Detection update for LNK vulnerability and others

August 1st, 2010
Comments Off

WEB-CLIENT Microsoft LNK shortcut download attempt (new)

CVE: 2010-2568
URL: http://www.microsoft.com/technet/security/advisory/2286198.mspx

Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2,
Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to
execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which
is not properly handled during icon display in Windows Explorer, as demonstrated
in the wild in July 2010, and originally reported for malware that leverages
CVE-2010-2772 in Siemens WinCC SCADA systems.

SQL WinCC DB default password security bypass attempt (new)

CVE: 2010-2568
URL: http://www.microsoft.com/technet/security/advisory/2286198.mspx

Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2,
Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to
execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which
is not properly handled during icon display in Windows Explorer, as demonstrated
in the wild in July 2010, and originally reported for malware that leverages
CVE-2010-2772 in Siemens WinCC SCADA systems.

BOTNET-CNC bagle.a http notification detection (updated)

URL: http://www.sophos.com/virusinfo/analyses/w32baglea.html
URL: http://www.symantec.com/security_response/writeup.jsp?docid=2004-011815-3332-99&tabid=2

BOTNET-CNC Trojan Peacomm command and control propagation detected (updated)

This Event has no details yet.

BOTNET-CNC Trojan Peacomm command and control propagation detected (updated)

This Event has no details yet.

BOTNET-CNC Trojan.Duntek Checkin GET Request (updated)

URL: http://www.symantec.com/security_response/writeup.jsp?docid=2006-102514-0554-99&tabid=2

BOTNET-CNC Asprox trojan initial query (updated)

URL: http://blogs.technet.com/neilcar/archive/2008/03/15/anatomy-of-a-sql-injection-incident-part-2-meat.aspx
URL: http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20080514

BOTNET-CNC Trojan.Bankpatch.C configuration attempt (updated)

URL: http://www.threatexpert.com/threats/trojan-bankpatch-c.html

BOTNET-CNC Trojan.Bankpatch.C malicious file download attempt (updated)

URL: http://www.threatexpert.com/threats/trojan-bankpatch-c.html

BOTNET-CNC Trojan.Bankpatch.C report home attempt (updated)

URL: http://www.threatexpert.com/threats/trojan-bankpatch-c.html

BOTNET-CNC Clampi virus communication detected (updated)

URL: http://www.symantec.com/security_response/writeup.jsp?docid=2008-011616-5036-99

BOTNET-CNC Zeus/Zbot malware config file download request (updated)

URL: http://www.viruslist.com/en/viruses/encyclopedia?virusid=21782783

BOTNET-CNC Sality virus HTTP GET request (updated)

URL: http://www.threatexpert.com/report.aspx?md5=b61aaef4d4dfbddbd8126c987fb77374

BOTNET-CNC Delf Trojan POST attempt (updated)

URL: http://www.threatexpert.com/report.aspx?md5=858295d163762748bf4821db5de041a1

BOTNET-CNC Backdoor SubSeven client connection to server (updated)

URL: http://www.threatexpert.com/report.aspx?md5=da8d7529a8a37335064ade9d04df08ad

BOTNET-CNC Hydraq/Aurora connection to C&C; server attempt (updated)

URL: http://www.virustotal.com/analisis/9051f618a5a8253a003167e65ce1311fa91a8b70d438a384be48b02e73ba855c-1263878624

BOTNET-CNC Possible Zeus User-Agent – _TEST_ (updated)

URL: http://en.wikipedia.org/wiki/Zeus_(trojan_horse)

BOTNET-CNC Possible Zeus User-Agent – ie (updated)

URL: http://en.wikipedia.org/wiki/Zeus_(trojan_horse)

BOTNET-CNC Possible Zeus User-Agent – Download (updated)

URL: http://en.wikipedia.org/wiki/Zeus_(trojan_horse)

BOTNET-CNC Possible Zeus User-Agent – Mozilla (updated)

URL: http://en.wikipedia.org/wiki/Zeus_(trojan_horse)

BOTNET-CNC Trojan command and control communication attempt (updated)

URL: http://www.threatexpert.com/report.aspx?md5=9a546564bf213ff866f48848f0f14027

BOTNET-CNC Koobface worm submission of collected data to C&C; server attempt (updated)

URL: http://threatexpert.com/report.aspx?md5=18395e9476bde417692f3a7ab807ac44

BOTNET-CNC Koobface contact to C&C; server attempt (updated)

URL: http://threatexpert.com/report.aspx?md5=efbc47d5e8f3ed68a13968cda586d68d

BOTNET-CNC Koobface request for captcha attempt (updated)

URL: http://threatexpert.com/report.aspx?md5=efbc47d5e8f3ed68a13968cda586d68d

BOTNET-CNC VanBot IRC communication attempt (updated)

URL: http://owned-nets.blogspot.com/2009/05/italianswiifatecihnocombaadshah-from.html

BOTNET-CNC Zbot malware config file download request (updated)

URL: http://www.threatexpert.com/report.aspx?md5=4cc069b84270be48bd84b7068dc3bf1a

BOTNET-CNC Zbot malware config file download request (updated)

URL: http://www.threatexpert.com/report.aspx?md5=2a2419d34c7990297d9a2f7413a9af2a

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16809.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16810.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16811.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16812.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16813.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16814.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16815.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16816.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16817.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16818.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16819.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16820.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16821.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16822.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16823.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16824.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16825.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16826.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16827.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16828.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16829.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16830.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16831.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16832.html

BOTNET-CNC known command and control channel traffic (updated)

URL: http://labs.snort.org/docs/16833.html

BLACKLIST DNS request for known malware domain qd.netkill.com.cn – Trojan-Downloader.Win32.Adload.rzx (updated)

URL: http://labs.snort.org/docs/16834.html

BLACKLIST DNS request for known malware domain exe.146843.com – Trojan.Win32.Opeg.a (updated)

URL: http://labs.snort.org/docs/16835.html

BLACKLIST DNS request for known malware domain ra03.e5732.com – Trojan-Clicker.Win32.Small.afg (updated)

URL: http://labs.snort.org/docs/16836.html

BLACKLIST DNS request for known malware domain dangercheats.com.br – Trojan.Win32.Refroso.arnq (updated)

URL: http://labs.snort.org/docs/16837.html

BLACKLIST DNS request for known malware domain xlm.ppvsr.com – Trojan-GameThief.Win32.OnLineGames.wwcf (updated)

URL: http://labs.snort.org/docs/16838.html

BLACKLIST DNS request for known malware domain sh16.e8753.com – Trojan.Win32.Scar.ccqb (updated)

URL: http://labs.snort.org/docs/16839.html

BLACKLIST DNS request for known malware domain rx11.e6532.com – Trojan.Win32.Opeg.a (updated)

URL: http://labs.snort.org/docs/16840.html

BLACKLIST DNS request for known malware domain podgorz.org – Trojan-Spy.Win32.Zbot.gen (updated)

URL: http://labs.snort.org/docs/16841.html

BLACKLIST DNS request for known malware domain sp19.e4578.com – Trojan-Downloader.Win32.Genome.njz (updated)

URL: http://labs.snort.org/docs/16842.html

BLACKLIST DNS request for known malware domain 1.7zsm.com – Trojan-Downloader.Win32.Agent.dtuo (updated)

URL: http://labs.snort.org/docs/16843.html

BLACKLIST DNS request for known malware domain rm08.e4562.com – Trojan-Downloader.Win32.Agent.dngx (updated)

URL: http://labs.snort.org/docs/16844.html

BLACKLIST DNS request for known malware domain rc04.e6532.com – Trojan-Downloader.Win32.Genome.awld (updated)

URL: http://labs.snort.org/docs/16845.html

BLACKLIST DNS request for known malware domain bedayton.com – Trojan-Downloader.Win32.Agent.dlhe (updated)

URL: http://labs.snort.org/docs/16846.html

BLACKLIST DNS request for known malware domain rz12.e6805.com – Trojan-Downloader.Win32.Genome.awld (updated)

URL: http://labs.snort.org/docs/16847.html

BLACKLIST DNS request for known malware domain in.chinaitlm.cn – Trojan.VBS.HideIcon.d (updated)

URL: http://labs.snort.org/docs/16848.html

BLACKLIST DNS request for known malware domain re05.e6532.com – Trojan-Downloader.Win32.Genome.awld (updated)

URL: http://labs.snort.org/docs/16849.html

BLACKLIST DNS request for known malware domain kldmten.net – Trojan-Spy.Win32.Zbot.akra (updated)

URL: http://labs.snort.org/docs/16850.html

BLACKLIST DNS request for known malware domain forelc.cc – Trojan-Ransom.Win32.XBlocker.ahe (updated)

URL: http://labs.snort.org/docs/16851.html

BLACKLIST DNS request for known malware domain v.yao63.com – Trojan-Downloader.Win32.Agent.dqns (updated)

URL: http://labs.snort.org/docs/16852.html

BLACKLIST DNS request for known malware domain vh26.e4578.com – Trojan.Win32.Opeg.a (updated)

URL: http://labs.snort.org/docs/16853.html

BLACKLIST DNS request for known malware domain up1.give2sms.com – Trojan-Downloader.Win32.Genome.est (updated)

URL: http://labs.snort.org/docs/16854.html

BLACKLIST DNS request for known malware domain d.123kuaihuo.com – Trojan.Win32.Scar.clbx (updated)

URL: http://labs.snort.org/docs/16855.html

BLACKLIST DNS request for known malware domain andy.cd – Backdoor.Win32.Agent.auto (updated)

URL: http://labs.snort.org/docs/16856.html

BLACKLIST DNS request for known malware domain site.mynet.com – Trojan.Win32.Buzus.dxsr (updated)

URL: http://labs.snort.org/docs/16857.html

BLACKLIST DNS request for known malware domain charter-x.biz – Packed.Win32.Krap.ae (updated)

URL: http://labs.snort.org/docs/16858.html

BLACKLIST DNS request for known malware domain gerherber.com – Trojan-Spy.Win32.Zbot.akdw (updated)

URL: http://labs.snort.org/docs/16859.html

BLACKLIST DNS request for known malware domain urodinam.net – Trojan.Win32.TDSS.azsj (updated)

URL: http://labs.snort.org/docs/16860.html

BLACKLIST DNS request for known malware domain gite-eguisheim.com – Trojan-Downloader.Win32.Piker.clp (updated)

URL: http://labs.snort.org/docs/16861.html

BLACKLIST DNS request for known malware domain phaizeipeu.ru – Packed.Win32.Krap.gx (updated)

URL: http://labs.snort.org/docs/16862.html

BLACKLIST DNS request for known malware domain teendx.com – Trojan-Spy.Win32.Zbot.gen (updated)

URL: http://labs.snort.org/docs/16863.html

BLACKLIST DNS request for known malware domain taiping2033.2288.org – Trojan-Downloader.Win32.Selvice.afy (updated)

URL: http://labs.snort.org/docs/16864.html

BLACKLIST DNS request for known malware domain cnfg.maxsitesrevenues.net – Trojan.Win32.BHO.afke (updated)

URL: http://labs.snort.org/docs/16865.html

BLACKLIST DNS request for known malware domain members.multimania.co.uk – Trojan.Win32.Inject.ahqv (updated)

URL: http://labs.snort.org/docs/16866.html

BLACKLIST DNS request for known malware domain down.toopc.com – Trojan-Dropper.Win32.Clons.hai (updated)

URL: http://labs.snort.org/docs/16867.html

BLACKLIST DNS request for known malware domain hostshack.net – Trojan.Win32.Buzus.empl (updated)

URL: http://labs.snort.org/docs/16868.html

BLACKLIST DNS request for known malware domain tt.vv49.com – Trojan-GameThief.Win32.OnLineGames.bnkb (updated)

URL: http://labs.snort.org/docs/16869.html

BLACKLIST DNS request for known malware domain search.sidegreen.com – Backdoor.Win32.Agent.arqi (updated)

URL: http://labs.snort.org/docs/16870.html

BLACKLIST DNS request for known malware domain parfaitpournous.com – Trojan-Spy.Win32.Zbot.gen (updated)

URL: http://labs.snort.org/docs/16871.html

BLACKLIST DNS request for known malware domain postmetoday.ru – Packed.Win32.Katusha.j (updated)

URL: http://labs.snort.org/docs/16872.html

BLACKLIST DNS request for known malware domain youword.cn – Trojan.Win32.Scar.bvgu (updated)

URL: http://labs.snort.org/docs/16873.html

BLACKLIST DNS request for known malware domain ophaeghaev.ru – Trojan-Spy.Win32.Zbot.akmi (updated)

URL: http://labs.snort.org/docs/16874.html

BLACKLIST DNS request for known malware domain up1.free-sms.co.kr – Trojan.Win32.Vilsel.akp (updated)

URL: http://labs.snort.org/docs/16875.html

BLACKLIST DNS request for known malware domain c.softdowns.info – Trojan.BAT.Agent.yn (updated)

URL: http://labs.snort.org/docs/16876.html

BLACKLIST DNS request for known malware domain ddkom.biz – Trojan.Win32.Scar.ckhr (updated)

URL: http://labs.snort.org/docs/16877.html

BLACKLIST DNS request for known malware domain vopret.ru – Trojan.Win32.FraudPack.axwn (updated)

URL: http://labs.snort.org/docs/16878.html

BLACKLIST DNS request for known malware domain dnfpomo.dnfranran.com – Trojan-GameThief.Win32.OnLineGames.bnkx (updated)

URL: http://labs.snort.org/docs/16879.html

BLACKLIST DNS request for known malware domain dnfuu.3322.org – Trojan-Downloader.Win32.Genome.asrx (updated)

URL: http://labs.snort.org/docs/16880.html

BLACKLIST DNS request for known malware domain sex-gifts.ru – Trojan-Spy.Win32.Zbot.gen (updated)

URL: http://labs.snort.org/docs/16881.html

BLACKLIST DNS request for known malware domain 111.168lala.com – Backdoor.Win32.Popwin.cyn (updated)

URL: http://labs.snort.org/docs/16882.html

BLACKLIST DNS request for known malware domain mcafee-registry.ru – Trojan-Spy.Win32.Zbot.akgb (updated)

URL: http://labs.snort.org/docs/16883.html

BLACKLIST DNS request for known malware domain bits4ever.ru – Trojan-Spy.Win32.Zbot.aknt (updated)

URL: http://labs.snort.org/docs/16884.html

BLACKLIST DNS request for known malware domain monicaecarlos.com – Trojan-Downloader.Win32.Genome.awxv (updated)

URL: http://labs.snort.org/docs/16885.html

BLACKLIST DNS request for known malware domain d.trymedia.com – Trojan-Dropper.Win32.Delf.fkk (updated)

URL: http://labs.snort.org/docs/16886.html

BLACKLIST DNS request for known malware domain hesneclimi.ru – Packed.Win32.Krap.ae (updated)

URL: http://labs.snort.org/docs/16887.html

BLACKLIST DNS request for known malware domain dbtte.com – Trojan-Banker.Win32.Banz.crk (updated)

URL: http://labs.snort.org/docs/16888.html

BLACKLIST DNS request for known malware domain h1.ripway.com – Trojan.Win32.Refroso.bcdq (updated)

URL: http://labs.snort.org/docs/16889.html

BLACKLIST DNS request for known malware domain in6cs.com – Trojan.Win32.Tdss.beea (updated)

URL: http://labs.snort.org/docs/16890.html

BLACKLIST DNS request for known malware domain solo1928.ru – Trojan-Spy.Win32.Zbot.gen (updated)

URL: http://labs.snort.org/docs/16891.html

BLACKLIST DNS request for known malware domain fg545633.host.zgridc.com – Trojan.Win32.Pincav.abub (updated)

URL: http://labs.snort.org/docs/16892.html

BLACKLIST DNS request for known malware domain primusdns.ru – Backdoor.Win32.Havar.eh (updated)

URL: http://labs.snort.org/docs/16893.html

BLACKLIST DNS request for known malware domain eq.pccppc.com – Trojan-Downloader.Win32.Pher.fkl (updated)

URL: http://labs.snort.org/docs/16894.html

BLACKLIST DNS request for known malware domain alodh.in – Backdoor.Win32.Delf.vde (updated)

URL: http://labs.snort.org/docs/16895.html

BLACKLIST DNS request for known malware domain reward.pnshop.co.kr – Backdoor.Win32.Agent.ahra (updated)

URL: http://labs.snort.org/docs/16896.html

BLACKLIST DNS request for known malware domain sympathy.hdnews.net – Trojan-Spy.Win32.Zbot.gen (updated)

URL: http://labs.snort.org/docs/16897.html

BLACKLIST DNS request for known malware domain sx21.e4578.com – Trojan.Win32.Scar.ccqb (updated)

URL: http://labs.snort.org/docs/16898.html

BLACKLIST DNS request for known malware domain downloadering.9966.org – Trojan.Win32.Vilsel.adxv (updated)

URL: http://labs.snort.org/docs/16899.html

BLACKLIST DNS request for known malware domain reportes201.com – Trojan-Downloader.Win32.Genome.ashe (updated)

URL: http://labs.snort.org/docs/16900.html

BLACKLIST DNS request for known malware domain local.1140.co.kr – Trojan-Downloader.Win32.Genome.aobm (updated)

URL: http://labs.snort.org/docs/16901.html

BLACKLIST DNS request for known malware domain promojoy.net – Packed.Win32.Krap.gx (updated)

URL: http://labs.snort.org/docs/16902.html

BLACKLIST DNS request for known malware domain gpwg.ws – Worm.Win32.AutoRun.bjca (updated)

URL: http://labs.snort.org/docs/16903.html

BLACKLIST DNS request for known malware domain xoomer.alice.it – Trojan-Downloader.Win32.Banload.kdu (updated)

URL: http://labs.snort.org/docs/16904.html

BLACKLIST DNS request for known malware domain xoomer.virgilio.it – Backdoor.Win32.Clar.d (updated)

URL: http://labs.snort.org/docs/16905.html

BLACKLIST DNS request for known malware domain down.p2pplay.com – Trojan-GameThief.Win32.OnLineGames.wgkv (updated)

URL: http://labs.snort.org/docs/16906.html

BLACKLIST DNS request for known malware domain livetrust.info – Trojan-Spy.Win32.Zbot.akku (updated)

URL: http://labs.snort.org/docs/16907.html

BLACKLIST DNS request for known malware domain ootaivilei.ru – Trojan-Spy.Win32.Zbot.akme (updated)

URL: http://labs.snort.org/docs/16908.html

BLACKLIST DNS request for known malware domain babah20122012.com – Trojan-Spy.Win32.Zbot.akbb (updated)

URL: http://labs.snort.org/docs/16909.html

BLACKLIST DNS request for known malware domain pattern – 0-0-0-0-0-0-0.info (updated)

URL: http://labs.snort.org/docs/16910.html

BLACKLIST URI request for known malicious URI – ucsp0416.exe?t= (updated)

URL: http://labs.snort.org/docs/16911.html

BLACKLIST URI request for known malicious URI – net/cfg2.bin (updated)

URL: http://labs.snort.org/docs/16912.html

BLACKLIST URI request for known malicious URI – count_log/log/boot.php?p= (updated)

URL: http://labs.snort.org/docs/16913.html

BLACKLIST URI request for known malicious URI – .bin?ucsp (updated)

URL: http://labs.snort.org/docs/16914.html

BLACKLIST URI request for known malicious URI – /MNG/Download/?File=AZF (updated)

URL: http://labs.snort.org/docs/16915.html

BLACKLIST URI request for known malicious URI – /jarun/jezerce (updated)

URL: http://labs.snort.org/docs/16916.html

BLACKLIST URI request for known malicious URI – /ekaterina/velika (updated)

URL: http://labs.snort.org/docs/16917.html

BLACKLIST URI request for known malicious URI – /ultimate/fight (updated)

URL: http://labs.snort.org/docs/16918.html

BLACKLIST URI request for known malicious URI – /tmp/pm.exe?t= (updated)

URL: http://labs.snort.org/docs/16919.html

BLACKLIST URI request for known malicious URI – /DownLoadFile/BaePo/ver (updated)

URL: http://labs.snort.org/docs/16920.html

BLACKLIST URI request for known malicious URI – /s1/launcher/update/Update/data/ (updated)

URL: http://labs.snort.org/docs/16921.html

BLACKLIST URI request for known malicious URI – /cgi-bin/rd.cgi?f=/vercfg.dat?AgentID= (updated)

URL: http://labs.snort.org/docs/16922.html

BLACKLIST URI request for known malicious URI – /search.php?username=coolweb07&keywords;= (updated)

URL: http://labs.snort.org/docs/16923.html

BLACKLIST URI request for known malicious URI – /inst.php?fff= (updated)

URL: http://labs.snort.org/docs/16924.html

BLACKLIST URI request for known malicious URI – /message.php?subid= (updated)

URL: http://labs.snort.org/docs/16925.html

BLACKLIST URI request for known malicious URI – strMode=setup&strID;=pcvaccine&strPC;= (updated)

URL: http://labs.snort.org/docs/16926.html

BLACKLIST URI request for known malicious URI – MGWEB.php?c=TestUrl (updated)

URL: http://labs.snort.org/docs/16927.html

BLACKLIST URI request for known malicious URI – /stat.html?0dPg0uXTraCSqrOdlrKpmpyorePbz (updated)

URL: http://labs.snort.org/docs/16928.html

BLACKLIST URI request for known malicious URI – gate.php?guid= (updated)

URL: http://labs.snort.org/docs/16929.html

BLACKLIST URI request for known malicious URI – count.asp?mac= (updated)

URL: http://labs.snort.org/docs/16930.html

BLACKLIST URI request for known malicious URI – feedbigfoot.php?m= (updated)

URL: http://labs.snort.org/docs/16931.html

BLACKLIST URI request for known malicious URI – /qqnongchang/qqkj. (updated)

URL: http://labs.snort.org/docs/16932.html

BLACKLIST URI request for known malicious URI – /root/9 frt.rar (updated)

URL: http://labs.snort.org/docs/16933.html

research Detection, New Logic

Rule Update

June 11th, 2010
Comments Off

SPECIFIC-THREATS Adobe Reader and Acrobat authplay.dll vulnerability exploit attempt (new)


This Event has no details yet.

WEB-MISC Microsoft Windows Help Centre escape sequence XSS attempt (new)


This Event has no details yet.

WEB-MISC long basic authorization string (updated)

Bugtraq: 3230
CVE: 2001-1067

Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of
service, and possibly execute arbitrary code, via an HTTP request with a long
Authorization header.

MULTIMEDIA Windows Media download (updated)

This Event has no details yet.

WEB-CLIENT Content-Disposition CLSID command attempt (updated)

Bugtraq: 9510
CVE: 2004-0420
URL: http://www.microsoft.com/technet/security/bulletin/ms04-024.mspx

The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows
2000, Windows XP, and Windows Server 2003 allows remote attackers to execute
arbitrary code by spoofing the type of a file via a CLSID specifier in the
filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.

WEB-CLIENT bitmap BitmapOffset integer overflow attempt (updated)

Bugtraq: 9663
CVE: 2004-0566
URL: http://www.microsoft.com/technet/security/bulletin/ms04-025.mspx

Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to
execute arbitrary code via a BMP image with a large bfOffBits value.

WEB-CLIENT JPEG parser heap overflow attempt (updated)

Bugtraq: 11173
CVE: 2004-0200
URL: http://www.microsoft.com/security/bulletins/200409_jpeg.mspx

Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device
Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute
arbitrary code via a JPEG image with a small JPEG COM field length that is
normalized to a large integer length before a memory copy operation.

WEB-CLIENT Windows Media Player directory traversal via Content-Disposition attempt (updated)

Bugtraq: 7517
CVE: 2003-0228
URL: http://www.microsoft.com/technet/security/bulletin/MS03-017.mspx

Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and
Windows Media Player for Windows XP allows remote attackers to execute arbitrary
code via a skins file with a URL containing hex-encoded backslash characters
(%5C) that causes an executable to be placed in an arbitrary location.

WEB-CLIENT Mozilla GIF single packet heap overflow – NETSCAPE2.0 (updated)

Bugtraq: 12881
CVE: 2005-0399

Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before
to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use
the same library, allows remote attackers to execute arbitrary code via a GIF
image with a crafted Netscape extension 2 block and buffer size.

WEB-CLIENT GIF transfer (updated)

This Event has no details yet.

WEB-CLIENT Bitmap width integer overflow attempt (updated)

Bugtraq: 11171
CVE: 2004-0904
CVE: 2008-3015
URL: http://bugzilla.mozilla.org/show_bug.cgi?id=255067
URL: http://www.microsoft.com/technet/security/bulletin/MS08-052.mspx

Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003
SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2,
PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000
Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008,
and Forefront Client Security 1.0 allows remote attackers to execute arbitrary
code via a BMP image file with a malformed BitMapInfoHeader that triggers a
buffer overflow, aka “GDI+ BMP Integer Overflow Vulnerability.”

WEB-CLIENT multipacket CHM file transfer start (updated)

This Event has no details yet.

WEB-CLIENT IE JPEG heap overflow single packet attempt (updated)

Bugtraq: 14282
Bugtraq: 14284
CVE: 2005-1988
URL: http://www.microsoft.com/technet/security/bulletin/MS05-038.mspx

Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote
attackers to execute arbitrary code via a web site or an HTML e-mail containing
a crafted JPEG image that causes memory corruption, aka “JPEG Image Rendering
Memory Corruption Vulnerability”.

WEB-CLIENT multipacket CBO CBL CBM file transfer start (updated)

This Event has no details yet.

WEB-CLIENT quicktime movie file transfer (updated)

This Event has no details yet.

WEB-CLIENT quicktime movie file component name integer overflow attempt (updated)

Bugtraq: 15308
CVE: 2005-2754
URL: http://docs.info.apple.com/article.html?artnum=302772

Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers
to execute arbitrary code via a crafted MOV file with “Improper movie
attributes.”

SPYWARE-PUT Trackware alexa runtime detection (updated)

URL: http://www.spywareguide.com/product_show.php?id=418
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453075454

SPYWARE-PUT Hijacker begin2search runtime detection – pass information (updated)

URL: http://www.spywareguide.com/product_show.php?id=924
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453088175

SPYWARE-PUT Snoopware casinoonnet runtime detection (updated)

URL: http://www.spyany.com/program/article_adw_rm_CasinoOnNet.html
URL: http://www.spywareguide.com/product_show.php?id=1254

SPYWARE-PUT Hijacker freescratch runtime detection – get card (updated)

URL: http://www.spywareguide.com/product_show.php?id=478
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453073903

SPYWARE-PUT keylogger pc actmon pro runtime detection – http (updated)

URL: http://www.spywareguide.com/product_show.php?id=1989

SPYWARE-PUT Trackware myway speedbar runtime detection – request config (updated)

URL: http://www.adwarereport.com/mt/archives/000062.html
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453090405

SPYWARE-PUT Trickler conscorr runtime detection (updated)

URL: http://www.spywareguide.com/product_show.php?id=1034

SPYWARE-PUT Adware gamespy_arcade runtime detection (updated)

URL: http://www.spywareguide.com/product_show.php?id=1241

SPYWARE-PUT Trackware ucmore runtime detection – track activity (updated)

URL: http://www.spywareguide.com/product_show.php?id=776
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=58660

SPYWARE-PUT Trackware ucmore runtime detection – get sponsor/ad links (updated)

URL: http://www.spywareguide.com/product_show.php?id=776
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=58660

SPYWARE-PUT Adware warez_p2p runtime detection – .txt .dat and .lst requests (updated)

URL: http://www.spywareguide.com/category_show.php?id=5

SPYWARE-PUT Hijacker couponbar runtime detection – get updates to toolbar buttons (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453079137

SPYWARE-PUT Trickler VX2/ABetterInternet transponder thinstaller runtime detection – post information (updated)

URL: http://research.sunbelt-software.com/threat_display.cfm?name=ABetterInternet&threatid=14797
URL: http://www.doxdesk.com/parasite/Transponder.html
URL: http://www.geekstogo.com/forum/Aurora_spyware_Nailexe-t24344.html

SPYWARE-PUT Hijacker copernic meta toolbar runtime detection – pass info to server (updated)

URL: http://www.copernic.com/en/products/meta/

SPYWARE-PUT Hijacker shopnav runtime detection – collect information (updated)

URL: http://www.spywareguide.com/product_show.php?id=582

SPYWARE-PUT Trackware wordiq toolbar runtime detection – get link info (updated)

URL: http://www.softpedia.com/progReportSpyware/12-3-196

SPYWARE-PUT Trackware adtools runtime detection – track user activity (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453082798

SPYWARE-PUT Trackware adtools-screenmate runtime detection – generate desktop alert (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453082798

SPYWARE-PUT Trackware adtools-communicator runtime detection – collect information (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453082798

SPYWARE-PUT Trackware adtools-communicator runtime detection – download self-update (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453082798

SPYWARE-PUT Adware download accelerator plus runtime detection – startup (updated)

URL: http://reviews.cnet.com/Download_Accelerator_Plus_5_3/4505-3513_7-20035409.html

SPYWARE-PUT Adware download accelerator plus runtime detection – download files (updated)

URL: http://reviews.cnet.com/Download_Accelerator_Plus_5_3/4505-3513_7-20035409.html

SPYWARE-PUT Adware download accelerator plus runtime detection – update (updated)

URL: http://reviews.cnet.com/Download_Accelerator_Plus_5_3/4505-3513_7-20035409.html

SPYWARE-PUT Hijacker dropspam runtime detection – pass information to its controlling server (updated)

URL: http://www.spywareguide.com/product_show.php?id=2437
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453097437

SPYWARE-PUT Hijacker dropspam runtime detection – third party information collection (updated)

URL: http://www.spywareguide.com/product_show.php?id=2437
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453097437

SPYWARE-PUT Trackware supreme toolbar runtime detection – track (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453097530

SPYWARE-PUT Trackware supreme toolbar runtime detection – pass information to its controlling server (updated)

URL: http://www.spywareguide.com/product_show.php?id=2437
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453097437

SPYWARE-PUT Trackware supreme toolbar runtime detection – third party information collection (updated)

URL: http://www.spywareguide.com/product_show.php?id=2437
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453097437

SPYWARE-PUT Adware weirdontheweb runtime detection – log url (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094260

SPYWARE-PUT Trackware iggsey toolbar detection – pass information to server (updated)

URL: http://www.spywareguide.com/product_show.php?id=2463
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094796

SPYWARE-PUT Hijacker 123mania runtime detection – sidesearch hijacking (updated)

URL: http://www.spywareguide.com/product_show.php?id=940

SPYWARE-PUT Trackware browserpal runtime detection – adblocker function (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453074906

SPYWARE-PUT trackware searchinweb detection – collect information (updated)

URL: http://www.spywareguide.com/product_show.php?id=1787

SPYWARE-PUT hijacker topfive searchassistant detection – update (updated)

URL: http://www.spywareguide.com/product_show.php?id=2645

SPYWARE-PUT Adware powerstrip runtime detection (updated)

URL: http://www.spywareguide.com/product_show.php?id=522
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453074932

SPYWARE-PUT Trickler teomasearchbar runtime detection (updated)

URL: http://www.castlecops.com/tk731-Teoma_Bar.html

SPYWARE-PUT Adware seekmo runtime detection – pop up ads (updated)

URL: http://www.spywareguide.com/product_show.php?id=2368

SPYWARE-PUT Hijacker smart shopper runtime detection – track/upgrade/report activities (updated)

URL: http://vil.mcafeesecurity.com/vil/content/v_133312.htm

SPYWARE-PUT Trackware squaretrade side bar runtime detection – collect user information (updated)

URL: http://sidebar.squaretrade.com
URL: http://vil.mcafeesecurity.com/vil/content/v_137515.htm

SPYWARE-PUT Trickler farmmext installtime/update request (updated)

URL: http://www.spyany.com/files/farmmext_exe.html
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453090784

SPYWARE-PUT Adware lop runtime detection – collect info request 2 (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453076024

SPYWARE-PUT Adware lop runtime detection – pop up ads (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453076024

SPYWARE-PUT Adware hotbar runtime detection – hotbar user-agent (updated)

URL: http://www.spywareguide.com/product_show.php?id=481
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453075474

SPYWARE-PUT Trackware quicksearch toolbar runtime detection – update (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453090680

SPYWARE-PUT Adware searchsquire runtime detection – get engine file (updated)

URL: http://www.spywareguide.com/product_show.php?id=584
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094363

SPYWARE-PUT Trickler clickalchemy runtime detection (updated)

URL: http://www.spywareguide.com/product_show.php?id=1095

SPYWARE-PUT Hijacker incredifind runtime detection – cookie (updated)

URL: http://www.spywareguide.com/product_show.php?id=530
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453077295

SPYWARE-PUT Hijacker sidefind runtime detection – cookie (updated)

URL: http://www.spywareguide.com/product_show.php?id=1147
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453088285

SPYWARE-PUT Hijacker customtoolbar runtime detection (updated)

URL: http://www.spywareguide.com/product_show.php?id=1182
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453074937

SPYWARE-PUT Adware targetsaver runtime detection (updated)

URL: http://www.spywareguide.com/product_show.php?id=1914
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453090707

SPYWARE-PUT Adware excite search bar runtime detection – config (updated)

URL: http://www.scanspyware.net/info/ExciteSearchBar.htm
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453078495

SPYWARE-PUT Hijacker richfind update detection (updated)

URL: http://users.telenet.be/marcvn/spyware/1954375.htm
URL: http://www.f-secure.com/sw-desc/iehijacker_richfind.shtml

SPYWARE-PUT Hijacker richfind auto search redirect detection (updated)

URL: http://users.telenet.be/marcvn/spyware/1954375.htm
URL: http://www.f-secure.com/sw-desc/iehijacker_richfind.shtml

SPYWARE-PUT Hijacker adblock update detection (updated)

URL: http://adblock.linkz.com/Home.php
URL: http://www.spywareguide.com/product_show.php?id=48

SPYWARE-PUT Hijacker adblock auto search redirect detection (updated)

URL: http://adblock.linkz.com/Home.php
URL: http://www.spywareguide.com/product_show.php?id=48

SPYWARE-PUT Hijacker adblock ie search assistant redirect detection (updated)

URL: http://adblock.linkz.com/Home.php
URL: http://www.spywareguide.com/product_show.php?id=48

SPYWARE-PUT Trickler wsearch runtime detection – auto update (updated)

URL: http://www.zhongsou.com

SPYWARE-PUT Trickler wsearch runtime detection – mp3 search (updated)

URL: http://www.zhongsou.com

SPYWARE-PUT Trickler wsearch runtime detection – desktop search (updated)

URL: http://www.zhongsou.com

SPYWARE-PUT Hijacker need2find initial configuration detection (updated)

URL: http://www.spywareguide.com/product_show.php?id=2195
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453096250

SPYWARE-PUT Adware altnet runtime detection – initial retrieval (updated)

URL: http://www.spywareguide.com/product_show.php?id=1369
URL: http://www.spywareremove.com/removeAltnet.html

SPYWARE-PUT Adware altnet runtime detection – update (updated)

URL: http://www.spywareguide.com/product_show.php?id=1369
URL: http://www.spywareremove.com/removeAltnet.html

SPYWARE-PUT Adware altnet runtime detection – status report (updated)

URL: http://www.spywareguide.com/product_show.php?id=1369
URL: http://www.spywareremove.com/removeAltnet.html

SPYWARE-PUT Hijacker microgaming runtime detection (updated)

URL: http://www.f-secure.com/sw-desc/microgaming.shtml
URL: http://www.spywareremove.com/removeMicrogaming.html

SPYWARE-PUT adware surfaccuracy runtime detection (updated)

URL: http://securityresponse.symantec.com/avcenter/venc/data/adware.surfaccuracy.html
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094263

SPYWARE-PUT Hijacker imeshbar runtime detection (updated)

URL: http://www.file.net/process/imeshbar.dll.html

SPYWARE-PUT Other-Technologies sony rootkit runtime detection (updated)

URL: http://www.schneier.com/blog/archives/2005/11/sonys_drm_rootk.html
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453096362

SPYWARE-PUT Trickler eacceleration downloadreceiver user-agent string detected (updated)

URL: http://www.spywareguide.com/product_show.php?id=398

SPYWARE-PUT Trickler spyblocs eblocs detection – get wsliveup.dat (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453088571

SPYWARE-PUT Trickler spyblocs eblocs detection – stbarpat.dat (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453088571

SPYWARE-PUT Trickler spyblocs eblocs detection – get spyblpat.dat/spyblini.ini (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453088571

SPYWARE-PUT Trickler spyblocs.eblocs detection – register request (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453088571

SPYWARE-PUT Hijacker girafa toolbar – toolbar update (updated)

URL: http://www.spywareguide.com/product_show.php?id=1135

SPYWARE-PUT Hijacker adbars runtime detection – search in toolbar (updated)

URL: http://www.spywareguide.com/product_show.php?id=1331
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453079049

SPYWARE-PUT Hijacker dotcomtoolbar runtime detection – toolbar information retrieve (updated)

URL: http://www.spywareguide.com/product_show.php?id=628
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453076986

SPYWARE-PUT Hijacker dotcomtoolbar runtime detection – url hook (updated)

URL: http://www.spywareguide.com/product_show.php?id=628
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453076986

SPYWARE-PUT Adware esyndicate runtime detection – postinstall request (updated)

URL: http://www.spywareguide.com/product_show.php?id=1759
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094058

SPYWARE-PUT Hijacker zeropopup runtime detection (updated)

URL: http://www.spywareguide.com/product_show.php?id=627
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453075510

SPYWARE-PUT Hijacker adstart runtime detection (updated)

URL: http://www.spywareguide.com/product_show.php?id=1750
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453088444

SPYWARE-PUT Trackware searchingall toolbar runtime detection – send user url request (updated)

URL: http://www.spywareguide.com/product_show.php?id=2581
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453097487

SPYWARE-PUT Snoopware totalvelocity zsearch runtime detection (updated)

URL: http://www.spywareguide.com/product_show.php?id=763
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453083031

SPYWARE-PUT Hijacker cws.cameup runtime detection – home page (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453079081

SPYWARE-PUT Hijacker cws.cameup runtime detection – search (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453079081

SPYWARE-PUT Hijacker makemesearch toolbar runtime detection – home page hijacker (updated)

URL: http://www.spywaredetails.com/index.php?a=spyware&act=read&id=1607

SPYWARE-PUT Hijacker makemesearch toolbar runtime detection – search (updated)

URL: http://www.spywaredetails.com/index.php?a=spyware&act=read&id=1607

SPYWARE-PUT Adware searchnugget toolbar runtime detection – check updates (updated)

URL: http://www.symantec.com/avcenter/venc/data/adware.searchnugget.html
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094349

SPYWARE-PUT Adware searchnugget toolbar runtime detection – redirect mistyped urls (updated)

URL: http://www.symantec.com/avcenter/venc/data/adware.searchnugget.html
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094349

SPYWARE-PUT Hijacker analyze IE runtime detection – default page hijacker (updated)

URL: http://www.spywaredetails.com/index.php?a=spyware&act=read&id=1680

SPYWARE-PUT Dialer yeaknet runtime detection – home page hijacker (updated)

URL: http://www.spywareguide.com/product_show.php?id=2446

SPYWARE-PUT Dialer yeaknet runtime detection – post-installation (updated)

URL: http://www.spywareguide.com/product_show.php?id=2446

SPYWARE-PUT Trickler Backdoor-BAC.gen.e runtime detection – post data (updated)

URL: http://vil.mcafeesecurity.com/vil/content/v_138750.htm

SPYWARE-PUT Adware yourenhancement runtime detection (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453097585

SPYWARE-PUT Hijacker troj_spywad.x runtime detection (updated)

URL: http://www.sophos.com/virusinfo/analyses/trojspywadi.html

SPYWARE-PUT Adware adpowerzone runtime detection (updated)

URL: http://www.spywareguide.com/product_show.php?id=1299

SPYWARE-PUT Hijacker extreme biz runtime detection – uniq1 (updated)

URL: http://vil.nai.com/vil/content/v_139122.htm

SPYWARE-PUT Trickler generic downloader.g runtime detection – spyware injection (updated)

URL: http://vil.mcafeesecurity.com/vil/content/v_128719.htm

SPYWARE-PUT Trickler generic downloader.g runtime detection – adv (updated)

URL: http://vil.mcafeesecurity.com/vil/content/v_128719.htm

SPYWARE-PUT Adware webredir runtime detection (updated)

URL: http://castlecops.com/tk1907-pxwma_dll.html

SPYWARE-PUT Trickler download arq variant runtime detection (updated)

URL: http://vil.nai.com/vil/content/v_137359.htm

SPYWARE-PUT Hijacker vip01 biz runtime detection – adv (updated)

URL: http://forums.maddoktor2.com/index.php?showtopic=3601

SPYWARE-PUT Other-Technologies alfacleaner runtime detection – update (updated)

URL: http://www.spywareguide.com/product_show.php?id=2733

SPYWARE-PUT Other-Technologies alfacleaner runtime detection – buy (updated)

URL: http://www.spywareguide.com/product_show.php?id=2733

SPYWARE-PUT Hijacker traffbest biz runtime detection – adv (updated)

URL: http://forums.maddoktor2.com/index.php?showtopic=3601

SPYWARE-PUT Hijacker wowok mp3 bar runtime detection – advertising 1 (updated)

URL: http://www.zdnet.com.au/downloads/0,39024478,39111669s,00.htm

SPYWARE-PUT Hijacker wowok mp3 bar runtime detection – advertising 2 (updated)

URL: http://www.zdnet.com.au/downloads/0,39024478,39111669s,00.htm

SPYWARE-PUT Hijacker wowok mp3 bar runtime detection – search assissant hijacking (updated)

URL: http://www.zdnet.com.au/downloads/0,39024478,39111669s,00.htm

SPYWARE-PUT Hijacker dsrch runtime detection – config info retrieval (updated)

URL: http://www.sunbelt-software.com/research/threat_display.cfm?name=DSrch&threatid=41080

SPYWARE-PUT Hijacker dsrch runtime detection – search assistant redirect (updated)

URL: http://www.sunbelt-software.com/research/threat_display.cfm?name=DSrch&threatid=41080

SPYWARE-PUT Hijacker dsrch runtime detection – side search redirect (updated)

URL: http://www.sunbelt-software.com/research/threat_display.cfm?name=DSrch&threatid=41080

SPYWARE-PUT Other-Technologies clicktrojan runtime detection – version check (updated)

URL: http://sunbeltblog.blogspot.com/2006/01/seen-in-wild-new-pay-per-click-fraud.html

SPYWARE-PUT Other-Technologies clicktrojan runtime detection – fake search query (updated)

URL: http://sunbeltblog.blogspot.com/2006/01/seen-in-wild-new-pay-per-click-fraud.html

SPYWARE-PUT Adware pay-per-click runtime detection – configuration (updated)

URL: http://ppcdomain.co.uk

SPYWARE-PUT Adware pay-per-click runtime detection – update (updated)

URL: http://ppcdomain.co.uk

SPYWARE-PUT Adware ares flash downloader 2.04 runtime detection (updated)

URL: http://www.download2you.com/details_page.asp?titleID=12388

SPYWARE-PUT Adware digink.com runtime detection (updated)

URL: http://www.nuker.com/container/details/snackman.php
URL: http://www.techsupportforum.com/archive/index.php/t-46308.html

SPYWARE-PUT Hijacker cool search runtime detection (updated)

URL: http://www.spywaredb.com/remove-pcshare-2-0/
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453079768

SPYWARE-PUT Other-Technologies spam maxy runtime detection (updated)

URL: http://secunia.com/virus_information/22999/spam-maxy/
URL: http://vil.mcafeesecurity.com/vil/content/v_136735.htm

SPYWARE-PUT Trickler jubster runtime detection (updated)

URL: http://freeware4pc.com/multimedia/jubster.shtml

SPYWARE-PUT Trackware shopathome user-agent detected (updated)

URL: http://www.spywareguide.com/product_show.php?id=700
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453076082

SPYWARE-PUT Trackware shopathome runtime detection – setcookie request (updated)

URL: http://www.spywareguide.com/product_show.php?id=700
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453076082

SPYWARE-PUT Adware trustyfiles v3.1.0.1 runtime detection – startup access (updated)

URL: http://www.softpicks.net/software/TrustyFiles-Personal-File-Sharing-13308.htm

SPYWARE-PUT Hijacker shopprreports runtime detection – services requests (updated)

URL: http://vil.mcafeesecurity.com/vil/content/v_133312.htm

SPYWARE-PUT Hijacker shopprreports runtime detection – track/upgrade/report activities (updated)

URL: http://vil.mcafeesecurity.com/vil/content/v_133312.htm

SPYWARE-PUT Trickler edonkey2000 runtime detection – version verification (updated)

URL: http://www.fbmsoftware.com/spyware-net/Process/edonkey2000_exe/705/

SPYWARE-PUT Trickler edonkey2000 runtime detection – get ads page (updated)

URL: http://www.fbmsoftware.com/spyware-net/Process/edonkey2000_exe/705/

SPYWARE-PUT Keylogger watchdog runtime detection – remote monitoring (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453098060

SPYWARE-PUT Trickler hmtoolbar runtime detection (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453096408

SPYWARE-PUT Hijacker chinese keywords runtime detection (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453074952

SPYWARE-PUT Trackware earthlink toolbar runtime detection – get up-to-date news info (updated)

URL: http://castlecops.com/startuplist-1068.html

SPYWARE-PUT Trackware earthlink toolbar runtime detection – click news button links (updated)

URL: http://castlecops.com/startuplist-1068.html

SPYWARE-PUT Trackware hotblox toolbar runtime detection – barad.asp request (updated)

URL: http://sparkles.nu/spy/proceed-34.html

SPYWARE-PUT Trackware hotblox toolbar runtime detection – ie autosearch hijack (updated)

URL: http://sparkles.nu/spy/proceed-34.html

SPYWARE-PUT Adware piolet runtime detection – user-agent (updated)

URL: http://taxster.fateback.com/piolet.htm

SPYWARE-PUT Adware piolet runtime detection – ads request (updated)

URL: http://taxster.fateback.com/piolet.htm

SPYWARE-PUT Hijacker clearsearch variant runtime detection – popup (updated)

URL: http://www.2-spyware.com/remove-clearsearch.html
URL: http://www.doxdesk.com/parasite/ClearSearch.html

SPYWARE-PUT Hijacker 2020search runtime detection (updated)

URL: http://www.spywareguide.com/product_show.php?id=640
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453076971

SPYWARE-PUT Adware adroar runtime detection (updated)

URL: http://www.spywareguide.com/product_show.php?id=761
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453077256

SPYWARE-PUT Adware hxdl runtime detection – hxlogonly user-agent (updated)

URL: http://www.spywareguide.com/product_show.php?id=516
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453075079

SPYWARE-PUT Adware hxdl runtime detection – hxdownload user-agent (updated)

URL: http://www.spywareguide.com/product_show.php?id=516
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453075079

SPYWARE-PUT Hijacker blazefind runtime detection – search bar (updated)

URL: http://www.spywareguide.com/product_show.php?id=724
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453079063

SPYWARE-PUT Trackware purityscan runtime detection – opt out of interstitial advertising (updated)

URL: http://www.spywareguide.com/product_show.php?id=618
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453073488

SPYWARE-PUT Adware morpheus runtime detection – ad 1 (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453075453
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=54367

SPYWARE-PUT Adware morpheus runtime detection – ad 2 (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453075453
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=54367

SPYWARE-PUT Hijacker adshooter.searchforit runtime detection – search engine (updated)

URL: http://www.spywareguide.com/product_show.php?id=860
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453079051

SPYWARE-PUT Trackware funwebproducts mywebsearchtoolbar-funtools runtime detection (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094235

SPYWARE-PUT Trackware webhancer runtime detection (updated)

URL: http://www.spywareguide.com/product_show.php?id=26
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=43482

SPYWARE-PUT Trickler album galaxy runtime detection – startup data (updated)

URL: http://codegravity.com/index.php/spyware

SPYWARE-PUT Hijacker starware toolbar runtime detection – weather request (updated)

URL: http://www.spywareguide.com/product_show.php?id=2009

SPYWARE-PUT Hijacker starware toolbar runtime detection – hijack ie browser (updated)

URL: http://www.spywareguide.com/product_show.php?id=2009

SPYWARE-PUT Hijacker starware toolbar runtime detection – collect information (updated)

URL: http://www.spywareguide.com/product_show.php?id=2009

SPYWARE-PUT Hijacker starware toolbar runtime detection – reference (updated)

URL: http://www.spywareguide.com/product_show.php?id=2009

SPYWARE-PUT Hijacker starware toolbar runtime detection – smileys (updated)

URL: http://www.spywareguide.com/product_show.php?id=2009

SPYWARE-PUT Hijacker starware toolbar runtime detection – update (updated)

URL: http://www.spywareguide.com/product_show.php?id=2009

SPYWARE-PUT Hijacker flashbar runtime detection – user-agent (updated)

URL: http://data.icxo.com/htmlnews/2006/07/10/875297.htm

SPYWARE-PUT Trickler urlblaze runtime detection – software information request (updated)

URL: http://www.spywareguide.com/product_show.php?id=743
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453073195

SPYWARE-PUT Trickler urlblaze runtime detection – files search or download (updated)

URL: http://www.spywareguide.com/product_show.php?id=743
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453073195

SPYWARE-PUT Hijacker swbar runtime detection (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453077852

SPYWARE-PUT Trackware trellian toolbarbrowser runtime detection (updated)

URL: http://www.toolbarbrowser.com

SPYWARE-PUT Snoopware 2-seek runtime detection – search in toolbar (updated)

URL: http://www.2-seek.com/toolbar.php

SPYWARE-PUT Snoopware 2-seek runtime detection – user info collection (updated)

URL: http://www.2-seek.com/toolbar.php

SPYWARE-PUT Hijacker adtraffic runtime detection – notfound website search hijack and redirection (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094115

SPYWARE-PUT Trickler whenu.clocksync runtime detection (updated)

URL: http://www.spywareguide.com/product_show.php?id=871
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453076030

SPYWARE-PUT Trickler whenu.weathercast runtime detection – check (updated)

URL: http://research.sunbelt-software.com/threat_display.cfm?name=WhenU.WeatherCast&threatid=14106
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453074634

SPYWARE-PUT Hijacker navexcel helper runtime detection – active/update (updated)

URL: http://www.spywareguide.com/product_show.php?id=607
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453074928

SPYWARE-PUT Adware smiley central runtime detection (updated)

URL: http://www.mac-net.com/893488.page
URL: http://www.spywareguide.com/product_show.php?id=2181

SPYWARE-PUT Hijacker rx toolbar runtime detection (updated)

URL: http://sarc.com/avcenter/venc/data/adware.rxtoolbar.html
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094367

SPYWARE-PUT Hijacker instafinder initial configuration detection (updated)

URL: http://www.spywareguide.com/product_show.php?id=1130
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453090786

SPYWARE-PUT Hijacker instafinder error redirect detection (updated)

URL: http://www.spywareguide.com/product_show.php?id=1130
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453090786

SPYWARE-PUT Hijacker avenuemedia.dyfuca runtime detection – search engine hijack (updated)

URL: http://www.itsecurity.com/security.htm?s=9473&sid=875854b6006d07f08dae34f1b78a4600

SPYWARE-PUT Hijacker avenuemedia.dyfuca runtime detection – post data (updated)

URL: http://www.itsecurity.com/security.htm?s=9473&sid=875854b6006d07f08dae34f1b78a4600

SPYWARE-PUT Hijacker netguide runtime detection (updated)

URL: http://castlecops.com/tk17754-CursorZone_Grip_Toolbar.html

SPYWARE-PUT Trickler maxsearch runtime detection – toolbar download (updated)

URL: http://www.spywareguide.com/product_show.php?id=2248

SPYWARE-PUT Trickler maxsearch runtime detection – retrieve command (updated)

URL: http://www.spywareguide.com/product_show.php?id=2248

SPYWARE-PUT Trickler maxsearch runtime detection – ack (updated)

URL: http://www.spywareguide.com/product_show.php?id=2248

SPYWARE-PUT Trickler maxsearch runtime detection – advertisement (updated)

URL: http://www.spywareguide.com/product_show.php?id=2248

SPYWARE-PUT Adware web-nexus runtime detection – ad url 1 (updated)

URL: http://www.spywareguide.com/product_show.php?id=381

SPYWARE-PUT Adware web-nexus runtime detection – config retrieval (updated)

URL: http://www.spywareguide.com/product_show.php?id=381

SPYWARE-PUT Adware web-nexus runtime detection – ad url 2 (updated)

URL: http://www.spywareguide.com/product_show.php?id=381

SPYWARE-PUT Trackware winsysba-a runtime detection – track surfing activity (updated)

URL: http://secunia.com/virus_information/26844/winsysba-a/

SPYWARE-PUT Hijacker findthewebsiteyouneed runtime detection – search hijack (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453098705

SPYWARE-PUT Hijacker findthewebsiteyouneed runtime detection – surf monitor (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453098705

SPYWARE-PUT Adware zango toolbar runtime detection (updated)

URL: http://www.spywareguide.com/product_show.php?id=2298

SPYWARE-PUT Adware desktopmedia runtime detection – ads popup (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453098156

SPYWARE-PUT Adware desktopmedia runtime detection – auto update (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453098156

SPYWARE-PUT Adware desktopmedia runtime detection – surf monitoring (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453098156

SPYWARE-PUT Trackware duduaccelerator runtime detection – send userinfo (updated)

URL: http://www.spywareguide.com/product_show.php?id=2550
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453097969

SPYWARE-PUT Trackware duduaccelerator runtime detection – trace info downloaded (updated)

URL: http://www.spywareguide.com/product_show.php?id=2550
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453097969

SPYWARE-PUT Trackware duduaccelerator runtime detection – trace login info (updated)

URL: http://www.spywareguide.com/product_show.php?id=2550
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453097969

SPYWARE-PUT Adware henbang runtime detection (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094312

SPYWARE-PUT Keylogger netobserve runtime detection – remote login response (updated)

URL: http://www.spywareguide.com/product_show.php?id=354
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453073490

SPYWARE-PUT Hijacker accoona runtime detection – collect info (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453096478

SPYWARE-PUT Hijacker accoona runtime detection – open sidebar search url (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453096478

SPYWARE-PUT Trackware deluxecommunications runtime detection – collect info (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453099974

SPYWARE-PUT Trackware deluxecommunications runtime detection – display popup ads (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453099974

SPYWARE-PUT Hijacker sogou runtime detection – keyword hijack (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453098380

SPYWARE-PUT Hijacker sogou runtime detection – search through sogou toolbar (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453098380

SPYWARE-PUT Hijacker ricercadoppia runtime detection (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453098730

SPYWARE-PUT Hijacker oemji bar runtime detection (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094187

SPYWARE-PUT Trackware relevantknowledge runtime detection (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453097949

SPYWARE-PUT Adware u88 runtime detection (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=Adware.U88&threatid=46383

SPYWARE-PUT Trickler zango easymessenger runtime detection (updated)

URL: http://www.spywareguide.com/product_show.php?id=2182

SPYWARE-PUT Hijacker kuaiso toolbar runtime detection (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453098930

SPYWARE-PUT Trackware bydou runtime detection (updated)

URL: http://bbs.360safe.com/viewthread.php?tid=58707

SPYWARE-PUT Trackware baigoo runtime detection (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453098801

SPYWARE-PUT Trackware bysoo runtime detection (updated)

URL: http://www.360safe.com/elist.html

SPYWARE-PUT Adware newweb runtime detection (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453097957

SPYWARE-PUT Trackware admedia runtime detection (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453098012

SPYWARE-PUT Hijacker bazookabar runtime detection (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453073886

SPYWARE-PUT Hijacker bazookabar runtime detection (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453073886

SPYWARE-PUT Adware mokead runtime detection (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453101519

POLICY download of executable content (updated)

URL: http://www.microsoft.com/smallbusiness/resources/technology/security/practice_safe_computing_and_thwart_online_thugs.mspx

SPYWARE-PUT Other-Technologies spydawn runtime detection – update checking (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453109604

SPYWARE-PUT Keylogger pcsentinelsoftware Keylogger runtime detection – upload infor (updated)

URL: http://www.pcsentinelsoftware.com

SPYWARE-PUT Trackware uplink runtime detection (updated)

URL: http://www.symantec.com/security_response/writeup.jsp?docid=2007-031317-1701-99&tabid=1

SPYWARE-PUT Other-Technologies spywarelocker 3.3 runtime detection – update checking (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=SpyLocked&threatid=129037

SPYWARE-PUT Hijacker snap toolbar runtime detection – cookie (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094831

SPYWARE-PUT Adware yayad runtime detection (updated)

URL: http://www.360safe.com/elist.html

SPYWARE-PUT Hijacker ez-greets toolbar runtime detection (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=EZ-Greets%20Toolbar&threatid=47475

SPYWARE-PUT Adware pprich runtime detection – version check (updated)

URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453100047

SPYWARE-PUT Trackware spynova runtime detection (updated)

URL: http://www.symantec.com/en/aa/enterprise/security_response/writeup.jsp?docid=2007-041614-3222-99

SPYWARE-PUT Hijacker lookquick runtime detection – hijack ie (updated)

URL: http://www.spywareguide.com/product_show.php?id=1810
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453079050

SPYWARE-PUT Trackware lookster toolbar runtime detection – hijack ie search assistant (updated)

URL: http://www.pestpatrol.com/spywarecenter/pest.aspx?id=453105797

SPYWARE-PUT Trackware lookster toolbar runtime detection – collect user information (updated)

URL: http://www.pestpatrol.com/spywarecenter/pest.aspx?id=453105797

SPYWARE-PUT Adware zamingo runtime detection (updated)

URL: http://www.spywareguide.com/spydet_795_zamingo.html
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453088136

SPYWARE-PUT Trackware snap ultrasearch/desktop toolbar runtime detection – cookie (updated)

URL: http://www.spynomore.com/toolbar-snap-ultrasearch.htm
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094831

SPYWARE-PUT Adware vroomsearch runtime detection (updated)

URL: http://www.spywareguide.com/spydet_1274_vroomsearch.html

SPYWARE-PUT Hijacker scn toolbar runtime detection – hijack ie searches (updated)

URL: http://www.spywareguide.com/spydet_1830_scn_toolbar.html

SPYWARE-PUT Hijacker scn toolbar runtime detection – get updates (updated)

URL: http://www.spywareguide.com/spydet_1830_scn_toolbar.html

SPYWARE-PUT Hijacker 3search runtime detection – update (updated)

URL: http://www.downloadfile.org
URL: http://www.softwarerevenue.org

SPYWARE-PUT Hijacker imesh mediabar runtime detection – auto update (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=imesh&threatid=6994
URL: http://www.spywaredata.com/spyware/malware/mediabar.dll.php

SPYWARE-PUT Adware winantivirus pro 2007 runtime detection (updated)

URL: http://www.spywareremove.com/security/winantiviruspro2007-removal-instructions

SPYWARE-PUT Trackware searchmiracle elitebar runtime detection – get ads (updated)

URL: http://www.spywareguide.com/product_show.php?id=1124
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094053

SPYWARE-PUT Trackware searchmiracle elitebar runtime detection – collect information (updated)

URL: http://www.spywareguide.com/product_show.php?id=1124
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094053

SPYWARE-PUT Trackware searchmiracle elitebar runtime detection – track activity (updated)

URL: http://www.spywareguide.com/product_show.php?id=1124
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094053

SPYWARE-PUT Hijacker personalweb runtime detection (updated)

URL: http://www.spywareguide.com/spydet_3785_personal_web.html

SPYWARE-PUT Adware avsystemcare runtime detection (updated)

URL: http://www.spywareguide.com/spydet_3529_avsystemcare.html

SPYWARE-PUT Adware pestbot runtime detection – update (updated)

URL: http://www.spywareguide.com/spydet_3581_pestbot.html
URL: http://www.spywarewarrior.com/rogue_anti-spyware.htm

SPYWARE-PUT Trackware winzix 2.2.0 runtime detection (updated)

URL: http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453118801

SPYWARE-PUT Adware netpumper 1.26 runtime detection (updated)

URL: http://ca.com/us/securityadvisor/pest/pest.aspx?id=453099585
URL: http://www.spywareguide.com/spydet_975_netpumper_1_2.html

SPYWARE-PUT Adware netguarder web cleaner runtime detection (updated)

URL: http://www.ca.com/ca/fr/securityadvisor/pest/pest.aspx?id=453075057
URL: http://www.spywareguide.com/spydet_1824_netguarder_web_cleaner.html

SPYWARE-PUT Adware 3wplayer 1.7 runtime detection (updated)

URL: http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453120279
URL: http://www.spywareremove.com/remove3wPlayer.html

SPYWARE-PUT Hijacker baidu toolbar runtime detection – discloses information (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?threatid=44261
URL: http://www.spywareguide.com/product_show.php?id=1250

SPYWARE-PUT Hijacker baidu toolbar runtime detection – updates automatically (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?threatid=44261
URL: http://www.spywareguide.com/product_show.php?id=1250

SPYWARE-PUT Adware elite protector runtime detection (updated)

URL: http://www.ca.com/ca/en/securityadvisor/pest/pest.aspx?id=453123830
URL: http://www.threatexpert.com/report.aspx?uid=413fd424-4727-46bb-af1b-125e21b34afb

SPYWARE-PUT Hijacker people pal toolbar runtime detection – automatic upgrade (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=PeoplePal%20Toolbar&threatid=48411
URL: http://www.emsisoft.com/en/malware/?Adware.Win32.PeoplePal

SPYWARE-PUT Hijacker deepdo toolbar runtime detection – automatic update (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=Deepdo%20Toolbar&threatid=129378
URL: http://www.spywareguide.com/product_show.php?id=3367

SPYWARE-PUT Hijacker ez-tracks toolbar runtime detection – initial traffic 1 (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=EZ-Tracks%20Toolbar&threatid=41189
URL: http://www.spywareremove.com/removeEZTracks.html

SPYWARE-PUT Hijacker ez-tracks toolbar runtime detection – initial traffic 2 (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=EZ-Tracks%20Toolbar&threatid=41189
URL: http://www.spywareremove.com/removeEZTracks.html

SPYWARE-PUT Adware contravirus runtime detection – update (updated)

URL: http://www.spywaredetector.net/spyware_encyclopedia/Fake%20Anti%20Spyware.Contra%20Virus.htm
URL: http://www.spywareguide.com/spydet_3552_contravirus.html

SPYWARE-PUT Hijacker dealio toolbar runtime detection user-agent detected (updated)

URL: http://ca.com/us/securityadvisor/pest/pest.aspx?id=453113199
URL: http://www.fbmsoftware.com/spyware-net/application/Dealio_Toolbar

SPYWARE-PUT Hijacker kword interkey runtime detection – search traffic 1 (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=Kword.InterKey&threatid=46477
URL: http://www.noadware.net/research/index2.php?item_id=2656&item_name=Kword.InterKey

SPYWARE-PUT Adware system doctor runtime detection – update status (updated)

URL: http://www.2-spyware.com/remove-systemdoctor.html
URL: http://www.spywareguide.com/spydet_3049_systemdoctor_2006.html

SPYWARE-PUT Trickler downloader trojan.gen runtime detection – get malicious link (updated)

URL: http://ca.com/us/securityadvisor/pest/pest.aspx?id=453120536
URL: http://www.prevx.com/filenames/X1895686732762432147-0/LAF4.EXE.html

SPYWARE-PUT Trickler downloader trojan.gen runtime detection – download malicious link (updated)

URL: http://ca.com/us/securityadvisor/pest/pest.aspx?id=453120536
URL: http://www.prevx.com/filenames/X1895686732762432147-0/LAF4.EXE.html

SPYWARE-PUT Adware virus heat runtime detection – presale request (updated)

URL: http://ca.com/us/securityadvisor/pest/pest.aspx?id=453124583
URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=VirusHeat&threatid=203189

SPYWARE-PUT Adware virus heat runtime detection – initial database connection (updated)

URL: http://ca.com/us/securityadvisor/pest/pest.aspx?id=453124583
URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=VirusHeat&threatid=203189

SPYWARE-PUT Hijacker locmag toolbar runtime detection – connection to toolbar (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=Locmag%20Toolbar&threatid=48497
URL: http://www.360zd.com/spyware/433.html

SPYWARE-PUT Hijacker locmag toolbar runtime detection – hijacks address bar (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=Locmag%20Toolbar&threatid=48497
URL: http://www.360zd.com/spyware/433.html

SPYWARE-PUT Hijacker eclickz toolbar runtime detection – search traffic (updated)

URL: http://spywaresignatures.com/details.php?spyware=eclickztoolbar
URL: http://www.emsisoft.com/en/malware/?Adware.Win32.eClickz+Toolbar

SPYWARE-PUT Hijacker zztoolbar runtime detection – toolbar traffic (updated)

URL: http://www.browserdefender.com/file/404730/site/chinarank.org.cn/
URL: http://www.spywareguide.com/spydet_5949_zztoolbar.html

SPYWARE-PUT Hijacker zztoolbar runtime detection – search traffic (updated)

URL: http://www.browserdefender.com/file/404730/site/chinarank.org.cn/
URL: http://www.spywareguide.com/spydet_5949_zztoolbar.html

SPYWARE-PUT Hijacker mxs toolbar runtime detection (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=MXS.Toolbar&threatid=97487

SPYWARE-PUT Adware registry defender runtime detection – presale request (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=Registry%20Defender&threatid=91028
URL: http://www.emsisoft.com/en/malware/?Adware.Win32.Registry+Defender

SPYWARE-PUT Adware registry defender runtime detection – error report request (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=Registry%20Defender&threatid=91028
URL: http://www.emsisoft.com/en/malware/?Adware.Win32.Registry+Defender

SPYWARE-PUT Adware spyware stop runtime detection – presale request (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=SpywareStop&threatid=205898
URL: http://www.prevx.com/filenames/1299278770072512825-0/SPYWARESTOP.MSI.html

SPYWARE-PUT Adware spyware stop runtime detection – auto updates (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=SpywareStop&threatid=205898
URL: http://www.prevx.com/filenames/1299278770072512825-0/SPYWARESTOP.MSI.html

SPYWARE-PUT Adware cashfiesta adbar runtime detection – updates traffic (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=CashFiesta%20AdBar&threatid=42051

SPYWARE-PUT Adware system defender runtime detection (updated)

URL: http://www.411-spyware.com/remove-systemdefender
URL: http://www.enigmasoftware.com/support/systemdefender-removal/

SPYWARE-PUT Adware winxdefender runtime detection – presale request (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=WinXDefender&threatid=155747
URL: http://www.411-spyware.com/remove-winxdefender

SPYWARE-PUT Adware winxdefender runtime detection – auto update (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=WinXDefender&threatid=155747
URL: http://www.411-spyware.com/remove-winxdefender

SPYWARE-PUT Hijacker searchnine toolbar runtime detection – hijacks address bar (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=SearchNine&threatid=117435
URL: http://spywarefiles.prevx.com/spywarefiles.asp?FXC=DJFC24641892

SPYWARE-PUT Hijacker music of faith toolbar runtime detection – hijacks search engine traffic #1 (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=Music%20of%20Faith&threatid=47479
URL: http://www.spywareterminator.com/item/3836/MusicOfFaith.html

SPYWARE-PUT Trackware syscleaner runtime detection – presale traffic (updated)

URL: http://ca.com/us/securityadvisor/pest/pest.aspx?id=453123831
URL: http://spywaredetector.net/spyware_encyclopedia/Fake%20Anti%20Spyware.SysCleaner.htm

SPYWARE-PUT Trackware syscleaner runtime detection – get update (updated)

URL: http://ca.com/us/securityadvisor/pest/pest.aspx?id=453123831
URL: http://spywaredetector.net/spyware_encyclopedia/Fake%20Anti%20Spyware.SysCleaner.htm

SPYWARE-PUT Trackware proofile toolbar runtime detection (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=Proofile%20Toolbar&threatid=127931

SPYWARE-PUT Hijacker find.fm toolbar runtime detection – automatic updates (updated)

URL: http://www.spywareguide.com/product_show.php?id=2360
URL: http://www.spywaresignatures.com/details.php?spyware=find.fmtoolbar

SPYWARE-PUT Hijacker find.fm toolbar runtime detection – hijacks address bar (updated)

URL: http://www.spywareguide.com/product_show.php?id=2360
URL: http://www.spywaresignatures.com/details.php?spyware=find.fmtoolbar

SPYWARE-PUT Hijacker ezreward runtime detection (updated)

URL: http://research.sunbeltsoftware.com/threatdisplay.aspx?name=ezReward&threatid=144116
URL: http://www.sophos.com/security/analyses/adware-and-puas/ezreward.html

SPYWARE-PUT Adware ie antivirus runtime detection – presale request (updated)

URL: http://ca.com/securityadvisor/pest/pest.aspx?id=453132958
URL: http://www.411-spyware.com/remove-ie-antivirus-3-2

SPYWARE-PUT Adware ie antivirus runtime detection – update request (updated)

URL: http://ca.com/securityadvisor/pest/pest.aspx?id=453132958
URL: http://www.411-spyware.com/remove-ie-antivirus-3-2

SPYWARE-PUT Adware xp antivirus runtime detection (updated)

URL: http://www.ca.com/securityadvisor/pest/pest.aspx?id=453122012
URL: http://www.spywareguide.com/spydet_27817_xpantivirus.html

SPYWARE-PUT Adware roogoo 2.0 runtime detection – popup ads (updated)

URL: http://www.spywareguide.com/spydet_3018_roogoo.html
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453097966

SPYWARE-PUT Adware roogoo 2.0 runtime detection – upgrade (updated)

URL: http://www.spywareguide.com/spydet_3018_roogoo.html
URL: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453097966

SPYWARE-PUT Hijacker alot toolbar runtime detection – weather request (updated)

URL: http://www.pchell.com/support/alot.shtml
URL: http://www.spywareremove.com/removeALOTToolbar.html

SPYWARE-PUT Trackware speed runner runtime detection (updated)

URL: http://spywarefiles.prevx.com/RRDAJJ44598849/SPEEDRUNNER.EXE.html
URL: http://www.bleepingcomputer.com/startups/SpeedRunner-22778.html

SPYWARE-PUT Trackware adclicker-fc.gen.a runtime detection – popup ads (updated)

URL: http://vil.nai.com/vil/content/v_144220.htm
URL: http://www.threatexpert.com/report.aspx?uid=c2699ec8-6cd1-4ad1-ace5-f29bb1133d91

SPYWARE-PUT Trackware adclicker-fc.gen.a runtime detection (updated)

URL: http://vil.nai.com/vil/content/v_144220.htm
URL: http://www.threatexpert.com/report.aspx?uid=c2699ec8-6cd1-4ad1-ace5-f29bb1133d91

SPYWARE-PUT Trickler fushion 1.2.4.17 runtime detection – notice (updated)

URL: http://www.siteadvisor.pl/sites/funshion.com/downloads/11570528/

SPYWARE-PUT Trickler fushion 1.2.4.17 runtime detection – underground traffic (updated)

URL: http://www.siteadvisor.pl/sites/funshion.com/downloads/11570528/

SPYWARE-PUT Adware malware destructor 4.5 runtime detection – order request (updated)

URL: http://ca.com/us/securityadvisor/pest/pest.aspx?id=453116773
URL: http://www.symantec.com/security_response/writeup.jsp?docid=2007-090713-4427-99

SPYWARE-PUT Adware malware destructor 4.5 runtime detection – auto update (updated)

URL: http://ca.com/us/securityadvisor/pest/pest.aspx?id=453116773
URL: http://www.symantec.com/security_response/writeup.jsp?docid=2007-090713-4427-99

SPYWARE-PUT Trickler pc privacy cleaner runtime detection – order/register request (updated)

URL: http://malware-remover.com/pcprivacycleaner-removal-tool-pc-privacy-cleaner/
URL: http://www.xp-vista.com/spyware-removal/pcprivacycleaner-pc-privacy-cleaner-removal-instructions

SPYWARE-PUT Trickler pc privacy cleaner runtime detection – auto update (updated)

URL: http://malware-remover.com/pcprivacycleaner-removal-tool-pc-privacy-cleaner/
URL: http://www.xp-vista.com/spyware-removal/pcprivacycleaner-pc-privacy-cleaner-removal-instructions

SPYWARE-PUT Trackware rightonadz.biz adrotator runtime detection – post user info to remote server (updated)

URL: http://www.askmehelpdesk.com/spyware-viruses-etc/pop-up-http-rightonadz-biz-bc-123kah-php-151385.html
URL: http://www.nettrafficchat.com/showthread.php?t=1347

SPYWARE-PUT Trackware rightonadz.biz adrotator runtime detection – ads (updated)

URL: http://www.askmehelpdesk.com/spyware-viruses-etc/pop-up-http-rightonadz-biz-bc-123kah-php-151385.html
URL: http://www.nettrafficchat.com/showthread.php?t=1347

SPYWARE-PUT Hijacker mediatubecodec 1.470.0 runtime detection – hijack ie (updated)

URL: http://ca.com/us/securityadvisor/pest/pest.aspx?id=453134350
URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=Trojan.NewMediaCodec&threatid=149335

SPYWARE-PUT Hijacker mediatubecodec 1.470.0 runtime detection – download other malware (updated)

URL: http://ca.com/us/securityadvisor/pest/pest.aspx?id=453134350
URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=Trojan.NewMediaCodec&threatid=149335

SPYWARE-PUT Hijacker adware.win32.ejik.ec variant runtime detection – call home (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=AdWare.Win32.Ejik.ec&threatid=281451
URL: http://www.emsisoft.fr/fr/malware/?Adware.Win32.Ejik.ec

SPYWARE-PUT Hijacker win32.bho.bgf runtime detection (updated)

URL: http://www.baidumsg.com/malwareremoval/malwareremoval_5947.html
URL: http://www.threatexpert.com/report.aspx?uid=77b8d3c8-e630-4719-b6fd-b5461820d8f1

WEB-CLIENT CyberLink PowerDVD playlist file handling stack overflow attempt (updated)

Bugtraq: 30341

PowerDVD is prone to multiple buffer-overflow vulnerabilities because it fails
to perform adequate boundary checks on user-supplied input.Successfully
exploiting these issues may allow remote attackers to execute arbitrary code in
the context of the application. Failed exploit attempts will cause denial-of-
service conditions.PowerDVD 8.0 is vulnerable; prior versions may also be
affected.

WEB-CLIENT CyberLink PowerDVD playlist file handling stack overflow attempt (updated)

Bugtraq: 30341

PowerDVD is prone to multiple buffer-overflow vulnerabilities because it fails
to perform adequate boundary checks on user-supplied input.Successfully
exploiting these issues may allow remote attackers to execute arbitrary code in
the context of the application. Failed exploit attempts will cause denial-of-
service conditions.PowerDVD 8.0 is vulnerable; prior versions may also be
affected.

SPYWARE-PUT Adware AdwareALERT runtime detection – auto update (updated)

URL: http://www.2-spyware.com/remove-adwarealert.html
URL: http://www.411-spyware.com/remove-adwarealert

SPYWARE-PUT Hijacker rediff toolbar runtime detection – hijack ie auto search (updated)

URL: http://secwatch.org/exploits/2007/03/Rediff.Toolbar_DoS.html.info
URL: http://www.fbmsoftware.com/spyware-net/application/Rediff_Toolbar/

SPYWARE-PUT Hijacker rediff toolbar runtime detection – get news info (updated)

URL: http://secwatch.org/exploits/2007/03/Rediff.Toolbar_DoS.html.info
URL: http://www.fbmsoftware.com/spyware-net/application/Rediff_Toolbar/

SPYWARE-PUT Trackware murzilka2 runtime detection (updated)

URL: http://www.liveinternet.ru/users/murzilka2/

SPYWARE-PUT Hijacker cpush 2 runtime detection – hijack ie home page (updated)

URL: http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453101269
URL: http://www.symantec.com/security_response/writeup.jsp?docid=2007-031215-0744-99

SPYWARE-PUT Hijacker cpush 2 runtime detection – auto update (updated)

URL: http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453101269
URL: http://www.symantec.com/security_response/writeup.jsp?docid=2007-031215-0744-99

SPYWARE-PUT Hijacker cashon runtime detection – hijack ie searches (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=CashOn&threatid=53428
URL: http://vil.nai.com/vil/content/v_142287.htm

SPYWARE-PUT Adware winsecuredisc runtime detection (updated)

URL: http://www.emsisoft.com/fr/malware/?Adware.Win32.WinSecureDisc
URL: http://www.spywareremove.com/removeWinSecureDisc.html

SPYWARE-PUT Adware swizzor runtime detection (updated)

URL: http://vil.nai.com/vil/content/v_136491.htm
URL: http://www.411-spyware.com/remove-swizzor

SPYWARE-PUT Adware brave sentry runtime detection – order request (updated)

URL: http://vil.nai.com/vil/content/v_138897.htm
URL: http://www.spywareremove.com/removeBravesentry.html

SPYWARE-PUT Adware brave sentry runtime detection – self update (updated)

URL: http://vil.nai.com/vil/content/v_138897.htm
URL: http://www.spywareremove.com/removeBravesentry.html

SPYWARE-PUT Hijacker Adware win32 mostofate runtime detection – hijack search (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=AdWare.Win32.Mostofate.dx&threatid=356346
URL: http://www.f-secure.com/sw-desc/adware_w32_mostofate.shtml

SPYWARE-PUT Hijacker Adware win32 mostofate runtime detection – redirect search results (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=AdWare.Win32.Mostofate.dx&threatid=356346
URL: http://www.f-secure.com/sw-desc/adware_w32_mostofate.shtml

SPYWARE-PUT Adware winspywareprotect runtime detection – download malicous code (updated)

URL: http://ca.com/us/securityadvisor/pest/pest.aspx?id=453132073
URL: http://www.spywareremove.com/removeWinSpywareProtect.html
URL: http://www.symantec.com/security_response/writeup.jsp?docid=2008-042206-4253-99&tabid=1

SPYWARE-PUT Adware winspywareprotect runtime detection – connection to malicious sites (updated)

URL: http://ca.com/us/securityadvisor/pest/pest.aspx?id=453132073
URL: http://www.spywareremove.com/removeWinSpywareProtect.html
URL: http://www.symantec.com/security_response/writeup.jsp?docid=2008-042206-4253-99&tabid=1

SPYWARE-PUT Adware winspywareprotect runtime detection – connection to malicious server (updated)

URL: http://ca.com/us/securityadvisor/pest/pest.aspx?id=453132073
URL: http://www.spywareremove.com/removeWinSpywareProtect.html
URL: http://www.symantec.com/security_response/writeup.jsp?docid=2008-042206-4253-99&tabid=1

SPYWARE-PUT RSPlug Trojan server connection attempt (updated)

URL: http://www.sophos.com/security/analyses/viruses-and-spyware/osxrsplugf.html

SPYWARE-PUT Hijacker cramtoolbar runtime detection – hijack (updated)

URL: http://www.spywareguide.com/product_show.php?id=2474
URL: http://www.symantec.com/security_response/writeup.jsp?docid=2005-091817-2335-99&tabid=1

SPYWARE-PUT Trackware rightonadz.biz adrotator runtime detection – ads (updated)

URL: http://www.sophos.com/security/analyses/adware-and-puas/rightonadz.html

SPYWARE-PUT Adware winreanimator runtime detection – register request (updated)

URL: http://www.411-spyware.com/effacer-winreanimator
URL: http://www.windowsvistaplace.com/winreanimator-removal-instructions-winreanimator/spyware-removal

SPYWARE-PUT Trackware 6sq toolbar runtime detection (updated)

URL: http://ca.com/fi/securityadvisor/pest/pest.aspx?id=453130697
URL: http://www.spycheck.es/genera.php?processfile=6sqtoolbar.dll&dir=otros&pag=165

SPYWARE-PUT Hijacker weatherstudio runtime detection (updated)

URL: http://ca.com/us/securityadvisor/pest/pest.aspx?id=453122854
URL: http://vil.nai.com/vil/content/v_137487.htm

SPYWARE-PUT rogue antivirus xp 2008 runtime detection – buy (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=Antivirus%20XP%202008%20(Winifixer)&threatid=310434
URL: http://www.symantec.com/security_response/writeup.jsp?docid=2008-071613-4343-99&tabid=2

SPYWARE-PUT rogue antivirus xp 2008 runtime detection – update (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=Antivirus%20XP%202008%20(Winifixer)&threatid=310434
URL: http://www.symantec.com/security_response/writeup.jsp?docid=2008-071613-4343-99&tabid=2

SPYWARE-PUT downloader trojan.nsis.agent.s runtime detection (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=Trojan-Downloader.NSIS.Agent.s&threatid=51530
URL: http://www.pctools.com/mrc/infections/id/Adware.Metadirect_hijacker/

SPYWARE-PUT Adware superiorads runtime detection (updated)

URL: http://www.adwareaway.net/superiorads.htm
URL: http://www.precisesecurity.com/threats/adwaresuperiorads/

SPYWARE-PUT Keylogger kamyab Keylogger v.3 runtime detection (updated)

URL: http://www.megasecurity.org/trojans/k/keylogger/Kamyabkeylogger3.0.html

SPYWARE-PUT Keylogger lord spy pro 1.4 runtime detection (updated)

This Event has no details yet.

SPYWARE-PUT Trackware adclicker trojan zlob.dnz runtime detection – ads (updated)

URL: http://www.threatexpert.com/report.aspx?uid=6b4f9be8-f080-4aa7-bb1a-c25231426315

SPYWARE-PUT Trackware owlforce runtime detection – remote server #2 (updated)

URL: http://spywaresignatures.com/details/owlforce.pdf
URL: http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453113210

SPYWARE-PUT Adware spyware guard 2008 runtime detection – contacts remote server (updated)

URL: http://malwaredatabase.net/blog/index.php/2008/10/23/antivirus-2009-2-file-added-5-domains-added-low-detection-136/
URL: http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453141606

SPYWARE-PUT Adware spyware guard 2008 runtime detection – purchase page (updated)

URL: http://malwaredatabase.net/blog/index.php/2008/10/23/antivirus-2009-2-file-added-5-domains-added-low-detection-136/
URL: http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453141606

SPYWARE-PUT downloader_trojan.gen2 runtime detection – scanner page (updated)

URL: http://research.sunbelt-software.com/threatdisplay.aspx?name=Trojan-Downloader.Gen&threatid=43099
URL: http://www.threatexpert.com/report.aspx?uid=6a5f4829-667f-4f53-876d-ca74fe4cfcf0

SPYWARE-PUT TT-bot botnet contact to C&C; server attempt (updated)

URL: http://anubis.iseclab.org/index.php?action=result&format=html&task_id=1494581651ca480640538ead93feabed2

SPYWARE-PUT Trojan hacktool attempt to contact server (updated)

URL: http://www.threatexpert.com/report.aspx?md5=f602982724b3562b80f435f0d87c6a5f

SPYWARE-PUT Malware contact to server attempt (updated)

URL: http://www.virustotal.com/analisis/c55e2acfed1996ddbd17ddd4cba57530dd34c207be9f9b327fa3fdbb10cdaa7c-1270750352

research Detection, New Logic

Microsoft Tuesday

June 9th, 2010
Comments Off

Microsoft Tuesday detection is heading into testing and out to sensors. There are also a number of non-MS Tuesday Events going out as well. The list is below.

WEB-ACTIVEX Microsoft Internet Explorer 8 Developer Tool ActiveX clsid access (new)
This Event has no details yet.

MISC .NET framework XMLDsig data tampering attempt (new)

CVE: 2009-0217
URL: http://osvdb.org/show/osvdb/56243
URL: http://www.microsoft.com/technet/security/bulletin/MS10-041.mspx

The design of the W3C XML Signature Syntax and Processing (XMLDsig)
recommendation, as implemented in products including (1) the Oracle Security
Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and
10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0
MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security
Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through
6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE
Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5,
and 4.0; and other products uses a parameter that defines an HMAC truncation
length (HMACOutputLength) but does not require a minimum for this length, which
allows attackers to spoof HMAC-based signatures and bypass authentication by
specifying a truncation length with a small number of bits.

EXPLOIT Microsoft Internet Explorer security zone restriction bypass attempt (new)

CVE: 2010-0255
URL: http://www.microsoft.com/technet/security/bulletin/MS10-035.mspx

Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent
rendering of non-HTML local files as HTML documents, which allows remote
attackers to bypass intended access restrictions and read arbitrary files via
vectors involving JavaScript exploit code that constructs a reference to a
file://127.0.0.1 URL, aka the dynamic OBJECT tag vulnerability, as demonstrated
by obtaining the data from an index.dat file, a variant of CVE-2009-1140 and
related to CVE-2008-1448.

WEB-CLIENT Microsoft Excel OBJ record stack buffer overflow attempt (new)

CVE: 2010-0822
URL: http://www.microsoft.com/technet/security/bulletin/MS10-038.mspx

Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and
Open XML File Format Converter for Mac allows remote attackers to execute
arbitrary code via a crafted Excel file, aka “Excel Object Stack Overflow
Vulnerability.”

WEB-CLIENT Microsoft Excel OBJ record stack buffer overflow attempt – with macro (new)

CVE: 2010-0822
URL: http://www.microsoft.com/technet/security/bulletin/MS10-038.mspx

Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and
Open XML File Format Converter for Mac allows remote attackers to execute
arbitrary code via a crafted Excel file, aka “Excel Object Stack Overflow
Vulnerability.”

WEB-CLIENT Microsoft Excel OBJ record stack buffer overflow attempt – with linkFmla (new)

CVE: 2010-0822
URL: http://www.microsoft.com/technet/security/bulletin/MS10-038.mspx

Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and
Open XML File Format Converter for Mac allows remote attackers to execute
arbitrary code via a crafted Excel file, aka “Excel Object Stack Overflow
Vulnerability.”

WEB-CLIENT Microsoft Excel OBJ record stack buffer overflow attempt – with macro and linkFmla (new)

CVE: 2010-0822
URL: http://www.microsoft.com/technet/security/bulletin/MS10-038.mspx

Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and
Open XML File Format Converter for Mac allows remote attackers to execute
arbitrary code via a crafted Excel file, aka “Excel Object Stack Overflow
Vulnerability.”

POLICY File URI scheme (new)
This Event has no details yet.

WEB-CLIENT Microsoft Excel Chart Sheet Substream memory corruption attempt (new)

CVE: 2010-0823
URL: http://www.microsoft.com/technet/security/bulletin/MS10-038.mspx

Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1
and SP2; Office 2004 for mac; Office 2008 for Mac; Open XML File Format
Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility
Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; allows
remote attackers to execute arbitrary code via a crafted Excel file, aka “Excel
Memory Corruption Vulnerability,” a different vulnerability than CVE-2010-1247
and CVE-2010-1249.

EXPLOIT Microsoft Excel WOpt record memory corruption attempt (new)

CVE: 2010-0824
URL: http://www.microsoft.com/technet/security/bulletin/MS10-038.mspx

Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for
Mac allows remote attackers to execute arbitrary code via a crafted Excel file,
aka “Excel Record Memory Corruption Vulnerability,” a different vulnerability
than CVE-2010-0821 and CVE-2010-1245.

EXPLOIT Microsoft Excel SxView record memory pointer corruption attempt (new)

CVE: 2010-1245
URL: http://www.microsoft.com/technet/security/bulletin/MS10-038.mspx

Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for
Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows
remote attackers to execute arbitrary code via a crafted Excel file, aka “Excel
Record Memory Corruption Vulnerability,” a different vulnerability than
CVE-2010-0824 and CVE-2010-0821.

EXPLOIT Microsoft Excel RealTimeData record stack buffer overflow attempt (new)

CVE: 2010-1246
URL: http://www.microsoft.com/technet/security/bulletin/MS10-XXX.mspx

Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote
attackers to execute arbitrary code via a crafted Excel file, aka “Excel RTD
Memory Corruption Vulnerability.”

WEB-CLIENT Microsoft Excel RealTimeData record heap memory corruption attempt – 2 (new)

CVE: 2010-1247
URL: http://www.microsoft.com/technet/security/bulletin/MS10-038.mspx

Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote
attackers to execute arbitrary code via a crafted Excel file, aka “Excel Memory
Corruption Vulnerability,” a different vulnerability than CVE-2010-0823 and
CVE-2010-1249.

EXPLOIT Microsoft Excel RealTimeData record heap memory corruption attempt – 1 (new)

CVE: 2010-1247
URL: http://www.microsoft.com/technet/security/bulletin/MS10-038.mspx

Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote
attackers to execute arbitrary code via a crafted Excel file, aka “Excel Memory
Corruption Vulnerability,” a different vulnerability than CVE-2010-0823 and
CVE-2010-1249.

WEB-CLIENT Microsoft Excel HFPicture record stack buffer overflow attempt (new)

CVE: 2010-1248
URL: http://www.microsoft.com/technet/security/bulletin/MS10-038.mspx

Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for
Mac allows remote attackers to execute arbitrary code via a crafted Excel file,
aka “Excel HFPicture Memory Corruption Vulnerability.”

WEB-CLIENT Microsoft Excel ExternName record stack buffer overflow attempt – 1 (new)

CVE: 2010-1249
URL: http://www.microsoft.com/technet/security/bulletin/MS10-038.mspx

Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for
Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows
remote attackers to execute arbitrary code via a crafted Excel file, aka “Excel
Memory Corruption Vulnerability,” a different vulnerability than CVE-2010-0823
and CVE-2010-1247.

WEB-CLIENT Microsoft Excel ExternName record stack buffer overflow attempt – 2 (new)

CVE: 2010-1249
URL: http://www.microsoft.com/technet/security/bulletin/MS10-038.mspx

Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for
Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows
remote attackers to execute arbitrary code via a crafted Excel file, aka “Excel
Memory Corruption Vulnerability,” a different vulnerability than CVE-2010-0823
and CVE-2010-1247.

WEB-CLIENT Microsoft Excel ExternName record stack buffer overflow attempt – 3 (new)

CVE: 2010-1249
URL: http://www.microsoft.com/technet/security/bulletin/MS10-038.mspx

Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for
Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows
remote attackers to execute arbitrary code via a crafted Excel file, aka “Excel
Memory Corruption Vulnerability,” a different vulnerability than CVE-2010-0823
and CVE-2010-1247.

WEB-CLIENT Microsoft Excel ExternName record stack buffer overflow attempt – 4 (new)

CVE: 2010-1249
URL: http://www.microsoft.com/technet/security/bulletin/MS10-038.mspx

Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for
Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows
remote attackers to execute arbitrary code via a crafted Excel file, aka “Excel
Memory Corruption Vulnerability,” a different vulnerability than CVE-2010-0823
and CVE-2010-1247.

WEB-CLIENT Microsoft Excel undocumented Publisher record heap buffer overflow attempt (new)

CVE: 2010-1250
URL: http://www.microsoft.com/technet/security/bulletin/MS10-038.mspx

Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for
Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows
remote attackers to execute arbitrary code via a crafted Excel file, aka “Excel
EDG Memory Corruption Vulnerability.”

WEB-CLIENT Microsoft Excel Lbl record stack overflow attempt (new)

CVE: 2010-1251
URL: http://www.microsoft.com/technet/security/bulletin/MS10-038.mspx

Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for
Mac allows remote attackers to execute arbitrary code via a crafted Excel file,
aka “Excel Record Stack Corruption Vulnerability.”

WEB-CLIENT Microsoft Excel BIFF5 ExternSheet record stack overflow attempt (new)

CVE: 2010-1252
URL: http://www.microsoft.com/technet/security/bulletin/MS10-038.mspx

Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for
Mac allows remote attackers to execute arbitrary code via a crafted Excel file,
aka “Excel String Variable Vulnerability.”

WEB-CLIENT Microsoft Excel DBQueryExt record memory corruption attempt (new)

CVE: 2010-1253
URL: http://www.microsoft.com/technet/security/bulletin/MS10-038.mspx

Microsoft Office Excel 2002 SP3, 2007 SP1, and SP2; Office 2004 for mac; Office
2008 for Mac; Open XML File Format Converter for Mac; and Office Compatibility
Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; allows
remote attackers to execute arbitrary code via an Excel file with crafted
DBQueryExt records that allow a function call to a “user-controlled pointer,”
aka “Excel ADO Object Vulnerability.”

WEB-CLIENT Microsoft Internet Explorer 8 cross-site scripting attempt (new)

CVE: 2010-1257
URL: http://www.microsoft.com/technet/security/bulletin/ms10-035.mspx

Cross-site scripting (XSS) vulnerability in the toStaticHTML API, as used in
Microsoft Office InfoPath 2003 SP3, 2007 SP1, and 2007 SP2; Office SharePoint
Server 2007 SP1 and SP2; SharePoint Services 3.0 SP1 and SP2; and Internet
Explorer 8 allows remote attackers to inject arbitrary web script or HTML via
vectors related to sanitization.

EXPLOIT Microsoft Internet Explorer style sheet array memory corruption attempt (new)

CVE: 2010-1259
CVE: 2010-1262
URL: http://www.microsoft.com/technet/security/bulletin/MS10-035.mspx

Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to
execute arbitrary code by accessing an object that (1) was not properly
initialized or (2) is deleted, leading to memory corruption, aka “Memory
Corruption Vulnerability.”

DOS SharePoint Server 2007 help.aspx denial of service attempt (new)

CVE: 2010-1264
URL: http://www.microsoft.com/technet/security/bulletin/MS10-039.mspx

Unspecified vulnerability in Microsoft Windows SharePoint Services 3.0 SP1 and
SP2 allows remote attackers to cause a denial of service (hang) via crafted
requests to the Help page that cause repeated restarts of the application pool,
aka “Sharepoint Help Page Denial of Service Vulnerability.”

EXPLOIT quartz.dll MJPEG content processing memory corruption attempt (new)

CVE: 2010-1879
URL: http://www.microsoft.com/technet/security/bulletin/MS10-033.mspx

Unspecified vulnerability in Quartz.dll for DirectShow; Windows Media Format
Runtime 9, 9.5, and 11; Media Encoder 9; and the Asycfilt.dll COM component
allows remote attackers to execute arbitrary code via a media file with crafted
compression data, aka “Media Decompression Vulnerability.”

WEB-CLIENT Microsoft Excel SxView heap overflow attempt (new)

CVE: 2010-0821
URL: http://www.microsoft.com/technet/security/bulletin/MS10-038.mspx

Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1
and SP2; Office 2004 for mac; Office 2008 for Mac; Open XML File Format
Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility
Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; allows
remote attackers to execute arbitrary code via a crafted Excel file, aka “Excel
Record Parsing Memory Corruption Vulnerability,” a different vulnerability than
CVE-2010-0824 and CVE-2010-1245.

WEB-CLIENT Windows Media Player JPG header record mismatch memory corruption attempt (new)

CVE: 2010-1880
URL: http://www.microsoft.com/technet/security/bulletin/MS10-033.mspx

Unspecified vulnerability in Quartz.dll for DirectShow on Microsoft Windows 2000
SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1, and Server 2008 allows remote
attackers to execute arbitrary code via a media file with crafted compression
data, aka “MJPEG Media Decompression Vulnerability.”

WEB-PHP horde help module arbitrary command execution attempt (updated)

Bugtraq: 17292
CVE: 2006-1491

Eval injection vulnerability in Horde Application Framework versions 3.0 before
3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitrary code
via the help viewer.

SPECIFIC-THREATS Possible Zeus User-Agent – ie (updated)

URL: http://en.wikipedia.org/wiki/Zeus_(trojan_horse)

WEB-CLIENT Free Download Manager .torrent parsing comment overflow attempt (updated)

Bugtraq: 33555
CVE: 2009-0184

Multiple buffer overflows in the torrent parsing implementation in Free Download
Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute
arbitrary code via (1) a long file name within a torrent file, (2) a long
tracker URL in a torrent file, or (3) a long comment in a torrent file.

WEB-CLIENT Free Download Manager .torrent parsing announce overflow attempt (updated)

Bugtraq: 33555
CVE: 2009-0184

Multiple buffer overflows in the torrent parsing implementation in Free Download
Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute
arbitrary code via (1) a long file name within a torrent file, (2) a long
tracker URL in a torrent file, or (3) a long comment in a torrent file.

WEB-CLIENT Free Download Manager .torrent parsing name overflow attempt (updated)

Bugtraq: 33555
CVE: 2009-0184

Multiple buffer overflows in the torrent parsing implementation in Free Download
Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute
arbitrary code via (1) a long file name within a torrent file, (2) a long
tracker URL in a torrent file, or (3) a long comment in a torrent file.

WEB-CLIENT Free Download Manager .torrent parsing path overflow attempt (updated)

Bugtraq: 33555
CVE: 2009-0184

Multiple buffer overflows in the torrent parsing implementation in Free Download
Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute
arbitrary code via (1) a long file name within a torrent file, (2) a long
tracker URL in a torrent file, or (3) a long comment in a torrent file.

WEB-MISC Microsoft Sharepoint XSS attempt (updated)

CVE: 2010-0817
URL: http://www.microsoft.com/technet/security/bulletin/MS10-039.mspx

Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft
SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services
3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web
script or HTML via the cid0 parameter.

research Uncategorized

Vulnerability Scanner Detection Updates

June 8th, 2010
Comments Off

It’s been a while since the blog was updated with Vulnerability Scanner updates, but over the last couple of months we’ve been busy pushing out new detection. Below is a list of 200 new plugins that have gone out.


RealNetworks RealPlayer HTTP Chunked Encoding Integer Overflow

Bugtraq: 37880
CVE: CVE-2009-4243

RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741,
RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10
and 10.1, Linux RealPlayer 10, and Helix Player 10.x allow remote attackers to
have an unspecified impact via a crafted media file that uses HTTP chunked
transfer coding, related to an “overflow.”


Linux : RealNetworks RealPlayer HTTP Chunked Encoding Integer Overflow

Bugtraq: 37880
CVE: CVE-2009-4243

RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741,
RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10
and 10.1, Linux RealPlayer 10, and Helix Player 10.x allow remote attackers to
have an unspecified impact via a crafted media file that uses HTTP chunked
transfer coding, related to an “overflow.”


Mac : RealNetworks RealPlayer HTTP Chunked Encoding Integer Overflow

Bugtraq: 37880
CVE: CVE-2009-4243

RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741,
RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10
and 10.1, Linux RealPlayer 10, and Helix Player 10.x allow remote attackers to
have an unspecified impact via a crafted media file that uses HTTP chunked
transfer coding, related to an “overflow.”


Google Chrome Multiple Code Execution Vulnerabilities

Bugtraq: 38177
CVE: CVE-2010-0315

Three code execution vulnerabilities exist in Google Chrome. Two vulnerabilities
are due to integer overflows in the v8 engine and another is due to
deserializing a sandbox message. The other vulnerability is due to an
unspecified error while parsing tags. A malicious user can exploit these
vulnerabilities by enticing a user to download a malicious web page. This may
result in code execution.


Adobe Reader and Acrobat Domain Sandbox Bypass

Bugtraq: 38198
CVE: CVE-2010-0186

Cross-domain vulnerability in Adobe Flash Player before 10.0.45.2, Adobe AIR
before 1.5.3.9130, and Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before
9.3.1 allows remote attackers to bypass intended sandbox restrictions and make
cross-domain requests via unspecified vectors.


Linux : Adobe Reader and Acrobat Domain Sandbox Bypass

Bugtraq: 38198
CVE: CVE-2010-0186

Cross-domain vulnerability in Adobe Flash Player before 10.0.45.2, Adobe AIR
before 1.5.3.9130, and Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before
9.3.1 allows remote attackers to bypass intended sandbox restrictions and make
cross-domain requests via unspecified vectors.


Mac : Adobe Reader and Acrobat Domain Sandbox Bypass

Bugtraq: 38198
CVE: CVE-2010-0186

Cross-domain vulnerability in Adobe Flash Player before 10.0.45.2, Adobe AIR
before 1.5.3.9130, and Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before
9.3.1 allows remote attackers to bypass intended sandbox restrictions and make
cross-domain requests via unspecified vectors.


Adobe Reader and Acrobat Libtiff TIFFFetchShortPair Stack Buffer Overflow

Bugtraq: 38195
CVE: Not available

Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x
before 9.3.1 allows attackers to cause a denial of service (application crash)
or possibly execute arbitrary code via unknown vectors.


Linux : Adobe Reader and Acrobat Libtiff TIFFFetchShortPair Stack Buffer Overflow

Bugtraq: 38195
CVE: Not available

Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x
before 9.3.1 allows attackers to cause a denial of service (application crash)
or possibly execute arbitrary code via unknown vectors.


Mac : Adobe Reader and Acrobat Libtiff TIFFFetchShortPair Stack Buffer Overflow

Bugtraq: 38195
CVE: Not available

Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x
before 9.3.1 allows attackers to cause a denial of service (application crash)
or possibly execute arbitrary code via unknown vectors.


Linux: Novell Products AES and RC4 Decryption Integer Underflow

Bugtraq: 37749
CVE: CVE-2009-4212

Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality
in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7
before 1.7.1, allow remote attackers to cause a denial of service (daemon crash)
or possibly execute arbitrary code by providing ciphertext with a length that is
too short to be valid.


EMC HomeBase SSL Service Directory Traversal

Bugtraq: 38380
CVE: Not available

Directory traversal vulnerability in the SSL Service in EMC HomeBase Server
allows remote attackers to overwrite arbitrary files with any content, and
consequently execute arbitrary code, via a .. (dot dot) in an unspecified
parameter.


Linux : EMC HomeBase SSL Service Directory Traversal

Bugtraq: 38380
CVE: Not available

Directory traversal vulnerability in the SSL Service in EMC HomeBase Server
allows remote attackers to overwrite arbitrary files with any content, and
consequently execute arbitrary code, via a .. (dot dot) in an unspecified
parameter.


Microsoft Windows MsgBox Help File Code Execution

Bugtraq: Not available

CVE: Not available

Arbitrary code can be executed on the remote host through the installed VBScript
Scripting Engine.


Erisesoft easyftpsvr CWD Command Buffer Overflow

Bugtraq: 38102
CVE: Not available

Lack of input length checks for the CWD command result in a buffer overflow
vulnerability, allowing the execution of arbitrary code by a remote attacker.


Novell eDirectory SOAP Request Parsing Denial of Service

Bugtraq: 38157
CVE: CVE-2010-0666

Unspecified vulnerability in eMBox in Novell eDirectory 8.8 SP5 Patch 2 and
earlier allows remote attackers to cause a denial of service (crash) via unknown
a crafted SOAP request, a different issue than CVE-2008-0926.


Microsoft Windows winhlp32.exe MsgBox Remote Code Execution

Bugtraq: 38463
CVE: CVE-2010-0483

vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4,
XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows
user-assisted remote attackers to execute arbitrary code by referencing a (1)
local pathname, (2) UNC share pathname, or (3) WebDAV server with a crafted .hlp
file in the fourth argument (aka helpfile argument) to the MsgBox function,
leading to code execution involving winhlp32.exe when the F1 key is pressed, aka
“VBScript Help Keypress Vulnerability.”


McAfee LinuxShield nailsd Privilege Escalation

Bugtraq: 38489
CVE: Not available

A privilege escalation vulnerability exists in McAfee LinuxShield. The
vulnerability is due to insufficient access control to the “nailsd” daemon,
which listens on port 65443/tcp. Remote authenticated attackers can exploit this
vulnerability to execute arbitrary code on vulnerable installations of McAfee
LinuxShield within the security context of the root user.


Open-FTPD Ftp Server Long Password Buffer Overflow

Bugtraq: 30993
CVE: Not available

A buffer overflow in Open-FTPD Ftp server cause remote unauthenticated attacker
to execute arbitrary code with System privileges.


Yahoo! Player Playlist Handling Buffer Overflow

Bugtraq: 38581
CVE: Not available

Yahoo! Player is prone to a stack-based buffer-overflow vulnerability because
the application fails to bounds-check user-supplied data before copying it into
an insufficiently sized buffer.


GNU Tar and Cpio rmt_read Heap buffer Overflow

Bugtraq: 38628
CVE: CVE-2010-0624

Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the
rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows
remote rmt servers to cause a denial of service (memory corruption) or possibly
execute arbitrary code by sending more data than was requested, related to
archive filenames that contain a : (colon) character.


Skype URI Handling Datapath Security Bypass

Bugtraq: 38699
CVE: Not available

The remote Skype client is affected by an information disclosure vulnerability.


httpdx FTP USER and PASS Denial of Service

Bugtraq: 38718
CVE: Not available

An integer underflows when processing certain FTP commands, which can be
exploited to crash the service by e.g. sending FTP “USER” and “PASS” commands
with only a zero byte (0×00) as parameter.


SAP MaxDB Malformed Handshake Request Buffer Overflow

Bugtraq: 38769
CVE: CVE-2010-1185

Stack-based buffer overflow in serv.exe in SAP MaxDB 7.4.3.32, and 7.6.0.37
through 7.6.06 allows remote attackers to execute arbitrary code via an invalid
length parameter in a handshake packet to TCP port 7210.


Texas Imperial Software WFTPD Pro Server REST Command Handling Denial of Service

Bugtraq: 38762
CVE: Not available

A Input validation error in Texas Imperial Software WFTPD Pro Server cause
denial of service.


Novell eDirectory DHOST Web Service Predictable Session Cookie

Bugtraq: 38782
CVE: CVE-2009-4655

The dhost web service in Novell eDirectory 8.8.5 uses a predictable session
cookie, which makes it easier for remote attackers to hijack sessions via a
modified cookie.


Mac : Apple Safari 4 Unspecified Remote Code Execution

Bugtraq: 38955
CVE: CVE-2010-1120

Unspecified vulnerability in Safari 4 on Apple Mac OS X 10.6 allows remote
attackers to execute arbitrary code via unknown vectors, as demonstrated by
Charlie Miller during a Pwn2Own competition at CanSecWest 2010.


Apple QuickTime H.263 Movie File Buffer Overflow

Bugtraq: 39020
CVE: CVE-2010-0062

Heap-based buffer overflow in CoreMedia and QuickTime in Apple Mac OS X before
10.6.3 allows remote attackers to execute arbitrary code or cause a denial of
service (application crash) via a crafted movie file with H.263 encoding.


Mac: Apple QuickTime H.263 Movie File Buffer Overflow

Bugtraq: 39020
CVE: CVE-2010-0062

Heap-based buffer overflow in CoreMedia and QuickTime in Apple Mac OS X before
10.6.3 allows remote attackers to execute arbitrary code or cause a denial of
service (application crash) via a crafted movie file with H.263 encoding.


Apple QuickTime H.261 Movie File Buffer Overflow

Bugtraq: 39020
CVE: CVE-2010-0514

Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows
remote attackers to execute arbitrary code or cause a denial of service
(application crash) via a crafted movie file with H.261 encoding.


Mac: Apple QuickTime H.261 Movie File Buffer Overflow

Bugtraq: 39020
CVE: CVE-2010-0514

Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows
remote attackers to execute arbitrary code or cause a denial of service
(application crash) via a crafted movie file with H.261 encoding.


Apple QuickTime H.264 Movie File Memory Corruption

Bugtraq: 39020
CVE: CVE-2010-0515

QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute
arbitrary code or cause a denial of service (memory corruption and application
crash) via a crafted movie file with H.264 encoding.


Mac: Apple QuickTime H.264 Movie File Memory Corruption

Bugtraq: 39020
CVE: CVE-2010-0515

QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute
arbitrary code or cause a denial of service (memory corruption and application
crash) via a crafted movie file with H.264 encoding.


Apple QuickTime RLE Movie File Buffer Overflow

Bugtraq: 39020
CVE: CVE-2010-0516

Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows
remote attackers to execute arbitrary code or cause a denial of service
(application crash) via a crafted movie file with RLE encoding.


Mac: Apple QuickTime RLE Movie File Buffer Overflow

Bugtraq: 39020
CVE: CVE-2010-0516

Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows
remote attackers to execute arbitrary code or cause a denial of service
(application crash) via a crafted movie file with RLE encoding.


Apple QuickTime M-JPEG Movie File Buffer Overflow

Bugtraq: 39020
CVE: CVE-2010-0517

Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows
remote attackers to execute arbitrary code or cause a denial of service
(application crash) via a crafted movie file with M-JPEG encoding.


Mac: Apple QuickTime M-JPEG Movie File Buffer Overflow

Bugtraq: 39020
CVE: CVE-2010-0517

Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows
remote attackers to execute arbitrary code or cause a denial of service
(application crash) via a crafted movie file with M-JPEG encoding.


Apple QuickTime Sorenson Movie File Memory Corruption

Bugtraq: 39020
CVE: CVE-2010-0518

QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute
arbitrary code or cause a denial of service (memory corruption and application
crash) via a crafted movie file with Sorenson encoding.


Mac: Apple QuickTime Sorenson Movie File Memory Corruption

Bugtraq: 39020
CVE: CVE-2010-0518

QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute
arbitrary code or cause a denial of service (memory corruption and application
crash) via a crafted movie file with Sorenson encoding.


Apple QuickTime FlashPix Movie File Integer Overflow

Bugtraq: 39020
CVE: CVE-2010-0519

Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote
attackers to execute arbitrary code or cause a denial of service (application
crash) via a crafted movie file with FlashPix encoding.


Mac: Apple QuickTime FlashPix Movie File Integer Overflow

Bugtraq: 39020
CVE: CVE-2010-0519

Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote
attackers to execute arbitrary code or cause a denial of service (application
crash) via a crafted movie file with FlashPix encoding.


Apple QuickTime FLC Movie File Buffer Overflow

Bugtraq: 39020
CVE: CVE-2010-0520

Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows
remote attackers to execute arbitrary code or cause a denial of service
(application crash) via a crafted movie file with FLC encoding.


Mac: Apple QuickTime FLC Movie File Buffer Overflow

Bugtraq: 39020
CVE: CVE-2010-0520

Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows
remote attackers to execute arbitrary code or cause a denial of service
(application crash) via a crafted movie file with FLC encoding.


Apple QuickTime MPEG Movie File Buffer Overflow

Bugtraq: 39020
CVE: CVE-2010-0526

Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows
remote attackers to execute arbitrary code or cause a denial of service
(application crash) via a crafted movie file with MPEG encoding.


Mac: Apple QuickTime MPEG Movie File Buffer Overflow

Bugtraq: 39020
CVE: CVE-2010-0526

Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows
remote attackers to execute arbitrary code or cause a denial of service
(application crash) via a crafted movie file with MPEG encoding.


Novell ZENworks Configuration Management Code Execution

Bugtraq: 39114
CVE: Not available

Novell ZENworks Configuration Management is prone to a remote code-execution
vulnerability. An attacker can leverage this issue to execute arbitrary code
with SYSTEM-level privileges. Failed exploit attempts will result in a denial-
of-service condition.


Apple iTunes MP4 File Handling Denial of Service

Bugtraq: 39113
CVE: CVE-2010-0531

Apple iTunes before 9.1 allows remote attackers to cause a denial of service
(infinite loop) via a crafted MP4 podcast file.


Mac : Apple iTunes MP4 File Handling Denial of Service

Bugtraq: 39113
CVE: CVE-2010-0531

Apple iTunes before 9.1 allows remote attackers to cause a denial of service
(infinite loop) via a crafted MP4 podcast file.


Novell ZENworks Configuration Management Preboot Service Code Execution

Bugtraq: 39111
CVE: Not available

Novell ZENworks Configuration Management is prone to an unspecified remote code-
execution vulnerability. An attacker can leverage this issue to execute
arbitrary code with SYSTEM-level privileges. Failed exploit attempts will result
in a denial-of-service condition.


Apple iTunes Privilege Escalation

Bugtraq: 39092
CVE: CVE-2010-0532

Race condition in the installation package in Apple iTunes before 9.1 on Windows
allows local users to gain privileges by replacing an unspecified file with a
Trojan horse.


Apple iTunes TIFF File Handling Memory Corruption

Bugtraq: 38673
CVE: CVE-2010-0043

ImageIO in Apple Safari before 4.0.5 on Windows allows remote attackers to
execute arbitrary code or cause a denial of service (memory corruption and
application crash) via a crafted TIFF image.


Apple iTunes TIFF File Handling Buffer Underflow

Bugtraq: 35451
CVE: CVE-2009-2285

Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 allows
context-dependent attackers to cause a denial of service (crash) via a crafted
TIFF image, a different vulnerability than CVE-2008-2327.


Apple iTunes ColorSync Integer Overflow

Bugtraq: 38674
CVE: CVE-2010-0040

Integer overflow in ColorSync in Apple Safari before 4.0.5 on Windows allows
remote attackers to execute arbitrary code or cause a denial of service
(application crash) via an image with a crafted color profile that triggers a
heap-based buffer overflow.


Apple QuickTime QDM2 Content Handling Memory Corruption

Bugtraq: 39160
CVE: CVE-2010-0059

CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute
arbitrary code or cause a denial of service (memory corruption and application
crash) via crafted audio content with QDM2 encoding.


Mac: Apple QuickTime QDM2 Content Handling Memory Corruption

Bugtraq: 39160
CVE: CVE-2010-0059

CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute
arbitrary code or cause a denial of service (memory corruption and application
crash) via crafted audio content with QDM2 encoding.


Apple QuickTime QDMC Content Handling Memory Corruption

Bugtraq: 39164
CVE: CVE-2010-0060

CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute
arbitrary code or cause a denial of service (memory corruption and application
crash) via crafted audio content with QDMC encoding.


Mac: Apple QuickTime QDMC Content Handling Memory Corruption

Bugtraq: 39164
CVE: CVE-2010-0060

CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute
arbitrary code or cause a denial of service (memory corruption and application
crash) via crafted audio content with QDMC encoding.


Apple QuickTime PICT File Handling Integer Overflow

Bugtraq: 39136
CVE: CVE-2010-0527

Integer overflow in Apple QuickTime before 7.6.6 on Windows allows remote
attackers to execute arbitrary code or cause a denial of service (application
crash) via a crafted PICT image.


Apple QuickTime Movie File Handling Memory Corruption

Bugtraq: 39139
CVE: CVE-2010-0528

Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute
arbitrary code or cause a denial of service (memory corruption and application
crash) via crafted color tables in a movie file.


Apple QuickTime PICT File Handling Buffer Overflow

Bugtraq: 39140
CVE: CVE-2010-0529

Heap-based buffer overflow in QuickTime.qts in Apple QuickTime before 7.6.6 on
Windows allows remote attackers to execute arbitrary code or cause a denial of
service (application crash) via a PICT image with a BkPixPat opcode (0×12)
containing crafted values that are used in a calculation for memory allocation.


Apple QuickTime BMP File Handling Memory Corruption

Bugtraq: 39141
CVE: CVE-2010-0536

Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute
arbitrary code or cause a denial of service (memory corruption and application
crash) via a crafted BMP image.


Apple Mac OS X Internet Enabled Disk Image Code Execution

Bugtraq: 39194
CVE: CVE-2010-0497

Disk Images in Apple Mac OS X before 10.6.3 does not provide the expected
warning for an unsafe file type in an internet enabled disk image, which makes
it easier for user-assisted remote attackers to execute arbitrary code via a
package file type.


Apple Mac OS X ImageIO Framework JPEG2000 Arithmetic Error

Bugtraq: 39171
CVE: CVE-2010-0505

Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.3 allows
remote attackers to execute arbitrary code or cause a denial of service
(application crash) via a crafted JP2 (JPEG2000) image, related to incorrect
calculation and the CGImageReadGetBytesAtOffset function.


Oracle Java Soundbank Resource Name Stack Buffer Overflow

Bugtraq: 39070
CVE: CVE-2010-0839

Unspecified vulnerability in the Sound component in Oracle Java SE and Java for
Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote
attackers to affect confidentiality, integrity, and availability via unknown
vectors.


Linux : Oracle Java Soundbank Resource Name Stack Buffer Overflow

Bugtraq: 39070
CVE: CVE-2010-0839

Unspecified vulnerability in the Sound component in Oracle Java SE and Java for
Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote
attackers to affect confidentiality, integrity, and availability via unknown
vectors.


Mozilla Firefox Cross Document DOM Node Moving Code Execution

Bugtraq: 38952
CVE: CVE-2010-1121

Unspecified vulnerability in Mozilla Firefox 3 allows remote attackers to
execute arbitrary code via unknown vectors that trigger memory corruption.


Linux : Mozilla Firefox Cross Document DOM Node Moving Code Execution

Bugtraq: 38952
CVE: CVE-2010-1121

Unspecified vulnerability in Mozilla Firefox 3 allows remote attackers to
execute arbitrary code via unknown vectors that trigger memory corruption.


Mac : Mozilla Firefox Cross Document DOM Node Moving Code Execution

Bugtraq: 38952
CVE: CVE-2010-1121

Unspecified vulnerability in Mozilla Firefox 3 allows remote attackers to
execute arbitrary code via unknown vectors that trigger memory corruption.


Mozilla Firefox WOFF Font Format dirEntry Remote Code Execution

Bugtraq: 38298
CVE: CVE-2010-1028

Integer overflow in the decompression functionality in the Web Open Fonts Format
(WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to
execute arbitrary code via a crafted WOFF file that triggers a buffer overflow.


Linux : Mozilla Firefox WOFF Font Format dirEntry Remote Code Execution

Bugtraq: 38298
CVE: CVE-2010-1028

Integer overflow in the decompression functionality in the Web Open Fonts Format
(WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to
execute arbitrary code via a crafted WOFF file that triggers a buffer overflow.


Mac : Mozilla Firefox WOFF Font Format dirEntry Remote Code Execution

Bugtraq: 38298
CVE: CVE-2010-1028

Integer overflow in the decompression functionality in the Web Open Fonts Format
(WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to
execute arbitrary code via a crafted WOFF file that triggers a buffer overflow.


CA XOsoft Multiple Products xosoapapi.asmx Multiple Remote Code Execution

Bugtraq: 39238
CVE: CVE-2010-1223

Multiple buffer overflows in CA XOsoft r12.0 and r12.5 allow remote attackers to
execute arbitrary code via (1) a malformed request to the ws_man/xosoapapi.asmx
SOAP endpoint or (2) a long string to the entry_point.aspx service.


Linux Kernel sctp_rcv_ootb Remote Denial of Service

Bugtraq: 38857
CVE: CVE-2010-0008

The SCTP implementation in the Linux kernel before 2.6.23 allows remote
attackers to cause a denial of service (infinite loop) via (1) an Out Of The
Blue (OOTB) chunk or (2) a chunk of zero length.


OpenSSL bn_wexpend Error Handling Remote Code Execution

Bugtraq: 38562
CVE: CVE-2009-3245

OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand
function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3)
crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact
and context-dependent attack vectors.


Linux : OpenSSL bn_wexpend Error Handling Remote Code Execution

Bugtraq: 38562
CVE: CVE-2009-3245

OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand
function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3)
crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact
and context-dependent attack vectors.


Mac : OpenSSL bn_wexpend Error Handling Remote Code Execution

Bugtraq: 38562
CVE: CVE-2009-3245

OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand
function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3)
crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact
and context-dependent attack vectors.


Oracle Java Runtime Environment Image File Buffer Overflow

Bugtraq: 39071
CVE: CVE-2010-0847

Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java
for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote
attackers to affect confidentiality, integrity, and availability via unknown
vectors.


Linux : Oracle Java Runtime Environment Image File Buffer Overflow

Bugtraq: 39071
CVE: CVE-2010-0847

Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java
for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote
attackers to affect confidentiality, integrity, and availability via unknown
vectors.


Clam AntiVirus Scanning qtm_decompress Memory Corruption

Bugtraq: 39262
CVE: CVE-2010-0098

ClamAV before 0.96 does not properly handle the (1) CAB and (2) 7z file formats,
which allows remote attackers to bypass virus detection via a crafted archive
that is compatible with standard archive utilities.


Oracle Java Web Start Launch Command-Line Injection

Bugtraq: 39346
CVE: Not available

A command-line injection vulnerability exists in Oracle Java SE and Java for
Business 6 Update 10 to 6 Update 19.


VMware Products Multiple Vulnerabilities

Bugtraq: Not available

CVE: Not available

Multiple VMware products are prone to remote code-execution vulnerability that
exist in VMware Tools, local privilege-escalation vulnerability, information-
disclosure vulnerability, remote denial-of-service vulnerability, remote format
string vulnerability, multiple heap-based buffer-overflow vulnerabilities.


Oracle Java Web Start InstallJRE Policy Bypass

Bugtraq: 39346
CVE: Not available

A policy bypass vulnerability exists in Oracle Java SE and Java for Business 6
Update 10 to 6 Update 19.


VMware Movie Decoder VMnc Codec Heap Buffer Overflow

Bugtraq: 39363
CVE: CVE-2009-1564

Heap-based buffer overflow in vmnc.dll in the VMnc media codec in VMware Movie
Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware
Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4
build 246459, and VMware Server 2.x on Windows, allows remote attackers to
execute arbitrary code via an AVI file with crafted video chunks that use
HexTile encoding.


Adobe Reader U3D CLODMeshDeclaration Shading Count Buffer Overflow

Bugtraq: 39329
CVE: CVE-2010-0196

A buffer overflow vulnerability in Adobe Reader 9.x before 9.3.2, and 8.x before
8.2.2 on Linux, allows attackers to cause a denial of service or possibly
execute arbitrary code via unknown vectors.


Microsoft Windows Kernel Null Pointer Dereference

Bugtraq: 39297
CVE: CVE-2010-0234

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista
Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate a
registry-key argument to an unspecified system call, which allows local users to
cause a denial of service (reboot) via a crafted application, aka “Windows
Kernel Null Pointer Vulnerability.”


Microsoft Windows Kernel Symbolic Link Value Denial of Service

Bugtraq: 39309
CVE: CVE-2010-0235

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and
Vista Gold does not perform the expected validation before creating a symbolic
link, which allows local users to cause a denial of service (reboot) via a
crafted application, aka “Windows Kernel Symbolic Link Value Vulnerability.”


Microsoft Windows 2000 Media Services Stack Buffer Overflow

Bugtraq: Not available

CVE: CVE-2010-0478

Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in
Media Services for Microsoft Windows 2000 Server SP4 allows remote attackers to
execute arbitrary code via crafted packets associated with transport
information, aka “Media Services Stack-based Buffer Overflow Vulnerability.”


Microsoft Windows Kernel Symbolic Link Creation Privilege Escalation

Bugtraq: 39324
CVE: CVE-2010-0237

The kernel in Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows local users
to gain privileges by creating a symbolic link from an untrusted registry hive
to a trusted registry hive, aka “Windows Kernel Symbolic Link Creation
Vulnerability.”


Microsoft Windows Kernel Registry Key Denial Of Service

Bugtraq: 39318
CVE: CVE-2010-0238

Unspecified vulnerability in registry-key validation in the kernel in Microsoft
Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold allows local
users to cause a denial of service (reboot) via a crafted application, aka
“Windows Kernel Registry Key Vulnerability.”


Microsoft Windows Virtual Path Parsing Denial Of Service

Bugtraq: 39319
CVE: CVE-2010-0481

The kernel in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008
Gold, SP2, and R2, and Windows 7 does not properly translate a registry key\’s
virtual path to its real path, which allows local users to cause a denial of
service (reboot) via a crafted application, aka “Windows Virtual Path Parsing
Vulnerability.”


Microsoft Windows Kernel Malformed Image Denial Of Service

Bugtraq: 39320
CVE: CVE-2010-0482

The kernel in Microsoft Windows Server 2008 R2 and Windows 7 does not properly
validate relocation sections of image files, which allows local users to cause a
denial of service (reboot) via a crafted file, aka “Windows Kernel Malformed
Image Vulnerability.”


Microsoft Windows Kernel Exception Handler Denial Of Service

Bugtraq: 39322
CVE: CVE-2010-0810

The kernel in Microsoft Windows Vista Gold, SP1, and SP2, and Windows Server
2008 Gold and SP2, does not properly handle unspecified exceptions, which allows
local users to cause a denial of service (reboot) via a crafted application, aka
“Windows Kernel Exception Handler Vulnerability.”


Microsoft Office Visio Index Calculation Memory Corruption

Bugtraq: 39302
CVE: CVE-2010-0256

Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not
properly calculate Donkey unspecified indexes associated with Visio files, which
allows remote attackers to execute arbitrary code via a crafted file, aka “Visio
Index Calculation Memory Corruption Vulnerability.”


Microsoft Office Publisher File Conversion TextBox Processing Buffer Overflow

Bugtraq: 39347
CVE: CVE-2010-0479

Buffer overflow in Microsoft Office Publisher 2002 SP3, 2003 SP3, and 2007 SP1
and SP2 allows remote attackers to execute arbitrary code via a crafted
Publisher file, aka “Microsoft Office Publisher File Conversion TextBox
Processing Buffer Overflow Vulnerability.”


Microsoft Windows SMTP Service MX Record Denial Of Service

Bugtraq: 39308
CVE: CVE-2010-0024

The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003
SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not
properly parse MX records, which allows remote DNS servers to cause a denial of
service (service outage) via a crafted response to a DNS MX record query, aka
“SMTP Server MX Record Vulnerability.”


Microsoft Windows SMTP Service Memory Allocation Information Disclosure

Bugtraq: 39381
CVE: CVE-2010-0025

The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003
SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, does not
properly allocate memory for SMTP command replies, which allows remote attackers
to read fragments of e-mail messages by sending a series of invalid commands and
then sending a STARTTLS command, aka “SMTP Memory Allocation Vulnerability.”


Microsoft Windows Kernel Memory Allocation Privilege Escalation

Bugtraq: 39323
CVE: CVE-2010-0236

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and
Vista Gold does not properly allocate memory for the destination key associated
with a symbolic-link registry key, which allows local users to gain privileges
via a crafted application, aka “Windows Kernel Memory Allocation Vulnerability.”


Microsoft Windows MPEG Layer-3 Audio Decoder Stack Buffer Overflow

Bugtraq: 39303
CVE: CVE-2010-0480

Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in
Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1,
and SP2, and Server 2008 Gold and SP2 allow remote attackers to execute
arbitrary code via a crafted AVI file, aka “MPEG Layer-3 Audio Decoder Stack
Overflow Vulnerability.”


Microsoft Windows Media Player Remote Code Execution

Bugtraq: 39351
CVE: CVE-2010-0268

Unspecified vulnerability in the Windows Media Player ActiveX control in Windows
Media Player (WMP) 9 on Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows
remote attackers to execute arbitrary code via crafted media content, aka “Media
Player Remote Code Execution Vulnerability.”


Microsoft Office Visio Attribute Validation Memory Corruption

Bugtraq: 39300
CVE: CVE-2010-0254

Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not
properly validate attributes in Visio files, which allows remote attackers to
execute arbitrary code via a crafted file, aka “Visio Attribute Validation
Memory Corruption Vulnerability.”


Microsoft Windows ISATAP IPv6 Source Address Spoofing

Bugtraq: 39352
CVE: CVE-2010-0812

Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and
Server 2008 Gold and SP2 allow remote attackers to bypass intended IPv4 source-
address restrictions via a mismatched IPv6 source address in a tunneled ISATAP
packet, aka “ISATAP IPv6 Source Address Spoofing Vulnerability.”


Microsoft Windows WinVerifyTrust Signature Validation Security Bypass

Bugtraq: 39328
CVE: CVE-2010-0486

The WinVerifyTrust function in Authenticode Signature Verification 5.1, 6.0, and
6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003
SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2,
and Windows 7 does not properly use unspecified fields in a file digest, which
allows user-assisted remote attackers to execute arbitrary code via a modified
(1) Portable Executable (PE) or (2) cabinet (aka .CAB) file that incorrectly
appears to have a valid signature, aka “WinVerifyTrust Signature Validation
Vulnerability.”


Microsoft Windows WinVerifyTrust Cabview Corruption Validation Security Bypass

Bugtraq: 39332
CVE: CVE-2010-0487

The Authenticode Signature verification functionality in cabview.dll in Cabinet
File Viewer Shell Extension 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4,
Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and
SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use
unspecified fields in a file digest, which allows remote attackers to execute
arbitrary code via a modified cabinet (aka .CAB) file that incorrectly appears
to have a valid signature, aka “Cabview Corruption Validation Vulnerability.”


Microsoft Windows SMB Client Invalid Memory Allocation

Bugtraq: 39312
CVE: CVE-2010-0269

The SMB client in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows
Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold,
SP2, and R2, and Windows 7 does not properly allocate memory for SMB responses,
which allows remote SMB servers and man-in-the-middle attackers to execute
arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka “SMB Client
Memory Allocation Vulnerability.”


Microsoft Windows SMB Client Transaction Memory Corruption

Bugtraq: 39339
CVE: CVE-2010-0270

The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not
properly validate fields in SMB transaction responses, which allows remote SMB
servers and man-in-the-middle attackers to execute arbitrary code or cause a
denial of service (memory corruption and reboot) via a crafted (1) SMBv1 or (2)
SMBv2 response, aka “SMB Client Transaction Vulnerability.”


Microsoft Windows SMB Client Response Parsing Memory Corruption

Bugtraq: 39336
CVE: CVE-2010-0476

The SMB client in Microsoft Windows Server 2003 SP2, Vista Gold, SP1, and SP2,
and Windows Server 2008 Gold and SP2 allows remote SMB servers and man-in-the-
middle attackers to execute arbitrary code or cause a denial of service (memory
corruption and reboot) via a crafted SMB transaction response that uses (1)
SMBv1 or (2) SMBv2, aka “SMB Client Response Parsing Vulnerability.”


Microsoft Windows SMB Client Message Size Vulnerability

Bugtraq: 39340
CVE: CVE-2010-0477

The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not
properly handle (1) SMBv1 and (2) SMBv2 response packets, which allows remote
SMB servers and man-in-the-middle attackers to execute arbitrary code via a
crafted packet that causes the client to read the entirety of the response, and
then improperly interact with the Winsock Kernel (WSK), aka “SMB Client Message
Size Vulnerability.”


Oracle Java System Directory Server DSML UTF-8 Denial of Service

Bugtraq: 39453
CVE: CVE-2010-0897

In the Sun Java System Directory Server component in Oracle Sun Product Suite
5.2, 6.0, 6.1, 6.2, 6.3, and 6.3.1 allows remote attackers to affect
confidentiality, integrity, and availability via unknown vectors related to
Directory Service Markup Language.


Adobe Acrobat and Reader Multiple Vulnerabilities – APSB10-09

Bugtraq: 39329
CVE: Not available

Critical vulnerabilities have been identified in Adobe Reader 9.3.1 (and earlier
versions) for Windows, Macintosh, and UNIX, Adobe Acrobat 9.3.1 (and earlier
versions) for Windows and Macintosh, and Adobe Reader 8.2.1 (and earlier
versions) and Adobe Acrobat 8.2.1 (and earlier versions) for Windows and
Macintosh. These vulnerabilities could cause the application to crash and could
potentially allow an attacker to take control of the affected system


Linux : Adobe Acrobat and Reader Multiple Vulnerabilities – APSB10-09

Bugtraq: 39329
CVE: Not available

Critical vulnerabilities have been identified in Adobe Reader 9.3.1 (and earlier
versions) for Windows, Macintosh, and UNIX, Adobe Acrobat 9.3.1 (and earlier
versions) for Windows and Macintosh, and Adobe Reader 8.2.1 (and earlier
versions) and Adobe Acrobat 8.2.1 (and earlier versions) for Windows and
Macintosh. These vulnerabilities could cause the application to crash and could
potentially allow an attacker to take control of the affected system


Mac : Adobe Acrobat and Reader Multiple Vulnerabilities – APSB10-09

Bugtraq: 39329
CVE: Not available

Critical vulnerabilities have been identified in Adobe Reader 9.3.1 (and earlier
versions) for Windows, Macintosh, and UNIX, Adobe Acrobat 9.3.1 (and earlier
versions) for Windows and Macintosh, and Adobe Reader 8.2.1 (and earlier
versions) and Adobe Acrobat 8.2.1 (and earlier versions) for Windows and
Macintosh. These vulnerabilities could cause the application to crash and could
potentially allow an attacker to take control of the affected system


Mac : Apple Mac OS X Apple Type Services libFontParser Code Execution

Bugtraq: 38955
CVE: CVE-2010-1120

Unspecified vulnerability in Safari 4 on Apple Mac OS X 10.6 allows remote
attackers to execute arbitrary code via unknown vectors, as demonstrated by
Charlie Miller during a Pwn2Own competition at CanSecWest 2010.


Oracle Database Server Multiple Vulnerabilities – April 2010

Bugtraq: Not available

CVE: Not available

Multiple vulnerabilities exist in Oracle Database Server. Some of these
vulnerabilities may be exploited by remote authenticated attackers to execute
arbitrary code on the target system. At least one of these vulnerabilities can
lead to full compromise of the system, where the injected code will run within
the security context of the system user.


IBM Lotus Notes SURunAs.exe Password Disclosure

Bugtraq: 39525
CVE: CVE-2010-1487

IBM Lotus Notes 7.0, 8.0, and 8.5 stores administrative credentials in cleartext
in SURunAs.exe, which allows local users to obtain sensitive information by
examining this file, aka SPR JSTN837SEG.


Multiple Vendors AgentX receive_agentx Stack Buffer Overflow

Bugtraq: 39564
CVE: CVE-2010-1318

Buffer overflow in the Atlcom.get_atlcom ActiveX control in gp.ocx in Adobe
Download Manager, as used in Adobe Reader and Acrobat 8.x before 8.2 and 9.x
before 9.3, allows remote attackers to execute arbitrary code via unspecified
parameters.


Multiple Vendors AgentX receive_agentx Integer Overflow

Bugtraq: 39490
CVE: CVE-2010-1319

Integer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as
used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and
other products, allows remote attackers to execute arbitrary code via a request
with a crafted payload length.


RealNetworks Helix Server NTLM Authentication Heap Overflow

Bugtraq: 39490
CVE: CVE-2010-1317

Heap-based buffer overflow in the NTLM authentication functionality in
RealNetworks Helix Server and Helix Mobile Server 11.x, 12.x, and 13.x allows
remote attackers to have an unspecified impact via invalid base64-encoded data.


VMware Remote Console Format String Code Execution

Bugtraq: 39396
CVE: CVE-2009-3732

Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote
Console (aka VMrc) allows remote attackers to execute arbitrary code via
unspecified vectors.


Google Chrome Multiple Vulnerabilities – Google Chrome 4.1.249.1059

Bugtraq: 39603
CVE: Not available

Multiple vulnerabilities have been reported in Google Chrome earlier than
4.1.249.1059.


Adobe Download Manager Atlcom.get_atlcom ActiveX Control Remote Code Execution

Bugtraq: 39615
CVE: CVE-2010-1278

Buffer overflow in the Atlcom.get_atlcom ActiveX control in gp.ocx in Adobe
Download Manager, as used in Adobe Reader and Acrobat 8.x before 8.2 and 9.x
before 9.3, allows remote attackers to execute arbitrary code via unspecified
parameters.


Linux : Adobe Download Manager Atlcom.get_atlcom ActiveX Control Remote Code Execution

Bugtraq: 39615
CVE: CVE-2010-1278

Buffer overflow in the Atlcom.get_atlcom ActiveX control in gp.ocx in Adobe
Download Manager, as used in Adobe Reader and Acrobat 8.x before 8.2 and 9.x
before 9.3, allows remote attackers to execute arbitrary code via unspecified
parameters.


Mac : Adobe Download Manager Atlcom.get_atlcom ActiveX Control Remote Code Execution

Bugtraq: 39615
CVE: CVE-2010-1278

Buffer overflow in the Atlcom.get_atlcom ActiveX control in gp.ocx in Adobe
Download Manager, as used in Adobe Reader and Acrobat 8.x before 8.2 and 9.x
before 9.3, allows remote attackers to execute arbitrary code via unspecified
parameters.


Apache ActiveMQ Source Code Disclosure

Bugtraq: 39636
CVE: Not available

The remote web server is affected by an information disclosure vulnerability.


Alt-N MDaemon Server Multiple Denial of Service Vulnerabilities

Bugtraq: 39657
CVE: Not available

MDaemon is prone to multiple remote denial-of-service vulnerabilities. An
attacker can exploit these issues to cause a crash, denying service to
legitimate users.


Google Chrome net-internals Cross Site Scripting

Bugtraq: 39667
CVE: CVE-2010-1503

Cross-site scripting (XSS) vulnerability in Google Chrome before 4.1.249.1059
allows remote attackers to inject arbitrary web script or HTML via vectors
related to a chrome://net-internals URI.


Novell ZENworks Configuration Management UploadServlet Code Execution

Bugtraq: 39114
CVE: Not available

An error in the UploadServlet within Remote Management of ZENworks Server
(zenserver.exe) can be exploited to upload a file to an arbitrary directory
(e.g. the web root). An attacker can leverage this issue to execute arbitrary
code with SYSTEM-level privileges. Failed exploit attempts will result in a
denial-of-service condition.


Microsoft Internet Explorer XSS Filter Cross Site Scripting

Bugtraq: Not available

CVE: CVE-2010-1489

The XSS Filter in Microsoft Internet Explorer 8 does not properly perform
neutering for the SCRIPT tag, which allows remote attackers to conduct cross-
site scripting (XSS) attacks against web sites that have no inherent XSS
vulnerabilities, a different issue than CVE-2009-4074.


Opera Browser Document Writing Uninitialized Memory Access

Bugtraq: 39855
CVE: CVE-2010-1728

Opera Web Browser is prone to a remote code-execution vulnerability. Attackers
can exploit this issue to execute arbitrary code or crash the affected
application.


Mac: Opera Browser Document Writing Uninitialized Memory Access

Bugtraq: 39855
CVE: Not available

Opera Web Browser is prone to a remote code-execution vulnerability. Attackers
can exploit this issue to execute arbitrary code or crash the affected
application.


Wing FTP Server HTTP protocol Directory Traversal

Bugtraq: 39744
CVE: Not available

A vulnerability is found in Wing FTP Server due to an input validation error
when processing HTTP requests. This can be exploited to access files outside the
web root folder via directory traversal attacks.


Oracle Database Server DBMS_CDC_PUBLISH Multiple Procedure SQL Injection

Bugtraq: 39422
CVE: CVE-2010-0870

Unspecified vulnerability in the Change Data Capture component in Oracle
Database 9.2.0.8 and 9.2.0.8DV allows remote authenticated users to affect
confidentiality and integrity, related to SYS.DBMS_CDC_PUBLISH.


Google Chrome GURL Cross Origin Bypass Vulnerability

Bugtraq: 39813
CVE: CVE-2010-1663

The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before
4.1.249.1064 allows remote attackers to bypass the Same Origin Policy via
unspecified vectors.


Google Chrome Font Handling Memory Corruption

Bugtraq: 39808
CVE: CVE-2010-1665

Google Chrome before 4.1.249.1064 does not properly handle fonts, which allows
remote attackers to cause a denial of service (memory corruption) and possibly
have unspecified other impact via unknown vectors.


Google Chrome HTML5 Media Handling Memory Corruption

Bugtraq: 39804
CVE: CVE-2010-1664

Google Chrome before 4.1.249.1064 does not properly handle HTML5 media, which
allows remote attackers to cause a denial of service (memory corruption) and
possibly have unspecified other impact via unknown vectors.


Microsoft Office SharePoint Server help.aspx Cross Site Scripting

Bugtraq: Not available

CVE: CVE-2010-0817

Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft
SharePoint Server 2007 12.0.0.6421, and possibly earlier versions, allows remote
attackers to inject arbitrary web script or HTML via the cid0 parameter.


Adobe Photoshop CS4 TIFF File Processing Code Execution

Bugtraq: 39849
CVE: CVE-2010-1279

Multiple unspecified vulnerabilities in Adobe Photoshop CS4 11.x before 11.0.1
allow user-assisted remote attackers to execute arbitrary code via a crafted
TIFF file.


PHP HTTP Chunked Encoding Memory Corruption

Bugtraq: 39877
CVE: Not available

PHP is prone to a remote integer-overflow vulnerability. An attacker can exploit
this issue to execute arbitrary code in the context of the PHP process. Failed
exploit attempts will result in a denial-of-service condition.


RealVNC VNC Server ClientCutText Message Memory Corruption

Bugtraq: 39895
CVE: Not available

RealVNC Server “ClientCutText” message memory corruptionremote or denial of
service.


Alt-N MDaemon Email Server Remote File Disclosure

Bugtraq: Not available

CVE: Not available

A vulnerability was reported in MDaemon. A remote user can view files on the
target system in certain situations. A remote user can supply a specially
crafted mailing list SUBSCRIBE request followed by an additional request to view
arbitrary human-readable files on target.


Microsoft Office Visio DXF File Inserting Buffer Overflow

Bugtraq: 39836
CVE: CVE-2010-1681

Microsoft Visio is prone to a remote buffer-overflow vulnerability. This issue
arises when the application processes a malicious file. Attackers can exploit
this issue to execute arbitrary code in the context of the user running the
application. Failed exploit attempts will result in a denial-of-service
condition.


Microsoft Windows SMTP Service Predictable DNS Query Id

Bugtraq: 39908
CVE: CVE-2010-1689

The Microsoft Windows Simple Mail Transfer Protocol (SMTP) Server is prone to a
DNS spoofing vulnerability. Successfully exploiting this issue allows remote
attackers to spoof DNS replies, allowing them to redirect network traffic and to
launch man-in-the-middle attacks.


Microsoft Windows SMTP Service DNS Response Spoofing

Bugtraq: 39910
CVE: CVE-2010-1690

The Microsoft Windows Simple Mail Transfer Protocol (SMTP) Server is prone to a
DNS spoofing vulnerability. Successfully exploiting this issue allows remote
attackers to spoof DNS replies, allowing them to redirect network traffic and to
launch man-in-the-middle attacks.


Oracle Java Deployment Toolkit ActiveX Control Remote Code Execution

Bugtraq: Not available

CVE: CVE-2010-1423

Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and
(b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when
running on Windows and possibly on Linux, allows remote attackers to execute
arbitrary code via the (1) -J or (2) -XXaltjvm argument to javaws.exe, which is
processed by the launch method. NOTE: some of these details are obtained from
third party information.


Linux : Oracle Java Deployment Toolkit ActiveX Control Remote Code Execution

Bugtraq: Not available

CVE: CVE-2010-1423

Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and
(b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when
running on Windows and possibly on Linux, allows remote attackers to execute
arbitrary code via the (1) -J or (2) -XXaltjvm argument to javaws.exe, which is
processed by the launch method. NOTE: some of these details are obtained from
third party information.


Apple Safari parent.close Code Execution

Bugtraq: 39990
CVE: CVE-2010-1939

Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote
attackers to execute arbitrary code by using window.open to create a popup
window for a crafted HTML document, and then calling the parent window\’s close
method, which triggers improper handling of a deleted window object.


RedHat JBoss Enterprise Application Platform JMX Console Authentication Bypass

Bugtraq: 39710
CVE: CVE-2010-0738

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise
Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3
before 4.3.0.CP08 performs access control only for the GET and POST methods,
which allows remote attackers to send requests to this application\’s GET
handler by using a different method.


Xitami Web Server AUX Processing Denial Of Service

Bugtraq: 40027
CVE: Not available

Xitami is prone to a denial-of-service vulnerability. Attackers can exploit this
issue to crash the affected application, denying service to legitimate users.


Microsoft Windows Mail and Outlook Express Integer Overflow

Bugtraq: 40052
CVE: CVE-2010-0816

Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6
SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 and SP2,
Windows Server 2008 Gold, SP2, and R2, and Windows 7; and Windows Mail on
Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7
allows remote e-mail servers and man-in-the-middle attackers to execute
arbitrary code via a crafted (1) POP3 or (2) IMAP response, as demonstrated by a
certain +OK response on TCP port 110, aka “Outlook Express and Windows Mail
Integer Overflow Vulnerability.


Microsoft Office VBE6.DLL Stack Memory Corruption

Bugtraq: 39931
CVE: CVE-2010-0815

VBE6.DLL in Microsoft Office XP SP3, Office 2003 SP3, 2007 Microsoft Office
System SP1 and SP2, Visual Basic for Applications (VBA), and VBA SDK 6.3 through
6.5 does not properly search for ActiveX controls that are embedded in
documents, which allows remote attackers to execute arbitrary code via a crafted
document, aka “VBE6.DLL Stack Memory Corruption Vulnerability.”


HP OpenView Network Node Manager ovet_demandpoll.exe Format String Code Execution

Bugtraq: 40065
CVE: CVE-2010-1550

Format string vulnerability in ovet_demandpoll.exe in HP OpenView Network Node
Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute
arbitrary code via format string specifiers in the sel parameter.


Adobe Shockwave Player Signedness Code Execution

Bugtraq: 40076
CVE: CVE-2010-0128

Integer signedness error in dirapi.dll in Adobe Shockwave Player before
11.5.7.609 and Adobe Director before 11.5.7.609 allows remote attackers to cause
a denial of service (memory corruption) or possibly execute arbitrary code via a
crafted .dir file that triggers an invalid read operation.


Mac : Adobe Shockwave Player Signedness Code Execution

Bugtraq: 40076
CVE: CVE-2010-0128

Integer signedness error in dirapi.dll in Adobe Shockwave Player before
11.5.7.609 and Adobe Director before 11.5.7.609 allows remote attackers to cause
a denial of service (memory corruption) or possibly execute arbitrary code via a
crafted .dir file that triggers an invalid read operation.


HP OpenView Network Node Manager netmon.exe Stack Buffer Overflow

Bugtraq: 40067
CVE: CVE-2010-1551

Stack-based buffer overflow in the _OVParseLLA function in ov.dll in netmon.exe
in Network Monitor in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and
7.53 allows remote attackers to execute arbitrary code via the sel parameter.


Adobe Shockwave Player Memory Corruption

Bugtraq: Not available

CVE: Not available

Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of
service (memory corruption) or possibly execute arbitrary code via unspecified
vectors.


Mac : Adobe Shockwave Player Memory Corruption

Bugtraq: Not available

CVE: Not available

Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of
service (memory corruption) or possibly execute arbitrary code via unspecified
vectors.


Adobe Shockwave Player Integer Overflow

Bugtraq: 40084
CVE: CVE-2010-0130

Integer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote
attackers to execute arbitrary code via a crafted .dir (aka Director) file.


Mac : Adobe Shockwave Player Integer Overflow

Bugtraq: 40084
CVE: CVE-2010-0130

Integer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote
attackers to execute arbitrary code via a crafted .dir (aka Director) file.


Adobe Shockwave Player Integer Overflow

Bugtraq: Not available

CVE: Not available

Heap-based buffer overflow in Adobe Shockwave Player before 11.5.7.609 might
allow remote attackers to execute arbitrary code via crafted embedded fonts in a
Shockwave file.


Mac : Adobe Shockwave Player Integer Overflow

Bugtraq: Not available

CVE: Not available

Heap-based buffer overflow in Adobe Shockwave Player before 11.5.7.609 might
allow remote attackers to execute arbitrary code via crafted embedded fonts in a
Shockwave file.


Adobe Shockwave Player Denial of Service

Bugtraq: 40088
CVE: CVE-2010-1282

Adobe Shockwave Player before 11.5.7.609 allows remote attackers to cause a
denial of service (infinite loop and CPU consumption) via a crafted ATOM size in
a .dir (aka Director) file.


Mac : Adobe Shockwave Player Denial of Service

Bugtraq: 40088
CVE: CVE-2010-1282

Adobe Shockwave Player before 11.5.7.609 allows remote attackers to cause a
denial of service (infinite loop and CPU consumption) via a crafted ATOM size in
a .dir (aka Director) file.


HP OpenView NNM snmpviewer.exe CGI Format String Code Execution

Bugtraq: 40068
CVE: CVE-2010-1552

Stack-based buffer overflow in the doLoad function in snmpviewer.exe in HP
OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote
attackers to execute arbitrary code via the act and app parameters.


HP OpenView NNM getnnmdata.exe CGI MaxAge Parameter Buffer Overflow

Bugtraq: 40070
CVE: CVE-2010-1553

Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node
Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute
arbitrary code via an invalid MaxAge parameter.


HP OpenView NNM getnnmdata.exe CGI ICount Parameter Buffer Overflow

Bugtraq: 40071
CVE: CVE-2010-1554

Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node
Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute
arbitrary code via an invalid iCount parameter.


HP OpenView NNM getnnmdata.exe CGI Hostname Parameter Buffer Overflow

Bugtraq: 40072
CVE: CVE-2010-1555

Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node
Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute
arbitrary code via an invalid Hostname parameter.


Oracle MySQL Database COM_FIELD_LIST Security Bypass

Bugtraq: 40109
CVE: CVE-2010-1848

MySQL is prone to a security-bypass vulnerability. An attacker can exploit this
issue to bypass certain security restrictions and to read and delete content
from the affected database. Other attacks may also be possible.


Oracle MySQL Database COM_FIELD_LIST Buffer Overflow

Bugtraq: 40106
CVE: CVE-2010-1850

MySQL is prone to a buffer-overflow vulnerability because it fails to perform
adequate boundary checks on user-supplied data. An authenticated attacker can
leverage this issue to execute arbitrary code within the context of the
vulnerable application. Failed exploit attempts will result in a denial-of-
service condition.


Adobe Shockwave Player DIR File Parsing Memory Corruption

Bugtraq: 40081
CVE: CVE-2010-1280

Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute
arbitrary code or cause a denial of service (memory corruption) via a crafted
.dir (aka Director) file, related to (1) an erroneous dereference and (2) a
certain Shock.dir file.


Adobe Shockwave Player DIR Files PAMI Chunk Code Execution

Bugtraq: 40079
CVE: CVE-2010-1292

The implementation of pami RIFF chunk parsing in Adobe Shockwave Player before
11.5.7.609 does not validate a certain value from a file before using it in
file-pointer calculations, which allows remote attackers to execute arbitrary
code or cause a denial of service (memory corruption) via a crafted .dir (aka
Director) file.


Mac : Apple Mac OS X Java mediaLibImage Object Processing Code Execution

Bugtraq: 40238
CVE: CVE-2010-0538

Apple Mac OS X is prone to a vulnerability that lets attackers run arbitrary
code because the software fails to properly handle Java applets containing
malicious \’mediaLibImage\’ objects. Successful exploits will allow an attacker
to run arbitrary code in the context of the affected software. Failed exploit
attempts may result in denial-of-service conditions.


Mac : Apple Mac OS X Java Window Drawing Handling Code Execution

Bugtraq: 40240
CVE: CVE-2010-0539

Apple Mac OS X is prone to a vulnerability that lets attackers run arbitrary
code because the software fails to properly handle window drawing in specially
crafted Java applets. Successful exploits will allow an attacker to run
arbitrary code in the context of the affected software. Failed exploit attempts
may result in denial-of-service conditions.


IBM WebSphere Application Server File Disclosure

Bugtraq: 40277
CVE: CVE-2010-0777

The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43,
6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle long
filenames and consequently sends an incorrect file in some responses, which
allows remote attackers to obtain sensitive information by reading the retrieved
file.


ClamAV AntiVirus PDF cli_pdf Denial of Service

Bugtraq: 40317
CVE: CVE-2010-1639

The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote
attackers to cause a denial of service (crash) via a malformed PDF file, related
to an inconsistency in the calculated stream length and the real stream length.


Adobe Shockwave Player 3D Parsing Memory Corruption

Bugtraq: 40077
CVE: CVE-2010-1283

Adobe Shockwave Player before 11.5.7.609 does not properly parse 3D objects in
.dir (aka Director) files, which allows remote attackers to execute arbitrary
code or cause a denial of service (heap memory corruption) via a modified field
in a 0xFFFFFF49 record.


Mac : Adobe Shockwave Player 3D Parsing Memory Corruption

Bugtraq: 40077
CVE: CVE-2010-1283

Adobe Shockwave Player before 11.5.7.609 does not properly parse 3D objects in
.dir (aka Director) files, which allows remote attackers to execute arbitrary
code or cause a denial of service (heap memory corruption) via a modified field
in a 0xFFFFFF49 record.


Adobe Photoshop CS4 ABR File Processing Buffer Overflow

Bugtraq: 40389
CVE: CVE-2010-1296

Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-
assisted remote attackers to execute arbitrary code via a crafted (1) .ASL, (2)
.ABR, or (3) .GRD file.


Mac : Adobe Photoshop CS4 ABR File Processing Buffer Overflow

Bugtraq: 40389
CVE: CVE-2010-1296

Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-
assisted remote attackers to execute arbitrary code via a crafted (1) .ASL, (2)
.ABR, or (3) .GRD file.


Google Chrome Multiple Vulnerabilities

Bugtraq: 40367
CVE: Not available

Multiple vulnerabilities have been reported in Google Chrome earlier than
5.0.375.55. Attackers can exploit these issues to execute arbitrary code in the
context of the browser, cause denial-of-service conditions, carry out cross-
domain scripting attacks, carry out spoofing attacks, and bypass intended
security restrictions; other attacks are also possible.


Linux : Google Chrome Multiple Vulnerabilities

Bugtraq: 40367
CVE: Not available

Multiple vulnerabilities have been reported in Google Chrome earlier than
5.0.375.55. Attackers can exploit these issues to execute arbitrary code in the
context of the browser, cause denial-of-service conditions, carry out cross-
domain scripting attacks, carry out spoofing attacks, and bypass intended
security restrictions; other attacks are also possible.


Mac: Google Chrome Multiple Vulnerabilities

Bugtraq: 40367
CVE: Not available

Multiple vulnerabilities have been reported in Google Chrome earlier than
5.0.375.55. Attackers can exploit these issues to execute arbitrary code in the
context of the browser, cause denial-of-service conditions, carry out cross-
domain scripting attacks, carry out spoofing attacks, and bypass intended
security restrictions; other attacks are also possible.


Adobe Acrobat Version Detection

Bugtraq: Not available

CVE: Not available

The remote windows host contains Adobe Acrobat.


Adobe AIR Version Detection

Bugtraq: Not available

CVE: Not available

The remote windows host contains Adobe AIR.


Adobe Reader Version Detection

Bugtraq: Not available

CVE: Not available

The remote windows host contains Adobe Reader.


Apple Safari Detection

Bugtraq: Not available

CVE: Not available

Detects the version of Apple Safari on the remote Windows host.


ClamAV Detection

Bugtraq: Not available

CVE: Not available

No summary available


Microsoft Exchange Server Detection

Bugtraq: Not available

CVE: Not available

Microsoft Exchange Server is installed on the remote Windows host.


Adobe Flash Player Version Detection

Bugtraq: Not available

CVE: Not available

The remote windows host contains Adobe FLash Player.


GNU tar and cpio version detection

Bugtraq: Not available

CVE: Not available

No summary available


IBM Lotus Notes Detection

Bugtraq: Not available

CVE: Not available

IBM Lotus Notes is installed on the remote Windows host.


iTunes Detection

Bugtraq: Not available

CVE: Not available

There is a media player installed on the remote Windows host.


LinuxShield Detection

Bugtraq: Not available

CVE: Not available

No summary available


Mac: Opera Detection

Bugtraq: Not available

CVE: Not available

Opera, an alternative web browser, is installed on the remote Mac host.


QuickTime Detection

Bugtraq: Not available

CVE: Not available

There is a media player installed on the remote Windows host.


Mac: QuickTime Detection

Bugtraq: Not available

CVE: Not available

There is a media player installed on the remote Mac OS X.


Adobe Shockwave Player Version Detection

Bugtraq: Not available

CVE: Not available

The remote windows host contains Adobe Shockwave Player.


Sun Java Runtime Environment (JRE) Detection

Bugtraq: Not available

CVE: Not available

Java runtime environment is installed on the remote Windows host


Detect VMware Player

Bugtraq: Not available

CVE: Not available

Detects if VMware Player is installed on the remote Windows host.


Detect VMware Workstation

Bugtraq: Not available

CVE: Not available

Detects if VMware Workstation is installed on the remote Windows host.


Xitami Server Detection

Bugtraq: Not available

CVE: Not available

Xitami Server is running on the remote host.

research Detection, New Logic, Vuln Scanner

May Microsoft Tuesday Update

May 12th, 2010
Comments Off

Rules update for today include the following

Microsoft Security Advisory MS10-030:
Microsoft Windows Mail contains a programming error that may allow a remote attacker to execute code on a vulnerable system. Exploitation can occur if the user connects to a malicious POP3 mail server.

Microsoft Security Advisory MS10-030:
A vulnerability in the way that Microsoft Office handles ActiveX controls may allow a remote attacker to execute code on an affected system.

Additionally, detection has been added for

Apple Safari Remote Code Execution Vulnerability:
Apple Safari incorrectly handles parent windows which may allow a remote attacker to execute code on an affected system.

research Detection, MS Tuesday

April Microsoft Tuesday

April 13th, 2010
Comments Off

The following coverage has been deployed and made live.

Microsoft Security Advisory (MS10-019):
The Microsoft CAB Subject Interface Package (SIP) implementation contains a programming error that may allow a remote attacker to bypass the authentication mechanism.

Microsoft Security Advisory (MS10-020):
The Microsoft implementation of the SMB protocol contains programming errors that may allow a remote attacker to execute code on an affected system.

Microsoft Security Advisory (MS10-023):
Microsoft Publisher contains a programming error that may allow a remote attacker to execute code on an affected system.

Microsoft Security Advisory (MS10-024):
The Microsoft SMTP service is prone to a Denial of Service condition that may be triggered by a remote attacker.

Microsoft Security Advisory (MS10-025):
The Microsoft Windows Media Service suffers from a programming error that may allow a remote attacker to execute code on an affected system.

Microsoft Security Advisory (MS10-026):
Microsoft Windows Media Player contains a programming error that may allow a remote attacker to execute code on an affected system.

Microsoft Security Advisory (MS10-027):
Microsoft Windows Media Player contains a programming error that may allow a remote attacker to execute code on an affected system via an ActiveX control.

Microsoft Security Advisory (MS10-028):
Microsoft Visio suffers from programming errors that may allow a remote attacker to execute code on an affected system.

Microsoft Security Advisory (MS10-029):
The Microsoft implementation of IPv6 contains a programming error that may allow a remote attacker to spoof connections to an affected host.

research MS Tuesday, New Logic

IDS Detection Coverage Update

April 8th, 2010
Comments Off

New rules out on the sensors!

Novell QuickFinder server cross-site-scripting attempt:

CVE ID: 2009-0611
BUGTRAQ ID: not available

PDF with click-to-launch executable:

CVE ID: not available
BUGTRAQ ID: not available

FTP ProFTPD username sql injection attempt:

CVE ID: 2009-0542
BUGTRAQ ID: 33722

VanBot IRC communication attempt:

CVE ID: not available
BUGTRAQ ID: not available

Zbot malware config file download request:

CVE ID: not available
BUGTRAQ ID: not available

Trillian AIM XML tag handling heap buffer overflow attempt:

CVE ID: 2008-5403
BUGTRAQ ID: 32645

Novell Groupwise Internet Agent RCPT command overflow attempt:

CVE ID: 2009-0410
BUGTRAQ ID: 33560

ORACLE Database sys.olapimpl_t package odcitablestart overflow attempt:

CVE ID: 2008-3974
BUGTRAQ ID: not available

Free Download Manager .torrent parsing comment overflow attempt:

CVE ID: 2009-0184
BUGTRAQ ID: 33555

Free Download Manager .torrent parsing announce overflow attempt:

CVE ID: 2009-0184
BUGTRAQ ID: 33555

Free Download Manager .torrent parsing name overflow attempt:

CVE ID: 2009-0184
BUGTRAQ ID: 33555

Free Download Manager .torrent parsing path overflow attempt:

CVE ID: 2009-0184
BUGTRAQ ID: 33555

Squid Proxy http version number overflow attempt:

CVE ID: 2008-4562
BUGTRAQ ID: 33668

research Detection, New Logic

MS10-018 Coverage

March 30th, 2010
Comments Off

Support for detecting the new MSIE vulnerability is out and live.

Microsoft Security Advisory (MS10-018):
Microsoft Internet Explorer contains several programming errors that may allow a remote attacker to execute code on an affected system.

research Detection, New Logic

Apple Safari CVE-2010-0049 Detection Added

March 23rd, 2010
Comments Off

Apple Safari contains a programming error that may allow a remote attacker to execute code on an affected system. The issue presents itself when the browser fails to properly process certain HTML elements concerning RTL text (CVE-2010-0049).

research Detection, New Logic

March Microsoft Tuesday

March 9th, 2010
Comments Off

IDS updates for MS Tuesday have gone out.

Microsoft Security Advisory (MS10-016):
Microsoft Windows Movie Maker contains a programming error that may allow a remote attacker to execute code on an affected system.

Microsoft Security Advisory (MS10-017):
Microsoft Excel contains several programming errors that may allow a remote attacker to execute code on an affected system.

research Detection, MS Tuesday, New Logic