[Full-disclosure] TPTI-09-15: HP OpenView Data Protector Cell Manager Heap Overflow Vulnerability

2009-12-19 Thread dvlabs
of memory and further lead to arbitrary code execution. -- Vendor Response: -- Disclosure Timeline: 2006-10-10 - Vulnerability reported to vendor 2009-12-17 - Coordinated public release of advisory -- Credit: This vulnerability was discovered by: * Pedram Amini, TippingPoint DVLabs

[Full-disclosure] TPTI-09-08: HP OpenView NNM ovlogin.exe CGI userid/passwd Heap Overflow Vulnerability

2009-12-10 Thread dvlabs
by: * Aaron Portnoy, TippingPoint DVLabs ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] TPTI-09-09: HP OpenView NNM ovsessionmgr.exe userid/passwd Heap Overflow Vulnerability

2009-12-10 Thread dvlabs
of advisory -- Credit: This vulnerability was discovered by: * Aaron Portnoy, TippingPoint DVLabs ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http

[Full-disclosure] TPTI-09-10: HP OpenView NNM webappmon.exe CGI Host Header Buffer Overflow Vulnerability

2009-12-10 Thread dvlabs
Portnoy, TippingPoint DVLabs ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] TPTI-09-14: HP OpenView NNM ovwebsnmpsrv.exe OVwSelection Stack Overflow Vulnerability

2009-12-10 Thread dvlabs
- Coordinated public release of advisory -- Credit: This vulnerability was discovered by: * Aaron Portnoy, TippingPoint DVLabs ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia

[Full-disclosure] TPTI-09-11: HP OpenView NNM OvWebHelp.exe CGI Topic Heap Overflow Vulnerability

2009-12-10 Thread dvlabs
Portnoy, TippingPoint DVLabs ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] TPTI-09-12: HP OpenView NNM ovalarm.exe CGI Accept-Language Stack Overflow Vulnerability

2009-12-10 Thread dvlabs
was discovered by: * Aaron Portnoy, TippingPoint DVLabs ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] TPTI-09-13: HP OpenView NNM snmpviewer.exe CGI Host Header Stack Overflow Vulnerability

2009-12-10 Thread dvlabs
, TippingPoint DVLabs ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] TPTI-09-07: Microsoft Windows License Logging Service Heap Corruption Vulnerability

2009-11-11 Thread dvlabs
- Coordinated public release of advisory -- Credit: This vulnerability was discovered by: * Cody Pierce, TippingPoint DVLabs ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored

[Full-disclosure] TPTI-09-06: Microsoft Windows Workstation Service NetrGetJoinInformation Heap Corruption Vulnerability

2009-08-12 Thread dvlabs
, TippingPoint DVLabs ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] TPTI-09-05: Microsoft DirectShow QuickTime Atom Parsing Memory Corruption Vulnerability

2009-07-15 Thread dvlabs
: This vulnerability was discovered by: * Aaron Portnoy, TippingPoint DVLabs ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] TPTI-09-03: Apple iTunes Multiple Protocol Handler Buffer Overflow Vulnerabilities

2009-06-03 Thread dvlabs
/HT3592 -- Disclosure Timeline: 2009-04-09 - Vulnerability reported to vendor 2009-06-02 - Coordinated public release of advisory -- Credit: This vulnerability was discovered by: * James King, TippingPoint DVLabs ___ Full-Disclosure - We believe

[Full-disclosure] TPTI-09-04: Apple Terminal xterm Resize Escape Sequence Memory Corruption Vulnerability

2009-06-03 Thread dvlabs
/HT3549 -- Disclosure Timeline: 2009-05-06 - Vulnerability reported to vendor 2009-06-02 - Coordinated public release of advisory -- Credit: This vulnerability was discovered by: * James King, TippingPoint DVLabs ___ Full-Disclosure - We believe

[Full-disclosure] TPTI-09-01: VMWare VMnc Codec Invalid RFB Message Type Heap Overflow

2009-04-06 Thread dvlabs
at: http://www.vmware.com/security/advisories/VMSA-2009-0005.html -- Disclosure Timeline: 2009-02-13 - Vulnerability reported to vendor 2009-04-06 - Coordinated public release of advisory -- Credit: This vulnerability was discovered by: * Aaron Portnoy, TippingPoint DVLabs

[Full-disclosure] TPTI-09-02: VMWare VMnc Codec Open-DML Standard Index dwSize Heap Overflow

2009-04-06 Thread dvlabs
://www.vmware.com/security/advisories/VMSA-2009-0005.html -- Disclosure Timeline: 2009-02-16 - Vulnerability reported to vendor 2009-04-06 - Coordinated public release of advisory -- Credit: This vulnerability was discovered by: * Aaron Portnoy, TippingPoint DVLabs

[Full-disclosure] TPTI-08-07: Microsoft Windows Message Queuing Service Heap Overflow and Memory Disclosure Vulnerability

2008-10-14 Thread dvlabs
release of advisory -- Credit: This vulnerability was discovered by: * Cody Pierce, TippingPoint DVLabs ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http

[Full-disclosure] TPTI-08-06: Landesk QIP Server Service Heal Packet Buffer Overflow

2008-09-15 Thread dvlabs
reported to vendor 2008-09-15 - Coordinated public release of advisory -- Credit: This vulnerability was discovered by: * Aaron Portnoy, TippingPoint DVLabs ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure

[Full-disclosure] TPTI-08-05: CA ETrust Secure Content Manager Gateway FTP LIST Stack Overflow Vulnerability

2008-06-04 Thread DVLabs
- Coordinated public release of advisory -- Credit: This vulnerability was discovered by: * Cody Pierce, TippingPoint DVLabs ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored

[Full-disclosure] TPTI-08-04: Microsoft Office Jet Database Engine Column Parsing Stack Overflow Vulnerability

2008-05-13 Thread DVLabs
/ms08-028.mspx -- Disclosure Timeline: 2008-04-19 - Vulnerability reported to vendor 2008-05-13 - Coordinated public release of advisory -- Credit: This vulnerability was discovered by: * Aaron Portnoy, TippingPoint DVLabs ___ Full-Disclosure - We

[Full-disclosure] TPTI-08-03: Microsoft Excel Rich Text Memory Corruption Vulnerability

2008-03-12 Thread DVLabs
public release of advisory -- Credit: This vulnerability was discovered by: * Cody Pierce, TippingPoint DVLabs ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia

[Full-disclosure] TPTI-08-02: Cisco Call Manager CTLProvider Heap Overflow Vulnerability

2008-01-16 Thread DVLabs
- Vulnerability reported to vendor 2008.01.16 - Coordinated public release of advisory -- Credit: This vulnerability was discovered by Cody Pierce - TippingPoint DVLabs. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full

[Full-disclosure] TPTI-08-01: Apple Quicktime Image File IDSC Atom Memory Corruption Vulnerability

2008-01-15 Thread DVLabs
- Vulnerability reported to vendor 2008.01.15 - Coordinated public release of advisory -- Credit: This vulnerability was discovered by Cody Pierce - TippingPoint DVLabs. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure

[Full-disclosure] TPTI-07-20: Apple Quicktime Movie Stack Overflow Vulnerability

2007-11-14 Thread DVLabs
-- Disclosure Timeline: 2007.10.19 - Vulnerability reported to vendor 2007.11.12 - Coordinated public release of advisory -- Credit: This vulnerability was discovered by Cody Pierce - TippingPoint DVLabs. ___ Full-Disclosure - We believe in it. Charter: http