GStreamer is a library for constructing graphs of media-handling components. The program attempts to reallocate the memory pointed to by stream->samples to accommodate stream->n_samples + samples_count elements of type QtDemuxSample. The problem is that samples_count is read from the input file. And if this value is big enough, this can lead to an integer overflow during the addition. As a consequence, g_try_renew might allocate memory for a significantly smaller number of elements than intended. Following this, the program iterates through samples_count elements and attempts to write samples_count number of elements, potentially exceeding the actual allocated memory size and causing an OOB-write. This vulnerability is fixed in 1.24.10.

ALL

18

News and views from the world of cybersecurity, hacking, and internet threats.

This site displays telemetry from Amateur Radio high-altitude balloon launches, using the SondeHub-Amateur database.

A question and answer site for information security professionals.

Well-documented, relevant, reliably discovered vulnerabilities and dedicated tools for pentesters by our IT security experts. TL;DR - we break things.

A guide to protecting yourself from electronic surveillance for people all over the world.

Educating IT Professionals To Make Smarter Decisions.

Real Intrusions by Real Attackers, The Truth Behind the Intrusion.

Trusted Cybersecurity News Platform.

A free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!

Analyse suspicious files, domains, IPs and URLs to detect malware and other breaches, automatically share them with the security community.

The largest collection of malware source code, samples, and papers on the internet.

All the networks. Found by Everyone.

Displays images from hundreds of webcams, cameras around the world, including a description of the web cam location. and Displays worldwide webcam images on the Google map.

Webcams from around the world.

ZoomEye really mapping global leader of cyberspace mapping.

The home to the largest curation of resources for beginners in AI/ML security, from leading AI/ML threat researchers at Protect AI. Start your journey into AI/ML hacking today.

Live Flight Tracker and Airport Status.

An internationally recognized cybersecurity event series providing the most technical and relevant information security research.

Bugcrowd teams with elite security researchers to reduce risk & improve security ROI through our bug bounty, pen testing, & vulnerability disclosure programs.

The Intelligence and research arm of Check Point Technologies provides leading cyber threat intelligence to Check Point customers and the greater intelligence community.

Extremely passionate about Windows exploit development, internals, C, Assembly, or anything low-level.

A fun, free platform for learning modern cryptography.

All about CTF (Capture The Flag).

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

The leading nonprofit defending digital privacy, free speech, and innovation.

RTC security Research, talks and tools. We are researchers in cyber-security, continually educating ourselves and developing knowledge and code. By sharing what we learn, we hope to push RTC security forward.

The best internet privacy and online security blog. Regular news, opinion, and product updates from the world’s leading ultra-fast VPN service.

Worldwide live positions of trains, busses, trams and other public transport vehicles. Find out if your train is on time and see where it is located right now.

At GreyNoise, we collect and analyze untargeted, widespread, and opportunistic scan and attack activity that reaches every server directly connected to the Internet.

The world's best dynamic repository for security vulnerabilities.

Welcome to the wiki where you will find each hacking trick/technique/whatever I have learnt from CTFs, real life apps, reading researches, and news.

Latest web security & vulnerabilities, product releases, product docs and faq blogs.

linux-training.be gives you books for free to study Linux.

18