Section: .. / 0708-advisories /
| /// File Name: |
sa26470.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for kdegraphics. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/26470/ | | File Size: | 8221 | | Last Modified: | Aug 15 21:37:35 2007 |
| MD5 Checksum: | 0f98337c76a6a6f26a88bb08e09d2075 |
|
| /// File Name: |
sa26468.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for koffice. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/26468/ | | File Size: | 9001 | | Last Modified: | Aug 15 21:37:35 2007 |
| MD5 Checksum: | 7f99106ed0d8980a4369bc7467154bf0 |
|
| /// File Name: |
sa26467.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for tetex. This fixes some vulnerabilities, where some have unknown impact and others can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/26467/ | | File Size: | 4822 | | Last Modified: | Aug 15 21:37:35 2007 |
| MD5 Checksum: | 911ccd46e48840991c4d861bc36a6fc9 |
|
| /// File Name: |
sa26465.txt |
Description:
|
Secunia Security Advisory - NTT OSS CENTER has reported a vulnerability in Apache Tomcat, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/26465/ | | File Size: | 2732 | | Last Modified: | Aug 15 21:37:35 2007 |
| MD5 Checksum: | b9068118dca52ddf8aa08fc0df16912e |
|
| /// File Name: |
sa26464.txt |
Description:
|
Secunia Security Advisory - Joey Mengele has discovered a vulnerability in SurgeMail, which can be exploited by malicious users to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/26464/ | | File Size: | 2389 | | Last Modified: | Aug 15 21:37:35 2007 |
| MD5 Checksum: | 579f8c0e87bfdd809dcddb6923619281 |
|
| /// File Name: |
sa26461.txt |
Description:
|
Secunia Security Advisory - NetJackal has discovered a vulnerability in Easy Chat Server, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/26461/ | | File Size: | 2381 | | Last Modified: | Aug 15 21:37:35 2007 |
| MD5 Checksum: | 51a3243e8883d76b1a03c4f7b12d29e1 |
|
| /// File Name: |
sa26460.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for Mozilla Products. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, conduct spoofing and cross-site scripting attacks, and potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/26460/ | | File Size: | 2694 | | Last Modified: | Aug 15 21:37:35 2007 |
| MD5 Checksum: | bf8cdb22d49842afe5d6b6c31ba3a5bd |
|
| /// File Name: |
sa26457.txt |
Description:
|
Secunia Security Advisory - Wouter Coekaerts has reported a vulnerability in now_playing.rb, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/26457/ | | File Size: | 2436 | | Last Modified: | Aug 15 21:37:35 2007 |
| MD5 Checksum: | 3337c9e02925377bb07ea1c40f868402 |
|
| /// File Name: |
sa26456.txt |
Description:
|
Secunia Security Advisory - Wouter Coekaerts has discovered a vulnerability in Konversation, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/26456/ | | File Size: | 2419 | | Last Modified: | Aug 15 21:37:35 2007 |
| MD5 Checksum: | 50b4af39571e8edf5cf527e803b44074 |
|
| /// File Name: |
sa26455.txt |
Description:
|
Secunia Security Advisory - Wouter Coekaerts has reported a vulnerability in xchat-xmms, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/26455/ | | File Size: | 2415 | | Last Modified: | Aug 15 21:37:35 2007 |
| MD5 Checksum: | 2ac66b75ecebe8b406a2c9dd669add56 |
|
| /// File Name: |
sa26454.txt |
Description:
|
Secunia Security Advisory - Wouter Coekaerts has reported a vulnerability in XMMS-Control, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/26454/ | | File Size: | 2423 | | Last Modified: | Aug 15 21:37:35 2007 |
| MD5 Checksum: | 7bd34ea56378c0c672c6632f80a11080 |
|
| /// File Name: |
sa26453.txt |
Description:
|
Secunia Security Advisory - Luigi Auriemma has discovered some vulnerabilities in Babo Violent, which can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/26453/ | | File Size: | 3004 | | Last Modified: | Aug 15 21:37:35 2007 |
| MD5 Checksum: | 2527c294bc34706e7ac461baa17ca28f |
|
| /// File Name: |
sa26451.txt |
Description:
|
Secunia Security Advisory - Luigi Auriemma has discovered a vulnerability in Zoidcom, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/26451/ | | File Size: | 2502 | | Last Modified: | Aug 15 21:37:35 2007 |
| MD5 Checksum: | 7889bcf1a5511cad4d8d4c3ce92a7565 |
|
| /// File Name: |
sa26448.txt |
Description:
|
Secunia Security Advisory - A weakness has been reported in AMD Catalyst Software Suite, which can be exploited by malicious, local users to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/26448/ | | File Size: | 2647 | | Last Modified: | Aug 15 21:37:35 2007 |
| MD5 Checksum: | 9f34cb61fbc3589434f18ba2363f2c35 |
|
| /// File Name: |
sa26438.txt |
Description:
|
Secunia Security Advisory - SUSE has issued an update for open-iscsi. This fixes some security issues, which can be exploited by malicious, local users to cause a DoS (Denial of Service),
| | Homepage: | http://secunia.com/advisories/26438/ | | File Size: | 2358 | | Last Modified: | Aug 15 21:37:35 2007 |
| MD5 Checksum: | f5920f831f5b4d0baca18491aef02e29 |
|
| /// File Name: |
sa26437.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in IBM AIX, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/26437/ | | File Size: | 2268 | | Last Modified: | Aug 15 21:37:35 2007 |
| MD5 Checksum: | ee1da4bd0b72fb8a16d926b3da228bfc |
|
| /// File Name: |
sa26434.txt |
Description:
|
Secunia Security Advisory - Rizgar has discovered a vulnerability in PHPCentral Poll, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/26434/ | | File Size: | 2359 | | Last Modified: | Aug 15 21:37:35 2007 |
| MD5 Checksum: | 90b35dc04b5e2e2e66811226eec1b8ca |
|
| /// File Name: |
sa26381.txt |
Description:
|
Secunia Security Advisory - Henri Lindberg has reported a vulnerability in ZyXEL ZyWALL / ZyNOS, which can be exploited by malicious people to conduct cross-site request forgery attacks.
| | Homepage: | http://secunia.com/advisories/26381/ | | File Size: | 2663 | | Last Modified: | Aug 15 21:37:35 2007 |
| MD5 Checksum: | c350f8410f05e265753ef457ef64a4e9 |
|
| /// File Name: |
glsa-200708-09.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200708-09 - Mozilla developers fixed several bugs, including an issue with modifying XPCNativeWrappers, a problem with event handlers executing elements outside of the document, and a cross-site scripting (XSS) vulnerability. They also fixed a problem with promiscuous IFRAME access and an XULRunner URL spoofing issue with the wyciwyg:// URI and HTTP 302 redirects. Denials of Service involving corrupted memory were fixed in the browser engine and the JavaScript engine. Finally, another XSS vulnerability caused by a regression in the CVE-2007-3089 patch was fixed. Versions less than 2.0.0.6 are affected.
| | Homepage: | http://security.gentoo.org/ | | File Size: | 5968 | | Related CVE(s): | CVE-2007-3089, CVE-2007-3656, CVE-2007-3734, CVE-2007-3735, CVE-2007-3736, CVE-2007-3737, CVE-2007-3738, CVE-2007-3844 | | Last Modified: | Aug 15 06:39:21 2007 |
| MD5 Checksum: | 644a817d047e617caf2ae4057ff42c67 |
|
| /// File Name: |
08.14.07-2.txt |
Description:
|
iDefense Security Advisory 08.14.07 - Remote exploitation of a buffer overflow vulnerability within Microsoft Corp.'s XML Core Services may allow an attacker to execute arbitrary code in the context of the current user. The vulnerability specifically exists in incorrect checking being performed on the length argument to the substringData() method of an XMLDOM object. When certain length values are supplied, a large region of memory is copied into a buffer of insufficient size. iDefense confirmed the existence of this vulnerability using Internet Explorer 6.x on Windows XP SP2. It is suspected that other versions are also affected.
| | Homepage: | http://www.idefense.com/ | | File Size: | 3933 | | Related CVE(s): | CVE-2007-2223 | | Last Modified: | Aug 15 06:36:51 2007 |
| MD5 Checksum: | 16d231b15a7d57fa94999dca7d16f492 |
|
| /// File Name: |
08.14.07-1.txt |
Description:
|
iDefense Security Advisory 08.14.07 - Remote exploitation of a Cross Site Scripting (XSS) vulnerability in the Windows Vista Sidebar RSS Gadget allows an attacker to execute arbitrary code with the privileges of the logged in user. The vulnerability exists within the parsing of the certain elements of the items in an RSS feed. A properly crafted HTML tag within these elements will not be removed, and will be rendered by the RSS gadget. Since the RSS gadget runs in the local zone, the injected JavaScript has full access to the system. iDefense has confirmed the existence of this vulnerability in Microsoft Windows Vista Business. Other versions are suspected to be vulnerable.
| | Author: | Aviv Raff | | Homepage: | http://www.idefense.com/ | | File Size: | 4897 | | Related CVE(s): | CVE-2007-3033 | | Last Modified: | Aug 15 06:35:18 2007 |
| MD5 Checksum: | 1aa166600fa7109e872458bec4156bc6 |
|
| /// File Name: |
zoidboom2.txt |
Description:
|
Zoidcom versions 0.6.7 and below suffer from a denial of service vulnerability.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related Exploit: | zoidboom2.zip | | File Size: | 1475 | | Last Modified: | Aug 15 06:31:41 2007 |
| MD5 Checksum: | d78b4b2d3d04444addb4af32ce2522a6 |
|
| /// File Name: |
bv2x.txt |
Description:
|
Babo Violent 2 versions 2.08.00 and below suffer from multiple vulnerabilities.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related Exploit: | bv2x.zip | | File Size: | 3967 | | Last Modified: | Aug 15 06:27:20 2007 |
| MD5 Checksum: | cdc86f19a3b8fc437bf33fa864d86c31 |
|
| /// File Name: |
lfsfp.txt |
Description:
|
Live For Speed versions 0.5X10 and below suffer from multiple buffer overflow vulnerabilities.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related Exploit: | lfsfp.zip | | File Size: | 4526 | | Last Modified: | Aug 15 06:23:28 2007 |
| MD5 Checksum: | 230d3bc49f1922554443690d579c2f02 |
|
| /// File Name: |
TPTI-07-14.txt |
Description:
|
Vulnerabilities allow remote attackers to execute arbitrary code on vulnerable installations of multiple Hewlett-Packard (HP) OpenView products, including: Performance Manager, Performance Agent, Reporter, Operations, Operations Manager, Service Quality Manager, Network Node Manager, Business Process Insight, Dashboard and Performance Insight. Authentication is not required to exploit these vulnerabilities. The specific flaws exists within the OpenView Shared Trace Service. A service that is distributed with multiple products as ovtrcsvc.exe and OVTrace.exe. The vulnerable service may be found bound to TCP port 5053 (ovtrcsvc.exe) or TCP port 5051 (OVTrace.exe). Specially crafted data through opcode handlers 0x1a and 0x0f can result in arbitrary code execution under the context of the SYSTEM user.
| | Author: | Cody Pierce, Pedram Amini, Aaron Portnay | | Homepage: | http://dvlabs.tippingpoint.com/ | | File Size: | 3620 | | Related CVE(s): | CVE-2007-1676 | | Last Modified: | Aug 15 06:11:14 2007 |
| MD5 Checksum: | 42bec810b1475c3040bb5b97899fc85d |
|
|
|
|
|