Computer Security
[EN] securityvulns.ru
no-pyccku



GIF buffer overflow in Mozilla/Netscape
updated since 07.09.2002
Published:07.09.2002
Source:BUGTRAQ
SecurityVulns ID:2273
Type:client
Level:7/10
Description:Heap overflow on zero width GIF images.
Affected:MOZILLA : Mozilla 1.0
Original documentdocumentZenith Parsec, zero-width gif: exploit PoC for NS6.2.3 (fixed in 7.0) [Was: GIFs Good, Flash Executable Bad] (07.09.2002)
Files:Source code for zero width gif exploit generator:
 zero width gif - example exploit
Discuss:Read or add your comments to this news (0 comments)

Crossite scripting in Internet Explorer and Konqueror
updated since 04.09.2002
Published:07.09.2002
Source:BUGTRAQ
SecurityVulns ID:2264
Type:client
Level:6/10
Description:It's possible to spoof domain by using %sF in URL's username: http://secretcookie.com%2F@hacker.com/
Affected:MICROSOFT : Internet Explorer 6.0
 KONQUEROR : Konqueror 3.0
Original documentdocumentPiotr Pawłow, MSIEv6 % encoding - Konqueror 3.0.3 also vulnerable (07.09.2002)
 documentLiu Die Yu, MSIEv6 % encoding causes a problem again (04.09.2002)
Discuss:Read or add your comments to this news (0 comments)

Long filenames buffer overflow in PGP
Published:07.09.2002
Source:BUGTRAQ
SecurityVulns ID:2272
Type:client
Level:5/10
Description:Buffer overflow on filenames longer than 192 bytes.
Affected:NAI : PGP Corporate Desktop 7.1
Original documentdocumentFoundstone Labs, Foundstone Labs Advisory - Remotely Exploitable Buffer Overflow in PGP (07.09.2002)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru