 |
|
|
|
| FreeBSD / Mac OS X integer overflow | | Published: |  | 24.03.2009 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 9766 | | Type: |  | local | | Level: |  | 7/10 | | Description: |  | Integer overflow in kernel space on process timers. |
| Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 24.03.2009 | | Source: |  | | | SecurityVulns ID: |  | 9768 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
|
| Evolution Data Server multiple security vulnerabilities | | Published: |  | 24.03.2009 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 9770 | | Type: |  | client | | Level: |  | 7/10 | | Description: |  | Signature spoofing, DoS, process memory disclosure, integer overflows. |
| CVE: |  | CVE-2009-0587 (Multiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation in (1) addressbook/libebook/e-vcard.c in evc or (2) camel/camel-mime-utils.c in libcamel.) | | |  | CVE-2009-0582 (The ntlm_challenge function in the NTLM SASL authentication mechanism in camel/camel-sasl-ntlm.c in Camel in Evolution Data Server (aka evolution-data-server) 2.24.5 and earlier, and 2.25.92 and earlier 2.25.x versions, does not validate whether a certain length value is consistent with the amount of data in a challenge packet, which allows remote mail servers to read information from the process memory of a client, or cause a denial of service (client crash), via an NTLM authentication type 2 packet with a length value that exceeds the amount of packet data.) | | |  | CVE-2009-0547 (Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.) |
| ZyXel G-570S multiple security vulnerabilities | | Published: |  | 24.03.2009 | | Source: |  | SECUNIA | | SecurityVulns ID: |  | 9771 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Unauthorized configuration access, DoS, information disclosure. |
| PostgreSQL DoS | | Published: |  | 24.03.2009 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 9765 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | Stack overflow on error message conversion. |
| Linux-PAM signed/unsignedconversion vulnerability | | Published: |  | 24.03.2009 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 9767 | | Type: |  | local | | Level: |  | 4/10 | | Description: |  | Problems with non-ASCII symbols in configuration file. |
| Affected: |  | PAM : Linux-PAM 1.0 | | CVE: |  | CVE-2009-0887 (Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration file contains non-ASCII usernames, might allow remote attackers to cause a denial of service, and might allow remote authenticated users to obtain login access with a different user's non-ASCII username, via a login attempt.) |
| Rittal CMC-TC Processing Unit II multiple security vulnerabilities | | Published: |  | 24.03.2009 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 9769 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Crossite scripting, session hijacking. |
|
|
|
|
|
|
|
|