 |
|
|
|
| Web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 12.01.2010 | | Source: |  | | | SecurityVulns ID: |  | 10512 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
|
| ACDSee applications buffer overflow | | Published: |  | 12.01.2010 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 10509 | | Type: |  | client | | Level: |  | 5/10 | | Description: |  | Buffer overflow on XBM files parsing. |
| Audiotran media player buffer overflow | | Published: |  | 12.01.2010 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 10510 | | Type: |  | client | | Level: |  | 5/10 | | Description: |  | Buffer overflow on playlists parsing. |
| Multiple applications log files terminal control characters injections | | Published: |  | 12.01.2010 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 10511 | | Type: |  | remote | | Level: |  | 3/10 | | Description: |  | ESC-sequences filtering is not performed. |
| Affected: |  | THTTPD : thttpd 2.25 | | |  | NGINX : nginx 0.7 | | |  | REDPILLLINPRO : Varnish 2.0 | | |  | CHEROKEE : Cherokee 0.99 | | |  | MINIHTTPD : mini_httpd 1.19 | | |  | WEBRICK : WEBrick 1.3 | | |  | ORION : Orion 2.0 | | |  | AOLSERVER : AOLserver 4.5 | | |  | YAWS : Yaws 1.85 | | |  | BOA : Boa 0.94 | | CVE: |  | CVE-2009-4496 (Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.) | | |  | CVE-2009-4495 (Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.) | | |  | CVE-2009-4494 (AOLserver 4.5.1 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.) | | |  | CVE-2009-4493 (Orion Application Server 2.0.7 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.) | | |  | CVE-2009-4492 (WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.) | | |  | CVE-2009-4491 (thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.) | | |  | CVE-2009-4490 (mini_httpd 1.19 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.) | | |  | CVE-2009-4489 (header.c in Cherokee before 0.99.32 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.) | | |  | CVE-2009-4488 (** DISPUTED ** Varnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. NOTE: the vendor disputes the significance of this report, stating that "This is not a security problem in Varnish or any other piece of software which writes a logfile. The real problem is the mistaken belief that you can cat(1) a random logfile to your terminal safely.") | | |  | CVE-2009-4487 (nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.) |
Panda Global Protection / Panda Internet Security weak security permissions updated since 02.11.2009 | | Published: |  | 12.01.2010 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 10368 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | Weak permissions for executable files. |
|
|
|
|
|
|
|
|