BugTraq Mode:
(Page 1412 of 1748)  < Prev  1407 1408 1409 1410 1411 1412 1413 1414 1415 1416 1417  Next >
ASP-rider is vulnerable to sql injection attack 2004-12-15
shervin khaleghjou (oil_karchack yahoo com)


-------------------www.karchack.com--------------------------

-------------------www.karchack.net--------------------------

affected software decribtion :

asp-rider is a full farsi weblog written in asp

www.asp-rider.com

--------------------------------------

Vulnerabilities:

the file

[ more ]  [ reply ]
iDEFENSE Security Advisory 12.14.04 - Microsoft Word 6.0/95 Document Converter Buffer Overflow Vulnerability 2004-12-14
customer service mailbox (customerservice idefense com)
Microsoft Word 6.0/95 Document Converter Buffer Overflow Vulnerability

iDEFENSE Security Advisory 12.14.04
www.idefense.com/application/poi/display?id=162&type=vulnerabilities
December 14, 2004

I. BACKGROUND

WordPad is a word processing application that uses the MFC rich edit
control classes. I

[ more ]  [ reply ]
[CAN-2004-1023] Insecure default file system permissions on Microsoft versions of Kerio Software 2004-12-14
Secure Computer Group (scg udc es)
______________________________________________________________________

Secure Computer Group - University of A Coruna
http://research.tic.udc.es/scg/

-- x --

dotpi.com Information Technologies Research Labs

[ more ]  [ reply ]
MDKSA-2004:149 - Updated postgresql packages fix temporary file vulnerability 2004-12-14
Mandrake Linux Security Team (security linux-mandrake com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: postgresql
Advisory ID:

[ more ]  [ reply ]
[SECURITY] [DSA 608-1] New zgv packages fix arbitrary code execution 2004-12-14
joey infodrom org (Martin Schulze)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
--
Debian Security Advisory DSA 608-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Martin Schulze
December 14th, 2004

[ more ]  [ reply ]
RICOH Aficio 450/455 PCL 5e Printer ICMP DOS vulnerability 2004-12-14
Hongzhen Zhou (felix__zhou hotmail com)


RICOH Aficio 450/455 PCL 5e Printer ICMP DOS vulnerability

AUTHOR:

(Fortinet, inc)

Hongzhen Zhou<felix__zhou _at_ hotmail _dot_ com>

DATE:

14/12/2004

PRODUCTS:

RICOH Aficio 450/455 PCL 5e Printer(SAVIN 9945 DPE/2045 DPE)

Other RICOH Aficio products (or Toshiba printer products?)

[ more ]  [ reply ]
[CAN-2004-1022] Insecure Credential Storage on Kerio Software 2004-12-14
Secure Computer Group (scg udc es)
______________________________________________________________________

Secure Computer Group - University of A Coruna
http://research.tic.udc.es/scg/

-- x --

dotpi.com Information Technologies Research Labs

[ more ]  [ reply ]
[ GLSA 200412-08 ] nfs-utils: Multiple remote vulnerabilities 2004-12-14
Luke Macken (lewk gentoo org)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200412-08
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - -

[ more ]  [ reply ]
ASP Calendar Vulnerability <www.ashiyane.com> 2004-12-14
ali reza AcTiOnSpIdEr (actionspider gmail com)


<< www.ashiyane.com >>

Release by AcTiOnSpIdEr

AcTiOnSpIdEr (at) gmail (dot) com [email concealed]

Advisory Name: ASP Calendar Vulnerability

Release Date:13 December 2004

Platform:Any website using asp Calendar

Severity:no password protected !

Overview :

----------

[ more ]  [ reply ]
STG Security Advisory: [SSA-20041209-13] UseModWiki XSS vulnerability 2004-12-14
advisory stgsecurity com


STG Security Advisory: [SSA-20041209-13] UseModWiki XSS vulnerability

Revision 1.0

Date Published: 2004-12-09 (KST)

Last Update: 2004-12-09

Disclosed by SSR Team (advisory (at) stgsecurity (dot) com [email concealed])

Summary

========

UseModWiki is one of famous wiki web applications. It has a cross-site

scripti

[ more ]  [ reply ]
[SECURITY] [DSA 609-1] New atari800 packages fix local root exploit 2004-12-14
joey infodrom org (Martin Schulze)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
--
Debian Security Advisory DSA 609-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Martin Schulze
December 14th, 2004

[ more ]  [ reply ]
MDKSA-2004:148 - Updated iproute2 packages fix temporary file vulnerability 2004-12-14
Mandrake Linux Security Team (security linux-mandrake com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: iproute2
Advisory ID:

[ more ]  [ reply ]
iDEFENSE Security Advisory 12.14.04 - Adobe Acrobat Reader 5.0.9 mailListIsPdf() Buffer Overflow Vulnerability 2004-12-14
customer service mailbox (customerservice idefense com)
Adobe Acrobat Reader 5.0.9 mailListIsPdf() Buffer Overflow Vulnerability

iDEFENSE Security Advisory 12.14.04
www.idefense.com/application/poi/display?id=161&type=vulnerabilities
December 14, 2004

I. BACKGROUND

Adobe Acrobat Reader is a program for viewing Portable Document Format
(PDF) documents.

[ more ]  [ reply ]
[ZH2004-18SA] Content-Type spoofing in Mozilla Firefox and Opera could allow users to bypass security restrictions 2004-12-13
Giovanni Delvecchio (badpenguin79 hotmail com)


Author: Giovanni Delvecchio

e-mail: badpenguin (at) zone-h (dot) org [email concealed]

Original advisory: http://www.zone-h.org/en/advisories/read/id=6502/

Browsers tested:

- Firefox 1.0

- Mozilla 1.7.x

- Opera 7.54 (*)

- Konqueror 3.3.1

- Epiphany

-Internet Explorer 6 with SP1

-Internet Explorer 6 with SP1

[ more ]  [ reply ]
Linux kernel scm_send local DoS 2004-12-14
Paul Starzetz (ihaquer isec pl)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Synopsis: Linux kernel scm_send local DoS
Product: Linux kernel
Version: 2.4 up to and including 2.4.28, 2.6 up to and including 2.6.9
Vendor: http://www.kernel.org/
URL: http://isec.pl/vulnerabilities/isec-0019-scm.txt
CVE: CAN-200

[ more ]  [ reply ]
Re: Secure Network Operations SNOsoft Research Team [SRT2004-12-14-0322] Symantec LiveUpdate Advisory 2004-12-13
secure symantec com
In-Reply-To: <20041213213212.23F5F4F563 (at) beast.secnetops (dot) com [email concealed]>

<full-disclosure (at) lists.netsys (dot) com [email concealed]>

>Subject: Secure Network Operations SNOsoft Research Team [SRT2004-12-14-0322] Symantec LiveUpdate Advisory

>Date: Mon, 13 Dec 2004 16:28:34 -0500

>Organization: Secure Network Operations, Inc.

---

[ more ]  [ reply ]
Possible local root vulnerability in Roxio Toast on Mac OS X 2004-12-14
fintler (fintler gmail com)
Possible local root vulnerability in Roxio Toast on Mac OS X
By fintler <fintler (at) gmail (dot) com [email concealed]>

Summary:

There is a format string bug in the binary (/Library/Application
Support/Roxio/TDIXSupport). It is installed suid root by default and
may be exploited by finding the offset and overwriting the stac

[ more ]  [ reply ]
phpBB Attachment Mod Directory Traversal HTTP POST Injection 2004-12-14
Paul Laudanski (zx castlecops com)
[//-------------------------------------------------------------------]
[ CastleCops(SM) Security Advisory 14 Dec 2004 ]
[---------------------------------------------------------------------]
[ http://castlecops.com/ ]
[-----------------------------------------------------------------

[ more ]  [ reply ]
Linux kernel IGMP vulnerabilities 2004-12-14
Paul Starzetz (ihaquer isec pl)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Synopsis: Linux kernel IGMP vulnerabilities
Product: Linux kernel
Version: 2.4 up to and including 2.4.28, 2.6 up to and including 2.6.9
Vendor: http://www.kernel.org/
URL: http://isec.pl/vulnerabilities/isec-0018-igmp.txt
CVE: CAN-

[ more ]  [ reply ]
Secure Network Operations SNOsoft Research Team [SRT2004-12-14-0322] Symantec LiveUpdate Advisory 2004-12-13
Secure Network Operations, Inc. (advisory secnetops com)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Secure Network Operations, Inc.
http://www.secnetops.com/research
Strategic Reconnaissance Team
research[at]secnetops[.]com
Team Lead Contact JxT[at]secnetops[.]com
Spam Contact

[ more ]  [ reply ]
NetWare Screensaver Authentication Bypass From The Local Console 2004-12-13
Adam Gray (agray novacoast com) (1 replies)
Novacoast Security Advisory
Novell Netware 5/5.1/6.0/6.5 Vulnerability

Synopsis:
Novacoast has discovered a vulnerability in the Novell NetWare Operating
System screen saver software. The vulnerability allows a local attacker
to bypass authentication and access the system console.

Descriptio

[ more ]  [ reply ]
[ GLSA 200412-06 ] PHProjekt: setup.php vulnerability 2004-12-10
Thierry Carrez (koon gentoo org)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200412-06
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - -

[ more ]  [ reply ]
[ GLSA 200412-07 ] file: Arbitrary code execution 2004-12-13
Matthias Geerdsen (vorlon gentoo org)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200412-07
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - -

[ more ]  [ reply ]
What's "may have exploitable buffer overflows" mean in tcpdump? 2004-12-13
Dragos Ruiu (dr kyx net)
WARNING: The SMB printer may have exploitable buffer overflows!!!

That's what the ./configure script on tcpdump-current warns me about
(re SMB printer). What exactly does this warning message mean?
If there are overflows, they should be fixed. If they are unfixed the
code should be removed.

If th

[ more ]  [ reply ]
Winamp 5.07 (latest version) Remote Crash + other stupid shizle 2004-12-13
b0f www.b0f.net (b0fnet yahoo com)


Winamp 5.07 (latest version) Remote Crash.

+ vuln to cause 100% cpu usage.

13/12/04

I. BACKGROUND

Winamp is a very popular windows audio

and video player. It also has alot

of other features and is used by

millions of people across the world.

II. DESCRIPTION

VULN 1.

There

[ more ]  [ reply ]
[ZH2004-19SA] Possible execution of remote shell commands in Opera with kfmclien 2004-12-13
Giovanni Delvecchio (badpenguin79 hotmail com)
Author: Giovanni Delvecchio
e-mail: badpenguin (at) zone-h (dot) org [email concealed]

Original Advisory: http://www.zone-h.org/advisories/read/id=6503

Tested version:
Opera 7.54 linux version with Kde 3.2.3

Problem:
=======
Opera for linux uses "kfmclient exec" as "Default Application" to handle
saved files.
This could be

[ more ]  [ reply ]
(Page 1412 of 1748)  < Prev  1407 1408 1409 1410 1411 1412 1413 1414 1415 1416 1417  Next >


 

Privacy Statement
Copyright 2010, SecurityFocus