❌

Normal view

[0day-rubbish] StreamSets Transformer 3.17.0 auth-mode none fallback and un-sandboxed ScalaDTransform execution to container root (8.1 primary)

6 October 2026 at 17:44

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in
StreamSets Transformer, the Spark-engine data-pipeline platform from
StreamSets Inc. (subsequently acquired by IBM), verified on version 3.17.0
analysed from the official container image.

Type: failing-open authentication plus un-sandboxed code injection. On the
web tier, CWE-306 and CWE-1188 with CWE-285 on the authorisation side: when
the effective http.authentication value...

[0day-rubbish] RCDevs WebADM 2.4.14 authenticated log viewer sid command injection to webadm uid 999 code execution (7.2)

6 October 2026 at 17:44

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in RCDevs WebADM
2.4.14, Freeware Edition, the closed-source IAM/MFA management platform from RCDevs
Security SA (Luxembourg) that fronts the vendor's OpenOTP, SpanKey and TiQR
authentication products.

Type: OS command injection (CWE-78, with CWE-20 and CWE-116 contributing, and
CWE-732/CWE-276 and CWE-250 added for two auxiliary conditions). The administrator
console log...

[0day-rubbish] Maian Cart 3.8 addBanners unrestricted banner upload to PHP webshell and administrator command execution (7.2 primary, PR:H)

6 October 2026 at 17:44

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in Maian
Cart 3.8, the self-hosted PHP shopping-cart system from Maian Media (Maian
Script World), verified end to end against a real installation of that
version.

Type: unrestricted upload of a file with a dangerous type (CWE-434), realized
as OS command execution (CWE-78) through an attacker-supplied PHP webshell,
with CWE-269 bearing on the execution privilege context. The...

[0day-rubbish] IPConfigure Orchid VMS 26.3.0 authenticated DNF repository GPG-key property command injection to root (7.2)

6 October 2026 at 17:44

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in
IPConfigure Orchid VMS, installed as Orchid Recorder, version 26.3.0.

Type: OS command injection (CWE-78, with CWE-20 bearing on it because no
character validation exists anywhere on the path; CWE-250 bears on the
result). The server property package.dnf.repo.gpg_key, the URL or path of
the GPG key signing the vendor RPM repository, is written through the
authenticated...

[0day-rubbish] Circutor LineEds 24.11.14-r0 unauthenticated pwrstudio events.xml shellExecute command injection (9.8)

6 October 2026 at 17:44

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in the pwrstudio
daemon shipped in Circutor LineEds (Line Energy Data System) industrial energy gateway
firmware 24.11.14-r0, engine variant pss0. Circutor S.A. is in Spain; the appliance sits
between metering and power-quality instrumentation on one side and an energy-management
or SCADA back office on the other.

Type: operating-system command injection (CWE-78) reached without...

[0day-rubbish] Asustor ADM 3.5.9.RWM1 (AS602T) music.cgi act=live stored-filename command injection reaching system() (8.8 primary, PR:L)

6 October 2026 at 17:44

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in the
media handler of the ADM (ASUSTOR Data Master) management portal, verified by
static analysis on the AS602T running ADM 3.5.9.RWM1 (x86-64, first-
generation G1 firmware line, from the distributed image
ADM_X64_G1_3.5.9.RWM1_AS602T.img).

Type: OS command injection (CWE-78), enabled by an argument-quoting breakout
(CWE-88) and by an incomplete list of disallowed values...

[0day-rubbish] Advantech WebAccess Node 9.2.3 unauthenticated CrystalRpt.aspx file upload and path traversal to code execution in w3wp.exe (9.8)

6 October 2026 at 17:44

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in Advantech
WebAccess Node 9.2.3, the closed-source industrial SCADA/HMI web server from
Advantech (Taiwan).

Type: unrestricted file upload (CWE-434) compounded by path traversal (CWE-22), on
a page that performs no authorization decision at all (CWE-306). CWE-73 and CWE-862
also map; CWE-250/CWE-269 apply conditionally where the pool runs at high
privilege. In the WaCrpt ASP.NET...

SEC Consult Research 20261001 :: Arbitrary Email sender spoofing in Apple iCloud mail

6 October 2026 at 17:44

Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Oct 06

SEC Consult Vulnerability Lab Research Announcement < 20261001 >
=======================================================================
title: Arbitrary Email sender spoofing in Apple iCloud mail
product: Apple iCloud mail (SMTP submission service)
vulnerable version: iCloud mail infrastructure (cloud service)
fixed version: Fixed by Apple (verified by SEC Consult, 2025-12-09)
CVE number: None...

SEC Consult SA-20260924-0 :: Multiple Vulnerabilities in Paessler PRTG Network Monitor #CVE-2026-4637 #CVE-2026-4638

6 October 2026 at 17:44

Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Oct 06

SEC Consult Vulnerability Lab Security Advisory < 20260924-0 >
=======================================================================
title: Multiple Vulnerabilities
product: Paessler PRTG Network Monitor
vulnerable version: <26.2.120.1449
Β  Β  Β  fixed version: 26.2.120.1449
Β  Β  Β  Β  Β CVE number: CVE-2026-4637, CVE-2026-4638
Β  Β  Β  Β  Β  Β  Β impact: high
homepage:...

[NotCVE-2026-0019] game-music-emu through 0.6.5 VGM Command Interpreter Missing Operand Length Check Allows Heap Out-of-Bounds Read

1 October 2026 at 06:16

Posted by advisories on Sep 30

----------------------------------------------------------------------------
NotCVE Advisory β€” NotCVE-2026-0019
----------------------------------------------------------------------------

[-] Summary:
An out-of-bounds read in the VGM command interpreter of game-music-emu
(libgme), the open-source video game music emulation library, allows an
attacker who supplies a crafted .vgm or .vgz file to read heap memory past
the end of the buffer...

[NotCVE-2026-0018] game-music-emu (libgme) through 0.6.5 Unbounded GYM Command Loop Allows Heap Out-of-Bounds Read

1 October 2026 at 06:16

Posted by advisories on Sep 30

----------------------------------------------------------------------------
NotCVE Advisory β€” NotCVE-2026-0018
----------------------------------------------------------------------------

[-] Summary:
An out-of-bounds read in the GYM playback path of game-music-emu (libgme),
the open-source video game music emulation library, allows an attacker who
supplies a crafted .gym file to read heap memory past the end of the
allocation holding the...

[NotCVE-2026-0017] game-music-emu (libgme) 0.6.5 and Earlier AY Loader NULL Pointer Dereference Allows Denial of Service

1 October 2026 at 06:16

Posted by advisories on Sep 30

----------------------------------------------------------------------------
NotCVE Advisory β€” NotCVE-2026-0017
----------------------------------------------------------------------------

[-] Summary:
A NULL pointer dereference in the AY file loader of game-music-emu
(libgme), the open-source video game music emulation library, allows an
attacker who supplies a crafted .ay file to terminate any application that
begins playback of it. CVSS:3.1...

[NotCVE-2026-0016] game-music-emu VGM Command Interpreter Unvalidated 0xE0 PCM Seek Offset Allows Out-of-Bounds Read and Denial of Service

1 October 2026 at 06:16

Posted by advisories on Sep 30

----------------------------------------------------------------------------
NotCVE Advisory β€” NotCVE-2026-0016
----------------------------------------------------------------------------

[-] Summary:
An out-of-bounds read in the VGM command interpreter of game-music-emu
(libgme), the open-source video game music emulation library, allows an
attacker who supplies a crafted .vgm or .vgz file to crash the hosting
process or to have adjacent...

APPLE-SA-09-28-2026-3 macOS Sequoia 15.8.1

29 September 2026 at 06:08

Posted by Apple Product Security via Fulldisclosure on Sep 28

APPLE-SA-09-28-2026-3 macOS Sequoia 15.8.1

macOS Sequoia 15.8.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149229.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

CoreGraphics
Available for: macOS Sequoia
Impact: Processing a maliciously crafted file may lead to arbitrary code...

APPLE-SA-09-28-2026-2 macOS Tahoe 26.7.1

29 September 2026 at 06:08

Posted by Apple Product Security via Fulldisclosure on Sep 28

APPLE-SA-09-28-2026-2 macOS Tahoe 26.7.1

macOS Tahoe 26.7.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149228.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

CoreGraphics
Available for: macOS Tahoe
Impact: Processing a maliciously crafted file may lead to arbitrary code...

APPLE-SA-09-28-2026-1 iOS 26.7.1 and iPadOS 26.7.1

29 September 2026 at 06:08

Posted by Apple Product Security via Fulldisclosure on Sep 28

APPLE-SA-09-28-2026-1 iOS 26.7.1 and iPadOS 26.7.1

iOS 26.7.1 and iPadOS 26.7.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149226.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

CoreGraphics
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation
and later, iPad Pro...

SEC Consult SA-20260923-0 :: Local Privilege Escalation in Honeywell IQ MultiAccess Update Service #CVE-2026-13742

27 September 2026 at 04:16

Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Sep 26

SEC Consult Vulnerability Lab Security Advisory < 20260923-0 >
=======================================================================
title: Local Privilege Escalation
product: Honeywell IQ MultiAccess Update Service
Β vulnerable version: IQ V27 & IQ V28
fixed version: IQ V27 SP1 & IQ V28 SP1
Β  Β  Β  Β  Β CVE number: CVE-2026-13742
Β  Β  Β  Β  Β  Β  Β impact: high
homepage:...

[SYSS-2026-071]: GDCM (Grassroots DICOM) - Format String (CWE-134)

27 September 2026 at 04:16

Posted by Matthias Deeg via Fulldisclosure on Sep 26

Advisory ID: SYSS-2026-071
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Format String (CWE-134)
Risk Level: Medium
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned
Author of...

[SYSS-2026-070]: GDCM (Grassroots DICOM) - Integer Overflow (CWE-190)

27 September 2026 at 04:16

Posted by Matthias Deeg via Fulldisclosure on Sep 26

Advisory ID: SYSS-2026-070
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Integer Overflow (CWE-190)
Risk Level: High
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned
Author of...

[SYSS-2026-069]: GDCM (Grassroots DICOM) - Integer Overflow (CWE-190)

27 September 2026 at 04:16

Posted by Matthias Deeg via Fulldisclosure on Sep 26

Advisory ID: SYSS-2026-069
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Integer Overflow (CWE-190)
Risk Level: High
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned
Author of...
❌