Computer Security
[EN] securityvulns.ru
no-pyccku



Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
Published:30.05.2008
Source:
SecurityVulns ID:9038
Type:remote
Level:5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. PHP-Nuke AutoHTML Module 2.0 - crossite scripting.
Affected:PHPNUKE : AutoHTML 2.0 module for PHP-Nuke
 XEROX : DocuShare 6
 DOTNETNUKE : Dot Net Nuke 4.8
Original documentdocumentadmin_(at)_bugreport.ir, Dot Net Nuke (DNN) <= 4.8.3 XSS Vulnerability (30.05.2008)
 documentHackers Center Security Group, XEROX DocuShare URL XSS Injection Vulnerabilities (30.05.2008)
 documentMustLive, Cross-Site Scripting vulnerability in AutoHTML for PHP-Nuke (30.05.2008)
Discuss:Read or add your comments to this news (0 comments)

Opera buffer overflow
Published:30.05.2008
Source:FULL-DISCLOSURE
SecurityVulns ID:9040
Type:client
Level:6/10
Description:Buffer overflow on TLS certificate parsing.
Affected:OPERA : Opera 9.24
CVE:CVE-2007-6521 (Unspecified vulnerability in Opera before 9.25 allows remote attackers to execute arbitrary code via crafted TLS certificates.)
Original documentdocumentAlexander Klink, [Full-disclosure] Opera - heap based buffer overflow (CVE-2007-6521) (30.05.2008)
Discuss:Read or add your comments to this news (0 comments)

Apple Mac OS X multiple security vulnerabilities
Published:30.05.2008
Source:APPLE
SecurityVulns ID:9039
Type:remote
Level:9/10
Description:AFP server directory traversal, Apache updates, AppKit memory corruption, Apple Pixlet Video multiple memory corruptions, Apple Type Services PDF printing fonts memory corruption, SSL information leak, multiple vulnerabilities in Graphics and Image engines on different filetypes and multimedia formats, Help Viewer buffer overflow, Unicode content filtering bypass, Image Capture directory traversal, DoS через IPv6, SMTP client buffer overflow, etc.
Affected:APPLE : Mac OS X 10.4
CVE:CVE-2008-1580
 CVE-2008-1578
 CVE-2008-1577
 CVE-2008-1576
 CVE-2008-1575
 CVE-2008-1574
 CVE-2008-1573
 CVE-2008-1572
 CVE-2008-1571
 CVE-2008-1036
 CVE-2008-1035
 CVE-2008-1034
 CVE-2008-1033
 CVE-2008-1032
 CVE-2008-1031
 CVE-2008-1030
 CVE-2008-1028
 CVE-2008-1027
 CVE-2008-0177
 CVE-2007-6359 (The cs_validate_page function in bsd/kern/ubc_subr.c in the xnu kernel 1228.0 and earlier in Apple Mac OS X 10.5.1 allows local users to cause a denial of service (failed assertion and system crash) via a crafted signed Mach-O binary that causes the hashes function to return NULL.)
Original documentdocumentAPPLE, About the security content of Security Update 2008-003 / Mac OS X 10.5.3 (30.05.2008)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru