Computer Security
[EN] securityvulns.ru
no-pyccku



WIN32 PostMessage API information leak
Published:15.03.2003
Source:BUGTRAQ
SecurityVulns ID:2658
Type:library
Level:5/10
Description:By using PostMessage(hwnd, EM_SETPASSWORDCHAR, 0, 0) it's possible to unmask password in dialog to copy it later via buffer. It alows to bypass WM_GETTEXT protection.
Affected:MICROSOFT : Windows 2000 Server
 MICROSOFT : Windows 2000 Professional
 MICROSOFT : Windows XP
Original documentdocumentPalan, Win32: Postmessage API security flaw (15.03.2003)
Discuss:Read or add your comments to this news (1 comments)

GiantRat Mailer weak encryption
Published:15.03.2003
Source:BUGTRAQ
SecurityVulns ID:2659
Type:local
Level:5/10
Description:Password is stored as cleartext in the word-readable file.
Affected:GIANTRAT : GiantRat Mailer 3.1
Original documentdocumentmaninthemiddle_(at)_hushmail.com, GiantRat Mailer exposes PoP password (15.03.2003)
Discuss:Read or add your comments to this news (0 comments)

Buffer overflows in ircII based clients
Published:15.03.2003
Source:BUGTRAQ
SecurityVulns ID:2660
Type:client
Level:5/10
Description:Multiple buffer overflows can only be exploited from server side.
Affected:BITCHX : BitchX 1.0
 IRCII : ircII 20020912
 EPIC4 : EPIC4 1.1
 EPIC4 : EPIC4 1.0
 XCHAT : xchat 2.0
Original documentdocumentTimo Sirainen, Buffer overflows in ircII-based clients (15.03.2003)
Files:"gespuis.c" is an irc bouncer, that can exploit BitchX/Epic clients
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru