Subscribe via feed.
Archive for November, 2015

[webapps] – WordPress Users Ultra Plugin 1.5.50 – Unrestricted File Upload

Posted by deepcore under Security (No Respond)

WordPress Users Ultra Plugin 1.5.50 – Unrestricted File Upload

Tags: ,

Mobile Application Security – Main Issues & Vulnerabilities

Posted by deepcore under exploit (No Respond)

TECO SG2 FBD Client 3.51 SEH Overwrite Buffer Overflow

Posted by deepcore under exploit (No Respond)

TECO SG2 FBD Client version 3.51 suffers from a vulnerability that is caused due to a boundary error in the processing of a Genie FBD, which can be exploited to cause a buffer overflow when a user opens e.g. a specially crafted .GFB file. Successful exploitation could allow execution of arbitrary code on the affected […]

TECO AP-PCLINK 1.094 TPC File Handling Buffer Overflow

Posted by deepcore under exploit (No Respond)

TECO AP-PCLINK version 1.094 suffers from a vulnerability that is caused due to a boundary error in the processing of a project file, which can be exploited to cause a buffer overflow when a user opens e.g. a specially crafted .TPC file. Successful exploitation could allow execution of arbitrary code on the affected machine.

TECO JN5 L510-DriveLink 1.482 SEH Overwrite Buffer Overflow

Posted by deepcore under exploit (No Respond)

TECO JN5 L510-DriveLink version 1.482 suffers from a vulnerability that is caused due to a boundary error in the processing of a project file, which can be exploited to cause a buffer overflow when a user opens e.g. a specially crafted .LF5 file. Successful exploitation could allow execution of arbitrary code on the affected machine.

Microsoft Windows 8.1 Ahcache.sys/NtApphelpCacheControl Privilege Escalation

Posted by deepcore under exploit (No Respond)

On Windows 8.1 Update 32/64 bit, the system call NtApphelpCacheControl (the code is actually in ahcache.sys) allows application compatibility data to be cached for quick reuse when new processes are created. A normal user can query the cache but cannot add new cached entries as the operation is restricted to administrators. This is checked in […]

Adobe Reader X / XI Out Of Bounds Read

Posted by deepcore under exploit (No Respond)

Adobe Reader X and XI for Windows suffer from an out-of-bounds read in CoolType.dll.

Kaspersky Antivirus DEX File Format Memory Corruption

Posted by deepcore under exploit (No Respond)

The attached testcase was found by fuzzing DEX files, and results in a heap overflow with a wild memcpy. Note that Kaspersky catch exceptions and continue execution, so running into unmapped pages doesn’t terminate the process, this should make exploitation quite realistic.

Cisco FireSIGHT Management Center Certificate Validation

Posted by deepcore under exploit (No Respond)

The Cisco FireSIGHT Management Center appliance suffers from a certificate validation vulnerability. FirePWNER exploit included. Versions affected include 5.2.x, 5.3.x, and 5.4.x.

Microsoft Windows Kernel Win32k.sys TTF Font Processing Buffer Overflow

Posted by deepcore under exploit (No Respond)

A number of Windows kernel crashes in the win32k.sys driver exist while processing a specific corrupted TTF font file. This finding documents an overflow with a malformed OS/2 table.