Computer Security
[EN] securityvulns.ru
no-pyccku



KOffice buffer overflow
Published:12.10.2005
Source:BUGTRAQ
SecurityVulns ID:5329
Type:client
Level:5/10
Description:Buffer overflow on RTF files parsing.
Affected:KDE : KOffice 1.3
 KDE : KOffice 1.2
 KDE : koffice 1.4
Original documentdocumentKDE, [KDE Security Advisory] KOffice/KWord RTF import buffer overflow (12.10.2005)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Windows Shell multiple vulnerabilities
Published:12.10.2005
Source:MICROSOFT
SecurityVulns ID:5334
Type:client
Level:6/10
Description:Problems with .lnk files processing, HTML files preview.
Affected:MICROSOFT : Windows 2000 Server
 MICROSOFT : Windows 2000 Professional
 MICROSOFT : Windows XP
 MICROSOFT : Windows 2003 Server
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS05-049 Vulnerabilities in Windows Shell Could Allow Remote Code Execution (900725) (12.10.2005)
Files:Microsoft Security Bulletin MS05-049 Vulnerabilities in Windows Shell Could Allow Remote Code Execution (900725)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Windows Client Service for NetWare buffer overflow
Published:12.10.2005
Source:MICROSOFT
SecurityVulns ID:5332
Type:remote
Level:6/10
Description:Buffer overflow in network file srevice.
Affected:MICROSOFT : Windows 2000 Server
 MICROSOFT : Windows 2000 Professional
 MICROSOFT : Windows XP
 MICROSOFT : Windows 2003 Server
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS05-046 Vulnerability in the Client Service for NetWare Could Allow Remote Code Execution (899589) (12.10.2005)
Files:Microsoft Security Bulletin MS05-046 Vulnerability in the Client Service for NetWare Could Allow Remote Code Execution (899589)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Direct Show memory corruption
Published:12.10.2005
Source:BUGTRAQ
SecurityVulns ID:5327
Type:client
Level:6/10
Description:It's possible to overwrite one byte of the dynamic memory with NULL within quartz.dll with crafted AVI file.
Affected:MICROSOFT : DirectX 8.0
 MICROSOFT : DirectX 9.0
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS05-050 Vulnerability in DirectShow Could Allow Remote Code Execution (904706) (12.10.2005)
 documentEEYE, [EEYEB20050510] - Microsoft DirectShow Remote Code Vulnerability (12.10.2005)
Files:Microsoft Security Bulletin MS05-050 Vulnerability in DirectShow Could Allow Remote Code Execution (904706)
Discuss:Read or add your comments to this news (0 comments)

Microsoft FTP client directory traversal
Published:12.10.2005
Source:MICROSOFT
SecurityVulns ID:5330
Type:client
Level:6/10
Description:It's possible to place downloaded file in any directory from server side.
Affected:MICROSOFT : Internet Explorer 6.0
 MICROSOFT : Windows XP
 MICROSOFT : Windows 2003 Server
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS05-044 Vulnerability in the Windows FTP Client Could Allow File Transfer Location Tampering (905495) (12.10.2005)
Files:Microsoft Internet Explorer FTP Download Directory Traversal PoC Exploit
 http://www.microsoft.com/technet/security/Bulletin/MS05-044.mspx
Discuss:Read or add your comments to this news (0 comments)

Microsoft Windows Network Connection Manager service buffer overflow
Published:12.10.2005
Source:MICROSOFT
SecurityVulns ID:5331
Type:remote
Level:6/10
Description:Buffer overflow in RPC service.
Affected:MICROSOFT : Windows 2000 Server
 MICROSOFT : Windows 2000 Professional
 MICROSOFT : Windows XP
 MICROSOFT : Windows 2003 Server
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS05-045 Vulnerability in Network Connection Manager Could Allow Denial of Service (905414) (12.10.2005)
Files:Windows Netman Service Local DOS Vulnerability
  Microsoft Security Bulletin MS05-045 Vulnerability in Network Connection Manager Could Allow Denial of Service (905414)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Design Tools COM object uninitialized memory reference
updated since 12.10.2005
Published:13.10.2005
Source:BUGTRAQ
SecurityVulns ID:5325
Type:client
Level:7/10
Description:CPolyCtrl class destructor attempts to call a function by the pointer from uninitialized dynamic memory region.
Affected:MICROSOFT : Internet Explorer 5.5
 MICROSOFT : Internet Explorer 6.0
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS05-052 umulative Security Update for Internet Explorer (896688) (13.10.2005)
 documentEEYE, [EEYEB20050915] - MDT2DD.DLL COM Object Uninitialized Heap Memory Vulnerability (12.10.2005)
Files:Microsoft Security Bulletin MS05-052 umulative Security Update for Internet Explorer (896688)
Discuss:Read or add your comments to this news (0 comments)

Multiple Microsoft Distributed Transaction Controller DoS conditions
updated since 12.10.2005
Published:13.10.2005
Source:BUGTRAQ
SecurityVulns ID:5328
Type:remote
Level:5/10
Description:Problems with TIP protocols handling, bounce attack is possible.
Affected:MICROSOFT : Windows 2000 Server
 MICROSOFT : Windows 2000 Professional
 MICROSOFT : Windows XP
 MICROSOFT : Windows 2003 Server
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS05-051 Vulnerabilities in MSDTC and COM+ Could Allow Remote Code Execution (902400) (13.10.2005)
 documentIDEFENSE, iDEFENSE Security Advisory 10.11.05: Microsoft Distributed Transaction Controller Packet Relay DoS Vulnerability (12.10.2005)
 documentIDEFENSE, iDEFENSE Security Advisory 10.11.05: Microsoft Distributed Transaction Controller TIP DoS Vulnerability (12.10.2005)
Files:MSDTC remote PoC exploit
 http://www.microsoft.com/technet/security/Bulletin/MS05-051.mspx
Discuss:Read or add your comments to this news (0 comments)

Microsoft Windows Microsoft Collaboration Data Objects buffer overflow
updated since 12.10.2005
Published:13.10.2005
Source:MICROSOFT
SecurityVulns ID:5333
Type:remote
Level:7/10
Description:Buffer overflow on parsing mail messages with Microsoft SMTP service.
Affected:MICROSOFT : Windows 2000 Server
 MICROSOFT : Windows 2000 Professional
 MICROSOFT : Exchange 2000
 MICROSOFT : Windows XP
 MICROSOFT : Windows 2003 Server
Original documentdocumentGary O'leary-Steele, [SEC-1 Advisory] Collaboration Data Objects Buffer Overflow Vulnerability (13.10.2005)
 documentMICROSOFT, Microsoft Security Bulletin MS05-048 Vulnerability in the Microsoft Collaboration Data Objects Could Allow Remote Code Execution (907245) (12.10.2005)
Files:Microsoft CDO Proof of Concept Exploit by Gary O'leary-Steele
 Microsoft Security Bulletin MS05-048 Vulnerability in the Microsoft Collaboration Data Objects Could Allow Remote Code Execution (907245)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Distributed Transaction Coordinator service memory corruption
updated since 12.10.2005
Published:13.10.2005
Source:BUGTRAQ
SecurityVulns ID:5326
Type:remote
Level:7/10
Description:Memory corruption as a result of integer overflow with anonymous remote access (Windows 2000) and authenticated access under Windows XP/2003.
Affected:MICROSOFT : Windows 2000 Server
 MICROSOFT : Windows 2000 Professional
 MICROSOFT : Windows XP
 MICROSOFT : Windows 2003 Server
Original documentdocumentEEYE, [EEYEB20050708] Microsoft Distributed Transaction Coordinator Memory Modification Vulnerability (12.10.2005)
Files:[EXPL] MSDTC Arbitrary Opposite Memory Write Flaw Exploit
 http://www.microsoft.com/technet/security/Bulletin/MS05-051.mspx
Discuss:Read or add your comments to this news (0 comments)

Microsoft Windows Plug and Play Service UMPNPMGR buffer overflow
updated since 12.10.2005
Published:17.11.2005
Source:BUGTRAQ
SecurityVulns ID:5324
Type:remote
Level:7/10
Description:Buffer overflow on PNP_GetDeviceList and PNP_GetDeviceListSize calls for anonymous user on Windows 2000 and authenticated user on Windows 2003 / XP. There is another one similar vulnerability, leading to memory leak with DoS conditions.
Affected:MICROSOFT : Windows 2000 Server
 MICROSOFT : Windows 2000 Professional
 MICROSOFT : Windows XP
 MICROSOFT : Windows 2003 Server
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS05-047 Vulnerability in Plug and Play Could Allow Remote Code Execution and Local Elevation of Privilege (905749) (12.10.2005)
 documentEEYE, [EEYEB20050803] - Windows UMPNPMGR wsprintfW Stack Buffer Overflow Vulnerability (12.10.2005)
Files:Denial of Service attack for MS UMPNPMGR PNP_GetDeviceList
 memory leak and eventual DOS when calling UPNP getdevicelist on windows 2000 server
 Windows UMPNPMGR wsprintfW Stack Buffer Overflow Vulnerability PoC
 Microsoft Security Bulletin MS05-047 Vulnerability in Plug and Play Could Allow Remote Code Execution and Local Elevation of Privilege (905749)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server