 |
|
|
|
| Oracle privilege escalation | | Published: |  | 14.11.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8338 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | Multi-step sequence of operations allows user to get SYSDBA privileges. |
| PHP multiple denial of service conditions | | Published: |  | 14.11.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8342 | | Type: |  | library | | Level: |  | 5/10 | | Description: |  | DoS in stream_wrapper_register(), dgettext(), dcgettext(), dngettext(), gettext(), ngettext(), dcgettext() functions. |
| Nagios plugins multiple security vulnerabilities | | Published: |  | 14.11.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8344 | | Type: |  | client | | Level: |  | 5/10 | | Description: |  | Buffer overflows in check_snmp and check_http on server reply parsing. |
| Affected: |  | NAGIOS : nagios-plugins 1.4 | | CVE: |  | CVE-2007-5623 (Buffer overflow in the check_snmp function in Nagios Plugins (nagios-plugins) 1.4.10 allows remote attackers to cause a denial of service (crash) via crafted snmpget replies.) | | |  | CVE-2007-5198 (Buffer overflow in the redir function in check_http.c in Nagios Plugins before 1.4.10 allows remote web servers to execute arbitrary code via long Location header responses (redirects).) |
| Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 14.11.2007 | | Source: |  | | | SecurityVulns ID: |  | 8337 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
PHP-Nuke: CAPTCHA protection bypass.
Peter’s Random Anti-Spam Image: CAPTACHA protection bypass and crossite scripting. |
| Original document |  | no-reply_(at)_aria-security.net, Free Forums "search" Sql Injection (14.11.2007) |
| |  | no-reply_(at)_aria-security.net, Aria-Security.Net: MetaCart SQL Injection (14.11.2007) |
| |  | no-reply_(at)_aria-security.net, DocuSafe "Search" SQL Injection (14.11.2007) |
| |  | ULTRA.HAQRS.4.ALL ULTRA.HAQRS.4.ALL, [Full-disclosure] 0day0day0day0day AURACMS XSS!! LATEST VERSION!!! 0day0day0day0day (14.11.2007) |
| |  | Elazar Broad, [Full-disclosure] WebEx GPCContainer Memory Access Violation (14.11.2007) |
| |  | MustLive, Vulnerabilities in Peter’s Random Anti-Spam Image (14.11.2007) |
| |  | joseph.giron13_(at)_gmail.com, ExoPHPdesk user profile XSS / profile SQL injection (14.11.2007) |
| |  | ISecAuditors Security Advisories, [ISecAuditors Security Advisories] VTLS.web.gateway cgi is vulnerable to XSS (14.11.2007) |
| |  | L4teral, AutoIndex <= 2.2.2 Cross Site Scripting and Denial of Service (14.11.2007) |
| |  | MustLive, Another vulnerability in PHP-Nuke captcha (14.11.2007) |
| IBM WebSphere MQ multiple security vulnerabilities | | Published: |  | 14.11.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8346 | | Type: |  | remote | | Level: |  | 5/10 |
| Microsoft Windows URL code execution | | Published: |  | 14.11.2007 | | Source: |  | MICROSOFT | | SecurityVulns ID: |  | 8335 | | Type: |  | client | | Level: |  | 7/10 | | Description: |  | Invalid handling of %xx sequences on external URL handlers in Windows XP with Internet Explorer 7 installed allows to execute applications. |
| Novell Netware client privilege escalation | | Published: |  | 14.11.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8341 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | Unprivileged user can manipulate kernel memory with \.\nwfilter device. |
| Emacs safe mode protection bypass | | Published: |  | 14.11.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8343 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | It's possible to bypass enable-local-variables safe mode. |
| Affected: |  | EMACS : emacs 22.1 | | CVE: |  | CVE-2007-5795 (The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search lists of unsafe or risky variables, which might allow user-assisted attackers to bypass intended restrictions and modify critical program variables via a file containing a Local variables declaration.) |
| KDE Konqueror cookie buffer overflow | | Published: |  | 14.11.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8345 | | Type: |  | client | | Level: |  | 5/10 | | Description: |  | Buffer overflow on oversized cookie. |
| WinPcap driver array overflow | | Published: |  | 14.11.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8339 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | Array index overflow in kernel mode on IOCTL handling. |
Microsoft Windows DNS server and DNS client DNS reply spoofing updated since 14.11.2007 | | Published: |  | 09.07.2008 | | Source: |  | MICROSOFT | | SecurityVulns ID: |  | 8336 | | Type: |  | remote | | Level: |  | 6/10 | | Description: |  | Weak pseudo-random generator is used to generate DNS request ID. |
F5 FirePass 4100 crossite scripting updated since 14.11.2007 | | Published: |  | 14.06.2009 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8340 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | SSL VPN download_plugin.php3, page backurl parameter, my.logon.php3, my.activation.php3 crossite scripting. |
|
|
|
|
|
|
|
|