Computer Security
[EN] securityvulns.ru
no-pyccku



Sendmail restricted shell (smrsh) protection bypass
Published:02.10.2002
Source:BUGTRAQ
SecurityVulns ID:2315
Type:local
Level:5/10
Description:Unescaped shell characters allows to execute commands.
Affected:SENDMAIL : Sendmail 8.12
 SENDMAIL : Sendmail 8.13
Original documentdocumentIDEFENSE, iDEFENSE Security Advisory 10.01.02: Sendmail smrsh bypass vulnerabilities (02.10.2002)
Discuss:Read or add your comments to this news (0 comments)

Apache Host: crossite scripting
Published:02.10.2002
Source:BUGTRAQ
SecurityVulns ID:2317
Type:remote
Level:4/10
Description:404 error message contains unescaped Host: header of HTTP request.
Affected:APACHE : Apache 2.0
Original documentdocumentMatthew Murphy, Apache 2 Cross-Site Scripting (02.10.2002)
Discuss:Read or add your comments to this news (0 comments)

Unauthorized access in OpenVMS POP3 server
updated since 30.09.2002
Published:02.10.2002
Source:BUGTRAQ
SecurityVulns ID:2303
Type:local
Level:5/10
Description:It's possible to overwrite local file by specifing it as a log file.
Affected:HP : OpenVMS 5.3
Original documentdocumentHP, [security bulletin] SSRT2371 HP OpenVMS Potential POP server local vulnerability (02.10.2002)
 documentMike Riley, OpenVMS POP server local vulnerability (30.09.2002)
Discuss:Read or add your comments to this news (0 comments)

IBM SecureWay DoS
updated since 02.10.2002
Published:09.10.2002
Source:SECURITEAM
SecurityVulns ID:2316
Type:remote
Level:5/10
Description:TCP packets with all flags set to 0 cause CPU exhaustion.
Affected:IBM : SecureWay 4.2
Original documentdocumentMauro Flores, Flood ACK packets cause an IBM SecureWay FireWall DoS (09.10.2002)
 documentSECURITEAM, [UNIX] Flood ACK Packets Cause an IBM SecureWay Firewall to Hang (02.10.2002)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Internet Explorer saved references and identifiers crossite scripting
updated since 02.10.2002
Published:23.10.2002
Source:BUGTRAQ
SecurityVulns ID:2314
Type:remote
Level:6/10
Description:By saving location.assign method of parent window it's possible to access it content any time. It's also possible to reference frame by it's identifier.
Affected:MICROSOFT : Internet Explorer 6.0
Original documentdocumentGreyMagic Software, Vulnerable cached objects in IE (9 advisories in 1) (23.10.2002)
 documentGreyMagic Software, Internet Explorer : The D-Day (15.10.2002)
 documentLiu Die Yu, MSIE:"SaveRef" turns Zone off (02.10.2002)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru