Section: .. / 0704-advisories /
| /// File Name: |
sa24772.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for tightvnc. This fixes some vulnerabilities, which potentially can be exploited by malicious users gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/24772/ | | File Size: | 2652 | | Last Modified: | Apr 7 15:35:58 2007 |
| MD5 Checksum: | 0929c42b9f09b6863a43eaaceb8f7fc3 |
|
| /// File Name: |
sa22924.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in GraceNote CDDBControl ActiveX Control, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/22924/ | | File Size: | 2649 | | Last Modified: | Apr 20 17:50:15 2007 |
| MD5 Checksum: | a21a74f8cd7a47aed3b4e7636bfc0c52 |
|
| /// File Name: |
glsa-200704-07.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200704-07 - libwpd contains heap-based overflows in two functions that convert WordPerfect document tables. In addition, it contains an integer overflow in a text-conversion function. Versions less than 0.8.9 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2644 | | Related CVE(s): | CVE-2007-0002, CVE-2007-1466 | | Last Modified: | Apr 7 20:56:06 2007 |
| MD5 Checksum: | d5e362d91a4c64bcc9be45ac5025f95d |
|
| /// File Name: |
major_rls40.txt |
Description:
|
The oboShop e-commerce web shopping script suffers from a session fixation issue.
| | Author: | David "Aesthetico" Vieira-Kurz | | Homepage: | http://www.majorsecurity.de | | File Size: | 2642 | | Last Modified: | Apr 7 20:46:43 2007 |
| MD5 Checksum: | e1a37980ab400a85150eb7bdeb46008a |
|
| /// File Name: |
sa24826.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for ipsec-tools. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/24826/ | | File Size: | 2637 | | Last Modified: | Apr 17 12:18:04 2007 |
| MD5 Checksum: | e89889c8e42cc5607f91d26d925c1fdb |
|
| /// File Name: |
sa24855.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in HP-UX, which can be exploited by malicious people to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/24855/ | | File Size: | 2637 | | Last Modified: | Apr 11 21:03:40 2007 |
| MD5 Checksum: | 2e5b5900c395aa9a4765f01fea49fdd3 |
|
| /// File Name: |
sa24671.txt |
Description:
|
Secunia Security Advisory - Hamid Ebadi has reported some vulnerabilities in RSPA (Really Simple PHP and Ajax), which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/24671/ | | File Size: | 2628 | | Last Modified: | Apr 5 01:27:45 2007 |
| MD5 Checksum: | 2765d42351964ca613e405289f95fa52 |
|
| /// File Name: |
glsa-200704-06.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200704-06 - Evince includes code from GNU gv that does not properly boundary check user-supplied data before copying it into process buffers. Versions less than 0.6.1-r3 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2627 | | Related CVE(s): | CVE-2006-5864 | | Last Modified: | Apr 7 20:55:51 2007 |
| MD5 Checksum: | 3a3242c9e2ec79fb6276d48088ec26b1 |
|
| /// File Name: |
sa24717.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in IBM Tivoli Provisioning Manager for OS Deployment, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/24717/ | | File Size: | 2626 | | Last Modified: | Apr 4 22:08:29 2007 |
| MD5 Checksum: | 35c2a145108cc18263d6d11dc1629273 |
|
| /// File Name: |
sa24848.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in Database Administration (dba) module, which can be exploited by malicious people to conduct cross-site scripting and request forgery attacks.
| | Homepage: | http://secunia.com/advisories/24848/ | | File Size: | 2599 | | Last Modified: | Apr 12 14:33:34 2007 |
| MD5 Checksum: | 53c320a1a1aa95e7b3d569c7cc3a5de9 |
|
| /// File Name: |
sa24689.txt |
Description:
|
Secunia Security Advisory - DarkFig has reported a vulnerability in MyBB, which can be exploited by malicious people to conduct SQL injection attacks and compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/24689/ | | File Size: | 2598 | | Last Modified: | Apr 5 02:55:47 2007 |
| MD5 Checksum: | 710fc3f72fedab1b6d9eaf0f3c83dc8f |
|
| /// File Name: |
sa24751.txt |
Description:
|
Secunia Security Advisory - Sumit Siddharth has discovered two vulnerabilities in WordPress, which can be exploited by malicious users to conduct SQL injection attacks or to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/24751/ | | File Size: | 2590 | | Last Modified: | Apr 5 01:27:45 2007 |
| MD5 Checksum: | ec2aee5a80d2a173d100b3a9b9fd9fb5 |
|
| /// File Name: |
sa24767.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Symantec Enterprise Security Manager (ESM), which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/24767/ | | File Size: | 2590 | | Last Modified: | Apr 7 15:35:58 2007 |
| MD5 Checksum: | d1b41da57cbe78b36505af272ef363ec |
|
| /// File Name: |
sa24830.txt |
Description:
|
Secunia Security Advisory - Two weaknesses have been reported in Apple AirPort Extreme Base Station, which can be exploited by malicious people to bypass certain security restrictions or to disclose certain sensitive information.
| | Homepage: | http://secunia.com/advisories/24830/ | | File Size: | 2587 | | Last Modified: | Apr 10 22:12:21 2007 |
| MD5 Checksum: | e37900668a656cfd760a3afedb41f3ea |
|
| /// File Name: |
MDKSA-2007-093.txt |
Description:
|
Mandriva Linux Security Advisory - A stack-based buffer overflow in the ZZIPlib library could allow user-assisted remote attackers to cause an application crash (DoS) or execute arbitrary code via a long filename.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 2580 | | Related CVE(s): | CVE-2007-1614 | | Last Modified: | Apr 24 03:44:04 2007 |
| MD5 Checksum: | deab07197054db0abcdcc24310a3bb22 |
|
| /// File Name: |
sa24823.txt |
Description:
|
Secunia Security Advisory - eEye Digital Security has reported a vulnerability in Windows Vista, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/24823/ | | File Size: | 2570 | | Last Modified: | Apr 10 22:12:21 2007 |
| MD5 Checksum: | a7b14cc9f0566a51537cb7fcd5cd901f |
|
| /// File Name: |
sa24875.txt |
Description:
|
Secunia Security Advisory - Avaya has acknowledged a vulnerability in various Avaya products, which potentially can be exploited by malicious people to bypass certain security restrictions when applications use GnuPG in an insecure manner.
| | Homepage: | http://secunia.com/advisories/24875/ | | File Size: | 2570 | | Last Modified: | Apr 16 12:29:53 2007 |
| MD5 Checksum: | 46fd67ecaeaaa74678684aff065259e8 |
|
| /// File Name: |
glsa-200704-05.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200704-05 - dmcox dmcox discovered a boundary error in the zzip_open_shared_io() function from zzip/file.c . Versions less than 0.13.49 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2567 | | Related CVE(s): | CVE-2007-1614 | | Last Modified: | Apr 4 20:46:42 2007 |
| MD5 Checksum: | 407a961e44b688039ee7d00350de2e08 |
|
| /// File Name: |
sa24822.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/24822/ | | File Size: | 2567 | | Last Modified: | Apr 10 22:12:21 2007 |
| MD5 Checksum: | 4df6bbafae746fdcda28d4d4b25b8ab4 |
|
| /// File Name: |
sa24873.txt |
Description:
|
Secunia Security Advisory - Gammarays has discovered two vulnerabilities in Chatness, which can be exploited by malicious people to bypass certain security restrictions and by malicious users to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/24873/ | | File Size: | 2559 | | Last Modified: | Apr 16 12:29:53 2007 |
| MD5 Checksum: | 146071cd4aab98e94824621c329375ec |
|
| /// File Name: |
glsa-200704-14.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200704-14 - The Coverity Scan project has discovered a memory leak within the handling of certain malformed Diameter format values inside an EAP-TTLS tunnel. Versions less than 1.1.6 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2554 | | Related CVE(s): | CVE-2007-2028 | | Last Modified: | Apr 18 20:54:45 2007 |
| MD5 Checksum: | 8596a06cdbf5c0c48a23fb0f0ab0577f |
|
| /// File Name: |
sa24624.txt |
Description:
|
Secunia Security Advisory - Sun has acknowledged a vulnerability in Mozilla 1.7 for Sun Solaris, which potentially can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/24624/ | | File Size: | 2548 | | Last Modified: | Apr 2 19:13:40 2007 |
| MD5 Checksum: | abd49a6468af189a4254783fd0399af2 |
|
| /// File Name: |
ZDI-07-016.txt |
Description:
|
A vulnerability allows remote attackers to delete any existing Document Management node on vulnerable installations of Oracle E-Business Suite. Authentication is not required to exploit this vulnerability. The specific flaw exists in the APPLSYS.FND_DM_NODES package. The procedure to delete nodes does not check for a valid session thereby allowing an attacker to arbitrarily delete any node registered, including the root node.
| | Author: | Joxean Koret | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2544 | | Related CVE(s): | CVE-2007-2170 | | Last Modified: | Apr 19 00:52:28 2007 |
| MD5 Checksum: | 197d6c1d20d50bda33ff6a94e5ea6f58 |
|
| /// File Name: |
sa24862.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in Crea-book, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/24862/ | | File Size: | 2543 | | Last Modified: | Apr 11 21:03:40 2007 |
| MD5 Checksum: | 668ac7692a58d90c57171770b15fce7f |
|
| /// File Name: |
sa24938.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in IBM Tivoli Monitoring, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/24938/ | | File Size: | 2543 | | Last Modified: | Apr 20 02:48:40 2007 |
| MD5 Checksum: | 58fab3ae4ea6c8586f74c7b138bacca4 |
|
|
|
|
|