 |
|
|
|
30.12.2007 Detailed | |
| | | Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
|  | | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
WordPress: local file include, directory traversal and information leak. |
| | ClamAV antivirus multiple security vulnerabilities
|  | | Protection bypass with UUEncode, race conditions on temporary files creation. |
| | |
|
29.12.2007 Detailed | |
| | 6! | Multiple security vulnerabilities in different Exif libraries (libexif, exiv2, exiftags)
|  | | Multiple DoS conditions, integer overflows, buffer overflows on parsing JPEG/TIFF/RIFF EXIF data. |
| | Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
|  | | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
WordPress: directory traversal and information leak. |
|
28.12.2007 Detailed | |
| | | Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
|  | | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
WordPress: DoS, crossite scripting, arbitrary files deletion. |
| | Extended Module Player multiple security vulnerabilities
|  | | Multiple buffer overflows. |
| | libnemesi RTSP client library multiple security vulnerabilities
|  | | Multiple buffer overflows. |
|
27.12.2007 Detailed | |
| | | PHP set_time_limit limitation bypass
|  | | It's possible to use ini_set("max_execution_time", 90000000); in safe mode instead of set_time_limit. |
| | Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
|  | | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
|
| | |
|
| | syslog-ng DoS
|  | | NULL pointer dereference on malformed timestamp format. |
|
| | Firefox DoS
|  | | Invalid INPUT tag designMode property processing. |
|
|
|
|
|
|
|
|
|