Advisories
archive

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors

UNISOC T612 LPE

Summary UNISOC (Shanghai) Technologies Co., Ltd. is a top-three global fabless semiconductor company headquartered in Shanghai, specializing in 2G/3G/4G/5G mobile communication, IoT, and smart device chipsets. Formerly Spreadtrum, it serves major brands like Honor, realme,

Linux Bridge STP Timer Use-After-Free

Summary A use-after-free vulnerability in the Linux kernel bridge (net/bridge) Spanning Tree Protocol (STP) implementation. A bridge that is administratively down while kernel STP is enabled, together with a port driven into the LEARNING state,

vBulletin Runtime Template runMaths Preauth RCE

Summary A vulnerability in vBulletin has been identified, the vulnerability allows an unauthenticated user to cause the vBulletin to execute arbitrary code (PHP) on the remote server. Vendor Response The vendor has issued a fix

ReadableStream TOCTOU: V8 Sandbox Bypass via Wasm Streaming

Summary Issue 433533359 is a TOCTOU data race between Blink’s ReadableStream consumer pipeline and V8’s WebAssembly streaming compiler. A renderer-controlled SharedArrayBuffer(SAB) mutated by a worker thread causes WebAssembly’s bytecode validator and its JIT to disagree

ipTIME Pre-Auth RCE in CWMP

Summary An unauthenticated attacker can remotely execute arbitrary code via the CWMP protocol on the ipTIME router. Vendor Response We have tried to reach out to the vendor through multiple channels (email and via KISA)

UNISOC T612 RCE

Summary UNISOC (Shanghai) Technologies Co., Ltd. is a top-three global fabless semiconductor company headquartered in Shanghai, specializing in 2G/3G/4G/5G mobile communication, IoT, and smart device chipsets. Formerly Spreadtrum, it serves major brands like Honor, realme,

Joomla! Novarain/Tassos Framework Vulnerabilities

Summary Source code review of the Novarain/Tassos Framework revealed three critical primitives – unauthenticated file read, unauthenticated file deletion, and SQL injection leading to arbitrary database read – across five widely deployed Joomla! extensions (Convert

?

Get in touch

Skip to content