VU#276408: Think Mutual Bank Mobile Banking App for iPhone fails to properly validate SSL certificates

Think Mutual Bank mobile banking app for iOS,version 3.1.5 and earlier,fails to properly validate SSL certificates provided by HTTPS connections,which may enable an attacker to conduct man-in-the-middle(MITM)attacks. Continue reading VU#276408: Think Mutual Bank Mobile Banking App for iPhone fails to properly validate SSL certificates

VU#219739: Portrait Displays SDK applications are vulnerable to arbitrary code execution and privilege escalation

Applications developed using the Portrait Display SDK,versions 2.30 through 2.34,default to insecure configurations which allow arbitrary code execution. Continue reading VU#219739: Portrait Displays SDK applications are vulnerable to arbitrary code execution and privilege escalation

VU#676632: IBM Lotus Domino server mailbox name stack buffer overflow

The IBM Lotus Domino server IMAP service contains a stack-based buffer overflow vulnerability in IMAP commands that refer to a mailbox name. This can allow a remote,authenticated attacker to execute arbitrary code with the privileges of the Domino server Continue reading VU#676632: IBM Lotus Domino server mailbox name stack buffer overflow

VU#507496: GIGABYTE BRIX UEFI firmware fails to implement write protection and is not cryptographically signed

GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 and GB-BXi7-5775 platforms,versions vF6 and vF2 respectively,fails to properly set the BIOSWE,BLE,SMM_BWP,and PRx bits to enforce write protection. It also is not cryptographically signed. These issues may permit an attacker to write arbitrary code to the platform firmware,potentially allowing for persistent firmware level rootkits or the creation of a permanent denial of service condition in the platform. Continue reading VU#507496: GIGABYTE BRIX UEFI firmware fails to implement write protection and is not cryptographically signed

VU#600671: PCAUSA Rawether for Windows local privilege escalation

PCAUSA’s Rawether framework does not properly validate BPF data,allowing a crafted malicious BPF program to perform operations on memory outside of its typical bounds on the driver’s receipt of network packets. This vulnerability may be exploited to perform local privilege escalation on Windows systems. Continue reading VU#600671: PCAUSA Rawether for Windows local privilege escalation