[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of May 2 2008[/b][/i]
[b]Windows:--[/b]
[SA30037] Akamai Download Manager Code Execution Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-01
A vulnerability has been reported in Akamai Download Manager, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30037/\"]http://secunia.com/advisories/30037/[/url]
--
[SA29990] E-Post Mail Server POP3 Password Disclosure Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-04-28
Tan Chew Keong has reported a vulnerability in E-Post Mail Server, which can be exploited by malicious people to disclose sensitive
information.
Full Advisory:
[url=\"http://secunia.com/advisories/29990/\"]http://secunia.com/advisories/29990/[/url]
--
[SA29979] MegaBBS SQL Injection and Cross-Site Scripting Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-04-28
AmnPardaz Security Research Team have reported some vulnerabilities in MegaBBS, which can be exploited by malicious users to conduct SQL injection attacks and by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29979/\"]http://secunia.com/advisories/29979/[/url]
--
[SA30036] SNMPc "SNMP TRAP" Packet Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-05-01
Wade Alcorn and John Heasman have reported a vulnerability in SNMPc, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30036/\"]http://secunia.com/advisories/30036/[/url]
--
[SA30007] Rising Antivirus "NtOpenProcess()" Hooked Function Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-04-29
Core Security Technologies has reported a vulnerability in Rising Antivirus, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30007/\"]http://secunia.com/advisories/30007/[/url]
--
[SA30006] Comodo Firewall Pro Hooked Functions Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-04-29
Core Security Technologies has reported some vulnerabilities in Comodo Firewall Pro, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30006/\"]http://secunia.com/advisories/30006/[/url]
--
[SA30005] BitDefender Antivirus 2008 "NtOpenProcess()" Hooked Function Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-04-29
Core Security Technologies has reported a vulnerability in BitDefender Antivirus 2008, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30005/\"]http://secunia.com/advisories/30005/[/url]
--
[SA29996] Sophos Anti-Virus "NtCreateKey()" Hooked Function Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-04-29
Core Security Technologies has reported a vulnerability in Sophos Anti-Virus, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29996/\"]http://secunia.com/advisories/29996/[/url]
[b]UNIX/Linux:--[/b]
[SA30033] Fedora update for poppler
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-30
Fedora has issued an update for poppler. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30033/\"]http://secunia.com/advisories/30033/[/url]
--
[SA30029] Red Hat update for thunderbird
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-01
Red Hat has issued an update for thunderbird. This fixes a vulnerability, which can potentially be exploited by malicious people
to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30029/\"]http://secunia.com/advisories/30029/[/url]
--
[SA30021] Fedora update for xine-lib
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-30
Fedora has issued an update for xine-lib. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30021/\"]http://secunia.com/advisories/30021/[/url]
--
[SA30020] GNOME PeerCast "HTTP::getAuthUserPass()" Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-30
Nico Golde has reported a vulnerability in GNOME PeerCast, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30020/\"]http://secunia.com/advisories/30020/[/url]
--
[SA30012] Debian update for iceape
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-29
Debian has issued an update for iceape. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30012/\"]http://secunia.com/advisories/30012/[/url]
--
[SA30003] Red Hat update for java-1.5.0-bea
Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-04-28
Red Hat has issued an update for java-1.5.0-bea. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), or compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30003/\"]http://secunia.com/advisories/30003/[/url]
--
[SA30001] Fedora update for KDE4
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-30
Fedora has issued an update for KDE4. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30001/\"]http://secunia.com/advisories/30001/[/url]
--
[SA29999] Red Hat update for java-1.4.2-bea
Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-04-28
Red Hat has issued an update for java-1.4.2-bea. This fixes a vulnerability, which can be exploited by malicious people to bypass
certain security restrictions and potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29999/\"]http://secunia.com/advisories/29999/[/url]
--
[SA29994] Fedora update for wordpress
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, System access
Released: 2008-04-30
Fedora has issued an update for wordpress. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting attacks, bypass certain security restrictions, and to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29994/\"]http://secunia.com/advisories/29994/[/url]
--
[SA29980] KDE KHTML PNG Processing Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-28
A vulnerability has been reported in KDE, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29980/\"]http://secunia.com/advisories/29980/[/url]
--
[SA30032] Fedora update for squid
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-04-30
Fedora has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30032/\"]http://secunia.com/advisories/30032/[/url]
--
[SA30031] Fedora update for moin
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-04-30
Fedora has issued an update for moin. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks and bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30031/\"]http://secunia.com/advisories/30031/[/url]
--
[SA30030] Fedora update for perl-Imager
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-30
Fedora has issued an update for perl-Imager. This fixes a vulnerability, which potentially can be exploited by malicious people
to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30030/\"]http://secunia.com/advisories/30030/[/url]
--
[SA30025] Fedora update for perl
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-30
Fedora has issued an update for perl. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30025/\"]http://secunia.com/advisories/30025/[/url]
--
[SA30023] Fedora update for lighttpd
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-04-30
Fedora has issued an update for lighttpd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30023/\"]http://secunia.com/advisories/30023/[/url]
--
[SA30011] Imager Image-Based Fill Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-29
A vulnerability has been reported in Imager, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30011/\"]http://secunia.com/advisories/30011/[/url]
--
[SA30009] Slackware update for libpng
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-04-29
Slackware has issued an update for libpng. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose potentially sensitive information, or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30009/\"]http://secunia.com/advisories/30009/[/url]
--
[SA29995] ZoneMinder Unspecified Code Execution Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-04-28
Some vulnerabilities have been reported in ZoneMinder, which potentially can be exploited by malicious users to compromise a
vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29995/\"]http://secunia.com/advisories/29995/[/url]
--
[SA29992] rPath update for libpng
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-04-30
rPath has issued an update for libpng. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose potentially sensitive information, or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/29992/\"]http://secunia.com/advisories/29992/[/url]
--
[SA29984] Fedora update for dbmail
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-04-30
Fedora has issued an update for dbmail. This fixes a vulnerability,
which can be exploited by malicious people to bypass certain security
restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29984/\"]http://secunia.com/advisories/29984/[/url]
--
[SA29976] IBM WebSphere Application Server Java Plugin Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-05-01
A vulnerability has been reported in IBM WebSphere Application Server, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29976/\"]http://secunia.com/advisories/29976/[/url]
--
[SA29986] HP-UX WBEM Services OpenPegasus PAM Module Buffer Overflows
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-04-30
HP has acknowledged some vulnerabilities in HP-UX, which can potentially be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29986/\"]http://secunia.com/advisories/29986/[/url]
--
[SA30027] cPanel Cross-Site Request Forgery Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-01
Some vulnerabilities have been reported in cPanel, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30027/\"]http://secunia.com/advisories/30027/[/url]
--
[SA30013] Debian update for wordpress
Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-05-02
Debian has issued an update for wordpress. This fixes a vulnerability, which can potentially be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30013/\"]http://secunia.com/advisories/30013/[/url]
--
[SA30004] miniBB "whatus" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-29
IRCRASH has discovered a vulnerability in miniBB, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30004/\"]http://secunia.com/advisories/30004/[/url]
--
[SA29988] Sun Solaris Apache Modules Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-28
Sun has acknowledged some vulnerabilities in Solaris, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29988/\"]http://secunia.com/advisories/29988/[/url]
--
[SA30042] Debian update for asterisk
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-05-01
Debian has issued an update for asterisk. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30042/\"]http://secunia.com/advisories/30042/[/url]
--
[SA30010] Fedora update for asterisk
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-04-30
Fedora has issued an update for asterisk. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30010/\"]http://secunia.com/advisories/30010/[/url]
--
[SA30044] Linux Kernel Multiple Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-05-02
Some vulnerabilities have been reported in the Linux kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to potentially gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30044/\"]http://secunia.com/advisories/30044/[/url]
--
[SA30018] Debian update for kernel
Critical: Less critical
Where: Local system
Impact: Security Bypass, Privilege escalation, DoS
Released: 2008-05-02
Debian has issued an update for the kernel. This fixes some vulnerabilities and security issues, which can be exploited by
malicious, local users to bypass certain security restrictions, cause a DoS (Denial of Service), or to potentially gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30018/\"]http://secunia.com/advisories/30018/[/url]
--
[SA29977] Gentoo update for kde
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-04-29
Gentoo has issued an update for kdelibs. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to potentially gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29977/\"]http://secunia.com/advisories/29977/[/url]
--
[SA30014] util-linux-ng "login" Audit Log Injection Weakness
Critical: Not critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-29
A weakness has been reported in util-linux-ng, which can be exploited by malicious people to manipulate certain data.
Full Advisory:
[url=\"http://secunia.com/advisories/30014/\"]http://secunia.com/advisories/30014/[/url]
--
[SA30008] GraphicsMagick Insecure File Extension Processing
Critical: Not critical
Where: From remote
Impact: Security Bypass
Released: 2008-05-02
A security issue has been reported in GraphicsMagick, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30008/\"]http://secunia.com/advisories/30008/[/url]
--
[SA29982] Fedora update for util-linux-ng
Critical: Not critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-30
Fedora has issued an update for util-linux-ng. This fixes a weakness, which can be exploited by malicious people to manipulate certain data.
Full Advisory:
[url=\"http://secunia.com/advisories/29982/\"]http://secunia.com/advisories/29982/[/url]
[b]Other:--[/b]
[SA30054] ALAXALA Networks AX Series BGP UPDATE Message Processing
Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-05-02
A vulnerability has been reported in ALAXALA Networks AX series, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30054/\"]http://secunia.com/advisories/30054/[/url]
--
[SA30038] Nortel Multimedia Communication Server PC Client Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-05-01
A vulnerability has been reported in Nortel Multimedia Communication Server (MCS), which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30038/\"]http://secunia.com/advisories/30038/[/url]
--
[SA30028] Hitachi GR Series BGP UPDATE Message Processing Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-05-02
A vulnerability has been reported in Hitachi GR series routers, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30028/\"]http://secunia.com/advisories/30028/[/url]
--
[SA30026] Motorola Surfboard Cable Modem Web Interface Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-30
Rook Security has reported a vulnerability in Motorola Surfboard Cable Modem, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30026/\"]http://secunia.com/advisories/30026/[/url]
[b]Cross Platform:--[/b]
[SA30022] Harris WapChat Multiple File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-05-02
k1n9k0ng has discovered some vulnerabilities in Harris WapChat, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30022/\"]http://secunia.com/advisories/30022/[/url]
--
[SA29989] PhpGedView Unspecified Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-29
A vulnerability has been reported in PhpGedView, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29989/\"]http://secunia.com/advisories/29989/[/url]
--
[SA29987] Sun StarOffice/StarSuite Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-28
Sun has acknowledged some vulnerabilities in Sun StarOffice and StarSuite, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29987/\"]http://secunia.com/advisories/29987/[/url]
--
[SA29978] Sun Java System Directory Server "bind-dn" Security Bypass
Critical: Highly critical
Where: From remote
Impact: Security Bypass
Released: 2008-04-28
Sun has acknowledged a vulnerability in Sun Java System Directory Server, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29978/\"]http://secunia.com/advisories/29978/[/url]
--
[SA30052] ActualAnalyzer Lite "style" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-05-02
IRCRASH has discovered a vulnerability in ActualAnalyzer, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30052/\"]http://secunia.com/advisories/30052/[/url]
--
[SA30048] PHP Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass, DoS, System access
Released: 2008-05-02
Some vulnerabilities have been reported in PHP, where some have unknown impacts and others can be exploited by malicious users to bypass certain security restrictions, and potentially by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30048/\"]http://secunia.com/advisories/30048/[/url]
--
[SA30046] vlbook Cross-Site Scripting and Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-05-02
IRCRASH has reported two vulnerabilities in vlbook, which can be exploited by malicious people to conduct cross-site scripting attacks or disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30046/\"]http://secunia.com/advisories/30046/[/url]
--
[SA30043] Robocode AWT Event Queue Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-05-02
A security issue has been reported in Robocode, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30043/\"]http://secunia.com/advisories/30043/[/url]
--
[SA30015] Project-Based Calendaring System File Disclosure Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-05-01
GoLd_M has discovered some vulnerabilities in Project-Based Calendaring System, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30015/\"]http://secunia.com/advisories/30015/[/url]
--
[SA29997] miniBB Cross-Site Scripting and SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-04-28
__GiReX__ has reported some vulnerabilities in miniBB, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29997/\"]http://secunia.com/advisories/29997/[/url]
--
[SA29991] Joovili "category" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-29
HaCkeR-EgY has reported a vulnerability in Joovili, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29991/\"]http://secunia.com/advisories/29991/[/url]
--
[SA29985] WebGUI Data Form List View Unspecified Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-05-02
A vulnerability with an unknown impact has been reported in WebGUI.
Full Advisory:
[url=\"http://secunia.com/advisories/29985/\"]http://secunia.com/advisories/29985/[/url]
--
[SA29983] Softbiz Web Host Directory Script "host_id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-30
M.Hasran Addahroni has reported a vulnerability in Softbiz Web Host Directory Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29983/\"]http://secunia.com/advisories/29983/[/url]
--
[SA29981] Jokes Site Script "catagorie" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-29
ProgenTR has reported a vulnerability in Jokes Site Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29981/\"]http://secunia.com/advisories/29981/[/url]
--
[SA30049] Mjguest "level" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-02
IRCRASH has discovered a vulnerability in Mjguest, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30049/\"]http://secunia.com/advisories/30049/[/url]
--
[SA30002] Sugar Community Edition RSS Module Information Disclosure Vulnerability
Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-04-29
Roberto Suggi Liverani has reported a vulnerability in Sugar Community Edition, which can be exploited by malicious users to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30002/\"]http://secunia.com/advisories/30002/[/url]
--
[SA29993] XOOPS Various Bluemoon inc. Modules Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-28
Some vulnerabilities have been reported in various Bluemoon inc. modules for XOOPS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29993/\"]http://secunia.com/advisories/29993/[/url]
Secunia Security Updates - May 2008
Moderators: Moderator, Global Moderator
Secunia Security Updates - May 2008

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Secunia Security Updates - May 2008
[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of May 8 2008[/b][/i]
[b]Windows:--[/b]
[SA30127] PostcardMentor "cat_fldAuto" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-08
InjEctOr5 has reported a vulnerability in PostcardMentor, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30127/\"]http://secunia.com/advisories/30127/[/url]
--
[SA30103] fipsCMS "lg" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-08
InjEctOr has reported a vulnerability in fipsCMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30103/\"]http://secunia.com/advisories/30103/[/url]
--
[SA30128] SAP Internet Transaction Server wgate.dll Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-08
A vulnerability has been reported in SAP Internet Transaction Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30128/\"]http://secunia.com/advisories/30128/[/url]
--
[SA30074] SysAid "searchField" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-05
Yogesh Kulkarni has discovered a vulnerability in SysAid, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30074/\"]http://secunia.com/advisories/30074/[/url]
--
[SA30063] Invensys Wonderware InTouch SuiteLink Service Denial of
Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-05-06
Core Security Technologies has reported a vulnerability in Invensys Wonderware InTouch, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30063/\"]http://secunia.com/advisories/30063/[/url]
[b]UNIX/Linux:--[/b]
[SA30124] NetBSD update for OpenSSL
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-08
NetBSD has issued an update for OpenSSL. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) and compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30124/\"]http://secunia.com/advisories/30124/[/url]
--
[SA30105] Ubuntu update for thunderbird
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, System access
Released: 2008-05-07
Ubuntu has issued an update for thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, conduct cross-site scripting attacks, or potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30105/\"]http://secunia.com/advisories/30105/[/url]
--
[SA30100] Ubuntu update for openoffice.org
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-07
Ubuntu has issued an update for openoffice.org. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30100/\"]http://secunia.com/advisories/30100/[/url]
--
[SA30073] Gentoo update for egroupware
Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-05-08
Gentoo has issued an update for egroupware. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions and compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30073/\"]http://secunia.com/advisories/30073/[/url]
--
[SA30129] Sun Solaris Tk GIF Processing Buffer Overflow Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-08
Sun has acknowledged some vulnerabilities in the Tcl GUI Toolkit Library included in Solaris, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30129/\"]http://secunia.com/advisories/30129/[/url]
--
[SA30118] rdesktop Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-05-08
Some vulnerabilities have been reported in rdesktop, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30118/\"]http://secunia.com/advisories/30118/[/url]
--
[SA30106] Debian update for kazehakase
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-05-07
Debian has issued an update for kazehakase. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service), disclose potentially sensitive information, and compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30106/\"]http://secunia.com/advisories/30106/[/url]
--
[SA30097] Debian update for blender
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-05-06
Debian has issued an update for blender. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30097/\"]http://secunia.com/advisories/30097/[/url]
--
[SA30095] SIPp Two Buffer Overflow Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-06
Two vulnerabilities have been reported in SIPp, which can be exploited by malicious people to cause a DoS (Denial of Service) or to
potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30095/\"]http://secunia.com/advisories/30095/[/url]
--
[SA30090] Online Rental Property Script "pid" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-05-06
M.Hasran Addahroni has reported a vulnerability in Online Rental Property Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30090/\"]http://secunia.com/advisories/30090/[/url]
--
[SA30078] Ubuntu update for cups
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-05-06
Ubuntu has issued an update for cups. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30078/\"]http://secunia.com/advisories/30078/[/url]
--
[SA30131] Sun Solaris TCP Implementation SYN Flood Denial of Service
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-05-08
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30131/\"]http://secunia.com/advisories/30131/[/url]
--
[SA30130] Sun Ray Server Software Kiosk Mode Vulnerability
Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-05-08
A vulnerability has been reported in Sun Ray Server Software, which can be exploited by malicious users to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30130/\"]http://secunia.com/advisories/30130/[/url]
--
[SA30080] ChiCoMaS "q" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-05
Hadi Kiamarsi has discovered a vulnerability in ChiCoMaS, which can be exploited by malicious people to conduct cross site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30080/\"]http://secunia.com/advisories/30080/[/url]
--
[SA30112] Red Hat update for kernel
Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-05-07
Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service), and by malicious, local users to cause a DoS, disclose potentially sensitive information, or gain escalated
privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30112/\"]http://secunia.com/advisories/30112/[/url]
--
[SA30099] Ubuntu update for ldm
Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-05-07
Ubuntu has issued an update for ldm. This fixes a security issue, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30099/\"]http://secunia.com/advisories/30099/[/url]
--
[SA30132] HP-UX LDAP-UX Privilege Escalation Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-05-08
A vulnerability has been reported in HP-UX, which can be exploited by
malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30132/\"]http://secunia.com/advisories/30132/[/url]
--
[SA30116] Red Hat update for kernel
Critical: Less critical
Where: Local system
Impact: Exposure of system information, Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-05-07
Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, or gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30116/\"]http://secunia.com/advisories/30116/[/url]
--
[SA30114] HP-UX update for Netscape Directory Server
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-05-07
HP-UX has issued an update for Netscape Directory Server (NDS). This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30114/\"]http://secunia.com/advisories/30114/[/url]
--
[SA30113] Ubuntu update for kdelibs
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-05-07
Ubuntu has issued an update for kdelibs. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to potentially gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30113/\"]http://secunia.com/advisories/30113/[/url]
--
[SA30111] QEMU "drive_init()" Disk Format Security Bypass
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-05-08
A vulnerability has been reported in QEMU, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30111/\"]http://secunia.com/advisories/30111/[/url]
--
[SA30110] Red Hat update for kernel
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-05-07
Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, or gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30110/\"]http://secunia.com/advisories/30110/[/url]
--
[SA30109] Ubuntu update for emacs
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-05-07
Ubuntu has issued an update for emacs. This fixes some security issues, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30109/\"]http://secunia.com/advisories/30109/[/url]
--
[SA30108] Linux Kernel Multiple Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-05-07
Some vulnerabilities have been reported in the Linux kernel, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30108/\"]http://secunia.com/advisories/30108/[/url]
--
[SA30086] Sun Solaris SSH X11 Forwarding Vulnerability
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation
Released: 2008-05-07
Sun has acknowledged a vulnerability in SSH included in Sun Solaris, which can be exploited by malicious, local users to disclose sensitive information or potentially perform actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30086/\"]http://secunia.com/advisories/30086/[/url]
--
[SA30093] Debian update for b2evolution
Critical: Not critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-06
Debian has issued an update for b2evolution. This fixes a vulnerability, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30093/\"]http://secunia.com/advisories/30093/[/url]
--
[SA30101] Linux Kernel "fcntl_setlk()" SMP Reordered Access Vulnerability
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-05-07
A vulnerability has been reported in the Linux kernel, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30101/\"]http://secunia.com/advisories/30101/[/url]
--
[SA30077] rPath update for kernel
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-05-08
rPath has issued an update for the kernel. This can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30077/\"]http://secunia.com/advisories/30077/[/url]
[b]Cross Platform:--[/b]
[SA30059] ITCms Arbitrary PHP Code Execution Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-06
Cod3rZ has reported a vulnerability in ITCms, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30059/\"]http://secunia.com/advisories/30059/[/url]
--
[SA30123] Galleristic "cat" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-08
cOndemned has discovered a vulnerability in Galleristic, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30123/\"]http://secunia.com/advisories/30123/[/url]
--
[SA30122] Sun Java System Web Server / Application Server JSP Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-05-08
Sun has acknowledged a vulnerability in Sun Java System Web Server and Sun Java System Application Server, which can be exploited by malicious people to disclose certain sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30122/\"]http://secunia.com/advisories/30122/[/url]
--
[SA30107] Musicbox "artistId" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-08
HaCkeR-EgY has reported a vulnerability in Musicbox, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30107/\"]http://secunia.com/advisories/30107/[/url]
--
[SA30091] mvnForum "QuickReply" Script Insertion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-08
Christian Holler has reported a vulnerability in mvnForum, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30091/\"]http://secunia.com/advisories/30091/[/url]
--
[SA30089] Auction XL "viewfaqs.php" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-06
M.Hasran Addahroni has reported a vulnerability in Auction XL, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30089/\"]http://secunia.com/advisories/30089/[/url]
--
[SA30085] Miniweb "historymonth" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-06
HaCkeR-EgY has reported a vulnerability in Miniweb, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30085/\"]http://secunia.com/advisories/30085/[/url]
--
[SA30084] DeluxeBB SQL Injection and PHP Code Execution
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, System access
Released: 2008-05-06
EgiX has discovered two vulnerabilities in DeluxeBB, which can be exploited by malicious users to compromise a vulnerable system and by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30084/\"]http://secunia.com/advisories/30084/[/url]
--
[SA30076] PHPEasyData "cat_id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-05-07
InjEctOr and ToTaL have discovered a vulnerability in PHPEasyData, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30076/\"]http://secunia.com/advisories/30076/[/url]
--
[SA30069] Maian Greetings Cross-Site Scripting and SQL Injection
Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-05-08
Khashayar Fereidani has reported some vulnerabilities in Maian Greetings, which can be exploited by malicious people to conduct
cross-site scripting or SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30069/\"]http://secunia.com/advisories/30069/[/url]
--
[SA30061] Nuke ET Security Bypass and Script Insertion Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-05-07
mrzayas has reported some vulnerabilities in Nuke ET, which can be exploited by malicious people to bypass certain security restrictions or conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30061/\"]http://secunia.com/advisories/30061/[/url]
--
[SA30058] BlogMe PHP "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-05
His0k4 has discovered a vulnerability in BlogMe PHP, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30058/\"]http://secunia.com/advisories/30058/[/url]
--
[SA30057] SMartBlog Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-05-05
Some vulnerabilities have been discovered in SMartBlog, which can be exploited by malicious people to disclose potentially sensitive information and conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30057/\"]http://secunia.com/advisories/30057/[/url]
--
[SA30056] phpDirectorySource SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of sensitive information
Released: 2008-05-05
InjEctOr and FishEr762 have discovered two vulnerabilities in phpDirectorySource, which can be exploited by malicious people to
conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30056/\"]http://secunia.com/advisories/30056/[/url]
--
[SA30133] Sun Java System Web Server Search Module Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-08
Sun has acknowledged a vulnerability in Sun Java System Web Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30133/\"]http://secunia.com/advisories/30133/[/url]
--
[SA30121] Tux CMS Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-08
Hadi Kiamarsi has discovered some vulnerabilities in Tux CMS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30121/\"]http://secunia.com/advisories/30121/[/url]
--
[SA30098] CMS Faethon "what" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-08
RoMaNcYxHaCkEr has discovered a vulnerability in CMS Faethon, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30098/\"]http://secunia.com/advisories/30098/[/url]
--
[SA30092] LifeType "newBlogUserName" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-06
Khashayar Fereidani has discovered a vulnerability in LifeType, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30092/\"]http://secunia.com/advisories/30092/[/url]
--
[SA30082] Sphider Suggestion Feature "query" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-08
Christian Holler has reported a vulnerability in Sphider, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30082/\"]http://secunia.com/advisories/30082/[/url]
--
[SA30079] TYPO3 powermail Extension Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-05
A vulnerability has been reported in the powermail extension for TYPO3, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30079/\"]http://secunia.com/advisories/30079/[/url]
--
[SA30075] LifeType "searchTerms" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-05
IRCRASH has reported a vulnerability in LifeType, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30075/\"]http://secunia.com/advisories/30075/[/url]
--
[SA30070] Maian Gallery "keywords" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-08
Khashayar Fereidani has reported a vulnerability in Maian Gallery, which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30070/\"]http://secunia.com/advisories/30070/[/url]
--
[SA30068] Maian Support Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-08
Khashayar Fereidani has discovered some vulnerabilities in Maian Support, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30068/\"]http://secunia.com/advisories/30068/[/url]
--
[SA30065] Maian Links Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-08
Khashayar Fereidani has discovered some vulnerabilities in Maian Links, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30065/\"]http://secunia.com/advisories/30065/[/url]
--
[SA30064] Bugzilla Security Bypass and Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-05-05
Some vulnerabilities have been reported in Bugzilla, which can be exploited by malicious users to bypass certain security restrictions or by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30064/\"]http://secunia.com/advisories/30064/[/url]
--
[SA30062] Zomplog "catname" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-05
Khashayar Fereidani has discovered a vulnerability in Zomplog, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30062/\"]http://secunia.com/advisories/30062/[/url]
--
[SA30060] Maian Weblog Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-07
Khashayar Fereidani has discovered some vulnerabilities in Maian Weblog, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30060/\"]http://secunia.com/advisories/30060/[/url]
--
[SA30081] IBM Rational Build Forge Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-05-05
A vulnerability has been reported in IBM Rational Build Forge, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30081/\"]http://secunia.com/advisories/30081/[/url]
--
[SA30134] MySQL MyISAM Table Privilege Check Bypass
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-05-08
A security issue has been reported in MySQL, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30134/\"]http://secunia.com/advisories/30134/[/url]
[b]Windows:--[/b]
[SA30127] PostcardMentor "cat_fldAuto" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-08
InjEctOr5 has reported a vulnerability in PostcardMentor, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30127/\"]http://secunia.com/advisories/30127/[/url]
--
[SA30103] fipsCMS "lg" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-08
InjEctOr has reported a vulnerability in fipsCMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30103/\"]http://secunia.com/advisories/30103/[/url]
--
[SA30128] SAP Internet Transaction Server wgate.dll Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-08
A vulnerability has been reported in SAP Internet Transaction Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30128/\"]http://secunia.com/advisories/30128/[/url]
--
[SA30074] SysAid "searchField" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-05
Yogesh Kulkarni has discovered a vulnerability in SysAid, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30074/\"]http://secunia.com/advisories/30074/[/url]
--
[SA30063] Invensys Wonderware InTouch SuiteLink Service Denial of
Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-05-06
Core Security Technologies has reported a vulnerability in Invensys Wonderware InTouch, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30063/\"]http://secunia.com/advisories/30063/[/url]
[b]UNIX/Linux:--[/b]
[SA30124] NetBSD update for OpenSSL
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-08
NetBSD has issued an update for OpenSSL. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) and compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30124/\"]http://secunia.com/advisories/30124/[/url]
--
[SA30105] Ubuntu update for thunderbird
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, System access
Released: 2008-05-07
Ubuntu has issued an update for thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, conduct cross-site scripting attacks, or potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30105/\"]http://secunia.com/advisories/30105/[/url]
--
[SA30100] Ubuntu update for openoffice.org
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-07
Ubuntu has issued an update for openoffice.org. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30100/\"]http://secunia.com/advisories/30100/[/url]
--
[SA30073] Gentoo update for egroupware
Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-05-08
Gentoo has issued an update for egroupware. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions and compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30073/\"]http://secunia.com/advisories/30073/[/url]
--
[SA30129] Sun Solaris Tk GIF Processing Buffer Overflow Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-08
Sun has acknowledged some vulnerabilities in the Tcl GUI Toolkit Library included in Solaris, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30129/\"]http://secunia.com/advisories/30129/[/url]
--
[SA30118] rdesktop Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-05-08
Some vulnerabilities have been reported in rdesktop, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30118/\"]http://secunia.com/advisories/30118/[/url]
--
[SA30106] Debian update for kazehakase
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-05-07
Debian has issued an update for kazehakase. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service), disclose potentially sensitive information, and compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30106/\"]http://secunia.com/advisories/30106/[/url]
--
[SA30097] Debian update for blender
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-05-06
Debian has issued an update for blender. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30097/\"]http://secunia.com/advisories/30097/[/url]
--
[SA30095] SIPp Two Buffer Overflow Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-06
Two vulnerabilities have been reported in SIPp, which can be exploited by malicious people to cause a DoS (Denial of Service) or to
potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30095/\"]http://secunia.com/advisories/30095/[/url]
--
[SA30090] Online Rental Property Script "pid" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-05-06
M.Hasran Addahroni has reported a vulnerability in Online Rental Property Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30090/\"]http://secunia.com/advisories/30090/[/url]
--
[SA30078] Ubuntu update for cups
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-05-06
Ubuntu has issued an update for cups. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30078/\"]http://secunia.com/advisories/30078/[/url]
--
[SA30131] Sun Solaris TCP Implementation SYN Flood Denial of Service
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-05-08
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30131/\"]http://secunia.com/advisories/30131/[/url]
--
[SA30130] Sun Ray Server Software Kiosk Mode Vulnerability
Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-05-08
A vulnerability has been reported in Sun Ray Server Software, which can be exploited by malicious users to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30130/\"]http://secunia.com/advisories/30130/[/url]
--
[SA30080] ChiCoMaS "q" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-05
Hadi Kiamarsi has discovered a vulnerability in ChiCoMaS, which can be exploited by malicious people to conduct cross site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30080/\"]http://secunia.com/advisories/30080/[/url]
--
[SA30112] Red Hat update for kernel
Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-05-07
Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service), and by malicious, local users to cause a DoS, disclose potentially sensitive information, or gain escalated
privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30112/\"]http://secunia.com/advisories/30112/[/url]
--
[SA30099] Ubuntu update for ldm
Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-05-07
Ubuntu has issued an update for ldm. This fixes a security issue, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30099/\"]http://secunia.com/advisories/30099/[/url]
--
[SA30132] HP-UX LDAP-UX Privilege Escalation Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-05-08
A vulnerability has been reported in HP-UX, which can be exploited by
malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30132/\"]http://secunia.com/advisories/30132/[/url]
--
[SA30116] Red Hat update for kernel
Critical: Less critical
Where: Local system
Impact: Exposure of system information, Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-05-07
Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, or gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30116/\"]http://secunia.com/advisories/30116/[/url]
--
[SA30114] HP-UX update for Netscape Directory Server
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-05-07
HP-UX has issued an update for Netscape Directory Server (NDS). This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30114/\"]http://secunia.com/advisories/30114/[/url]
--
[SA30113] Ubuntu update for kdelibs
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-05-07
Ubuntu has issued an update for kdelibs. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to potentially gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30113/\"]http://secunia.com/advisories/30113/[/url]
--
[SA30111] QEMU "drive_init()" Disk Format Security Bypass
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-05-08
A vulnerability has been reported in QEMU, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30111/\"]http://secunia.com/advisories/30111/[/url]
--
[SA30110] Red Hat update for kernel
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-05-07
Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, or gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30110/\"]http://secunia.com/advisories/30110/[/url]
--
[SA30109] Ubuntu update for emacs
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-05-07
Ubuntu has issued an update for emacs. This fixes some security issues, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30109/\"]http://secunia.com/advisories/30109/[/url]
--
[SA30108] Linux Kernel Multiple Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-05-07
Some vulnerabilities have been reported in the Linux kernel, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30108/\"]http://secunia.com/advisories/30108/[/url]
--
[SA30086] Sun Solaris SSH X11 Forwarding Vulnerability
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation
Released: 2008-05-07
Sun has acknowledged a vulnerability in SSH included in Sun Solaris, which can be exploited by malicious, local users to disclose sensitive information or potentially perform actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30086/\"]http://secunia.com/advisories/30086/[/url]
--
[SA30093] Debian update for b2evolution
Critical: Not critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-06
Debian has issued an update for b2evolution. This fixes a vulnerability, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30093/\"]http://secunia.com/advisories/30093/[/url]
--
[SA30101] Linux Kernel "fcntl_setlk()" SMP Reordered Access Vulnerability
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-05-07
A vulnerability has been reported in the Linux kernel, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30101/\"]http://secunia.com/advisories/30101/[/url]
--
[SA30077] rPath update for kernel
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-05-08
rPath has issued an update for the kernel. This can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30077/\"]http://secunia.com/advisories/30077/[/url]
[b]Cross Platform:--[/b]
[SA30059] ITCms Arbitrary PHP Code Execution Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-06
Cod3rZ has reported a vulnerability in ITCms, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30059/\"]http://secunia.com/advisories/30059/[/url]
--
[SA30123] Galleristic "cat" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-08
cOndemned has discovered a vulnerability in Galleristic, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30123/\"]http://secunia.com/advisories/30123/[/url]
--
[SA30122] Sun Java System Web Server / Application Server JSP Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-05-08
Sun has acknowledged a vulnerability in Sun Java System Web Server and Sun Java System Application Server, which can be exploited by malicious people to disclose certain sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30122/\"]http://secunia.com/advisories/30122/[/url]
--
[SA30107] Musicbox "artistId" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-08
HaCkeR-EgY has reported a vulnerability in Musicbox, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30107/\"]http://secunia.com/advisories/30107/[/url]
--
[SA30091] mvnForum "QuickReply" Script Insertion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-08
Christian Holler has reported a vulnerability in mvnForum, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30091/\"]http://secunia.com/advisories/30091/[/url]
--
[SA30089] Auction XL "viewfaqs.php" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-06
M.Hasran Addahroni has reported a vulnerability in Auction XL, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30089/\"]http://secunia.com/advisories/30089/[/url]
--
[SA30085] Miniweb "historymonth" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-06
HaCkeR-EgY has reported a vulnerability in Miniweb, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30085/\"]http://secunia.com/advisories/30085/[/url]
--
[SA30084] DeluxeBB SQL Injection and PHP Code Execution
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, System access
Released: 2008-05-06
EgiX has discovered two vulnerabilities in DeluxeBB, which can be exploited by malicious users to compromise a vulnerable system and by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30084/\"]http://secunia.com/advisories/30084/[/url]
--
[SA30076] PHPEasyData "cat_id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-05-07
InjEctOr and ToTaL have discovered a vulnerability in PHPEasyData, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30076/\"]http://secunia.com/advisories/30076/[/url]
--
[SA30069] Maian Greetings Cross-Site Scripting and SQL Injection
Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-05-08
Khashayar Fereidani has reported some vulnerabilities in Maian Greetings, which can be exploited by malicious people to conduct
cross-site scripting or SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30069/\"]http://secunia.com/advisories/30069/[/url]
--
[SA30061] Nuke ET Security Bypass and Script Insertion Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-05-07
mrzayas has reported some vulnerabilities in Nuke ET, which can be exploited by malicious people to bypass certain security restrictions or conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30061/\"]http://secunia.com/advisories/30061/[/url]
--
[SA30058] BlogMe PHP "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-05
His0k4 has discovered a vulnerability in BlogMe PHP, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30058/\"]http://secunia.com/advisories/30058/[/url]
--
[SA30057] SMartBlog Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-05-05
Some vulnerabilities have been discovered in SMartBlog, which can be exploited by malicious people to disclose potentially sensitive information and conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30057/\"]http://secunia.com/advisories/30057/[/url]
--
[SA30056] phpDirectorySource SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of sensitive information
Released: 2008-05-05
InjEctOr and FishEr762 have discovered two vulnerabilities in phpDirectorySource, which can be exploited by malicious people to
conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30056/\"]http://secunia.com/advisories/30056/[/url]
--
[SA30133] Sun Java System Web Server Search Module Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-08
Sun has acknowledged a vulnerability in Sun Java System Web Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30133/\"]http://secunia.com/advisories/30133/[/url]
--
[SA30121] Tux CMS Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-08
Hadi Kiamarsi has discovered some vulnerabilities in Tux CMS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30121/\"]http://secunia.com/advisories/30121/[/url]
--
[SA30098] CMS Faethon "what" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-08
RoMaNcYxHaCkEr has discovered a vulnerability in CMS Faethon, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30098/\"]http://secunia.com/advisories/30098/[/url]
--
[SA30092] LifeType "newBlogUserName" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-06
Khashayar Fereidani has discovered a vulnerability in LifeType, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30092/\"]http://secunia.com/advisories/30092/[/url]
--
[SA30082] Sphider Suggestion Feature "query" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-08
Christian Holler has reported a vulnerability in Sphider, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30082/\"]http://secunia.com/advisories/30082/[/url]
--
[SA30079] TYPO3 powermail Extension Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-05
A vulnerability has been reported in the powermail extension for TYPO3, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30079/\"]http://secunia.com/advisories/30079/[/url]
--
[SA30075] LifeType "searchTerms" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-05
IRCRASH has reported a vulnerability in LifeType, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30075/\"]http://secunia.com/advisories/30075/[/url]
--
[SA30070] Maian Gallery "keywords" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-08
Khashayar Fereidani has reported a vulnerability in Maian Gallery, which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30070/\"]http://secunia.com/advisories/30070/[/url]
--
[SA30068] Maian Support Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-08
Khashayar Fereidani has discovered some vulnerabilities in Maian Support, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30068/\"]http://secunia.com/advisories/30068/[/url]
--
[SA30065] Maian Links Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-08
Khashayar Fereidani has discovered some vulnerabilities in Maian Links, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30065/\"]http://secunia.com/advisories/30065/[/url]
--
[SA30064] Bugzilla Security Bypass and Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-05-05
Some vulnerabilities have been reported in Bugzilla, which can be exploited by malicious users to bypass certain security restrictions or by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30064/\"]http://secunia.com/advisories/30064/[/url]
--
[SA30062] Zomplog "catname" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-05
Khashayar Fereidani has discovered a vulnerability in Zomplog, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30062/\"]http://secunia.com/advisories/30062/[/url]
--
[SA30060] Maian Weblog Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-07
Khashayar Fereidani has discovered some vulnerabilities in Maian Weblog, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30060/\"]http://secunia.com/advisories/30060/[/url]
--
[SA30081] IBM Rational Build Forge Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-05-05
A vulnerability has been reported in IBM Rational Build Forge, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30081/\"]http://secunia.com/advisories/30081/[/url]
--
[SA30134] MySQL MyISAM Table Privilege Check Bypass
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-05-08
A security issue has been reported in MySQL, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30134/\"]http://secunia.com/advisories/30134/[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Secunia Security Updates - May 2008
[i][b][url=\"http://secunia.com\"]Secunia[/url] Vulnerabilities Content Listing for the week of May 22, 2008[/b][/i]
[b]Windows:--[/b]
[SA30336] Trillian Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-22
Some vulnerabilities have been reported in Trillian, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30336/\"]http://secunia.com/advisories/30336/[/url]
--
[SA30309] IBM Lotus Sametime Community Services Multiplexer Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-22
A vulnerability has been reported in IBM Lotus Sametime, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30309/\"]http://secunia.com/advisories/30309/[/url]
--
[SA30305] PhotoStockPlus Uploader Tool ActiveX Control Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-20
Will Dormann has reported some vulnerabilities in PhotoStockPlus Uploader Tool ActiveX control, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30305/\"]http://secunia.com/advisories/30305/[/url]
--
[SA30295] how2ASP Webboard "qNo" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-20
CWH Underground has discovered a vulnerability in how2ASP Webboard, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30295/\"]http://secunia.com/advisories/30295/[/url]
--
[SA30333] AppServ "appservlang" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-21
tan_prathan has reported a vulnerability in AppServ, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30333/\"]http://secunia.com/advisories/30333/[/url]
--
[SA30289] Cisco Voice Portal Privilege Escalation Vulnerability
Critical: Less critical
Where: From local network
Impact: Privilege escalation
Released: 2008-05-22
A vulnerability has been reported in Cisco Voice Portal (CVP), which can be exploited by malicious users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30289/\"]http://secunia.com/advisories/30289/[/url]
--
[SA30297] Stunnel Windows Privilege Escalation Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-05-20
A vulnerability has been reported in Stunnel, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30297/\"]http://secunia.com/advisories/30297/[/url]
[b]UNIX/Linux:--[/b]
[SA30338] Gentoo update for gnutls
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-22
Gentoo has issued an update for gnutls. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30338/\"]http://secunia.com/advisories/30338/[/url]
--
[SA30331] Ubuntu update for gnutls
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-22
Ubuntu has issued an update for gnutls. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30331/\"]http://secunia.com/advisories/30331/[/url]
--
[SA30328] Gentoo update for clamav
Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-05-21
Gentoo has issued an update for clamav. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, to cause a DoS (Denial of Service), or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30328/\"]http://secunia.com/advisories/30328/[/url]
--
[SA30327] Gentoo Update for Mozilla Products
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-05-21
Gentoo has issued updates for mozilla-firefox, mozilla-firefox-bin, seamonkey, seamonkey-bin, mozilla-thunderbird, mozilla-thunderbird-bin, and xulrunner. These fix some weaknesses and vulnerabilities, which can be exploited by malicious people to disclose sensitive information, conduct cross-site scripting attacks, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30327/\"]http://secunia.com/advisories/30327/[/url]
--
[SA30325] Debian update for gnome-peercast
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
Debian has issued an update for gnome-peercast. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30325/\"]http://secunia.com/advisories/30325/[/url]
--
[SA30324] Debian update for gnutls13
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
Debian has issued an update for gnutls13. This fixes some vulnerabilities, which can be exploited to cause a DoS (Denial of
Service) or to potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30324/\"]http://secunia.com/advisories/30324/[/url]
--
[SA30320] Debian update for peercast
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
Debian has issued an update for peercast. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30320/\"]http://secunia.com/advisories/30320/[/url]
--
[SA30317] Red Hat update for gnutls
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
Red Hat has issued an update for gnutls. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30317/\"]http://secunia.com/advisories/30317/[/url]
--
[SA30302] Fedora update for gnutls
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
Fedora has issued an update for gnutls. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30302/\"]http://secunia.com/advisories/30302/[/url]
--
[SA30287] GnuTLS Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
Some vulnerabilities have been reported in GnuTLS, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30287/\"]http://secunia.com/advisories/30287/[/url]
--
[SA30358] Debian update for speex
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-22
Debian has issued an update for speex. This fixes a vulnerability, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30358/\"]http://secunia.com/advisories/30358/[/url]
--
[SA30353] Debian update for libfishsound
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-22
Debian has issued an update for libfishsound. This fixes a vulnerability, which can be exploited by malicious people to compromise
an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30353/\"]http://secunia.com/advisories/30353/[/url]
--
[SA30346] Interchange Unspecified HTTP POST Request Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-05-22
A vulnerability has been reported in Interchange, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30346/\"]http://secunia.com/advisories/30346/[/url]
--
[SA30341] Red Hat update for vsftpd
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-05-22
Red Hat has issued an update for vsftpd. This fixes a vulnerability, which can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30341/\"]http://secunia.com/advisories/30341/[/url]
--
[SA30326] Gentoo update for perl and libperl
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
Gentoo has issued an update for perl and libperl. This fixes a vulnerability, which potentially can be exploited by malicious people
to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30326/\"]http://secunia.com/advisories/30326/[/url]
--
[SA30323] Red Hat update for libxslt
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
Red Hat has issued an update for libxslt. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30323/\"]http://secunia.com/advisories/30323/[/url]
--
[SA30288] Debian update for php4
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, DoS, System access
Released: 2008-05-19
Debian has issued an update for php4. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, and malicious people to disclose potentially sensitive information, bypass certain security restrictions, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30288/\"]http://secunia.com/advisories/30288/[/url]
--
[SA30280] Debian update for netpbm-free
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-19
Debian has issued an update for netpbm-free. This fixes a vulnerability, which can potentially be exploited by malicious people
to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30280/\"]http://secunia.com/advisories/30280/[/url]
--
[SA30352] Red Hat update for nss_ldap
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-22
Red Hat has issued an update for nss_ldap. This fixes a security issue, which can be exploited by malicious people to manipulate certain data.
Full Advisory:
[url=\"http://secunia.com/advisories/30352/\"]http://secunia.com/advisories/30352/[/url]
--
[SA30342] Red Hat update for dovecot
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-05-22
Red Hat has issued an update for dovecot. This fixes a weakness and a security issue, which can be exploited by malicious users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30342/\"]http://secunia.com/advisories/30342/[/url]
--
[SA30313] Red Hat update for bind
Critical: Less critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-05-22
Red Hat has issued an update for bind. This fixes a security issue, which can be exploited by malicious, local users to bypass certain
security restrictions, and a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30313/\"]http://secunia.com/advisories/30313/[/url]
--
[SA30291] Fedora update for Django
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-21
Fedora has issued an update for Django. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30291/\"]http://secunia.com/advisories/30291/[/url]
--
[SA30283] Nagios CGI Unspecified Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-20
A vulnerability has been reported in Nagios, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30283/\"]http://secunia.com/advisories/30283/[/url]
--
[SA30351] Red Hat update for mysql
Critical: Less critical
Where: From local network
Impact: Security Bypass, Privilege escalation, DoS
Released: 2008-05-22
Red Hat has issued an update for mysql. This fixes some security issues and vulnerabilities, which can be exploited by malicious users to cause a DoS (Denial of Service), bypass certain security restrictions, and gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30351/\"]http://secunia.com/advisories/30351/[/url]
--
[SA30312] Mtr "split_redraw()" Buffer Overflow Vulnerability
Critical: Less critical
Where: From local network
Impact: System access
Released: 2008-05-20
Adam Zabrocki has discovered a vulnerability in Mtr, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30312/\"]http://secunia.com/advisories/30312/[/url]
--
[SA30294] Red Hat update for kernel
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-05-20
Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users and
malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30294/\"]http://secunia.com/advisories/30294/[/url]
--
[SA30361] IBM AIX update for OpenSSH
Critical: Less critical
Where: Local system
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-05-22
IBM has acknowledged some vulnerabilities in OpenSSH, which can be exploited by malicious, local users to bypass certain security
restrictions or disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30361/\"]http://secunia.com/advisories/30361/[/url]
--
[SA30349] IBM AIX Multiple Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-05-22
Some vulnerabilities have been reported in IBM AIX, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30349/\"]http://secunia.com/advisories/30349/[/url]
--
[SA30339] Red Hat update for setroubleshoot
Critical: Less critical
Where: Local system
Impact: Cross Site Scripting, Privilege escalation
Released: 2008-05-22
Red Hat has issued an update for setroubleshoot. This fixes two security issues, which can be exploited by malicious, local users to
conduct script insertion attacks and to perform certain actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30339/\"]http://secunia.com/advisories/30339/[/url]
--
[SA30286] Debian update for gforge
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-05-16
Debian has issued an update for gforge. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30286/\"]http://secunia.com/advisories/30286/[/url]
--
[SA30360] IBM AIX ftpd "quote cwd" Full Path Disclosure Weakness
Critical: Not critical
Where: From remote
Impact: Exposure of system information
Released: 2008-05-22
A weakness has been reported in IBM AIX, which can be exploited by malicious people to disclose system information.
Full Advisory:
[url=\"http://secunia.com/advisories/30360/\"]http://secunia.com/advisories/30360/[/url]
--
[SA30357] Sun Solaris STREAMS Administrative Driver Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-05-22
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30357/\"]http://secunia.com/advisories/30357/[/url]
--
[SA30329] Red Hat update for compiz
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-05-22
Red Hat has issued an update for compiz. This fixes a security issue, which can be exploited by malicious people with physical access to a system to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30329/\"]http://secunia.com/advisories/30329/[/url]
--
[SA30308] HP-UX useradd Security Bypass
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-05-20
A security issue has been reported in HP-UX, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30308/\"]http://secunia.com/advisories/30308/[/url]
[b]Other:--[/b]
[SA30322] Cisco IOS SSH Server Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-05-22
Some vulnerabilities have been reported in Cisco IOS, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30322/\"]http://secunia.com/advisories/30322/[/url]
--
[SA30316] Cisco Service Control Engine SSH Server Denial of Service Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-05-22
Some vulnerabilities have been reported in Cisco Service Control Engine, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30316/\"]http://secunia.com/advisories/30316/[/url]
[b]Cross Platform:--[/b]
[SA30332] IBM Lotus Domino 6 Web Server Cross-Site Scripting and Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2008-05-21
Some vulnerabilities have been reported in IBM Lotus Domino, which can be exploited by malicious people to conduct cross-site scripting attacks or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30332/\"]http://secunia.com/advisories/30332/[/url]
--
[SA30330] FileZilla GnuTLS Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
Some vulnerabilities have been reported in FileZilla, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30330/\"]http://secunia.com/advisories/30330/[/url]
--
[SA30310] IBM Lotus Domino Web Server Cross-Site Scripting and Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2008-05-21
Some vulnerabilities have been reported in IBM Lotus Domino, which can be exploited by malicious people to conduct cross-site scripting attacks or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30310/\"]http://secunia.com/advisories/30310/[/url]
--
[SA30319] ComicShout "comic_id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-05-21
D3m0n has reported a vulnerability in ComicShout, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30319/\"]http://secunia.com/advisories/30319/[/url]
--
[SA30315] libxslt XSL File Processing Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
A vulnerability has been reported in libxslt, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30315/\"]http://secunia.com/advisories/30315/[/url]
--
[SA30314] PHP-Jokesite "cat_id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-21
Cyb3r-1sT has reported a vulnerability in PHP-Jokesite, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30314/\"]http://secunia.com/advisories/30314/[/url]
--
[SA30304] PHP-Fusion Forum Rank System Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-05-20
Matrix86 has reported two vulnerabilities in the Forum Rank System module for PHP-Fusion, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30304/\"]http://secunia.com/advisories/30304/[/url]
--
[SA30301] GNU/Gallery "show" Local File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-05-19
t0pP8uZz has discovered a vulnerability in GNU/Gallery, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30301/\"]http://secunia.com/advisories/30301/[/url]
--
[SA30299] Borland Interbase 2007 Packet Processing Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
Damian Frizza has reported a vulnerability in Borland Interbase, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30299/\"]http://secunia.com/advisories/30299/[/url]
--
[SA30296] WR-Meeting "msnum" File Disclosure Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-05-19
Cr@zy_King has discovered a vulnerability in WR-Meeting, which can be
exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30296/\"]http://secunia.com/advisories/30296/[/url]
--
[SA30293] CMS WebManager-Pro SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-05-19
dun has reported some vulnerabilities in CMS WebManager-Pro, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30293/\"]http://secunia.com/advisories/30293/[/url]
--
[SA30284] FireFTP Extension for Firefox Directory Traversal Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-05-20
Tan Chew Keong has reported a vulnerability in the FireFTP extension for Firefox, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30284/\"]http://secunia.com/advisories/30284/[/url]
--
[SA30282] SunShop Shopping Cart "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-19
irvian has reported a vulnerability in SunShop Shopping Cart, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30282/\"]http://secunia.com/advisories/30282/[/url]
--
[SA30281] FicHive "letter" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-21
A vulnerability has been discovered in FicHive, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30281/\"]http://secunia.com/advisories/30281/[/url]
--
[SA30279] Rantx "logininfo" Security Bypass Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-05-16
t0pP8uZz has discovered a vulnerability in Rantx, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30279/\"]http://secunia.com/advisories/30279/[/url]
--
[SA30300] CA ARCserve Backup Multiple Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-05-20
Some vulnerabilities have been reported in CA ARCserve Backup, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30300/\"]http://secunia.com/advisories/30300/[/url]
--
[SA30356] IBM HTTP Server Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-22
IBM has acknowledged some vulnerabilities in IBM HTTP Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30356/\"]http://secunia.com/advisories/30356/[/url]
--
[SA30348] Snort Fragmented IP Packets TTL Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-05-22
A vulnerability has been reported in Snort, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30348/\"]http://secunia.com/advisories/30348/[/url]
--
[SA30335] Stunnel OCSP Revoked Certificate Security Issue
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-05-22
A security issue has been reported in Stunnel, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30335/\"]http://secunia.com/advisories/30335/[/url]
--
[SA30334] SAP Web Application Server Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-22
Digital Security Research Group has reported a vulnerability in SAP Web Application Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30334/\"]http://secunia.com/advisories/30334/[/url]
--
[SA30307] dotCMS "search_query" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-20
Russ McRee has reported a vulnerability in dotCMS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30307/\"]http://secunia.com/advisories/30307/[/url]
[b]Windows:--[/b]
[SA30336] Trillian Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-22
Some vulnerabilities have been reported in Trillian, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30336/\"]http://secunia.com/advisories/30336/[/url]
--
[SA30309] IBM Lotus Sametime Community Services Multiplexer Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-22
A vulnerability has been reported in IBM Lotus Sametime, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30309/\"]http://secunia.com/advisories/30309/[/url]
--
[SA30305] PhotoStockPlus Uploader Tool ActiveX Control Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-20
Will Dormann has reported some vulnerabilities in PhotoStockPlus Uploader Tool ActiveX control, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30305/\"]http://secunia.com/advisories/30305/[/url]
--
[SA30295] how2ASP Webboard "qNo" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-20
CWH Underground has discovered a vulnerability in how2ASP Webboard, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30295/\"]http://secunia.com/advisories/30295/[/url]
--
[SA30333] AppServ "appservlang" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-21
tan_prathan has reported a vulnerability in AppServ, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30333/\"]http://secunia.com/advisories/30333/[/url]
--
[SA30289] Cisco Voice Portal Privilege Escalation Vulnerability
Critical: Less critical
Where: From local network
Impact: Privilege escalation
Released: 2008-05-22
A vulnerability has been reported in Cisco Voice Portal (CVP), which can be exploited by malicious users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30289/\"]http://secunia.com/advisories/30289/[/url]
--
[SA30297] Stunnel Windows Privilege Escalation Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-05-20
A vulnerability has been reported in Stunnel, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30297/\"]http://secunia.com/advisories/30297/[/url]
[b]UNIX/Linux:--[/b]
[SA30338] Gentoo update for gnutls
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-22
Gentoo has issued an update for gnutls. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30338/\"]http://secunia.com/advisories/30338/[/url]
--
[SA30331] Ubuntu update for gnutls
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-22
Ubuntu has issued an update for gnutls. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30331/\"]http://secunia.com/advisories/30331/[/url]
--
[SA30328] Gentoo update for clamav
Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-05-21
Gentoo has issued an update for clamav. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, to cause a DoS (Denial of Service), or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30328/\"]http://secunia.com/advisories/30328/[/url]
--
[SA30327] Gentoo Update for Mozilla Products
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-05-21
Gentoo has issued updates for mozilla-firefox, mozilla-firefox-bin, seamonkey, seamonkey-bin, mozilla-thunderbird, mozilla-thunderbird-bin, and xulrunner. These fix some weaknesses and vulnerabilities, which can be exploited by malicious people to disclose sensitive information, conduct cross-site scripting attacks, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30327/\"]http://secunia.com/advisories/30327/[/url]
--
[SA30325] Debian update for gnome-peercast
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
Debian has issued an update for gnome-peercast. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30325/\"]http://secunia.com/advisories/30325/[/url]
--
[SA30324] Debian update for gnutls13
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
Debian has issued an update for gnutls13. This fixes some vulnerabilities, which can be exploited to cause a DoS (Denial of
Service) or to potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30324/\"]http://secunia.com/advisories/30324/[/url]
--
[SA30320] Debian update for peercast
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
Debian has issued an update for peercast. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30320/\"]http://secunia.com/advisories/30320/[/url]
--
[SA30317] Red Hat update for gnutls
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
Red Hat has issued an update for gnutls. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30317/\"]http://secunia.com/advisories/30317/[/url]
--
[SA30302] Fedora update for gnutls
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
Fedora has issued an update for gnutls. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30302/\"]http://secunia.com/advisories/30302/[/url]
--
[SA30287] GnuTLS Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
Some vulnerabilities have been reported in GnuTLS, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30287/\"]http://secunia.com/advisories/30287/[/url]
--
[SA30358] Debian update for speex
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-22
Debian has issued an update for speex. This fixes a vulnerability, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30358/\"]http://secunia.com/advisories/30358/[/url]
--
[SA30353] Debian update for libfishsound
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-22
Debian has issued an update for libfishsound. This fixes a vulnerability, which can be exploited by malicious people to compromise
an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30353/\"]http://secunia.com/advisories/30353/[/url]
--
[SA30346] Interchange Unspecified HTTP POST Request Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-05-22
A vulnerability has been reported in Interchange, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30346/\"]http://secunia.com/advisories/30346/[/url]
--
[SA30341] Red Hat update for vsftpd
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-05-22
Red Hat has issued an update for vsftpd. This fixes a vulnerability, which can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30341/\"]http://secunia.com/advisories/30341/[/url]
--
[SA30326] Gentoo update for perl and libperl
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
Gentoo has issued an update for perl and libperl. This fixes a vulnerability, which potentially can be exploited by malicious people
to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30326/\"]http://secunia.com/advisories/30326/[/url]
--
[SA30323] Red Hat update for libxslt
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
Red Hat has issued an update for libxslt. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30323/\"]http://secunia.com/advisories/30323/[/url]
--
[SA30288] Debian update for php4
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, DoS, System access
Released: 2008-05-19
Debian has issued an update for php4. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, and malicious people to disclose potentially sensitive information, bypass certain security restrictions, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30288/\"]http://secunia.com/advisories/30288/[/url]
--
[SA30280] Debian update for netpbm-free
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-19
Debian has issued an update for netpbm-free. This fixes a vulnerability, which can potentially be exploited by malicious people
to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30280/\"]http://secunia.com/advisories/30280/[/url]
--
[SA30352] Red Hat update for nss_ldap
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-22
Red Hat has issued an update for nss_ldap. This fixes a security issue, which can be exploited by malicious people to manipulate certain data.
Full Advisory:
[url=\"http://secunia.com/advisories/30352/\"]http://secunia.com/advisories/30352/[/url]
--
[SA30342] Red Hat update for dovecot
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-05-22
Red Hat has issued an update for dovecot. This fixes a weakness and a security issue, which can be exploited by malicious users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30342/\"]http://secunia.com/advisories/30342/[/url]
--
[SA30313] Red Hat update for bind
Critical: Less critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-05-22
Red Hat has issued an update for bind. This fixes a security issue, which can be exploited by malicious, local users to bypass certain
security restrictions, and a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30313/\"]http://secunia.com/advisories/30313/[/url]
--
[SA30291] Fedora update for Django
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-21
Fedora has issued an update for Django. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30291/\"]http://secunia.com/advisories/30291/[/url]
--
[SA30283] Nagios CGI Unspecified Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-20
A vulnerability has been reported in Nagios, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30283/\"]http://secunia.com/advisories/30283/[/url]
--
[SA30351] Red Hat update for mysql
Critical: Less critical
Where: From local network
Impact: Security Bypass, Privilege escalation, DoS
Released: 2008-05-22
Red Hat has issued an update for mysql. This fixes some security issues and vulnerabilities, which can be exploited by malicious users to cause a DoS (Denial of Service), bypass certain security restrictions, and gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30351/\"]http://secunia.com/advisories/30351/[/url]
--
[SA30312] Mtr "split_redraw()" Buffer Overflow Vulnerability
Critical: Less critical
Where: From local network
Impact: System access
Released: 2008-05-20
Adam Zabrocki has discovered a vulnerability in Mtr, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30312/\"]http://secunia.com/advisories/30312/[/url]
--
[SA30294] Red Hat update for kernel
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-05-20
Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users and
malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30294/\"]http://secunia.com/advisories/30294/[/url]
--
[SA30361] IBM AIX update for OpenSSH
Critical: Less critical
Where: Local system
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-05-22
IBM has acknowledged some vulnerabilities in OpenSSH, which can be exploited by malicious, local users to bypass certain security
restrictions or disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30361/\"]http://secunia.com/advisories/30361/[/url]
--
[SA30349] IBM AIX Multiple Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-05-22
Some vulnerabilities have been reported in IBM AIX, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30349/\"]http://secunia.com/advisories/30349/[/url]
--
[SA30339] Red Hat update for setroubleshoot
Critical: Less critical
Where: Local system
Impact: Cross Site Scripting, Privilege escalation
Released: 2008-05-22
Red Hat has issued an update for setroubleshoot. This fixes two security issues, which can be exploited by malicious, local users to
conduct script insertion attacks and to perform certain actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30339/\"]http://secunia.com/advisories/30339/[/url]
--
[SA30286] Debian update for gforge
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-05-16
Debian has issued an update for gforge. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30286/\"]http://secunia.com/advisories/30286/[/url]
--
[SA30360] IBM AIX ftpd "quote cwd" Full Path Disclosure Weakness
Critical: Not critical
Where: From remote
Impact: Exposure of system information
Released: 2008-05-22
A weakness has been reported in IBM AIX, which can be exploited by malicious people to disclose system information.
Full Advisory:
[url=\"http://secunia.com/advisories/30360/\"]http://secunia.com/advisories/30360/[/url]
--
[SA30357] Sun Solaris STREAMS Administrative Driver Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-05-22
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30357/\"]http://secunia.com/advisories/30357/[/url]
--
[SA30329] Red Hat update for compiz
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-05-22
Red Hat has issued an update for compiz. This fixes a security issue, which can be exploited by malicious people with physical access to a system to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30329/\"]http://secunia.com/advisories/30329/[/url]
--
[SA30308] HP-UX useradd Security Bypass
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-05-20
A security issue has been reported in HP-UX, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30308/\"]http://secunia.com/advisories/30308/[/url]
[b]Other:--[/b]
[SA30322] Cisco IOS SSH Server Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-05-22
Some vulnerabilities have been reported in Cisco IOS, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30322/\"]http://secunia.com/advisories/30322/[/url]
--
[SA30316] Cisco Service Control Engine SSH Server Denial of Service Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-05-22
Some vulnerabilities have been reported in Cisco Service Control Engine, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30316/\"]http://secunia.com/advisories/30316/[/url]
[b]Cross Platform:--[/b]
[SA30332] IBM Lotus Domino 6 Web Server Cross-Site Scripting and Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2008-05-21
Some vulnerabilities have been reported in IBM Lotus Domino, which can be exploited by malicious people to conduct cross-site scripting attacks or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30332/\"]http://secunia.com/advisories/30332/[/url]
--
[SA30330] FileZilla GnuTLS Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
Some vulnerabilities have been reported in FileZilla, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30330/\"]http://secunia.com/advisories/30330/[/url]
--
[SA30310] IBM Lotus Domino Web Server Cross-Site Scripting and Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2008-05-21
Some vulnerabilities have been reported in IBM Lotus Domino, which can be exploited by malicious people to conduct cross-site scripting attacks or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30310/\"]http://secunia.com/advisories/30310/[/url]
--
[SA30319] ComicShout "comic_id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-05-21
D3m0n has reported a vulnerability in ComicShout, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30319/\"]http://secunia.com/advisories/30319/[/url]
--
[SA30315] libxslt XSL File Processing Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
A vulnerability has been reported in libxslt, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30315/\"]http://secunia.com/advisories/30315/[/url]
--
[SA30314] PHP-Jokesite "cat_id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-21
Cyb3r-1sT has reported a vulnerability in PHP-Jokesite, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30314/\"]http://secunia.com/advisories/30314/[/url]
--
[SA30304] PHP-Fusion Forum Rank System Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-05-20
Matrix86 has reported two vulnerabilities in the Forum Rank System module for PHP-Fusion, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30304/\"]http://secunia.com/advisories/30304/[/url]
--
[SA30301] GNU/Gallery "show" Local File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-05-19
t0pP8uZz has discovered a vulnerability in GNU/Gallery, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30301/\"]http://secunia.com/advisories/30301/[/url]
--
[SA30299] Borland Interbase 2007 Packet Processing Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-21
Damian Frizza has reported a vulnerability in Borland Interbase, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30299/\"]http://secunia.com/advisories/30299/[/url]
--
[SA30296] WR-Meeting "msnum" File Disclosure Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-05-19
Cr@zy_King has discovered a vulnerability in WR-Meeting, which can be
exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30296/\"]http://secunia.com/advisories/30296/[/url]
--
[SA30293] CMS WebManager-Pro SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-05-19
dun has reported some vulnerabilities in CMS WebManager-Pro, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30293/\"]http://secunia.com/advisories/30293/[/url]
--
[SA30284] FireFTP Extension for Firefox Directory Traversal Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-05-20
Tan Chew Keong has reported a vulnerability in the FireFTP extension for Firefox, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30284/\"]http://secunia.com/advisories/30284/[/url]
--
[SA30282] SunShop Shopping Cart "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-19
irvian has reported a vulnerability in SunShop Shopping Cart, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30282/\"]http://secunia.com/advisories/30282/[/url]
--
[SA30281] FicHive "letter" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-21
A vulnerability has been discovered in FicHive, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30281/\"]http://secunia.com/advisories/30281/[/url]
--
[SA30279] Rantx "logininfo" Security Bypass Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-05-16
t0pP8uZz has discovered a vulnerability in Rantx, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30279/\"]http://secunia.com/advisories/30279/[/url]
--
[SA30300] CA ARCserve Backup Multiple Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-05-20
Some vulnerabilities have been reported in CA ARCserve Backup, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30300/\"]http://secunia.com/advisories/30300/[/url]
--
[SA30356] IBM HTTP Server Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-22
IBM has acknowledged some vulnerabilities in IBM HTTP Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30356/\"]http://secunia.com/advisories/30356/[/url]
--
[SA30348] Snort Fragmented IP Packets TTL Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-05-22
A vulnerability has been reported in Snort, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30348/\"]http://secunia.com/advisories/30348/[/url]
--
[SA30335] Stunnel OCSP Revoked Certificate Security Issue
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-05-22
A security issue has been reported in Stunnel, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30335/\"]http://secunia.com/advisories/30335/[/url]
--
[SA30334] SAP Web Application Server Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-22
Digital Security Research Group has reported a vulnerability in SAP Web Application Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30334/\"]http://secunia.com/advisories/30334/[/url]
--
[SA30307] dotCMS "search_query" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-20
Russ McRee has reported a vulnerability in dotCMS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30307/\"]http://secunia.com/advisories/30307/[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
