Computer Security
[EN] securityvulns.ru
no-pyccku



catdoc symbolic links
Published:30.10.2004
Source:BUGTRAQ
SecurityVulns ID:4137
Type:remote
Level:5/10
Description:xlsview creates temporary files unsecurely.
Affected:CATDOC : catdoc 0.91
Original documentdocumentDEBIAN, [SECURITY] [DSA 575-1] New catdoc packages fix temporary file vulnerability (30.10.2004)
Discuss:Read or add your comments to this news (0 comments)

PHP+cURL local file access protection bypass
Published:30.10.2004
Source:BUGTRAQ
SecurityVulns ID:4138
Type:local
Level:5/10
Description:It's possible to address any local file by file:// URL.
Affected:PHP : PHP 4.3
Original documentdocumentFraMe, PHP4 cURL functions bypass open_basedir (30.10.2004)
Discuss:Read or add your comments to this news (0 comments)

PostgreSQL symbolic links
Published:30.10.2004
Source:BUGTRAQ
SecurityVulns ID:4139
Type:local
Level:5/10
Description:make_oidjoins_check script temporary files problem.
Affected:POSTGRES : PostgreSQL 7.4
Original documentdocumentOPENPKG, [OpenPKG-SA-2004.046] OpenPKG Security Advisory (postgresql) (30.10.2004)
Discuss:Read or add your comments to this news (0 comments)

MacOS X Privilege escalation
Published:30.10.2004
Source:SECUNIA
SecurityVulns ID:4140
Type:local
Level:6/10
Description:It's possible to launch application before logon.
Affected:APPLE : Remote Desktop 2.0
Original documentdocumentSECUNIA, [SA11711] Apple Remote Desktop Privilege Escalation Vulnerability (30.10.2004)
Discuss:Read or add your comments to this news (0 comments)

shadow privilege escalation
Published:30.10.2004
Source:BUGTRAQ
SecurityVulns ID:4141
Type:local
Level:5/10
Description:It's possible to change account properties.
Affected:Shadow : shadow 4.0
Original documentdocumentSECUNIA, [SA13028] Shadow "passwd_check()" Security Bypass Vulnerability (30.10.2004)
Discuss:Read or add your comments to this news (0 comments)

ImageMagic buffer overflow
Published:30.10.2004
Source:SECUNIA
SecurityVulns ID:4142
Type:client
Level:5/10
Description:Buffer overflow on EXIF format parsing.
Affected:IMAGEMAGIC : ImageMagick 6.1
Original documentdocumentSECUNIA, [SA12995] ImageMagick EXIF Parser Buffer Overflow Vulnerability (30.10.2004)
Discuss:Read or add your comments to this news (0 comments)

PuTTY SSH2 buffer overflow
updated since 28.10.2004
Published:30.10.2004
Source:BUGTRAQ
SecurityVulns ID:4132
Type:remote
Level:5/10
Description:Buffer overflow on SSH2_MSG_DEBUG packet processing.
Affected:PUTTY : PuTTY 0.55
 TORTOISECVS : TortoiseCVS 1.8
Original documentdocumentSECUNIA, [SA13012] TortoiseCVS "SSH2_MSG_DEBUG" Packet Handling Buffer Overflow (30.10.2004)
 documentIDEFENSE, iDEFENSE Security Advisory 10.27.04 - PuTTY SSH2_MSG_DEBUG Buffer Overflow Vulnerability (28.10.2004)
Discuss:Read or add your comments to this news (0 comments)

CGI bugs
updated since 25.10.2004
Published:30.10.2004
Source:
SecurityVulns ID:4115
Type:remote
Level:5/10
Affected:PHORUM : Phorum 5.0
 DISTINCWEBCREATI : dwc_articles 1.6
 IPPLAN : IPPlan 3.0
 MONIWIKI : MoniWiki 1.0
 OPENWFE : Open WorkFlow Engine 1.4
 DADAIMC : dadaIMC 0.98
 SKFORUM : SKForum 1.4
 CUTENEWS : CuteNews.RU 026
 PHPCODEGENIE : phpCodeGenie 3.0
 PHPLIST : phplist 2.8
 MEGAUPLOAD : Mega Upload 1.4
 HORDE : Horde 2.2
Original documentdocumentSECUNIA, [SA12992] Horde "Help Window" Cross-Site Scripting Vulnerability (30.10.2004)
 documentSECUNIA, [SA12993] Mega Upload Unspecified "File List" Vulnerability (30.10.2004)
 documentSECUNIA, [SA12994] PHPlist Unspecified Vulnerability (30.10.2004)
 documentSECUNIA, [SA12853] phpCodeGenie "Simple Application Generation" Code Execution Vulnerability (30.10.2004)
 documenttjomka1_(at)_navigator.lv, CuteNews.RU v026 - bugs (27.10.2004)
 documentSECUNIA, [SA12980] Phorum Unspecified Cross-Site Scripting and SQL Injection (26.10.2004)
 documentSECUNIA, [SA12965] SKForum Unspecified "my wiki" and "wiki" Vulnerability (26.10.2004)
 documentSECUNIA, [SA12955] dadaIMC "Post An Article" Script Insertion Vulnerability (26.10.2004)
 documentJose Antonio, Two Vulnerabilities in OpenWFE Web Client (26.10.2004)
 documentSSR Team, [Full-Disclosure] STG Security Advisory: [SSA-20041022-08] MoniWiki XSS vulnerability (25.10.2004)
 documentSECUNIA, [SA12960] IPplan Unspecified SQL Injection Vulnerabilities (25.10.2004)
 documentRene, dwc_articles possible sql injection (25.10.2004)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server