«
Expand/Collapse
374 items tagged "flash"
Related tags:
wordpress [+],
logic error [+],
gallery [+],
album gallery [+],
arbitrary code execution [+],
suse security [+],
security announcement [+],
information disclosure vulnerability [+],
grand [+],
announcement [+],
album [+],
adobe systems inc [+],
memory corruption [+],
stack overflow [+],
overflow vulnerability [+],
ocx [+],
flash player [+],
flash cards [+],
electronic flash [+],
electronic [+],
denial of service [+],
command execution [+],
buffer overflow [+],
abbs [+],
vulnerability research [+],
media logic [+],
flash player 10 [+],
display [+],
class [+],
web page versions [+],
swf player [+],
sp3 [+],
shell metacharacters [+],
shell [+],
service vulnerability [+],
security issues [+],
security control [+],
rich internet [+],
remote shell [+],
remote security [+],
proof of concept [+],
order [+],
nuclear situation [+],
msdn flash [+],
msdn [+],
microsoft msdn [+],
microsoft [+],
memory region [+],
memory [+],
media [+],
iran [+],
idefense security advisory [+],
hacks [+],
gallery 1 [+],
flash content [+],
flash chat [+],
flash activex control [+],
felix [+],
exploits [+],
disclosure [+],
cross [+],
corruption [+],
chatblazer [+],
chat [+],
black hat [+],
avm [+],
arbitrary code [+],
approach [+],
action script [+],
Bugs [+],
1 flash [+],
zero day [+],
virtual machine [+],
vector [+],
usa [+],
upload [+],
sql injection [+],
ria [+],
read [+],
poc [+],
patches [+],
landscape [+],
internet application [+],
html [+],
flash6 [+],
etag [+],
digital [+],
cookies [+],
content [+],
cameras [+],
ExploitsVulnerabilities [+],
code execution [+],
world of medicine [+],
vulnerabilities [+],
updates [+],
trigger [+],
tag [+],
steady rhythm [+],
stack buffer [+],
shutter [+],
server memory [+],
security hole [+],
second [+],
safer use [+],
reusing [+],
programmable delay [+],
precise timing [+],
practical joke [+],
phpcms [+],
pacemaker [+],
overflow code [+],
overflow [+],
out [+],
null pointer [+],
mt cumulus [+],
malware [+],
magic 8 ball [+],
mac webcam [+],
lobs [+],
lob [+],
integer overflow [+],
infected [+],
image processing [+],
hp switches [+],
heap [+],
great reputation [+],
google [+],
glsa [+],
flash timer [+],
flash media [+],
flash circuit [+],
flash card [+],
flash authors [+],
fix [+],
file upload [+],
file [+],
fabulous [+],
exploit [+],
design [+],
delay [+],
debuts [+],
day [+],
david prutchi [+],
david [+],
darknet [+],
critical vulnerability [+],
cloud [+],
classic [+],
bugtraq [+],
bug [+],
buffer overflow vulnerabilities [+],
ball [+],
amnesty [+],
adobe updates [+],
abu dhabi [+],
player [+],
adobe [+],
adobe flash player [+],
integer overflow vulnerability [+],
buffer overflow vulnerability [+],
player versions [+],
web browser plug [+],
remote buffer overflow vulnerability [+],
remote buffer overflow [+],
red hat security [+],
flash gallery [+],
cross site scripting [+],
vulnerability [+],
zero,
zdi,
xss,
worm,
widget,
webmaster tips,
web worm,
web application security,
web,
vupen,
vulnerability audit,
vulnerability assessment,
uri parsing,
unpatched,
txt,
tips,
tgz,
talk,
system,
support flash,
storage options,
stock option,
steve jobs,
slideshow,
server directory,
sequencer,
security bulletin,
security,
screw,
s. military,
retired,
resource exhaustion,
remote control,
reader,
protection mechanism,
prisonbreak,
prison break,
preisschlacht,
power,
php,
photography,
peggy,
pdf,
open,
news php,
news,
movie,
module,
mike bailey,
media server,
lighting,
leonard,
led display,
led,
leaves,
jpeg data,
iphone,
ipad,
invalid pointer,
intentional behavior,
inclusion,
hybrid web,
hijacking,
heap memory,
hack,
fmp,
flaw,
flash system,
flash storage,
flash slideshow maker,
flash reader,
flash plugin,
flash movie player,
flash hacks,
flash drive,
flash developers,
flash animations,
first appearance,
fg vd,
eeprom,
drive,
dont see,
dll,
directory traversal vulnerability,
destroyer,
cyber security,
critical flaws,
corrupt data,
controlling,
compact,
chart,
chaos communication congress,
breach,
boss,
bkis,
bans,
bad,
auktionshaus,
audio,
arduino,
applications flash,
apple boss,
apple,
adobe products,
adobe flashplayer,
adobe flash player 10,
adobe flash,
acrobat,
HackIt,
263a,
0 day
-
-
19:22
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0688-01 - The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update fixes one vulnerability in Adobe Flash Player. This vulnerability is detailed on the Adobe security page APSB12-09, listed in the References section. Specially-crafted SWF content could cause flash-plugin to crash or, potentially, execute arbitrary code when a victim loads a page containing the specially-crafted SWF content. All users of Adobe Flash Player should install this updated package, which upgrades Flash Player to version 10.3.183.19.
-
19:22
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0688-01 - The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update fixes one vulnerability in Adobe Flash Player. This vulnerability is detailed on the Adobe security page APSB12-09, listed in the References section. Specially-crafted SWF content could cause flash-plugin to crash or, potentially, execute arbitrary code when a victim loads a page containing the specially-crafted SWF content. All users of Adobe Flash Player should install this updated package, which upgrades Flash Player to version 10.3.183.19.
-
19:22
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0688-01 - The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update fixes one vulnerability in Adobe Flash Player. This vulnerability is detailed on the Adobe security page APSB12-09, listed in the References section. Specially-crafted SWF content could cause flash-plugin to crash or, potentially, execute arbitrary code when a victim loads a page containing the specially-crafted SWF content. All users of Adobe Flash Player should install this updated package, which upgrades Flash Player to version 10.3.183.19.
-
-
22:57
»
Packet Storm Security Exploits
This Metasploit module exploits a vulnerability in Adobe Flash Player for Linux, version 10.0.12.36 and 9.0.151.0 and prior. An input validation vulnerability allows command execution when the browser loads a SWF file which contains shell metacharacters in the arguments to the ActionScript launch method. The victim must have Adobe AIR installed for the exploit to work. This Metasploit module was tested against version 10.0.12.36 (10r12_36).
-
22:57
»
Packet Storm Security Recent Files
This Metasploit module exploits a vulnerability in Adobe Flash Player for Linux, version 10.0.12.36 and 9.0.151.0 and prior. An input validation vulnerability allows command execution when the browser loads a SWF file which contains shell metacharacters in the arguments to the ActionScript launch method. The victim must have Adobe AIR installed for the exploit to work. This Metasploit module was tested against version 10.0.12.36 (10r12_36).
-
22:57
»
Packet Storm Security Misc. Files
This Metasploit module exploits a vulnerability in Adobe Flash Player for Linux, version 10.0.12.36 and 9.0.151.0 and prior. An input validation vulnerability allows command execution when the browser loads a SWF file which contains shell metacharacters in the arguments to the ActionScript launch method. The victim must have Adobe AIR installed for the exploit to work. This Metasploit module was tested against version 10.0.12.36 (10r12_36).
-
6:19
»
Packet Storm Security Advisories
VUPEN Vulnerability Research Team discovered a critical vulnerability in Adobe Flash Player. The vulnerability is caused by an invalid object being used when parsing a malformed video via "NetStream.appendBytes", which could allow remote attackers to leak memory and execute arbitrary code despite ASLR and DEP enabled.
-
-
21:25
»
Packet Storm Security Exploits
Adobe Flash Player versions prior to 10.3.183.16 and 11.x before 11.1.102.63 suffer from an information disclosure vulnerability. This archive has research related to this issue, proof of concept source code, and a swf that demonstrates the issue.
-
21:25
»
Packet Storm Security Recent Files
Adobe Flash Player versions prior to 10.3.183.16 and 11.x before 11.1.102.63 suffer from an information disclosure vulnerability. This archive has research related to this issue, proof of concept source code, and a swf that demonstrates the issue.
-
21:25
»
Packet Storm Security Misc. Files
Adobe Flash Player versions prior to 10.3.183.16 and 11.x before 11.1.102.63 suffer from an information disclosure vulnerability. This archive has research related to this issue, proof of concept source code, and a swf that demonstrates the issue.
-
-
16:51
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0434-01 - The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update fixes one vulnerability in Adobe Flash Player. This vulnerability is detailed on the Adobe security page APSB12-07, listed in the References section. Specially-crafted SWF content could cause flash-plugin to crash or, potentially, execute arbitrary code when a victim loads a page containing the specially-crafted SWF content. All users of Adobe Flash Player should install this updated package, which upgrades Flash Player to version 10.3.183.18.
-
16:51
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0434-01 - The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update fixes one vulnerability in Adobe Flash Player. This vulnerability is detailed on the Adobe security page APSB12-07, listed in the References section. Specially-crafted SWF content could cause flash-plugin to crash or, potentially, execute arbitrary code when a victim loads a page containing the specially-crafted SWF content. All users of Adobe Flash Player should install this updated package, which upgrades Flash Player to version 10.3.183.18.
-
16:51
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0434-01 - The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update fixes one vulnerability in Adobe Flash Player. This vulnerability is detailed on the Adobe security page APSB12-07, listed in the References section. Specially-crafted SWF content could cause flash-plugin to crash or, potentially, execute arbitrary code when a victim loads a page containing the specially-crafted SWF content. All users of Adobe Flash Player should install this updated package, which upgrades Flash Player to version 10.3.183.18.
-
-
18:05
»
Packet Storm Security Exploits
This Metasploit module exploits a vulnerability found in Adobe Flash Player. By supplying a corrupt .mp4 file loaded by Flash, it is possible to gain arbitrary remote code execution under the context of the user. This vulnerability has been exploited in the wild as part of the "Iran's Oil and Nuclear Situation.doc" phishing campaign.
-
18:05
»
Packet Storm Security Recent Files
This Metasploit module exploits a vulnerability found in Adobe Flash Player. By supplying a corrupt .mp4 file loaded by Flash, it is possible to gain arbitrary remote code execution under the context of the user. This vulnerability has been exploited in the wild as part of the "Iran's Oil and Nuclear Situation.doc" phishing campaign.
-
18:05
»
Packet Storm Security Misc. Files
This Metasploit module exploits a vulnerability found in Adobe Flash Player. By supplying a corrupt .mp4 file loaded by Flash, it is possible to gain arbitrary remote code execution under the context of the user. This vulnerability has been exploited in the wild as part of the "Iran's Oil and Nuclear Situation.doc" phishing campaign.
-
-
14:32
»
Packet Storm Security Exploits
This Metasploit module exploits a vulnerability found in Adobe Flash Player's Flash10u.ocx component. When processing a MP4 file (specifically the Sequence Parameter Set), Flash will see if pic_order_cnt_type is equal to 1, which sets the num_ref_frames_in_pic_order_cnt_cycle field, and then blindly copies data in offset_for_ref_frame on the stack, which allows arbitrary remote code execution under the context of the user. Numerous reports also indicate that this vulnerability has been exploited in the wild. Please note that the exploit requires a SWF media player in order to trigger the bug, which currently isn't included in the framework. However, software such as Longtail SWF Player is free for non-commercial use, and is easily obtainable.
-
14:32
»
Packet Storm Security Recent Files
This Metasploit module exploits a vulnerability found in Adobe Flash Player's Flash10u.ocx component. When processing a MP4 file (specifically the Sequence Parameter Set), Flash will see if pic_order_cnt_type is equal to 1, which sets the num_ref_frames_in_pic_order_cnt_cycle field, and then blindly copies data in offset_for_ref_frame on the stack, which allows arbitrary remote code execution under the context of the user. Numerous reports also indicate that this vulnerability has been exploited in the wild. Please note that the exploit requires a SWF media player in order to trigger the bug, which currently isn't included in the framework. However, software such as Longtail SWF Player is free for non-commercial use, and is easily obtainable.
-
14:32
»
Packet Storm Security Misc. Files
This Metasploit module exploits a vulnerability found in Adobe Flash Player's Flash10u.ocx component. When processing a MP4 file (specifically the Sequence Parameter Set), Flash will see if pic_order_cnt_type is equal to 1, which sets the num_ref_frames_in_pic_order_cnt_cycle field, and then blindly copies data in offset_for_ref_frame on the stack, which allows arbitrary remote code execution under the context of the user. Numerous reports also indicate that this vulnerability has been exploited in the wild. Please note that the exploit requires a SWF media player in order to trigger the bug, which currently isn't included in the framework. However, software such as Longtail SWF Player is free for non-commercial use, and is easily obtainable.
-
-
7:55
»
Packet Storm Security Exploits
Adobe Flash Player MP4 SequenceParameterSetNALUnit remote code execution exploit that works against versions 10.3.181.34 and below on XP SP3.
-
-
4:01
»
Hack a Day
Most people use pacemakers to, you know, keep their heart pumping at a steady rhythm. [David Prutchi] on the other hand has found a pretty novel use for some of the old pacemakers he has in his collection. We really had no idea that pacemakers had uses outside the world of medicine, but [David] has [...]
-
-
14:19
»
Packet Storm Security Advisories
VUPEN Vulnerability Research Team discovered a vulnerability in Adobe Flash Player. The vulnerability is caused by an uninitialized stack variable when processing an invalid "SAlign" property of the Flash ActiveX control, which could be exploited by remote attackers to compromise a vulnerable system via a specially crafted web page. Versions prior to 11.1.102.55 are affected.
-
14:19
»
Packet Storm Security Recent Files
VUPEN Vulnerability Research Team discovered a vulnerability in Adobe Flash Player. The vulnerability is caused by an uninitialized stack variable when processing an invalid "SAlign" property of the Flash ActiveX control, which could be exploited by remote attackers to compromise a vulnerable system via a specially crafted web page. Versions prior to 11.1.102.55 are affected.
-
14:19
»
Packet Storm Security Misc. Files
VUPEN Vulnerability Research Team discovered a vulnerability in Adobe Flash Player. The vulnerability is caused by an uninitialized stack variable when processing an invalid "SAlign" property of the Flash ActiveX control, which could be exploited by remote attackers to compromise a vulnerable system via a specially crafted web page. Versions prior to 11.1.102.55 are affected.
-
-
13:29
»
SecuriTeam
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of the Adobe Flash Player.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
15:44
»
SecuriTeam
Remote exploitation of an integer overflow vulnerability in Adobe Systems Inc.'s Flash Player could allow an attacker to execute arbitrary code with the privileges of the current user.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
0:40
»
SecDocs
Authors:
Felix 'FX' Lindner Tags:
Rich Internet Applications Flash Event:
Black Hat USA 2010 Abstract: The talk presents a simple but effective approach for securing Rich Internet Application (RIA) content before using it. Focusing on Adobe Flash content, the security threats presented by Flash movies are discussed, as well as their inner workings that allow such attacks to happen. Some of those details will make you laugh, some will make you wince. Based on the properties discussed, the idea behind the defense approach will be presented, as well as the code implementing it and the results of using it in the real world. After a year of development, we hope to release a working tool to the world, so you can apply the defense technique to your web browser.
-
-
13:05
»
SecDocs
Authors:
Felix 'FX' Lindner Tags:
Rich Internet Applications Flash Event:
Black Hat USA 2010 Abstract: The talk presents a simple but effective approach for securing Rich Internet Application (RIA) content before using it. Focusing on Adobe Flash content, the security threats presented by Flash movies are discussed, as well as their inner workings that allow such attacks to happen. Some of those details will make you laugh, some will make you wince. Based on the properties discussed, the idea behind the defense approach will be presented, as well as the code implementing it and the results of using it in the real world. After a year of development, we hope to release a working tool to the world, so you can apply the defense technique to your web browser.
-
-
21:18
»
Packet Storm Security Recent Files
Whitepaper called Flash Cookies And Privacy II: Now With HTML5 And ETag Respawning. This is a follow-up study that reassesses the flash cookie landscape and examines a new tracking vector, HTML5 local storage, and cache-cookies via ETags.
-
21:18
»
Packet Storm Security Misc. Files
Whitepaper called Flash Cookies And Privacy II: Now With HTML5 And ETag Respawning. This is a follow-up study that reassesses the flash cookie landscape and examines a new tracking vector, HTML5 local storage, and cache-cookies via ETags.
-
-
22:17
»
Packet Storm Security Advisories
SUSE Security Announcement - Flash-Player was updated to version 10.3.188.5 to fix various buffer and integer overflows. Earlier flash-player versions can be exploited to execute arbitrary code remotely with the privileges of the attacked user.
-
22:17
»
Packet Storm Security Recent Files
SUSE Security Announcement - Flash-Player was updated to version 10.3.188.5 to fix various buffer and integer overflows. Earlier flash-player versions can be exploited to execute arbitrary code remotely with the privileges of the attacked user.
-
22:17
»
Packet Storm Security Misc. Files
SUSE Security Announcement - Flash-Player was updated to version 10.3.188.5 to fix various buffer and integer overflows. Earlier flash-player versions can be exploited to execute arbitrary code remotely with the privileges of the attacked user.
-
-
20:59
»
Packet Storm Security Advisories
iDefense Security Advisory 08.09.11 - Remote exploitation of a memory corruption vulnerability in Adobe Systems Inc.'s Flash Player could allow an attacker to execute arbitrary code with the privileges of the current user. The vulnerability occurs when parsing a maliciously formatted sequence of ActionScript code inside an Adobe Flash file. The problem exists in a certain ActionScript function method of the built-in "flash.display" class. When malformed parameters are supplied to this function, a memory corruption will occur, leading to an exploitable condition.
-
20:59
»
Packet Storm Security Recent Files
iDefense Security Advisory 08.09.11 - Remote exploitation of a memory corruption vulnerability in Adobe Systems Inc.'s Flash Player could allow an attacker to execute arbitrary code with the privileges of the current user. The vulnerability occurs when parsing a maliciously formatted sequence of ActionScript code inside an Adobe Flash file. The problem exists in a certain ActionScript function method of the built-in "flash.display" class. When malformed parameters are supplied to this function, a memory corruption will occur, leading to an exploitable condition.
-
20:59
»
Packet Storm Security Misc. Files
iDefense Security Advisory 08.09.11 - Remote exploitation of a memory corruption vulnerability in Adobe Systems Inc.'s Flash Player could allow an attacker to execute arbitrary code with the privileges of the current user. The vulnerability occurs when parsing a maliciously formatted sequence of ActionScript code inside an Adobe Flash file. The problem exists in a certain ActionScript function method of the built-in "flash.display" class. When malformed parameters are supplied to this function, a memory corruption will occur, leading to an exploitable condition.
-
-
5:31
»
Packet Storm Security Advisories
Red Hat Security Advisory 2011-0869-01 - The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update fixes one vulnerability in Adobe Flash Player. This vulnerability is detailed on the Adobe security page APSB11-18, listed in the References section. Specially-crafted SWF content could cause flash-plugin to crash or, potentially, execute arbitrary code. All users of Adobe Flash Player should install this updated package, which upgrades Flash Player to version 10.3.181.26. Various other issues were also addressed.
-
5:31
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2011-0869-01 - The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update fixes one vulnerability in Adobe Flash Player. This vulnerability is detailed on the Adobe security page APSB11-18, listed in the References section. Specially-crafted SWF content could cause flash-plugin to crash or, potentially, execute arbitrary code. All users of Adobe Flash Player should install this updated package, which upgrades Flash Player to version 10.3.181.26. Various other issues were also addressed.
-
18:41
»
Packet Storm Security Advisories
Red Hat Security Advisory 2011-0850 - The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update fixes one vulnerability in Adobe Flash Player. This vulnerability is detailed on the Adobe security page APSB11-13, listed in the References section. All users of Adobe Flash Player should install this updated package, which upgrades Flash Player to version 10.3.181.22 Various other issues were also addressed.
-
18:41
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2011-0850 - The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update fixes one vulnerability in Adobe Flash Player. This vulnerability is detailed on the Adobe security page APSB11-13, listed in the References section. All users of Adobe Flash Player should install this updated package, which upgrades Flash Player to version 10.3.181.22 Various other issues were also addressed.
-
18:41
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2011-0850 - The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update fixes one vulnerability in Adobe Flash Player. This vulnerability is detailed on the Adobe security page APSB11-13, listed in the References section. All users of Adobe Flash Player should install this updated package, which upgrades Flash Player to version 10.3.181.22 Various other issues were also addressed.
-
-
21:04
»
SecuriTeam
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash Player.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
10:04
»
Packet Storm Security Exploits
This Metasploit module exploits a vulnerability in Adobe Flash Player that was discovered, and has been exploited actively in the wild. By embedding a specially crafted .swf file, Adobe Flash crashes due to an invalid use of an object type, which allows attackers to overwrite a pointer in memory, and results arbitrary code execution.
-
10:04
»
Packet Storm Security Recent Files
This Metasploit module exploits a vulnerability in Adobe Flash Player that was discovered, and has been exploited actively in the wild. By embedding a specially crafted .swf file, Adobe Flash crashes due to an invalid use of an object type, which allows attackers to overwrite a pointer in memory, and results arbitrary code execution.
-
10:04
»
Packet Storm Security Misc. Files
This Metasploit module exploits a vulnerability in Adobe Flash Player that was discovered, and has been exploited actively in the wild. By embedding a specially crafted .swf file, Adobe Flash crashes due to an invalid use of an object type, which allows attackers to overwrite a pointer in memory, and results arbitrary code execution.
-
-
13:18
»
SecDocs
Authors:
Felix 'FX' Lindner Tags:
Rich Internet Applications Flash Event:
Black Hat Abu Dhabi 2010 Abstract: The talk presents a simple but effective approach for securing Adobe Flash content before using it. The security threats presented by Flash movies are discussed, as well as their inner workings that allow such attacks to happen. Some of those details will make you laugh, some will make you wince. Based on the properties discussed, the idea behind the defense approach will be presented, as well as the code implementing it and the results of using it in the real world.
-
-
22:56
»
Packet Storm Security Exploits
This Metasploit module exploits a vulnerability in AVM2 action script virtual machine used in Adobe Flash Player versions 9.0 through 10. The AVM fails to properly verify bytecode streams prior to executing it. This can cause uninitialized memory to be executed. Utilizing heap spraying techniques to control the uninitialized memory region it is possible to execute arbitrary code. Typically Flash Player is not used as a standalone application. Often, SWF files are embedded in other file formats or specifically loaded via a web browser. Malcode was discovered in the wild which embedded a malformed SWF file within an Excel spreadsheet. This exploit is based off the byte stream found within that malcode sample.
-
22:56
»
Packet Storm Security Recent Files
This Metasploit module exploits a vulnerability in AVM2 action script virtual machine used in Adobe Flash Player versions 9.0 through 10. The AVM fails to properly verify bytecode streams prior to executing it. This can cause uninitialized memory to be executed. Utilizing heap spraying techniques to control the uninitialized memory region it is possible to execute arbitrary code. Typically Flash Player is not used as a standalone application. Often, SWF files are embedded in other file formats or specifically loaded via a web browser. Malcode was discovered in the wild which embedded a malformed SWF file within an Excel spreadsheet. This exploit is based off the byte stream found within that malcode sample.
-
22:56
»
Packet Storm Security Misc. Files
This Metasploit module exploits a vulnerability in AVM2 action script virtual machine used in Adobe Flash Player versions 9.0 through 10. The AVM fails to properly verify bytecode streams prior to executing it. This can cause uninitialized memory to be executed. Utilizing heap spraying techniques to control the uninitialized memory region it is possible to execute arbitrary code. Typically Flash Player is not used as a standalone application. Often, SWF files are embedded in other file formats or specifically loaded via a web browser. Malcode was discovered in the wild which embedded a malformed SWF file within an Excel spreadsheet. This exploit is based off the byte stream found within that malcode sample.
-
-
20:55
»
SecuriTeam
Remote exploitation of a memory corruption vulnerability in Adobe Systems Inc.'s Flash Player could allow an attacker to execute arbitrary code with the privileges of the current user.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
20:55
»
SecuriTeam
Remote exploitation of an integer overflow vulnerability in Adobe Systems Inc.'s Flash Player could allow an attacker to execute arbitrary code with the privileges of the current user.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
8:03
»
Hack a Day
Here’s a flash trigger with a programmable delay. These triggers are often used to capture quick events like a balloon popping. The technique takes place in a dark room with the shutter open. When the event is triggered the flash illuminates the scene and an image is captured. Because these require precise timing it has [...]
-
-
15:00
»
Hack a Day
Hackaday forum user [arfink] has shown us a brilliant practical joke he built. This is a magic 8 ball that will blind you with a flash when you flip it over. Have you ever been in a room with one of these and not flipped it over? Neither have we. Using a basic flash circuit [...]