Section: .. / 0702-advisories /
| /// File Name: |
NGS00403.txt |
Description:
|
BrightStor ARCserve Backup for Laptops and Desktops r11.1 suffers from a remote c ode execution vulnerability. By sending a specially crafted packet to the LGSERVER.EXE process that listens on TCP port 1900, it is possible to cause a stack overflow that allows arbitrary code execution as Local System.
| | Author: | Mark Litchfield | | Homepage: | http://www.ngssoftware.com/ | | File Size: | 2532 | | Last Modified: | Jan 31 23:43:31 2007 |
| MD5 Checksum: | bb9d6d34d81c344270cf41343b5ab20a |
|
| /// File Name: |
NGS00404.txt |
Description:
|
BrightStor ARCserve Backup for Laptops and Desktops r11.1 suffers from a remote code execution vulnerability. By sending a specially crafted packet to the LGSERVER.EXE process that listens on TCP port 2200, it is possible to execute arbitrary code as SYSTEM on a Windows Platform.
| | Author: | Mark Litchfield | | Homepage: | http://www.ngssoftware.com/ | | File Size: | 2389 | | Last Modified: | Jan 31 23:42:37 2007 |
| MD5 Checksum: | b7f57a2008ba7f24d464595979b82415 |
|
| /// File Name: |
NGS00471.txt |
Description:
|
Versions of Jetty, the popular java web server, are vulnerable to a session id prediction attack. Jetty uses java.util.Random to generate session ids. The internal state of this generator can be easily discovered, leading to an attacker being able to hijack existing and future sessions. Jetty versions below 4.2.27, 5.1.12, 6.0.2 and 6.1.0pre3 are affected.
| | Author: | Chris Anley | | Homepage: | http://www.ngssoftware.com/ | | File Size: | 4889 | | Last Modified: | Feb 6 00:40:04 2007 |
| MD5 Checksum: | 4bdbaba8ee24eb86cc078feb1cda8988 |
|
| /// File Name: |
OpenPKG-SA-2007.009.txt |
Description:
|
OpenPKG Security Advisory - According to a vendor security advisory, a vulnerability exists in the SessionPlugin extension of the Wiki engine TWiki, version up to and including 4.1.0. The vulnerability allows local users to cause TWiki to execute arbitrary Perl code with the privileges of the web server process by creating CGI session files on the local filesystem.
| | Homepage: | http://www.openpkg.com/security/ | | File Size: | 2739 | | Related CVE(s): | CVE-2007-0669 | | Last Modified: | Feb 13 02:52:56 2007 |
| MD5 Checksum: | bd35fb2c1d0a51753c89312576a4f3c5 |
|
| /// File Name: |
pharming.txt |
Description:
|
A concept of drive-by pharming has been introduced where DNS for home routers can be easily redirected on home networks for targeted attacks. Obvious, but amusingly powerful.
| | Author: | Oliver Friedrichs, Zulfikar Ramzan | | File Size: | 1607 | | Last Modified: | Feb 16 02:57:41 2007 |
| MD5 Checksum: | 9f34ea6420700e851af5151123ddd889 |
|
| /// File Name: |
phish-bypass.txt |
Description:
|
Firefox 2.0.0.1 and Opera 9.10 are susceptible to a bypass vulnerability in their respective Fraud/Phishing protection mechanisms.
| | Author: | Kanedaaa | | Homepage: | http://kaneda.bohater.net/ | | File Size: | 3640 | | Last Modified: | Feb 7 23:46:34 2007 |
| MD5 Checksum: | 7357694f9eed45bd07c50bd2b0589726 |
|
| /// File Name: |
pwg141-xss.txt |
Description:
|
PHPWebGallery version 1.4.1 suffers from multiple cross site scripting flaws.
| | Author: | Simon Bonnard | | File Size: | 509 | | Last Modified: | Feb 27 19:46:27 2007 |
| MD5 Checksum: | a55343f4a4fdbf73b3fb8c0d1d3e425f |
|
| /// File Name: |
qwik-format.txt |
Description:
|
qwik-smtpd suffers from a format string vulnerability.
| | Author: | H0tTurk- | | File Size: | 1168 | | Last Modified: | Feb 22 21:53:23 2007 |
| MD5 Checksum: | 3a1b56e6ea8a4bcf5582517a6d35de6c |
|
| /// File Name: |
readirchange.txt |
Description:
|
ReadDirectoryChangesW() in Microsoft Windows 2000/XP/2003/Vista does not check a user's permissions for child objects, making it possible to retrieve information about objects that a user has no LIST permissions for.
| | Author: | 3APA3A | | Homepage: | http://securityvulns.com/ | | Related Exploit: | spydir.c | | File Size: | 3321 | | Related CVE(s): | CVE-2007-0843 | | Last Modified: | Feb 23 21:45:58 2007 |
| MD5 Checksum: | 6c04fac47932131d4237f8749f08f6fa |
|
| /// File Name: |
sa22452.txt |
Description:
|
Secunia Security Advisory - Yag Kohha has reported a vulnerability in Microsoft Data Access Components, which potentially can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/22452/ | | File Size: | 4291 | | Last Modified: | Feb 14 14:41:53 2007 |
| MD5 Checksum: | 15953ac5e941bc47b3d27b32eed1ed24 |
|
| /// File Name: |
sa23014.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered a vulnerability in Internet Explorer 7, which can be exploited by a malicious website to spoof the address bar.
| | Homepage: | http://secunia.com/advisories/23014/ | | File Size: | 2834 | | Last Modified: | Feb 23 17:44:59 2007 |
| MD5 Checksum: | 8456339862c7d8ef6b3d1ec86424691b |
|
| /// File Name: |
sa23217.txt |
Description:
|
Secunia Security Advisory - Joren McReynolds has reported some vulnerabilities in DevTrack, which can be exploited by malicious users to conduct script insertion attacks and by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/23217/ | | File Size: | 2954 | | Last Modified: | Feb 12 19:06:32 2007 |
| MD5 Checksum: | 0293457982904ff2cd26e66b7b3e5877 |
|
| /// File Name: |
sa23988.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for mozilla-firefox. This fixes some vulnerabilities, which can be exploited by malicious people to gain knowledge of certain information, conduct cross-site scripting attacks, and potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/23988/ | | File Size: | 9487 | | Last Modified: | Feb 4 23:30:20 2007 |
| MD5 Checksum: | a2979b7d97622020cba83a97a124f49a |
|
| /// File Name: |
sa23994.txt |
Description:
|
Secunia Security Advisory - Parvez Anwar has discovered a vulnerability in GOM Player, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/23994/ | | File Size: | 2363 | | Last Modified: | Feb 4 23:30:20 2007 |
| MD5 Checksum: | ea09de4238bf2c12d958883f216e7914 |
|
| /// File Name: |
sa23995.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in IBM AIX, which potentially can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/23995/ | | File Size: | 2316 | | Last Modified: | Feb 4 23:30:20 2007 |
| MD5 Checksum: | 1cdd54317cdffb71d97017e62813e927 |
|
| /// File Name: |
sa23996.txt |
Description:
|
Secunia Security Advisory - Sun has acknowledged a security issue in Sun Solaris, which can be exploited by malicious, local users to bypass certain security restrictions, manipulate data, and cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/23996/ | | File Size: | 2624 | | Last Modified: | Feb 4 23:30:20 2007 |
| MD5 Checksum: | 610ad97fdb8d4e1fb74b758f49103f2a |
|
| /// File Name: |
sa23998.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered some vulnerabilities in MailEnable Web Mail Client, which can be exploited by malicious people to conduct cross-site request forgery attacks, cross-site scripting attacks, and script insertion attacks.
| | Homepage: | http://secunia.com/advisories/23998/ | | File Size: | 3696 | | Last Modified: | Feb 14 14:41:53 2007 |
| MD5 Checksum: | 73bbef42af1a2ec4a736c33ac7a030b5 |
|
| /// File Name: |
sa23999.txt |
Description:
|
Secunia Security Advisory - Parvez Anwar has discovered a vulnerability in Total Video Player, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/23999/ | | File Size: | 2419 | | Last Modified: | Feb 14 14:41:53 2007 |
| MD5 Checksum: | 1b4cf1c59246e5252238f65243a01544 |
|
| /// File Name: |
sa24000.txt |
Description:
|
Secunia Security Advisory - Cyber-Security has reported some vulnerabilities in phpEventMan, which can be exploited by malicious people to compromise vulnerable systems.
| | Homepage: | http://secunia.com/advisories/24000/ | | File Size: | 2513 | | Last Modified: | Feb 4 23:30:20 2007 |
| MD5 Checksum: | 882ea95614cde6386aaac3c114626438 |
|
| /// File Name: |
sa24001.txt |
Description:
|
Secunia Security Advisory - xoron has discovered a vulnerability in Phpbb Tweaked, which can be exploited by malicious people to compromise vulnerable systems.
| | Homepage: | http://secunia.com/advisories/24001/ | | File Size: | 2440 | | Last Modified: | Feb 4 23:30:20 2007 |
| MD5 Checksum: | 3f97d7bd336e42844e09b32d5c743f3e |
|
| /// File Name: |
sa24002.txt |
Description:
|
Secunia Security Advisory - xoron has discovered a vulnerability in Hailboards, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/24002/ | | File Size: | 2463 | | Last Modified: | Feb 4 23:30:20 2007 |
| MD5 Checksum: | 4b6b18b5e9178057b5f850b4f0374ec7 |
|
| /// File Name: |
sa24003.txt |
Description:
|
Secunia Security Advisory - GolD_M has reported some vulnerabilities in Epistemon, which can be exploited by malicious people to compromise vulnerable systems.
| | Homepage: | http://secunia.com/advisories/24003/ | | File Size: | 2475 | | Last Modified: | Feb 4 23:30:20 2007 |
| MD5 Checksum: | 9e3d7506366287d2a6bdfe586790ddc5 |
|
| /// File Name: |
sa24004.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for squirrelmail. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and script insertion attacks.
| | Homepage: | http://secunia.com/advisories/24004/ | | File Size: | 2534 | | Last Modified: | Feb 4 23:30:20 2007 |
| MD5 Checksum: | 0642f049c4d3247f9b7692bef9ce4e7b |
|
| /// File Name: |
sa24005.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for elinks. This fixes a vulnerability, which can be exploited by malicious people to expose sensitive information and manipulate data.
| | Homepage: | http://secunia.com/advisories/24005/ | | File Size: | 2238 | | Last Modified: | Feb 4 23:30:20 2007 |
| MD5 Checksum: | 0167f714d2c6b2440bcdd5a8acfc1ade |
|
|
|
|
|