Defense in depth — the Microsoft way (part 43): restricting the DLL load order fails

Posted by Stefan Kanthak on Sep 08

Hi @ll,

according to <https://msdn.microsoft.com/en-us/library/ms684179.aspx>
and <https://msdn.microsoft.com/en-us/library/ms682586.aspx>,
LoadLibraryEx with LOAD_WITH_ALTERED_SEARCH_PATH should NOT search
the calling program’s application directory:

| Note that the standard search strategy and the alternate search
| strategy specified by LoadLibraryEx with LOAD_WITH_ALTERED_SEARCH_PATH
| differ in just one way: The standard…

cve request: Airmail URLScheme render and file:// xss vulnerability

Posted by redrain root on Sep 08

Airmail is a popular email client on iOS and OS X.
I found a vulnerability in airmail of the latest version which could cause
a file:// xss and arbitrary file read.

Author: redrain, yu.hong () chaitin com
Date: 2016-08-15
Version: 3.0.2 and earlier
Platform: OS X and iOS
Site: http://airmailapp.com/
Vendor: http://airmailapp.com/
Vendor Notified: 2016-08-15

Vulnerability:
There is a file:// xss in airmail version 3.0.2 and earlier.
The app can…

CVE-2016-4264 Adobe ColdFusion <= 11 XXE Vulnerability

Posted by Dawid Golunski on Sep 08

Vulnerability: Adobe ColdFusion <= 11 XXE Injection
CVE: CVE-2016-4264
Vendor ID: APSB16-30
Discovered by: Dawid Golunski (http://legalhackers.com)

Adobe ColdFusion in versions 11 and below is vulnerable to XXE
Injection when processing untrusted office documents.

Depending on a web application’s functionality and the attacker’s ability to
supply a malicious document to be processed by a vulnerable ColdFusion
application, this…

CVE request – Samsumg Mobile Phone SVE-2016-6248: SystemUI Security issue

Posted by 0xr0ot on Sep 08

Hi,

Description of the potential vulnerability:
SVE-2016-6248: SystemUI Security issue
Severity: Medium
Affected versions: L(5.0/5.1), M(6.0) devices with Exynos7420 chipset
Reported on: June 7, 2016
Disclosure status: Privately disclosed.
The vulnerability exists due to a null pointer dereference on fimg2d driver.
The patch verifies if the object is null before dereferencing it.

Fix:…

Persistent Cross-Site Scripting vulnerability in WordPress due to unsafe processing of file names

Posted by Summer of Pwnage on Sep 08

————————————————————————
Persistent Cross-Site Scripting vulnerability in WordPress due to unsafe
processing of file names
————————————————————————
Han Sahin, July 2016

————————————————————————
Abstract
————————————————————————
A persistent Cross-Site…

CVE-2016-4381

HPE XP7 Command View Advanced Edition (CVAE) Suite 6.x through 8.x before 8.4.1-02, when Replication Manager (RepMgr) and Device Manager (DevMgr) are enabled, allows local users to bypass intended access restrictions via unspecified vectors.