Computer Security
[EN] securityvulns.ru
no-pyccku



ColdFusion MX file uploading and error messages memory leak
updated since 17.04.2004
Published:19.04.2004
Source:BUGTRAQ
SecurityVulns ID:3618
Type:remote
Level:5/10
Description:Memory leak on terminated file upload and oversized error message.
Affected:MACROMEDIA : ColdFusion MX 6.1
Original documentdocumentK. K. Mookhey, Network Intelligence Advisory - Denial of Service Vulnerability in ColdFusion MX (19.04.2004)
 documentMACROMEDIA, MPSB04-06 - Security Patch available for ColdFusion MX 6.1 File Upload Denial of service (17.04.2004)
Discuss:Read or add your comments to this news (0 comments)

Squirrelmail chpasswd buffer overflow
Published:19.04.2004
Source:BUGTRAQ
SecurityVulns ID:3619
Type:local
Level:5/10
Description:Buffer overflow on oversized username.
Affected:SQUIRRELMAIL : SquirrelMail 1.5
Original documentdocumentMatias Neiff, Squirrelmail Chpasswod bof (19.04.2004)
Files:Squirrelmail Change_passwd Buffer Overflow Exploit
 Squirrelmail chpasswd local root exploit by deadcraft
 Squirrelmail chpasswd local root bruteforce exploit
Discuss:Read or add your comments to this news (0 comments)

Zaep crosssite scripting
Published:19.04.2004
Source:FULL-DISCLOSURE
SecurityVulns ID:3620
Type:remote
Level:5/10
Description:Crossite scripting in message validation web interface.
Affected:ZAEP : Zaep AntiSpam 2.0
Original documentdocumentAviram Jenik, [Full-Disclosure] Zaep AntiSpam Cross Site Scripting (19.04.2004)
Discuss:Read or add your comments to this news (0 comments)

Fastream NETFile DoS
Published:19.04.2004
Source:BUGTRAQ
SecurityVulns ID:3622
Type:remote
Level:5/10
Description:Server crashes on unknown FTP username/password.
Affected:FASTREAM : NETFile 6.5
Original documentdocumentDonato Ferrante, DoS in NETFile FTP/Web Server (19.04.2004)
Discuss:Read or add your comments to this news (0 comments)

Serv-U buffer overflow
updated since 26.01.2004
Published:19.04.2004
Source:BUGTRAQ
SecurityVulns ID:3394
Type:remote
Level:6/10
Description:Stack overflow in non-RFC 'chmod' and 'mdtm' and 'ls -l' commands.
Affected:RHINOSOFT : Serv-U 4.2
 RHINOSOFT : Serv-U 5.0
Original documentdocumentSECURITEAM, [NT] Serv-U LIST -l Parameter Buffer Overflow (19.04.2004)
 documentbkbll, [Full-Disclosure] [vulnwatch] Serv-U MDTM Command Buffer Overflow Vulnerability (26.02.2004)
 documentSome Guy, [Full-Disclosure] Serv-U 4.1 Memory Corruption / Whatever (17.02.2004)
 documenticbm, [SST]ServU MDTM command remote buffero verflow adv (26.01.2004)
Files:erv-U FTPD 2.x/3.x/4.x/5.x "MDTM" Command Remote Exploit
 serv-u 4.2 site chmod long_file_name stack overflow exp
 Serv-U FTPD 3.x/4.x "SITE CHMOD" Command remote exploit V1.0
 Serv-U "SITE CHMOD" exploit
 Serv-U MDTM exploits
 Serv-U FTPD 3.x/4.x/5.x "MDTM" Command remote overflow exploit
Discuss:Read or add your comments to this news (0 comments)

Symantec Security Check / Trend Micro HouseCall/ RAV online scanning/ Panda ActiveScan / Mcafee FreeScan / BitDefender ActiveX buffer overflow adn another problems
updated since 23.06.2003
Published:19.04.2004
Source:FULL-DISCLOSURE
SecurityVulns ID:2922
Type:client
Level:5/10
Description:Multiple buffer overflows. File upload and execution.
Affected:SYMANTEC : Symantec RuFSI Utility Class
 TRENDMICRO : Trend Micro HouseCall ActiveX
 RAV : RAV Online Scanning ActiveX
 PANDA : ActiveScan 5.0
 MCAFEE : Mcafee FreeScan
Original documentdocumentRafel Ivgi, [Full-Disclosure] BitDefender Scan Online(ActiveX) - Remote File Download & Execute & Private Information Disclosure (19.04.2004)
 documentS G Masood, McAfee Freescan ActiveX Information Disclosure [Additional Details & PoC] (08.04.2004)
 documentRafel Ivgi, [Full-Disclosure] Symantec Virus Detection(Free ActiveX) - Remote Buffer Overflow (07.04.2004)
 documentRafel Ivgi, [Full-Disclosure] Mcafee FreeScan - Remote Buffer Overflow and Private Information Disclosure (07.04.2004)
 documentRafel Ivgi, Panda ActiveScan 5.0 - Remote Buffer Overflow and A Crash(D.O.S) (07.04.2004)
 documenttrihuynh_(at)_zeeup.com, RAV ActiveX Buffer overflow in ravupdt.dll file (01.08.2003)
 documenttrihuynh_(at)_zeeup.com, [Full-Disclosure] RAV Antivirus : Buffer Overflow in Online Scanning ActiveX (18.07.2003)
 documentc c, [Full-Disclosure] Trend Micro ActiveX Multiple Overflows (13.07.2003)
 documentc c, [Full-Disclosure] Symantec ActiveX control buffer overflow (23.06.2003)
Discuss:Read or add your comments to this news (0 comments)

CGI bugs
updated since 19.04.2004
Published:24.04.2004
Source:BUGTRAQ
SecurityVulns ID:3621
Type:remote
Level:5/10
Affected:PHPBB : phpBB 2.0
 POSTNUKE : PostNuke 0.7
 PHORUM : Phorum 3.4
 POSTNUKE : PostNuke 0.726
 ADVANCEDGUESTBOO : Advanced Guestbook 2.2
 POSTNUKE : phprofession 2.5
 FUSIONPHP : Fusion News 3.6
 PHPNUKE : PhpNuke Protector System 1.15
 NQT : Network Query Tool 1.6
Original documentdocumentJanek Vind, [waraxe-2004-SA#024 - XSS and full path disclosure in Network Query Tool 1.6] (24.04.2004)
 documentk1LL3r B0y, [Full-Disclosure] Cross Site Scripting fusion news (23.04.2004)
 documentshr3kst3r_(at)_hushmail.com, [Full-Disclosure] pisg XSS (22.04.2004)
 documentJanek Vind, [waraxe-2004-SA#021 - Multiple vulnerabilities in phprofession 2.5 module for PostNuke] (22.04.2004)
 documentJanek Vind, [waraxe-2004-SA#022 - Multiple vulnerabilities in PostNuke 0.726 Phoenix - part 2] (22.04.2004)
 documentJQ, Advanced Guestbook 2.2 -- SQL Injection Exploit (22.04.2004)
 documentValerio Santinelli, [PNSA 2004-2] PostNuke Security Advisory PNSA 2004-2 (22.04.2004)
 documentDariusz 'Officerrr' Kolasinski, phpBB modified by Przemo arbitary code execution (20.04.2004)
 documentReady Response, phpBB 2.0.8a and lower - IP spoofing vulnerability (20.04.2004)
 documentJanek Vind, [Full-Disclosure] [waraxe-2004-SA#020 - Multiple vulnerabilities in PostNuke 0.726 Phoenix] (19.04.2004)
 documentJanek Vind, [Full-Disclosure] [waraxe-2004-SA#019 - Critical sql injection bug in Phorum 3.4.7] (19.04.2004)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru