Section: .. / 0712-advisories /
| /// File Name: |
sa28114.txt |
Description:
|
Secunia Security Advisory - Sun has acknowledged some vulnerabilities in Gimp, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/28114/ | | File Size: | 2686 | | Last Modified: | Dec 18 19:48:19 2007 |
| MD5 Checksum: | bb4d55d001779d689af7d33e6615d6be |
|
| /// File Name: |
sa28119.txt |
Description:
|
Secunia Security Advisory - t0pP8uZz & xprog have reported a vulnerability in PHP Real Estate Classifieds, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/28119/ | | File Size: | 2503 | | Last Modified: | Dec 18 19:48:19 2007 |
| MD5 Checksum: | 429fa0846a8f7eff10d6bfab2b3da09c |
|
| /// File Name: |
sa28120.txt |
Description:
|
Secunia Security Advisory - Luigi Auriemma has reported a vulnerability in PeerCast, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/28120/ | | File Size: | 2412 | | Last Modified: | Dec 18 19:48:19 2007 |
| MD5 Checksum: | 2a718a0361042d336b37b85233ff0a84 |
|
| /// File Name: |
sa28129.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in CUPS, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/28129/ | | File Size: | 2617 | | Last Modified: | Dec 18 19:48:19 2007 |
| MD5 Checksum: | 15f4bbdb168b4d7b3cfaa67272bdeeb1 |
|
| /// File Name: |
sa28132.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Exiv2, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.
| | Homepage: | http://secunia.com/advisories/28132/ | | File Size: | 2565 | | Last Modified: | Dec 18 19:48:19 2007 |
| MD5 Checksum: | b5098268b2f6fa8a10e11b0f238c845c |
|
| /// File Name: |
sa28134.txt |
Description:
|
Secunia Security Advisory - rgod has discovered a vulnerability in iMesh, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/28134/ | | File Size: | 2493 | | Last Modified: | Dec 18 19:48:19 2007 |
| MD5 Checksum: | f97332217a4fe8cc1d967cf9a7fb0fc0 |
|
| /// File Name: |
sa28139.txt |
Description:
|
Secunia Security Advisory - A security issue has been reported in the Alternate pdftops Filter for CUPS, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
| | Homepage: | http://secunia.com/advisories/28139/ | | File Size: | 2513 | | Last Modified: | Dec 18 19:48:19 2007 |
| MD5 Checksum: | 9e5d2c5b6f00b8eb87bb809285fbca64 |
|
| /// File Name: |
sa28142.txt |
Description:
|
Secunia Security Advisory - rgod has discovered a vulnerability in SurgeMail, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/28142/ | | File Size: | 2445 | | Last Modified: | Dec 18 19:48:19 2007 |
| MD5 Checksum: | debfcd75f9f8434f76465be77fb7464c |
|
| /// File Name: |
sa28143.txt |
Description:
|
Secunia Security Advisory - rgod has discovered a vulnerability in RaidenHTTPD, which can be exploited by malicious people to disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/28143/ | | File Size: | 2554 | | Last Modified: | Dec 18 19:48:19 2007 |
| MD5 Checksum: | 2474394839728886d6731fa62aee12b4 |
|
| /// File Name: |
sa28118.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in syslog-ng, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/28118/ | | File Size: | 2785 | | Last Modified: | Dec 18 12:39:14 2007 |
| MD5 Checksum: | 102acc472ceb280210385af1e4c30e6c |
|
| /// File Name: |
sa28138.txt |
Description:
|
Secunia Security Advisory - Peter Österberg has discovered a vulnerability in the Automatic Image Upload with Thumbnails module for PunBB, which can be exploited by malicious users to conduct cross-site scripting attacks and to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/28138/ | | File Size: | 2934 | | Last Modified: | Dec 18 12:39:14 2007 |
| MD5 Checksum: | f7be10279eb1b51ecfcdf9d8e844296a |
|
| /// File Name: |
appian-dos.txt |
Description:
|
The Appian Business Suite version 5.6 SP1 is vulnerable to a remote denial of service attack due to the way it handles packets on port 5400.
| | Author: | Chris Castaldo | | File Size: | 3913 | | Last Modified: | Dec 18 12:17:10 2007 |
| MD5 Checksum: | aaade840266b1013d4e3236dcd6d6ad7 |
|
| /// File Name: |
sa28097.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for autofs. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/28097/ | | File Size: | 3601 | | Last Modified: | Dec 17 21:24:21 2007 |
| MD5 Checksum: | 6726cda417a7e51d1f0bf8918ad88534 |
|
| /// File Name: |
sa28106.txt |
Description:
|
Secunia Security Advisory - Two vulnerabilities have been reported in Flyspray, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/28106/ | | File Size: | 2506 | | Last Modified: | Dec 17 21:24:21 2007 |
| MD5 Checksum: | a85a0b934fbd4de5101725282b9e4585 |
|
| /// File Name: |
ZDI-07-079.txt |
Description:
|
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett-Packard HP-UX operating system. Authentication is not required to exploit this vulnerability. The specific flaw exists within the function sw_rpc_agent_init (opcode 0x04) defined in swagentd. Specific malformed arguments can cause function pointers to be overwritten and thereby result in arbitrary code execution. HP-UX version 11.11 is affected.
| | Author: | Tenable Network Security | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3137 | | Related CVE(s): | CVE-2007-6195 | | Last Modified: | Dec 17 21:24:12 2007 |
| MD5 Checksum: | ad412a33d41e87fe9a61a70ae52818d0 |
|
| /// File Name: |
ZDI-07-078.txt |
Description:
|
A vulnerability allows attackers to execute arbitrary code on vulnerable installations of St. Bernard Open File Manager. Authentication is not required to exploit this vulnerability. The specific flaw resides in the Open File Manager service, ofmnt.exe, which listens by default on a random TCP port near 1000. The process blindly copies user-suppled data to a static heap buffer. By supplying an overly large amount of data, an attacker can overflow that buffer leading to arbitrary code execution in the context of the SYSTEM user. Open File Manager version 9.5 is affected.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3361 | | Related CVE(s): | CVE-2007-6281 | | Last Modified: | Dec 17 21:23:04 2007 |
| MD5 Checksum: | 31da33da8dcfead04f175ae756208305 |
|
| /// File Name: |
ZDI-07-077.txt |
Description:
|
Vulnerabilities allow attackers to execute arbitrary code on vulnerable installations of Trend Micro ServerProtect. Authentication is not required to exploit these vulnerabilities. ServerProtect version 5.58 is affected.
| | Author: | Eric DETOISIEN | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3571 | | Last Modified: | Dec 17 21:21:46 2007 |
| MD5 Checksum: | a2dc2f74641791ae4540449193656821 |
|
| /// File Name: |
uber-upload.txt |
Description:
|
Uber Uploader versions 5.3.6 and below suffer from a remote file upload vulnerability.
| | Author: | JosS | | Homepage: | http://www.spanish-hackers.com/ | | File Size: | 1732 | | Last Modified: | Dec 17 21:18:28 2007 |
| MD5 Checksum: | 23779cbba8bb1a5097810d8a1b0a4136 |
|
| /// File Name: |
ZSA-2007-029.txt |
Description:
|
syslog-ng Open Source Edition versions below 2.0.6 and Premium Edition versions below 2.1.8 suffer from a denial of service vulnerability.
| | Author: | Oriol Carreras | | Homepage: | http://www.balabit.com/network-security/syslog-ng/ | | File Size: | 2947 | | Last Modified: | Dec 17 21:08:34 2007 |
| MD5 Checksum: | f36fe0adc8e9edc5d00ee1a0af237a9c |
|
| /// File Name: |
dsa-1434-1.txt |
Description:
|
Debian Security Advisory 1434-1 - It was discovered that in MyDNS, a domain name server with database backend, the daemon could be crashed through malicious remote update requests, which may lead to denial of service.
| | Homepage: | http://www.debian.org/security | | File Size: | 6375 | | Related CVE(s): | CVE-2007-2362 | | Last Modified: | Dec 17 20:28:06 2007 |
| MD5 Checksum: | 35e4d66d0ee02432694954c25e256514 |
|
| /// File Name: |
dsa-1433-1.txt |
Description:
|
Debian Security Advisory 1433-1 - Several remote vulnerabilities have been discovered in centericq, a text-mode multi-protocol instant messenger client, which could allow remote attackers to execute arbitrary code due to insufficient bounds-testing.
| | Homepage: | http://www.debian.org/security | | File Size: | 18402 | | Related CVE(s): | CVE-2007-3713 | | Last Modified: | Dec 17 20:27:38 2007 |
| MD5 Checksum: | 3fd1f42b2e14e56c457f07ea326a9d91 |
|
| /// File Name: |
dsa-1432-1.txt |
Description:
|
Debian Security Advisory 1432-1 - Alin Rad Pop discovered that link-grammar, Carnegie Mellon University's link grammar parser for English, performed insufficient validation within its tokenizer, which could allow a malicious input file to execute arbitrary code.
| | Homepage: | http://www.debian.org/security | | File Size: | 8879 | | Related CVE(s): | CVE-2007-5395 | | Last Modified: | Dec 17 20:26:26 2007 |
| MD5 Checksum: | 764bcc1dc4dd9095916d5a12c1972e44 |
|
| /// File Name: |
SSRT071502.txt |
Description:
|
HP Security Bulletin - A potential security vulnerability has been identified with the HP Quick Launch Button (QLB) software running on Windows. The vulnerability could be exploited remotely to execute arbitrary code or to gain privileged access.
| | Homepage: | http://www.hp.com/ | | File Size: | 6734 | | Related CVE(s): | CVE-2007-6331, CVE-2007-6332, CVE-2007-6333 | | Last Modified: | Dec 17 20:24:27 2007 |
| MD5 Checksum: | 80ea31203b6b91cb16508db40df1656d |
|
| /// File Name: |
sa28108.txt |
Description:
|
Secunia Security Advisory - Slackware has issued an update for mysql. This fixes a security issue and some vulnerabilities, which can be exploited by malicious, local users to manipulate certain data and by malicious users to bypass certain security restrictions and cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/28108/ | | File Size: | 2810 | | Last Modified: | Dec 17 19:58:34 2007 |
| MD5 Checksum: | 73c7ba2c949eb588067d296e6fdc6bba |
|
|
|
|
|