Computer Security
[EN] securityvulns.ru
no-pyccku



Novell Groupwise Client memory cleartext password
Published:21.06.2005
Source:BUGTRAQ
SecurityVulns ID:4913
Type:local
Level:4/10
Description:Cleartext password is stored in memory.
Affected:NOVELL : GroupWise 5.5
 NOVELL : GroupWise 6.0
 NOVELL : GroupWise 6.5
Original documentdocumentSecurity Team, Novell GroupWise Plain Text Password Vulnerability. (21.06.2005)
Discuss:Read or add your comments to this news (0 comments)

PeerCast p2p multimedia broadcasting format string vulnerability
updated since 30.05.2005
Published:21.06.2005
Source:SECUNIA
SecurityVulns ID:4838
Type:remote
Level:6/10
Description:Format string bug on HTTP request parsing.
Affected:PEERCAST : PeerCast 0.1211
Original documentdocumentJeiAr, Format String Vulnerability In Peercast 0.1211 And Earlier (30.05.2005)
 documentSECUNIA, [SA15536] PeerCast URL Format String Vulnerability (30.05.2005)
Files:PeerCast <= 0.1211 remote format string exploit
Discuss:Read or add your comments to this news (0 comments)

Novell Netmail weak permissons
Published:21.06.2005
Source:SECUNIA
SecurityVulns ID:4915
Type:local
Level:5/10
Description:uid/gid 500/500 is incorrectly set as file owner.
Affected:NOVELL : NetMail 3.52
Original documentdocumentSECUNIA, [SA15763] Novell NetMail File Ownership Security Issue (21.06.2005)
Discuss:Read or add your comments to this news (0 comments)

Multiple browsers dialog content spoofing
Published:21.06.2005
Source:SECUNIA
SecurityVulns ID:4914
Type:client
Level:5/10
Description:It's possible to spoof dialog window origin.
Affected:MICROSOFT : Internet Explorer 5.5
 MICROSOFT : Internet Explorer 6.0
 MOZILLA : Mozilla 1.7
 MOZILLA : Camino 0.8
 MOZILLA : Firefox 1.0
 OPERA : Opera 8.0
 ICAB : iCab 2.9
 APPLE : Safari 2.0
 MICROSOFT : Internet Explorer 5.2 for Mac
Original documentdocumentSECUNIA, [SA15491] Microsoft Internet Explorer Dialog Origin Spoofing Vulnerability (21.06.2005)
 documentSECUNIA, [SA15492] Internet Explorer for Mac Dialog Origin Spoofing Vulnerability (21.06.2005)
 documentSECUNIA, [SA15474] Safari Dialog Origin Spoofing Vulnerability (21.06.2005)
 documentSECUNIA, [SA15488] Opera Dialog Origin Spoofing Vulnerability (21.06.2005)
 documentSECUNIA, [SA15477] iCab Dialog Origin Spoofing Vulnerability (21.06.2005)
 documentSECUNIA, [SA15489] Mozilla / Firefox / Camino Dialog Origin Spoofing Vulnerability (21.06.2005)
Discuss:Read or add your comments to this news (0 comments)

Enterasys Vertical Horizon switches backdoor accounts
Published:21.06.2005
Source:FULL-DISCLOSURE
SecurityVulns ID:4916
Type:remote
Level:5/10
Description:There is undocumented backdoor account tiger/tiger123, in addition some privileged control character combination are available to unprivileged user from console or telnet session.
Affected:ENTERASYS : VH-2402S
 ENTERASYS : VH-8G
Original documentdocumentJacek Lipkowski, [Full-disclosure] Undocumented account vulnerability in Enterasys Vertical Horizon switches (21.06.2005)
Discuss:Read or add your comments to this news (0 comments)

Lyris List Manager multiple vulnerabilities
Published:21.06.2005
Source:BUGTRAQ
SecurityVulns ID:4917
Type:remote
Level:5/10
Affected:LYRIS : List Manager 8.5
Original documentdocumentH D Moore, Security Contact for Lyris (21.06.2005)
Discuss:Read or add your comments to this news (0 comments)

Multiple tcpdump / ethereal sniffers vulnerabilities
updated since 28.04.2005
Published:21.06.2005
Source:BUGTRAQ
SecurityVulns ID:4735
Type:remote
Level:6/10
Description:Endless loops during handling RSVP, ISIS, BGP, LDP protocols, buffer overflows in ANSI A, GSM MAP, AIM, DISTCC, FCELS, SIP, KINK, LMP, Telnet, TZSP, WSP, BER, SMB, H.245, Bittorrent, Fibre Channel and many others.
Affected:ETHEREAL : Ethereal 0.10
 TCPDUMP : tcpdump 3.9
Original documentdocumentSimon L. Nielsen, Another tcpdump BGP infinite loop vulnerability (CAN-2005-1267) (21.06.2005)
 documentadvisories, remote root security bug in ethereal 0.9.13 >= and <= 0.10.10 (11.05.2005)
 documentEjovi Nuwere, [Full-disclosure] [SecurityLab] Ethereal 0.10.10 SIP Dissector Overflow (10.05.2005)
 documentEjovi Nuwere, [SecurityLab] Ethereal 0.10.10 SIP Dissector Overflow (10.05.2005)
 documentSECURITEAM, [NEWS] Ethereal Protocol Dissectors Buffer Overflow Vulnerabilities (06.05.2005)
 documentVade 79, tcpdump(/ethereal)[]: (RSVP) rsvp_print() infinite loop DOS. (28.04.2005)
 documentVade 79, tcpdump[v3.8.x/v3.9.1]: ISIS, BGP, and LDP infinite loop DOS exploits. (28.04.2005)
Files:tcpdump(/ethereal)[]: (RSVP) rsvp_print() infinite loop DOS
 tcpdump[3.8.x/3.9.1]: (ISIS) isis_print() infinite loop DOS
 tcpdump[3.8.x]: (BGP) RT_ROUTING_INFO infinite loop DOS
 tcpdump[3.8.x]: (LDP) ldp_print() infinite loop DOS
 Tcpdump Remote Denial of Service Exploit (bgp_update_print)
 Build a BGP4 update message with what you want as payload
 Ethereal <= 0.10.10 dissect_ipc_state() DoS
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod
 



Rating@Mail.ru