious XXE payload
2. Add a file on the file system to be read…
Posted by Weber Thomas via Fulldisclosure on Nov 21
St. Pölten UAS 20241118-1
——————————————————————————-
title| Path Traversal
product| Korenix JetPort 5601
vulnerable version| 1.2
fixed version| –
CVE number| CVE-2024-11303
impact| High
homepage| https://www.korenix.com/
found| 2024-05-24
by| P. Oberndorfer, B. Tösch, M….
Posted by Weber Thomas via Fulldisclosure on Nov 21
St. Pölten UAS 20241118-0
——————————————————————————-
title| Multiple Stored Cross-Site Scripting
product| SEH utnserver Pro
vulnerable version| 20.1.22
fixed version| 20.1.35
CVE number| CVE-2024-11304
impact| High
homepage| https://www.seh-technology.com/
found| 2024-05-24
by| P….
Posts navigation
News, Advisories and much more