Section: .. / 0703-advisories /
| /// File Name: |
dsa-1267-1.txt |
Description:
|
Debian Security Advisory 1267-1 - It was discovered that WebCalendar, a PHP-based calendar application, insufficiently protects an internal variable, which allows remote file inclusion.
| | Homepage: | http://www.debian.org/security | | File Size: | 2913 | | Related CVE(s): | CVE-2007-1343 | | Last Modified: | Mar 20 06:12:20 2007 |
| MD5 Checksum: | bb55eb5cfc33fa297c1418b6d5dd3764 |
|
| /// File Name: |
libftp-bo.txt |
Description:
|
LIBFTP version 5.0 suffers from multiple local buffer overflow vulnerabilities.
| | Author: | starcadi | | File Size: | 1770 | | Last Modified: | Mar 20 06:01:31 2007 |
| MD5 Checksum: | 39f29f28b73702c1b5f3bb03da6528db |
|
| /// File Name: |
qftp.txt |
Description:
|
QFTP (LIBFtp 3.1-1) suffers from a local buffer overflow vulnerability.
| | Author: | starcadi | | File Size: | 633 | | Last Modified: | Mar 20 05:59:06 2007 |
| MD5 Checksum: | 81266b9e91932a7f5a52e8bd1d940f21 |
|
| /// File Name: |
cisco-xss.txt |
Description:
|
Fourteen different Cisco applications suffer from a cross site scripting vulnerability in their help system.
| | Author: | cassio | | File Size: | 1663 | | Last Modified: | Mar 20 05:57:55 2007 |
| MD5 Checksum: | ea8b77a5e05660af0a11a01b1ccaf78f |
|
| /// File Name: |
03.15.07-1.txt |
Description:
|
iDefense Security Advisory 03.15.07 - Local exploitation of an input processing vulnerability within Horde Project's Horde and IMP allows attackers to delete arbitrary files. This vulnerability specifically exists due to the improper handling of the output from an execution of find(1). The output from find(1) is passed directly to a "for X in Y; do" as the Y value. Since the Y value is delimited by spaces, the for loop will process files containing spaces in their path as separate files. An attacker can create a file path containing spaces to manipulate the output from find(1).
| | Homepage: | http://www.idefense.com/ | | File Size: | 3824 | | Last Modified: | Mar 20 05:56:48 2007 |
| MD5 Checksum: | 37895c99333e5f22c5409a1ca8d7816f |
|
| /// File Name: |
ibm-xss.txt |
Description:
|
IBM's Rational ClearQuest Web application version 7.0.0.0 suffers from a cross site scripting flaw.
| | Author: | James Clarke | | Homepage: | http://www.clarkee.co.uk/ | | File Size: | 2301 | | Last Modified: | Mar 20 05:55:52 2007 |
| MD5 Checksum: | 3936fd7a6c1a097be907fd94e5050e5c |
|
| /// File Name: |
Norton-symtdi.txt |
Description:
|
Norton insufficiently protects its driver \Device\SymEvent against a manipulation by malicious applications and it fails to validate its input buffer.
| | Homepage: | http://www.matousec.com/ | | Related Exploit: | BTP00012P002NF.zip | | File Size: | 1260 | | Last Modified: | Mar 20 05:52:15 2007 |
| MD5 Checksum: | d9c914d2896555ba0270ede4ad91d5f3 |
|
| /// File Name: |
glsa-200703-13.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200703-13 - The SSH Secure Shell Server contains a format string vulnerability in the SFTP code that handles file transfers (scp2 and sftp2). In some situations, this code passes the accessed filename to the system log. During this operation, an unspecified error could allow uncontrolled stack access. Versions less than 4.3.7 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3187 | | Related CVE(s): | CVE-2006-0705 | | Last Modified: | Mar 20 05:12:32 2007 |
| MD5 Checksum: | b56d2c9a45892d02d35e413b38c81ef8 |
|
| /// File Name: |
ie7-phish.txt |
Description:
|
Internet Explorer 7.0 is vulnerable to cross-site scripting in one of its local resources. In combination with a design flaw in this specific local resource it is possible for an attacker to easily conduct phishing attacks against IE7 users.
| | Author: | avivra | | Homepage: | http://aviv.raffon.net/ | | File Size: | 2162 | | Last Modified: | Mar 20 04:31:59 2007 |
| MD5 Checksum: | 3b996a2ffb89a7c0d6ec5ff9b53a31ae |
|
| /// File Name: |
03.14.07-1.txt |
Description:
|
iDefense Security Advisory 03.14.07 - Remote exploitation of a divide by zero error in Trend Micro AntiVirus may allow attackers to cause a denial of service. The vulnerability exists in the kernel driver, VsapiNT.sys. This driver is responsible for scanning various file formats for malicious content. The code that parses UPX files takes an integer value from an attacker supplied file and uses it as a divisor. This results in a divide by zero error in kernel mode. This causes a kernel fault resulting in a blue screen of death (BSOD). iDefense has confirmed the existence of this vulnerability in Trend Micro AntiVirus version 14.10.1041, engine version 8.320.1003. Previous versions may also be affected.
| | Homepage: | http://www.idefense.com/ | | File Size: | 3527 | | Last Modified: | Mar 20 04:28:42 2007 |
| MD5 Checksum: | a8a4894d3b7deab3e2f1b8c739d2db42 |
|
| /// File Name: |
minigzip.txt |
Description:
|
Python version 2.5 (Modules/zlib) minigzip suffers from a local buffer overflow vulnerability.
| | Author: | starcadi | | File Size: | 692 | | Last Modified: | Mar 20 04:27:50 2007 |
| MD5 Checksum: | 966ec760b9fb7249d4fae827165b099f |
|
| /// File Name: |
glsa-200703-12.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200703-12 - Frank Benkstein discovered a possible NULL pointer dereference in apps/silcd/command.c if a new channel is created without specifying a valid hmac or cipher algorithm name. Versions less than 1.0.2-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2342 | | Last Modified: | Mar 20 04:04:59 2007 |
| MD5 Checksum: | 792905849b53a216bce49214e7b25bd1 |
|
| /// File Name: |
n.runs-SA-2007.006.txt |
Description:
|
PHProjekt version 5.2.0 suffers from a privilege escalation vulnerability.
| | Author: | Alexios Fakos | | Homepage: | http://www.nruns.com/ | | File Size: | 3392 | | Last Modified: | Mar 20 04:04:46 2007 |
| MD5 Checksum: | 66dd131430a93cb420337e9ab18cbb4c |
|
| /// File Name: |
n.runs-SA-2007.005.txt |
Description:
|
PHProjekt version 5.2.0 suffers from a cross site request forgery vulnerability.
| | Author: | Alexios Fakos | | Homepage: | http://www.nruns.com/ | | File Size: | 3784 | | Last Modified: | Mar 20 04:03:59 2007 |
| MD5 Checksum: | 6279521fc77b42d5bd00fcb54de756c9 |
|
| /// File Name: |
n.runs-SA-2007.004.txt |
Description:
|
PHProjekt version 5.2.0 suffers from cross site scripting and filter evasion vulnerabilities.
| | Author: | Alexios Fakos | | Homepage: | http://www.nruns.com/ | | File Size: | 3786 | | Last Modified: | Mar 20 04:03:07 2007 |
| MD5 Checksum: | 18ee3380c9805f3b32320c501dee4051 |
|
| /// File Name: |
n.runs-SA-2007.003.txt |
Description:
|
PHProjekt version 5.2.0 suffers from a SQL injection vulnerability.
| | Author: | Alexios Fakos | | Homepage: | http://www.nruns.com/ | | File Size: | 3742 | | Last Modified: | Mar 20 04:02:16 2007 |
| MD5 Checksum: | 1b6f4d8350d2713a6ef18e077f149916 |
|
| /// File Name: |
fortinet-mcafee.txt |
Description:
|
Multiple remote buffer overflow vulnerabilities exist in the ActiveX Control named "SiteManager.Dll" of McAfee ePolicy Orchestrator. A remote attacker who successfully exploit these vulnerabilities can completely take control of the affected system. Affected software versions include McAfee ePolicy Orchestrator 3.6.1 and McAfee ePolicy Orchestrator 3.5 patch 6.
| | Author: | cocoruder | | Homepage: | http://www.fortinet.com/ | | File Size: | 6206 | | Last Modified: | Mar 20 03:59:23 2007 |
| MD5 Checksum: | 796dbbbee6e2d7dd23564ff29854fb73 |
|
| /// File Name: |
TA07-072A.txt |
Description:
|
Technical Cyber Security Alert TA07-072A - Apple has released Security Update 2007-003 to correct multiple vulnerabilities affecting Apple Mac OS X and Mac OS X Server. The most serious of these vulnerabilities may allow a remote attacker to execute arbitrary code. Attackers may take advantage of the less serious vulnerabilities to bypass security restrictions or cause a denial of service.
| | Homepage: | http://www.us-cert.gov/ | | File Size: | 4644 | | Last Modified: | Mar 20 03:57:08 2007 |
| MD5 Checksum: | 5818caa857489bc6d013b81030b14eeb |
|
| /// File Name: |
sa24595.txt |
Description:
|
Secunia Security Advisory - ajann has reported a vulnerability in ScriptMagix Jokes, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/24595/ | | File Size: | 2195 | | Last Modified: | Mar 20 03:46:32 2007 |
| MD5 Checksum: | 20065859602797d1d79d7b7af2b16cfb |
|
| /// File Name: |
sa24594.txt |
Description:
|
Secunia Security Advisory - ajann has reported a vulnerability in ScriptMagix Recipes, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/24594/ | | File Size: | 2201 | | Last Modified: | Mar 20 03:46:32 2007 |
| MD5 Checksum: | 49bc3010c68e37b1caaa223d6e3dbfee |
|
| /// File Name: |
sa24593.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for openoffice.org. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/24593/ | | File Size: | 11735 | | Last Modified: | Mar 20 03:46:32 2007 |
| MD5 Checksum: | 690ca4c6912bb4d1db72141a7f6e7119 |
|
| /// File Name: |
sa24590.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for lookup-el. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
| | Homepage: | http://secunia.com/advisories/24590/ | | File Size: | 2769 | | Last Modified: | Mar 20 03:46:32 2007 |
| MD5 Checksum: | 3ca5a54e05d79b62db8556423a6ec527 |
|
| /// File Name: |
sa24586.txt |
Description:
|
Secunia Security Advisory - dmcox dmcox has reported a vulnerability in ZZIPlib Library, which potentially can be exploited by malicious people to gain escalated privileges or compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/24586/ | | File Size: | 2382 | | Last Modified: | Mar 20 03:46:32 2007 |
| MD5 Checksum: | 6673793beb5c5b62d9ed0286aa47aef3 |
|
| /// File Name: |
sa24585.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in LedgerSMB, which potentially can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/24585/ | | File Size: | 2157 | | Last Modified: | Mar 20 03:46:32 2007 |
| MD5 Checksum: | dc59e38d43b53b00a6368a4734957fc8 |
|
| /// File Name: |
sa24583.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for tcpdump. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/24583/ | | File Size: | 4556 | | Last Modified: | Mar 20 03:46:32 2007 |
| MD5 Checksum: | 3c4d56712467451125efc6b6bb07e20a |
|
|
|
|
|