Section: .. / 0802-advisories /
| /// File Name: |
sa29110.txt |
Description:
|
Secunia Security Advisory - Iron has discovered a vulnerability in DBHcms, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/29110/ | | File Size: | 2355 | | Last Modified: | Feb 26 14:03:01 2008 |
| MD5 Checksum: | 927800c5168d37024e35dba559f399ef |
|
| /// File Name: |
sa29072.txt |
Description:
|
Secunia Security Advisory - Nir Goldshlager (Avnet) has reported a vulnerability in IBM Lotus Quickr/QuickPlace, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/29072/ | | File Size: | 2353 | | Last Modified: | Feb 25 20:15:00 2008 |
| MD5 Checksum: | 485d05e26658abec346b89ce60f62f52 |
|
| /// File Name: |
sa29071.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for turba2. This fixes a security issue, which can be exploited by malicious users to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/29071/ | | File Size: | 2980 | | Last Modified: | Feb 25 20:14:50 2008 |
| MD5 Checksum: | 6db49aebe9fd294346b9d61fac8df671 |
|
| /// File Name: |
sa29076.txt |
Description:
|
Secunia Security Advisory - RoMaNcYxHaCkEr has reported two vulnerabilities in phpQLAdmin, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/29076/ | | File Size: | 2483 | | Last Modified: | Feb 25 20:14:50 2008 |
| MD5 Checksum: | 7632fac32504ce5b9d01d576efbad7e0 |
|
| /// File Name: |
sa29086.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for iceape. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/29086/ | | File Size: | 15942 | | Last Modified: | Feb 25 20:14:50 2008 |
| MD5 Checksum: | 8621e415b558a697a15f38d98629a02f |
|
| /// File Name: |
sa29090.txt |
Description:
|
Secunia Security Advisory - S@BUN has discovered a vulnerability in the Gary's Cookbook component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/29090/ | | File Size: | 2391 | | Last Modified: | Feb 25 20:14:50 2008 |
| MD5 Checksum: | 3488e22484e68151f4e8aa904ffc3949 |
|
| /// File Name: |
sa29092.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in TikiWiki, which can be exploited by malicious users to conduct script insertion attacks.
| | Homepage: | http://secunia.com/advisories/29092/ | | File Size: | 2419 | | Last Modified: | Feb 25 20:14:50 2008 |
| MD5 Checksum: | e471827e0e2b0ec102232eb0aa0c33aa |
|
| /// File Name: |
sa29093.txt |
Description:
|
Secunia Security Advisory - Ivan Sanchez and Maximiliano Soler have reported a vulnerability in Matt's Whois, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/29093/ | | File Size: | 2200 | | Last Modified: | Feb 25 20:14:50 2008 |
| MD5 Checksum: | af85f293da4de7ea27c0921aeff5686d |
|
| /// File Name: |
sa29094.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in GraphicsMagick, which can be exploited by malicious people to conduct DoS (Denial of Service) attacks or compromise a user's system.
| | Homepage: | http://secunia.com/advisories/29094/ | | File Size: | 2252 | | Last Modified: | Feb 25 20:14:50 2008 |
| MD5 Checksum: | 93a60a45ac8ee22a155860bdbf6711b7 |
|
| /// File Name: |
sa29097.txt |
Description:
|
Secunia Security Advisory - A security issue has been reported in Net Activity Viewer, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/29097/ | | File Size: | 2440 | | Last Modified: | Feb 25 20:14:50 2008 |
| MD5 Checksum: | ac3ea7433d193510e7845a4e81d43c0a |
|
| /// File Name: |
sa29100.txt |
Description:
|
Secunia Security Advisory - Sun has acknowledged a vulnerability in Solaris, which can be exploited by malicious people to bypass certain security restrictions and cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/29100/ | | File Size: | 3286 | | Last Modified: | Feb 25 20:14:50 2008 |
| MD5 Checksum: | f125a0ee7eccb76e472fd7b29d20ccef |
|
| /// File Name: |
sa28938.txt |
Description:
|
Secunia Security Advisory - .mario has reported a vulnerability in Snom 320 SIP Phone, which can be exploited by malicious people to conduct cross-site request forgery attacks.
| | Homepage: | http://secunia.com/advisories/28938/ | | File Size: | 2439 | | Last Modified: | Feb 25 20:14:33 2008 |
| MD5 Checksum: | 7aec0fb7e573cb0532f2d2996d09b831 |
|
| /// File Name: |
sa29058.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for kernel-2.4.27 and kernel-2.6.8. This fixes some weaknesses, security issues, and vulnerabilities, where one has an unknown impact, and others can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, bypass certain security restrictions, and gain escalated privileges, and by malicious people to cause a DoS.
| | Homepage: | http://secunia.com/advisories/29058/ | | File Size: | 71106 | | Last Modified: | Feb 25 17:35:43 2008 |
| MD5 Checksum: | 319171c1089a678df625d829902ff167 |
|
| /// File Name: |
sa29083.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for nss_ldap. This fixes a security issue, which can be exploited by malicious people to manipulate certain data.
| | Homepage: | http://secunia.com/advisories/29083/ | | File Size: | 2396 | | Last Modified: | Feb 25 17:35:43 2008 |
| MD5 Checksum: | be0bc044d4d699bb215c80d0b109f0f5 |
|
| /// File Name: |
surgemailz.txt |
Description:
|
SurgeMail Mail Server version 38k4 and below and beta 39a along with Netwin's Webmail versions 3.1s and below are all susceptible to format string and buffer overflow vulnerabilities.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related Exploit: | surgemailz.zip | | File Size: | 3180 | | Last Modified: | Feb 25 16:14:57 2008 |
| MD5 Checksum: | 9ea0da1e064b31e03535439af47761af |
|
| /// File Name: |
sa29036.txt |
Description:
|
Secunia Security Advisory - Adrian Pastor has reported some vulnerabilities in ZyXEL products, which can be exploited by malicious users to gain escalated privileges and by malicious people to bypass certain security restrictions or to hijack user sessions.
| | Homepage: | http://secunia.com/advisories/29036/ | | File Size: | 4620 | | Last Modified: | Feb 25 16:11:25 2008 |
| MD5 Checksum: | 3fa534278c1e6d914031d276090da39d |
|
| /// File Name: |
sa29087.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for cups. This fixes two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/29087/ | | File Size: | 2671 | | Last Modified: | Feb 25 16:11:14 2008 |
| MD5 Checksum: | d4bd25d38b5f8d5fe66e92b4d2c69617 |
|
| /// File Name: |
sa29106.txt |
Description:
|
Secunia Security Advisory - Hendrik-Jan Verheij has discovered a vulnerability in Joomla!, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/29106/ | | File Size: | 2537 | | Last Modified: | Feb 25 16:11:14 2008 |
| MD5 Checksum: | fd78ab9c37d3e50339ecb79b61deb088 |
|
| /// File Name: |
sa29107.txt |
Description:
|
Secunia Security Advisory - Two vulnerabilities have been discovered in the XM-Memberstats module for Xoops, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/29107/ | | File Size: | 2504 | | Last Modified: | Feb 25 16:11:14 2008 |
| MD5 Checksum: | 039004258a60fd4dcca72dff93779e63 |
|
| /// File Name: |
dsa-1508-1.txt |
Description:
|
Debian Security Advisory 1508-1 - Dan Dennison discovered that Diatheke, a CGI program to make a bible website, performs insufficient sanitising of a parameter, allowing a remote attacker to execute arbitrary shell commands as the web server user.
| | Homepage: | http://www.debian.org/security | | File Size: | 15005 | | Related CVE(s): | CVE-2008-0932 | | Last Modified: | Feb 25 16:11:08 2008 |
| MD5 Checksum: | a691db077309b48439b497dcbe48b208 |
|
| /// File Name: |
MDVSA-2008-049.txt |
Description:
|
Mandriva Linux Security Advisory - A race condition in nss_ldap, when used in applications that use pthread and fork after a call to nss_ldap, does not properly handle the LDAP connection, which might cause nss_ldap to return the wrong user data to the wrong process, giving one user access to data belonging to another user, in some cases.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 2894 | | Related CVE(s): | CVE-2007-5794 | | Last Modified: | Feb 25 15:59:03 2008 |
| MD5 Checksum: | 800b8ecf21f91b665521f7a262d05567 |
|
| /// File Name: |
s21sec-040-en.txt |
Description:
|
S21Sec Advisory - BEA Weblogic versions 7.0sp6, 8.1sp4, and 9.0sp2 suffer from a flaw where it is possible to launch a credential brute force attack against known users through an internal servlet that permits the bypass of the user locking mechanism.
| | Author: | Ramon Pinuaga Cascales | | Homepage: | http://www.s21sec.com/ | | File Size: | 1899 | | Last Modified: | Feb 25 15:58:30 2008 |
| MD5 Checksum: | 6b2ed5236648b861932af9ca7a34a770 |
|
| /// File Name: |
ciscoval-bypass.txt |
Description:
|
Cisco has confirmed that their 7921 Wi-Fi VoIP phone is vulnerable to a bypass vulnerability where digital certificates are not verified.
| | Author: | George Ou | | Related File: | vocera-flaw.txt | | File Size: | 1381 | | Last Modified: | Feb 25 13:20:21 2008 |
| MD5 Checksum: | e703237a6234a63dc3a23f32e0382281 |
|
| /// File Name: |
glsa-200802-10.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200802-10 - Python 2.3 includes a copy of PCRE which is vulnerable to an integer overflow vulnerability, leading to a buffer overflow. Versions less than 2.3.6-r4 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2678 | | Related CVE(s): | CVE-2006-7228 | | Last Modified: | Feb 25 11:14:47 2008 |
| MD5 Checksum: | ba26bac01970e11b6688fa1541f28ef2 |
|
| /// File Name: |
dsa-1507-1.txt |
Description:
|
Debian Security Advisory 1507-1 - Peter Paul Elfferich discovered that turba2, a contact management component for horde framework did not correctly check access rights before allowing users to edit addresses. This could result in valid users being able to alter private address records.
| | Homepage: | http://www.debian.org/security | | File Size: | 3888 | | Related CVE(s): | CVE-2008-0807 | | Last Modified: | Feb 25 11:14:27 2008 |
| MD5 Checksum: | bc1d1a94e06e85238bcdab46df7d4bbe |
|
|
|
|
|