 |
|
|
|
| libtiff memory corruption | | Published: |  | 04.09.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 9262 | | Type: |  | library | | Level: |  | 6/10 | | Description: |  | Memory corruption on LZW decoding. |
| Affected: |  | LIBTIFF : libtiff 3.8 | | CVE: |  | CVE-2008-2327 (Multiple buffer underflows in the (1) LZWDecode, (2) LZWDecodeCompat, and (3) LZWDecodeVector functions in tif_lzw.c in the LZW decoder in LibTIFF 3.8.2 and earlier allow context-dependent attackers to execute arbitrary code via a crafted TIFF file, related to improper handling of the CODE_CLEAR code.) |
| Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 04.09.2008 | | Source: |  | | | SecurityVulns ID: |  | 9261 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
myPHPNuke: SQL injection. |
| Cisco PIX and Cisco ASA multiple security vulnerabilities | | Published: |  | 04.09.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 9263 | | Type: |  | remote | | Level: |  | 6/10 | | Description: |  | Multiple DoS conditions on SIP parsing and VPN authentication, memory leaks, information leak. |
| Affected: |  | CISCO : PIX 7.0 | | |  | CISCO : PIX 7.1 | | |  | CISCO : PIX 8.0 | | |  | CISCO : PIX 8.1 | | CVE: |  | CVE-2008-2736 (Unspecified vulnerability in Cisco Adaptive Security Appliance (ASA) 5500 devices 8.0(3)15, 8.0(3)16, 8.1(1)4, and 8.1(1)5, when configured as a clientless SSL VPN endpoint, allows remote attackers to obtain usernames and passwords via unknown vectors, aka Bug ID CSCsq45636.) | | |  | CVE-2008-2735 (The HTTP server in Cisco Adaptive Security Appliance (ASA) 5500 devices 8.0 before 8.0(3)15 and 8.1 before 8.1(1)5, when configured as a clientless SSL VPN endpoint, does not properly process URIs, which allows remote attackers to cause a denial of service (device reload) via a URI in a crafted SSL or HTTP packet, aka Bug ID CSCsq19369.) | | |  | CVE-2008-2734 (Memory leak in the crypto functionality in Cisco Adaptive Security Appliance (ASA) 5500 devices 7.2 before 7.2(4)2, 8.0 before 8.0(3)14, and 8.1 before 8.1(1)4, when configured as a clientless SSL VPN endpoint, allows remote attackers to cause a denial of service (memory consumption and VPN hang) via a crafted SSL or HTTP packet, aka Bug ID CSCso66472.) | | |  | CVE-2008-2733 (Cisco PIX and Adaptive Security Appliance (ASA) 5500 devices 7.2 before 7.2(4)2, 8.0 before 8.0(3)14, and 8.1 before 8.1(1)4, when configured as a client VPN endpoint, do not properly process IPSec client authentication, which allows remote attackers to cause a denial of service (device reload) via a crafted authentication attempt, aka Bug ID CSCso69942.) | | |  | CVE-2008-2732 (Multiple unspecified vulnerabilities in the SIP inspection functionality in Cisco PIX and Adaptive Security Appliance (ASA) 5500 devices 7.0 before 7.0(7)16, 7.1 before 7.1(2)71, 7.2 before 7.2(4)7, 8.0 before 8.0(3)20, and 8.1 before 8.1(1)8 allow remote attackers to cause a denial of service (device reload) via unknown vectors, aka Bug IDs CSCsq07867, CSCsq57091, CSCsk60581, and CSCsq39315.) |
Novell iPrint client multiple security vulnerabilities updated since 26.08.2008 | | Published: |  | 04.09.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 9246 | | Type: |  | client | | Level: |  | 5/10 | | Description: |  | Information leak, multiple buffer overflow. |
Google Chrome browser multiple security vulnerabilities updated since 04.09.2008 | | Published: |  | 13.09.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 9260 | | Type: |  | client | | Level: |  | 5/10 | | Description: |  | Automatic file download, DoS, buffer overflows. |
| Original document |  | MustLive, New DoS vulnerability in Google Chrome (13.09.2008) |
| |  | MustLive, New Automatic File Download vulnerabilities in Google Chrome (12.09.2008) |
| |  | MustLive, Automatic File Download vulnerabilities in Google Chrome (10.09.2008) |
| |  | MustLive, New Automatic File Download vulnerability in Google Chrome (09.09.2008) |
| |  | HACKERS PAL, Google Chrome Auto download exploit .. (07.09.2008) |
| |  | MustLive, New DoS vulnerability in Google Chrome (DoS on MouseOver) (07.09.2008) |
| |  | MustLive, New Automatic File Download vulnerability in Google Chrome (07.09.2008) |
| |  | MustLive, New DoS vulnerability in Google Chrome (06.09.2008) |
| |  | MustLive, DoS vulnerability in Google Chrome (06.09.2008) |
| |  | jplopezy_(at)_gmail.com, other google chrome crash (06.09.2008) |
| |  | quakerdoomer_(at)_fmguy.com, Risky Chrome (The perfect cleartext password offering ) (06.09.2008) |
| |  | Security Vulnerability Research Team, Google Chrome 0.2.149.27 'SaveAs' Function Buffer Overflow Vulnerability (06.09.2008) |
| |  | MustLive, New Automatic File Download vulnerability in Google Chrome (04.09.2008) |
| |  | MustLive, Automatic File Download vulnerability in Google Chrome (04.09.2008) |
| |  | psy.echo_(at)_gmail.com, Google Chrome Browser (ver.0.2.149.27) Vulnerability (04.09.2008) |
| |  | nerex_(at)_live.com, Google Chrome Automatic File Download (04.09.2008) |
|
|
|
|
|
|
|
|