what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 50 of 99 RSS Feed

Files Date: 2007-11-26 to 2007-11-27

dxmsft-overflow.txt
Posted Nov 26, 2007
Authored by Elazar Broad

Multiple stack overflows exist in dxmsft.dll version 6.3.2900.3199 (Image DirectX Transforms). Proof of concept included.

tags | exploit, overflow, proof of concept
SHA-256 | 1b85d83ec0370ebc75c7b10a611ff9fcd7a11423b1a70abdadf3cecff9ca49b7
Gentoo Linux Security Advisory 200711-28
Posted Nov 26, 2007
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200711-28 - Tavis Ormandy and Will Drewry (Google Security Team) discovered a heap-based buffer overflow in the Regular Expression engine (regcomp.c) that occurs when switching from byte to Unicode (UTF-8) characters in a regular expression. Versions less than 5.8.8-r4 are affected.

tags | advisory, overflow
systems | linux, gentoo
advisories | CVE-2007-5116
SHA-256 | 769a4ef5ba214baf68c09b6f6ac71052ca6e71e3e526c72a4a6c1e5539995b89
wordpress-cookie-auth.txt
Posted Nov 26, 2007
Authored by Steven J. Murdoch | Site cl.cam.ac.uk

Wordpress versions 1.5 through 2.3.1 suffer from a cookie authentication vulnerability.

tags | advisory
SHA-256 | dcf620597516557871bd390192f9dd05e32ea32acc9591a2243559cb230b97ad
Mandriva Linux Security Advisory 2007.225
Posted Nov 26, 2007
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory - The SNMP agent in net-snmp 5.4.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a GETBULK request with a large max-repeaters value.

tags | advisory, remote, denial of service
systems | linux, mandriva
advisories | CVE-2007-5846
SHA-256 | 988809a993837cdc067f4db99495ab39ba79bcf1b42aba30a5fcd539c60547a6
citrix-xss.txt
Posted Nov 26, 2007
Authored by nnposter

Citrix NetScaler version 8.0 suffers from a cross site scripting vulnerability in the web management interface.

tags | exploit, web, xss
SHA-256 | 8426e8030866ae4e9293a3c8ac554e49da50c56b21b4b5d5eaff85db4813d8ec
omnipcx-reroute.txt
Posted Nov 26, 2007
Authored by Daniel Stirnimann | Site csnc.ch

The Alcatel OmniPCX Enterprise VoIP system versions 7.1 and below are susceptible to a audio stream reroute vulnerability.

tags | advisory
SHA-256 | d29537c266f821c0cf2d28d26b204741fde07dfd462299873ecfdbe79f73a3b3
joomlajuser-rfi.txt
Posted Nov 26, 2007
Authored by NoGe

The Joomla component JUser version 1.0.14 suffers from a remote file inclusion vulnerability.

tags | exploit, remote, code execution, file inclusion
SHA-256 | d70cc245adce09458cd457fc2ceb3e1b324393cd6c907f460443b0de5be27e0a
clickbanex-sql.txt
Posted Nov 26, 2007
Authored by The-0utl4w | Site aria-security.net

ClickAndBaneX suffers from a SQL injection vulnerability.

tags | exploit, sql injection
SHA-256 | 3b3d7a737db6b0af5e55544c3bd8999a534b75fb7e9e515298c841423a949e89
Gentoo Linux Security Advisory 200711-27
Posted Nov 26, 2007
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200711-27 - Alin Rad Pop from Secunia Research discovered a boundary error in the function separate_sentence() in file tokenize.c when processing an overly long word which might lead to a stack-based buffer overflow. Versions less than 4.2.4-r1 are affected.

tags | advisory, overflow
systems | linux, gentoo
advisories | CVE-2007-5395
SHA-256 | 3422987a83a99edd74624803a9b23872643492b4b2340e20ec2e6035077b1935
Gentoo Linux Security Advisory 200711-26
Posted Nov 26, 2007
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200711-26 - Joachim Schrod discovered several buffer overflow vulnerabilities and an insecure temporary file creation in the dvilj application that is used by dvips to convert DVI files to printer formats. Bastien Roucaries reported that the dvips application is vulnerable to two stack-based buffer overflows when processing DVI documents with long \href{} URIs. teTeX also includes code from Xpdf that is vulnerable to a memory corruption and two heap-based buffer overflows (GLSA 200711-22); and it contains code from T1Lib that is vulnerable to a buffer overflow when processing an overly long font filename (GLSA 200710-12). Versions less than 3.0_p1-r6 are affected.

tags | advisory, overflow, vulnerability
systems | linux, gentoo
advisories | CVE-2007-5935, CVE-2007-5936, CVE-2007-5937
SHA-256 | f85e6812ccb3c629600cfb843c3cc21c6dc61a44005ea7f1ddc7406ce7c155fd
Gentoo Linux Security Advisory 200711-25
Posted Nov 26, 2007
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200711-25 - Joe Gallo and Artem Russakovskii reported an error in the convert_search_mode_to_innobase() function in ha_innodb.cc in the InnoDB engine that is leading to a failed assertion when handling CONTAINS operations. Versions less than 5.0.44-r2 are affected.

tags | advisory
systems | linux, gentoo
advisories | CVE-2007-5925
SHA-256 | 8a44317ed2cdce532a1bec6c0df6f1c71a2072e98aeacb643fe5635596e10b4b
Gentoo Linux Security Advisory 200711-24
Posted Nov 26, 2007
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200711-24 - Multiple vulnerabilities have been reported in Mozilla Thunderbird's HTML browser engine and JavaScript engine that can be exploited to cause a memory corruption. Versions less than 2.0.0.9 are affected.

tags | advisory, javascript, vulnerability
systems | linux, gentoo
advisories | CVE-2007-5339, CVE-2007-5340
SHA-256 | c926415fb8614d2ec0a289182c798f9506d21916479b72febb2c28f46ab81920
Gentoo Linux Security Advisory 200711-23
Posted Nov 26, 2007
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200711-23 - Multiple vulnerabilities have been discovered in several VMware products. Neel Mehta and Ryan Smith (IBM ISS X-Force) discovered that the DHCP server contains an integer overflow vulnerability, an integer underflow vulnerability and another error when handling malformed packets, leading to stack-based buffer overflows or stack corruption. Rafal Wojtczvk (McAfee) discovered two unspecified errors that allow authenticated users with administrative or login privileges on a guest operating system to corrupt memory or cause a Denial of Service. Another unspecified vulnerability related to untrusted virtual machine images was discovered. Versions less than 6.0.1.55017 are affected.

tags | advisory, denial of service, overflow, vulnerability
systems | linux, gentoo
advisories | CVE-2004-0813, CVE-2006-3619, CVE-2006-4146, CVE-2006-4600, CVE-2007-0061, CVE-2007-0062, CVE-2007-0063, CVE-2007-1716, CVE-2007-4496, CVE-2007-4497, CVE-2007-5617
SHA-256 | a3526d292c687ba2acc51426a177e22a29167c158a791debbef984335b9765fc
Gentoo Linux Security Advisory 200711-22
Posted Nov 26, 2007
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200711-22 - Alin Rad Pop (Secunia Research) discovered several vulnerabilities in the Stream.cc file of Xpdf: An integer overflow in the DCTStream::reset() method and a boundary error in the CCITTFaxStream::lookChar() method, both leading to heap-based buffer overflows. He also discovered a boundary checking error in the DCTStream::readProgressiveDataUnit() method causing memory corruption. Note: Gentoo's version of Xpdf is patched to use the Poppler library, so the update to Poppler will also fix Xpdf. Versions less than 0.6.1-r1 are affected.

tags | advisory, overflow, vulnerability
systems | linux, gentoo
advisories | CVE-2007-4352, CVE-2007-5392, CVE-2007-5393
SHA-256 | 5f52b9f84d9302e6e300d1d2e51875e562148246b4abd18aa941c15e42413c79
certspoof.txt
Posted Nov 26, 2007
Authored by Nils Toedtmann

Mozilla based browsers (Firefox, Netscape, etc), Konqueror and Safari 2 do not bind a user-approved webserver certificate to the originating domain name. This makes the user vulnerable to certificate spoofing by "subjectAltName:dNSName" extensions.

tags | advisory, spoof
SHA-256 | bea6d858652bffab5a7023af650bba3ef9010cf7d7f2166821b4a21d8b7abec7
live555x.zip
Posted Nov 26, 2007
Authored by Luigi Auriemma | Site aluigi.org

Proof of concept exploit that demonstrates a memory accession violation in LIVE555 Media Server versions 2007.11.01 and below.

tags | exploit, proof of concept
SHA-256 | 19fc2a72d6bcf1168854357be19ce52bc3f50bd6a2aa90a33934b95524f532c0
live555x.txt
Posted Nov 26, 2007
Authored by Luigi Auriemma | Site aluigi.org

LIVE555 Media Server versions 2007.11.01 and below suffer from a denial of service vulnerability due to a memory access violation.

tags | advisory, denial of service
SHA-256 | 7fc5868caaff49e311fec4dcc9be9ebf3b1c85576e691e467bd7101da6de8f37
Debian Linux Security Advisory 1407-1
Posted Nov 26, 2007
Authored by Debian | Site debian.org

Debian Security Advisory 1407-1 - Alin Rad Pop discovered that the Common UNIX Printing System is vulnerable to an off-by-one buffer overflow in the code to process IPP packets, which may lead to the execution of arbitrary code.

tags | advisory, overflow, arbitrary
systems | linux, unix, debian
advisories | CVE-2007-4351
SHA-256 | 753a3d68ac28924d7c9af18a0c52d8384412685adfd7519aebfba8c0b6da387c
adv84-K-159-2007.txt
Posted Nov 26, 2007
Authored by M.Hasran Addahroni | Site advisories.echo.or.id

ProfileCMS versions 1.0 and below suffer from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 6d3c01126eefaa9348bc69c733c8390764d7741cff5d70a141bddc035413de3f
sciuris-inject.txt
Posted Nov 26, 2007
Authored by Liz0ziM | Site expw0rm.com

Sciurus Hosting Panel remote code injection exploit.

tags | exploit, remote
SHA-256 | 970c84d08146a628ed14566ad0049f63e193da51f4d9ca6972676548a3f8b934
icebb-database.txt
Posted Nov 26, 2007
Authored by Gu1ll4um3r0m41n

IceBB versions 1.0-rc6 and below database authentication details exploit.

tags | exploit
SHA-256 | 8cec67a3a6e76358d69f0d7d9b85a3112391c9ad2fd11c0c9b41aaefa0939cee
hotscripts-sql.txt
Posted Nov 26, 2007
Authored by t0pp8uzz, xprog

HotScripts Clone Script suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 39d4a9b19a3827d0e0a819e3e9062e6c200ce6266c7700f8574b7e550c5fd27f
vigilecms-multi.txt
Posted Nov 26, 2007
Authored by DevilAuron | Site devilsnight.altervista.org

VigileCMS version 1.4 suffers from local file inclusion, cross site scripting, and cross site request forgery vulnerabilities.

tags | exploit, local, vulnerability, xss, file inclusion, csrf
SHA-256 | 4e56b7d8ae88dc17992c6e483bbc9c99081cdb9a938209b69c7a90eb54a816ea
phpbbviet-rfi.txt
Posted Nov 26, 2007
Authored by XORON

phpBBViet version 0.22 suffers from a remote file inclusion vulnerability.

tags | exploit, remote, code execution, file inclusion
SHA-256 | 0d78987879a884969ed9f4f4b4dff77b7c045918cac93442a6effda1354247d2
Gentoo Linux Security Advisory 200711-21
Posted Nov 26, 2007
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200711-21 - Tavis Ormandy of the Google Security Team discovered a heap-based overflow vulnerability in the NE2000 driver. He also discovered a divide-by-zero error in the emulated floppy disk controller. Versions less than 2.3 are affected.

tags | advisory, overflow
systems | linux, gentoo
advisories | CVE-2007-2893, CVE-2007-2894
SHA-256 | c23da803fed5ae5bfbfb3200e80352b8e73008f52d3771106d7e9eae43bd6a91
Page 2 of 4
Back1234Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    48 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    60 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    44 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close