Section: .. / 0612-advisories /
| /// File Name: |
sa23371.txt |
Description:
|
Secunia Security Advisory - Alfredo Ortega has reported a vulnerability in the mod_ctrls module for ProFTPD, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/23371/ | | File Size: | 2666 | | Last Modified: | Dec 14 10:45:41 2006 |
| MD5 Checksum: | de29859546f4e378ddeeb83e0094b2f4 |
|
| /// File Name: |
glsa-200612-21.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200612-21 - The read_multipart function of the CGI library shipped with Ruby (cgi.rb) does not properly check boundaries in MIME multipart content. This is a different issue than GLSA 200611-12. Versions less than 1.8.5_p2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2663 | | Last Modified: | Dec 22 01:17:33 2006 |
| MD5 Checksum: | a828a0c735f3a68bd9f6b9f43240ea24 |
|
| /// File Name: |
glsa-200612-19.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200612-19 - Steve Rigler discovered that pam_ldap does not correctly handle PasswordPolicyResponse control responses from an LDAP directory. This causes the pam_authenticate() function to always succeed, even if the previous authentication failed. Versions less than 183 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2662 | | Last Modified: | Dec 22 01:16:52 2006 |
| MD5 Checksum: | 858a8324fd729cdd34528a6d7186e7b4 |
|
| /// File Name: |
ZDI-06-051.txt |
Description:
|
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Mozilla Firefox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. Affected versions are Mozilla Firefox 2.0.0.0 and Mozilla Firefox 1.5.0.4 through 1.5.0.8.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2659 | | Related CVE(s): | CVE-2006-6504 | | Last Modified: | Dec 22 01:06:04 2006 |
| MD5 Checksum: | 0d8cae7b5d09fc8bc72e3f7ebaddf508 |
|
| /// File Name: |
glsa-200611-23.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200611-23 - Sebastian Krahmer of the SuSE Security Team discovered that the System.CodeDom.Compiler classes of Mono create temporary files with insecure permissions. Versions less than 1.1.13.8.1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2655 | | Last Modified: | Dec 1 01:12:58 2006 |
| MD5 Checksum: | ff15db32ee66b84b5be05f8b5c60f988 |
|
| /// File Name: |
sa23289.txt |
Description:
|
Secunia Security Advisory - Laurent Gaffié and Benjamin Mossé have reported some vulnerabilities in The Classifieds Ad System, which can be exploited by malicious people conduct SQL injection and cross-site scripting vulnerabilities.
| | Homepage: | http://secunia.com/advisories/23289/ | | File Size: | 2648 | | Last Modified: | Dec 8 22:32:56 2006 |
| MD5 Checksum: | 6c273a26f189fdd09d75cddcb0894bc2 |
|
| /// File Name: |
sa23492.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in w3m, which potentially can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/23492/ | | File Size: | 2642 | | Last Modified: | Dec 27 23:54:47 2006 |
| MD5 Checksum: | ed4e0f29b5387ffa88c21a1107bbd09f |
|
| /// File Name: |
sa23181.txt |
Description:
|
Secunia Security Advisory - Mr_KaLiMaN has reported a vulnerability in @lex Guestbook, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/23181/ | | File Size: | 2642 | | Last Modified: | Dec 6 03:07:49 2006 |
| MD5 Checksum: | fe219cbc37985fd7797010c96cf7c7b2 |
|
| /// File Name: |
hpftp-dos.txt |
Description:
|
Both versions 2.4 and 2.4.5 of HP printers suffer from a buffer overflow in the LIST and NLST commands.
| | Author: | Joxean Koret | | Related Exploit: | dos2.4.py.txt | | File Size: | 2638 | | Last Modified: | Dec 22 00:55:40 2006 |
| MD5 Checksum: | b7271c9e9e52fe202a24a09b0a7eccfb |
|
| /// File Name: |
sa23472.txt |
Description:
|
Secunia Security Advisory - Netragard has reported two vulnerabilities in @Mail, which potentially can be exploited by malicious people to conduct cross-site scripting attacks or cross-site request forgery attacks.
| | Homepage: | http://secunia.com/advisories/23472/ | | File Size: | 2635 | | Last Modified: | Dec 27 23:54:47 2006 |
| MD5 Checksum: | 59ead0cd59e762828fc89be832da006d |
|
| /// File Name: |
sa23336.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in HP Integrated Lights Out (iLO), which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/23336/ | | File Size: | 2631 | | Last Modified: | Dec 14 10:45:41 2006 |
| MD5 Checksum: | f8c9f706c2c556852bc02e962340f009 |
|
| /// File Name: |
sa23430.txt |
Description:
|
Secunia Security Advisory - A weakness has been reported in NeoScale Systems CryptoStor 700 Series, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/23430/ | | File Size: | 2629 | | Last Modified: | Dec 19 20:15:33 2006 |
| MD5 Checksum: | deb560b700bafd3909f938db24d78a99 |
|
| /// File Name: |
sa23293.txt |
Description:
|
Secunia Security Advisory - DeltahackingTEAM has reported a vulnerability in awrate.com Message Board, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/23293/ | | File Size: | 2629 | | Last Modified: | Dec 8 22:32:56 2006 |
| MD5 Checksum: | d86bf77c1727ee0fe4daf52d4c96fdb1 |
|
| /// File Name: |
glsa-200612-02.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200612-02 - A possible buffer overflow has been reported in the Real Media input plugin. Versions less than 1.1.2-r3 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2628 | | Last Modified: | Dec 11 16:52:38 2006 |
| MD5 Checksum: | 0827e85ed7a3d3ee74d94bfdf663b536 |
|
| /// File Name: |
ZDI-06-053.txt |
Description:
|
A vulnerability allows remote attackers to execute arbitrary code on affected versions of Novell NetMail. Authentication is not required to exploit this vulnerability. The specific flaw exists in the NetMail IMAP service, imapd.exe. The service does not sufficiently validate user-input length values when literals are appended to IMAP verbs to specify a command continuation request. The memory allocated to store the additional data may be insufficient, leading to an exploitable heap-based buffer overflow. Novell NetMail 3.5.2 is affected.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2627 | | Related CVE(s): | CVE-2006-6424 | | Last Modified: | Dec 28 00:41:47 2006 |
| MD5 Checksum: | ec5de911d3f800d11fd8101ca211945a |
|
| /// File Name: |
sa23222.txt |
Description:
|
Secunia Security Advisory - Aria-Security Team have reported two vulnerabilities in DUware DUpaypal, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/23222/ | | File Size: | 2625 | | Last Modified: | Dec 6 03:07:49 2006 |
| MD5 Checksum: | 4885706d810c1f632ac62a718cf2f421 |
|
| /// File Name: |
sa23192.txt |
Description:
|
Secunia Security Advisory - Greg Linares has discovered a vulnerability in BlazeVideo HDTV Player, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/23192/ | | File Size: | 2624 | | Last Modified: | Dec 6 03:07:49 2006 |
| MD5 Checksum: | ce0fb5d3fd3620b75327f83ba4b3235c |
|
| /// File Name: |
sa23203.txt |
Description:
|
Secunia Security Advisory - A weakness has been reported in KDE, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/23203/ | | File Size: | 2622 | | Last Modified: | Dec 6 03:07:49 2006 |
| MD5 Checksum: | b72a1ce82ff4153959bf0d4a62889163 |
|
| /// File Name: |
sa23228.txt |
Description:
|
Secunia Security Advisory - Aria-Security Team have reported two vulnerabilities in DUware DUnews, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/23228/ | | File Size: | 2621 | | Last Modified: | Dec 6 03:07:49 2006 |
| MD5 Checksum: | 0f99bb323c4447735133f7dd4fbdbbe6 |
|
| /// File Name: |
sa23239.txt |
Description:
|
Secunia Security Advisory - maluc has reported a vulnerability in Google Mini Search Appliance and Google Search Appliance, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/23239/ | | File Size: | 2620 | | Last Modified: | Dec 6 03:07:49 2006 |
| MD5 Checksum: | f2b27ac37f8473207c94f23de1c5cd47 |
|
| /// File Name: |
sa23456.txt |
Description:
|
Secunia Security Advisory - Mr_KaLiMaN has discovered some vulnerabilities in Xt-News, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/23456/ | | File Size: | 2619 | | Last Modified: | Dec 27 23:54:47 2006 |
| MD5 Checksum: | fa16f49c3bbc43f94b120fcc463597fd |
|
| /// File Name: |
ZDI-06-052.txt |
Description:
|
A vulnerability allows remote attackers to execute arbitrary code on affected installations of Novell NetMail. Successful exploitation requires the attacker to successfully authenticate to the affected service. The specific flaw exists in NetMail's implementation of the Network Messaging Application Protocol (NMAP). The NMAP server lacks bounds checking on parameters supplied to the STOR command, which can lead to an exploitable buffer overflow. The vulnerable daemon, nmapd.exe, binds to TCP port 689. Novell NetMail 3.5.2 is affected.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2617 | | Related CVE(s): | CVE-2006-6424 | | Last Modified: | Dec 28 00:40:54 2006 |
| MD5 Checksum: | ccd5a2f83eb163b9f31a2c4c7b24d37f |
|
| /// File Name: |
sa23224.txt |
Description:
|
Secunia Security Advisory - Aria-Security Team have reported a vulnerability in DUware DUdownload, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/23224/ | | File Size: | 2615 | | Last Modified: | Dec 6 03:07:49 2006 |
| MD5 Checksum: | 7ad660da0436ea39ecfb6c989fa7be60 |
|
| /// File Name: |
sa23151.txt |
Description:
|
Secunia Security Advisory - Greg Linares has discovered a vulnerability in AtomixMP3, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/23151/ | | File Size: | 2611 | | Last Modified: | Dec 6 03:07:49 2006 |
| MD5 Checksum: | bb8a8f07768a6f1757747c98f2b7091d |
|
| /// File Name: |
sa23182.txt |
Description:
|
Secunia Security Advisory - Greg Linares has discovered a vulnerability in VUPlayer, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/23182/ | | File Size: | 2605 | | Last Modified: | Dec 6 03:07:49 2006 |
| MD5 Checksum: | 063b34524395392e6aeb868d78955a1a |
|
|
|
|
|