«
Expand/Collapse
323 items tagged "integer overflow vulnerability"
Related tags:
proof of concept [+],
file [+],
safer use [+],
python [+],
module [+],
fax [+],
extension [+],
decoder [+],
calendar [+],
buffer overflow vulnerability [+],
audioop [+],
apple mac os [+],
glibc [+],
integer [+],
shmop [+],
researcher [+],
remote [+],
read [+],
opera [+],
mandriva linux [+],
gentoo linux security [+],
core control [+],
cogent [+],
arabic x [+],
apple mac os x [+],
alsa [+],
windows [+],
timezone [+],
tiffroundup [+],
teechart [+],
sterling trader [+],
sterling [+],
professional [+],
paf [+],
net [+],
libsndfile [+],
gdi [+],
framework [+],
based buffer overflow [+],
adobe acrobat [+],
x quicktime [+],
video streams [+],
timothy b. terriberry [+],
shell session [+],
reader [+],
poll [+],
plotlinecentral [+],
pict [+],
overflow error [+],
overflow code [+],
outlook [+],
oom [+],
office [+],
microsoft reader [+],
memory allocations [+],
mandriva [+],
mail [+],
lzw compression [+],
iconics [+],
heap [+],
gnash [+],
gentoo [+],
flash plugin version [+],
dll [+],
createdashedpath [+],
corruption [+],
array functions [+],
array [+],
arbitrary code execution [+],
apple quicktime [+],
overflow [+],
wxgtk [+],
winamp [+],
web [+],
virtual machine [+],
tgz [+],
site [+],
sftp [+],
serial number [+],
research [+],
proof [+],
proftpd [+],
opera web [+],
number [+],
nsv [+],
mso [+],
mod [+],
microsoft excel [+],
lzw [+],
image converter [+],
image [+],
handling [+],
gzip [+],
gnashimage [+],
gimp [+],
foobar [+],
elf [+],
element [+],
dom nodes [+],
datahub [+],
datagram sockets [+],
concept [+],
codesys [+],
ccid [+],
card [+],
browser [+],
bmp image [+],
bmp [+],
autonomy [+],
apple [+],
advisory [+],
adobe systems inc [+],
acrobat [+],
php [+],
adobe [+],
linux [+],
linux kernel [+],
xml [+],
xfs [+],
x jpeg encoded [+],
x cve [+],
x coregraphics [+],
x colorsync [+],
webkit [+],
vupen [+],
vendor [+],
tiff images [+],
symphony [+],
sun java runtime environment [+],
sun java runtime [+],
sun [+],
shockwave 3d [+],
shockwave [+],
security research [+],
secunia [+],
runtime [+],
rpc [+],
reliable [+],
record [+],
php version [+],
numberformatter [+],
multiple [+],
movie file [+],
movie [+],
lotus symphony [+],
lotus [+],
library [+],
jpeg encoded [+],
image object [+],
ibm [+],
gdi library [+],
flashpix [+],
filter text [+],
ext [+],
excel [+],
encoderparameter [+],
encoded [+],
d asset [+],
codec [+],
code execution [+],
bugtraq [+],
block [+],
audio [+],
apple safari [+],
apple lossless [+],
adobe shockwave player [+],
activex [+],
acl [+],
player [+],
kernel [+],
security [+],
flash [+],
adobe flash player [+],
function [+],
bzip2 [+],
bzip [+],
mozilla firefox [+],
mozilla [+],
firefox [+],
seamonkey [+],
vulnerability [+],
oracle java [+],
java [+],
gnu [+],
chunk [+],
png [+],
oracle [+],
libtiff [+],
libpng [+],
idefense security advisory [+],
idefense [+],
exif [+],
decompress [+],
cve [+],
business [+],
thunderbird [+],
process [+],
microsoft [+],
zsl,
xnview,
valet,
txt,
theora,
tex,
string set,
string,
security technologies,
s system,
retired,
realplayer version,
realplayer,
realnetworks realplayer,
realnetworks inc,
realnetworks,
real networks inc,
real,
proxy,
picasa,
parsing,
pango pango,
pango,
paint,
outlook express,
opera web browser,
networks,
ms10,
modo,
microsoft windows,
microsoft paint,
microsoft outlook express,
lxo,
luxology modo,
luxology,
live,
kvm,
keyview,
kasa,
jpeg,
issue,
image processing,
heap corruption,
google picasa,
google,
glyph,
gdomap,
express,
dospecial,
dicom,
deimos,
cupsimagereadtiff,
cups,
core,
content length,
configuration file,
configuration,
common library,
colorsync profile,
chunk data,
buffer overflow condition,
buffer,
attacker,
arbitrary configuration,
arbitrary code,
arbitrary,
apple itunes,
apache,
agentx
-
-
13:42
»
Packet Storm Security Exploits
An integer overflow vulnerability has been discovered in the EncoderParameter class of the .NET Framework. Exploiting this vulnerability results in an overflown integer that is used to allocate a buffer on the heap. After the incorrect allocation, one or more user-supplied buffers are copied in the new buffer, resulting in a corruption of the heap.
-
13:42
»
Packet Storm Security Recent Files
An integer overflow vulnerability has been discovered in the EncoderParameter class of the .NET Framework. Exploiting this vulnerability results in an overflown integer that is used to allocate a buffer on the heap. After the incorrect allocation, one or more user-supplied buffers are copied in the new buffer, resulting in a corruption of the heap.
-
13:42
»
Packet Storm Security Misc. Files
An integer overflow vulnerability has been discovered in the EncoderParameter class of the .NET Framework. Exploiting this vulnerability results in an overflown integer that is used to allocate a buffer on the heap. After the incorrect allocation, one or more user-supplied buffers are copied in the new buffer, resulting in a corruption of the heap.
-
-
16:32
»
Packet Storm Security Exploits
Code Audit Labs has discovered an integer overflow vulnerability in array functions like Int32Array, Int16Array, etc in Opera versions 11.60 and below.
-
16:32
»
Packet Storm Security Recent Files
Code Audit Labs has discovered an integer overflow vulnerability in array functions like Int32Array, Int16Array, etc in Opera versions 11.60 and below.
-
16:32
»
Packet Storm Security Misc. Files
Code Audit Labs has discovered an integer overflow vulnerability in array functions like Int32Array, Int16Array, etc in Opera versions 11.60 and below.
-
-
21:14
»
SecuriTeam
Oracle Java contains an integer overflow vulnerability in the Color Management Module (CMM.).
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
15:44
»
SecuriTeam
Remote exploitation of an integer overflow vulnerability in Adobe Systems Inc.'s Flash Player could allow an attacker to execute arbitrary code with the privileges of the current user.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
21:45
»
Packet Storm Security Advisories
iDefense Security Advisory 08.09.11 - Remote exploitation of an integer overflow vulnerability in Adobe Systems Inc.'s Flash Player could allow an attacker to execute arbitrary code with the privileges of the current user. During the allocation of an array within a certain internal ActionScript function, a size calculation may cause an integer value to overflow. This condition may lead to the bounds of an undersized array being overflown during a memory copy operation. This can result in arbitrary code execution.
-
21:45
»
Packet Storm Security Recent Files
iDefense Security Advisory 08.09.11 - Remote exploitation of an integer overflow vulnerability in Adobe Systems Inc.'s Flash Player could allow an attacker to execute arbitrary code with the privileges of the current user. During the allocation of an array within a certain internal ActionScript function, a size calculation may cause an integer value to overflow. This condition may lead to the bounds of an undersized array being overflown during a memory copy operation. This can result in arbitrary code execution.
-
21:45
»
Packet Storm Security Misc. Files
iDefense Security Advisory 08.09.11 - Remote exploitation of an integer overflow vulnerability in Adobe Systems Inc.'s Flash Player could allow an attacker to execute arbitrary code with the privileges of the current user. During the allocation of an array within a certain internal ActionScript function, a size calculation may cause an integer value to overflow. This condition may lead to the bounds of an undersized array being overflown during a memory copy operation. This can result in arbitrary code execution.
-
-
12:44
»
SecuriTeam
Microsoft Office Contains a vulnerability caused by an integer overflow error in the MSO component.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
19:47
»
Packet Storm Security Exploits
Iconics GENESIS32 version 9.21.201.01 suffers from an integer overflow vulnerability. The GenBroker service on port 38080 is affected by three integer overflow vulnerabilities while handling opcode 0x4b0, which is caused by abusing the the memory allocations needed for the number of elements passed by the client. This results unexpected behaviors such as direct registry calls, memory location calls, or arbitrary remote code execution. Please note that in order to ensure reliability, this exploit will try to open calc (hidden), inject itself into the process, and then open up a shell session. Also, DEP bypass is supported.
-
19:47
»
Packet Storm Security Recent Files
Iconics GENESIS32 version 9.21.201.01 suffers from an integer overflow vulnerability. The GenBroker service on port 38080 is affected by three integer overflow vulnerabilities while handling opcode 0x4b0, which is caused by abusing the the memory allocations needed for the number of elements passed by the client. This results unexpected behaviors such as direct registry calls, memory location calls, or arbitrary remote code execution. Please note that in order to ensure reliability, this exploit will try to open calc (hidden), inject itself into the process, and then open up a shell session. Also, DEP bypass is supported.
-
19:47
»
Packet Storm Security Misc. Files
Iconics GENESIS32 version 9.21.201.01 suffers from an integer overflow vulnerability. The GenBroker service on port 38080 is affected by three integer overflow vulnerabilities while handling opcode 0x4b0, which is caused by abusing the the memory allocations needed for the number of elements passed by the client. This results unexpected behaviors such as direct registry calls, memory location calls, or arbitrary remote code execution. Please note that in order to ensure reliability, this exploit will try to open calc (hidden), inject itself into the process, and then open up a shell session. Also, DEP bypass is supported.
-
-
17:04
»
SecuriTeam
.Microsoft Windows Contains a vulnerability is caused by an integer overflow error in the GDI+ library
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
17:39
»
SecuriTeam
Apple Safari Contains a vulnerability is caused by an integer overflow error in the WebKit library when handling block dimensions.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
17:03
»
Packet Storm Security Exploits
Microsoft Reader versions 2.1.1.3143 and below suffer from an integer overflow vulnerability during the handling of the number of pieces of the initial ITLS header at offset 0x10. Proof of concept code included.
-
17:03
»
Packet Storm Security Recent Files
Microsoft Reader versions 2.1.1.3143 and below suffer from an integer overflow vulnerability during the handling of the number of pieces of the initial ITLS header at offset 0x10. Proof of concept code included.
-
17:03
»
Packet Storm Security Misc. Files
Microsoft Reader versions 2.1.1.3143 and below suffer from an integer overflow vulnerability during the handling of the number of pieces of the initial ITLS header at offset 0x10. Proof of concept code included.
-
-
20:55
»
SecuriTeam
Remote exploitation of an integer overflow vulnerability in Adobe Systems Inc.'s Flash Player could allow an attacker to execute arbitrary code with the privileges of the current user.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
5:49
»
Packet Storm Security Advisories
iDefense Security Advisory 02.08.11 - Remote exploitation of an integer overflow vulnerability in Adobe Systems Inc.'s Flash Player could allow an attacker to execute arbitrary code with the privileges of the current user. The vulnerability occurs when parsing a maliciously formatted sequence of ActionScript code inside an Adobe Flash file. The problem exists in the ActionScript method of the built-in "Function" class, which accepts an array object as a second parameter and uses this array's length multiplied by four for a memory allocation without any overflow checks. Then it writes the array's content into the allocated memory, which corrupts memory and leads to an exploitable condition. iDefense has confirmed the existence of this vulnerability in the Flash Plugin version 10.1.82.76 and 10.1.85.3. A full list of vulnerable Adobe products can be found in Adobe Security Bulletin APSB11-02.
-
5:49
»
Packet Storm Security Recent Files
iDefense Security Advisory 02.08.11 - Remote exploitation of an integer overflow vulnerability in Adobe Systems Inc.'s Flash Player could allow an attacker to execute arbitrary code with the privileges of the current user. The vulnerability occurs when parsing a maliciously formatted sequence of ActionScript code inside an Adobe Flash file. The problem exists in the ActionScript method of the built-in "Function" class, which accepts an array object as a second parameter and uses this array's length multiplied by four for a memory allocation without any overflow checks. Then it writes the array's content into the allocated memory, which corrupts memory and leads to an exploitable condition. iDefense has confirmed the existence of this vulnerability in the Flash Plugin version 10.1.82.76 and 10.1.85.3. A full list of vulnerable Adobe products can be found in Adobe Security Bulletin APSB11-02.
-
5:49
»
Packet Storm Security Misc. Files
iDefense Security Advisory 02.08.11 - Remote exploitation of an integer overflow vulnerability in Adobe Systems Inc.'s Flash Player could allow an attacker to execute arbitrary code with the privileges of the current user. The vulnerability occurs when parsing a maliciously formatted sequence of ActionScript code inside an Adobe Flash file. The problem exists in the ActionScript method of the built-in "Function" class, which accepts an array object as a second parameter and uses this array's length multiplied by four for a memory allocation without any overflow checks. Then it writes the array's content into the allocated memory, which corrupts memory and leads to an exploitable condition. iDefense has confirmed the existence of this vulnerability in the Flash Plugin version 10.1.82.76 and 10.1.85.3. A full list of vulnerable Adobe products can be found in Adobe Security Bulletin APSB11-02.
-
-
14:47
»
Packet Storm Security Advisories
iDefense Security Advisory 02.08.11 - Remote exploitation of a buffer overflow vulnerability in multiple versions of Microsoft Corp.'s Windows could allow attackers to execute arbitrary code on the targeted host. An integer overflow vulnerability exists in the "shimgvw" library. During the processing of an image within a certain function, a bitmap containing a large "biWidth" value can be used to cause an integer calculation overflow. This condition can lead to the overflow of a heap buffer and may result in the execute arbitrary code on the targeted host.
-
14:47
»
Packet Storm Security Recent Files
iDefense Security Advisory 02.08.11 - Remote exploitation of a buffer overflow vulnerability in multiple versions of Microsoft Corp.'s Windows could allow attackers to execute arbitrary code on the targeted host. An integer overflow vulnerability exists in the "shimgvw" library. During the processing of an image within a certain function, a bitmap containing a large "biWidth" value can be used to cause an integer calculation overflow. This condition can lead to the overflow of a heap buffer and may result in the execute arbitrary code on the targeted host.
-
14:47
»
Packet Storm Security Misc. Files
iDefense Security Advisory 02.08.11 - Remote exploitation of a buffer overflow vulnerability in multiple versions of Microsoft Corp.'s Windows could allow attackers to execute arbitrary code on the targeted host. An integer overflow vulnerability exists in the "shimgvw" library. During the processing of an image within a certain function, a bitmap containing a large "biWidth" value can be used to cause an integer calculation overflow. This condition can lead to the overflow of a heap buffer and may result in the execute arbitrary code on the targeted host.
-
-
19:19
»
SecuriTeam
Winamp contains a vulnerability that can be exploited to cause a heap-based buffer overflow via a specially crafted NSV stream or file.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
19:17
»
SecuriTeam
Winamp contains a vulnerability that can be exploited to cause a heap-based buffer overflow via a specially crafted NSV stream or file.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
11:58
»
Packet Storm Security Advisories
Gentoo Linux Security Advisory 201101-3 - Timothy B. Terriberry discovered that libvpx contains an integer overflow vulnerability in the processing of video streams that may allow user-assisted execution of arbitrary code. libvpx is vulnerable to an integer overflow vulnerability when processing crafted VP8 video streams. Versions less than 0.9.5 are affected.
-
11:58
»
Packet Storm Security Recent Files
Gentoo Linux Security Advisory 201101-3 - Timothy B. Terriberry discovered that libvpx contains an integer overflow vulnerability in the processing of video streams that may allow user-assisted execution of arbitrary code. libvpx is vulnerable to an integer overflow vulnerability when processing crafted VP8 video streams. Versions less than 0.9.5 are affected.
-
11:58
»
Packet Storm Security Misc. Files
Gentoo Linux Security Advisory 201101-3 - Timothy B. Terriberry discovered that libvpx contains an integer overflow vulnerability in the processing of video streams that may allow user-assisted execution of arbitrary code. libvpx is vulnerable to an integer overflow vulnerability when processing crafted VP8 video streams. Versions less than 0.9.5 are affected.
-
-
17:01
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2010-251 - Security researchers Yosuke Hasegawa and Masatoshi Kimura reported that the x-mac-arabic, x-mac-farsi and x-mac-hebrew character encodings are vulnerable to XSS attacks due to some characters being converted to angle brackets when displayed by the rendering engine. Google security researcher Michal Zalewski reported that when a window was opened to a site resulting in a network or certificate error page, the opening site could access the document inside the opened window and inject arbitrary content. An attacker could use this bug to spoof the location bar and trick a user into thinking they were on a different site than they actually were. Mozilla security researcher moz_bug_r_a4 reported that the fix for could be circumvented permitting the execution of arbitrary JavaScript with chrome privileges. Security researcher regenrecht reported via TippingPoint's Zero Day Initiative that JavaScript arrays were vulnerable to an integer overflow vulnerability. Various other security issues were addressed in Firefox.
-
17:01
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2010-251 - Security researchers Yosuke Hasegawa and Masatoshi Kimura reported that the x-mac-arabic, x-mac-farsi and x-mac-hebrew character encodings are vulnerable to XSS attacks due to some characters being converted to angle brackets when displayed by the rendering engine. Google security researcher Michal Zalewski reported that when a window was opened to a site resulting in a network or certificate error page, the opening site could access the document inside the opened window and inject arbitrary content. An attacker could use this bug to spoof the location bar and trick a user into thinking they were on a different site than they actually were. Mozilla security researcher moz_bug_r_a4 reported that the fix for could be circumvented permitting the execution of arbitrary JavaScript with chrome privileges. Security researcher regenrecht reported via TippingPoint's Zero Day Initiative that JavaScript arrays were vulnerable to an integer overflow vulnerability. Various other security issues were addressed in Firefox.
-
-
19:22
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2010-251 - Security issues were identified and fixed in firefox. Security researchers Yosuke Hasegawa and Masatoshi Kimura reported that the x-mac-arabic, x-mac-farsi and x-mac-hebrew character encodings are vulnerable to XSS attacks due to some characters being converted to angle brackets when displayed by the rendering engine. Google security researcher Michal Zalewski reported that when a window was opened to a site resulting in a network or certificate error page, the opening site could access the document inside the opened window and inject arbitrary content. Mozilla security researcher moz_bug_r_a4 reported that the fix for could be circumvented permitting the execution of arbitrary JavaScript with chrome privileges. Security researcher regenrecht reported via TippingPoint's Zero Day Initiative that JavaScript arrays were vulnerable to an integer overflow vulnerability. Various other issues were also addressed.
-
19:22
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2010-251 - Security issues were identified and fixed in firefox. Security researchers Yosuke Hasegawa and Masatoshi Kimura reported that the x-mac-arabic, x-mac-farsi and x-mac-hebrew character encodings are vulnerable to XSS attacks due to some characters being converted to angle brackets when displayed by the rendering engine. Google security researcher Michal Zalewski reported that when a window was opened to a site resulting in a network or certificate error page, the opening site could access the document inside the opened window and inject arbitrary content. Mozilla security researcher moz_bug_r_a4 reported that the fix for could be circumvented permitting the execution of arbitrary JavaScript with chrome privileges. Security researcher regenrecht reported via TippingPoint's Zero Day Initiative that JavaScript arrays were vulnerable to an integer overflow vulnerability. Various other issues were also addressed.
-
19:22
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2010-251 - Security issues were identified and fixed in firefox. Security researchers Yosuke Hasegawa and Masatoshi Kimura reported that the x-mac-arabic, x-mac-farsi and x-mac-hebrew character encodings are vulnerable to XSS attacks due to some characters being converted to angle brackets when displayed by the rendering engine. Google security researcher Michal Zalewski reported that when a window was opened to a site resulting in a network or certificate error page, the opening site could access the document inside the opened window and inject arbitrary content. Mozilla security researcher moz_bug_r_a4 reported that the fix for could be circumvented permitting the execution of arbitrary JavaScript with chrome privileges. Security researcher regenrecht reported via TippingPoint's Zero Day Initiative that JavaScript arrays were vulnerable to an integer overflow vulnerability. Various other issues were also addressed.
-
-
22:01
»
Packet Storm Security Recent Files
Gentoo Linux Security Advisory 201009-1 - An integer overflow vulnerability in wxGTK might enable remote attackers to cause the execution of arbitrary code. wxGTK is prone to an integer overflow error in the wxImage::Create() function in src/common/image.cpp, possibly leading to a heap-based buffer overflow. Versions less than 2.8.10.1-r1 are affected.
-
22:01
»
Packet Storm Security Advisories
Gentoo Linux Security Advisory 201009-1 - An integer overflow vulnerability in wxGTK might enable remote attackers to cause the execution of arbitrary code. wxGTK is prone to an integer overflow error in the wxImage::Create() function in src/common/image.cpp, possibly leading to a heap-based buffer overflow. Versions less than 2.8.10.1-r1 are affected.
-
-
16:59
»
SecuriTeam
An integer overflow vulnerability was discovered in Microsoft Windows Outlook Express and Windows Mail.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
13:57
»
SecuriTeam
An integer overflow vulnerability was discovered in Microsoft Windows Outlook Express and Windows Mail.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
12:56
»
SecuriTeam
An integer overflow vulnerability was discovered in Microsoft Windows Outlook Express and Windows Mail.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
23:55
»
SecuriTeam
fA vulnerability was discovered in Adobe Shockwave Player, which can be exploited by malicious people to potentially compromise a user's system.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!