 |
|
|
|
| Sun JRE / JDK multiple security vulnerabilities | | Published: |  | 01.06.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 7762 | | Type: |  | library | | Level: |  | 7/10 | | Description: |  | Buffer and integer overflows in JPG and BMP processing, sandbox protection bypass with system classes. |
| Affected: |  | SUN : JRE 1.5 | | |  | SUN : JDK 1.5 | | |  | SUN : JDK 1.6 | | |  | SUN : JRE 1.6 | | CVE: |  | CVE-2007-2789 (The BMP image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03, and 1.6.x before 1.6.0_01-b06, on Unix/Linux systems, allows remote attackers to trigger the opening of arbitrary local files via a crafted BMP file, which causes a denial of service (system hang) in certain cases such as /dev/tty, and has other unspecified impact.) | | |  | CVE-2007-2788 (Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03, and 1.6.x before 1.6.0_01-b06, allows remote attackers to execute arbitrary code or cause a denial of service (JVM crash) via a crafted JPEG or BMP file.) | | |  | CVE-2007-2435 (Sun Java Web Start in JDK and JRE 5.0 Update 10 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, allows remote attackers to perform unauthorized actions via an application that grants privileges to itself, related to "Incorrect Use of System Classes" and probably related to support for JNLP files.) |
| PHP multiple security vulnerabilities | | Published: |  | 01.06.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 7764 | | Type: |  | library | | Level: |  | 6/10 | | Description: |  | chunk_split() integer overflow. |
| Affected: |  | PHP : PHP 4.4 | | |  | PHP : PHP 5.2 | | CVE: |  | CVE-2007-2872 (Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments.) | | |  | CVE-2007-2756 (The gdPngReadData function in libgd 2.0.34 allows user-assisted attackers to cause a denial of service (CPU consumption) via a crafted PNG image with truncated data, which causes an infinite loop in the png_read_info function in libpng.) | | |  | CVE-2007-1900 (CRLF injection vulnerability in the FILTER_VALIDATE_EMAIL filter in ext/filter in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to inject arbitrary e-mail headers via an e-mail address with a '\n' character, which causes a regular expression to ignore the subsequent part of the address string.) | | |  | CVE-2007-1887 (Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows context-dependent attackers to execute arbitrary code via an empty value of the in parameter, as demonstrated by calling the sqlite_udf_decode_binary function with a 0x01 character.) |
| Microsoft Windows Active Directory users account enumeration | | Published: |  | 01.06.2007 | | Source: |  | FULL-DISCLOSURE | | SecurityVulns ID: |  | 7766 | | Type: |  | remote | | Level: |  | 4/10 | | Description: |  | It's possible to enumerate accounts with Logon Hours limitation set. |
| GNU findutils locate buffer overflow | | Published: |  | 01.06.2007 | | Source: |  | | | SecurityVulns ID: |  | 7763 | | Type: |  | remote | | Description: |  | Heap buffer overflow on parsing old-format locate database. |
| Affected: |  | GNU : findutils 4.2 | | CVE: |  | CVE-2007-2452 (Heap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent attackers to execute arbitrary code via a long pathname in a locate database that has the old format, a different vulnerability than CVE-2001-1036.) |
| Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 01.06.2007 | | Source: |  | | | SecurityVulns ID: |  | 7765 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
Mozilla Firefox / Thunderbird / SeaMonkey multiple security vulnerabilities updated since 01.06.2007 | | Published: |  | 05.06.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 7761 | | Type: |  | client | | Level: |  | 8/10 | | Description: |  | Multiple DoS conditions, addEventListener method crossite scripting. Multiple heap oberflows, integer overflows, etc. |
| Affected: |  | MOZILLA : Thunderbird 1.5 | | |  | MOZILLA : Firefox 1.5 | | |  | MOZILLA : Seamonkey 1.0 | | |  | MOZILLA : Firefox 2.0 | | |  | MOZILLA : Thunderbird 2.0 | | |  | MOZILLA : SeaMonkey 1.1 | | |  | ICEAPE : iceape 1.0 | | |  | XULRUNNER : xulrunner 1.8 | | |  | ICEWEASEL : iceweasel 2.0 | | CVE: |  | CVE-2007-2871 (Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to spoof or hide the browser chrome, such as the location bar, by placing XUL popups outside of the browser's content pane. NOTE: this issue can be leveraged for phishing and other attacks.) | | |  | CVE-2007-2870 (Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to bypass the same-origin policy and conduct cross-site scripting (XSS) and other attacks by using the addEventListener method to add an event listener for a site, which is executed in the context of that site.) | | |  | CVE-2007-2869 (The form autocomplete feature in Mozilla Firefox 1.5.x before 1.5.0.12, 2.x before 2.0.0.4, and possibly earlier versions, allows remote attackers to cause a denial of service (persistent temporary CPU consumption) via a large number of characters in a submitted form.) | | |  | CVE-2007-2868 (Multiple vulnerabilities in the JavaScript engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that trigger memory corruption.) | | |  | CVE-2007-2867 (Multiple vulnerabilities in the layout engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to cause a denial of service (crash) via vectors related to dangling pointers, heap corruption, signed/unsigned, and other issues.) | | |  | CVE-2007-1562 (The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.) | | |  | CVE-2007-1558 (The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions. NOTE: this design-level issue potentially affects all products that use APOP, including (1) Thunderbird 1.x before 1.5.0.12 and 2.x before 2.0.0.4, (2) Evolution, (3) mutt, (4) fetchmail, and (5) SeaMonkey 1.0.x before 1.0.9 and 1.1.x before 1.1.2.) | | |  | CVE-2007-1362 (Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to cause a denial of service via (1) a large cookie path parameter, which triggers memory consumption, or (2) an internal delimiter within cookie path or name values, which could trigger a misinterpretation of cookie data, aka "Path Abuse in Cookies.") |
|
|
|
|
|
|
|
|