Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

9/22/2010
11:03 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Product Watch: eEye Revives Free Zero-Day Vulnerability Tracker Site

Aims to be a 'one-stop shop' for zero-day vulnerabilities, analysis

eEye Digital Security founder Marc Maiffret's recent return to the company was capped off today with the rerelease of an updated version of the security firm's freebie zero-day vulnerability disclosure and analysis service he once spearheaded.

The new Zero Day Tracker contains the latest zero-day vulnerabilities and analysis on each one -- including some being reported by eEye researchers -- and ways to mitigate and protect against attacks using these bugs. "We're trying to be more of a zero-day historian, if you will. We'll keep track of something we've seen or ZDI [or others] have done," Maiffret says. "This is a completely free public resource."

eEye's previous zero-day tracker page was out at a time when zero-day vulnerabilities weren't the predominant bugs being used in real-world attacks, he says. "We're seeing more commonly that zero-day vulnerabilities are now being used and in more widespread attacks. So we decided it was important to bring [the tracker service] back because it's even more relevant now," Maiffret says. "Organizations can come to the site and see a list of what's out there and how it might affect their business.

"Our goal is to be a one-stop shop page to see the status of all current zero-days," he says. "This is a resource for IT folks to see what the threat landscape looks like ... and making sure we keep pressure on software companies" to fix their vulnerabilities, he says.

eEye will include unpatched bugs on the site, and the bugs it discloses won't include details on how to exploit them until a patch is released, he says.

Maiffret says there's almost always a zero-day bug out there affecting the majority of Web application configurations. "The reality is that it doesn't matter how or when a researcher releases a zero-day," he says. "[It] doesn't dramatically change the threat landscape because there are five other better ones being used in the wild."

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Preventing PTSD and Burnout for Cybersecurity Professionals
Craig Hinkley, CEO, WhiteHat Security,  9/16/2019
US Turning Up the Heat on North Korea's Cyber Threat Operations
Jai Vijayan, Contributing Writer,  9/16/2019
MITRE Releases 2019 List of Top 25 Software Weaknesses
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-16531
PUBLISHED: 2019-09-20
LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.
CVE-2019-9717
PUBLISHED: 2019-09-19
In Libav 12.3, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c has a complex format argument to sscanf.
CVE-2019-9719
PUBLISHED: 2019-09-19
A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c misuses snprintf.
CVE-2019-9720
PUBLISHED: 2019-09-19
A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c misuses snprintf.
CVE-2019-16525
PUBLISHED: 2019-09-19
An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filtered in the checklist-icon.php file, and it is possible to inject JavaScript code.