BugTraq Mode:
(Page 1241 of 1748)  < Prev  1236 1237 1238 1239 1240 1241 1242 1243 1244 1245 1246  Next >
iDefense Security Advisory 12.05.05: Multiple Vendor xpdf DCTStream Progressive Heap Overflow 2005-12-06
iDEFENSE Labs (labs-no-reply idefense com)
Multiple Vendor xpdf DCTStream Progressive Heap Overflow

iDefense Security Advisory 12.05.05
www.idefense.com/application/poi/display?id=343&type=vulnerabilities
December 5, 2005

I. BACKGROUND

Xpdf is an open-source viewer for Portable Document Format (PDF) files.

II. DESCRIPTION

Local exploita

[ more ]  [ reply ]
iDefense Security Advisory 12.05.05: Multiple Vendor xpdf DCTStream Baseline Heap Overflow Vulnerability 2005-12-06
iDEFENSE Labs (labs-no-reply idefense com)
Multiple Vendor xpdf DCTStream Baseline Heap Overflow Vulnerability

iDefense Security Advisory 12.05.05
www.idefense.com/application/poi/display?id=342&type=vulnerabilities
December 5, 2005

I. BACKGROUND

Xpdf is an open-source viewer for Portable Document Format (PDF) files.

II. DESCRIPTION

Loc

[ more ]  [ reply ]
Horde IMP Webmail Client XSS all versions 2005-12-06
Igor (sprog online ru)
Hello All,

PRELUDE
What is HORDE?
http://www.horde.org/about/
The Mission
The Horde Project is about creating high quality Open Source applications, based on PHP and the Horde Framework.

The guiding principles of the Horde Project are to create solid standards-ba

[ more ]  [ reply ]
SUSE Security Announcement: kernel various security and bugfixes (SUSE-SA:2005:067) 2005-12-06
Marcus Meissner (meissner suse de)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

________________________________________________________________________
______

SUSE Security Announcement

Package: kernel
Announcement ID: SUSE-SA:2005:067
Date:

[ more ]  [ reply ]
Buffer Overflow in MultiTech VoIP Implementations 2005-12-05
SecurityLab Research (SLAB_research securitylab net)
SecurityLab Technologies, Inc.
--- www.securitylab.net ---

Security Advisory
Advisory Name: Buffer Overflow in MultiTech VoIP Implementations
Release Date: December 05, 2005
Application: MultiVoIP Gateway
Platform: Multiple
Severity: Moderate
Author: Ejovi Nuwere <SLAB_research[AT

[ more ]  [ reply ]
Outpost24 Public Security Note: Linux/Elxbot 2005-12-05
David Jacoby (security outpost24 com)

_______ __ __ ______ _____
| |.--.--.| |_ .-----..-----..-----.| |_ |__ || | |
| - || | || _|| _ || _ ||__ --|| _|| __||__ |
|_______||_____||____|| __||_____||_____||____||______| |__|
Public Security Note |__| http://w

[ more ]  [ reply ]
Blog System v1.2 Multiple SQL Injection Vulnerabilities 2005-12-05
vipsta gmail com
Blog System v1.2 (http://www.netartmedia.net/blogsystem/)
is vulnerable to 2 SQL injection vulnerabilities for failure to correctly sanitize SQL parameters.

http://[HOST]/index.php?mode=home&cat=-99[SQL CODE]

http://[HOST]/blog.php?user=[USER]&note=-99[SQL CODE]

[ more ]  [ reply ]
have you ever been BluePIMped? 2005-12-04
KF (lists) (kf_lists digitalmunition com)
Chapter 9 style ala Stealing the network.

enjoy...
have you ever been BluePIMped?

Exploiting The Widcomm BTStackServer by KF (kf_lists[at]digitalmunition[dot]com)

On August 12, 2004 Ryan Naraine of internetnews.com described a serious vulnerability in
Widcomm's widely deployed Bluetooth Conne

[ more ]  [ reply ]
Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers 2005-01-06
David Litchfield (davidl ngssoftware com)
Dear security community and Oracle users,
Many of my customers run Oracle. Much of the U.K. Critical National
Infrastructure relies on Oracle; indeed this is true for many other
countries as well. I know that there's a lot of private information about me
stored in Oracle databases out there. I have

[ more ]  [ reply ]
[USN-180-2] MySQL 4.1 vulnerability 2005-12-05
Martin Pitt (martin pitt canonical com)
===========================================================
Ubuntu Security Notice USN-180-2 December 05, 2005
mysql-dfsg-4.1 vulnerability
CVE-2005-2558
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 5.10 (Breezy Badger

[ more ]  [ reply ]
[USN-223-1] Inkscape vulnerability 2005-12-05
Martin Pitt (martin pitt canonical com)
===========================================================
Ubuntu Security Notice USN-223-1 December 05, 2005
inkscape vulnerability
CVE-2005-3885
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 5.04 (Hoary Hedgehog)

Th

[ more ]  [ reply ]
[scip_Advisory] e107 v0.6 rate.php manipulation 2005-12-05
Marc Ruef (maru scip ch)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

e107 v0.6 rate.php voting manipulation and forwarding vulnerability

scip AG Vulnerability Advisory (11/10/2005)
http://www.scip.ch

I. INTRODUCTION

e107 is the name of an open-source content management system (cms) that
relies on php and sql.

More

[ more ]  [ reply ]
[security bulletin] HPSBUX01059 SSRT4704 Revised - HP-UX Running wu-ftpd Local Unauthorized Access 2005-12-05
security-alert hp com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c00572225
Version: 3

HPSBUX01059 SSRT4704 Revised - HP-UX Running wu-ftpd Local
Unauthorized Access

NOTICE: The information in this Security Bulletin should be acted
upon as soon as possible.

Re

[ more ]  [ reply ]
eXtreme Styles mod <= 2.2.1 Multiple Vulnerabilities 2005-12-03
tommie1 adelphia net
eXtreme Styles mod <= 2.2.1 Multiple Vulnerabilities
====================================================
http://www.phpbbstyles.com/

Description
===========
These vulnerabilities could allow an attacker that has gained
administrative access view file content on the system.

1. Remote File Content

[ more ]  [ reply ]
Zen-Cart <= 1.2.6d blind SQL injection / remote commands execution: 2005-12-02
retrogod aliceposta it
Zen-Cart <= 1.2.6d blind SQL injection / remote commands execution:

software:
site: http://www.zencart.com/
description:"Zen Cart? truly is the art of e-commerce; a free, user-friendly,
open source shopping cart system. The software is being developed
by group of like

[ more ]  [ reply ]
more MD5 colliding examples 2005-12-02
Gerardo Richarte (gera corest com)
hello everybody, last month we presented in a lightning talk at PacSec
a few interesting and somehow new things related to MD5 collisions: 2
different Win32 .EXE files with the same MD5 hash, and 4 different files
(inputs) with the same MD5 hash.

These are direct results of reimplementing the alr

[ more ]  [ reply ]
[Updated] [FLSA-2005:166943] Updated php packages fix security issues 2005-12-03
Marc Deslauriers (marcdeslauriers videotron ca)
---------------------------------------------------------------------
Fedora Legacy Update Advisory

Synopsis: Updated php packages fix security issues
Advisory ID: FLSA:166943
Issue date: 2005-12-02
Product: Red Hat Linux, Fedora Core
Keywords:

[ more ]  [ reply ]
QNX 4.25 suided dhcp.client binary 2005-12-03
lms fe up pt
Hello all,

I recently got a QNX 4.25 vmware image and i found that the dhcp.client shipped
with it is suided.

This obviously enables a normal user to control the NIC's configuration and
produce some other attacks (eg: if the system has some services which depend on
'host/ip based' authentication [

[ more ]  [ reply ]
PHP-Fusion v6.00.109 SQL Injection and Info. Disclosure 2005-12-03
xer0x west gmail com
In the latest version of PHP-Fusion, the content management system by Digitanium (php-fusion.co.uk), there is an SQL Error in messages.php that reveals path names and a table name, and someone could possibly manipulate the SQL database.
The error is as follows, it is with the Search and Sort option:

[ more ]  [ reply ]
MDKSA-2005:222 - Updated mailman packages fix various vulnerabilities 2005-12-02
Mandriva Security Team (security mandriva com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDKSA-2005:222
http://www.mandriva.com/security/
_____________________________________________________________________

[ more ]  [ reply ]
Alisveristr E-Commerce Admin Login SQL İnjection 2005-12-03
B3g0k hackermail com
###Hi all
###B3g0k[at]hackermail.com
###Kurdish Hacker
###Special Thanx All Kurdish Hackers
###Freedom For Ocalan!!!
###-----------------------------------
###Alisveristr E-commerce User Login Sql İnjection
###Alisveristr E-commerce Admin Login Sql ###İnjection
###-------------------------

[ more ]  [ reply ]
Re: WebCalendar 2005-12-03
Louis Wang (bill louis gmail com)
Hi, Dan:

For some vulnerability has fixed by the vendor, I have update this
vulnerability advisory, sorry for any trouble I have caused to you.

The following is the updated advisory.:

===================================================
WebCalendar CRLF Injection Vulnerability

I. BACKGROUND
WebC

[ more ]  [ reply ]
eXtreme Styles mod <= 2.2.1 Multiple Vulnerabilities 2005-12-03
tommie1 adelphia net
Site: http://www.phpbbstyles.com/

1. Remote File Content Disclosure
http://forum/admin/xs_edit.php?edit=../../../../etc/passwd

2. Full Path Disclosure
http://forum/admin/xs_edit.php?edit=&viewbackup=1

http://wtf.bz/

[ more ]  [ reply ]
MDKSA-2005:221 - Updated spamassassin packages fixes vulnerability 2005-12-02
Mandriva Security Team (security mandriva com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDKSA-2005:221
http://www.mandriva.com/security/
_____________________________________________________________________

[ more ]  [ reply ]
Re: Re: Microsoft Windows CreateRemoteThread Exploit 2005-12-03
warl0ck linuxmail org
You are a bit wrong q7x some firewalls
and security programs will stop you from
calling that function(and some others like that), for example the Tiny
Personal Firewall.

[ more ]  [ reply ]
[OpenPKG-SA-2005.026] OpenPKG Security Advisory (lynx) 2005-12-03
OpenPKG (openpkg openpkg org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

________________________________________________________________________

OpenPKG Security Advisory The OpenPKG Project
http://www.openpkg.org/security.html http://www.openpkg.org
openpkg-security (at) openpkg (dot) org [email concealed]

[ more ]  [ reply ]
[OpenPKG-SA-2005.027] OpenPKG Security Advisory (php) 2005-12-03
OpenPKG (openpkg openpkg org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

________________________________________________________________________

OpenPKG Security Advisory The OpenPKG Project
http://www.openpkg.org/security.html http://www.openpkg.org
openpkg-security (at) openpkg (dot) org [email concealed]

[ more ]  [ reply ]
MDKSA-2005:223 - Updated webmin package fixes format string vulnerability 2005-12-02
Mandriva Security Team (security mandriva com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDKSA-2005:223
http://www.mandriva.com/security/
_____________________________________________________________________

[ more ]  [ reply ]
[OpenPKG-SA-2005.025] OpenPKG Security Advisory (perl) 2005-12-03
OpenPKG (openpkg openpkg org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

________________________________________________________________________

OpenPKG Security Advisory The OpenPKG Project
http://www.openpkg.org/security.html http://www.openpkg.org
openpkg-security (at) openpkg (dot) org [email concealed]

[ more ]  [ reply ]
(Page 1241 of 1748)  < Prev  1236 1237 1238 1239 1240 1241 1242 1243 1244 1245 1246  Next >


 

Privacy Statement
Copyright 2010, SecurityFocus