Section: .. / Last 20 Files /
| /// File Name: | cisco-sa-20080514-cup.txt | Description:
| Cisco Security Advisory - Administrators of systems running all Cisco Unified Presence versions can determine the software version by viewing the main page of the Cisco Unified Presence Administration interface. The software version can be determined by running the command show version active via the Command Line Interface (CLI). | | Homepage: | http://www.cisco.com/ | | File Size: | 11779 | | Related CVE(s): | CVE-2008-1740, CVE-2008-1741 | | Last Modified: | May 15 04:28:20 2008 | | MD5 Checksum: | fddfe8a3e45e0c202a50e5bc67fa484a |
|
| /// File Name: | cisco-sa-20080514-csm.txt | Description:
| Cisco Security Advisory - The Cisco Content Switching Module (CSM) and Cisco Content Switching Module with SSL (CSM-S) contain a memory leak vulnerability that can result in a denial of service condition. The vulnerability exists when the CSM or CSM-S is configured for layer 7 load balancing. An attacker can trigger this vulnerability when the CSM or CSM-S processes TCP segments with a specific combination of TCP flags while servers behind the CSM/CSM-S are overloaded and/or fail to accept a TCP connection. | | Homepage: | http://www.cisco.com/ | | File Size: | 17388 | | Related CVE(s): | CVE-2008-1749 | | Last Modified: | May 15 04:25:13 2008 | | MD5 Checksum: | 0a7dfcd9f771e114ed6eafdd02388931 |
|
| /// File Name: | debian-sploit.txt | Description:
| A nice walk through discussing step by step how to brute force ssh logins using the recent Debian OpenSSL random number generator vulnerability. | | Author: | Markus Mueller | | File Size: | 1649 | | Last Modified: | May 15 04:21:12 2008 | | MD5 Checksum: | bc660b433dce3c75055028112f9966d3 |
|
| /// File Name: | EC2ND-2008-CFP.txt | Description:
| Call For Papers for EC2ND. The fourth annual EC2ND conference will take place on December 11th and 12th 2008 in the Faculty of Engineering and Computing at Dublin City University. | | Homepage: | http://2008.ec2nd.org/ | | File Size: | 4073 | | Last Modified: | May 15 04:19:00 2008 | | MD5 Checksum: | 25512bf60111f41dda218b3da90bc361 |
|
| /// File Name: | sqlfuzzer.py.txt | Description:
| SQL Injector version 1.0 is a fuzzing utility written in Python. | | Author: | Beenu Arora | | File Size: | 775 | | Last Modified: | May 15 04:17:36 2008 | | MD5 Checksum: | 30658df42570e5cc8bf5a21363643df6 |
|
| /// File Name: | xsschecker.py.txt | Description:
| Cross site scripting fuzzing utility written in Python. | | Author: | Beenu Arora | | File Size: | 1945 | | Last Modified: | May 15 04:16:34 2008 | | MD5 Checksum: | 87e7d424c10d56a7fc8c08dc5f96dc2a |
|
| /// File Name: | msie-crosszone.txt | Description:
| Microsoft Internet Explorer is prone to a cross-zone scripting vulnerability in its Print Table of Links feature. | | Author: | Aviv Raff | | Homepage: | http://aviv.raffon.net/ | | File Size: | 2188 | | Last Modified: | May 15 04:14:42 2008 | | MD5 Checksum: | ac941e58ffb4c9380b7ee22bd963676f |
|
| /// File Name: | win32-generator.txt | Description:
| win32 Download and Execute shellcode generator (browsers edition). | | Author: | YAG KOHHA | | File Size: | 2830 | | Last Modified: | May 15 03:52:57 2008 | | MD5 Checksum: | 3f071fcc1f92a0892c3107f22313a641 |
|
| /// File Name: | dsa-1577-1.txt | Description:
| Debian Security Advisory 1577-1 - Stephen Gran and Mark Hymers discovered that some scripts run by GForge, a collaborative development tool, open files in write mode in a potentially insecure manner. This may be exploited to overwrite arbitrary files on the local system. | | Homepage: | http://www.debian.org/security | | File Size: | 5237 | | Related CVE(s): | CVE-2008-0167 | | Last Modified: | May 15 03:51:39 2008 | | MD5 Checksum: | 81f578fa45368e855560e91c2dd60d4e |
|
| /// File Name: | dsa-1576-1.txt | Description:
| Debian Security Advisory 1576-1 - The recently announced vulnerability in Debian's openssl package (DSA-1571-1, CVE-2008-0166) indirectly affects OpenSSH. As a result, all user and host keys generated using broken versions of the openssl package must be considered untrustworthy, even after the openssl update has been applied. | | Homepage: | http://www.debian.org/security | | File Size: | 15197 | | Related CVE(s): | CVE-2008-0166 | | Last Modified: | May 15 03:50:46 2008 | | MD5 Checksum: | a79fd4e6e656f73f69d8c73cf16f3723 |
|
| /// File Name: | glsa-200805-15.txt | Description:
| Gentoo Linux Security Advisory GLSA 200805-15 - Kentaro Oda reported an infinite loop in the file field.c when parsing an MP3 file with an ID3_FIELD_TYPE_STRINGLIST field that ends in '\0'. Versions less than 0.15.1b-r2 are affected. | | Homepage: | http://security.gentoo.org | | File Size: | 2415 | | Related CVE(s): | CVE-2008-2109 | | Last Modified: | May 15 03:49:12 2008 | | MD5 Checksum: | a924bb8eeda8ff0dbe39e3cd31978d5e |
|
| /// File Name: | USN-612-6.txt | Description:
| Ubuntu Security Notice 612-6 - USN-612-3 addressed a weakness in OpenSSL certificate and keys generation in OpenVPN by adding checks for vulnerable certificates and keys to OpenVPN. A regression was introduced in OpenVPN when using TLS and multi-client/server which caused OpenVPN to not start when using valid SSL certificates. It was also found that openssl-vulnkey from openssl-blacklist would fail when stderr was not available. This caused OpenVPN to fail to start when used with applications such as NetworkManager. A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain encryption keys are much more common than they should be, such that an attacker could guess the key through a brute-force attack given minimal knowledge of the system. This particularly affects the use of encryption keys in OpenSSH, OpenVPN and SSL certificates. This vulnerability only affects operating systems which (like Ubuntu) are based on Debian. However, other systems can be indirectly affected if weak keys are imported into them. | | Homepage: | http://security.ubuntu.com/ | | File Size: | 8081 | | Related CVE(s): | CVE-2008-0166 | | Last Modified: | May 15 03:47:36 2008 | | MD5 Checksum: | 1b121b32f5b219bf781da551ba98e314 |
|
| /// File Name: | USN-612-5.txt | Description:
| Ubuntu Security Notice 612-5 - Matt Zimmerman discovered that entries in ~/.ssh/authorized_keys with options (such as "no-port-forwarding" or forced commands) were ignored by the new ssh-vulnkey tool introduced in OpenSSH (see USN-612-2). This could cause some compromised keys not to be listed in ssh-vulnkey's output. A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain encryption keys are much more common than they should be, such that an attacker could guess the key through a brute-force attack given minimal knowledge of the system. This particularly affects the use of encryption keys in OpenSSH, OpenVPN and SSL certificates. This vulnerability only affects operating systems which (like Ubuntu) are based on Debian. However, other systems can be indirectly affected if weak keys are imported into them. | | Homepage: | http://security.ubuntu.com/ | | File Size: | 16139 | | Related CVE(s): | CVE-2008-0166 | | Last Modified: | May 15 03:46:36 2008 | | MD5 Checksum: | 12c2407158560e7b8cd3525552c71aec |
|
| /// File Name: | USN-612-4.txt | Description:
| Ubuntu Security Notice 612-4 - USN-612-1 fixed vulnerabilities in openssl. This update provides the corresponding updates for ssl-cert -- potentially compromised snake-oil SSL certificates will be regenerated. A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain encryption keys are much more common than they should be, such that an attacker could guess the key through a brute-force attack given minimal knowledge of the system. This particularly affects the use of encryption keys in OpenSSH, OpenVPN and SSL certificates. This vulnerability only affects operating systems which (like Ubuntu) are based on Debian. However, other systems can be indirectly affected if weak keys are imported into them. | | Homepage: | http://security.ubuntu.com/ | | File Size: | 4207 | | Related CVE(s): | CVE-2008-0166 | | Last Modified: | May 15 03:45:47 2008 | | MD5 Checksum: | fbb384be18c0b97874a042383317e896 |
|
| /// File Name: | rgboard-rfixss.txt | Description:
| Rgboard versions 3.0.12 and below suffer from remote file inclusion and cross site scripting vulnerabilities. | | Author: | e.wiZz! | | File Size: | 1500 | | Last Modified: | May 15 03:42:51 2008 | | MD5 Checksum: | f28af15ada7cfa6dd19a7611e4129ee5 |
|
| /// File Name: | hordeturba-xss.txt | Description:
| Horde and Turbo Contact Manager suffers from multiple cross site scripting vulnerabilities. | | Author: | Ivan Sanchez | | Homepage: | http://www.nullcode.com.ar/ | | File Size: | 1639 | | Last Modified: | May 15 03:41:40 2008 | | MD5 Checksum: | 6eadbbe84f8cd8b298ef48dbfbf36532 |
|
|
|
|
|