Computer Security
[EN] securityvulns.ru
no-pyccku



Entrust libKmp buffer overflow
Published:27.08.2004
Source:X-FORCE
SecurityVulns ID:3940
Type:library
Level:7/10
Description:Buffer overflow during incoming ISAKMP request processing.
Affected:SYMANTEC : Symantec Enterprise Firewall 7.0
 SYMANTEC : Symantec Gateway Security 2.0
 ENTRUST : libKmp
 SYMANTEC : Symantec Enterprise Firewall 8.0
 SYMANTEC : VelociRaptor 1.5
 SYMANTEC : Symantec Gateway Security 1.0
Original documentdocumentX-FORCE, ISS Protection Brief: Entrust Libkmp Library Buffer Overflow (27.08.2004)
Discuss:Read or add your comments to this news (0 comments)

D-Link DI-624/NetworkEverywhere NR041 crossite scripting
updated since 03.07.2004
Published:27.08.2004
Source:BUGTRAQ
SecurityVulns ID:3814
Type:remote
Level:4/10
Description:Information from DFHCP request is shown on web administration page without filtering.
Affected:DLINK : D-Link 624
 NETWORKEVERYWHER : NR041
Original documentdocumentMathieu Lacroix, bug found (27.08.2004)
 documentCerberus Vulgaris, DLINK 624, script injection vulnerability (03.07.2004)
Discuss:Read or add your comments to this news (0 comments)

JRE/JDK/WINAMP/ICQ/MediaPlayer sound schema files download
updated since 17.07.2002
Published:27.08.2004
Source:BUGTRAQ
SecurityVulns ID:2160
Type:client
Level:6/10
Description:ICQ sound schemas are downloaded without user's intervation. It allows to upload file to known location.
Affected:MICROSOFT : Media Player 7.1
 SUN : JDK 1.4
 ORACLE : JRE 1.4
 MIRABILIS : ICQ 2002
 NULLSOFT : Winamp 2.80
 NULLSOFT : Winamp 3.0
 NULLSOFT : WinAmp 5.04
Original documentdocumentsilent, WinAmp => 5.04 XML Remote Code exec (27.08.2004)
 documenthttp-equiv_(at)_excite.com, Terrible: Windows Media Player (28.08.2002)
 documentjelmer, RETRY : newly released winamp 3 fails to address serious "execution of arbitrary" code issue when combined with MSIE6 (20.08.2002)
 documentjelmer, WINAMP also allows execution of arbitrary code (probably a lot more programs aswell) (19.07.2002)
 documentjelmer, Java webstart also allows execution of arbitrary code (19.07.2002)
 documentjelmer, ICQ and MSIE allow execution of arbitrary code (17.07.2002)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server