Computer Security
[EN] securityvulns.ru
no-pyccku



Microsoft Content Management Server crossite scripting
updated since 09.10.2002
Published:23.01.2003
Source:BUGTRAQ
SecurityVulns ID:2337
Type:remote
Level:5/10
Description:Crossite scripting in ManualLogin.asp.
Affected:MICROSOFT : Content Management Server 2001
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS03-002: Cumulative Patch for Microsoft Content Management Server (810487) (23.01.2003)
 documentHugo Vázquez Caramés, CSS on Microsoft Content Management Server (09.10.2002)
Discuss:Read or add your comments to this news (0 comments)

CVS double free bug
Published:23.01.2003
Source:CERT
SecurityVulns ID:2550
Type:remote
Level:9/10
Description:Double free() bug on processing directory request.
Affected:CVS : cvs 1.11
Original documentdocumentStefan Esser, Advisory 01/2003: CVS remote vulnerability (23.01.2003)
 documentCERT, CERT Advisory CA-2003-02 Double-Free Bug in CVS Server (23.01.2003)
Files:Exploit for CVS double free() for Linux pserver
 Test program for CVS double-free.
Discuss:Read or add your comments to this news (0 comments)

Sun Solaris Kodak Color Management System directory traversal)
Published:23.01.2003
Source:BUGTRAQ
SecurityVulns ID:2551
Type:remote
Level:6/10
Description:Directory traversal in KCS_OPEN_PROFILE may be exploited via ToolTalk.
Affected:SUN : Solaris 2.6
 SUN : Solaris 8
 SUN : Solaris 7
 SUN : Solaris 2.5
 SUN : Solaris 9
Original documentdocumentEntercept Ricochet Team, Entercept Ricochet Advisory: Sun Solaris KCMS Library Service Daemon Arbitrary File Retrieval Vulnerability (23.01.2003)
Discuss:Read or add your comments to this news (0 comments)

WinRAR buffer overflow
Published:23.01.2003
Source:BUGTRAQ
SecurityVulns ID:2552
Type:client
Level:5/10
Description:Stack overflow on oversized file extention during extraction.
Affected:RARSOFT : WinRar 3.10
Original documentdocumentnesumin, WinRAR buffer overflow vulnerability (23.01.2003)
Discuss:Read or add your comments to this news (0 comments)

Multiple bugs in Apache for Windows
Published:23.01.2003
Source:BUGTRAQ
SecurityVulns ID:2554
Type:remote
Level:5/10
Description:Multiple bugs during URL parsing.
Affected:APACHE : Apache 2.0
Original documentdocumentMatthew Murphy, Path Parsing Errata in Apache HTTP Server (23.01.2003)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Outlook 2000 V1 Exchange server certificates flaw
Published:23.01.2003
Source:MICROSOFT
SecurityVulns ID:2556
Type:client
Level:5/10
Description:Message may be sent unecrypted.
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS03-003: Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure (812262) (23.01.2003)
Discuss:Read or add your comments to this news (0 comments)

Windows 2000 SMB signing protection bypass
updated since 14.12.2002
Published:23.01.2003
Source:MICROSOFT
SecurityVulns ID:2475
Type:m-i-t-m
Level:5/10
Description:During connectio nsetup it's possible to switch off SMB signing regardless of policy setting.
Affected:MICROSOFT : Windows 2000 Server
 MICROSOFT : Windows 2000 Advanced Server
 MICROSOFT : Windows 2000 Professional
 MICROSOFT : Windows XP
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS02-070: Flaw in SMB Signing Could Enable Group Policy to be Modified (309376) (23.01.2003)
 documentMICROSOFT, Microsoft Security Bulletin MS02-070: Flaw in SMB Signing Could Enable Group Policy to be Modified (309376) (14.12.2002)
Discuss:Read or add your comments to this news (0 comments)

Buffer overflow in Microsoft Windows NT/2000/XP Locator service
updated since 23.01.2003
Published:30.01.2003
Source:MICROSOFT
SecurityVulns ID:2553
Type:remote
Level:7/10
Description:Buffer overflow during packet parsing on Domain Controllers.
Affected:MICROSOFT : Windows NT 4.0 Server
 MICROSOFT : Windows 2000 Server
 MICROSOFT : Windows 2000 Advanced Server
Original documentdocumentNGSSoftware Insight Security Research, Microsoft RPC Locator Buffer Overflow Vulnerability (#NISR29012003) (30.01.2003)
 documentMICROSOFT, Microsoft Security Bulletin MS03-001: Unchecked Buffer in Locator Service Could Lead to Code Execution (810833) (23.01.2003)
Files:Microsoft RPC locator service remote exploit by NTeam
 Locator (RPC Service) Proof of concept, by obscou
Discuss:Read or add your comments to this news (0 comments)

Crossite browsing tracing attacks
updated since 23.01.2003
Published:26.01.2006
Source:BUGTRAQ
SecurityVulns ID:2555
Type:client
Level:5/10
Description:Multiple browsing components allow to trace user browsing and to gather different information about user.
Original documentdocumentAmit Klein (AKsecurity), Technical Note by Amit Klein: "XST Strikes Back" (26.01.2006)
 documentRain Forest Puppy, [VulnWatch] administrivia: cross-site tracing (23.01.2003)
Files:White Hat security Cross-Site Tracing papers
Discuss:Read or add your comments to this news (1 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru