Computer Security
[EN] securityvulns.ru
no-pyccku



*BSD ibcs2 information leak
updated since 12.08.2003
Published:19.09.2003
Source:BUGTRAQ
SecurityVulns ID:3053
Type:local
Level:5/10
Description:statfs call with large argument length allows to read kernel memory content.
Affected:NETBSD : NetBSD 1.5
 FREEBSD : FreeBSD 4.8
 FREEBSD : FreeBSD 5.1
Original documentdocumentNETBSD, NetBSD Security Advisory 2003-013: Kernel memory disclosure via ibcs2 (19.09.2003)
 documentFREEBSD, Kernel memory disclosure via ibcs2 (12.08.2003)
Discuss:Read or add your comments to this news (0 comments)

CGI bugs
updated since 16.09.2003
Published:19.09.2003
Source:
SecurityVulns ID:3121
Type:remote
Level:5/10
Affected:JELSOFT : vBulletin 2.2
 BANDSITE : Bandsite Portal System 1.5
 SPAIZNUKE : SPAIZ-NUKE 1.1
 MAMBO : Mambo 4.0
Original documentdocumentLifo Fifo, Several Mambo 4.0.14 Stable Exploits (19.09.2003)
 documentRoberto, vBulletin Multiple Cross Site Scripting Vulnerabilities (19.09.2003)
 document1dt.w0lf, SPAIZ-NUKE v1.1 XSS bug (19.09.2003)
 documentSECURITEAM, [UNIX] Vulnerability in Bandsite Allows Gaining Admin Access (16.09.2003)
Discuss:Read or add your comments to this news (0 comments)

Unauthorized Solaris sadmind access
updated since 16.09.2003
Published:19.09.2003
Source:SECURITEAM
SecurityVulns ID:3122
Type:remote
Level:8/10
Description:It's possible to bypass authentication process by sequence of specially crafted RPC calls.
Original documentdocumentH D Moore, Solaris SADMIND Exploitation (19.09.2003)
 documentSECURITEAM, [UNIX] Remote Root Exploitation of Default Solaris sadmind Setting (16.09.2003)
Files:Remote command executiong via sadmind
Discuss:Read or add your comments to this news (0 comments)

OpenSSD memory corruption
updated since 16.09.2003
Published:19.09.2003
Source:BUGTRAQ
SecurityVulns ID:3123
Type:remote
Level:6/10
Description:Because of memory allocation problems it's possible to overwrite memory block with zeros.
Affected:OPENSSH : openssh 3.4
 CISCO : CiscoWorks 1105
 CISCO : Cisco SN 5428
 LSH : lsh 1.4
Original documentdocumentCISCO, Cisco Security Advisory: OpenSSH Server Vulnerabilities (17.09.2003)
 documentCERT, CERT Advisory CA-2003-24 Buffer Management Vulnerability in OpenSSH (17.09.2003)
 documentX-FORCE, ISS Security Brief: OpenSSH Memory Corruption Vulnerability (17.09.2003)
 documentENGARDE, [ESA-20030916-023] OpenSSH buffer management error. (16.09.2003)
Files:exploit for lsh 1.4.x
Discuss:Read or add your comments to this news (0 comments)

Multiple IBM DB2 bugs
updated since 19.09.2003
Published:19.09.2003
Source:BUGTRAQ
SecurityVulns ID:3127
Type:remote
Level:6/10
Description:Format string bugs, buufer overflows.
Affected:IBM : DB2 7.2
 IBM : DB2 8.1
Original documentdocumentKevin Finisterre, SRT2003-11-06-0710 - IBM DB2 Multiple local security issues (10.11.2003)
 documentPentest Security Advisories, ptl-2003-02: IBM DB2 INVOKE Command Stack Overflow Vulnerability (03.10.2003)
 documentPentest Security Advisories, ptl-2003-01: IBM DB2 LOAD Command Stack Overflow Vulnerability (03.10.2003)
 documentAaron C. Newman, AppSecInc Security Alert: Denial of Service Vulnerability in DB2 Discovery Service (22.09.2003)
 documentCORE SECURITY TECHNOLOGIES ADVISORIES, CORE-2003-0531: Multiple IBM DB2 Stack Overflow Vulnerabilities (19.09.2003)
Discuss:Read or add your comments to this news (0 comments)

Multiple NetBSD bugs
Published:19.09.2003
Source:BUGTRAQ
SecurityVulns ID:3128
Type:local
Level:5/10
Description:DoS, kernel memory reading.
Affected:NETBSD : NetBSD 1.5
 NETBSD : NetBSD 1.6
Original documentdocumentNETBSD, NetBSD Security Advisory 2003-014: Insufficient argument checking in sysctl(2) (19.09.2003)
Discuss:Read or add your comments to this news (0 comments)

Plug & Play Web Server multiple bugs
updated since 19.09.2003
Published:03.11.2003
Source:BUGTRAQ
SecurityVulns ID:3125
Type:remote
Level:5/10
Description:Directory traversal, DoS.
Affected:PANDPSOFTWARE : Plug & Play Web Server 1.0002
Original documentdocumentOliver Karow, DoS in Plug and Play Web Server Proxy Server (03.11.2003)
 documentBahaa Naamneh, Directory traversal in Plug & Play Web Server (19.09.2003)
 documentBahaa Naamneh, Denial Of Service in Plug & Play Web (FTP) Server (19.09.2003)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru