Computer Security
[EN] securityvulns.ru
no-pyccku



Microsoft Windows SMB file system client buffer overflow
updated since 09.02.2005
Published:15.06.2005
Source:MICROSOFT
SecurityVulns ID:4459
Type:client
Level:8/10
Description:Buffer overflow on nework protocol parsing.
Affected:MICROSOFT : Windows NT 4.0 Workstation
 MICROSOFT : Windows NT 4.0 Server
 MICROSOFT : Windows 2000 Server
 MICROSOFT : Windows 2000 Professional
 MICROSOFT : Windows XP
 MICROSOFT : Windows 2003 Server
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS05-027 Vulnerability in Server Message Block Could Allow Remote Code Execution (896422) (15.06.2005)
 documentEEYE, Update: MS05-011 EEYE: Windows SMB Client Transaction Response Handling Vulnerability (10.03.2005)
 documentEEYE, EEYE: Windows SMB Client Transaction Response Handling Vulnerability (09.02.2005)
 documentMICROSOFT, Microsoft Security Bulletin MS05-011 Vulnerability in Server Message Block Could Allow Remote Code Execution (885250) (09.02.2005)
Files:Windows SMB Client Transaction Response Handling PoC
 Microsoft Security Bulletin MS05-011 Vulnerability in Server Message Block Could Allow Remote Code Execution (885250)
  Microsoft Security Bulletin MS05-027 Vulnerability in Server Message Block Could Allow Remote Code Execution (896422)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Windows HTML Help files parsing buffer overflow
Published:15.06.2005
Source:MICROSOFT
SecurityVulns ID:4888
Type:client
Level:8/10
Description:Heap overflow on HTML help (.chm) files structure parsing.
Affected:MICROSOFT : Windows 2000 Server
 MICROSOFT : Windows 2000 Professional
 MICROSOFT : Windows XP
 MICROSOFT : Windows 2003 Server
Original documentdocumentNGSSoftware Insight Security Research, High Risk Vulnerability in HTML Help (ITSS Parser) (15.06.2005)
 documentMICROSOFT, Microsoft Security Bulletin MS05-026 Vulnerability in HTML Help Could Allow Remote Code Execution (896358) (15.06.2005)
 documentEEYE, [VulnWatch] eEye Advisory - EEYEB-20050316 - HTML Help File Parsing Buffer Overflow (15.06.2005)
Files: Microsoft Security Bulletin MS05-026 Vulnerability in HTML Help Could Allow Remote Code Execution (896358)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Windows Web Client service (WebDav client) buffer overflow
Published:15.06.2005
Source:MICROSOFT
SecurityVulns ID:4890
Type:local
Level:6/10
Description:Buffer overflow on client request parsing.
Affected:MICROSOFT : Windows XP
 MICROSOFT : Windows 2003 Server
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS05-028 Vulnerability in Web Client Service Could Allow Remote Code Execution (896426) (15.06.2005)
Files: Microsoft Security Bulletin MS05-028 Vulnerability in Web Client Service Could Allow Remote Code Execution (896426)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Outlook Express NNTP client buffer overflow
Published:15.06.2005
Source:MICROSOFT
SecurityVulns ID:4892
Type:client
Level:5/10
Description:Buffer overflow on NNTP server reply parsing.
Affected:MICROSOFT : Internet Explorer 5.5
 MICROSOFT : Internet Explorer 6.0
Original documentdocumentIDEFENSE, iDEFENSE Security Advisory 06.14.05: Microsoft Outlook Express NNTP Response Parsing Buffer Overflow Vulnerability (15.06.2005)
 documentMICROSOFT, Microsoft Security Bulletin MS05-030 Cumulative Security Update in Outlook Express (897715) (15.06.2005)
Files:MS OE NNTP LIST Buffer Overflow (MS05-030) EXP
 Microsoft Security Bulletin MS05-030 Cumulative Security Update in Outlook Express (897715)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Step-by-Step Interactive Training buffer overflow
Published:15.06.2005
Source:MICROSOFT
SecurityVulns ID:4893
Type:remote
Level:5/10
Description:Buffer overflow on link files (.cbo, .cbl, .cbm) parsing.
Affected:MICROSOFT : Step-by-Step Interactive Training
Original documentdocumentIDEFENSE, iDEFENSE Security Advisory 06.14.05: Microsoft Windows Interactive Training Buffer Overflow Vulnerability (15.06.2005)
 documentMICROSOFT, Microsoft Security Bulletin MS05-031 Vulnerability in Step-by-Step Interactive Training Could Allow Remote Code Execution (898458) (15.06.2005)
Files:Microsoft Security Bulletin MS05-031 Vulnerability in Step-by-Step Interactive Training Could Allow Remote Code Execution (898458)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Internet Explorer PNG images buffer overflow
Published:15.06.2005
Source:MICROSOFT
SecurityVulns ID:4889
Type:client
Level:8/10
Description:Heap overflow on large specific PNG chunk.
Affected:MICROSOFT : Windows 2000 Server
 MICROSOFT : Windows 2000 Professional
 MICROSOFT : Windows XP
 MICROSOFT : Windows 2003 Server
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS05-025 Cumulative Security Update for Internet Explorer (883939) (15.06.2005)
 documentX-FORCE, Internet Explorer PNG Overflow (15.06.2005)
Files: Microsoft Security Bulletin MS05-025 Cumulative Security Update for Internet Explorer (883939)
Discuss:Read or add your comments to this news (0 comments)

Multiple system telnet client information leak
Published:15.06.2005
Source:BUGTRAQ
SecurityVulns ID:4891
Type:client
Level:5/10
Description:Telnet server can request client's environment variables.
Affected:MICROSOFT : Windows XP
 MICROSOFT : Windows 2003 Server
 MIT : krb5 1.3
 MICROSOFT : Windows Services for UNIX 3.5
 MICROSOFT : Windows Services for UNIX 3.0
 MICROSOFT : Windows Services for UNIX 2.2
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS05-033 Vulnerability in Telnet Client Could Allow Information Disclosure (896428) (15.06.2005)
 documentIDEFENSE, iDEFENSE Security Advisory 06.14.05: Multiple Vendor Telnet Client Information Disclosure Vulnerability (15.06.2005)
Files: Microsoft Security Bulletin MS05-033 Vulnerability in Telnet Client Could Allow Information Disclosure (896428)
Discuss:Read or add your comments to this news (0 comments)

Microsoft ISA Server proxy / firewall multiple vulnerabilities
Published:15.06.2005
Source:MICROSOFT
SecurityVulns ID:4894
Type:remote
Level:6/10
Description:Cache poisoning problem, NetBIOS predefined filter vulnerability.
Affected:MICROSOFT : ISA Server 2000
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS05-034 Cumulative Security Update for ISA Server 2000 (899753) (15.06.2005)
Files:Microsoft Security Bulletin MS05-034 Cumulative Security Update for ISA Server 2000 (899753)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Agent content spoofing
Published:15.06.2005
Source:MICROSOFT
SecurityVulns ID:4895
Type:client
Level:5/10
Description:Microsoft Agent ActiveX allows to spoof trusted site content.
Affected:MICROSOFT : Windows 2000 Server
 MICROSOFT : Windows 2000 Professional
 MICROSOFT : Windows XP
 MICROSOFT : Windows 2003 Server
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS05-032 Vulnerability in Microsoft Agent Could Allow Spoofing (890046) (15.06.2005)
Files: Microsoft Security Bulletin MS05-032 Vulnerability in Microsoft Agent Could Allow Spoofing (890046)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Outlook Web Access crossite scripting
updated since 08.07.2003
Published:15.06.2005
Source:BUGTRAQ
SecurityVulns ID:2960
Type:remote
Level:6/10
Description:It's possible to inject script into message and to acces username/password.
Affected:MICROSOFT : Exchange 5.5
 MICROSOFT : Exchange 2000
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS05-029 Vulnerability in Outlook Web Access for Exchange Server 5.5 Could Allow Cross-Site Scripting Attacks (895179) (15.06.2005)
 documentAmit Klein, HTTP Response Splitting vulnerability in Microsoft Outlook Web Access for Exchange 5.5 (12.08.2004)
 documentMICROSOFT, Microsoft Security Bulletin MS04-026 Vulnerability in Exchange Server 5.5 Outlook Web Access Could Allow Cross-Site Scripting and Spoofing Attacks (842436) (11.08.2004)
 documentOry Segal, Vulnerability in Exchange Server 5.5 Outlook Web Access Could Allow Cross-Site Scripting Attack (Microsoft Security Bulletin MS03-047) (17.10.2003)
 documentMICROSOFT, Microsoft Security Bulletin MS03-047 (16.10.2003)
 documentHugo Vázquez Caramés, Domain User Credentials access via OWA XSS (10.07.2003)
 documentHugo Vázquez Caramés, XSS in OWA allows stealing windows domain user credentials (08.07.2003)
Files:Microsoft Security Bulletin MS04-026 Vulnerability in Exchange Server 5.5 Outlook Web Access Could Allow Cross-Site Scripting and Spoofing Attacks (842436)
  Microsoft Security Bulletin MS05-029 Vulnerability in Outlook Web Access for Exchange Server 5.5 Could Allow Cross-Site Scripting Attacks (895179)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server