BugTraq Mode:
(Page 1574 of 1748)  < Prev  1569 1570 1571 1572 1573 1574 1575 1576 1577 1578 1579  Next >
Aardvark Topsites 4.1.0 Vulnerabilities 2003-12-16
JeiAr (security gulftech org)


Vendor : Aardvarkind

URL : http://www.aardvarkind.com

Version : Aardvark Topsites PHP 4.1.0

Risk : Multiple Vulnerabilities

Description:

Aardvark Topsites is a popular free PHP topsites script. See URL

for details.

Plaintext Database Pass Weakness:

The login info for t

[ more ]  [ reply ]
Microsoft's plans for making XP more secure 2003-12-16
Richard M. Smith (rms computerbytesman com)
Microsoft has just released a document describing the changes they will be
making in service pack 2 to make Windows XP more secure. Many of the
interesting changes are in Internet Explorer. The attached links provide
the details.

Richard M. Smith
http://www.ComputerBytesMan.com

=================

[ more ]  [ reply ]
Re: Buffer overflow/privilege escalation in MacOS X 2003-12-16
Max (rusmir tula net)
In-Reply-To: <Pine.LNX.4.58.0312151132450.13512 (at) fsj.fqfubzr (dot) arg [email concealed]>

Hi,

It seems that my original message needs some clarification.

Firstly, the demonstration quoted below does not give you a root shell. It shows that there is a segmentation fault caused by access to invalid memory region. The r

[ more ]  [ reply ]
J2EE 1.4 reference implementation: database component allows remote code execution 2003-12-16
Marc Schoenefeld (schonef uni-muenster de)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Illegalaccess.org security advisory i/12-2003 (www.illegalaccess.org)

J2EE 1.4 reference implementation: database component allows remote code
execution

Brief
=====

Product : J2EE reference implementation (java.sun.com/j2ee/download.html)
Component

[ more ]  [ reply ]
[RHSA-2003:403-01] Updated lftp packages fix security vulnerability 2003-12-16
bugzilla redhat com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ---------------------------------------------------------------------
Red Hat Security Advisory

Synopsis: Updated lftp packages fix security vulnerability
Advisory ID: RHSA-2003:403-01
Issue date: 2003-12-16
U

[ more ]  [ reply ]
Multiple DUWare Product Vulnerabilities 2003-12-15
JeiAr (security gulftech org)


Vendor : DUWare

URL : http://www.duware.com

Version : DU Portal 3.0 / Multiple DUWare Products

Risk : High / Multiple Vulnerabilities

Description:

DUportal Pro is a professional Web portal and online community. DUportal

Pro contains numerous advanced features such as Web-based

[ more ]  [ reply ]
Self-signed certs unrestricted in Windows XP 2003-12-14
Andrew Daviel (advax triumf ca)

It appears that if a self-signed (test) certificate is installed under
Windows XP, that it acquires all (or an unreasonable number of) privileges
by default.

I was testing a webserver and Java applet which I had signed with
a self-signed cert (https://andrew.triumf.ca/mterm/)

I notice that under

[ more ]  [ reply ]
Invision Power Board SQL Injection Vuln [ All Versions ] 2003-12-16
JeiAr (security gulftech org)


Vendor : Invision Power Services

URL : http://www.invisionpower.com

Version : All Versions Up To v2.0 Alpha 3

Risk : SQL Injection Vulnerability

Description:

Invision Power Board (IPB) is a professional forum system that has been

built from the ground up with speed and security

[ more ]  [ reply ]
Re: Buffer overflow/privilege escalation in MacOS X 2003-12-15
Dave G. (daveg atstake com) (1 replies)
> Date: Mon, 15 Dec 2003 11:54:02 -0800
> From: Max <rusmir (at) tula (dot) net [email concealed]>
> To: bugtraq (at) securityfocus (dot) com [email concealed]
> Subject: Buffer overflow/privilege escalation in MacOS X
>
> Hi,
>
> It appears that parts of MacOSX that didn't come from BSD are
> not very well written and have significant security issues.
>
>

[ more ]  [ reply ]
Re: Buffer overflow/privilege escalation in MacOS X 2003-12-16
Seth Arnold (sarnold wirex com)
MDKSA-2003:116 - Updated lftp packages fix buffer overflow vulnerability 2003-12-15
Mandrake Linux Security Team (security linux-mandrake com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandrake Linux Security Update Advisory
_______________________________________________________________________

Package name: lftp
Advisory ID:

[ more ]  [ reply ]
Invision Power Top Site List SQL Inection 2003-12-15
JeiAr (security gulftech org)


Vendor : Invision Power Services

URL : http://www.invisionpower.com

Version : Invision Power Top Site List v1.1 / *

Risk : SQL Injection Vulnerability

Description:

Invision Power Top Site List is a flexible site ranking script

written in PHP, the popular programming choice for w

[ more ]  [ reply ]
osCommerce 2.2-MS1 SQL Injection Vulnerability 2003-12-12
JeiAr (security gulftech org)


Vendor : osCommerce

URL : http://www.oscommerce.com

Version : osCommerce 2.2-MS1 / Older Versions?

Risk : SQL Injection Vulnerability

Description:

osCommerce is an online shop e-commerce solution under on going

development by the open source community. Its feature packed

out-o

[ more ]  [ reply ]
Issues In CGINews and CGIForum 2003-12-14
JeiAr (security gulftech org)


Vendor : Markus Triska

URL : http://triskam.virtualave.net/cginews.html

Version : 1.07 And Possible Earlier & CGIForum 1.09

Risk : Weak Encryption & Info Disclosure

Description:

CGINews is a multi-user Web site news posting system written in Perl.

Main features include: adding,

[ more ]  [ reply ]
lftp buffer overflows 2003-12-13
Härnhammar, Ulf (Ulf Harnhammar 9485 student uu se)
lftp buffer overflows
---------------------

PROGRAM: lftp
VENDOR: Alexander V. Lukyanov et al.
HOMEPAGE: http://lftp.yar.ru/
VULNERABLE VERSIONS: 2.3.0, 2.4.9, 2.6.6, 2.6.7, 2.6.8, 2.6.9,
probably all versions inbetween
IMMUNE VERSIONS: 2.6.10, older versions with my patch applied

* PROGRAM DESC

[ more ]  [ reply ]
re: Breaking the checksum (a new TCP/IP blind data injection technique) 2003-12-15
anon (anonpoet inconnu isu edu)
This is a good line of thought that needs to be re-addressed every now and
then, but I can remember discussing this exact attack ten years ago.
There's even an RFC on it. RFC 1858 if memory serves.

anonpoet
larsj [at] inel (dot) gov

[ more ]  [ reply ]
re:Breaking the checksum (a new TCP/IP blind data injection technique 2003-12-15
Michal Zalewski (lcamtuf ghettot org)
On Mon, 15 Dec 2003 LARSJ (at) inel (dot) gov [email concealed] wrote:

> This is a good line of thought that needs to be re-addressed every now
> and then, but I can remember discussing this exact attack ten years ago.
> There's even an RFC on it. RFC 1858 if memory serves.

Lars,

Nope. The set of attacks discussed in RFC1858

[ more ]  [ reply ]
Cyrus IMSP remote root vulnerability 2003-12-15
Felix Lindner (felix lindner nruns com)
________________________________________________________________________

n.runs GmbH
http://www.nruns.com/ security (at) nruns (dot) com [email concealed]
n.runs-SA-2003.001 15-Dec-2003
____________________________

[ more ]  [ reply ]
RE: SQL Injection Vuln In osCommerce 2.2-MS1 2003-12-15
JeiAr (security gulftech org)


Threw together a quick script that shop owners or admins can use to test whether or not they are vuln. Should be handy in cases where store owners are not sure what version they are running etc.

http://www.gulftech.org/vuln/ossqlin.txt

[ more ]  [ reply ]
Get admin rights using Doro (pdf creator) 2003-12-14
Ramon Kukla (ml portsonline net)
Hi,

a few days ago i discovered a bug in Doro[1]. Doro is a free tool to
create pdf files from any windows program. After installing Doro you
have a new printer called 'Doro PDF Writer'.
If you select 'Print' the spooler calls the printer filter 'doro.dll'.
The 'doro.dll' then starts 'doro.exe' and

[ more ]  [ reply ]
Buffer overflow/privilege escalation in MacOS X 2003-12-15
Max (rusmir tula net)
Hi,

It appears that parts of MacOSX that didn't come from BSD are
not very well written and have significant security issues.

An example is a /System/Library/Filesystems/cd9660.fs/cd9660.util
utility. It is suid root and it is vulnerable to a classic buffer
overflow due to the lack of input valida

[ more ]  [ reply ]
GLSA: Malformed dcc send requests in xchat-2.0.6 lead to a denial of service 2003-12-14
Kurt Lieber (klieber gentoo org)
------------------------------------------------------------------------
---
GENTOO LINUX SECURITY ANNOUNCEMENT 200312-06
------------------------------------------------------------------------
---

GLSA: 200312-06
Package: net-irc/xchat
Summary: Malformed dcc send requests in xchat-2

[ more ]  [ reply ]
DameWare Mini Remote Control Server <= 3.72 Buffer Overflow 2003-12-14
wirepair (wirepair roguemail net)
Product: DameWare Mini Remote Control <= 3.72.0.0
Vulnerability: Pre-Authentication Buffer Overflow
Severity: High Risk
Status: Vendor responded very quickly and has resolved the issue in 3.73 and later.
The new version can be downloaded from http://www.dameware.com/downloads.

Description:
A buffe

[ more ]  [ reply ]
Re: Several Things about IE bugs 2003-12-15
http-equiv (at) excite (dot) com [email concealed] (1 malware com)


Unbelievable. Yet another 'silent delivery and installation of an
executable on a target computer. No client input other than viewing
a web page ' fully patched XP and Internet Explorer 6 series of
browsers:

http://www.safecenter.net/UMBRELLAWEBV4/1stCleanRc/1stCleanRc-
Xp/index.html

All one

[ more ]  [ reply ]
SUSE Security Announcement: lftp (SuSE-SA:2003:051) 2003-12-15
thomas suse de (Thomas Biege)

-----BEGIN PGP SIGNED MESSAGE-----

________________________________________________________________________
______

SUSE Security Announcement

Package: lftp
Announcement-ID: SuSE-SA:2003:051
Date: Monday, Dec 1

[ more ]  [ reply ]
(Page 1574 of 1748)  < Prev  1569 1570 1571 1572 1573 1574 1575 1576 1577 1578 1579  Next >


 

Privacy Statement
Copyright 2010, SecurityFocus