Time from Vendor Informed Date, to Vendor Solution Date

This page presents a list of vulnerabilities with the longest "time to patch". This is calculated by looking at the vendor informed date and the vendor solution date. In short, once the vendor became aware of the vulnerability, how long did it take them to patch? This timeframe can be used to gauge the maturity of a vendor's security patch response time. Vendors with exceptionally long patch times should evaluate their procedures while customers should remind the vendors that security is important.

Key 270+ Days 180-269 Days 0-179 Days

<< Back to Browse

ID Disc Date Time to Patch Title
34395 2007-05-08 2280 days Microsoft Excel Filter Record Handling Remote Code Execution
62740 2010-03-04 2225 days CA SiteMinder WebWorks Help wwhelp/wwhimpl/common/html/frameset.htm Unspecified Parameter XSS
33567 2004-06-17 1423 days XMB U2U Instant Messenger memcp.php recipient Field XSS
66388 2010-07-15 1416 days XMB Admin Password Manipulation CSRF
78670 2011-12-13 1352 days Oracle Java SE / Java for Business java:compiler Malformed .java Handling DoS
81500 2011-08-01 1308 days OpenSSH gss-serv.c ssh_gssapi_parse_ename Function Field Length Value Parsing Remote DoS
68706 2010-10-18 1245 days IBM Informix Dynamic Server portmap.exe librpc.dll Crafted RPC Packet Remote Overflow
32912 2007-01-17 1222 days Oracle Database XMLDB Unspecified XSS
48328 2008-07-28 1221 days Apple iTunes Update Authenticity Verification Weakness
61205 2009-12-17 1173 days HP Storage OpenView Data Protector Cell Manager _rm32.rm_getMem() Function Remote Overflow
61206 2009-12-16 1163 days HP Storage OpenView Data Protector Backup Client Service MSG_PROTOCOL Command Remote Overflow
64437 2010-05-05 1144 days HP Mercury LoadRunner Agent magentproc.exe Remote Arbitrary Code Execution
33130 2007-02-08 1072 days HP Network Node Manager (NNM) Remote Console Directory Permission Weakness Privilege Escalation
71952 2011-04-19 1012 days Oracle Multiple Products Oracle Help help/topics/iastop_cs/iastop_cs_farm_page.html locale Parameter XSS
71953 2011-04-19 1012 days Oracle Multiple Products Application Service Level Management /em/console/target/svclvl/slrule targetType Parameter SQL Injection
12368 2004-12-09 1011 days UseModWiki wiki.pl XSS
68705 2010-10-18 984 days IBM Informix Dynamic Server oninit.exe Logging Function Remote Overflow
40401 2007-08-14 963 days IBM AIX cfgcon swcons -p Argument Symlink Local Privilege Escalation
81267 2012-04-17 914 days Oracle Database Server / Enterprise Manager Database Grid Control /em/console/ecm/config/compareWizard/compareWizFirstConfig fConfigGuid Parameter SQL Injection
72558 2011-02-04 905 days IBM Lotus Domino IMAP/POP3 mail from Command Non-Printable Character Expansion Remote Code Execution
72559 2011-02-04 905 days IBM Lotus Domino NRouter Service Calendar Request Attachment Name Parsing Remote Code Execution
72560 2011-02-04 905 days IBM Lotus Domino iCalendar nrouter.exe Meeting Request Content-Type Header Parsing Remote Code Execution
72561 2011-02-04 905 days IBM Lotus Domino SMTP Service Multiple Filename Arguments Remote Code Execution
66830 2010-08-03 895 days Citrix Multiple Product ICA Connection Graphics Packet Handling Remote Code Execution
70838 2011-02-07 890 days Novell eDirectory for Linux NCP FileSetLock Request Handling Remote DoS
22582 2006-01-17 877 days Oracle Application Server Reports Developer rwservlet customize Variable Arbitrary XML File Portion Disclosure
55806 2009-07-13 876 days Microsoft Office Web Components OWC10.Spreadsheet ActiveX msDataSourceObject() Method Memory Corruption
56914 2009-08-11 866 days Microsoft Office Web Components OWC10 ActiveX Loading/Unloading Memory Allocation Arbitrary Code Execution
27852 2006-08-08 834 days Microsoft IE Uninitialized COM Object Memory Corruption
72714 2011-06-01 827 days Cisco AnyConnect Secure Mobility Client ActiveX IObjectSafety Headend Server Spoofing Remote Code Execution
70599 2011-01-20 814 days Iconfidant SSL Server Key Exchange Client Master Key Packet Overflow
61965 2010-01-19 804 days RealNetworks Multiple Products Invalid ASMRuleBook Structure Overflow
56435 2008-11-18 790 days WebKit WebCore xml/XMLHttpRequest.cpp Set-Cookie HTTP Response Header Restriction Weakness
68707 2010-10-18 783 days IBM Informix Dynamic Server DBINFO Keyword SQL Query Remote Overflow
61966 2010-01-19 770 days RealNetworks Multiple Products Crafted GIF File Chunk Size Overflow
14238 2005-02-25 757 days BadBlue ext.dll mfcisapicommand Parameter Remote Overflow
65507 2010-03-01 753 days EMC Networker portmap.exe librpc.dll Authentication Functionality Multiple Overflows
62783 2010-03-01 753 days IBM Informix Dynamic Server portmap.exe librpc.dll Authentication Functionality Multiple Overflows
68040 2010-09-14 749 days IBM Lotus Domino nnotes.dll MailCheck821Address Function iCalendar Email Address ORGANIZER:mailto Header Remote Overflow
61967 2010-01-21 741 days RealNetworks Multiple Products Crafted Media File HTTP Chunked Transfer Overflow
61972 2010-01-19 739 days RealNetworks Multiple Products CMediumBlockAllocator::Alloc Method Crafted RTSP SET_PARAMETER Handling Overflow
15537 2005-04-18 738 days PayProCart usrauthstamp.php IP Disclosure
61973 2010-01-19 712 days RealNetworks Multiple Products smlrender.dll SMIL File Handling Overflow
56834 2009-08-06 692 days CA Multiple Products Data Transport Services Library (dtscore.dll) Token Searching Routine Remote Overflow
59966 2009-11-10 689 days Cisco Linksys WAP4400N Association Request Unspecified Remote DoS
58865 2009-10-13 665 days Microsoft Multiple Products GDI+ TIFF Image Handling Overflow
57241 2007-10-04 657 days vtiger CRM include/utils/ListViewUtils.php Disabled Field Restriction Weakness
69845 2010-12-10 654 days RealPlayer Multiple Products RealMedia File MDPR Header Array Index Error Arbitrary Code Execution
37923 2007-07-11 653 days SquirrelMail G/PGP (GPG) Plugin gpg_keyring.php deleteKey Function Arbitrary Command Execution
37924 2007-07-11 653 days SquirrelMail G/PGP (GPG) Plugin gpg_key_functions.php gpg_recv_key Function Arbitrary Command Execution
57243 2007-10-09 652 days vtiger CRM Unspecified Attachment / Report / Filter Manipulation
47397 2008-08-12 644 days Microsoft Office WPGIMP32.FLT Filter WordPerfect Graphics (WPG) File Handling Arbitrary Code Execution
61968 2010-01-19 617 days RealNetworks Multiple Products SIPR Codec Field Handling Overflow
61969 2010-01-19 616 days RealNetworks Multiple Products Compressed GIF File Handling Overflow
45367 2008-05-19 615 days CA Multiple Product caloggerd Log Daemon Traversal Arbitrary File Manipulation
58866 2009-10-13 614 days Microsoft Multiple Products GDI+ TIFF Image Handling Memory Corruption Arbitrary Code Execution
60855 2009-12-08 610 days Microsoft Windows Intel Indeo41 Codec IV41 movi Record Handling Overflow
56915 2009-08-11 609 days Microsoft Office Web Components OWC10.Spreadsheet ActiveX BorderAround() Method Heap Corruption Arbitrary Code Execution
77086 2008-09-08 608 days Atlassian Confluence Username XSS
69836 2010-12-10 604 days RealPlayer Multiple Products Audio Stream Multi-rate Data Remote Overflow
53734 2009-04-15 602 days Oracle Database Workspace Manager LT.ROLLBACKWORKSPACE SQL Injection
35505 2007-04-27 597 days VMware Workstation Shared Folders Feature Host System Arbitrary File Write
70058 2010-10-13 589 days Oracle Fusion Middleware BI Publisher Unspecified Response Splitting
60437 2009-11-19 588 days PHP on Windows popen Invalid Mode Handling DoS
63316 2010-03-26 577 days Novell NetWare NWFTPD.nlm Multiple FTP Command Handling Overflow
70056 2010-10-13 574 days Oracle Fusion Middleware BPEL Console BPELCONSOLE/DEFAULT/processLog.jsp processName Parameter XSS
74931 2011-04-20 572 days Fail2ban Multiple Temporary File Symlink Arbitrary File Append
76001 2011-09-30 570 days Adobe Photoshop Elements Brush (ABR) File Handling Overflow
76002 2011-09-30 570 days Adobe Photoshop Elements Gradient (GRD) File Handling Overflow
67982 2010-09-14 567 days Microsoft Outlook E-mail Content Parsing Remote Overflow
54159 2009-04-28 567 days Symantec Multiple Products Intel Alert Originator Service (IAO.EXE) MsgSys.exe Process Overflow
28932 2008-05-09 558 days Tumbleweed Integrated Messaging Exchange (IME) Default Configuration Password Weakness
28933 2008-05-09 558 days Tumbleweed Integrated Messaging Exchange (IME) Cookie Password Weak Encoding
28722 2008-05-09 558 days Tumbleweed Email Firewall (EMF) Administration Module statusView.do Multiple Parameter XSS
28735 2008-05-09 558 days Tumbleweed Email Firewall (EMF) GET Request JSESSIONID Session ID Disclosure
28736 2008-05-09 558 days Tumbleweed Email Firewall (EMF) JSESSIONID Session Fixation
28737 2008-05-09 558 days Tumbleweed Email Firewall (EMF) Session Concurrency
28759 2008-05-09 553 days Tumbleweed Email Firewall (EMF) /emfadmin/logon.do Malformed password Variable Information Disclosure
51342 2009-01-14 550 days Oracle Secure Backup login.php rbtool Parameter Arbitrary Command Execution
58844 2009-10-13 545 days Microsoft Windows Media Player ASF Runtime Voice Sample Rate Handling Arbitrary Code Execution
71614 2011-02-15 544 days Oracle Java SE / Java for Business Deployment Java Runtime WWW-Authenticate Request Remote NTLM Hash Disclosure
58869 2009-10-13 536 days Microsoft Office Malformed Object Handling Memory Corruption Arbitrary Code Execution
69856 2010-12-10 533 days RealPlayer Multiple Products pnen3260.dll Module AAC File TIT2 Atom Overflow
69834 2010-12-10 533 days RealPlayer Multiple Products ICY SHOUTcast Stream StreamTitle Tag Use-after-free Arbitrary Code Execution
69837 2010-12-10 533 days RealPlayer Multiple Products RTSP Stream GIF87a File Screen Descriptor Header Remote Overflow
69838 2010-12-10 533 days RealPlayer Multiple Products Real Audio File Cook Codec Multiple Subbands Overflow
57242 2008-02-06 532 days vtiger CRM Account Billing / Shipping Address Overwrite
62612 2010-03-01 529 days IBM Lotus Domino Web Access ActiveX Unspecified Overflow
63919 2010-04-15 528 days AgentX++ AgentX::receive_agentx() Function Remote Overflow
63920 2010-04-15 528 days AgentX++ AgentX::receive_agentx() Function Integer Overflow
76518 2011-10-18 526 days Oracle Database Vault DV_ACCTMGR CIPasswordChange API Password Manipulation
76519 2011-10-18 526 days Oracle Database Vault SYSDBA CIPasswordChange API Password Manipulation
53741 2009-04-15 525 days Oracle Application Server Oracle Process Manager and Notification (opmn) Daemon POST URI Handling Remote Format String
69806 2010-12-14 523 days Microsoft Office TIFF Image Converter Endian Conversion Buffer Overflow
69807 2010-12-14 523 days Microsoft Office Document Imaging Endian Conversion TIFF Image Handling Memory Corruption
69874 2010-09-30 520 days Novell eDirectory Server Malformed Index Handling Remote DoS
22304 2006-01-10 517 days Solaris uustat -S Parameter Local Overflow
56916 2009-08-11 512 days Microsoft Office Web Components HTMLURL Parameter ActiveX Spreadsheet Object Handling Overflow
29982 2008-05-09 509 days Tumbleweed Integrated Messaging Exchange (IME) TW_TxnAccDeliveryPageEntry.tpl tsi Variable Malformed Input DoS
29983 2008-05-09 509 days Tumbleweed Integrated Messaging Exchange (IME) TW_TxnAccMaillistEditEntryStart.tpl lii Variable Malformed Input DoS

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2012 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use