Section: .. / 0710-advisories /
| /// File Name: |
sa27442.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in NuFW, which can potentially be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/27442/ | | File Size: | 2356 | | Last Modified: | Oct 30 19:58:14 2007 |
| MD5 Checksum: | e76cbd41954daa350de09bdd82b49d24 |
|
| /// File Name: |
sa27444.txt |
Description:
|
Secunia Security Advisory - Jesper Jurcenoks has reported a vulnerability in Saxon (Simple Accessible XHTML Online News), which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/27444/ | | File Size: | 2630 | | Last Modified: | Oct 30 19:58:14 2007 |
| MD5 Checksum: | f1a6fe6a38ebb16ff3e49f0c8158bbb7 |
|
| /// File Name: |
sa27449.txt |
Description:
|
Secunia Security Advisory - Doz has reported a vulnerability in Omnistar Live, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/27449/ | | File Size: | 2292 | | Last Modified: | Oct 30 19:58:14 2007 |
| MD5 Checksum: | 704690b7e2b799f7a194b56c8c2b4352 |
|
| /// File Name: |
sa27453.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for tar. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/27453/ | | File Size: | 2803 | | Last Modified: | Oct 30 19:58:14 2007 |
| MD5 Checksum: | 3fcbb78492ff3c0bc1f851c66c2f2c5c |
|
| /// File Name: |
sa27460.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for python. This fixes a security issue, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27460/ | | File Size: | 4035 | | Last Modified: | Oct 30 19:58:14 2007 |
| MD5 Checksum: | ef937a5a794929c95a2f37e41e4bd560 |
|
| /// File Name: |
secunia-ipswitch.txt |
Description:
|
Secunia Research has discovered a vulnerability in the IMail Client, which potentially can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error within the IMail Client when processing emails containing multipart MIME data. Affected is the IMail Client 9.22 included with IPSwitch IMail Server 2006.22.
| | Homepage: | http://secunia.com/ | | File Size: | 4440 | | Related CVE(s): | CVE-2007-4345 | | Last Modified: | Oct 30 12:20:14 2007 |
| MD5 Checksum: | 2ecb467ba9ae08a8347f31a5fa740574 |
|
| /// File Name: |
airkiosk-xss.txt |
Description:
|
Sutra's Airkiosk is susceptible to a cross site scripting vulnerability due to using an old formlib.pl.
| | Author: | Skien | | File Size: | 947 | | Last Modified: | Oct 30 12:15:41 2007 |
| MD5 Checksum: | b3b219465b6f5be31767749ee631a0a2 |
|
| /// File Name: |
NGS00419.txt |
Description:
|
NGSSoftware Insight Security Research Advisory - It is possible to cause the Java Virtual Machine to overwrite an arbitrary memory location with an arbitrary value (repeatedly and in a stable manner) when parsing a malformed TrueType font. JDK and JRE versions 5.0 Update 9 and below as well as SDK and JRE versions 1.4.2_14 and below are affected.
| | Author: | John Heasman | | Homepage: | http://www.ngssoftware.com/ | | File Size: | 4670 | | Last Modified: | Oct 29 20:39:02 2007 |
| MD5 Checksum: | c0cef6830fd8bb988ca43b15caf178dc |
|
| /// File Name: |
NGS00443.txt |
Description:
|
NGSSoftware Insight Security Research Advisory - JDK and JRE versions 6 Update 1 and below, 5.0 Update 11 and below, and SDK and JRE versions 1.4.2_14 and below contain a vulnerability that allows an untrusted applet to violate the network access restrictions placed on it by the Java sandbox.
| | Author: | John Heasman | | Homepage: | http://www.ngssoftware.com/ | | File Size: | 3849 | | Last Modified: | Oct 29 20:38:03 2007 |
| MD5 Checksum: | 294b79541b86bde15e4205357ff9f957 |
|
| /// File Name: |
vfd-zlib.txt |
Description:
|
It appears that Virtual Floppy Drive is susceptible to an old zlib vulnerability associated with version 1.2.2.
| | Author: | Stefan Kanthak | | File Size: | 808 | | Related CVE(s): | CAN-2005-2096 | | Last Modified: | Oct 29 20:34:39 2007 |
| MD5 Checksum: | c9dab74bdea6472743947bcd8494b6f9 |
|
| /// File Name: |
sa27413.txt |
Description:
|
Secunia Security Advisory - GoLd_M has discovered a vulnerability in Sige, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27413/ | | File Size: | 2546 | | Last Modified: | Oct 29 20:32:58 2007 |
| MD5 Checksum: | ffa3fc1111e4bf2e1acefbc9ddddff9d |
|
| /// File Name: |
sa27013.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered some vulnerabilities in IBM Tivoli Storage Manager Client, which can be exploited by malicious people to conduct script insertion attacks.
| | Homepage: | http://secunia.com/advisories/27013/ | | File Size: | 2796 | | Last Modified: | Oct 29 20:32:43 2007 |
| MD5 Checksum: | 4b8ca3a83ee7b1628bab0b6755e0ec4e |
|
| /// File Name: |
sa27270.txt |
Description:
|
Secunia Security Advisory - Parvez Anwar has discovered a vulnerability in Sony CONNECT Player (SonicStage), which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/27270/ | | File Size: | 2485 | | Last Modified: | Oct 29 20:32:43 2007 |
| MD5 Checksum: | 03fbcf24748e63a180002823a0635914 |
|
| /// File Name: |
sa27417.txt |
Description:
|
Secunia Security Advisory - Luigi Auriemma has reported a vulnerability in World in Conflict, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/27417/ | | File Size: | 2442 | | Last Modified: | Oct 29 20:32:43 2007 |
| MD5 Checksum: | 7046967c3b96b5660ab26fca76bbd3d7 |
|
| /// File Name: |
sa27422.txt |
Description:
|
Secunia Security Advisory - 0x90 has discovered a security issue in Micro Login System, which can be exploited by malicious people to disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/27422/ | | File Size: | 2333 | | Last Modified: | Oct 29 20:32:43 2007 |
| MD5 Checksum: | 93cb0fcb95a5292fb71f6b6abfcfbec4 |
|
| /// File Name: |
sa27425.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for iceweasel. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/27425/ | | File Size: | 9963 | | Last Modified: | Oct 29 20:32:43 2007 |
| MD5 Checksum: | 51965f1294cc761244713f61b0d0fea5 |
|
| /// File Name: |
sa27427.txt |
Description:
|
Secunia Security Advisory - Sun has acknowledged some vulnerabilities in Mozilla 1.7 for Sun Solaris, which potentially can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/27427/ | | File Size: | 2488 | | Last Modified: | Oct 29 20:32:43 2007 |
| MD5 Checksum: | c177d118d764092f2dc035893231aab6 |
|
| /// File Name: |
sa27433.txt |
Description:
|
Secunia Security Advisory - Nortel has acknowledged a vulnerability in Business Communications Manager, which potentially can be exploited by malicious people to poison the DNS cache.
| | Homepage: | http://secunia.com/advisories/27433/ | | File Size: | 2345 | | Last Modified: | Oct 29 20:32:43 2007 |
| MD5 Checksum: | 4a5ad5d0a1acd1e4c48e67819767a0c6 |
|
| /// File Name: |
realplayer-heap.txt |
Description:
|
All versions of RealPlayer 10 and some builds of RealPlayer 10.5 suffer from a heap overflow in the ID3 tag parsing code.
| | Author: | John Heasman | | Homepage: | http://www.ngssoftware.com/ | | File Size: | 2669 | | Last Modified: | Oct 29 16:51:26 2007 |
| MD5 Checksum: | 3f95c0eb6dbfcedfad035ee38be0fe1e |
|
| /// File Name: |
dsa-1388-3.txt |
Description:
|
Debian Security Advisory 1388-3 - The patch used to correct the DHCP server buffer overflow in DSA-1388-1 was incomplete and did not adequately resolve the problem. This update to the previous advisory makes available updated packages based on a newer version of the patch.
| | Homepage: | http://www.debian.org/security | | File Size: | 10015 | | Related CVE(s): | CVE-2007-5365 | | Last Modified: | Oct 29 16:49:26 2007 |
| MD5 Checksum: | 209da10a5803dcf3037c51bb709fbda1 |
|
| /// File Name: |
sa27435.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Django, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/27435/ | | File Size: | 2606 | | Last Modified: | Oct 29 16:44:48 2007 |
| MD5 Checksum: | f731d7e7e8ebc5196cb4a71ea302fb0f |
|
| /// File Name: |
sa27403.txt |
Description:
|
Secunia Security Advisory - rPath has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, conduct phishing attacks, manipulate certain data, and compromise a user's system.
| | Homepage: | http://secunia.com/advisories/27403/ | | File Size: | 2470 | | Last Modified: | Oct 29 16:44:26 2007 |
| MD5 Checksum: | ec1537435e9d3a9bedea65348ff87ad5 |
|
| /// File Name: |
oracle-dbms.txt |
Description:
|
Team SHATTER Security Alert - Oracle Database Server provides the SYS.DBMS_AQADM_SYS package that is used internally by the SYS.DBMS_AQADM package to provide procedures to manage Oracle Streams Advanced Queuing (AQ) configuration and administration information. This package contains the procedure DBLINK_INFO which is vulnerable to buffer overflow attacks. Affected versions include Oracle Database Server versions 9iR1, 9iR2 (9.2.0.7 and previous patchsets) and 10gR1.
| | Author: | Esteban Martinez Fayo | | Homepage: | http://www.appsecinc.com/ | | File Size: | 2614 | | Last Modified: | Oct 29 16:44:02 2007 |
| MD5 Checksum: | 11ee5bddc080a902b7e88e2b8bc4f72a |
|
| /// File Name: |
oracle-mdsys.txt |
Description:
|
Team SHATTER Security Alert - Oracle Database Server provides the MDSYS.SDO_CS package that contains subprograms for working with coordinate systems. This package contains the function TRANSFORM which is vulnerable to buffer overflow attacks. Affected versions include Oracle Database Server versions 8iR3, 9iR1, 9iR2 (9.2.0.6 and previous patchsets) and 10gR1 (10.1.0.4 and previous patchsets).
| | Author: | Esteban Martinez Fayo | | Homepage: | http://www.appsecinc.com/ | | File Size: | 2472 | | Last Modified: | Oct 29 16:42:01 2007 |
| MD5 Checksum: | b120d424ad08773ef44118fa184376a9 |
|
|
|
|
|