New User, Welcome!     Login

<< Previous Next >>

analysis

VUPEN Security Research - Adobe Flash Player ActionScript FileReference Buffer Overflow (APSB11-21)

Adobe Flash Player v10.3.181.34 and prior
Adobe Flash Player v10.3.185.25 and prior for Android
Adobe AIR version 2.7 and prior


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a code execution exploit
are available through the VUPEN Binary Analysis & Exploits Service :


VUPEN Security Research - Adobe Acrobat and Reader TIFF BitsPerSample Heap Overflow Vulnerability

Adobe Acrobat and Reader X (10.1) and prior
Adobe Acrobat and Reader 9.4.5 and prior
Adobe Acrobat and Reader 8.3 and prior


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a code execution exploit
are available through the VUPEN Binary Analysis & Exploits Service :


VUPEN Security Research - Adobe Acrobat and Reader Picture Dimensions Heap Overflow Vulnerability

Adobe Acrobat and Reader X (10.1) and prior
Adobe Acrobat and Reader 9.4.5 and prior
Adobe Acrobat and Reader 8.3 and prior


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a proof-of-concept code
are available through the VUPEN Binary Analysis & Exploits Service :


VUPEN Security Research - Adobe Acrobat and Reader IFF Processing Heap Overflow Vulnerability

Adobe Acrobat and Reader X (10.1) and prior
Adobe Acrobat and Reader 9.4.5 and prior
Adobe Acrobat and Reader 8.3 and prior


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a code execution exploit
are available through the VUPEN Binary Analysis & Exploits Service :


VUPEN Security Research - Adobe Acrobat and Reader PCX Processing Heap Overflow Vulnerability

Adobe Acrobat and Reader X (10.1) and prior
Adobe Acrobat and Reader 9.4.5 and prior
Adobe Acrobat and Reader 8.3 and prior


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a proof-of-concept code
are available through the VUPEN Binary Analysis & Exploits Service :


VUPEN Security Research - Adobe Acrobat and Reader BMP Dimensions Heap Overflow Vulnerability

Adobe Acrobat and Reader X (10.1) and prior
Adobe Acrobat and Reader 9.4.5 and prior
Adobe Acrobat and Reader 8.3 and prior


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a code execution exploit
are available through the VUPEN Binary Analysis & Exploits Service :


VUPEN Security Research - Adobe Acrobat and Reader Picture Processing Stack Overflow Vulnerability

Adobe Acrobat and Reader X (10.1) and prior
Adobe Acrobat and Reader 9.4.5 and prior
Adobe Acrobat and Reader 8.3 and prior


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a code execution exploit
are available through the VUPEN Binary Analysis & Exploits Service :


VUPEN Security Research - Microsoft Office Excel Formula Record Heap Corruption Vulnerability

Microsoft Office 2007 Service Pack 2
Microsoft Office 2003 Service Pack 3
Microsoft Office 2002 Service Pack 3


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a code execution exploit
are available through the VUPEN Binary Analysis & Exploits Service :


VUPEN Security Research - Novell GroupWise "TZNAME" Remote Buffer Overflow Vulnerability

---------------------------

Novell GroupWise v8.0.2 (SP2) Hot Patch 2 (HP2) and prior


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a proof-of-concept code
are available through the VUPEN Binary Analysis & Exploits portal :


VUPEN Security Research - Novell GroupWise "integerList" Remote Buffer Overflow Vulnerability

---------------------------

Novell GroupWise v8.0.2 (SP2) Hot Patch 2 (HP2) and prior


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a code execution exploit
are available through the VUPEN Binary Analysis & Exploits portal :


VUPEN Security Research - Novell GroupWise "RRULE" Remote Buffer Overflow Vulnerability

---------------------------

Novell GroupWise v8.0.2 (SP2) Hot Patch 2 (HP2) and prior


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a proof-of-concept code
are available through the VUPEN Binary Analysis & Exploits portal :


VUPEN Security Research - Novell GroupWise "BYWEEKNO" Remote Memory Corruption Vulnerability

---------------------------

Novell GroupWise v8.0.2 (SP2) Hot Patch 2 (HP2) and prior


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a proof-of-concept code
are available through the VUPEN Binary Analysis & Exploits portal :


VUPEN Security Research - Google Chrome WebKit Engine Ruby Tag Stale Pointer Vulnerability

---------------------------

Google Chrome versions prior to 14.0.835.202


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a proof-of-concept code
are available through the VUPEN Binary Analysis & Exploits portal :


VUPEN Security Research - Google Chrome WebKit Engine Child Tag Deletion Stale Pointer Vulnerability

---------------------------

Google Chrome versions prior to 14.0.835.202


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a proof-of-concept code
are available through the VUPEN Binary Analysis & Exploits portal :


VUPEN Security Research - Microsoft Internet Explorer "X-UA-COMPATIBLE" Use-after-free Vulnerability

Microsoft Windows Vista x64 Edition Service Pack 2
Microsoft Windows Server 2008 for 32-bit Systems Service Pack 2
Microsoft Windows Server 2008 for x64-based Systems Service Pack 2


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a proof-of-concept code
are available through the VUPEN Binary Analysis & Exploits portal :


VUPEN Security Research - Microsoft Windows Time Behaviour Remote Use-after-free Vulnerability (MS11-090)

Microsoft Windows Server 2003 Service Pack 2
Microsoft Windows Server 2003 x64 Edition Service Pack 2
Microsoft Windows Server 2003 SP2 (Itanium)


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a code execution exploit
are available through the VUPEN Binary Analysis & Exploits portal :


VUPEN Security Research - Microsoft Windows Media Player DVR-MS Buffer Overflow Vulnerability (MS11-092)

Microsoft Windows 7 (32-bit) Service Pack 1
Microsoft Windows 7 (x64)
Microsoft Windows 7 (x64) Service Pack 1


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a proof-of-concept code
are available through the VUPEN Binary Analysis & Exploits portal :


VUPEN Security Research - Adobe Flash Player "SAlign" Memory Corruption Vulnerability (CVE-2011-2459)

---------------------------

Adobe Flash Player versions prior to 11.1.102.55


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a proof-of-concept code
are available through the VUPEN Binary Analysis & Exploits portal :


VUPEN Security Research - Microsoft Windows "datime.dll" Remote Code Execution Vulnerability (MS11-090)

Microsoft Windows Server 2003 Service Pack 2
Microsoft Windows Server 2003 x64 Edition Service Pack 2
Microsoft Windows Server 2003 SP2 (Itanium)


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a code execution exploit
are available through the VUPEN Binary Analysis & Exploits portal :


VUPEN Security Research - Adobe Acrobat and Reader Image Processing Integer Overflow (APSB12-01)

Adobe Acrobat and Reader X (10.1.1) and prior
Adobe Acrobat and Reader 9.4.7 and prior


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth technical analysis of the vulnerability and a proof-of-concept
code are available through the VUPEN Binary Analysis & Exploits portal:


XCon 2012 XFocus Information Security Conference Call for Paper

      - Web application vulnerability research
      - Application reverse engineering and related automated tools
      - Database security & attacks
      - Advanced Trojans, worms and backdoor technique

   --- Intrusion detection/forensics analysis
     - Traffic analysis
     - Real-time data structure recovery 
     - File system analysis & recovery
     - Intrusion detection and anti-detection technique
     - Reverse engineering (malicious code analysis technique, vulnerability research) 

VUPEN Security Research - Adobe Flash Player "Matrix3D" Remote Memory Corruption (CVE-2012-0768)

---------------------------

Adobe Flash Player version 11.1.102.62 and prior


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth technical analysis of the vulnerability and a proof-of-concept
code are available through the VUPEN Binary Analysis & Exploits portal:


VUPEN Security Research - Microsoft Internet Explorer VML Remote Code Execution (MS12-023 / CVE-2012-0172)

Microsoft Windows Server 2008 R2 for x64-based Systems Service Pack 1
Microsoft Windows Server 2008 R2 for Itanium-based Systems
Microsoft Windows Server 2008 R2 for Itanium-based Systems Service Pack 1


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth technical analysis of the vulnerability and a working exploit
are available through the VUPEN Binary Analysis & Exploits portal:


VUPEN Security Research - Adobe Flash Player NetStream Remote Code Execution Vulnerability (APSB12-07 / CVE-2012-0773)

---------------------------

Adobe Flash Player versions prior to 11.2.202.228


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth technical analysis of the vulnerability and a working exploit
are available through the VUPEN Binary Analysis & Exploits portal:


[security bulletin] HPSBST02280 SSRT071480 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS07-055 to MS07-060

NOTE: Patch installation instructions are shown at the end of this table.

 -------------------------------------------------
MS Patch - MS07-055 Vulnerability in Kodak Image Viewer Could Allow Remote Code Execution (923810) 
Analysis -  Possible security issue exists. Patch will run successfully.
Action -  For SMA v2.1, customers should download patch from Microsoft and install.
 ------------------------------------------------- 
MS Patch - MS07-056 Security Update for Outlook Express and Windows Mail (941202) 
Analysis -  Possible security issue exists. Patch will run successfully.
Action -  For SMA v2.1, customers should download patch from Microsoft and install.

CORE-2007-0817: Remote Command execution, HTML and JavaScript injection vulnerabilities in AOL's Instant Messaging software

requests the exact version numbers of the AIM clients used, proof of
concept code and/or a description of how to reproduce the test.
*2007-09-14*: Email sent to AOL indicating that a second post with
additional information about the bug has been made by the third-party [2].
Core requests further details about this publicly disclosed bug and asks
AOL to provide the analysis that lead the AOL team to conclude that it is
of a different nature of those reported by Core. This email includes
detailed step-by-step instructions on how to bypass the server-side
filtering mechanism accompanied with the exact version number of the AIM
client used (6.1.41.2) and the sample code. Core's own analysis of current
publicly available information indicates that the bug is indeed of similar

RE: CORE-2007-0817: Remote Command execution, HTML and JavaScript injection vulnerabilities in AOL's Instant Messaging software

requests the exact version numbers of the AIM clients used, proof of
concept code and/or a description of how to reproduce the test.
*2007-09-14*: Email sent to AOL indicating that a second post with
additional information about the bug has been made by the third-party [2].
Core requests further details about this publicly disclosed bug and asks
AOL to provide the analysis that lead the AOL team to conclude that it is
of a different nature of those reported by Core. This email includes
detailed step-by-step instructions on how to bypass the server-side
filtering mechanism accompanied with the exact version number of the AIM
client used (6.1.41.2) and the sample code. Core's own analysis of current
publicly available information indicates that the bug is indeed of similar

CORE-2008-0826 - Internet Explorer Security Zone restrictions bypass

function 'FindMimeFromData' in 'URLMON.DLL'[5].

In the following section, proof of concept code is provided to
demonstrate the problem using the local storage used by Internet
Explorer to store the user's browsing history to deliver HTML with
scripting code and force IE to render it. This analysis is valid for any
Windows NT based operating system but should be slightly modified to run
under Windows Vista. It takes advantage of the following features:

   1. The IE user's browsing history is compounded of different files
and folders. One of these files is named 'index.dat', and is usually

VUPEN Security Research - Microsoft Office Excel Record Processing Code Execution Vulnerability

Microsoft Office Excel 2002 Service Pack 3
Microsoft Office XP Service Pack 3


IV. Exploits - PoCs & Binary Analysis
----------------------------------------

In-depth binary analysis of the vulnerability and a code exeution
exploit have been released by VUPEN through the VUPEN Binary Analysis
& Exploits Service :

[HITB-Announce] HITBSecConf2010 - Malaysia Call for Papers

# Apple / OS X security vulnerabilities
# SS7/Backbone telephony networks
# VoIP security
# Data Recovery, Forensics and Incident Response
# HSDPA / CDMA Security / WIMAX Security
# Network Protocol and Analysis
# Smart Card and Physical Security
# Virus and Worms
# WLAN, GPS, HAM Radio, Satellite, RFID and Bluetooth Security
# Analysis of malicious code
# Applications of cryptographic techniques

<<Previous Next>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!