|
Prev week |
Colapse all |
Post message
AST-2011-001: Stack buffer overflow in SIP channel driver 2011-01-18 Asterisk Security Team (security asterisk org) 'Seo Panel' Cookie-Rendered Persistent XSS Vulnerability (CVE-2010-4331) 2011-01-15 Mark Stanislav (mark stanislav gmail com) 'Seo Panel' Cookie-Rendered Persistent XSS Vulnerability (CVE-2010-4331) Mark Stanislav - mark.stanislav (at) gmail (dot) com [email concealed] I. DESCRIPTION --------------------------------------- A vulnerability exists in 'Seo Panel' page rendering which allows for unfiltered, unencrypted content to be presented to a user [ more ] [ reply ] Kingsoft AntiVirus 2011 SP5.2 KisKrnl.sys <= 2011.1.13.89 Local Kernel Mode D.O.S Exploit(3 lines of code) 2011-01-16 th_decoder 126 com # Kingsoft AntiVirus 2011 SP5.2 KisKrnl.sys <= 2011.1.13.89 Local Kernel Mode D.O.S Exploit # Date: 2011-1-16 # Author: MJ0011 # Version: KingSoft AntiVirus 2011 SP5.2 with KisKrnl.sys <=2011.1.13.89 # Tested on: Windows XP SP3 DETAILS: KisKrnl.sys hook the kernel function KiFastCallEntry , but is [ more ] [ reply ] [ GLSA 201101-03 ] libvpx: User-assisted execution of arbitrary code 2011-01-15 Tim Sammut (underling gentoo org) [ GLSA 201101-06 ] IO::Socket::SSL: Certificate validation error 2011-01-16 Stefan Behte (craig gentoo org) [ GLSA 201101-02 ] Tor: Remote heap-based buffer overflow 2011-01-15 Tim Sammut (underling gentoo org) [SECURITY] [DSA 2144-1] Security update for wireshark 2011-01-15 Moritz Muehlenhoff (jmm debian org) Remote Code Execution in ICQ 7 2011-01-14 Daniel Seither (post tiwoc de) SUMMARY The ICQ 7 instant messaging client allows remote code execution due to a flaw in its automatic update mechanism. VULNERABLE APPLICATIONS All versions of ICQ 7 for Windows, up to version 7.2, build 3525 (which is the current version) ICQ 6 and older versions were not tested. Other ICQ c [ more ] [ reply ] [SECURITY] [DSA-2143-1] New mysql-dfsg-5.0 packages fix several vulnerabilities 2011-01-14 Giuseppe Iuculano (iuculano debian org) [security bulletin] HPSBUX02608 SSRT100333 rev.2 - HP-UX Running Java, Remote Execution of Arbitrary Code, Disclosure of Information, and Other Vulnerabilities 2011-01-14 security-alert hp com -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c02616748 Version: 1 HPSBUX02608 SSRT100333 rev.2 - HP-UX Running Java, Remote Execution of Arbitrary Code, Disclosure of Information, and Other Vulnerabilities NOTICE: The information in this Se [ more ] [ reply ] Drupal 5.x, 6.x <= Stored Cross Site Scripting Vulnerability 2011-01-13 YGN Ethical Hacker Group (lists yehg net) ======================================================================== == Drupal 5.x, 6.x <= Stored Cross Site Scripting Vulnerability ======================================================================== == 1. OVERVIEW Drupal 5.x and 6.x are currently vulnerable to Stored Cross Site Scriptin [ more ] [ reply ] [MajorSecurity SA-081]Contao CMS 2.9.2 - Persistent Cross Site Scripting Issue 2011-01-12 david kurz majorsecurity net [MajorSecurity SA-081]Contao CMS 2.9.2 - Persistent Cross Site Scripting Issue Details ============= Product: Contao CMS 2.9.2 Security-Risk: moderated Remote-Exploit: yes Vendor-URL: http://www.contao.org/ Advisory-Status: published Credits ============= Discovered by: David Vieira-Kurz Affected [ more ] [ reply ] [USN-1042-2] PHP5 regression 2011-01-13 Steve Beattie (sbeattie ubuntu com) =========================================================== Ubuntu Security Notice USN-1042-2 January 13, 2011 php5 regression https://launchpad.net/bugs/701765 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 [ more ] [ reply ] [security bulletin] HPSBMA02624 SSRT100195 rev.1 - HP LoadRunner, Remote Execution of Arbitrary Code 2011-01-13 security-alert hp com -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c02680678 Version: 1 HPSBMA02624 SSRT100195 rev.1 - HP LoadRunner, Remote Execution of Arbitrary Code NOTICE: The information in this Security Bulletin should be acted upon as soon as possible. [ more ] [ reply ] |
|
Privacy Statement |
Ubuntu Security Notice USN-1044-1 January 18, 2011
dbus vulnerability
CVE-2010-4352
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.04 LTS
Ubuntu 9.10
U
[ more ] [ reply ]