 |
|
|
|
30.05.2007 Detailed | |
| | | Mozilla multiple addons upgrade weakness
|  | | Upgrade mechanism of multiple addons allows upgrade via unsecure HTTP connection without using of SSL/TLS certificates, makeing active man-in-the-middle attacks possible. |
| | Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
|  | | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
| | |
|
26.05.2007 Detailed | |
| | 6! | Sun Web Proxy multiple buffer overflows
|  | | Multiple buffer overflows in SOCKS server. |
| | Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
|  | | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
| | Dart Communications PowerTCP ActiveX buffer overflow updated since 25.05.2007
|  | | Buffer overflows in QuickZip, Install and Uninstall methods. |
|
| | Asterisk information leak
|  | | Empty IAX2 packet causes memory content leak and potential DoS condition because of missed terminating NULL byte. |
|
| | Yate VoIP server DoS
|  | | NULL pointer dereference on absent "purpose" parameter of SIP "Call-Info" header. |
|
|
|
|
|
|
|
|
|