Computer Security
[EN] securityvulns.ru
no-pyccku



LAND attack DoS against Microsoft Windows 2003 and Microsoft Windows XP
updated since 05.03.2005
Published:16.12.2005
Source:BUGTRAQ
SecurityVulns ID:4555
Type:remote
Level:7/10
Description:LAND attack (ICMP or TCP SYN packet with equal SRC and DST IPs and ports) causes target host to freeze.
Affected:MICROSOFT : Windows XP
 MICROSOFT : Windows 2003 Server
 LINKSYS : Linksys BEFW11S4
 LINKSYS : Linksys WRT54GS
 WESTELL : Versalink 327W
 SCIENTIFICATLANT : Scientific Atlantic DPX2100
Original documentdocumentSynister Syntax, RLA ("Remote LanD Attack") (16.12.2005)
 documentKonrad Malewski, Windows (XP, 2k3, Longhorn) is vulnerable to IpV6 Land attack. (17.05.2005)
 documentDejan Levaja, Windows Server 2003 and XP SP2 LAND attack vulnerability (05.03.2005)
Files:IpV6 Land attack
 newLand v0.1 - Proof of concept tool for the new LAND attack
Discuss:Read or add your comments to this news (3 comments)

Multiple Microsoft Internet Explorer vulnerabilities
updated since 14.12.2005
Published:16.12.2005
Source:CERT
SecurityVulns ID:5528
Type:client
Level:7/10
Description:Code execution, memory corruption, download dialog manipulation, unencrypted HTTPS proxy data leak.
Affected:MICROSOFT : Internet Explorer 5.5
 MICROSOFT : Internet Explorer 6.0
Original documentdocumentSECUNIA, Secunia Research: Microsoft Internet Explorer Keyboard Shortcut Processing Vulnerability (16.12.2005)
 documentMICROSOFT, Microsoft Security Bulletin MS05-054 Cumulative Security Update for Internet Explorer (905915) (14.12.2005)
 documentSECUNIA, Secunia Research: Internet Explorer Suppressed "Download Dialog" Vulnerability (14.12.2005)
 documentCERT, US-CERT Technical Cyber Security Alert TA05-347A -- Microsoft Internet Explorer Vulnerabilities (14.12.2005)
Files: Microsoft Security Bulletin MS05-054 Cumulative Security Update for Internet Explorer (905915)
Discuss:Read or add your comments to this news (1 comments)

Web applications security vulnerabilities (PHP, ASP, CGI, Perl, etc)
Published:16.12.2005
Source:
SecurityVulns ID:5530
Type:remote
Level:5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Affected:EZ : ezUpload 2.2
 PHPNUKE : PHP-Nuke 7.9
 EZDATABASE : ezDatabase 2.1
 SMARTCHOICES : PDEstore 1.8
 NIGHTMEDIA : The CITY Shop 1.3
 CLICKCARTPRO : ClickCartPro 5.1
 STATICSTORE : StaticStore 1.189
 ZAYGO : HostingCart 2.0
 ZAYGO : DomainCart 2.0
 PLEXUM : PlexCart X3
 PAYPALSHOPPINGCA : PPCal Shopping Cart 3.3
 ECTOOLS : ECTOOLS 1.0
 SOFT4E : ECW-Cart 2.03
 EDATCART : eDatCat 3.0
 COMMERCESQL : CommerceSQL 1.0
 ATLANTPRO : AtlantForum 4.0
 ATLANTPRO : Atlant Pro 8.09
 ALMONDSOFT : Almond Classifieds 5.02
 ALMONDSOFT : Almond Personals 4.05
 DCSCRIPTS : DCForum 6.25
 BBBOARD : bbBoard 2.56
 FOCALMEDIA : SiteNet BBS 2.0
 BINARYCONCEPTS : Binary Board System 0.2
 SCARECROW : ScareCrow 2.13
 PHPXPLORER : phpXplorer 0.9
 PAFILEDB : paFileDB Extreme Edition
 LIMBOCMS : LIMBO CMS 1,0
 OPENCMS : OpenCms 6.0
Original documentdocumentMarc Ruef, [Full-disclosure] [scip_Advisory 1910] Alkacon OpenCms 6.0.2 login Cross Site Scripting (16.12.2005)
 documenthackeriri_(at)_yahoo.com, Bug in HC (16.12.2005)
 documentB3g0k_(at)_hackermail.com, Bypass XSS filter in PHPNUKE 7.9=>x (16.12.2005)
 documentB3g0k_(at)_hackermail.com, MarmaraWeb E-commerce Remote Command Exucetion (16.12.2005)
 documentB3g0k_(at)_hackermail.com, MarmaraWeb E-commerce Script Cross Site Scripting (16.12.2005)
 documentretrogod_(at)_aliceposta.it, LIMBO CMS <= v1.0.4.2 _SERVER[] array overwrite / remote code execution (16.12.2005)
 documentr0t, PDEstore XSS vuln. (16.12.2005)
 documentr0t, The CITY Shop XSS vuln. (16.12.2005)
 documentr0t, ClickCartPro (CCP) XSS vuln. (16.12.2005)
 documentr0t, StaticStore Search Engine Friendly E-Commerce XSS (16.12.2005)
 documentr0t, HostingCart XSS (16.12.2005)
 documentr0t, DomainCart XSS (16.12.2005)
 documentr0t, PlexCart X3 SQL inj. vuln. (16.12.2005)
 documentr0t, PPCal Shopping Cart XSS (16.12.2005)
 documentr0t, ECTOOLS - Onlineshop XSS (16.12.2005)
 documentr0t, ECW-Cart XSS vuln. (16.12.2005)
 documentr0t, eDatCat XSS vuln. (16.12.2005)
 documentr0t, CommerceSQL XSS vuln. (16.12.2005)
 documentr0t, AtlantForum XSS vuln. (16.12.2005)
 documentr0t, Atlant Pro XSS vuln. (16.12.2005)
 documentr0t, AlmondSoft Products SQL inj. (16.12.2005)
 documentr0t, DCForum XSS vuln. (16.12.2005)
 documentr0t, bbBoard v2 XSS vuln. (16.12.2005)
 documentr0t, SiteNet BBS XSS vuln (16.12.2005)
 documentr0t, Binary Board System XSS vuln. (16.12.2005)
 documentr0t, ScareCrow Message Board XSS vuln. (16.12.2005)
 documentr0t, phpXplorer XSS vuln. (16.12.2005)
 documentr0t, paFileDB Extreme Edition SQL inj (16.12.2005)
 documentr0t, ezUpload Pro vuln (16.12.2005)
 documentr0t, ezDatabase vuln. (16.12.2005)
Files:imbo <= 1.0.4.2 _SERVER[REMOTE_ADDR] overwrite/ remote cmmnds xctn
Discuss:Read or add your comments to this news (0 comments)

Business Objects WebIntelligence DoS
Published:16.12.2005
Source:BUGTRAQ
SecurityVulns ID:5534
Type:remote
Level:5/10
Description:It's possible to lock out administrator's account with unsuccessfull authentication attempts.
Affected:BUSINESSOBJECTS : WebIntelligence 6.5
Original documentdocumentmkemp4_(at)_csc.com, Business Objects WebIntelligence 6.5x Account Lockout and System DoS (16.12.2005)
Discuss:Read or add your comments to this news (0 comments)

libavcodec / xine library buffer overflow
Published:16.12.2005
Source:BUGTRAQ
SecurityVulns ID:5536
Type:library
Level:5/10
Description:Heap buffer overflow on PNG file parsing.
Affected:MPLAYER : MPlayer 1.0
 XINE : xine 1.1
 XINE : xinelib 1.1
 XMOVIE : xmovie 1.9
 FFMPEG : ffmpeg 0.4
 FFMPEG : gstreamer-ffmpeg 0.8
Original documentdocumentMANDRIVA, MDKSA-2005:232 - Updated gstreamer-ffmpeg packages fix buffer overflow vulnerability (16.12.2005)
 documentMANDRIVA, MDKSA-2005:231 - Updated ffmpeg packages fix buffer overflow vulnerability (16.12.2005)
 documentMANDRIVA, MDKSA-2005:230 - Updated mplayer packages fix buffer overflow vulnerability (16.12.2005)
 documentMANDRIVA, MDKSA-2005:229 - Updated xmovie packages fix buffer overflow vulnerability (16.12.2005)
 documentMANDRIVA, MDKSA-2005:228 - Updated xine-lib packages fix buffer overflow vulnerability (16.12.2005)
Discuss:Read or add your comments to this news (0 comments)

AppScan QA automated vulnerability testing tool buffer overflow
Published:16.12.2005
Source:BUGTRAQ
SecurityVulns ID:5531
Type:client
Level:5/10
Description:Buffer overflow on oversized HTTP server WWW-Authenticate header Realm parameter.
Affected:APPSCAN : AppScan QA 5.0
Original documentdocumentMariano Nuñez Di Croce, CYBSEC - Security Advisory: Watchfire AppScan QA Remote Code Execution (16.12.2005)
Discuss:Read or add your comments to this news (0 comments)

TrendMicro ServerProtect multiple vulnerabilities
Published:16.12.2005
Source:BUGTRAQ
SecurityVulns ID:5532
Type:remote
Level:7/10
Description:Buffer overflows on HTTP chunked encoding parsing, DoS, directory traversal.
Affected:TRENDMICRO : ServerProtect for Windows Management Console 5.58
Original documentdocumentIDEFENSE, iDefense Security Advisory 12.14.05: Trend Micro ServerProtect Crystal Reports ReportServer File Disclosure (16.12.2005)
 documentIDEFENSE, iDefense Security Advisory 12.14.05: Trend Micro ServerProtect EarthAgent Remote DoS Vulnerability (16.12.2005)
 documentIDEFENSE, iDefense Security Advisory 12.14.05: Trend Micro ServerProtect relay.dll Chunked Overflow Vulnerability (16.12.2005)
 documentIDEFENSE, iDefense Security Advisory 12.14.05: Trend Micro ServerProtect isaNVWRequest.dll Chunked Overflow (16.12.2005)
Discuss:Read or add your comments to this news (0 comments)

Apache mod_imap crossite scripting
Published:16.12.2005
Source:BUGTRAQ
SecurityVulns ID:5533
Type:remote
Level:5/10
Description:Referer crossite scripting.
Affected:APACHE : Apache 1.3
Original documentdocumentOPENPKG, [OpenPKG-SA-2005.029] OpenPKG Security Advisory (apache) (16.12.2005)
Discuss:Read or add your comments to this news (0 comments)

Trend Micro PC-Cillin Internet Security antivirus / firewall weak file permissions
Published:16.12.2005
Source:BUGTRAQ
SecurityVulns ID:5535
Type:local
Level:5/10
Affected:TRENDMICRO : PC-Cillin Internet Security 2005 12.00
Original documentdocumentIDEFENSE, iDefense Security Advisory 12.14.05: Trend Micro PC-Cillin Internet Security Insecure File Permission Vulnerability (16.12.2005)
Discuss:Read or add your comments to this news (0 comments)

libremail library format string bug
Published:16.12.2005
Source:FULL-DISCLOSURE
SecurityVulns ID:5538
Type:library
Level:5/10
Description:Buffer overflow on parsing POP3 server response.
Affected:LIBREMAIL : libremail 1.1
Original documentdocumentoudad mehdi, [Full-disclosure] ZRCSA-200505: libremail - "pop.c" Format String Vulnerability (16.12.2005)
Discuss:Read or add your comments to this news (0 comments)

Avaya wireless access points weak cryptography
Published:16.12.2005
Source:SECUNIA
SecurityVulns ID:5539
Type:remote
Level:5/10
Description:Static WEP key 12345 is used.
Affected:AVAYA : Avaya Wireless AP-3
 AVAYA : Avaya Wireless AP-4
 AVAYA : Avaya Wireless AP-5
 AVAYA : Avaya Wireless AP-6
 AVAYA : Avaya Wireless AP-7
Original documentdocumentSECUNIA, [SA18047] Avaya Wireless Access Points Static WEP Key Authentication Bypass (16.12.2005)
Discuss:Read or add your comments to this news (0 comments)

SSH Tectia Server privilege escalation
Published:16.12.2005
Source:SECUNIA
SecurityVulns ID:5540
Type:remote
Level:5/10
Affected:SSH : SSH Tectia Server 5.0
Original documentdocumentSECUNIA, [SA18001] SSH Tectia Server Host-Based Authentication Security Issue (16.12.2005)
Discuss:Read or add your comments to this news (0 comments)

Multiple AIX multiple vulnerabilities
updated since 16.12.2005
Published:03.01.2006
Source:BUGTRAQ
SecurityVulns ID:5537
Type:local
Level:6/10
Description:Buffer overflow in heap debugging, buffer overflows in muxatmd, slocal, file access privilege escalation in getShell and getCommand.
Affected:IBM : AIX 5.1
 IBM : AIX 5.2
 IBM : AIX 5.3
Original documentdocumentXFOCUS Security Team, [xfocus-SD-060101]AIX getCommand&getShell two vulnerabilities (03.01.2006)
 documentNGSSoftware Insight Security Research, Patches available for IBM AIX flaws (16.12.2005)
Discuss:Read or add your comments to this news (1 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Ðåéòèíã@Mail.ru