Red Hat Security Advisory 2016-0286-01 – Chromium is an open-source web browser, powered by WebKit. Two flaws were found in the processing of malformed web content. A web page containing malicious content could cause Chromium to crash, execute arbitrary code, or disclose sensitive information when visited by the victim. All Chromium users should upgrade to these updated packages, which contain Chromium version 48.0.2564.116, which corrects these issues. After installing the update, Chromium must be restarted for the changes to take effect.
Monthly Archives: February 2016
Adobe Flash SimpleButton Creation Type Creation
There is a type confusion vulnerability in the SimpleButton constructor. Flash stores an empty button to use to create buttons for optimization reasons. If this object is created using a SWF tag before it is created in the Button class, and it not of type Button, type confusion can occur.
libquicktime 1.2.4 Integer Overflow
libquicktime version 1.2.4 suffers from an integer overflow vulnerability.
OpenCms 9.5.2 Cross Site Scripting
OpenCms version 9.5.2 suffers from a cross site scripting vulnerability.
Ubiquiti Networks airCRM Cross Site Scripting
Ubiquiti Networks airCRM suffers from a cross site scripting vulnerability.
InstantCoder 1.0 Local File Inclusion / Directory Traversal
InstantCoder version 1.0 suffers from local file inclusion and directory traversal vulnerabilities.
New Silverlight Attacks Appear in Angler Exploit Kit
Exploits targeting a patched Silverlight vulnerability have found their way into the Angler Exploit Kit and victims are being hit with TeslaCrypt ransomware.
Apache Tomcat Security Manager Bypass
ResourceLinkFactory.setGlobalContext() is a public method and was accessible by web applications running under a security manager without any checks. This allowed a malicious web application to inject a malicious global context that could in turn be used to disrupt other web applications and/or read and write data owned by other web applications. Apache Tomcat versions 7.0.0 through 7.0.67, 8.0.0.RC1 through 8.0.30, and 9.0.0.M1 through 9.0.0.M2 are affected.
IRS Warns Tax-Related Phishing, Malware Surging
The IRS warns businesses and consumers about a significant increase in tax-related phishing and malware attacks.
Android porn clicker on Google Play: Appendix
Trojan clicker servers Google Play information Package names of trojan clickers found on the infected servers
The post Android porn clicker on Google Play: Appendix appeared first on We Live Security.