<?xml version="1.0" encoding="utf-8"?><rss version="2.0">
<channel>
<title><![CDATA[eEye Zero-Day Tracker]]></title>
<link><![CDATA[http://www.eeye.com/Resources/Media-Center/RSS?rss=Zero-Day-Tracker]]></link>
<description><![CDATA[The tracker catalogs the latest Zero-Day vulnerabilities and provides detailed analysis of each, including affected software, severity level, potential impact, and mitigation and protection procedures.]]></description>
<language><![CDATA[en-US]]></language>
<item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20111206</guid>
  <title><![CDATA[Adobe Reader/Acrobat U3D Memory Corruption Vulnerability]]></title>
  <description><![CDATA[Adobe Reader and Acrobat contain an unspecified vulnerability, which occurs when parsing U3D data. This can be exploited to grant attackers the ability to execute arbitrary code. This vulnerability has been exploited in the wild, primarily on the 9.4.6 version of each product.]]></description>
  <pubDate>Tue, 06 Dec 2011 08:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20111206]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20111114</guid>
  <title><![CDATA[Firefox 8.0 Null Pointer Dereference Vulnerability]]></title>
  <description><![CDATA[Mozilla Firefox 8.0 contains a null pointer dereference vulnerability.]]></description>
  <pubDate>Mon, 14 Nov 2011 08:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20111114]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20111114-(1)</guid>
  <title><![CDATA[Apple OS X Sandbox Predefined Profile Bypass Vulnerability]]></title>
  <description><![CDATA[Apple Mac OS X contains a vulnerability when restricting access to application uses a pre-defined sandbox profile (Seatbelt). Successful exploitation may allow an attacker to perform certain functions outside of the sandbox, bypassing intended sandbox restrictions.<br />
<br />
Note: According to CORE&#39;s advisory, Apple does not believe this issue has any security implications and they intend to update their documentation to reflect the sandbox profile&#39;s functionality. ]]></description>
  <pubDate>Thu, 10 Nov 2011 08:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20111114-(1)]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20111104</guid>
  <title><![CDATA[Microsoft Excel 2003 Use After Free]]></title>
  <description><![CDATA[Microsoft Excel 2003 contains a use-after-free vulnerability, possibly located in the VBscript macro handler.&nbsp; Successful exploitation may allow an attacker to remotely execute arbitrary code in the context of the currently logged on user.]]></description>
  <pubDate>Fri, 04 Nov 2011 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20111104]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20111102</guid>
  <title><![CDATA[Apache HTTP Server ap_pregsub() buffer overflow]]></title>
  <description><![CDATA[There is an integer overflow vulnerability in the ap_pregsub function of the Apache Web server.&nbsp; This integer overflow can lead to a buffer overflow and allow an attacker to execute arbitrary code.&nbsp; The Apache Web server runs with elevated privileges, an attacker would need to exploit this locally but would gain elevated privileges on the machine.]]></description>
  <pubDate>Wed, 02 Nov 2011 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20111102]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20111025</guid>
  <title><![CDATA[Trend Micro IWSS 3.1 privilege escalation]]></title>
  <description><![CDATA[The Trend Micro InterScan Web Security Suite (IWSS) will run scripts titled either &quot;PatchExe.sh&quot; or &quot;RollbackExe.sh&quot; out of the current directory with root privileges regardless of the privileges with which the&nbsp; IWSS was initially launched with.&nbsp; Successful exploitation would give an attacker root level access to the target machine.]]></description>
  <pubDate>Tue, 25 Oct 2011 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20111025]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20111018</guid>
  <title><![CDATA[Skype Multiple 0day Vulnerabilities]]></title>
  <description><![CDATA[Skype contains multiple vulnerabilities.&nbsp; Successful exploitation could result in a wide variety of conditions, including denial of service and remote code execution.]]></description>
  <pubDate>Tue, 18 Oct 2011 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20111018]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20111012-(1)</guid>
  <title><![CDATA[VMware ESXi and ESX Multiple Vulnerabilities]]></title>
  <description><![CDATA[VMware ESXi and ESX contain multiple vulnerabilities.&nbsp; Successful exploitation could result in a wide variety of conditions, including denial of service and remote code execution.]]></description>
  <pubDate>Wed, 12 Oct 2011 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20111012-(1)]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110923</guid>
  <title><![CDATA[Internet Explorer MHTML Mime-Formatted Request Vulnerability]]></title>
  <description><![CDATA[Microsoft Internet Explorer ignores the file extension of the target document when parsing data with the MHTML protocol handler.&nbsp; Successful exploitation could allow information disclosure via cross-site scripting.]]></description>
  <pubDate>Fri, 23 Sep 2011 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110923]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110918</guid>
  <title><![CDATA[OS X Lion Fails to Verify Authentication Before Changing User Password]]></title>
  <description><![CDATA[OS X Lion does not request&nbsp; user authentication at the time that a local user attempts to change their password. Therefore, any user account that is currently logged in can have their password changed by someone, with local access, who does not know the account's password.]]></description>
  <pubDate>Sun, 18 Sep 2011 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110918]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110918-(1)</guid>
  <title><![CDATA[OS X Lion Fails to Protect Users' Password Hashes]]></title>
  <description><![CDATA[OS X Lion contains an information disclosure vulnerability, which permits any user to access the password hashes of any other user on the system.]]></description>
  <pubDate>Sun, 18 Sep 2011 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110918-(1)]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110902</guid>
  <title><![CDATA[Apple Mac OS X Keychain Certificate Security Bypass]]></title>
  <description><![CDATA[OS X does not properly handle the Extended Validation certificate attribute of Certificate Authority certificates. Within the Keychain, if a user has marked an Extended Validation certificate as not to be trusted, OS X will still trust it.]]></description>
  <pubDate>Fri, 02 Sep 2011 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110902]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110725</guid>
  <title><![CDATA[Mac OS X Lion OpenLDAP Security Bypass]]></title>
  <description><![CDATA[Mac OS X Lion OpenLDAP server contains a vulnerability that permits certain clients to log in using invalid usernames and invalid passwords.]]></description>
  <pubDate>Mon, 25 Jul 2011 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110725]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/17273</guid>
  <title><![CDATA[Symantec Backup Exec System Recovery 8.5 Kernel Pointer Dereference]]></title>
  <description><![CDATA[Symantec Backup Exec System Recovery contains a vulnerability in the way the CD/DVD driver present in GEARAspiWDM.sys handles IOCTL inputs.  Successful exploitation may result in remote code execution.]]></description>
  <pubDate>Thu, 12 May 2011 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/17273]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110412</guid>
  <title><![CDATA[Microsoft HTML Help]]></title>
  <description><![CDATA[Microsoft HTML Help contains a vulnerability when decompressing help files.  Successful exploitation of the vulnerability could allow remote code execution.]]></description>
  <pubDate>Tue, 12 Apr 2011 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110412]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110402</guid>
  <title><![CDATA[IE9 VUPEN Non-disclosed Remote Code Execution Vullnerability]]></title>
  <description><![CDATA[VUPEN has privately disclosed a fully-functioning exploit against IE9 and older versions to its Government customers.  VUPEN states that the vulnerability and exploit are reliable and bypass ASLR, DEP and the IE Sandbox.]]></description>
  <pubDate>Sat, 02 Apr 2011 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110402]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110311</guid>
  <title><![CDATA[PHP Substr_Replace Memory Corruption]]></title>
  <description><![CDATA[PHP contains a use-after-free vulnerability in the substr_replace function. Successful exploitation could allow attackers to cause denial of service conditions and potentially execute arbitrary code.]]></description>
  <pubDate>Sun, 13 Mar 2011 08:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110311]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110307</guid>
  <title><![CDATA[Microsoft .NET Framework Optimization Service Privilege Escalation]]></title>
  <description><![CDATA[Microsoft .NET Framework contains a vulnerability when handling permissions for the .NET Runtime Optimization Service. Successful exploitation could allow an authenticated attacker to gain elevated privileges.]]></description>
  <pubDate>Mon, 07 Mar 2011 08:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110307]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110222</guid>
  <title><![CDATA[Citrix Licensing Server 11.x Unspecified Vulnerabilities]]></title>
  <description><![CDATA[Citrix Licensing Server 11.x Administration Console contains multiple unspecified vulnerabilities in third-party components. An attacker could gain access to the licensing administrative interface or cause a denial of service against licensing components. Exploitation requires interaction with an administrator authenticated to the Licensing Server (e.g. clicking a crafted link).]]></description>
  <pubDate>Tue, 22 Feb 2011 08:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110222]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110215</guid>
  <title><![CDATA[Oracle 10/11g exp.exe - param file Local Buffer Overflow]]></title>
  <description><![CDATA[Oracle Database is susceptible to a local buffer overflow vulnerability. Successful exploitation would yield arbitrary code execution under the context of the Oracle database.]]></description>
  <pubDate>Tue, 15 Feb 2011 08:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2011/20110215]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2010/20101222-(1)</guid>
  <title><![CDATA[Microsoft WMI Administrative Tools ActiveX Remote Code Execution]]></title>
  <description><![CDATA[Microsoft WMI Administrative Tools contains a vulnerability in the WBEMSingleView.ocx ActiveX object. Successful exploitation could allow execution of arbitrary code.]]></description>
  <pubDate>Wed, 22 Dec 2010 08:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2010/20101222-(1)]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2010/20101104</guid>
  <title><![CDATA[Adobe Reader printSeps() Heap Corruption]]></title>
  <description><![CDATA[Adobe Reader contain a heap corruption vulnerability that is caused by an undocumented API call, printSeps(). Calling this function, which is found in escript.api, could lead to an application crash or more potently, execution of arbitrary code in the context of the current user.]]></description>
  <pubDate>Thu, 04 Nov 2010 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2010/20101104]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2010/20101102</guid>
  <title><![CDATA[Trend Micro Titanium Maximum Security 2011 Local Kernel Level Privilege Escalation]]></title>
  <description><![CDATA[Trend Micro Maximum Security 2011 contains a local privilege escalation vulnerability that is caused by a pointer overwrite vulnerability. This could be leveraged to allow an attacker to gain kernel-level privileges and execute arbitrary code.]]></description>
  <pubDate>Tue, 02 Nov 2010 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2010/20101102]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2010/20100914</guid>
  <title><![CDATA[Microsoft Outlook Web Access (OWA) CSRF Privilege Elevation Vulnerability]]></title>
  <description><![CDATA[A Cross-site Request Forgery (CSRF) vulnerability within Microsoft Outlook Web Access could allow remote attackers to hijack an authenticated user's OWA session. This would allow the remote attacker to read, write, edit, and delete email's in the same context as the logged in user.]]></description>
  <pubDate>Tue, 14 Sep 2010 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2010/20100914]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2010/20100823</guid>
  <title><![CDATA[Microsoft Windows Insecure Library Loading Vulnerability  (DLL Hijacking)]]></title>
  <description><![CDATA[Multiple Microsoft Windows applications contain a vulnerability when loading DLLs, causing susceptibility to DLL preloading attacks. This is due to insecure programming practices and the search order Microsoft Windows performs when loading Dynamic Link Library modules. When combined, in certain scenarios, these two factors could allow an attacker to load a malicious DLL that would compromise the client's machine. Files that are opened by affected applications from attacker controlled locations (e.g. a WebDAV server, local directory, archive folder, etc.) could allow the attacker to execute arbitrary code at the logged-in user's privilege level.]]></description>
  <pubDate>Mon, 23 Aug 2010 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2010/20100823]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2010/20100811</guid>
  <title><![CDATA[Windows Service Isolation Bypass Privilege Elevation Vulnerability]]></title>
  <description><![CDATA[Microsoft Windows systems with Internet Information Services (IIS), SQL Server, and Windows Telephony Application Programming Interfaces (TAPI), contain a security issue in the way that Windows Service Isolation feature handles processes using the NetworkService account. An attacker that is able to execute untrusted code within a process owned by the NetworkService account could gain LocalSystem privileges and thus execute arbitrary code with elevated privileges.]]></description>
  <pubDate>Wed, 11 Aug 2010 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2010/20100811]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2010/20100630</guid>
  <title><![CDATA[Microsoft Internet Explorer 6 Memory Address Disclosure ]]></title>
  <description><![CDATA[Microsoft Internet Explorer&nbsp;6 contains a vulnerability when calculating timer ID&#39;s that could cause specific memory addresses (i.e. persistent memory locations) to be disclosed. If an attacker is able to combine knowledge of memory locations with a more critical vulnerability (e.g. one that could potentially allow code execution), then it could be further leveraged to bypass ASLR (Address Space Layout Randomization) protection.]]></description>
  <pubDate>Wed, 30 Jun 2010 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2010/20100630]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2010/20100608</guid>
  <title><![CDATA[Microsoft Office XP COM Object Instantiation Validation Vulnerability]]></title>
  <description><![CDATA[Microsoft Office XP contains an unspecified vulnerability when validating COM objects that have been instantiated within applications (e.g. Excel, PowerPoint, Publisher, Visio, Word). An attacker that is able to coerce a user into opening a crafted document could exploit this vulnerability to execute arbitrary code. Other Microsoft applications, such as Visual Studio 2003, may install the mso.dll library used by Office XP. Since there are no publicly acknowledged links between MS10-036 and Visual Studio 2003, exploitation may be possible and cannot be fully ruled out.]]></description>
  <pubDate>Tue, 08 Jun 2010 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2010/20100608]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2006/20061028</guid>
  <title><![CDATA[Internet Connection Sharing DoS]]></title>
  <description><![CDATA[A denial of service vulnerability exists within the Internet Connection Sharing service in Microsoft Windows XP. This vulnerability allows a LAN-side attacker to send a specialy-crafted DNS request to a vulnerable host in order to cause a denial of service for the ICS service, which also includes the Windows firewall service, potentially fostering further exploitation when the firewall is taken offline.]]></description>
  <pubDate>Sat, 28 Oct 2006 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2006/20061028]]></link>
</item><item>
  <guid isPermaLink="false">http://www.eeye.com/resources/security-center/research/zero-day-tracker/2005/20051116</guid>
  <title><![CDATA[RPC Memory Exhaustion]]></title>
  <description><![CDATA[The three referenced exploits take advantage of an inherent problem in RPC, in which an attacker gets to supply the size of an output buffer, and RPC allocates the buffer and (more importantly) initializes it to zeroes, which causes the entire memory range to become committed. For huge output buffers, the target service (which is given all the virtual memory it wants, due to its privileges) will cause virtual memory exhaustion, in the worst cases resulting in page file thrashing, a &quot;low virtual memory&quot; message, and general system unresponsiveness.<br />
<br />
For the UPNP service, the vulnerable function is PNP_GetDeviceList(), which is available over the RPC endpoint for the UPNP (8D9F4E40-A03D-11CE-8F69-08003E30051B) in opnum 0x0A. The MIDL for the vulnerable opnum is:<br />
long PNP_GetDeviceList (<br />
[in][unique][string] wchar_t * arg_1,<br />
[out][size_is(*arg_3)][length_is(*arg_3)] wchar_t * arg_3, //vulnerable argument<br />
[in, out] long * arg_3, //vulnerable argument<br />
[in] long arg_4<br />
);<br />
<br />
Regarding the Print Spooler service, the vulnerable function is GetPrinterData(), which is available over the RPC endpoint for the SPOOLSS (12345678-1234-abcd-ef00-0123456789ab) in opnum 0x1A. The MIDL for the vulnerable opnum is:<br />
long RpcGetPrinterData (<br />
[in][context_handle] void * arg_1,<br />
[in][string] wchar_t * arg_2,<br />
[out] long * arg_3,<br />
[out][size_is(arg_5)] char * arg_4, //vulnerable argument<br />
[in] long arg_5, //vulnerable argument<br />
[out] long * arg_6<br />
);<br />
<br />
<b>NOTE:</b> Because the vulnerability is inherent within RPC and not these specific services, it is likely that other services are also &quot;vulnerable&quot; to the same exploitation.]]></description>
  <pubDate>Wed, 16 Nov 2005 08:00:00 GMT</pubDate>
  <link><![CDATA[http://www.eeye.com/resources/security-center/research/zero-day-tracker/2005/20051116]]></link>
</item></channel>
</rss>

