|
Colapse all |
Post message
Mantis Bugtracker Remote PHP Code Execution Vulnerability 2004-08-20 Jose Antonio (joxeankoret yahoo es) EXPLOIT: Qt bmp heap overflow 2004-08-21 infamous41md hotpop com /* * heap overflow exploit for qt bmp parsing bug * infamous42md AT hotpop DOT com * * shouts to mitakeet, MB, and peeps @hackaholic * * ok, pretty standard heap overflow here. we spill across our chunk and * overwrite the boundary tag for next chunk. the only problems i had was * f [ more ] [ reply ] MDKSA-2004:086 - Updated kdelibs and kdebase packages fix multiple vulnerabilities 2004-08-21 Mandrake Linux Security Team (security linux-mandrake com) BadBlue Webserver v2.5 Denial Of Service Vulnerability 2004-08-20 GulfTech Security (security gulftech org) ########################################################## # GulfTech Security Research August, 18th 2004 ########################################################## # Vendor : BadBlue # URL : http://www.badblue.com # Version : BadBlue Webserver v2.5 # Risk : Denial of Service ###### [ more ] [ reply ] [Fwd: Re: [vchkpw] vpopmail <= 5.4.2 (sybase vulnerability) (fwd)] 2004-08-19 Myron Davis (myrond linmail org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ---------------------------- Original Message ---------------------------- Subject: Re: [vchkpw] vpopmail <= 5.4.2 (sybase vulnerability) (fwd) From: "Tom Collins" <tom (at) tomlogic (dot) com [email concealed]> Date: Thu, August 19, 2004 9:12 am To: vchkpw (at) inter7 (dot) com [email concealed] [ more ] [ reply ] Re: First vulnerabilities in the SP2 - XP ?... 2004-08-18 Matthew Roberts (webmaster matthew1471 co uk) In-Reply-To: <200408180941.16239.radoslav.dejanovic (at) opsus (dot) hr [email concealed]> >This basically tells the user to open CMD and then execute the attachment in command line. Now, someone has to be really, really dumb to do that. People might forget that dragging and dropping to a command prompt actually executes [ more ] [ reply ] XV multiple buffer overflows, exploit included 2004-08-20 infamous41md hotpop com Program Description: xv is an interactive image manipulation program for the X Window System. It can operate on images in the GIF, JPEG, TIFF, PBM, PGM, PPM, XPM, X11 bitmap, Sun Rasterfile, Targa, RLE, RGB, BMP, PCX, FITS, and PM formats on all known types of X displays. It can generate PostScrip [ more ] [ reply ] NetBSD Security Advisory 2004-009: ftpd root escalation 2004-08-17 NetBSD Security-Officer (security-officer netbsd org) [ GLSA 200408-19 ] courier-imap: Remote Format String Vulnerability 2004-08-19 Joshua J. Berry (condordes gentoo org) (1 replies) - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200408-19 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - - [ more ] [ reply ] Re: [ GLSA 200408-19 ] courier-imap: Remote Format String Vulnerability 2004-08-21 infamous41md hotpop com Buffer overflow in sarad 2004-08-20 Matthias Bethke (Matthias Bethke gmx net) I have found several buffer overflows in the sarad program used to serve the British National Corpus (http://www.natcorp.ox.ac.uk/SARA/). At least one (I didn't check the others too closely) allows execution of arbitrary code over the network with the rights of the daemon which is supposed to be a d [ more ] [ reply ] RE: Driver for display goes to a infinite loop by viewing a html! 2004-08-16 Christopher Wagner (chrisw pacaids com) In the interest of yet more completeness, I tested this on a few different machines here at my office, here are the results: Test image was 10000000px by 10000000px - ~11kb in size It appears as all black in Mozilla of any version/platform/arch I tried. Mozilla Firefox 0.9.3 operates slowly (not [ more ] [ reply ] Xines_Mine.c Open Security Group Advisory 2004-08-17 c0ntex open-security org /* ************************************************************************ ***************************************** $ An open security advisory #6 - Xine vcd MRL input identifier management overflow ************************************************************************ ****************** [ more ] [ reply ] |
|
Privacy Statement |
------------------------------------------------------------------------
---
Mantis Bugtracker Remote PHP Code
Execution Vulnerability
------------------------------------------------------------------------
---
Author: Joxean Koret
Date: 08-01-2004
Location: Basque Country
[ more ] [ reply ]