CVE-2016-3755

decoder/ih264d_parse_pslice.c in mediaserver in Android 6.x before 2016-07-01 does not properly select concealment frames, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28470138.

CVE-2016-3756

Tremolo/res012.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not validate the number of partitions, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28556125.

CVE-2016-3757

The print_maps function in toolbox/lsof.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows user-assisted attackers to gain privileges via a crafted application that attempts to list a long name of a memory-mapped file, aka internal bug 28175237. NOTE: print_maps is not related to the Vic Abell lsof product.

CVE-2016-3758

Multiple buffer overflows in libdex/OptInvocation.cpp in DexClassLoader in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow attackers to gain privileges via a crafted application that provides a long filename, aka internal bug 27840771.

CVE-2016-3759

The Framework APIs in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow attackers to read backup data via a crafted application that leverages priv-app access to insert a backup transport, aka internal bug 28406080.

Persistent Cross-Site Scripting in All in One SEO Pack WordPress Plugin

Posted by Summer of Pwnage on Jul 09

————————————————————————
Persistent Cross-Site Scripting in All in One SEO Pack WordPress Plugin
————————————————————————
David Vaartjes, July 2016

————————————————————————
Abstract
————————————————————————
A stored Cross-Site Scripting vulnerability was…

Ultimate Member Local File Inclusion vulnerability

Posted by Summer of Pwnage on Jul 09

————————————————————————

Ultimate Member Local File Inclusion vulnerability

————————————————————————

Burak Kelebek, July 2016

————————————————————————

Abstract

————————————————————————

It was discovered that Ultimate Member is vulnerable to PHP File…

Another CEO Hacked… It's Twitter CEO Jack Dorsey!

Twitter account of another high profile has been hacked!

This time, it’s Twitter CEO Jack Dorsey.

OurMine claimed responsibility for the hack, which was spotted after the group managed to post some benign video clips.

The team also tweeted at 2:50 AM ET today saying “Hey, its OurMine,we are testing your security,” with a link to their website that promotes and sells its own “services” for