 |
|
|
|
| Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 31.08.2007 | | Source: |  | | | SecurityVulns ID: |  | 8106 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
| Ubuntu linux tcpwrappers protection bypass | | Published: |  | 31.08.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8109 | | Type: |  | library | | Level: |  | 5/10 | | Description: |  | It's possible to connect to services configured to block connections. |
| Wireshark sniffer DoS | | Published: |  | 31.08.2007 | | Source: |  | SECURITEAM | | SecurityVulns ID: |  | 8114 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Infinite loop on DNP3 protocol parsing. |
Cisco CallManager crossite scripting and SQL injection updated since 25.05.2007 | | Published: |  | 31.08.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 7740 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Crossite scripting via /CCMAdmin/serverlist.asp. SQL injection with /CCMUser/logon.asp. |
VMWare multiple security vulnerabilities updated since 27.08.2007 | | Published: |  | 31.08.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8097 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | Multiple vulnerabilities allow unprivileged user of host system to control guest systems. |
| Doomsday game multiple security vulnerabilities | | Published: |  | 31.08.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8108 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Multiple buffer overflows and format string vulnerabilities. |
| postfix-policyd buffer overflow | | Published: |  | 31.08.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8107 | | Type: |  | remote | | Level: |  | 7/10 | | Description: |  | Buffer overflow on SMTP commands parsing. |
| Affected: |  | POSTFIX : postfix policyd 1.80 | | CVE: |  | CVE-2007-3791 (Buffer overflow in the w_read function in sockets.c in Cami Sardinha and Nigel Kukard policyd before 1.81 for Postfix allows remote attackers to cause a denial of service and possibly execute arbitrary code via long SMTP commands. NOTE: some of these details are obtained from third party information.) |
| Yahoo Messenger ActiveX buffer overflow | | Published: |  | 31.08.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8110 | | Type: |  | client | | Level: |  | 7/10 | | Description: |  | Buffer overflows in fvCom() and info() methods of YVerInfo.GetInfo.1. |
| Affected: |  | YAHOO : Yahoo! Messenger 8.1 | | CVE: |  | CVE-2007-4515 (Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 allows remote attackers to execute arbitrary code via unspecified vectors involving arguments to the (1) fvCom and (2) info methods. NOTE: some of these details are obtained from third party information.) |
| Cisco CSS ssh DoS | | Published: |  | 31.08.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8111 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | More than 5 concurent ssh conenctions cause ssh service to crash. |
| Norman multiple antiviral products privilege escalation | | Published: |  | 31.08.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8112 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | Nvcoaft51 driver creates NvcOa device with out ACL with multiple vulnerabilities on IOCTLs processing. |
| E-scan antiviral products weak permissions | | Published: |  | 31.08.2007 | | Source: |  | FULL-DISCLOSURE | | SecurityVulns ID: |  | 8113 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | Weak installation folder permissions. |
| Linux aacraid driver IOCTL privilege escalation | | Published: |  | 31.08.2007 | | Source: |  | CVE | | SecurityVulns ID: |  | 8115 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | Insufficient user's permissions check leads to denial of service conditions or privilege escalation. |
| Affected: |  | LINUX : kernel 2.6 | | CVE: |  | CVE-2007-4308 (The (1) aac_cfg_open and (2) aac_compat_ioctl functions in the SCSI layer ioctl path in aacraid in the Linux kernel before 2.6.23-rc2 do not check permissions for ioctls, which might allow local users to cause a denial of service or gain privileges.) |
|
|
|
|
|
|
|
|