[Full-disclosure] ZDI-11-123: Microsoft PowerPoint TimeCommandBehaviorContainer Remote Code Execution Vulnerability

2011-04-12 Thread ZDI Disclosures
ZDI-11-123: Microsoft PowerPoint TimeCommandBehaviorContainer Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-123 April 12, 2011 -- CVE ID: CVE-2011-0655 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Microsoft -- Affected Products: Micro

[Full-disclosure] ZDI-11-122: RealNetworks RealPlayer OpenURLInDefaultBrowser Remote Code Execution Vulnerability

2011-04-12 Thread ZDI Disclosures
ZDI-11-122: RealNetworks RealPlayer OpenURLInDefaultBrowser Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-122 April 12, 2011 -- CVE ID: CVE-2011-1426 -- CVSS: 9.7, (AV:N/AC:L/Au:N/C:C/I:P/A:C) -- Affected Vendors: RealNetworks -- Affected Products: Re

[Full-disclosure] ZDI-11-121: Microsoft Office XP Data Validation Record Parsing Remote Code Execution Vulnerability

2011-04-12 Thread ZDI Disclosures
ZDI-11-121: Microsoft Office XP Data Validation Record Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-121 April 12, 2011 -- CVE ID: CVE-2011-0105 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Microsoft -- Affected Products: Mic

[Full-disclosure] ZDI-11-120: Microsoft Office Excel RealTimeData Record Parsing Remote Code Execution Vulnerability

2011-04-12 Thread ZDI Disclosures
ZDI-11-120: Microsoft Office Excel RealTimeData Record Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-120 April 12, 2011 -- CVE ID: CVE-2011-0101 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Microsoft -- Affected Products: Micr

[Full-disclosure] ZDI-11-119: (Pwn2Own) Microsoft Internet Explorer onPropertyChange Remote Code Execution Vulnerability

2011-04-12 Thread ZDI Disclosures
ZDI-11-119: (Pwn2Own) Microsoft Internet Explorer onPropertyChange Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-119 April 12, 2011 -- CVE ID: CVE-2011-1345 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Microsoft -- Affected Products:

[Full-disclosure] ZDI-11-118: Novell ZENworks Asset Management Path Traversal File Overwrite Remote Code Execution Vulnerability

2011-04-11 Thread ZDI Disclosures
ZDI-11-118: Novell ZENworks Asset Management Path Traversal File Overwrite Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-118 April 11, 2011 -- CVE ID: CVE-2010-4229 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Novell -- Affected Prod

[Full-disclosure] ZDI-11-117: McAfee Firewall Reporter GeneralUtilities.pm isValidClient Authentication Bypass Vulnerability

2011-04-11 Thread ZDI Disclosures
ZDI-11-117: McAfee Firewall Reporter GeneralUtilities.pm isValidClient Authentication Bypass Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-117 April 11, 2011 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: McAfee -- Affected Products: McAfee Firewall Repo

[Full-disclosure] ZDI-11-116: Novell File Reporter Agent XML Parsing Remote Code Execution Vulnerability

2011-04-04 Thread ZDI Disclosures
ZDI-11-116: Novell File Reporter Agent XML Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-116 April 4, 2011 -- CVE ID: CVE-2011-0994 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Novell -- Affected Products: Novell File Reporte

[Full-disclosure] ZDI-11-115: IBM solidDB solid.exe Authentication Bypass Remote Code Execution Vulnerability

2011-04-01 Thread ZDI Disclosures
ZDI-11-115: IBM solidDB solid.exe Authentication Bypass Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-115 April 1, 2011 -- CVSS: 9.3, (AV:N/AC:M/Au:N/C:C/I:C/A:C) -- Affected Vendors: IBM -- Affected Products: IBM solidDB -- TippingPoint(TM) IPS Custo

[Full-disclosure] ZDI-11-041: (0day) Multiple Browser Node Processing Stack Overflow Vulnerability

2011-04-01 Thread ZDI Disclosures
ZDI-11-041: (0day) Multiple Browser Node Processing Stack Overflow Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-911 April 1, 2011 -- CVE ID: CVE-C000-00FD -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Microsoft Google Mikul Apple ISC -- Affected Products: M

[Full-disclosure] ZDI-11-113: Zend Server Java Bridge Design Flaw Remote Code Execution Vulnerability

2011-03-28 Thread ZDI Disclosures
ZDI-11-113: Zend Server Java Bridge Design Flaw Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-113 March 28, 2011 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Zend -- Affected Products: Zend Zend Server -- TippingPoint(TM) IPS Custome

[Full-disclosure] ZDI-11-112: (0 day) Hewlett-Packard Data Protector Media Operations DBServer.exe Remote Code Execution Vulnerability

2011-03-23 Thread ZDI Disclosures
ZDI-11-112: (0 day) Hewlett-Packard Data Protector Media Operations DBServer.exe Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-112 March 23, 2011 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Hewlett-Packard -- Affected Products: Hewle

[Full-disclosure] ZDI-11-111: (0Day) Hewlett-Packard Virtual SAN Appliance hydra.exe Login Request Remote Code Execution Vulnerability

2011-03-23 Thread ZDI Disclosures
ZDI-11-111: (0Day) Hewlett-Packard Virtual SAN Appliance hydra.exe Login Request Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-111 March 23, 2011 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Hewlett-Packard -- Affected Products: Hewle

[Full-disclosure] ZDI-11-110: (0day) IBM Lotus Domino Server Controller Authentication Bypass Remote Code Execution Vulnerability

2011-03-22 Thread ZDI Disclosures
ZDI-11-110: (0day) IBM Lotus Domino Server Controller Authentication Bypass Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-110 March 22, 2011 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: IBM -- Affected Products: IBM Lotus Domino -- V

[Full-disclosure] ZDI-11-109: (Pwn2Own) Apple Safari OfficeArtBlip Parsing Remote Code Execution Vulnerability

2011-03-22 Thread ZDI Disclosures
ZDI-11-109: (Pwn2Own) Apple Safari OfficeArtBlip Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-109 March 22, 2011 -- CVE ID: CVE-2011-1417 -- CVSS: 9.7, (AV:N/AC:L/Au:N/C:C/I:C/A:P) -- Affected Vendors: Apple -- Affected Products: Apple Safari

[Full-disclosure] ZDI-11-108: Mac OS X Compact Font Format Decoder Remote Code Execution Vulnerability

2011-03-22 Thread ZDI Disclosures
ZDI-11-108: Mac OS X Compact Font Format Decoder Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-108 March 22, 2011 -- CVE ID: CVE-2011-0176 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Apple -- Affected Products: Apple Preview -- Ti

[Full-disclosure] ZDI-11-107: Libtiff ThunderCode Decoder THUNDER_2BITDELTAS Remote Code Execution Vulnerability

2011-03-21 Thread ZDI Disclosures
ZDI-11-107: Libtiff ThunderCode Decoder THUNDER_2BITDELTAS Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-107 March 21, 2011 -- CVE ID: CVE-2011-1167 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Libtiff -- Affected Products: Libtiff l

[Full-disclosure] ZDI-11-106: Novell Netware NWFTPD.NLM DELE Remote Code Execution Vulnerability

2011-03-18 Thread ZDI Disclosures
ZDI-11-106: Novell Netware NWFTPD.NLM DELE Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-106 March 18, 2011 -- CVE ID: CVE-2010-4228 -- CVSS: 9, (AV:N/AC:L/Au:S/C:C/I:C/A:C) -- Affected Vendors: Novell -- Affected Products: Novell Netware -- TippingPo

[Full-disclosure] ZDI-11-105: Hewlett-Packard Client Automation radexecd.exe Remote Code Execution Vulnerability

2011-03-18 Thread ZDI Disclosures
ZDI-11-105: Hewlett-Packard Client Automation radexecd.exe Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-105 March 18, 2011 -- CVE ID: CVE-2011-0889 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Hewlett-Packard -- Affected Products: H

[Full-disclosure] ZDI-11-103: Mozilla Firefox JSON.stringify Dangling Pointer Remote Code Execution Vulnerability

2011-03-02 Thread ZDI Disclosures
ZDI-11-103: Mozilla Firefox JSON.stringify Dangling Pointer Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-103 March 2, 2011 -- CVE ID: CVE-2011-0055 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Mozilla -- Affected Products: Mozilla Fi

[Full-disclosure] ZDI-11-102: PostgreSQL Plus Advanced Server DBA Management Server Remote Authentication Bypass Vulnerability

2011-03-02 Thread ZDI Disclosures
ZDI-11-102: PostgreSQL Plus Advanced Server DBA Management Server Remote Authentication Bypass Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-102 March 2, 2011 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Postgres -- Affected Products: Postgres Plus SQL

[Full-disclosure] ZDI-11-101: Apple iPhone Webkit Library Javascript Array sort Method Remote Code Execution Vulnerability

2011-03-02 Thread ZDI Disclosures
ZDI-11-101: Apple iPhone Webkit Library Javascript Array sort Method Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-101 March 2, 2011 -- CVE ID: CVE-2011-0154 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Apple -- Affected Products: App

[Full-disclosure] ZDI-11-100: Apple Webkit Root HTMLBRElement Style Remote Code Execution Vulnerability

2011-03-02 Thread ZDI Disclosures
ZDI-11-100: Apple Webkit Root HTMLBRElement Style Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-100 March 2, 2011 -- CVE ID: CVE-2011-0149 -- CVSS: 9, (AV:N/AC:M/Au:N/C:C/I:P/A:C) -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- Tippi

[Full-disclosure] ZDI-11-099: Apple Webkit Font Glyph Layout Remote Code Execution Vulnerability

2011-03-02 Thread ZDI Disclosures
ZDI-11-099: Apple Webkit Font Glyph Layout Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-099 March 2, 2011 -- CVE ID: CVE-2011-0133 -- CVSS: 9.7, (AV:N/AC:L/Au:N/C:C/I:P/A:C) -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- TippingPoin

[Full-disclosure] ZDI-11-098: Apple Safari Webkit Runin Box Promotion Remote Code Execution Vulnerability

2011-03-02 Thread ZDI Disclosures
ZDI-11-098: Apple Safari Webkit Runin Box Promotion Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-098 March 2, 2011 -- CVE ID: CVE-2011-0132 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- Vul

[Full-disclosure] ZDI-11-097: Apple Webkit setOuterText Memory Corruption Remote Code Execution Vulnerability

2011-03-02 Thread ZDI Disclosures
ZDI-11-097: Apple Webkit setOuterText Memory Corruption Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-097 March 2, 2011 -- CVE ID: CVE-2011-0116 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Apple -- Affected Products: Apple WebKit --

[Full-disclosure] ZDI-11-096: Apple Safari WebKit Range Object Remote Code Execution Vulnerability

2011-03-02 Thread ZDI Disclosures
ZDI-11-096: Apple Safari WebKit Range Object Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-096 March 2, 2011 -- CVE ID: CVE-2011-0115 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- TippingPoin

[Full-disclosure] ZDI-11-095: Apple Webkit Error Message Mutation Remote Code Execution Vulnerability

2011-03-02 Thread ZDI Disclosures
ZDI-11-095: Apple Webkit Error Message Mutation Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-095 March 2, 2011 -- CVE ID: CVE-2010-1824 -- CVSS: 9.7, (AV:N/AC:L/Au:N/C:C/I:P/A:C) -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- Tippi

[Full-disclosure] ZDI-11-094: (0 day) Hewlett-Packard StorageWorks File Migration Agent Remote Archive Tampering Vulnerability

2011-02-28 Thread ZDI Disclosures
ZDI-11-094: (0 day) Hewlett-Packard StorageWorks File Migration Agent Remote Archive Tampering Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-094 February 28, 2011 -- CVSS: 7.5, (AV:N/AC:L/Au:N/C:P/I:P/A:P) -- Affected Vendors: Hewlett-Packard -- Affected Products: Hewlett-P

[Full-disclosure] ZDI-11-093: CA Internet Security Suite HIPS XML Security Database Parser Class Remote Code Execution Vulnerability

2011-02-23 Thread ZDI Disclosures
ZDI-11-093: CA Internet Security Suite HIPS XML Security Database Parser Class Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-093 February 23, 2011 -- CVE ID: CVE-2011-1036 -- CVSS: 9.3, (AV:N/AC:M/Au:N/C:C/I:C/A:C) -- Affected Vendors: CA -- Affected

[Full-disclosure] ZDI-11-092: (0day) Cisco Secure Desktop CSDWebInstaller ActiveX Control Cleaner.cab Remote Code Execution Vulnerability

2011-02-23 Thread ZDI Disclosures
ZDI-11-092: (0day) Cisco Secure Desktop CSDWebInstaller ActiveX Control Cleaner.cab Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-092 February 23, 2011 -- CVE ID: CVE-2011-0925 -- CVSS: 8.3, (AV:N/AC:M/Au:N/C:P/I:P/A:C) -- Affected Vendors: Cisco -- A

[Full-disclosure] ZDI-11-091: (0day) Cisco Secure Desktop CSDWebInstaller Remote Code Execution Vulnerability

2011-02-23 Thread ZDI Disclosures
ZDI-11-091: (0day) Cisco Secure Desktop CSDWebInstaller Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-091 February 23, 2011 -- CVE ID: CVE-2011-0926 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Cisco -- Affected Products: Cisco Secure

[Full-disclosure] ZDI-11-090: Novell Netware RPC XNFS xdrDecodeString Remote Code Execution Vulnerability

2011-02-23 Thread ZDI Disclosures
ZDI-11-090: Novell Netware RPC XNFS xdrDecodeString Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-090 February 18, 2011 -- CVE ID: CVE-2010-4227 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Novell -- Affected Products: Novell Netware

[Full-disclosure] ZDI-11-089: Novell ZenWorks TFTPD Remote Code Execution Vulnerability

2011-02-17 Thread ZDI Disclosures
ZDI-11-089: Novell ZenWorks TFTPD Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-089 February 17, 2011 -- CVE ID: CVE-2010-4323 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Novell -- Affected Products: Novell Zenworks -- TippingPoint

[Full-disclosure] ZDI-11-088: Cisco Security Agent Management st_upload Remote Code Execution Vulnerability

2011-02-16 Thread ZDI Disclosures
ZDI-11-088: Cisco Security Agent Management st_upload Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-088 February 16, 2011 -- CVE ID: CVE-2011-0364 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Cisco -- Affected Products: Cisco Securit

[Full-disclosure] ZDI-11-087: Novell iPrint LPD Remote Code Execution Vulnerability

2011-02-16 Thread ZDI Disclosures
ZDI-11-087: Novell iPrint LPD Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-087 February 16, 2011 -- CVE ID: CVE-2010-4328 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Novell -- Affected Products: Novell iPrint -- TippingPoint(TM) IPS

[Full-disclosure] ZDI-11-085: Oracle Java XGetSamplePtrFromSnd Remote Code Execution Vulnerability

2011-02-15 Thread ZDI Disclosures
ZDI-11-085: Oracle Java XGetSamplePtrFromSnd Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-085 February 15, 2011 -- CVE ID: CVE-2010-4462 -- CVSS: 7.5, (AV:N/AC:L/Au:N/C:P/I:P/A:P) -- Affected Vendors: Oracle -- Affected Products: Oracle Java Runtime

[Full-disclosure] ZDI-11-082: Oracle Java Runtime NTLM Authentication Information Leakage Vulnerability

2011-02-15 Thread ZDI Disclosures
ZDI-11-082: Oracle Java Runtime NTLM Authentication Information Leakage Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-082 February 15, 2011 -- CVE ID: CVE-2010-4466 -- CVSS: 6.4, (AV:N/AC:L/Au:N/C:P/I:P/A:N) -- Affected Vendors: Oracle -- Affected Products: Oracle Java Run

[Full-disclosure] ZDI-11-086: Oracle Java Webstart Trusted JNLP Extension Remote Code Execution Vulnerability

2011-02-15 Thread ZDI Disclosures
ZDI-11-086: Oracle Java Webstart Trusted JNLP Extension Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-086 February 15, 2011 -- CVE ID: CVE-2010-4463 -- CVSS: 9.7, (AV:N/AC:L/Au:N/C:C/I:C/A:P) -- Affected Vendors: Oracle -- Affected Products: Oracle Ja

[Full-disclosure] ZDI-11-084: Oracle Java Unsigned Applet Applet2ClassLoader Remote Code Execution Vulnerability

2011-02-15 Thread ZDI Disclosures
ZDI-11-084: Oracle Java Unsigned Applet Applet2ClassLoader Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-084 February 15, 2011 -- CVE ID: CVE-2010-4452 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Oracle -- Affected Products: Oracle J

[Full-disclosure] ZDI-11-083: Oracle Java Applet Clipboard Injection Remote Code Execution Vulnerability

2011-02-15 Thread ZDI Disclosures
ZDI-11-083: Oracle Java Applet Clipboard Injection Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-083 February 15, 2011 -- CVE ID: CVE-2010-4465 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Oracle -- Affected Products: Oracle Java Run

[Full-disclosure] TPTI-11-05: Adobe Shockwave PFR1 Font Chunk Parsing Remote Code Execution Vulnerability

2011-02-09 Thread ZDI Disclosures
TPTI-11-05: Adobe Shockwave PFR1 Font Chunk Parsing Remote Code Execution Vulnerability http://dvlabs.tippingpoint.com/advisory/TPTI-11-05 February 8, 2011 -- CVE ID: CVE-2011-0569 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Adobe -- Affected Products: Adobe Shockwave Playe

[Full-disclosure] TPTI-11-04: Adobe Shockwave GIF Logical Screen Descriptor Parsing Remote Code Execution Vulnerability

2011-02-09 Thread ZDI Disclosures
TPTI-11-04: Adobe Shockwave GIF Logical Screen Descriptor Parsing Remote Code Execution Vulnerability http://dvlabs.tippingpoint.com/advisory/TPTI-11-04 February 8, 2011 -- CVE ID: CVE-2010-4189 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Adobe -- Affected Products: Adobe S

[Full-disclosure] TPTI-11-03: Adobe Shockwave Font Xtra String Decoding Remote Code Execution Vulnerability

2011-02-09 Thread ZDI Disclosures
TPTI-11-03: Adobe Shockwave Font Xtra String Decoding Remote Code Execution Vulnerability http://dvlabs.tippingpoint.com/advisory/TPTI-11-03 February 8, 2011 -- CVE ID: CVE-2011-0556 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Adobe -- Affected Products: Adobe Shockwave Pla

[Full-disclosure] TPTI-11-02: Adobe Shockwave TextXtra Invalid Seek Remote Code Execution Vulnerability

2011-02-09 Thread ZDI Disclosures
TPTI-11-02: Adobe Shockwave TextXtra Invalid Seek Remote Code Execution Vulnerability http://dvlabs.tippingpoint.com/advisory/TPTI-11-02 February 8, 2011 -- CVE ID: CVE-2011-0555 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Adobe -- Affected Products: Adobe Shockwave Player

[Full-disclosure] TPTI-11-01: Adobe Shockwave dirapi.dll IFWV Trusted Offset Remote Code Execution Vulnerability

2011-02-09 Thread ZDI Disclosures
TPTI-11-01: Adobe Shockwave dirapi.dll IFWV Trusted Offset Remote Code Execution Vulnerability http://dvlabs.tippingpoint.com/advisory/TPTI-11-01 February 8, 2011 -- CVE ID: CVE-2010-4188 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Adobe -- Affected Products: Adobe Shockwav

[Full-disclosure] ZDI-11-081: Adobe Flash Player Point Object Remote Code Execution Vulnerability

2011-02-08 Thread ZDI Disclosures
ZDI-11-081: Adobe Flash Player Point Object Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-081 February 8, 2011 -- CVE ID: CVE-2011-0578 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Adobe -- Affected Products: Adobe Flash Player -- Vul

[Full-disclosure] ZDI-11-080: Adobe Shockwave CSWV Chunk Substructure Offset Value Remote Code Execution Vulnerability

2011-02-08 Thread ZDI Disclosures
ZDI-11-080: Adobe Shockwave CSWV Chunk Substructure Offset Value Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-080 February 8, 2011 -- CVE ID: CVE-2010-4190 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Adobe -- Affected Products: Adob

[Full-disclosure] ZDI-11-079: Adobe Shockwave Player 0xFFFFFF45 Record Count Element Remote Code Execution Vulnerability

2011-02-08 Thread ZDI Disclosures
ZDI-11-079: Adobe Shockwave Player 0xFF45 Record Count Element Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-079 February 8, 2011 -- CVE ID: CVE-2011-0557 -- CVSS: 9, (AV:N/AC:L/Au:N/C:C/I:P/A:P) -- Affected Vendors: Adobe -- Affected Products: Ad

[Full-disclosure] ZDI-11-078: Adobe Shockwave Player FFFFFF88 Record Count Element Remote Code Execution Vulnerability

2011-02-08 Thread ZDI Disclosures
ZDI-11-078: Adobe Shockwave Player FF88 Record Count Element Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-078 February 8, 2011 -- CVE ID: CVE-2010-4192 -- CVSS: 9, (AV:N/AC:L/Au:N/C:C/I:P/A:P) -- Affected Vendors: Adobe -- Affected Products: Adob

[Full-disclosure] ZDI-11-077: Adobe Acrobat Reader U3D Texture Parser ILBM Remote Code Execution Vulnerability

2011-02-08 Thread ZDI Disclosures
ZDI-11-077: Adobe Acrobat Reader U3D Texture Parser ILBM Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-077 February 8, 2011 -- CVE ID: CVE-2011-0590 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Adobe -- Affected Products: Adobe Acroba

[Full-disclosure] ZDI-11-076: RealNetworks Real Player Predictable Temporary File Remote Code Execution Vulnerability

2011-02-08 Thread ZDI Disclosures
ZDI-11-076: RealNetworks Real Player Predictable Temporary File Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-076 February 8, 2011 -- CVE ID: CVE-2011-0694 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: RealNetworks -- Affected Products

[Full-disclosure] ZDI-11-075: Adobe Acrobat Reader rt3d.dll Multimedia Playing Arbitrary Memory Overwite Remote Code Execution Vulnerability

2011-02-08 Thread ZDI Disclosures
ZDI-11-075: Adobe Acrobat Reader rt3d.dll Multimedia Playing Arbitrary Memory Overwite Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-075 February 8, 2011 -- CVE ID: CVE-2011-0606 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Adobe -- A

[Full-disclosure] ZDI-11-074: Adobe Reader u3d Parent Node Count Remote Code Execution Vulnerability

2011-02-08 Thread ZDI Disclosures
ZDI-11-074: Adobe Reader u3d Parent Node Count Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-074 February 8, 2011 -- CVE ID: CVE-2011-0600 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Adobe -- Affected Products: Adobe Reader -- Vulne

[Full-disclosure] ZDI-11-073: Adobe Reader ICC Parsing Remote Code Execution Vulnerability

2011-02-08 Thread ZDI Disclosures
ZDI-11-073: Adobe Reader ICC Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-073 February 8, 2011 -- CVE ID: CVE-2011-0598 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Adobe -- Affected Products: Adobe Reader -- Vulnerability De

[Full-disclosure] ZDI-11-072: Adobe Reader BMP ColorData Remote Code Execution Vulnerability

2011-02-08 Thread ZDI Disclosures
ZDI-11-072: Adobe Reader BMP ColorData Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-072 February 8, 2011 -- CVE ID: CVE-2011-0599 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Adobe -- Affected Products: Adobe Reader -- TippingPoint(T

[Full-disclosure] ZDI-11-071: Adobe Reader BMP RLE_8 Decompression Remote Code Execution Vulnerability

2011-02-08 Thread ZDI Disclosures
ZDI-11-071: Adobe Reader BMP RLE_8 Decompression Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-071 February 8, 2011 -- CVE ID: CVE-2011-0596 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Adobe -- Affected Products: Adobe Reader -- Vul

[Full-disclosure] ZDI-11-070: Adobe Acrobat Reader U3D Texture .fli RLE Decompression Remote Code Execution Vulnerability

2011-02-08 Thread ZDI Disclosures
ZDI-11-070: Adobe Acrobat Reader U3D Texture .fli RLE Decompression Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-070 February 8, 2011 -- CVE ID: CVE-2011-0595 -- CVSS: 9.7, (AV:N/AC:L/Au:N/C:C/I:C/A:P) -- Affected Vendors: Adobe -- Affected Products:

[Full-disclosure] ZDI-11-069: Adobe Acrobat Reader U3D Texture psd RLE Decompression Remote Code Execution Vulnerability

2011-02-08 Thread ZDI Disclosures
ZDI-11-069: Adobe Acrobat Reader U3D Texture psd RLE Decompression Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-069 February 8, 2011 -- CVE ID: CVE-2011-0593 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Adobe -- Affected Products: Ad

[Full-disclosure] ZDI-11-068: Adobe Acrobat Reader U3D Texture bmp RLE Decompression Remote Code Execution Vulnerability

2011-02-08 Thread ZDI Disclosures
ZDI-11-068: Adobe Acrobat Reader U3D Texture bmp RLE Decompression Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-068 February 8, 2011 -- CVE ID: CVE-2011-0592 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Adobe -- Affected Products: Ad

[Full-disclosure] ZDI-11-067: Adobe Acrobat Reader U3D Texture rgba RLE Decompression Remote Code Execution Vulnerability

2011-02-08 Thread ZDI Disclosures
ZDI-11-067: Adobe Acrobat Reader U3D Texture rgba RLE Decompression Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-067 February 8, 2011 -- CVE ID: CVE-2011-0591 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Adobe -- Affected Products: A

[Full-disclosure] ZDI-11-066: Adobe Acrobat Reader U3D Texture .iff RLE Decompression Remote Code Execution Vulnerability

2011-02-08 Thread ZDI Disclosures
ZDI-11-066: Adobe Acrobat Reader U3D Texture .iff RLE Decompression Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-066 February 8, 2011 -- CVE ID: CVE-2011-0590 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Adobe -- Affected Products:

[Full-disclosure] ZDI-11-065: Adobe Reader Controlled memset Remote Code Execution Vulnerability

2011-02-08 Thread ZDI Disclosures
ZDI-11-065: Adobe Reader Controlled memset Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-065 February 8, 2011 -- CVE ID: CVE-2011-0567 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Adobe -- Affected Products: Adobe Reader -- Vulnerabi

[Full-disclosure] ZDI-11-064: Microsoft Windows WmiTraceMessageVa Local Kernel Vulnerability

2011-02-08 Thread ZDI Disclosures
ZDI-11-064: Microsoft Windows WmiTraceMessageVa Local Kernel Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-064 February 8, 2011 -- CVE ID: CVE-2011-0045 -- CVSS: 6.8, (AV:L/AC:L/Au:S/C:C/I:C/A:C) -- Affected Vendors: Microsoft -- Affected Products: Microsoft Windows XP --

[Full-disclosure] ZDI-11-063: Microsoft Visio 2007 LZW Stream Decompression Exception Vulnerability

2011-02-08 Thread ZDI Disclosures
ZDI-11-063: Microsoft Visio 2007 LZW Stream Decompression Exception Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-063 February 8, 2011 -- CVE ID: CVE-2011-0092 -- Affected Vendors: Microsoft -- Affected Products: Microsoft Other -- Vulnerability Details: This vulnerability

[Full-disclosure] ZDI-11-062: Multiple Vendor Calendar Manager RPC Service Remote Code Execution Vulnerability

2011-02-08 Thread ZDI Disclosures
ZDI-11-062: Multiple Vendor Calendar Manager RPC Service Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-062 February 8, 2011 -- CVE ID: CVE-2010-4435 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Hewlett-Packard IBM Sun Microsystems --

[Full-disclosure] ZDI-11-061: EMC Replication Manager Client irccd.exe Remote Code Execution Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-061: EMC Replication Manager Client irccd.exe Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-061 February 7, 2011 -- CVE ID: CVE-2011-0647 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: EMC -- Affected Products: EMC Replication M

[Full-disclosure] ZDI-11-060: Novell eDirectory Malformed NCP Request Denial of Service Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-060: Novell eDirectory Malformed NCP Request Denial of Service Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-060 February 7, 2011 -- CVE ID: CVE-2010-4327 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Novell -- Affected Products: Novell eDirectory -

[Full-disclosure] ZDI-11-059: CA ETrust Secure Content Manager Common Services Transport Remote Code Execution Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-059: CA ETrust Secure Content Manager Common Services Transport Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-059 February 7, 2011 - This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline. To vie

[Full-disclosure] ZDI-11-057: Hewlett-Packard Data Protector Cell Manager Service Authentication Bypass Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-057: Hewlett-Packard Data Protector Cell Manager Service Authentication Bypass Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-057 February 7, 2011 - This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline. To view mitig

[Full-disclosure] ZDI-11-055: Hewlett-Packard Data Protector Client EXEC_CMD Perl Remote Code Execution Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-055: Hewlett-Packard Data Protector Client EXEC_CMD Perl Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-055 February 7, 2011 - This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline. To view mitig

[Full-disclosure] ZDI-11-058: SCO Openserver IMAP Daemon Long Verb Parsing Remote Code Execution Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-058: SCO Openserver IMAP Daemon Long Verb Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-058 February 7, 2011 - This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline. To view mitigations

[Full-disclosure] ZDI-11-056: Hewlett-Packard Data Protector Client EXEC_SETUP Remote Code Execution Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-056: Hewlett-Packard Data Protector Client EXEC_SETUP Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-056 February 7, 2011 - This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline. To view mitigati

[Full-disclosure] ZDI-11-054: Hewlett-Packard Data Protector Client EXEC_CMD omni_chk_ds.sh Remote Code Execution Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-054: Hewlett-Packard Data Protector Client EXEC_CMD omni_chk_ds.sh Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-054 February 7, 2011 - This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline. To

[Full-disclosure] ZDI-11-052: Lotus Domino Server diiop Client Request Operation Remote Code Execution Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-052: Lotus Domino Server diiop Client Request Operation Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-052 February 7, 2011 - This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline. To view mitiga

[Full-disclosure] ZDI-11-053: Lotus Domino Server diiop getEnvironmentString Remote Code Execution Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-053: Lotus Domino Server diiop getEnvironmentString Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-053 February 7, 2011 - This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline. To view mitigation

[Full-disclosure] ZDI-11-051: IBM Lotus Notes cai URI Handler Remote Code Execution Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-051: IBM Lotus Notes cai URI Handler Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-051 February 7, 2011 - This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline. To view mitigations for this vuln

[Full-disclosure] ZDI-11-049: IBM Lotus Domino SMTP Multiple Filename Arguments Remote Code Execution Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-049: IBM Lotus Domino SMTP Multiple Filename Arguments Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-049 February 7, 2011 - This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline. To view mitigat

[Full-disclosure] ZDI-11-046: IBM Lotus Domino Calendar Request Attachment Name Parsing Remote Code Execution Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-046: IBM Lotus Domino Calendar Request Attachment Name Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-046 February 7, 2011 - This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline. To view

[Full-disclosure] ZDI-11-050: IBM Informix Dynamic Server SET ENVIRONMENT Remote Code Execution Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-050: IBM Informix Dynamic Server SET ENVIRONMENT Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-050 February 7, 2011 - This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline. To view mitigations f

[Full-disclosure] ZDI-11-045: IBM Lotus Domino IMAP/POP3 Non-Printable Character Expansion Remote Code Execution Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-045: IBM Lotus Domino IMAP/POP3 Non-Printable Character Expansion Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-045 February 7, 2011 - This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline. To v

[Full-disclosure] ZDI-11-044: Microsoft PowerPoint 2007 OfficeArt Atom Remote Code Execution Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-044: Microsoft PowerPoint 2007 OfficeArt Atom Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-044 February 7, 2011 - This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline. To view mitigations for

[Full-disclosure] ZDI-11-048: IBM Lotus Domino iCalendar Meeting Request Parsing Remote Code Execution Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-048: IBM Lotus Domino iCalendar Meeting Request Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-048 February 7, 2011 - This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline. To view mitiga

[Full-disclosure] ZDI-11-047: IBM Lotus Domino LDAP Bind Request Remote Code Execution Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-047: IBM Lotus Domino LDAP Bind Request Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-047 February 7, 2011 - This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline. To view mitigations for this

[Full-disclosure] ZDI-11-042: Microsoft Office Excel Axis Properties Record Parsing Remote Code Execution Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-042: Microsoft Office Excel Axis Properties Record Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-042 February 7, 2011 - This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline. To view mit

[Full-disclosure] ZDI-11-043: Microsoft Excel 2007 Office Drawing Layer Remote Code Execution Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-043: Microsoft Excel 2007 Office Drawing Layer Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-043 February 7, 2011 - This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline. To view mitigations for

[Full-disclosure] ZDI-11-041: Microsoft Office Excel Office Art Object Parsing Remote Code Execution Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-041: Microsoft Office Excel Office Art Object Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-041 February 7, 2011 - This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline. To view mitigati

[Full-disclosure] ZDI-11-040: Microsoft Office Excel 2003 Invalid Object Type Remote Code Execution Vulnerability

2011-02-07 Thread ZDI Disclosures
ZDI-11-040: Microsoft Office Excel 2003 Invalid Object Type Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-040 February 7, 2011 - This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline. To view mitigatio

[Full-disclosure] ZDI-11-039: BMC PATROL Agent Service Daemon BGS_MULTIPLE_READS Remote Code Execution Vulnerability

2011-02-03 Thread ZDI Disclosures
ZDI-11-039: BMC PATROL Agent Service Daemon BGS_MULTIPLE_READS Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-039 February 3, 2011 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: BMC Software -- Affected Products: BMC Software Patrol --

[Full-disclosure] ZDI-11-037: Symantec IM Manager Administrative Interface IMAdminSchedTask.asp Eval Code Injection Remote Code Execution Vulnerability

2011-01-31 Thread ZDI Disclosures
ZDI-11-037: Symantec IM Manager Administrative Interface IMAdminSchedTask.asp Eval Code Injection Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-037 January 31, 2011 -- CVE ID: CVE-2010-3719 -- CVSS: 8.5, (AV:N/AC:M/Au:S/C:C/I:C/A:C) -- Affected Vendors

[Full-disclosure] ZDI-11-036: IBM DB2 db2dasrrm receiveDASMessage Remote Code Execution Vulnerability

2011-01-31 Thread ZDI Disclosures
ZDI-11-036: IBM DB2 db2dasrrm receiveDASMessage Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-036 January 31, 2011 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: IBM -- Affected Products: IBM DB2 Universal Database -- Vulnerability Deta

[Full-disclosure] ZDI-11-035: IBM DB2 db2dasrrm validateUser Remote Code Execution Vulnerability

2011-01-31 Thread ZDI Disclosures
ZDI-11-035: IBM DB2 db2dasrrm validateUser Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-035 January 31, 2011 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: IBM -- Affected Products: IBM DB2 Universal Database -- Vulnerability Details: T

[Full-disclosure] ZDI-11-034: HP OpenView Performance Insight Server Backdoor Account Code Execution Vulnerability

2011-01-31 Thread ZDI Disclosures
ZDI-11-034: HP OpenView Performance Insight Server Backdoor Account Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-034 January 31, 2011 -- CVE ID: CVE-2011-0276 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Hewlett-Packard -- Affected Product

[Full-disclosure] ZDI-11-034: HP OpenView Performance Insight Server Backdoor Account Code Execution Vulnerability

2011-01-31 Thread ZDI Disclosures
ZDI-11-034: HP OpenView Performance Insight Server Backdoor Account Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-034 January 31, 2011 -- CVE ID: CVE-2011-0276 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Hewlett-Packard -- Affected Product

[Full-disclosure] ZDI-11-033: Realplayer vidplin.dll AVI Parsing Remote Code Execution Vulnerability

2011-01-27 Thread ZDI Disclosures
ZDI-11-033: Realplayer vidplin.dll AVI Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-033 January 27, 2011 -- CVE ID: CVE-2010-4393 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: RealNetworks -- Affected Products: RealNetworks Re

[Full-disclosure] ZDI-11-033: Realplayer vidplin.dll AVI Parsing Remote Code Execution Vulnerability

2011-01-27 Thread ZDI Disclosures
ZDI-11-033: Realplayer vidplin.dll AVI Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-033 January 27, 2011 -- CVE ID: CVE-2010-4393 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: RealNetworks -- Affected Products: RealNetworks Re

[Full-disclosure] ZDI-11-032: Symantec Intel Alert Originator Service iao.exe Remote Code Execution Vulnerability

2011-01-27 Thread ZDI Disclosures
ZDI-11-032: Symantec Intel Alert Originator Service iao.exe Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-032 January 27, 2011 -- CVE ID: CVE-2010-111 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Symantec -- Affected Products: Symant

[Full-disclosure] ZDI-11-031: Symantec AMS Intel Alert Handler Pin Number Parsing Remote Code Execution Vulnerability

2011-01-27 Thread ZDI Disclosures
ZDI-11-031: Symantec AMS Intel Alert Handler Pin Number Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-031 January 27, 2011 -- CVE ID: CVE-2010-111 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Symantec -- Affected Products: Sy

[Full-disclosure] ZDI-11-030: Symantec AMS Intel Alert Handler Modem String Parsing Remote Code Execution Vulnerability

2011-01-27 Thread ZDI Disclosures
ZDI-11-030: Symantec AMS Intel Alert Handler Modem String Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-030 January 27, 2011 -- CVE ID: CVE-2010-111 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Symantec -- Affected Products:

[Full-disclosure] ZDI-11-029: Symantec AMS Intel Alert Handler Service CreateProcess Remote Code Execution Vulnerability

2011-01-27 Thread ZDI Disclosures
ZDI-11-029: Symantec AMS Intel Alert Handler Service CreateProcess Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-029 January 27, 2011 -- CVE ID: CVE-2010-111 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Symantec -- Affected Products:

<    1   2   3   4   5   6   7   8   9   10   >