exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 977 RSS Feed

Files Date: 2012-02-01 to 2012-02-29

Mandriva Linux Security Advisory 2012-023-1
Posted Feb 28, 2012
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2012-023 - A vulnerability has been found and corrected in libvpx. VP8 Codec SDK before 1.0.0 Duclair allows remote attackers to cause a denial of service unspecified corrupt input or by starting decoding from a P-frame, which triggers an out-of-bounds read, related to the clamping of motion vectors in SPLITMV blocks. The updated packages have been patched to correct this issue. This is a symbolic advisory correction because there was a clash with MDVSA-2012:023 that addressed libxml2.

tags | advisory, remote, denial of service
systems | linux, mandriva
advisories | CVE-2012-0823
SHA-256 | 5760ddad7ab7f5d50d45e9d6d2b01846dcf94ede1f8a9d2ef97fe65d6bc27c3f
Mandriva Linux Security Advisory 2012-022-1
Posted Feb 28, 2012
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2012-022 - Security issues were identified and fixed in mozilla firefox and thunderbird. An integer overflow in the libpng library can lead to a heap-buffer overflow when decompressing certain PNG images. This leads to a crash, which may be potentially exploitable. The mozilla firefox and thunderbird packages have been upgraded to the latest respective versions which is not affected by this security flaw. Additionally the rootcerts packages has been upgraded to the latest version as of 2012/02/18 and the NSS library has been rebuilt accordingly to pickup the changes. This is a symbolic advisory correction because there was a clash with MDVSA-2012:022 that addressed libpng.

tags | advisory, overflow
systems | linux, mandriva
advisories | CVE-2011-3026
SHA-256 | 6c745d9d52173219392680d02b0a80f2ccd95e95f7941c4746e37f33fda62ceb
Mandriva Linux Security Advisory 2012-025
Posted Feb 28, 2012
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2012-025 - Heap-based buffer overflow in process.c in smbd in Samba allows remote attackers to cause a denial of service or possibly execute arbitrary code via a Batched request that triggers infinite recursion. The updated packages have been patched to correct this issue.

tags | advisory, remote, denial of service, overflow, arbitrary
systems | linux, mandriva
advisories | CVE-2012-0870
SHA-256 | af6946ff7346145357d5f9633e3b4cabee3c482c6018138fa764fa1f07c698c8
Mandriva Linux Security Advisory 2012-024
Posted Feb 28, 2012
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2012-024 - Ruby before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service via crafted input to an application that maintains a hash table. The updated packages have been patched to correct this issue.

tags | advisory, denial of service, ruby
systems | linux, mandriva
advisories | CVE-2011-4815
SHA-256 | 44b5393632217703390da470f7fefc75b8bdaafb0b6e2a9d36de950d30ad3bcd
darkb0t IRC Python Bot 0.3
Posted Feb 28, 2012
Authored by baltazar

darkb0t is an IRC bot written in Python that is capable of doing reverse DNS lookups, google dork searching, performing link checking on SQL injection, and more.

Changes: Added new checks.
tags | sql injection, python
SHA-256 | fc4219efe6ae1275b002e2675f490152ed141e4cb8ee0e508199e6134eff932d
Ubuntu Security Notice USN-1377-1
Posted Feb 28, 2012
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 1377-1 - Drew Yao discovered that the WEBrick HTTP server was vulnerable to cross-site scripting attacks when displaying error pages. A remote attacker could use this flaw to run arbitrary web script. Drew Yao discovered that Ruby's BigDecimal module did not properly allocate memory on 64-bit platforms. An attacker could use this flaw to cause a denial of service or possibly execute arbitrary code with user privileges. Various other issues were also addressed.

tags | advisory, remote, web, denial of service, arbitrary, xss, ruby
systems | linux, ubuntu
advisories | CVE-2010-0541, CVE-2011-0188, CVE-2011-1004, CVE-2011-1005, CVE-2011-2686, CVE-2011-2705, CVE-2011-4815, CVE-2010-0541, CVE-2011-0188, CVE-2011-1004, CVE-2011-1005, CVE-2011-2686, CVE-2011-2705, CVE-2011-4815
SHA-256 | cec298eba7976ebaa181ffd4c17d9f86fd8b7f0120e64642a7761c57933776cd
Metasploit Low Level View
Posted Feb 28, 2012
Authored by Saad Talaat

Whitepaper called Metasploit: Low Level View. It touches on topics such as code injection and malware detection evasion / Metasploit encoders.

tags | paper
SHA-256 | 07e3eb3f9a8a6d81bd3f80976de99d9b360b6c9b90ddb4432b6343a6f12cc0c2
ImgPals Photo Host 1.0 Stable Admin Account Deactivation
Posted Feb 28, 2012
Authored by CorryL

ImgPals Photo Host version 1.0 STABLE suffers from a remote administrative account disabling vulnerability.

tags | exploit, remote
SHA-256 | 8c780762899fca7c8bc34cb516d77adf4aed068e1971cb7d7c17d6457fafd235
REC0N 2012 Call For Papers
Posted Feb 28, 2012
Authored by REC0N 2012 | Site recon.cx

The REC0N 2012 Call For Papers has been announced. It will take place June 14th through June 16h, 2012 in Montreal, Canada.

tags | paper, conference
SHA-256 | d8be753bc58b7479ec005c38ff804b7f008e8d9737d33209f5c4b6326927ca60
Ubuntu Security Notice USN-1375-1
Posted Feb 28, 2012
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 1375-1 - The httplib2 Python library earlier than version 0.7.0 did not perform any server certificate validation when using HTTPS connections. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to alter or compromise confidential information in applications that used the httplib2 library.

tags | advisory, remote, web, python
systems | linux, ubuntu
SHA-256 | a63a7a4c0796d2e294993168bb60e26b7a9fa704397e1fe1bdc13730e913f609
Gentoo Linux Security Advisory 201202-07
Posted Feb 28, 2012
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201202-7 - Multiple vulnerabilities were found in libvirt, the worst of which might allow guest OS users to read arbitrary files on the host OS. Versions less than 0.9.3-r1 are affected.

tags | advisory, arbitrary, vulnerability
systems | linux, gentoo
advisories | CVE-2011-1146, CVE-2011-1486, CVE-2011-2178, CVE-2011-2511
SHA-256 | 174a3477cdb83676abe9282ccb2195b63c18c5ee3d51f67ae0d74c3aeffc9587
Ubuntu Security Notice USN-1376-1
Posted Feb 28, 2012
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 1376-1 - Juraj Somorovsky discovered that libxml2 was vulnerable to hash table collisions. If a user or application linked against libxml2 were tricked into opening a specially crafted XML file, an attacker could cause a denial of service.

tags | advisory, denial of service
systems | linux, ubuntu
advisories | CVE-2012-0841
SHA-256 | 073bc618e97ea21ba50aa4f143095cd3ce54bb7398fe488d63f3e1eda1db3105
Debian Security Advisory 2419-1
Posted Feb 28, 2012
Authored by Debian | Site debian.org

Debian Linux Security Advisory 2419-1 - Two vulnerabilities were discovered in Puppet, a centralized configuration management tool.

tags | advisory, vulnerability
systems | linux, debian
advisories | CVE-2012-1053, CVE-2012-1054
SHA-256 | 11d35b7f35e7ba4a7e843737818ea54afa99b8b4146c843dba48c5f54f55e6d0
Debian Security Advisory 2418-1
Posted Feb 28, 2012
Authored by Debian | Site debian.org

Debian Linux Security Advisory 2418-1 - Several local vulnerabilities have been discovered in PostgreSQL, an object-relational SQL database.

tags | advisory, local, vulnerability
systems | linux, debian
advisories | CVE-2012-0866, CVE-2012-0867, CVE-2012-0868
SHA-256 | 11a657217072f0210bb50b55f2208a3bed8d0b8e9a9900e5683fd14a41024efb
Debian Security Advisory 2414-2
Posted Feb 28, 2012
Authored by Debian | Site debian.org

Debian Linux Security Advisory 2414-2 - It was discovered that the last security update for F*X, DSA-2414-1, introduced a regression. Updated packages are now available to address this problem.

tags | advisory
systems | linux, debian
advisories | CVE-2012-0869
SHA-256 | 163b9eaa211f872e647739bda275ef73dadabe562d1e45464ced23724f4d2944
Microsoft AdCenter Service Cross Site Scripting
Posted Feb 27, 2012
Authored by longrifle0x, Vulnerability Laboratory | Site vulnerability-lab.com

Microsoft AdCenter Service at advertising.microsoft.com suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | bfc3b732d673df4880817aa7756d4afdd7c03f172b1d0eec1bcb0099bf1d84cb
DeepSec 2012 Call For Papers
Posted Feb 27, 2012
Site deepsec.net

DeepSec 2012 Call For Papers - "Sector v6" will be held November 27th to the 30th, 2012 in Austria.

tags | paper, conference
SHA-256 | bf095e6d0d3623b8f974e12bbcf45836644c033d55b9a4139a9f2ff5cc9d6c0b
Sysax 5.53 SSH Username Buffer Overflow Exploit
Posted Feb 27, 2012
Authored by Craig Freyman

Sysax Multi Server versions 5.53 and below SSH username buffer overflow pre-authentication remote code execution exploit with egghunter shellcode that binds a shell to port 4444.

tags | exploit, remote, overflow, shell, shellcode, code execution
SHA-256 | 1a9e244ba23211e8a0745f4370e9f10d0e94ad75ca261b64e8e40b6e0606839f
Sysax Multi Server 5.53 SFTP Post Auth SEH Exploit
Posted Feb 27, 2012
Authored by Craig Freyman

Sysax Multi Server version 5.53 SFTP post authentication SEH exploit with egghunter shellcode that binds a shell to port 4444.

tags | exploit, shell, shellcode
SHA-256 | e3ee80f9e583422dca0ef40fef6b1c192c1da12311e53628b885e95e7f419bbe
Socusoft Photo 2 Video 8.05 Buffer Overflow
Posted Feb 27, 2012
Authored by Julien Ahrens, Vulnerability Laboratory | Site vulnerability-lab.com

Socusoft Photo 2 Video version 8.05 suffers from a buffer overflow vulnerability.

tags | exploit, overflow
SHA-256 | ec0e7d80300a84c40d226a2e9521bc1913c77ea22caf5e0a89c1471ddcca54d6
OSQA CMS 3b Cross Site Scripting
Posted Feb 27, 2012
Authored by longrifle0x, Vulnerability Laboratory | Site vulnerability-lab.com

OSQA CMS version 3b suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 8ccd9aaca10f4913b22f49de9b319d8b4ec82f417d7ad5124948fd42f0a4705a
Wolf CMS 0.7.5 Cross Site Scripting / SQL Injection
Posted Feb 27, 2012
Authored by longrifle0x, Vulnerability Laboratory | Site vulnerability-lab.com

Wolf CMS version 0.7.5 suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | b9e7ab88017430740c0d855ac83d248cf03578f89ecbe93156b18443bc9dec1b
Mozilla Firefox 4.0.1 Integer Overflow
Posted Feb 27, 2012
Authored by pa_kt

Mozilla Firefox version 4.0.1 Array.reduceRight() integer overflow exploit.

tags | exploit, overflow
advisories | CVE-2011-2371
SHA-256 | 7765d8391885eb46e7e47c01a9ee30c61bc0afc6001023851f365b67c51d6eae
Lorewing Design SQL Injection
Posted Feb 27, 2012
Authored by Th4 MasK

Lorewing Design suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | d37d692264cf19a734d977818b9ec9b8557419b10765c6da0bead9c994c984df
Kongreg8 1.7.3 Cross Site Scripting
Posted Feb 27, 2012
Authored by G13

Kongreg8 version 1.7.3 suffers from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | abdf8efff96ddecb1a404dedbb3ce6abfd572e08b10ca43308a053c807578f6b
Page 1 of 40
Back12345Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close