Real/Time Information
Cisco Unified Communications Manager (CUCM), formerly Cisco
CallManager, contains a denial of service (DoS) vulnerability in the
Computer Telephony Integration (CTI) Manager service that may cause
an interruption in voice services and an authentication bypass
vulnerability in the Real-Time Information Server (RIS) Data
Collector that may expose information that is useful for
reconnaissance.
Cisco has released free software updates that address these
vulnerabilities. There are no workarounds for these vulnerabilities.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
ZDI-12-148 : GE Proficy Real-Time Information Portal Remote Interface
Service Remote Code Execution Vulnerability
http://www.zerodayinitiative.com/advisories/ZDI-12-148
August 22, 2012
- -- CVE ID:
CVE-2012-0232
ZDI-11-120: Microsoft Office Excel RealTimeData Record Parsing Remote Code Execution Vulnerability
http://www.zerodayinitiative.com/advisories/ZDI-11-120
April 12, 2011
-- CVE ID:
CVE-2011-0101
-- CVSS:
VUPEN Security Research - Microsoft Office Excel RealTimeData Array Indexing
Vulnerability (CVE-2010-3240)
http://www.vupen.com/english/research.php
I. BACKGROUND
---------------------
Microsoft Office Excel is a powerful tool you can use to create and
- Database security & attacks
- Advanced Trojans, worms and backdoor technique
--- Intrusion detection/forensics analysis
- Traffic analysis
- Real-time data structure recovery
- File system analysis & recovery
- Intrusion detection and anti-detection technique
- Reverse engineering (malicious code analysis technique, vulnerability research)
> - Advanced Trojans, worms and backdoor technique
> - Encryption & decryption technique
>
> --- Intrusion detection/forensics analysis
> - File system analysis & recovery
> - Real-time data structure recovery
> - Reverse engineering (malicious code analysis technique,
> vulnerability research)
> - Traffic analysis
> - Intrusion detection and anti-detection technique
>
- Encryption & decryption technique
- Routing device
--- Intrusion detection/forensics analysis
- File system analysis & recovery
- Real-time data structure recovery
- Reverse engineering (malicious code analysis technique, vulnerability research)
- Intrusion detection and anti-detection technique
- Traffic analysis
--- Wireless & VoIP security
>> - Advanced Trojans, worms and backdoor technique
>> - Encryption & decryption technique
>>
>> --- Intrusion detection/forensics analysis
>> - File system analysis & recovery
>> - Real-time data structure recovery
>> - Reverse engineering (malicious code analysis technique,
>> vulnerability research)
>> - Traffic analysis
>> - Intrusion detection and anti-detection technique
>>
- Encryption & decryption technique
- Routing device
--- Intrusion detection/forensics analysis
- File system analysis & recovery
- Real-time data structure recovery
- Reverse engineering (malicious code analysis technique, vulnerability research)
- Intrusion detection and anti-detection technique
- Traffic analysis
--- Wireless & VoIP security
- Encryption & decryption technique
- Routing device
--- Intrusion detection/forensics analysis
- File system analysis & recovery
- Real-time data structure recovery
- Reverse engineering (malicious code analysis technique, vulnerability research)
- Intrusion detection and anti-detection technique
- Traffic analysis
--- Wireless & VoIP security
- Advanced Trojans, worms and backdoor technique
- Encryption & decryption technique
--- Intrusion detection/forensics analysis
- File system analysis & recovery
- Real-time data structure recovery
- Reverse engineering (malicious code analysis technique,
vulnerability research)
- Traffic analysis
- Intrusion detection and anti-detection technique
VUPEN Security Research - Microsoft Office Excel Real Time Data Stack
Overwrite Vulnerability (CVE-2011-0105)
http://www.vupen.com/english/research.php
I. BACKGROUND
---------------------
"Microsoft Office Excel is a powerful tool you can use to create and format
- Encryption & decryption technique
- Routing device
--- Intrusion detection/forensics analysis
- File system analysis & recovery
- Real-time data structure recovery
- Reverse engineering (malicious code analysis technique, vulnerability research)
- Intrusion detection and anti-detection technique
- Traffic analysis
--- Wireless & VoIP security
|