New User, Welcome!     Login

<< Previous Next >>

Coordinated Public Disclosure

iDefense Security Advisory 08.25.09: Autonomy KeyView Excel File SST Parsing Integer Overflow Vulnerability

05/07/2009  - Symantec holding on Autonomy fix
05/07/2009  - Autonomy requested clarification
05/07/2009  - Sent clarification.
08/11/2009  - Disclosure coordination
08/17/2009  - Disclosure re-coordination
08/25/2009  - Coordinated Public Disclosure

IX. CREDIT

This vulnerability was discovered by Joshua J. Drake of iDefense Labs.


iDefense Security Advisory 12.04.08: Sun Java JRE Pack200 Decompression Integer Overflow Vulnerability

VIII. DISCLOSURE TIMELINE

10/02/2008  Initial Vendor Notification
11/25/2008  Initial Vendor Reply
12/02/2008  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by regenrecht.


iDefense Security Advisory 11.09.10: Microsoft Word RTF File Parsing Stack Buffer Overflow Vulnerability

VIII. DISCLOSURE TIMELINE

08/12/2009  Initial Vendor Notification
08/12/2009  Initial Vendor Reply
11/09/2010  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by wushi of team509.


iDefense Security Advisory 03.04.10: Autonomy KeyView OLE Document Integer Overflow Vulnerability

VIII. DISCLOSURE TIMELINE

09/28/2009  Initial Vendor Notification
09/28/2009  Initial Vendor Reply
03/04/2010  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was discovered by Joshua J. Drake of iDefense Labs.


iDefense Security Advisory 04.15.09: IBM AIX muxatmd Buffer Overflow Vulnerability

VIII. DISCLOSURE TIMELINE

12/16/2008  - Initial Vendor Notification
12/16/2008  - Requested PoC
01/06/2009  - PoC Sent
04/15/2009  - Coordinated Public Disclosure

IX. CREDIT

The discoverer of this vulnerability wishes to remain anonymous.


iDefense Security Advisory 08.09.11: Adobe Flash Player Integer Overflow

VIII. DISCLOSURE TIMELINE

04/27/2011  Initial Vendor Notification
04/27/2011  Vendor Reply
08/09/2011  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by Vitaliy Toropov.


iDefense Security Advisory 01.13.09: Oracle Database 10g R2 Summary Advisor Arbitrary File Rewrite Vulnerability

VIII. DISCLOSURE TIMELINE

03/24/2008  - Initial Vendor Notification
03/25/2008  - Initial Vendor Response
11/24/2008  - Status update from Vendor
01/12/2009  - Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by Code Audit Labs
(http://vulnhunt.com).

iDefense Security Advisory 04.09.10: VMware VMnc Codec Heap Overflow Vulnerability

VIII. DISCLOSURE TIMELINE

08/25/2009  Initial Vendor Notification
08/25/2009  Initial Vendor Reply
04/09/2010  Coordinated Public Disclosure

IX. CREDIT

The discoverer of this vulnerability wishes to remain anonymous.


iDefense Security Advisory 05.12.09: Microsoft PowerPoint PPT95 Import Multiple Stack Buffer Overflow Vulnerabilities

07/22/2008  - Status Update Requested
07/23/2008  - Initial Response - Update planned in November
12/11/2008  - Status Update Received - no estimated release date
02/19/2009  - Status Update Received - new case manager, estimated
release date 06/09/2009
05/12/2009  - Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by Marsu.


iDefense Security Advisory 07.20.11: Safari WebKit TIFF Use-After-Free Vulnerability

VIII. DISCLOSURE TIMELINE

02/02/2011  Initial Vendor Notification
02/02/2011  Initial Vendor Reply
07/20/2011  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by Juan Pablo Lopez
Yacubian.

iDefense Security Advisory 04.29.09: Symantec System Center Alert Management System Console Arbitrary Program Execution Design Error Vulnerability

12/11/2008  - Requested Status Update
12/11/2008  - Vendor Status Update
04/14/2009  - Requested CVE
04/14/2009  - Requested Status Update
04/15/2009  - Vendor Status Update
04/28/2009  - Coordinated Public Disclosure

IX. CREDIT

The discoverer of this vulnerability wishes to remain anonymous.


iDefense Security Advisory 04.15.09: Microsoft WordPad Word97 Converter Stack Buffer Overflow Vulnerability

12/31/2008  - PoC Request
01/06/2009  - PoC Sent
01/07/2009  - PoC Rcpt. ACK
02/19/2009  - Vendor Status Update
03/31/2009  - CVE Assigned
04/14/2009  - Coordinated Public Disclosure

IX. CREDIT

This vulnerability was discovered by Jun Mao and Sean Larsson, iDefense
Labs.

iDefense Security Advisory 12.04.08: Sun Java JRE TrueType Font Parsing Integer Overflow Vulnerability

07/31/2008  Initial Vendor Notification
08/01/2008  Initial Vendor Reply
10/21/2008  Additional Vendor Feedback
11/26/2008  Additional Vendor Feedback
12/02/2008  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by Sebastian Apelt
(webmaster@buzzworld.org).

ZDI-09-059: Oracle Secure Backup Administration Server Multiple Command Injection Vulnerabilities

http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuj
ul2009.html

-- Disclosure Timeline:
2009-03-26 - Vulnerability reported to vendor
2009-08-18 - Coordinated Public Disclosure

-- Credit:
This vulnerability was discovered by:
    * Anonymous


iDefense Security Advisory 03.30.10: Oracle Java Runtime Environment Image FIle Buffer Overflow Vulnerability

VIII. DISCLOSURE TIMELINE

12/15/2009  Initial Vendor Notification
12/16/2009  Initial Vendor Reply
03/30/2010  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by regenrecht.


iDefense Security Advisory 05.12.09: Microsoft PowerPoint Integer Overflow Vulnerability

10/01/2008  - Vendor Case Number Issued
12/11/2008  - Vendor Status Update
01/16/2009  - Disclosure Projected
01/20/2009  - Vendor Clarification
02/19/2009  - Vendor Status Update
05/12/2009  - Coordinated Public Disclosure

IX. CREDIT

This vulnerability was discovered by Sean Larsson, iDefense Labs.


iDefense Security Advisory 12.04.08: Sun Java JRE TrueType Font Parsing Heap Overflow Vulnerability

VIII. DISCLOSURE TIMELINE

09/10/2008  Initial Vendor Notification
10/28/2008  Initial Vendor Reply
11/25/2008  Additional Vendor Feedback
12/02/2008  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was discovered by Sean Larsson, iDefense Labs.


iDefense Security Advisory 07.20.11: Multiple Vendor WebKit MathML Use-After-Free Vulnerability

VIII. DISCLOSURE TIMELINE

12/15/2010  Initial Vendor Notification
12/15/2010  Initial Vendor Reply
07/20/2011  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by wushi of team509.


iDefense Security Advisory 02.23.10: Multiple Vendor NOS Microsystems getPlus Downloader Input Validation Vulnerability

VIII. DISCLOSURE TIMELINE

06/09/2009  Initial Vendor Notification
06/09/2009  Initial Vendor Reply
02/23/2010  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by Yorick Koster.


iDefense Security Advisory 06.16.10: Samba 3.3.12 Memory Corruption Vulnerability

VIII. DISCLOSURE TIMELINE

06/04/2010  Initial Vendor Notification
06/04/2010  Initial Vendor Reply
06/16/2010  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was discovered by Jun Mao, iDefense Labs.


iDefense Security Advisory 04.12.11: Microsoft Excel Memory Corruption Vulnerability

VIII. DISCLOSURE TIMELINE

09/09/2010  Initial Vendor Notification
09/09/2010  Initial Vendor Reply
04/12/2011  Coordinated Public Disclosure

IX. CREDIT

The discoverer of this vulnerability wishes to remain anonymous.


iDefense Security Advisory 03.11.10: Multiple Vendor WebKit HTML Element Use After Free Vulnerability

VIII. DISCLOSURE TIMELINE

12/15/2009  Initial Vendor Notification
12/15/2009  Initial Vendor Reply
03/11/2010  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by wushi&Z of team509.


iDefense Security Advisory 02.09.10: Microsoft PowerPoint OEPlaceholderAtom Use-After-Free Vulnerability

VIII. DISCLOSURE TIMELINE

07/08/2009  Initial Vendor Notification
07/08/2009  Initial Vendor Reply
02/09/2010  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was discovered by Sean Larsson, iDefense Labs.


iDefense Security Advisory 12.09.08: Microsoft Internet Explorer 5.01 EMBED tag Long File Name Extension Stack Buffer Overflow Vulnerability (iDefense Exclusive)

08/26/2008  Initial Vendor Notification
08/26/2008  Initial Vendor Reply
09/24/2008  Additional Vendor Feedback
12/02/2008  Additional Vendor Feedback
12/09/2008  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was discovered by Jun Mao of iDefense Labs.


iDefense Security Advisory 07.20.11: Multiple Vendor WebKit SVG animVal Memory Corruption Vulnerability

VIII. DISCLOSURE TIMELINE

12/01/2010  Initial Vendor Notification
12/01/2010  Initial Vendor Reply
07/20/2011  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by wushi of team509.


iDefense Security Advisory 09.26.11: Novell GroupWise iCal Date Invalid Array Indexing Vulnerability

VIII. DISCLOSURE TIMELINE

07/20/2011  Initial Vendor Notification
07/21/2011  Vendor Reply
09/26/2011  Coordinated Public Disclosure

IX. CREDIT

The discoverer of this vulnerability wishes to remain anonymous.


iDefense Security Advisory 03.26.09: Sun Java Runtine Environment (JRE) Type1 Font Parsing Integer Signedness Vulnerability

02/18/2009  - Initial Contact
02/18/2009  - PoC Requested
02/19/2009  - PoC Sent
03/10/2009  - Disclosure Date Set
03/25/2009  - Coordinated Public Disclosure

IX. CREDIT

This vulnerability was discovered by Sean Larsson, iDefense.


iDefense Security Advisory 05.14.09: Multiple Vendor Outside In Multiple Integer Overflow Vulnerabilities

02/25/2009  - GoodLink status update
02/27/2009  - Oracle status update
03/06/2009  - GoodLink status update
04/14/2009  - Oracle patch released
05/13/2009  - CVE Corelation requested from Oracle
05/14/2009  - Coordinated Public Disclosure
05/14/2009  - GoodLink ready for disclosure coordinated with iDefense

IX. CREDIT

This vulnerability was discovered by Joshua J. Drake, iDefense Labs.

iDefense Security Advisory 07.14.11: Citrix Access Gateway ActiveX Stack Buffer Overflow Vulnerability

VIII. DISCLOSURE TIMELINE

07/01/2009  Initial Vendor Notification
07/02/2009  Initial Vendor Reply
07/14/2011  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by Michal Trojnara.


iDefense Security Advisory 05.12.09: Microsoft PowerPoint PPT 4.0 Importer Multiple Stack Buffer Overflow Vulnerabilities

08/29/2008  - PoC Requested
09/02/2008  - PoC Requested
09/03/2008  - PoC Sent
09/04/2008  - Vendor assigned case number
12/11/2008  - Status update received - no estimated release date
05/12/2009  - Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by Marsu.


<<Previous Next>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!