 |
|
|
|
Multiple MacOS X vulnerabilities updated since 18.08.2005 | | Published: |  | 22.08.2005 | | Source: |  | CERT | | SecurityVulns ID: |  | 5114 | | Type: |  | remote | | Level: |  | 7/10 | | Description: |  | Apple Mac OS X Directory Services contains a buffer overflow, Apple Mac OS X Server servermgrd authentication vulnerable to buffer overflow, Apple Mac OS X AppKit vulnerable to buffer overflow via the handling of maliciously crafted rich text files, Apple Mac OS X AppKit vulnerable to buffer overflow via maliciously crafted Microsoft Word files, Apple Mac OS X Safari vulnerable to arbitrary command execution via URLs in PDF files, Apple Safari fails to perform security checks on links in rich text content. |
| LM Sensors symbolic links problem | | Published: |  | 22.08.2005 | | Source: |  | SECUNIA | | SecurityVulns ID: |  | 5133 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | Unsafe temporary files creation. |
| elm mail agent buffer overflow | | Published: |  | 22.08.2005 | | Source: |  | FULL-DISCLOSURE | | SecurityVulns ID: |  | 5128 | | Type: |  | client | | Level: |  | 6/10 | | Description: |  | Buffer overflow on oversized Expires: e-mail header. |
| Linux kernel multiple vulnerabilities | | Published: |  | 22.08.2005 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 5127 | | Type: |  | remote | | Level: |  | 6/10 | | Description: |  | Multiple DoS conditions, code execution while mounting compressed ISO file system, IPSec protection bypass by local user. |
Lotus Domino weak files permissions updated since 14.08.2005 | | Published: |  | 22.08.2005 | | Source: |  | SECURITEAM | | SecurityVulns ID: |  | 5104 | | Type: |  | local | | Level: |  | 6/10 | | Description: |  | Database names.nsf with password hashes is world readable. |
| Affected: |  | IBM : Lotus Domino 6.5 | | CVE: |  | CVE-2007-0977 (IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.nsf in a manner accessible through Readviewentries and OpenDocument requests to the defaultview view, a different vector than CVE-2005-2428.) | | |  | CVE-2005-2696 (IBM Lotus Notes does not properly restrict access to password hashes in the Notes Address Book (NAB), which allows remote attackers to obtain sensitive information via the (1) password digest field in the Administration tab of a Lotus Notes client, (2) "PasswordDigest" and "HTTPPassword" fields in the document properties in the NAB, or (3) a direct query to the Domino LDAP server, a different vulnerability than CVE-2005-2428.) | | |  | CVE-2005-2428 (Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696.) |
| ProcessExplorer system monitoring tool buffer overflow | | Published: |  | 22.08.2005 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 5131 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | Buffer overflow during parsing of CompanyName and VersionInfo PE file headers of running process. |
Multiple Computer Associates software vulnerabilities updated since 22.08.2005 | | Published: |  | 23.08.2005 | | Source: |  | SECUNIA | | SecurityVulns ID: |  | 5130 | | Type: |  | remote | | Level: |  | 7/10 | | Description: |  | CA Message Queuing service buffer overflow, DoS and privilege escalation. |
Web applications security vulnerabilities (PHP, ASP, CGI, Perl, etc) updated since 22.08.2005 | | Published: |  | 28.08.2005 | | Source: |  | | | SecurityVulns ID: |  | 5129 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
| Original document |  | retrogod_(at)_aliceposta.it, Looking Glass v20040427 arbitrary commands execution / cross site scripting (28.08.2005) |
| |  | Cedric Cochin, Multiple PHP Images Galleries EXIF Metadata XSS Vulnerabilities (28.08.2005) |
| |  | Scott Dewey, Simple PHP Blog File Upload and User Credentials Exposure Vulnerabilities (28.08.2005) |
| |  | nf2, XSS security hole in phpwebnotes. (28.08.2005) |
| |  | fournaux_(at)_khmerdev.com, AWstats Path Disclosure Vulnerability (28.08.2005) |
| |  | SECUNIA, [SA16597] PhotoPost PHP Pro EXIF Data Script Insertion Vulnerability (26.08.2005) |
| |  | SECUNIA, [SA16598] Simple PHP Blog Image File Upload Vulnerability (26.08.2005) |
| |  | SECUNIA, [SA16594] Gallery EXIF Data Script Insertion Vulnerability (26.08.2005) |
| |  | SECUNIA, [SA16596] YaPig EXIF Data Script Insertion Vulnerability (26.08.2005) |
| |  | SECUNIA, [SA16595] phpGraphy EXIF Data Script Insertion Vulnerability (26.08.2005) |
| |  | SECUNIA, [SA16516] vBulletin BBCode IMG Tag Cross-Site Request Forgery (26.08.2005) |
| |  | astovidatu_(at)_security-project.org, PaFileDB 3.1 - SQL-Injection (26.08.2005) |
| |  | SECUNIA, [Full-disclosure] Secunia Research: SqWebMail Attached File Script Insertion Vulnerability (24.08.2005) |
| |  | SECUNIA, [SA16522] SaveWebPortal Multiple Vulnerabilities (24.08.2005) |
| |  | SECUNIA, [SA16523] Netquery "host" Parameter Arbitrary Command Execution (24.08.2005) |
| |  | SECUNIA, [SA16511] AreaEdit SpellChecker Plugin Code Execution Vulnerability (23.08.2005) |
| |  | SECUNIA, [SA16514] RunCMS SQL Injection and Arbitrary Variable Overwrite Vulnerability (23.08.2005) |
| |  | Maksymilian Arciemowicz, [SECURITYREASON.COM] Multiple vulnerabilities in PostNuke 0.760-RC4b=>x cXIb8O3.15 (23.08.2005) |
| |  | phuket, SQL Injection and PHP Code Injection Vulnerabilities in PHPKit 1.6.1 (23.08.2005) |
| |  | bl2k_(at)_shabgard.org, Nephp Publisher Enterprise 3.04 Cross Site Scripting (22.08.2005) |
| |  | SECUNIA, [SA16506] Mantis Cross-Site Scripting and SQL Injection Vulnerabilities (22.08.2005) |
| |  | SECUNIA, [SA16499] Coppermine Photo Gallery EXIF Data Script Insertion (22.08.2005) |
| |  | h4cky0u, [Full-disclosure] BBCode [IMG] [/IMG ] Tag Vulnerability (22.08.2005) |
PCRE regular expressions library integer overflow updated since 22.08.2005 | | Published: |  | 05.09.2005 | | Source: |  | SECUNIA | | SecurityVulns ID: |  | 5132 | | Type: |  | library | | Level: |  | 6/10 | | Description: |  | pcre_compile.c {} regexp parameter integer overflow. |
|
|
|
|
|
|
|
|