Computer Security
[EN] securityvulns.ru no-pyccku


dnsmasq multiple security vulnerabilities
Published:02.09.2009
Source:
SecurityVulns ID:10194
Type:remote
Threat Level:
6/10
Description:Multiple vulnerabilities on TFTP processing.
Affected:DNSMASQ : dnsmasq 2.45
CVE:CVE-2009-2958 (The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option.)
 CVE-2009-2957 (Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request.)
Original documentdocumentDEBIAN, [SECURITY] [DSA 1876-1] New dnsmasq packages fix remote code execution (02.09.2009)

Network Appliance NetCache DoS
Published:02.09.2009
Source:
SecurityVulns ID:10196
Type:remote
Threat Level:
5/10
Description:Error on Cache-Control: prefetch processing.
Affected:NETAPP : NetCache 6.0
Original documentdocumentArturo 'Buanzo' Busleiman, [ADVISORY] NetCache URL DoS - Argentinian ISP (02.09.2009)

VMWare Studio directory traversal
Published:02.09.2009
Source:
SecurityVulns ID:10197
Type:remote
Threat Level:
5/10
Description:Directory traversal in Web interface.
Affected:VMWARE : VMware Studio 2.0
CVE:CVE-2009-2968 (Directory traversal vulnerability in a support component in the web interface in VMware Studio 2.0 public beta before build 1017-185256 allows remote attackers to upload files to arbitrary locations via unspecified vectors.)
Original documentdocumentVMWARE, VMSA-2009-0011 VMware Studio 2.0 addresses a security issue in the public beta version of Studio 2.0 (02.09.2009)

BKAV eOffice code execution
Published:02.09.2009
Source:
SecurityVulns ID:10198
Type:client
Threat Level:
5/10
Affected:BKAV : BKAV eOffice 5.1
Original documentdocumentNam Nguyen, [BMSA-2009-06] Remote code execution in BKAV eOffice (02.09.2009)

Opera Unite multiple security vulnerabilities
Published:02.09.2009
Source:
SecurityVulns ID:10199
Type:client
Threat Level:
5/10
Description:Request spoofing, crossite scripting, information leak, etc.
Affected:OPERA : Opera Unite 10.00
Original documentdocumentInferno, Pwning Opera Unite with Inferno's Eleven (02.09.2009)

Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
updated since 02.09.2009
Published:02.09.2009
Source:
SecurityVulns ID:10200
Type:remote
Threat Level:
5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Affected:JSFTEMPLATING : JSFTemplating 1.2
 KENAI : Mojarra Scales 1.2
 GLASSFISH : GlassFish 3
 IKIWIKI : ikiwiki 2.53
 IKIWIKI : ikiwiki 3.1415926
CVE:CVE-2009-2944 (Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before 3.1415926 and 2.x before 2.53.4 allows context-dependent attackers to read arbitrary files via crafted TeX commands.)
Original documentdocumentSEC Consult Vulnerability Lab, SEC Consult SA-20090901-0 :: File disclosure vulnerability in JSFTemplating, Mojarra Scales and GlassFish Application Server v3 Admin console (02.09.2009)

OpenOffice multiple security vulnerabilities
updated since 02.09.2009
Published:07.09.2009
Source:
SecurityVulns ID:10195
Type:local
Threat Level:
6/10
Description:Buffer overflow and integer overflow on Microsoft Word and EMF documents parsing, vulnerable version in included VCRedist_x86.
Affected:OPENOFFICE : OpenOffice 3.1
CVE:CVE-2009-2139 (Heap-based buffer overflow in svtools/source/filter.vcl/wmf/enhwmf.cxx in Go-oo 2.x and 3.x before 3.0.1, previously named ooo-build and related to OpenOffice.org (OOo), allows remote attackers to execute arbitrary code via a crafted EMF file, a similar issue to CVE-2008-2238.)
 CVE-2009-0201 (Heap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via unspecified records in a crafted Word document, related to "table parsing.")
 CVE-2009-0200 (Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via crafted records in the document table of a Word document, leading to a heap-based buffer overflow.)
Original documentdocumentDEBIAN, [SECURITY] [DSA 1880-1] New OpenOffice.org packages fix arbitrary code execution (07.09.2009)
 documentSECUNIA, Secunia Research: OpenOffice.org Word Document Table Parsing Integer Underflow (02.09.2009)
 documentSECUNIA, Secunia Research: OpenOffice.org Word Document Table Parsing Integer Underflow (02.09.2009)
 documentSECUNIA, Secunia Research: OpenOffice.org Word Document Table Parsing Buffer Overflow (02.09.2009)
 documentStefan Kanthak, Vulnerable MSVC++ runtime distributed with OpenOffice.org 3.1.1 for Windows (02.09.2009)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod