[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing For The Week of January 3 2008[/i][/b]
[b]Windows:--[/b]
[SA28307] Georgia SoftWorks SSH2 Server Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-03
Luigi Auriemma has reported some vulnerabilities in Georgia SoftWorks SSH2 Server, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28307/\"]http://secunia.com/advisories/28307/[/url]
--
[SA28276] RealPlayer Unspecified Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-03
Evgeny Legerov has reported a vulnerability in RealPlayer, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28276/\"]http://secunia.com/advisories/28276/[/url]
[b]UNIX/Linux:--[/b]
[SA28290] Gentoo update for opera
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, System access
Released: 2008-01-02
Gentoo has issued an update for opera. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, and compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28290/\"]http://secunia.com/advisories/28290/[/url]
--
[SA28286] Gentoo update for openoffice, openoffice-bin, and hsqldb
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-02
Gentoo has issued an update for openoffice, openoffice-bin, and hsqldb. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28286/\"]http://secunia.com/advisories/28286/[/url]
--
[SA28278] Gentoo update for clamav
Critical: Highly critical
Where: From remote
Impact: Unknown, DoS, System access
Released: 2008-01-02
Gentoo has issued an update for clamav. This fixes some vulnerabilities, where one vulnerability has an unknown impact and
others can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28278/\"]http://secunia.com/advisories/28278/[/url]
--
[SA28277] Gentoo update for mozilla-firefox/-bin and seamonkey/-bin
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2008-01-02
Gentoo has issued an update for mozilla-firefox, mozilla-firefox-bin, seamonkey, and seamonkey-bin. This fixes a security issue and some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and request forgery attacks and potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28277/\"]http://secunia.com/advisories/28277/[/url]
--
[SA28260] Debian update for peercast
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-02
Debian has issued an update for peercast. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28260/\"]http://secunia.com/advisories/28260/[/url]
--
[SA28325] Mandriva update for wireshark
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-03
Mandriva has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28325/\"]http://secunia.com/advisories/28325/[/url]
--
[SA28312] Asterisk "BYE/Also" Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-03
A vulnerability has been reported in Asterisk, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28312/\"]http://secunia.com/advisories/28312/[/url]
--
[SA28309] AGENCY4NET WEBFTP "file" Directory Traversal Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-01-03
GoLd_M has discovered a vulnerability in AGENCY4NET WEBFTP, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28309/\"]http://secunia.com/advisories/28309/[/url]
--
[SA28289] Gentoo update for emul-linux-x86-gtklibs
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-02
Gentoo has issued an update for emul-linux-x86-gtklibs. This fixes a vulnerability, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28289/\"]http://secunia.com/advisories/28289/[/url]
--
[SA28288] Gentoo update for wireshark
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-02
Gentoo has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28288/\"]http://secunia.com/advisories/28288/[/url]
--
[SA28268] Gentoo update for exiftags
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-02
Gentoo has issued an update for exiftags. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28268/\"]http://secunia.com/advisories/28268/[/url]
--
[SA28267] Gentoo update for exiv2
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-02
Gentoo has issued an update for exiv2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28267/\"]http://secunia.com/advisories/28267/[/url]
--
[SA28266] Gentoo update for libexif
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-02
Gentoo has issued an update for libexif. This fixes two vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28266/\"]http://secunia.com/advisories/28266/[/url]
--
[SA28265] Debian update for libsndfile
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-02
Debian has issued an update for libsndfile. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28265/\"]http://secunia.com/advisories/28265/[/url]
--
[SA28253] Netembryo "Url_init()" Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-28
Luigi Auriemma has reported a vulnerability in Netembryo, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28253/\"]http://secunia.com/advisories/28253/[/url]
--
[SA28269] Gentoo update for mt-daapd
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-01-02
Gentoo has acknowledged some vulnerabilities mt-daapd, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28269/\"]http://secunia.com/advisories/28269/[/url]
--
[SA28321] Fedora update for qt
Critical: Less critical
Where: From remote
Impact: Security Bypass, Spoofing
Released: 2008-01-03
Fedora has issued an update for qt. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28321/\"]http://secunia.com/advisories/28321/[/url]
--
[SA28320] Avaya Products openssh Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-03
Avaya has acknowledged some vulnerabilities in various Avaya products, which can be exploited by malicious people to disclose certain system information and to inject certain data.
Full Advisory:
[url=\"http://secunia.com/advisories/28320/\"]http://secunia.com/advisories/28320/[/url]
--
[SA28319] Avaya Products pam Vulnerability and Security Issue
Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-03
Avaya has acknowledged a vulnerability and a security issue in various Avaya products, which can be exploited by malicious, local users to disclose sensitive information and by malicious users to inject certain data.
Full Advisory:
[url=\"http://secunia.com/advisories/28319/\"]http://secunia.com/advisories/28319/[/url]
--
[SA28310] Fedora update for wordpress
Critical: Less critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of sensitive information
Released: 2008-01-03
Fedora has issued an update for wordpress. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, and conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28310/\"]http://secunia.com/advisories/28310/[/url]
--
[SA28271] Dovecot LDAP Auth Cache Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-02
A security issue has been reported in Dovecot, which can be exploited by malicious users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28271/\"]http://secunia.com/advisories/28271/[/url]
--
[SA28255] Debian update for tar
Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-01-02
Debian has issued an update for tar. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28255/\"]http://secunia.com/advisories/28255/[/url]
--
[SA28279] Gentoo update for syslog-ng
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-01-02
Gentoo has issued an update for syslog-ng. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28279/\"]http://secunia.com/advisories/28279/[/url]
[b]Other:[/b]
none
[b]Cross Platform:--[/b]
[SA28287] White_dune Format String and Buffer Overflow Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-03
Luigi Auriemma has reported some vulnerabilities in White_dune, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28287/\"]http://secunia.com/advisories/28287/[/url]
--
[SA28318] PHP Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass
Released: 2008-01-03
Some vulnerabilities have been reported in PHP, where some have unknown impact and others can be exploited by malicious users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28318/\"]http://secunia.com/advisories/28318/[/url]
--
[SA28295] Joomla PU Arcade Component "fid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-03
HouSSamix has reported a vulnerability in the PU Arcade component for Joomla, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28295/\"]http://secunia.com/advisories/28295/[/url]
--
[SA28293] Plone LiveSearch Module News Item Script Insertion
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-02
ilmila has discovered a vulnerability in Plone, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28293/\"]http://secunia.com/advisories/28293/[/url]
--
[SA28285] CMS Made Simple "templateid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-03
EgiX has reported a vulnerability in CMS Made Simple, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28285/\"]http://secunia.com/advisories/28285/[/url]
--
[SA28281] zenphoto "albumnr" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-03
Silentz has discovered a vulnerability in zenphoto, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28281/\"]http://secunia.com/advisories/28281/[/url]
--
[SA28280] MyPHP Forum SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-03
x0kster has reported some vulnerabilities in MyPHP Forum, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28280/\"]http://secunia.com/advisories/28280/[/url]
--
[SA28263] Logaholic Cross-Site Scripting and SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-01-03
malibu.r has reported some vulnerabilities in Logaholic, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28263/\"]http://secunia.com/advisories/28263/[/url]
--
[SA28258] PHCDownload "string" Cross-Site Scripting and SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-01-03
lostmon has discovered some vulnerabilities in PHCDownload, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28258/\"]http://secunia.com/advisories/28258/[/url]
--
[SA28306] milliscripts Redirection "cat" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-03
Jose Luis Góngora Fernández has reported a vulnerability in milliscripts Redirection, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28306/\"]http://secunia.com/advisories/28306/[/url]
--
[SA28303] phpWebSite "search" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-03
Audun Larsen has discovered a vulnerability in phpWebSite, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28303/\"]http://secunia.com/advisories/28303/[/url]
--
[SA28274] Apache Tomcat JULI Logging Component Security Bypass
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-01-02
A security issue has been reported in Apache Tomcat, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28274/\"]http://secunia.com/advisories/28274/[/url]
Secunia Bulletins January 2008
Moderators: Moderator, Global Moderator
Secunia Bulletins January 2008

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Secunia Bulletins January 2008
[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing For The Week of January 10 2008[/b][/i]
[b]Windows:--[/b]
[SA28399] AOL Radio AOLMediaPlaybackControl.exe Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-10
Will Dormann has reported a vulnerability in AOL Radio, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28399/\"]http://secunia.com/advisories/28399/[/url]
--
[SA28379] Gateway CWebLaunchCtl ActiveX Control "DoWebLaunch()" Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-09
Some vulnerabilities have been discovered in Gateway CWebLaunchCtl ActiveX control, which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28379/\"]http://secunia.com/advisories/28379/[/url]
--
[SA28411] IBM Lotus Domino Unspecified Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-10
A vulnerability has been reported in IBM Lotus Domino, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28411/\"]http://secunia.com/advisories/28411/[/url]
--
[SA28337] PortalApp Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data
Released: 2008-01-09
r3dm0v3 has reported some vulnerabilities in PortalApp, which can be exploited by malicious people to conduct cross-site scripting and SQL
injection attacks or bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28337/\"]http://secunia.com/advisories/28337/[/url]
--
[SA28408] McAfee E-Business Server Authentication Packet Handling Vulnerability
Critical: Moderately critical
Where: From local network
Impact: System access, DoS
Released: 2008-01-10
Leon Juranic has reported a vulnerability in McAfee E-Business Server, which can be exploited by malicious people to cause a DoS (Denial of
Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28408/\"]http://secunia.com/advisories/28408/[/url]
--
[SA28396] Novell Client nicm.sys Privilege Escalation Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-10
A vulnerability has been reported in Novell Client, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28396/\"]http://secunia.com/advisories/28396/[/url]
--
[SA28366] Motorola netOctopus Agent nantsys.sys Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-08
A vulnerability has been reported in Motorola netOctopus, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28366/\"]http://secunia.com/advisories/28366/[/url]
--
[SA28351] Novell ZENworks Endpoint Security Management Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-07
A vulnerability has been reported in Novell ZENworks Endpoint Security Management, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28351/\"]http://secunia.com/advisories/28351/[/url]
--
[SA28341] Microsoft Windows LSASS Privilege Escalation Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-08
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28341/\"]http://secunia.com/advisories/28341/[/url]
[b]UNIX/Linux:--[/b]
[SA28412] SUSE Update for Multiple Packages
Critical: Highly critical
Where: From remote
Impact: Unknown, Security Bypass, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2008-01-10
SUSE has issued an update for multiple packages. This fixes some vulnerabilities, where one vulnerability has unknown impacts and others
can be exploited by malicious, local users to disclose and manipulate sensitive information and cause a DoS (Denial of Service), by malicious users to bypass certain security restrictions, and by malicious people to cause a DoS and compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28412/\"]http://secunia.com/advisories/28412/[/url]
--
[SA28398] HP-UX update for Firefox
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, System access
Released: 2008-01-09
HP has issued an update for Firefox. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive
information, conduct phishing and cross-site scripting attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28398/\"]http://secunia.com/advisories/28398/[/url]
--
[SA28406] Gentoo update for R
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-01-10
Gentoo has issued an update for R. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of
Service), disclose sensitive information, or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28406/\"]http://secunia.com/advisories/28406/[/url]
--
[SA28403] Gentoo update for squid
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-10
Gentoo has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28403/\"]http://secunia.com/advisories/28403/[/url]
--
[SA28400] Mandriva update for libexif
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-10
Mandriva has issued an update for libexif. This fixes two vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28400/\"]http://secunia.com/advisories/28400/[/url]
--
[SA28387] Avaya Products Perl Regular Expressions Unicode Data Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-09
Avaya has acknowledged a vulnerability in various Avaya products, which potentially can be exploited by malicious people to compromise a
vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28387/\"]http://secunia.com/advisories/28387/[/url]
--
[SA28384] xine-lib SDP Attributes Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-09
Luigi Auriemma has discovered a vulnerability in xine-lib, which potentially can be exploited by malicious people to compromise a user's
system.
Full Advisory:
[url=\"http://secunia.com/advisories/28384/\"]http://secunia.com/advisories/28384/[/url]
--
[SA28381] Ubuntu update for squid
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-10
Ubuntu has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28381/\"]http://secunia.com/advisories/28381/[/url]
--
[SA28380] Ubuntu update for opal
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-09
Ubuntu has issued an update for opal. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an
application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28380/\"]http://secunia.com/advisories/28380/[/url]
--
[SA28377] Debian update for libarchive
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-09
Debian has issued an update for libarchive. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28377/\"]http://secunia.com/advisories/28377/[/url]
--
[SA28374] Debian update for fail2ban
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-10
Debian has issued an update for fail2ban. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28374/\"]http://secunia.com/advisories/28374/[/url]
--
[SA28373] FlexBB "flexbb_temp_id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-08
Eugene Minaev has discovered a vulnerability in FlexBB, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28373/\"]http://secunia.com/advisories/28373/[/url]
--
[SA28353] Fedora update for python-cherrypy
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-07
Fedora has issued an update for python-cherrypy. This fixes a vulnerability, which can be exploited by malicious people to bypass
certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28353/\"]http://secunia.com/advisories/28353/[/url]
--
[SA28350] Mandriva update for squid
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-07
Mandriva has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28350/\"]http://secunia.com/advisories/28350/[/url]
--
[SA28347] Debian update for eggdrop
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-07
Debian has issued an update for eggdrop. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable
system.
Full Advisory:
[url=\"http://secunia.com/advisories/28347/\"]http://secunia.com/advisories/28347/[/url]
--
[SA28346] rPath update for libexif
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-07
rPath has issued an update for libexif. This fixes two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of
Service) or to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28346/\"]http://secunia.com/advisories/28346/[/url]
--
[SA28345] rPath update for tetex
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-07
rPath has issued an update for tetex, tetex-afm, tetex-dvips, tetex-fonts, tetex-latex, and tetex-xdvi. This fixes a vulnerability,
which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28345/\"]http://secunia.com/advisories/28345/[/url]
--
[SA28342] Debian update for wzdftpd
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-07
Debian has issued an update for wzdftpd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service) or potentially to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28342/\"]http://secunia.com/advisories/28342/[/url]
--
[SA28334] Debian update for maradns
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-04
Debian has issued an update for maradns. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28334/\"]http://secunia.com/advisories/28334/[/url]
--
[SA28333] Debian update for freetype
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-08
Debian has issued an update for freetype. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service) and potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28333/\"]http://secunia.com/advisories/28333/[/url]
--
[SA28329] MaraDNS CNAME Record Resource Rotation Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-04
A vulnerability has been reported in MaraDNS, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28329/\"]http://secunia.com/advisories/28329/[/url]
--
[SA28386] Ubuntu update for cups
Critical: Moderately critical
Where: From local network
Impact: Privilege escalation, DoS
Released: 2008-01-09
Ubuntu has issued an update for cups. This fixes a vulnerability which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system, and a security issue which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28386/\"]http://secunia.com/advisories/28386/[/url]
--
[SA28338] Red Hat update for tog-pegasus
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-01-08
Red Hat has issued an update for tog-pegasus. This fixes a vulnerability, which can potentially be exploited by malicious people
to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28338/\"]http://secunia.com/advisories/28338/[/url]
--
[SA28404] Debian update for dovecot
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-10
Debian has issued an update for dovecot. This fixes a security issue, which can be exploited by malicious users to bypass certain security
restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28404/\"]http://secunia.com/advisories/28404/[/url]
--
[SA28388] Gentoo update for unp
Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-01-09
Gentoo has issued an update for unp. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28388/\"]http://secunia.com/advisories/28388/[/url]
--
[SA28385] Ubuntu update for pwlib
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-01-09
Ubuntu has issued an update for pwlib. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28385/\"]http://secunia.com/advisories/28385/[/url]
--
[SA28375] IBM WebSphere Application Server for z/OS HTTP Server Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-09
IBM has acknowledged a vulnerability in IBM Websphere Application Server for z/OS, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28375/\"]http://secunia.com/advisories/28375/[/url]
--
[SA28361] Debian update for tomcat5
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-01-08
Debian has issued an update for tomcat5. This fixes some vulnerabilities, which can be exploited by malicious people and
malicious users to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28361/\"]http://secunia.com/advisories/28361/[/url]
--
[SA28360] Red Hat update for e2fsprogs
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-08
Red Hat has issued an update for e2fsprogs. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28360/\"]http://secunia.com/advisories/28360/[/url]
--
[SA28352] Fedora update for mantis
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-07
Fedora has issued an update for mantis. This fixes a vulnerability, which can be exploited by malicious users to conduct script insertion
attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28352/\"]http://secunia.com/advisories/28352/[/url]
--
[SA28413] Ubuntu update for Net-SNMP
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-01-10
Ubuntu has issued an update for Net-SNMP. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28413/\"]http://secunia.com/advisories/28413/[/url]
--
[SA28401] Gentoo update for openafs
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-01-10
Gentoo has issued an update for openafs. This fixes a vulnerability, which can be exploited by malicious users to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28401/\"]http://secunia.com/advisories/28401/[/url]
--
[SA28376] Mandriva update for postgresql
Critical: Less critical
Where: From local network
Impact: Privilege escalation, DoS
Released: 2008-01-10
Mandriva has issued an update for postgresql. This fixes some vulnerabilities, which can be exploited by malicious users to gain
escalated privileges or to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28376/\"]http://secunia.com/advisories/28376/[/url]
--
[SA28344] rPath update for cups
Critical: Less critical
Where: From local network
Impact: DoS, System access
Released: 2008-01-07
rPath has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious users to cause a DoS (Denial of Service)
or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28344/\"]http://secunia.com/advisories/28344/[/url]
--
[SA28343] Debian update for mysql-dfsg-5.0
Critical: Less critical
Where: From local network
Impact: Security Bypass, Manipulation of data, DoS
Released: 2008-01-07
Debian has issued an update for mysql-dfsg-5.0. This fixes some security issues and a vulnerability, which can be exploited by
malicious users to bypass certain security restrictions, manipulate data, and cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28343/\"]http://secunia.com/advisories/28343/[/url]
--
[SA28327] OpenAFS File Server Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-01-04
A vulnerability has been reported in OpenAFS, which can be exploited by malicious users to cause a DoS (Denial od Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28327/\"]http://secunia.com/advisories/28327/[/url]
--
[SA28402] Gentoo update for claws-mail
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-10
Gentoo has issued an update for claws-mail. This fixes a security issue, which can be exploited by malicious, local users to perform
certain actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28402/\"]http://secunia.com/advisories/28402/[/url]
--
[SA28405] Xen DR7 and CR4 Register Handling Denial of Service Vulnerabilities
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-01-10
Some vulnerabilities have been reported in Xen, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28405/\"]http://secunia.com/advisories/28405/[/url]
--
[SA28349] Debian update for loop-aes-utils
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-07
Debian has issued an update for loop-aes-utils. This fixes a vulnerability, which can be exploited by malicious, local users to
perform certain actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28349/\"]http://secunia.com/advisories/28349/[/url]
--
[SA28348] Debian update for util-linux
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-07
Debian has issued an update for util-linux. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain
actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28348/\"]http://secunia.com/advisories/28348/[/url]
--
[SA28339] Ubuntu update for tomboy
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-08
Ubuntu has issued an update for tomboy. This fixes a security issue, which can be exploited by malicious, local users to gain escalated
privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28339/\"]http://secunia.com/advisories/28339/[/url]
[b]Other:--[/b]
[SA28394] Ingate Firewall and SIParator Port Exhaustion Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-10
Ingate has acknowledged a vulnerability in Ingate Firewall and SIParator, which can be exploited by malicious people to cause a DoS
(Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28394/\"]http://secunia.com/advisories/28394/[/url]
--
[SA28357] Aruba Mobility Controller LDAP User Authentication Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-07
A security issue has been reported in Aruba Mobility Controller, which can be exploited by malicious people to bypass certain security
restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28357/\"]http://secunia.com/advisories/28357/[/url]
--
[SA28364] Linksys WRT54GL Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-09
Tomaz Bratusa has reported a vulnerability in Linksys WRT54GL, which can be exploited by malicious people to conduct cross-site request
forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28364/\"]http://secunia.com/advisories/28364/[/url]
[b]Cross Platform:--[/b]
[SA28421] Kolab Server ClamAV Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Unknown, DoS, System access
Released: 2008-01-10
Some vulnerabilities have been reported in Kolab Server, where one vulnerability has an unknown impact and others can be exploited by
malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28421/\"]http://secunia.com/advisories/28421/[/url]
--
[SA28420] osDate "php121dir" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-01-10
Cold z3ro has discovered a vulnerability in osDate, which can be exploited by malicious people to disclose sensitive information or to
compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28420/\"]http://secunia.com/advisories/28420/[/url]
--
[SA28383] VLC Media Player SDP Processing Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-10
Luigi Auriemma has reported a vulnerability in VLC Media Player, which can potentially be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28383/\"]http://secunia.com/advisories/28383/[/url]
--
[SA28368] VMware ESX Server Multiple Security Updates
Critical: Highly critical
Where: From remote
Impact: Privilege escalation, DoS, System access
Released: 2008-01-08
VMware has issued an update for VMware ESX Server. This fixes some vulnerabilities, which can be exploited by malicious, local users to
perform actions with escalated privileges and by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28368/\"]http://secunia.com/advisories/28368/[/url]
--
[SA28365] VMware ESX Server and VirtualCenter Multiple Security Updates
Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-01-08
VMware has issued updates for VMware ESX Server and VirtualCenter. These fix some vulnerabilities, which can be exploited by malicious
people to bypass certain security restrictions, to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28365/\"]http://secunia.com/advisories/28365/[/url]
--
[SA28363] HP-UX update for Thunderbird
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-09
HP has issued an update for Thunderbird. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28363/\"]http://secunia.com/advisories/28363/[/url]
--
[SA28355] SAM Broadcaster samPHPweb "commonpath" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-07
Crackers_Child has discovered a vulnerability in the samPHPweb template included in SAM Broadcaster, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28355/\"]http://secunia.com/advisories/28355/[/url]
--
[SA28336] Loudblog "template" Code Execution Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-07
Eugene Minaev has discovered a vulnerability in Loudblog, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28336/\"]http://secunia.com/advisories/28336/[/url]
--
[SA28330] Strawberry "text" PHP Code Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-07
Eugene Minaev has discovered a vulnerability in Strawberry, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28330/\"]http://secunia.com/advisories/28330/[/url]
--
[SA28328] NetRisk Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Manipulation of data, System access
Released: 2008-01-07
hadihadi and S.W.A.T. have discovered some vulnerabilities in NetRisk, which can be exploited by malicious people to conduct SQL injection
attacks and to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28328/\"]http://secunia.com/advisories/28328/[/url]
--
[SA28414] R PCRE Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-01-10
Some vulnerabilities have been reported in R, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose sensitive information, or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28414/\"]http://secunia.com/advisories/28414/[/url]
--
[SA28393] DomPHP "mail" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-10
j0j0 has discovered a vulnerability in DomPHP, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28393/\"]http://secunia.com/advisories/28393/[/url]
--
[SA28382] Multiple Horde Products Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-10
Some vulnerabilities have been reported in various Horde products, which can be exploited by malicious people to bypass certain security
restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28382/\"]http://secunia.com/advisories/28382/[/url]
--
[SA28378] Docebo "Accept-Language" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-10
EgiX has discovered a vulnerability in Docebo, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28378/\"]http://secunia.com/advisories/28378/[/url]
--
[SA28371] Eggblog "eggblogpassword" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-09
gemaglabin and Elekt have discovered a vulnerability in eggblog, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28371/\"]http://secunia.com/advisories/28371/[/url]
--
[SA28370] vtiger CRM File Disclosure Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-01-10
A vulnerability has been reported in vtiger CRM, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28370/\"]http://secunia.com/advisories/28370/[/url]
--
[SA28362] Tribisur "id" and "cat" SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-07
x0kster has discovered some vulnerabilities in Tribisur, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28362/\"]http://secunia.com/advisories/28362/[/url]
--
[SA28354] CherryPy Session Id Directory Traversal Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-07
A vulnerability has been reported in CherryPy, which can be exploited by malicious people to bypass certain security settings.
Full Advisory:
[url=\"http://secunia.com/advisories/28354/\"]http://secunia.com/advisories/28354/[/url]
--
[SA28340] RunCms newbb_plus "Client-IP" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-09
gemaglabin and Elekt have discovered a vulnerability in RunCms, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28340/\"]http://secunia.com/advisories/28340/[/url]
--
[SA28331] eTicket Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-01-04
Some vulnerabilities have been discovered in eTicket, which can be exploited by malicious people to conduct script insertion, cross-site
scripting, and SQL injection attacks, and by malicious users to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28331/\"]http://secunia.com/advisories/28331/[/url]
--
[SA28409] MaxDB DBM Command Processing Command Execution Vulnerability
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-01-10
Luigi Auriemma has discovered a vulnerability in MaxDB, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28409/\"]http://secunia.com/advisories/28409/[/url]
--
[SA28358] OpenPegasus PAM Module Buffer Overflow Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-01-08
Some vulnerabilities have been reported in OpenPegasus, which can potentially be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28358/\"]http://secunia.com/advisories/28358/[/url]
--
[SA28369] NetRisk "page" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-07
hadihadi has discovered a vulnerability in NetRisk, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28369/\"]http://secunia.com/advisories/28369/[/url]
--
[SA28356] Sun Java System Identity Manager Unspecified Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-10
Some vulnerabilities have been reported in Sun Java System Identity Manager, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28356/\"]http://secunia.com/advisories/28356/[/url]
--
[SA28335] PRO-Search Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-04
MustLive has reported some vulnerabilities in PRO-Search, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28335/\"]http://secunia.com/advisories/28335/[/url]
--
[SA28359] PostgreSQL Multiple Vulnerabilities
Critical: Less critical
Where: From local network
Impact: Privilege escalation, DoS
Released: 2008-01-07
Some vulnerabilities have been reported in PostgreSQL, which can be exploited by malicious users to gain escalated privileges or to cause a
DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28359/\"]http://secunia.com/advisories/28359/[/url]
[b]Windows:--[/b]
[SA28399] AOL Radio AOLMediaPlaybackControl.exe Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-10
Will Dormann has reported a vulnerability in AOL Radio, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28399/\"]http://secunia.com/advisories/28399/[/url]
--
[SA28379] Gateway CWebLaunchCtl ActiveX Control "DoWebLaunch()" Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-09
Some vulnerabilities have been discovered in Gateway CWebLaunchCtl ActiveX control, which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28379/\"]http://secunia.com/advisories/28379/[/url]
--
[SA28411] IBM Lotus Domino Unspecified Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-10
A vulnerability has been reported in IBM Lotus Domino, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28411/\"]http://secunia.com/advisories/28411/[/url]
--
[SA28337] PortalApp Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data
Released: 2008-01-09
r3dm0v3 has reported some vulnerabilities in PortalApp, which can be exploited by malicious people to conduct cross-site scripting and SQL
injection attacks or bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28337/\"]http://secunia.com/advisories/28337/[/url]
--
[SA28408] McAfee E-Business Server Authentication Packet Handling Vulnerability
Critical: Moderately critical
Where: From local network
Impact: System access, DoS
Released: 2008-01-10
Leon Juranic has reported a vulnerability in McAfee E-Business Server, which can be exploited by malicious people to cause a DoS (Denial of
Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28408/\"]http://secunia.com/advisories/28408/[/url]
--
[SA28396] Novell Client nicm.sys Privilege Escalation Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-10
A vulnerability has been reported in Novell Client, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28396/\"]http://secunia.com/advisories/28396/[/url]
--
[SA28366] Motorola netOctopus Agent nantsys.sys Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-08
A vulnerability has been reported in Motorola netOctopus, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28366/\"]http://secunia.com/advisories/28366/[/url]
--
[SA28351] Novell ZENworks Endpoint Security Management Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-07
A vulnerability has been reported in Novell ZENworks Endpoint Security Management, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28351/\"]http://secunia.com/advisories/28351/[/url]
--
[SA28341] Microsoft Windows LSASS Privilege Escalation Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-08
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28341/\"]http://secunia.com/advisories/28341/[/url]
[b]UNIX/Linux:--[/b]
[SA28412] SUSE Update for Multiple Packages
Critical: Highly critical
Where: From remote
Impact: Unknown, Security Bypass, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2008-01-10
SUSE has issued an update for multiple packages. This fixes some vulnerabilities, where one vulnerability has unknown impacts and others
can be exploited by malicious, local users to disclose and manipulate sensitive information and cause a DoS (Denial of Service), by malicious users to bypass certain security restrictions, and by malicious people to cause a DoS and compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28412/\"]http://secunia.com/advisories/28412/[/url]
--
[SA28398] HP-UX update for Firefox
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, System access
Released: 2008-01-09
HP has issued an update for Firefox. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive
information, conduct phishing and cross-site scripting attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28398/\"]http://secunia.com/advisories/28398/[/url]
--
[SA28406] Gentoo update for R
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-01-10
Gentoo has issued an update for R. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of
Service), disclose sensitive information, or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28406/\"]http://secunia.com/advisories/28406/[/url]
--
[SA28403] Gentoo update for squid
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-10
Gentoo has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28403/\"]http://secunia.com/advisories/28403/[/url]
--
[SA28400] Mandriva update for libexif
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-10
Mandriva has issued an update for libexif. This fixes two vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28400/\"]http://secunia.com/advisories/28400/[/url]
--
[SA28387] Avaya Products Perl Regular Expressions Unicode Data Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-09
Avaya has acknowledged a vulnerability in various Avaya products, which potentially can be exploited by malicious people to compromise a
vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28387/\"]http://secunia.com/advisories/28387/[/url]
--
[SA28384] xine-lib SDP Attributes Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-09
Luigi Auriemma has discovered a vulnerability in xine-lib, which potentially can be exploited by malicious people to compromise a user's
system.
Full Advisory:
[url=\"http://secunia.com/advisories/28384/\"]http://secunia.com/advisories/28384/[/url]
--
[SA28381] Ubuntu update for squid
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-10
Ubuntu has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28381/\"]http://secunia.com/advisories/28381/[/url]
--
[SA28380] Ubuntu update for opal
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-09
Ubuntu has issued an update for opal. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an
application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28380/\"]http://secunia.com/advisories/28380/[/url]
--
[SA28377] Debian update for libarchive
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-09
Debian has issued an update for libarchive. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28377/\"]http://secunia.com/advisories/28377/[/url]
--
[SA28374] Debian update for fail2ban
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-10
Debian has issued an update for fail2ban. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28374/\"]http://secunia.com/advisories/28374/[/url]
--
[SA28373] FlexBB "flexbb_temp_id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-08
Eugene Minaev has discovered a vulnerability in FlexBB, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28373/\"]http://secunia.com/advisories/28373/[/url]
--
[SA28353] Fedora update for python-cherrypy
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-07
Fedora has issued an update for python-cherrypy. This fixes a vulnerability, which can be exploited by malicious people to bypass
certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28353/\"]http://secunia.com/advisories/28353/[/url]
--
[SA28350] Mandriva update for squid
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-07
Mandriva has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28350/\"]http://secunia.com/advisories/28350/[/url]
--
[SA28347] Debian update for eggdrop
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-07
Debian has issued an update for eggdrop. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable
system.
Full Advisory:
[url=\"http://secunia.com/advisories/28347/\"]http://secunia.com/advisories/28347/[/url]
--
[SA28346] rPath update for libexif
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-07
rPath has issued an update for libexif. This fixes two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of
Service) or to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28346/\"]http://secunia.com/advisories/28346/[/url]
--
[SA28345] rPath update for tetex
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-07
rPath has issued an update for tetex, tetex-afm, tetex-dvips, tetex-fonts, tetex-latex, and tetex-xdvi. This fixes a vulnerability,
which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28345/\"]http://secunia.com/advisories/28345/[/url]
--
[SA28342] Debian update for wzdftpd
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-07
Debian has issued an update for wzdftpd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service) or potentially to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28342/\"]http://secunia.com/advisories/28342/[/url]
--
[SA28334] Debian update for maradns
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-04
Debian has issued an update for maradns. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28334/\"]http://secunia.com/advisories/28334/[/url]
--
[SA28333] Debian update for freetype
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-08
Debian has issued an update for freetype. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service) and potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28333/\"]http://secunia.com/advisories/28333/[/url]
--
[SA28329] MaraDNS CNAME Record Resource Rotation Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-04
A vulnerability has been reported in MaraDNS, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28329/\"]http://secunia.com/advisories/28329/[/url]
--
[SA28386] Ubuntu update for cups
Critical: Moderately critical
Where: From local network
Impact: Privilege escalation, DoS
Released: 2008-01-09
Ubuntu has issued an update for cups. This fixes a vulnerability which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system, and a security issue which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28386/\"]http://secunia.com/advisories/28386/[/url]
--
[SA28338] Red Hat update for tog-pegasus
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-01-08
Red Hat has issued an update for tog-pegasus. This fixes a vulnerability, which can potentially be exploited by malicious people
to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28338/\"]http://secunia.com/advisories/28338/[/url]
--
[SA28404] Debian update for dovecot
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-10
Debian has issued an update for dovecot. This fixes a security issue, which can be exploited by malicious users to bypass certain security
restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28404/\"]http://secunia.com/advisories/28404/[/url]
--
[SA28388] Gentoo update for unp
Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-01-09
Gentoo has issued an update for unp. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28388/\"]http://secunia.com/advisories/28388/[/url]
--
[SA28385] Ubuntu update for pwlib
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-01-09
Ubuntu has issued an update for pwlib. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28385/\"]http://secunia.com/advisories/28385/[/url]
--
[SA28375] IBM WebSphere Application Server for z/OS HTTP Server Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-09
IBM has acknowledged a vulnerability in IBM Websphere Application Server for z/OS, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28375/\"]http://secunia.com/advisories/28375/[/url]
--
[SA28361] Debian update for tomcat5
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-01-08
Debian has issued an update for tomcat5. This fixes some vulnerabilities, which can be exploited by malicious people and
malicious users to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28361/\"]http://secunia.com/advisories/28361/[/url]
--
[SA28360] Red Hat update for e2fsprogs
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-08
Red Hat has issued an update for e2fsprogs. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28360/\"]http://secunia.com/advisories/28360/[/url]
--
[SA28352] Fedora update for mantis
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-07
Fedora has issued an update for mantis. This fixes a vulnerability, which can be exploited by malicious users to conduct script insertion
attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28352/\"]http://secunia.com/advisories/28352/[/url]
--
[SA28413] Ubuntu update for Net-SNMP
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-01-10
Ubuntu has issued an update for Net-SNMP. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28413/\"]http://secunia.com/advisories/28413/[/url]
--
[SA28401] Gentoo update for openafs
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-01-10
Gentoo has issued an update for openafs. This fixes a vulnerability, which can be exploited by malicious users to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28401/\"]http://secunia.com/advisories/28401/[/url]
--
[SA28376] Mandriva update for postgresql
Critical: Less critical
Where: From local network
Impact: Privilege escalation, DoS
Released: 2008-01-10
Mandriva has issued an update for postgresql. This fixes some vulnerabilities, which can be exploited by malicious users to gain
escalated privileges or to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28376/\"]http://secunia.com/advisories/28376/[/url]
--
[SA28344] rPath update for cups
Critical: Less critical
Where: From local network
Impact: DoS, System access
Released: 2008-01-07
rPath has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious users to cause a DoS (Denial of Service)
or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28344/\"]http://secunia.com/advisories/28344/[/url]
--
[SA28343] Debian update for mysql-dfsg-5.0
Critical: Less critical
Where: From local network
Impact: Security Bypass, Manipulation of data, DoS
Released: 2008-01-07
Debian has issued an update for mysql-dfsg-5.0. This fixes some security issues and a vulnerability, which can be exploited by
malicious users to bypass certain security restrictions, manipulate data, and cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28343/\"]http://secunia.com/advisories/28343/[/url]
--
[SA28327] OpenAFS File Server Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-01-04
A vulnerability has been reported in OpenAFS, which can be exploited by malicious users to cause a DoS (Denial od Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28327/\"]http://secunia.com/advisories/28327/[/url]
--
[SA28402] Gentoo update for claws-mail
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-10
Gentoo has issued an update for claws-mail. This fixes a security issue, which can be exploited by malicious, local users to perform
certain actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28402/\"]http://secunia.com/advisories/28402/[/url]
--
[SA28405] Xen DR7 and CR4 Register Handling Denial of Service Vulnerabilities
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-01-10
Some vulnerabilities have been reported in Xen, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28405/\"]http://secunia.com/advisories/28405/[/url]
--
[SA28349] Debian update for loop-aes-utils
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-07
Debian has issued an update for loop-aes-utils. This fixes a vulnerability, which can be exploited by malicious, local users to
perform certain actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28349/\"]http://secunia.com/advisories/28349/[/url]
--
[SA28348] Debian update for util-linux
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-07
Debian has issued an update for util-linux. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain
actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28348/\"]http://secunia.com/advisories/28348/[/url]
--
[SA28339] Ubuntu update for tomboy
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-08
Ubuntu has issued an update for tomboy. This fixes a security issue, which can be exploited by malicious, local users to gain escalated
privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28339/\"]http://secunia.com/advisories/28339/[/url]
[b]Other:--[/b]
[SA28394] Ingate Firewall and SIParator Port Exhaustion Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-10
Ingate has acknowledged a vulnerability in Ingate Firewall and SIParator, which can be exploited by malicious people to cause a DoS
(Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28394/\"]http://secunia.com/advisories/28394/[/url]
--
[SA28357] Aruba Mobility Controller LDAP User Authentication Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-07
A security issue has been reported in Aruba Mobility Controller, which can be exploited by malicious people to bypass certain security
restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28357/\"]http://secunia.com/advisories/28357/[/url]
--
[SA28364] Linksys WRT54GL Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-09
Tomaz Bratusa has reported a vulnerability in Linksys WRT54GL, which can be exploited by malicious people to conduct cross-site request
forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28364/\"]http://secunia.com/advisories/28364/[/url]
[b]Cross Platform:--[/b]
[SA28421] Kolab Server ClamAV Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Unknown, DoS, System access
Released: 2008-01-10
Some vulnerabilities have been reported in Kolab Server, where one vulnerability has an unknown impact and others can be exploited by
malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28421/\"]http://secunia.com/advisories/28421/[/url]
--
[SA28420] osDate "php121dir" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-01-10
Cold z3ro has discovered a vulnerability in osDate, which can be exploited by malicious people to disclose sensitive information or to
compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28420/\"]http://secunia.com/advisories/28420/[/url]
--
[SA28383] VLC Media Player SDP Processing Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-10
Luigi Auriemma has reported a vulnerability in VLC Media Player, which can potentially be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28383/\"]http://secunia.com/advisories/28383/[/url]
--
[SA28368] VMware ESX Server Multiple Security Updates
Critical: Highly critical
Where: From remote
Impact: Privilege escalation, DoS, System access
Released: 2008-01-08
VMware has issued an update for VMware ESX Server. This fixes some vulnerabilities, which can be exploited by malicious, local users to
perform actions with escalated privileges and by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28368/\"]http://secunia.com/advisories/28368/[/url]
--
[SA28365] VMware ESX Server and VirtualCenter Multiple Security Updates
Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-01-08
VMware has issued updates for VMware ESX Server and VirtualCenter. These fix some vulnerabilities, which can be exploited by malicious
people to bypass certain security restrictions, to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28365/\"]http://secunia.com/advisories/28365/[/url]
--
[SA28363] HP-UX update for Thunderbird
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-09
HP has issued an update for Thunderbird. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28363/\"]http://secunia.com/advisories/28363/[/url]
--
[SA28355] SAM Broadcaster samPHPweb "commonpath" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-07
Crackers_Child has discovered a vulnerability in the samPHPweb template included in SAM Broadcaster, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28355/\"]http://secunia.com/advisories/28355/[/url]
--
[SA28336] Loudblog "template" Code Execution Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-07
Eugene Minaev has discovered a vulnerability in Loudblog, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28336/\"]http://secunia.com/advisories/28336/[/url]
--
[SA28330] Strawberry "text" PHP Code Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-07
Eugene Minaev has discovered a vulnerability in Strawberry, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28330/\"]http://secunia.com/advisories/28330/[/url]
--
[SA28328] NetRisk Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Manipulation of data, System access
Released: 2008-01-07
hadihadi and S.W.A.T. have discovered some vulnerabilities in NetRisk, which can be exploited by malicious people to conduct SQL injection
attacks and to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28328/\"]http://secunia.com/advisories/28328/[/url]
--
[SA28414] R PCRE Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-01-10
Some vulnerabilities have been reported in R, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose sensitive information, or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28414/\"]http://secunia.com/advisories/28414/[/url]
--
[SA28393] DomPHP "mail" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-10
j0j0 has discovered a vulnerability in DomPHP, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28393/\"]http://secunia.com/advisories/28393/[/url]
--
[SA28382] Multiple Horde Products Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-10
Some vulnerabilities have been reported in various Horde products, which can be exploited by malicious people to bypass certain security
restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28382/\"]http://secunia.com/advisories/28382/[/url]
--
[SA28378] Docebo "Accept-Language" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-10
EgiX has discovered a vulnerability in Docebo, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28378/\"]http://secunia.com/advisories/28378/[/url]
--
[SA28371] Eggblog "eggblogpassword" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-09
gemaglabin and Elekt have discovered a vulnerability in eggblog, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28371/\"]http://secunia.com/advisories/28371/[/url]
--
[SA28370] vtiger CRM File Disclosure Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-01-10
A vulnerability has been reported in vtiger CRM, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28370/\"]http://secunia.com/advisories/28370/[/url]
--
[SA28362] Tribisur "id" and "cat" SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-07
x0kster has discovered some vulnerabilities in Tribisur, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28362/\"]http://secunia.com/advisories/28362/[/url]
--
[SA28354] CherryPy Session Id Directory Traversal Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-07
A vulnerability has been reported in CherryPy, which can be exploited by malicious people to bypass certain security settings.
Full Advisory:
[url=\"http://secunia.com/advisories/28354/\"]http://secunia.com/advisories/28354/[/url]
--
[SA28340] RunCms newbb_plus "Client-IP" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-09
gemaglabin and Elekt have discovered a vulnerability in RunCms, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28340/\"]http://secunia.com/advisories/28340/[/url]
--
[SA28331] eTicket Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-01-04
Some vulnerabilities have been discovered in eTicket, which can be exploited by malicious people to conduct script insertion, cross-site
scripting, and SQL injection attacks, and by malicious users to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28331/\"]http://secunia.com/advisories/28331/[/url]
--
[SA28409] MaxDB DBM Command Processing Command Execution Vulnerability
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-01-10
Luigi Auriemma has discovered a vulnerability in MaxDB, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28409/\"]http://secunia.com/advisories/28409/[/url]
--
[SA28358] OpenPegasus PAM Module Buffer Overflow Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-01-08
Some vulnerabilities have been reported in OpenPegasus, which can potentially be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28358/\"]http://secunia.com/advisories/28358/[/url]
--
[SA28369] NetRisk "page" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-07
hadihadi has discovered a vulnerability in NetRisk, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28369/\"]http://secunia.com/advisories/28369/[/url]
--
[SA28356] Sun Java System Identity Manager Unspecified Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-10
Some vulnerabilities have been reported in Sun Java System Identity Manager, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28356/\"]http://secunia.com/advisories/28356/[/url]
--
[SA28335] PRO-Search Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-04
MustLive has reported some vulnerabilities in PRO-Search, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28335/\"]http://secunia.com/advisories/28335/[/url]
--
[SA28359] PostgreSQL Multiple Vulnerabilities
Critical: Less critical
Where: From local network
Impact: Privilege escalation, DoS
Released: 2008-01-07
Some vulnerabilities have been reported in PostgreSQL, which can be exploited by malicious users to gain escalated privileges or to cause a
DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28359/\"]http://secunia.com/advisories/28359/[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Secunia Bulletins January 2008
[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing For The Week of January 24 2008[/b][/i]
[b]Windows:--[/b]
[SA28599] Lycos FileUploader Module File Upload Component ActiveX Control Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-23
Elazar Broad has discovered a vulnerability in Lycos FileUploader Module, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28599/\"]http://secunia.com/advisories/28599/[/url]
--
[SA28595] HP Virtual Rooms Install HPVirtualRooms14 Class ActiveX Control Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-22
Elazar Broad has discovered a vulnerability in HP Virtual Rooms Install, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28595/\"]http://secunia.com/advisories/28595/[/url]
--
[SA28557] Toshiba Surveillix RecordSend Class ActiveX Control Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-21
retrogod has discovered two vulnerabilities in the Toshiba Surveillix RecordSend Class ActiveX control, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28557/\"]http://secunia.com/advisories/28557/[/url]
--
[SA28563] Microsoft Visual Basic ".dsr" File Handling Buffer Overflows
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-21
shinnai has discovered two vulnerabilities in Microsoft Visual Basic, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28563/\"]http://secunia.com/advisories/28563/[/url]
--
[SA28639] Web Wiz Rich Text Editor "sub" Directory Traversal Vulnerability
Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-01-24
AmnPardaz Security Research Team has reported a vulnerability in Web Wiz Rich Text Editor, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28639/\"]http://secunia.com/advisories/28639/[/url]
--
[SA28601] Web Wiz Forums Directory Traversal Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-01-24
AmnPardaz Security Research Team has reported some vulnerabilities in Web Wiz Forums, which can be exploited by malicious users and malicious people to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28601/\"]http://secunia.com/advisories/28601/[/url]
--
[SA28586] IBM WebSphere Business Modeler Repository Deletion Security Issue
Critical: Less critical
Where: From local network
Impact: Manipulation of data
Released: 2008-01-22
A security issue has been reported in IBM WebSphere Business Modeler, which can be exploited by malicious users to manipulate certain data.
Full Advisory:
[url=\"http://secunia.com/advisories/28586/\"]http://secunia.com/advisories/28586/[/url]
--
[SA28578] BitDefender Update Server HTTP Server Directory Traversal Vulnerability
Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-01-21
Oliver Karow has discovered a vulnerability in BitDefender Update Server, which can be exploited by malicious people to disclose
sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28578/\"]http://secunia.com/advisories/28578/[/url]
[b]UNIX/Linux:--[/b]
[SA28590] Citadel SMTP "makeuserkey()" Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-22
prdelka has discovered a vulnerability in Citadel, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28590/\"]http://secunia.com/advisories/28590/[/url]
--
[SA28587] Fedora update for clamav
Critical: Highly critical
Where: From remote
Impact: Unknown, DoS, System access
Released: 2008-01-23
Fedora has issued an update for clamav. This fixes some vulnerabilities, where one vulnerability has an unknown impact and
others can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28587/\"]http://secunia.com/advisories/28587/[/url]
--
[SA28570] Gentoo update for netscape-flash
Critical: Highly critical
Where: From remote
Impact: Unknown, Security Bypass, Cross Site Scripting, Manipulation of data, Exposure of sensitive information, Privilege
escalation, DoS, System access
Released: 2008-01-21
Gentoo has issued an update for netscape-flash. This fixes some vulnerabilities, where one vulnerability has an unknown impact and others can be exploited by malicious, local users to gain escalated privileges and by malicious people to bypass certain security restrictions, conduct cross-site scripting and HTTP request splitting attacks, disclose sensitive information, cause a Denial of Service (DoS), or to potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28570/\"]http://secunia.com/advisories/28570/[/url]
--
[SA28631] HTTP File Server Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, Manipulation of data, Exposure of system information, DoS, System access
Released: 2008-01-24
Felipe Aragon and Alec Storm have reported some vulnerabilities and security issues in HTTP File Server, which can be exploited by malicious people to disclose system information, conduct spoofing and cross-site scripting attacks, bypass certain security restrictions, manipulate data, and potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28631/\"]http://secunia.com/advisories/28631/[/url]
--
[SA28614] Debian update for libvorbis
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-22
Debian has issued an update for libvorbis. This fixes some vulnerabilties, which can be exploited by malicious people to cause a
DoS (Denial of Service) and potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28614/\"]http://secunia.com/advisories/28614/[/url]
--
[SA28612] HP-UX ARPA Transport Unspecified Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-24
A vulnerability has been reported in HP-UX, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28612/\"]http://secunia.com/advisories/28612/[/url]
--
[SA28610] Debian update for exiv2
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-24
Debian has issued an update for exiv2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28610/\"]http://secunia.com/advisories/28610/[/url]
--
[SA28602] Gentoo update for tikiwiki
Critical: Moderately critical
Where: From remote
Impact: Unknown, Cross Site Scripting
Released: 2008-01-24
Gentoo has issued an update for tikiwiki. This fixes some vulnerabilities, where some have unknown impacts and others can be
exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28602/\"]http://secunia.com/advisories/28602/[/url]
--
[SA28583] Red Hat update for wireshark
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-21
Red Hat has issued an update for wireshark. This fixes some
vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28583/\"]http://secunia.com/advisories/28583/[/url]
--
[SA28564] Red Hat update for wireshark
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-21
Red Hat has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28564/\"]http://secunia.com/advisories/28564/[/url]
--
[SA28555] Mandriva update for cairo
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-22
Mandriva has issued an update for cairo. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28555/\"]http://secunia.com/advisories/28555/[/url]
--
[SA28548] Debian update for flac
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-21
Debian has issued an update for flac. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28548/\"]http://secunia.com/advisories/28548/[/url]
--
[SA28546] Debian update for horde3
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data
Released: 2008-01-21
Debian has issued an update for horde3. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions and manipulate data.
Full Advisory:
[url=\"http://secunia.com/advisories/28546/\"]http://secunia.com/advisories/28546/[/url]
--
[SA28607] Avaya Products httpd Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-22
Avaya has acknowledged some vulnerabilities in various Avaya products, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28607/\"]http://secunia.com/advisories/28607/[/url]
--
[SA28591] Fedora update for mantis
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-23
Fedora has issued an update for mantis. This fixes a vulnerability, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28591/\"]http://secunia.com/advisories/28591/[/url]
--
[SA28589] ELOG Script Insertion and Denial of Service Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2008-01-22
Some vulnerabilities have been reported in ELOG, which can be exploited by malicious users to cause a DoS (Denial of Service) and conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28589/\"]http://secunia.com/advisories/28589/[/url]
--
[SA28569] Gentoo update for libcdio
Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-01-21
Gentoo has issued an update for libcdio. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28569/\"]http://secunia.com/advisories/28569/[/url]
--
[SA28551] Debian update for mantis
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information
Released: 2008-01-21
Debian has issued an update for mantis. This fixes a vulnerability, which can be exploited by malicious users to conduct script insertion attacks, and a security issue, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28551/\"]http://secunia.com/advisories/28551/[/url]
--
[SA28549] Debian update for tomcat5.5
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information
Released: 2008-01-21
Debian has issued an update for tomcat5.5. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks, and a security issue, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28549/\"]http://secunia.com/advisories/28549/[/url]
--
[SA28545] Fedora update for boost
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-01-23
Fedora has issued an update for boost. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28545/\"]http://secunia.com/advisories/28545/[/url]
--
[SA28541] Fedora update for e2fsprogs
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-21
Fedora has issued an update for e2fsprogs. This fixes a some vulnerabilities, which potentially can be exploited by malicious people
to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28541/\"]http://secunia.com/advisories/28541/[/url]
--
[SA28643] Red Hat update for kernel
Critical: Less critical
Where: From local network
Impact: Security Bypass, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2008-01-24
Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a Denial of Service (DoS), disclose potentially sensitive information, bypass certain security restrictions, and corrupt a file
system, and by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28643/\"]http://secunia.com/advisories/28643/[/url]
--
[SA28592] Fedora update for xorg-x11-server
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-23
Fedora has issued an update for xorg-x11-server. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28592/\"]http://secunia.com/advisories/28592/[/url]
--
[SA28616] Mandriva update for x11-server-xgl
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-24
Mandriva has issued an update for x11-server-xgl. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28616/\"]http://secunia.com/advisories/28616/[/url]
--
[SA28609] IBM AIX Multiple Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Manipulation of data, Exposure of sensitive information, Privilege escalation
Released: 2008-01-24
Some vulnerabilities have been reported in IBM AIX, which can be exploited by malicious, local users to disclose potentially sensitive information, manipulate certain files, or gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28609/\"]http://secunia.com/advisories/28609/[/url]
--
[SA28571] Mandriva update for libxfont
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-24
Mandriva has issued an update for libxfont. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28571/\"]http://secunia.com/advisories/28571/[/url]
--
[SA28559] rPath update for mysql
Critical: Less critical
Where: Local system
Impact: Manipulation of data
Released: 2008-01-18
rPath has issued an update for mysql. This fixes a vulnerability, which can be exploited by malicious, local users to manipulate certain data.
Full Advisory:
[url=\"http://secunia.com/advisories/28559/\"]http://secunia.com/advisories/28559/[/url]
--
[SA28558] rPath update for kernel
Critical: Less critical
Where: Local system
Impact: Security Bypass, Manipulation of data
Released: 2008-01-18
rPath has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions and corrupt a file system.
Full Advisory:
[url=\"http://secunia.com/advisories/28558/\"]http://secunia.com/advisories/28558/[/url]
--
[SA28550] Sun Solaris X Window System and X Server Multiple
Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-18
Sun has acknowledged some vulnerabilities in Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28550/\"]http://secunia.com/advisories/28550/[/url]
--
[SA28544] Red Hat update for libXfont
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-18
Red Hat has issued an update for libXfont. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28544/\"]http://secunia.com/advisories/28544/[/url]
--
[SA28543] Red Hat update for xorg-x11-server
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-18
Red Hat has issued an update for xorg-x11-server. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information or to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28543/\"]http://secunia.com/advisories/28543/[/url]
--
[SA28542] Red Hat update for XFree86
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-18
Red Hat has issued an update for XFree86. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, or gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28542/\"]http://secunia.com/advisories/28542/[/url]
--
[SA28540] SUSE update for Xorg and XFree
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-18
SUSE has issued an update for Xorg and XFree. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, or gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28540/\"]http://secunia.com/advisories/28540/[/url]
--
[SA28539] Debian update for xorg-server
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-18
Debian has issued an update for xorg-server. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information or to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28539/\"]http://secunia.com/advisories/28539/[/url]
--
[SA28574] Ubuntu update for apt-listchanges
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-21
Ubuntu has issued an update for apt-listchanges. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28574/\"]http://secunia.com/advisories/28574/[/url]
[b]Other:--[/b]
[SA28625] Cisco PIX and ASA Time-To-Live Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-24
Cisco has acknowledged a vulnerability in Cisco PIX and ASA appliances, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28625/\"]http://secunia.com/advisories/28625/[/url]
--
[SA28553] OKI C5510MFP Configuration Interface Security Issues
Critical: Less critical
Where: From local network
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-01-18
Compass Security AG has reported two security issues in OKI C5510MFP, which can be exploited by malicious people to disclose sensitive information and to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28553/\"]http://secunia.com/advisories/28553/[/url]
[b]Cross Platform:--[/b]
[SA28580] phpAutoVideo File Inclusion and Cross-Site Scripting
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-01-21
H-T Team have reported two vulnerabilities in phpAutoVideo, which can be exploited by malicious people to conduct cross-site scripting attacks, disclose sensitive information, or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28580/\"]http://secunia.com/advisories/28580/[/url]
--
[SA28568] Small Axe Weblog linkbar.php File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-01-21
Two vulnerabilities have been reported in Small Axe Weblog, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28568/\"]http://secunia.com/advisories/28568/[/url]
--
[SA28556] HP Oracle for OpenView Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Unknown
Released: 2008-01-18
HP has acknowledged some vulnerabilities with unknown impacts in HP OfO (Oracle for Openview), which can be exploited by malicious users and malicious people.
Full Advisory:
[url=\"http://secunia.com/advisories/28556/\"]http://secunia.com/advisories/28556/[/url]
--
[SA28640] SDL_image Two Buffer Overflow Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-24
Two vulnerabilities have been reported in SDL_image, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28640/\"]http://secunia.com/advisories/28640/[/url]
--
[SA28624] PHP-Nuke "modules/Search/index.php" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-23
Foster & 1dt.w0lf have discovered a vulnerability in PHP-Nuke, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28624/\"]http://secunia.com/advisories/28624/[/url]
--
[SA28619] Liquid-Silver CMS "update" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-01-24
Stack-Terrorist has discovered a vulnerability in Liquid-Silver CMS, which can be exploited by malicious people to disclose sensitive
information.
Full Advisory:
[url=\"http://secunia.com/advisories/28619/\"]http://secunia.com/advisories/28619/[/url]
--
[SA28617] aconon Mail "template" Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information
Released: 2008-01-24
Arno Töll has reported a vulnerability in aconon Mail, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28617/\"]http://secunia.com/advisories/28617/[/url]
--
[SA28606] Interstage HTTP Server Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2008-01-22
Fujitsu has acknowledged some vulnerabilities in Interstage HTTP Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28606/\"]http://secunia.com/advisories/28606/[/url]
--
[SA28605] PacerCMS Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Cross Site Scripting
Released: 2008-01-22
Some vulnerabilities have been reported in PacerCMS, which can be exploited by malicious people to conduct script insertion attacks and by malicious users to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28605/\"]http://secunia.com/advisories/28605/[/url]
--
[SA28594] aflog SQL Injection and Script Insertion Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-01-23
shinmai has discovered some vulnerabilities in aflog, which can be exploited by malicious users to conduct script insertion attacks, and by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28594/\"]http://secunia.com/advisories/28594/[/url]
--
[SA28588] WebSphere Application Server Two Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-01-22
Some vulnerabilities with unknown impact have been reported in WebSphere Application Server.
Full Advisory:
[url=\"http://secunia.com/advisories/28588/\"]http://secunia.com/advisories/28588/[/url]
--
[SA28581] AlstraSoft Forum Pay Per Post Exchange "catid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-22
t0pP8uZz & xprog have reported a vulnerability in AlstraSoft Forum Pay Per Post Exchange, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28581/\"]http://secunia.com/advisories/28581/[/url]
--
[SA28576] IBM WebSphere Application Server serveServletsByClassnameEnabled Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-01-21
A vulnerability has been reported in IBM WebSphere Application Server, which has an unknown impact.
Full Advisory:
[url=\"http://secunia.com/advisories/28576/\"]http://secunia.com/advisories/28576/[/url]
--
[SA28572] MyBB SQL Injection and Cross-Site Request Forgery
Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-01-21
Some vulnerabilities have been reported in MyBB, which can be exploited by malicious users to conduct SQL injection or cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28572/\"]http://secunia.com/advisories/28572/[/url]
--
[SA28567] WordPress WP-Forum Plugin "user" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-21
websec Team have discovered a vulnerability in the WP-Forum plugin for WordPress, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28567/\"]http://secunia.com/advisories/28567/[/url]
--
[SA28566] Famp3 "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-18
IRCRASH has discovered a vulnerability in Famp3, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28566/\"]http://secunia.com/advisories/28566/[/url]
--
[SA28565] FaPersianHack "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-18
IRCRASH has discovered a vulnerability in FaPersianHack, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28565/\"]http://secunia.com/advisories/28565/[/url]
--
[SA28560] Clever Copy SQL Injection and Cross-Site Scripting
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-01-18
hadihadi has discovered some vulnerabilities in Clever Copy, which can be exploited by malicious people to conduct cross-site scripting attacks and SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28560/\"]http://secunia.com/advisories/28560/[/url]
--
[SA28547] Openfire Jetty Information Disclosure Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-01-18
A vulnerability has been reported in Openfire, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28547/\"]http://secunia.com/advisories/28547/[/url]
--
[SA28562] AXIGEN Mail Server AXIMilter Format String Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-01-21
hempel has discovered a vulnerability in the AXIGEN Mail Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28562/\"]http://secunia.com/advisories/28562/[/url]
--
[SA28633] Drupal Workflow Module Workflow Message Script Insertion
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-24
A vulnerability has been reported in the Workflow module for Drupal, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28633/\"]http://secunia.com/advisories/28633/[/url]
--
[SA28632] Drupal Archive Module Unspecified Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-24
Some vulnerabilities have been reported in the Archive module for Drupal, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28632/\"]http://secunia.com/advisories/28632/[/url]
--
[SA28629] MediaWiki Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-24
A vulnerability has been reported in MediaWiki, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28629/\"]http://secunia.com/advisories/28629/[/url]
--
[SA28622] Mozilla Firefox "chrome:" Directory Traversal Security Issue
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-24
Gerry Eisenhaur has discovered a security issue in Mozilla Firefox, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28622/\"]http://secunia.com/advisories/28622/[/url]
--
[SA28593] WordPress Permalinks Migration Plugin Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-24
g30rg3_x has discovered a vulnerability in the Permalinks Migration plugin for WordPress, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28593/\"]http://secunia.com/advisories/28593/[/url]
--
[SA28582] OZJournals "id" Information Disclosure Vulnerability
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-01-22
shinmai has discovered a vulnerability in OZJournals, which can be exploited by malicious people to disclose potentially sensitive
information.
Full Advisory:
[url=\"http://secunia.com/advisories/28582/\"]http://secunia.com/advisories/28582/[/url]
--
[SA28579] ISC BIND libbind "inet_network()" Off-By-One Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-21
A vulnerability has been reported in ISC BIND, which can be exploited by malicious people to cause a DoS (Denial of Service) or to
potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28579/\"]http://secunia.com/advisories/28579/[/url]
--
[SA28577] Mantis "Most Active" Script Insertion Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-21
A vulnerability has been reported in Mantis, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28577/\"]http://secunia.com/advisories/28577/[/url]
--
[SA28573] singapore "gallery" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-21
Rubén Ventura Piña has discovered a vulnerability in singapore, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28573/\"]http://secunia.com/advisories/28573/[/url]
--
[SA28561] cPanel Leech Protect "rurl" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-18
Aria-Security Team have reported a vulnerability in cPanel, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28561/\"]http://secunia.com/advisories/28561/[/url]
--
[SA28604] IBM Tivoli Provisioning Manager for OS Deployment HTTP Server Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-01-22
A vulnerability has been reported in IBM Tivoli Provisioning Manager for OS Deployment, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28604/\"]http://secunia.com/advisories/28604/[/url]
--
[SA28603] IBM Tivoli Business Service Manager Password Disclosure
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-01-22
Some security issues have been reported in IBM Tivoli Business Service Manager, which potentially can be exploited by malicious, local users to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28603/\"]http://secunia.com/advisories/28603/[/url]
--
[SA28613] Kayako SupportSuite "syncml/index.php" Information Disclosure
Critical: Not critical
Where: From remote
Impact: Exposure of system information
Released: 2008-01-22
Janek Vind has reported a vulnerability in Kayako SupportSuite, which can be exploited by malicious people to disclose system information.
Full Advisory:
[url=\"http://secunia.com/advisories/28613/\"]http://secunia.com/advisories/28613/[/url]
--
[SA28552] Apache Tomcat SingleSignOn Information Disclosure
Critical: Not critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2008-01-21
A security issue has been reported in Apache Tomcat, which can be exploited by malicious people to disclose potentially sensitive
information.
Full Advisory:
[url=\"http://secunia.com/advisories/28552/\"]http://secunia.com/advisories/28552/[/url]
[b]Windows:--[/b]
[SA28599] Lycos FileUploader Module File Upload Component ActiveX Control Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-23
Elazar Broad has discovered a vulnerability in Lycos FileUploader Module, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28599/\"]http://secunia.com/advisories/28599/[/url]
--
[SA28595] HP Virtual Rooms Install HPVirtualRooms14 Class ActiveX Control Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-22
Elazar Broad has discovered a vulnerability in HP Virtual Rooms Install, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28595/\"]http://secunia.com/advisories/28595/[/url]
--
[SA28557] Toshiba Surveillix RecordSend Class ActiveX Control Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-21
retrogod has discovered two vulnerabilities in the Toshiba Surveillix RecordSend Class ActiveX control, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28557/\"]http://secunia.com/advisories/28557/[/url]
--
[SA28563] Microsoft Visual Basic ".dsr" File Handling Buffer Overflows
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-21
shinnai has discovered two vulnerabilities in Microsoft Visual Basic, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28563/\"]http://secunia.com/advisories/28563/[/url]
--
[SA28639] Web Wiz Rich Text Editor "sub" Directory Traversal Vulnerability
Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-01-24
AmnPardaz Security Research Team has reported a vulnerability in Web Wiz Rich Text Editor, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28639/\"]http://secunia.com/advisories/28639/[/url]
--
[SA28601] Web Wiz Forums Directory Traversal Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-01-24
AmnPardaz Security Research Team has reported some vulnerabilities in Web Wiz Forums, which can be exploited by malicious users and malicious people to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28601/\"]http://secunia.com/advisories/28601/[/url]
--
[SA28586] IBM WebSphere Business Modeler Repository Deletion Security Issue
Critical: Less critical
Where: From local network
Impact: Manipulation of data
Released: 2008-01-22
A security issue has been reported in IBM WebSphere Business Modeler, which can be exploited by malicious users to manipulate certain data.
Full Advisory:
[url=\"http://secunia.com/advisories/28586/\"]http://secunia.com/advisories/28586/[/url]
--
[SA28578] BitDefender Update Server HTTP Server Directory Traversal Vulnerability
Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-01-21
Oliver Karow has discovered a vulnerability in BitDefender Update Server, which can be exploited by malicious people to disclose
sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28578/\"]http://secunia.com/advisories/28578/[/url]
[b]UNIX/Linux:--[/b]
[SA28590] Citadel SMTP "makeuserkey()" Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-22
prdelka has discovered a vulnerability in Citadel, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28590/\"]http://secunia.com/advisories/28590/[/url]
--
[SA28587] Fedora update for clamav
Critical: Highly critical
Where: From remote
Impact: Unknown, DoS, System access
Released: 2008-01-23
Fedora has issued an update for clamav. This fixes some vulnerabilities, where one vulnerability has an unknown impact and
others can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28587/\"]http://secunia.com/advisories/28587/[/url]
--
[SA28570] Gentoo update for netscape-flash
Critical: Highly critical
Where: From remote
Impact: Unknown, Security Bypass, Cross Site Scripting, Manipulation of data, Exposure of sensitive information, Privilege
escalation, DoS, System access
Released: 2008-01-21
Gentoo has issued an update for netscape-flash. This fixes some vulnerabilities, where one vulnerability has an unknown impact and others can be exploited by malicious, local users to gain escalated privileges and by malicious people to bypass certain security restrictions, conduct cross-site scripting and HTTP request splitting attacks, disclose sensitive information, cause a Denial of Service (DoS), or to potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28570/\"]http://secunia.com/advisories/28570/[/url]
--
[SA28631] HTTP File Server Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, Manipulation of data, Exposure of system information, DoS, System access
Released: 2008-01-24
Felipe Aragon and Alec Storm have reported some vulnerabilities and security issues in HTTP File Server, which can be exploited by malicious people to disclose system information, conduct spoofing and cross-site scripting attacks, bypass certain security restrictions, manipulate data, and potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28631/\"]http://secunia.com/advisories/28631/[/url]
--
[SA28614] Debian update for libvorbis
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-22
Debian has issued an update for libvorbis. This fixes some vulnerabilties, which can be exploited by malicious people to cause a
DoS (Denial of Service) and potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28614/\"]http://secunia.com/advisories/28614/[/url]
--
[SA28612] HP-UX ARPA Transport Unspecified Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-24
A vulnerability has been reported in HP-UX, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28612/\"]http://secunia.com/advisories/28612/[/url]
--
[SA28610] Debian update for exiv2
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-24
Debian has issued an update for exiv2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28610/\"]http://secunia.com/advisories/28610/[/url]
--
[SA28602] Gentoo update for tikiwiki
Critical: Moderately critical
Where: From remote
Impact: Unknown, Cross Site Scripting
Released: 2008-01-24
Gentoo has issued an update for tikiwiki. This fixes some vulnerabilities, where some have unknown impacts and others can be
exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28602/\"]http://secunia.com/advisories/28602/[/url]
--
[SA28583] Red Hat update for wireshark
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-21
Red Hat has issued an update for wireshark. This fixes some
vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28583/\"]http://secunia.com/advisories/28583/[/url]
--
[SA28564] Red Hat update for wireshark
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-21
Red Hat has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28564/\"]http://secunia.com/advisories/28564/[/url]
--
[SA28555] Mandriva update for cairo
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-22
Mandriva has issued an update for cairo. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28555/\"]http://secunia.com/advisories/28555/[/url]
--
[SA28548] Debian update for flac
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-21
Debian has issued an update for flac. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28548/\"]http://secunia.com/advisories/28548/[/url]
--
[SA28546] Debian update for horde3
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data
Released: 2008-01-21
Debian has issued an update for horde3. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions and manipulate data.
Full Advisory:
[url=\"http://secunia.com/advisories/28546/\"]http://secunia.com/advisories/28546/[/url]
--
[SA28607] Avaya Products httpd Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-22
Avaya has acknowledged some vulnerabilities in various Avaya products, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28607/\"]http://secunia.com/advisories/28607/[/url]
--
[SA28591] Fedora update for mantis
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-23
Fedora has issued an update for mantis. This fixes a vulnerability, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28591/\"]http://secunia.com/advisories/28591/[/url]
--
[SA28589] ELOG Script Insertion and Denial of Service Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2008-01-22
Some vulnerabilities have been reported in ELOG, which can be exploited by malicious users to cause a DoS (Denial of Service) and conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28589/\"]http://secunia.com/advisories/28589/[/url]
--
[SA28569] Gentoo update for libcdio
Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-01-21
Gentoo has issued an update for libcdio. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28569/\"]http://secunia.com/advisories/28569/[/url]
--
[SA28551] Debian update for mantis
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information
Released: 2008-01-21
Debian has issued an update for mantis. This fixes a vulnerability, which can be exploited by malicious users to conduct script insertion attacks, and a security issue, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28551/\"]http://secunia.com/advisories/28551/[/url]
--
[SA28549] Debian update for tomcat5.5
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information
Released: 2008-01-21
Debian has issued an update for tomcat5.5. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks, and a security issue, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28549/\"]http://secunia.com/advisories/28549/[/url]
--
[SA28545] Fedora update for boost
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-01-23
Fedora has issued an update for boost. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28545/\"]http://secunia.com/advisories/28545/[/url]
--
[SA28541] Fedora update for e2fsprogs
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-21
Fedora has issued an update for e2fsprogs. This fixes a some vulnerabilities, which potentially can be exploited by malicious people
to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28541/\"]http://secunia.com/advisories/28541/[/url]
--
[SA28643] Red Hat update for kernel
Critical: Less critical
Where: From local network
Impact: Security Bypass, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2008-01-24
Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a Denial of Service (DoS), disclose potentially sensitive information, bypass certain security restrictions, and corrupt a file
system, and by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28643/\"]http://secunia.com/advisories/28643/[/url]
--
[SA28592] Fedora update for xorg-x11-server
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-23
Fedora has issued an update for xorg-x11-server. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28592/\"]http://secunia.com/advisories/28592/[/url]
--
[SA28616] Mandriva update for x11-server-xgl
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-24
Mandriva has issued an update for x11-server-xgl. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28616/\"]http://secunia.com/advisories/28616/[/url]
--
[SA28609] IBM AIX Multiple Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Manipulation of data, Exposure of sensitive information, Privilege escalation
Released: 2008-01-24
Some vulnerabilities have been reported in IBM AIX, which can be exploited by malicious, local users to disclose potentially sensitive information, manipulate certain files, or gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28609/\"]http://secunia.com/advisories/28609/[/url]
--
[SA28571] Mandriva update for libxfont
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-24
Mandriva has issued an update for libxfont. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28571/\"]http://secunia.com/advisories/28571/[/url]
--
[SA28559] rPath update for mysql
Critical: Less critical
Where: Local system
Impact: Manipulation of data
Released: 2008-01-18
rPath has issued an update for mysql. This fixes a vulnerability, which can be exploited by malicious, local users to manipulate certain data.
Full Advisory:
[url=\"http://secunia.com/advisories/28559/\"]http://secunia.com/advisories/28559/[/url]
--
[SA28558] rPath update for kernel
Critical: Less critical
Where: Local system
Impact: Security Bypass, Manipulation of data
Released: 2008-01-18
rPath has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions and corrupt a file system.
Full Advisory:
[url=\"http://secunia.com/advisories/28558/\"]http://secunia.com/advisories/28558/[/url]
--
[SA28550] Sun Solaris X Window System and X Server Multiple
Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-18
Sun has acknowledged some vulnerabilities in Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28550/\"]http://secunia.com/advisories/28550/[/url]
--
[SA28544] Red Hat update for libXfont
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-18
Red Hat has issued an update for libXfont. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28544/\"]http://secunia.com/advisories/28544/[/url]
--
[SA28543] Red Hat update for xorg-x11-server
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-18
Red Hat has issued an update for xorg-x11-server. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information or to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28543/\"]http://secunia.com/advisories/28543/[/url]
--
[SA28542] Red Hat update for XFree86
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-18
Red Hat has issued an update for XFree86. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, or gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28542/\"]http://secunia.com/advisories/28542/[/url]
--
[SA28540] SUSE update for Xorg and XFree
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-18
SUSE has issued an update for Xorg and XFree. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, or gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28540/\"]http://secunia.com/advisories/28540/[/url]
--
[SA28539] Debian update for xorg-server
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-18
Debian has issued an update for xorg-server. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information or to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28539/\"]http://secunia.com/advisories/28539/[/url]
--
[SA28574] Ubuntu update for apt-listchanges
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-21
Ubuntu has issued an update for apt-listchanges. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28574/\"]http://secunia.com/advisories/28574/[/url]
[b]Other:--[/b]
[SA28625] Cisco PIX and ASA Time-To-Live Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-24
Cisco has acknowledged a vulnerability in Cisco PIX and ASA appliances, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28625/\"]http://secunia.com/advisories/28625/[/url]
--
[SA28553] OKI C5510MFP Configuration Interface Security Issues
Critical: Less critical
Where: From local network
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-01-18
Compass Security AG has reported two security issues in OKI C5510MFP, which can be exploited by malicious people to disclose sensitive information and to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28553/\"]http://secunia.com/advisories/28553/[/url]
[b]Cross Platform:--[/b]
[SA28580] phpAutoVideo File Inclusion and Cross-Site Scripting
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-01-21
H-T Team have reported two vulnerabilities in phpAutoVideo, which can be exploited by malicious people to conduct cross-site scripting attacks, disclose sensitive information, or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28580/\"]http://secunia.com/advisories/28580/[/url]
--
[SA28568] Small Axe Weblog linkbar.php File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-01-21
Two vulnerabilities have been reported in Small Axe Weblog, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28568/\"]http://secunia.com/advisories/28568/[/url]
--
[SA28556] HP Oracle for OpenView Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Unknown
Released: 2008-01-18
HP has acknowledged some vulnerabilities with unknown impacts in HP OfO (Oracle for Openview), which can be exploited by malicious users and malicious people.
Full Advisory:
[url=\"http://secunia.com/advisories/28556/\"]http://secunia.com/advisories/28556/[/url]
--
[SA28640] SDL_image Two Buffer Overflow Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-24
Two vulnerabilities have been reported in SDL_image, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28640/\"]http://secunia.com/advisories/28640/[/url]
--
[SA28624] PHP-Nuke "modules/Search/index.php" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-23
Foster & 1dt.w0lf have discovered a vulnerability in PHP-Nuke, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28624/\"]http://secunia.com/advisories/28624/[/url]
--
[SA28619] Liquid-Silver CMS "update" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-01-24
Stack-Terrorist has discovered a vulnerability in Liquid-Silver CMS, which can be exploited by malicious people to disclose sensitive
information.
Full Advisory:
[url=\"http://secunia.com/advisories/28619/\"]http://secunia.com/advisories/28619/[/url]
--
[SA28617] aconon Mail "template" Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information
Released: 2008-01-24
Arno Töll has reported a vulnerability in aconon Mail, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28617/\"]http://secunia.com/advisories/28617/[/url]
--
[SA28606] Interstage HTTP Server Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2008-01-22
Fujitsu has acknowledged some vulnerabilities in Interstage HTTP Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28606/\"]http://secunia.com/advisories/28606/[/url]
--
[SA28605] PacerCMS Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Cross Site Scripting
Released: 2008-01-22
Some vulnerabilities have been reported in PacerCMS, which can be exploited by malicious people to conduct script insertion attacks and by malicious users to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28605/\"]http://secunia.com/advisories/28605/[/url]
--
[SA28594] aflog SQL Injection and Script Insertion Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-01-23
shinmai has discovered some vulnerabilities in aflog, which can be exploited by malicious users to conduct script insertion attacks, and by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28594/\"]http://secunia.com/advisories/28594/[/url]
--
[SA28588] WebSphere Application Server Two Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-01-22
Some vulnerabilities with unknown impact have been reported in WebSphere Application Server.
Full Advisory:
[url=\"http://secunia.com/advisories/28588/\"]http://secunia.com/advisories/28588/[/url]
--
[SA28581] AlstraSoft Forum Pay Per Post Exchange "catid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-22
t0pP8uZz & xprog have reported a vulnerability in AlstraSoft Forum Pay Per Post Exchange, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28581/\"]http://secunia.com/advisories/28581/[/url]
--
[SA28576] IBM WebSphere Application Server serveServletsByClassnameEnabled Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-01-21
A vulnerability has been reported in IBM WebSphere Application Server, which has an unknown impact.
Full Advisory:
[url=\"http://secunia.com/advisories/28576/\"]http://secunia.com/advisories/28576/[/url]
--
[SA28572] MyBB SQL Injection and Cross-Site Request Forgery
Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-01-21
Some vulnerabilities have been reported in MyBB, which can be exploited by malicious users to conduct SQL injection or cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28572/\"]http://secunia.com/advisories/28572/[/url]
--
[SA28567] WordPress WP-Forum Plugin "user" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-21
websec Team have discovered a vulnerability in the WP-Forum plugin for WordPress, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28567/\"]http://secunia.com/advisories/28567/[/url]
--
[SA28566] Famp3 "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-18
IRCRASH has discovered a vulnerability in Famp3, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28566/\"]http://secunia.com/advisories/28566/[/url]
--
[SA28565] FaPersianHack "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-18
IRCRASH has discovered a vulnerability in FaPersianHack, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28565/\"]http://secunia.com/advisories/28565/[/url]
--
[SA28560] Clever Copy SQL Injection and Cross-Site Scripting
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-01-18
hadihadi has discovered some vulnerabilities in Clever Copy, which can be exploited by malicious people to conduct cross-site scripting attacks and SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28560/\"]http://secunia.com/advisories/28560/[/url]
--
[SA28547] Openfire Jetty Information Disclosure Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-01-18
A vulnerability has been reported in Openfire, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28547/\"]http://secunia.com/advisories/28547/[/url]
--
[SA28562] AXIGEN Mail Server AXIMilter Format String Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-01-21
hempel has discovered a vulnerability in the AXIGEN Mail Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28562/\"]http://secunia.com/advisories/28562/[/url]
--
[SA28633] Drupal Workflow Module Workflow Message Script Insertion
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-24
A vulnerability has been reported in the Workflow module for Drupal, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28633/\"]http://secunia.com/advisories/28633/[/url]
--
[SA28632] Drupal Archive Module Unspecified Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-24
Some vulnerabilities have been reported in the Archive module for Drupal, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28632/\"]http://secunia.com/advisories/28632/[/url]
--
[SA28629] MediaWiki Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-24
A vulnerability has been reported in MediaWiki, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28629/\"]http://secunia.com/advisories/28629/[/url]
--
[SA28622] Mozilla Firefox "chrome:" Directory Traversal Security Issue
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-24
Gerry Eisenhaur has discovered a security issue in Mozilla Firefox, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28622/\"]http://secunia.com/advisories/28622/[/url]
--
[SA28593] WordPress Permalinks Migration Plugin Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-24
g30rg3_x has discovered a vulnerability in the Permalinks Migration plugin for WordPress, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28593/\"]http://secunia.com/advisories/28593/[/url]
--
[SA28582] OZJournals "id" Information Disclosure Vulnerability
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-01-22
shinmai has discovered a vulnerability in OZJournals, which can be exploited by malicious people to disclose potentially sensitive
information.
Full Advisory:
[url=\"http://secunia.com/advisories/28582/\"]http://secunia.com/advisories/28582/[/url]
--
[SA28579] ISC BIND libbind "inet_network()" Off-By-One Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-21
A vulnerability has been reported in ISC BIND, which can be exploited by malicious people to cause a DoS (Denial of Service) or to
potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28579/\"]http://secunia.com/advisories/28579/[/url]
--
[SA28577] Mantis "Most Active" Script Insertion Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-21
A vulnerability has been reported in Mantis, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28577/\"]http://secunia.com/advisories/28577/[/url]
--
[SA28573] singapore "gallery" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-21
Rubén Ventura Piña has discovered a vulnerability in singapore, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28573/\"]http://secunia.com/advisories/28573/[/url]
--
[SA28561] cPanel Leech Protect "rurl" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-18
Aria-Security Team have reported a vulnerability in cPanel, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28561/\"]http://secunia.com/advisories/28561/[/url]
--
[SA28604] IBM Tivoli Provisioning Manager for OS Deployment HTTP Server Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-01-22
A vulnerability has been reported in IBM Tivoli Provisioning Manager for OS Deployment, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28604/\"]http://secunia.com/advisories/28604/[/url]
--
[SA28603] IBM Tivoli Business Service Manager Password Disclosure
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-01-22
Some security issues have been reported in IBM Tivoli Business Service Manager, which potentially can be exploited by malicious, local users to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28603/\"]http://secunia.com/advisories/28603/[/url]
--
[SA28613] Kayako SupportSuite "syncml/index.php" Information Disclosure
Critical: Not critical
Where: From remote
Impact: Exposure of system information
Released: 2008-01-22
Janek Vind has reported a vulnerability in Kayako SupportSuite, which can be exploited by malicious people to disclose system information.
Full Advisory:
[url=\"http://secunia.com/advisories/28613/\"]http://secunia.com/advisories/28613/[/url]
--
[SA28552] Apache Tomcat SingleSignOn Information Disclosure
Critical: Not critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2008-01-21
A security issue has been reported in Apache Tomcat, which can be exploited by malicious people to disclose potentially sensitive
information.
Full Advisory:
[url=\"http://secunia.com/advisories/28552/\"]http://secunia.com/advisories/28552/[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
