New User, Welcome!     Login

Next Page >>

Coordinated Public Disclosure

iDefense Security Advisory 11.10.09: Microsoft Word FIB Processing Stack Buffer Overflow Vulnerability

03/06/2009  - Initial Contact
03/07/2009  - Initial Response
05/21/2009  - Tentative disclosure set for September
06/25/2009  - Requested CVE from Vendor
11/10/2009  - Coordinated Public Disclosure

IX. CREDIT

This vulnerability was discovered by Jun Mao, iDefense Labs.


iDefense Security Advisory 08.10.10: Microsoft Word RTF File Parsing Heap Buffer Overflow Vulnerability

VIII. DISCLOSURE TIMELINE

08/12/2009  Initial Vendor Notification
08/12/2009  Initial Vendor Reply
08/10/2010  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by wushi of team509.


iDefense Security Advisory 01.10.11: HP Network Node Manager Command Injection Vulnerability

VIII. DISCLOSURE TIMELINE

02/28/2010  Initial Vendor Notification
02/28/2010  Initial Vendor Reply
01/10/2011  Coordinated Public Disclosure

IX. CREDIT

The discoverer of this vulnerability wishes to remain anonymous.


iDefense Security Advisory 04.12.11: Microsoft Internet Explorer Use-After-Free Memory Corruption Vulnerability

VIII. DISCLOSURE TIMELINE

11/24/2010  Initial Vendor Notification
11/24/2010  Initial Vendor Reply
04/12/2011  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by anonymous.


iDefense Security Advisory 01.13.09: Oracle Secure Backup Administration Server login.php Command Injection Vulnerability

VIII. DISCLOSURE TIMELINE

07/18/2008  Initial Vendor Notification
07/30/2008  Initial Vendor Reply
11/24/2008  Additional Vendor Feedback
01/13/2009  Coordinated Public Disclosure

IX. CREDIT

The discoverer of this vulnerability wishes to remain anonymous.


iDefense Security Advisory 02.08.11: Adobe Flash Player ActionScript Integer Overflow Vulnerability

VIII. DISCLOSURE TIMELINE

09/22/2010  Initial Vendor Notification
09/22/2010  Initial Vendor Reply
02/08/2011  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by Vitaliy Toropov.


iDefense Security Advisory 06.25.09: Motorola Timbuktu Pro PlughNTCommand Stack Based Buffer Overflow Vulnerability

09/15/2008  - Vendor update received
03/12/2009  - Vendor status requested
03/12/2009  - Vendor update received
04/24/2009  - Vendor status requested
04/24/2009  - Tentative disclosure set to May 13
06/25/2009  - Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by Rubn Santamarta of
reversemode.com.

iDefense Security Advisory 03.26.09: Sun Java Web Start (JWS ) PNG Decoding Integer Overflow Vulnerability

02/18/2009  - Initial Contact
02/18/2009  - PoC Requested
02/19/2009  - PoC Sent
03/10/2009  - Disclosure Date Set
03/25/2009  - Coordinated Public Disclosure

IX. CREDIT

This vulnerability was discovered by regenrecht.


iDefense Security Advisory 06.10.10: Adobe Flash Player Out Of Bounds Memory Indexing Vulnerability

VIII. DISCLOSURE TIMELINE

08/06/2009  Initial Vendor Notification
08/06/2009  Initial Vendor Reply
06/10/2010  Coordinated Public Disclosure

IX. CREDIT

The discoverer of this vulnerability wishes to remain anonymous.


iDefense Security Advisory 09.26.11: Novell GroupWise iCal RRULE ByWeekNo Memory Corruption Vulnerability

VIII. DISCLOSURE TIMELINE

07/20/2011  Initial Vendor Notification
07/21/2011  Vendor Reply
09/26/2011  Coordinated Public Disclosure

IX. CREDIT

The discoverer of this vulnerability wishes to remain anonymous.


iDefense Security Advisory 10.12.11: Apple Mobile OfficeImport Framework Word Document Parsing Memory Corruption Vulnerability

VIII. DISCLOSURE TIMELINE

10/27/2010  Initial Vendor Notification
10/27/2010  Vendor Reply
10/12/2011  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by Tobias Klein.


iDefense Security Advisory 12.10.08: Microsoft Excel Malformed Object Memoy Corruption Vulnerability

VIII. DISCLOSURE TIMELINE

07/21/2008  Initial Vendor Notification
07/22/2008  Initial Vendor Reply
07/24/2008  Additional Vendor Feedback
12/09/2008  Coordinated Public Disclosure

IX. CREDIT

The discoverer of this vulnerability wishes to remain anonymous.


iDefense Security Advisory 11.10.09: Microsoft Excel FEATHEADER Record Memory Corruption Vulnerability

VIII. DISCLOSURE TIMELINE

04/30/2009  - Initial Contact
04/30/2009  - Initial Vendor Response
11/10/2009  - Coordinated Public Disclosure

IX. CREDIT

This vulnerability was discovered by Sean Larsson, iDefense Labs.


iDefense Security Advisory 02.06.09: HP Network Node Manager Multiple Information Disclosure Vulnerabilities

06/19/2008  Vendor Case # SSRT080095 set
07/10/2008  PoC sent
01/22/2009  Vendor says patch is ready
02/05/2009  Requested CVE from vendor
02/05/2009  Requested date coordination
02/06/2009  Coordinated Public Disclosure

IX. CREDIT

The discoverer of this vulnerability wishes to remain anonymous.


iDefense Security Advisory 03.21.11: Apple OfficeImport Framework Excel Memory Corruption Vulnerability

VIII. DISCLOSURE TIMELINE

01/07/2011  Initial Vendor Notification
01/07/2011  Initial Vendor Reply
03/21/2011  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by Tobias Klein.


iDefense Security Advisory 03.26.09: Sun Java Web Start (JWS ) GIF Decoding Heap Corruption Vulnerability

02/18/2009  - Initial Contact
02/18/2009  - PoC Requested
02/19/2009  - PoC Sent
03/10/2009  - Disclosure Date Set
03/25/2009  - Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by regenrecht.


iDefense Security Advisory 03.26.09: Sun Java Runtime Environment (JRE) Pack200 Decompression Integer Overflow Vulnerability

01/09/2009  - Initial Contact
01/22/2009  - requested PoC
01/22/2009  - sent PoC
01/31/2009  - Vendor acknowledged PoC
02/05/2009  - Requested CVE from vendor
03/25/2009  - Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by regenrecht.


iDefense Security Advisory 03.02.11: Apple CoreGraphics Library Heap Memory Corruption Vulnerability

VIII. DISCLOSURE TIMELINE

08/11/2010  Initial Vendor Notification
08/11/2010  Initial Vendor Reply
03/02/2011  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was discovered by Andrzej Dyjak


iDefense Security Advisory 05.14.09: Multiple Vendor Outside In Multiple Spreadsheet Buffer Overflow Vulnerabilities

02/25/2009  - GoodLink status update
02/27/2009  - Oracle status update
03/06/2009  - GoodLink status update
04/14/2009  - Oracle patch released
05/13/2009  - CVE Corelation requested from Oracle
05/14/2009  - Coordinated Public Disclosure
05/14/2009  - GoodLink ready for disclosure coordinated with iDefense

IX. CREDIT

This vulnerability was discovered by Joshua J. Drake, iDefense Labs.

iDefense Security Advisory 03.09.10: Microsoft Excel Sheet Object Type Confusion Vulnerability

VIII. DISCLOSURE TIMELINE

09/10/2009  Initial Vendor Notification
09/11/2009  Initial Vendor Reply
03/09/2010  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was discovered by Sean Larsson, iDefense Labs.


iDefense Security Advisory 03.09.10: Microsoft Excel FNGROUPNAME Record Uninitialized Memory Vulnerability

VIII. DISCLOSURE TIMELINE

09/25/2009  Initial Vendor Notification
09/25/2009  Initial Vendor Reply
03/09/2010  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was discovered by Sean Larsson, iDefense Labs.


iDefense Security Advisory 05.14.09: Multiple Vendor Outside In Spreadsheet Integer Overflow Vulnerability

02/25/2009  - GoodLink status update
02/27/2009  - Oracle status update
03/06/2009  - GoodLink status update
04/14/2009  - Oracle patch released
05/13/2009  - CVE Corelation requested from Oracle
05/14/2009  - Coordinated Public Disclosure
05/14/2009  - GoodLink ready for disclosure coordinated with iDefense

IX. CREDIT

This vulnerability was discovered by Joshua J. Drake, iDefense Labs.

iDefense Security Advisory 03.30.10: Microsoft Internet Explorer 'onreadystatechange' Use After Free Vulnerability

VIII. DISCLOSURE TIMELINE

07/21/2009  Initial Vendor Notification
07/21/2009  Initial Vendor Reply
03/30/2010  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by wushi of team509.


iDefense Security Advisory 12.04.08: Sun Java Web Start GIF Decoding Memory Corruption Vulnerability

VIII. DISCLOSURE TIMELINE

10/01/2008  Initial Vendor Notification
11/05/2008  Initial Vendor Reply
11/25/2008  Additional Vendor Feedback
12/02/2008  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by regenrecht.


iDefense Security Advisory 01.13.09: RIM BlackBerry Enterprise Server Attachment Service PDF Distiller 'bitmaps' Heap Overflow Vulnerability

12/17/2008  Initial Vendor Notification
12/17/2008  Initial Vendor Reply
12/17/2008  PoC Code Provided To Vendor
12/17/2008  Request Additional Information
01/06/2009  Additional Vendor Feedback
01/12/2009  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was discovered by Sean Larsson, iDefense Labs.


iDefense Security Advisory 12.09.08: Microsoft Windows Graphics Device Interface Integer Overflow Vulnerability

05/21/2008  Initial Vendor Notification
05/21/2008  Initial Vendor Reply
09/05/2008  Additional Information Provided to Vendor
10/14/2008  Additional Vendor Feedback
12/09/2008  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was discovered by Jun Mao of iDefense based on a
submission from an anonymous contributor.

iDefense Security Advisory 09.26.11: Novell GroupWise iCal RRULE Weekday Recurrence Heap Overflow Vulnerability

VIII. DISCLOSURE TIMELINE

07/20/2011  Initial Vendor Notification
07/21/2011  Vendor Reply
09/26/2011  Coordinated Public Disclosure

IX. CREDIT

The discoverer of this vulnerability wishes to remain anonymous.


iDefense Security Advisory 07.15.09: Microsoft Office Publisher 2007 Arbitrary Pointer Dereference Vulnerability

01/08/2009  - Initial Contact
01/09/2009  - PoC Requested
01/09/2009  - PoC Sent
01/09/2009  - Vendor Case Number Assigned
02/20/2009  - Vendor Status Update
07/14/2009  - Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by Lionel d'Hauenens
(LaboSkopia) ( www.laboskopia.com )

iDefense Security Advisory 12.08.09: Microsoft Internet Explorer HTML Layout Engine Uninitialized Memory Vulnerability

VIII. DISCLOSURE TIMELINE

06/09/2009  Initial Vendor Notification
06/09/2009  Initial Vendor Reply
12/08/2009  Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by team509.


iDefense Security Advisory 06.25.09: Unisys Business Information Server Stack Buffer Overflow

05/06/2009  - Clarification received and new clarification requested.
05/07/2009  - Unisys request response.
05/07/2009  - iDefense response regarding PGP key
05/07/2009  - Unisys confirmation.
06/22/2009  - CVE-2009-1628 Assigned by vendor
06/25/2009  - Coordinated Public Disclosure

IX. CREDIT

This vulnerability was reported to iDefense by FistFuXXer.


Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!