Computer Security
[EN] securityvulns.ru
no-pyccku



WebMod Half-Life dedicated server plugin integer overflow
Published:28.02.2005
Source:SECUNIA
SecurityVulns ID:4534
Type:remote
Level:5/10
Description:Integer overflow with Content-Length: POST request.
Affected:WEBMOD : WebMod 0.47
 WEBMOD : WebMod 0.48
CVE:CVE-2007-1260 (Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execute arbitrary code via a long string in the Content-Length HTTP header.)
Original documentdocumentSECUNIA, [SA14302] WebMod "Content-Length" Buffer Overflow Vulnerability (28.02.2005)
Discuss:Read or add your comments to this news (0 comments)

Mozilla and Firefox browsers buffer overflow
Published:28.02.2005
Source:BUGTRAQ
SecurityVulns ID:4536
Type:client
Level:5/10
Description:Heap based buffer overflow in text processing functions.
Affected:MOZILLA : Mozilla 1.7
 MOZILLA : Firefox 1.0
Original documentdocumentIDEFENSE, iDEFENSE Security Advisory 02.28.05: Mozilla Firefox and Mozilla Browser Out Of Memory Heap Corruption Design Error (28.02.2005)
Discuss:Read or add your comments to this news (0 comments)

report bug bug reporting application weak permissions
Published:28.02.2005
Source:FULL-DISCLOSURE
SecurityVulns ID:4537
Type:local
Level:5/10
Description:Per-user configuration file is world readable and may contain sensitive information, such as SMTP server password.
Affected:REPORTBUG : reportbug 2.62
Original documentdocumentUBUNTU, [Full-Disclosure] [USN-88-1] reportbug information disclosure (28.02.2005)
Discuss:Read or add your comments to this news (0 comments)

NX Server / FreeNX X Server protection bypass
Published:28.02.2005
Source:SECUNIA
SecurityVulns ID:4538
Type:local
Level:5/10
Affected:FREENX : FreeNX 0.2
 NOMACHINE : NX Server 1.4
Original documentdocumentSECUNIA, [SA14402] FreeNX X Server Authentication Bypass Security Issue (28.02.2005)
Discuss:Read or add your comments to this news (0 comments)

gaim instant messanger DoS
updated since 25.02.2005
Published:28.02.2005
Source:FULL-DISCLOSURE
SecurityVulns ID:4524
Type:remote
Level:5/10
Description:Application crashes on receiving file with with parenthesis in the name and during HTML parsing.
Affected:GAIM : gaim 1.1
Original documentdocumentRandall Perry, [Full-Disclosure] GAIM exploit (25.02.2005)
Discuss:Read or add your comments to this news (0 comments)

Insecure GFI Languard Network Security Scanner password storage
Published:28.02.2005
Source:BUGTRAQ
SecurityVulns ID:4540
Type:local
Level:4/10
Description:Password is stored in memory in cleartext.
Original documentdocumentHat-Squad Security Team, [Hat-Squad] GFI L.N.S.S 5.0 Insecure Credential Storage (28.02.2005)
Discuss:Read or add your comments to this news (0 comments)

Mitel 3300 ICP IP PBX VOIP device Web session hijack
Published:28.02.2005
Source:VULNWATCH
SecurityVulns ID:4541
Type:remote
Level:5/10
Description:Predictable session id allos to hijack Web administration session.
Affected:MITEL : Mitel 3300 ICP
Original documentdocumentCOLSAIRE, [VulnWatch] Corsaire Security Advisory - Mitel 3300 ICP web interface session hijacking issue (28.02.2005)
Discuss:Read or add your comments to this news (0 comments)

kppp KDE dialer file descriptors leak
Published:28.02.2005
Source:BUGTRAQ
SecurityVulns ID:4535
Type:local
Level:5/10
Description:File descriptors are leaked for /etc/hosts and /etc/resolv.conf.
Affected:KDE : KPPP 2.1
Original documentdocumentIDEFENSE, iDEFENSE Security Advisory 02.28.05: KPPP Privileged File Descriptor Leak Vulnerability (28.02.2005)
Discuss:Read or add your comments to this news (0 comments)

PHP, ASP, CGI web applications security vulnerabilities
updated since 28.02.2005
Published:03.03.2005
Source:
SecurityVulns ID:4539
Type:remote
Level:5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, etc.
Affected:PHPBB : phpBB 2.0
 DFORUM : D-FORUM 1.11
 CUTEPHP : CuteNews 1.3
 POSTNUKE : Postnuke 0.75
 CUBECART : CubeCart 2.0
 PANEWS : paNews 2.0
 POSTNUKE : PostNuke 0.76
 PBLANG : PBLang 4.63
 427BB : 427BB 2.1
 DEMOF : forumwa 1
 PHPCOIN : phpCOIN 1.2
 NEWSPHP : PHP News 1.2
 AURACMS : AuraCMS 1.5
 WBB : Burning Board 2.0
 WBB : Burning Board 2.1
 WBB : Burning Board 2.2
 WBB : Burning Board 2.3
 PHPNUKE : PABox 1.6
 MYFORUM : FOROS 3.2
 STADTAUS : Download Center Lite 1.5
 STADTAUS : Form Mail Script 2.3
 PHPTOURNEY : phpTourney 0.8
 WFSECTIONS : wfsections 1.07
 DRUPAL : Drupal 4.5
 DRUPAL : Drupal 4.4
 DRUPAL : Drupal 4.6
Original documentdocumentDRUPAL, [Full-disclosure] [DRUPAL-SA-2005-001] New Drupal release fixes critical security issue (03.06.2005)
 documentSECUNIA, [SA14515] Drupal Unspecified Cross-Site Scripting Vulnerability (07.03.2005)
 documentkreon, wfsections 1.07 advisory (07.03.2005)
 documentkreon, phpTourney 0.8.0 SQL-Injection (05.03.2005)
 documentWesley aka PPC, LOOKNMEET HTML INJECT EXPLOIT (05.03.2005)
 documentWesley aka PPC, phpBB 2.0.12 Session Handling Administrator Authentication Bypass -SIMPLIFIED- (05.03.2005)
 documentHaCkZaTaN, -==phpBB 2.0.13 Full path disclosure==- (05.03.2005)
 documentFilip Groszynski, PHP Form Mail Script (2.3) - Arbitrary File Inclusion (VXSfx) (05.03.2005)
 documentFilip Groszynski, Download Center Lite (DCL) - Arbitrary File Inclusion (VXSfx) (05.03.2005)
 documentBlack Angel, My-forum.org cookies vulnerability - data bug (04.03.2005)
 documentFabian Becker, TYPO3 SQL Injection vunerabilitie (04.03.2005)
 documentRift, [XSS] paBox 1.6 (04.03.2005)
 documentSECUNIA, [SA14450] Woltlab Burning Board SQL Injection Vulnerability (03.03.2005)
 documentSECUNIA, [SA14464] D-Forum "page" Parameter Cross-Site Scripting Vulnerability (03.03.2005)
 documentahmad muammar, Vulnerabilities in Aura CMS (03.03.2005)
 documentFilip Groszynski, PHP News <= 1.2.4 - Remote File Inclusion (VXSfx) (02.03.2005)
 documentSECUNIA, [SA14439] phpCOIN Multiple Vulnerabilities (02.03.2005)
 documentSECUNIA, [SA14433] PostNuke Multiple Vulnerabilities (02.03.2005)
 documentRaven, Forumwa search.php xss vulnerability (02.03.2005)
 documentRaven, 427BB profile.php XSS vulnerability. (01.03.2005)
 documentRaven, Software PBLang 4.63 sendpm.php reply file read vulnerability (01.03.2005)
 documentRaven, Software PBLang 4.63 delpm.php authentication vulnerability (01.03.2005)
 documentKernelpanik Labs - Security Lists, [Full-Disclosure] Kernelpanik Labs Digest 2005-2 (01.03.2005)
 documentJoCaNoR SeCuRiTy TeaM, [ Postnuke all versions + pnphpbb <=1.2 sql injection - jocanor ] (01.03.2005)
 documentSECUNIA, [SA14416] CubeCart Cross-Site Scripting Vulnerabilities (01.03.2005)
 documentMaksymilian Arciemowicz, [SECURITYREASON.COM] PostNuke Critical SQL Injection 0.760-RC2=>x cXIb8O3.1 (01.03.2005)
 documentMaksymilian Arciemowicz, [SECURITYREASON.COM] PostNuke Critical XSS 0.760-RC2=>x cXIb8O3.2 (01.03.2005)
 documentMaksymilian Arciemowicz, [SECURITYREASON.COM] PostNuke SQL Injection 0.760-RC2=>x cXIb8O3.3 (01.03.2005)
 documentMaksymilian Arciemowicz, [SECURITYREASON.COM] PostNuke SQL Injection 0.760-RC2=>x cXIb8O3.3 (01.03.2005)
 documentSECUNIA, [SA14413] phpBB "autologinid" Security Bypass (28.02.2005)
Files:phpBB <= 2.0.12 UID Exploit
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server