Computer Security
[EN] securityvulns.ru
no-pyccku



Microsoft Internet Explorer buffer overflow
updated since 29.06.2005
Published:13.07.2005
Source:FULL-DISCLOSURE
SecurityVulns ID:4942
Type:local
Level:8/10
Description:Buffer overflow while parsing document with embedded non-ActiveX <object> elements.
Affected:MICROSOFT : Internet Explorer 6.0
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS05-037 Vulnerability in JView Profiler Could Allow Remote Code Execution (903235) (12.07.2005)
 documentDaniel Fabian, [Full-disclosure] SEC-CONSULT SA-20050629-0 (29.06.2005)
Files:Internet Explorer non-ActiveX control crash PoC
 Microsoft Internet Explorer "javaprxy.dll" Code Execution Exploit
 Microsoft Security Bulletin MS05-037 Vulnerability in JView Profiler Could Allow Remote Code Execution (903235)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Word buffer overflows
Published:13.07.2005
Source:VULNWATCH
SecurityVulns ID:4988
Type:client
Level:6/10
Description:Stack overflow on font information parsing.
Affected:MICROSOFT : Office 2000
 MICROSOFT : Office XP
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS05-035 Vulnerability in Microsoft Word Could Allow Remote Code Execution (12.07.2005)
 documentIDEFENSE, [VulnWatch] iDEFENSE Security Advisory 07.12.05: Microsoft Word 2000 and Word 2002 Font Parsing Buffer Overflow Vulnerability (12.07.2005)
Files:Microsoft Security Bulletin MS05-035 Vulnerability in Microsoft Word Could Allow Remote Code Execution (903672)
Discuss:Read or add your comments to this news (0 comments)

Multiple MIT krb5 Kerberos 5 vulnerabilities
Published:13.07.2005
Source:BUGTRAQ
SecurityVulns ID:4990
Type:library
Level:8/10
Description:krb5_recvauth() double free() problem. Buffer overflow and memory corruption in KDC.
Affected:SUN : Solaris 9
 SUN : Solaris 10
 SUN : Seam 1.0
 MIT : krb5 1.4
Original documentdocumentSECUNIA, [SA16060] Sun Solaris / SEAM Kerberos KDC Vulnerabilities (13.07.2005)
 documentMIT, MITKRB5-SA-2005-002: buffer overflow, heap corruption in KDC (13.07.2005)
 documentMIT, MITKRB5-SA-2005-003: double-free in krb5_recvauth (13.07.2005)
Discuss:Read or add your comments to this news (0 comments)

MailEnable mail server multiple vulnerabilities
updated since 07.04.2005
Published:13.07.2005
Source:BUGTRAQ
SecurityVulns ID:4642
Type:remote
Level:5/10
Description:DoS on extended ASCII characted in EHLO command. Multiple IMAP buffer overflows. Authorization HTTPS buffer overflow.
Affected:MAILENABLE : MailEnable Professional 1.54
 MAILENABLE : MailEnable Enterprise Edition 1.04
Original documentdocumentCORE SECURITY TECHNOLOGIES ADVISORIES, CORE-2005-0629: MailEnable Buffer Overflow Vulnerability (13.07.2005)
 documentSECUNIA, [SA15986] MailEnable IMAP "STATUS" Command Buffer Overflow (13.07.2005)
 documentCorryL, [Full-disclosure] MailEnable HTTPS Buffer Overflow [x0n3-h4ck] (25.04.2005)
 documentH D Moore, Re: [Full-disclosure] MailEnable Imapd remote BoF + Exploit [x0n3-h4ck] (07.04.2005)
 documentexpanders, [Full-disclosure] MailEnable Imapd remote BoF + Exploit [x0n3-h4ck] (07.04.2005)
 documentCorryL, MailEnable Smtpd remote Dos [x0n3-h4ck] (06.04.2005)
Files:MailEnable (Enterprise <= 1.04)(Professional <= 1.54) remote Imapd exploit
 MailEnable (Enterprise & Professional) HTTPS remote BoF exploit
 MailEnable (Enterprise <= 1.04)-(Professional <= 1.54 SMTPd remote DOS exploit
Discuss:Read or add your comments to this news (0 comments)

Multiple MacOS X vulnerabilities
Published:13.07.2005
Source:SECUNIA
SecurityVulns ID:4993
Type:remote
Level:7/10
Description:System wide denial of service on parsing malcrafted TCP packet. Possibility to overwrite system widget.
Affected:APPLE : Mac OS X 10.4
Original documentdocumentSECUNIA, [SA16047] Apple Mac OS X Two Vulnerabilities (13.07.2005)
Discuss:Read or add your comments to this news (1 comments)

Heartbeat symbolic links problem
Published:13.07.2005
Source:SECUNIA
SecurityVulns ID:4994
Type:local
Level:5/10
Description:Smlink problems on temporary files creation in different code fragments.
Affected:HEARTBEAT : Heartbeat 1.2
 HEARTBEAT : Heartbeat 0.4
Original documentdocumentSECUNIA, [SA16039] Heartbeat Multiple Insecure Temporary File Creation (13.07.2005)
Discuss:Read or add your comments to this news (0 comments)

Electronic Mail Operator symbolic links problem
Published:13.07.2005
Source:SECUNIA
SecurityVulns ID:4995
Type:local
Level:5/10
Description:stats_dump() symlink problem during temporary file creation.
Affected:ELMO : elmo 1.3
Original documentdocumentSECUNIA, [SA15977] Elmo "stats_dump()" Insecure Temporary File Creation (13.07.2005)
Discuss:Read or add your comments to this news (0 comments)

Multiple SoftiaCom wMailServer vulnerabilities
Published:13.07.2005
Source:BUGTRAQ
SecurityVulns ID:4991
Type:remote
Level:5/10
Description:Users passwords are stored in unsafe place. Buffer overflow on oversized SMTP command.
Affected:DARWEB : SoftiaCom wMailServer 1.0
Original documentdocumentSecuBox fRoGGz, SoftiaCom MailServer v2.0 - Denial Of Service (13.07.2005)
 documentSecuBox fRoGGz, SoftiaCom MailServer - Local Password Disclosure Vulnerability (13.07.2005)
Files:SoftiaCom Software - wMailServer v1.0 Denial Of Service - Crash Vulnerability PoC
 SoftiaCom Software - wMailServer v1.0 Local Password Disclosure Vulnerability PoC
Discuss:Read or add your comments to this news (0 comments)

Apple Darwin Streaming Server special device name DoS
Published:13.07.2005
Source:FULL-DISCLOSURE
SecurityVulns ID:4997
Type:remote
Level:5/10
Description:DoS with Web interface while requesting document with special DOS device name.
Affected:APPLE : Darwin Streaming Server 5.5
Original documentdocumentSowhat ., [Full-disclosure] APPLE Darwin Streaming Server Web Admin Remote Denial of Serivce (13.07.2005)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Windows Color Management module buffer overflow
updated since 13.07.2005
Published:17.07.2005
Source:MICROSOFT
SecurityVulns ID:4989
Type:client
Level:9/10
Description:Buffer overflow during ICC tags processing in different graphics formats, including JPEG.
Affected:MICROSOFT : Windows 2000 Server
 MICROSOFT : Windows 2000 Professional
 MICROSOFT : Windows XP
 MICROSOFT : Windows 2003 Server
Original documentdocumentedward11_(at)_postmaster.co.uk, Internet Explorer / MSN ICC Profiles Crash PoC Exploit (17.07.2005)
 documentX-FORCE, ISS Protection Brief: Microsoft ICM Image Compromise (13.07.2005)
 documentMICROSOFT, Microsoft Security Bulletin MS05-036 Vulnerability in Microsoft Color Management Module Could Allow Remote Code Execution (901214) (12.07.2005)
Files:MS05-036 ICC Stack Overflow Exploit
 Windows XP ICC Exploit
 Microsoft Security Bulletin MS05-036 Vulnerability in Microsoft Color Management Module Could Allow Remote Code Execution (901214)
Discuss:Read or add your comments to this news (2 comments)

BIG-IP multiple problems
updated since 13.07.2005
Published:22.07.2005
Source:SECUNIA
SecurityVulns ID:4996
Type:remote
Level:5/10
Description:Certificates handling problem allows to bypass authentication process.
Affected:F5 : 3-DNS Controller 4.5
 F5 : 3-DNS Controller 4.6
 F5 : BIG-IP 9.1
 F5 : BIG-IP 9.0
Original documentdocumentSECUNIA, [SA16159] F5 Networks BIG-IP / 3-DNS Multiple Vulnerabilities (22.07.2005)
 documentSECUNIA, [SA16008] BIG-IP Unspecified SSL Authentication Security Bypass (13.07.2005)
Discuss:Read or add your comments to this news (0 comments)

Multiple Mozilla / Firefox / Funderbird browsers and mail agent vulnerabilities
updated since 13.07.2005
Published:27.07.2005
Source:SECUNIA
SecurityVulns ID:4992
Type:client
Level:8/10
Description:Multiple crossite scripting vulnerabilities, bypassing scripting protection, code execution.
Affected:MOZILLA : Mozilla 1.7
 MOZILLA : Firefox 1.0
 MOZILLA : Thunderbird 1.0
Original documentdocumentSECURITEAM, [NEWS] XBL Implementation Allows Script Execution (Gecko) (27.07.2005)
 documentSECUNIA, [SA16062] Mozilla Thunderbird XBL Controls Script Execution Vulnerability (15.07.2005)
 documentSECUNIA, [SA16043] Firefox Multiple Vulnerabilities (13.07.2005)
 documentSECUNIA, [SA16059] Mozilla Multiple Vulnerabilities (13.07.2005)
Files:Mozilla Suite/Firefox InstallVersion->compareTo() Code Execution exploit(metasploit)
 Mozilla Firefox URLs Script Injection Exploit
 Mozilla XBL Implementation Script Execution exploit
 Mozilla Firefox "Set As Wallpaper" Code Execution Exploit
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru