Section: .. / 0807-advisories /
| /// File Name: |
sa31041.txt |
Description:
|
Secunia Security Advisory - Fugitif has reported some vulnerabilities in eSyndiCat Directory Software, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/31041/ | | File Size: | 2384 | | Last Modified: | Jul 11 18:05:03 2008 |
| MD5 Checksum: | 78a87339041cfcd7e520b1a07fd32c7b |
|
| /// File Name: |
sa31043.txt |
Description:
|
Secunia Security Advisory - Sun has acknowledged some vulnerabilities in Thunderbird included in Sun Solaris, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, conduct cross-site scripting attacks, or compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/31043/ | | File Size: | 2551 | | Last Modified: | Jul 11 18:05:03 2008 |
| MD5 Checksum: | 20e0daa0655facd3b73bed63b7eaea7d |
|
| /// File Name: |
sa31048.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in the Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to potentially gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/31048/ | | File Size: | 2726 | | Last Modified: | Jul 11 18:05:03 2008 |
| MD5 Checksum: | cb00663efd674edecbdfb3d81265700d |
|
| /// File Name: |
sa31050.txt |
Description:
|
Secunia Security Advisory - Julian Rodriguez has discovered some vulnerabilities in Pagefusion, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/31050/ | | File Size: | 2272 | | Last Modified: | Jul 11 18:05:03 2008 |
| MD5 Checksum: | c39232f3aff39be6685d5e10985d996a |
|
| /// File Name: |
sa31051.txt |
Description:
|
Secunia Security Advisory - SUSE has issued an update for MozillaFirefox. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, disclose sensitive information, or potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/31051/ | | File Size: | 4818 | | Last Modified: | Jul 11 18:05:03 2008 |
| MD5 Checksum: | cf4ba3323f29a8830018c1c5f01e51bb |
|
| /// File Name: |
sa31052.txt |
Description:
|
Secunia Security Advisory - SUSE has issued an update for bind. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
| | Homepage: | http://secunia.com/advisories/31052/ | | File Size: | 5778 | | Last Modified: | Jul 11 18:05:03 2008 |
| MD5 Checksum: | 956ced675fafad14308da318b469faa2 |
|
| /// File Name: |
SUSE-SA-2008-033.txt |
Description:
|
SUSE Security Announcement - SUSE has released updates that address the recent cache poisoning vulnerability regarding bind.
| | Homepage: | http://www.suse.com | | File Size: | 16492 | | Related CVE(s): | CVE-2008-1447 | | Last Modified: | Jul 11 18:04:56 2008 |
| MD5 Checksum: | 4eee8765a56b57a922fbf0148e92e177 |
|
| /// File Name: |
MDVSA-2008-143.txt |
Description:
|
Mandriva Linux Security Advisory - An integer overflow flaw was found in Pidgin's MSN protocol handler that could allow for the execution of arbitrary code if a user received a malicious MSN message. In addition, this update provides the ability to use ICQ networks again on Mandriva Linux 2008.0, as in MDVSA-2008:103 (updated pidgin for 2008.1). The updated packages have been patched to correct this issue.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 7955 | | Related CVE(s): | CVE-2008-2927 | | Last Modified: | Jul 10 23:19:52 2008 |
| MD5 Checksum: | 585f78d48977a3a6f020773f8989e0cc |
|
| /// File Name: |
sa30931.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities with unknown impact have been reported in IBM Data ONTAP.
| | Homepage: | http://secunia.com/advisories/30931/ | | File Size: | 2171 | | Last Modified: | Jul 10 21:33:05 2008 |
| MD5 Checksum: | 843ffd281919403d2a0d6d30f5e7a006 |
|
| /// File Name: |
sa31019.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for bind. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
| | Homepage: | http://secunia.com/advisories/31019/ | | File Size: | 2074 | | Last Modified: | Jul 10 21:33:05 2008 |
| MD5 Checksum: | 45118413318789173225acb96bb41509 |
|
| /// File Name: |
sa31021.txt |
Description:
|
Secunia Security Advisory - Slackware has issued an update for mozilla-firefox. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, disclose sensitive information, or potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/31021/ | | File Size: | 2729 | | Last Modified: | Jul 10 21:33:05 2008 |
| MD5 Checksum: | 00f50e5f69d54f15833b45668e8f09ed |
|
| /// File Name: |
sa31027.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in the OpenID module for Drupal, which can be exploited by malicious people to conduct cross-site scripting or cross-site request forgery attacks.
| | Homepage: | http://secunia.com/advisories/31027/ | | File Size: | 2509 | | Last Modified: | Jul 10 21:33:05 2008 |
| MD5 Checksum: | 7fdaaf64d48eab7c6584b531ea74eec6 |
|
| /// File Name: |
sa31029.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for openoffice and openoffice-bin. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/31029/ | | File Size: | 2073 | | Last Modified: | Jul 10 18:53:11 2008 |
| MD5 Checksum: | 93e6aec5a0255c4d2f1c8ea64264dd57 |
|
| /// File Name: |
07.09.08-1.txt |
Description:
|
iDefense Security Advisory 07.09.08 - Remote exploitation of a heap buffer overflow vulnerability in Novell Inc.'s eDirectory could allow an attacker to execute arbitrary code with the privileges of the affected service. The vulnerability exists due to an incorrect calculation when allocating a heap buffer to store the search parameters. By passing NULL search parameters, it is possible to overflow a heap based buffer with the string "(null)". This can result in the corruption of heap management structures, and depending on the layout of the heap, possibly function pointers. iDefense has confirmed the existence of this vulnerability in eDirectory version 8.8 SP2 for Linux. Other versions may also be affected.
| | Homepage: | http://www.idefense.com/ | | File Size: | 3583 | | Related CVE(s): | CVE-2008-1809 | | Last Modified: | Jul 10 18:52:18 2008 |
| MD5 Checksum: | 394dfb4afcb412feb3f9e7d2d0495f4e |
|
| /// File Name: |
ZDI-08-041.txt |
Description:
|
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell eDirectory. Authentication is not required to exploit this vulnerability. The specific flaw exists within dhost.exe, bound by default to TCP port 524. Flawed arithmetic applied to a user-supplied value results in an integer overflow and subsequently a complete stack smash allowing an attacker to execute arbitrary code via SEH redirection.
| | Author: | Sebastian Apelt | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3388 | | Last Modified: | Jul 10 18:50:57 2008 |
| MD5 Checksum: | 9cfa34b6bf73c1a556194e079dd0e523 |
|
| /// File Name: |
sa30996.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for openldap. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/30996/ | | File Size: | 2337 | | Last Modified: | Jul 10 18:48:53 2008 |
| MD5 Checksum: | 3058017ef3b23b9519d331f9520b1fea |
|
| /// File Name: |
sa31023.txt |
Description:
|
Secunia Security Advisory - Slackware has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, disclose sensitive information, or potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/31023/ | | File Size: | 2719 | | Last Modified: | Jul 10 18:48:53 2008 |
| MD5 Checksum: | 5d969ed775e1d09a7ce07bd71a14c485 |
|
| /// File Name: |
msowa-xss.txt |
Description:
|
Several cross site scripting vulnerabilities were found in within Outlook Web Access (OWA) 2003/2007. An attacker can craft a malicious email which will trigger within a user's browser. Different version of OWA and different clients (Light and Premium) have different attack vectors which can result in an attacker gaining persistent control over a victim's use of Outlook Web Access.
| | Author: | Michael Jordon | | Homepage: | http://www.contextis.co.uk/ | | File Size: | 3890 | | Related CVE(s): | CVE-2008-2247, CVE-2008-2248 | | Last Modified: | Jul 10 18:46:39 2008 |
| MD5 Checksum: | 0592215043fc314dfab9727e7150652a |
|
| /// File Name: |
sa31000.txt |
Description:
|
Secunia Security Advisory - k1tk4t has reported a vulnerability in AuraCMS, which can be exploited by malicious people to manipulate certain data.
| | Homepage: | http://secunia.com/advisories/31000/ | | File Size: | 2113 | | Last Modified: | Jul 10 18:39:19 2008 |
| MD5 Checksum: | 60329dad083fed3084001dc169800f96 |
|
| /// File Name: |
sa31009.txt |
Description:
|
Secunia Security Advisory - Hussin X has reported a vulnerability in DreamPics Builder, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/31009/ | | File Size: | 2088 | | Last Modified: | Jul 10 18:39:19 2008 |
| MD5 Checksum: | 049ec6465af4b42d865546d2e4ba7891 |
|
| /// File Name: |
sa31020.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for java-1.7.0-icedtea. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose system information or potentially sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/31020/ | | File Size: | 2238 | | Last Modified: | Jul 10 18:39:19 2008 |
| MD5 Checksum: | d58cc4aa714055f8d1aad1cc5244655f |
|
| /// File Name: |
sa31022.txt |
Description:
|
Secunia Security Advisory - Slackware has issued an update for bind. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
| | Homepage: | http://secunia.com/advisories/31022/ | | File Size: | 3361 | | Last Modified: | Jul 10 18:39:19 2008 |
| MD5 Checksum: | 11ab95722a0fbdb18bdda36a6df884a6 |
|
| /// File Name: |
sa31024.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in vbDrupal, which can be exploited by malicious people to conduct cross-site scripting, cross-site request forgery, session fixation, SQL injection, and script insertion attacks.
| | Homepage: | http://secunia.com/advisories/31024/ | | File Size: | 2049 | | Last Modified: | Jul 10 18:39:19 2008 |
| MD5 Checksum: | 0f00c3bee1744f9a61e1117183683e37 |
|
| /// File Name: |
sa31025.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for nx. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/31025/ | | File Size: | 2127 | | Last Modified: | Jul 10 18:39:19 2008 |
| MD5 Checksum: | a4381c6ab86956d41f5c19d642d29927 |
|
| /// File Name: |
sa31026.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for apache. This fixes a some vulnerabilities, which can be exploited by malicious people to conduct cross-site request forgery attacks and cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/31026/ | | File Size: | 2053 | | Last Modified: | Jul 10 18:39:19 2008 |
| MD5 Checksum: | 629a25b4874211ba8a668971b9605bb3 |
|
|
|
|
|