|
Colapse all |
Post message
PHP Event Calendar Multiple Parameter Cross Site Scripting Vulnerability 2006-09-13 OS2A BTO (os2a bto gmail com) [SECURITY] [DSA 1175-1] New isakmpd packages fix replay protection bypass 2006-09-13 joey infodrom org (Martin Schulze) [EEYEB-20080824] Internet Explorer Compressed Content URL Heap Overflow Vulnerability #2 2006-09-12 eEye Advisories (Advisories eeye com) Internet Explorer Compressed Content URL Heap Overflow Vulnerability #2 http://research.eeye.com/html/advisories/published/AD20060912.html Release Date: September 12, 2006 Date Reported: August 24, 2006 Severity: High (Code Execution) Systems Affected: Internet Explorer 5 SP4 with MS06-042 - Win [ more ] [ reply ] iDefense Security Advisory 09.12.06: Multiple Vendor X Server CID-keyed Fonts 'CIDAFM()' Integer Overflow 2006-09-12 iDefense Labs (labs-no-reply idefense com) Multiple Vendor X Server CID-keyed Fonts 'CIDAFM()' Integer Overflow Vulnerability iDefense Security Advisory 09.12.06 http://www.idefense.com/intelligence/vulnerabilities/ Sep 12, 2006 I. BACKGROUND The X Window System is a graphical windowing system based on a client/server model. More informat [ more ] [ reply ] iDefense Security Advisory 09.12.06: Multiple Vendor X Server CID-keyed Fonts 'scan_cidfont()' Integer Overflow Vulnerability 2006-09-12 iDefense Labs (labs-no-reply idefense com) Multiple Vendor X Server CID-keyed Fonts 'scan_cidfont()' Integer Overflow Vulnerability iDefense Security Advisory 09.12.06 http://www.idefense.com/intelligence/vulnerabilities/ Sep 12, 2006 I. BACKGROUND The X Window System is a graphical windowing system based on a client/server model. More in [ more ] [ reply ] iDefense Security Advisory 09.12.06: Apple QuickTime FLIC File Heap Overflow Vulnerability 2006-09-12 iDefense Labs (labs-no-reply idefense com) Apple QuickTime FLIC File Heap Overflow Vulnerability iDefense Security Advisory 09.12.06 http://www.idefense.com/intelligence/vulnerabilities/ Sep 12, 2006 I. BACKGROUND Quicktime is Apple's media player product used to render video and other media. For more information visit http://www.apple.c [ more ] [ reply ] Apple QuickTime H.264 Integer Overflow Vulnerability 2006-09-12 Sowhat (smaillist gmail com) Apple QuickTime H.264 Integer Overflow Vulnerability By Sowhat of Nevis Labs Date: 2006.09.12 http://www.nevisnetworks.com http://secway.org/advisory/AD20060912.txt CVE: CVE-2006-4381 Vendor: Apple Inc. Affected Versions: Apple QuickTime versions < 7.1.3 Overview: By carefully crafting a co [ more ] [ reply ] [USN-344-1] X.org vulnerabilities 2006-09-12 Martin Pitt (martin pitt canonical com) =========================================================== Ubuntu Security Notice USN-344-1 September 12, 2006 libxfont, xorg vulnerabilities CVE-2006-3739, CVE-2006-3740 =========================================================== A security issue affects the following Ubuntu releases: U [ more ] [ reply ] Computer Terrorism (UK) :: Incident Response Centre - Adobe/Macromedia Flash Player Vulnerability 2006-09-12 irc computerterrorism com Computer Terrorism (UK) :: Incident Response Centre www.computerterrorism.com Security Advisory: CT12-09-2006 ============================================================ Adobe/Macromedia Flash Player - Remote Code Execution ============================================================ [ more ] [ reply ] Computer Terrorism (UK) :: Incident Response Centre - Microsoft Publisher Font Parsing Vulnerability 2006-09-12 irc computerterrorism com Computer Terrorism (UK) :: Incident Response Centre www.computerterrorism.com Security Advisory: CT12-09-2006-2.htm ============================================== Microsoft Publisher Font Parsing Vulnerability ============================================== Advisory Date: 12th, Sept [ more ] [ reply ] Apple QuickTime Player H.264 Codec Remote Integer Overflow 2006-09-12 Piotr Bania (bania piotr gmail com) Apple QuickTime Player H.264 Codec Remote Integer Overflow by Piotr Bania <bania.piotr (at) gmail (dot) com [email concealed]> http://www.piotrbania.com All rights reserved. Severity: Critical - potencial remote code execution. CVE: CVE-2006-4386 Orginal URL: http://piotrbania.com/all/adv/quicktime-integer-ove [ more ] [ reply ] ERRATA: [ GLSA 200609-05 ] OpenSSL, AMD64 x86 emulation base libraries: RSA signature forgery 2006-09-12 Sune Kloppenborg Jeppesen (jaervosz gentoo org) Session Token Remains Valid After Logout in IBM Lotus Domino Web Access 2006-09-12 dave ferguson fishnetsecurity com I. SYNOPSIS Title: Session Token Remains Valid After Logout in IBM Lotus Domino Web Access 7.0.1 Release Date: 09/12/2006 Affected Application: IBM Lotus Domino Web Access 7.0.1 (versions prior to 7.0.1 were not tested but may still be vulnerable). Nominal Severity: Low Severity If Success [ more ] [ reply ] NETGEAR Rotuer DG834GT Firmware V1.01.28 (DoS) 2006-09-12 nullflag gmail com ============= NullFlag nullflag (at) gmail (dot) com [email concealed] FROM SAUDI ARABIA ------------- Producer: NETGEAR http://www.netgear.com ============= In the login window when trying to send in the username field big amount of data (like 1000 byte) it gonna be DoSed. You need to rest the router after that. Tha [ more ] [ reply ] Newsscript version 0.5 (print.php) Local File Inclusion Vulnerability 2006-09-12 daftrix gmail com # Subject: --- "Newsscript version 0.5 (print.php) Local File Inclusion Vulnerability " # Vulnerable version: --- "Newsscript version 0.5" # Vendor URL: --- Emaill - mail (at) webmaster-journal (dot) com [email concealed] --- Website - http://webmaster-journal.com # Available in: ---http://www.coms [ more ] [ reply ] LedgerSMB 1.0.0 and SQL-Ledger 2.6.18 and earler arbitrary code execution 2006-09-12 Chris Travers (chris metatrontech com) Hi all; Summary: A directory transversal issue was found in LedgerSMB 1.0.0 involving the terminal variable. This vulnerability was inherited from the SQL-Ledger codebase. Due to the fact that SQL-Ledger has a built-in text editor, this issue could result in arbitrary code execution on the ser [ more ] [ reply ] WTools v0.0.1-ALPH - Remote File Include Vulnerabilities 2006-09-11 erne ernealizm com # ERNE ---- ERNEALiZM ---- BU ASK BiTMEZ---- # WTools v0.0.1-ALPH - Remote File Include Vulnerabilities # site : http://www.comscripts.com/jump.php?action=script&id=1880 # Script : WTools v0.0.1-ALPH # Credits : ERNE # Contact : erne (at) ernealizm (dot) com [email concealed] and irc.gigachat.net #ku [ more ] [ reply ] rPSA-2006-0167-1 xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs 2006-09-12 rPath Update Announcements (announce-noreply rpath com) rPath Security Advisory: 2006-0167-1 Published: 2006-09-12 Products: rPath Linux 1 Rating: Critical Exposure Level Classification: Local Root Deterministic Privilege Escalation Updated Versions: xorg-x11=/conary.rpath.com@rpl:devel//1/6.8.2-30.2-1 xorg-x11-fonts=/conary.rpath.com@rpl:dev [ more ] [ reply ] Sql injection in Tikiwiki 2006-09-10 Omid (omid hackers ir) Hi, There are 2 sql injections in Tikiwiki 1.9.4 (and maybe before versions) : I) There is a call to "get_process()" function in "tiki-g-admin_processes.php" file, without checking "pid" parameter : File /tiki-g-admin_processes.php, Line 35 : :: $info = $processManager->get_process($_REQUEST["pid" [ more ] [ reply ] CMS.R. the Content Management System admin authentication baypass 2006-09-11 security soqor net Hello Title : CMS.R. the Content Management System admin authentication baypass Discovered by : HACKERS PAL Copyrights : HACKERS PAL Website : WwW.SoQoR.NeT Email : security (at) soqor (dot) net [email concealed] The Vulnerability works 100% with magic_quotes_gpc = off put the user name value (' or 1=1/*) [code] [ more ] [ reply ] ShAnKaR: multiple PHP application poison NULL byte vulnerability 2006-09-11 3APA3A (3APA3A SECURITY NNOV RU) (1 replies) Author: ShAnKaR Title: multiple PHP application poison NULL byte vulnerability Applications: phpBB 2.0.21, punBB 1.2.12 Threat Level: Critical Original advisory (in Russian): http://www.security.nnov.ru/Odocument221.html Poison NULL byte vulnerability for perl CGI applications was described in [ more ] [ reply ] Re: ShAnKaR: multiple PHP application poison NULL byte vulnerability 2006-09-12 Jerome Athias (jerome athias free fr) SolpotCrew Advisory #8 - Mcgallerypro (path_to_folder) Remote File Inclusion 2006-09-10 chris_hasibuan yahoo com |
|
Privacy Statement |
SoftComplex Inc. 's PHP Event Calendar, a reusable PHP script that
extends a web site's functionality with an event scheduler or news
archive.
http://www.softcomplex.com/products/php_event_calendar/
Attached is the advisory which deta
[ more ] [ reply ]