 |
|
|
|
| Web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 19.10.2009 | | Source: |  | | | SecurityVulns ID: |  | 10326 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
| IBM DB2 JDBC DoS | | Published: |  | 19.10.2009 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 10328 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | jdbcReadString() read behind memory. |
Adobe Acrobat / Reader multiple security vulnerabilities updated since 14.10.2009 | | Published: |  | 19.10.2009 | | Source: |  | CERT | | SecurityVulns ID: |  | 10320 | | Type: |  | remote | | Level: |  | 8/10 | | Description: |  | Multiple memory corruptions, array index overflows, etc. |
| Affected: |  | ADOBE : Adobe Reader 8.1 | | |  | ADOBE : Adobe Reader 9.1 | | |  | ADOBE : Adobe Reader 7.1 | | CVE: |  | CVE-2009-3459 (Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.) | | |  | CVE-2009-3458 (Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-2998.) | | |  | CVE-2009-2998 (Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-3458.) | | |  | CVE-2009-2997 (Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors.) | | |  | CVE-2009-2991 (Unspecified vulnerability in the Mozilla plug-in in Adobe Reader and Acrobat 8.x before 8.1.7, and possibly 7.x before 7.1.4 and 9.x before 9.2, might allow remote attackers to execute arbitrary code via unknown vectors.) | | |  | CVE-2009-2990 (Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitrary code via unspecified vectors.) | | |  | CVE-2009-2985 (Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-2996.) |
| Zoiper softphone DoS | | Published: |  | 19.10.2009 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 10332 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Crash on SIP request parsing. |
| UiTV UiPlayer ActiveX buffer overflow | | Published: |  | 19.10.2009 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 10327 | | Type: |  | client | | Level: |  | 5/10 | | Description: |  | Buffer overflow in UiCheck.dll |
| CVE: |  | CVE-2009-2970 (Stack-based buffer overflow in the GetUiDllVersion function in an ActiveX control in UiCheck.dll before 1.0.0.7 in UiTV UiPlayer, as used in BaiduX and other products, allows remote attackers to execute arbitrary code via the filename parameter.) |
| xpdf integer overflow | | Published: |  | 19.10.2009 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 10329 | | Type: |  | client | | Level: |  | 6/10 | | Description: |  | Integer overflow during PDF parsing leads to heap overflow. |
| 3COM OfficeConnect routers multiple security vulnerabilities | | Published: |  | 19.10.2009 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 10330 | | Type: |  | remote | | Level: |  | 6/10 | | Description: |  | Backdoor accounts, password stored in clear text, code execution. |
| McKesson Horizon Clinical Infrastructure multiple hardcoded accounts | | Published: |  | 19.10.2009 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 10331 | | Type: |  | remote | | Level: |  | 6/10 | | Description: |  | Multiple unchangable hardcoded accounts. |
|
|
|
|
|
|
|
|