exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 503 RSS Feed

Files

ExtCalendar 2.0 Beta 2 Cross Site Scripting
Posted Feb 28, 2010
Authored by LiquidWorm

ExtCalendar version 2.0 Beta 2 suffers from a cross site scripting vulnerability.

tags | advisory, xss
SHA-256 | f3ff74b4568f9159c2fd60ec484fe6464f1648d875317b00de9d9708cd6f6a11
Ubuntu Security Notice 905-1
Posted Feb 27, 2010
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 905-1 - It was discovered that sudo did not properly validate the path for the 'sudoedit' pseudo-command. A local attacker could exploit this to execute arbitrary code as root if sudo was configured to allow the attacker to use sudoedit. The sudoedit pseudo-command is not used in the default installation of Ubuntu. It was discovered that sudo did not reset group permissions when the 'runas_default' configuration option was used. A local attacker could exploit this to escalate group privileges if sudo was configured to allow the attacker to run commands under the runas_default account. The runas_default configuration option is not used in the default installation of Ubuntu. This issue affected Ubuntu 8.04 LTS, 8.10 and 9.04.

tags | advisory, arbitrary, local, root
systems | linux, ubuntu
advisories | CVE-2010-0426, CVE-2010-0427
SHA-256 | 6429269d5a7e2fc27d46e77eeca2faf4ade70b577099f07867e05c9aa22b77c1
Mandriva Linux Security Advisory 2010-050
Posted Feb 26, 2010
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2010-050 - This release fixes several important issues to help prevent a detection bypass and denial of service attacks against ModSecurity. Quite a few small but notable bugs were fixed. The latest Core Ruleset (2.0.5) is included. This update provides mod_security 2.5.12, which is not vulnerable to these issues.

tags | advisory, denial of service
systems | linux, mandriva
SHA-256 | 6c71492b8421e92f36cdd1a6901462fa3a8ad3e3f74fa98728a535318bf3f961
getPlus Insufficient Domain Name Validation
Posted Feb 26, 2010
Authored by Yorick Koster | Site akitasecurity.nl

getPlus suffers from an insufficient domain name validation vulnerability. A new Adobe Download Manager was released that resolves this issue.

tags | advisory
advisories | CVE-2010-0189
SHA-256 | e071af8d3f4b8b962bc5edfde3e6bfc33db4acd32f7296e78e2eaedc666e6e16
Asterisk Project Security Advisory - AST-2010-003
Posted Feb 26, 2010
Authored by Mark Michelson | Site asterisk.org

Asterisk Project Security Advisory - Host access rules using permit= and deny= configurations behave unpredictably if the CIDR notation /0 is used. Depending on the system's behavior, this may act as desired, but in other cases it might not, thereby allowing access from hosts that should be denied.

tags | advisory
SHA-256 | 1b93b33da3d5184c379547d81b5050d83dfdbc328a9e859576be03060c04eeb1
Mandriva Linux Security Advisory 2010-049
Posted Feb 26, 2010
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2010-049 - sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the name of an executable file in an arbitrary directory, which allows local users to gain privileges via a crafted executable file, as demonstrated by a file named sudoedit in a user's home directory. Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers. The updated packages have been patched to correct this issue.

tags | advisory, arbitrary, local
systems | linux, mandriva
advisories | CVE-2010-0426
SHA-256 | e08356d2265f5bbf8e1e1d35a2a50499020c9010536a56aec7e5bd3169bf8174
Mandriva Linux Security Advisory 2010-048
Posted Feb 26, 2010
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2010-048 - Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests. The updated packages have been patched to correct this issue.

tags | advisory, remote, web
systems | linux, mandriva
advisories | CVE-2010-0464
SHA-256 | 5a74a11549ef957148ffdfc501ea49d478176ec6645d67961c660a4b2edc9d22
DATEV Active-X Control Remote Command Execution
Posted Feb 26, 2010
Authored by Nikolas Sotiriu | Site sotiriu.de

The DATEV Active-X control suffers from a remote command execution vulnerability.

tags | advisory, remote, activex
advisories | CVE-2010-0689
SHA-256 | 0813b6e932bdf3408d8be317740e7fb909e9982105a6a146fa81b12ae71dbb2b
Secunia Security Advisory 38752
Posted Feb 26, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A security issue has been reported in Asterisk, which can be exploited by malicious people to potentially bypass certain security restrictions.

tags | advisory
SHA-256 | cb7691a7d72f6398bfb3a87125f6fd54d3c21d2155d5731fb531f8f43c895e07
Secunia Security Advisory 38705
Posted Feb 26, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Fedora has issued an update for mingw32-libltdl. This fixes a security issue, which can be exploited by malicious, local users to potentially gain escalated privileges.

tags | advisory, local
systems | linux, fedora
SHA-256 | 2eea838cca988ed6f1dd1bdc96d5ab0a425fa9a7390d7ee9cdf0c0ca3c64653b
Secunia Security Advisory 38740
Posted Feb 26, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Hitachi has acknowledged a security issue in Hitachi JP1/Cm2/Network Node Manager, which can be exploited by malicious, local users to manipulate certain data and potentially gain escalated privileges.

tags | advisory, local
SHA-256 | 5a50d76623ea018d8c52b0adbf3f8d9656d074b19d9468a5dc552656b96f04fd
Secunia Security Advisory 38734
Posted Feb 26, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A security issue has been discovered in XMail, which can be exploited by malicious, local users to gain escalated privileges.

tags | advisory, local
SHA-256 | fe6fd1aec68484cf82e50c4e37b17533d36d2c9ca53ee0da426e234d1c822ccf
Secunia Security Advisory 38737
Posted Feb 26, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in Hitachi products, which can be exploited by malicious people to conduct cross-site scripting attacks.

tags | advisory, xss
SHA-256 | 813a68ad33d780ef9bc4b42bfcc7f70898b91b5bac7dc30051a9508bdef43e9e
Secunia Security Advisory 38667
Posted Feb 26, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Maciej Gojny has reported a vulnerability in WebAdministrator Lite CMS, which can be exploited by malicious people to conduct SQL injection attacks.

tags | advisory, sql injection
SHA-256 | 04610b3c86767c1a8e1fd37a836f47ebf9edd38c88b09c8ac3ebe6a44170c455
Secunia Security Advisory 38708
Posted Feb 26, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Two vulnerabilities have been reported in PHP, which can be exploited by malicious users to bypass certain security restrictions.

tags | advisory, php, vulnerability
SHA-256 | b6cd9bf29d55c8ed6e0e758be7d6b36840c11372e39fd34f804bcadaba3f7d69
Secunia Security Advisory 38747
Posted Feb 26, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in Website Baker, which can be exploited by malicious people to bypass certain security restrictions.

tags | advisory
SHA-256 | 7a7a6e2308c8fae16d5646238153c82732533c9711f52a998e1516dcdaed5c61
Secunia Security Advisory 38746
Posted Feb 26, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Red Hat has issued an update for sudo. This fixes multiple security issues, which can be exploited by malicious, local users to gain escalated privileges.

tags | advisory, local
systems | linux, redhat
SHA-256 | 35e5b53719103a457aba638dc0803d9a09aef73c04535f326cb2f9211a4b2b68
Secunia Security Advisory 38720
Posted Feb 26, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - mr_me has discovered a vulnerability in Orbital Viewer, which can be exploited by malicious people to compromise a user's system.

tags | advisory
SHA-256 | a69cce1fdbb4ced86ee264f4d007a285114667db56fb59593bfa2d3462581eb5
Secunia Security Advisory 38691
Posted Feb 26, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been discovered in the HD FLV Player component for Joomla, which can be exploited by malicious people to conduct SQL injection attacks.

tags | advisory, sql injection
SHA-256 | e632da662b74d8fe8ef2c7228d9dff4e2cc755086fb241ad6c9dd72a5796d8fe
Secunia Security Advisory 38686
Posted Feb 26, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Ubuntu has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

tags | advisory, denial of service
systems | linux, ubuntu
SHA-256 | 5da3cf117bd48a71be1c1249bb4d3d2e3aa89ea0e2804712b2b9e60ad46b5ac1
Secunia Security Advisory 38699
Posted Feb 26, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been discovered in WikyBlog, which can be exploited by malicious people to conduct cross-site scripting attacks.

tags | advisory, xss
SHA-256 | 947b4bb5ba4e9ce67a33a243bb53b8fc855d70e69c7f08df12ce2a0f9ff3edd0
Secunia Security Advisory 38738
Posted Feb 26, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Matthias -apoc- Hecker has discovered a security issue in rbot, which can be exploited by malicious people to bypass certain security restrictions.

tags | advisory
SHA-256 | 6503c1bb291527908923c3a571dbe9f9bd6e41f3c903dea0a6285870feab5c57
Secunia Security Advisory 38743
Posted Feb 26, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been discovered in Newbie CMS, which can be exploited by malicious people to bypass certain security restrictions.

tags | advisory
SHA-256 | 3498685e75f0a1709034d7c2f83aac60516f3cc82b8d92c5d703da002bb4e94c
Secunia Security Advisory 38719
Posted Feb 26, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - AbdulAziz Hariri and Mohammad Abou Hayt have discovered a vulnerability in Symantec Altiris Deployment Solution, which can be exploited by malicious people to cause a DoS (Denial of Service).

tags | advisory, denial of service
SHA-256 | 633463f0456554a5e678f23da7ea2492c6627bdc63d68cdbdf2acfd43471e7ae
Secunia Security Advisory 38676
Posted Feb 26, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Multiple vulnerabilities have been reported in Article Friendly, which can be exploited by malicious people to conduct SQL injection and cross-site request forgery attacks.

tags | advisory, vulnerability, sql injection, csrf
SHA-256 | 60f2338783aafb2b3907a6a5cf8ac97a7bb009937c1caa46c2fa521120184b5c
Page 1 of 21
Back12345Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
US Senators Propose Law To Require Bare Minimum Security Standards
Posted Nov 27, 2024

tags | headline, government, usa, password
Telco Engineer Who Spied On Employer For Beijing Gets 4 Years
Posted Nov 27, 2024

tags | headline, government, privacy, usa, phone, china, cyberwar, spyware, voip
New York Fines GEICO And Travelers $11.3 Million In Data Breach Cases
Posted Nov 27, 2024

tags | headline, hacker, government, privacy, usa, data loss
ProjectSend Vulnerability Exploited In The Wild
Posted Nov 27, 2024

tags | headline, hacker, flaw
CyberVolk Analysis Explores Ransomware, Hacktivism Connections
Posted Nov 27, 2024

tags | headline, hacker, malware, russia, cybercrime, cryptography
Russian Cyberspies Hacked Building Across Street From Target For W-Fi Attack
Posted Nov 25, 2024

tags | headline, hacker, government, russia, wireless, spyware
Cyberattacks Cost British Businesses $55 Billion In Past 5 Years
Posted Nov 25, 2024

tags | headline, malware, britain, cybercrime, fraud, cryptography
How The ZX Spectrum Became A 1980s Icon
Posted Nov 25, 2024

tags | headline, science
China Has Pwned Thousands And Thousands Of Telco Devices
Posted Nov 25, 2024

tags | headline, government, privacy, usa, china, cyberwar, spyware
Here's What Happens If You Don't Layer Network Security Or Remove Unused Web Shells
Posted Nov 22, 2024

tags | headline, government, privacy, cybercrime, data loss, japan
View More News →
packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close