Computer Security
[EN] securityvulns.ru
no-pyccku



Internet Explorer cookie spoofing
Published:15.11.2004
Source:BUGTRAQ
SecurityVulns ID:4189
Type:remote
Level:4/10
Description:Under certain conditions it's possible to change cookie path.
Original documentdocumentsnsadv_(at)_lac.co.jp, [SNS Advisory No.79] A Possibility of Cookie Overwrite in Microsoft Internet Explorer (15.11.2004)
Discuss:Read or add your comments to this news (0 comments)

Webroot Spy Sweeper weak encryption
Published:15.11.2004
Source:BUGTRAQ
SecurityVulns ID:4190
Type:local
Level:5/10
Description:Password is stored in registry uencrypted.
Affected:WEBROOT : Spy Sweeper 3.2
CVE:CVE-2006-6959 (WebRoot Spy Sweeper 4.5.9 and earlier allows local users to bypass the "Startup-Shield" security restrictions by modifying certain registry keys.)
Original documentdocumentFrank Mileto, [Full-Disclosure] Webroot Spy Sweeper Enterprise Adminpassord open to the world (15.11.2004)
Discuss:Read or add your comments to this news (0 comments)

NetNote DoS
Published:15.11.2004
Source:BUGTRAQ
SecurityVulns ID:4191
Type:remote
Level:5/10
Description:Malcrafted string to TCP/6123 causes program to crash.
Affected:ALSHARE : NetNote Server 2.2
Original documentdocumentclass 101, [Full-Disclosure] [Advisory + Exploit] NetNote Server 2.2, Remote Crafted String Vulnerability (15.11.2004)
Discuss:Read or add your comments to this news (0 comments)

Attachment spoofing code execution in Eudora
updated since 28.05.2003
Published:15.11.2004
Source:BUGTRAQ
SecurityVulns ID:2847
Type:client
Level:5/10
Description:If "attach" and "attach.exe" co-exist in message and "attach" is clicked, "attach.exe" will be silently executed instead.
Affected:QUALCOMM : Eudora 5.2
 QUALCOMM : Eudora 6.0
 QUALCOMM : Eudora 6.1
 EUDORA : Eudora 6.2
Original documentdocumentPaul Szabo, Eudora 6.2 attachment spoof (15.11.2004)
 documentPaul Szabo, Eudora 6.2.0.7 attachment spoof (11.10.2004)
 documentPaul Szabo, Eudora 6.1.2 attachment spoof (08.07.2004)
 documentPaul Szabo, Eudora 6.0.1 LaunchProtect (26.11.2003)
 documentPaul Szabo, Eudora 6.0 attachment spoof, exploit (16.09.2003)
 documentPaul Szabo, Re: Eudora 5.2.1 attachment spoof (28.05.2003)
Discuss:Read or add your comments to this news (0 comments)

SAMBA buffer overflow
updated since 15.11.2004
Published:16.11.2004
Source:FULL-DISCLOSURE
SecurityVulns ID:4192
Type:remote
Level:5/10
Description:By setting small buffer in TRANSACT2_QFILEPATHINFO it's possible to cause dynamic memory buffer overflow on oversized path.
Affected:SAMBA : Samba 3.0
Original documentdocumentSAMBA, [SAMBA] CAN-2004-0882: Possiebl Buffer Overrun in smbd (16.11.2004)
 documentStefan Esser, [Full-Disclosure] Advisory 13/2004: Samba 3.x QFILEPATHINFO unicode filename buffer overflow (15.11.2004)
Discuss:Read or add your comments to this news (0 comments)

CGI bugs
updated since 15.11.2004
Published:19.11.2004
Source:
SecurityVulns ID:4188
Type:remote
Level:5/10
Affected:INVISION : Invision Power Board 2.0
 PHPSCHEDULEIT : phpScheduleIt 1.0
 PHPMYADMIN : phpMyAdmin 2.6
 THEFACEBOOK : TheFaceBook
 AZTEK : Aztek
 PUNBB : PunBB 1.3
 PHPNUKE : Event Calendar 2.13
 APPSERV : AppServ 2.5
 DUWARE : DUGallery
 CLICKANDBUILD : ClickandBuild
Original documentdocumentSECUNIA, [SA13236] ClickandBuild Constructed Store "listPos" Cross-Site Scripting Vulnerability (19.11.2004)
 documentSECUNIA, [SA13241] phpMyAdmin Cross-Site Scripting Vulnerabilities (19.11.2004)
 documentSECURITEAM, [NT] DUGallery Database disclosure (19.11.2004)
 documentsaudi linux, AppServ 2.5.x and Prior Exploit (19.11.2004)
 documentAlexander Anisimov, [MaxPatrol] SQL-injection in Invision Power Board 2.x (19.11.2004)
 documentAndrew Smith, [Full-Disclosure] Click and Build eCommerce Platform Cross Site Scripting (18.11.2004)
 documentSECUNIA, [SA13206] phpScheduleIt Reservation Manipulation Vulnerability (17.11.2004)
 documentJanek Vind, [waraxe-2004-SA#038 - Multiple vulnerabilities in Event Calendar module for PhpNuke] (17.11.2004)
 documentSECUNIA, [SA13201] PunBB Private Message System Module Two Vulnerabilities (16.11.2004)
 documentSECUNIA, [SA13202] Aztek Forum Cross-Site Scripting Vulnerabilities (16.11.2004)
 documentAlex Lanstein, XSS in TheFaceBook round 2 (16.11.2004)
 documentAlex Lanstein, Multiple XSS holes in TheFaceBook (15.11.2004)
 documentJérôme ATHIAS, SQL Injection in phpBT (bug.php - Add) (15.11.2004)
Discuss:Read or add your comments to this news (0 comments)

IPSwitch IMAIL Mail server IMAP buffer overflow
updated since 15.11.2004
Published:11.03.2005
Source:BUGTRAQ
SecurityVulns ID:4193
Type:remote
Level:5/10
Description:Buffer overflow in IMAP DELETE and EXAMINE commands.
Affected:IPSWITCH : IMail 8.13
 IPSWITCH : IMail 8.15
Original documentdocumentIDEFENSE, iDEFENSE Security Advisory 03.10.05: Ipswitch Collaboration Suite IMAP EXAMINE Buffer Overflow Vulnerability (11.03.2005)
 documentJérôme ATHIAS, IPSwitch-IMail-8.13 Stack Overflow in the DELETE Command (15.11.2004)
Files:IPSwitch-IMail-8.13 Stack Overflow in the DELETE Command exploit
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru