<![CDATA[ZDI: Published Advisories]]> http://www.zerodayinitiative.com/advisories/published/ Sat Jul 4 05:54:49 2009 +0000 zdi@tippingpoint.com (Author) Tippingpoint, all rights reserved ZDI Bird Feeder en http://blogs.law.harvard.edu/tech/rss <![CDATA[ZDI-09-044: Adobe Shockwave Player Director File Parsing Pointer Overwrite Vulnerability]]> http://feedproxy.google.com/~r/ZDI-Published-Advisories/~3/xbPcayWY_Eo/ This vulnerability allows remote attackers to execute code on vulnerable installations of Adobe&#39;s Shockwave Player. User interaction is required in that a user must visit a malicious web site.<img src="http://feeds.feedburner.com/~r/ZDI-Published-Advisories/~4/xbPcayWY_Eo" height="1" width="1"/> Wed, 24 Jun 2009 12:00:00 +0000 http://www.zerodayinitiative.com/advisories/ZDI-09-044/ <![CDATA[ZDI-09-043: Apple Java CColourUIResource Pointer Dereference Code Execution Vulnerability]]> http://feedproxy.google.com/~r/ZDI-Published-Advisories/~3/RIpdZWoRJXU/ his vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Java HotSpot. User interaction is required to exploit this vulnerability in that the target must visit a malicious page.<img src="http://feeds.feedburner.com/~r/ZDI-Published-Advisories/~4/RIpdZWoRJXU" height="1" width="1"/> Tue, 16 Jun 2009 12:00:00 +0000 http://www.zerodayinitiative.com/advisories/ZDI-09-043/ <![CDATA[ZDI-09-042: Adobe Reader U3D RHAdobeMeta Stack Overflow Vulnerability]]> http://feedproxy.google.com/~r/ZDI-Published-Advisories/~3/QXGCdkwixkE/ This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Acrobat and Adobe Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious web address or open a malicious file.<img src="http://feeds.feedburner.com/~r/ZDI-Published-Advisories/~4/QXGCdkwixkE" height="1" width="1"/> Wed, 10 Jun 2009 12:00:00 +0000 http://www.zerodayinitiative.com/advisories/ZDI-09-042/ <![CDATA[ZDI-09-041: Microsoft Internet Explorer 8 Rows Property Dangling Pointer Code Execution Vulnerability]]> http://feedproxy.google.com/~r/ZDI-Published-Advisories/~3/bMfD-RN9xqI/ This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer 8. User interaction is required to exploit this vulnerability in that the target must visit a malicious page.<img src="http://feeds.feedburner.com/~r/ZDI-Published-Advisories/~4/bMfD-RN9xqI" height="1" width="1"/> Wed, 10 Jun 2009 12:00:00 +0000 http://www.zerodayinitiative.com/advisories/ZDI-09-041/ <![CDATA[ZDI-09-040: Microsoft Office Excel QSIR Record Pointer Corruption Vulnerability]]> http://feedproxy.google.com/~r/ZDI-Published-Advisories/~3/htu0AYSYvig/ This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office Excel. Exploitation requires user interaction in that a victim must open a malicious XLS file.<img src="http://feeds.feedburner.com/~r/ZDI-Published-Advisories/~4/htu0AYSYvig" height="1" width="1"/> Wed, 10 Jun 2009 12:00:00 +0000 http://www.zerodayinitiative.com/advisories/ZDI-09-040/ <![CDATA[ZDI-09-039: Microsoft Internet Explorer onreadystatechange Memory Corruption Vulnerability]]> http://feedproxy.google.com/~r/ZDI-Published-Advisories/~3/LcaIK1NYA8o/ This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page.<img src="http://feeds.feedburner.com/~r/ZDI-Published-Advisories/~4/LcaIK1NYA8o" height="1" width="1"/> Wed, 10 Jun 2009 12:00:00 +0000 http://www.zerodayinitiative.com/advisories/ZDI-09-039/ <![CDATA[ZDI-09-038: Microsoft Internet Explorer Event Handler Memory Corruption Vulnerability]]> http://feedproxy.google.com/~r/ZDI-Published-Advisories/~3/liFp6nH_2kE/ This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page.<img src="http://feeds.feedburner.com/~r/ZDI-Published-Advisories/~4/liFp6nH_2kE" height="1" width="1"/> Wed, 10 Jun 2009 12:00:00 +0000 http://www.zerodayinitiative.com/advisories/ZDI-09-038/ <![CDATA[ZDI-09-037: Microsoft Internet Explorer Concurrent Ajax Request Memory Corruption Vulnerability]]> http://feedproxy.google.com/~r/ZDI-Published-Advisories/~3/MeFRkK0g_0M/ This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page.<img src="http://feeds.feedburner.com/~r/ZDI-Published-Advisories/~4/MeFRkK0g_0M" height="1" width="1"/> Wed, 10 Jun 2009 12:00:00 +0000 http://www.zerodayinitiative.com/advisories/ZDI-09-037/ <![CDATA[ZDI-09-036: Microsoft Internet Explorer setCapture Memory Corruption Vulnerability]]> http://feedproxy.google.com/~r/ZDI-Published-Advisories/~3/ZjhW16FtMNY/ This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page.<img src="http://feeds.feedburner.com/~r/ZDI-Published-Advisories/~4/ZjhW16FtMNY" height="1" width="1"/> Wed, 10 Jun 2009 12:00:00 +0000 http://www.zerodayinitiative.com/advisories/ZDI-09-036/ <![CDATA[ZDI-09-035: Microsoft Word Document Stack Based Buffer Overflow Vulnerability]]> http://feedproxy.google.com/~r/ZDI-Published-Advisories/~3/-fIv0K_WoB8/ This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Word. User interaction is required to exploit this vulnerability in that the target must visit a malicious page, open a malicious e-mail, or open a malicious file.<img src="http://feeds.feedburner.com/~r/ZDI-Published-Advisories/~4/-fIv0K_WoB8" height="1" width="1"/> Wed, 10 Jun 2009 12:00:00 +0000 http://www.zerodayinitiative.com/advisories/ZDI-09-035/