Computer Security
[EN] securityvulns.ru
no-pyccku



cups DoS
Published:09.06.2003
Source:BUGTRAQ
SecurityVulns ID:2888
Type:remote
Level:5/10
Description:DoS on incomplete header.
Affected:CUPS : cups 1.1
Original documentdocumentSebastian Krahmer, SuSE Security Announcement: cups (SuSE-SA:2003:028) (09.06.2003)
Discuss:Read or add your comments to this news (0 comments)

gzip znew symbolic links problem
Published:09.06.2003
Source:BUGTRAQ
SecurityVulns ID:2889
Type:local
Level:5/10
Description:Unsafe temporary files creation.
Original documentdocumentDEBIAN, [SECURITY] [DSA-308-1] New gzip packages fix insecure temporary file creation (09.06.2003)
Discuss:Read or add your comments to this news (0 comments)

Novell iChain buffer overflow
Published:09.06.2003
Source:BUGTRAQ
SecurityVulns ID:2890
Type:remote
Level:5/10
Affected:NOVELL : iChain 2.2
Original documentdocumentNOVELL, NOVL-2003-2966205 - iChain 2.2 Field Patch 1a (09.06.2003)
Discuss:Read or add your comments to this news (0 comments)

Novell Netware HTTPSTK DoS
Published:09.06.2003
Source:BUGTRAQ
SecurityVulns ID:2891
Type:library
Level:5/10
Description:Invelid processing for Keep-Alive packet.
Original documentdocumentNOVELL, NOVL-2003-2966181 - HTTPSTK DOS (09.06.2003)
Discuss:Read or add your comments to this news (0 comments)

SpeakFreely multiple bugs
Published:09.06.2003
Source:BUGTRAQ
SecurityVulns ID:2892
Type:remote
Level:6/10
Description:Multiple buffer overflows
Affected:SPEAKFREE : Speak Freely 7.5
Original documentdocumentfozzy_(at)_dmpfrance.com, Speak Freely <=7.5 multiple remote and local vulnerabilities (the Hackademy Audit) (09.06.2003)
Discuss:Read or add your comments to this news (0 comments)

xaos privilege escalation
Published:09.06.2003
Source:BUGTRAQ
SecurityVulns ID:2893
Type:local
Level:5/10
Description:Program is installed as suid root.
Affected:XAOS : xaos 3.0
Original documentdocumentDEBIAN, [SECURITY] [DSA-310-1] New xaos packages fix improper setuid-root execution (09.06.2003)
 documentbazarr_(at)_ziplip.com, BAZARR LOCAL ROOT AGAIN. HI GUYS. DONT READ THIS (09.06.2003)
Files:xaos <= 3.0-23 ? 0day local root xploit on debian 3.0 whoody
Discuss:Read or add your comments to this news (0 comments)

Multiple bugs in FTP clients
Published:09.06.2003
Source:BUGTRAQ
SecurityVulns ID:2894
Type:client
Level:5/10
Description:Bugs during parsing FTP server data.
Affected:CEDSOFT : FlashFXP
 SMARTFTP : SmartFTP 1.0
 RHINO : FTP Voyager 10.0
 LEAPFTP : LeapFTP 2.7
CVE:CVE-2007-0825 (FlashFXP 3.4.0 build 1145 allows remote servers to cause a denial of service (CPU consumption) via a response to a PWD command that contains a long string with deeply nested directory structure, possibly due to a buffer overflow.)
 CVE-2007-0790 (Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.)
 CVE-2003-1319 (Multiple buffer overflows in SmartFTP 1.0.973, and other versions before 1.0.976, allow remote attackers to execute arbitrary code via (1) a long response to a PWD command, which triggers a stack-based overflow, and (2) a long line in a response to a file LIST command, which triggers a heap-based overflow.)
Original documentdocumentnesumin, [LeapFTP] "PASV" Reply Buffer Overflow Vulnerability (09.06.2003)
 documentnesumin, [FTP Voyager] File List Buffer Overflow Vulnerability (09.06.2003)
 documentnesumin, [SmartFTP] Two Buffer Overflow Vulnerabilities (09.06.2003)
 documentnesumin, [FlashFXP] Two Buffer Overflow Vulnerabilities (09.06.2003)
Files:LeapFTP remote buffer overflow exploit
 FlashFXP V 3.4.0 build 1145 Buffer Overflow DoS
 SmartFTP Client v 2.0.1002 Heap Overflow DoS
Discuss:Read or add your comments to this news (0 comments)

Buffer overflow in zblast
Published:09.06.2003
Source:BUGTRAQ
SecurityVulns ID:2895
Type:local
Level:5/10
Description:Local overflow gives egid games.
Affected:ZBLAST : zblast 1.2
Original documentdocumentVade 79, linux)zblast/xzb[v1.2]: local buffer overflow. (games) (09.06.2003)
Files:(linux)zblast/xzb[v1.2]: local buffer overflow
Discuss:Read or add your comments to this news (0 comments)

Переполнение буфера в eterm (buffer overflow)
updated since 14.01.2002
Published:09.06.2003
Source:BUGTRAQ
SecurityVulns ID:1680
Type:local
Level:6/10
Описание:Переполнение буфера при разборе переменных окружения.
Affected:ETERM : eterm 0.9
Original documentdocumentDEBIAN, [SECURITY] [DSA-309-1] New eterm packages fix buffer overflow (09.06.2003)
 documentCharles 'core' Stevenson, Eterm SGID utmp Buffer Overflow (Local) (14.01.2002)
Files:local root xploit for Eterm
Discuss:Read or add your comments to this news (0 comments)

Multiple bugs in Apache
updated since 29.05.2003
Published:09.06.2003
Source:BUGTRAQ
SecurityVulns ID:2858
Type:remote
Level:6/10
Description:Bugs causing remote DoS and under some specific conditions to code execution.
Affected:APACHE : Apache 2.0
 APACHE : mod_gzip 1.3
Original documentdocumentMatthew Murphy, Apache 2.x APR Exploit Code (09.06.2003)
 documentMatthew Murphy, Mod_gzip Debug Mode Vulnerabilities (03.06.2003)
 documentIDEFENSE, Apache Portable Runtime Denial of Service and Arbitrary Code Execution Vulnerability (31.05.2003)
 documentAPACHE, [SECURITY] [ANNOUNCE] Apache 2.0.46 released (29.05.2003)
Files:Apache 2.0 APR Exploit
 remote exploit for mod_gzip (with debug_mode)
Discuss:Read or add your comments to this news (0 comments)

mail buffer overflow
updated since 03.06.2003
Published:09.06.2003
Source:SECURITYFOCUS
SecurityVulns ID:2872
Type:client
Level:6/10
Description:Buffer overflow on parsing Cc: header in message.
Affected:REDHAT : RedHat Linux 9.0
 SLACKWARE : Slackware Linux 8.1
Original documentdocumentD4rkGr3y, Re: Linux /bin/mail Carbon Copy Field Buffer Overrun Vulnerability (09.06.2003)
Files:/bin/mail exploit for mdk/8.2 is attached
 Linux /bin/mail Carbon Copy Field Buffer Overrun Vulnerability
Discuss:Read or add your comments to this news (0 comments)

Multiple Internet Explorer bugs
updated since 05.06.2003
Published:09.06.2003
Source:BUGTRAQ
SecurityVulns ID:2875
Type:remote
Level:7/10
Description:New cumulativ update fixes buffer overflow and code execution.
Affected:MICROSOFT : Internet Explorer 5.5
 MICROSOFT : Internet Explorer 6.0
Original documentdocumentAlumni, IE-object tag longtype exploit (09.06.2003)
 documentEEYE, Internet Explorer Object Type Property Overflow (05.06.2003)
 documentMICROSOFT, Microsoft Security Bulletin MS03-020: Cumulative Patch for Internet Explorer (818529) (05.06.2003)
Files:IE Object Type Overflow Exploit
Discuss:Read or add your comments to this news (0 comments)

WWW&FTP Server directory traversal
Published:09.06.2003
Source:ZUDTEAM
SecurityVulns ID:2885
Type:remote
Level:5/10
Description:Directory traversal with /../
Affected:WWWFTP : WWW&FTP SERVER 6.3
Original documentdocumentnimber, Vulnerability in WWW&FTP SERVER 6.3 (09.06.2003)
Discuss:Read or add your comments to this news (0 comments)

Mini HTTP Server buffer overflow
Published:09.06.2003
Source:ZUDTEAM
SecurityVulns ID:2886
Type:remote
Level:5/10
Description:Buffer overflow on oversized URL.
Affected:MINIHTTP : Mini HTTP Server 1.0
Original documentdocumentnimber, Buffer overflow in Mini HTTP Server (09.06.2003)
Discuss:Read or add your comments to this news (0 comments)

CGI bugs
updated since 09.06.2003
Published:28.06.2003
Source:
SecurityVulns ID:2887
Type:remote
Level:5/10
Affected:POSTNUKE : PostNuke 0.7
 PHPBB : phpBB 2.02
 PVD : PVD access manager 2.0
 CGI : vote.pl
 CGI : rear.pl
 MAXWEBPORTAL : Max Web Portal 1.30
 PHPZEN : zenTrack 2.4
 SYNKRON : Synkron.web 3
 SPYKE : Spyke's PHP Board 2.1
 PSOFT : H-Sphere 2.3
 PLANETPOD : podboard 0.0
 SPHERA : HostingDirector 3.0
 PMACHINE : pMachine 2.1
 XMBFORUM : XMB Forum 1.8
 TUTOS : Tutos 1.1
 DEERFIELD : VisNetic WebMail 5.8
 GUESTBOOKHOST : GuestBookHost
 MOREGROUPWARE : Moregroupware 0.6
 AWSD : WebBBS 5.12
Original documentdocumentlavieangel_(at)_mydomain.com, WebBBS Guestbook : Cross Site Scripting (28.06.2003)
 documentFrançois SORIN, [KSA-002] Multiple Vulnerabilities In Moregroupware (26.06.2003)
 documentJulien L., GuestBookHost : Cross Site Scripting (25.06.2003)
 documentRushjo_(at)_tripbit.org, TA-2003-06 php-form-misconfiguration in VisNetic WebMail v.5.8.6.6 (24.06.2003)
 documentsilent needel, XSS Exploit In phpBB viewtopic.php (24.06.2003)
 documentFrançois SORIN, [KSA-001] Multiple vulnerabilities in Tutos (23.06.2003)
 documentKnight Commander, Many XSS Vulnerabilities in XMB Forum. (23.06.2003)
 documentfrog frog, pMachine (PHP) : Include() Security Hole (23.06.2003)
 documentLorenzo Hernandez Garcia-Hierro, Sphera Hosting Director Control Panel Multiple Vulnerabilities: XSS-Session Hijacking-DoS/Buffer Overflow-Another User Accounts access (14.06.2003)
 documentidoru_(at)_VIDEOSOFT.NET.UY, Cross site scripting in Post-Nuke (14.06.2003)
 documentMask_NBTA, podboard dev 0.0 Script Injection (14.06.2003)
 documentLorenzo Hernandez Garcia-Hierro, PSOFT H-Sphere Cross Site Scripting Vulnerabilities (10.06.2003)
 documentMarc Bromm, Several bugs found in "Spyke's PHP Board" (10.06.2003)
 documentSecuriTeam, [NEWS] XSS Vulnerability in Synkron.web CMS (09.06.2003)
 documentfarking_(at)_i-ownur.info, zenTrack Remote Command Execution Vulnerabilities (09.06.2003)
 documentJeiAr, Critical Vulnerabilities In Max Web Portal (09.06.2003)
 documentnimber, Ошибки в CGI (09.06.2003)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru