Computer Security
[EN] securityvulns.ru
no-pyccku



CGI bugs
updated since 01.09.2003
Published:04.09.2003
Source:
SecurityVulns ID:3083
Type:remote
Level:5/10
Affected:WEBCALENDAR : WebCalendar 0.9
 SITEBUILDER : SiteBuilder 1.4
 PTHPPRODUCTIONS : Gastenboek
 TSINTER : TSguestbook 2.1
Original documentdocumentnoconflic, Webcalendar <= 0.9.42 Cross Site Scripting Attacks and Potential SQL Injection Attack (04.09.2003)
 documentJim Pangalos, ZH2003-26SA (security advisory): TSguestbook Ver. 2.1 Cross-Site Scripting Vulnerability (03.09.2003)
 documentmorning_wood, PtHProductions Gastenboek - XSS (03.09.2003)
 documentZero-X ScriptKiddy, Directory Traversal in SITEBUILDER - v1.4 (03.09.2003)
 documentidoru_(at)_VIDEOSOFT.NET.UY, [Full-Disclosure] XSS in ezboard (01.09.2003)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Windows NetBIOS information leak
Published:04.09.2003
Source:MICROSOFT
SecurityVulns ID:3086
Type:remote
Level:5/10
Description:Uninitialized memory structure during reply to NetBIOS name request allows attacker to read few bytes from remote host's memory.
Affected:MICROSOFT : Windows NT 4.0 Workstation
 MICROSOFT : Windows NT 4.0 Server
 MICROSOFT : Windows 2000 Server
 MICROSOFT : Windows 2000 Professional
 MICROSOFT : Windows XP
 MICROSOFT : Windows 2003 Server
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS03-034: Flaw in NetBIOS Could Lead to Information Disclosure (Q824105) (04.09.2003)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Word macro protection bypass
Published:04.09.2003
Source:MICROSOFT
SecurityVulns ID:3087
Type:client
Level:7/10
Affected:MICROSOFT : Office 2000
 MICROSOFT : Office 97
 MICROSOFT : Office XP
 MICROSOFT : Works 2001
 MICROSOFT : Works 2002
 MICROSOFT : Works 2003
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS03-035: Flaw in Microsoft Word Could Enable Macros to Run Automatically(827653) (04.09.2003)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Visual Basic for Applications buffer overflow
updated since 04.09.2003
Published:04.09.2003
Source:MICROSOFT
SecurityVulns ID:3089
Type:library
Level:8/10
Description:Buffer overflow on opening macro document.
Affected:MICROSOFT : Office 2000
 MICROSOFT : Office 97
 MICROSOFT : Office XP
 MICROSOFT : Works 2001
 MICROSOFT : Works 2002
 MICROSOFT : Works 2003
 MICROSOFT : Publisher 2002
 MICROSOFT : Visual Basic for Applications SDK 5.0
 MICROSOFT : Visual Basic for Applications SDK 6.0
 MICROSOFT : Visual Basic for Applications SDK 6.2
 MICROSOFT : Visual Basic for Applications SDK 6.3
 MICROSOFT : Project 2000
 MICROSOFT : Project 2002
 MICROSOFT : Visio 2000
 MICROSOFT : Visio 2002
 MICROSOFT : Business Solutions Great Plains 7.5
 MICROSOFT : Business Solutions Dynamics 6.0
 MICROSOFT : Business Solutions Dynamics 7.0
 MICROSOFT : Business Solutions eEnterprise 6.0
 MICROSOFT : Business Solutions eEnterprise 7.0
 MICROSOFT : Business Solutions Solomon 4.5
 MICROSOFT : Business Solutions Solomon 5.0
 MICROSOFT : Business Solutions Solomon 5.5
Original documentdocumentSECURITEAM, [NT] Additional Technical Information Released on VBE Document Property Buffer Overflow (08.09.2003)
 documentEEYE, EEYE: VBE Document Property Buffer Overflow (04.09.2003)
 documentMICROSOFT, Microsoft Security Bulletin MS03-037: Flaw in Visual Basic for Applications Could Allow Arbitrary Code Execution(822715) (04.09.2003)
Discuss:Read or add your comments to this news (0 comments)

Microsft Access Snapshot Viewer buffer overflow
Published:04.09.2003
Source:MICROSOFT
SecurityVulns ID:3090
Type:client
Level:8/10
Description:Buffer overflow in ActiveX component marked as safe.
Affected:MICROSOFT : Office 2000
 MICROSOFT : Office 97
 MICROSOFT : Office XP
 MICROSOFT : Acess 97
 MICROSOFT : Acess 2000
 MICROSOFT : Acess 2002
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS03-038: Unchecked buffer in Microsoft Access Snapshot Viewer Could Allow Code Execution(827104) (04.09.2003)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Internet Explorer showHelp crossite scripting
updated since 07.02.2003
Published:04.09.2003
Source:MICROSOFT
SecurityVulns ID:2574
Type:client
Level:6/10
Description:Subsequent calls to showHelp cause content to be displayed in the same security zone.
Affected:MICROSOFT : Internet Explorer 5.0
 MICROSOFT : Internet Explorer 5.5
 MICROSOFT : Internet Explorer 6.0
Original documentdocumentArman Nayyeri, IE: CHM Attacks are still alive (CHM attack without showHelp()) (04.09.2003)
 documentMICROSOFT, Microsoft Security Bulletin MS03-004: Cumulative Patch for Internet Explorer (810847) (07.02.2003)
 documentAndreas Sandblad, showHelp("file:") disables security in IE - Sandblad advisory #11 (07.02.2003)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Word Perfect convertor buffer overflow
updated since 04.09.2003
Published:08.09.2003
Source:MICROSOFT
SecurityVulns ID:3088
Type:client
Level:6/10
Description:Buffer overflow during Word Perfect document convertion.
Affected:MICROSOFT : Office 2000
 MICROSOFT : Office 97
 MICROSOFT : Office XP
 MICROSOFT : Works 2001
 MICROSOFT : Works 2002
 MICROSOFT : Works 2003
 MICROSOFT : Frontpage 2000
 MICROSOFT : Frontpage 2002
 MICROSOFT : Publisher 2000
 MICROSOFT : Publisher 2002
Original documentdocumentSECURITEAM, [NT] Additional Information Released on Microsoft WordPerfect Document Converter Buffer Overflow (08.09.2003)
 documentEEYE, EEYE: Microsoft WordPerfect Document Converter Buffer Overflow (04.09.2003)
 documentMICROSOFT, Microsoft Security Bulletin MS03-036: Buffer Overrun in WordPerfect Converter Could Allow Code Execution(827103) (04.09.2003)
Files:Microsoft WordPerfect Document Converter Exploit
Discuss:Read or add your comments to this news (0 comments)

stunnel file descriptors leak
updated since 04.09.2003
Published:25.11.2003
Source:BUGTRAQ
SecurityVulns ID:3091
Type:local
Level:5/10
Description:Child process has access to critical descriptors.
Affected:STUNNEL : stunnel 3.24
 STUNNEL : stunnel 4.00
 STUNNEL : stunnel 3.25
Original documentdocumentREDHAT, [RHSA-2003:296-01] Updated stunnel packages available (25.11.2003)
 documentSteve Grubb, Stunnel-3.x Daemon Hijacking (04.09.2003)
Files:stunnel descriptor leak PoC
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru