The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication.
Before importing a project into Vuforia, a user could modify the “resourceDirectory� attribute in the appConfig.json file to be a different path.
A user could use the “Upload Resource� functionality to upload files to any location on the disk.
An attacker with local access to the machine could record the traffic, which could allow them to resend requests without the server authenticating that the user or session are valid.
Ноутбуки есть вероятно, у большинства читателей Хабра. Кто-то привык работать с ноутбуком без дополнительных экранов, кто-то подключает 1, 2 и больше дисплеев. Ну а кто-то покупает устройство с дополнительными экранами. Такие устройства есть, их нельзя назвать очень уж распространенными, но все же они продаются. О них сегодня и поговорим. Читать дальше →
SABnzbd is an open source automated Usenet download tool. A design flaw was discovered in SABnzbd that could allow remote code execution. Manipulating the Parameters setting in the Notification Script functionality allows code execution with the privileges of the SABnzbd process. Exploiting the vulnerabilities requires access to the web interface. Remote exploitation is possible if users[exposed their setup to the internet or other untrusted networks without setting a username/password. By default SABnzbd…
IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could allow a privileged user to obtain highly sensitive information by enabling debug mode. IBM X-Force ID: 257104.
RenderDoc through 1.26 allows an Integer Overflow with a resultant Buffer Overflow (issue 1 of 2).
RenderDoc through 1.26 allows an Integer Overflow with a resultant Buffer Overflow (issue 2 of 2).
RenderDoc through 1.26 allows local privilege escalation via a symlink attack.