Google Chrome for Android Remote Arbitrary Code Execution Vulnerability
Monday, 16 November 2015 17:05

A vulnerability was reported in Google Chrome for Android. A remote attacker can excute arbitrary code on the target system.No solution was available at the time of this entry.

Cisco SocialMiner WeChat Page Cross-Site Scripting Vulnerability
Wednesday, 04 November 2015 14:07

A vulnerability was reported in the WeChat page of Cisco Social Miner.An unauthenticated, remote attacker may be able to send a malicious script to an unsuspecting user.No fix was available at the time of this entry.

Arbitrary code execution resp. escalation of privilege with Mozilla's SETUP.EXE
Thursday, 29 October 2015 11:23

Mozilla's (executable) full setup packages for Windows allow arbitrary code execution resp. escalation of privilege: their SETUP.EXE loads SHFOLDER.DLL ['] from a temporary (sub)directory "%TEMP%\7zS.tmp\" created during self-extraction of the full setup packages. Avoid using executables for installation except the native installer package format of the resp. target OS.

Detail infomation about this vulnerability

Western Digital Self-Encrypting Hard Drive Crypto Fail
Tuesday, 20 October 2015 16:45

Western Digital self-encrypting hard drives suffer from having an extractable AES key that can be used to decrypt all data. No patch is available currently. Source & Details

LibreSSL Leak / Overflow
Monday, 19 October 2015 16:13

Various vulnerabilities are discovered in all versions of LibreSSL. These include a memory leak and a buffer overflow. Details can be found in here.

