Computer Security
[EN] securityvulns.ru
no-pyccku



IA WebMail buffer overflow
Published:03.11.2003
Source:BUGTRAQ
SecurityVulns ID:3223
Type:remote
Level:5/10
Description:Stack overflow on oversized HTTP GET request.
Affected:TNSOFT : IA WebMail 3.1
Original documentdocumentPeter Winter-Smith, IA WebMail Server 3.x Buffer Overflow Vulnerability (03.11.2003)
Files:IA WebMail Server Buffer Overflow Exploit
 IA WebMail Server 3.x Buffer Overflow Vulnerability
Discuss:Read or add your comments to this news (0 comments)

tHTTPd directory traversal
updated since 03.11.2003
Published:03.11.2003
Source:BUGTRAQ
SecurityVulns ID:3224
Type:remote
Level:5/10
Description:If virtual hosts are usid it's possible to traverse directories with ../ in Host: header.
Affected:THTTPD : thttpd 2.23
Original documentdocumentSECURITEAM, [UNIX] tHTTPd Virtual Hosting Security Hole (Host: ../..) (03.11.2003)
Discuss:Read or add your comments to this news (0 comments)

MacOS X privilege escalation
Published:03.11.2003
Source:BUGTRAQ
SecurityVulns ID:3225
Type:local
Level:5/10
Description:There are conditions it's possible to obtains local root access having access to USB keyboard during boot process.
Affected:APPLE : MacOS X 10.2
Original documentdocumentJason Storm, Console Root On OSX up to 10.2.8 (03.11.2003)
Discuss:Read or add your comments to this news (0 comments)

Webweaver DoS
Published:03.11.2003
Source:BUGTRAQ
SecurityVulns ID:3226
Type:remote
Level:5/10
Description:Large number of data in GET request causes server to crash.
Affected:BRS : WebWeaver 1.06
Original documentdocumentd4rkgr3y, BRS WebWeaver 1.06 remote DoS vulnerability (03.11.2003)
Files:BRS WebWeaver v.1.06 remote DoS exploit
Discuss:Read or add your comments to this news (0 comments)

Multiple jre/jdk installation symbolic link bugs
Published:03.11.2003
Source:BUGTRAQ
SecurityVulns ID:3227
Type:local
Level:5/10
Affected:SUN : JDK 1.4
 SUN : JRE 1.4
Original documentdocumentStan Bubrouski, Advisory: Sun's jre/jdk 1.4.2 multiple vulernabilities in linux installers (03.11.2003)
Discuss:Read or add your comments to this news (0 comments)

Citrix Metaframe crossite scripting
Published:03.11.2003
Source:BUGTRAQ
SecurityVulns ID:3228
Type:remote
Level:5/10
Description:login.asp crossite scripting.
Affected:CITRIX : MetaFrame XP
Original documentdocumentadvisories_(at)_irmplc.com, IRM 008: Citrix Metaframe XP is vulnerable to Cross Site Scripting (03.11.2003)
Discuss:Read or add your comments to this news (0 comments)

Multiple unichat bugs
Published:03.11.2003
Source:BUGTRAQ
SecurityVulns ID:3229
Type:remote
Level:5/10
Affected:UNICHAT : Unichat 1.00
Original documentdocumentDarkKnight, Unichat Vulnerabilities (03.11.2003)
Discuss:Read or add your comments to this news (1 comments)

Choutcast buffer overflow
Published:03.11.2003
Source:BUGTRAQ
SecurityVulns ID:3230
Type:remote
Level:5/10
Description:Buffer overflow on oversized icy-name and icy-url parameters.
Affected:NULLSOFT : Shoutcast Server 1.9
Original documentdocumentHEX, ShoutCast server 1.9.2/win32 (03.11.2003)
Files:SHOUTcast v1.9.2 remote exploit
 SHOUTcast 1.9.2 remote heap overrun exploit binary version by m00 Security
Discuss:Read or add your comments to this news (0 comments)

Plug & Play Web Server multiple bugs
updated since 19.09.2003
Published:03.11.2003
Source:BUGTRAQ
SecurityVulns ID:3125
Type:remote
Level:5/10
Description:Directory traversal, DoS.
Affected:PANDPSOFTWARE : Plug & Play Web Server 1.0002
Original documentdocumentOliver Karow, DoS in Plug and Play Web Server Proxy Server (03.11.2003)
 documentBahaa Naamneh, Directory traversal in Plug & Play Web Server (19.09.2003)
 documentBahaa Naamneh, Denial Of Service in Plug & Play Web (FTP) Server (19.09.2003)
Discuss:Read or add your comments to this news (0 comments)

SHOUTcast Server buffer overflow
updated since 13.08.2001
Published:03.11.2003
Source:BUGTRAQ
SecurityVulns ID:1385
Type:remote
Level:5/10
Description:buffer overflow on long User-Agent HTTP header in admin.cgi and in processing of internal administration protocol.
Affected:NULLSOFT : SHOUTcast Server 1.8
Original documentdocumenteSDee, SHOUTcast 1.8.9 bufferoverflow (05.06.2002)
 documentBrian Dittmer, Shoutcast server 1.8.3 win32 (22.01.2002)
 documentFraMe, Denial of Service in SHOUTcast Server 1.8.2 Linux/w32/? (13.08.2001)
Files:Denial of Service in SHOUTcast Server 1.8.2 Linux/w32/?
Discuss:Read or add your comments to this news (0 comments)

Memory leak DoS in EServ
updated since 12.05.2003
Published:03.11.2003
Source:SECURITEAM
SecurityVulns ID:2810
Type:remote
Level:5/10
Description:On every connection few Kb of memory are reserver and never free'd back.
Affected:ETYPE : Eserv 2.99
 ETYPE : Eserv 3.00
Original documentdocumentd4rkgr3y, Memory-leak vulnerability in EServ/3.00 (03.11.2003)
 documentSECURITEAM, [NT] eServ Memory Leak Enables Denial of Service Attacks (12.05.2003)
Discuss:Read or add your comments to this news (0 comments)

Buffer overflow in VMware GSX
updated since 25.07.2002
Published:03.11.2003
Source:BUGTRAQ
SecurityVulns ID:2184
Type:remote
Level:6/10
Description:Buffer overflow during user's authentication.
Affected:VMWARE : VMware GSX Server 2.0
Original documentdocumentDarryl Swofford, VMWare GSX Server Authentication Server Buffer Overflow Vulnerability - Update (03.11.2003)
 documentMingyan Liu, VMware GSX Server Remote Buffer Overflow (25.07.2002)
Files:VMwareOverflowTest v1.0
Discuss:Read or add your comments to this news (0 comments)

Microsoft internet explorer local files access
updated since 27.10.2003
Published:03.11.2003
Source:BUGTRAQ
SecurityVulns ID:3204
Type:client
Level:6/10
Description:Redirection with Location: file:/// allows to open local file in known location. Macromedia flash allows to store HTML text in known file.
Affected:MICROSOFT : Internet Explorer 6.0
 MACROMEDIA : Flash Player 6.0
Original documentdocumentLiu Die Yu, Redirection and refresh parses local file (03.11.2003)
 documentMind Warper, Internet Explorer Vulnerability: Content-Location works with both triple and double slash (03.11.2003)
 documentThor Larholm, Re: Internet Explorer and Opera local zone restriction bypass (27.10.2003)
 documentMind Warper, Internet Explorer and Opera local zone restriction bypass (27.10.2003)
Discuss:Read or add your comments to this news (0 comments)

CGI bugs
updated since 03.11.2003
Published:05.11.2003
Source:
SecurityVulns ID:3222
Type:remote
Level:5/10
Affected:JAVAZOOM : jChatBox 2.5
 WEBWIZFORUM : Web Wiz Forum 7.5
 VIENUKE : VieNuke
 MPM : MPM Guestbook 1.2
 TRITANIUM : Tritanium Bulletin Board 1.2
 PHPKIT : PHPKIT
 JOHNBEATTY : John Beatty Photo Album 1.0
Original documentdocumentSecuriTeam, [UNIX] OpenAutoClassifieds Cross-Site Scripting Vulnerability (05.11.2003)
 documentnimber, Advisories: CSS in PHP Photo Album by John Beatty ver. 1.0 (05.11.2003)
 documentben.moeckel_(at)_badwebmasters.net, [Full-Disclosure] [bWM#017] Cross-Site-Scripting @ PHPKIT (03.11.2003)
 documentVirginity Security, Virginity Security Advisory 2003-002 : Tritanium Bulletin Board - Read and write from/to internal (protected) Threads (03.11.2003)
 documentSECURITEAM, [UNIX] MPM Guestbook Multiple Vulnerabilities (CSS, Path Disclosure) (03.11.2003)
 documentManuel [ekerazha], [Full-Disclosure] SQL Injections in VieNuke (03.11.2003)
 documentAlexander Antipov, [Full-Disclosure] Unauthorized access in Web Wiz Forum (03.11.2003)
 documentNavy, jchat box advisory (03.11.2003)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru