Computer Security
[EN] securityvulns.ru
no-pyccku



Multiple bugs in Oracle Listener
Published:15.08.2002
Source:NTBUGTRAQ
SecurityVulns ID:2228
Type:remote
Level:6/10
Description:Format string bug, DoS.
Affected:ORACLE : Oracle 9i
 ORACLE : Oracle 8i
Original documentdocumentX-FORCE, Remote Denial of Service Vulnerability in Oracle9i SQL*NET (15.08.2002)
 documentNGSSoftware Insight Security Research, Oracle Listener Control Format String Vulnerabilities (#NISR14082002) (15.08.2002)
Discuss:Read or add your comments to this news (0 comments)

CGI bugs
updated since 15.08.2002
Published:25.08.2002
Source:BUGTRAQ
SecurityVulns ID:2229
Type:remote
Level:5/10
Affected:CGI : L-Forum 2.4
 CGI : mantisbt 0.17
 CAFELOG : b2 Weblog Tool 2.06
 CGI : php-affiliate 1.0
 CGI : Web Shop Manager 1.1
 ICEWARP : IceWarp Webmail 3.3
 PHPNUKE : PHP-Nuke 5.6
 CGI : Bonsai
 TOMAHAWK : SteelArrow
 PROHOST : FUDforum 2.0
 ACHIEVO : Achievo 0.7
 ACHIEVO : Achievo 0.8
 ACHIEVO : Achievo 0.9
 BLAZIX : Blazix 1.2
Original documentdocumentAuriemma Luigi, Blazix 1.2 jsp view and free protected folder access (25.08.2002)
 documentJeroen Latour, [Mantis Advisory/2002-07] Bugs in private projects listed on 'View Bugs' (25.08.2002)
 documentJeroen Latour, [Mantis Advisory/2002-06] Private bugs accessible in Mantis (25.08.2002)
 documentJeroen Latour, Arbitrary code execution problem in Achievo (23.08.2002)
 documentUlf Harnhammar, FUDforum file access and SQL Injection (20.08.2002)
 documentNGSSoftware Insight Security Research, Multiple Buffer Overflow vulnerabilities in SteelArrow (#NISR19082002B) (20.08.2002)
 documentJeroen Latour, [Mantis Advisory/2002-03] Bug listings of private projects can be viewed through cookie manipulation (20.08.2002)
 documentJeroen Latour, [Mantis Advisory/2002-05] Arbitrary code execution and file reading vulnerability in Mantis (20.08.2002)
 documentJeroen Latour, [Mantis Advisory/2002-01] SQL poisoning vulnerability in Mantis (20.08.2002)
 documentJeroen Latour, [Mantis Advisory/2002-02] Limiting output to reporters can be bypassed (20.08.2002)
 documentJeroen Latour, [Mantis Advisory/2002-04] Arbitrary code execution vulnerability in Mantis (20.08.2002)
 documentStan Bubrouski, Advisory: Bonsai XSS and Physical Path Revealing Vulnerabilities (20.08.2002)
 document<-delusion->, PHP-Nuke v5.6 - Users can compromise admin accts. (16.08.2002)
 documentUlf Harnhammar, L-Forum XSS and upload spoofing (16.08.2002)
 documentDarC KonQuesT, IceWarp Webmail XSS (16.08.2002)
 documentTacettin Karadeniz, Web Shop Manager Security Vulnerability (16.08.2002)
 documentMOD, Input validation attack in php-affiliate-v1.0 (16.08.2002)
 documentMatthew Murphy, Multiple Vulnerabilities in CafeLog Weblog Package (15.08.2002)
 documentJoao Gouveia, mantisbt security flaw (15.08.2002)
 documentMatthew Murphy, L-Forum Vulnerability - SQL Injection (15.08.2002)
Discuss:Read or add your comments to this news (0 comments)

Internet explorer (and others) CA certificate attack
updated since 15.08.2002
Published:29.11.2003
Source:BUGTRAQ
SecurityVulns ID:2227
Type:m-i-t-m
Level:5/10
Description:For intermediate CA only signature is checked, missed check for basic constaint allows to use any valid certificate as CA certificate.
Affected:MICROSOFT : Office 2000
 MICROSOFT : Internet Explorer 5.5
 MICROSOFT : Internet Information Server 5.0
 MICROSOFT : Internet Explorer 6.0
 KDE : KDE 3.0
 TINYSSL : TinySSL 1.03
 SUN : JSSE 1.0
 OPENCA : OpenCA 0.9
Original documentdocumentMichael Bell, [OpenCA Advisory] Vulnerabilities in signature verification (29.11.2003)
 documentAlex Loots, Incorrect Certificate Validation in Java Secure Socket Extension (28.01.2003)
 documentMICROSOFT, UPDATE: Microsoft Security Bulletin MS02-050: Certificate Validation Flaw Could Enable Identity Spoofing (Q329115) (21.11.2002)
 documentMICROSOFT, Security Bulletin MS02-050: Certificate Validation Flaw Could Enable Identity Spoofing (Q328145) (05.09.2002)
 documentMike Benham, Outlook S/MIME Vulnerability (03.09.2002)
 documentKDE, KDE Security Advisory: Konqueror SSL vulnerability (20.08.2002)
 documentJohan Persson, Insufficient Verification of Client Certificates in IIS 5.0 pre sp3 (20.08.2002)
 documentAdam Megacz, TinySSL Vendor Statement: Basic Constraints Vulnerability (15.08.2002)
 documentMike Benham, IE SSL Vulnerability (15.08.2002)
Files:IE SSL Exploit
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru