Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Fanrong1992

Pesquisador deIceSword Lab of Qihoo 360
#17331de 53,639
15.6CVSS total
Vulnerabilidades · 2
Alta
2
PT-2019-19158
7.8
2019-12-18
Apple · Apple Macos · CVE-2019-8701
**Name of the Vulnerable Software and Affected Versions** macOS versions prior to 10.15 **Description** A memory corruption issue was addressed with improved memory handling, allowing an application to potentially execute arbitrary code with system privileges. **Recommendations** For versions prior to 10.15, update to macOS Catalina 10.15 to resolve the issue.
PT-2017-14606
7.8
2017-11-17
Upx · Upx · CVE-2017-16869
**Name of the Vulnerable Software and Affected Versions** UPX version 3.94 **Description** The issue allows remote attackers to cause a denial of service, resulting in invalid memory access and application crash, or possibly have other unspecified impacts via a crafted Mach-O file. This is related to the `canPack` and `unpack` functions. The vendor has stated that there is no security implication. **Recommendations** For UPX version 3.94, consider avoiding the use of crafted Mach-O files to minimize the risk of exploitation. As a temporary workaround, consider restricting the use of the `canPack` and `unpack` functions until further guidance is available. At the moment, there is no information about a newer version that contains a fix for this issue.