code execution
Critical flaw in Cisco Secure Desktop
By secgeeks - Posted on April 9th, 2010
Tagged:
- aapl
- activex control
- adobe pdf reader
- adobe reader
- anti spam law
- antivirus software
- antivirus software
- antivirus software
- antivirus software
- antivirus software
- antivirus software
- antivirus software
- antivirus software
- antivirus software
- antivirus solution
- apache software foundation
- apple fans
- archive file formats
- assumptions
- attacker
- bad guys
- batten down
- batten down the hatches
- china reports
- code execution
- computer security researcher
- continual challenge
- corruption case
- cross compilers
- cyber attacks
- cyber attacks
- cyber attacks
- cyber attacks
- cyber attacks
- cyber attacks
- cyber attacks
- cyber commander
- cyber training
- digital war
- dirty laundry
- ftc staff
- government accountability office
- government accountability office
- government accountability office
- government accountability office
- hack
- hacker
- hacker
- infosec
- initial reviews
- intego
- intuit
- italian judge
- java plugin
- java update
- law enforcement officials
- longtime provider
- mac antivirus
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- mac os x
- macworld
- malicious attacks
- malicious users
- malware
- malware
- malware
- malware
- malware
- malware
- malware
- malware
- malware
- malware
- massive headache
- michelle obama
- mid 80s
- ms patch
- national security agency
- network administrators
- nonplussed
- pc world
- personal finances
- physical security
- pilot fish
- privacy study
- s computer networks
- safari browser
- security researchers
- security researchers
- security researchers
- security researchers
- security researchers
- security researchers
- security researchers
- security researchers
- security researchers
- security researchers
- security researchers
- security researchers
- security researchers
- security researchers
- security researchers
- security researchers
- security risks
- security team
- security team
- security team
- security team
- security team
- security team
- security team
- social networking sites
- social networking sites
- social networking sites
- social networking sites
- social networks
- social networks
- social networks
- social networks
- software bugs
- sun ships
- unsolicited email
- vulnerability
- vulnerability
- vulnerability
- vulnerability
- vulnerability
- vulnerability
- vulnerability
- vulnerability
- vulnerability
- vulnerability
- vulnerability
- windows server 2003 r2
- world researchers
- worm infections
- yearlong study
- young adults
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
137
vote
If an attacker can entice a user to visit an attacker controlled web page, the vulnerable ActiveX control could be invoked to download an attacker-modified package.
Apple patches Pwn2Own flaw used to hack Safari
By secgeeks - Posted on March 31st, 2010
Tagged:
- aapl
- adobe partner
- adobe pdf reader
- anti spam law
- antivirus software
- antivirus software
- antivirus software
- antivirus software
- antivirus software
- antivirus software
- antivirus software
- antivirus software
- antivirus solution
- apache org
- apache software foundation
- bad guys
- batten down
- canadian hacker
- china search engine
- coalmine
- code execution
- command line parameters
- computer operating system
- computer security researcher
- continual challenge
- cross compilers
- cyber attacks
- cyber attacks
- cyber attacks
- cyber attacks
- cyber attacks
- cyber attacks
- cyber commander
- cyber threat
- cyber training
- digital war
- flu cases
- foreign correspondents club
- ftc staff
- hack
- hacker
- hackings
- health care organization
- initial reviews
- ipad
- java flaw
- java plugin
- law enforcement officials
- longtime provider
- mac antivirus
- macworld
- malware
- malware
- malware
- malware
- malware
- malware
- malware
- malware
- malware
- massive headache
- michelle obama
- microsoft employ
- mid 80s
- ms patch
- national science foundation
- national security agency
- network administrators
- network solutions
- new ground
- new york times
- nonplussed
- novel approach
- passwords hackers
- pc users
- pc world
- phisher
- pilot fish
- political opponents
- preventing spam
- privacy in the workplace
- ransomware
- s computer networks
- safari browser
- security weaknesses
- social networking sites
- social networking sites
- social networking sites
- software bugs
- spammer
- swine flu
- target reports
- vulnerability
- vulnerability
- vulnerability
- vulnerability
- vulnerability
- vulnerability
- vulnerability
- vulnerability
- vulnerability
- vulnerability
- windows server 2003 r2
- yahoo email accounts
- youtube
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
- zero day
127
vote
According to Apple's advisory accompanying the patch, the actual vulnerability was not in the Safari browser but in the way ATS (Apple Type Services) handles certain fonts.




Recent comments
6 weeks 4 days ago
49 weeks 2 days ago
50 weeks 3 days ago
1 year 3 days ago
1 year 3 days ago
1 year 3 days ago
1 year 3 days ago
1 year 6 weeks ago
1 year 14 weeks ago
1 year 16 weeks ago