Monthly Archives: May 2016
The Intercept Releasing Docs Leaked By NSA Whistleblower Snowden
Nexon Games Privilege Escalation
Multiple Nexon games suffer from an unquoted path privilege escalation vulnerability.
Debian Security Advisory 3580-1
Debian Linux Security Advisory 3580-1 – Nikolay Ermishkin from the Mail.Ru Security Team and Stewie discovered several vulnerabilities in ImageMagick, a program suite for image manipulation. These vulnerabilities, collectively known as ImageTragick, are the consequence of lack of sanitization of untrusted input. An attacker with control on the image input could, with the privileges of the user running the application, execute code (CVE-2016-3714), make HTTP GET or FTP requests (CVE-2016-3718), or delete (CVE-2016-3715), move (CVE-2016-3716), or read (CVE-2016-3717) local files.
Hex: Shard Of Fate 1.0.1.026 Privilege Escalation
Hex: Shard of Fate version 1.0.1.026 suffers from an unquoted path privilege escalation vulnerability.
TP-Link SC2020n Authenticated Telnet Injection
The TP-Link SC2020n Network Video Camera is vulnerable to OS Command Injection via the web interface. By firing up the telnet daemon, it is possible to gain root on the device. The vulnerability exists at /cgi-bin/admin/servetest, which is accessible with credentials.
Google to Face a Record $3.4 Billion AntiTrust Fine in Europe
Google faces a record anti-trust penalty of about 3 BILLION Euros (US$3.4 Billion) from the European Commission in the coming days, according to reports.
After 7-years of the investigation, the European Commission filed anti-trust charges against Google last year for violating antitrust laws.
<!– adsense –>
The European Union accused the search engine giant that it had abused its dominance
![]()
Chrome Defaults to HTML5 over Adobe Flash Starting in Q4
Google has announced that hacker-favorite Adobe Flash Player will no longer, as of Q4, be the default in Chrome. Instead, Chrome will default to HTML5.
SAP MII 15.0 Directory Traversal
SAP MII version 15.0 suffers from a directory traversal vulnerability.
SAP NetWeaver AS JAVA 7.4 Cross Site Scripting
SAP NetWeaver AS JAVA version 7.4 suffers from a cross site scripting vulnerability.
