Section: .. / 0608-advisories /
| /// File Name: |
sa21575.txt |
Description:
|
Secunia Security Advisory - Chris Boulton has reported a vulnerability in XennoBB, which can be exploited by malicious users to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/21575/ | | File Size: | 2295 | | Last Modified: | Aug 26 20:18:48 2006 |
| MD5 Checksum: | ba41b48b351d0f35b5d384c5db55af97 |
|
| /// File Name: |
sa21686.txt |
Description:
|
Secunia Security Advisory - Thomas Wolff has discovered a security issue in xbiff2, which can be exploited by malicious, local users to disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/21686/ | | File Size: | 2293 | | Last Modified: | Aug 30 16:08:53 2006 |
| MD5 Checksum: | 6c8008da00cb4b227751620f625d4e00 |
|
| /// File Name: |
sa21395.txt |
Description:
|
Secunia Security Advisory - Philipp Niedziela has discovered a vulnerability in NEWSolved Lite, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/21395/ | | File Size: | 2285 | | Last Modified: | Aug 9 20:40:54 2006 |
| MD5 Checksum: | 59de45bfec09c5229c60f69f28591c63 |
|
| /// File Name: |
TSRT-06-08.txt |
Description:
|
An arbitrary code execution vulnerability exists in Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific vulnerability can lead to code execution when instantiating the Internet.HHCtrl COM object through Internet Explorer. The flaw exists due to invalid freeing of heap memory when several calls to the "Image" property of the ActiveX control are performed. By abusing the jscript.dll CScriptBody::Release() function user supplied data can be executed.
| | Author: | Cody Pierce | | Homepage: | http://www.tippingpoint.com/ | | File Size: | 2281 | | Related CVE(s): | CVE-2006-3357 | | Last Modified: | Aug 18 02:17:42 2006 |
| MD5 Checksum: | 7828ca0ead357bb71ab8824fba67dda7 |
|
| /// File Name: |
sa21383.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in CakePHP, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/21383/ | | File Size: | 2280 | | Last Modified: | Aug 9 20:40:54 2006 |
| MD5 Checksum: | 6c1ed08b5696ab57dd7d7d4ae047a5a8 |
|
| /// File Name: |
sa21281.txt |
Description:
|
Secunia Security Advisory - SirDarckCat has discovered a vulnerability in X-Statistics, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/21281/ | | File Size: | 2279 | | Last Modified: | Aug 2 04:14:26 2006 |
| MD5 Checksum: | a02bdb4607792daa1dacd95ec884d0aa |
|
| /// File Name: |
sa21304.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in libTIFF, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/21304/ | | File Size: | 2279 | | Last Modified: | Aug 2 23:35:36 2006 |
| MD5 Checksum: | 4c7b620a7dd0786eeedb0b2945fb20ba |
|
| /// File Name: |
sa21635.txt |
Description:
|
Secunia Security Advisory - kefka has discovered a vulnerability in HLstats, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/21635/ | | File Size: | 2278 | | Last Modified: | Aug 29 12:55:20 2006 |
| MD5 Checksum: | c67269bc6f4886e107f3cd5c1302e98b |
|
| /// File Name: |
INFIGO-2006-08-04.txt |
Description:
|
During an audit, a critical vulnerability has been discovered in the MDaemon POP3 server. There is a buffer overflow vulnerability in 'USER' and 'APOP' command processing part of the Altn MDaemon POP3 server. The vulnerability can be triggered with providing a long string to USER or APOP commands with '@' characters included in the string. In this case, MDaemon will incorectly process the string and a heap overflow will happen as a result. To trigger the vulnerability, a few USER commands have to be sent to the POP3 Server. Sometimes (depending on the heap state and string length), it is even possible to redirect code execution directly to the supplied input buffer on the heap. MDaemon versions 8 and 9 are confirmed vulnerable.
| | Author: | Leon Juranic | | Homepage: | http://www.infigo.hr/ | | Related Exploit: | mdaemon_poc.txt | | File Size: | 2277 | | Last Modified: | Aug 27 19:13:23 2006 |
| MD5 Checksum: | d2a66b4cd82218e9adf2ff9ae6a3ab77 |
|
| /// File Name: |
sa21571.txt |
Description:
|
Secunia Security Advisory - SHiKaA has reported a vulnerability in Fantastic News, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/21571/ | | File Size: | 2277 | | Last Modified: | Aug 26 20:18:48 2006 |
| MD5 Checksum: | 4d916fcce0cfc4127abcda167b964c26 |
|
| /// File Name: |
sa21371.txt |
Description:
|
Secunia Security Advisory - Ahmad Maulana has reported a vulnerability in PHP Simple Shop, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/21371/ | | File Size: | 2276 | | Last Modified: | Aug 9 20:40:54 2006 |
| MD5 Checksum: | ae1f16e5c6f2607dc13139818c7cbe3d |
|
| /// File Name: |
sa21407.txt |
Description:
|
Secunia Security Advisory - Tr_ZiNDaN has reported a vulnerability in phNNTP, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/21407/ | | File Size: | 2276 | | Last Modified: | Aug 9 20:40:54 2006 |
| MD5 Checksum: | bb9eeb113f90778daede99ca58497c63 |
|
| /// File Name: |
sa21289.txt |
Description:
|
Secunia Security Advisory - h07 has discovered a vulnerability in Easy File Sharing FTP Server, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/21289/ | | File Size: | 2275 | | Last Modified: | Aug 2 04:14:26 2006 |
| MD5 Checksum: | 30718bb5f7fde3fe45254c8d75ee7827 |
|
| /// File Name: |
sa21576.txt |
Description:
|
Secunia Security Advisory - McAfee Avert Labs has reported a vulnerability in the Linux Kernel, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/21576/ | | File Size: | 2273 | | Last Modified: | Aug 26 20:18:48 2006 |
| MD5 Checksum: | abfa96fd3b5a3396a4274b70e0ea6175 |
|
| /// File Name: |
sa21279.txt |
Description:
|
Secunia Security Advisory - A security issue has been reported in Sun Fire T2000, which potentially can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/21279/ | | File Size: | 2269 | | Last Modified: | Aug 2 23:35:36 2006 |
| MD5 Checksum: | 815fd588d9ae855be4070ebb1eefa374 |
|
| /// File Name: |
sa21344.txt |
Description:
|
Secunia Security Advisory - David Vieira-Kurz has discovered a vulnerability in toendaCMS, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/21344/ | | File Size: | 2269 | | Last Modified: | Aug 9 20:40:54 2006 |
| MD5 Checksum: | 5f1e2fdcc114c57601fc1a60934bd649 |
|
| /// File Name: |
NISR02082006B.txt |
Description:
|
NGSSoftware Insight Security Research Advisory - Informix Dynamic Server is a database developed by IBM. When IBM released a patch for the overly long username buffer overflow (CVE-2006-3853) it was discovered that the patch introduced a new buffer overflow vulnerability. Versions affected include 9.40.xC7 and xC8, 10.00.xC3 and xC4.
| | Author: | David Litchfield | | Homepage: | http://www.ngssoftware.com/ | | File Size: | 2267 | | Related CVE(s): | CVE-2006-3853, CVE-2006-3854 | | Last Modified: | Aug 27 00:34:28 2006 |
| MD5 Checksum: | 0d741bc614c48dd1b99de79937d95136 |
|
| /// File Name: |
sa21397.txt |
Description:
|
Secunia Security Advisory - ASIANEAGLE has reported a vulnerability in YenerTurk Haber Script, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/21397/ | | File Size: | 2264 | | Last Modified: | Aug 9 20:40:54 2006 |
| MD5 Checksum: | b564c9bf808097fa35efa09b8bb3a8aa |
|
| /// File Name: |
sa21456.txt |
Description:
|
Secunia Security Advisory - rPath has issued an update for krb5. This fixes a security issue, which potentially can be exploited by malicious, local users to perform certain actions with escalated privileges.
| | Homepage: | http://secunia.com/advisories/21456/ | | File Size: | 2255 | | Last Modified: | Aug 17 00:44:27 2006 |
| MD5 Checksum: | acec74283278f2139d01ebcc446d7587 |
|
| /// File Name: |
sa21399.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for apache. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/21399/ | | File Size: | 2254 | | Last Modified: | Aug 9 20:40:54 2006 |
| MD5 Checksum: | 4fa2769d858c9f384d21578baaab39bf |
|
| /// File Name: |
sa21536.txt |
Description:
|
Secunia Security Advisory - Thomas Pollet has discovered a vulnerability in TikiWiki, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/21536/ | | File Size: | 2254 | | Last Modified: | Aug 26 20:18:48 2006 |
| MD5 Checksum: | 34b2c8e12e25d6201e7aef5a65ad2811 |
|
| /// File Name: |
sa21358.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for mozilla-thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks and compromise a user's system.
| | Homepage: | http://secunia.com/advisories/21358/ | | File Size: | 2252 | | Last Modified: | Aug 9 20:40:54 2006 |
| MD5 Checksum: | 261d7d63dd072297ec690637f19b2249 |
|
| /// File Name: |
sa21574.txt |
Description:
|
Secunia Security Advisory - mdx has discovered a vulnerability within bigAPE-Backup, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/21574/ | | File Size: | 2252 | | Last Modified: | Aug 26 20:18:48 2006 |
| MD5 Checksum: | ace13b729bc68ffc9f13cd6d8ac2d178 |
|
| /// File Name: |
sa21330.txt |
Description:
|
Secunia Security Advisory - beford has reported a vulnerability in Kayako eSupport, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/21330/ | | File Size: | 2251 | | Last Modified: | Aug 9 20:40:54 2006 |
| MD5 Checksum: | 76fa9d058bba8267d0bc0c0ecdb9faa2 |
|
| /// File Name: |
sa21353.txt |
Description:
|
Secunia Security Advisory - x0r0n has discovered a vulnerability in ZoneX Publishers Gold Edition, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/21353/ | | File Size: | 2249 | | Last Modified: | Aug 9 20:40:54 2006 |
| MD5 Checksum: | 376de7c809d93bc987b78a69b027f476 |
|
|
|
|
|