New User, Welcome!     Login

Next Page >>

Disclosure Timeline

Avast aswRdr.sys Kernel Pool Corruption and Local Privilege Escalation

Copyright 2009 Giuseppe Bonfa'. All rights reserved.


***Disclosure Timeline***

Discover Date: -
PoC Code: porting C++ 26/09/2009
Vendor Notify: 26/09/2009
Vendor Reply: 15/09/2009

OpenNMS Multiple Vulnerabilities

Vulnerability Information            5
Vulnerability Details                5
Proof-of-Concept                5
Security Analysis                6
Discovery                    6
Disclosure Timeline                6
About BugSec LTD.                6
References                    6


 

[W02-1008] GearSoftware Powered Products Local Privilege Escalation (Microsoft Windows Kernel IopfCompleteRequest Integer Overflow)

   3. Technical Description
   4. Exploiting it
   5. References
   6. Affected Products
   7. Credits
   8. Disclosure Timeline
   9. Contact





Diigo Toolbar - Global XSS and Information Leakage in SSL URLs

== Fix ==
Download latest version of Diigo Toolbar

== Disclosure Timeline ==
* 12 May 2008 - Vendor Informed
* 2 June 2008 - Another e-mail to vendor to check if they've fixed
* 3 June 2008 - Vendor informed me that it's fixed
* 20 June 2008 - Public Release


Cross site scripting issues in s9y (CVE-2008-1386, CVE-2008-1387)

wget --referer='http://<hr onMouseOver="alert(7)">' http://someblog.com/

Workaround/Fix

If you are using the referrer plugin, upgrade to 1.3.1.
Disclosure Timeline

2008-03-18 Vendor contacted
2008-03-18 Vendor answered
2008-03-18 Vendor fixed issue in trunk/branch revision
2008-04-22 Vendor released 1.3.1

Cross site scripting issues in s9y (CVE-2008-1386, CVE-2008-1387)

wget --referer='http://<hr onMouseOver="alert(7)">' http://someblog.com/

Workaround/Fix

If you are using the referrer plugin, upgrade to 1.3.1.
Disclosure Timeline

2008-03-18 Vendor contacted
2008-03-18 Vendor answered
2008-03-18 Vendor fixed issue in trunk/branch revision
2008-04-22 Vendor released 1.3.1

[Reversemode Advisory] February Advisories : Microsoft Word 2003 + Fortinet Forticlient

user who started the application.

Microsoft has addressed this issue (among others) in its february 
bulletin: http://www.microsoft.com/technet/security/Bulletin/MS08-009.mspx

Disclosure Timeline:
07/02/2007 - Vendor Contacted
07/02/2007 - Vendor Acknowledged
01/10/2008 - Vendor confirms vulnerability and plans to fix it.
02/12/2008 - Coordinated disclosure


[CAL-20100204-2]Adobe Shockwave Player Director File Parsing integer overflow vulnerability

ref
http://hi.baidu.com/fs_fx/blog/item/fa74a61705b5e24621a4e951.html
http://www.adobe.com/support/security/bulletins/apsb10-12.html

Disclosure Timeline
===================
2010-2-6 report to vendor
2010-2-7 vendor ask poc file
2010-2-7 we sent the poc file.
2010-2-8 vendor comfirm the issue.

ZDI-10-087: Adobe Shockwave Invalid Offset Memory Corruption Remote Code Execution Vulnerability

Adobe has issued an update to correct this vulnerability. More
details can be found at:

http://www.adobe.com/support/security/bulletins/apsb10-12.html

-- Disclosure Timeline:
2010-02-02 - Vulnerability reported to vendor
2010-05-11 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:

ZDI-10-054: Sun Java Runtime Environment JPEGImageReader stepX Remote Code Execution Vulnerability

Sun Microsystems has issued an update to correct this vulnerability. More
details can be found at:

http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html

-- Disclosure Timeline:
2009-12-10 - Vulnerability reported to vendor
2010-04-05 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:

ZDI-10-027: Skype Protocol Handler datapath Argument Injection Remote Code Execution Vulnerability

Skype has issued an update that corrects this vulnerability. More
details can be found at:

http://share.skype.com/sites/garage/2010/03/10/ReleaseNotes_4.2.0.155.pdf

-- Disclosure Timeline:
2009-07-14 - Initial report to vendor, no response.
2010-01-07 - Follow-up report, again no response.
2010-01-11 - Received support e-mail with update notice from Skype.
2010-01-11 - We responded the same day stating that the new version does not address our reported bugs.
2010-01-12 - Skype requests more details, specifically a screen shot.

ZDI-10-103: Microsoft Office Excel DBQueryExt Record Unspecified ADO Object Remote Code Execution Vulnerability

Microsoft has issued an update to correct this vulnerability. More
details can be found at:

http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx

-- Disclosure Timeline:
2010-01-06 - Vulnerability reported to vendor
2010-06-08 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:

pmwiki: persistent cross site scripting (XSS), CVE-2010-1481

||width="
|| " onMouseOver=alert(1) " ||test||

The vendor has been contacted, but has not replied to my report.

Disclosure Timeline

2010-04-19: Vendor contacted
2010-05-07: Published advisory

Credits

ZDI-10-051: Sun Java Runtime RMIConnectionImpl Privileged Context Remote Code Execution Vulnerability

Sun Microsystems has issued an update to correct this vulnerability. More
details can be found at:

http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html

-- Disclosure Timeline:
2009-10-21 - Vulnerability reported to vendor
2010-04-05 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:

TPTI-10-02: Microsoft Office PowerPoint Viewer TextCharsAtom Record Code Execution Vulnerability

Microsoft has issued an update to correct this vulnerability. More
details can be found at:

http://www.microsoft.com/technet/security/Bulletin/MS10-004.mspx

-- Disclosure Timeline:
2009-10-29 - Vulnerability reported to vendor
2010-02-09 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:

ZDI-10-114: Adobe Flash Player AVM2 getouterscope Opcode Remote Code Execution Vulnerability

Adobe has issued an update to correct this vulnerability. More
details can be found at:

http://www.adobe.com/go/apsb10-14

-- Disclosure Timeline:

2010-06-25 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:

ZDI-10-092: Apple Webkit Option Element ContentEditable Remote Code Execution Vulnerability

Apple has issued an update to correct this vulnerability. More
details can be found at:

http://support.apple.com/kb/HT4196

-- Disclosure Timeline:
2010-05-10 - Vulnerability reported to vendor
2010-06-08 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:

ZDI-10-112: Novell Access Manager Arbitrary File Upload Remote Code Execution Vulnerability

Novell has issued an update to correct this vulnerability. More
details can be found at:

http://www.novell.com/support/php/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=7006255&amp;sliceId=1&amp;docTypeID=DT_TID_1_1&amp;dialogID=149517296&amp;stateId=0%200%20149513677,

-- Disclosure Timeline:
2009-12-10 - Vulnerability reported to vendor
2010-06-21 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:

ZDI-10-101: Apple Webkit SVG RadialGradiant Run-in Remote Code Execution Vulnerability

Apple has issued an update to correct this vulnerability. More
details can be found at:

http://support.apple.com/kb/HT4196

-- Disclosure Timeline:
2010-05-03 - Vulnerability reported to vendor
2010-06-08 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:

ZDI-10-094: Apple Webkit SelectionController via Marquee Event Remote Code Execution Vulnerability

Apple has issued an update to correct this vulnerability. More
details can be found at:

http://support.apple.com/kb/HT4196

-- Disclosure Timeline:
2010-02-23 - Vulnerability reported to vendor
2010-06-08 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:

ZDI-10-089: Adobe Shockwave Director PAMI Chunk Remote Code Execution Vulnerability

Adobe has issued an update to correct this vulnerability. More
details can be found at:

http://www.adobe.com/support/security/bulletins/apsb10-12.html

-- Disclosure Timeline:
2010-04-08 - Vulnerability reported to vendor
2010-05-11 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:

ZDI-10-053: Sun Java Runtime Environment MIDI File metaEvent Remote Code Execution Vulnerability

Sun Microsystems has issued an update to correct this vulnerability. More
details can be found at:

http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html

-- Disclosure Timeline:
2009-12-10 - Vulnerability reported to vendor
2010-04-05 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:

ZDI-10-095: Apple Webkit DOCUMENT_POSITION_DISCONNECTED Attribute Remote Code Execution Vulnerability

Apple has issued an update to correct this vulnerability. More
details can be found at:

http://support.apple.com/kb/HT4196

-- Disclosure Timeline:
2009-12-04 - Vulnerability reported to vendor
2010-06-08 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:

ZDI-10-035: Apple QuickTime genl Atom Remote Code Execution Vulnerability

by a set of nested loops which can result in arbitrary code execution. 

-- Vendor Response:


-- Disclosure Timeline:
2009-03-26 - Vulnerability reported to vendor
2010-04-02 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:

ZDI-10-031: Apple Webkit Blink Event Dangling Pointer Remote Code Execution Vulnerability

Apple has issued an update to correct this vulnerability. More
details can be found at:

http://support.apple.com/kb/HT4070

-- Disclosure Timeline:
2009-10-27 - Vulnerability reported to vendor
2010-03-16 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:

ZDI-10-032: SAP MaxDB Malformed Handshake Request Remote Code Execution Vulnerability

-- Vendor Response:
SAP states:
A solution was provided via SAP note 1409425
(https://service.sap.com/sap/support/notes/1409425)

-- Disclosure Timeline:
2009-11-09 - Vulnerability reported to vendor
2010-03-16 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:

ZDI-10-098: Apple Webkit First-Letter Pseudo-Element Style Remote Code Execution Vulnerability

Apple has issued an update to correct this vulnerability. More
details can be found at:

http://support.apple.com/kb/HT4196

-- Disclosure Timeline:
2010-02-23 - Vulnerability reported to vendor
2010-06-08 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:

ZDI-10-022: IBM Informix librpc.dll Multiple Remote Code Execution Vulnerabilities

http://www-933.ibm.com/support/fixcentral/
APAR URLs 
 http://www.ibm.com/support/docview.wss?uid=swg1IC55329
 http://www.ibm.com/support/docview.wss?uid=swg1IC55330

-- Disclosure Timeline:
2008-02-07 - Vulnerability reported to vendor
2010-03-01 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:

ZDI-10-043: Apple QuickTime FlashPix NumberOfTiles Remote Code Execution Vulnerability

Apple has issued an update to correct this vulnerability. More
details can be found at:

http://support.apple.com/kb/HT4104

-- Disclosure Timeline:
2009-10-27 - Vulnerability reported to vendor
2010-04-02 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:

ZDI-10-065: CA XOsoft xosoapapi.asmx Multiple Remote Code Execution Vulnerabilities

Computer Associates has issued an update to correct this vulnerability. More
details can be found at:

https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=232869

-- Disclosure Timeline:
2009-12-16 - Vulnerability reported to vendor
2010-04-06 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!