New User, Welcome!     Login

<< Previous Next >>

interaction

ZDI-10-015: Microsoft Windows RLE Video Decompressor Remote Code Execution Vulnerability

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows attackers to execute arbitrary code on
applications that utilize DirectShow for rendering video on Microsoft
Windows. User interaction is required to exploit this vulnerability in
that the target must be coerced into decompressing a malicious video.

The specific flaw exists within the decompression of a specific type of
video stream contained in an .AVI file. The application misuses a length
field for an allocation causing the memory allocation to be too small to

ZDI-08-062: Apple QuickTime MDAT Frame Parsing Memory Corruption Vulnerability

-- Affected Products:
Apple Quicktime

-- Vulnerability Details:
This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of Apple QuickTime. User interaction is
required to exploit this vulnerability in that the target must visit a
malicious page or open a malicious file.

The specific flaw exists in the parsing of mov video files in
QuickTimeH264.scalar. A maliciously crafted MDAT atom can cause a heap

ZDI-08-057: Apple QuickTime IV32 Codec Parsing Stack Overflow Vulnerability

-- Affected Products:
Apple Quicktime

-- Vulnerability Details:
This vulnerability allows attackers to execute arbitrary code on
vulnerable installations of Apple QuickTime. User interaction is
required to exploit this vulnerability in that the target must visit a
malicious page or open a malicious file.

The specific flaw exists within the parsing of QuickTime files that
utilize the Indeo video codec. A lack of proper bounds checking within

http://www.zerodayinitiative.com/advisories/ZDI-08-046

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows remote attackers to execute arbitrary code on
systems with vulnerable installations of the RealNetworks RealPlayer.
User interaction is required to exploit this vulnerability in that the
target must visit a malicious page or open a malicious file.

The specific flaw exists in RealPlayer's rjbdll.dll module when handling
the deletion of media library files. An attacker could exploit this
vulnerability using an ActiveX control 

ZDI-08-047: RealNetworks RealPlayer rmoc3260 ActiveX Control Memory Corruption Vulnerability

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows remote attackers to execute code on vulnerable
installations of RealPlayer. User interaction is required in that a user
must visit a malicious web site.

The specific flaw exists in the rmoc3260 ActiveX control exposed through
the following CLSIDs:


ZDI-10-041: Apple QuickTime QDM2/QDCA Atom Remote Code Execution Vulnerability

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of Apple QuickTime. User interaction is
required to exploit this vulnerability in that the target must visit a
malicious page or open a malicious file.

The specific flaw exists during the rendering of an audio stream
utilizing QDesign's audio codec. The application will perform an

ZDI-10-049: Mozilla Firefox PluginArray nsMimeType Dangling Pointer Remote Code Execution Vulnerability

Mozilla Firefox 3.5.x


-- Vulnerability Details:
This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of Mozilla Firefox. User interaction is
required to exploit this vulnerability in that a user must be coerced to
viewing a malicious document.

The specific flaw exists within the way the application implements the
window.navigator.plugins array. Due to the application freeing the

TPTI-09-01: VMWare VMnc Codec Invalid RFB Message Type Heap Overflow

VMWare, Inc. VMWare Server
VMWare, Inc. VMWare ACE

-- Vulnerability Details:
This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of multiple VMWare products. User interaction
is required in that a user must visit a malicious web page or open a
malicious video file.

Upon installation VMWare Workstation, Server, Player, and ACE register
vmnc.dll as a video codec driver to handle compression and decompression

ZDI-09-073: Adobe Reader Compact Font Format Malformed Index Memory Corruption Vulnerability

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of Adobe Acrobat and Adobe Reader. User
interaction is required to exploit this vulnerability in that the target
must visit a malicious page or open a malicious file.

The specific flaw exists when the application parses a PDF file
containing a malformed Compact Font Format stream. While decoding the
font embedded in this stream, the application will explicitly trust a

Layered Defense Research Advisory: Juniper Netscreen Firewall Cross-Site-Scripting (XSS) event log injection

Juniper Netscreen Firewall 
ScreenOS version 5.4.0r9.0
================================================== 
2) Severity Rating: 
Low - Moderate
Impact: Potential system compromises but requires user interaction. 
================================================== 
3) Description of Vulnerability
A Cross-Site Scripting (XSS) Injection vulnerability was discovered within the Juniper Netscreen firewall NetOS version 5.4.0r9.0. The vulnerability is caused by failure to validate input from the web interface login, and telnet session login. This makes it possible for an attacker to inject javascript as part of the user name during login. The javascript is then stored in the device event logs. When the event logs are viewed within the Netscreen web console the javascript is executed. A successful attack would allow an attacker to run JavaScript on the computer system connecting to the netscreen web management console which could lead to system compromise. 
================================================== 
4) Solution 

ZDI-09-087: Microsoft Internet Explorer CSS Race Condition Code Execution Vulnerability

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows remote attackers to potentially execute
arbitrary code on vulnerable installations of Microsoft Internet
Explorer. User interaction is required to exploit this vulnerability in
that the target must visit a malicious page.

The specific flaw exists during a race condition while repetitively
clicking between two elements at a fast rate. When clicking back and
forth between these two elements a corruption occurs resulting in a call

ZDI-10-014: Microsoft Internet Explorer item Object Memory Corruption Remote Code Execution Vulnerability

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of Microsoft Internet Explorer. User
interaction is required to exploit this vulnerability in that the target
must visit a malicious page.

The specific flaw exists in the handling of cloned DOM objects in
JavaScript. A specially crafted sequence of object cloning can result in
the use of a pointer after it has been freed. Successful exploitation

ZDI-09-012: Microsoft Internet Explorer Malformed CSS Memory Corruption

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of Microsoft Internet Explorer. User
interaction is required to exploit this vulnerability in that the target
must visit a malicious page.

The specific flaw exists when processing, in XHTML strict mode, a CSS
stylesheet containing a specific combination of style directives one of
which must be a 'zoom'. The fault in processing results in a memory

ZDI-10-096: Apple Webkit Recursive Use Element Remote Code Execution Vulnerability

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of Apple's Webkit. User interaction is required
to exploit this vulnerability in that the target must visit a malicious
page or open a malicious file.

The specific flaw exists within how the WebKit library handles
recursively defined Use elements. Upon expanding the target of the use

ZDI-10-028: Skype URI Processing Arbitrary XML File Deletion Vulnerability

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows remote attackers to remove arbitrary XML files
on vulnerable installations of Skype. User interaction is required to
exploit this vulnerability in that the target must visit a malicious
page.

The specific flaw exists in Skype's handling of the 'skype-plugin:'
protocol. An attacker can specify a malicious URI, that upon clicking,

ZDI-10-022: IBM Informix librpc.dll Multiple Remote Code Execution Vulnerabilities

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows attackers to execute arbitrary code on
vulnerable installations of both IBM Informix Dynamic Server and EMC
Legato Networker. User interaction is not required to exploit this
vulnerability.

The specific flaws exist within the RPC protocol parsing library,
librpc.dll, utilized by the ISM Portmapper service (portmap.exe) bound
by default to TCP port 36890. During authentication, a lack of proper

ZDI-09-062: Microsoft Internet Explorer JScript arguments Invocation Memory Corruption Vulnerability

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of Microsoft Internet Explorer. User
interaction is required to exploit this vulnerability in that the target
must visit a malicious page.

The specific flaw exists when parsing the jscript keyword "arguments".
Because the arguments object is not available until a certain time,
invoking it can result in memory corruption. Successful exploitation of

[scip_Advisory 4143] Shemes Grabbit Malicious NZB Date Denial of Service

scip AG Vulnerability ID 4143 (07/08/2010)
http://www.scip.ch/?vuldb.4143

I. INTRODUCTION

Grabbit is a popular freeware client for binary Usenet interaction.

More information is available on the official web site at the following URL:

http://www.shemes.com/index.php?p=download


ZDI-10-040: Apple QuickTime RLE Bit Depth Remote Code Execution Vulnerability

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of Apple QuickTime. User interaction is
required to exploit this vulnerability in that the target must visit a
malicious page or open a malicious file.

The specific flaw exists during the parsing of samples from a malformed
.mov file utilizing the RLE codec. While decoding RLE data, the

ZDI-08-029: Trillian AIM.DLL Long HTML Font Parameter Stack Overflow Vulnerability

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of Trillian. User interaction is required to
exploit this vulnerability in that the target must open a malicious
image file.

The specific flaws exists during the parsing of messages with overly
long attribute values within the FONT tag. The value for any attribute

ZDI-10-046: Mozilla Firefox Web Worker Array Remote Code Execution Vulnerability

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of Mozilla Firefox. User interaction is
required to exploit this vulnerability in that the target must visit a
malicious page.

The specific flaw exists within the implementation of web worker
threads. Due to mishandling the array data type while processing posted

ZDI-10-095: Apple Webkit DOCUMENT_POSITION_DISCONNECTED Attribute Remote Code Execution Vulnerability

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows remote attackers to execute arbitrary code on
software utilizing a vulnerable version of Apple's Webkit. User
interaction is required to exploit this vulnerability in that the target
must visit a malicious page.

The specific flaw exists within the way that Apple's Webkit handles the
DOCUMENT_POSITION_DISCONNECTED attribute when a container is removed.
This attribute is responsible for ensuring that a node is disconnected

iDefense Security Advisory 07.28.09: Multiple Vendor Microsoft ATL/MFC ActiveX Security Bypass Vulnerability

specially crafted Web page leveraging the vulnerability. While there is
no way to forcibly make a victim visit a website, exploitation may
occur through normal Web browsing.

This vulnerability greatly increases the attack surface accessible via
Internet Explorer by decreasing the amount of user interaction
necessary to access other initialization vulnerabilities.

IV. DETECTION

iDefense has confirmed the existence of this vulnerability inside

ZDI-09-079: Sun Java Runtime AWT setBytePixels Heap Overflow Vulnerability

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of Sun Java Runtime Environment. User
interaction is required to exploit this vulnerability in that the target
must visit a malicious page.

The specific flaw exists in the processing of arguments to the
setBytePixels AWT library function. Due to the lack of bounds checking
on the parameters to the function a user controllable memcpy can result

ZDI-09-093: Adobe Flash Player ActionScript Exception Handler Integer Overflow Vulnerability

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of Adobe Flash Player. User interaction is
required to exploit this vulnerability in that the target must visit a
malicious web page or open a malicious SWF file.

The specific flaw exists in the generation of ActionScript exception
handlers. In Verifier::parseExceptionHandlers(), a large value for

ZDI-10-023: Multiple Vendor librpc.dll Signedness Error Remote Code Execution Vulnerability

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows attackers to execute arbitrary code on
vulnerable installations of both IBM Informix Dynamic Server and EMC
Legato Networker. User interaction is not required to exploit this
vulnerability.

The specific flaw exists within the RPC protocol parsing library,
librpc.dll, utilized by the ISM Portmapper service (portmap.exe) bound
by default to TCP port 36890. During authentication, a lack of a proper

RE: NSOADV-2010-004: McAfee LinuxShield remote/local code execution

Description:
============

This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of McAfee LinuxShield. User interaction is not
required to exploit this vulnerability but an attacker must be
authenticated.

The LinuxShield Webinterface communicates with the localy installed
"nailsd" daemon, which listens on port 65443/tcp, to do configuration

ZDI-09-088: Microsoft Internet Explorer IFrame Attributes Circular Reference Dangling Pointer Vulnerability

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of Microsoft Internet Explorer. User
interaction is required to exploit this vulnerability in that the target
must visit a malicious web page.

The specific flaw exists during deallocation of a circular dereference
for a CAttrArray object. If the CAttrArray object has been freed prior
to the tearing down of the webpage, the application will access the

ZDI-09-041: Microsoft Internet Explorer 8 Rows Property Dangling Pointer Code Execution Vulnerability

Microsoft Internet Explorer

-- Vulnerability Details:
This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of Microsoft Internet Explorer 8. User
interaction is required to exploit this vulnerability in that the target
must visit a malicious page.

The specific flaw exists during the rendering of an HTML page with
malformed row property references, resulting in a dangling pointer which
can be abused to execute arbitrary code. Internet Explorer 7 is not

ZDI-09-035: Microsoft Word Document Stack Based Buffer Overflow Vulnerability

-- Affected Products:
Microsoft Office Word

-- Vulnerability Details:
This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of Microsoft Word. User interaction is required
to exploit this vulnerability in that the target must visit a malicious
page, open a malicious e-mail, or open a malicious file.

The specific flaw exists within the parsing of vulnerable tags inside a
Microsoft Word document. Microsoft Word trusts a length field read from

<<Previous Next>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!