 |
|
|
|
| Planet VC-200M DSL router DoS | | Published: |  | 21.08.2007 | | Source: |  | SECURITYVULNS | | SecurityVulns ID: |  | 8072 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Inaccessible administration interface on HTTP GET request with missed Host: header. |
| Affected: |  | PLANET : VC-200M | | CVE: |  | CVE-2007-4477 (The administration interface in the Planet VC-200M VDSL2 router allows remote attackers to cause a denial of service (administration interface outage) via an HTTP request without a Host header.) |
| Toribash multiple security vulnerabilities | | Published: |  | 21.08.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8074 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Format string vulnerability, multiple buffer overflows, multiple DoS conditions. |
| Mercury/32 / Mercury/NLM SMTP server buffer overflow | | Published: |  | 21.08.2007 | | Source: |  | FULL-DISCLOSURE | | SecurityVulns ID: |  | 8079 | | Type: |  | remote | | Level: |  | 7/10 | | Description: |  | Buffer overflow on oversized CRAM-MD5 authentication string. |
| Cisco 7940 SIP IPPhones DoS | | Published: |  | 21.08.2007 | | Source: |  | FULL-DISCLOSURE | | SecurityVulns ID: |  | 8080 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | A sequence of malformed SIP requests causes device to crash. |
| Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 21.08.2007 | | Source: |  | | | SecurityVulns ID: |  | 8071 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
| Affected: |  | MCLINKSCOUNTER : mcLinksCounter 1.2 | | |  | MYREFERER : My_REFERER 1.08 | | |  | BUTTERFLY : Butterfly online vistors counter 1.08 | | |  | GURURHABER : Gurur Portal 2.0 | | |  | JOOMLA : SimpleFAQ 2.11 | | CVE: |  | CVE-2007-4486 (Multiple PHP remote file inclusion vulnerabilities in index.php in Linkliste 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) styl[top], (2) url_eintrag, or (3) styl[themen] parameter.) | | |  | CVE-2007-4484 (PHP remote file inclusion vulnerability in login.php in My_REFERER 1.08 allows remote attackers to execute arbitrary PHP code via a URL in the value parameter.) | | |  | CVE-2007-4479 (Cross-site scripting (XSS) vulnerability in search.html in Search Engine Builder allows remote attackers to inject arbitrary web script or HTML via the searWords parameter.) | | |  | CVE-2006-4863 (** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Marc Cagninacci mcLinksCounter 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the langfile parameter in (1) login.php, (2) stats.php, (3) detail.php, or (4) erase.php. NOTE: CVE and a third party dispute this vulnerability, because the langfile parameter is set to english.php in each file.) |
| rFactor game / gMotor2 engine multiple security vulnerabilities | | Published: |  | 21.08.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8073 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Buffer overflow and multiple denial of service conditions. |
| Checkpoint ZoneAlarm multiple privilege escalations | | Published: |  | 21.08.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8075 | | Type: |  | local | | Level: |  | 6/10 | | Description: |  | Vsdatant.sys driver multiple IOCTLs buffer overflows. Weak permissions for executable files. |
| Affected: |  | CHECKPOINT : ZoneAlarm 7.0 | | CVE: |  | CVE-2007-4216 (vsdatant.sys 6.5.737.0 in Check Point Zone Labs ZoneAlarm before 7.0.362 allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in a METHOD_NEITHER (1) IOCTL 0x8400000F or (2) IOCTL 0x84000013 request, which can be used to overwrite arbitrary memory locations.) | | |  | CVE-2005-2932 |
| NVIDIA Linux drivers DoS | | Published: |  | 21.08.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8076 | | Type: |  | local | | Level: |  | 6/10 | | Description: |  | Invalid value sent to device may cause hardware damage. |
| Affected: |  | NVIDIA : nvidia-drivers 1.0 | | |  | NVIDIA : nvidia-drivers 100.14 | | CVE: |  | CVE-2007-3532 (NVIDIA drivers (nvidia-drivers) before 1.0.7185, 1.0.9639, and 100.14.11, as used in Gentoo Linux and possibly other distributions, creates /dev/nvidia* device files with insecure permissions, which allows local users to modify video card settings, cause a denial of service (crash or physical video card damage), and obtain sensitive information.) |
| Rsync off-by-one buffer overflow | | Published: |  | 21.08.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8077 | | Type: |  | client | | Level: |  | 5/10 | | Description: |  | Multiple off-by-on overflows. |
| Affected: |  | RSYNC : rsync 2.6 | | CVE: |  | CVE-2007-4091 (Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via directory names that are not properly handled when calling the f_name function.) |
| EMC Legato Networker buffer overflow | | Published: |  | 21.08.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8078 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Buffer overflow in SUNRPC (TCP/111) Networker Remote Exec Service. |
| Affected: |  | EMC : Legat oNetWorker 7.2 | | CVE: |  | CVE-2007-3618 (Stack-based buffer overflow in the NetWorker Remote Exec Service (nsrexecd.exe) in EMC Software NetWorker 7.x.x allows remote attackers to execute arbitrary code via a (1) poll or (2) kill request with a "long invalid subcmd.") |
ICMP flood DoS against PalmOS updated since 15.05.2003 | | Published: |  | 21.08.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 2822 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | ICMP flood causes device to fail temporary. |
Microsoft Internet Explorer saved pages crossite scripting updated since 21.08.2007 | | Published: |  | 24.11.2008 | | Source: |  | MustLive | | SecurityVulns ID: |  | 8081 | | Type: |  | client | | Level: |  | 3/10 | | Description: |  | Crossite scripting in context of local machine is possible on saving URL with address like
http://site/--><script>alert("XSS")</script> |
|
|
|
|
|
|
|
|