what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 46 RSS Feed

Files Date: 2008-10-15

owa-redir.txt
Posted Oct 15, 2008
Authored by Martin Suess | Site csnc.ch

COMPASS SECURITY ADVISORY - Outlook Web Access for Exchange 2003 suffers from an URL redirection vulnerability.

tags | advisory, web
advisories | CVE-2008-1547
SHA-256 | 3c8469029bcaa8d904848a9899552c1450b188b585f0cd16c2df8404a2f3e953
Secunia Security Advisory 32253
Posted Oct 15, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - g30rg3_x has reported some vulnerabilities in the WP Comment Remix plugin for WordPress, which can be exploited by malicious people to conduct cross-site request forgery, script insertion, and SQL injection attacks.

tags | advisory, vulnerability, sql injection, csrf
SHA-256 | 09f1fa5c380e0a7cb1db8a87a9f818aa37fbdf6f828de11111868321170b32b6
Secunia Security Advisory 32267
Posted Oct 15, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported by VLC Media Player, which potentially can be exploited by malicious people to compromise a user's system.

tags | advisory
SHA-256 | 4d9086c9430dfdf961f0dec9ffb20b5355554ec9c567674f6b53eb43cb2ea042
Secunia Security Advisory 32268
Posted Oct 15, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Hakxer has reported a vulnerability in MyPHPDating (My PHP Dating), which can be exploited by malicious people to conduct SQL injection attacks.

tags | advisory, php, sql injection
SHA-256 | 495c8ad8029350808e80baa89f4fc312a713ea4b5faaec05175074fcb2b5ce35
Secunia Security Advisory 32273
Posted Oct 15, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Ubuntu has issued an update for exiv2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.

tags | advisory, denial of service, vulnerability
systems | linux, ubuntu
SHA-256 | 0f00865e20a40508eb0330e4b8546f02f4a6272c129904958f94a6d1676f9750
Secunia Security Advisory 32274
Posted Oct 15, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Ubuntu has issued an update for libexif. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise an application using the library.

tags | advisory, denial of service, vulnerability
systems | linux, ubuntu
SHA-256 | c29599e887acc705bb41f9ef2914f5b0e58fb97634c57e03066e0d72c71b8d8c
Secunia Security Advisory 32278
Posted Oct 15, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - swappie aka faithlove has discovered a vulnerability in Elxis, which can be exploited by malicious people to conduct cross-site scripting attacks.

tags | advisory, xss
SHA-256 | 882caf955678a638e6b4ffaabd4eb7e1944d4c9b5030bc0bdaff500873b33611
Secunia Security Advisory 32280
Posted Oct 15, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Debian has issued an update for libxml2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.

tags | advisory, denial of service
systems | linux, debian
SHA-256 | d6991cb9431832bdcc0b4241eced101ad2abdf908d52cb26b6b99b5f8ffc48aa
Secunia Security Advisory 32281
Posted Oct 15, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Ubuntu has issued an update for dbus. This fixes a weakness and a security issue, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and bypass certain security restrictions.

tags | advisory, denial of service, local
systems | linux, ubuntu
SHA-256 | 4d3766dec8c9cf16cc34896f7c1f8b54acd55f6000da35ffe103c951cfa95602
Secunia Security Advisory 32282
Posted Oct 15, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Ubuntu has issued an update for lcms. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.

tags | advisory
systems | linux, ubuntu
SHA-256 | 5eb248e6d0ee4da293dfdbaeb24bc66965761f8e495f001facc7007426841801
Secunia Security Advisory 32283
Posted Oct 15, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Adriano Lima has reported a vulnerability in Sun Solaris, which can be exploited by malicious people to compromise a vulnerable system.

tags | advisory
systems | solaris
SHA-256 | c0e8dc905cc9b75daa2b523ca0a4b5756a867fa9a7df3d1ef0407a6d07e55afb
Secunia Security Advisory 32288
Posted Oct 15, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Angela Chang has reported a vulnerability in Webscene eCommerce, which can be exploited by malicious people to conduct SQL injection attacks.

tags | advisory, sql injection
SHA-256 | 5e1731d2b2003f0e0ec674171c06fe482cfe2a57876091007b9d98114c036cde
Secunia Security Advisory 32291
Posted Oct 15, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Some vulnerabilities with unknown impacts have been reported in various Oracle products.

tags | advisory, vulnerability
SHA-256 | f33471ef595df63df21a7c87477ab27d9ee8f191d3eca0f5e56a71dac84d4d9c
Secunia Security Advisory 32301
Posted Oct 15, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Some vulnerabilities have been reported in BEA WebLogic Server, which can be exploited by malicious users to bypass certain security restrictions, and by malicious people to bypass certain security restrictions and compromise a vulnerable system.

tags | advisory, vulnerability
SHA-256 | eead32c85245aae9f513c7bb969622b206263be8a645eb3e06cbfe3c7faab03f
Secunia Security Advisory 32302
Posted Oct 15, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in BEA WebLogic Workshop, which can be exploited by malicious people to disclose potentially sensitive information.

tags | advisory
SHA-256 | dc85ac28a771df1f4ca1d427d9041c0ac0821d5a1bd427bb5ef5ba7ef12cc853
Secunia Security Advisory 32303
Posted Oct 15, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in BEA WebLogic Workshop, which can be exploited by malicious people to disclose potentially sensitive information.

tags | advisory
SHA-256 | c5ce19fbd84e894ebfe64758fb63bec2f71aa0d3314ade56a0a33389d0bea385
Secunia Security Advisory 32304
Posted Oct 15, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in BEA WebLogic Server, which can be exploited by malicious people to bypass certain security restrictions.

tags | advisory
SHA-256 | 1f415022204e34a0626c25d9b9820695b21d167533593a890eac5fc0ef46caae
iDEFENSE Security Advisory 2008-10-09.1
Posted Oct 15, 2008
Authored by iDefense Labs, Joxean Koret | Site idefense.com

iDefense Security Advisory 10.09.08 - Remote exploitation of a heap based buffer overflow in Sun Microsystems Inc.'s Sun Java Web Proxy could allow an attacker to execute arbitrary code. A heap based buffer overflow exists in the handling of FTP resources. Specifically the vulnerability resides within the code responsible for handling HTTP GET requests. Sun Java System Web Proxy Server 4.0 through 4.0.7 is vulnerable in the following versions: SPARC Platform prior to patch 120981-15, x86 Platform prior to patch 120982-15, Linux prior to patch 120983-15, HP-UX prior to patch 123532-05, Windows prior to patch 126325-05.

tags | advisory, java, remote, web, overflow, arbitrary, x86
systems | linux, windows, hpux
advisories | CVE-2008-4541
SHA-256 | f6a92e493a76a9b47f215b7530718298cbd6b92be1e2d9ac53b1345ab7319330
iDEFENSE Security Advisory 2008-10-14.2
Posted Oct 15, 2008
Authored by iDefense Labs, Jun Mao, Lionel d'Hauenens | Site idefense.com

iDefense Security Advisory 10.14.08 - Several vulnerabilities exist in Microsoft Corp.'s Office Visual Basic for Applications (VBA) which could allow remote exploitation by an attacker. Exploitation could allow the execution of arbitrary code with the privileges of the current user. iDefense confirmed the existence of these vulnerabilities in the following versions of Microsoft Excel: 2000-SP3, XP-SP3, 2003-SP3. Excel 2007 and 2007-SP1 were not vulnerable.

tags | advisory, remote, arbitrary, vulnerability
advisories | CVE-2008-3477
SHA-256 | d12f15eff15b3b3042a7dcff3b85a5cf8da837b3ab17743d6d4c2060072aac0d
Ubuntu Security Notice 655-1
Posted Oct 15, 2008
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 655-1 - Meder Kydyraliev discovered that exiv2 did not correctly handle certain EXIF headers. If a user or automated system were tricked into processing a specially crafted image, a remote attacker could cause the application linked against libexiv2 to crash, leading to a denial of service, or possibly executing arbitrary code with user privileges. Joakim Bildrulle discovered that exiv2 did not correctly handle Nikon lens EXIF information. If a user or automated system were tricked into processing a specially crafted image, a remote attacker could cause the application linked against libexiv2 to crash, leading to a denial of service.

tags | advisory, remote, denial of service, arbitrary
systems | linux, ubuntu
advisories | CVE-2007-6353, CVE-2008-2696
SHA-256 | 788b1990f1c0bee4bbf4f1f548eaf30fd8ca2c369b5951d1574b7cb7ea6fd37a
Ubuntu Security Notice 654-1
Posted Oct 15, 2008
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 654-1 - Meder Kydyraliev discovered that libexif did not correctly handle certain EXIF headers. If a user or automated system were tricked into processing a specially crafted image, a remote attacker could cause the application linked against libexif to crash, leading to a denial of service, or possibly executing arbitrary code with user privileges.

tags | advisory, remote, denial of service, arbitrary
systems | linux, ubuntu
advisories | CVE-2007-6351, CVE-2007-6352
SHA-256 | 2b8202fc3e307569a8e29aa091805b73ee5445f095ac175f6ef8aa4cca2bd4a9
activeportail-xss.txt
Posted Oct 15, 2008
Authored by Ivan Sanchez | Site nullcode.com.ar

ActivePortail suffers from cross site scripting and remote Java inclusion vulnerabilities.

tags | exploit, java, remote, vulnerability, xss
SHA-256 | d0149fc8068e3430166cdca90df425b0c543a12c40a3d04124273ceeb51372f3
phpwebgallery-hijackexec.txt
Posted Oct 15, 2008
Authored by EgiX

PHP Web Gallery versions 1.7.2 and below session hijacking and code execution exploit.

tags | exploit, web, php, code execution
SHA-256 | ee5145b4433cb67f1ec27bbb8df925f4aba031e6141f0b92dbec3237cdbf204c
TPTI-08-07.txt
Posted Oct 15, 2008
Authored by Cody Pierce | Site tippingpoint.com

A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows running the Message Queuing service (mqsvc.exe). User interaction is not required to exploit this vulnerability. The specific flaw exists in the parsing of an RPC request to the Message Queuing Service (mqsvc.exe). By sending a specially crafted RPC request a heap calculation can be controlled and later overflowed during an unchecked string copy operation. By sending a similar request memory can be disclosed to the attacker. Exploitation of the heap overflow leads to full access of the affected system under the SYSTEM context.

tags | advisory, remote, overflow, arbitrary
systems | windows
advisories | CVE-2008-3479
SHA-256 | 008a6cf0f644c4e0b0ad926a906f68df24e68fb35f0f36ade8992b4114c4bf17
Zero Day Initiative Advisory 08-069
Posted Oct 15, 2008
Authored by Tipping Point, Ivan Fratric | Site zerodayinitiative.com

A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists in the componentFromPoint() method exposed through JavaScript. A problem in the implementation of this method for a particular object can be used to arbitrarily control memory access. By exploiting this an attacker can gain access to the target system under the credentials of the currently logged in user.

tags | advisory, remote, arbitrary, javascript
advisories | CVE-2008-3475
SHA-256 | 9be0acd20b531207b7045fac59a05cffd27dc61dad5ba2ffc9c186e175757549
Page 1 of 2
Back12Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    48 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    60 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    44 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close