Several vulnerabilities were discovered in qemu-kvm, a full
virtualization solution on x86 hardware.
Monthly Archives: February 2016
DSA-3471 qemu – security update
Several vulnerabilities were discovered in qemu, a full virtualization
solution on x86 hardware.
Botan C++ Crypto Algorithms Library 1.10.12
Botan is a C++ library of cryptographic algorithms, including AES, DES, SHA-1, RSA, DSA, Diffie-Hellman, and many others. It also supports X.509 certificates and CRLs, and PKCS #10 certificate requests, and has a high level filter/pipe message processing system. The library is easily portable to most systems and compilers, and includes a substantial tutorial and API reference.
Comodo Chromodo Browser Disable Same Origin Policy
When you install Comodo Internet Security, by default a new browser called Chromodo is installed and set as the default browser. Additionally, all shortcuts are replaced with Chromodo links and all settings, cookies, etc are imported from Chrome. They also hijack DNS settings, among other shady practices.
Google Chrome Privilege Escalation
There is an overflow in the ui::PlatformCursor WebCursor::GetPlatformCursor method in Google Chrome.
Adobe Flash Processing AVC Causes Stack Corruption
This mp4 file causes stack corruption in Flash. To run the test, load LoadMP42.swf?file=null.mp4 from a remote server.
Samsung Galaxy S6 LibQjpeg Je_free Crash
This jpg file causes an invalid pointer to be freed when media scanning occurs on Samsung Galaxy S6.
Samsung Galaxy S6 Android.media.process Face Recognition Memory Corruption
This proof of concept file causes memory corruption when it is scanned by the face recognition library in android.media.process.
Samsung SecEmailUI Script Injection
The default Samsung email client’s email viewer and composer (implemented in SecEmailUI.apk) doesn’t sanitize HTML email content for scripts before rendering the data inside a WebView. This allows an attacker to execute arbitrary JavaScript when a user views a HTML email which contains HTML script tags or other events.
Mobile Drive Free 1.8 Local File Inclusion / File Upload
Mobile Drive Free 1.8 suffers from local file inclusion and remote file upload vulnerabilities.