[Full-disclosure] EEYE: CA BrightStor ArcServe Backup Server Arbitrary Pointer Dereference

2007-10-11 Thread eEye Advisories
CA BrightStor ARCserve Backup Server Arbitrary Pointer Dereference Release Date: October 11, 2007 Date Reported: June 18, 2007 Severity: High (Remote Code Execution) Vendor: Computer Associates (CA) Systems Affected: BrightStor ARCserve Backup 11.5 BrightStor ARCserve Backup 11.1 BrightStor

[Full-disclosure] EEYE: Multiple Vulnerabilities in CA ARCserve for Laptops Desktops

2007-09-22 Thread eEye Advisories
Multiple Vulnerabilities in CA ARCserve for Laptops Desktops Release Date: September 20, 2007 Date Reported: June 5, 2007 Severity: High (Remote Code Execution) Vendor: Computer Associates (CA) Systems Affected: CA ARCserve Backup for Laptops and Desktops r11.5 CA ARCserve Backup for Laptops

[Full-disclosure] EEYE: Windows Metafile AttemptWrite Heap Overflow

2007-08-15 Thread eEye Advisories
Windows Metafile AttemptWrite Heap Overflow Release Date: August 14, 2007 Date Reported: March 27, 2007 Severity: High (Code Execution) Systems Affected: Windows 2000 SP4 Windows XP SP2 Windows Server 2003 SP1 Overview: eEye Digital Security has discovered a heap overflow vulnerability in the

[Full-disclosure] EEYE: VGX.DLL Compressed Content Heap Overflow Vulnerability

2007-08-15 Thread eEye Advisories
VGX.DLL Compressed Content Heap Overflow Vulnerability Release Date: August 14, 2007 Date Reported: October 24, 2006 Severity: High (Code Execution) Systems Affected: Internet Explorer 6 SP1 - Windows 2000 SP4 Internet Explorer 6 SP1 - Windows XP SP1 Internet Explorer 6 SP2 - Windows XP SP2

[Full-disclosure] EEYE: Microsoft Publisher 2007 Arbitrary Pointer Dereference

2007-07-10 Thread eEye Advisories
Microsoft Publisher 2007 Arbitrary Pointer Dereference Release Date: July 10, 2007 Date Reported: February 16, 2007 Severity: High (Remote Code Execution) Vendor: Microsoft Vendor Software Affected: Microsoft Office 2007 Small Business Microsoft Office 2007 Professional Microsoft Office 2007

[Full-disclosure] EEYE: Sun Java WebStart JNLP Stack Buffer Overflow Vulnerability

2007-07-09 Thread eEye Advisories
Sun Java WebStart JNLP Stack Buffer Overflow Vulnerability Release Date: July 5, 2007 Date Reported: Jan 19, 2007 Severity: High (Remote Code Execution) Vendor: Sun Microsystems Systems Affected: Java Runtime Environment 6 Update 1, and earlier Java Runtime Environment 5 Update 11, and

[Full-disclosure] EEYE: Yahoo Webcam ActiveX Controls Multiple Buffer Overflows

2007-06-08 Thread eEye Advisories
Yahoo Webcam ActiveX Controls Multiple Buffer Overflows Release Date: June 8, 2007 Date Reported: June 5, 2007 Severity: High (Remote Code Execution) Vendor: Yahoo!, Inc. Systems Affected: Yahoo Messenger 8 for Windows Overview: eEye Digital Security has discovered two critical

[Full-disclosure] EEYE: Windows Vista CSRSS Dangling Process Pointer Privilege Escalation

2007-04-10 Thread eEye Advisories
Windows Vista CSRSS Dangling Process Pointer Privilege Escalation Release Date: April 10, 2007 Date Reported: January 19, 2007 Severity: Medium (Local Privilege Escalation to SYSTEM) Vendor: Microsoft Systems Affected: Windows Vista Overview: eEye Digital Security has discovered a local

[Full-disclosure] EEYE: Windows VDM Zero Page Race Condition Privilege Escalation

2007-04-10 Thread eEye Advisories
Windows VDM Zero Page Race Condition Privilege Escalation Release Date: April 10, 2007 Date Reported: December 12, 2006 Severity: Medium (Local Privilege Escalation to Kernel) Systems Affected: Windows NT 4.0 SP6 Windows 2000 SP4 Windows XP SP2 (x86) Windows Server 2003 SP2 (x86) Overview:

[Full-disclosure] EEYE: Intel Network Adapter Driver Local Privilege Escalation

2006-12-07 Thread eEye Advisories
eEye Research - http://research.eeye.com Intel Network Adapter Driver Local Privilege Escalation Release Date: December 7, 2006 Date Reported: July 10, 2006 Severity: Medium (Local Privilege Escalation to Kernel) Systems Affected: Windows 2000, XP, 2003, Vista Intel PRO 10/100 -

[Full-disclosure] EEYE: Adobe Download Manager AOM Stack Buffer Overflow Vulnerability

2006-12-05 Thread eEye Advisories
eEye Research - http://research.eeye.com Adobe Download Manager AOM Stack Buffer Overflow Vulnerability Release Date: December 5, 2006 Date Reported: November 10, 2006 Severity: High (Code Execution) Systems Affected: Adobe Download Manager 2.1.x and earlier Overview: eEye Digital Security

[Full-disclosure] EEYE: Workstation Service NetpManageIPCConnect Buffer Overflow

2006-11-14 Thread eEye Advisories
eEye Research - http://research.eeye.com Workstation Service NetpManageIPCConnect Buffer Overflow Release Date: November 14, 2006 Date Reported: July 25, 2006 Severity: High (Remote Code Execution) Vendor: Microsoft Systems Affected: Windows 2000 (Remote Code Execution) Windows XP SP1 (Local

[Full-disclosure] [EEYEB-20080824] Internet Explorer Compressed Content URL Heap Overflow Vulnerability #2

2006-09-12 Thread eEye Advisories
Internet Explorer Compressed Content URL Heap Overflow Vulnerability #2 http://research.eeye.com/html/advisories/published/AD20060912.html Release Date: September 12, 2006 Date Reported: August 24, 2006 Severity: High (Code Execution) Systems Affected: Internet Explorer 5 SP4 with MS06-042 -

[Full-disclosure] [EEYEB-20080824] Internet Explorer Compressed Content URL Heap Overflow Vulnerability #2

2006-09-12 Thread eEye Advisories
Internet Explorer Compressed Content URL Heap Overflow Vulnerability #2 http://research.eeye.com/html/advisories/published/AD20060912.html Release Date: September 12, 2006 Date Reported: August 24, 2006 Severity: High (Code Execution) Systems Affected: Internet Explorer 5

[Full-disclosure] [EEYEB-20060703] IBM eGatherer ActiveX Code Execution Vulnerability

2006-08-16 Thread eEye Advisories
IBM eGatherer ActiveX Code Execution Vulnerability Release Date: August 16, 2006 Date Reported: July 3, 2006 Patch Development Time (in days): 44 Severity: High (Remote Code Execution) Vendor: IBM / Lenovo Systems Affected: Windows NT 4.0 (All versions) Windows 2000 (All versions) Windows XP

[Full-disclosure] [EEYEB-20060719] McAfee Subscription Manager Stack Buffer Overflow

2006-08-07 Thread eEye Advisories
McAfee Subscription Manager Stack Buffer Overflow Release Date: August 7, 2006 Date Reported: July 19, 2006 Patch Development Time (In Days): 17 Days Severity: High (Remote Code Execution) Vendor: McAfee Systems Affected: McAfee AntiSpyware 1.x, 2.x McAfee Internet Security Suite 6.x,

[Full-disclosure] [EEYEB-20060227] D-Link Router UPNP Stack Overflow

2006-07-17 Thread eEye Advisories
D-Link Router UPNP Stack Overflow Release Date: July 13, 2006 Date Reported: February 27, 2006 Patch Development Time (In Days): 136 Severity: High (Remote Code Execution) Vendor: D-Link Routers Affected: DI-524 Rev A DI-524 Rev C DI-524 Rev D DI-604 Rev E DI-624 Rev C DI-624 Rev D DI-784

[Full-disclosure] EEYE: McAfee ePolicy Orchestrator Remote Compromise

2006-07-14 Thread eEye Advisories
McAfee ePolicy Orchestrator Remote Compromise Release Date: July 13, 2006 Severity: High (Remote Code Execution) Vendor: McAfee Systems Affected: McAfee Common Management (EPO) Agent versions below version 3.5.5.438 Overview: McAfee ePolicy Orchestrator is the remote security management

[Full-disclosure] [EEYEB-20060524] Symantec Remote Management Stack Buffer Overflow

2006-06-12 Thread eEye Advisories
Symantec Remote Management Stack Buffer Overflow Release Date: June 12, 2006 Date Reported: May 24, 2006 Severity: High (Remote Code Execution) Systems Affected: Symantec AntiVirus 10.0.x for Windows (all versions) Symantec AntiVirus 10.1.x for Windows (all versions) Symantec Client Security

[Full-disclosure] [EEYEB-20060307] Apple QuickTime FPX Integer Overflow

2006-05-11 Thread eEye Advisories
Apple QuickTime FPX Integer Overflow Release Date: May 11, 2006 Date Reported: March 7, 2006 Patch Development Time (In Days): 65 Severity: High (Remote Code Execution) Vendor: Apple Systems Affected: Quicktime on Windows 2000 Quicktime on Windows XP Quicktime on Mac OS X 10.3.9

[Full-disclosure] [EEYEB20051011B] - Microsoft Distributed Transaction Coordinator Denial of Service

2006-05-09 Thread eEye Advisories
Microsoft Distributed Transaction Coordinator Denial of Service http://www.eeye.com/html/research/advisories/AD20060509b.html Release Date: May 9, 2006 Date Reported: October 11, 2005 Patch Development Time (In Days): 210 Severity: Low (Denial of Service) Systems Affected: Windows NT 4.0

[Full-disclosure] [EEYEB20051011A] - Microsoft Distributed Transaction Coordinator Heap Overflow

2006-05-09 Thread eEye Advisories
Microsoft Distributed Transaction Coordinator Heap Overflow http://www.eeye.com/html/research/advisories/AD20060509a.html Release Date: May 9, 2006 Date Reported: October 11, 2005 Patch Development Time (In Days): 210 Severity: High (Remote Code Execution) Systems Affected: Windows NT 4.0

[Full-disclosure] [EEYEB-20060227] Juniper Networks SSL-VPN Client Buffer Overflow

2006-04-26 Thread eEye Advisories
Juniper Networks SSL-VPN Client Buffer Overflow Release Date: April 25, 2006 Date Reported: February 27, 2006 Patch Development Time (In Days): 57 Days Severity: High (Remote Code Execution) Vendor: Juniper Networks Software Affected: Juniper SSL-VPN JuniperSetup Control Operating Systems

[Full-disclosure] [EEYEB-20051017] Windows Media Player BMP Heap Overflow

2006-02-14 Thread eEye Advisories
EEYEB-20051017 Windows Media Player BMP Heap Overflow Release Date: February 14, 2006 Date Reported: October 17, 2005 Patch Development Time (In Days): 60 Severity: High (Remote Code Execution) Vendor: Microsoft Systems Affected: Microsoft Windows Media Player 7.1 through 10 Windows NT