There is a use after free vulnerability in the ActionScript 2 TextField.filters array property.
Monthly Archives: August 2015
CVE-2015-2502 (internet_explorer)
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka “Memory Corruption Vulnerability,” as exploited in the wild in August 2015.
Microsoft Releases Critical Security Update for Internet Explorer
Original release date: August 19, 2015
Microsoft has released a critical security update to address a vulnerability in Internet Explorer. Exploitation of this vulnerability could allow a remote attacker to take control of an affected system if the user views a specially crafted webpage.
Users and administrators are encouraged to review Microsoft Bulletin MS15-093 for details and apply the necessary update.
This product is provided subject to this Notification and this Privacy & Use policy.
FTP Commander 8.02 Buffer Overflow
FTP Commander version 8.02 Costum Command SEH overwrite buffer overflow exploit.
Car security vulnerability study finally sees light of day
A major security vulnerability study into modern cars has finally been released, two years after it was originally intended to be published.
The post Car security vulnerability study finally sees light of day appeared first on We Live Security.
![]()
ASUS selects Avast SecureLine VPN to offer secure browsing to users
Avast SecureLine VPN anonymizes your browsing and makes your logins, emails, instant messages, and credit card details invisible.
We’re happy to announce that Avast SecureLine VPN will now be preloaded onto ASUS notebooks. Avast SecureLine VPN is now being made available on the company’s popular notebooks worldwide (with the exception of China), making it possible to provide users across the globe with a secure online experience by protecting them from hackers and other vulnerabilities.
Avast SecureLine VPN on ASUS devices gives consumers peace of mind, knowing that their sensitive personal data and information is protected and they can browse the Internet safely. Our strategic partnership with ASUS allows us to bring both a high-quality product along with safety and security to consumers – something we think is essential in today’s always-on, digital world, said Avast CEO Vince Steckler.
Through this partnership, users of the ASUS X series notebooks will receive 30 days free of Avast SecureLine VPN. Customers can also look forward to a discounted renewal after these 30 days have expired. For those of you who don’t already know (and love) what Avast SecureLine VPN accomplishes, the product anonymizes your browsing and makes your logins, emails, instant messages, and credit card details invisible.
ASUS selected Avast SecureLine VPN because of Avast’s reputable brand name and popularity throughout the world – and for that, we’re grateful. In addition to being available preloaded on ASUS notebooks, you can also find Avast solutions available on Google Play and in the Apple Store.
Follow Avast on Facebook, Twitter, YouTube, and Google+ where we keep you updated on cybersecurity news every day.
![]()
Back to school: 5 challenges that parents and teachers face in IT security
With children gradually going back to school in Latin American regions, it’s time to remind our children of the importance of IT security.
The post Back to school: 5 challenges that parents and teachers face in IT security appeared first on We Live Security.
![]()
Adobe Releases Security Update for LiveCycle Data Services
Original release date: August 18, 2015
Adobe has released a security update to address a vulnerability in LiveCycle Data Services versions 4.7, 4.6.2, 4.5, and 3.0.x. Exploitation of this vulnerability may allow a remote attacker to obtain sensitive information from an affected system.
US-CERT recommends that users and administrators review Adobe Security Bulletin APSB15-20 and apply the necessary updates.
This product is provided subject to this Notification and this Privacy & Use policy.
DSA-3340 zendframework – security update
Dawid Golunski discovered that when running under PHP-FPM in a threaded
environment, Zend Framework, a PHP framework, did not properly handle
XML data in multibyte encoding. This could be used by remote attackers
to perform an XML External Entity attack via crafted XML data.
DSA-3339 openjdk-6 – security update
Several vulnerabilities have been discovered in OpenJDK, an
implementation of the Oracle Java platform, resulting in the execution
of arbitrary code, breakouts of the Java sandbox, information disclosure,
denial of service or insecure cryptography.