what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 46 of 46 RSS Feed

Files Date: 2011-12-08 to 2011-12-09

Suricata IDPE 1.1.1
Posted Dec 8, 2011
Site openinfosecfoundation.org

Suricata is a network intrusion detection and prevention engine developed by the Open Information Security Foundation and its supporting vendors. The engine is multi-threaded and has native IPv6 support. It's capable of loading existing Snort rules and signatures and supports the Barnyard and Barnyard2 tools.

Changes: This release fixes a crash in the SMTP parser and a problem with AF_PACKET compilation.
tags | tool, intrusion detection
systems | unix
SHA-256 | 6ff337ca71ca015d50e73a2bb90e02d894b617935482802102648d51b3876fac
Ubuntu Security Notice USN-1290-1
Posted Dec 8, 2011
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 1290-1 - Simo Sorce discovered that a NULL pointer dereference existed in the Kerberos Key Distribution Center (KDC). An authenticated remote attacker could use this to cause a denial of service.

tags | advisory, remote, denial of service
systems | linux, ubuntu
advisories | CVE-2011-1530
SHA-256 | 7ed0fbc4432ed32166067d84ab8cbdd22401e5d3e348a0d58e255c272905e643
Zero Day Initiative Advisory 11-344
Posted Dec 8, 2011
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 11-344 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of RealNetworks RealPlayer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the way that the application allocates space for parsing sample data encoded with the RV20 codec. After allocation, the application will partially fill the allocation with sample data. Upon usage of this sample data, the application will use the uninitialized data to calculate an index that is then written into. This can lead to code execution under the context of the application.

tags | advisory, remote, arbitrary, code execution
advisories | CVE-2011-4253
SHA-256 | 50e66ded99d11173f3c8167b6f12e294aa22a831c7b09425d4215df5292503c6
Hack In The Box 2012 Europe Call For Papers
Posted Dec 8, 2011
Site cfp.hackinthebox.org

The Call for Papers for the third annual HITBSecConf in Europe is now open. Taking place from the 21st through the 25th of May at the Okura Hotel in Amsterdam, it will be a quad-track conference featuring keynote speakers Andy Ellis (Chief Security Officer, Akamai) and Bruce Schneier (Chief Security Technology Officer, BT).

tags | paper, conference
SHA-256 | b91449f24b3ad6b16eddc8476a1114a0c9926f521215ee6b5b71c02c8e4e9775
KnowledgeTree login.php Blind SQL Injection
Posted Dec 8, 2011
Authored by Digital Defense, r@b13$, sxkeebler | Site digitaldefense.net

The KnowledgeTree login.php login page is vulnerable to a blind SQL injection vulnerability within the username field. An attacker can leverage this flaw to execute arbitrary SQL commands and extract sensitive information from the backend database using standard blind SQL exploitation techniques. Additionally, an attacker may be able to leverage this flaw to compromise the database server host OS.

tags | advisory, arbitrary, php, sql injection
SHA-256 | d3f77e8bceace3fc7ce207fa65ce9c2f16782589248552275d3f46df8cd67399
Zeema CMS Cross Site Scripting / SQL Injection
Posted Dec 8, 2011
Authored by MustLive

Zeema CMS suffers from cross site scripting, information leakage and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | 0e88167fb75ef28d1a96a7a15c4869c8737467e133fe9a9d89a228940d3866b0
Zero Day Initiative Advisory 11-343
Posted Dec 8, 2011
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 11-343 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of RealNetworks Realplayer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the mp4arender.dll module. If the channel count is altered inside the esds atom, the allocated buffer will be too small to support the decoded audio data, causing a heap overflow. This vulnerability can be leveraged to execute code under the context of the user running the application.

tags | advisory, remote, overflow, arbitrary
advisories | CVE-2011-4260
SHA-256 | 1de47a5d32b9c4dcf8ee7ada8fb59ba281f7d617834a3920d1d09016015f5407
Zero Day Initiative Advisory 11-342
Posted Dec 8, 2011
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 11-342 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell Zenworks Asset Management. Authentication is not required to exploit this vulnerability. The flaw exists within the rtrlet component. This process listens on TCP port 8080. When handling an unauthenticated file upload the process does not properly sanitize the path. Directory traversal can be used to drop a file in an arbitrary location and a null byte inserted into the filename to provide arbitrary extension. A remote attacker can exploit this vulnerability to execute arbitrary code under the context of SYSTEM.

tags | advisory, remote, arbitrary, tcp, file upload
advisories | CVE-2011-2653
SHA-256 | 2cee1a50137f6669e7975ff91ba14fa783263398787505aebdbcb678aa0d7213
Zero Day Initiative Advisory 11-341
Posted Dec 8, 2011
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 11-341 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Cisco WebEx Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within atdl2006.dll. The vulnerability is caused by lack of validation when parsing WRF files. A specially crafted WRF file will cause the application to incorrectly push a size value to a memcpy, allowing for corruption of heap memory. An attacker can leverage this vulnerability to execute arbitrary code on the target system under the context of the current user.

tags | advisory, remote, arbitrary
systems | cisco
advisories | CVE-2011-3319
SHA-256 | 5c6949e6b0eb36f74456cb25567b1e74b31591741a2cf52ed895cf5427bb2ef4
Zero Day Initiative Advisory 11-340
Posted Dec 8, 2011
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 11-340 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Quicktime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within how the application parses font names embedded within an atom. When parsing the font name, the application will treat a length from the file as a signed value when copying font data into a buffer. Due to an unsigned promotion, this can be used to write outside the bounds of a buffer which can lead to code execution under the context of the application.

tags | advisory, remote, arbitrary, code execution
systems | apple
advisories | CVE-2011-3248
SHA-256 | ffbb90a377f7fda3461c5ed9be6cf21b276f42f9402309e92d8f8fa99e3ce910
Ubuntu Security Notice USN-1289-1
Posted Dec 8, 2011
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 1289-1 - It was discovered that colord incorrectly handled certain SQL queries. A local attacker could exploit this to modify arbitrary sqlite databases. On Ubuntu, colord runs as its own user by default, so standard file permissions would limit which databases could be altered.

tags | advisory, arbitrary, local
systems | linux, ubuntu
advisories | CVE-2011-4349
SHA-256 | 944dc4557f647d8c7e2c3999af2bd590b59c0bcc4f31cd6ab77053fa15ad5b05
Red Hat Security Advisory 2011-1794-01
Posted Dec 8, 2011
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2011-1794-01 - Red Hat Network Satellite provides a solution to organizations requiring absolute control over and privacy of the maintenance and package deployment of their servers. It allows organizations to utilize the benefits of the Red Hat Network without having to provide public Internet access to their servers or other client systems. A cross-site scripting flaw was found in the RHN Satellite web interface. An authenticated RHN Satellite user could use this flaw to perform a cross-site scripting attack against other authenticated users who are using the RHN Satellite web interface.

tags | advisory, web, xss
systems | linux, redhat
advisories | CVE-2011-4346
SHA-256 | 286a1ca30d9eebb4be69c57c808e9bb7ffcec46221040018550c5a6c050e714d
Google Open Redirect
Posted Dec 8, 2011
Authored by suckure

Google suffers from an open redirection vulnerability. This may be working as designed, but is still a bad idea.

tags | exploit
SHA-256 | f7474650d0d2df3b430a067c98ddeef035d67a88cefcac0a961622e82270052c
Mandriva Linux Security Advisory 2011-181
Posted Dec 8, 2011
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2011-181 - Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via vectors involving an error that occurs after an FTP data transfer. The updated packages have been upgraded to the latest version 1.3.3g which is not vulnerable to this issue.

tags | advisory, remote, arbitrary
systems | linux, mandriva
advisories | CVE-2011-4130
SHA-256 | 0be1d40f8f3b58111ad1f44517b3cd8c334da98ee590aaee94305394e4d7a9d6
Secunia Security Advisory 47166
Posted Dec 8, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - SUSE has issued an update for Ruby on Rails. This fixes multiple vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, manipulate certain data, and conduct HTTP response splitting, cross-site scripting, cross-site request forgery, and SQL injection attacks.

tags | advisory, web, vulnerability, xss, sql injection, ruby, csrf
systems | linux, suse
SHA-256 | bfe7c7d7034c5f981bd3bbc5a78f5d11333245afc7a91893b2a016ab66b6d06d
Secunia Security Advisory 47088
Posted Dec 8, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Ubuntu has issued an update for linux. This fixes multiple vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and potentially gain escalated privileges and by malicious people to cause a DoS.

tags | advisory, denial of service, local, vulnerability
systems | linux, ubuntu
SHA-256 | 88dfed92bd77ef1ab0bb01538361300ac75327af5a01f9a22b5f463695fba866
Secunia Security Advisory 47164
Posted Dec 8, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - sxkeebler and r@b13$ have discovered a vulnerability in KnowledgeTree, which can be exploited by malicious people to conduct SQL injection attacks.

tags | advisory, sql injection
SHA-256 | fa35b9a8793bab6f29a55f683fd3212322c25a58f21790ade01770b3bff30f71
Secunia Security Advisory 47070
Posted Dec 8, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in D-Link ShareCenter DNS-320, which can be exploited by malicious people to bypass certain security restrictions.

tags | advisory
SHA-256 | b1e928d3eb6b296c9cf54144893f785646721391e3d5b3a69b3f17b47f4258bf
Secunia Security Advisory 47167
Posted Dec 8, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in CA SiteMinder, which can be exploited by malicious people to conduct cross-site scripting attacks.

tags | advisory, xss
SHA-256 | f9a2f59abf701f2320d90715d6d209e2a6bd9c5fa69ee322bab7a7110a7e589d
Secunia Security Advisory 47105
Posted Dec 8, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Ubuntu has issued an update for linux-lts-backport-maverick. This fixes multiple vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and potentially gain escalated privileges and by malicious people to cause a DoS.

tags | advisory, denial of service, local, vulnerability
systems | linux, ubuntu
SHA-256 | e1a724ccc8ea96c7419f8365d917bbe25c8b80ecc70cf5b2e29a92ad2eb0bbe0
Secunia Security Advisory 47136
Posted Dec 8, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Darren McDonald has reported some weaknesses and two vulnerabilities in One Click Orgs, which can be exploited by malicious users to potentially cause a DoS (Denial of Service), manipulate certain data, and conduct spoofing and script insertion attacks and by malicious people to disclose sensitive information and conduct spoofing attacks.

tags | advisory, denial of service, spoof, vulnerability
SHA-256 | 46115d6f290c4a29cf5eb2dedde6e676f1b3d8481a0c9e358f4830cc24b007eb
Page 2 of 2
Back12Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    48 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    60 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close