Section: .. / 0710-advisories /
| /// File Name: |
TPTI-07-016.txt |
Description:
|
Vulnerabilities allow a remote attacker to execute arbitrary code on vulnerable installations of Computer Associates' BrightStor Hierarchical Storage Manager. Authentication is not required to exploit these vulnerabilities. The specific flaws exist in the CsAgent service that listens by default on TCP port 2000. An opcode parsing switch statement multiplexes data funneling across various vulnerable routines. A user-supplied DWORD size value is assumed by the vulnerable agent to contain the correct length of the subsequent data and is passed directly to memory allocation routines. At least 26 out of the available 68 opcodes are vulnerable to various overflows that allow for remote code execution due to insecure data copy operations.
| | Author: | Aaron Portnoy | | Homepage: | http://www.tippingpoint.com/ | | File Size: | 2444 | | Related CVE(s): | CVE-2007-5082 | | Last Modified: | Oct 2 20:27:55 2007 |
| MD5 Checksum: | b45214555ac98338dbf353986bcee9d2 |
|
| /// File Name: |
sa27032.txt |
Description:
|
Secunia Security Advisory - GeFORC3 has reported two vulnerabilities in Netkamp Emlak Scripti, which can be exploited by malicious people to conduct cross-site scripting attacks and SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/27032/ | | File Size: | 2444 | | Last Modified: | Oct 1 23:39:07 2007 |
| MD5 Checksum: | f5346a5cbbd9eef5b20a83594591b0e6 |
|
| /// File Name: |
sa27186.txt |
Description:
|
Secunia Security Advisory - OpenBSD has issued an update for OpenSSL. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27186/ | | File Size: | 2444 | | Last Modified: | Oct 12 21:32:46 2007 |
| MD5 Checksum: | a9a439793d3607a7220304f08e7a0964 |
|
| /// File Name: |
sa27208.txt |
Description:
|
Secunia Security Advisory - 0in has reported a vulnerability in PicoFlat CMS, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27208/ | | File Size: | 2444 | | Last Modified: | Oct 12 20:30:02 2007 |
| MD5 Checksum: | c8f6b2c7f06fd642b27774e2d95a8d92 |
|
| /// File Name: |
sa27417.txt |
Description:
|
Secunia Security Advisory - Luigi Auriemma has reported a vulnerability in World in Conflict, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/27417/ | | File Size: | 2442 | | Last Modified: | Oct 29 20:32:43 2007 |
| MD5 Checksum: | 7046967c3b96b5660ab26fca76bbd3d7 |
|
| /// File Name: |
sa27146.txt |
Description:
|
Secunia Security Advisory - Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/27146/ | | File Size: | 2441 | | Last Modified: | Oct 10 22:52:18 2007 |
| MD5 Checksum: | 5a9fd8f676e14472ee2ac1bfca6498ec |
|
| /// File Name: |
sa27074.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Hitachi Cosminexus Agent, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/27074/ | | File Size: | 2439 | | Last Modified: | Oct 5 21:33:17 2007 |
| MD5 Checksum: | 9c06fd90fcb04d2b0ad96bc4c5bbbf23 |
|
| /// File Name: |
sa27050.txt |
Description:
|
Secunia Security Advisory - 0in has discovered a vulnerability in Poppawid, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27050/ | | File Size: | 2438 | | Last Modified: | Oct 3 19:13:39 2007 |
| MD5 Checksum: | 4c66edcf64efd168bef5c6809cfe4083 |
|
| /// File Name: |
sa27178.txt |
Description:
|
Secunia Security Advisory - shinnai has discovered a security issue in the ionCube loaders, which can be exploited by malicious, local users to bypass certain access restrictions.
| | Homepage: | http://secunia.com/advisories/27178/ | | File Size: | 2436 | | Last Modified: | Oct 12 20:30:02 2007 |
| MD5 Checksum: | 67f03fc057e0f2bf5bc8fc6990c79b90 |
|
| /// File Name: |
sa27029.txt |
Description:
|
Secunia Security Advisory - Francesco Ongaro and Antonio Parata have discovered a vulnerability in Original Photo Gallery, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27029/ | | File Size: | 2435 | | Last Modified: | Oct 3 16:39:01 2007 |
| MD5 Checksum: | 529d68f05e050b521e7880292d182faf |
|
| /// File Name: |
sa27123.txt |
Description:
|
Secunia Security Advisory - Janek Vind has reported a vulnerability in FCKEditor, which potentially can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27123/ | | File Size: | 2435 | | Last Modified: | Oct 12 00:13:39 2007 |
| MD5 Checksum: | c1119edd56a1e93fbfc512fe3482c95f |
|
| /// File Name: |
sa27139.txt |
Description:
|
Secunia Security Advisory - S.W.A.T. has discovered a vulnerability in LiveAlbum, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27139/ | | File Size: | 2429 | | Last Modified: | Oct 10 00:59:53 2007 |
| MD5 Checksum: | 9e9bd92453cfab86cbbb06dbca21186e |
|
| /// File Name: |
sa27352.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for drupal. This fixes some vulnerabilities, which can be exploited by malicious users to conduct HTTP response splitting attacks, and by malicious people to conduct cross-site request forgery and cross-site scripting attacks, bypass certain security restrictions, and to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27352/ | | File Size: | 2429 | | Last Modified: | Oct 24 23:40:24 2007 |
| MD5 Checksum: | 8360d896eb0cc3f3a10a7ea9f1d6870e |
|
| /// File Name: |
sa27346.txt |
Description:
|
Secunia Security Advisory - Michael Brooks has reported some vulnerabilities in Simple Machines Forum, which can be exploited by malicious users and malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/27346/ | | File Size: | 2427 | | Last Modified: | Oct 22 18:54:34 2007 |
| MD5 Checksum: | 8dfd1e4f44ac86cce4d71429c7dd906f |
|
| /// File Name: |
sa27293.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in vbDrupal, which can be exploited by malicious users to conduct HTTP response splitting attacks, and by malicious people to conduct cross-site scripting and cross-site request forgery attacks, bypass certain security restrictions, and compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27293/ | | File Size: | 2426 | | Last Modified: | Oct 18 17:54:59 2007 |
| MD5 Checksum: | 56bf4ac6a2e397d026248e935516be6f |
|
| /// File Name: |
sa27355.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for flac. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/27355/ | | File Size: | 2425 | | Last Modified: | Oct 23 19:22:54 2007 |
| MD5 Checksum: | 5a3da1dcf200fd22ffe00965fdfa310f |
|
| /// File Name: |
sa27158.txt |
Description:
|
Secunia Security Advisory - Tan Chew Keong has reported a vulnerability in Adobe Pagemaker, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/27158/ | | File Size: | 2424 | | Last Modified: | Oct 10 22:52:18 2007 |
| MD5 Checksum: | 04992f6a47598916c1408b72e75c9a37 |
|
| /// File Name: |
sa27173.txt |
Description:
|
Secunia Security Advisory - Omer Singer has reported a vulnerability in phpMyAdmin, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/27173/ | | File Size: | 2424 | | Last Modified: | Oct 12 00:13:39 2007 |
| MD5 Checksum: | 3e27dbaf0c5de45774eaa81e50166849 |
|
| /// File Name: |
sa27231.txt |
Description:
|
Secunia Security Advisory - A security issue has been reported in Cisco CallManager, which can be exploited by malicious people to hijack user sessions.
| | Homepage: | http://secunia.com/advisories/27231/ | | File Size: | 2424 | | Last Modified: | Oct 19 11:32:30 2007 |
| MD5 Checksum: | bdf17a1a625f51c2c874bf3c11d4b4f3 |
|
| /// File Name: |
sa27189.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in SUSE Linux Enterprise Server, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/27189/ | | File Size: | 2423 | | Last Modified: | Oct 16 00:22:55 2007 |
| MD5 Checksum: | 0a4f39bafaf91fe3ab31d51f9499c444 |
|
| /// File Name: |
sa27394.txt |
Description:
|
Secunia Security Advisory - Sun has acknowledged a vulnerability in Solaris, which potentially can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27394/ | | File Size: | 2422 | | Last Modified: | Oct 29 11:03:58 2007 |
| MD5 Checksum: | 8f84e92ef09a621691ee0cfe37046d2a |
|
| /// File Name: |
sa27055.txt |
Description:
|
Secunia Security Advisory - David Kierznowski has reported a vulnerability in FeedBurner FeedSmith, which can be exploited by malicious people to conduct cross-site request forgery attacks.
| | Homepage: | http://secunia.com/advisories/27055/ | | File Size: | 2421 | | Last Modified: | Oct 5 01:20:47 2007 |
| MD5 Checksum: | ce12f62aab6faacdc0c98bcb540c02db |
|
| /// File Name: |
sa27322.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions and to cause a DoS (Denial of Service), and by malicious people to cause a DoS.
| | Homepage: | http://secunia.com/advisories/27322/ | | File Size: | 2421 | | Last Modified: | Oct 22 14:39:08 2007 |
| MD5 Checksum: | bbf7e0cc16dc11b7bd659c1922a5826e |
|
| /// File Name: |
sa27062.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for elinks. This fixes a weakness, which can be exploited by malicious people to disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/27062/ | | File Size: | 2420 | | Last Modified: | Oct 5 01:20:47 2007 |
| MD5 Checksum: | bcf47a3a809e7392a30c9d8ba1f3b088 |
|
| /// File Name: |
sa27201.txt |
Description:
|
Secunia Security Advisory - Sun has acknowledged a vulnerability in Sun StorageTek 3510 FC Array, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/27201/ | | File Size: | 2420 | | Last Modified: | Oct 16 18:06:25 2007 |
| MD5 Checksum: | e50d050cfaae13dd32ff2f01f1b0df08 |
|
|
|
|
|