Time from Vendor Informed Date, to Vendor Solution Date

This page presents a list of vulnerabilities with the longest "time to patch". This is calculated by looking at the vendor informed date and the vendor solution date. In short, once the vendor became aware of the vulnerability, how long did it take them to patch? This timeframe can be used to gauge the maturity of a vendor's security patch response time. Vendors with exceptionally long patch times should evaluate their procedures while customers should remind the vendors that security is important.

Key 270+ Days 180-269 Days 0-179 Days

<< Back to Browse

ID Disc Date Time to Patch Title
90171 2003-09-02 3367 days GNU C Library (glibc) printf() Incomplete Multibyte Sequence Handling Infinite Loop DoS
88592 2005-01-16 2888 days phpGiftReq index.php Multiple Parameter SQL Injection
88591 2005-01-16 2888 days phpGiftReq item.php itemid Parameter SQL Injection
34395 2007-05-08 2280 days Microsoft Excel Filter Record Handling Remote Code Execution
62740 2010-03-04 2225 days CA SiteMinder WebWorks Help wwhelp/wwhimpl/common/html/frameset.htm Unspecified Parameter XSS
91769 2005-05-07 2216 days Newscoop Frontend PHP Tag Injection Remote Code Execution
91635 2005-05-30 1537 days Libxslt libxslt/extensions.c Concurrent XSLT Stylesheet Loading Missing Thread Safety Arbitrary Code Execution
33567 2004-06-17 1423 days XMB U2U Instant Messenger memcp.php recipient Field XSS
66388 2010-07-15 1416 days XMB Admin Password Manipulation CSRF
91766 2003-08-26 1407 days dpkg Tar Archive Extraction Incorrect File Permissions Setting Weakness
78670 2011-12-13 1352 days Oracle Java SE / Java for Business java:compiler Malformed .java Handling DoS
81500 2011-08-01 1308 days OpenSSH gss-serv.c ssh_gssapi_parse_ename Function Field Length Value Parsing Remote DoS
68706 2010-10-18 1245 days IBM Informix Dynamic Server portmap.exe librpc.dll Crafted RPC Packet Remote Overflow
32912 2007-01-17 1222 days Oracle Database XMLDB Unspecified XSS
48328 2008-07-28 1221 days Apple iTunes Update Authenticity Verification Weakness
71515 2010-10-28 1209 days WebKit Nested first-letter Pseudo Element Non-layout Style Change Handling Memory Corruption
86373 2012-10-16 1208 days Oracle Business Intelligence Enterprise Edition /em/console/help/webapp/HELP_10.1.3_NT_060914.0911.178/ohw_jslibs/vt_chrome.js URI XSS
61205 2009-12-17 1173 days HP Storage OpenView Data Protector Cell Manager _rm32.rm_getMem() Function Remote Overflow
89939 2013-02-07 1164 days Rack Rack::Session::Cookie Function Timing Attack Remote Code Execution
61206 2009-12-16 1163 days HP Storage OpenView Data Protector Backup Client Service MSG_PROTOCOL Command Remote Overflow
64437 2010-05-05 1144 days HP Mercury LoadRunner Agent magentproc.exe Remote Arbitrary Code Execution
73563 2008-02-01 1117 days Universal Feed Parser (feedparser) feedparser.py DOCTYPE Declaration DoS
91765 2003-01-28 1111 days dpkg dpkg-source -b Argument Symlink Arbitrary File Overwrite
33130 2007-02-08 1072 days HP Network Node Manager (NNM) Remote Console Directory Permission Weakness Privilege Escalation
70851 2011-02-08 1057 days IBM Lotus Domino SMTP Service Filename Parameter Unspecified Overflow
71952 2011-04-19 1012 days Oracle Multiple Products Oracle Help help/topics/iastop_cs/iastop_cs_farm_page.html locale Parameter XSS
71953 2011-04-19 1012 days Oracle Multiple Products Application Service Level Management /em/console/target/svclvl/slrule targetType Parameter SQL Injection
12368 2004-12-09 1011 days UseModWiki wiki.pl XSS
68705 2010-10-18 984 days IBM Informix Dynamic Server oninit.exe Logging Function Remote Overflow
40401 2007-08-14 963 days IBM AIX cfgcon swcons -p Argument Symlink Local Privilege Escalation
90797 2008-05-27 963 days Cerberus Helpdesk Arbitrary Group Custom Fields Disclosure
92701 2012-06-17 958 days SAP NetWeaver Portal /irj/servlet/prt/portal/prtroot/com.sap.portal.usermanagement.admin.UserMapping systemid Parameter XSS
81267 2012-04-17 914 days Oracle Database Server / Enterprise Manager Database Grid Control /em/console/ecm/config/compareWizard/compareWizFirstConfig fConfigGuid Parameter SQL Injection
85863 2012-09-21 909 days Oracle Database Authentication Protocol Arbitrary User Session Key / Salt Remote Disclosure
72558 2011-02-05 905 days IBM Lotus Domino IMAP/POP3 mail from Command Non-Printable Character Expansion Remote Code Execution
72559 2011-02-05 905 days IBM Lotus Domino NRouter Service Calendar Request Attachment Name Parsing Remote Code Execution
66830 2010-08-03 895 days Citrix Multiple Product ICA Connection Graphics Packet Handling Remote Code Execution
70838 2011-02-07 890 days Novell eDirectory for Linux NCP FileSetLock Request Handling Remote DoS
22582 2006-01-17 877 days Oracle Application Server Reports Developer rwservlet customize Variable Arbitrary XML File Portion Disclosure
55806 2009-07-13 876 days Microsoft Office Web Components OWC10.Spreadsheet ActiveX msDataSourceObject() Method Memory Corruption
88476 2005-02-08 871 days International Components for Unicode for C/C++ (ICU4C) TextCache Infinite Loop DoS
56914 2009-08-11 866 days Microsoft Office Web Components OWC10 ActiveX Loading/Unloading Memory Allocation Arbitrary Code Execution
63300 2009-10-14 849 days gif2png gif2png.c Command Line Argument Overflow
27852 2006-08-08 834 days Microsoft IE Uninitialized COM Object Memory Corruption
72714 2011-06-01 827 days Cisco AnyConnect Secure Mobility Client ActiveX IObjectSafety Headend Server Spoofing Remote Code Execution
70599 2011-01-20 814 days Iconfidant SSL Server Key Exchange Client Master Key Packet Overflow
61965 2010-01-19 804 days RealNetworks Multiple Products Invalid ASMRuleBook Structure Overflow
66083 2009-02-03 795 days LibTIFF td_stripbytecount Field Handling Weakness Crafted TIFF File DoS
56435 2008-11-18 790 days WebKit WebCore xml/XMLHttpRequest.cpp Set-Cookie HTTP Response Header Restriction Weakness
72260 2009-02-09 789 days LibTIFF OJPEG Decoder tif_ojpeg.c Crafted TIFF File Handling Overflow
68707 2010-10-18 783 days IBM Informix Dynamic Server DBINFO Keyword SQL Query Remote Overflow
61966 2010-01-19 770 days RealNetworks Multiple Products Crafted GIF File Chunk Size Overflow
14238 2005-02-25 757 days BadBlue ext.dll mfcisapicommand Parameter Remote Overflow
65507 2010-03-01 753 days EMC Networker portmap.exe librpc.dll Authentication Functionality Multiple Overflows
62783 2010-03-01 753 days IBM Informix Dynamic Server portmap.exe librpc.dll Authentication Functionality Multiple Overflows
68040 2010-09-14 749 days IBM Lotus Domino nnotes.dll MailCheck821Address Function iCalendar Email Address ORGANIZER:mailto Header Remote Overflow
61967 2010-01-21 741 days RealNetworks Multiple Products Crafted Media File HTTP Chunked Transfer Overflow
61972 2010-01-19 739 days RealNetworks Multiple Products CMediumBlockAllocator::Alloc Method Crafted RTSP SET_PARAMETER Handling Overflow
15537 2005-04-18 738 days PayProCart usrauthstamp.php IP Disclosure
61973 2010-01-19 712 days RealNetworks Multiple Products smlrender.dll SMIL File Handling Overflow
90276 2010-05-24 712 days Apache Axis2 axis2.xml Plaintext Password Local Disclosure
89368 2009-07-09 703 days Jenkins Update Center Cleartext Proxy Password Disclosure
56834 2009-08-06 692 days CA Multiple Products Data Transport Services Library (dtscore.dll) Token Searching Routine Remote Overflow
59966 2009-11-10 689 days Cisco Linksys WAP4400N Association Request Unspecified Remote DoS
58865 2009-10-13 665 days Microsoft Multiple Products GDI+ TIFF Image Handling Overflow
57241 2007-10-04 657 days vtiger CRM include/utils/ListViewUtils.php Disabled Field Restriction Weakness
69845 2010-12-10 654 days RealPlayer Multiple Products RealMedia File MDPR Header Array Index Error Arbitrary Code Execution
37923 2007-07-11 653 days SquirrelMail G/PGP (GPG) Plugin gpg_keyring.php deleteKey Function Arbitrary Command Execution
37924 2007-07-11 653 days SquirrelMail G/PGP (GPG) Plugin gpg_key_functions.php gpg_recv_key Function Arbitrary Command Execution
57243 2007-10-09 652 days vtiger CRM Unspecified Attachment / Report / Filter Manipulation
47397 2008-08-12 644 days Microsoft Office WPGIMP32.FLT Filter WordPerfect Graphics (WPG) File Handling Arbitrary Code Execution
61968 2010-01-19 617 days RealNetworks Multiple Products SIPR Codec Field Handling Overflow
61969 2010-01-19 616 days RealNetworks Multiple Products Compressed GIF File Handling Overflow
45367 2008-05-19 615 days CA Multiple Product caloggerd Log Daemon Traversal Arbitrary File Manipulation
58866 2009-10-13 614 days Microsoft Multiple Products GDI+ TIFF Image Handling Memory Corruption Arbitrary Code Execution
60855 2009-12-08 610 days Microsoft Windows Intel Indeo41 Codec IV41 movi Record Handling Overflow
56915 2009-08-11 609 days Microsoft Office Web Components OWC10.Spreadsheet ActiveX BorderAround() Method Heap Corruption Arbitrary Code Execution
77086 2008-09-08 608 days Atlassian Confluence Username XSS
47265 2008-07-31 607 days Blue Coat K9 Web Protection Filter Service (k9filter.exe) Referer Header Handling Buffer Overflow
69836 2010-12-10 604 days RealPlayer Multiple Products Audio Stream Multi-rate Data Remote Overflow
53734 2009-04-15 602 days Oracle Database Workspace Manager LT.ROLLBACKWORKSPACE SQL Injection
47264 2008-07-31 601 days Blue Coat K9 Web Protection Filter Service (k9filter.exe) HTTP Version Response Handling Remote Overflows
35505 2007-04-27 597 days VMware Workstation Shared Folders Feature Host System Arbitrary File Write
70058 2010-10-13 589 days Oracle Fusion Middleware BI Publisher Unspecified Response Splitting
60437 2009-11-19 588 days PHP on Windows popen Invalid Mode Handling DoS
63316 2010-03-26 577 days Novell NetWare NWFTPD.nlm Multiple FTP Command Handling Overflow
70056 2010-10-13 574 days Oracle Fusion Middleware BPEL Console BPELCONSOLE/DEFAULT/processLog.jsp processName Parameter XSS
74931 2011-04-20 572 days Fail2ban Multiple Temporary File Symlink Arbitrary File Append
76001 2011-09-30 570 days Adobe Photoshop Elements Brush (ABR) File Handling Overflow
76002 2011-09-30 570 days Adobe Photoshop Elements Gradient (GRD) File Handling Overflow
67982 2010-09-14 567 days Microsoft Outlook E-mail Content Parsing Remote Overflow
54159 2009-04-28 567 days Symantec Multiple Products Intel Alert Originator Service (IAO.EXE) MsgSys.exe Process Overflow
91131 2013-03-05 566 days Disk Pool Manager Multiple dpm_*() Function SQL Injection
28932 2008-05-09 558 days Tumbleweed Integrated Messaging Exchange (IME) Default Configuration Password Weakness
28933 2008-05-09 558 days Tumbleweed Integrated Messaging Exchange (IME) Cookie Password Weak Encoding
28722 2008-05-09 558 days Tumbleweed Email Firewall (EMF) Administration Module statusView.do Multiple Parameter XSS
28735 2008-05-09 558 days Tumbleweed Email Firewall (EMF) GET Request JSESSIONID Session ID Disclosure
28736 2008-05-09 558 days Tumbleweed Email Firewall (EMF) JSESSIONID Session Fixation
28737 2008-05-09 558 days Tumbleweed Email Firewall (EMF) Session Concurrency
28759 2008-05-09 553 days Tumbleweed Email Firewall (EMF) /emfadmin/logon.do Malformed password Variable Information Disclosure

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2002 - 2013 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use