CVE-2013-5169
published 2013-10-24CVE-2013-5169: CoreGraphics in Apple Mac OS X before 10.9, when display-sleep mode is used, does not ensure that screen locking blocks the visibility of all windows, which…
PriorityP46low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.34%
27.0th percentile
CoreGraphics in Apple Mac OS X before 10.9, when display-sleep mode is used, does not ensure that screen locking blocks the visibility of all windows, which allows physically proximate attackers to obtain sensitive information by reading the screen.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.8.5 | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
GOM Player 2.2.53.5169 - '.reg' Local Buffer Overflow (SEH)
exploitdb·2013-12-09
CVE-2013-6356 GOM Player 2.2.53.5169 - '.reg' Local Buffer Overflow (SEH)
GOM Player 2.2.53.5169 - '.reg' Local Buffer Overflow (SEH)
---
#!/usr/bin/perl
######################################################################################################
# Exploit Title: GOM Player 2.2.53.5169 - SEH Buffer Overflow (.reg)
# Date: 11-26-2013
# Exploit Author: Mike Czumak (T_v3rn1x) -- @SecuritySift
# Vulnerable Software/Version: GOM Player 2.2.53.5169
# Vendor Site: http://player.gomlab.com/eng/
# Vulnerable Software Link: http://www.oldapps.com/gom_player.php?old_gom_player=12874
# Tested On: Windows XP SP3 (Only crashes Win 7 b/c no suitable seh modules or jmp/call regs found)
# Details:
# -- GOM Player uses registry keys to set various attributes including the equalizer presets
# -- These registry values can be found here: HKEY_CURRENT_USER\Software\GRETE
Exploit-DB
GOMPlayer 2.2.53.5169 - '.wav' Crash (PoC)
exploitdb·2013-09-04
CVE-2013-5716 GOMPlayer 2.2.53.5169 - '.wav' Crash (PoC)
GOMPlayer 2.2.53.5169 - '.wav' Crash (PoC)
---
# Exploit Title: GOMPlayer Version 2.2.53.5169 (.wav) - Crash POC
# Date: 03-09-2013
# Exploit Author: ariarat
# Software Link: http://download.cnet.com/GOM-Media-Player/3000-13632_4-10551786.html?part=dl-GOMMediaP&subj=dl&tag=button
# Version: 2.2.53.5169 (Probably old version of software too)
# Vendor Homepage: www.gomlab.com
# Tested on: [ Windows XP sp3]
#============================================================================================
# After creating POC file (.wav),drag it to Player!
#============================================================================================
# Contact :
#------------------
# Web Page : http://ariarat.blogspot.com
# Email : [email protected]
#======================================
No writeups or analysis indexed.
2013-10-24
Published