Section: .. / 0612-advisories /
| /// File Name: |
sa23468.txt |
Description:
|
Secunia Security Advisory - rPath has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to gain knowledge of certain information, conduct cross-site scripting attacks, and potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/23468/ | | File Size: | 2293 | | Last Modified: | Dec 27 23:54:47 2006 |
| MD5 Checksum: | a3325b69f29e5d5a685e2cdf7f7517cf |
|
| /// File Name: |
sa23467.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for links2. This fixes some vulnerabilities, which can be exploited by malicious people to expose sensitive information and manipulate data.
| | Homepage: | http://secunia.com/advisories/23467/ | | File Size: | 3934 | | Last Modified: | Dec 27 23:54:47 2006 |
| MD5 Checksum: | 51f01b3eec7ed12ed6d3aeb031764b82 |
|
| /// File Name: |
sa23461.txt |
Description:
|
Secunia Security Advisory - putosoft softputo has reported a vulnerability in Oracle Portal, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/23461/ | | File Size: | 2402 | | Last Modified: | Dec 27 23:54:47 2006 |
| MD5 Checksum: | c199bfb8a87c08edf6f91fb15e464614 |
|
| /// File Name: |
sa23456.txt |
Description:
|
Secunia Security Advisory - Mr_KaLiMaN has discovered some vulnerabilities in Xt-News, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/23456/ | | File Size: | 2619 | | Last Modified: | Dec 27 23:54:47 2006 |
| MD5 Checksum: | fa16f49c3bbc43f94b120fcc463597fd |
|
| /// File Name: |
sa23455.txt |
Description:
|
Secunia Security Advisory - Sun has acknowledged a vulnerability in Solaris, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/23455/ | | File Size: | 2378 | | Last Modified: | Dec 27 23:54:47 2006 |
| MD5 Checksum: | 9082d1292065eaf4338093a26a6f2f6f |
|
| /// File Name: |
sa23453.txt |
Description:
|
Secunia Security Advisory - DarkFig has reported a vulnerability in Ixprim Content Management System, which can be exploited by malicious people to manipulate data.
| | Homepage: | http://secunia.com/advisories/23453/ | | File Size: | 2527 | | Last Modified: | Dec 27 23:54:47 2006 |
| MD5 Checksum: | 6cebbd49844b688666c91492342a7e52 |
|
| /// File Name: |
sa23452.txt |
Description:
|
Secunia Security Advisory - Michael Meeks has reported a security issue in GConf, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/23452/ | | File Size: | 2464 | | Last Modified: | Dec 27 23:54:47 2006 |
| MD5 Checksum: | 37e81e1af8b0678f88d467ce036f7964 |
|
| /// File Name: |
sa23450.txt |
Description:
|
Secunia Security Advisory - nuffsaid has discovered a vulnerability in PowerClan, which can be exploited by malicious people to compromise vulnerable systems.
| | Homepage: | http://secunia.com/advisories/23450/ | | File Size: | 2383 | | Last Modified: | Dec 27 23:54:47 2006 |
| MD5 Checksum: | b987f0c6bf003acfefcfe2cff4b8d991 |
|
| /// File Name: |
sa23448.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/23448/ | | File Size: | 3535 | | Last Modified: | Dec 27 23:54:47 2006 |
| MD5 Checksum: | da57cd42a08a464bf9f270d847a85f25 |
|
| /// File Name: |
sa23444.txt |
Description:
|
Secunia Security Advisory - Fukumori has reported a vulnerability in a-blog, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/23444/ | | File Size: | 2349 | | Last Modified: | Dec 27 23:54:47 2006 |
| MD5 Checksum: | 7418816933c87fc1da92bc92a95ebdd9 |
|
| /// File Name: |
sa23437.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in Novell NetMail, which can be exploited by malicious users to cause a DoS (Denial of Service) or compromise a vulnerable system and by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/23437/ | | File Size: | 3763 | | Last Modified: | Dec 27 23:54:47 2006 |
| MD5 Checksum: | f3b0c6212b79a3250208a20eb347f1a1 |
|
| /// File Name: |
NETRAGARD-20061206.txt |
Description:
|
Netragard, L.L.C Advisory - @Mail version 4.51 does not properly sanitize email allowing for cross site scripting attacks.
| | Homepage: | http://www.netragard.com | | File Size: | 6550 | | Last Modified: | Dec 22 04:06:59 2006 |
| MD5 Checksum: | 1e73247370f70b7019041da3b6f68945 |
|
| /// File Name: |
n.runs-SA-2006.005.txt |
Description:
|
NOD32 Antivirus software versions prior 1.1743 suffer from an arbitrary code execution flaw.
| | Author: | Sergio Alvarez | | Homepage: | http://www.nruns.com/ | | File Size: | 3023 | | Last Modified: | Dec 22 01:30:31 2006 |
| MD5 Checksum: | 71f7684a19a0c5a1f9e2a99803f7c984 |
|
| /// File Name: |
dsa-1240-1.txt |
Description:
|
Debian Security Advisory 1240-1 - Teemu Salmela discovered that the links2 character mode web browser performs insufficient sanitizing of smb:// URIs, which might lead to the execution of arbitrary shell commands.
| | Homepage: | http://www.debian.org/security | | File Size: | 3904 | | Related CVE(s): | CVE-2006-5925 | | Last Modified: | Dec 22 01:28:46 2006 |
| MD5 Checksum: | 9c7071225feb82126fb74828c98cbf9f |
|
| /// File Name: |
CAID-34876.txt |
Description:
|
CAID 34876 - CA CleverPath Portal and other CA solutions that embed Portal technology contain a session verification vulnerability.
| | Author: | Ken Williams | | Homepage: | http://www3.ca.com/ | | File Size: | 5236 | | Last Modified: | Dec 22 01:27:02 2006 |
| MD5 Checksum: | c9aa7f4a6d99dd533dcedb00dfb05c4a |
|
| /// File Name: |
TA06-354A.txt |
Description:
|
Technical Cyber Security Alert - Mozilla has released new versions of Firefox, Thunderbird, and SeaMonkey to address several vulnerabilities. Further details about these vulnerabilities are available from Mozilla and the Vulnerability Notes Database. An attacker could exploit these vulnerabilities by convincing a user to view a specially-crafted HTML document, such as a web page or HTML email message.
| | Homepage: | http://www.us-cert.gov/ | | File Size: | 4383 | | Last Modified: | Dec 22 01:26:09 2006 |
| MD5 Checksum: | 70b2ef26d46f564454a1be08addd4eb4 |
|
| /// File Name: |
MDKSA-2006-234.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-234 - XSP (the Mono ASP.NET server) is vulnerable to source disclosure attack which allow a malicious user to obtain the source code of the server-side application. This vulnerability grants the attacker deeper knowledge of the Web application logic.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 3507 | | Related CVE(s): | CVE-2006-6104 | | Last Modified: | Dec 22 01:24:36 2006 |
| MD5 Checksum: | 9ea2a571d0eb176321fb5f26077db788 |
|
| /// File Name: |
USN-397-1.txt |
Description:
|
Ubuntu Security Notice 397-1 - Jose Ramon Palanco discovered that the mono System.Web class did not consistently verify local file paths. As a result, the source code for mono web applications could be retrieved remotely, possibly leading to further compromise via the application's source.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 23737 | | Related CVE(s): | CVE-2006-6104 | | Last Modified: | Dec 22 01:21:29 2006 |
| MD5 Checksum: | a949f0ca6731a6a8592c47a80bedeb44 |
|
| /// File Name: |
SSRT061288.txt |
Description:
|
HP Security Bulletin - Various potential security vulnerabilities have been identified in Microsoft software that is running on the Storage Management Appliance (SMA). Some of these vulnerabilities may be pertinent to the SMA, please check the table in the Resolution section of this Security Bulletin.
| | Homepage: | http://www.hp.com | | File Size: | 10211 | | Last Modified: | Dec 22 01:18:33 2006 |
| MD5 Checksum: | 07d4129b1f7db1894f08d5d669085a85 |
|
| /// File Name: |
glsa-200612-21.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200612-21 - The read_multipart function of the CGI library shipped with Ruby (cgi.rb) does not properly check boundaries in MIME multipart content. This is a different issue than GLSA 200611-12. Versions less than 1.8.5_p2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2663 | | Last Modified: | Dec 22 01:17:33 2006 |
| MD5 Checksum: | a828a0c735f3a68bd9f6b9f43240ea24 |
|
| /// File Name: |
glsa-200612-20.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200612-20 - M. Joonas Pihlaja discovered several buffer overflows in loader_argb.c, loader_png.c, loader_lbm.c, loader_jpeg.c, loader_tiff.c, loader_tga.c, loader_pnm.c and an out-of-bounds memory read access in loader_tga.c. Versions less than 1.3.0 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3166 | | Last Modified: | Dec 22 01:17:08 2006 |
| MD5 Checksum: | b6280592846dc94c99dfa386c24f1058 |
|
| /// File Name: |
glsa-200612-19.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200612-19 - Steve Rigler discovered that pam_ldap does not correctly handle PasswordPolicyResponse control responses from an LDAP directory. This causes the pam_authenticate() function to always succeed, even if the previous authentication failed. Versions less than 183 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2662 | | Last Modified: | Dec 22 01:16:52 2006 |
| MD5 Checksum: | 858a8324fd729cdd34528a6d7186e7b4 |
|
| /// File Name: |
monoxsp.txt |
Description:
|
The Mono XSP ASP.NET server allows for source code disclosure when a %20 is appended to a URI. Version 1.2.1 is affected.
| | Author: | Jose Palanco | | Homepage: | http://www.eazel.es/ | | File Size: | 2028 | | Last Modified: | Dec 22 01:14:54 2006 |
| MD5 Checksum: | a79913fa7c708275ea05c5fffc00667a |
|
| /// File Name: |
n.runs-SA-2006.004.txt |
Description:
|
ESET NOD32 Antivirus suffers from a arbitrary code execution vulnerability. Versions prior to 1.1743 are affected.
| | Author: | Sergio Alvarez | | Homepage: | http://www.nruns.com/ | | File Size: | 3213 | | Last Modified: | Dec 22 01:10:26 2006 |
| MD5 Checksum: | bcf4e953377560b703e9250d30f8f620 |
|
| /// File Name: |
ZDI-06-051.txt |
Description:
|
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Mozilla Firefox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. Affected versions are Mozilla Firefox 2.0.0.0 and Mozilla Firefox 1.5.0.4 through 1.5.0.8.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2659 | | Related CVE(s): | CVE-2006-6504 | | Last Modified: | Dec 22 01:06:04 2006 |
| MD5 Checksum: | 0d8cae7b5d09fc8bc72e3f7ebaddf508 |
|
|
|
|
|