http://bandai.go.th/newsdetail.php?id=37
http://bandai.go.th/newsdetail.php?id=37 notified by Ashiyane Digital Security Team
Apple Quicktime 7 Invalid Atom Length Buffer Overflow
This Metasploit module exploits a vulnerability found in Apple Quicktime. The flaw is triggered when Quicktime fails to properly handle the data length for certain atoms such as 'rdrf' or 'dref' in the Alis record, which may result a buffer overflow by loading a specially crafted .mov file, and allows arbitrary code execution under the context of the user.
[webapps] – Flux Player v3.1.0 iOS – Multiple Vulnerabilities
Flux Player v3.1.0 iOS - Multiple Vulnerabilities
[webapps] – WiFly 1.0 Pro iOS – Multiple Vulnerabilities
WiFly 1.0 Pro iOS - Multiple Vulnerabilities
[dos] – Windows Movie Maker Version 2.1.4026.0 (.wav) – Crash POC
Windows Movie Maker Version 2.1.4026.0 (.wav) - Crash POC
[local] – Symantec Workspace Virtualization 6.4.1895.0 Local Kernel Mode Privilege Escalation
Symantec Workspace Virtualization 6.4.1895.0 Local Kernel Mode Privilege Escalation
[webapps] – Dell PacketTrap PSA 7.1 – Multiple XSS Vulnerabilities
Dell PacketTrap PSA 7.1 - Multiple XSS Vulnerabilities
[webapps] – Xibo 1.2.2 and 1.4.1 (index.php, p param) – Directory Traversal Vulnerability
Xibo 1.2.2 and 1.4.1 (index.php, p param) - Directory Traversal Vulnerability
[webapps] – ePhoto Transfer v1.2.1 iOS – Multiple Vulnerabilities
ePhoto Transfer v1.2.1 iOS - Multiple Vulnerabilities
[webapps] – Anchor CMS 0.9.1 – Stored XSS Vulnerability
Anchor CMS 0.9.1 - Stored XSS Vulnerability