Computer Security
[EN] securityvulns.ru
no-pyccku



Microsoft Word WordPerfect filter buffer overflow
updated since 15.09.2004
Published:17.09.2004
Source:MICROSOFT
SecurityVulns ID:4003
Type:client
Level:6/10
Description:Buffer overflow on WordPerfect format parsing.
Affected:MICROSOFT : Office 2000
 MICROSOFT : Office XP
 MICROSOFT : Office 2003
 MICROSOFT : Microsoft Works 2001
 MICROSOFT : Microsoft Works 2002
 MICROSOFT : Microsoft Works 2003
 MICROSOFT : Microsoft Works 2004
Original documentdocumentNGSSoftware Insight Security Research Advisory (NISR), Microsoft WordPerfect 5.x Converter Heap Overflow (17.09.2004)
 documentMICROSOFT, Microsoft Security Bulletin MS04-027 Vulnerability in WordPerfect Converter Could Allow Code Execution (884933) (15.09.2004)
Files:Microsoft Security Bulletin MS04-027 Vulnerability in WordPerfect Converter Could Allow Code Execution (884933)
Discuss:Read or add your comments to this news (0 comments)

Windows XP SP2 dangerous content filtering protection bypass
Published:17.09.2004
Source:BUGTRAQ
SecurityVulns ID:4014
Type:client
Level:5/10
Description:Comment in predefined format causes content to bypass protection.
Affected:MICROSOFT : Windows XP
Original documentdocumentcns, IE6 + XP SP2 Vulnerability (17.09.2004)
Discuss:Read or add your comments to this news (0 comments)

Google Toolbar Local zone scripting
Published:17.09.2004
Source:BUGTRAQ
SecurityVulns ID:4015
Type:client
Level:6/10
Description:By using resource from GoogleToolbar1.dll it's possible to execute scripting in local zone.
Affected:GOOGLE : GoogleToolbar 2.0
Original documentdocumentViPeR, GoogleToolbar:About -- Allows Script Injection (17.09.2004)
Discuss:Read or add your comments to this news (0 comments)

Sudo symboli links problem
Published:17.09.2004
Source:SUDO
SecurityVulns ID:4016
Type:local
Level:6/10
Description:Unsafe temporary fiels access in sudo -u.
Original documentdocumentSUDO, Sudoedit can expose file contents (17.09.2004)
Files:sudoedit Exploit
Discuss:Read or add your comments to this news (0 comments)

WhatsUp Gold special DOS device access
Published:17.09.2004
Source:BUGTRAQ
SecurityVulns ID:4017
Type:remote
Level:5/10
Affected:IPSWITCH : WhatsUp Gold 8.03
Original documentdocumentIDEFENSE, iDEFENSE Security Advisory 09.16.04: Ipswitch WhatsUp Gold Remote Denial of Service Vulnerability (17.09.2004)
Discuss:Read or add your comments to this news (0 comments)

Business Objects WebIntelligence protection bypass
Published:17.09.2004
Source:FULL-DISCLOSURE
SecurityVulns ID:4018
Type:remote
Level:5/10
Description:Access control is implemented on the client-side by only displaying the permitted actions in the browser.
Affected:BUSINESSOBJECTS : WebIntelligence 2.7
 BUSINESSOBJECTS : Business Objects 5.1
Original documentdocumentadvisories, [Full-Disclosure] Corsaire Security Advisory - Business Objects WebIntelligence XSS issue (17.09.2004)
 documentadvisories, [Full-Disclosure] Corsaire Security Advisory - Business Objects WebIntelligence arbitrary document deletion issue (17.09.2004)
Discuss:Read or add your comments to this news (0 comments)

Pigeon Server DoS
Published:17.09.2004
Source:FULL-DISCLOSURE
SecurityVulns ID:4019
Type:remote
Level:5/10
Description:Oversized username causes server to hang.
Affected:TECHNOEL : Pigeon Server 3.02
Original documentdocumentLuigi Auriemma, [Full-Disclosure] Freeze in Pigeon Server 3.02.0143 (17.09.2004)
Discuss:Read or add your comments to this news (0 comments)

multiple browsers cookie spoofing
updated since 25.08.2004
Published:17.09.2004
Source:BUGTRAQ
SecurityVulns ID:3939
Type:library
Level:4/10
Description:It's possible to spoof cookies for few 3rd level domains.
Affected:MICROSOFT : Internet Explorer 6.0
 KDE : KDE 3.2
 MOZILLA : Firefox 0.9
 KDE : KDE 3.3
 KDE : Konqueror 3.1
Original documentdocumentPaul Johnston, wp-04-0001: Multiple Browser Cookie Injection Vulnerabilities (17.09.2004)
 documentKDE, KDE Security Advisory: Konqueror Cross-Domain Cookie Injection (25.08.2004)
 documentGENTOO, [ GLSA 200408-23 ] kdelibs: Cross-domain cookie injection vulnerability (25.08.2004)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru