Computer Security
[EN] securityvulns.ru
no-pyccku



Sybari Antigen e-mail content filtering protection bypass
Published:21.09.2005
Source:BUGTRAQ
SecurityVulns ID:5233
Type:remote
Level:5/10
Description:Messages with "Antigen forwarded attachment" in the Subject are not checked.
Affected:SYBARI : Antigen 8.0
Original documentdocumentAlan Monaghan, Antigen 8.0 for Exchange/SMTP Rule Vulnerability (21.09.2005)
Discuss:Read or add your comments to this news (0 comments)

HP Tru64 Unix ftpd DoS
Published:21.09.2005
Source:BUGTRAQ
SecurityVulns ID:5235
Type:remote
Level:5/10
Affected:HP : Tru64 5.1
 HP : Tru64 4.0
Original documentdocumentHP, [security bulletin] SSRT5971 rev.0 - HP Tru64 Unix FTP Daemon (ftpd) Remote Denial of Service (DoS) (21.09.2005)
Discuss:Read or add your comments to this news (0 comments)

Multiple ClamAV antivirus vulnerabilities
updated since 21.09.2005
Published:21.09.2005
Source:BUGTRAQ
SecurityVulns ID:5236
Type:remote
Level:7/10
Description:Buffer overflow on checking UPX-packed files, infinite loop on checking FSG-packed files.
Affected:CLAMAV : ClamAV 0.86
Original documentdocumentGENTOO, [ GLSA 200509-13 ] Clam AntiVirus: Multiple vulnerabilities (21.09.2005)
Discuss:Read or add your comments to this news (0 comments)

Safari browser memory corruption
updated since 21.09.2005
Published:21.09.2005
Source:BUGTRAQ
SecurityVulns ID:5237
Type:client
Level:5/10
Description:Invalid address reference on address like data://<h1>crash</h1>.
Affected:APPLE : Safari 2.0
Original documentdocumentJonathan Rockway, Possible memory corruption problems in Apple Safari (21.09.2005)
Discuss:Read or add your comments to this news (0 comments)

Multiple masqmail vulnerabilities
Published:21.09.2005
Source:FULL-DISCLOSURE
SecurityVulns ID:5238
Type:remote
Level:5/10
Description:Unfiltered shell characters in the From: address, symbolic links problem during log file creation.
Affected:MASQMAIL : masqmail 0.2
Original documentdocumentMANDRIVA, [Full-disclosure] MDKSA-2005:168 - Updated masqmail packages fix vulnerabilities (21.09.2005)
Discuss:Read or add your comments to this news (0 comments)

Multiple Opera Mail agent vulnerabilities
Published:21.09.2005
Source:BUGTRAQ
SecurityVulns ID:5231
Type:client
Level:6/10
Description:Attached files are opened from local cache making it's possible to execute javascript in context of "file://". By adding ',' character to file extension it's possible to bypass content filtering.
Affected:OPERA : Opera 8.02
Original documentdocumentSECUNIA, Secunia Research: Opera Mail Client Attachment Spoofing and ScriptInsertion (21.09.2005)
Discuss:Read or add your comments to this news (0 comments)

Web applications security vulnerabilities (PHP, ASP, CGI, Perl, etc)
updated since 21.09.2005
Published:21.09.2005
Source:
SecurityVulns ID:5232
Type:remote
Level:5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Affected:PHPBB : phpBB 2.0
 VBULLETIN : vBulletin 3.0
 ALSTRASOFT : EPay Pro 2.0
 HESK : Hesk 0.93
 CUREPHP : CuteNews 1.4
 WEBMIN : Usermin 1.150
 WEBMIN : Webmin 1.220
 PHPATM : PHP Advanced Transfer Manager 1.30
 TAC : Vista 3.0
 TAC : Vista 4.2
Original documentdocumentSNS, [SNS Advisory No.83] Webmin/Usermin PAM Authentication Bypass Vulnerability (26.09.2005)
 documentSECUNIA, TAC Vista "Template" Disclosure of Sensitive Information Vulnerability (21.09.2005)
 documentSECUNIA, PHP Advanced Transfer Manager Multiple Vulnerabilities (21.09.2005)
 documentSECUNIA, Webmin / Usermin PAM Authentication Bypass Vulnerability (21.09.2005)
 documentretrogod_(at)_aliceposta.it, CuteNews 1.4.0 remote code execution (21.09.2005)
 documentThomas Waldegger, [BuHa-Security] Multiple vulnerabilities in (admincp/modcp of) vBulletin 3.0.8/9 (21.09.2005)
 documenth4cky0u_(at)_gmail.com , Alstrasoft Epay Pro 2.0 and prior Directory Traversal Vulnerability (21.09.2005)
 documentSmOk3, phpBB 2.0.17 remote avatar size bug (21.09.2005)
 documentos2a_bto_(at)_gmail.com, Hesk Session ID Validation Vulnerability (21.09.2005)
Discuss:Read or add your comments to this news (0 comments)

bacula symbolic links vulnerability
Published:21.09.2005
Source:BUGTRAQ
SecurityVulns ID:5234
Type:local
Level:5/10
Description:Temporary files are created insecurely.
Affected:BACULA : bacula 1.36
Original documentdocumentEric Romang / ZATAZ.com, bacula insecure temporary file creation (21.09.2005)
Discuss:Read or add your comments to this news (0 comments)

Rational ClearQuest crossite scripting
Published:21.09.2005
Source:SECUNIA
SecurityVulns ID:5243
Type:remote
Level:5/10
Affected:IBM : Rational ClearQuest 2002
 IBM : Rational ClearQuest 2003
Original documentdocumentSECUNIA, Rational ClearQuest Cross-Site Scripting Vulnerability (21.09.2005)
Discuss:Read or add your comments to this news (0 comments)

Checkpoint VPN-1 DoS
Published:21.09.2005
Source:BUGTRAQ
SecurityVulns ID:5239
Type:remote
Level:5/10
Description:Flood with specific spoofed packets from local network causes firewall to hang.
Affected:CHECKPOINT : VPN-1 5.0
Original documentdocumentJ. Oquendo, [Full-disclosure] Checkpoint VPN DoS woes (21.09.2005)
Discuss:Read or add your comments to this news (0 comments)

BNBT / CBTT / XBNBT DoS
Published:21.09.2005
Source:SECUNIA
SecurityVulns ID:5241
Type:remote
Level:5/10
Affected:BNBT : BNBT 8.5
 CBTT : CBTT 8.0
 XBNBT : XBNBT 8,1
Original documentdocumentSECUNIA, BNBT / CBTT / XBNBT Denial of Service Vulnerability (21.09.2005)
Discuss:Read or add your comments to this news (0 comments)

Sun Solaris tl driver DoS
Published:21.09.2005
Source:SECUNIA
SecurityVulns ID:5242
Type:remote
Level:5/10
Affected:ORACLE : Solaris 10
Original documentdocumentSECUNIA, Sun Solaris "tl" Driver Denial of Service Vulnerability (21.09.2005)
Discuss:Read or add your comments to this news (0 comments)

MCCS Multi Computer Control System DoS
updated since 21.09.2005
Published:01.10.2005
Source:SECUNIA
SecurityVulns ID:5244
Type:remote
Level:5/10
Description:DoS on internal UDP-based control protocol parsing.
Affected:MCCS : Multi-Computer Control System 1.1
Original documentdocumentSECUNIA, Multi-Computer Control System (MCCS) Denial of Service Vulnerability (21.09.2005)
Files:MCCS Command DOS Exploit
Discuss:Read or add your comments to this news (0 comments)

Firefox / Opera code execution
updated since 21.09.2005
Published:23.11.2005
Source:SECUNIA
SecurityVulns ID:5240
Type:client
Level:6/10
Description:Command lines arguments can be pasted through URL if Firefox or Opera are invoked from external application in Unix-like systems.
Affected:MOZILLA : Firefox 1.0
 OPERA : Opera 8.5
Original documentdocumentSECUNIA, [Full-disclosure] Secunia Research: Opera Command Line URL Shell Command Injection (22.11.2005)
 documentSECUNIA, Firefox Command Line URL Shell Command Injection (21.09.2005)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server