decoder/ih264d_parse_pslice.c in mediaserver in Android 6.x before 2016-07-01 does not properly select concealment frames, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28470138.
Monthly Archives: July 2016
CVE-2016-3756
Tremolo/res012.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not validate the number of partitions, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28556125.
CVE-2016-3757
The print_maps function in toolbox/lsof.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows user-assisted attackers to gain privileges via a crafted application that attempts to list a long name of a memory-mapped file, aka internal bug 28175237. NOTE: print_maps is not related to the Vic Abell lsof product.
CVE-2016-3758
Multiple buffer overflows in libdex/OptInvocation.cpp in DexClassLoader in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow attackers to gain privileges via a crafted application that provides a long filename, aka internal bug 27840771.
CVE-2016-3759
The Framework APIs in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow attackers to read backup data via a crafted application that leverages priv-app access to insert a backup transport, aka internal bug 28406080.
WordPress Ultimate Member 1.3.64 Local File Inclusion
WordPress Ultimate Member plugin version 1.3.64 suffers from a local file inclusion vulnerability.
Persistent Cross-Site Scripting in All in One SEO Pack WordPress Plugin
Posted by Summer of Pwnage on Jul 09
————————————————————————
Persistent Cross-Site Scripting in All in One SEO Pack WordPress Plugin
————————————————————————
David Vaartjes, July 2016
————————————————————————
Abstract
————————————————————————
A stored Cross-Site Scripting vulnerability was…
Ultimate Member Local File Inclusion vulnerability
Posted by Summer of Pwnage on Jul 09
————————————————————————
Ultimate Member Local File Inclusion vulnerability
————————————————————————
Burak Kelebek, July 2016
————————————————————————
Abstract
————————————————————————
It was discovered that Ultimate Member is vulnerable to PHP File…
Another CEO Hacked… It's Twitter CEO Jack Dorsey!
Twitter account of another high profile has been hacked!
This time, it’s Twitter CEO Jack Dorsey.
OurMine claimed responsibility for the hack, which was spotted after the group managed to post some benign video clips.
The team also tweeted at 2:50 AM ET today saying “Hey, its OurMine,we are testing your security,” with a link to their website that promotes and sells its own “services” for
![]()
Snowden says It's a 'Dark Day for Russia' after Putin Signs Anti-Terror Law
Whistleblower and ex-NSA employee Edward Snowden has criticized a new anti-terror law introduced on Thursday by Russian President Vladimir Putin, referring it as “repressive” and noting that it is a “dark day for Russia.”
The new legislation signed by Putin would compel the country’s telephone carriers and Internet providers to record and store the private communications of each and every one
![]()
