 |
|
|
|
| freetype integer overflow | | Published: |  | 25.05.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 7734 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | Integer overflow on TTF fonts parsing leads to heap bufffer overflow. |
| Affected: |  | FREETYPE : FreeType 2.3 | | CVE: |  | CVE-2007-2754 (Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.) |
| Cisco routers SSL DoS | | Published: |  | 25.05.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 7735 | | Type: |  | remote | | Level: |  | 6/10 | | Description: |  | Multiple vulnerabilities on SSL packets parsing. |
| Microsoft IIS unauthorized files access | | Published: |  | 25.05.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 7736 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | It's possible to bypass authentication with null.htw template. |
| MicroWorld eScan multiple content filtering products buffer overflow | | Published: |  | 25.05.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 7739 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Buffer overflow in TCP/2222 agent management interface. |
| Credant Mobile Guardian Shield information leak | | Published: |  | 25.05.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 7745 | | Type: |  | local | | Level: |  | 4/10 | | Description: |  | Sensitive information is stored in memory in crear-text form and may be stored in paging file. |
| MySQl database server DoS | | Published: |  | 25.05.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 7741 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Division by zero and NULL-pointer dereference on malcrafted IF condition. |
| Affected: |  | ORACLE : MySQL 5.0 | | CVE: |  | CVE-2007-2583 (The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference.) |
Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) updated since 25.05.2007 | | Published: |  | 25.05.2007 | | Source: |  | | | SecurityVulns ID: |  | 7737 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
| Original document |  | DEBIAN, [SECURITY] [DSA 1297-1] New gforge-plugin-scmcvs packages fix arbitrary shell command execution (25.05.2007) |
| |  | vagrant Pest, WIYS v1.0 Cross-Site Scripting Vulnerability - (05.24.2007) (NEW) (25.05.2007) |
| |  | Janek Vind, [waraxe-2007-SA#051] - Sql Injection in 2z Project 0.9.5 (25.05.2007) |
| |  | the_3dit0r_(at)_yahoo.com, ABC Excel Parser Pro v4.0 Remote File Include Exploit (25.05.2007) |
| |  | vagrant Pest, BoastMachine v3.0 platinum - Session Эd Hacking (25.05.2007) |
| |  | john_(at)_martinelli.com, RedLevel Advisory #021 - CubeCart v3.0.16 SQL Injection Vulnerability (25.05.2007) |
| |  | Cornelius Riemenschneider, SQL-Injection in IP-TRACKING Mod for phpBB2.0.x (25.05.2007) |
| |  | the_3dit0r_(at)_yahoo.com, phpPgAdmin-4.1.1 Remote File Include & Url Redirecting Vulnerabilitiy (25.05.2007) |
| |  | john_(at)_martinelli.com, RedLevel Advisory #020 - HLstats v1.35 Cross-Site Scripting Vulnerability #3 (25.05.2007) |
| |  | john_(at)_martinelli.com, RedLevel Advisory #018 - RM EasyMail Plus - Cross-Site Scripting Vulnerability #2 (25.05.2007) |
| |  | CorryL, GMTT Music Distro 1.2 XSS Exploit (25.05.2007) |
| |  | john_(at)_martinelli.com, RedLevel Advisory #017 - PsychoStats v3.0.6b Multiple Cross-Site Scripting Vulnerabilities (25.05.2007) |
| |  | Janek Vind, [waraxe-2007-SA#050] - Sql Injection in WordPress 2.1.3 (25.05.2007) |
| |  | securityresearch_(at)_netvigilance.com, Jetbox CMS version 2.1 XSS Attack Vulnerability (25.05.2007) |
| |  | john_(at)_martinelli.com, RedLevel Advisory #022 - ClonusWiki .5 Cross-Site Scripting Vulnerability (25.05.2007) |
| Cisco multiple devices DoS | | Published: |  | 25.05.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 7738 | | Type: |  | remote | | Level: |  | 6/10 | | Description: |  | Denial of service on ASN.1 parsing due to vulnerability in cryptographics library. |
| Opera BitTorrent buffer overflow | | Published: |  | 25.05.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 7742 | | Type: |  | client | | Level: |  | 6/10 | | Description: |  | Buffer overflow on BitTorrent headers parsing. |
| Array overflow in Linux kernel | | Published: |  | 25.05.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 7747 | | Type: |  | library | | Level: |  | 6/10 | | Description: |  | DecNET dn_fib_props() and TCP/IP fib_props() functions array index overflow. |
| Affected: |  | LINUX : kernel 2.6 | | CVE: |  | CVE-2007-2172 (A typo in Linux kernel 2.6 before 2.6.21-rc6 causes RTA_MAX to be used as an array size instead of RTN_MAX, which leads to an "out of bound access" by the (1) dn_fib_props (dn_fib.c, DECNet) and (2) fib_props (fib_semantics.c, IPv4) functions.) |
| KSign KSignSWAT ActiveX buffer overflow | | Published: |  | 25.05.2007 | | Source: |  | FULL-DISCLOSURE | | SecurityVulns ID: |  | 7748 | | Type: |  | client | | Level: |  | 5/10 | | Description: |  | Multiple buffer overflows in different methods. |
| Apple Mac OS X pppd privilege escalation | | Published: |  | 25.05.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 7743 | | Type: |  | local | | Level: |  | 6/10 | | Description: |  | It's possible to attach user-supplied module to privileged process with 'plugin' command. |
Avast antivirus code execution updated since 25.05.2007 | | Published: |  | 26.05.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 7744 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Code execution on CAB files parsing. Integer overflow on .SIS parsing. |
Dart Communications PowerTCP ActiveX buffer overflow updated since 25.05.2007 | | Published: |  | 26.05.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 7746 | | Type: |  | client | | Level: |  | 5/10 | | Description: |  | Buffer overflows in QuickZip, Install and Uninstall methods. |
Cisco CallManager crossite scripting and SQL injection updated since 25.05.2007 | | Published: |  | 31.08.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 7740 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Crossite scripting via /CCMAdmin/serverlist.asp. SQL injection with /CCMUser/logon.asp. |
|
|
|
|
|
|
|
|