Computer Security
[EN] securityvulns.ru
no-pyccku



Windows Help buffer overflow
Published:11.03.2003
Source:BUGTRAQ
SecurityVulns ID:2641
Type:client
Level:6/10
Description:Buffer overflow on :LNK processing in .CNT files.
Affected:MICROSOFT : Windows 2000 Server
 MICROSOFT : Windows 2000 Professional
Original documentdocumentdescript, Win32hlp exploit for : ":LINK overflow" (11.03.2003)
Files:Win32hlp exploit for : ":LINK overflow"
Discuss:Read or add your comments to this news (0 comments)

HP-UX stmkfont buffer overflow
Published:11.03.2003
Source:SECURITEAM
SecurityVulns ID:2642
Type:local
Level:5/10
Description:Buffer overflow during command line parsing.
Original documentdocumentSECURITEAM, [EXPL] STMKFont Exploit Code Released (11.03.2003)
Files:Exploit for command stmkfont of HPUX to get bin gid
Discuss:Read or add your comments to this news (0 comments)

DeleGate array index overflow
Published:11.03.2003
Source:SECURITEAM
SecurityVulns ID:2643
Type:remote
Level:6/10
Description:Array index overflow on large number of User-Agent in robots.txt
Affected:DELEGATE : DeleGate 8.3
 DELEGATE : DeleGate 8.4
Original documentdocumentSNS, [SNS Advisory No.63] DeleGate Pointer Array Overflow May Let Remote Users Execute Arbitrary Code (11.03.2003)
 documentSECURITEAM, [NEWS] DeleGate Pointer Array Overflow May Let Remote Users Execute Arbitrary Code (11.03.2003)
Discuss:Read or add your comments to this news (0 comments)

Forum Web Server multiple bugs
Published:11.03.2003
Source:SECURITEAM
SecurityVulns ID:2644
Type:remote
Level:5/10
Description:Crossite scripting, directory traversal on file upload, information leak.
Affected:FORUM : Forum Web Server 1.60
Original documentdocumentSECURITEAM, [NT] Multiple Vulnerabilities Found in Forum Web Server (11.03.2003)
Discuss:Read or add your comments to this news (0 comments)

qpopper buffer overflow
Published:11.03.2003
Source:BUGTRAQ
SecurityVulns ID:2646
Type:remote
Level:8/10
Description:Qvsnprintf doesn't NULL-terminates string exceeding maximum length.
Affected:QUALCOMM : qpopper 4.0
Original documentdocumentFlorian Heinz, QPopper 4.0.x buffer overflow vulnerability (11.03.2003)
Files:Exploit for qpopper 4.0.x
Discuss:Read or add your comments to this news (0 comments)

Internet Explorer .mht DoS
Published:11.03.2003
Source:BUGTRAQ
SecurityVulns ID:2647
Type:client
Level:4/10
Description:If executable with MZP signature but without actual data is included, NULL pointer reference occurs.
Affected:MICROSOFT : Internet Explorer 5.5
 MICROSOFT : Internet Explorer 6.0
Original documentdocumentTom Tanaka, .MHT Buffer Overflow in Internet Explorer (11.03.2003)
Discuss:Read or add your comments to this news (0 comments)

PeopleSoft XML unauthorized access
updated since 21.01.2003
Published:11.03.2003
Source:X-FORCE
SecurityVulns ID:2546
Type:remote
Level:6/10
Description:It's possible to access any webserver files by using XML External Entities. By using SchedulerTransfer servlett it's possible to write arbitrary files on server.
Affected:PEOPLESOFT : PeopleTools 8.18
 PEOPLESOFT : PeopleTools 8.40
 PEOPLESOFT : PeopleTools 8.41
Original documentdocumentX-FORCE, ISS Security Brief: PeopleSoft PeopleTools Remote Command Execution Vulnerability (11.03.2003)
 documentX-FORCE, ISS Security Brief: PeopleSoft XML External Entities Vulnerability (21.01.2003)
Discuss:Read or add your comments to this news (0 comments)

CGI bugs
updated since 11.03.2003
Published:16.03.2003
Source:SECURITEAM
SecurityVulns ID:2645
Type:remote
Level:5/10
Affected:THUNDERSTONE : Texis
 PHPNUKE : PHP-Nuke 6.0
 CIRCLE : Guestbook 1.1
 JACOBUDDY : Jacobuddy 3.0
 LXR : Cross-Referencing Linux 0.9
 PHPNUKE : PHP-Nuke 6.5
 SQUIRRELMAIL : VPOPMail Account Administration 0.9
 UKFSN : Business::OnlinePayment::WorldPay::Junior 1.05
 RSA : ClearTrust
Original documentdocumentSir Mordred The Traitor, @(#)Mordred Security Labs - RSA ClearTrust Cross Site Scripting issues (16.03.2003)
 documentJason Clifford, Remote Exploit in Business::OnlinePayment::WorldPay::Junior (16.03.2003)
 documentflur, Guestbook v1.1.3 CSS Vuln (15.03.2003)
 documentSir Mordred The Traitor, @(#)Mordred Labs advisory - Texis sensitive information leak (15.03.2003)
 documentmaninthemiddle_(at)_hushmail.com, GiantRat Mailer exposes PoP password (15.03.2003)
 documenterror, VPOPMail Account Administration (squirrel mail) version 0.9.7 (13.03.2003)
 documentfrog frog, PHP-Nuke 6.0 & 6.5RC2 SQL Injection Again (11.03.2003)
 documentRipe, Cross-Referencing Linux vulnerability (11.03.2003)
 documentSECURITEAM, [UNIX] Sourceforge Jacobuddy Cross Site Scripting (XSS) and Upload Exploit (11.03.2003)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru