Computer Security
[EN] securityvulns.ru
no-pyccku



SCO uidadmin buffer overflow
updated since 28.08.2001
Published:13.12.2005
Source:BUGTRAQ
SecurityVulns ID:1434
Type:local
Level:6/10
Description:Buffer overflow on parsing -S command line parameter.
Affected:SCO : UnixWare 7.1
 SCO : Open UNIX 8.0
Original documentdocumentIDEFENSE, iDEFENSE Security Advisory 12.12.05: SCO Unixware Setuid 'uidadmin' Scheme Buffer Overflow Vulnerability (13.12.2005)
 documentCALDERA, Security Update: [CSSA-2001-SCO.14] Open Unix, UnixWare: uidadmin buffer overflow (28.08.2001)
Discuss:Read or add your comments to this news (0 comments)

NetGear firewalls/routers TCP SYN flood DoS
Published:13.12.2005
Source:BUGTRAQ
SecurityVulns ID:5524
Type:remote
Level:5/10
Affected:NETGEAR : NetGear RP114
Original documentdocumentMarc Ruef, [scip_Advisory] NetGear RP114 Flooding Denial of Service (13.12.2005)
Discuss:Read or add your comments to this news (0 comments)

Web applications security vulnerabilities (PHP, ASP, CGI, Perl, etc)
Published:13.12.2005
Source:
SecurityVulns ID:5523
Type:remote
Level:5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Affected:HORDE : Horde 3.0
 DCPPORTAL : DCP-Portal 6.1
 MYBLOGGIE : myBloggie 2.1
 E107 : e107 0.7
 MANTIS : Mantis 1.0
 PHPWEBTHINGS : PHPWebthings 1.4
 PHPWEBGALLERY : PhpWebGallery 1.5
 PHPJK : PHP JackKnife 2.21
 POWERDEV : EncapsGallery 1.0
 SNIPEGALLERY : Snipe Gallery 3.1
 PLOGGER : Plogger
 UTOPIA : utopia NewPro 1.1
 ARABPORTAL : Arab Portal 2
 HORDE : Kronolith 2.0
 HORDE : Mnemo 2.0
 HORDE : Nag 2.0
 HORDE : turba 2.0
 GUESTSERVER : Guestserver 4.12
 MCGALLERYPRO : mcGallery PRO 2.2
 EVERYAUCTION : EveryAuction 1.53
Original documentdocumentSECUNIA, [SA18016] EveryAuction "searchstring" Cross-Site Scripting Vulnerability (13.12.2005)
 documentr0t, mcGallery PRO vuln. (13.12.2005)
 documentsilversmith_(at)_ashiyane.com, IMOEL CMS Sql password discovery (13.12.2005)
 documentjaakko_(at)_ritke.fi, Guestserver guestbook system vulnerabilities (13.12.2005)
 documentJohannes Greil, SEC Consult SA-20051211-0 :: Several XSS issues in Horde Framework, Kronolith Calendar, Mnemo Notes, Nag Tasks and Turba Addressbook (13.12.2005)
 documentstranger-killer_(at)_hotmail.com, Arab Portal v2 Beta2 SQL Injections (13.12.2005)
 documentphp-checker_(at)_glide.stanford.edu, [PHP-CHECKER] 99 potential SQL injection vulnerabilities (13.12.2005)
 documentr0t, Mantis bugtracking system XSS vuln. (13.12.2005)
 documentr0t, PhpWebGallery multiple SQL inj. (13.12.2005)
 documentr0t, PHP JackKnife XSS vuln. (13.12.2005)
 documentr0t, EncapsGallery SQL inj. vuln. (13.12.2005)
 documentr0t, Snipe Gallery SQL&XSS vuln. (13.12.2005)
 documentr0t, Plogger SQL&XSS vuln. (13.12.2005)
Discuss:Read or add your comments to this news (0 comments)

Nortel SSL VPN multiple vulnerabilities
Published:13.12.2005
Source:BUGTRAQ
SecurityVulns ID:5525
Type:remote
Level:6/10
Description:Crossite scripting, code execution.
Affected:NORTEL : Nortel SSL VPN 4.2
Original documentdocumentDaniel Fabian, SEC Consult SA-20051211-0 :: Nortel SSL VPN Cross Site Scripting/Command Execution (13.12.2005)
Discuss:Read or add your comments to this news (0 comments)

MacOS X perl privilege escalation
Published:13.12.2005
Source:SECUNIA
SecurityVulns ID:5526
Type:library
Level:5/10
Description:Instruction "$< = numeric_id;" for setting uid doesn't work.
Affected:APPLE : MacOS X 10.3
Original documentdocumentSECUNIA, [SA17922] Mac OS X Perl "$<" Privilege Dropping Security Issue (13.12.2005)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru