Section: .. / 0708-advisories /
| /// File Name: |
TISA2007-04-Public.txt |
Description:
|
DVD Rental System version 5.1 suffers from cross site scripting and cross site request forgery vulnerabilities.
| | Author: | Edi Strosar | | Homepage: | http://www.teamintell.com/ | | File Size: | 3008 | | Last Modified: | Aug 8 07:12:20 2007 |
| MD5 Checksum: | 7fcb752628b3c00797b33ae256d9f653 |
|
| /// File Name: |
USN-494-1.txt |
Description:
|
Ubuntu Security Notice 494-1 - Sean Larsson discovered multiple integer overflows in Gimp. By tricking a user into opening a specially crafted DICOM, PNM, PSD, PSP, RAS, XBM, or XWD image, a remote attacker could exploit this to execute arbitrary code with the user's privileges.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 17012 | | Related CVE(s): | CVE-2006-4519 | | Last Modified: | Aug 8 07:09:06 2007 |
| MD5 Checksum: | 6dd892ea6ad69dd3a2dc450dc6e1cc13 |
|
| /// File Name: |
CVE-2007-3384.txt |
Description:
|
Tomcat versions 3.3 through 3.3.2 suffer from a cross site scripting vulnerability.
| | Author: | Tomasz Kuczynski | | Homepage: | http://tomcat.apache.org/ | | File Size: | 1059 | | Related CVE(s): | CVE-2007-3384 | | Last Modified: | Aug 8 07:08:17 2007 |
| MD5 Checksum: | e08a51b467ebfdc1f8018c1438f6b4ba |
|
| /// File Name: |
baidu-exec.txt |
Description:
|
The ActiveX control BaiduBar.dll in Baidu Soba suffers from a remote code execution vulnerability
| | Author: | cocoruder | | Homepage: | http://ruder.cdut.net/ | | File Size: | 4538 | | Last Modified: | Aug 8 07:06:36 2007 |
| MD5 Checksum: | 4539f57d904fff3e42c14587fd32339e |
|
| /// File Name: |
MDKSA-2007-152.txt |
Description:
|
Mandriva Linux Security Advisory - A number of security vulnerabilities have been discovered and corrected in the latest Mozilla Firefox program, version 2.0.0.6.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 52335 | | Related CVE(s): | CVE-2007-3089, CVE-2007-3285, CVE-2007-3656, CVE-2007-3670, CVE-2007-3734, CVE-2007-3735, CVE-2007-3736, CVE-2007-3737, CVE-2007-3738, CVE-2007-3844, CVE-2007-3845 | | Last Modified: | Aug 8 07:04:03 2007 |
| MD5 Checksum: | a0fd2b4a65019d2ea2d16383d6d1de2a |
|
| /// File Name: |
MDKSA-2007-151.txt |
Description:
|
Mandriva Linux Security Advisory - A number of format string flaws have been discovered in how Qt handled error messages by Dirk Mueller and Tracey Parry of Portcullis Computer Security. If an application linked against Qt created an error message from user-supplied data in a certain way, it could possibly lead to the execution of arbitrary code or a denial of service.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 12281 | | Related CVE(s): | CVE-2007-3388 | | Last Modified: | Aug 8 07:02:33 2007 |
| MD5 Checksum: | 9ec9446759f68678fe951a1f04c4e0e2 |
|
| /// File Name: |
FreeBSD-SA-07-07.bind.txt |
Description:
|
FreeBSD Security Advisory - An attacker who can see the query id for some request(s) sent by named(8) is likely to be able to perform DNS cache poisoning by predicting the query id for other request(s).
| | Homepage: | http://security.freebsd.org/ | | File Size: | 5024 | | Related CVE(s): | CVE-2007-2926 | | Last Modified: | Aug 8 07:01:53 2007 |
| MD5 Checksum: | 1899f894331dbbaf028a86edf33311ce |
|
| /// File Name: |
FreeBSD-SA-07-06.tcpdump.txt |
Description:
|
FreeBSD Security Advisory - By crafting malicious BGP packets, an attacker could exploit a vulnerability in tcpdump allowing them to execute code or crash the process.
| | Homepage: | http://security.freebsd.org/ | | File Size: | 4183 | | Related CVE(s): | CVE-2007-3798 | | Last Modified: | Aug 8 07:00:58 2007 |
| MD5 Checksum: | 1bd850f1efce8de400f13f7c5649dc81 |
|
| /// File Name: |
FreeBSD-SA-07-01.jail.txt |
Description:
|
FreeBSD Security Advisory - Due to the lack of handling of potential symbolic links the host's jail rc.d(8) script is vulnerable to "symlink attacks". By replacing /var/log/console.log inside the jail with a symbolic link it is possible for the superuser (root) inside the jail to overwrite files on the host system outside the jail with arbitrary content. This in turn can be used to execute arbitrary commands with non-jailed superuser privileges.
| | Homepage: | http://security.freebsd.org/ | | File Size: | 8186 | | Related CVE(s): | CVE-2007-0166 | | Last Modified: | Aug 8 06:59:47 2007 |
| MD5 Checksum: | 91c3bba6bc61df9f97171190e093fef4 |
|
| /// File Name: |
kde357-dos.txt |
Description:
|
KDE's Konqueror versions 3.5.7 and below suffer from a denial of service vulnerability.
| | Author: | Thomas Waldegger | | Homepage: | http://buha.info/board/ | | File Size: | 3606 | | Last Modified: | Aug 8 06:58:07 2007 |
| MD5 Checksum: | 40a2b81559278a98990ee22636d8c909 |
|
| /// File Name: |
mambocms-fixation.txt |
Description:
|
Mambo CMS version 4.6.2 suffers from a session fixation vulnerability.
| | Author: | Tomaz Bratusa | | Homepage: | http://www.teamintell.com/ | | File Size: | 5215 | | Last Modified: | Aug 8 06:40:21 2007 |
| MD5 Checksum: | 2770f3bf47ebfd85f23883e72a2243c3 |
|
| /// File Name: |
SSRT071432.txt |
Description:
|
HP Security Bulletin - A potential security vulnerability has been identified with HP-UX running ARPA Transport. The vulnerability could be exploited locally by an authorized user to create a Denial of Service (DoS).
| | Homepage: | http://www.hp.com/ | | File Size: | 6097 | | Last Modified: | Aug 8 06:31:19 2007 |
| MD5 Checksum: | 5c175efff24fa477038a94d061aeebcc |
|
| /// File Name: |
SSRT071437.txt |
Description:
|
HP Security Bulletin - A potential security vulnerability has been identified with HP-UX running ARPA Transport. The vulnerability could be exploited remotely to create a Denial of Service (DoS).
| | Homepage: | http://www.hp.com/ | | File Size: | 6231 | | Last Modified: | Aug 8 06:30:48 2007 |
| MD5 Checksum: | 7c65d7d639fe44bf652593ea71456e15 |
|
| /// File Name: |
USN-493-1.txt |
Description:
|
Ubuntu Security Notice 493-1 - A flaw was discovered in handling of "about:blank" windows used by addons. A malicious web site could exploit this to modify the contents, or steal confidential data (such as passwords), of other web pages. Jesper Johansson discovered that spaces and double-quotes were not correctly handled when launching external programs. In rare configurations, after tricking a user into opening a malicious web page, an attacker could execute helpers with arbitrary arguments with the user's privileges.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 23784 | | Related CVE(s): | CVE-2007-3844, CVE-2007-3845 | | Last Modified: | Aug 8 06:27:26 2007 |
| MD5 Checksum: | f9d508262fd7a81703b35191aaacfa3a |
|
| /// File Name: |
sa26358.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for kdegraphics. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/26358/ | | File Size: | 2534 | | Last Modified: | Aug 8 06:01:26 2007 |
| MD5 Checksum: | 7dbdb4139f95d2c64b18636bdbed767d |
|
| /// File Name: |
sa26352.txt |
Description:
|
Secunia Security Advisory - Stephan Munz has discovered some vulnerabilities in Help Center Live, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/26352/ | | File Size: | 2471 | | Last Modified: | Aug 8 06:01:26 2007 |
| MD5 Checksum: | 4a65ee6e2e92b2037a9a51cbbb1fd939 |
|
| /// File Name: |
sa26351.txt |
Description:
|
Secunia Security Advisory - Robert Swiecki has discovered a vulnerablity in Konqueror, which can be exploited by malicious people to conduct spoofing attacks.
| | Homepage: | http://secunia.com/advisories/26351/ | | File Size: | 2702 | | Last Modified: | Aug 8 06:01:26 2007 |
| MD5 Checksum: | a3de7957f0422900eb21f60823851c2c |
|
| /// File Name: |
sa26349.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in IBM AIX, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/26349/ | | File Size: | 2207 | | Last Modified: | Aug 8 06:01:26 2007 |
| MD5 Checksum: | d4de2dc4f86aa62df1b25c28b7a99eea |
|
| /// File Name: |
sa26346.txt |
Description:
|
Secunia Security Advisory - r0t has reported some vulnerabilities in VisionProject, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/26346/ | | File Size: | 2585 | | Last Modified: | Aug 8 06:01:26 2007 |
| MD5 Checksum: | 7b5ce98a492fa3bf5c1a8e22aa21df83 |
|
| /// File Name: |
sa26345.txt |
Description:
|
Secunia Security Advisory - phoenix has discovered a vulnerability in the Blue Memories theme for WordPress, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/26345/ | | File Size: | 2513 | | Last Modified: | Aug 8 06:01:26 2007 |
| MD5 Checksum: | 60c5048a02e7a8e8bd2d125964f5f0cb |
|
| /// File Name: |
sa26344.txt |
Description:
|
Secunia Security Advisory - Avaya has acknowledged a vulnerability in Avaya CMS / IR, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
| | Homepage: | http://secunia.com/advisories/26344/ | | File Size: | 2645 | | Last Modified: | Aug 8 06:01:26 2007 |
| MD5 Checksum: | 40d5eefc78c2188abaeb9de1c14eab39 |
|
| /// File Name: |
sa26343.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for tetex-bin. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/26343/ | | File Size: | 8452 | | Last Modified: | Aug 8 06:01:26 2007 |
| MD5 Checksum: | 09b649578dc3d3ee7c5f5a31b12df255 |
|
| /// File Name: |
sa26342.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for libextractor. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise an application using the library.
| | Homepage: | http://secunia.com/advisories/26342/ | | File Size: | 8167 | | Last Modified: | Aug 8 06:01:26 2007 |
| MD5 Checksum: | 4a0696f146b3cd4ea00eaa260d76c7dc |
|
| /// File Name: |
sa26339.txt |
Description:
|
Secunia Security Advisory - k1tk4t has discovered some vulnerabilities in LANAI CMS, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/26339/ | | File Size: | 2525 | | Last Modified: | Aug 8 06:01:26 2007 |
| MD5 Checksum: | 2e2d7540f21a769c10b068cd0025ea73 |
|
| /// File Name: |
sa26338.txt |
Description:
|
Secunia Security Advisory - Aria-Security Team has reported a vulnerability in Next Gen Portfolio Manager, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/26338/ | | File Size: | 2256 | | Last Modified: | Aug 8 06:01:26 2007 |
| MD5 Checksum: | 89dc5dc9585aa72d66d88da1c5ba82f2 |
|
|
|
|
|