Computer Security
[EN] securityvulns.ru
no-pyccku



IceCast array overflow
Published:30.09.2004
Source:BUGTRAQ
SecurityVulns ID:4049
Type:remote
Level:7/10
Description:Large number of headers in request leads to array overflow.
Affected:ICECAST : Icecast 2.0
Original documentdocumentLuigi Auriemma, Code execution in Icecast 2.0.1 (30.09.2004)
Files:IceCast <= 2.0.1 Exploit v1.1 by cyrex
Discuss:Read or add your comments to this news (0 comments)

ParaChat directory traversal
Published:30.09.2004
Source:BUGTRAQ
SecurityVulns ID:4050
Type:remote
Level:5/10
Description:Directory traversal with ..%5C/.
Affected:PARACHAT : ParaChat 5.5
Original documentdocumentDonato Ferrante, directory traversal in ParaChat Server 5.5 (30.09.2004)
Discuss:Read or add your comments to this news (0 comments)

HP StorageWorks protection bypass
Published:30.09.2004
Source:BUGTRAQ
SecurityVulns ID:4051
Type:remote
Level:5/10
Description:Protection bypass in Command View XP.
Affected:HP : StorageWorks XP48
 HP : StorageWorks XP128
 HP : StorageWorks XP256
 HP : StorageWorks XP512
 HP : StorageWorks XP1024
Original documentdocumentHP, [security bulletin] SSRT4794 rev.0 HPStorageWorks Command View XP access restriction bypass (30.09.2004)
Discuss:Read or add your comments to this news (0 comments)

MS SQL Server 7 buffer overflow
Published:30.09.2004
Source:BUGTRAQ
SecurityVulns ID:4052
Type:remote
Level:5/10
Affected:MICROSOFT : SQL Server 7.0
Original documentdocumentsecurma massine, MSSQL 7.0 DoS (30.09.2004)
Discuss:Read or add your comments to this news (0 comments)

freenet6 weak permissions
Published:30.09.2004
Source:FULL-DISCLOSURE
SecurityVulns ID:4053
Type:remote
Level:5/10
Description:tspc.conf file with login and password is world readable.
Affected:FREENET6 : freenet6 0.9
Original documentdocumentDEBIAN, [Full-Disclosure] [SECURITY] [DSA 555-1] New frenet6 packages fix potential information leak (30.09.2004)
Discuss:Read or add your comments to this news (0 comments)

Multiple IRIX bugs
Published:30.09.2004
Source:SECUNIA
SecurityVulns ID:4054
Type:remote
Level:7/10
Description:TCP connections spoofing, DoS.
Affected:SGI : IRIX 6.5
Original documentdocumentSECUNIA, [SA12682] SGI IRIX update for kernel (30.09.2004)
Discuss:Read or add your comments to this news (0 comments)

AIX libXm.a multiple bugs
Published:30.09.2004
Source:SECUNIA
SecurityVulns ID:4056
Type:library
Level:7/10
Affected:IBM : AIX 5.1
 IBM : AIX 5.2
 IBM : AIX 5.3
Original documentdocumentSECUNIA, [SA12677] AIX libXm.a Multiple Vulnerabilities (30.09.2004)
Discuss:Read or add your comments to this news (0 comments)

Computer Associates Unicenter default password
Published:30.09.2004
Source:SECUNIA
SecurityVulns ID:4058
Type:local
Level:5/10
Description:Database access password is stored in installation batch files as cleartext.
Affected:CA : Unicenter ServicePlus Service Desk 6.0
 CA : CA Common Services 3.1
Original documentdocumentSECUNIA, [SA12639] Computer Associates Unicenter Common Services Password Disclosure (30.09.2004)
Discuss:Read or add your comments to this news (0 comments)

PeopleSoft HRMS session spoofing
Published:30.09.2004
Source:SECUNIA
SecurityVulns ID:4059
Type:remote
Level:5/10
Affected:PEOPLESOFT : Human Resources Management System 7.0
Original documentdocumentSECUNIA, [SA12674] PeopleSoft HRMS Page Manipulation and Identity Spoofing (30.09.2004)
Discuss:Read or add your comments to this news (0 comments)

Multiple PHP request parsing bugs
updated since 16.09.2004
Published:30.09.2004
Source:VULNWATCH
SecurityVulns ID:4007
Type:remote
Level:7/10
Description:Invalid request parameters parsing leads to leakage of memory content and rewriting of internal variables.
Affected:PHP : PHP 4.1
 PHP : PHP 5.0
Original documentdocumentStefano Di Paola, PHP File Upload Vulnerability POC (30.09.2004)
 documentStefano Di Paola, [VulnWatch] Php Vulnerability N. 2 (16.09.2004)
 documentStefano Di Paola, [VulnWatch] PHP Vulnerability N. 1 (16.09.2004)
Discuss:Read or add your comments to this news (0 comments)

Multiple Real products multiple bugs
updated since 30.09.2004
Published:20.01.2005
Source:SECUNIA
SecurityVulns ID:4057
Type:client
Level:6/10
Description:RealPlayer ActiveX 'ShowPreferences' Buffer Overflow Vulnerability. Malcrafted RMP files arbitrary files deletion.
Affected:REAL : RealPlayer 8
 REAL : RealPlayer 10
 REAL : RealOne Player 2
 REAL : RealOne Player 1
 HELIXCOMMUNITY : Helix Player 1.0
 REAL : RealPlayer 10.5
 REAL : Helix Server 9.0
Original documentdocumentNGSSoftware Insight Security Research, RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g) (20.01.2005)
 documentNGSSoftware Insight Security Research, RealPlayer Arbitrary File Deletion Vulnerability (#NISR19012005f) (20.01.2005)
 documentNGSSoftware Insight Security Research, RealPlayer 'ShowPreferences' Buffer Overflow Vulnerability (#NISR19012005e) (20.01.2005)
 documentIDEFENSE, [Full-Disclosure] iDEFENSE Security Advisory 10.07.04: RealNetworks Helix Server Content-Length Denial of Service Vulnerability (08.10.2004)
 documentNGSSoftware Insight Security Research, Patch available for multiple high risk vulnerabilities in RealPlayer (07.10.2004)
 documentEEYE, EEYE: RealPlayer pnen3260.dll Heap Overflow (02.10.2004)
 documentSECUNIA, [SA12672] RealOne Player / RealPlayer / Helix Player Multiple Vulnerabilities (30.09.2004)
Discuss:Read or add your comments to this news (0 comments)

dBpowerAMP music converter / audio player buffer overflow
updated since 30.09.2004
Published:28.12.2005
Source:SECUNIA
SecurityVulns ID:4055
Type:client
Level:5/10
Description:Buffer overflow during different playlists file formats parsing (pls, m3u, mcc).
Affected:DBPOWERAMP : dBpowerAMP Music Converter 10.0
 DBPOWERAMP : dBpowerAMP Audio Player 2.0
 DBPOWERAMP : dBpowerAMP Music Converter 11.5
Original documentdocumentSecuBox fRoGGz, dBpowerAMP Music Converter v11.5 and priors Local Buffer Overflow Issue (28.12.2005)
 documentSECUNIA, [SA12684] dBpowerAMP Audio Player / Music Converter Playlist Handling Buffer Overflow (30.09.2004)
Files:Illustrate dBpowerAMP dMCShell Module Buffer Overflow
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru