❌

Reading view

[0day-rubbish] StreamSets Transformer 3.17.0 auth-mode none fallback and un-sandboxed ScalaDTransform execution to container root (8.1 primary)

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in
StreamSets Transformer, the Spark-engine data-pipeline platform from
StreamSets Inc. (subsequently acquired by IBM), verified on version 3.17.0
analysed from the official container image.

Type: failing-open authentication plus un-sandboxed code injection. On the
web tier, CWE-306 and CWE-1188 with CWE-285 on the authorisation side: when
the effective http.authentication value...
  •  

[0day-rubbish] RCDevs WebADM 2.4.14 authenticated log viewer sid command injection to webadm uid 999 code execution (7.2)

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in RCDevs WebADM
2.4.14, Freeware Edition, the closed-source IAM/MFA management platform from RCDevs
Security SA (Luxembourg) that fronts the vendor's OpenOTP, SpanKey and TiQR
authentication products.

Type: OS command injection (CWE-78, with CWE-20 and CWE-116 contributing, and
CWE-732/CWE-276 and CWE-250 added for two auxiliary conditions). The administrator
console log...
  •  

[0day-rubbish] Maian Cart 3.8 addBanners unrestricted banner upload to PHP webshell and administrator command execution (7.2 primary, PR:H)

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in Maian
Cart 3.8, the self-hosted PHP shopping-cart system from Maian Media (Maian
Script World), verified end to end against a real installation of that
version.

Type: unrestricted upload of a file with a dangerous type (CWE-434), realized
as OS command execution (CWE-78) through an attacker-supplied PHP webshell,
with CWE-269 bearing on the execution privilege context. The...
  •  

[0day-rubbish] IPConfigure Orchid VMS 26.3.0 authenticated DNF repository GPG-key property command injection to root (7.2)

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in
IPConfigure Orchid VMS, installed as Orchid Recorder, version 26.3.0.

Type: OS command injection (CWE-78, with CWE-20 bearing on it because no
character validation exists anywhere on the path; CWE-250 bears on the
result). The server property package.dnf.repo.gpg_key, the URL or path of
the GPG key signing the vendor RPM repository, is written through the
authenticated...
  •  

[0day-rubbish] Circutor LineEds 24.11.14-r0 unauthenticated pwrstudio events.xml shellExecute command injection (9.8)

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in the pwrstudio
daemon shipped in Circutor LineEds (Line Energy Data System) industrial energy gateway
firmware 24.11.14-r0, engine variant pss0. Circutor S.A. is in Spain; the appliance sits
between metering and power-quality instrumentation on one side and an energy-management
or SCADA back office on the other.

Type: operating-system command injection (CWE-78) reached without...
  •  

[0day-rubbish] Asustor ADM 3.5.9.RWM1 (AS602T) music.cgi act=live stored-filename command injection reaching system() (8.8 primary, PR:L)

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in the
media handler of the ADM (ASUSTOR Data Master) management portal, verified by
static analysis on the AS602T running ADM 3.5.9.RWM1 (x86-64, first-
generation G1 firmware line, from the distributed image
ADM_X64_G1_3.5.9.RWM1_AS602T.img).

Type: OS command injection (CWE-78), enabled by an argument-quoting breakout
(CWE-88) and by an incomplete list of disallowed values...
  •  

[0day-rubbish] Advantech WebAccess Node 9.2.3 unauthenticated CrystalRpt.aspx file upload and path traversal to code execution in w3wp.exe (9.8)

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in Advantech
WebAccess Node 9.2.3, the closed-source industrial SCADA/HMI web server from
Advantech (Taiwan).

Type: unrestricted file upload (CWE-434) compounded by path traversal (CWE-22), on
a page that performs no authorization decision at all (CWE-306). CWE-73 and CWE-862
also map; CWE-250/CWE-269 apply conditionally where the pool runs at high
privilege. In the WaCrpt ASP.NET...
  •  

SEC Consult Research 20261001 :: Arbitrary Email sender spoofing in Apple iCloud mail

Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Oct 06

SEC Consult Vulnerability Lab Research Announcement < 20261001 >
=======================================================================
title: Arbitrary Email sender spoofing in Apple iCloud mail
product: Apple iCloud mail (SMTP submission service)
vulnerable version: iCloud mail infrastructure (cloud service)
fixed version: Fixed by Apple (verified by SEC Consult, 2025-12-09)
CVE number: None...
  •  

SEC Consult SA-20260924-0 :: Multiple Vulnerabilities in Paessler PRTG Network Monitor #CVE-2026-4637 #CVE-2026-4638

Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Oct 06

SEC Consult Vulnerability Lab Security Advisory < 20260924-0 >
=======================================================================
title: Multiple Vulnerabilities
product: Paessler PRTG Network Monitor
vulnerable version: <26.2.120.1449
Β  Β  Β  fixed version: 26.2.120.1449
Β  Β  Β  Β  Β CVE number: CVE-2026-4637, CVE-2026-4638
Β  Β  Β  Β  Β  Β  Β impact: high
homepage:...
  •  

[NotCVE-2026-0019] game-music-emu through 0.6.5 VGM Command Interpreter Missing Operand Length Check Allows Heap Out-of-Bounds Read

Posted by advisories on Sep 30

----------------------------------------------------------------------------
NotCVE Advisory β€” NotCVE-2026-0019
----------------------------------------------------------------------------

[-] Summary:
An out-of-bounds read in the VGM command interpreter of game-music-emu
(libgme), the open-source video game music emulation library, allows an
attacker who supplies a crafted .vgm or .vgz file to read heap memory past
the end of the buffer...
  •  

[NotCVE-2026-0018] game-music-emu (libgme) through 0.6.5 Unbounded GYM Command Loop Allows Heap Out-of-Bounds Read

Posted by advisories on Sep 30

----------------------------------------------------------------------------
NotCVE Advisory β€” NotCVE-2026-0018
----------------------------------------------------------------------------

[-] Summary:
An out-of-bounds read in the GYM playback path of game-music-emu (libgme),
the open-source video game music emulation library, allows an attacker who
supplies a crafted .gym file to read heap memory past the end of the
allocation holding the...
  •  

[NotCVE-2026-0017] game-music-emu (libgme) 0.6.5 and Earlier AY Loader NULL Pointer Dereference Allows Denial of Service

Posted by advisories on Sep 30

----------------------------------------------------------------------------
NotCVE Advisory β€” NotCVE-2026-0017
----------------------------------------------------------------------------

[-] Summary:
A NULL pointer dereference in the AY file loader of game-music-emu
(libgme), the open-source video game music emulation library, allows an
attacker who supplies a crafted .ay file to terminate any application that
begins playback of it. CVSS:3.1...
  •  

[NotCVE-2026-0016] game-music-emu VGM Command Interpreter Unvalidated 0xE0 PCM Seek Offset Allows Out-of-Bounds Read and Denial of Service

Posted by advisories on Sep 30

----------------------------------------------------------------------------
NotCVE Advisory β€” NotCVE-2026-0016
----------------------------------------------------------------------------

[-] Summary:
An out-of-bounds read in the VGM command interpreter of game-music-emu
(libgme), the open-source video game music emulation library, allows an
attacker who supplies a crafted .vgm or .vgz file to crash the hosting
process or to have adjacent...
  •  

APPLE-SA-09-28-2026-3 macOS Sequoia 15.8.1

Posted by Apple Product Security via Fulldisclosure on Sep 28

APPLE-SA-09-28-2026-3 macOS Sequoia 15.8.1

macOS Sequoia 15.8.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149229.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

CoreGraphics
Available for: macOS Sequoia
Impact: Processing a maliciously crafted file may lead to arbitrary code...
  •  

APPLE-SA-09-28-2026-2 macOS Tahoe 26.7.1

Posted by Apple Product Security via Fulldisclosure on Sep 28

APPLE-SA-09-28-2026-2 macOS Tahoe 26.7.1

macOS Tahoe 26.7.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149228.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

CoreGraphics
Available for: macOS Tahoe
Impact: Processing a maliciously crafted file may lead to arbitrary code...
  •  

APPLE-SA-09-28-2026-1 iOS 26.7.1 and iPadOS 26.7.1

Posted by Apple Product Security via Fulldisclosure on Sep 28

APPLE-SA-09-28-2026-1 iOS 26.7.1 and iPadOS 26.7.1

iOS 26.7.1 and iPadOS 26.7.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149226.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

CoreGraphics
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation
and later, iPad Pro...
  •  

SEC Consult SA-20260923-0 :: Local Privilege Escalation in Honeywell IQ MultiAccess Update Service #CVE-2026-13742

Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Sep 26

SEC Consult Vulnerability Lab Security Advisory < 20260923-0 >
=======================================================================
title: Local Privilege Escalation
product: Honeywell IQ MultiAccess Update Service
Β vulnerable version: IQ V27 & IQ V28
fixed version: IQ V27 SP1 & IQ V28 SP1
Β  Β  Β  Β  Β CVE number: CVE-2026-13742
Β  Β  Β  Β  Β  Β  Β impact: high
homepage:...
  •  

[SYSS-2026-071]: GDCM (Grassroots DICOM) - Format String (CWE-134)

Posted by Matthias Deeg via Fulldisclosure on Sep 26

Advisory ID: SYSS-2026-071
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Format String (CWE-134)
Risk Level: Medium
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned
Author of...
  •  

[SYSS-2026-070]: GDCM (Grassroots DICOM) - Integer Overflow (CWE-190)

Posted by Matthias Deeg via Fulldisclosure on Sep 26

Advisory ID: SYSS-2026-070
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Integer Overflow (CWE-190)
Risk Level: High
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned
Author of...
  •  

[SYSS-2026-069]: GDCM (Grassroots DICOM) - Integer Overflow (CWE-190)

Posted by Matthias Deeg via Fulldisclosure on Sep 26

Advisory ID: SYSS-2026-069
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Integer Overflow (CWE-190)
Risk Level: High
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned
Author of...
  •  
❌