Section: .. / 0606-advisories /
| /// File Name: |
SSRT5953-2.txt |
Description:
|
HP Security Bulletin - A potential security vulnerability has been identified with HP-UX running /sbin/passwd which could be locally exploited to create a Denial of Service (DoS).
| | Homepage: | http://www.hp.com/ | | File Size: | 5946 | | Last Modified: | Jul 2 11:36:55 2006 |
| MD5 Checksum: | 35379522f364702cbe7c0509dc32b776 |
|
| /// File Name: |
SSRT5996.txt |
Description:
|
HP Security Bulletin - A potential security vulnerability has been identified with HP-UX mkdir(1). The vulnerability could be exploited by a local user to gain unauthorized access.
| | Homepage: | http://www.hp.com | | File Size: | 5996 | | Last Modified: | Jul 2 11:36:02 2006 |
| MD5 Checksum: | 5885a248ecdb685fddcc37cea9d22638 |
|
| /// File Name: |
hobbit42.txt |
Description:
|
All versions under the 4.2 release of Hobbit prior to 2006-Jun-30 suffer from a flaw where the logfetch utility can be used to read any file on the filesystem.
| | Author: | Henrik Stoerner | | File Size: | 1338 | | Last Modified: | Jul 2 11:30:38 2006 |
| MD5 Checksum: | 00c7b00d096a6972d0ad00603d75d045 |
|
| /// File Name: |
ZDI-06-020.txt |
Description:
|
Apple iTunes suffers from an integer overflow vulnerability when performing AAC file parsing.
| | Author: | ATmaCA | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2586 | | Related CVE(s): | CVE-2006-1467 | | Last Modified: | Jul 2 11:03:54 2006 |
| MD5 Checksum: | 9568b00e86eab1b60b7eea9bb878f07e |
|
| /// File Name: |
glsa-200606-30.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-30 - The iax_net_read function in the iaxclient library fails to properly handle IAX2 packets with truncated full frames or mini-frames. These frames are detected in a length check but processed anyway, leading to buffer overflows. Versions less than 0.8.5_p1 are affected.
| | Homepage: | http://security.gentoo.org/ | | File Size: | 2662 | | Last Modified: | Jul 2 10:35:36 2006 |
| MD5 Checksum: | 0b29c20b7b202f3b37f4a87c7fe4b7ae |
|
| /// File Name: |
NCPbypass.txt |
Description:
|
The NCP VPN/PKI client version 8.30 suffers from a UDP bypass vulnerability in its provided firewall functionality.
| | Author: | ml3 | | File Size: | 2920 | | Last Modified: | Jul 2 10:34:49 2006 |
| MD5 Checksum: | 5df2469e5bfef853ca32a7099d5d83ad |
|
| /// File Name: |
libwmf0284.txt |
Description:
|
libwmf version 0.2.8.4 has been found susceptible to an integer overflow in memory allocation that leads to a heap overflow.
| | Author: | sean | | File Size: | 6940 | | Last Modified: | Jul 2 10:16:24 2006 |
| MD5 Checksum: | 544d8a84acef4d5a6afade28d5179290 |
|
| /// File Name: |
dsa-1104-1.txt |
Description:
|
Debian Security Advisory 1104-1 - Several vulnerabilities have been discovered in OpenOffice.org, a free office suite. It turned out to be possible to embed arbitrary BASIC macros in documents in a way that OpenOffice.org does not see them but executes them anyway without any user interaction. It is possible to evade the Java sandbox with specially crafted Java applets. Loading malformed XML documents can cause buffer overflows and cause a denial of service or execute arbitrary code.
| | Homepage: | http://www.debian.org/security | | File Size: | 14974 | | Related CVE(s): | CVE-2006-2198, CVE-2006-2199, CVE-2006-3117 | | Last Modified: | Jul 2 10:11:49 2006 |
| MD5 Checksum: | cefc0ae21542ef25d3f254cf1cf7e8fa |
|
| /// File Name: |
SSRT061105.txt |
Description:
|
HP Security Bulletin - Potential security vulnerabilities have been identified in Perl 5.8.2 and earlier running on HP Tru64 UNIX. These vulnerabilities could be exploited by a local user to execute unauthorized code.
| | Homepage: | http://www.hp.com | | File Size: | 5873 | | Related CVE(s): | CVE-2005-3962 | | Last Modified: | Jul 2 10:06:33 2006 |
| MD5 Checksum: | 56aa368efda8e86f8a33699326515563 |
|
| /// File Name: |
secunia-phpRaid.txt |
Description:
|
Secunia Research has discovered some vulnerabilities in phpRaid, which can be exploited by malicious people to conduct SQL injection attacks or to compromise a vulnerable system. Versions 3.0.4, 3.0.5, and 3.0.6 are affected.
| | Author: | Sven Krewitt | | Homepage: | http://secunia.com/ | | File Size: | 6133 | | Related CVE(s): | CVE-2006-3115, CVE-2006-3116 | | Last Modified: | Jul 2 09:39:53 2006 |
| MD5 Checksum: | 567128c57aa78ea2aa4c30399cb721f7 |
|
| /// File Name: |
speedstream.txt |
Description:
|
Speedstream routers have UPnP/1.0 support. An attacker can access protected files and bypass the password protection without logging in using the UPnP part of the tree.
| | Author: | Jaime Blasco | | File Size: | 2282 | | Last Modified: | Jul 2 09:34:34 2006 |
| MD5 Checksum: | 5b78c72d204a6b19edd46049d9575a56 |
|
| /// File Name: |
glsa-200606-29.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-29 - Tikiwiki fails to properly sanitize user input before processing it, including in SQL statements. Versions less than 1.9.4 are affected.
| | Homepage: | http://security.gentoo.org/ | | File Size: | 2597 | | Last Modified: | Jul 2 09:22:16 2006 |
| MD5 Checksum: | 950ff506d1204d1b7e7e871c41d677b9 |
|
| /// File Name: |
glsa-200606-28.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-28 - Michael Marek discovered that the Horde Web Application Framework performs insufficient input sanitizing. Versions less than 3.1.1-r1 are affected.
| | Homepage: | http://security.gentoo.org/ | | File Size: | 2591 | | Last Modified: | Jul 2 09:21:43 2006 |
| MD5 Checksum: | 136a990b21ed079ea1a0d1d47561133c |
|
| /// File Name: |
sa20888.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Novell GroupWise, which can be exploited by malicious users to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/20888/ | | File Size: | 3039 | | Last Modified: | Jun 29 20:48:34 2006 |
| MD5 Checksum: | e56cac7593368be62ce0fdcbb1d1da03 |
|
| /// File Name: |
sa20884.txt |
Description:
|
Secunia Security Advisory - rUnViRuS has reported a vulnerability in MKPortal, which can be exploited by malicious people to disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/20884/ | | File Size: | 2176 | | Last Modified: | Jun 29 20:48:34 2006 |
| MD5 Checksum: | 4dc04d70910ec6d8b03db0205066d046 |
|
| /// File Name: |
sa20883.txt |
Description:
|
Secunia Security Advisory - Botan has discovered a vulnerability in PHP iCalendar, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/20883/ | | File Size: | 2273 | | Last Modified: | Jun 29 20:48:34 2006 |
| MD5 Checksum: | 125b843b471bc2a31abaa1be5e948658 |
|
| /// File Name: |
sa20882.txt |
Description:
|
Secunia Security Advisory - KeyCoder has discovered a vulnerability in the MyAds module for Xoops, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/20882/ | | File Size: | 2221 | | Last Modified: | Jun 29 20:48:34 2006 |
| MD5 Checksum: | 15da7b2ccddc3deddef147a2f7810417 |
|
| /// File Name: |
sa20880.txt |
Description:
|
Secunia Security Advisory - luny has reported a vulnerability in PHP/MySQL Classifieds Script, which can be exploited by malicious users to conduct script insertion attacks.
| | Homepage: | http://secunia.com/advisories/20880/ | | File Size: | 2177 | | Last Modified: | Jun 29 20:48:34 2006 |
| MD5 Checksum: | 430e63f7b33c36247b3ec2297479e3a9 |
|
| /// File Name: |
sa20879.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for mutt. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/20879/ | | File Size: | 2551 | | Last Modified: | Jun 29 20:48:34 2006 |
| MD5 Checksum: | 110fd318f0fcb58ade9d05eff9f9432c |
|
| /// File Name: |
sa20877.txt |
Description:
|
Secunia Security Advisory - Apple has issued an update for Mac OS X, which fixes multiple vulnerabilities.
| | Homepage: | http://secunia.com/advisories/20877/ | | File Size: | 3397 | | Last Modified: | Jun 29 20:48:34 2006 |
| MD5 Checksum: | 75c0db9e1bf66ffc1f5bd0a37b128eaf |
|
| /// File Name: |
sa20876.txt |
Description:
|
Secunia Security Advisory - Chris Steipp has reported some vulnerabilities in PatchLink Update Server, which can be exploited by malicious people to conduct SQL injection attacks, manipulate certain information, and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/20876/ | | File Size: | 3023 | | Last Modified: | Jun 29 20:48:34 2006 |
| MD5 Checksum: | ef8841652ef8739583892fe3510996ae |
|
| /// File Name: |
sa20873.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in MyBB, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks, and manipulate certain information.
| | Homepage: | http://secunia.com/advisories/20873/ | | File Size: | 2904 | | Last Modified: | Jun 29 20:48:34 2006 |
| MD5 Checksum: | 3fd6deac2faa2f30143c4de4a5568ff1 |
|
| /// File Name: |
sa20870.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities and a security issue have been reported in Cisco Wireless Control System (WCS), which can be exploited by malicious, local users to gain knowledge of sensitive information, and by malicious people to gain knowledge of sensitive information, conduct cross-site scripting attacks, bypass certain security restrictions and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/20870/ | | File Size: | 4157 | | Last Modified: | Jun 29 20:48:34 2006 |
| MD5 Checksum: | dfcc7ecf6c95a5d5470c591e29efa5f8 |
|
| /// File Name: |
sa20865.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered some vulnerabilities in phpRaid, which can be exploited by malicious people to conduct SQL injection attacks or compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/20865/ | | File Size: | 2892 | | Last Modified: | Jun 29 20:48:34 2006 |
| MD5 Checksum: | 9db6d32c4e47212ef292a1b9b21ae9e4 |
|
|
|
|
|