Computer Security
[EN] securityvulns.ru
no-pyccku



Multiple bugzilla bugs
updated since 30.08.2001
Published:13.11.2003
Source:BUGTRAQ
SecurityVulns ID:1442
Type:remote
Level:7/10
Description:Multiple bugs are fixed during audit
Affected:MOZILLA : Bugzilla 2.13
 MOZILLA : Bugzilla 2.14
 MOZILLA : Bugzilla 2.16
 MOZILLA : Bugzilla 2.17
Original documentdocumentBUGZILLA, [BUGZILLA] Security Advisory - information leak (13.11.2003)
 documentDavid Miller, [BUGZILLA] Security Advisory - SQL injection, information leak (05.11.2003)
 documentDavid Miller, [BUGZILLA] Security Advisory - remote database password disclosure (03.01.2003)
 documentDavid Miller, XSS vulnerability in Bugzilla if upgraded from 2.10 or earlier (27.11.2002)
 documentDavid Miller, [BUGZILLA] Security Advisory (02.10.2002)
 documentDavid Miller, [BUGZILLA] Security Advisory For Versions of Bugzilla 2.14 Prior To 2.14.2, 2.16 Prior To 2.16rc2 (12.06.2002)
 documentDave Miller, Security Advisory for Bugzilla v2.15 (cvs20020103) and older (08.01.2002)
 documentfunkysh, Inproper input validation in Bugzilla <=2.14 - exploit (08.01.2002)
 documentMOZILLA, Security Advisory for Bugzilla v2.13 and older (30.08.2001)
Files:Bugzilla <= 2.14 remote exploit - funkysh@sm.pl
Discuss:Read or add your comments to this news (0 comments)

Multiple peoplesoft bugs
Published:13.11.2003
Source:BUGTRAQ
SecurityVulns ID:3247
Type:remote
Level:5/10
Affected:PEOPLESOFT : PeopleTools 8.43
Original documentdocumentadvisories, Corsaire Security Advisory: PeopleSoft PeopleBooks Search CGI multiple argument issues (13.11.2003)
 documentadvisories, Corsaire Security Advisory: PeopleSoft IScript XSS issue (13.11.2003)
 documentadvisories, Corsaire Security Advisory: PeopleSoft Gateway Administration servlet path disclosure issue (13.11.2003)
 documentX-FORCE, ISS Security Brief: PeopleSoft IClient Servlet Remote Command Execution Vulnerability (13.11.2003)
Discuss:Read or add your comments to this news (0 comments)

GAIM information leak
Published:13.11.2003
Source:BUGTRAQ
SecurityVulns ID:3249
Type:remote
Level:5/10
Description:IRC plugins registers user's IP and accoun.
Affected:GAIM : gaim 0.72
Original documentdocument'ken'@FTU , Gaim IRC Local Account Information Leakage (13.11.2003)
Discuss:Read or add your comments to this news (0 comments)

clamav format string bug
Published:13.11.2003
Source:BUGTRAQ
SecurityVulns ID:3251
Type:remote
Level:6/10
Description:Format string bug in e-mail address during syslog() call.
Affected:CLAMAV : clamav 0.60
Original documentdocumentKevin Finisterre, SRT2003-11-11-1151 - clamav-milter remote exploit / DoS (13.11.2003)
Discuss:Read or add your comments to this news (0 comments)

Nokia IPSO crossite scripting
Published:13.11.2003
Source:BUGTRAQ
SecurityVulns ID:3255
Type:remote
Level:5/10
Description:Crossite scripting in web administration interface.
Affected:NOKIA : IPSO 3.6
 NOKIA : IPSO 3.5
 NOKIA : IPSO 3.7
Original documentdocumentFishNet Security CSIRT, Nokia IPSO Script Injection Vulnerability leads to Passive Remote Root, via Network Voyager (13.11.2003)
Discuss:Read or add your comments to this news (0 comments)

Hylafax format string bug
Published:13.11.2003
Source:BUGTRAQ
SecurityVulns ID:3246
Type:remote
Level:5/10
Affected:HYLAFAX : HylaFAX 4.1
Original documentdocumentSUSE, SUSE Security Announcement: hylafax (SuSE-SA:2003:045) (13.11.2003)
Discuss:Read or add your comments to this news (0 comments)

Eudora buffer overflow
Published:13.11.2003
Source:BUGTRAQ
SecurityVulns ID:3248
Type:client
Level:5/10
Description:Buffer overflow during "reply to all" on oversized From: and Reply-To: of original message.
Affected:QUALCOMM : Eudora 5.2
Original documentdocumentsnsadv_(at)_lac.co.jp, [SNS Advisory No.69] Eudora "Reply-To-All" Buffer Overflow Vulnerability (13.11.2003)
Discuss:Read or add your comments to this news (0 comments)

UnixWare privilege escalation
Published:13.11.2003
Source:BUGTRAQ
SecurityVulns ID:3250
Type:local
Level:6/10
Description:Problems with procfs lead to local privilege escalation.
Affected:SCO : UnixWare 7.1
 SCO : Open UNIX 8.0
Original documentdocumentadvisories_(at)_texonet.com, Insecure handling of procfs descriptors in UnixWare 7.1.1, 7.1.3 and Open UNIX 8.0.0 can lead to local privilege escalation. (13.11.2003)
Discuss:Read or add your comments to this news (0 comments)

HP-UX Software Distributor buffer overflow
Published:13.11.2003
Source:BUGTRAQ
SecurityVulns ID:3252
Type:remote
Level:5/10
Description:Buffer overflow on LANG variable parsing.
Affected:HP : HP-UX 11.00
 HP : HP-UX 11.11
Original documentdocumentNsfocus Security Team, NSFOCUS SA2003-07: HP-UX Software Distributor Buffer Overflow Vulnerability (13.11.2003)
Discuss:Read or add your comments to this news (0 comments)

xinetd memory leak DoS
updated since 19.04.2003
Published:13.11.2003
Source:BUGTRAQ
SecurityVulns ID:2749
Type:remote
Level:5/10
Description:144 bytes are leaked on unsuccessful connection.
Affected:XINETD : xinetd 2.3
Original documentdocumentCONECTIVA, [CLA-2003:782] Conectiva Security Announcement - xinetd (13.11.2003)
 documentSteve Grubb, Xinetd 2.3.10 Memory Leaks (19.04.2003)
Discuss:Read or add your comments to this news (0 comments)

IBM AIX libIM buffer overflow
updated since 14.02.2003
Published:13.11.2003
Source:BUGTRAQ
SecurityVulns ID:2593
Type:library
Level:6/10
Description:Buffer overflow on NLS functions.
Affected:IBM : AIX 4.3
 HP : HP-UX 11.00
 IBM : AIX 5.1
 HP : HP-UX 11.11
 HP : HP-UX 11.22
 IBM : AIX 5.2
Original documentdocumentNsfocus Security Team, NSFOCUS SA2003-08: HP-UX libc NLSPATH Environment Variable Privilege Elevation Vulnerability (13.11.2003)
 documentchoi sungwoon, /usr/bin/enq and /usr/bin/X11/aixterm exploit in AIX (18.02.2003)
 documentIDEFENSE, iDEFENSE Security Advisory 02.12.03: Buffer Overflow in AIX libIM.a (14.02.2003)
 documentIBM, libIM.a buffer overflow vulnerability (14.02.2003)
Files:Get a local rootshell from /usr/bin/ct,using HP-UX location language format string bug.
Discuss:Read or add your comments to this news (0 comments)

zebra DoS
updated since 13.11.2003
Published:15.11.2003
Source:BUGTRAQ
SecurityVulns ID:3254
Type:remote
Level:5/10
Description:Few bugs with DoS conditions.
Affected:ZEBRA : zebra 0.93
 QUAGGA : Quagga 0.96
Original documentdocumentPaul Jakma, Quagga remote vulnerability (15.11.2003)
 documentREDHAT, [RHSA-2003:307-01] Updated zebra packages fix security vulnerabilities (13.11.2003)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru