Google Chrome before 42.0.2311.90 does not always ask the user before proceeding with CONTENT_SETTINGS_TYPE_FULLSCREEN and CONTENT_SETTINGS_TYPE_MOUSELOCK changes, which allows user-assisted remote attackers to cause a denial of service (UI disruption) by constructing a crafted HTML document containing JavaScript code with requestFullScreen and requestPointerLock calls, and arranging for the user to access this document with a file: URL.
Monthly Archives: April 2015
ADB Backup Traversal / File Overwrite
ADB backup on Android version 4.0.4 allows for file overwrite via modified tar headers.
Android 4.4 MTP Path Traversal
The doSendObjectInfo() method of the MtpServer class implemented in frameworks/av/media/mtp/MtpServer.cpp on Android 4.4 does not validate the name parameter of the incoming MTP packet, leading to a path traversal vulnerability.
WordPress Content Slide 1.4.2 CSRF / Cross Site Scripting
WordPress Content Slide plugin version 1.4.2 suffers from cross site request forgery and stored cross site scripting vulnerabilities.
112 ipTIME Remote Code Execution
Many 112 ipTIME routers / modems / firewalls suffer from a remote root code execution vulnerability.
Android Backup Agent Arbitrary Code Execution
The Android backup agent implementation was vulnerable to privilege escalation and race condition. An attacker with adb shell access could run arbitrary code as the system (1000) user (or any other valid package). The attack is tested on Android OS 4.4.4.
WordPress Citizen Space 1.1 Cross Site Scripting
WordPress Citizen Space plugin version 1.1 suffers from a cross site scripting vulnerability.
Mac OS X Local Denial Of Service
Local denial of service exploit for Mac OS X kernel versions prior to 10.10.3.
DSA-3229 mysql-5.5 – security update
Several issues have been discovered in the MySQL database server. The
vulnerabilities are addressed by upgrading MySQL to the new upstream
version 5.5.43. Please see the MySQL 5.5 Release Notes and Oracle’s
Critical Patch Update advisory for further details:
Wolf CMS 0.8.2 Shell Upload
Wolf CMS version 0.8.2 suffers from a remote shell upload vulnerability.