«
Expand/Collapse
371 items tagged "heap"
Related tags:
integer [+],
denial of service [+],
corruption [+],
arbitrary code execution [+],
winamp [+],
usa [+],
jasper [+],
windows [+],
reader [+],
player [+],
overflows [+],
microsoft [+],
kingview [+],
integer overflow [+],
heap corruption [+],
zip file [+],
winamp versions [+],
novell [+],
linux [+],
idefense [+],
exploits [+],
buffer overflow vulnerability [+],
overflow [+],
xchat [+],
vulnerability [+],
reflection [+],
qcp [+],
libcgroup [+],
attachmate [+],
afm [+],
zip [+],
understanding [+],
uipc [+],
tiff image [+],
scada [+],
paper [+],
ntp [+],
javascript [+],
handling [+],
freebsd [+],
font [+],
firefox [+],
feng shui [+],
evince [+],
david litchfield [+],
code execution [+],
clickunzip [+],
apple mac os [+],
alexander sotirov [+],
adobe acrobat [+],
acrobat [+],
zipper [+],
zipitfast [+],
xnview [+],
xendesktop [+],
xenapp [+],
vallen [+],
usbmuxd [+],
truetype [+],
traversal [+],
time zone name [+],
tif [+],
thundercode [+],
system heap [+],
system [+],
strategic [+],
stack overflows [+],
socket [+],
skinny channel [+],
server [+],
safer use [+],
read [+],
query [+],
qcp file [+],
pivot [+],
php [+],
photoshop [+],
phar [+],
personal edition [+],
personal [+],
oracle hyperion [+],
oracle [+],
objects [+],
novell groupwise [+],
net [+],
movicon [+],
microsoft windows server [+],
microsoft reader [+],
metaserver rt [+],
metaserver [+],
memory leak [+],
memory copy [+],
libzip [+],
libusbmuxd [+],
libtiff [+],
kernel panic [+],
java runtime environment [+],
intuit [+],
integer overflow vulnerability [+],
information leak [+],
image [+],
hyperion [+],
hmi [+],
groupwise [+],
gimp [+],
gif [+],
ghostscript [+],
ftp [+],
framework [+],
frame size [+],
extension [+],
execution [+],
exe version [+],
eviews [+],
dos [+],
directory traversal vulnerability [+],
directory [+],
decoder [+],
data frame [+],
data execution prevention [+],
cups [+],
crash proof [+],
corruption issues [+],
code [+],
citrix xml service [+],
chunk [+],
c heap [+],
bytecode [+],
avira [+],
authors [+],
apclient [+],
antivir [+],
annotation [+],
alarmpoint [+],
adobe photoshop [+],
overflow vulnerability [+],
x tiff image [+],
whitepaper [+],
weakness [+],
tor unspecified [+],
tim shelton tags [+],
taichi [+],
spray [+],
shockwave [+],
realnetworks [+],
proxy [+],
presto [+],
powerhmi [+],
portuguese [+],
persistent data [+],
pe explorer [+],
pdf [+],
pcx image [+],
pcx [+],
pagemanager [+],
overflow error [+],
nppftp [+],
notepad [+],
nginx [+],
multiple products [+],
mozilla firefox [+],
memory allocator [+],
memory allocation [+],
linux kernel [+],
kernel [+],
justin ferguson tags [+],
justin ferguson [+],
ibm [+],
heap allocations [+],
hdtv [+],
hat europe [+],
granularity [+],
getarena [+],
genstat [+],
f secure [+],
explorer 1 [+],
explorer [+],
exploiting [+],
exploitation techniques [+],
exploitation methods [+],
exploitation [+],
expert [+],
europe [+],
driver [+],
data structure [+],
cvs [+],
chaos communication congress [+],
bugtraq [+],
blazevideo [+],
attack [+],
asterisk [+],
array [+],
analyzer [+],
aix operating system [+],
aix [+],
adobe shockwave player [+],
activex [+],
abcm [+],
proof of concept [+],
based buffer overflow [+],
xls [+],
x imageio [+],
windows common control [+],
wincc [+],
winamp 5 [+],
wellintech [+],
webapps [+],
web player [+],
vlc [+],
vista [+],
unity [+],
tor socks connection [+],
tiff integer [+],
temperature logger [+],
temperature [+],
stts [+],
smashing [+],
simatic [+],
siemens simatic [+],
siemens [+],
resolver [+],
regular expression [+],
real networks [+],
real [+],
python [+],
pyfribidi [+],
psp image [+],
psp [+],
plugin [+],
player versions [+],
pcre [+],
openoffice [+],
notes [+],
networks [+],
ms windows [+],
mozilla [+],
midioutplaynextpolyevent [+],
midi [+],
media [+],
marinescu [+],
maradns [+],
lotus [+],
local [+],
kvwebsvr [+],
irfanview [+],
inspircd [+],
information store [+],
imageio [+],
historyserver [+],
heap management [+],
hash [+],
hacks [+],
getbandproctiff [+],
fribidi [+],
flv [+],
flashpix [+],
flash [+],
expression [+],
exploit [+],
exe [+],
excel [+],
essentials [+],
driver ast [+],
dns [+],
dlabel [+],
day [+],
damn [+],
d web [+],
compost pile [+],
compost heap [+],
compost [+],
common control library [+],
common [+],
chemistry [+],
calculator version [+],
calculator [+],
burning [+],
buffer overflow [+],
bsd [+],
avs [+],
atoms [+],
ashampoo burning studio [+],
ashampoo [+],
apple safari [+],
apple quicktime [+],
apple mac os x [+],
apple coregraphics [+],
adrian marinescu [+],
adobe flash player [+],
activex control [+],
buffer [+],
memory [+],
memory corruption [+],
realplayer [+],
poc [+],
idefense security advisory [+],
remote [+],
multiple [+],
black hat [+],
heap memory [+],
buffer overflow vulnerabilities [+],
adobe [+],
xterm,
xpdf,
word,
windows movie maker,
wav,
vulnerability research,
vmware products,
vmware,
video,
vendor,
vault,
ubuntu,
txt,
triologic,
tooltalk,
tag,
system versions,
symbol dictionary,
sybase,
ssl certificate,
ssl,
split,
solaris,
slideshow,
sip,
shop,
sfcb,
sblim,
rspmp,
rsp,
rle,
repeat,
rendering,
record,
realmedia,
reader v3,
rcs,
quicktime pict,
processing,
powerpoint,
point,
pls,
pict,
pdf reader software,
patent claims,
paint shop,
paint,
owl,
overflow errors,
outlook,
otsav,
opiereadrec,
opie,
online,
ogg,
ofl,
offset,
office,
ocx,
norex,
netstorage,
mp3 player,
movie,
mov,
mod,
moaub,
microsoft windows defender,
microsoft security bulletin,
microsoft producer,
microsoft powerpoint,
microsoft outlook,
microsoft excel,
microsoft corp,
messenger,
message,
mdxtuple,
mdxset,
mbm,
mandriva,
maker,
m3u file,
m3u,
live,
lite,
liquidxml,
linkedslideatom,
libhx,
li guillaume lovet,
legend,
kernel stack,
jbig,
ingres database,
ingres,
ica,
ibm db2,
hosted,
hextile,
gnu,
ftp client,
fss,
freetype,
foxit,
floating point conversion,
flash slideshow maker,
flare,
file vault,
file,
fetchmail,
engine position,
engine,
encoded,
dos vulnerability,
dll,
dj legend,
defender,
database,
data architect,
daemon,
cve,
critical vulnerability,
corel,
converter,
control,
client,
classic,
citrix ica client,
citrix ica,
citrix,
cinepak codec,
cinepak,
certificate,
call,
bugs microsoft,
buffer overflows,
bigant,
ben hawkes,
barnowl,
barcode,
audio converter,
audio,
argument,
arbitrary code,
aol,
advantage,
advanced,
active x,
acoustica
-
-
21:37
»
SecDocs
Authors:
Julien Vanegue Tags:
heap overflow heap Event:
Chaos Communication Congress 27th (27C3) 2010 Abstract: The dynamic memory allocator is a fundamental component of modern operating systems, and one of the most important sources of security vulnerabilities. In this presentation, we emphasize on a particular weakness of the heap management that has proven to be the root cause of many escalation of privilege bugs in the windows kernel and other critical remote vulnerabilities in user-land applications. The problem is not specific to any operating system and is present in both user-land and kernel-land allocators. The presentation is divided into three parts. First, we will reveal the exact nature of the weakness and provide a taxonomy of all tested operating systems (both in the Windows and UNIX world, most of them are exposed). We then present a custom static analyzer for this class of defects based on the HAVOC framework, a heap-aware verifier for C programs, developed in the RISE team at Microsoft Research. We have deployed the analyzer on multiple kernel components, some of them reaching one million lines of C code. The analyzer produces a reasonable amount of warnings without any complex configuration. Finally, we generalize our analysis technique by characterizing what happens when the size of heap chunks is in the neighbourhood of zero (e.g. near-zero allocations) and give another example of fixed remote bug. We emphasize that this weakness should not be considered as a new class of vulnerabilities (such as buffer overflow), but rather a new type of code defect in the same style as integer overflows, as many occurrences are legit and do not lead to a bug.
-
21:37
»
SecDocs
Authors:
Julien Vanegue Tags:
heap overflow heap Event:
Chaos Communication Congress 27th (27C3) 2010 Abstract: The dynamic memory allocator is a fundamental component of modern operating systems, and one of the most important sources of security vulnerabilities. In this presentation, we emphasize on a particular weakness of the heap management that has proven to be the root cause of many escalation of privilege bugs in the windows kernel and other critical remote vulnerabilities in user-land applications. The problem is not specific to any operating system and is present in both user-land and kernel-land allocators. The presentation is divided into three parts. First, we will reveal the exact nature of the weakness and provide a taxonomy of all tested operating systems (both in the Windows and UNIX world, most of them are exposed). We then present a custom static analyzer for this class of defects based on the HAVOC framework, a heap-aware verifier for C programs, developed in the RISE team at Microsoft Research. We have deployed the analyzer on multiple kernel components, some of them reaching one million lines of C code. The analyzer produces a reasonable amount of warnings without any complex configuration. Finally, we generalize our analysis technique by characterizing what happens when the size of heap chunks is in the neighbourhood of zero (e.g. near-zero allocations) and give another example of fixed remote bug. We emphasize that this weakness should not be considered as a new class of vulnerabilities (such as buffer overflow), but rather a new type of code defect in the same style as integer overflows, as many occurrences are legit and do not lead to a bug.
-
13:42
»
Packet Storm Security Exploits
An integer overflow vulnerability has been discovered in the EncoderParameter class of the .NET Framework. Exploiting this vulnerability results in an overflown integer that is used to allocate a buffer on the heap. After the incorrect allocation, one or more user-supplied buffers are copied in the new buffer, resulting in a corruption of the heap.
-
13:42
»
Packet Storm Security Recent Files
An integer overflow vulnerability has been discovered in the EncoderParameter class of the .NET Framework. Exploiting this vulnerability results in an overflown integer that is used to allocate a buffer on the heap. After the incorrect allocation, one or more user-supplied buffers are copied in the new buffer, resulting in a corruption of the heap.
-
13:42
»
Packet Storm Security Misc. Files
An integer overflow vulnerability has been discovered in the EncoderParameter class of the .NET Framework. Exploiting this vulnerability results in an overflown integer that is used to allocate a buffer on the heap. After the incorrect allocation, one or more user-supplied buffers are copied in the new buffer, resulting in a corruption of the heap.
-
-
15:12
»
Packet Storm Security Exploits
This Metasploit module exploits an uninitialized variable vulnerability in the Annotation Objects ActiveX component. The activeX component loads into memory without opting into ALSR so this module exploits the vulnerability against windows Vista and Windows 7 targets. A large heap spray is required to fulfill the requirement that EAX points to part of the ROP chain in a heap chunk and the calculated call will hit the pivot in a separate heap chunk. This will take some time in the users browser.
-
15:12
»
Packet Storm Security Recent Files
This Metasploit module exploits an uninitialized variable vulnerability in the Annotation Objects ActiveX component. The activeX component loads into memory without opting into ALSR so this module exploits the vulnerability against windows Vista and Windows 7 targets. A large heap spray is required to fulfill the requirement that EAX points to part of the ROP chain in a heap chunk and the calculated call will hit the pivot in a separate heap chunk. This will take some time in the users browser.
-
15:12
»
Packet Storm Security Misc. Files
This Metasploit module exploits an uninitialized variable vulnerability in the Annotation Objects ActiveX component. The activeX component loads into memory without opting into ALSR so this module exploits the vulnerability against windows Vista and Windows 7 targets. A large heap spray is required to fulfill the requirement that EAX points to part of the ROP chain in a heap chunk and the calculated call will hit the pivot in a separate heap chunk. This will take some time in the users browser.
-
-
20:23
»
Packet Storm Security Exploits
Presto! PageManager versions 9.01 and below suffer from heap overflow, arbitrary file downloading, and denial of service vulnerabilities.
-
-
16:45
»
Packet Storm Security Exploits
This Metasploit module exploits a heap overflow vulnerability in the Windows Multimedia Library (winmm.dll). The vulnerability occurs when parsing specially crafted MIDI files. Remote code execution can be achieved by using Windows Media Player's ActiveX control. Exploitation is done by supplying a specially crafted MIDI file with specific events, causing the offset calculation being higher than how much is available on the heap (0x400 allocated by WINMM!winmmAlloc), and then allowing us to either "inc al" or "dec al" a byte. This can be used to corrupt an array (CImplAry) we setup, and force the browser to confuse types from tagVARIANT objects, which leverages remote code execution under the context of the user. At this time, for IE 8 target, JRE (Java Runtime Environment) is required to bypass DEP (Data Execution Prevention). Note: Based on our testing, the vulnerability does not seem to trigger when the victim machine is operated via rdesktop.
-
16:45
»
Packet Storm Security Recent Files
This Metasploit module exploits a heap overflow vulnerability in the Windows Multimedia Library (winmm.dll). The vulnerability occurs when parsing specially crafted MIDI files. Remote code execution can be achieved by using Windows Media Player's ActiveX control. Exploitation is done by supplying a specially crafted MIDI file with specific events, causing the offset calculation being higher than how much is available on the heap (0x400 allocated by WINMM!winmmAlloc), and then allowing us to either "inc al" or "dec al" a byte. This can be used to corrupt an array (CImplAry) we setup, and force the browser to confuse types from tagVARIANT objects, which leverages remote code execution under the context of the user. At this time, for IE 8 target, JRE (Java Runtime Environment) is required to bypass DEP (Data Execution Prevention). Note: Based on our testing, the vulnerability does not seem to trigger when the victim machine is operated via rdesktop.
-
16:45
»
Packet Storm Security Misc. Files
This Metasploit module exploits a heap overflow vulnerability in the Windows Multimedia Library (winmm.dll). The vulnerability occurs when parsing specially crafted MIDI files. Remote code execution can be achieved by using Windows Media Player's ActiveX control. Exploitation is done by supplying a specially crafted MIDI file with specific events, causing the offset calculation being higher than how much is available on the heap (0x400 allocated by WINMM!winmmAlloc), and then allowing us to either "inc al" or "dec al" a byte. This can be used to corrupt an array (CImplAry) we setup, and force the browser to confuse types from tagVARIANT objects, which leverages remote code execution under the context of the user. At this time, for IE 8 target, JRE (Java Runtime Environment) is required to bypass DEP (Data Execution Prevention). Note: Based on our testing, the vulnerability does not seem to trigger when the victim machine is operated via rdesktop.
-
-
7:34
»
Packet Storm Security Exploits
Oracle Hyperion Strategic Finance client version 12.x Tidestone Formula One workbook OLE control TTF16 (6.3.5 Build 1) SetDevNames() remote heap overflow exploit.
-
7:34
»
Packet Storm Security Recent Files
Oracle Hyperion Strategic Finance client version 12.x Tidestone Formula One workbook OLE control TTF16 (6.3.5 Build 1) SetDevNames() remote heap overflow exploit.
-
7:34
»
Packet Storm Security Misc. Files
Oracle Hyperion Strategic Finance client version 12.x Tidestone Formula One workbook OLE control TTF16 (6.3.5 Build 1) SetDevNames() remote heap overflow exploit.
-
-
6:39
»
Packet Storm Security Exploits
GenStat versions 14.1.0.5943 and below suffer from an array overflow with write2 and a heap overflow. Proof of concept code included.
-
-
15:34
»
Packet Storm Security Advisories
iDefense Security Advisory 09.26.11 - Remote exploitation of a heap overflow vulnerability in Novell Inc.'s GroupWise could allow an attacker to execute arbitrary code with the privileges of the affected service. This vulnerability is present in the calendar processing code, which resides within the GroupWise Internet Agent (GWIA) process. The vulnerability occurs when parsing a malformed calendar recurrence (RRULE) that recurs on weekdays. A heap based buffer overflow can be triggered due to the lack of checks to ensure that there is enough space in the buffer to hold all of the RRULE entry data. Novell GroupWise 8.0x up to (and including) 8.02HP2 are vulnerable.
-
15:34
»
Packet Storm Security Recent Files
iDefense Security Advisory 09.26.11 - Remote exploitation of a heap overflow vulnerability in Novell Inc.'s GroupWise could allow an attacker to execute arbitrary code with the privileges of the affected service. This vulnerability is present in the calendar processing code, which resides within the GroupWise Internet Agent (GWIA) process. The vulnerability occurs when parsing a malformed calendar recurrence (RRULE) that recurs on weekdays. A heap based buffer overflow can be triggered due to the lack of checks to ensure that there is enough space in the buffer to hold all of the RRULE entry data. Novell GroupWise 8.0x up to (and including) 8.02HP2 are vulnerable.
-
15:34
»
Packet Storm Security Misc. Files
iDefense Security Advisory 09.26.11 - Remote exploitation of a heap overflow vulnerability in Novell Inc.'s GroupWise could allow an attacker to execute arbitrary code with the privileges of the affected service. This vulnerability is present in the calendar processing code, which resides within the GroupWise Internet Agent (GWIA) process. The vulnerability occurs when parsing a malformed calendar recurrence (RRULE) that recurs on weekdays. A heap based buffer overflow can be triggered due to the lack of checks to ensure that there is enough space in the buffer to hold all of the RRULE entry data. Novell GroupWise 8.0x up to (and including) 8.02HP2 are vulnerable.
-
6:25
»
Packet Storm Security Advisories
iDefense Security Advisory 09.26.11 - Remote exploitation of a heap overflow vulnerability in Novell Inc.'s GroupWise could allow an attacker to execute arbitrary code with the privileges of the affected service. This vulnerability is present in the calendar processing code, which resides within the GroupWise Internet Agent (GWIA) process. The vulnerability occurs when parsing a malformed time zone description field (TZNAME). A heap based buffer overflow can be triggered by supplying an excessively long string when copying the time zone name. Novell GroupWise 8.0x up to (and including) 8.02HP2 are vulnerable.
-
6:25
»
Packet Storm Security Recent Files
iDefense Security Advisory 09.26.11 - Remote exploitation of a heap overflow vulnerability in Novell Inc.'s GroupWise could allow an attacker to execute arbitrary code with the privileges of the affected service. This vulnerability is present in the calendar processing code, which resides within the GroupWise Internet Agent (GWIA) process. The vulnerability occurs when parsing a malformed time zone description field (TZNAME). A heap based buffer overflow can be triggered by supplying an excessively long string when copying the time zone name. Novell GroupWise 8.0x up to (and including) 8.02HP2 are vulnerable.
-
6:25
»
Packet Storm Security Misc. Files
iDefense Security Advisory 09.26.11 - Remote exploitation of a heap overflow vulnerability in Novell Inc.'s GroupWise could allow an attacker to execute arbitrary code with the privileges of the affected service. This vulnerability is present in the calendar processing code, which resides within the GroupWise Internet Agent (GWIA) process. The vulnerability occurs when parsing a malformed time zone description field (TZNAME). A heap based buffer overflow can be triggered by supplying an excessively long string when copying the time zone name. Novell GroupWise 8.0x up to (and including) 8.02HP2 are vulnerable.
-
-
13:44
»
SecDocs
Authors:
Tim Shelton Tags:
heap overflow heap AIX Event:
Black Hat USA 2010 Abstract: With the ever increasing importance of providing and maintaining reliable services for both infrastructure support as well as business continuity, companies rely upon the IBM AIX operating system. In most cases, these machines hold the most critical data available for their business which makes IBM AIX a highly valued target from a hacker’s perspective. Over the past decade, hackers have increasingly focused on infiltrating valuable data such as proprietary databases, credit information, product pricing information and more. As such, the importance of protecting the IBM AIX operating system should be priority one. Initial heap exploitation research was first documented and published by David Litchfield, in August of 2005. His paper entitled, ”An Introduction to Heap overflows on AIX 5.3L” focused on AIX heap abuse within the utilization of heap’s free()/rightmost() functions. While Litchfield’s method solves one scenario, there is an additional scenario that has been left out. So what is the difference between the leftmost call versus rightmost? A stack trace will show leftmost is utilized when a fresh heap segment is requested, while rightmost is utilized when the application requests the heap to remove a previously allocated chunk from memory.
-
13:44
»
SecDocs
Authors:
Tim Shelton Tags:
heap overflow heap AIX Event:
Black Hat USA 2010 Abstract: With the ever increasing importance of providing and maintaining reliable services for both infrastructure support as well as business continuity, companies rely upon the IBM AIX operating system. In most cases, these machines hold the most critical data available for their business which makes IBM AIX a highly valued target from a hacker’s perspective. Over the past decade, hackers have increasingly focused on infiltrating valuable data such as proprietary databases, credit information, product pricing information and more. As such, the importance of protecting the IBM AIX operating system should be priority one. Initial heap exploitation research was first documented and published by David Litchfield, in August of 2005. His paper entitled, ”An Introduction to Heap overflows on AIX 5.3L” focused on AIX heap abuse within the utilization of heap’s free()/rightmost() functions. While Litchfield’s method solves one scenario, there is an additional scenario that has been left out. So what is the difference between the leftmost call versus rightmost? A stack trace will show leftmost is utilized when a fresh heap segment is requested, while rightmost is utilized when the application requests the heap to remove a previously allocated chunk from memory.
-
-
12:12
»
Packet Storm Security Exploits
This Metasploit module exploits a heap overflow in Realplayer when handling a .QCP file. The specific flaw exists within qcpfformat.dll. A static 256 byte buffer is allocated on the heap and user-supplied data from the file is copied within a memory copy loop. This allows a remote attacker to execute arbitrary code running in the context of the web browser via a .QCP file with a specially crafted "fmt" chunk. At this moment this module exploits the flaw on Windows XP IE6, IE7.
-
12:12
»
Packet Storm Security Recent Files
This Metasploit module exploits a heap overflow in Realplayer when handling a .QCP file. The specific flaw exists within qcpfformat.dll. A static 256 byte buffer is allocated on the heap and user-supplied data from the file is copied within a memory copy loop. This allows a remote attacker to execute arbitrary code running in the context of the web browser via a .QCP file with a specially crafted "fmt" chunk. At this moment this module exploits the flaw on Windows XP IE6, IE7.
-
12:12
»
Packet Storm Security Misc. Files
This Metasploit module exploits a heap overflow in Realplayer when handling a .QCP file. The specific flaw exists within qcpfformat.dll. A static 256 byte buffer is allocated on the heap and user-supplied data from the file is copied within a memory copy loop. This allows a remote attacker to execute arbitrary code running in the context of the web browser via a .QCP file with a specially crafted "fmt" chunk. At this moment this module exploits the flaw on Windows XP IE6, IE7.
-
-
7:17
»
Packet Storm Security Advisories
Context discovered two memory corruption issues related to Firefox code that processes WebGL, that could result in remote code execution via a malicious web page. Heap overflows make use of the WebGL shader compiler and the ANGLE library. Versions 4.0.1 and 5 are affected.
-
7:17
»
Packet Storm Security Recent Files
Context discovered two memory corruption issues related to Firefox code that processes WebGL, that could result in remote code execution via a malicious web page. Heap overflows make use of the WebGL shader compiler and the ANGLE library. Versions 4.0.1 and 5 are affected.
-
7:17
»
Packet Storm Security Misc. Files
Context discovered two memory corruption issues related to Firefox code that processes WebGL, that could result in remote code execution via a malicious web page. Heap overflows make use of the WebGL shader compiler and the ANGLE library. Versions 4.0.1 and 5 are affected.
-
-
19:39
»
Packet Storm Security Exploits
A heap corruption vulnerability has been found in the Citrix XML Service of XenApp and XenDesktop which is installed on every server used for sharing applications. Successful exploitation allows arbitrary code execution on the server running the XML service.
-
19:39
»
Packet Storm Security Recent Files
A heap corruption vulnerability has been found in the Citrix XML Service of XenApp and XenDesktop which is installed on every server used for sharing applications. Successful exploitation allows arbitrary code execution on the server running the XML service.
-
19:39
»
Packet Storm Security Misc. Files
A heap corruption vulnerability has been found in the Citrix XML Service of XenApp and XenDesktop which is installed on every server used for sharing applications. Successful exploitation allows arbitrary code execution on the server running the XML service.
-
-
7:22
»
Packet Storm Security Advisories
A heap overflow is caused by a signedness vulnerability within copyImageBlockSetTiff(). The crash occurs within any application using the framework, including Preview, QuickLook, Safari and Mail.
-
-
6:14
»
Packet Storm Security Exploits
Winamp versions 5.61 and below suffer from multiple heap overflows and corruption and an integer overflow. Proof of concept code included.
-
-
20:59
»
SecuriTeam
Remote exploitation of a heap memory corruption vulnerability in Apple Inc.'s CoreGraphics.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
15:05
»
Packet Storm Security Recent Files
Whitepaper called Understanding the heap by breaking it. A case study of the heap as a persistent data structure through non-traditional exploitation techniques.
-
15:05
»
Packet Storm Security Misc. Files
Whitepaper called Understanding the heap by breaking it. A case study of the heap as a persistent data structure through non-traditional exploitation techniques.
-
-
10:58
»
Packet Storm Security Exploits
The PHP phar extension suffers from a heap overflow vulnerability. PHP version 5.3.6 is affected with phar extension version 1.1.1.
-
-
17:06
»
Packet Storm Security Exploits
Microsoft Reader versions 2.1.1.3143 and below and versions 2.6.1.7169 and below suffer from a heap overflow vulnerability caused by the allocation of a certain amount of memory and the copying of arbitrary data during the decompression of the sections. Proof of concept code included.
-
17:06
»
Packet Storm Security Recent Files
Microsoft Reader versions 2.1.1.3143 and below and versions 2.6.1.7169 and below suffer from a heap overflow vulnerability caused by the allocation of a certain amount of memory and the copying of arbitrary data during the decompression of the sections. Proof of concept code included.
-
17:06
»
Packet Storm Security Misc. Files
Microsoft Reader versions 2.1.1.3143 and below and versions 2.6.1.7169 and below suffer from a heap overflow vulnerability caused by the allocation of a certain amount of memory and the copying of arbitrary data during the decompression of the sections. Proof of concept code included.
-
-
14:02
»
Hack a Day
HackHut user [lackawanna] is looking to start his own compost pile, but as many urban composters discover, things can get quite smelly if you don’t manage it properly. The process of composting is broken up into two phases, aerobic and anaerobic decomposition. The former is the first stage to occur and produces plenty of heat, [...]
-
-
12:44
»
Packet Storm Security Exploits
RealPlayer versions 14.0.1.633 and below suffers from a heap overflow during the handling of IVR files. This is caused by the allocation of a certain amount of data (frame size) decided by the attacker and the copying of another arbitrary amount on the same buffer. Proof of concept exploit included.
-
12:44
»
Packet Storm Security Recent Files
RealPlayer versions 14.0.1.633 and below suffers from a heap overflow during the handling of IVR files. This is caused by the allocation of a certain amount of data (frame size) decided by the attacker and the copying of another arbitrary amount on the same buffer. Proof of concept exploit included.
-
12:44
»
Packet Storm Security Misc. Files
RealPlayer versions 14.0.1.633 and below suffers from a heap overflow during the handling of IVR files. This is caused by the allocation of a certain amount of data (frame size) decided by the attacker and the copying of another arbitrary amount on the same buffer. Proof of concept exploit included.
-
-
15:41
»
Packet Storm Security Advisories
iDefense Security Advisory 03.02.11 - Remote exploitation of a heap memory corruption vulnerability in Apple Inc.'s CoreGraphics library could allow an attacker to execute arbitrary code with the privileges of the current user. This vulnerability occurs during the processing of an embedded International Color Consortium (ICC) profile within a JPEG image. A small block of heap memory may be allocated for processing certain profile data. An index value is used to reference locations within this heap block. The index value can be manipulated in a manner that results in multiple memory writes to locations outside the bounds of the heap allocated block. This condition may lead to arbitrary code execution.
-
15:41
»
Packet Storm Security Recent Files
iDefense Security Advisory 03.02.11 - Remote exploitation of a heap memory corruption vulnerability in Apple Inc.'s CoreGraphics library could allow an attacker to execute arbitrary code with the privileges of the current user. This vulnerability occurs during the processing of an embedded International Color Consortium (ICC) profile within a JPEG image. A small block of heap memory may be allocated for processing certain profile data. An index value is used to reference locations within this heap block. The index value can be manipulated in a manner that results in multiple memory writes to locations outside the bounds of the heap allocated block. This condition may lead to arbitrary code execution.
-
15:41
»
Packet Storm Security Misc. Files
iDefense Security Advisory 03.02.11 - Remote exploitation of a heap memory corruption vulnerability in Apple Inc.'s CoreGraphics library could allow an attacker to execute arbitrary code with the privileges of the current user. This vulnerability occurs during the processing of an embedded International Color Consortium (ICC) profile within a JPEG image. A small block of heap memory may be allocated for processing certain profile data. An index value is used to reference locations within this heap block. The index value can be manipulated in a manner that results in multiple memory writes to locations outside the bounds of the heap allocated block. This condition may lead to arbitrary code execution.
-
11:11
»
Packet Storm Security Advisories
iDefense Security Advisory 03.01.11 - Remote exploitation of a heap memory corruption vulnerability in Apple Inc.'s CoreGraphics library could allow an attacker to execute arbitrary code with the privileges of the current user. This vulnerability occurs during the processing of an embedded International Color Consortium (ICC) profile within a JPEG image. A small block of heap memory may be allocated for processing certain profile data. An index value is used to reference locations within this heap block. The index value can be manipulated in a manner that results in multiple memory writes to locations outside the bounds of the heap allocated block. This condition may lead to arbitrary code execution.
-
11:11
»
Packet Storm Security Recent Files
iDefense Security Advisory 03.01.11 - Remote exploitation of a heap memory corruption vulnerability in Apple Inc.'s CoreGraphics library could allow an attacker to execute arbitrary code with the privileges of the current user. This vulnerability occurs during the processing of an embedded International Color Consortium (ICC) profile within a JPEG image. A small block of heap memory may be allocated for processing certain profile data. An index value is used to reference locations within this heap block. The index value can be manipulated in a manner that results in multiple memory writes to locations outside the bounds of the heap allocated block. This condition may lead to arbitrary code execution.
-
11:11
»
Packet Storm Security Misc. Files
iDefense Security Advisory 03.01.11 - Remote exploitation of a heap memory corruption vulnerability in Apple Inc.'s CoreGraphics library could allow an attacker to execute arbitrary code with the privileges of the current user. This vulnerability occurs during the processing of an embedded International Color Consortium (ICC) profile within a JPEG image. A small block of heap memory may be allocated for processing certain profile data. An index value is used to reference locations within this heap block. The index value can be manipulated in a manner that results in multiple memory writes to locations outside the bounds of the heap allocated block. This condition may lead to arbitrary code execution.
-
-
16:40
»
SecuriTeam
RealPlayer contains a vulnerability caused by a heap overflow error when handling malformed RA5 files.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
16:40
»
SecuriTeam
RealPlayer contains a vulnerability caused by a heap overflow error when handling Audio data within media files.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
10:22
»
Packet Storm Security Exploits
This archive holds advisories, exploits, and even a video for multiple Avira vulnerabilities. Avira AntiVir Personal Edition with avguard.exe version 7.00.00.52 suffers from a heap overflow. avgntdd.sys suffers from arbitrary memory overwrite and trusted input vulnerabilities.
-
10:22
»
Packet Storm Security Recent Files
This archive holds advisories, exploits, and even a video for multiple Avira vulnerabilities. Avira AntiVir Personal Edition with avguard.exe version 7.00.00.52 suffers from a heap overflow. avgntdd.sys suffers from arbitrary memory overwrite and trusted input vulnerabilities.
-
10:22
»
Packet Storm Security Misc. Files
This archive holds advisories, exploits, and even a video for multiple Avira vulnerabilities. Avira AntiVir Personal Edition with avguard.exe version 7.00.00.52 suffers from a heap overflow. avgntdd.sys suffers from arbitrary memory overwrite and trusted input vulnerabilities.