(CVE-2020-0961) Microsoft Jet Database file position integer overflow Memory Corruption

CVE: CVE-2020-0961 Tested Versions: msexcl40.dll 4.0.9801.17 Product URL(s): https://microsoft.com Description of the vulnerability msexcl40.dll is a part of Microsoft Jet Excel, it is responsible for to process excel files when opening a specially crafted .xls file, an memory corruption will occur. The crash occurs at msexcl40!memcpy+0x2a: (42b8.1bc0): Access violation - code c0000005 (first/second chance not available) First chance exceptions are reported before any exception handling. This exception may be expected and handled....

November 13, 2019 · 4 min · Shi Ji (@Puzzorsj), Meysam Firouzi

(CVE-2019-1406) Microsoft Jet Engine ColumnLvText Type Confusion

CVE: CVE-2019-1406 Tested Versions: Windows 10 version 1903 and below Windows 7 Product URL(s): https://www.microsoft.com The Microsoft Jet Database Engine (also Microsoft JET Engine or simply Jet) is a database engine on which several Microsoft products have been built. JET stands for Joint Engine Technology. Microsoft Access and Visual Basic have used Jet as their underlying database engine. Description of the vulnerability The vulnerable DLL msjet40.dll is a component in versions from Windows 7 to Windows 10....

November 12, 2019 · 3 min · Shi Ji (@Puzzorsj) & Meysam Firouzi

(CVE-2019-2984) Oracle VirtualBox Video Hardware Acceleration NULL Pointer Dereferences

CVE: CVE-2019-2984 Tested Versions: Oracle VirtualBox 5.2.18 revision r123745 Product URL(s): https://virtualbox.org VirtualBox is a x86 and AMD64/Intel64 virtualization product for enterprise as well as home use. It is a solution commercially supported by Oracle, in addition to being made available as open source software. It runs on various host platforms like Windows, Linux, Mac and Solaris and also supports a large number of guest operating systems. There are several interfaces for the guest to communicate with the host in VirtualBox, one of them is Host-Guest Shared Memory Interface (HGSMI) services....

October 20, 2019 · 5 min · Phạm Hồng Phi (@anhdaden)

(CVE-2019-3002) Oracle VirtualBox Integer Divide by Zero in hdaR3StreamInit

CVE: CVE-2019-3002 Tested Versions: Oracle VirtualBox 6.0.4 revision r128413 Product URL(s): https://virtualbox.org VirtualBox is a x86 and AMD64/Intel64 virtualization product for enterprise as well as home use. It is a solution commercially supported by Oracle, in addition to being made available as open source software. It runs on various host platforms like Windows, Linux, Mac and Solaris and also supports a large number of guest operating systems. Vulnerability Intel HD Audio (HDA) is the default VirtualBox Audio Controller for Windows guests....

October 20, 2019 · 3 min · Phạm Hồng Phi (@anhdaden)

(CVE-2019-3005) Oracle VirtualBox NULL Pointer Dereference in hdaR3WalClkSet

CVE: CVE-2019-3005 Tested Versions: Oracle VirtualBox 6.0.4 revision r128413 Product URL(s): https://virtualbox.org VirtualBox is a x86 and AMD64/Intel64 virtualization product for enterprise as well as home use. It is a solution commercially supported by Oracle, in addition to being made available as open source software. It runs on various host platforms like Windows, Linux, Mac and Solaris and also supports a large number of guest operating systems. Vulnerability Intel HD Audio (HDA) is the default VirtualBox Audio Controller for Windows guests....

October 20, 2019 · 3 min · Phạm Hồng Phi (@anhdaden)

(CVE-2019-3026) Oracle VirtualBox VBoxSVGA Invalid Check in vmsvgaFIFOLoop

CVE: CVE-2019-3026 Tested Versions: Oracle VirtualBox 6.0.4 revision r128413 Product URL(s): https://virtualbox.org VirtualBox is a x86 and AMD64/Intel64 virtualization product for enterprise as well as home use. It is a solution commercially supported by Oracle, in addition to being made available as open source software. It runs on various host platforms like Windows, Linux, Mac and Solaris and also supports a large number of guest operating systems. Vulnerability VboxSVGA is the default Video Adapter for Windows guests....

October 20, 2019 · 4 min · Phạm Hồng Phi (@anhdaden)

(CVE-2019-3031) Oracle VirtualBox VMSVGA Out-of-Bounds Read in vmsvga3dSetLightEnabled

CVE: CVE-2019-3031 Tested Versions: Oracle VirtualBox 6.0.4 revision r128413 Product URL(s): https://virtualbox.org VirtualBox is a x86 and AMD64/Intel64 virtualization product for enterprise as well as home use. It is a solution commercially supported by Oracle, in addition to being made available as open source software. It runs on various host platforms like Windows, Linux, Mac and Solaris and also supports a large number of guest operating systems. Vulnerability Besides the default VirtualBox Video Adapter, VirtualBox also emulates VMware virtual SVGA device....

October 20, 2019 · 3 min · Phạm Hồng Phi (@anhdaden)