Subscribe via feed.
Archive for February, 2016

Avast File Read

Posted by deepcore under exploit (No Respond)

This one is complicated, but allows an attacker to read any file on the filesystem by clicking a link. You don’t even have to know the name or path of the file, because you can also retrieve directory listings using this attack. Additionally, you can send arbitrary authenticated HTTP requests, and read the responses. This […]

Netgear Pro NMS 300 Code Execution / File Download

Posted by deepcore under exploit (No Respond)

Netgear Pro NMS 300 suffers from code execution and arbitrary file download vulnerabilities.

ThumbDrive 1.1 Local File Inclusion / File Upload

Posted by deepcore under exploit (No Respond)

ThumbDrive version 1.1 suffers from local file inclusion and remote file upload vulnerabilities.

Mobile Drive Free 1.8 Local File Inclusion / File Upload

Posted by deepcore under exploit (No Respond)

Mobile Drive Free 1.8 suffers from local file inclusion and remote file upload vulnerabilities.

Samsung SecEmailUI Script Injection

Posted by deepcore under exploit (No Respond)

The default Samsung email client’s email viewer and composer (implemented in SecEmailUI.apk) doesn’t sanitize HTML email content for scripts before rendering the data inside a WebView. This allows an attacker to execute arbitrary JavaScript when a user views a HTML email which contains HTML script tags or other events.

Samsung Galaxy S6 Android.media.process Face Recognition Memory Corruption

Posted by deepcore under exploit (No Respond)

This proof of concept file causes memory corruption when it is scanned by the face recognition library in android.media.process.

Samsung Galaxy S6 LibQjpeg Je_free Crash

Posted by deepcore under exploit (No Respond)

This jpg file causes an invalid pointer to be freed when media scanning occurs on Samsung Galaxy S6.

Adobe Flash Processing AVC Causes Stack Corruption

Posted by deepcore under exploit (No Respond)

This mp4 file causes stack corruption in Flash. To run the test, load LoadMP42.swf?file=null.mp4 from a remote server.

Google Chrome Privilege Escalation

Posted by deepcore under exploit (No Respond)

There is an overflow in the ui::PlatformCursor WebCursor::GetPlatformCursor method in Google Chrome.

Comodo Chromodo Browser Disable Same Origin Policy

Posted by deepcore under exploit (No Respond)

When you install Comodo Internet Security, by default a new browser called Chromodo is installed and set as the default browser. Additionally, all shortcuts are replaced with Chromodo links and all settings, cookies, etc are imported from Chrome. They also hijack DNS settings, among other shady practices.