eEye: Active 0-day Vulnerabilities - 6

by Donna Buenaventura Moderator - 2/14/07 5:55 AM

There are 6 left. It was 11 0-day vulnerabilities few days ago. New in the list is the product by Sun.

Updated list:

The following entries are active zero-day vulnerabilities. They have been publicly disclosed and/or used in attacks, and do not have any published vendor-supplied patch.

1. Sun Solaris Telnet Bypass
Vendor: Sun
Application: Solaris 10, Solaris 11
Severity: High
Date Disclosed: 2/12/2007
Days of Exposure: 2

2. Word Unspecified Exploit(4)
Vendor: Microsoft
Application: Word 2000
Severity: Medium
Date Disclosed: 2/9/2007
Days of Exposure: 5

3. Windows MessageBox / NtRaiseHardError
Vendor: Microsoft
Application: Windows 2000, Windows XP, Windows 2003, Windows Vista
Severity: Medium
Date Disclosed: 12/15/2006
Days of Exposure: 61

4. Internet Connection Sharing DoS
Vendor: Microsoft
Application: Windows XP
Severity: Medium
Date Disclosed: 10/28/2006
Days of Exposure: 109

5. Microsoft Office 2003 PPT Local DoS
Vendor: Microsoft
Application: PowerPoint 2003
Severity: Medium
Date Disclosed: 10/12/2006
Days of Exposure: 125

6. RPC Memory Exhaustion
Vendor: Microsoft
Application: Windows 2000 SP4 (anonymous), Other Operating Systems are being researched.
Severity: Low
Date Disclosed: 11/16/2005
Days of Exposure: 455

For zero-day vulnerabilities have been patched by the vendor, see http://research.eeye.com/html/alerts/zeroday/index.html