Mobile Application Security – Main Issues & Vulnerabilities
TECO SG2 FBD Client 3.51 SEH Overwrite Buffer Overflow
TECO SG2 FBD Client version 3.51 suffers from a vulnerability that is caused due to a boundary error in the processing of a Genie FBD, which can be exploited to cause a buffer overflow when a user opens e.g. a specially crafted .GFB file. Successful exploitation could allow execution of arbitrary code on the affected […]
TECO AP-PCLINK 1.094 TPC File Handling Buffer Overflow
TECO AP-PCLINK version 1.094 suffers from a vulnerability that is caused due to a boundary error in the processing of a project file, which can be exploited to cause a buffer overflow when a user opens e.g. a specially crafted .TPC file. Successful exploitation could allow execution of arbitrary code on the affected machine.
TECO JN5 L510-DriveLink 1.482 SEH Overwrite Buffer Overflow
TECO JN5 L510-DriveLink version 1.482 suffers from a vulnerability that is caused due to a boundary error in the processing of a project file, which can be exploited to cause a buffer overflow when a user opens e.g. a specially crafted .LF5 file. Successful exploitation could allow execution of arbitrary code on the affected machine.
Microsoft Windows 8.1 Ahcache.sys/NtApphelpCacheControl Privilege Escalation
On Windows 8.1 Update 32/64 bit, the system call NtApphelpCacheControl (the code is actually in ahcache.sys) allows application compatibility data to be cached for quick reuse when new processes are created. A normal user can query the cache but cannot add new cached entries as the operation is restricted to administrators. This is checked in […]
Adobe Reader X / XI Out Of Bounds Read
Adobe Reader X and XI for Windows suffer from an out-of-bounds read in CoolType.dll.
Kaspersky Antivirus DEX File Format Memory Corruption
The attached testcase was found by fuzzing DEX files, and results in a heap overflow with a wild memcpy. Note that Kaspersky catch exceptions and continue execution, so running into unmapped pages doesn’t terminate the process, this should make exploitation quite realistic.
Cisco FireSIGHT Management Center Certificate Validation
The Cisco FireSIGHT Management Center appliance suffers from a certificate validation vulnerability. FirePWNER exploit included. Versions affected include 5.2.x, 5.3.x, and 5.4.x.
Microsoft Windows Kernel Win32k.sys TTF Font Processing Buffer Overflow
A number of Windows kernel crashes in the win32k.sys driver exist while processing a specific corrupted TTF font file. This finding documents an overflow with a malformed OS/2 table.