Computer Security
[EN] securityvulns.ru
no-pyccku



WeFi information leak
updated since 04.07.2008
Published:10.07.2008
Source:BUGTRAQ
SecurityVulns ID:9130
Type:local
Level:5/10
Description:Log files are stored in world-readable folder.
Affected:WEFI : WeFi 3.2
 WEFI : WeFi 3.3
Original documentdocumentXiaShing_(at)_gmail.com, Local information disclosure in WeFi Client v3.3.3.0 (10.07.2008)
 documentXiaShing_(at)_gmail.com, Local vulnerability in WeFi Client v3.2.1.4.1(Update) (04.07.2008)
Discuss:Read or add your comments to this news (0 comments)

Microsoft SQL Server multiple security vulnerabilities
updated since 09.07.2008
Published:10.07.2008
Source:MICROSOFT
SecurityVulns ID:9136
Type:local
Level:6/10
Description:Buffer overflows, memorry corruptions, information leak.
Affected:MICROSOFT : SQL Server 7.0
 MICROSOFT : SQL Server 2000
 MICROSOFT : SQL Server 2005
CVE:CVE-2008-0107
 CVE-2008-0106
 CVE-2008-0086
 CVE-2008-0085
Original documentdocumentBrett Moore, Insomnia : ISVA-080709.1 - Microsoft SQL Server - Corrupt Backup File Heap Overflow (10.07.2008)
 documentIDEFENSE, iDefense Security Advisory 07.08.08: Microsoft SQL Server Restore Integer Underflow Vulnerability (10.07.2008)
 documentMICROSOFT, Microsoft Security Bulletin MS08-040 – Important Vulnerabilities in Microsoft SQL Server Could Allow Elevation of Privilege (941203) (09.07.2008)
Files:Microsoft Security Bulletin MS08-040 – Important Vulnerabilities in Microsoft SQL Server Could Allow Elevation of Privilege (941203)
Discuss:Read or add your comments to this news (0 comments)

libpoppler library uninitialized pointer
updated since 09.07.2008
Published:10.07.2008
Source:BUGTRAQ
SecurityVulns ID:9139
Type:library
Level:6/10
Description:Uninitialized pointer dereference on PDF parsing.
Affected:POPPLER : Poppler 0.8
CVE:CVE-2008-2950 (The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constructor, which allows remote attackers to execute arbitrary code via a crafted PDF document.)
Original documentdocumentFelipe Andres Manzano, [Full-disclosure] #2008-007 libpoppler uninitialized pointer - POC (10.07.2008)
 documentAndrea Barisani, [oCERT-2008-007] libpoppler uninitialized pointer (09.07.2008)
Files:libpoppler uninitialized pointer exploit
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Πειςθνγ@Mail.ru