Section: .. / 0802-advisories /
| /// File Name: |
sa28824.txt |
Description:
|
Secunia Security Advisory - Luigi Auriemma has discovered a vulnerability in Ipswitch Instant Messaging, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/28824/ | | File Size: | 2471 | | Last Modified: | Feb 8 19:15:54 2008 |
| MD5 Checksum: | 1a9a90976488089f8ed44792b1b36559 |
|
| /// File Name: |
sa28840.txt |
Description:
|
Secunia Security Advisory - Alexandr Polyakov and Stas Svistunovich have discovered some vulnerabilities in MODx, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks.
| | Homepage: | http://secunia.com/advisories/28840/ | | File Size: | 3136 | | Last Modified: | Feb 8 19:15:54 2008 |
| MD5 Checksum: | bdae89cf607d7166c92828691eae6a5f |
|
| /// File Name: |
sa28845.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for gd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
| | Homepage: | http://secunia.com/advisories/28845/ | | File Size: | 2959 | | Last Modified: | Feb 8 19:15:54 2008 |
| MD5 Checksum: | ded6c8bc727b0774bd62f519a235a482 |
|
| /// File Name: |
sa28820.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in VPN-1 SecuRemote/SecureClient NGX R60 and NGAI R56, which can be exploited by malicious, local users to disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/28820/ | | File Size: | 2771 | | Last Modified: | Feb 8 18:02:08 2008 |
| MD5 Checksum: | 77091559d2900811348dbbd15e8e9558 |
|
| /// File Name: |
tomcat-disclose.txt |
Description:
|
Apache Tomcat versions 6.0.5 through 6.0.15 suffer from an interesting flaw. If an exception occurs during the processing of parameters then it is possible that the parameters submitted for that request will be incorrectly processed as part of a following request.
| | Homepage: | http://tomcat.apache.org/security.html | | File Size: | 978 | | Related CVE(s): | CVE-2008-0002 | | Last Modified: | Feb 8 18:01:34 2008 |
| MD5 Checksum: | 60b98ac1f2ff69dbe2e3779706818f68 |
|
| /// File Name: |
sa28758.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities and weaknesses have been reported Mozilla Firefox, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/28758/ | | File Size: | 4403 | | Last Modified: | Feb 8 17:58:07 2008 |
| MD5 Checksum: | cc56263b501aca6ea2fd3230beed6bee |
|
| /// File Name: |
sa28818.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for firefox. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/28818/ | | File Size: | 2616 | | Last Modified: | Feb 8 17:58:07 2008 |
| MD5 Checksum: | 2131f4606ae8e470738fb4dfbf5d94d4 |
|
| /// File Name: |
mwsc-disclose.txt |
Description:
|
Level Platforms, Inc.'s Managed Workplace Server Center versions 4.x, 5.x, and 6.x suffer from information disclosure vulnerabilities.
| | Homepage: | http://www.tech-serve.com/ | | File Size: | 5055 | | Related CVE(s): | CVE-2008-0636 | | Last Modified: | Feb 8 17:57:57 2008 |
| MD5 Checksum: | 674f27556167fd344d0144a2d3e39660 |
|
| /// File Name: |
emerdal-null.txt |
Description:
|
The configuration web server integrated in Emerald versions 5.0.49 and below, RadiusNT and RadiusX versions 5.1.38 and below, Radius test client versions 4.0.20 and below, and Air Marshal versions 2.0.4 and below suffer from a NULL byte vulnerability.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | File Size: | 2584 | | Last Modified: | Feb 8 17:43:00 2008 |
| MD5 Checksum: | 07867e64a299722998266ae14583e711 |
|
| /// File Name: |
dsa-1487-1.txt |
Description:
|
Debian Security Advisory 1487-1 - Several vulnerabilities have been discovered in the EXIF parsing code of the libexif library, which can lead to denial of service or the execution of arbitrary code if a user is tricked into opening a malformed image.
| | Homepage: | http://www.debian.org/security | | File Size: | 11366 | | Related CVE(s): | CVE-2007-2645, CVE-2007-6351, CVE-2007-6352 | | Last Modified: | Feb 8 17:27:50 2008 |
| MD5 Checksum: | 81af98f9648733bc1b0b12b3e6769280 |
|
| /// File Name: |
asus-samba.txt |
Description:
|
The ASUS Eee PC as shipped with Xandros comes with a vulnerable version of Samba installed that allows for remote compromise.
| | Homepage: | http://www.risesecurity.org/ | | File Size: | 5077 | | Last Modified: | Feb 8 17:26:29 2008 |
| MD5 Checksum: | 0c58ff1acc1480a4349bdc34730d9cf7 |
|
| /// File Name: |
sa28754.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or potentially to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/28754/ | | File Size: | 2496 | | Last Modified: | Feb 8 16:18:36 2008 |
| MD5 Checksum: | 6bfa3c29373e9b8f72873cadfce26173 |
|
| /// File Name: |
sa28808.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in Mozilla Thunderbird, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or potentially to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/28808/ | | File Size: | 2587 | | Last Modified: | Feb 8 16:18:36 2008 |
| MD5 Checksum: | d90ccb026795e4d34d110be8bf87cb7f |
|
| /// File Name: |
sa28839.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for firefox. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/28839/ | | File Size: | 28428 | | Last Modified: | Feb 8 16:18:36 2008 |
| MD5 Checksum: | 91a5279e16ab7b4c25cc5a8b1b9ca6bc |
|
| /// File Name: |
sa28853.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Symantec Ghost Solution Suite, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/28853/ | | File Size: | 2814 | | Last Modified: | Feb 8 16:18:36 2008 |
| MD5 Checksum: | 00c93ee9167ca75f3d45bb9c40ef5728 |
|
| /// File Name: |
sa28856.txt |
Description:
|
Secunia Security Advisory - Two security issues have been reported in Website META Language, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
| | Homepage: | http://secunia.com/advisories/28856/ | | File Size: | 2413 | | Last Modified: | Feb 8 16:18:36 2008 |
| MD5 Checksum: | 04f628d2511b7e03fea83e4e8e71dbc8 |
|
| /// File Name: |
sa28799.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for gnumeric. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/28799/ | | File Size: | 2168 | | Last Modified: | Feb 8 03:23:14 2008 |
| MD5 Checksum: | 3c3f6a191f998512fa51aa130d8be2b8 |
|
| /// File Name: |
MDVSA-2008-042.txt |
Description:
|
Mandriva Linux Security Advisory - A potential vulnerability was discovered in Qt4 version 4.3.0 through 4.3.2 which may cause a certificate verification in SSL connections not to be performed. As a result, code that uses QSslSocket could be tricked into thinking that the certificate was verified correctly when it actually failed in one or more criteria.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 8235 | | Related CVE(s): | CVE-2007-5965 | | Last Modified: | Feb 8 03:23:05 2008 |
| MD5 Checksum: | 31f621027015afc57042c111b0bd09f0 |
|
| /// File Name: |
USN-576-1.txt |
Description:
|
Ubuntu Security Notice 576-1 - Code execution, cross site scripting, arbitrary upload, and a large amount of other vulnerabilities have been patched in Firefox.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 31729 | | Related CVE(s): | CVE-2008-0412, CVE-2008-0413, CVE-2008-0414, CVE-2008-0415, CVE-2008-0416, CVE-2008-0417, CVE-2008-0418, CVE-2008-0419, CVE-2008-0420, CVE-2008-0591, CVE-2008-0592, CVE-2008-0593, CVE-2008-0594 | | Last Modified: | Feb 7 23:34:59 2008 |
| MD5 Checksum: | d874184c41ea454f78e3de284d23c156 |
|
| /// File Name: |
adobe-print.txt |
Description:
|
A design error vulnerability exists in Adobe Reader and Adobe Acrobat Professional. A remote attacker who successfully exploit this vulnerability can control the printer without user's permission. Affected software versions include Adobe Reader 8.1.1 and below and Adobe Acrobat Professional 8.1.1 and below.
| | Author: | cocoruder | | Homepage: | http://ruder.cdut.net/ | | File Size: | 1301 | | Last Modified: | Feb 7 23:32:09 2008 |
| MD5 Checksum: | 18d7663c9bdf663b2b385e73e35eb32a |
|
| /// File Name: |
02.07.08-2.txt |
Description:
|
iDefense Security Advisory 02.07.08 - Remote exploitation of a memory corruption vulnerability within version 9.1 of IBM Corp.'s DB2 Universal Database Administration Server (DAS) allows attackers to crash the service or potentially execute arbitrary code in the context of the affected service. iDefense has confirmed the existence of this vulnerability in the DAS (db2dassrm) as included with DB2 9.1 with Fix Pack 2 for both Linux and Windows platforms. Previous versions, as well as builds for other platforms, are suspected to be vulnerable.
| | Homepage: | http://www.idefense.com/ | | File Size: | 4180 | | Related CVE(s): | CVE-2007-3676 | | Last Modified: | Feb 7 23:27:37 2008 |
| MD5 Checksum: | 77c7a11e062f401ce426e2c6b5e41b14 |
|
| /// File Name: |
02.07.08-1.txt |
Description:
|
iDefense Security Advisory 02.07.08 - Local exploitation of a library loading vulnerability in IBM Corp.'s DB2 Universal Database could allow attackers to gain root privileges. When the DB2INSTANCE environment variable is set, the libdb2 library will use the corresponding user's directory in place of the DB2 instance directory. This allows an unprivileged local user to control the directory structure on which several set-uid root binaries operate. iDefense has confirmed the existence of this vulnerability in IBM Corp.'s DB2 Universal Database 9.1 with FixPack 2 installed on a Linux system. Other versions, including those for other UNIX systems, are also suspected to be vulnerable.
| | Homepage: | http://www.idefense.com/ | | File Size: | 3749 | | Related CVE(s): | CVE-2007-5757 | | Last Modified: | Feb 7 23:26:30 2008 |
| MD5 Checksum: | b0bfa4ee621d60cb4db6c9c3e2745456 |
|
| /// File Name: |
rintintin.txt |
Description:
|
TinTin++ / WinTin++ versions 1.97.9 and below suffer from buffer overflow and file creation vulnerabilities.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related Exploit: | rintintin.zip | | File Size: | 3129 | | Last Modified: | Feb 7 23:22:06 2008 |
| MD5 Checksum: | 2a79d4f49f6543c06689dd8aac3e7f20 |
|
| /// File Name: |
ipsimene.txt |
Description:
|
Ipswitch Instant Messaging versions 2.0.8.1 and below suffer from format string, NULL pointer, and file creation vulnerabilities.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related Exploit: | ipsimene.zip | | File Size: | 4197 | | Last Modified: | Feb 7 23:18:53 2008 |
| MD5 Checksum: | 5aa330a61c03eedf9eccbf494192ef2f |
|
| /// File Name: |
MDVSA-2008-041.txt |
Description:
|
Mandriva Linux Security Advisory - The ReadImage() function in Tk did not check codeSize read from GIF images prior to initializing the append array, which could lead to a buffer overflow with unknown impact.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 7928 | | Related CVE(s): | CVE-2008-0553 | | Last Modified: | Feb 7 21:35:43 2008 |
| MD5 Checksum: | a0d7e2ec2821412aeccaa3db54191735 |
|
|
|
|
|