Computer Security
[EN] securityvulns.ru no-pyccku


Apple Safari for Windows buffer overflow and content spoofing
updated since 22.03.2008
Published:23.03.2008
Source:
SecurityVulns ID:8819
Type:client
Threat Level:
5/10
Description:Buffer overflow on oversized download filename.
Original documentdocumentjplopezy_(at)_gmail.com, Safari browser 3.1 (525.13) spoofing (23.03.2008)
 documentjplopezy_(at)_gmail.com, Safari 3.1 for windows download bug (22.03.2008)

Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
Published:23.03.2008
Source:
SecurityVulns ID:8824
Type:remote
Threat Level:
5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Affected:PHPADDRESSBOOK : phpAddressBook 2.11
Original documentdocumentGuns_(at)_0x90.com.ar, phpAddressBook v2.11 Multiple Local File Inclusion Vulnerabilities (23.03.2008)

Mitsubishi GB-50A unauthorized access
Published:23.03.2008
Source:
SecurityVulns ID:8823
Type:remote
Threat Level:
5/10
Description:Access authentication is not implemented.
Affected:MITSUBISHI : GB-50A
Original documentdocumentChris Withers, hacking the mitsubishi GB-50A (23.03.2008)
Files:Exploits mitsubishi GB-50A

unzip / bzip2 DoS
updated since 23.03.2008
Published:30.03.2009
Source:
SecurityVulns ID:8822
Type:remote
Threat Level:
5/10
Affected:BZIP : bzip2 1.0
 ANALOG : analog 6.0
CVE:CVE-2008-1372 (bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite for Archive Formats.)
 CVE-2008-0888 (The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.)
Original documentdocumentGENTOO, [ GLSA 200903-40 ] Analog: Denial of Service (30.03.2009)
 documentRPATH, rPSA-2008-0118-1 bzip2 (23.03.2008)
 documentRPATH, rPSA-2008-0116-1 unzip (23.03.2008)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod