Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

9/22/2010
11:03 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Product Watch: eEye Revives Free Zero-Day Vulnerability Tracker Site

Aims to be a 'one-stop shop' for zero-day vulnerabilities, analysis

eEye Digital Security founder Marc Maiffret's recent return to the company was capped off today with the rerelease of an updated version of the security firm's freebie zero-day vulnerability disclosure and analysis service he once spearheaded.

The new Zero Day Tracker contains the latest zero-day vulnerabilities and analysis on each one -- including some being reported by eEye researchers -- and ways to mitigate and protect against attacks using these bugs. "We're trying to be more of a zero-day historian, if you will. We'll keep track of something we've seen or ZDI [or others] have done," Maiffret says. "This is a completely free public resource."

eEye's previous zero-day tracker page was out at a time when zero-day vulnerabilities weren't the predominant bugs being used in real-world attacks, he says. "We're seeing more commonly that zero-day vulnerabilities are now being used and in more widespread attacks. So we decided it was important to bring [the tracker service] back because it's even more relevant now," Maiffret says. "Organizations can come to the site and see a list of what's out there and how it might affect their business.

"Our goal is to be a one-stop shop page to see the status of all current zero-days," he says. "This is a resource for IT folks to see what the threat landscape looks like ... and making sure we keep pressure on software companies" to fix their vulnerabilities, he says.

eEye will include unpatched bugs on the site, and the bugs it discloses won't include details on how to exploit them until a patch is released, he says.

Maiffret says there's almost always a zero-day bug out there affecting the majority of Web application configurations. "The reality is that it doesn't matter how or when a researcher releases a zero-day," he says. "[It] doesn't dramatically change the threat landscape because there are five other better ones being used in the wild."

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Aviation Faces Increasing Cybersecurity Scrutiny
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/22/2019
Microsoft Tops Phishers' Favorite Brands as Facebook Spikes
Kelly Sheridan, Staff Editor, Dark Reading,  8/22/2019
Capital One Breach: What Security Teams Can Do Now
Dr. Richard Gold, Head of Security Engineering at Digital Shadows,  8/23/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-15540
PUBLISHED: 2019-08-25
filters/filter-cso/filter-stream.c in the CSO filter in libMirage 3.2.2 in CDemu does not validate the part size, triggering a heap-based buffer overflow that can lead to root access by a local Linux user.
CVE-2019-15538
PUBLISHED: 2019-08-25
An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a ...
CVE-2016-6154
PUBLISHED: 2019-08-23
The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).
CVE-2019-5594
PUBLISHED: 2019-08-23
An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8.3.6 and 8.5.0 admin webUI may allow an unauthenticated attacker to perform a reflected XSS attack via the search field in the webUI.
CVE-2019-6695
PUBLISHED: 2019-08-23
Lack of root file system integrity checking in Fortinet FortiManager VM application images of all versions below 6.2.1 may allow an attacker to implant third-party programs by recreating the image through specific methods.