Published Advisories

PUBLISHED ADVISORIES

The following is a list of all publicly disclosed vulnerabilities discovered by Zero Day Initiative researchers. While the affected vendor is working on a patch for these vulnerabilities, Trend Micro customers are protected from exploitation by security filters delivered ahead of public disclosure.

All security vulnerabilities that are acquired by the Zero Day Initiative are handled according to the ZDI Disclosure Policy. Once the affected vendor patches the vulnerability, we publish an accompanying security advisory which describes the issue, including links to the vendor's fixes.

Available in RSS Format
ZDI ID ZDI CAN AFFECTED VENDOR(S) CVE CVSS v3.0 PUBLISHED UPDATED TITLE
ZDI-07-080 ZDI-CAN-173 3Com TippingPoint, Juniper     2010-01-27 Multiple Vendor Web Console Privilege Escalation Vulnerability
ZDI-07-079 ZDI-CAN-201 Hewlett-Packard CVE-2007-6195   2007-12-17 Hewlett-Packard HP-UX swagentd Buffer Overflow Vulnerability
ZDI-07-078 ZDI-CAN-225 St. Bernard CVE-2007-6281   2007-12-17 St. Bernard Open File Manager Heap Overflow Vulnerability
ZDI-07-077 ZDI-CAN-157 Trend Micro CVE-2007-6507   2007-12-17 Trend Micro ServerProtect StRpcSrv.dll Insecure Method Exposure Vulnerability
ZDI-07-076 ZDI-CAN-178 Microsoft, Microsoft CVE-2007-3039   2007-12-11 Microsoft Windows Message Queuing Service Stack Overflow Vulnerability
ZDI-07-075 ZDI-CAN-230 Microsoft CVE-2007-5344   2007-12-11 Microsoft Internet Explorer Element Tags Vulnerability
ZDI-07-074 ZDI-CAN-189 Microsoft CVE-2007-3903   2007-12-11 Microsoft Internet Explorer Node Manipulation Memory Corruption Vulnerability
ZDI-07-073 ZDI-CAN-229 Microsoft CVE-2007-3902   2007-12-11 2020-04-17 Microsoft Internet Explorer setExpression Code Execution Vulnerability
ZDI-07-072 ZDI-CAN-162 Novell CVE-2007-6302   2007-12-10 Novell NetMail AntiVirus Agent Multiple Heap Overflow Vulnerabilities
ZDI-07-071 ZDI-CAN-111 Hewlett-Packard CVE-2007-6204   2007-12-06 Hewlett-Packard OpenView Network Node Manager Multiple CGI Buffer Overflow Vulnerabilities
ZDI-07-070 ZDI-CAN-236 Skype CVE-2007-5989   2007-12-06 Skype URI Handler Remote Heap Corruption Vulnerability
ZDI-07-069 ZDI-CAN-143 Computer Associates CVE-2007-5328   2007-11-26 CA BrightStor ARCserve Backup Message Engine Insecure Method Exposure Vulnerability
ZDI-07-068 ZDI-CAN-242 Apple CVE-2007-4672   2007-11-05 Apple QuickTime Uncompressedfile Opcode Stack Overflow Vulnerability
ZDI-07-067 ZDI-CAN-241 Apple CVE-2007-4676   2007-11-05 Apple QuickTime PICT File Poly Opcodes Heap Corruption Vulnerability
ZDI-07-066 ZDI-CAN-240 Apple CVE-2007-4676   2007-11-05 Apple Quicktime PICT File PackBitsRgn Parsing Heap Corruption Vulnerability
ZDI-07-065 ZDI-CAN-239 Apple CVE-2007-4677   2007-11-05 Apple QuickTime Color Table RGB Parsing Heap Corruption Vulnerability
ZDI-07-064 ZDI-CAN-199 Novell CVE-2007-5767   2007-10-31 Novell Client Trust Heap Overflow Vulnerability
ZDI-07-063 ZDI-CAN-150 RealNetworks CVE-2007-2264   2007-10-31 2023-09-20 RealPlayer RA Field Size File Processing Heap Overflow Vulnerability
ZDI-07-062 ZDI-CAN-148 RealNetworks CVE-2007-4599   2007-10-31 RealNetworks RealPlayer PLS File Memory Corruption Vulnerability
ZDI-07-061 ZDI-CAN-141 RealNetworks CVE-2007-2263   2007-11-02 RealNetworks RealPlayer SWF Processing Remote Code Execution Vulnerability
ZDI-07-060 ZDI-CAN-134 Hewlett-Packard CVE-2007-5413   2007-10-31 Hewlett-Packard OpenView Radia Integration Server File System Exposure Vulnerability
ZDI-07-059 ZDI-CAN-047 IBM, Verity CVE-2007-5909   2007-10-31 Verity KeyView SDK Multiple File Format Parsing Vulnerabilities
ZDI-07-058 ZDI-CAN-159 Oracle / PeopleSoft CVE-2007-5766   2007-10-31 Oracle E-Business Suite SQL Injection Vulnerability
ZDI-07-057 ZDI-CAN-237 Firebird CVE-2007-4992   2007-10-10 Firebird process_packet() Remote Stack Overflow Vulnerability
ZDI-07-056 ZDI-CAN-125 IBM CVE-2007-2582   2007-10-10 IBM DB2 DB2JDS Multiple Vulnerabilities
ZDI-07-055 ZDI-CAN-164 Microsoft, Microsoft, Microsoft, Microsoft CVE-2007-2228   2007-10-10 Microsoft Windows DCERPC Authentication Denial of Service Vulnerability
ZDI-07-054 ZDI-CAN-188 IBM, IBM CVE-2007-4880   2007-09-24 IBM Tivoli Storage Manager Express CAD Service Buffer Overflow Vulnerability
ZDI-07-053 ZDI-CAN-018 Microsoft CVE-2007-4991   2007-09-20 Microsoft ISA Server SOCKS4 Proxy Connection Leakage Vulnerability
ZDI-07-052 ZDI-CAN-208 MIT CVE-2007-3999   2007-09-12 Multiple Kerberos Implementations Authentication Context Stack Overflow Vulnerability
ZDI-07-051 ZDI-CAN-217 Trend Micro CVE-2007-4731   2007-09-07 Trend Micro ServerProtect TMregChange() Stack Overflow Vulnerability
ZDI-07-050 ZDI-CAN-215 Trend Micro CVE-2007-4218   2007-09-07 Trend Micro ServerProtect RPCFN_SetComputerName() Stack Overflow Vulnerability
ZDI-07-049 ZDI-CAN-170 EMC CVE-2007-3618   2007-08-20 EMC Legato Networker Remote Exec Service Stack Overflow Vulnerabilities
ZDI-07-048 ZDI-CAN-096 Microsoft CVE-2007-2223   2007-08-14 Microsoft Internet Explorer substringData Heap Overflow Vulnerability
ZDI-07-047 ZDI-CAN-198 Microsoft, Microsoft, Microsoft, Microsoft CVE-2007-3035   2007-08-14 Microsoft Windows Media Player Malformed Skin Header Code Execution Vulnerability
ZDI-07-046 ZDI-CAN-182 Microsoft, Microsoft, Microsoft, Microsoft CVE-2007-3037   2007-08-14 Microsoft Windows Media Player Skin Parsing Size Mismatch Heap Overflow Vulnerability
ZDI-07-045 ZDI-CAN-146 Novell CVE-2007-2954   2007-08-06 Novell Client NWSPOOL.DLL Stack Overflow Vulnerability
ZDI-07-044 ZDI-CAN-147 BakBone CVE-2007-3911   2007-07-25 BakBone NetVault Reporter Scheduler Heap Overflow Vulnerability
ZDI-07-043 ZDI-CAN-179 Ipswitch CVE-2007-2795   2007-07-19 Ipswitch IMail IMAP Daemon SUBSCRIBE Stack Overflow Vulnerability
ZDI-07-042 ZDI-CAN-166 Ipswitch CVE-2007-2795   2007-07-19 Ipswitch IMail Server GetIMailHostEntry Memory Corruption Vulnerability
ZDI-07-041 ZDI-CAN-127 Panda Software CVE-2007-3026   2007-07-20 Panda Software AdminSecure Agent Heap Overflow Vulnerability
ZDI-07-040 ZDI-CAN-124 Symantec CVE-2007-0447   2007-07-12 Symantec AntiVirus Engine CAB Parsing Heap Overflow Vulnerability
ZDI-07-039 ZDI-CAN-097 Symantec CVE-2007-3699   2007-07-12 Symantec AntiVirus Engine RAR File Parsing DoS Vulnerability
ZDI-07-038 ZDI-CAN-168 Microsoft CVE-2007-1751   2007-06-12 Microsoft Internet Explorer Prototype Dereference Code Execution Vulnerability
ZDI-07-037 ZDI-CAN-119 Microsoft CVE-2007-3027   2007-06-12 Microsoft Internet Explorer Language Pack Installation Remote Code Execution Vulnerability
ZDI-07-036 ZDI-CAN-149 Arris CVE-2007-2796   2007-06-11 Arris Cadant C3 CMTS Remote DoS Vulnerability
ZDI-07-035 ZDI-CAN-154 Computer Associates CVE-2007-2864   2007-06-05 CA Multiple Product AV Engine CAB Header Parsing Stack Overflow Vulnerability
ZDI-07-034 ZDI-CAN-123 Computer Associates CVE-2007-2863   2007-06-05 CA Multiple Product AV Engine CAB Filename Parsing Stack Overflow Vulnerability
ZDI-07-033 ZDI-CAN-197 Samba CVE-2007-2446   2007-07-11 Samba lsa_io_trans_names Heap Overflow Vulnerability
ZDI-07-032 ZDI-CAN-194 Samba CVE-2007-2446   2007-07-11 Samba sec_io_acl Heap Overflow Vulnerability
ZDI-07-031 ZDI-CAN-193 Samba CVE-2007-2446   2007-07-11 Samba smb_io_notify_option_type_data Heap Overflow Vulnerability
ZDI-07-030 ZDI-CAN-192 Samba CVE-2007-2446   2007-07-11 Samba netdfs_io_dfs_EnumInfo_d Heap Overflow Vulnerability
ZDI-07-029 ZDI-CAN-191 Samba CVE-2007-2446   2007-07-11 Samba lsa_io_privilege_set Heap Overflow Vulnerability
ZDI-07-028 ZDI-CAN-104 Computer Associates CVE-2007-2522   2007-05-10 CA eTrust AntiVirus Server inoweb Buffer Overflow Vulnerability
ZDI-07-027 ZDI-CAN-098 Microsoft CVE-2007-0944   2007-05-08 Microsoft Internet Explorer Table Column Deletion Memory Corruption Vulnerability
ZDI-07-026 ZDI-CAN-131 Microsoft, Microsoft, Microsoft CVE-2007-0215   2007-05-08 Microsoft Excel BIFF File Format Named Graph Record Parsing Stack Overflow Vulnerability
ZDI-07-025 ZDI-CAN-156 Trend Micro CVE-2007-2508   2007-05-07 Trend Micro ServerProtect AgRpcCln.dll Stack Overflow Vulnerability
ZDI-07-024 ZDI-CAN-155 Trend Micro CVE-2007-2508   2007-05-07 Trend Micro ServerProtect EarthAgent Stack Overflow Vulnerability
ZDI-07-023 ZDI-CAN-190 Apple CVE-2007-2175   2007-05-01 Apple QTJava toQTPointer() Pointer Arithmetic Memory Overwrite Vulnerability
ZDI-07-022 ZDI-CAN-171 Computer Associates CVE-2007-2139   2007-04-24 CA BrightStor ArcServe Media Server Multiple Buffer Overflow Vulnerabilities
ZDI-07-021 ZDI-CAN-087 GraceNote CVE-2007-0443   2007-04-19 GraceNote CDDBControl ActiveX Buffer Overflow Vulnerability
ZDI-07-020 ZDI-CAN-153 BMC Software CVE-2007-1972   2007-04-18 BMC Performance Manager SNMP Command Execution Vulnerability
ZDI-07-019 ZDI-CAN-151 BMC Software CVE-2007-2136   2007-04-18 BMC Patrol PerformAgent bgs_sdservice Memory Corruption Vulnerability
ZDI-07-018 ZDI-CAN-069 IBM CVE-2007-2137   2007-04-17 IBM Tivoli Monitoring Express Universal Agent Heap Overflow Vunlerability
ZDI-07-017 ZDI-CAN-132 Oracle / PeopleSoft CVE-2007-2135   2007-04-18 Oracle E-Business Suite Arbitrary Document Download Vulnerability
ZDI-07-016 ZDI-CAN-136 Oracle / PeopleSoft CVE-2007-2170   2007-04-17 Oracle E-Business Suite Arbitrary Node Deletion Vulnerability
ZDI-07-015 ZDI-CAN-181 Novell CVE-2007-2171   2007-04-18 Novell Groupwise WebAccess Base64 Decoding Stack Overflow Vulnerability
ZDI-07-014 ZDI-CAN-138 Kaspersky CVE-2007-1112   2007-04-05 Kaspersky Antivirus ActiveX Unsafe Methods Vulnerability
ZDI-07-013 ZDI-CAN-113 Kaspersky CVE-2007-0445   2007-04-05 Kaspersky AntiVirus Engine ARJ Archive Parsing Heap Overflow Vulnerability
ZDI-07-012 ZDI-CAN-110 Yahoo! CVE-2007-1680   2007-04-03 Yahoo! Messenger AudioConf ActiveX Control Buffer Overflow Vulnerability
ZDI-07-011 ZDI-CAN-060 IBM CVE-2007-1675   2007-03-28 IBM Lotus Domino IMAP Server CRAM-MD5 Authentication Buffer Overflow Vulnerability
ZDI-07-010 ZDI-CAN-093 Apple CVE-2007-0714   2007-03-07 Apple Quicktime UDTA Parsing Heap Overflow Vulnerability
ZDI-07-009 ZDI-CAN-133 Novell CVE-2007-1350   2007-03-07 Novell Netmail WebAdmin Buffer Overflow Vulnerability
ZDI-07-008 ZDI-CAN-152 Apache CVE-2007-0774   2007-03-02 Apache Tomcat JK Web Server Connector Long URL Stack Overflow Vulnerability
ZDI-07-007 ZDI-CAN-112 Mercury, Mercury, Mercury CVE-2007-0446   2007-02-08 Hewlett-Packard Mercury LoadRunner Agent Stack Overflow Vulnerability
ZDI-07-006 ZDI-CAN-101 Citrix, Citrix, Citrix CVE-2007-0444   2007-01-24 Citrix Metaframe Presentation Server Print Provider Buffer Overflow Vulnerability
ZDI-07-005 ZDI-CAN-054 Sun Microsystems CVE-2007-0243   2007-01-16 Sun Microsystems Java GIF File Parsing Memory Corruption Vulnerability
ZDI-07-004 ZDI-CAN-130 Computer Associates CVE-2007-0169   2007-01-11 CA BrightStor ARCserve Backup Tape Engine Buffer Overflow Vulnerability
ZDI-07-003 ZDI-CAN-129 Computer Associates CVE-2007-0169   2007-01-11 CA BrightStor ARCserve Backup Message Engine Buffer Overflow Vulnerability
ZDI-07-002 ZDI-CAN-118 Computer Associates CVE-2007-0168   2007-01-11 CA BrightStor ARCserve Backup Tape Engine Code Execution Vulnerability
ZDI-07-001 ZDI-CAN-073 QUALCOMM CVE-2006-6336   2007-01-05 QUALCOMM Eudora WorldMail Remote Management Heap Overflow Vulnerability