 |
|
|
|
| WireShark DoS | | Published: |  | 24.11.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 9451 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | CPU resource exhaustion on oversized SMTP request. |
| Affected: |  | WIRESHARK : Wireshark 1.0 | | CVE: |  | CVE-2008-5285 (Wireshark 1.0.4 and earlier allows remote attackers to cause a denial of service via a long SMTP request, which triggers an infinite loop.) |
| Linux kernel multiple security vulnerabilities | | Published: |  | 24.11.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 9453 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | Multiple DoS conditions |
| Affected: |  | LINUX : kernel 2.6 | | CVE: |  | CVE-2008-5029 (The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors.) | | |  | CVE-2008-4934 (The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (system crash) via a crafted hfsplus filesystem image.) | | |  | CVE-2008-4933 (Buffer overflow in the hfsplus_find_cat function in fs/hfsplus/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfsplus filesystem image with an invalid catalog namelength field, related to the hfsplus_cat_build_key_uni function.) |
| Apple iPhone Configuration Web Utility directory traversal | | Published: |  | 24.11.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 9454 | | Type: |  | remote | | Level: |  | 6/10 | | Description: |  | ACcess outside web root is possible. |
| OpenSSH cryptographic weakness | | Published: |  | 24.11.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 9455 | | Type: |  | m-i-t-m | | Level: |  | 3/10 | | Description: |  | With low probability it's possible to recover few bits of plaintext. |
| Microsoft Windows LDAP users enumeration | | Published: |  | 24.11.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 9459 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Different serverreply on invalid username and invalid password. |
| Adobe Flash multiple security vulnerabilities | | Published: |  | 24.11.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 9452 | | Type: |  | client | | Level: |  | 8/10 | | Description: |  | Code execution, information leakage, DoS. |
| EMC Control Center SAN Manager multiple security vulnerabilities | | Published: |  | 24.11.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 9457 | | Type: |  | remote | | Level: |  | 7/10 | | Description: |  | Buffer overflow, unauthroized files access via TCP/10444. |
| ffdshow codec buffer overflow | | Published: |  | 24.11.2008 | | Source: |  | FULL-DISCLOSURE | | SecurityVulns ID: |  | 9458 | | Type: |  | client | | Level: |  | 6/10 | | Description: |  | Buffer overflow on oversized URI |
Microsoft Internet Explorer saved pages crossite scripting updated since 21.08.2007 | | Published: |  | 24.11.2008 | | Source: |  | MustLive | | SecurityVulns ID: |  | 8081 | | Type: |  | client | | Level: |  | 3/10 | | Description: |  | Crossite scripting in context of local machine is possible on saving URL with address like
http://site/--><script>alert("XSS")</script> |
| KVIrc shell characters vulnerabilities | | Published: |  | 24.11.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 9456 | | Type: |  | client | | Level: |  | 6/10 | | Description: |  | Shell characters vulnerability on irc:/// URI parsing. |
Linux kernel multiple security vulnerabilities updated since 05.11.2008 | | Published: |  | 24.11.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 9409 | | Type: |  | remote | | Level: |  | 6/10 | | Description: |  | Buffer overflow on oversized ESSID in ndiswrapper. DoS with corrupter ext2 / ext3 filesystem. |
| Affected: |  | LINUX : kernel 2.6 | | CVE: |  | CVE-2008-4395 (Multiple buffer overflows in the ndiswrapper module 1.53 for the Linux kernel 2.6 allow remote attackers to execute arbitrary code by sending packets over a local wireless network that specify long ESSIDs.) | | |  | CVE-2008-3528 (The error-reporting functionality in (1) fs/ext2/dir.c, (2) fs/ext3/dir.c, and possibly (3) fs/ext4/dir.c in the Linux kernel 2.6.26.5 does not limit the number of printk console messages that report directory corruption, which allows physically proximate attackers to cause a denial of service (temporary system hang) by mounting a filesystem that has corrupted dir->i_size and dir->i_blocks values and performing (a) read or (b) write operations. NOTE: there are limited scenarios in which this crosses privilege boundaries.) |
|
|
|
|
|
|
|
|