|
Colapse all |
Post message
ASP-rider is vulnerable to sql injection attack 2004-12-15 shervin khaleghjou (oil_karchack yahoo com) iDEFENSE Security Advisory 12.14.04 - Microsoft Word 6.0/95 Document Converter Buffer Overflow Vulnerability 2004-12-14 customer service mailbox (customerservice idefense com) Microsoft Word 6.0/95 Document Converter Buffer Overflow Vulnerability iDEFENSE Security Advisory 12.14.04 www.idefense.com/application/poi/display?id=162&type=vulnerabilities December 14, 2004 I. BACKGROUND WordPad is a word processing application that uses the MFC rich edit control classes. I [ more ] [ reply ] [CAN-2004-1023] Insecure default file system permissions on Microsoft versions of Kerio Software 2004-12-14 Secure Computer Group (scg udc es) MDKSA-2004:149 - Updated postgresql packages fix temporary file vulnerability 2004-12-14 Mandrake Linux Security Team (security linux-mandrake com) [SECURITY] [DSA 608-1] New zgv packages fix arbitrary code execution 2004-12-14 joey infodrom org (Martin Schulze) RICOH Aficio 450/455 PCL 5e Printer ICMP DOS vulnerability 2004-12-14 Hongzhen Zhou (felix__zhou hotmail com) [CAN-2004-1022] Insecure Credential Storage on Kerio Software 2004-12-14 Secure Computer Group (scg udc es) [ GLSA 200412-08 ] nfs-utils: Multiple remote vulnerabilities 2004-12-14 Luke Macken (lewk gentoo org) ASP Calendar Vulnerability <www.ashiyane.com> 2004-12-14 ali reza AcTiOnSpIdEr (actionspider gmail com) STG Security Advisory: [SSA-20041209-13] UseModWiki XSS vulnerability 2004-12-14 advisory stgsecurity com STG Security Advisory: [SSA-20041209-13] UseModWiki XSS vulnerability Revision 1.0 Date Published: 2004-12-09 (KST) Last Update: 2004-12-09 Disclosed by SSR Team (advisory (at) stgsecurity (dot) com [email concealed]) Summary ======== UseModWiki is one of famous wiki web applications. It has a cross-site scripti [ more ] [ reply ] [SECURITY] [DSA 609-1] New atari800 packages fix local root exploit 2004-12-14 joey infodrom org (Martin Schulze) MDKSA-2004:148 - Updated iproute2 packages fix temporary file vulnerability 2004-12-14 Mandrake Linux Security Team (security linux-mandrake com) iDEFENSE Security Advisory 12.14.04 - Adobe Acrobat Reader 5.0.9 mailListIsPdf() Buffer Overflow Vulnerability 2004-12-14 customer service mailbox (customerservice idefense com) Adobe Acrobat Reader 5.0.9 mailListIsPdf() Buffer Overflow Vulnerability iDEFENSE Security Advisory 12.14.04 www.idefense.com/application/poi/display?id=161&type=vulnerabilities December 14, 2004 I. BACKGROUND Adobe Acrobat Reader is a program for viewing Portable Document Format (PDF) documents. [ more ] [ reply ] [ZH2004-18SA] Content-Type spoofing in Mozilla Firefox and Opera could allow users to bypass security restrictions 2004-12-13 Giovanni Delvecchio (badpenguin79 hotmail com) Author: Giovanni Delvecchio e-mail: badpenguin (at) zone-h (dot) org [email concealed] Original advisory: http://www.zone-h.org/en/advisories/read/id=6502/ Browsers tested: - Firefox 1.0 - Mozilla 1.7.x - Opera 7.54 (*) - Konqueror 3.3.1 - Epiphany -Internet Explorer 6 with SP1 -Internet Explorer 6 with SP1 [ more ] [ reply ] Re: Secure Network Operations SNOsoft Research Team [SRT2004-12-14-0322] Symantec LiveUpdate Advisory 2004-12-13 secure symantec com In-Reply-To: <20041213213212.23F5F4F563 (at) beast.secnetops (dot) com [email concealed]> <full-disclosure (at) lists.netsys (dot) com [email concealed]> >Subject: Secure Network Operations SNOsoft Research Team [SRT2004-12-14-0322] Symantec LiveUpdate Advisory >Date: Mon, 13 Dec 2004 16:28:34 -0500 >Organization: Secure Network Operations, Inc. --- [ more ] [ reply ] Possible local root vulnerability in Roxio Toast on Mac OS X 2004-12-14 fintler (fintler gmail com) Possible local root vulnerability in Roxio Toast on Mac OS X By fintler <fintler (at) gmail (dot) com [email concealed]> Summary: There is a format string bug in the binary (/Library/Application Support/Roxio/TDIXSupport). It is installed suid root by default and may be exploited by finding the offset and overwriting the stac [ more ] [ reply ] phpBB Attachment Mod Directory Traversal HTTP POST Injection 2004-12-14 Paul Laudanski (zx castlecops com) [//-------------------------------------------------------------------] [ CastleCops(SM) Security Advisory 14 Dec 2004 ] [---------------------------------------------------------------------] [ http://castlecops.com/ ] [----------------------------------------------------------------- [ more ] [ reply ] Secure Network Operations SNOsoft Research Team [SRT2004-12-14-0322] Symantec LiveUpdate Advisory 2004-12-13 Secure Network Operations, Inc. (advisory secnetops com) NetWare Screensaver Authentication Bypass From The Local Console 2004-12-13 Adam Gray (agray novacoast com) (1 replies) Novacoast Security Advisory Novell Netware 5/5.1/6.0/6.5 Vulnerability Synopsis: Novacoast has discovered a vulnerability in the Novell NetWare Operating System screen saver software. The vulnerability allows a local attacker to bypass authentication and access the system console. Descriptio [ more ] [ reply ] Re: NetWare Screensaver Authentication Bypass From The Local Console 2004-12-14 Brad Bendily (brad selu edu) What's "may have exploitable buffer overflows" mean in tcpdump? 2004-12-13 Dragos Ruiu (dr kyx net) WARNING: The SMB printer may have exploitable buffer overflows!!! That's what the ./configure script on tcpdump-current warns me about (re SMB printer). What exactly does this warning message mean? If there are overflows, they should be fixed. If they are unfixed the code should be removed. If th [ more ] [ reply ] Winamp 5.07 (latest version) Remote Crash + other stupid shizle 2004-12-13 b0f www.b0f.net (b0fnet yahoo com) [ZH2004-19SA] Possible execution of remote shell commands in Opera with kfmclien 2004-12-13 Giovanni Delvecchio (badpenguin79 hotmail com) Author: Giovanni Delvecchio e-mail: badpenguin (at) zone-h (dot) org [email concealed] Original Advisory: http://www.zone-h.org/advisories/read/id=6503 Tested version: Opera 7.54 linux version with Kde 3.2.3 Problem: ======= Opera for linux uses "kfmclient exec" as "Default Application" to handle saved files. This could be [ more ] [ reply ] |
|
Privacy Statement |
-------------------www.karchack.com--------------------------
-------------------www.karchack.net--------------------------
affected software decribtion :
asp-rider is a full farsi weblog written in asp
www.asp-rider.com
--------------------------------------
Vulnerabilities:
the file
[ more ] [ reply ]