|
Colapse all |
Post message
[USN-186-2] Ubuntu 4.10 packages for USN-186-1 Firefox security update 2005-09-25 Martin Pitt (martin pitt canonical com) [ GLSA 200509-18 ] Qt: Buffer overflow in the included zlib library 2005-09-26 Sune Kloppenborg Jeppesen (jaervosz gentoo org) SUSE Security Announcement: XFree86-server,xorg-x11-server (SUSE-SA:2005:056) 2005-09-26 Thomas Biege (thomas suse de) FL Studio 5 (.flp file processing) Heap Overflow 2005-09-26 varunuppal linuxmail org Release Date:-- 26th September 2005 Severity:-- High (Arbitrary Code Execution) Vendor:-- Image-Line Software Vendor Status:-- Vendor Contacted --- No Response Systems Affected:-- Fl Studio v5.0.1 (Confirmed) Vulnerability may also exist in previous and current versions Background:-- FL Studi [ more ] [ reply ] Server crash and motd deletion in MultiTheftAuto 0.5 patch 1 2005-09-25 Luigi Auriemma (aluigi autistici org) [USN-186-1] Mozilla and Firefox vulnerabilities 2005-09-23 Martin Pitt (martin pitt canonical com) =========================================================== Ubuntu Security Notice USN-186-1 September 23, 2005 mozilla, mozilla-firefox vulnerabilities CAN-2005-2968, MFSA-2005-58 =========================================================== A security issue affects the following Ubuntu releases: [ more ] [ reply ] [ GLSA 200509-16 ] Mantis: XSS and SQL injection vulnerabilities 2005-09-24 Thierry Carrez (koon gentoo org) [SECURITY] [DSA 817-1] New python2.2 packages fix arbitrary code execution 2005-09-22 joey infodrom org [ GLSA 200509-17 ] Webmin, Usermin: Remote code execution through PAM authentication 2005-09-24 Thierry Carrez (koon gentoo org) My Little Forum 1.5 / 1.6beta SQL Injection 2005-09-22 retrogod aliceposta it My Little Forum 1.5 / 1.6beta SQL Injection software: site: http://www.mylittlehomepage.net/my_little_forum software: "A simple web-forum that supports classical thread view (message tree) as well as messagebord view to display the messages. Requires PHP > 4.1 and a MySQL database." 1) look at th [ more ] [ reply ] Hijacking Bluetooth Headsets for Fun and Profit? 2005-09-23 KF (lists) (kf_lists digitalmunition com) MailGust 1.9 SQL Injection 2005-09-24 retrogod aliceposta it MailGust 1.9 SQL injection / board takevor software: site: http://www.mailgust.org/ description: Mailgust is three softwares in one: * Mailing list manager * Newsletter distribution tool * Message Board Mailgust is written in php and uses a mysql database. vulnerability: if magic quotes off [ more ] [ reply ] "Exploiting the XmlHttpRequest object in IE" - paper by Amit Klein 2005-09-24 Amit Klein (AKsecurity) (aksecurity hotpop com) AlstraSoft E-Friends Remote Command Exucetion 2005-09-24 khc bsdmail org AlstraSoft E-Friends Remote command exucetion Site : http://www.alstrasoft.com/efriends.htm Description : AlstraSoft E-Friends is an online social networking software that allows you to start your own site just like Friendster and Tribe.net. The E-Friends software allows members to connect to pe [ more ] [ reply ] [SECURITY] [DSA 820-1] New courier packages fix cross-site scripting 2005-09-24 joey infodrom org (Martin Schulze) PhpMyFAQ 1.5.1 multiple vulnerabilities 2005-09-22 retrogod aliceposta it 2.31 23/09/2005 PhpMyFaq 1.5.1 SQL injection / board takeover / user info disclosure / path disclosure remote code / commands execution software: site: http://www.phpmyfaq.de/ description: "phpMyFAQ is a multilingual, completely database-driven FAQ-system. It supports various databases to store al [ more ] [ reply ] Secunia Research: 7-Zip ARJ Archive Handling Buffer Overflow 2005-09-23 Secunia Research (vuln secunia com) [SECURITY] [DSA 819-1] New python2.1 packages fix arbitrary code execution 2005-09-23 joey infodrom org (Martin Schulze) Sql injection in jPortal version 2.3.1 (module download) 2005-09-23 krasza gmail com Versions: all from 2.2.1 to 2.3.1(+Service Pack)+shop jportal(I check this bug only on one site) SQL injection attack if magic_quotes_qpc=Off Problem is in file serching engine (download.php), witch code is in ?module/down.inc.php? file: <code> if($cat=='all') { $q_ = "AND title LIKE '%$word%'"; [ more ] [ reply ] Secunia Research: PowerArchiver ACE/ARJ Archive Handling BufferOverflow 2005-09-23 Secunia Research (vuln secunia com) [scip_Advisory 1746] Microsoft Internet Explorer 6.0 embedded content cross site scripting 2005-09-22 Marc Ruef (maru scip ch) (1 replies) Microsoft Internet Explorer 6.0 embedded content cross site scripting scip AG Vulnerability ID 1746 (09/22/2005) http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=1746 I. INTRODUCTION Microsoft Internet Explorer is since many years the most popular web browser. The main reason for this popularity is [ more ] [ reply ] Re: [Full-disclosure] [scip_Advisory 1746] Microsoft Internet Explorer 6.0 embedded content cross site scripting 2005-09-22 Brion Vibber (brion pobox com) [security bulletin] SSRT5998 Rev.2 HP System Management Homepage (v2.0.x) Denial of Service (DoS) and XSS 2005-09-22 security-alert hp com Hack Dot AE v2 2005-09-22 SpyHat SpyHat com Dear All, On our anniversary Hack Dot AE renew the worldwide Hacking Contest and invite you all to a new challenge. The first contest attracted huge interest from challengers from all over the world. This year contest is similarly constructed of 7 different levels which are more advanced and divers [ more ] [ reply ] My Little Forum 1.5 / 1.6beta SQL Injection 2005-09-22 retrogod aliceposta it My Little Forum 1.5 / 1.6beta SQL Injection software: site: http://www.mylittlehomepage.net/my_little_forum software: "A simple web-forum that supports classical thread view (message tree) as well as messagebord view to display the messages. Requires PHP > 4.1 and a MySQL database." 1) look at th [ more ] [ reply ] [SECURITY] [DSA 817-1] New python2.2 packages fix arbitrary code execution 2005-09-22 joey infodrom org (Martin Schulze) HTTP Request Smuggling - ERRATA (the IIS 48K buffer phenomenon) 2005-09-22 Amit Klein (AKsecurity) (aksecurity hotpop com) Hi With respect to the IIS/5.0 48K "bug" (see "HTTP Request Smuggling", http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf, pages 6-7 or 4-5), Noam Ben-Yochanan commented that IIS/5.x provides with the programmer with a way to consume the request body (beyond the 48K usually read), thu [ more ] [ reply ] |
|
Privacy Statement |
Ubuntu Security Notice USN-186-2 September 25, 2005
mozilla-firefox vulnerabilities
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 4.10 (Warty Warthog)
The foll
[ more ] [ reply ]