<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4266483606648360079</id><updated>2012-01-24T00:08:55.630Z</updated><category term='remote'/><category term='windows'/><category term='dos'/><category term='0day exploits'/><category term='vista'/><category term='local'/><category term='mac'/><title type='text'>[ X - Zero-Day ]</title><subtitle type='html'>The dumping ground for Zero-Day Exploits..
&lt;BR&gt;
The following entries are active zero-day vulnerabilities.
&lt;BR&gt;
Exploits that do not have any published vendor-supplied patch.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://x-zeroday.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://x-zeroday.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>lem0n</name><uri>http://www.blogger.com/profile/05722076653739547167</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>15</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4266483606648360079.post-4623278017470018890</id><published>2007-02-09T19:08:00.000Z</published><updated>2007-03-06T19:15:11.967Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='0day exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='remote'/><category scheme='http://www.blogger.com/atom/ns#' term='windows'/><category scheme='http://www.blogger.com/atom/ns#' term='local'/><title type='text'>Word Unspecified Exploit [4]</title><summary type='text'>Vendor:: MicrosoftApplication:: Word XP                            Word 2000Disclosed:: 09-02-07Description:: This is reported by McAfee as a different vulnerability than all previous Word zero-day vulnerabilities. Microsoft has acknowledged that this vulnerability does cause a denial of service for Word, and claims that exploitability is not possible. However, without any technical details </summary><link rel='replies' type='application/atom+xml' href='http://x-zeroday.blogspot.com/feeds/4623278017470018890/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4266483606648360079&amp;postID=4623278017470018890' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/4623278017470018890'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/4623278017470018890'/><link rel='alternate' type='text/html' href='http://x-zeroday.blogspot.com/2007/02/word-unspecified-exploit-4.html' title='Word Unspecified Exploit [4]'/><author><name>lem0n</name><uri>http://www.blogger.com/profile/05722076653739547167</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4266483606648360079.post-302817200025911591</id><published>2007-01-28T17:18:00.000Z</published><updated>2007-02-01T19:29:21.723Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='0day exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='mac'/><category scheme='http://www.blogger.com/atom/ns#' term='local'/><title type='text'>Apple crashdump Privilege Escalation Vulnerability</title><summary type='text'>Vendor:: AppleApplication:: Mac OS XDisclosed:: 28-01-07Description:: Crashreporterd is the daemon responsible for detecting application crashes. Crashreporterd listens for mach exceptions and when it detects a mach exception launches crashdump to investigate the crash and report it to the user. Crashdump is a helper tool used by the crashreporterd daemon to create crash reports and notify the </summary><link rel='replies' type='application/atom+xml' href='http://x-zeroday.blogspot.com/feeds/302817200025911591/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4266483606648360079&amp;postID=302817200025911591' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/302817200025911591'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/302817200025911591'/><link rel='alternate' type='text/html' href='http://x-zeroday.blogspot.com/2007/01/apple-crashdump-privilege-escalation.html' title='Apple crashdump Privilege Escalation Vulnerability'/><author><name>lem0n</name><uri>http://www.blogger.com/profile/05722076653739547167</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4266483606648360079.post-7167297938554494507</id><published>2007-01-27T22:45:00.000Z</published><updated>2007-02-01T19:30:12.266Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='0day exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='remote'/><category scheme='http://www.blogger.com/atom/ns#' term='windows'/><category scheme='http://www.blogger.com/atom/ns#' term='mac'/><title type='text'>Telestream Flip4Mac WMV Parsing Memory Corruption Vulnerability</title><summary type='text'>Vendor:: AppleApplication:: Mac OS X - WindowsQuickTime™ Player 7.1.3Windows Media ® Components     for Quicktime 2.1.0.33Disclosed:: 27-01-07Description:: Flip4Mac fails to properly handle WMV files with a crafted ASF_File_Properties_Object size                             field, leading to an exploitable memory corruption condition, which can be abused remotely                             for </summary><link rel='replies' type='application/atom+xml' href='http://x-zeroday.blogspot.com/feeds/7167297938554494507/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4266483606648360079&amp;postID=7167297938554494507' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/7167297938554494507'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/7167297938554494507'/><link rel='alternate' type='text/html' href='http://x-zeroday.blogspot.com/2007/01/telestream-flip4mac-wmv-parsing-memory.html' title='Telestream Flip4Mac WMV Parsing Memory Corruption Vulnerability'/><author><name>lem0n</name><uri>http://www.blogger.com/profile/05722076653739547167</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4266483606648360079.post-6425888270235256643</id><published>2007-01-25T19:23:00.000Z</published><updated>2007-02-01T19:32:25.845Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='dos'/><category scheme='http://www.blogger.com/atom/ns#' term='0day exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='remote'/><category scheme='http://www.blogger.com/atom/ns#' term='mac'/><title type='text'>Apple CFNetwork HTTP Response Denial of Service</title><summary type='text'>Vendor:: AppleApplication:: Mac OS XDisclosed:: 25-01-07Description::         CFNetwork fails to handle certain HTTP responses properly, causing the        _CFNetConnectionWillEnqueueRequests() function to dereference a NULL pointer, leading to        a denial of service condition exploitable by a server sending a crafted response to a        client application making use of this API.Exploit::</summary><link rel='replies' type='application/atom+xml' href='http://x-zeroday.blogspot.com/feeds/6425888270235256643/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4266483606648360079&amp;postID=6425888270235256643' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/6425888270235256643'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/6425888270235256643'/><link rel='alternate' type='text/html' href='http://x-zeroday.blogspot.com/2007/01/apple-cfnetwork-http-response-denial-of.html' title='Apple CFNetwork HTTP Response Denial of Service'/><author><name>lem0n</name><uri>http://www.blogger.com/profile/05722076653739547167</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4266483606648360079.post-3713800423527621125</id><published>2007-01-23T19:01:00.000Z</published><updated>2007-02-01T19:33:00.605Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='0day exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='remote'/><category scheme='http://www.blogger.com/atom/ns#' term='mac'/><title type='text'>Apple QuickDraw GetSrcBits32ARGB() Memory Corruption Vulnerability</title><summary type='text'>Vendor:: AppleApplication:: Mac OS XDisclosed:: 23-01-07Description:: QuickDraw is integrated in Mac OS X since very early versions, used by Quicktime and any other application that needs to handle PICT images. A vulnerability exists in the handling of ARGB        records (Alpha RGB) within PICT images, that leads to an exploitable memory corruption condition (ex. denial of service, so-called </summary><link rel='replies' type='application/atom+xml' href='http://x-zeroday.blogspot.com/feeds/3713800423527621125/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4266483606648360079&amp;postID=3713800423527621125' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/3713800423527621125'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/3713800423527621125'/><link rel='alternate' type='text/html' href='http://x-zeroday.blogspot.com/2007/01/apple-quickdraw-getsrcbits32argb-memory.html' title='Apple QuickDraw GetSrcBits32ARGB() Memory Corruption Vulnerability'/><author><name>lem0n</name><uri>http://www.blogger.com/profile/05722076653739547167</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_yEtAUfZ75PI/RbayASqaDFI/AAAAAAAAABM/KA60KnFmHe4/s72-c/quickdraw-bad.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4266483606648360079.post-5117727925687762702</id><published>2007-01-22T23:00:00.000Z</published><updated>2007-02-01T19:33:38.989Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='0day exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='mac'/><category scheme='http://www.blogger.com/atom/ns#' term='local'/><title type='text'>Apple UserNotificationCenter Privilege Escalation Vulnerability</title><summary type='text'>Vendor:: AppleApplication:: Mac OS XDisclosed:: 22-01-07Description:: UserNotificationCenter retains wheel privileges on execution time, and still has a UID associated                    with the current user. Because of this, it&gt; will attempt to run any InputManager provided                   by the user. Code within the input manager will run under wheel privileges. In combination with diskutil</summary><link rel='replies' type='application/atom+xml' href='http://x-zeroday.blogspot.com/feeds/5117727925687762702/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4266483606648360079&amp;postID=5117727925687762702' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/5117727925687762702'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/5117727925687762702'/><link rel='alternate' type='text/html' href='http://x-zeroday.blogspot.com/2007/01/apple-usernotificationcenter-privilege.html' title='Apple UserNotificationCenter Privilege Escalation Vulnerability'/><author><name>lem0n</name><uri>http://www.blogger.com/profile/05722076653739547167</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4266483606648360079.post-1529042552457123213</id><published>2007-01-21T18:40:00.000Z</published><updated>2007-02-01T19:34:08.861Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='0day exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='mac'/><category scheme='http://www.blogger.com/atom/ns#' term='local'/><title type='text'>Apple System Preferences writeconfig Local Privilege Escalation Vulnerability</title><summary type='text'>Vendor:: AppleApplication:: Mac OS XDisclosed:: 21-01-07Description:: The preference panes setuid helper, writeconfig, makes use of a shell script which           lacks of PATH sanitization, allowing users to execute arbitrary binaries under           root privileges.Apple provides the following description in the        The        Preference Application documentation::         System Preferences</summary><link rel='replies' type='application/atom+xml' href='http://x-zeroday.blogspot.com/feeds/1529042552457123213/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4266483606648360079&amp;postID=1529042552457123213' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/1529042552457123213'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/1529042552457123213'/><link rel='alternate' type='text/html' href='http://x-zeroday.blogspot.com/2007/01/apple-system-preferences-writeconfig.html' title='Apple System Preferences writeconfig Local Privilege Escalation Vulnerability'/><author><name>lem0n</name><uri>http://www.blogger.com/profile/05722076653739547167</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4266483606648360079.post-7339770157431465486</id><published>2007-01-17T19:58:00.000Z</published><updated>2007-02-01T19:34:29.774Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='0day exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='remote'/><category scheme='http://www.blogger.com/atom/ns#' term='mac'/><category scheme='http://www.blogger.com/atom/ns#' term='local'/><title type='text'>Apple SLP Daemon Service Registration Buffer Overflow Vulnerability</title><summary type='text'>Vendor:: AppleApplication:: Mac OS XDisclosed:: 17-01-07Description:: slpd is vulnerable to a buffer overflow condition when processing the attr-list        field of a registration request, leading to an exploitable denial of service condition and        potential arbitrary execution. It would allow unprivileged local (and possibly remote) users to        execute arbitrary code under root </summary><link rel='replies' type='application/atom+xml' href='http://x-zeroday.blogspot.com/feeds/7339770157431465486/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4266483606648360079&amp;postID=7339770157431465486' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/7339770157431465486'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/7339770157431465486'/><link rel='alternate' type='text/html' href='http://x-zeroday.blogspot.com/2007/01/apple-slp-daemon-service-registration.html' title='Apple SLP Daemon Service Registration Buffer Overflow Vulnerability'/><author><name>lem0n</name><uri>http://www.blogger.com/profile/05722076653739547167</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4266483606648360079.post-7921404117316268034</id><published>2006-12-15T03:53:00.000Z</published><updated>2007-02-01T19:35:04.318Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='vista'/><category scheme='http://www.blogger.com/atom/ns#' term='0day exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='remote'/><category scheme='http://www.blogger.com/atom/ns#' term='windows'/><title type='text'>NtRaiseHardError</title><summary type='text'>Vendor:: MicrosoftApplication:: WindowsWindows 2000Windows XPWindows 2003Windows VistaDisclosed:: 15-12-06Description::A double-free vulnerability exists in WINSRV.DLL's handling of certain hard error messages that may be locally exploitable for the purpose of privilege escalation to SYSTEM.Calling one of the MessageBox APIs with the MB_SERVICE_NOTIFICATION flag set invokes USER32.DLL!</summary><link rel='replies' type='application/atom+xml' href='http://x-zeroday.blogspot.com/feeds/7921404117316268034/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4266483606648360079&amp;postID=7921404117316268034' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/7921404117316268034'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/7921404117316268034'/><link rel='alternate' type='text/html' href='http://x-zeroday.blogspot.com/2007/01/microsoft-windows-ntraiseharderror.html' title='NtRaiseHardError'/><author><name>lem0n</name><uri>http://www.blogger.com/profile/05722076653739547167</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4266483606648360079.post-4673294258819044666</id><published>2006-11-27T23:51:00.000Z</published><updated>2007-02-01T19:36:46.350Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='0day exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='mac'/><category scheme='http://www.blogger.com/atom/ns#' term='local'/><title type='text'>Mac OS X AppleTalk AIOCREGLOCALZN Ioctl Memory Corruption</title><summary type='text'>Vendor:: MacApplication::  OS X Disclosed:: 27-11-06Description::          Mac OS X AppleTalk protocol handling code is vulnerable to an exploitable memory corruption     issue. This particular vulnerability is caused by failure to validate input data in the     AIOCREGLOCALZN ioctl command, and can be abused by unprivileged users by opening an AppleTalk     socket and issuing the ioctl control </summary><link rel='replies' type='application/atom+xml' href='http://x-zeroday.blogspot.com/feeds/4673294258819044666/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4266483606648360079&amp;postID=4673294258819044666' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/4673294258819044666'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/4673294258819044666'/><link rel='alternate' type='text/html' href='http://x-zeroday.blogspot.com/2006/11/mac-os-x-appletalk-aiocreglocalzn-ioctl.html' title='Mac OS X AppleTalk AIOCREGLOCALZN Ioctl Memory Corruption'/><author><name>lem0n</name><uri>http://www.blogger.com/profile/05722076653739547167</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4266483606648360079.post-7885833073325547347</id><published>2006-11-26T21:40:00.000Z</published><updated>2007-02-01T19:37:01.704Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='0day exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='remote'/><category scheme='http://www.blogger.com/atom/ns#' term='mac'/><title type='text'>Mac OS X Universal Binary Loading Memory Corruption</title><summary type='text'>Vendor:: MacApplication:: OS XDisclosed:: 26-11-06Description::      Mac OS X fails to properly handle corrupted Universal Binaries, leading to an exploitable memory     corruption condition with potential risk of kernel-mode arbitrary code execution.     This particular vulnerability is caused by an integer overflow in the fatfile_getarch2() function.     Local unprivileged users can abuse this </summary><link rel='replies' type='application/atom+xml' href='http://x-zeroday.blogspot.com/feeds/7885833073325547347/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4266483606648360079&amp;postID=7885833073325547347' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/7885833073325547347'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/7885833073325547347'/><link rel='alternate' type='text/html' href='http://x-zeroday.blogspot.com/2007/01/mac-os-x-universal-binary-loading.html' title='Mac OS X Universal Binary Loading Memory Corruption'/><author><name>lem0n</name><uri>http://www.blogger.com/profile/05722076653739547167</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4266483606648360079.post-6416188968380427025</id><published>2006-11-06T17:45:00.000Z</published><updated>2007-02-01T19:37:15.362Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='0day exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='windows'/><category scheme='http://www.blogger.com/atom/ns#' term='local'/><title type='text'>Windows kernel GDI local privilege escalation</title><summary type='text'>Vendor:: MicrosoftApplication:: WindowsDisclosed:: 06-11-06Description::      A vulnerability in the handling of GDI kernel structures of Microsoft Windows leads to an exploitable     memory corruption condition, causing a denial of service (so-called BSoD) or arbitrary code execution     on successful exploitation. This would allow a local user to escalate privileges, gaining full control     of</summary><link rel='replies' type='application/atom+xml' href='http://x-zeroday.blogspot.com/feeds/6416188968380427025/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4266483606648360079&amp;postID=6416188968380427025' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/6416188968380427025'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/6416188968380427025'/><link rel='alternate' type='text/html' href='http://x-zeroday.blogspot.com/2006/11/windows-kernel-gdi-local-privilege.html' title='Windows kernel GDI local privilege escalation'/><author><name>lem0n</name><uri>http://www.blogger.com/profile/05722076653739547167</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4266483606648360079.post-840313673979001263</id><published>2006-10-28T00:16:00.000Z</published><updated>2007-02-01T19:37:28.482Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='dos'/><category scheme='http://www.blogger.com/atom/ns#' term='0day exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='remote'/><category scheme='http://www.blogger.com/atom/ns#' term='windows'/><title type='text'>Internet Connection Sharing DoS</title><summary type='text'>Vendor:: MicrosoftApplication:: WindowsDisclosed:: 28-10-06Description:: Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to cause a denial of service (svchost.exe crash) via a malformed DNS query, which results in a null pointer dereference.Exploit:: Remote Shutdown of Windows Firewall from LANThus </summary><link rel='replies' type='application/atom+xml' href='http://x-zeroday.blogspot.com/feeds/840313673979001263/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4266483606648360079&amp;postID=840313673979001263' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/840313673979001263'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/840313673979001263'/><link rel='alternate' type='text/html' href='http://x-zeroday.blogspot.com/2006/10/internet-connection-sharing-dos.html' title='Internet Connection Sharing DoS'/><author><name>lem0n</name><uri>http://www.blogger.com/profile/05722076653739547167</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4266483606648360079.post-43278530738662019</id><published>2006-10-27T00:07:00.000Z</published><updated>2007-02-01T19:37:42.574Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='dos'/><category scheme='http://www.blogger.com/atom/ns#' term='0day exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='remote'/><category scheme='http://www.blogger.com/atom/ns#' term='windows'/><title type='text'>NAT Helper Components [ipnathlp.dll] Remote DOS</title><summary type='text'>Vendor:: MicrosoftApplication:: Internet ExplorerDisclosed:: 27-10-06Description:: The "Execute" method of ADODB.Connection.2.7 and ADODB.Connection.2.8 objects allow malicious script to free heap memory in a way that circumvents the script interpreter's memory manager. The second argument to Execute, a variant, is passed to VariantClear, which will free the associated string memory using </summary><link rel='replies' type='application/atom+xml' href='http://x-zeroday.blogspot.com/feeds/43278530738662019/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4266483606648360079&amp;postID=43278530738662019' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/43278530738662019'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/43278530738662019'/><link rel='alternate' type='text/html' href='http://x-zeroday.blogspot.com/2006/10/adodbconnection-activex.html' title='NAT Helper Components [ipnathlp.dll] Remote DOS'/><author><name>lem0n</name><uri>http://www.blogger.com/profile/05722076653739547167</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4266483606648360079.post-4899170277590990184</id><published>2005-11-16T23:51:00.000Z</published><updated>2007-02-01T19:38:26.033Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='dos'/><category scheme='http://www.blogger.com/atom/ns#' term='0day exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='remote'/><category scheme='http://www.blogger.com/atom/ns#' term='windows'/><title type='text'>RPC Memory Exhaustion</title><summary type='text'>Vendor:: MicrosoftApplication:: WindowsDisclosed:: 16-11-05Description:: Three referenced exploits take advantage of an inherent problem in RPC, in which an attacker gets to supply the size of an output buffer, and RPC allocates the buffer and (more importantly) initializes it to zeroes, which causes the entire memory range to become committed. For huge output buffers, the target service (which </summary><link rel='replies' type='application/atom+xml' href='http://x-zeroday.blogspot.com/feeds/4899170277590990184/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4266483606648360079&amp;postID=4899170277590990184' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/4899170277590990184'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4266483606648360079/posts/default/4899170277590990184'/><link rel='alternate' type='text/html' href='http://x-zeroday.blogspot.com/2007/01/rpc-memory-exhaustion.html' title='RPC Memory Exhaustion'/><author><name>lem0n</name><uri>http://www.blogger.com/profile/05722076653739547167</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
