BugTraq Mode:
(Page 897 of 1748)  < Prev  892 893 894 895 896 897 898 899 900 901 902  Next >
iDefense Security Advisory 07.11.07: Symantec AntiVirus symtdi.sys Local Privilege Escalation Vulnerability 2007-07-11
iDefense Labs (labs-no-reply idefense com)
Symantec AntiVirus symtdi.sys Local Privilege Escalation Vulnerability

iDefense Security Advisory 07.11.07
http://labs.idefense.com/intelligence/vulnerabilities/
Jul 11, 2007

I. BACKGROUND

Symantec has a wide range of Anti-Virus and Internet Security products
that are designed to protect users fr

[ more ]  [ reply ]
iDefense Security Advisory 07.11.07: Symantec Backup Exec RPC Remote Heap Overflow Vulnerability 2007-07-11
iDefense Labs (labs-no-reply idefense com)
Symantec Backup Exec RPC Remote Heap Overflow Vulnerability

iDefense Security Advisory 07.11.07
http://labs.idefense.com/intelligence/vulnerabilities/
Jul 11, 2007

I. BACKGROUND

Symantec Backup Exec is a data recovery solution. It provides backup
services and includes agents that provide protecti

[ more ]  [ reply ]
Re: [Full-disclosure] iDefense Security Advisory 07.09.07: WinPcap NPF.SYS Local Privilege Escalation Vulnerability 2007-07-11
KJK::Hyperion (hackbunny s0ftpj org)
iDefense Labs wrote:
> WinPcap NPF.SYS Local Privilege Escalation Vulnerability
>
> iDefense Security Advisory 07.09.07
> http://labs.idefense.com/intelligence/vulnerabilities/
> Jul 09, 2007
>
> I. BACKGROUND
>
> WinPcap is a software package that facilitates real-time link-level
> network access f

[ more ]  [ reply ]
Dotclear remote script execution 2007-07-11
Sacha (digimag gmail com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello,

There is a French website about two vulnerabilities ; the one works on
Wordpress (27/05/2007) and the other on Dotclear (08/07/2007) :

http://ar3av.free.fr/sommaire.php

If a Dotclear blog administrator is logged in (or has a cookie for
automa

[ more ]  [ reply ]
Cisco Security Advisory: Cisco Unified Communications Manager and Presence Server Unauthorized Access Vulnerabilities 2007-07-11
Cisco Systems Product Security Incident Response Team (psirt cisco com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Cisco Security Advisory: Cisco Unified Communications Manager and
Presence Server Unauthorized Access Vulnerabilities

Document ID: 97060

Advisory ID: cisco-sa-20070711-voip

http://www.cisco.com/warp/public/707/cisco-sa-20070711-voip.shtml

Revision 1

[ more ]  [ reply ]
Cisco Security Advisory: Cisco Unified Communications Manager Overflow Vulnerabilities 2007-07-11
Cisco Systems Product Security Incident Response Team (psirt cisco com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Cisco Security Advisory: Cisco Unified Communications Manager
Overflow Vulnerabilities

Document ID: 92015

Advisory ID: cisco-sa-20070711-cucm

http://www.cisco.com/warp/public/707/cisco-sa-20070711-cucm.shtml

Revision 1.0

For Public Release 2007 Jul

[ more ]  [ reply ]
Re: Advisory - Clam AntiVirus RAR File Handling Denial Of Service Vulnerability. 2007-07-11
Metaeye SG (contact metaeye org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Noam Rathaus wrote:
> Hi,
>
> The vulnerability also affects unrar (3.70 beta 3 freeware by Alexander
> Roshal), as it tries to read a negative location from a pointer reference in
> the SET_VALUE(false,Data,Addr-Offset) function (found in rarvm.cp

[ more ]  [ reply ]
Powered By Dvbbs Version 7.1.0 Sp1 By Pass 2007-07-11
RaeD BsdMail Com
By : Hasadya Raed
Contact : Raed (at) BsdMail (dot) Com [email concealed]
Israel
--------------------------
Script : Dvbbs Version 7.1.0 Sp1
Dork : "Powered By Dvbbs Version 7.1.0 Sp1"
--------------------------
Exploit :
http://www.victim.com/Data/Dvbbs7.mdb

[ more ]  [ reply ]
Re: Advisory - Clam AntiVirus RAR File Handling Denial Of Service Vulnerability. 2007-07-11
Noam Rathaus (noamr beyondsecurity com)
Hi,

The vulnerability also affects unrar (3.70 beta 3 freeware by Alexander
Roshal), as it tries to read a negative location from a pointer reference in
the SET_VALUE(false,Data,Addr-Offset) function (found in rarvm.cpp).

The values of Addr is 1666528 while Offset is 4546004 which of course resu

[ more ]  [ reply ]
Advisory - Clam AntiVirus RAR File Handling Denial Of Service Vulnerability. 2007-07-11
Metaeye SG (contact metaeye org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Vendor
- ------
Clam Antivirus (http://www.clamav.net)

Product
- -------
Clamav (libclamav)

Versions Affected
- -----------------
All before 0.91

Severity
- --------
Moderate

Issue
- -----
Clamav crashes due to processing of standard filters in RAR

[ more ]  [ reply ]
SquirrelMail G/PGP Encryption Plug-in Remote Command Execution Vulnerability 2007-07-11
does_not_exist jmp-esp kicks-ass net
SquirrelMail G/PGP Encryption Plug-in Remote Command Execution Vulnerability

Bugtraq ID: 24782

-----------------------------

There are various vulnerabilities in this software! One is in keyring_main.php!
$fpr is not escaped from shellcommands!

testbox:/home/w00t# cat /tmp/w00t
cat: /tmp/w00t: N

[ more ]  [ reply ]
rPSA-2007-0137-1 tshark wireshark 2007-07-11
rPath Update Announcements (announce-noreply rpath com)
rPath Security Advisory: 2007-0137-1
Published: 2007-07-11
Products: rPath Linux 1
Rating: Major
Exposure Level Classification:
Indirect User Deterministic Denial of Service
Updated Versions:
tshark=/conary.rpath.com@rpl:devel//1/0.99.6-0.1-1
wireshark=/conary.rpath.com@rpl:devel//1/0.99

[ more ]  [ reply ]
Advisory: Arbitrary kernel mode memory writes in AVG 2007-07-11
john-lindsay ngssoftware com
=======
Summary
=======
Name: Arbitrary kernel mode memory writes in AVG Antivirus
Release Date: 10 July 2007
Reference: NGS00500
Discover: Jonathan Lindsay <john-lindsay ngssoftware com>
Vendor: Grisoft
Vendor Reference: N/A
Systems Affected: Windows NT based systems
Risk: High
Status: Fixed

=====

[ more ]  [ reply ]
Low Risk Vulnerability in Active Directory 2007-07-11
NGSSoftware Insight Security Research (nisr ngssoftware com)
Peter Winter-Smith of NGSSoftware has discovered a low risk vulnerability in
Active Directory which can allow an unauthenticated user to cause a denial
of service condition on any affected system.

The only affected platform is Windows 2000 with Active Directory. Windows
2003 Server is NOT affected

[ more ]  [ reply ]
[USN-482-1] OpenOffice.org vulnerability 2007-07-11
Kees Cook (kees ubuntu com)
===========================================================
Ubuntu Security Notice USN-482-1 July 10, 2007
openoffice.org(2)/-amd64 vulnerability
CVE-2007-0245
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6

[ more ]  [ reply ]
SUN Java JNLP Overflow 2007-07-11
Brett Moore (brett moore security-assessment com)
========================================================================

= SUN Java JNLP Overflow
=
= Vendor Advisory:
= http://sunsolve.sun.com/search/document.do?assetkey=1-26-102996-1
=
= Affected Software:
= Java Web Start in JDK and JRE 6 Update 1 and earlier
= Java Web Start in JDK

[ more ]  [ reply ]
durito: enVivo!CMS SQL injection 2007-07-11
3APA3A (3APA3A SECURITY NNOV RU)
Dear bugtraq (at) securityfocus (dot) com [email concealed],

durito [damagelab] -durito[at]mail[dot]ru- reported SQL injection
vulnerability in enVivo!CMS through ID parameter of default.asp.

Example:

http://www.example.com/default.asp?action=article&ID=-1+or+1=(SELECT+TOP
+1+username+from+users)--

Original me

[ more ]  [ reply ]
[ MDKSA-2007:145 ] - Updated wireshark packages fix multiple vulnerabilities 2007-07-11
security mandriva com

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDKSA-2007:145
http://www.mandriva.com/security/
____________________________________________________________________

[ more ]  [ reply ]
XSS Tunnelling White Paper and Tool 2007-07-10
Ferruh Mavituna (ferruh mavituna com)
XSS Tunnelling is the tunnelling of HTTP traffic through an opened XSS
Channel. Thus any application with HTTP proxy support can tunnel its
traffic through an XSS Channel (a channel opened by a tool like XSS
Shell).

White paper is explaining XSS Tunnelling, benefits, real worlds
examples and basic

[ more ]  [ reply ]
TippingPoint IPS Signature Evasion 2007-07-10
Paul Craig (paul craig security-assessment com)
========================================================================

= TippingPoint IPS Signature Evasion
=
= Vendor Website:
= http://www.tippingpoint.com
=
= Affected Version:
= TippingPoint IPS running TOS versions 2.1 & 2.2.0 - 2.2.4
=
= Vendor Notified. 18th January 2006
= Public Disc

[ more ]  [ reply ]
Re: Re: [Eleytt] 7LIPIEC2007 2007-07-10
gynvael coldwind pl
Michal Zalewski wrote:
>> 1. Firefox 2.0.0.4 Remote Denial of Service Vulnerability
>> http://sapheal.hack.pl/phun/ff2die/
>This does not crash on me, and I can't see a likely mechanism of action
>that would lead to a DoS condition.

It did hang Firefox 2.0.0.4 (32 bit) at my place (Microsoft Vista

[ more ]  [ reply ]
EEYE: Microsoft Publisher 2007 Arbitrary Pointer Dereference 2007-07-10
eEye Advisories (Advisories eeye com)
Microsoft Publisher 2007 Arbitrary Pointer Dereference

Release Date:
July 10, 2007

Date Reported:
February 16, 2007

Severity:
High (Remote Code Execution)

Vendor:
Microsoft

Vendor Software Affected:
Microsoft Office 2007 Small Business
Microsoft Office 2007 Professional
Microsoft Office 2007 Ul

[ more ]  [ reply ]
Multiple .NET Null Byte Injection Vulnerabilities 2007-07-10
Paul Craig (paul craig security-assessment com)
========================================================================

= Multiple .NET Null Byte Injection Vulnerabilities
=
= Vendor Website:
= http://www.microsoft.com
=
= Affected Version:
= .NET FrameWork v1.1 SP1
= .NET FrameWork v2.0.50727
=
= Vendor Notified - October, 2006
= Publi

[ more ]  [ reply ]
Re: Re: WinPcap NPF.SYS Privilege Elevation Vulnerability 2007-07-10
mballano gmail com
Hello Gianluca,

You are right, i'm so sorry about my "bug", i'm updating the advisory right now in order to fix it. The latest affected version is 4.0 as you said.

Updated advisory at :

http://www.48bits.com/exploits/npfxpl.c

Kind regards,

Mario Ballano

[ more ]  [ reply ]
[ MDKSA-2007:144 ] - Updated OpenOffice.org packages fix RTF import vulnerability 2007-07-10
security mandriva com

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDKSA-2007:144
http://www.mandriva.com/security/
____________________________________________________________________

[ more ]  [ reply ]
Re: WinPcap NPF.SYS Privilege Elevation Vulnerability 2007-07-10
Gerald Combs (gerald wireshark org)
mballano (at) gmail (dot) com [email concealed] wrote:
> WinPcap NPF.SYS Privilege Elevation Vulnerability PoC exploit
> -------------------------------------------------------------
>
> Affected software:
>
> (*) WinPcap versions affected (Confirmed)
>
> - WinPcap 3.1
> - WinPcap 4.1
^^^^^^^^^^^

Can you c

[ more ]  [ reply ]
Re: Whitepaper - DNS pinning and web proxies 2007-07-10
Amit Klein (aksecurity gmail com)
Hello

The statements below, as well as on the paper itself ("So far,
discussion has focused solely on browser issues and has ignored the
fact that web proxies are also vulnerable to the same attacks.") are
somewhat inaccurate.

Please look at the following BugTraq posting submitted July 29th, 2002

[ more ]  [ reply ]
SYMSA-2007-005: Vista Windows Firewall Incorrectly Applies Filtering to Teredo Interface 2007-07-09
research symantec com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Symantec Vulnerability Research
http://www.symantec.com/research
Security Advisory

Advisory ID: SYMSA-2007-005
Advisory Title: Vista Windows Firewall Incorrectly Applies

[ more ]  [ reply ]
iDefense Security Advisory 07.09.07: IBM AIX libodm ODMPATH Stack Overflow Vulnerability 2007-07-10
iDefense Labs (labs-no-reply idefense com)
IBM AIX libodm ODMPATH Stack Overflow Vulnerability

iDefense Security Advisory 07.09.07
http://labs.idefense.com/intelligence/vulnerabilities/
Jul 09, 2007

I. BACKGROUND

AIX applications use libodm to access system settings and device
configuration data stored in the Object Database Manager. The

[ more ]  [ reply ]
Whitepaper - DNS pinning and web proxies 2007-07-10
Dafydd Stuttard (daf ngssoftware com)
DNS-based attacks against browsers have been known about for years. These
attacks have received increased attention recently, following the discovery
of defects within browser-based DNS pinning defences.

So far, discussion has focused on browser issues. However, the same attacks
can also be perform

[ more ]  [ reply ]
(Page 897 of 1748)  < Prev  892 893 894 895 896 897 898 899 900 901 902  Next >


 

Privacy Statement
Copyright 2010, SecurityFocus