Computer Security
[EN] securityvulns.ru no-pyccku


Apple QuickTime multiple security vulnerabilities
updated since 06.11.2007
Published:15.11.2007
Source:
SecurityVulns ID:8320
Type:remote
Threat Level:
7/10
Description:Multiple buffer overflows and memory corruption on different graphics and video file formats.
Affected:APPLE : QuickTime 7.2
CVE:CVE-2007-4677
 CVE-2007-4676
 CVE-2007-4675 (Heap-based buffer overflow in the QuickTime VR extension 7.2.0.240 in QuickTime.qts in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via a QTVR (QuickTime Virtual Reality) movie file containing a large size field in the atom header of a panorama sample atom.)
 CVE-2007-4674
 CVE-2007-4672
Original documentdocumentDVLabs, TPTI-07-20: Apple Quicktime Movie Stack Overflow Vulnerability (15.11.2007)
 documentvulndev 48bits, [48Bits Advisory] QuickTime Panorama Sample Atom Heap Overflow (14.11.2007)
 documentCERT, US-CERT Technical Cyber Security Alert TA07-310A -- Apple QuickTime Updates for Multiple Vulnerabilities (07.11.2007)
 documentIDEFENSE, iDefense Security Advisory 11.05.07: Apple QuickTime Panorama Sample Atom Heap Buffer Overflow Vulnerability (06.11.2007)

Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
updated since 15.11.2007
Published:17.11.2007
Source:
SecurityVulns ID:8347
Type:remote
Threat Level:
5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Affected:RUBY : Ruby on Rails 1.2
 LIFERAY : Liferay Portal Enterprise 4.1
CVE:CVE-2007-5380
 CVE-2007-3227 (Cross-site scripting (XSS) vulnerability in the to_json function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.)
Original documentdocumentthetaung_(at)_gmail.com, Javamail login username and password same email problem (17.11.2007)
 documentProCheckUp Research, PR07-02: XSS on Liferay Portal Enterprise 4.1.1 login page ('login' parameter) (17.11.2007)
 documentMC Iglo, Aida-Web Information Exposure (17.11.2007)
 documentadmin_(at)_biyofrm.com, Sciurus Hosting Panel Code İnjection (17.11.2007)
 documentGENTOO, [ GLSA 200711-17 ] Ruby on Rails: Multiple vulnerabilities (15.11.2007)
Files:Exploits Sciurus Hosting Panel Code injection

Apple Mac OS X multiple security vulnerabilities
updated since 15.11.2007
Published:17.11.2007
Source:
SecurityVulns ID:8348
Type:remote
Threat Level:
6/10
Description:Mach ports privilege escalation. Multiple Appletalk protocol handling vulnerabilities. ldt privilege escalation.
Affected:APPLE : MacOS X 10.3
 APPLE : MacOS X 10.4
CVE:CVE-2007-4269 (Integer overflow in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a crafted AppleTalk Session Protocol (ASP) message on an AppleTalk socket, which triggers a heap-based buffer overflow.)
 CVE-2007-4268
 CVE-2007-4267
 CVE-2007-3749
Original documentdocumentRISE Security, [RISE-2007004] Apple Mac OS X 10.4.x Kernel i386_set_ldt() Integer Overflow Vulnerability (17.11.2007)
 documentRISE Security, [Full-disclosure] [RISE-2007004] Apple Mac OS X 10.4.x Kernel i386_set_ldt() Integer Overflow Vulnerability (16.11.2007)
 documenttk_(at)_trapkit.de, [TKADV2007-001] Mac OS X TIOCSETD IOCTL Kernel Memory Corruption Vulnerability (16.11.2007)
 documentCERT, US-CERT Technical Cyber Security Alert TA07-319A -- Apple Updates for Multiple Vulnerabilities (16.11.2007)
 documentIDEFENSE, [Full-disclosure] iDefense Security Advisory 11.14.07: Apple Mac OS X AppleTalk mbuf Kernel Heap Overflow Vulnerability (15.11.2007)
 documentIDEFENSE, [Full-disclosure] iDefense Security Advisory 11.14.07: Apple Mac OS X Mach Port Inheritance Privilege Escalation Vulnerability (15.11.2007)
Files:Exploits Apple Mac OS X 10.4.x Kernel i386_set_ldt() Integer Overflow Vulnerability

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod