Secunia Updates - June 2008

Moderators: Moderator, Global Moderator

Post Reply
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Updates - June 2008

Post by Tami »

[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of June 5 2008[/b][/i]

[b]Windows:--[/b]

[SA30469] Ourgame GLWorld GLIEDown2.dll ActiveX Control Vulnerabilities

Critical: Extremely critical
Where: From remote
Impact: System access
Released: 2008-06-02

Multiple vulnerabilities have been discovered in the GLIEDown2.dll ActiveX control bundled with Ourgame GLWorld, which can be exploited by
malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30469/\"]http://secunia.com/advisories/30469/[/url]

--

[SA30537] Akamai Download Manager Arbitrary File Download Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-05

A vulnerability has been reported in Akamai Download Manager, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30537/\"]http://secunia.com/advisories/30537/[/url]

--

[SA30533] Magic Rm AVI Mpeg to MP3 Converter & Editor NCTSoft ActiveX Controls Buffer Overflows

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-04

Some vulnerabilities have been discovered in Magic Rm AVI Mpeg to MP3 Converter & Editor, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30533/\"]http://secunia.com/advisories/30533/[/url]

--

[SA30531] Code-it Software Products NCTAudioGrabber2 ActiveX Control Buffer Overflows

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-04

Some vulnerabilities have been discovered in various Code-it Software products, which can be exploited by malicious people to compromise a
user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30531/\"]http://secunia.com/advisories/30531/[/url]

--

[SA30530] Ease MP3 Recorder NCTAudioFile2 ActiveX Control Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-04

A vulnerability has been discovered in Ease MP3 Recorder, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30530/\"]http://secunia.com/advisories/30530/[/url]

--

[SA30529] Ease Jukebox NCTSoft ActiveX Controls Buffer Overflow Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-04

Some vulnerabilities have been discovered in Ease Jukebox, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30529/\"]http://secunia.com/advisories/30529/[/url]

--

[SA30528] MightSOFT Products NCTSoft ActiveX Controls Buffer Overflow Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-04

Some vulnerabilities have been discovered in various MightSOFT products, which can be exploited by malicious people to compromise a
user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30528/\"]http://secunia.com/advisories/30528/[/url]

--

[SA30525] Saga CD Ripper NCTAudioGrabber2 ActiveX Control Buffer Overflows

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-04

Some vulnerabilities have been discovered in Saga CD Ripper, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30525/\"]http://secunia.com/advisories/30525/[/url]

--

[SA30518] CA Secure Content Manager Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-04

Some vulnerabilities have been reported in CA eTrust Content Manager, which can be exploited by malicious people to cause a DoS (Denial of
Service) or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30518/\"]http://secunia.com/advisories/30518/[/url]

--

[SA30516] HP Instant Support HPISDataManager.dll ActiveX Control Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-04

Some vulnerabilities have been reported in HP Instant Support, which potentially can be exploited by malicious people to bypass certain
security restrictions and compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30516/\"]http://secunia.com/advisories/30516/[/url]

--

[SA30512] Icona SpA DownloaderActiveX ActiveX Control Module Code Execution Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-04

Nine:Situations:Group::SnoopyAssault has discovered a vulnerability in Icona SpA DownloaderActiveX ActiveX Control Module, which can be
exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30512/\"]http://secunia.com/advisories/30512/[/url]

--

[SA30511] goodvdsoft.com Products NCTAudioFile2 ActiveX Control Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-03

A vulnerability has been discovered in various goodvdsoft.com products, which can be exploited by malicious people to compromise a user's
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30511/\"]http://secunia.com/advisories/30511/[/url]

--

[SA30510] Akram Software Products NCTAudioFile2 ActiveX Control Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-03

A vulnerability has been discovered in various Akram Software products, which can be exploited by malicious people to compromise a user's
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30510/\"]http://secunia.com/advisories/30510/[/url]

--

[SA30509] ColorfulSoft Products NCTAudioFile2 ActiveX Control Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-03

A vulnerability has been discovered in various ColorfulSoft products, which can be exploited by malicious people to compromise a user's
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30509/\"]http://secunia.com/advisories/30509/[/url]

--

[SA30508] ALO Software Products NCTAudioFile2 ActiveX Control Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-03

A vulnerability has been discovered in various ALO Software products, which can be exploited by malicious people to compromise a user's
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30508/\"]http://secunia.com/advisories/30508/[/url]

--

[SA30506] Cool Record Edit NCTAudioFile2 ActiveX Control Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-03

A vulnerability has been discovered in Cool Record Edit, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30506/\"]http://secunia.com/advisories/30506/[/url]

--

[SA30501] QuickerSite Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data, Exposure of system information, System access
Released: 2008-06-04

AmnPardaz Security Research Team has reported multiple vulnerabilities in QuickerSite, which can be exploited by malicious people to bypass
certain security restrictions, conduct cross-site scripting attacks, script insertion attacks, SQL injection attacks, and potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30501/\"]http://secunia.com/advisories/30501/[/url]

--

[SA30497] Alt-N SecurityGateway "username" Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-02

securfrog has discovered a vulnerability in Alt-N SecurityGateway, which can be exploited by malicious people to compromise a vulnerable
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30497/\"]http://secunia.com/advisories/30497/[/url]

--

[SA30489] rPath update for samba

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-03

rPath has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30489/\"]http://secunia.com/advisories/30489/[/url]

--

[SA30467] Apple Safari on Windows Code Execution Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-02

A vulnerability has been reported in Apple Safari in combination with Microsoft Windows, which can be exploited by malicious people to
compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30467/\"]http://secunia.com/advisories/30467/[/url]

--

[SA30459] Color7 Technology Products NCTAudioFile2 ActiveX Control Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-30

A vulnerability has been discovered in various Color7 Technology products, which can be exploited by malicious people to compromise a
user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30459/\"]http://secunia.com/advisories/30459/[/url]

--

[SA30458] Audio Editor Plus NCTSoft ActiveX Controls Buffer Overflow
Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-30

Some vulnerabilities have been discovered in Audio Editor Plus, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30458/\"]http://secunia.com/advisories/30458/[/url]

--

[SA30457] Powerful Audio Tool NCTAudioInformation2.dll ActiveX Control Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-30

A vulnerability has been discovered in Powerful Audio Tool, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30457/\"]http://secunia.com/advisories/30457/[/url]

--

[SA30456] Crystal MP3 Recorder NCTAudioInformation2.dll ActiveX Control Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-30

A vulnerability has been discovered in Crystal MP3 Recorder, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30456/\"]http://secunia.com/advisories/30456/[/url]

--

[SA30454] Easy Audio Redactor NCTSoft ActiveX Controls Buffer Overflow Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-30

Some vulnerabilities have been discovered in Easy Audio Redactor, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30454/\"]http://secunia.com/advisories/30454/[/url]

--

[SA30453] Total Audio Recorder and Editor NCTSoft ActiveX Controls Buffer Overflow Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-30

Some vulnerabilities have been discovered in Total Audio Recorder and Editor, which can be exploited by malicious people to compromise a
user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30453/\"]http://secunia.com/advisories/30453/[/url]

--

[SA30452] My Phone Files Media Studio NCTSoft ActiveX Controls Buffer Overflow Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-30

Some vulnerabilities have been discovered in My Phone Files Media Studio, which can be exploited by malicious people to compromise a
user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30452/\"]http://secunia.com/advisories/30452/[/url]

--

[SA30451] Total Audio Capture NCTSoft ActiveX Controls Buffer Overflow Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-30

Some vulnerabilities have been discovered in Total Audio Capture, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30451/\"]http://secunia.com/advisories/30451/[/url]

--

[SA30450] Digital Smart Software Products NCTAudioFile2 ActiveX Control Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-30

A vulnerability has been discovered in Digital Smart Software products, which can be exploited by malicious people to compromise a user's
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30450/\"]http://secunia.com/advisories/30450/[/url]

--

[SA30447] HiFi Software Products NCTAudioFile2 ActiveX Control Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-30

A vulnerability has been discovered in various HiFi products, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30447/\"]http://secunia.com/advisories/30447/[/url]

--

[SA30446] Gold Wave Editor NCTAudioFile2 ActiveX Control Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-30

A vulnerability has been discovered in Gold Wave Editor, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30446/\"]http://secunia.com/advisories/30446/[/url]

--

[SA30547] Skype File URI Code Execution Vulnerability

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-06-05

A vulnerability has been reported in Skype, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30547/\"]http://secunia.com/advisories/30547/[/url]

--

[SA30503] Battle Blog "entry" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-04

Bl@ckbe@rD has reported a vulnerability in Battle Blog, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30503/\"]http://secunia.com/advisories/30503/[/url]

--

[SA30498] freeSSHd SFTP Directory Buffer Overflow Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-02

securfrog has discovered a vulnerability in freeSSHd, which can be exploited by malicious users to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30498/\"]http://secunia.com/advisories/30498/[/url]

--

[SA30487] Sleipnir Script Execution Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-06-04

A vulnerability has been reported in Sleipnir, which can be exploited by malicious people to execute arbitrary script code.

Full Advisory:
[url=\"http://secunia.com/advisories/30487/\"]http://secunia.com/advisories/30487/[/url]

--

[SA30474] MDaemon WorldClient Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-03

securfrog has discovered some vulnerabilities in MDaemon, which can be exploited by malicious people to cause a DoS (Denial of Service) and by malicious users to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30474/\"]http://secunia.com/advisories/30474/[/url]

--

[SA30455] DVBBS login.asp SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-05-30

hackerb has reported a vulnerability in DVBBS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30455/\"]http://secunia.com/advisories/30455/[/url]

--

[SA30502] HP StorageWorks Storage Mirroring Software Buffer Overflow

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-06-03

A vulnerability has been reported in HP StorageWorks Storage Mirroring Software, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30502/\"]http://secunia.com/advisories/30502/[/url]

--

[SA30532] BitKinex WebDAV and FTP Clients Directory Traversal Vulnerability

Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-06-04

Tan Chew Keong has reported two vulnerabilities in BitKinex, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30532/\"]http://secunia.com/advisories/30532/[/url]

--

[SA30481] DotNetNuke Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-02

AmnPardaz Security Research Team have reported a vulnerability in DotNetNuke, which can be exploited by malicious people to conduct
cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30481/\"]http://secunia.com/advisories/30481/[/url]

--

[SA30534] Kaspersky Products kl1.sys Driver Buffer Overflow Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-06-04

A vulnerability has been reported in some Kaspersky products, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30534/\"]http://secunia.com/advisories/30534/[/url]


[b]UNIX/Linux:--[/b]

[SA30546] NASA BigView PPM File Processing Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-05

Core Security Technologies has reported a vulnerability in NASA BigView, which can be exploited by malicious people to compromise a
user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30546/\"]http://secunia.com/advisories/30546/[/url]

--

[SA30543] SUSE update for samba

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-05

SUSE has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30543/\"]http://secunia.com/advisories/30543/[/url]

--

[SA30536] Red Hat update for evolution

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-04

Red Hat has issued an update for evolution. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30536/\"]http://secunia.com/advisories/30536/[/url]

--

[SA30535] VMware ESX Server Multiple Security Updates

Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-06-05

VMware has issued an update for VMware ESX Server. This fixes some vulnerabilities, which can be exploited by malicious people to disclose
potentially sensitive information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30535/\"]http://secunia.com/advisories/30535/[/url]

--

[SA30527] Red Hat update for evolution and evolution28

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-04

Red Hat has issued an update for evolution and evolution28. This fixes two vulnerabilities, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30527/\"]http://secunia.com/advisories/30527/[/url]

--

[SA30507] Sun Solaris update for Adobe Flash Player

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data, Exposure of sensitive information, Privilege escalation, DoS,
System access
Released: 2008-06-03

Sun has issued an update for Adobe Flash Player. This fixes some vulnerabilities where one has an unknown impact and others can be
exploited by malicious, local users to gain escalated privileges, and by malicious people to bypass certain security restrictions, conduct
cross-site scripting and HTTP request splitting attacks, disclose sensitive information, cause a Denial of Service (DoS), or to potentially compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30507/\"]http://secunia.com/advisories/30507/[/url]

--

[SA30491] rPath update for evolution

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-03

rPath has issued an update for evolution. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30491/\"]http://secunia.com/advisories/30491/[/url]

--

[SA30485] Fedora update for imlib2

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-03

Fedora has issued an update for imlib2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service) or compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/30485/\"]http://secunia.com/advisories/30485/[/url]

--

[SA30478] Debian update for samba

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-02

Debian has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30478/\"]http://secunia.com/advisories/30478/[/url]

--

[SA30449] Fedora update for samba

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-02

Fedora has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30449/\"]http://secunia.com/advisories/30449/[/url]

--

[SA30555] Asterisk Addons "ooh323" Denial of Service Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-06-05

A vulnerability has been reported in Asterisk Addons, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30555/\"]http://secunia.com/advisories/30555/[/url]

--

[SA30538] Sun Solaris "inet_network()" Off-By-One Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-05

Sun has acknowledged a vulnerability in Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30538/\"]http://secunia.com/advisories/30538/[/url]

--

[SA30521] Gentoo update for libxslt

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-04

Gentoo has issued an update for libxslt. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service) and potentially to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30521/\"]http://secunia.com/advisories/30521/[/url]

--

[SA30517] Asterisk "pedantic" SIP Processing Denial of Service

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-06-04

A vulnerability has been reported in Asterisk, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30517/\"]http://secunia.com/advisories/30517/[/url]

--

[SA30499] Linux Kernel Denial of Service Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-06-02

Some vulnerabilities have been reported in the Linux Kernel, which can be exploited by malicious, local users and malicious people to cause a
DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30499/\"]http://secunia.com/advisories/30499/[/url]

--

[SA30486] Fedora update for libpng

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-06-03

Fedora has issued an update for libpng. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service), disclose potentially sensitive information, or potentially compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/30486/\"]http://secunia.com/advisories/30486/[/url]

--

[SA30479] Debian update for libvorbis

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-03

Debian has issued an update for libvorbis. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) and potentially to compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/30479/\"]http://secunia.com/advisories/30479/[/url]

--

[SA30460] Fedora update for openssl

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-06-02

Fedora has issued an update for openssl. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30460/\"]http://secunia.com/advisories/30460/[/url]

--

[SA30553] Red Hat update for cups

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-06-05

Red Hat has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30553/\"]http://secunia.com/advisories/30553/[/url]

--

[SA30484] Solaris Samba Multiple Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-06-02

Sun has acknowledged some vulnerabilities in Solaris, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30484/\"]http://secunia.com/advisories/30484/[/url]

--

[SA30473] Avaya CMS Solaris Print Service Unspecified Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-06-02

Avaya has acknowledged some vulnerabilities in Avaya CMS, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30473/\"]http://secunia.com/advisories/30473/[/url]

--

[SA30475] GreenSQL-Console Cross-Site Scripting and Information Disclosure

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information
Released: 2008-06-02

Some vulnerabilities and a weakness have been reported in GreenSQL-Console, which can be exploited by malicious people to
disclose system information or conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30475/\"]http://secunia.com/advisories/30475/[/url]

--

[SA30522] Gentoo update for mtr

Critical: Less critical
Where: From local network
Impact: System access
Released: 2008-06-04

Gentoo has issued an update for mtr. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30522/\"]http://secunia.com/advisories/30522/[/url]

--

[SA30542] Avaya CMS Solaris crontab Privilege Escalation Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-06-05

Avaya has acknowledged a vulnerability in Avaya CMS, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30542/\"]http://secunia.com/advisories/30542/[/url]

--

[SA30515] Ubuntu update for linux

Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-06-04

Ubuntu has issued an update for the kernel. This fixes a security issue and some vulnerabilities, which can be exploited by malicious, local
users to cause a DoS (Denial of Service) or gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30515/\"]http://secunia.com/advisories/30515/[/url]

--

[SA30483] Sun Cluster Global File System Unspecified Vulnerability

Critical: Less critical
Where: Local system
Impact: Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-06-02

A vulnerability has been reported in Sun Cluster, which can be exploited by malicious, local users to disclose sensitive information
or potentially manipulate certain data.

Full Advisory:
[url=\"http://secunia.com/advisories/30483/\"]http://secunia.com/advisories/30483/[/url]

--

[SA30482] Sun Solaris crontab Privilege Escalation Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-06-02

A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30482/\"]http://secunia.com/advisories/30482/[/url]


[b]Other:--[/b]

[SA30552] Cisco ASA and PIX Security Appliances Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS
Released: 2008-06-05

Some vulnerabilities have been reported in Cisco ASA and PIX appliances, which can be exploited by malicious people to bypass
certain security restrictions or to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30552/\"]http://secunia.com/advisories/30552/[/url]

[b]
Cross Platform:--[/b]

[SA30523] Sun Java System Active Server Pages Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-06-04

Some vulnerabilities and a security issue have been reported in Sun Java System Active Server Pages, which can be exploited by malicious
users to compromise a vulnerable system, and by malicious people to disclose sensitive information, manipulate certain data, bypass certain
security restrictions, or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30523/\"]http://secunia.com/advisories/30523/[/url]

--

[SA30472] LokiCMS admin.php Authentication Bypass Vulnerability

Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-06-02

trueend5 has discovered a vulnerability in LokiCMS, which can be exploited by malicious people to bypass certain security restrictions
and compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30472/\"]http://secunia.com/advisories/30472/[/url]

--

[SA30463] CMSimple File Upload and Local File Inclusion

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-06-02

irk4z has reported two vulnerabilities in CMSimple, which can be exploited by malicious people to disclose sensitive information and
compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30463/\"]http://secunia.com/advisories/30463/[/url]

--

[SA30462] Social Site Generator Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Manipulation of data, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-06-02

Some vulnerabilities have been reported in Social Site Generator, which can be exploited by malicious people to disclose sensitive information,
conduct SQL injection attacks, and compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30462/\"]http://secunia.com/advisories/30462/[/url]

--

[SA30541] Joomla JotLoader Component "cid" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-05

His0k4 has discovered a vulnerability in the JotLoader component for Joomla!, which can be exploited by malicious people to conduct SQL
injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30541/\"]http://secunia.com/advisories/30541/[/url]

--

[SA30540] PHP Address Book Cross-Site Scripting and SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-06-05

CWH Underground has reported some vulnerabilities in PHP Address Book, which can be exploited by malicious people to conduct cross-site
scripting and SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30540/\"]http://secunia.com/advisories/30540/[/url]

--

[SA30526] IBM WebSphere Application Server Web Services Unspecified Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-06-04

A vulnerability with an unknown impact has been reported in IBM WebSphere Application Server.

Full Advisory:
[url=\"http://secunia.com/advisories/30526/\"]http://secunia.com/advisories/30526/[/url]

--

[SA30520] 427BB SQL Injection and Cross-Site Scripting vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-06-05

CWH Underground has discovered some vulnerabilities in 427BB, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30520/\"]http://secunia.com/advisories/30520/[/url]

--

[SA30513] Joomla JoomRadio Component "id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-04

His0k4 has discovered two vulnerabilities in the JoomRadio component for Joomla!, which can be exploited by malicious people to conduct SQL
injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30513/\"]http://secunia.com/advisories/30513/[/url]

--

[SA30505] Joomla IDoBlog Component "userid" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-04

His0k4 has discovered a vulnerability in the IDoBlog component for Joomla!, which can be exploited by malicious people to conduct SQL
injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30505/\"]http://secunia.com/advisories/30505/[/url]

--

[SA30504] OtomiGenX "userAccount" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-03

virangar security team (hadihadi) has discovered a vulnerability in OtomiGenX, which can be exploited by malicious people to conduct SQL
injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30504/\"]http://secunia.com/advisories/30504/[/url]

--

[SA30496] PassWiki "site_id" Local File Inclusion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-06-02

A vulnerability has been reported in PassWiki, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/30496/\"]http://secunia.com/advisories/30496/[/url]

--

[SA30495] LimeSurvey Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Unknown, Cross Site Scripting
Released: 2008-06-03

Some vulnerabilities have been reported in LimeSurvey, where some have unknown impacts and others can be exploited by malicious people to conduct cross-site request forgery attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30495/\"]http://secunia.com/advisories/30495/[/url]

--

[SA30494] CMS Easyway "mid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-04

Lidloses_Auge has reported a vulnerability in CMS Easyway, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30494/\"]http://secunia.com/advisories/30494/[/url]

--

[SA30493] Joomla PrayerCenter Component "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-02

His0k4 has discovered a vulnerability in the PrayerCenter component for Joomla, which can be exploited by malicious people to conduct SQL
injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30493/\"]http://secunia.com/advisories/30493/[/url]

--

[SA30492] Joomla Bible Study Component "id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-03

Stack & Jadi have reported a vulnerability in the Bible Study component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30492/\"]http://secunia.com/advisories/30492/[/url]

--

[SA30490] Joomla MyContent Component "id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-02

His0k4 has discovered a vulnerability in the MyContent component for Joomla!, which can be exploited by malicious people to conduct SQL
injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30490/\"]http://secunia.com/advisories/30490/[/url]

--

[SA30480] TorrentTrader "info_hash" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-02

Charles Vaughn has reported a vulnerability in TorrentTrader, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30480/\"]http://secunia.com/advisories/30480/[/url]

--

[SA30477] SMEweb Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-06-03

CWH Underground has discovered some vulnerabilities in SMEweb, which can be exploited by malicious people to conduct cross-site scripting
and SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30477/\"]http://secunia.com/advisories/30477/[/url]

--

[SA30468] ikiwiki Empty Passwords Security Issue

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-06-02

A security issue has been reported in ikiwiki, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/30468/\"]http://secunia.com/advisories/30468/[/url]

--

[SA30465] HiveMaker Professional "cid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-03

M.Hasran Addahroni has reported a vulnerability in HiveMaker Professional, which can be exploited by malicious people to conduct SQL
injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30465/\"]http://secunia.com/advisories/30465/[/url]

--

[SA30464] PsychoStats Multiple SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-02

Mr.SQL has reported some vulnerabilities in PsychoStats, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30464/\"]http://secunia.com/advisories/30464/[/url]

--

[SA30461] Joomla Simple Shop Galore Component "catid" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-05

His0k4 has discovered a vulnerability in the Simple Shop Galore component for Joomla!, which can be exploited by malicious people to
conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30461/\"]http://secunia.com/advisories/30461/[/url]

--

[SA30448] CMS from Scratch Information Disclosure and File Upload

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-05-30

Stack has discovered some vulnerabilities in CMS from Scratch, which can be exploited by malicious users to disclose sensitive information
and to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30448/\"]http://secunia.com/advisories/30448/[/url]

--

[SA30557] SamTodo "tid" and "completed" Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-05

David Sopas Ferreira has discovered some vulnerabilities in SamTodo, which can be exploited by malicious people to conduct cross-site
scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30557/\"]http://secunia.com/advisories/30557/[/url]

--

[SA30551] Slash Cross-Site Scripting and SQL Injection

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-06-05

Some vulnerabilities have been reported in Slash, which can be exploited by malicious users to conduct SQL injection attacks and by
malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30551/\"]http://secunia.com/advisories/30551/[/url]

--

[SA30524] phpInstantGallery Multiple Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-05

Some vulnerabilities have been discovered in phpInstantGallery, which can be exploited by malicious people to conduct cross-site scripting
attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30524/\"]http://secunia.com/advisories/30524/[/url]

--

[SA30500] Apache Tomcat Host Manager "name" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-03

A vulnerability has been reported in Tomcat, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30500/\"]http://secunia.com/advisories/30500/[/url]

--

[SA30488] meBiblio Multiple Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-03

CWH Underground has discovered some vulnerabilities in meBiblio, which can be exploited by malicious people to conduct cross-site scripting
attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30488/\"]http://secunia.com/advisories/30488/[/url]

--

[SA30466] Kaya CGI Framework HTTP Header Injection Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-02

A vulnerability has been reported in Kaya, which can be exploited by
malicious people to conduct HTTP header injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30466/\"]http://secunia.com/advisories/30466/[/url]

--

[SA30556] VMware Products Multiple Vulnerabilities

Critical: Less critical
Where: Local system
Impact: Security Bypass, Privilege escalation
Released: 2008-06-05

Some vulnerabilities have been reported in multiple VMware Products, which can be exploited by malicious, local users to bypass certain
security restrictions or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30556/\"]http://secunia.com/advisories/30556/[/url]

--

[SA30476] VMware Products Multiple Vulnerabilities

Critical: Less critical
Where: Local system
Impact: Security Bypass, Privilege escalation
Released: 2008-06-02

Some vulnerabilities have been reported in multiple VMware products, which can be exploited by malicious, local users to bypass certain
security restrictions or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30476/\"]http://secunia.com/advisories/30476/[/url]

--

[SA30545] Sun Service Tag Registry Local Denial of Service Weakness

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-06-05

A weakness has been reported in Sun Service Tag, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30545/\"]http://secunia.com/advisories/30545/[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Updates - June 2008

Post by Tami »

[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listings for the week of June 12 2008[/b][/i]

[b]Windows:--[/b]

[SA30625] Logitech Desktop Messenger BackWeb ActiveX Control Unspecified Buffer Overflows

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-11

Will Dormann has reported some vulnerabilities in Logitech Desktop Messenger, which can be exploited by malicious people to compromise a
user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30625/\"]http://secunia.com/advisories/30625/[/url]

--

[SA30603] Black Ice Annotation SDK BiAnno Control "AnnoSaveToTiff()" Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-11

shinnai has discovered a vulnerability in Black Ice Annotation SDK, which can be exploited by malicious people to compromise a user's
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30603/\"]http://secunia.com/advisories/30603/[/url]

--

[SA30598] BackWeb Lite Install Runner ActiveX Control Unspecified Buffer Overflows

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-11

Will Dormann has reported some vulnerabilities in BackWeb Lite Install Runner ActiveX Control, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30598/\"]http://secunia.com/advisories/30598/[/url]

--

[SA30579] Microsoft DirectX MJPEG/SAMI File Processing Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-10

Two vulnerabilities have been reported in Microsoft DirectX, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30579/\"]http://secunia.com/advisories/30579/[/url]

--

[SA30575] Internet Explorer "substringData()" Memory Corruption
Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-10

A vulnerability has been reported in Internet Explorer, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30575/\"]http://secunia.com/advisories/30575/[/url]

--

[SA30610] Pooya Site Builder SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-12

AmnPardaz Security Research Team has reported some vulnerabilities in Pooya Site Builder, which can be exploited by malicious people to
conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30610/\"]http://secunia.com/advisories/30610/[/url]

--

[SA30593] Todd Woolums ASP News Management Information Disclosure and SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-11

Some vulnerabilities have been discovered in Todd Woolums ASP News Management, which can be exploited by malicious people to disclose
potentially sensitive information and conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30593/\"]http://secunia.com/advisories/30593/[/url]

--

[SA30583] Realm CMS Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data, Exposure of system information
Released: 2008-06-10

AmnPardaz Security Research Team has reported some vulnerabilities in Realm CMS, which can be exploited by malicious people to bypass certain security restrictions, to disclose system information, or to conduct cross-site scripting and SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30583/\"]http://secunia.com/advisories/30583/[/url]

--

[SA30582] Real-Estate-Website Cross-Site Scripting and SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-06-10

JosS has reported some vulnerabilities in Real-Estate-Website, which can be exploited by malicious people to conduct cross-site scripting
and SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30582/\"]http://secunia.com/advisories/30582/[/url]

--

[SA30576] Novell GroupWise Messenger Client Buffer Overflow Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-06-09

Some vulnerabilities have been reported in Novell GroupWise Messenger, which can be exploited by malicious people to compromise a vulnerable
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30576/\"]http://secunia.com/advisories/30576/[/url]

--

[SA30569] JiRo's FAQ Manager eXperience "fID" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-09

Underz0ne Crew have reported a vulnerability in JiRo's FAQ Manager eXperience, which can be exploited by malicious people to conduct SQL
injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30569/\"]http://secunia.com/advisories/30569/[/url]

--

[SA30638] Citect Products ODBC Server Component Buffer Overflow

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-06-12

Core Security Technologies has reported a vulnerability in CitectSCADA and CitectFacilities, which can be exploited by malicious people to
cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30638/\"]http://secunia.com/advisories/30638/[/url]

--

[SA30643] Absolute News Manager XE Multiple Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-06-12

AmnPardaz Security Research Team has reported some vulnerabilities in Absolute News Manager XE, which can be exploited by malicious people to conduct cross-site scripting attacks and by malicious users to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30643/\"]http://secunia.com/advisories/30643/[/url]

--

[SA30641] Absolute Banner Manager XE Multiple Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-06-12

AmnPardaz Security Research Team has reported some vulnerabilities in Absolute Banner Manager XE, which can be exploited by malicious people to conduct cross-site scripting attacks and by malicious users to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30641/\"]http://secunia.com/advisories/30641/[/url]

--

[SA30640] Absolute Form Processor XE Cross-Site Scripting
Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-12

AmnPardaz Security Research Team has reported some vulnerabilities in
Absolute Form Processor XE, which can be exploited by malicious people
to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30640/\"]http://secunia.com/advisories/30640/[/url]

--

[SA30623] Tornado Knowledge Retrieval System "p" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-11

unohope has reported a vulnerability in Tornado Knowledge Retrieval System, which can be exploited by malicious people to conduct
cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30623/\"]http://secunia.com/advisories/30623/[/url]

--

[SA30617] DotNetNuke Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-12

Some vulnerabilities have been reported in DotNetNuke, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30617/\"]http://secunia.com/advisories/30617/[/url]

--

[SA30609] Absolute Control Panel XE "name" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-12

AmnPardaz Security Research Team has reported a vulnerability in Absolute Control Panel XE, which can be exploited by malicious people
to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30609/\"]http://secunia.com/advisories/30609/[/url]

--

[SA30605] BitTorrent Web UI Malformed HTTP "Range" Header Denial of
Service

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-06-11

Secunia Research has discovered a vulnerability in BitTorrent, which can be exploited by malicious people to cause a DoS (Denial of
Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30605/\"]http://secunia.com/advisories/30605/[/url]

--

[SA30578] Microsoft Windows Speech Recognition Security Issue

Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-06-10

A security issue has been reported in Microsoft Windows, which potentially can be exploited by malicious people to compromise a user's
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30578/\"]http://secunia.com/advisories/30578/[/url]

--

[SA30559] ALFTP FTP Client Directory Download Directory Traversal Vulnerability

Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-06-06

Tan Chew Keong has reported a vulnerability in ALFTP FTP Client, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30559/\"]http://secunia.com/advisories/30559/[/url]

--

[SA30587] Microsoft Windows Pragmatic General Multicast Denial of Service

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-06-10

Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30587/\"]http://secunia.com/advisories/30587/[/url]

--

[SA30586] Microsoft Windows Active Directory LDAP Request Processing Denial of Service

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-06-10

A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people or malicious users to cause a DoS (Denial
of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30586/\"]http://secunia.com/advisories/30586/[/url]

--

[SA30584] Microsoft Windows WINS Privilege Escalation Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-06-10

A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30584/\"]http://secunia.com/advisories/30584/[/url]


[b]UNIX/Linux:--
[/b]
[SA30634] Fedora update for openoffice.org

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-12

Fedora has issued an update for openoffice.org. This fixes a vulnerability, which can be exploited by malicious people to compromise
a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30634/\"]http://secunia.com/advisories/30634/[/url]

--

[SA30620] Sun Solaris Firefox Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-06-11

Sun has acknowledged some vulnerabilities in Firefox included in Sun Solaris, which can be exploited by malicious people to disclose
sensitive information, bypass certain security restrictions, conduct spoofing, cross-site scripting, and phishing attacks, or to compromise
a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30620/\"]http://secunia.com/advisories/30620/[/url]

--

[SA30581] SUSE Update for Multiple Packages

Critical: Highly critical
Where: From remote
Impact: Spoofing, Exposure of sensitive information, Privilege escalation, DoS, System access
Released: 2008-06-09

SUSE has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious, local users to
disclose potentially sensitive information, malicious users to gain escalated privileges, and malicious people to cause a DoS (Denial of
Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30581/\"]http://secunia.com/advisories/30581/[/url]

--

[SA30572] Gentoo update for imlib2

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-09

Gentoo has issued an update for imlib2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/30572/\"]http://secunia.com/advisories/30572/[/url]

--

[SA30571] Ubuntu update for evolution

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-09

Ubuntu has issued an update for evolution. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30571/\"]http://secunia.com/advisories/30571/[/url]

--

[SA30564] Fedora update for evolution

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-06

Fedora has issued an update for evolution. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30564/\"]http://secunia.com/advisories/30564/[/url]

--

[SA30652] Sun Java Access Manager Unspecified Security Bypass

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-06-12

A vulnerability has been reported in Sun Java Access Manager, which can be exploited by malicious people to bypass certain security
restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/30652/\"]http://secunia.com/advisories/30652/[/url]

--

[SA30624] Red Hat update for perl

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-12

Red Hat has issued an update for perl. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a
vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30624/\"]http://secunia.com/advisories/30624/[/url]

--

[SA30616] HP-UX update for Apache and Tomcat with PHP

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-06-11

HP has issued an update for Apache and Tomcat with PHP. This fixes a vulnerability, which can potentially be exploited by malicious people
to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30616/\"]http://secunia.com/advisories/30616/[/url]

--

[SA30591] Courier Authentication Library SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-10

A vulnerability has been reported in the Courier Authentication Library, which can be exploited by malicious people to conduct SQL
injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30591/\"]http://secunia.com/advisories/30591/[/url]

--

[SA30590] Iconfidant SSH Denial of Service Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-06-10

Some vulnerabilities have been reported in Iconfidant SSH, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30590/\"]http://secunia.com/advisories/30590/[/url]

--

[SA30644] rPath update for kernel

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-06-12

rPath has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service) and potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30644/\"]http://secunia.com/advisories/30644/[/url]

--

[SA30580] Linux Kernel ASN.1 BER Decoding Vulnerability

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-06-09

A vulnerability has been reported in the Linux Kernel, which can be exploited by malicious people to cause a DoS (Denial of Service) and
potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30580/\"]http://secunia.com/advisories/30580/[/url]

--

[SA30649] Fedora update for kronolith

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-12

Fedora has issued an update for kronolith. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site
scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30649/\"]http://secunia.com/advisories/30649/[/url]

--

[SA30592] Debian update for tomcat5.5

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-10

Debian has issued an update for tomcat5.5. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site
scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30592/\"]http://secunia.com/advisories/30592/[/url]

--

[SA30568] openwsman "Content-Length" Processing Vulnerability

Critical: Less critical
Where: From remote
Impact: Privilege escalation
Released: 2008-06-09

A vulnerability has been reported in openwsman, which can be exploited by malicious users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30568/\"]http://secunia.com/advisories/30568/[/url]

--

[SA30563] Fedora update for snort

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-06-06

Fedora has issued an update for snort. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security
restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/30563/\"]http://secunia.com/advisories/30563/[/url]

--

[SA30647] Fedora update for net-snmp

Critical: Less critical
Where: From local network
Impact: Spoofing, DoS, System access
Released: 2008-06-12

Fedora has issued an update for net-snmp. This fixes some vulnerabilities, which can be exploited by malicious people to spoof
authenticated SNMPv3 packets and potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30647/\"]http://secunia.com/advisories/30647/[/url]

--

[SA30615] Red Hat update for net-snmp

Critical: Less critical
Where: From local network
Impact: Spoofing, DoS, System access
Released: 2008-06-11

Red Hat has issued an update for net-snmp. This fixes some vulnerabilities, which can be exploited by malicious people to spoof
authenticated SNMPv3 packets and compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30615/\"]http://secunia.com/advisories/30615/[/url]

--

[SA30596] Red Hat update for ucd-snmp

Critical: Less critical
Where: From local network
Impact: Spoofing
Released: 2008-06-10

Red Hat has issued an update for ucd-snmp. This fixes a vulnerability, which can be exploited by malicious people to spoof authenticated
SNMPv3 packets.

Full Advisory:
[url=\"http://secunia.com/advisories/30596/\"]http://secunia.com/advisories/30596/[/url]

--

[SA30574] Net-SNMP HMAC Authentication Spoofing Vulnerability

Critical: Less critical
Where: From local network
Impact: Spoofing
Released: 2008-06-10

A vulnerability has been reported in Net-SNMP, which can be exploited by malicious people to spoof authenticated SNMPv3 packets.

Full Advisory:
[url=\"http://secunia.com/advisories/30574/\"]http://secunia.com/advisories/30574/[/url]

--

[SA30637] Debian update for xorg-server

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-06-12

Debian has issued an update for xorg-server. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30637/\"]http://secunia.com/advisories/30637/[/url]

--

[SA30630] Red Hat update for xorg-x11-server

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-06-12

Red Hat has issued an update for xorg-x11-server. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30630/\"]http://secunia.com/advisories/30630/[/url]

--

[SA30629] Red Hat update for XFree86

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-06-12

Red Hat has issued an update for XFree86. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30629/\"]http://secunia.com/advisories/30629/[/url]

--

[SA30628] Red Hat update for XFree86

Critical: Less critical
Where: Local system
Impact: DoS, Privilege escalation, Exposure of sensitive information
Released: 2008-06-12

Red Hat has issued an update for XFree86. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30628/\"]http://secunia.com/advisories/30628/[/url]

--

[SA30654] Sun Solaris UltraSPARC Kernel Module Local Denial of Service

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-06-12

A vulnerability has been reported in Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30654/\"]http://secunia.com/advisories/30654/[/url]

--

[SA30653] Sun Solaris Event Port Local Denial of Service

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-06-12

A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30653/\"]http://secunia.com/advisories/30653/[/url]


[b]Other:--[/b]

[SA30612] Cisco Products SNMPv3 Two Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: Spoofing
Released: 2008-06-11

Two vulnerabilities have been reported in various Cisco products, which can be exploited by malicious people to spoof authenticated SNMPv3
packets.

Full Advisory:
[url=\"http://secunia.com/advisories/30612/\"]http://secunia.com/advisories/30612/[/url]

--

[SA30648] Ingate Firewall and SIParator SNMP HMAC Spoofing

Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-06-12

Ingate has acknowledged a vulnerability in Ingate Firewall and SIParator, which can be exploited by malicious people to spoof
authenticated SNMPv3 packets.

Full Advisory:
[url=\"http://secunia.com/advisories/30648/\"]http://secunia.com/advisories/30648/[/url]

--

[SA30626] Juniper Networks Session and Resource Control Appliances SNMP HMAC Spoofing

Critical: Less critical
Where: From local network
Impact: Spoofing
Released: 2008-06-11

A vulnerability has been reported in Juniper Networks Session and Resource Control (SRC) appliances, which can be exploited by malicious
people to spoof authenticated SNMPv3 packets.

Full Advisory:
[url=\"http://secunia.com/advisories/30626/\"]http://secunia.com/advisories/30626/[/url]

--

[SA30562] Linksys WRH54G Denial of Service Vulnerability

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-06-10

A vulnerability has been reported in Linksys WRH54G, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30562/\"]http://secunia.com/advisories/30562/[/url]

[b]
Cross Platform:--[/b]

[SA30635] Sun StarOffice/StarSuite "rtl_allocateMemory()" Integer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-12

Sun has acknowledged a vulnerability in StarOffice/StarSuite, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30635/\"]http://secunia.com/advisories/30635/[/url]

--

[SA30599] OpenOffice "rtl_allocateMemory()" Integer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-10

A vulnerability has been reported in OpenOffice, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30599/\"]http://secunia.com/advisories/30599/[/url]

--

[SA30632] Drupal Magic Tabs Module Arbitrary PHP Code Execution

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-06-12

A vulnerability has been reported in the Magic Tabs module for Drupal, which can be exploited by malicious users to compromise a vulnerable
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30632/\"]http://secunia.com/advisories/30632/[/url]

--

[SA30619] TYPO3 File Upload and Cross-Site Scripting Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2008-06-11

Two vulnerabilities have been reported in TYPO3, which can be exploited by malicious people to conduct cross-site scripting attacks, and by
malicious users to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30619/\"]http://secunia.com/advisories/30619/[/url]

--

[SA30618] Drupal Aggregation Module Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data, System access
Released: 2008-06-12

Some vulnerabilities have been reported in the Aggregation module for Drupal, which can be exploited by malicious people to bypass certain
security restrictions, conduct cross-site scripting attacks, SQL injection attacks, and potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30618/\"]http://secunia.com/advisories/30618/[/url]

--

[SA30614] JAMM CMS "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-12

h0yt3r has reported a vulnerability in JAMM CMS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30614/\"]http://secunia.com/advisories/30614/[/url]

--

[SA30611] net2ftp Unspecified Request Handling Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information, System access
Released: 2008-06-11

Tan Chew Keong has reported a vulnerability in net2ftp, which potentially can be exploited by malicious people to disclose sensitive
information, delete certain files, and compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30611/\"]http://secunia.com/advisories/30611/[/url]

--

[SA30607] yblog SQL Injection and Cross-Site Scripting

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2008-06-12

unohope has discovered some vulnerabilities in yblog, which can be exploited by malicious people to conduct cross-site scripting and SQL
injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30607/\"]http://secunia.com/advisories/30607/[/url]

--

[SA30606] eFiction "list" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-12

Mr.SQL has discovered a vulnerability in eFiction, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30606/\"]http://secunia.com/advisories/30606/[/url]

--

[SA30600] FreeType Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-11

Some vulnerabilities have been reported in FreeType, which potentially can be exploited by malicious people to compromise an application using
the library.

Full Advisory:
[url=\"http://secunia.com/advisories/30600/\"]http://secunia.com/advisories/30600/[/url]

--

[SA30597] Achievo Multiple File Extensions Vulnerability

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-06-12

EgiX has discovered a vulnerability in Achievo, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30597/\"]http://secunia.com/advisories/30597/[/url]

--

[SA30595] TNTforum "modulo" Directory Traversal Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-06-11

A vulnerability has been discovered in TNTforum, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/30595/\"]http://secunia.com/advisories/30595/[/url]

--

[SA30589] Fujitsu Interstage Management Console Arbitrary File Access

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information
Released: 2008-06-10

A vulnerability has been reported in various Fujitsu products, which can be exploited by malicious people to bypass certain security
restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/30589/\"]http://secunia.com/advisories/30589/[/url]

--

[SA30577] Powie pNews "shownews" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-10

Cr@zy_King has discovered a vulnerability in Powie pNews, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30577/\"]http://secunia.com/advisories/30577/[/url]

--

[SA30570] Joomla GameQ Component "category_id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-09

His0k4 has discovered a vulnerability in the GameQ component for Joomla!, which can be exploited by malicious people to conduct SQL
injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30570/\"]http://secunia.com/advisories/30570/[/url]

--

[SA30567] Joomla yvComment Component "ArticleID" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-09

His0k4 has discovered a vulnerability in the yvComment component for Joomla!, which can be exploited by malicious people to conduct SQL
injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30567/\"]http://secunia.com/advisories/30567/[/url]

--

[SA30566] Joomla Rapid Recipe Component "recipe_id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-09

His0k4 has discovered a vulnerability in the Rapid Recipe component for Joomla!, which can be exploited by malicious people to conduct SQL
injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30566/\"]http://secunia.com/advisories/30566/[/url]

--

[SA30561] e107 eChat Plugin "nick" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-06

hadihadi has discovered a vulnerability in the eChat plugin for e107, which can be exploited by malicious people to conduct SQL injection
attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30561/\"]http://secunia.com/advisories/30561/[/url]

--

[SA30560] VLC Media Player GnuTLS and Libxml2 Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-09

Some vulnerabilities have been reported in VLC Media Player, which potentially can be exploited by malicious people to cause a DoS (Denial
of Service) or compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30560/\"]http://secunia.com/advisories/30560/[/url]

--

[SA30650] Gallery Multiple Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data, Exposure of system information, Exposure of sensitive
information
Released: 2008-06-12

Some vulnerabilities and a weakness have been reported in Gallery, which can be exploited by malicious people to conduct cross-site
scripting attacks, disclose sensitive information, and manipulate data.

Full Advisory:
[url=\"http://secunia.com/advisories/30650/\"]http://secunia.com/advisories/30650/[/url]

--

[SA30636] Opera Multiple Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Spoofing, Exposure of sensitive information
Released: 2008-06-12

Some vulnerabilities have been reported in Opera, which can be exploited by malicious people to disclose potentially sensitive
information or to conduct spoofing attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30636/\"]http://secunia.com/advisories/30636/[/url]

--

[SA30631] Drupal Taxonomy Image Module Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-12

Some vulnerabilities have been reported in the Taxonomy Image module for Drupal, which can be exploited by malicious people to conduct
cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30631/\"]http://secunia.com/advisories/30631/[/url]

--

[SA30621] Apache mod_proxy Interim Responses Denial of Service

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-06-11

A vulnerability has been reported in the Apache mod_proxy module, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30621/\"]http://secunia.com/advisories/30621/[/url]

--

[SA30608] IPTBB "email" SQL Injection Vulnerability

Critical: Less critical
Where: From remote
Impact: Manipulation of data, Privilege escalation
Released: 2008-06-12

CWH Underground has discovered a vulnerability in IPTBB, which can be exploited by malicious users to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30608/\"]http://secunia.com/advisories/30608/[/url]

--

[SA30604] GlassFish Administration Console Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-11

Eduardo Neves has discovered a vulnerability in GlassFish, which can be
exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30604/\"]http://secunia.com/advisories/30604/[/url]

--

[SA30602] SyndeoCMS File Disclosure and Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-06-11

CWH Underground has discovered some vulnerabilities in SyndeoCMS, which can be exploited by malicious people to conduct cross-site scripting
attacks, and by malicious users to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/30602/\"]http://secunia.com/advisories/30602/[/url]

--

[SA30594] NASM "ppscan()" Off-By-One Vulnerability

Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-06-11

A vulnerability has been reported in NASM, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30594/\"]http://secunia.com/advisories/30594/[/url]

--

[SA30573] PHP Image Gallery "action" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-10

Russ McRee has reported a vulnerability in PHP Image Gallery, which can be exploited by malicious people to conduct cross-site scripting
attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30573/\"]http://secunia.com/advisories/30573/[/url]

--

[SA30627] X.org X11 Multiple Vulnerabilities

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation,
DoS
Released: 2008-06-12

Some vulnerabilities have been reported in X.org X11, which can be exploited by malicious, local users to cause a DoS (Denial of Service),
disclose potentially sensitive information, or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30627/\"]http://secunia.com/advisories/30627/[/url]

--

[SA30622] Drupal Node Hierarchy Module Improper Access Check

Critical: Not critical
Where: From remote
Impact: Security Bypass
Released: 2008-06-12

A security issue has been reported in the Node Hierarchy module for Drupal, which can be exploited by malicious users to bypass certain
security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/30622/\"]http://secunia.com/advisories/30622/[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Updates - June 2008

Post by Tami »

[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of June 19 2008[/b][/i]

[b]Windows:--[/b]

[SA30709] Novell iPrint Client ActiveX Control Parameter Handling Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Unknown, System access
Released: 2008-06-16

Some vulnerabilities have been discovered in Novell iPrint Client, which can be exploited by malicious people to compromise a user's
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30709/\"]http://secunia.com/advisories/30709/[/url]

--

[SA30696] muvee autoProducer DXTTextOutEffect "FontSetting" Property Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-16

Nine:Situations:Group::Trotzkista has discovered a vulnerability in muvee autoProducer, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30696/\"]http://secunia.com/advisories/30696/[/url]

--

[SA30695] XChat "ircs" URI Handling Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-16

securfrog has discovered a vulnerability in XChat, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30695/\"]http://secunia.com/advisories/30695/[/url]

--

[SA30707] S.T.A.L.K.E.R.: Shadow of Chernobyl Long Nickname Denial of Service

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-06-19

Luigi Auriemma has reported a vulnerability in S.T.A.L.K.E.R.: Shadow of Chernobyl, which can be exploited by malicious people to cause a DoS
(Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30707/\"]http://secunia.com/advisories/30707/[/url]

--

[SA30705] doITLive CMS Cross-Site Scripting and SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-06-19

AmnPardaz Security Research Team has reported a vulnerability in doITLive CMS, which can be exploited by malicious people to conduct
cross-site scripting and SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30705/\"]http://secunia.com/advisories/30705/[/url]

--

[SA30687] E-SMART CART "category_id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-16

JosS has reported a vulnerability in E-SMART CART, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30687/\"]http://secunia.com/advisories/30687/[/url]

--

[SA30681] Dana IRC Client Buffer Overflow Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-16

t0pP8uZz has discovered a vulnerability in the Dana IRC client, which potentially can be exploited by malicious people to compromise a user's
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30681/\"]http://secunia.com/advisories/30681/[/url]

--

[SA30675] Crysis HTTP/XML-RPC Server Denial of Service

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-06-17

Luigi Auriemma has reported a vulnerability in Crysis, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30675/\"]http://secunia.com/advisories/30675/[/url]

--

[SA30749] UltraEdit FTP/SFTP Browser Directory Download Directory Traversal Vulnerability

Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-06-18

Tan Chew Keong has reported a vulnerability in UltraEdit, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30749/\"]http://secunia.com/advisories/30749/[/url]

--

[SA30745] ManageEngine OpUtils "hostName" Script Insertion Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-18

Jason Rhodes has discovered a vulnerability in ManageEngine OpUtils, which can be exploited by malicious users to conduct script insertion
attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30745/\"]http://secunia.com/advisories/30745/[/url]

--

[SA30739] SurgeMail IMAP Processing Denial of Service Vulnerability

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-06-19

A vulnerability has been reported in SurgeMail, which can be exploited by malicious users to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30739/\"]http://secunia.com/advisories/30739/[/url]

--

[SA30725] Glub Tech Secure FTP Directory Download Directory Traversal Vulnerability

Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-06-16

Tan Chew Keong has reported a vulnerability in Glub Tech Secure FTP, which can be exploited by malicious people to compromise a user's
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30725/\"]http://secunia.com/advisories/30725/[/url]

--

[SA30706] Crysis Disconnect Packet Information Disclosure

Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-06-16

Luigi Auriemma has reported a security issue in Crysis, which can be exploited by malicious people to disclose potentially sensitive
information.

Full Advisory:
[url=\"http://secunia.com/advisories/30706/\"]http://secunia.com/advisories/30706/[/url]

--

[SA30753] BlueCoat WinProxy Deterministic Network Enhancer Privilege Escalation

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-06-18

mu-b has reported a vulnerability in BlueCoat WinProxy, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30753/\"]http://secunia.com/advisories/30753/[/url]

--

[SA30747] Cisco VPN Client Deterministic Network Enhancer Privilege Escalation

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-06-18

mu-b has reported a vulnerability in Cisco VPN Client, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30747/\"]http://secunia.com/advisories/30747/[/url]

--

[SA30744] SafeNet Products Deterministic Network Enhancer Privilege Escalation

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-06-18

mu-b has reported a vulnerability in SafeNet products, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30744/\"]http://secunia.com/advisories/30744/[/url]

--

[SA30741] Symantec Altiris Notification Server Agent GUI Privilege Escalation

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-06-18

A vulnerability has been reported in Symantec Altiris Notification Server, which can be exploited by malicious, local users to gain
escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30741/\"]http://secunia.com/advisories/30741/[/url]

--

[SA30728] Deterministic Network Enhancer Privilege Escalation Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-06-18

mu-b has reported a vulnerability in Deterministic Network Enhancer, which can be exploited by malicious, local users to gain escalated
privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30728/\"]http://secunia.com/advisories/30728/[/url]

--

[SA30714] No-IP Windows Dynamic Update Client Information Disclosure

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-06-17

Charalambous Glafkos and George Nicolaou have discovered a security issue in No-IP Windows Dynamic Update Client (DUC), which can be
exploited by malicious, local users to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/30714/\"]http://secunia.com/advisories/30714/[/url]

[b]
UNIX/Linux:--[/b]

[SA30736] Ubuntu update for samba

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-18

Ubuntu has issued an update for samba. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a vulnerable
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30736/\"]http://secunia.com/advisories/30736/[/url]

--

[SA30727] Debian update for imlib2

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-16

Debian has issued an update for imlib2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service) and compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/30727/\"]http://secunia.com/advisories/30727/[/url]

--

[SA30720] Red Hat update for openoffice.org

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-16

Red Hat has issued an update for openoffice.org. This fixes a vulnerability, which can be exploited by malicious people to compromise
a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30720/\"]http://secunia.com/advisories/30720/[/url]

--

[SA30717] SUSE Update for Multiple Packages

Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-06-16

SUSE has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious, local users to
bypass certain security restrictions and malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30717/\"]http://secunia.com/advisories/30717/[/url]

--

[SA30716] SUSE update for evolution

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-16

SUSE has issued an update for evolution. This fixes a two vulnerabilities, which can be exploited by malicious people to
compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30716/\"]http://secunia.com/advisories/30716/[/url]

--

[SA30702] Gentoo update for evolution

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-17

Gentoo has issued an update for evolution. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30702/\"]http://secunia.com/advisories/30702/[/url]

--

[SA30676] VMware ESX Server update for Tomcat and Java JRE

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-06-17

VMware has issued an update for VMware ESX Server. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service), bypass certain security restrictions, manipulate data, disclose sensitive/system information, or potentially
compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30676/\"]http://secunia.com/advisories/30676/[/url]

--

[SA30766] Sun Solaris FreeType Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-19

Sun has acknowledged some vulnerabilities in Solaris, which can potentially can be exploited by malicious people to compromise an
application using the libfreetype library.

Full Advisory:
[url=\"http://secunia.com/advisories/30766/\"]http://secunia.com/advisories/30766/[/url]

--

[SA30740] Fedora update for freetype

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-18

Fedora has issued an update for freetype. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/30740/\"]http://secunia.com/advisories/30740/[/url]

--

[SA30735] Fedora update for roundcubemail

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-16

Fedora has issued an update for roundcubemail. This fixes a vulnerability, which can be exploited by malicious people to conduct
script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30735/\"]http://secunia.com/advisories/30735/[/url]

--

[SA30718] Avaya CMS Solaris "inet_network()" Off-By-One Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-16

Avaya has acknowledged a vulnerability in Avaya CMS, which can be exploited by malicious people to cause a DoS (Denial of Service) or to
potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30718/\"]http://secunia.com/advisories/30718/[/url]

--

[SA30713] Gentoo update for rdesktop

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-06-16

Gentoo has issued an update for rdesktop. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30713/\"]http://secunia.com/advisories/30713/[/url]

--

[SA30701] Gentoo update for cbrpager

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-06-17

Gentoo has issued an update for cbrpager. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30701/\"]http://secunia.com/advisories/30701/[/url]

--

[SA30694] Sun Java System Calendar Server Denial of Service

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-06-17

A vulnerability has been reported in Sun Java System Calendar Server, which can be exploited by malicious people to cause a DoS (Denial of
Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30694/\"]http://secunia.com/advisories/30694/[/url]

--

[SA30660] Debian update for typo3

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2008-06-13

Debian has issued an update for typo3. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site
scripting attacks, and by malicious users to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30660/\"]http://secunia.com/advisories/30660/[/url]

--

[SA30661] Debian update for mt-daapd

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-06-13

Debian has issued an update for mt-daapd. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30661/\"]http://secunia.com/advisories/30661/[/url]

--

[SA30658] Fedora update for kernel

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-06-13

Fedora has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service) and potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30658/\"]http://secunia.com/advisories/30658/[/url]

--

[SA30765] CGIWrap Error Message Charset Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-19

A vulnerability has been reported in CGIWrap, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30765/\"]http://secunia.com/advisories/30765/[/url]

--

[SA30742] Fetchmail Large Header Processing Denial of Service

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-06-18

A vulnerability has been reported in Fetchmail, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30742/\"]http://secunia.com/advisories/30742/[/url]

--

[SA30682] SUSE update for opera

Critical: Less critical
Where: From remote
Impact: Spoofing, Exposure of sensitive information
Released: 2008-06-19

SUSE has issued an update for opera. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially
sensitive information or to conduct spoofing attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30682/\"]http://secunia.com/advisories/30682/[/url]

--

[SA30719] Linux Kernel "pppol2tp_recvmsg()" Memory Corruption Vulnerability

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-06-16

A vulnerability has been reported in the Linux Kernel, which potentially can be exploited by malicious people to cause a DoS (Denial
of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30719/\"]http://secunia.com/advisories/30719/[/url]

--

[SA30700] Sun Solaris e1000g Gigabit Ethernet Driver Denial of Service

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-06-16

A vulnerability has been reported in Sun Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30700/\"]http://secunia.com/advisories/30700/[/url]

--

[SA30665] Sun Solaris SNMPv3 Authentication Bypass

Critical: Less critical
Where: From local network
Impact: Security Bypass
Released: 2008-06-16

Sun has acknowledged a vulnerability in Solaris, which can be exploited by malicious people to spoof authenticated SNMPv3 packets.

Full Advisory:
[url=\"http://secunia.com/advisories/30665/\"]http://secunia.com/advisories/30665/[/url]

--

[SA30715] SUSE update for xorg-x11 and XFree86

Critical: Less critical
Where: Local system
Impact: Security Bypass, Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-06-16

SUSE has issued an update for xorg-x11 and XFree86. This fixes a security issue and some vulnerabilities, which can be exploited by
malicious people with physical access to a system to bypass certain security restrictions and by malicious local users to cause a DoS
(Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30715/\"]http://secunia.com/advisories/30715/[/url]

--

[SA30693] Sun Solaris IP Multicast Filter Privilege Escalation

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-06-16

Tobias Klein has reported a vulnerability in Sun Solaris, which potentially can be exploited by malicious, local users to gain
escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30693/\"]http://secunia.com/advisories/30693/[/url]

--

[SA30671] Sun Solaris X Server Extensions Multiple Vulnerabilities

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-06-16

Sun has acknowledged multiple vulnerabilities in Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service),
disclose potentially sensitive information, or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30671/\"]http://secunia.com/advisories/30671/[/url]

--

[SA30666] Debian update for xorg-server

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-06-13

Debian has issued an update for xorg-server. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30666/\"]http://secunia.com/advisories/30666/[/url]

--

[SA30664] Ubuntu update for xorg-server

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-06-13

Ubuntu has issued an update for xorg-server. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30664/\"]http://secunia.com/advisories/30664/[/url]

--

[SA30659] Fedora update for xorg-x11-server

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-06-13

Fedora has issued an update for xorg-x11-server. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30659/\"]http://secunia.com/advisories/30659/[/url]


[b]Other:--[/b]

[SA30767] Cisco Intrusion Prevention System Jumbo Frames Denial of Service

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS
Released: 2008-06-19

A vulnerability has been reported in Cisco Intrusion Prevention System, which can be exploited by malicious people to cause a DoS (Denial of
Service) or bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/30767/\"]http://secunia.com/advisories/30767/[/url]

--

[SA30732] IBM HMC Apache Multiple Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-18

IBM has acknowledged some vulnerabilities in IBM HMC, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30732/\"]http://secunia.com/advisories/30732/[/url]

--

[SA30670] Xerox WorkCenter Web Services Unspecified Unauthorized Access

Critical: Less critical
Where: From local network
Impact: Security Bypass, Manipulation of data
Released: 2008-06-13

A vulnerability has been reported in Xerox WorkCentre, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/30670/\"]http://secunia.com/advisories/30670/[/url]

--

[SA30669] Xerox WorkCentre Web Server Unspecified Script Insertion

Critical: Less critical
Where: From local network
Impact: Cross Site Scripting
Released: 2008-06-13

A vulnerability has been reported in Xerox WorkCentre, which can be exploited by malicious people to conduct script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30669/\"]http://secunia.com/advisories/30669/[/url]


[b]Cross Platform:-[/b]-

[SA30761] Mozilla Firefox Unspecified Code Execution Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-19

A vulnerability has been reported in Mozilla Firefox, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30761/\"]http://secunia.com/advisories/30761/[/url]

--

[SA30683] Contenido Cross-Site Scripting and File Inclusion Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-06-16

RoMaNcYxHaCkEr has discovered some vulnerabilities in Contenido, which can be exploited by malicious people to conduct cross-site scripting
attacks, disclose sensitive information, or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30683/\"]http://secunia.com/advisories/30683/[/url]

--

[SA30674] EZCMS "page" SQL Injection and Security Bypass Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-06-16

Some vulnerabilities have been reported in EZCMS, which can be exploited by malicious people to conduct SQL injection attacks and
bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/30674/\"]http://secunia.com/advisories/30674/[/url]

--

[SA30764] Drupal TrailScout Module Cross-Site Scripting and SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-06-19

Some vulnerabilities have been reported in the TrailScout Module for Drupal, which can be exploited by malicious users to conduct script
insertion attacks and malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30764/\"]http://secunia.com/advisories/30764/[/url]

--

[SA30759] OFFSystem HTTP Headers Processing Buffer Overflows

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-19

Some vulnerabilities have been reported in OFFSystem, which potentially can be exploited by malicious people to cause a DoS (Denial of Service)
or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30759/\"]http://secunia.com/advisories/30759/[/url]

--

[SA30743] BoatScripts Classifieds "type" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-19

Stack has reported a vulnerability in BoatScripts Classifieds, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30743/\"]http://secunia.com/advisories/30743/[/url]

--

[SA30738] Carscripts Classifieds "cat" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-19

Stack has reported a vulnerability in Carscripts Classifieds, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30738/\"]http://secunia.com/advisories/30738/[/url]

--

[SA30734] RoundCube Webmail Script Insertion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-16

A vulnerability has been reported in RoundCube Webmail, which can be exploited by malicious people to conduct script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30734/\"]http://secunia.com/advisories/30734/[/url]

--

[SA30733] vBulletin Cross-Site Scripting Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-16

A vulnerability has been reported in vBulletin, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30733/\"]http://secunia.com/advisories/30733/[/url]

--

[SA30731] Vim Shell Command Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-06-16

Jan Minar has reported some vulnerabilities in Vim, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30731/\"]http://secunia.com/advisories/30731/[/url]

--

[SA30729] Comparison Engine Power "id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-18

Mr.SQL has reported a vulnerability in Comparison Engine Power, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30729/\"]http://secunia.com/advisories/30729/[/url]

--

[SA30726] Easy Webstore "cat_path" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-19

Mr.SQL has reported a vulnerability in Easy Webstore, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30726/\"]http://secunia.com/advisories/30726/[/url]

--

[SA30724] MyBizz-Classifieds "cat" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-19

HaCker_Egy has reported a vulnerability in MyBizz-Classifieds, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30724/\"]http://secunia.com/advisories/30724/[/url]

--

[SA30723] eroCMS "site" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-18

Mr.SQL has reported a vulnerability in eroCMS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30723/\"]http://secunia.com/advisories/30723/[/url]

--

[SA30722] Maxtrade AIO "categori" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-19

HaCker_Egy has reported a vulnerability in Maxtrade AIO, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30722/\"]http://secunia.com/advisories/30722/[/url]

--

[SA30711] Exero CMS "theme" Local File Inclusion Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-06-18

Some vulnerabilities have been reported in Exero CMS, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/30711/\"]http://secunia.com/advisories/30711/[/url]

--

[SA30699] Clever Copy "searchtype" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-16

h0yt3r has discovered a vulnerability in Clever Copy, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30699/\"]http://secunia.com/advisories/30699/[/url]

--

[SA30692] MyMarket "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-17

h0yt3r has discovered a vulnerability in MyMarket, which can be
exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30692/\"]http://secunia.com/advisories/30692/[/url]

--

[SA30691] Open Azimyt CMS "lang" Local File Inclusion

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-06-18

Digital Security Research Group have reported a vulnerability in Open Azimyt CMS, which can be exploited by malicious people to disclose
sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/30691/\"]http://secunia.com/advisories/30691/[/url]

--

[SA30690] WebChamado SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-16

Some vulnerabilities have been reported in WebChamado, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30690/\"]http://secunia.com/advisories/30690/[/url]

--

[SA30689] Pre ADS Portal SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-16

M.Hasran Addahroni has reported a vulnerability in Pre ADS Portal, which can be exploited by malicious people to conduct SQL injection
attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30689/\"]http://secunia.com/advisories/30689/[/url]

--

[SA30688] gllcTS2 SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-16

Some vulnerabilities have been reported in gllcTS2, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30688/\"]http://secunia.com/advisories/30688/[/url]

--

[SA30686] PHP JOBWEBSITE PRO "JobSearch3.php" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-16

Two vulnerabilities have been reported in PHP JOBWEBSITE PRO, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30686/\"]http://secunia.com/advisories/30686/[/url]

--

[SA30685] Mambo "includes/Cache/Lite/Output.php" File Inclusion

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information, System access
Released: 2008-06-16

irk4z has discovered a vulnerability in Mambo, which can be exploited by malicious people to disclose sensitive information and compromise a
vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30685/\"]http://secunia.com/advisories/30685/[/url]

--

[SA30684] Pre Job Board "JobSearch3.php" SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-16

JosS has reported a vulnerability in Pre Job Board, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30684/\"]http://secunia.com/advisories/30684/[/url]

--

[SA30679] PHPMyCart "cat" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-16

h0yt3r has reported a vulnerability in PHPMyCart, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30679/\"]http://secunia.com/advisories/30679/[/url]

--

[SA30678] WallCity-Server Shoutcast Admin Panel Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-06-16

Some vulnerabilities have been discovered in Shoutcast Admin Panel, which can be exploited by malicious people to conduct cross-site
scripting attacks or to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/30678/\"]http://secunia.com/advisories/30678/[/url]

--

[SA30677] Cartweaver "prodId" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-16

h0yt3r has reported a vulnerability in Cartweaver, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30677/\"]http://secunia.com/advisories/30677/[/url]

--

[SA30673] easyTrade "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-18

A vulnerability has been reported in easyTrade, which can be exploited by malicious people to conduct SQL injection attacks

Full Advisory:
[url=\"http://secunia.com/advisories/30673/\"]http://secunia.com/advisories/30673/[/url]

--

[SA30672] AlstraSoft AskMe Pro SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, Manipulation of data
Released: 2008-06-16

t0pP8uZz has reported some vulnerabilities in AstraSoft AskMe Pro, which can be exploited by malicious people to conduct SQL injection
attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30672/\"]http://secunia.com/advisories/30672/[/url]

--

[SA30668] Skulltag Packet Parsing Denial of Service

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-06-17

Luigi Auriemma has reported a vulnerability in Skulltag, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30668/\"]http://secunia.com/advisories/30668/[/url]

--

[SA30657] ClamAV Petite Processing Denial of Service Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-06-17

A vulnerability has been reported in ClamAV, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30657/\"]http://secunia.com/advisories/30657/[/url]

--

[SA30758] DekiWiki Search Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-19

A vulnerability has been reported in DekiWiki, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30758/\"]http://secunia.com/advisories/30758/[/url]

--

[SA30750] OpenDocMan Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-18

Some vulnerabilities have been discovered in OpenDocMan, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30750/\"]http://secunia.com/advisories/30750/[/url]

--

[SA30748] Novell eDirectory iMonitor Error Message Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-18

A vulnerability has been reported in Novell eDirectory, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30748/\"]http://secunia.com/advisories/30748/[/url]

--

[SA30746] Adobe Flex 3 History Management Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-18

A vulnerability has been reported in Adobe Flex 3, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30746/\"]http://secunia.com/advisories/30746/[/url]

--

[SA30704] Turba Contact View Script Insertion Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-16

A vulnerability has been reported in Turba, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30704/\"]http://secunia.com/advisories/30704/[/url]

--

[SA30698] MediaWiki WikiHiero Extension Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-17

Some vulnerabilities have been reported in the WikiHiero extension for MediaWiki, which can be exploited by malicious people to conduct
cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30698/\"]http://secunia.com/advisories/30698/[/url]

--

[SA30697] Horde Products Cross-Site Scripting and Script Insertion

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-16

Some vulnerabilities have been reported in various Horde products, which can be exploited by malicious users to conduct script insertion
attacks and by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30697/\"]http://secunia.com/advisories/30697/[/url]

--

[SA30680] Family Connections Multiple SQL Injection Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-16

CWH Underground has discovered some vulnerabilities in Family Connections, which can be exploited by malicious users to conduct SQL
injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30680/\"]http://secunia.com/advisories/30680/[/url]

--

[SA30662] Lyris ListManager "words" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-16

Russ McRee has discovered a vulnerability in Lyris ListManager, which can be exploited by malicious people to conduct cross-site scripting
attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30662/\"]http://secunia.com/advisories/30662/[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Updates - June 2008

Post by Tami »

[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of June 26 2008[/b][/i]

[b]Windows:--[/b]

[SA30775] Apple Safari for Windows Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2008-06-20

Some vulnerabilities and a security issue have been reported in Apple Safari, which can be exploited by malicious people to disclose
sensitive information or to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30775/\"]http://secunia.com/advisories/30775/[/url]

--

[SA30858] Ektron CMS400.NET Unspecified Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-06-26

A vulnerability has been reported in Ektron CMS400.NET, which has an unknown impact.

Full Advisory:
[url=\"http://secunia.com/advisories/30858/\"]http://secunia.com/advisories/30858/[/url]

--

[SA30857] Internet Explorer 6 Window "location" Handling Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-06-26

Ph4nt0m Security Team has discovered a vulnerability in Internet Explorer 6, which can be exploited by malicious people to conduct
cross-domain scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30857/\"]http://secunia.com/advisories/30857/[/url]

--

[SA30851] Internet Explorer 7 Frame Location Handling Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Spoofing
Released: 2008-06-26

sirdarckcat has discovered a vulnerability in Internet Explorer, which can be exploited by malicious people to conduct spoofing attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30851/\"]http://secunia.com/advisories/30851/[/url]

--

[SA30824] Ektron CMS400.NET "res" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-26

DigiTrust Group Vulnerability Research Team has reported a vulnerability in Ektron CMS400.NET, which can be exploited by malicious
people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30824/\"]http://secunia.com/advisories/30824/[/url]

--

[SA30823] SunAge Multiple Denial of Service Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-06-26

Luigi Auriemma has reported some vulnerabilities in SunAge, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30823/\"]http://secunia.com/advisories/30823/[/url]

--

[SA30815] Call of Duty 4: Modern Warfare Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-23

Luigi Auriemma has reported some vulnerabilities in Call of Duty 4: Modern Warfare, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30815/\"]http://secunia.com/advisories/30815/[/url]

--

[SA30787] sHibby sHop "sayfa" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-23

KnocKout has reported a vulnerability in sHibby sHop, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30787/\"]http://secunia.com/advisories/30787/[/url]

--

[SA30774] DUware DUcalendar "iEve" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-25

Bl@ckbe@rD has reported a vulnerability in DUware DUcalendar, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30774/\"]http://secunia.com/advisories/30774/[/url]

--

[SA30854] Nortel SIP Multimedia PC Client Session Handling Denial of Service

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-06-26

A vulnerability has been reported in Nortel SIP Multimedia PC Client, which can be exploited by malicious people to cause a DoS (Denial of
Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30854/\"]http://secunia.com/advisories/30854/[/url]

--

[SA30788] WISE-FTP 4 Directory Download Directory Traversal Vulnerability

Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-06-20

Tan Chew Keong has reported a vulnerability in WISE-FTP, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30788/\"]http://secunia.com/advisories/30788/[/url]

--

[SA30848] Cisco Unified Communications Manager Authentication Bypass and Denial of Service

Critical: Less critical
Where: From local network
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, DoS
Released: 2008-06-26

A vulnerability and a security issue have been reported in Cisco Unified Communications Manager, which can be exploited by malicious
people to bypass certain security restrictions or to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30848/\"]http://secunia.com/advisories/30848/[/url]

--

[SA30812] DC++ NULL Pointer Dereference Denial of Service

Critical: Not critical
Where: From remote
Impact: DoS
Released: 2008-06-25

A weakness has been reported in DC++, which can be exploited by
malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30812/\"]http://secunia.com/advisories/30812/[/url]


[b]UNIX/Linux:--[/b]

[SA30840] Sun Solaris Adobe Reader Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-26

Sun has acknowledged some vulnerabilities in Adobe Reader included in Sun Solaris, which can be exploited by malicious people to cause a DoS
(Denial of Service) or compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30840/\"]http://secunia.com/advisories/30840/[/url]

--

[SA30835] HP-UX HP CIFS Server Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-24

HP has acknowledged some vulnerabilities in HP-UX, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30835/\"]http://secunia.com/advisories/30835/[/url]

--

[SA30831] Fedora update for ruby

Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-06-25

Fedora has issued an update for ruby. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive
information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30831/\"]http://secunia.com/advisories/30831/[/url]

--

[SA30805] Red Hat update for IBMJava2-JRE and IBMJava2-SDK

Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-06-24

Red Hat has issued an update for IBMJava2-JRE and IBMJava2-SDK. This fixes some vulnerabilities, which potentially can be exploited by
malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30805/\"]http://secunia.com/advisories/30805/[/url]

--

[SA30780] Gentoo update for ibm-jdk-bin and ibm-jre-bin

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-06-25

Gentoo has issued an update for ibm-jdk-bin and ibm-jre-bin. This fixes some vulnerabilities, which can be exploited by malicious people to
bypass certain security restrictions, manipulate data, disclose sensitive/system information, cause a DoS (Denial of Service), or to
compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30780/\"]http://secunia.com/advisories/30780/[/url]

--

[SA30829] Fedora update for clamav

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-06-23

Fedora has issued an update for clamav. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30829/\"]http://secunia.com/advisories/30829/[/url]

--

[SA30828] Fedora update for php

Critical: Moderately critical
Where: From remote
Impact: System access, DoS, Security Bypass, Unknown
Released: 2008-06-23

Fedora has issued an update for php. This fixes some vulnerabilities, where some have unknown impacts and others can be exploited by
malicious users to bypass certain security restrictions, and potentially by malicious people to cause a DoS (Denial of Service) or
to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30828/\"]http://secunia.com/advisories/30828/[/url]

--

[SA30827] Fedora update for xemacs-packages-extra

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-06-23

Fedora has issued an update for xemacs-packages-extra. This fixes a vulnerability, which can be exploited by malicious people to compromise
a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/30827/\"]http://secunia.com/advisories/30827/[/url]

--

[SA30825] Gentoo update for openssl

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-06-24

Gentoo has issued an update for openssl. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30825/\"]http://secunia.com/advisories/30825/[/url]

--

[SA30821] Red Hat update for freetype

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-23

Red Hat has issued an update for freetype. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/30821/\"]http://secunia.com/advisories/30821/[/url]

--

[SA30820] Gentoo update for libvorbis

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-24

Gentoo has issued an update for libvorbis. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) and potentially to compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/30820/\"]http://secunia.com/advisories/30820/[/url]

--

[SA30819] Gentoo update for freetype

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-24

Gentoo has issued an update for freetype. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/30819/\"]http://secunia.com/advisories/30819/[/url]

--

[SA30818] SUSE update for kernel

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, Privilege escalation, DoS, System access
Released: 2008-06-23

SUSE has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to
disclose potentially sensitive information, bypass certain security restrictions, cause a DoS (Denial of Service), and gain escalated
privileges, and malicious people to cause a DoS and potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30818/\"]http://secunia.com/advisories/30818/[/url]

--

[SA30798] Link ADS 1 "linkid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-25

Hussin X has reported a vulnerability in Link ADS 1, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30798/\"]http://secunia.com/advisories/30798/[/url]

--

[SA30793] Viral DX 1 "bannerid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-25

Hussin X has reported a vulnerability in Viral DX 1, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30793/\"]http://secunia.com/advisories/30793/[/url]

--

[SA30785] Kolab Server ClamAV Petite Processing Denial of Service

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-06-20

A vulnerability has been reported in Kolab Server, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30785/\"]http://secunia.com/advisories/30785/[/url]

--

[SA30783] Debian update for libtk-img

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-20

Debian has issued an update for libtk-img. This fixes a vulnerability, which can be exploited by malicious people to compromise an application
using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/30783/\"]http://secunia.com/advisories/30783/[/url]

--

[SA30836] Fedora update for nasm

Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-06-26

Fedora has issued an update for nasm. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30836/\"]http://secunia.com/advisories/30836/[/url]

--

[SA30826] Fedora update for gallery2

Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-06-23

Fedora has issued an update for gallery2. This fixes some vulnerabilities and a weakness, which can be exploited by malicious people to conduct cross-site scripting attacks, disclose sensitive information, and manipulate data.

Full Advisory:
[url=\"http://secunia.com/advisories/30826/\"]http://secunia.com/advisories/30826/[/url]

--

[SA30816] Fedora update for phpMyAdmin

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-25

Fedora has issued an update for phpMyAdmin. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30816/\"]http://secunia.com/advisories/30816/[/url]

--

[SA30814] Fedora update for horde

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-25

Fedora has issued an update for horde. This fixes a vulnerability, which can be exploited by malicious users to conduct script insertion
attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30814/\"]http://secunia.com/advisories/30814/[/url]

--

[SA30850] Red Hat update for kernel

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, DoS
Released: 2008-06-26

Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service) or to disclose potentially sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/30850/\"]http://secunia.com/advisories/30850/[/url]

--

[SA30849] Red Hat update for kernel

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation
Released: 2008-06-26

Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to
disclose potentially sensitive information or gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30849/\"]http://secunia.com/advisories/30849/[/url]

--

[SA30837] Fedora update for perl

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-06-26

Fedora has issued an update for perl. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions
with escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30837/\"]http://secunia.com/advisories/30837/[/url]

--

[SA30809] rPath update for xorg-x11

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-06-23

rPath has issued an update for xorg-x11. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30809/\"]http://secunia.com/advisories/30809/[/url]

--

[SA30803] Red Hat sblim Insecure RPATH Privilege Escalation

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-06-24

Red Hat has acknowledged a vulnerability in sblim, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30803/\"]http://secunia.com/advisories/30803/[/url]

--

[SA30790] Perl "File::Path::rmtree" Insecure chmod on Symbolic Links

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-06-26

A vulnerability has been reported in Perl, which can be exploited by malicious, local user to perform actions with escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30790/\"]http://secunia.com/advisories/30790/[/url]

--

[SA30781] Xen PVFB Shared Framebuffer Processing Vulnerability

Critical: Less critical
Where: Local system
Impact: Security Bypass, DoS
Released: 2008-06-20

A vulnerability has been reported in Xen, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or
potentially bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/30781/\"]http://secunia.com/advisories/30781/[/url]

--

[SA30776] Apple Mac OS X ARDAgent Privilege Escalation Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-06-23

A vulnerability has been discovered in Mac OS X, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/30776/\"]http://secunia.com/advisories/30776/[/url]


[b]Other:--[/b]

[SA30852] Nortel Media Processing Server OpenSSL Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-26

Nortel has acknowledged some vulnerabilities in Media Processing Server, which can be exploited by malicious people to cause a DoS
(Denial of Service) or potentially to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30852/\"]http://secunia.com/advisories/30852/[/url]

--

[SA30847] Cisco Wide Area Application Services CUPS IPP Tags Memory Corruption

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-06-26

Cisco has acknowledged a vulnerability in Wide Area Application Services (WAAS), which can be exploited by malicious people to
compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30847/\"]http://secunia.com/advisories/30847/[/url]

--

[SA30844] Nortel Communication Server Command Processing Denial of Service

Critical: Not critical
Where: From local network
Impact: DoS
Released: 2008-06-26

A vulnerability has been reported in Nortel Communication Server, which can be exploited by malicious people to cause a DoS (Denial of
Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30844/\"]http://secunia.com/advisories/30844/[/url]


[b]Cross Platform:--[/b]

[SA30834] Benja CMS Cross-Site Scripting and Security Bypass
Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-06-24

CWH Underground has discovered some vulnerabilities in Benja CMS, which can be exploited by malicious people to conduct cross-site scripting
attacks and bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/30834/\"]http://secunia.com/advisories/30834/[/url]

--

[SA30832] Adobe Reader/Acrobat JavaScript Method Handling Vulnerability

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-24

A vulnerability has been reported in Adobe Reader/Acrobat, which potentially can be exploited by malicious people to compromise a user's
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30832/\"]http://secunia.com/advisories/30832/[/url]

--

[SA30806] Jamroom "jamroom[jm_dir]" File Inclusion Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-23

Some vulnerabilities have been reported in Jamroom, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30806/\"]http://secunia.com/advisories/30806/[/url]

--

[SA30804] emuCMS Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Manipulation of data, System access
Released: 2008-06-23

Some vulnerabilities have been discovered in emuCMS, which can be exploited by malicious people to conduct SQL injection attacks or to
compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30804/\"]http://secunia.com/advisories/30804/[/url]

--

[SA30797] le.cms "cms/admin/upload.php" Security Bypass

Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-06-23

t0pP8uZz has reported a vulnerability in le.cms, which can be exploited by malicious people to bypass certain security restrictions and
compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30797/\"]http://secunia.com/advisories/30797/[/url]

--

[SA30789] NConvert / GFL SDK Sun TAAC "format" Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-20

Secunia Research has discovered a vulnerability in NConvert and GFL SDK, which can be exploited by malicious people to compromise a user's
system.

Full Advisory:
[url=\"http://secunia.com/advisories/30789/\"]http://secunia.com/advisories/30789/[/url]

--

[SA30784] ODARS "CLASSES_ROOT" File Inclusion Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-06-23

CraCkEr has discovered a vulnerability in ODARS, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30784/\"]http://secunia.com/advisories/30784/[/url]

--

[SA30778] Hedgehog-CMS "c_temp_path" File Inclusion Vulnerability

Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-06-23

CraCkEr has discovered a vulnerability in Hedgehog-CMS, which can be exploited by malicious people to disclose sensitive information or
compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/30778/\"]http://secunia.com/advisories/30778/[/url]

--

[SA30833] mask PHP File Manager Cookie Security Bypass

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-06-25

A vulnerability has been reported in mask PHP File Manager (mPFM), which can be exploited by malicious people to bypass certain security
restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/30833/\"]http://secunia.com/advisories/30833/[/url]

--

[SA30811] FubarForum "page" Local File Inclusion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-06-23

cOndemned has reported a vulnerability in FubarForum, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/30811/\"]http://secunia.com/advisories/30811/[/url]

--

[SA30810] Softbiz Jokes and Funny Pictures Script "sbjoke_id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-26

Hussin X has reported a vulnerability in Softbiz Jokes and Funny Pictures Script, which can be exploited by malicious people to conduct
SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30810/\"]http://secunia.com/advisories/30810/[/url]

--

[SA30807] CiBlog "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-25

Mr.SQL has reported a vulnerability in CiBlog, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30807/\"]http://secunia.com/advisories/30807/[/url]

--

[SA30800] AproxEngine "page" Local File Inclusion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-06-23

SkyOut has discovered a vulnerability in AproxEngine, which can be exploited by malicious people to disclose potentially sensitive
information.

Full Advisory:
[url=\"http://secunia.com/advisories/30800/\"]http://secunia.com/advisories/30800/[/url]

--

[SA30796] CCleague Pro admin.php SQL Injection and Authentication Bypass

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-06-23

t0pP8uZz has discovered some vulnerabilities in CCleague Pro, which can be exploited by malicious people to bypass certain security restrictions
or to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30796/\"]http://secunia.com/advisories/30796/[/url]

--

[SA30795] Online Fantasy Football League SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-23

t0pP8uZz has reported some vulnerabilities in Online Fantasy Football League, which can be exploited by malicious people to conduct SQL
injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30795/\"]http://secunia.com/advisories/30795/[/url]

--

[SA30794] AJ HYIP "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-23

Hussin X has reported a vulnerability in AJ HYIP, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30794/\"]http://secunia.com/advisories/30794/[/url]

--

[SA30791] Joomla EXP Shop Component "catid" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-23

His0k4 has reported a vulnerability in the EXP Shop component for Joomla!, which can be exploited by malicious people to conduct SQL
injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30791/\"]http://secunia.com/advisories/30791/[/url]

--

[SA30782] WebGUI Collaboration RSS Feed Information Disclosure

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-06-25

A security issue has been reported in WebGUI, which can be exploited by malicious people to disclose potentially sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/30782/\"]http://secunia.com/advisories/30782/[/url]

--

[SA30779] HTML Purifier CSS Cross-Site Scripting and Script Insertion

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-23

Two vulnerabilities have been reported in HTML Purifier, which can be exploited by malicious people to conduct cross-site scripting or script
insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30779/\"]http://secunia.com/advisories/30779/[/url]

--

[SA30846] Drupal Suggested Terms Module Script Insertion Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-26

A vulnerability has been reported in the Suggested Terms module for Drupal, which can be exploited by malicious users to conduct script
insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30846/\"]http://secunia.com/advisories/30846/[/url]

--

[SA30845] Caucho Resin "file" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-26

A vulnerability has been reported in Caucho Resin, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30845/\"]http://secunia.com/advisories/30845/[/url]

--

[SA30839] Novell Groupwise WebAccess Simple Interface Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-25

A vulnerability has been reported in Novell Groupwise, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30839/\"]http://secunia.com/advisories/30839/[/url]

--

[SA30830] RT Devel::StackTrace Denial of Service Vulnerability

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-06-25

A vulnerability has been reported in RT, which can exploited by malicious users to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/30830/\"]http://secunia.com/advisories/30830/[/url]

--

[SA30822] JSCAPE Secure FTP Applet Host Key Verification Security Issue

Critical: Less critical
Where: From remote
Impact: Spoofing
Released: 2008-06-23

n.runs AG has reported a security issue in JSCAPE Secure FTP Applet, which can be exploited by malicious people to conduct spoofing
attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30822/\"]http://secunia.com/advisories/30822/[/url]

--

[SA30813] phpMyAdmin Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-24

Some vulnerabilities have been reported in phpMyAdmin, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30813/\"]http://secunia.com/advisories/30813/[/url]

--

[SA30773] TYPO3 DCD GoogleMap Extension Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-19

A vulnerability has been reported in the DCD GoogleMap (dcdgooglemap) extension for TYPO3, which can be exploited by malicious people to
conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/30773/\"]http://secunia.com/advisories/30773/[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Post Reply

Return to “Security”