[Full-disclosure] ZDI-10-144: Apple Webkit Rendering Counter Remote Code Execution Vulnerability

2010-08-09 Thread ZDI Disclosures
ZDI-10-144: Apple Webkit Rendering Counter Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-144 August 9, 2010 -- CVE ID: CVE-2010-1784 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- Vulnerability

[Full-disclosure] ZDI-10-143: Novell Sentinel Log Manager Multiple Servlet Remote Code Execution Vulnerabilities

2010-08-09 Thread ZDI Disclosures
ZDI-10-143: Novell Sentinel Log Manager Multiple Servlet Remote Code Execution Vulnerabilities http://www.zerodayinitiative.com/advisories/ZDI-10-143 August 9, 2010 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Novell -- Affected Products: Novell Security Manager -- Vulnerabil

[Full-disclosure] TPTI-10-06: Novell iPrint Client Browser Plugin ExecuteRequest debug Parameter Remote Code Execution Vulnerability

2010-08-05 Thread ZDI Disclosures
TPTI-10-06: Novell iPrint Client Browser Plugin ExecuteRequest debug Parameter Remote Code Execution Vulnerability http://dvlabs.tippingpoint.com/advisory/TPTI-10-06 August 4, 2010 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Novell -- Affected Products: Novell iPrint -- Tipp

[Full-disclosure] TPTI-10-05: Novell iPrint Client Browser Plugin Remote File Deletion Vulnerability

2010-08-05 Thread ZDI Disclosures
TPTI-10-05: Novell iPrint Client Browser Plugin Remote File Deletion Vulnerability http://dvlabs.tippingpoint.com/advisory/TPTI-10-05 August 4, 2010 -- CVSS: 7.8, (AV:N/AC:L/Au:N/C:N/I:N/A:C) -- Affected Vendors: Novell -- Affected Products: Novell iPrint -- TippingPoint(TM) IPS Customer Prote

[Full-disclosure] ZDI-10-142: Apple Webkit SVG First-Letter Style Remote Code Execution Vulnerability

2010-08-05 Thread ZDI Disclosures
ZDI-10-142: Apple Webkit SVG First-Letter Style Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-142 August 5, 2010 -- CVE ID: CVE-2010-1785 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- Tipping

[Full-disclosure] ZDI-10-141: Apple Webkit SVG ForeignObject Rendering Layout Remote Code Execution Vulnerability

2010-08-05 Thread ZDI Disclosures
ZDI-10-141: Apple Webkit SVG ForeignObject Rendering Layout Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-141 August 5, 2010 -- CVE ID: CVE-2010-1786 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Apple -- Affected Products: Apple Safari

[Full-disclosure] ZDI-10-140: Novell iPrint Client Browser Plugin operation Parameter Remote Code Execution Vulnerability

2010-08-05 Thread ZDI Disclosures
ZDI-10-140: Novell iPrint Client Browser Plugin operation Parameter Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-140 August 5, 2010 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Novell -- Affected Products: Novell iPrint -- TippingPoin

[Full-disclosure] ZDI-10-139: Novell iPrint Client Browser Plugin Parameter Name Remote Code Execution

2010-08-05 Thread ZDI Disclosures
ZDI-10-139: Novell iPrint Client Browser Plugin Parameter Name Remote Code Execution http://www.zerodayinitiative.com/advisories/ZDI-10-139 August 5, 2010 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Novell -- Affected Products: Novell iPrint -- TippingPoint(TM) IPS Customer

[Full-disclosure] ZDI-10-138: Novell iPrint Server Queue Name Remote Code Execution Vulnerability

2010-08-05 Thread ZDI Disclosures
ZDI-10-138: Novell iPrint Server Queue Name Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-138 August 5, 2010 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Novell -- Affected Products: Novell iPrint -- TippingPoint(TM) IPS Customer Protect

[Full-disclosure] ZDI-10-137: Hewlett-Packard OpenView NNM webappmon.exe execvp_nc Remote Code Execution Vulnerability

2010-07-21 Thread ZDI Disclosures
ZDI-10-137: Hewlett-Packard OpenView NNM webappmon.exe execvp_nc Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-137 July 21, 2010 -- CVE ID: CVE-2010-2703 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Hewlett-Packard -- Affected Products

[Full-disclosure] ZDI-10-136: Novell Teaming ajaxUploadImageFile Remote Code Execution Vulnerability

2010-07-21 Thread ZDI Disclosures
ZDI-10-136: Novell Teaming ajaxUploadImageFile Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-136 July 21, 2010 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Novell -- Affected Products: Novell Access Manager -- TippingPoint(TM) IPS Cust

[Full-disclosure] ZDI-10-135: Novell Groupwise WebAccess Multiple Cross-Site Scripting Vulnerabilities

2010-07-20 Thread ZDI Disclosures
ZDI-10-135: Novell Groupwise WebAccess Multiple Cross-Site Scripting Vulnerabilities http://www.zerodayinitiative.com/advisories/ZDI-10-135 July 20, 2010 -- CVSS: 4.3, (AV:N/AC:M/Au:N/C:P/I:N/A:N) -- Affected Vendors: Novell -- Affected Products: Novell GroupWise WebAccess -- TippingPoint(TM)

[Full-disclosure] ZDI-10-134: Mozilla Firefox DOM Attribute Cloning Remote Code Execution Vulnerability

2010-07-20 Thread ZDI Disclosures
ZDI-10-134: Mozilla Firefox DOM Attribute Cloning Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-134 July 20, 2010 -- CVE ID: CVE-2010-1208 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Mozilla Firefox -- Affected Products: Mozilla Firef

[Full-disclosure] ZDI-10-133: Mozilla Firefox CSS font-face Remote Code Execution Vulnerability

2010-07-20 Thread ZDI Disclosures
ZDI-10-133: Mozilla Firefox CSS font-face Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-133 July 20, 2010 -- CVE ID: CVE-2010-2752 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Mozilla Firefox -- Affected Products: Mozilla Firefox 3.6.x

[Full-disclosure] ZDI-10-132: Mozilla Firefox Plugin Parameter EnsureCachedAttrParamArrays Remote Code Execution Vulnerability

2010-07-20 Thread ZDI Disclosures
ZDI-10-132: Mozilla Firefox Plugin Parameter EnsureCachedAttrParamArrays Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-132 July 20, 2010 -- CVE ID: CVE-2010-1214 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Mozilla Firefox -- Affected

[Full-disclosure] ZDI-10-131: Mozilla Firefox nsTreeSelection Dangling Pointer Remote Code Execution Vulnerability

2010-07-20 Thread ZDI Disclosures
ZDI-10-131: Mozilla Firefox nsTreeSelection Dangling Pointer Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-131 July 20, 2010 -- CVE ID: CVE-2010-2753 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Mozilla Firefox -- Affected Products: Mo

[Full-disclosure] ZDI-10-130: Mozilla Firefox NodeIterator Remote Code Execution Vulnerability

2010-07-20 Thread ZDI Disclosures
ZDI-10-130: Mozilla Firefox NodeIterator Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-130 July 20, 2010 -- CVE ID: CVE-2010-1209 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Mozilla Firefox -- Affected Products: Mozilla Firefox 3.6.x

[Full-disclosure] ZDI-10-129: Novell Netware Groupwise Internet Gateway Remote Code Execution Vulnerability

2010-07-16 Thread ZDI Disclosures
ZDI-10-129: Novell Netware Groupwise Internet Gateway Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-129 July 16, 2010 -- CVSS: 9, (AV:N/AC:L/Au:S/C:C/I:C/A:C) -- Affected Vendors: Novell -- Affected Products: Novell Netware -- TippingPoint(TM) IPS Custo

[Full-disclosure] ZDI-10-128: Ipswitch Imail Server Queuemgr Format String Remote Code Execution Vulnerability

2010-07-15 Thread ZDI Disclosures
ZDI-10-128: Ipswitch Imail Server Queuemgr Format String Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-128 July 15, 2010 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Ipswitch -- Affected Products: Ipswitch IMail -- TippingPoint(TM) IPS

[Full-disclosure] ZDI-10-127: Ipswitch Imail Server Mailing List Remote Code Execution Vulnerability

2010-07-15 Thread ZDI Disclosures
ZDI-10-127: Ipswitch Imail Server Mailing List Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-127 July 15, 2010 -- CVSS: 9, (AV:N/AC:L/Au:S/C:C/I:C/A:C) -- Affected Vendors: Ipswitch -- Affected Products: Ipswitch IMail -- TippingPoint(TM) IPS Customer P

[Full-disclosure] ZDI-10-126: Ipswitch Imail Server List Mailer Reply-To Address Remote Code Execution Vulnerability

2010-07-15 Thread ZDI Disclosures
ZDI-10-126: Ipswitch Imail Server List Mailer Reply-To Address Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-126 July 15, 2010 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Ipswitch -- Affected Products: Ipswitch IMail -- TippingPoint(T

[Full-disclosure] ZDI-10-125: IBM SolidDB solid.exe Handshake Request Username Field Remote Code Execution Vulnerability

2010-07-13 Thread ZDI Disclosures
ZDI-10-125: IBM SolidDB solid.exe Handshake Request Username Field Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-125 July 13, 2010 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: IBM -- Affected Products: IBM solidDB -- TippingPoint(TM) I

[Full-disclosure] ZDI-10-124: Oracle Secure Backup Web Interface Various Post-Auth Command Injection Remote Code Execution Vulnerabilities

2010-07-13 Thread ZDI Disclosures
ZDI-10-124: Oracle Secure Backup Web Interface Various Post-Auth Command Injection Remote Code Execution Vulnerabilities http://www.zerodayinitiative.com/advisories/ZDI-10-124 July 13, 2010 -- CVSS: 9, (AV:N/AC:L/Au:S/C:C/I:C/A:C) -- Affected Vendors: Oracle -- Affected Products: Oracle Secure

[Full-disclosure] ZDI-10-123: Oracle Secure Backup Administration Authentication Bypass Vulnerability

2010-07-13 Thread ZDI Disclosures
ZDI-10-123: Oracle Secure Backup Administration Authentication Bypass Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-123 July 13, 2010 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Oracle -- Affected Products: Oracle Secure Backup -- Vulnerability Details: Th

[Full-disclosure] ZDI-10-122: Oracle Secure Backup Administration Command Injection Remote Code Execution Vulnerability

2010-07-13 Thread ZDI Disclosures
ZDI-10-122: Oracle Secure Backup Administration Command Injection Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-122 July 13, 2010 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Oracle -- Affected Products: Oracle Secure Backup -- Vulnera

[Full-disclosure] ZDI-10-121: Command Injection Remote Code Execution Vulnerability

2010-07-13 Thread ZDI Disclosures
ZDI-10-121: Command Injection Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-121 July 13, 2010 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Oracle -- Affected Products: Oracle Secure Backup -- Vulnerability Details: This vulnerability al

[Full-disclosure] ZDI-10-120: Oracle Secure Backup Administration objectname Command Injection Remote Code Execution Vulnerability

2010-07-13 Thread ZDI Disclosures
ZDI-10-120: Oracle Secure Backup Administration objectname Command Injection Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-120 July 13, 2010 -- CVSS: 9, (AV:N/AC:L/Au:S/C:C/I:C/A:C) -- Affected Vendors: Oracle -- Affected Products: Oracle Secure Backup

[Full-disclosure] ZDI-10-119: Oracle Secure Backup Administration $other Variable Command Injection Remote Code Execution Vulnerability

2010-07-13 Thread ZDI Disclosures
ZDI-10-119: Oracle Secure Backup Administration $other Variable Command Injection Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-119 July 13, 2010 -- CVSS: 9, (AV:N/AC:L/Au:S/C:C/I:C/A:C) -- Affected Vendors: Oracle -- Affected Products: Oracle Secure Bac

[Full-disclosure] ZDI-10-118: Oracle Secure Backup Administration uname Authentication Bypass Vulnerability

2010-07-13 Thread ZDI Disclosures
ZDI-10-118: Oracle Secure Backup Administration uname Authentication Bypass Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-118 July 13, 2010 -- CVSS: 9.7, (AV:N/AC:L/Au:N/C:C/I:C/A:P) -- Affected Vendors: Oracle -- Affected Products: Oracle Secure Backup -- Vulnerability Deta

[Full-disclosure] TPTI-10-04: Oracle Secure Backup Scheduler Service Remote Code Execution Vulnerability

2010-07-13 Thread ZDI Disclosures
TPTI-10-04: Oracle Secure Backup Scheduler Service Remote Code Execution Vulnerability http://dvlabs.tippingpoint.com/advisory/TPTI-10-04 -- CVE ID: CVE-2010-0898 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Oracle -- Affected Products: Oracle Secure Backup -- TippingPoint(T

[Full-disclosure] ZDI-10-117: Microsoft Office Access AccWizObjects ActiveX Control Uninitialized Imports Remote Code Execution Vulnerability

2010-07-13 Thread ZDI Disclosures
ZDI-10-117: Microsoft Office Access AccWizObjects ActiveX Control Uninitialized Imports Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-117 July 13, 2010 -- CVE ID: CVE-2010-0814 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Microsoft --

[Full-disclosure] ZDI-10-116: Adobe Reader CLOD Progressive Mesh Continuation Resolution Remote Code Execution Vulnerability

2010-06-30 Thread ZDI Disclosures
ZDI-10-116: Adobe Reader CLOD Progressive Mesh Continuation Resolution Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-116 June 30, 2010 -- CVE ID: CVE-2010-2202 -- Affected Vendors: Adobe -- Affected Products: Adobe Reader Adobe Acrobat -- Vulnerability

[Full-disclosure] ZDI-10-115: Adobe Flash Player AVM newFrameState Integer Overfow Remote Code Execution Vulnerability

2010-06-25 Thread ZDI Disclosures
ZDI-10-115: Adobe Flash Player AVM newFrameState Integer Overfow Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-115 June 25, 2010 -- CVE ID: CVE-2010-2160 -- Affected Vendors: Adobe -- Affected Products: Adobe Flash Player -- TippingPoint(TM) IPS Custome

[Full-disclosure] ZDI-10-114: Adobe Flash Player AVM2 getouterscope Opcode Remote Code Execution Vulnerability

2010-06-25 Thread ZDI Disclosures
ZDI-10-114: Adobe Flash Player AVM2 getouterscope Opcode Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-114 June 25, 2010 -- CVE ID: CVE-2010-2160 -- Affected Vendors: Adobe -- Affected Products: Adobe Flash Player -- TippingPoint(TM) IPS Customer Protec

[Full-disclosure] ZDI-10-113: Mozilla Firefox XSLT Sort Remote Code Execution Vulnerability

2010-06-23 Thread ZDI Disclosures
ZDI-10-113: Mozilla Firefox XSLT Sort Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-113 June 23, 2010 -- CVE ID: CVE-2010-1199 -- Affected Vendors: Mozilla Firefox -- Affected Products: Mozilla Firefox 3.6.x -- TippingPoint(TM) IPS Customer Protection: T

[Full-disclosure] ZDI-10-112: Novell Access Manager Arbitrary File Upload Remote Code Execution Vulnerability

2010-06-21 Thread ZDI Disclosures
ZDI-10-112: Novell Access Manager Arbitrary File Upload Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-112 June 21, 2010 -- CVE ID: CVE-2010-0284 -- Affected Vendors: Novell -- Affected Products: Novell Access Manager -- Vulnerability Details: This vulne

[Full-disclosure] ZDI-10-111: Adobe Flash Player LocalConnection Memory Corruption Remote Code Execution Vulnerability

2010-06-21 Thread ZDI Disclosures
ZDI-10-111: Adobe Flash Player LocalConnection Memory Corruption Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-111 June 21, 2010 -- CVE ID: CVE-2010-2188 -- Affected Vendors: Adobe -- Affected Products: Adobe Flash Player -- TippingPoint(TM) IPS Custome

[Full-disclosure] ZDI-10-110: Adobe Flash Player Multiple Tag JPEG Parsing Remote Code Execution Vulnerability

2010-06-16 Thread ZDI Disclosures
ZDI-10-110: Adobe Flash Player Multiple Tag JPEG Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-110 June 16, 2010 -- CVE ID: CVE-2010-2171 -- Affected Vendors: Adobe -- Affected Products: Adobe Flash Player -- Vulnerability Details: This vulnerab

[Full-disclosure] ZDI-10-109: Adobe Flash Player Multiple Atom MP4 Parsing Remote Code Execution Vulnerability

2010-06-16 Thread ZDI Disclosures
ZDI-10-109: Adobe Flash Player Multiple Atom MP4 Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-109 June 16, 2010 -- CVE ID: CVE-2010-2162 -- Affected Vendors: Adobe -- Affected Products: Adobe Flash Player -- TippingPoint(TM) IPS Customer Protec

[Full-disclosure] ZDI-10-108: HP OpenView NNM ovwebsnmpsrv.exe Command Line Argument Remote Code Execution Vulnerability

2010-06-16 Thread ZDI Disclosures
ZDI-10-108: HP OpenView NNM ovwebsnmpsrv.exe Command Line Argument Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-108 June 16, 2010 -- CVE ID: CVE-2010-1964 -- Affected Vendors: Hewlett-Packard -- Affected Products: Hewlett-Packard OpenView Network Node M

[Full-disclosure] ZDI-10-107: Multiple Sourcefire Products Static Web SSL Keys Vulnerability

2010-06-10 Thread ZDI Disclosures
ZDI-10-107: Multiple Sourcefire Products Static Web SSL Keys Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-107 June 10, 2010 -- Affected Vendors: Sourcefire -- Affected Products: Sourcefire 3D Sensor 1000 Sourcefire 3D Sensor 2000 Sourcefire 3D Sensor 9900 Sourcefire Defense Ce

[Full-disclosure] TPTI-10-03: Sophos Anti-Virus SAVOnAccessFilter Local Privilege Escalation Vulnerability

2010-06-09 Thread ZDI Disclosures
TPTI-10-03: Sophos Anti-Virus SAVOnAccessFilter Local Privilege Escalation Vulnerability http://dvlabs.tippingpoint.com/advisory/TPTI-10-03 June 9, 2010 -- Affected Vendors: Sophos -- Affected Products: Sophos Sophos Anti-Virus -- Vulnerability Details: This vulnerability allows local attackers

[Full-disclosure] ZDI-10-106: Hewlett-Packard OpenView NNM ovutil.dll getProxiedStorageAddress Remote Code Execution Vulnerability

2010-06-08 Thread ZDI Disclosures
ZDI-10-106: Hewlett-Packard OpenView NNM ovutil.dll getProxiedStorageAddress Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-106 June 8, 2010 -- CVE ID: CVE-2010-1961 -- Affected Vendors: Hewlett-Packard -- Affected Products: Hewlett-Packard OpenView Netwo

[Full-disclosure] ZDI-10-105: Hewlett-Packard OpenView NNM ovwebsnmpsrv.exe Bad Option Remote Code Execution Vulnerability

2010-06-08 Thread ZDI Disclosures
ZDI-10-105: Hewlett-Packard OpenView NNM ovwebsnmpsrv.exe Bad Option Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-105 June 8, 2010 -- CVE ID: CVE-2010-1960 -- Affected Vendors: Hewlett-Packard -- Affected Products: Hewlett-Packard OpenView Network Node

[Full-disclosure] ZDI-10-104: Microsoft Office Excel SxView Record Parsing Remote Code Execution Vulnerability

2010-06-08 Thread ZDI Disclosures
ZDI-10-104: Microsoft Office Excel SxView Record Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-104 June 8, 2010 -- CVE ID: CVE-2010-0821 -- Affected Vendors: Microsoft -- Affected Products: Microsoft Office Excel -- TippingPoint(TM) IPS Customer

[Full-disclosure] ZDI-10-103: Microsoft Office Excel DBQueryExt Record Unspecified ADO Object Remote Code Execution Vulnerability

2010-06-08 Thread ZDI Disclosures
ZDI-10-103: Microsoft Office Excel DBQueryExt Record Unspecified ADO Object Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-103 June 8, 2010 -- CVE ID: CVE-2010-1253 -- Affected Vendors: Microsoft -- Affected Products: Microsoft Office Excel -- TippingPoi

[Full-disclosure] ZDI-10-102: Microsoft Internet Explorer Stylesheet Array Removal Remote Code Execution Vulnerability

2010-06-08 Thread ZDI Disclosures
ZDI-10-102: Microsoft Internet Explorer Stylesheet Array Removal Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-102 June 8, 2010 -- CVE ID: CVE-2010-1262 -- Affected Vendors: Microsoft -- Affected Products: Microsoft Internet Explorer 8 -- TippingPoint(T

[Full-disclosure] ZDI-10-101: Apple Webkit SVG RadialGradiant Run-in Remote Code Execution Vulnerability

2010-06-08 Thread ZDI Disclosures
ZDI-10-101: Apple Webkit SVG RadialGradiant Run-in Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-101 June 8, 2010 -- CVE ID: CVE-2010-1749 -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- TippingPoint(TM) IPS Customer Protection: Tipping

[Full-disclosure] ZDI-10-100: Apple Webkit ConditionEventListener Remote Code Execution Vulnerability

2010-06-08 Thread ZDI Disclosures
ZDI-10-100: Apple Webkit ConditionEventListener Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-100 June 8, 2010 -- CVE ID: CVE-2010-1402 -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- TippingPoint(TM) IPS Customer Protection: TippingPoi

[Full-disclosure] ZDI-10-099: Apple Webkit ProcessInstruction Target Error Message Insertion Remote Code Execution Vulnerability

2010-06-08 Thread ZDI Disclosures
ZDI-10-099: Apple Webkit ProcessInstruction Target Error Message Insertion Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-099 June 8, 2010 -- CVE ID: CVE-2010-1403 -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- TippingPoint(TM) IPS Cust

[Full-disclosure] ZDI-10-098: Apple Webkit First-Letter Pseudo-Element Style Remote Code Execution Vulnerability

2010-06-08 Thread ZDI Disclosures
ZDI-10-098: Apple Webkit First-Letter Pseudo-Element Style Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-098 June 8, 2010 -- CVE ID: CVE-2010-1401 -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- TippingPoint(TM) IPS Customer Protection:

[Full-disclosure] ZDI-10-097: Apple Webkit ContentEditable moveParagraphs Uninitialized Element Remote Code Execution Vulnerability

2010-06-08 Thread ZDI Disclosures
ZDI-10-097: Apple Webkit ContentEditable moveParagraphs Uninitialized Element Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-097 June 8, 2010 -- CVE ID: CVE-2010-1398 -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- TippingPoint(TM) IPS C

[Full-disclosure] ZDI-10-096: Apple Webkit Recursive Use Element Remote Code Execution Vulnerability

2010-06-08 Thread ZDI Disclosures
ZDI-10-096: Apple Webkit Recursive Use Element Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-096 June 8, 2010 -- CVE ID: CVE-2010-1404 -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- TippingPoint(TM) IPS Customer Protection: TippingPoin

[Full-disclosure] ZDI-10-095: Apple Webkit DOCUMENT_POSITION_DISCONNECTED Attribute Remote Code Execution Vulnerability

2010-06-08 Thread ZDI Disclosures
ZDI-10-095: Apple Webkit DOCUMENT_POSITION_DISCONNECTED Attribute Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-095 June 8, 2010 -- CVE ID: CVE-2010-1397 -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- TippingPoint(TM) IPS Customer Prot

[Full-disclosure] ZDI-10-094: Apple Webkit SelectionController via Marquee Event Remote Code Execution Vulnerability

2010-06-08 Thread ZDI Disclosures
ZDI-10-094: Apple Webkit SelectionController via Marquee Event Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-094 June 8, 2010 -- CVE ID: CVE-2010-1399 -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- TippingPoint(TM) IPS Customer Protect

[Full-disclosure] ZDI-10-093: Apple Webkit CSS Charset Text Transformation Remote Code Execution Vulnerability

2010-06-08 Thread ZDI Disclosures
ZDI-10-093: Apple Webkit CSS Charset Text Transformation Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-093 June 8, 2010 -- CVE ID: CVE-2010-1770 -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- TippingPoint(TM) IPS Customer Protection: T

[Full-disclosure] ZDI-10-092: Apple Webkit Option Element ContentEditable Remote Code Execution Vulnerability

2010-06-08 Thread ZDI Disclosures
ZDI-10-092: Apple Webkit Option Element ContentEditable Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-092 June 8, 2010 -- CVE ID: CVE-2010-1396 -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- TippingPoint(TM) IPS Customer Protection: Ti

[Full-disclosure] ZDI-10-091: Apple Webkit Attribute Child Removal Remote Code Execution Vulnerability

2010-06-08 Thread ZDI Disclosures
ZDI-10-091: Apple Webkit Attribute Child Removal Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-091 June 8, 2010 -- CVE ID: CVE-2010-1119 -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- TippingPoint(TM) IPS Customer Protection: TippingPo

[Full-disclosure] ZDI-10-090: Novell ZENworks Configuration Management Preboot Service Remote Code Execution Vulnerability

2010-06-01 Thread ZDI Disclosures
ZDI-10-090: Novell ZENworks Configuration Management Preboot Service Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-090 June 1, 2010 -- Affected Vendors: Novell -- Affected Products: Novell Zenworks -- TippingPoint(TM) IPS Customer Protection: TippingPoin

[Full-disclosure] ZDI-10-089: Adobe Shockwave Director PAMI Chunk Remote Code Execution Vulnerability

2010-05-11 Thread ZDI Disclosures
ZDI-10-089: Adobe Shockwave Director PAMI Chunk Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-089 May 11, 2010 -- CVE ID: CVE-2010-1292 -- Affected Vendors: Adobe -- Affected Products: Adobe Shockwave Player -- TippingPoint(TM) IPS Customer Protection:

[Full-disclosure] ZDI-10-088: Adobe Shockwave Player 3D Parsing Memory Corruption Vulnerability

2010-05-11 Thread ZDI Disclosures
ZDI-10-088: Adobe Shockwave Player 3D Parsing Memory Corruption Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-088 May 11, 2010 -- CVE ID: CVE-2010-1283 -- Affected Vendors: Adobe -- Affected Products: Adobe Shockwave Player -- TippingPoint(TM) IPS Customer Protection: Tipping

[Full-disclosure] ZDI-10-087: Adobe Shockwave Invalid Offset Memory Corruption Remote Code Execution Vulnerability

2010-05-11 Thread ZDI Disclosures
ZDI-10-087: Adobe Shockwave Invalid Offset Memory Corruption Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-087 May 11, 2010 -- CVE ID: CVE-2010-1281 -- Affected Vendors: Adobe -- Affected Products: Adobe Shockwave Player -- Vulnerability Details: This v

[Full-disclosure] ZDI-10-086: HP OpenView NNM getnnmdata.exe CGI Invalid Hostname Remote Code Execution Vulnerability

2010-05-11 Thread ZDI Disclosures
ZDI-10-086: HP OpenView NNM getnnmdata.exe CGI Invalid Hostname Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-086 May 11, 2010 -- CVE ID: CVE-2010-1555 -- Affected Vendors: Hewlett-Packard -- Affected Products: Hewlett-Packard OpenView Network Node Manag

[Full-disclosure] ZDI-10-085: HP OpenView NNM getnnmdata.exe CGI Invalid ICount Remote Code Execution Vulnerability

2010-05-11 Thread ZDI Disclosures
ZDI-10-085: HP OpenView NNM getnnmdata.exe CGI Invalid ICount Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-085 May 11, 2010 -- CVE ID: CVE-2010-1554 -- Affected Vendors: Hewlett-Packard -- Affected Products: Hewlett-Packard OpenView Network Node Manager

[Full-disclosure] ZDI-10-084: HP OpenView NNM getnnmdata.exe CGI Invalid MaxAge Remote Code Execution Vulnerability

2010-05-11 Thread ZDI Disclosures
ZDI-10-084: HP OpenView NNM getnnmdata.exe CGI Invalid MaxAge Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-084 May 11, 2010 -- CVE ID: CVE-2010-1553 -- Affected Vendors: Hewlett-Packard -- Affected Products: Hewlett-Packard OpenView Network Node Manager

[Full-disclosure] ZDI-10-083: HP OpenView NNM snmpviewer.exe CGI Multiple Variable Remote Code Execution Vulnerability

2010-05-11 Thread ZDI Disclosures
ZDI-10-083: HP OpenView NNM snmpviewer.exe CGI Multiple Variable Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-083 May 11, 2010 -- CVE ID: CVE-2010-1552 -- Affected Vendors: Hewlett-Packard -- Affected Products: Hewlett-Packard OpenView Network Node Mana

[Full-disclosure] ZDI-10-082: HP OpenView NNM netmon sel CGI Variable Remote Code Execution Vulnerability

2010-05-11 Thread ZDI Disclosures
ZDI-10-082: HP OpenView NNM netmon sel CGI Variable Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-082 May 11, 2010 -- CVE ID: CVE-2010-1551 -- Affected Vendors: Hewlett-Packard -- Affected Products: Hewlett-Packard OpenView Network Node Manager -- Tippi

[Full-disclosure] ZDI-10-081: HP OpenView NNM ovet_demandpoll sel CGI Variable Format String Remote Code Execution Vulnerability

2010-05-11 Thread ZDI Disclosures
ZDI-10-081: HP OpenView NNM ovet_demandpoll sel CGI Variable Format String Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-081 May 11, 2010 -- CVE ID: CVE-2010-1550 -- Affected Vendors: Hewlett-Packard -- Affected Products: Hewlett-Packard OpenView Network

[Full-disclosure] ZDI-10-080: HP Mercury LoadRunner Agent Trusted Input Remote Code Execution Vulnerability

2010-05-06 Thread ZDI Disclosures
ZDI-10-080: HP Mercury LoadRunner Agent Trusted Input Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-080 May 6, 2010 -- CVE ID: CVE-2010-1549 -- Affected Vendors: Hewlett-Packard -- Affected Products: Hewlett-Packard LoadRunner -- TippingPoint(TM) IPS Cu

[Full-disclosure] ZDI-10-079: Realnetworks Helix Server NTLM Authentication Invalid Base64 Remote Code Execution Vulnerability

2010-04-28 Thread ZDI Disclosures
ZDI-10-079: Realnetworks Helix Server NTLM Authentication Invalid Base64 Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-079 April 28, 2010 -- CVE ID: CVE-2010-1317 -- Affected Vendors: RealNetworks -- Affected Products: RealNetworks Helix Server -- Tippi

[Full-disclosure] ZDI-10-078: Novell ZENworks Configuration Management UploadServlet Remote Code Execution Vulnerability

2010-04-23 Thread ZDI Disclosures
ZDI-10-078: Novell ZENworks Configuration Management UploadServlet Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-078 April 23, 2010 -- Affected Vendors: Novell -- Affected Products: Novell Zenworks -- TippingPoint(TM) IPS Customer Protection: TippingPoin

[Full-disclosure] ZDI-10-077: Adobe Download Manager Atlcom.get_atlcom ActiveX Control Remote Code Execution Vulnerability

2010-04-21 Thread ZDI Disclosures
ZDI-10-077: Adobe Download Manager Atlcom.get_atlcom ActiveX Control Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-077 April 21, 2010 -- CVE ID: CVE-2010-1278 -- Affected Vendors: Adobe -- Affected Products: Adobe Download Manager -- TippingPoint(TM) IP

[Full-disclosure] ZDI-10-076: Apple Preview libFontParser SpecialEncoding Remote Code Execution Vulnerability

2010-04-14 Thread ZDI Disclosures
ZDI-10-076: Apple Preview libFontParser SpecialEncoding Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-076 April 14, 2010 -- CVE ID: CVE-2010-1120 -- Affected Vendors: Apple -- Affected Products: Apple Preview -- TippingPoint(TM) IPS Customer Protection:

[Full-disclosure] ZDI-10-072: Cisco Secure Desktop CSDWebInstaller ActiveX Control Remote Code Execution Vulnerability

2010-04-14 Thread ZDI Disclosures
ZDI-10-072: Cisco Secure Desktop CSDWebInstaller ActiveX Control Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-072 April 14, 2010 -- Affected Vendors: Cisco -- Affected Products: Cisco Secure Desktop -- TippingPoint(TM) IPS Customer Protection: TippingPo

[Full-disclosure] ZDI-10-075: Sun Microsystems Directory Server Enterprise DSML UTF-8 Denial of Service Vulnerability

2010-04-13 Thread ZDI Disclosures
ZDI-10-075: Sun Microsystems Directory Server Enterprise DSML UTF-8 Denial of Service Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-075 April 13, 2010 -- CVE ID: CVE-2010-0897 -- Affected Vendors: Sun Microsystems -- Affected Products: Sun Microsystems Directory Server -- Ti

[Full-disclosure] ZDI-10-074: Sun Microsystems Directory Server Enterprise ASN.1 Parsing Remote Code Execution Vulnerability

2010-04-13 Thread ZDI Disclosures
ZDI-10-074: Sun Microsystems Directory Server Enterprise ASN.1 Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-074 April 13, 2010 -- CVE ID: CVE-2010-0897 -- Affected Vendors: Sun Microsystems -- Affected Products: Sun Microsystems Directory Server

[Full-disclosure] ZDI-10-073: Sun Microsystems Directory Server DSML-over-HTTP Username Search Denial of Service Vulnerability

2010-04-13 Thread ZDI Disclosures
ZDI-10-073: Sun Microsystems Directory Server DSML-over-HTTP Username Search Denial of Service Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-073 April 13, 2010 -- CVE ID: CVE-2010-0897 -- Affected Vendors: Sun Microsystems -- Affected Products: Sun Microsystems Directory Serv

[Full-disclosure] ZDI-10-071: Adobe Reader TrueType Font Handling Remote Code Execution Vulnerability

2010-04-13 Thread ZDI Disclosures
ZDI-10-071: Adobe Reader TrueType Font Handling Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-071 April 13, 2010 -- CVE ID: CVE-2010-0195 -- Affected Vendors: Adobe -- Affected Products: Adobe Reader -- TippingPoint(TM) IPS Customer Protection: TippingP

[Full-disclosure] ZDI-10-070: Microsoft Windows Media Player Codec Retrieval Dangling Pointer Remote Code Execution Vulnerability

2010-04-13 Thread ZDI Disclosures
ZDI-10-070: Microsoft Windows Media Player Codec Retrieval Dangling Pointer Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-070 April 13, 2010 -- CVE ID: CVE-2010-0268 -- Affected Vendors: Microsoft -- Affected Products: Microsoft Windows Media Player 9 -

[Full-disclosure] ZDI-10-069: Microsoft Office Publisher File Conversion TextBox Processing Buffer Overflow Vulnerability

2010-04-13 Thread ZDI Disclosures
ZDI-10-069: Microsoft Office Publisher File Conversion TextBox Processing Buffer Overflow Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-069 April 13, 2010 -- CVE ID: CVE-2010-0479 -- Affected Vendors: Microsoft -- Affected Products: Microsoft Office Publisher -- TippingPoint

[Full-disclosure] ZDI-10-068: Apple QuickTime H.263 Array Index Parsing Remote Code Execution Vulnerability

2010-04-09 Thread ZDI Disclosures
ZDI-10-068: Apple QuickTime H.263 Array Index Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-068 April 9, 2010 -- CVE ID: CVE-2010-0062 -- Affected Vendors: Apple -- Affected Products: Apple Quicktime -- TippingPoint(TM) IPS Customer Protection:

[Full-disclosure] ZDI-10-067: Apple QuickTime Pict BkPixPat Remote Code Execution Vulnerability

2010-04-06 Thread ZDI Disclosures
ZDI-10-067: Apple QuickTime Pict BkPixPat Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-067 April 6, 2010 -- CVE ID: CVE-2010-0529 -- Affected Vendors: Apple -- Affected Products: Apple Quicktime -- TippingPoint(TM) IPS Customer Protection: TippingPoint

[Full-disclosure] ZDI-10-066: CA XOsoft Control Service entry_point.aspx Remote Code Execution Vulnerability

2010-04-06 Thread ZDI Disclosures
ZDI-10-066: CA XOsoft Control Service entry_point.aspx Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-066 April 6, 2010 -- CVE ID: CVE-2010-1223 -- Affected Vendors: Computer Associates -- Affected Products: Computer Associates XOsoft High Availability C

[Full-disclosure] ZDI-10-065: CA XOsoft xosoapapi.asmx Multiple Remote Code Execution Vulnerabilities

2010-04-06 Thread ZDI Disclosures
ZDI-10-065: CA XOsoft xosoapapi.asmx Multiple Remote Code Execution Vulnerabilities http://www.zerodayinitiative.com/advisories/ZDI-10-065 April 6, 2010 -- CVE ID: CVE-2010-1223 -- Affected Vendors: Computer Associates -- Affected Products: Computer Associates XOsoft High Availability Computer

[Full-disclosure] ZDI-10-063: Mozilla Firefox Cross Document DOM Node Moving Code Execution Vulnerability

2010-04-05 Thread ZDI Disclosures
ZDI-10-063: Mozilla Firefox Cross Document DOM Node Moving Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-063 April 5, 2010 -- CVE ID: CVE-2010-1121 -- Affected Vendors: Mozilla Firefox -- Affected Products: Mozilla Firefox 3.6.x -- TippingPoint(TM) IPS Custome

[Full-disclosure] ZDI-10-062: Novell Netware NWFTPD RMD/RNFR/DELE Argument Parsing Remote Code Execution Vulnerabilities

2010-04-05 Thread ZDI Disclosures
ZDI-10-062: Novell Netware NWFTPD RMD/RNFR/DELE Argument Parsing Remote Code Execution Vulnerabilities http://www.zerodayinitiative.com/advisories/ZDI-10-062 April 5, 2010 -- CVE ID: CVE-2010-0625 -- Affected Vendors: Novell -- Affected Products: Novell Netware -- TippingPoint(TM) IPS Customer

[Full-disclosure] ZDI-10-061: Sun Java Runtime CMM readMabCurveData Remote Code Execution Vulnerability

2010-04-05 Thread ZDI Disclosures
ZDI-10-061: Sun Java Runtime CMM readMabCurveData Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-061 April 5, 2010 -- CVE ID: CVE-2010-0838 -- Affected Vendors: Sun Microsystems -- Affected Products: Sun Microsystems Java Runtime -- Vulnerability Details

[Full-disclosure] ZDI-10-060: Sun Java Runtime Environment MixerSequencer Invalid Array Index Remote Code Execution Vulnerability

2010-04-05 Thread ZDI Disclosures
ZDI-10-060: Sun Java Runtime Environment MixerSequencer Invalid Array Index Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-060 April 5, 2010 -- CVE ID: CVE-2010-0842 -- Affected Vendors: Sun Microsystems -- Affected Products: Sun Microsystems Java Runtime

[Full-disclosure] ZDI-10-059: Sun Java Runtime Environment JPEGImageEncoderImpl Remote Code Execution Vulnerability

2010-04-05 Thread ZDI Disclosures
ZDI-10-059: Sun Java Runtime Environment JPEGImageEncoderImpl Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-059 April 5, 2010 -- CVE ID: CVE-2010-0846 -- Affected Vendors: Sun Microsystems -- Affected Products: Sun Microsystems Java Runtime -- TippingPo

[Full-disclosure] ZDI-10-058: Apple Mac OS X ImageIO Framework JPEG2000 Remote Code Execution Vulnerability

2010-04-05 Thread ZDI Disclosures
ZDI-10-058: Apple Mac OS X ImageIO Framework JPEG2000 Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-058 April 5, 2010 -- CVE ID: CVE-2010-0505 -- Affected Vendors: Apple -- Affected Products: Apple OS X -- TippingPoint(TM) IPS Customer Protection: Tippi

[Full-disclosure] ZDI-10-057: Sun Java Runtime Environment JPEGImageDecoderImpl Remote Code Execution Vulnerability

2010-04-05 Thread ZDI Disclosures
ZDI-10-057: Sun Java Runtime Environment JPEGImageDecoderImpl Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-057 April 5, 2010 -- CVE ID: CVE-2010-0849 -- Affected Vendors: Sun Microsystems -- Affected Products: Sun Microsystems Java Runtime -- Vulnerabi

[Full-disclosure] ZDI-10-056: Sun Java Runtime Environment Trusted Methods Chaining Remote Code Execution Vulnerability

2010-04-05 Thread ZDI Disclosures
ZDI-10-056: Sun Java Runtime Environment Trusted Methods Chaining Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-056 April 5, 2010 -- CVE ID: CVE-2010-0840 -- Affected Vendors: Sun Microsystems -- Affected Products: Sun Microsystems Java Runtime -- Vulne

[Full-disclosure] ZDI-10-055: Sun Java Runtime Environment Mutable InetAddress Socket Policy Violation Vulnerability

2010-04-05 Thread ZDI Disclosures
ZDI-10-055: Sun Java Runtime Environment Mutable InetAddress Socket Policy Violation Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-055 April 5, 2010 -- CVE ID: CVE-2010-0095 -- Affected Vendors: Sun Microsystems -- Affected Products: Sun Microsystems Java Runtime -- Vulnerab

[Full-disclosure] ZDI-10-054: Sun Java Runtime Environment JPEGImageReader stepX Remote Code Execution Vulnerability

2010-04-05 Thread ZDI Disclosures
ZDI-10-054: Sun Java Runtime Environment JPEGImageReader stepX Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-054 April 5, 2010 -- CVE ID: CVE-2010-0841 -- Affected Vendors: Sun Microsystems -- Affected Products: Sun Microsystems Java Runtime -- TippingP

[Full-disclosure] ZDI-10-053: Sun Java Runtime Environment MIDI File metaEvent Remote Code Execution Vulnerability

2010-04-05 Thread ZDI Disclosures
ZDI-10-053: Sun Java Runtime Environment MIDI File metaEvent Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-053 April 5, 2010 -- CVE ID: CVE-2010-0844 -- Affected Vendors: Sun Microsystems -- Affected Products: Sun Microsystems Java Runtime -- TippingPoi

[Full-disclosure] ZDI-10-052: Sun Java Runtime Environment XNewPtr Remote Code Execution Vulnerability

2010-04-05 Thread ZDI Disclosures
ZDI-10-052: Sun Java Runtime Environment XNewPtr Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-052 April 5, 2010 -- CVE ID: CVE-2010-0843 -- Affected Vendors: Sun Microsystems -- Affected Products: Sun Microsystems Java Runtime -- TippingPoint(TM) IPS C

[Full-disclosure] ZDI-10-051: Sun Java Runtime RMIConnectionImpl Privileged Context Remote Code Execution Vulnerability

2010-04-05 Thread ZDI Disclosures
ZDI-10-051: Sun Java Runtime RMIConnectionImpl Privileged Context Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-051 April 5, 2010 -- CVE ID: CVE-2010-0094 -- Affected Vendors: Sun Microsystems -- Affected Products: Sun Microsystems Java Runtime -- Tippi

[Full-disclosure] ZDI-10-050: Mozilla Firefox nsTreeSelection EventListener Remote Code Execution Vulnerability

2010-04-02 Thread ZDI Disclosures
ZDI-10-050: Mozilla Firefox nsTreeSelection EventListener Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-050 April 2, 2010 -- CVE ID: CVE-2010-0175 -- Affected Vendors: Mozilla Firefox -- Affected Products: Mozilla Firefox 3.5.x -- Vulnerability Details

[Full-disclosure] ZDI-10-049: Mozilla Firefox PluginArray nsMimeType Dangling Pointer Remote Code Execution Vulnerability

2010-04-02 Thread ZDI Disclosures
ZDI-10-049: Mozilla Firefox PluginArray nsMimeType Dangling Pointer Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-049 April 2, 2010 -- CVE ID: CVE-2010-0177 -- Affected Vendors: Mozilla Firefox -- Affected Products: Mozilla Firefox 3.5.x -- Vulnerabili

[Full-disclosure] ZDI-10-048: Mozilla Firefox nsTreeContentView Dangling Pointer Remote Code Execution Vulnerability

2010-04-02 Thread ZDI Disclosures
ZDI-10-048: Mozilla Firefox nsTreeContentView Dangling Pointer Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-048 April 2, 2010 -- CVE ID: CVE-2010-0176 -- Affected Vendors: Mozilla Firefox -- Affected Products: Mozilla Firefox 3.5.x -- Vulnerability De

<    3   4   5   6   7   8   9   10   11   12   >