Computer Security
[EN] securityvulns.ru
no-pyccku




31.12.2002
Detailed
 Leafnode CPU exhaustion
document If message is crossposted to few groups where one is prefix for another and then requested by message id programs goes into infinite loop.
  


30.12.2002
Detailed
 Gallery code execution
   
  


28.12.2002
Detailed
6!PHP buffer overflow
document Buffer overflow in wordwrap function.
 Multiple Windows 2000 driver signing problems
document It's possible to spoof file with older one, problem in certificate chain validation.
 CGI bugs
updated since 26.11.2002
   
  


27.12.2002
Detailed
 Internet Explorer Macromedia Flash crossite scripting
document It's possible to inject script into flash object URL.
  


24.12.2002
Detailed
6!CUPS multiple bugs
updated since 20.12.2002
document Integer overflows, symbolic links, unautyhorized access, DoS, переполнения буфера.
 MatLab symbolik links problem
document Startup shell scripts use temporary files in unsafe way.
 Hyperion Ftp Server buffer overflow
document Buffer overflow in dir command.
  


23.12.2002
Detailed
7!KDE uncommented shell characters problems
document User supplied data is not controlled during the call to external application
  


21.12.2002
Detailed
10!Mulbiple bugs in different SSH2 realizations
updated since 17.12.2002
document Differeng bugs on malformed packets processing during keys exchange.
7!tmpwatch attack
document File name may be changed or deleted during temporary files removing process leaving possibility of symlink attack.
6!RealNetworks HELIX buffer overflow
updated since 21.12.2002
document Buffer overflow in RTSP SETUP and DESCRIBE commands.
 Buffer overflow in Axis video products
document Buffer overflow in Web interface.
 Weak nCipher PKCS#11 encryption
document Library error may lead to uncrypted key in certificate.
 Unauthorized Polycom ViewStation access
document Administrator's password is stored in unsafe location.
 CGI bugs
updated since 17.12.2002
   
  


20.12.2002
Detailed
 Cisco EIGRP DoS
document DoS on receiving huge neighbour list.
 Enceladus Server Suite multiple bugs
updated since 10.12.2002
document Buffer overflow in FTP CD command, directory traversal.
  


19.12.2002
Detailed
 Multiple WinAmp buffer overflow
updated since 19.12.2002
document Buffer overflow during ID3v2 tags processing.
 Buffer overflow in Windows XP Shell
document Buffer overflow on audio file processing.
  


18.12.2002
Detailed
 Weak Okens Stormwatch password
document Empty sa account password.
 linux mmap DoS
document Insufficient argument check causes attempt to access inaccessable memory pages.
  


17.12.2002
Detailed
6!Multiple bugs in Macromedia flash plugin
updated since 09.08.2002
document Buffer overflows, local file reading.
 Macromedia ColdFusion crossite scripting
document Crossite scripting in error message.
 Multiple XML parsers DTD DoS
document By using DTD part of XML document it's possible to cause 100% CPU exhaustion.
  


16.12.2002
Detailed
 Cleartext Cryptainer memory password
document Cleartext password in process' memory.
  


15.12.2002
Detailed
 CGI bugs
updated since 09.12.2002
   
  


14.12.2002
Detailed
7!Sun Cobalt RaQ4 command execution
updated since 09.12.2002
document /cgi-bin/.cobalt/overflow/overflow.cgi allows command execution.
6!Microsoft Internet Explorer PNG integer overflow
document Integer overflow dusing PNG deflate unpacking.
6!Microsoft Java VM multiple bugs
   
6!Buffer overflows in fetchmail
updated since 30.09.2002
document Buffer overflows on addresses parsing.
6!Multiple bugs in Microsoft Virtual Java Machine
updated since 09.09.2002
document Amongg others there are bugs allowing file access on client computer.
 persl safe.pm protection bypass
document Safe mode doesn't work if it was already used.
 VisNetic multiple bugs
updated since 12.12.2002
document Buffer overflow in GTTP OPTIONS request. Crossite scripting.
  


11.12.2002
Detailed
6!Tetex command execution
document Uncommented shell characters during system() call in kpathsea library.
 Cisco Optical Service Module DoS
   
 TrendMicro PC-cillin/OfficeScan buffer overflow
document Buffer overflow in POP3 proxy.
 apt-www-proxy multiple bugs
document Buffer overflow, DoS.
 tcpdump BGP buffer overflow
document Buffer overflow on BGP packets decoding.
 FTP clients directory traversal
document Server can put relative or absolute path in filename.
  


10.12.2002
Detailed
6!Buffer overflow in Cyrus SASL
document Buffer overflow on oversized canonized name and on commented characters used.
  


09.12.2002
Detailed
8!Buffer overflows in OpenLDAP2
document Few serious buffer overflows.
7!Multiple Microsoft Internet Explorer bugs
updated since 21.11.2002
document New cumulative patch fixes multiple bugs.
 Multiple akfingerd bugs
document Symbolic links, undropped egid, DoS.
 TrendMicro InterScan VirusWall open proxy
document There is no limitation for CONNECT usage.
 Microsoft Windows XP information leakage
   
 SAP privelege escalation
document Relative path is used on external programm call.
 Microsoft Outlook DoS
document Malformed mail headers causes Outlook to crash.
 Ikonboard crossite scripting
updated since 04.10.2002
document [IMG]javascript:alert(document.cookie).gif[/IMG], Photo/javascript:alert(document.cookie) URL, Photo, X-Forwarded-For scripting.
  


04.12.2002
Detailed
 Internet Explorer modal dialog style crossite scripting
document By using <IMG width="0" height="0" style="width: expression(alert());"> script may be executed in local zone.
 squirellmail php bugs
updated since 25.01.2002
document Uninitialized PHP valirables, crossite scripting.
  


03.12.2002
Detailed
6!FreeSWAN DoS
document Short packet handlink problem.
6!Buffer overflow in Cyrus Sieve
document Buffer overflow on error messsage generation.
6!Integer overflow in cyrus-imap
document Integer overflow on line longer than 2Gb.
 CGI bugs
   
 Multipel bugs in Webster Web Server
document Buffer overflows, crossite scripting, directory traversal.
 Lawson weak permissions
document Access restriction is not used during access to external DBMS.
 pserv buffer overflow
updated since 26.11.2002
document buffer overflow on POST parsing.
  

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru