Section: .. / 0606-advisories /
| /// File Name: |
USN-306-1.txt |
Description:
|
Ubuntu Security Notice 306-1: MySQL did not correctly handle NULL as the second argument to the str_to_date() function. An authenticated user could exploit this to crash the server.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 3753 | | Last Modified: | Jun 29 05:10:18 2006 |
| MD5 Checksum: | f039dfc5bda4a0534f6505e2bd7066ee |
|
| /// File Name: |
USN-307-1.txt |
Description:
|
Ubuntu Security Notice 307-1: TAKAHASHI Tamotsu discovered that mutt's IMAP backend did not sufficiently check the validity of namespace strings. If an user connects to a malicious IMAP server, that server could exploit this to crash mutt or even execute arbitrary code with the privileges of the mutt user.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 4557 | | Last Modified: | Jun 29 05:10:23 2006 |
| MD5 Checksum: | 7ac826fa7ad237b9f2e338301c45d2fd |
|
| /// File Name: |
vCardPRO.txt |
Description:
|
vCard PRO suffers from multiple SQL injection vulnerabilities.
| | Author: | CrAzY.CrAcKeR | | File Size: | 277 | | Last Modified: | Jun 29 05:20:25 2006 |
| MD5 Checksum: | 578bff83cbfc168dd47e24f752b236f0 |
|
| /// File Name: |
VMSA-2006-0001.txt |
Description:
|
VMware Security Advisory VMSA-2006-0001 - VMware ESX server versions prior to 2.5.2 upgrade patch 2, prior to 2.1.2 upgrade patch 6, and prior to 2.0.1 upgrade patch 6 suffer from a cross site scripting issue.
| | Homepage: | http://www.vmware.com/ | | File Size: | 4684 | | Related CVE(s): | CVE-2005-3619 | | Last Modified: | Jun 5 09:58:26 2006 |
| MD5 Checksum: | 61b5e6777e1c19b7a84cf4b7643ab10b |
|
| /// File Name: |
VMSA-2006-0001.txt.asc |
Description:
|
VMware Security Advisory VMSA-2006-0001: VMware ESX Server Cross Site Scripting issue
| | Homepage: | http://www.vmware.com/ | | File Size: | 4684 | | Last Modified: | Jun 3 06:14:30 2006 |
| MD5 Checksum: | 61b5e6777e1c19b7a84cf4b7643ab10b |
|
| /// File Name: |
VMSA-2006-0002.txt.asc |
Description:
|
VMware Security Advisory VMSA-2006-0002 - VMware Server sensitive information lifetime issue.
| | Homepage: | http://www.vmware.com/ | | File Size: | 2024 | | Last Modified: | Jun 3 06:15:10 2006 |
| MD5 Checksum: | b16bf9b795ebc1fbfc4db374f48200ea |
|
| /// File Name: |
VMSA-20060621-01.txt |
Description:
|
An integer overflow vulnerability exists in the Opera Web Browser due to the improper handling of JPEG files. Versions 8.54 and below are affected.
| | Author: | Chris Ries | | Homepage: | http://www.vigilantminds.com/ | | File Size: | 982 | | Last Modified: | Jun 27 07:18:44 2006 |
| MD5 Checksum: | c713f413ef158efe2249dbfbcac9297d |
|
| /// File Name: |
vmwareXSS.txt |
Description:
|
VMware ESX server versions prior to 2.5.2 upgrade patch 2, prior to 2.1.2 upgrade patch 6, and prior to 2.0.1 upgrade patch 6 suffer from a cross site scripting issue.
| | Author: | Stephen de Vries | | File Size: | 4887 | | Related CVE(s): | CVE-2005-3619 | | Last Modified: | Jun 5 09:21:49 2006 |
| MD5 Checksum: | 9299a8b2678099c57c8f9844c027288b |
|
| /// File Name: |
vuln-rnd.txt |
Description:
|
Malicious Flash files with explicit java scripts can be embedded within Excel spreadsheets using a "Shockwave Flash Object" which can be made to run once the file is opened by the user.
| | Author: | Debasis Mohanty | | Homepage: | http://www.hackingspirits.com | | File Size: | 2987 | | Last Modified: | Jun 27 06:32:26 2006 |
| MD5 Checksum: | 21cd8db536d702939f5c714b8569730b |
|
| /// File Name: |
WBB-2.3.4.txt |
Description:
|
WBB version 2.3.4 suffers from a SQL injection vulnerability in misc.php.
| | Author: | CrAzY.CrAcKeR | | Homepage: | http://www.alshmokh.com | | File Size: | 366 | | Last Modified: | Jun 1 02:55:13 2006 |
| MD5 Checksum: | 5162e488e10a5188ca636881ab4d7e11 |
|
| /// File Name: |
WebCalendar-1.0.3.txt |
Description:
|
WebCalendar 1.0.3 suffers from a flaw that lets an attacker read any file if register_globals = On.
| | Author: | socsam | | File Size: | 995 | | Last Modified: | Jun 1 03:01:07 2006 |
| MD5 Checksum: | d315ac5a48afdda0c0564de28cf566c7 |
|
| /// File Name: |
WingedGalleryv1.0.txt |
Description:
|
Winged Gallery v1.0 suffers from cross site scripting
| | Author: | luny | | File Size: | 296 | | Last Modified: | Jun 29 06:14:18 2006 |
| MD5 Checksum: | 6041dca3a4f429b350bed254d26e9ce1 |
|
| /// File Name: |
winscpFun.txt |
Description:
|
The URI handler for WinSCP version 3.8.1 allows for extra command line switches to be passed to SCP.
| | Author: | Jelmer Kuperus | | File Size: | 1624 | | Last Modified: | Jun 12 10:54:22 2006 |
| MD5 Checksum: | 76c7b7690629fa1c3743ba6b931827ec |
|
| /// File Name: |
XtremeDownloadsv.1.0.txt |
Description:
|
Xtreme Downloads v.1.0 suffers from multiple file inclusion vulnerabilities.
| | Author: | black-cod3 | | File Size: | 836 | | Last Modified: | Jun 11 05:18:12 2006 |
| MD5 Checksum: | cbeae17188a9aeec9788422977ef360e |
|
| /// File Name: |
ZDI-06-017.txt |
Description:
|
ZDI-06-017: Microsoft Internet Explorer UTF-8 Decoding Heap Overflow Vulnerability
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2836 | | Last Modified: | Jun 14 06:45:43 2006 |
| MD5 Checksum: | 5169664e4955e1e214ede4cbe4b7aa83 |
|
| /// File Name: |
ZDI-06-018.txt |
Description:
|
ZDI-06-018: Microsoft Internet Explorer DXImageTransform ActiveX Memory Corruption Vulnerability
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3324 | | Last Modified: | Jun 14 06:46:06 2006 |
| MD5 Checksum: | 216a4ab19b6d5ac80b3646f8e2a95f78 |
|
| /// File Name: |
ZDI-06-019.txt |
Description:
|
ZDI-06-019: GraceNote CDDBControl ActiveX Buffer Overflow Vulnerability
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3324 | | Last Modified: | Jun 29 05:22:53 2006 |
| MD5 Checksum: | 049a0ed920fa7d0cf46ca1958a9a8360 |
|
| /// File Name: |
ZDI-06-020.txt |
Description:
|
Apple iTunes suffers from an integer overflow vulnerability when performing AAC file parsing.
| | Author: | ATmaCA | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2586 | | Related CVE(s): | CVE-2006-1467 | | Last Modified: | Jul 2 11:03:54 2006 |
| MD5 Checksum: | 9568b00e86eab1b60b7eea9bb878f07e |
|
| /// File Name: |
zeroboard.txt |
Description:
|
Zeroboard suffers from a file upload an extension bypass vulnerability.
| | Author: | Choi Min-sung | | File Size: | 3674 | | Last Modified: | Jun 26 06:57:10 2006 |
| MD5 Checksum: | 877057ceea0c5ce25e2a083c093ab2c5 |
|
|
|
|
|