 |
|
|
|
| World in Conflict game server DoS | | Published: |  | 12.10.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8237 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | NULL pointer dereference on invalid TCP/52999 port data. |
| Linux initscripts weak permissions | | Published: |  | 12.10.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8238 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | Weak permissions for /var/log/btmp files cause information leak about unsuccessful logon attempt. |
Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) updated since 12.10.2007 | | Published: |  | 12.10.2007 | | Source: |  | | | SecurityVulns ID: |  | 8239 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
| 3Com 3CRWER100-75 unauthorized access | | Published: |  | 12.10.2007 | | Source: |  | | | SecurityVulns ID: |  | 8240 | | Type: |  | remote | | Level: |  | 3/10 | | Description: |  | Under specific conditions it's possible to access wireless router administration interface from external network. |
| CiscoWorks Wireless LAN Solution Engine Cisco Wireless Control System Conversion Utility default password | | Published: |  | 12.10.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8241 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Conversion utility adds default password. |
| G Data antivirus buffer overflow | | Published: |  | 12.10.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8242 | | Type: |  | remote | | Level: |  | 6/10 | | Description: |  | ScanObjectBrowser.DLL SelectPath() function buffer overflow. |
| CA BrightStor ARCServe BackUp multiple security vulnerabilities | | Published: |  | 12.10.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8243 | | Type: |  | remote | | Level: |  | 7/10 | | Description: |  | TCP/6504 RPC-based requests processing multiple buffer overflows. |
| Affected: |  | CA : Brightstor ARCserve Backup 11.1 | | |  | CA : Brightstor ARCserve Backup 11.0 | | |  | CA : BrightStor ARCserve Backup 10.5 | | |  | CA : BrightStor ARCserve Backup 9.01 | | |  | CA : Brightstor ARCserve Backup 11.5 | | CVE: |  | CVE-2007-5332 (Multiple unspecified vulnerabilities in (1) mediasvr and (2) caloggerd in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, have unknown impact and attack vectors related to memory corruption.) | | |  | CVE-2007-5331 (Queue.dll for the message queuing service (LQserver.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to execute arbitrary code via a malformed ONRPC protocol request for operation 0x76, which causes ARCserve Backup to dereference arbitrary pointers.) | | |  | CVE-2007-5330 (The cadbd RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to (1) execute arbitrary code via stack-based buffer overflows in unspecified RPC procedures, and (2) trigger memory corruption related to the use of "handle" RPC arguments as pointers.) | | |  | CVE-2007-5329 (Unspecified vulnerability in dbasvr in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, has unknown impact and attack vectors related to memory corruption.) | | |  | CVE-2007-5328 (CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows attackers to execute arbitrary code via a "Privileged function exposure.") | | |  | CVE-2007-5327 (Stack-based buffer overflow in the RPC interface for the Message Engine (mediasvr.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to execute arbitrary code via a long argument in the 0x10d opnum.) | | |  | CVE-2007-5326 (Multiple buffer overflows in (1) RPC and (2) rpcx.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote attackers to execute arbitrary code via unspecified vectors.) | | |  | CVE-2007-5325 (Multiple buffer overflows in (1) the Message Engine and (2) AScore.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote attackers to execute arbitrary code via unspecified vectors.) |
Asterisk malformed MIME boundary multiple buffer overflows and DoS updated since 27.08.2007 | | Published: |  | 12.10.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8094 | | Type: |  | remote | | Level: |  | 6/10 | | Description: |  | Multiple buffer overflows and crash on malformed MIME boundary if IMAP storage is used for Voicemail. |
| Affected: |  | ASTERISK : Asterisk 1.4 | | CVE: |  | CVE-2007-4521 (Asterisk Open Source 1.4.5 through 1.4.11, when configured to use an IMAP voicemail storage backend, allows remote attackers to cause a denial of service via an e-mail with an "invalid/corrupted" MIME body, which triggers a crash when the recipient listens to voicemail.) |
OpenBSD DHCP server buffer overflow updated since 12.10.2007 | | Published: |  | 05.11.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8244 | | Type: |  | remote | | Level: |  | 7/10 | | Description: |  | Integer overflow with "maximum message size" option leads to buffer overflow. |
|
|
|
|
|
|
|
|