Subscribe via feed.

Tokend Privacy Leak / Arbitrary File Creation

The Tokend OS X module suffers from privacy leak and arbitrary file creation vulnerabilities.

Tags: , ,

Apple Security Advisory 2013-02-19-1

Apple Security Advisory 2013-02-19-1 – Multiple vulnerabilities existed in Java 1.6.0_37, the most serious of which may allow an untrusted Java applet to execute arbitrary code outside the Java sandbox. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user. These issues were addressed by updating to Java version 1.6.0_41.

Tags: , , , ,

Transferable Remote 1.1 XSS / LFI / Command Injection

Transferable Remote version 1.1 for iPad and iPhone suffers from cross site scripting, remote command injection, and local file inclusion vulnerabilities.

Tags: , , ,

Apple Security Advisory 2013-02-01-1

Apple Security Advisory 2013-02-01-1 – Multiple vulnerabilities exist in Java 1.6.0_37, the most serious of which may allow an untrusted Java applet to execute arbitrary code outside the Java sandbox. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user.

Tags: , , ,

Zed Attack Proxy 2.0.0 Mac OS X Release

The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing.

Tags: , ,

Apple Security Advisory 2013-01-28-2

Apple Security Advisory 2013-01-28-2 – Apple TV 5.2 is now available and addresses multiple security vulnerabilities.

Tags: , ,

Apple QuickTime Player 7.7.3 Out Of Bounds

Apple QuickTime Player Windows version 7.7.3 suffers from an out of bounds read vulnerability.

Tags: , , , ,

Secunia Security Advisory 52002

Secunia Security Advisory – Two security issues and multiple vulnerabilities have been reported in Apple iOS, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, and compromise a user’s device.

Tags: , ,

Apple Security Advisory 2012-11-29-1

Apple Security Advisory 2012-11-29-1 – Apple TV 5.1.1 is now available and addresses information disclosure and code execution vulnerabilities.

Tags: , ,

Apple QuickTime 7.7.2 TeXML Style Element font-table Field Stack Buffer Overflow

This Metasploit module exploits a vulnerability found in Apple QuickTime.

Tags: , ,