Section: .. / 0712-advisories /
| /// File Name: |
ZDI-07-074.txt |
Description:
|
A vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The flaw exists due to improper use of the "cloneNode" and "nodeValue" javascript functions. When a specially crafted element is used during a repetitive call to one of these functions memory corruption can occur leading to remote code execution. Affected versions are 6 and 7.
| | Author: | Sam Thomas | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3060 | | Related CVE(s): | CVE-2007-3903 | | Last Modified: | Dec 11 23:38:59 2007 |
| MD5 Checksum: | 9d7271a44009b158cbf029b35d907e4d |
|
| /// File Name: |
firefox20011-dos.txt |
Description:
|
Firefox 2.0.0.11 appears to suffer from an INPUT denial of service flaw.
| | Author: | Azizov Emin | | File Size: | 3054 | | Last Modified: | Dec 6 01:10:53 2007 |
| MD5 Checksum: | dd76142b0e61be6770af6c6996a4cd2d |
|
| /// File Name: |
sa28038.txt |
Description:
|
Secunia Security Advisory - Sowhat has reported a vulnerability in some Trend Micro products, which potentially can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/28038/ | | File Size: | 3048 | | Last Modified: | Dec 13 13:34:25 2007 |
| MD5 Checksum: | d956dc983a351999fe3efc0bdb05092b |
|
| /// File Name: |
sa27894.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27894/ | | File Size: | 3035 | | Last Modified: | Dec 12 14:13:13 2007 |
| MD5 Checksum: | d69f5340bce4f8f4835c9127d9ff16c4 |
|
| /// File Name: |
sa28197.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/28197/ | | File Size: | 3025 | | Last Modified: | Dec 24 13:50:38 2007 |
| MD5 Checksum: | f0e94f7d93806f36234c20bb5c702ff6 |
|
| /// File Name: |
sa28207.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/28207/ | | File Size: | 3025 | | Last Modified: | Dec 24 18:08:43 2007 |
| MD5 Checksum: | c1e8a4123018191b4fc643cbdeae690f |
|
| /// File Name: |
sa28049.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in Cybozu products, which can be exploited by malicious people to conduct cross-site scripting and HTTP header injection attacks.
| | Homepage: | http://secunia.com/advisories/28049/ | | File Size: | 3022 | | Last Modified: | Dec 11 21:35:59 2007 |
| MD5 Checksum: | e0834130ed081bc8259c5b023b6c1b67 |
|
| /// File Name: |
sa27925.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in Jetty, which can be exploited by malicious people to conduct HTTP response splitting and cross-site scripting attacks and potentially hijack a user session.
| | Homepage: | http://secunia.com/advisories/27925/ | | File Size: | 3019 | | Last Modified: | Dec 5 22:48:33 2007 |
| MD5 Checksum: | 5bb2d995600532381994fb373eab05bc |
|
| /// File Name: |
ZDI-07-070.txt |
Description:
|
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Skype. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. Versions below 3.6 Gold are affected.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3015 | | Related CVE(s): | CVE-2007-5989 | | Last Modified: | Dec 7 19:52:36 2007 |
| MD5 Checksum: | 79876e3be8515d55bca5083fc99177ad |
|
| /// File Name: |
glsa-200712-04.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200712-04 - Multiple integer overflows were reported, one of which Peter Valchev (Google Security) found to be leading to a heap-based buffer overflow in the cairo_image_surface_create_from_png() function that processes PNG images. Versions less than 1.4.12 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3006 | | Related CVE(s): | CVE-2007-5503 | | Last Modified: | Dec 10 17:40:45 2007 |
| MD5 Checksum: | c8181a83e53f8c137b7101bdae456400 |
|
| /// File Name: |
sa28149.txt |
Description:
|
Secunia Security Advisory - A security issue has been reported in Asterisk, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/28149/ | | File Size: | 2996 | | Last Modified: | Dec 19 19:28:49 2007 |
| MD5 Checksum: | 065c0bfba43b9d6a2dd0a2ef19ea80f3 |
|
| /// File Name: |
glsa-200712-06.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200712-06 - Adriano Lima and Ramon de Carvalho Valle reported that functions isc_attach_database() and isc_create_database() do not perform proper boundary checking when processing their input. Versions less than 2.0.3.12981.0-r2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2984 | | Related CVE(s): | CVE-2007-4992, CVE-2007-5246 | | Last Modified: | Dec 10 17:41:10 2007 |
| MD5 Checksum: | ad7dce3e42bd491bc9ff96405e6919f9 |
|
| /// File Name: |
sa28044.txt |
Description:
|
Secunia Security Advisory - Multiple vulnerabilities have been reported in IBM AIX, which have unknown impacts.
| | Homepage: | http://secunia.com/advisories/28044/ | | File Size: | 2983 | | Last Modified: | Dec 12 14:13:13 2007 |
| MD5 Checksum: | 3f341c5952ce1998e43b9e848d5519e5 |
|
| /// File Name: |
glsa-200712-09.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200712-09 - Chris Rohlf discovered that the Gtk::MessageDialog.new() method in the file gtk/src/rbgtkmessagedialog.c does not properly sanitize the message parameter before passing it to the gtk_message_dialog_new() function. Versions less than 0.16.0-r2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2981 | | Related CVE(s): | CVE-2007-6183 | | Last Modified: | Dec 10 17:43:18 2007 |
| MD5 Checksum: | 814b4fabe1fa41db564d277ab4ffe2d1 |
|
| /// File Name: |
sa27760.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered a vulnerability in Samba, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27760/ | | File Size: | 2981 | | Last Modified: | Dec 10 16:32:21 2007 |
| MD5 Checksum: | fc5f90418d3831ec6d0d2f2cf6796cbb |
|
| /// File Name: |
sa28007.txt |
Description:
|
Secunia Security Advisory - Luigi Auriemma has reported some vulnerabilities in Easy File Sharing Web Server, which can be exploited by malicious people to disclose sensitive information and by malicious users to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/28007/ | | File Size: | 2976 | | Last Modified: | Dec 10 19:57:22 2007 |
| MD5 Checksum: | 0546d64b8517348810c3cfeb58dc54ad |
|
| /// File Name: |
sa27993.txt |
Description:
|
Secunia Security Advisory - Slackware has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27993/ | | File Size: | 2972 | | Last Modified: | Dec 12 14:13:13 2007 |
| MD5 Checksum: | 587b8c6b9eb082b42037be30eda21bd1 |
|
| /// File Name: |
glsa-200712-24.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200712-24 - The Cairo versions used by the AMD64 x86 emulation GTK+ libraries were vulnerable to integer overflow vulnerabilities (GLSA 200712-04). Versions less than 20071214 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2954 | | Last Modified: | Dec 31 16:41:32 2007 |
| MD5 Checksum: | 9952142e0dc83abd85329c25fefb11b4 |
|
| /// File Name: |
ZSA-2007-029.txt |
Description:
|
syslog-ng Open Source Edition versions below 2.0.6 and Premium Edition versions below 2.1.8 suffer from a denial of service vulnerability.
| | Author: | Oriol Carreras | | Homepage: | http://www.balabit.com/network-security/syslog-ng/ | | File Size: | 2947 | | Last Modified: | Dec 17 21:08:34 2007 |
| MD5 Checksum: | f36fe0adc8e9edc5d00ee1a0af237a9c |
|
| /// File Name: |
sa28065.txt |
Description:
|
Secunia Security Advisory - A weakness has been reported in Meridian Prolog Manager, which can be exploited by malicious people to brute force user passwords.
| | Homepage: | http://secunia.com/advisories/28065/ | | File Size: | 2947 | | Last Modified: | Dec 18 19:48:19 2007 |
| MD5 Checksum: | bda2bfe6e8a4ffb7332a50f23f121210 |
|
| /// File Name: |
msoffice-signature.txt |
Description:
|
Microsoft Office 2007's digital signature protection does not protect meta-data.
| | Author: | Henrich C. Poehls, Dong Tran, Finn Petersen, Frederic Pscheid | | File Size: | 2944 | | Last Modified: | Dec 12 17:33:42 2007 |
| MD5 Checksum: | 4344e3549407ac807bc6531c29a6bf52 |
|
| /// File Name: |
sa28042.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for e2fsprogs. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise an application using the library.
| | Homepage: | http://secunia.com/advisories/28042/ | | File Size: | 2943 | | Last Modified: | Dec 11 21:35:59 2007 |
| MD5 Checksum: | 51d344b1e58b4c8096b4b29d5caf74d2 |
|
| /// File Name: |
sa28138.txt |
Description:
|
Secunia Security Advisory - Peter Österberg has discovered a vulnerability in the Automatic Image Upload with Thumbnails module for PunBB, which can be exploited by malicious users to conduct cross-site scripting attacks and to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/28138/ | | File Size: | 2934 | | Last Modified: | Dec 18 12:39:14 2007 |
| MD5 Checksum: | f7be10279eb1b51ecfcdf9d8e844296a |
|
| /// File Name: |
sa28031.txt |
Description:
|
Secunia Security Advisory - Luigi Auriemma has reported some vulnerabilities in BadBlue, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, and compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/28031/ | | File Size: | 2926 | | Last Modified: | Dec 11 21:35:59 2007 |
| MD5 Checksum: | c7084aa21e8bdf504ad305b692628e04 |
|
| /// File Name: |
sa28063.txt |
Description:
|
Secunia Security Advisory - A security issue and two vulnerabilities have been reported in MySQL, which can be exploited by malicious users to gain escalated privileges, manipulate certain data, or to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/28063/ | | File Size: | 2919 | | Last Modified: | Dec 13 13:34:25 2007 |
| MD5 Checksum: | e308426d353f71023aa8ae9dc6a9f96e |
|
|
|
|
|