Section: .. / 0801-advisories /
| /// File Name: |
sa28629.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in MediaWiki, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/28629/ | | File Size: | 3101 | | Last Modified: | Jan 25 02:43:48 2008 |
| MD5 Checksum: | 1dbd4ad883a3f1be0a0cc5955df11412 |
|
| /// File Name: |
sa28631.txt |
Description:
|
Secunia Security Advisory - Felipe Aragon and Alec Storm have reported some vulnerabilities and security issues in HTTP File Server, which can be exploited by malicious people to disclose system information, conduct spoofing and cross-site scripting attacks, bypass certain security restrictions, manipulate data, and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/28631/ | | File Size: | 3475 | | Last Modified: | Jan 25 02:43:48 2008 |
| MD5 Checksum: | e29f197eefceb0b88ba7ecaf976688dc |
|
| /// File Name: |
sa28632.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in the Archive module for Drupal, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/28632/ | | File Size: | 2376 | | Last Modified: | Jan 25 02:43:48 2008 |
| MD5 Checksum: | 170e17fad089d9533de314f9fb4d4a28 |
|
| /// File Name: |
sa28633.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in the Workflow module for Drupal, which can be exploited by malicious users to conduct script insertion attacks.
| | Homepage: | http://secunia.com/advisories/28633/ | | File Size: | 2532 | | Last Modified: | Jan 25 02:43:48 2008 |
| MD5 Checksum: | 1c81feb5cc962609e775651ac1f99a9b |
|
| /// File Name: |
sa28639.txt |
Description:
|
Secunia Security Advisory - AmnPardaz Security Research Team has reported a vulnerability in Web Wiz Rich Text Editor, which can be exploited by malicious people to disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/28639/ | | File Size: | 2530 | | Last Modified: | Jan 25 02:43:48 2008 |
| MD5 Checksum: | 6b075ff88b101d5f220199543c1b78bc |
|
| /// File Name: |
sa28640.txt |
Description:
|
Secunia Security Advisory - Two vulnerabilities have been reported in SDL_image, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
| | Homepage: | http://secunia.com/advisories/28640/ | | File Size: | 2849 | | Last Modified: | Jan 25 02:43:48 2008 |
| MD5 Checksum: | ce39d4b00105883e2f6d4b957c561e89 |
|
| /// File Name: |
sa28643.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a Denial of Service (DoS), disclose potentially sensitive information, bypass certain security restrictions, and corrupt a file system, and by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/28643/ | | File Size: | 2664 | | Last Modified: | Jan 25 02:43:48 2008 |
| MD5 Checksum: | 54f0292d477c84d5c980f4fd091e7258 |
|
| /// File Name: |
glsa-200801-10.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200801-10 - Jesus Olmos Gonzalez from isecauditors reported insufficient sanitization of the movies parameter in file tiki-listmovies.php. Mesut Timur from H-Labs discovered that the input passed to the "area_name" parameter in file tiki-special_chars.php is not properly sanitised before being returned to the user. redflo reported multiple unspecified vulnerabilities in files tiki-edit_css.php, tiki-list_games.php, and tiki-g-admin_shared_source.php. Versions less than 1.9.9 are affected.
| | Homepage: | http://security.gentoo.org/ | | File Size: | 3415 | | Related CVE(s): | CVE-2007-6526, CVE-2007-6528, CVE-2007-6529 | | Last Modified: | Jan 24 00:21:37 2008 |
| MD5 Checksum: | 25103debfa92866d5cbd7645429937f0 |
|
| /// File Name: |
dsa-1474-1.txt |
Description:
|
Debian Security Advisory 1474-1 - Meder Kydyraliev discovered an integer overflow in the thumbnail handling of libexif, the EXIF/IPTC metadata manipulation library, which could result in the execution of arbitrary code.
| | Homepage: | http://www.debian.org/security | | File Size: | 8360 | | Related CVE(s): | CVE-2007-6353 | | Last Modified: | Jan 24 00:19:45 2008 |
| MD5 Checksum: | 5c9d4faa07dd7534e4fb1bc754522876 |
|
| /// File Name: |
dsa-1444-2.txt |
Description:
|
Debian Security Advisory 1444-2 - Several remote vulnerabilities have been discovered in PHP, a server-side, HTML-embedded scripting language. It was discovered that the patch for CVE-2007-4659 could lead to regressions in some scenarios. The fix has been reverted for now, a revised update will be provided in a future PHP DSA.
| | Homepage: | http://www.debian.org/security | | File Size: | 45049 | | Related CVE(s): | CVE-2007-3799, CVE-2007-3998, CVE-2007-4657, CVE-2007-4658, CVE-2007-4660, CVE-2007-4662, CVE-2007-5898, CVE-2007-5899 | | Last Modified: | Jan 24 00:18:43 2008 |
| MD5 Checksum: | 823471db4321b65f0f2a84ab52ac56a9 |
|
| /// File Name: |
cisco-sa-20080123-avs.txt |
Description:
|
Cisco Security Advisory - Versions of the Cisco Application Velocity System (AVS) prior to software version AVS 5.1.0 do not prompt users to modify system account passwords during the initial configuration process. Because there is no requirement to change these credentials during the initial configuration process, an attacker may be able to leverage the accounts that have default credentials, some of which have root privileges, to take full administrative control of the AVS system.
| | Homepage: | http://www.cisco.com/ | | File Size: | 20371 | | Related CVE(s): | CVE-2008-0029 | | Last Modified: | Jan 23 23:25:41 2008 |
| MD5 Checksum: | c63427ba381292b84f12fd1fbb98d7bd |
|
| /// File Name: |
cisco-sa-20080123-asa.txt |
Description:
|
Cisco Security Advisory - A crafted IP packet vulnerability exists in the Cisco PIX 500 Series Security Appliance (PIX) and the Cisco 5500 Series Adaptive Security Appliance (ASA) that may result in a reload of the device. This vulnerability is triggered during processing of a crafted IP packet when the Time-to-Live (TTL) decrement feature is enabled.
| | Homepage: | http://www.cisco.com/ | | File Size: | 12690 | | Related CVE(s): | CVE-2008-0028 | | Last Modified: | Jan 23 23:24:57 2008 |
| MD5 Checksum: | ee44bd7dede178400b8e0e71a92c6bea |
|
| /// File Name: |
SSRT071463.txt |
Description:
|
HP Security Bulletin - A potential security vulnerability has been identified with HP-UX running ARPA Transport. The vulnerability could be exploited remotely to create a Denial of Service (DoS).
| | Homepage: | http://www.hp.com/ | | File Size: | 6112 | | Related CVE(s): | CVE-2007-6425 | | Last Modified: | Jan 23 23:23:13 2008 |
| MD5 Checksum: | e792e02b727dc82a389280021f36ff76 |
|
| /// File Name: |
sdl-overflow.txt |
Description:
|
SDL_Image versions 1.2.6 and below suffer from a GIF handling buffer overflow vulnerability.
| | Author: | Gynvael Coldwind | | File Size: | 2593 | | Last Modified: | Jan 23 23:10:09 2008 |
| MD5 Checksum: | c94c656a83149b5559377c10f2795419 |
|
| /// File Name: |
sa28442.txt |
Description:
|
Secunia Security Advisory - QTRinux has reported some vulnerabilities in Lama Software, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/28442/ | | File Size: | 2488 | | Last Modified: | Jan 23 22:55:21 2008 |
| MD5 Checksum: | 9376f4056e2b1c70b1481fd2829a1eb6 |
|
| /// File Name: |
sa28487.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for bind. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/28487/ | | File Size: | 6866 | | Last Modified: | Jan 23 22:55:21 2008 |
| MD5 Checksum: | 2e31c5910ad11bfaf3e719b8333b4576 |
|
| /// File Name: |
sa28500.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for libXfont. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/28500/ | | File Size: | 4153 | | Last Modified: | Jan 23 22:55:21 2008 |
| MD5 Checksum: | 335e4c015f962cbdea59cb6dc0b4acd6 |
|
| /// File Name: |
sa28507.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for xine-lib. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/28507/ | | File Size: | 12186 | | Last Modified: | Jan 23 22:55:21 2008 |
| MD5 Checksum: | 25c8e6c7923b6cf885424f1b41160258 |
|
| /// File Name: |
sa28545.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for boost. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/28545/ | | File Size: | 3619 | | Last Modified: | Jan 23 22:55:21 2008 |
| MD5 Checksum: | 313924db96a08dfdf4767ce53f99a770 |
|
| /// File Name: |
sa28587.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for clamav. This fixes some vulnerabilities, where one vulnerability has an unknown impact and others can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/28587/ | | File Size: | 9710 | | Last Modified: | Jan 23 22:55:21 2008 |
| MD5 Checksum: | d11db020353cc07c75d0f804beb64b96 |
|
| /// File Name: |
sa28591.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for mantis. This fixes a vulnerability, which can be exploited by malicious users to conduct script insertion attacks.
| | Homepage: | http://secunia.com/advisories/28591/ | | File Size: | 2611 | | Last Modified: | Jan 23 22:55:21 2008 |
| MD5 Checksum: | 705e8e4b9886a0ffe4a0d1651fbe2d32 |
|
|
|
|
|