.:[ packet storm ]:.
                             
digital honesty
digital honesty

 Section:  .. / 0804-advisories  /

Page 25 of 25
<< 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 >> Files 600 - 608 of 608
Currently sorted by: File NameSort By: Last Modified, File Size

 ///  File Name: ZDI-08-015.txt
Description:
A vulnerability allows attackers to execute arbitrary code on vulnerable installations of Apple QuickTime Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the quicktime.qts library. The vulnerability resides in the component's parsing of 'crgn' atoms. A lack of proper sanity checks on the region size field can result in a heap based buffer overflow leading to arbitrary code execution under the context of the currently logged in user. Version 7.4.1 is affected.
Author:Sanbin Li
Homepage:http://www.zerodayinitiative.com/
File Size:3223
Related CVE(s):CVE-2008-1017
Last Modified:Apr 4 19:47:18 2008
MD5 Checksum:9c6642a80f757742c14a9e01a910ccbf

 ///  File Name: ZDI-08-016.txt
Description:
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists in the parsing of the QuickTime Channel Compositor atom. When the movie file contains a malformed 'chan' atom, a heap corruption occurs resulting in the execution of arbitrary code. Version 7.4.1 is affected.
Homepage:http://www.zerodayinitiative.com/
File Size:3095
Related CVE(s):CVE-2008-1018
Last Modified:Apr 4 19:48:34 2008
MD5 Checksum:ce95497bee97f6b5779de8557aa8055e

 ///  File Name: ZDI-08-017.txt
Description:
A vulnerability allows attackers to execute arbitrary code on vulnerable installations of Apple QuickTime Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the quicktime.qts library responsible for parsing Kodak encoded images. A lack of proper error checking can result in a heap based buffer overflow leading to arbitrary code execution under the context of the currently logged in user. Version 7.4.1 is affected.
Author:Ruben Santamarta
Homepage:http://www.zerodayinitiative.com/
File Size:2935
Related CVE(s):CVE-2008-1020
Last Modified:Apr 4 19:49:41 2008
MD5 Checksum:71f08357b01b38db42fb821eaa3dce66

 ///  File Name: ZDI-08-018.txt
Description:
A vulnerability allows attackers to execute arbitrary code on vulnerable installations of Apple QuickTime Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of QuickTime files that utilize the Animation codec. A lack of proper length checks can result in a heap based buffer overflow leading to arbitrary code execution under the context of the currently logged in user. Version 7.4.1 is affected.
Homepage:http://www.zerodayinitiative.com/
File Size:3171
Related CVE(s):CVE-2008-1021
Last Modified:Apr 4 19:51:11 2008
MD5 Checksum:fe8354f74872ddc5dccc2455a6d692b7

 ///  File Name: ZDI-08-019.txt
Description:
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must open a malicious file. The specific flaw exists in the parsing of the QuickTime VR 'obji' atom. When the size of the atom is set to 0, a stack overflow condition occurs resulting in the execution of arbitrary code. Version 7.4.1 is affected.
Homepage:http://www.zerodayinitiative.com/
File Size:3094
Related CVE(s):CVE-2008-1022
Last Modified:Apr 4 19:53:54 2008
MD5 Checksum:415cd4d63c1fe26974238ae00be12600

 ///  File Name: ZDI-08-020.txt
Description:
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. User interaction is required in that a user must open a malicious file or visit a malicious web page. The specific flaw exists within the parsing of malformed WMF files. A vulnerability exists in the GDI function CreateDIBPatternBrushPt used when processing WMF files. Due to a mis-calculation of user data a heap chunk can be under-allocated and later used resulting in a heap overflow. Successful exploitation can result in system compromise under the credentials of the currently logged in user.
Homepage:http://www.zerodayinitiative.com/
File Size:3067
Related CVE(s):CVE-2008-1083
Last Modified:Apr 8 23:37:34 2008
MD5 Checksum:13384b757b12fe9e07c41b89de003d0d

 ///  File Name: ZDI-08-021.txt
Description:
A vulnerability allows remote attackers to execute code on vulnerable installations of Adobe's Flash Player. User interaction is required in that a user must visit a malicious web site. The specific flaw exists when the Flash player attempts to access embedded Actionscript objects that have not been properly instantiated. In order for exploitation to occur, an attacker would have to modify a DeclareFunction2 Actionscript tag within an SWF file. Exploitation of this vulnerability can result in arbitrary code execution under the context of the currently logged in user.
Homepage:http://www.zerodayinitiative.com/
File Size:3273
Related CVE(s):CVE-2007-6019
Last Modified:Apr 8 23:38:14 2008
MD5 Checksum:1c08f7fa969eb04fa424f7f014901bb5

 ///  File Name: ZDI-08-022.txt
Description:
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Safari. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists in the regular expression compiler (JavaScriptCore/pcre/pcre_compile.cpp) in WebKit. When nesting regular expressions with large repetitions, a heap overflow occurs resulting in a condition allowing the execution of arbitrary code.
Homepage:http://www.zerodayinitiative.com/
File Size:3372
Related CVE(s):CVE-2008-1026
Last Modified:Apr 16 18:08:34 2008
MD5 Checksum:8c59082cde3c46c9f1624a17dd595252