New User, Welcome!     Login

<< Previous Next >>

Vulnerability Research Team

VUPEN Security Research - Adobe Acrobat and Reader "newfunction" Memory Corruption Vulnerability (CVE-2010-2168)

II. DESCRIPTION
---------------------

VUPEN Vulnerability Research Team discovered a critical vulnerability in
Adobe Acrobat and Reader.

This vulnerability is caused by a memory corruption error when processing
the "newfunction" operator (bytecode 0x44) while parsing Flash content 
within

[security bulletin] HPSBPI02733 SSRT100646 rev.1 - Certain HP LaserJet Printers, Remote Unauthorized Access to Files

CVE-2011-4785    (AV:N/AC:L/Au:N/C:C/I:N/A:N)       7.8
===========================================================
             Information on CVSS is documented
            in HP Customer Notice: HPSN-2008-002

The Hewlett-Packard Company thanks the Digital Defense, Inc. (DDI) Vulnerability Research Team (VRT) for reporting this vulnerability to security-alert@hp.com.

RESOLUTION

HP has provided the following firmware to resolve the vulnerability.


TELUS Security Labs VR - Symantec Antivirus Intel Alert Handler Service Denial of Service

  2009-10-20 Vendor response
  2011-01-26 Coordinated public disclosure

8. Credits

Junaid Bohio of Vulnerability Research Team, TELUS Security Labs

9. References

  CVE: CVE-2010-0111


VUPEN Security Research - Microsoft Office Excel WOPT Heap Corruption Vulnerability (CVE-2010-0824)

II. DESCRIPTION
---------------------

VUPEN Vulnerability Research Team discovered a critical vulnerability
affecting Microsoft Office Excel.

The vulnerability is caused by a heap corruption error when processing
malformed WOPT (recType 0x80B) records, which could be exploited by
attackers to execute arbitrary code by tricking a user into opening

VUPEN Security Research - Microsoft Office Word Document Stack Overflow Vulnerability (CVE-2010-3214)

II. DESCRIPTION
---------------------

VUPEN Vulnerability Research Team discovered a critical vulnerability
in Microsoft Office Word.

The vulnerability is caused by a stack overflow error when processing
certain structures in a Word document, which could be exploited by remote
attackers to execute arbitrary code by tricking a user into opening a

DDIVRT-2009-23 Apache ActiveMQ Numerous Cross Site Scripting Issues

---------------
February 23rd, 2009

Discovered By
-------------
Digital Defense, Inc. Vulnerability Research Team
Credit: David Marshall and r@b13$

Vulnerability Description
-------------------------
ActiveMQ 5.2.0’s /admin interface gathers input from the user in numerous forms which are not properly sanitized.  Attackers may insert script tags to have them execute when a user browses the affected areas of the page.

VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2009-1564 and CVE-2009-1565 to these
    issues.

    VMware would like to thank iDefense, Sebastien Renaud of VUPEN
    Vulnerability Research Team (http://www.vupen.com) and Alin Rad Pop
    of Secunia Research for reporting these issues to us.

    To remediate the above issues either install the stand alone movie
    decoder or update your product using the table below.


VUPEN Security Research - Microsoft Windows Time Behaviour Remote Use-after-free Vulnerability (MS11-090)

II. DESCRIPTION
---------------------

VUPEN Vulnerability Research Team discovered a vulnerability in Microsoft
Windows.

The vulnerability is caused by a use-after-free error in the "mshtml.dll"
module when handling a specific Time behavior, which could be exploited by
remote attackers to compromise a vulnerable system via a specially crafted

VUPEN Security Research - Adobe Flash Player "Matrix3D" Remote Memory Corruption (CVE-2012-0768)

II. DESCRIPTION
---------------------

VUPEN Vulnerability Research Team discovered a critical vulnerability
in Adobe Acrobat and Reader.

The vulnerability is caused by a memory corruption error within the
Matrix3D class when processing malformed 3D data within SWF files, which
could be exploited by attackers to potentially compromise a vulnerable

VUPEN Security Research - OpenOffice Word Document Processing Heap Overflow Vulnerabilities

II. DESCRIPTION
--------------------- 

VUPEN Vulnerability Research Team discovered critical vulnerabilities
affecting OpenOffice.org.

The first vulnerability is caused by a heap overflow error when
processing malformed "sprmTDefTable" records in a Word document,
which could be exploited by attackers to execute arbitrary code.

VUPEN Security Research - Adobe Acrobat and Reader GIF Data Buffer Overflow Vulnerability

II. DESCRIPTION
---------------------

VUPEN Vulnerability Research Team discovered a critical vulnerability in
Adobe Acrobat and Reader.

This vulnerability is caused by a buffer overflow error when processing
malformed GIF (Graphics Interchange Format) data, which could be exploited
by attackers to execute arbitrary code by tricking a user into opening

DDIVRT-2011-32 Axway SecureTransport '/icons/' Directory Traversal

---------------
July 15, 2011

Discovered By
-------------
Digital Defense, Inc. Vulnerability Research Team
Credit: sxkeebler and r@b13$

Vulnerability Description
-------------------------
The Axway SecureTransport device contains a directory traversal in 

VUPEN Security Research - Microsoft Internet Explorer "CIframeElement" Object Use-after-free Vulnerability (CVE-2010-2558)

II. DESCRIPTION
---------------------

VUPEN Vulnerability Research Team discovered a critical vulnerability
affecting Microsoft Internet Explorer.

The vulnerability is caused by a use-after-free error when processing
"CIframeElement" objects, which could be exploited by remote attackers to
execute arbitrary code by tricking a user into visiting a specially crafted

DDIVRT-2009-28 Sun Solaris 10 rpc.cmsd Buffer Overflow and Denial of Service (CVE-2010-3509)

---------------
November 3, 2009

Discovered By
-------------
Digital Defense, Inc. Vulnerability Research Team
Credit: Alex Kaszczuk, Alan Chin, Jose R. Hernandez and r@b13$

Vulnerability Description
-------------------------
The rpc.cmsd service contains an integer overflow which can allow a malicious unauthenticated user to cause a denial of service, or remotely execute arbitrary code with root privileges.

VUPEN Security Research - Adobe Flash Player NetStream Remote Code Execution Vulnerability (APSB12-07 / CVE-2012-0773)

II. DESCRIPTION
---------------------

VUPEN Vulnerability Research Team discovered a critical vulnerability
in Adobe Flash Player.

The vulnerability is caused by an invalid object being used when parsing
a malformed video via "NetStream.appendBytes", which could allow remote
attackers to leak memory and execute arbitrary code despite ASLR and DEP 

[security bulletin] HPSBPI02398 SSRT080166 rev.5 - Certain HP LaserJet Printers, HP Color LaserJet Printers, and HP Digital Senders, Remote Unauthorized Access to Files

CVE-2008-4419    (AV:N/AC:L/Au:N/C:C/I:N/A:N)       7.8
===========================================================
             Information on CVSS is documented
            in HP Customer Notice: HPSN-2008-002

The Hewlett-Packard Company thanks the Digital Defense, Inc. (DDI) Vulnerability Research Team (VRT) for reporting this vulnerability to security-alert@hp.com.

Note: For further information on Secure Printing and Imaging please refer to http://www.hp.com/go/secureprinting

RESOLUTION


VUPEN Security Research - Adobe Acrobat and Reader PCX Processing Heap Overflow Vulnerability

II. DESCRIPTION
---------------------

VUPEN Vulnerability Research Team discovered a critical vulnerability
in Adobe Acrobat and Reader.

The vulnerability is caused by a heap overflow error when processing
malformed PCX data within a PDF document, which could be exploited by
attackers to compromise a vulnerable system by tricking a user

VUPEN Security Research - Apple Quicktime PICT Processing Integer Overflow Vulnerability

II. DESCRIPTION
--------------------- 

VUPEN Vulnerability Research Team discovered a vulnerability in
Apple Quicktime.

The flaw is caused by an integer overflow error when processing PICT files
with malformed data and atoms, which could be exploited by attackers to
execute arbitrary code by tricking a user into visiting a specially

VUPEN Security Research - Microsoft Office Publisher Size Value Heap Corruption Vulnerability (VUPEN-SR-2010-200)

II. DESCRIPTION
---------------------

VUPEN Vulnerability Research Team discovered a critical vulnerability
in Microsoft Office Publisher.

The vulnerability is caused by a heap corruption error in "pubconv.dll" 
while
trusting a size value from a Publisher document, which could be exploited by

VUPEN Security Research - Apple iTunes ColorSync Profile Integer Overflow Vulnerability

II. DESCRIPTION

--------------------- 

VUPEN Vulnerability Research Team discovered a vulnerability in
Apple iTunes.

The flaw is caused by an integer overflow error in ColorSync when
processing certain images with an embedded color profile, which
could be exploited by attackers to potentially execute arbitrary

[security bulletin] HPSBPI02398 SSRT080166 rev.2 - Certain HP LaserJet Printers, HP Color LaserJet Printers, and HP Digital Senders, Remote Unauthorized Access to Files

Reference                         Base Vector               Base Score 
CVE-2008-4419     (AV:N/AC:L/Au:N/C:C/I:N/A:N)      7.8
===============================================
Information on CVSS is documented in HP Customer Notice: HPSN-2008-002.

The Hewlett-Packard Company thanks the Digital Defense, Inc. (DDI) Vulnerability Research Team (VRT) for reporting this vulnerability to security-alert@hp.com.

RESOLUTION

HP has provided firmware updates and preliminary firmware updates to resolve this vulnerability. The firmware updates and preliminary firmware updates are available as described below.


[security bulletin] HPSBPI02398 SSRT080166 rev.6 - Certain HP LaserJet Printers, HP Color LaserJet Printers, and HP Digital Senders, Remote Unauthorized Access to Files

CVE-2008-4419    (AV:N/AC:L/Au:N/C:C/I:N/A:N)       7.8
===========================================================
             Information on CVSS is documented
            in HP Customer Notice: HPSN-2008-002

The Hewlett-Packard Company thanks the Digital Defense, Inc. (DDI) Vulnerability Research Team (VRT) for reporting this vulnerability to security-alert@hp.com.

Note: For further information on Secure Printing and Imaging please refer to http://www.hp.com/go/secureprinting

RESOLUTION


VUPEN Security Research - Adobe Acrobat and Reader IFF Processing Heap Overflow Vulnerability

II. DESCRIPTION
---------------------

VUPEN Vulnerability Research Team discovered a critical vulnerability
in Adobe Acrobat and Reader.

The vulnerability is caused by a heap overflow error when processing
malformed IFF data within a PDF document, which could be exploited by
attackers to compromise a vulnerable system by tricking a user

VUPEN Security Research - Google Chrome WebKit Engine Ruby Tag Stale Pointer Vulnerability

II. DESCRIPTION
---------------------

VUPEN Vulnerability Research Team discovered a vulnerability in Google 
Chrome.

The vulnerability is caused by a stale pointer in the WebKit engine when
deleting a Ruby tag and its children in a specific order, which could be
exploited by remote attackers to compromise a vulnerable system via a

DDIVRT-2009-24 Precidia Ether232 Memory Corruption

---------------
March 10th, 2009

Discovered By
-------------
Digital Defense, Inc. Vulnerability Research Team
Credit: Steven James and princeofnigeria and r@b13$

Vulnerability Description
-------------------------
Certain Precidia Ether232 devices contain memory overwrite and authentication flaws.

VUPEN Security Research - VMware Products Movie Decoder Heap Overflow Vulnerability

II. DESCRIPTION
---------------------

VUPEN Vulnerability Research Team discovered a vulnerability in
VMware products.

The flaw is caused by a heap overflow error in the VMnc media codec
when processing malformed AVI files, which could be exploited by
attackers to potentially execute arbitrary code by tricking a user

VUPEN Security Research - Adobe Acrobat and Reader U3D Integer Overflow Vulnerability

II. DESCRIPTION
--------------------- 

VUPEN Vulnerability Research Team discovered a critical vulnerability
affecting Adobe Acrobat and Reader.

This vulnerability is caused by an integer overflow error in the U3D module
when processing malformed data, which could be exploited by attackers to
execute arbitrary code by tricking a user into opening a specially crafted

[security bulletin] HPSBPI02398 SSRT080166 rev.3 - Certain HP LaserJet Printers, HP Color LaserJet Printers, and HP Digital Senders, Remote Unauthorized Access to Files

Reference                         Base Vector               Base Score 
CVE-2008-4419     (AV:N/AC:L/Au:N/C:C/I:N/A:N)      7.8
===============================================
Information on CVSS is documented in HP Customer Notice: HPSN-2008-002.

The Hewlett-Packard Company thanks the Digital Defense, Inc. (DDI) Vulnerability Research Team (VRT) for reporting this vulnerability to security-alert@hp.com.

RESOLUTION

HP has provided firmware updates and preliminary firmware updates to resolve this vulnerability. The firmware updates and preliminary firmware updates are available as described below.


VUPEN Security Research - RealPlayer Sound Data Handling Buffer Overflow Vulnerability (VUPEN-SR-2010-004)

II. DESCRIPTION
---------------------

VUPEN Vulnerability Research Team discovered a critical vulnerability
in RealPlayer.

The vulnerability is caused by a heap overflow error when handling sound
data within media files, which could be exploited by remote attackers to 
execute

VUPEN Security Research - RealPlayer AAC Data Handling Buffer Overflow Vulnerability (VUPEN-SR-2010-005)

II. DESCRIPTION
---------------------

VUPEN Vulnerability Research Team discovered a critical vulnerability
in RealPlayer.

The vulnerability is caused by a heap overflow error when handling malformed
AAC files, which could be exploited by remote attackers to execute arbitrary
code by tricking a user into visiting a specially crafted web page.

<<Previous Next>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!