[url=\"http://secunia.com\"]Secunia[/url] Vulnerabilities Content Listing for the week of August 14th 2008 Part One - Windows & Unix
[b]Windows:--[/b]
[SA31498] Microsoft Visual Studio Masked Edit Control "Mask" Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-14
A vulnerability has been reported in Microsoft Visual Studio, which can potentially be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31498/\"]http://secunia.com/advisories/31498/[/url]
--
[SA31481] FlashGet FTP PWD Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-08-14
Krystian Kloskowski has discovered a vulnerability in FlashGet, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31481/\"]http://secunia.com/advisories/31481/[/url]
--
[SA31454] Microsoft Office Excel Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2008-08-12
Multiple vulnerabilities have been reported in Microsoft Excel, which can be exploited by malicious people to gain knowledge of sensitive information or compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31454/\"]http://secunia.com/advisories/31454/[/url]
--
[SA31453] Microsoft Office PowerPoint Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-08-12
Some vulnerabilities have been reported in Microsoft PowerPoint, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31453/\"]http://secunia.com/advisories/31453/[/url]
--
[SA31445] BitTorrent "created by" Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-12
A vulnerability has been discovered in BitTorrent, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31445/\"]http://secunia.com/advisories/31445/[/url]
--
[SA31441] uTorrent "created by" Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-12
A vulnerability has been discovered in uTorrent, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/31441/\"]http://secunia.com/advisories/31441/[/url]
--
[SA31440] Trend Micro Products ObjRemoveCtrl Class Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-08-11
Some vulnerabilities have been reported in multiple Trend Micro products, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31440/\"]http://secunia.com/advisories/31440/[/url]
--
[SA31397] Webex Meeting Manager WebexUCFObject ActiveX Control Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-08-07
Elazar Broad has discovered a vulnerability in Webex Meeting Manager, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31397/\"]http://secunia.com/advisories/31397/[/url]
--
[SA31385] Microsoft Windows Color Management System Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-08-12
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31385/\"]http://secunia.com/advisories/31385/[/url]
--
[SA31375] Internet Explorer Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-08-12
Multiple vulnerabilities have been reported in Internet Explorer, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31375/\"]http://secunia.com/advisories/31375/[/url]
--
[SA31336] Microsoft Office Filters Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-08-12
Multiple vulnerabilities have been reported in Microsoft Office, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31336/\"]http://secunia.com/advisories/31336/[/url]
--
[SA31452] SOURCENEXT Virus Security / Virus Security ZERO Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-08-12
A vulnerability has been reported in SOURCENEXT Virus Security and Virus Security ZERO, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31452/\"]http://secunia.com/advisories/31452/[/url]
--
[SA31446] Microsoft Windows Messenger ActiveX Control Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-08-12
A vulnerability has been reported in Microsoft Windows Messenger, which can be exploited by malicious people to gain knowledge of sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31446/\"]http://secunia.com/advisories/31446/[/url]
--
[SA31442] WinGate IMAP Server Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-11
João Antunes has discovered a vulnerability in WinGate, which can be exploited by malicious users to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/31442/\"]http://secunia.com/advisories/31442/[/url]
--
[SA31434] CA Products kmxfw.sys Privilege Escalation and Denial of Service
Critical: Moderately critical
Where: From remote
Impact: Privilege escalation, DoS
Released: 2008-08-12
Some vulnerabilities have been reported in multiple CA products, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to potentially gain escalated privileges, and by malicious people to cause a DoS.
Full Advisory: [url=\"http://secunia.com/advisories/31434/\"]http://secunia.com/advisories/31434/[/url]
--
[SA31415] Internet Explorer MHTML Protocol Handler Cross-Domain Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-08-12
A vulnerability has been reported in Internet Explorer, which can be exploited by malicious people to gain knowledge of sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31415/\"]http://secunia.com/advisories/31415/[/url]
--
[SA31376] HydraIRC "irc://" URI Handling Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-05
securfrog has discovered a vulnerability in HydraIRC, which can be exploited by malicious people to potentially compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31376/\"]http://secunia.com/advisories/31376/[/url]
--
[SA31371] Winamp "NowPlaying" Unspecified Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-08-05
A vulnerability with an unknown impact has been reported in Winamp.
Full Advisory: [url=\"http://secunia.com/advisories/31371/\"]http://secunia.com/advisories/31371/[/url]
--
[SA31368] E.Z. Poll "Username" and "Password" SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-04
t0fx has discovered some vulnerabilities in E. Z. Poll, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/31368/\"]http://secunia.com/advisories/31368/[/url]
--
[SA31319] CA ARCserve Backup for Laptops and Desktops LGServer Service Integer Underflow
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-08-01
A vulnerability has been reported in CA ARCserve Backup for Laptops and Desktops, which can be exploited by malicious people to cause a DoS
(Denial of Service) or compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31319/\"]http://secunia.com/advisories/31319/[/url]
--
[SA31480] hMailServer IMAP Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-08-13
João Antunes has reported a vulnerability in hMailServer, which can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31480/\"]http://secunia.com/advisories/31480/[/url]
--
[SA31455] Microsoft Office SharePoint Server Privilege Escalation Vulnerability
Critical: Less critical
Where: From remote
Impact: Privilege escalation
Released: 2008-08-12
A vulnerability has been reported in Microsoft Office SharePoint Server, which can be exploited by malicious users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31455/\"]http://secunia.com/advisories/31455/[/url]
--
[SA31432] Adobe Presenter "viewer.swf" and "loadflash.js" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-11
Some vulnerabilities have been reported in Adobe Presenter, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31432/\"]http://secunia.com/advisories/31432/[/url]
--
[SA31411] Microsoft Windows IPsec Policy Processing Information Disclosure
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-08-12
A security issue has been reported in Microsoft Windows, which may expose sensitive information to malicious people
Full Advisory:
[url=\"http://secunia.com/advisories/31411/\"]http://secunia.com/advisories/31411/[/url]
--
[SA31369] KAPhotoservice "page" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-08
by_casper41 has reported a vulnerability in KAPhotoservice, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31369/\"]http://secunia.com/advisories/31369/[/url]
--
[SA31325] MailEnable IMAP Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-08-01
A vulnerability has been reported in MailEnable, which can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31325/\"]http://secunia.com/advisories/31325/[/url]
--
[SA31417] Microsoft Windows Event System Privilege Escalation Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-12
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31417/\"]http://secunia.com/advisories/31417/[/url]
--
[SA31361] Sun xVM VirtualBox "VBoxDrv.sys" IOCTL Privilege Escalation Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-05
Core Security Technologies has reported a vulnerability in Sun xVM VirtualBox, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31361/\"]http://secunia.com/advisories/31361/[/url]
--
[SA31433] McAfee Encrypted USB Manager "Re-use Threshold" Security Bypass
Critical: Not critical
Where: From remote
Impact: Security Bypass
Released: 2008-08-11
McAfee has acknowledged a security issue in McAfee Encrypted USB Manager, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31433/\"]http://secunia.com/advisories/31433/[/url]
[b]UNIX/Linux:--[/b]
[SA31497] Red Hat Network Satellite Server Update for Sun Java / IBM Java Runtime
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-08-14
Red Hat has issued an update for the Red Hat Network Satellite Server Sun Java and IBM Java runtimes. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose system information or potentially sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31497/\"]http://secunia.com/advisories/31497/[/url]
--
[SA31492] Red Hat Network Satellite Server Update for Solaris Client
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, DoS, System access
Released: 2008-08-14
Red Hat has issued an update for the Red Hat Network Satellite Server Solaris client. This fixes some vulnerabilities, which can be exploited by malicious people to expose sensitive information, bypass certain security restrictions, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31492/\"]http://secunia.com/advisories/31492/[/url]
--
[SA31489] VMware ESXi OpenSSL Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-13
VMware has acknowledged some vulnerabilities in VMware ESXi, which can be exploited by malicious people to cause a DoS (Denial of Service) and
potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31489/\"]http://secunia.com/advisories/31489/[/url]
--
[SA31467] VMware updates for OpenSSL, net-snmp, and perl
Critical: Highly critical
Where: From remote
Impact: Spoofing, DoS, System access
Released: 2008-08-13
VMware has issued updated OpenSSL, net-snmp, and perl packages. This fixes some vulnerabilities, which can be exploited by malicious people to spoof authenticated SNMPv3 packets, cause a DoS (Denial of Service), and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31467/\"]http://secunia.com/advisories/31467/[/url]
--
[SA31465] Yelp Invalid URI Format String Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-14
A vulnerability has been reported in Yelp, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31465/\"]http://secunia.com/advisories/31465/[/url]
--
[SA31428] Gentoo update for acroread
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-11
Gentoo has issued an update for acroread. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31428/\"]http://secunia.com/advisories/31428/[/url]
--
[SA31405] Fedora update for poppler
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-08
Fedora has issued an update for poppler. This fixes a vulnerability, which can be exploited by malicious people to compromise an application using the library.
Full Advisory: [url=\"http://secunia.com/advisories/31405/\"]http://secunia.com/advisories/31405/[/url]
--
[SA31403] Fedora update for thunderbird
Critical: Highly critical
Where: From remote
Impact: Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-08-08
Fedora has issued an update for thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to conduct spoofing attacks, disclose sensitive information, and to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31403/\"]http://secunia.com/advisories/31403/[/url]
--
[SA31393] Ubuntu update for xine-lib
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-11
Ubuntu has issued an update for xine-lib. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31393/\"]http://secunia.com/advisories/31393/[/url]
--
[SA31377] Gentoo update for Mozilla products
Critical: Highly critical
Where: From remote
Impact: System access, DoS, Exposure of sensitive information, Exposure of system information, Spoofing, Cross Site Scripting, Security Bypass
Released: 2008-08-06
Gentoo has issued an update for various Mozilla products. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, disclose sensitive information, or potentially compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31377/\"]http://secunia.com/advisories/31377/[/url]
--
[SA31372] Gentoo update for xine-lib
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-06
Gentoo has issued an update for xine-lib. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31372/\"]http://secunia.com/advisories/31372/[/url]
--
[SA31352] Sun Solaris Adobe Reader Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Privilege escalation, DoS, System access
Released: 2008-08-04
Sun has acknowledged a vulnerability and a security issue in Adobe Reader in Sun Solaris, which can be exploited by malicious, local users to perform certain actions with escalated privileges and potentially by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31352/\"]http://secunia.com/advisories/31352/[/url]
--
[SA31339] SUSE Update for Multiple Packages
Critical: Highly critical
Where: From remote
Impact: System access, DoS, Exposure of sensitive information, Cross Site Scripting
Released: 2008-08-08
SUSE has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious users to conduct script insertion attacks, and by malicious people to disclose potentially sensitive information, conduct cross-site request forgery attacks, and compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31339/\"]http://secunia.com/advisories/31339/[/url]
--
[SA31326] Apple Mac OS X Security Update Fixes Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Spoofing, Privilege escalation, DoS, System access
Released: 2008-08-01
Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities.
Full Advisory: [url=\"http://secunia.com/advisories/31326/\"]http://secunia.com/advisories/31326/[/url]
--
[SA31321] Red Hat Extras and Supplementary RealPlayer Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-08-01
Red Hat has acknowledged a vulnerability in RealPlayer, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31321/\"]http://secunia.com/advisories/31321/[/url]
--
[SA31320] Red Hat update for java-1.5.0-ibm
Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access, Security Bypass
Released: 2008-08-01
Red Hat has issued an update for java-1.5.0-ibm. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, or compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31320/\"]http://secunia.com/advisories/31320/[/url]
--
[SA31495] HP Tru64 UNIX BIND Query Port DNS Cache Poisoning
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-08-14
HP has acknowledged a vulnerability in HP Tru64 UNIX, which can be exploited by malicious people to poison the DNS cache.
Full Advisory: [url=\"http://secunia.com/advisories/31495/\"]http://secunia.com/advisories/31495/[/url]
--
[SA31493] Red Hat update for Red Hat Network Satellite Server
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, DoS
Released: 2008-08-14
Red Hat has issued an update for Red Hat Network Satellite Server. This fixes some vulnerabilities, which can be exploited by malicious users to
disclose potentially sensitive information, and malicious people to bypass certain security restrictions, disclose sensitive information, conduct cross-site scripting attacks, and cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31493/\"]http://secunia.com/advisories/31493/[/url]
--
[SA31478] IPsec-Tools racoon Phase 1 Handler Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-08-13
A vulnerability has been reported in IPsec-Tools, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31478/\"]http://secunia.com/advisories/31478/[/url]
--
[SA31473] rPath update for idle and python
Critical: Moderately critical
Where: From remote
Impact: Unknown, DoS, System access
Released: 2008-08-14
rPath has issued an update for idle and python. This fixes some vulnerabilities, where some have unknown impact and others can potentially be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31473/\"]http://secunia.com/advisories/31473/[/url]
--
[SA31471] HP-UX ftpd Unspecified Privileged Access Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS
Released: 2008-08-13
A vulnerability has been reported in HP-UX, which can be exploited by malicious people to bypass certain security restrictions and to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31471/\"]http://secunia.com/advisories/31471/[/url]
--
[SA31457] Joomla "token" Password Change Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-08-13
d3m0n has reported a vulnerability in Joomla!, which can be exploited by malicious people to bypass certain security restrictions and manipulate data.
Full Advisory: [url=\"http://secunia.com/advisories/31457/\"]http://secunia.com/advisories/31457/[/url]
--
[SA31437] Gentoo update for clamav
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-08-11
Gentoo has issued an update for clamav. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31437/\"]http://secunia.com/advisories/31437/[/url]
--
[SA31422] Red Hat update for dnsmasq
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-08-12
Red Hat has issued an update for dnsmasq. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
Full Advisory: [url=\"http://secunia.com/advisories/31422/\"]http://secunia.com/advisories/31422/[/url]
--
[SA31413] ZeeBuddy "adid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-08-11
Hussin X has reported a vulnerability in ZeeBuddy, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31413/\"]http://secunia.com/advisories/31413/[/url]
--
[SA31409] PHP Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Exposure of sensitive information, DoS, System access
Released: 2008-08-12
Some vulnerabilities have been reported in PHP, where some have an unknown impact and others can potentially be exploited by malicious people to disclose sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31409/\"]http://secunia.com/advisories/31409/[/url]
--
[SA31399] Fedora update for libxslt
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-08
Fedora has issued an update for libxslt. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.
Full Advisory: [url=\"http://secunia.com/advisories/31399/\"]http://secunia.com/advisories/31399/[/url]
--
[SA31395] Gentoo update for libxslt
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-07
Gentoo has issued an update for libxslt. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory: [url=\"http://secunia.com/advisories/31395/\"]http://secunia.com/advisories/31395/[/url]
--
[SA31388] rPath update for cups
Critical: Moderately critical
Where: From remote
Impact: System access, DoS
Released: 2008-08-06
rPath has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31388/\"]http://secunia.com/advisories/31388/[/url]
--
[SA31387] rPath update for gaim
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-06
rPath has issued an update for gaim. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31387/\"]http://secunia.com/advisories/31387/[/url]
--
[SA31386] Sun Solaris "snoop" Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-08-06
Some vulnerabilities have been reported in Sun Solaris, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31386/\"]http://secunia.com/advisories/31386/[/url]
--
[SA31378] Gentoo update for wireshark
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS
Released: 2008-08-06
Gentoo has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information or cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31378/\"]http://secunia.com/advisories/31378/[/url]
--
[SA31365] Ubuntu update for python
Critical: Moderately critical
Where: From remote
Impact: Unknown, DoS, System access
Released: 2008-08-04
Ubuntu has issued an update for python. This fixes some vulnerabilities, where some have unknown impact and others can potentially be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31365/\"]http://secunia.com/advisories/31365/[/url]
--
[SA31363] Ubuntu update for libxslt
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-04
Ubuntu has issued an update for libxslt. This fixes a some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.
Full Advisory: [url=\"http://secunia.com/advisories/31363/\"]http://secunia.com/advisories/31363/[/url]
--
[SA31358] Slackware update for python
Critical: Moderately critical
Where: From remote
Impact: Unknown, DoS, System access
Released: 2008-08-05
Slackware has issued an update for python. This fixes some vulnerabilities, where some have unknown impact and others can potentially be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31358/\"]http://secunia.com/advisories/31358/[/url]
--
[SA31347] GIT Pathname Processing Multiple Buffer Overflows
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-05
Some vulnerabilities have been reported in GIT, which can potentially be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31347/\"]http://secunia.com/advisories/31347/[/url]
--
[SA31332] Gentoo update for python
Critical: Moderately critical
Where: From remote
Impact: Unknown, DoS, System access
Released: 2008-08-04
Gentoo has issued an update for python. This fixes some vulnerabilities, where some have unknown impact and others can potentially be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31332/\"]http://secunia.com/advisories/31332/[/url]
--
[SA31331] Red Hat update for libxslt
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-01
Red Hat has issued an update for libxslt. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/31331/\"]http://secunia.com/advisories/31331/[/url]
--
[SA31328] Avaya Communication Manager Perl Regular Expressions Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-01
Avaya has acknowledged a vulnerability in Perl in Avaya Communication Manager, which can potentially be exploited by malicious people to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31328/\"]http://secunia.com/advisories/31328/[/url]
--
[SA31324] Debian update for cupsys
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-08-01
Debian has issued an update for cupsys. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31324/\"]http://secunia.com/advisories/31324/[/url]
--
[SA31459] Fedora update for condor
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-08-13
Fedora has issued an update for condor. This fixes a security issue, which can be exploited by malicious users to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31459/\"]http://secunia.com/advisories/31459/[/url]
--
[SA31450] IPsec-Tools racoon Denial of Service
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-08-12
A vulnerability has been reported in IPsec-Tools, which can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31450/\"]http://secunia.com/advisories/31450/[/url]
--
[SA31449] GooCMS "s" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-12
ahmadbaby has discovered a vulnerability in GooCMS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31449/\"]http://secunia.com/advisories/31449/[/url]
--
[SA31444] Bugzilla importxml.pl Directory Traversal Vulnerability
Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-08-12
A vulnerability has been reported in Bugzilla, which can be exploited by malicious users to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31444/\"]http://secunia.com/advisories/31444/[/url]
--
[SA31438] Gentoo update for stunnel
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-08-11
Gentoo has issued an update for stunnel. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31438/\"]http://secunia.com/advisories/31438/[/url]
--
[SA31426] Sun Solaris "sendfilev()" Denial of Service
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-08-12
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31426/\"]http://secunia.com/advisories/31426/[/url]
--
[SA31425] Ovidentia "item" SQL Injection Vulnerability
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-12
IRCRASH has discovered a vulnerability in Ovidentia, which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31425/\"]http://secunia.com/advisories/31425/[/url]
--
[SA31423] Red Hat update for condor
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-08-12
Red Hat has issued an update for condor. This fixes a security issue, which can be exploited by malicious users to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31423/\"]http://secunia.com/advisories/31423/[/url]
--
[SA31416] Fedora update for httpd
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-08-08
Fedora has issued an update for httpd. This fixes two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31416/\"]http://secunia.com/advisories/31416/[/url]
--
[SA31412] Sun Solaris Trusted Extensions Labeled Networking Unauthorised Access
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-08-08
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31412/\"]http://secunia.com/advisories/31412/[/url]
--
[SA31404] Fedora update for httpd
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-08-08
Fedora has issued an update for httpd. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31404/\"]http://secunia.com/advisories/31404/[/url]
--
[SA31402] Xoops Kshop Module "search" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-07
Lostmon has discovered a vulnerability in the Kshop module for Xoops, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31402/\"]http://secunia.com/advisories/31402/[/url]
--
[SA31400] HP-UX libc Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-08-07
HP has acknowledged a vulnerability in libc, which can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31400/\"]http://secunia.com/advisories/31400/[/url]
--
[SA31390] Pidgin SSL Verification Security Issue
Critical: Less critical
Where: From remote
Impact: Spoofing
Released: 2008-08-06
A security issue has been reported in Pidgin, which can be exploited by malicious people to conduct spoofing attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/31390/\"]http://secunia.com/advisories/31390/[/url]
--
[SA31384] Apache mod_proxy_ftp Wildcard Characters Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-06
A vulnerability has been reported in Apache, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31384/\"]http://secunia.com/advisories/31384/[/url]
--
[SA31380] Debian update for httracker
Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-08-04
Debian has issued an update for httracker. This fixes a security issue, which can be exploited by malicious people to potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31380/\"]http://secunia.com/advisories/31380/[/url]
--
[SA31360] Debian update for opensc
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-08-04
Debian has issued an update for opensc. This fixes a security issue, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31360/\"]http://secunia.com/advisories/31360/[/url]
--
[SA31359] csphonebook "letter" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-07
Ghost Hacker has discovered a vulnerability in csphonebook, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31359/\"]http://secunia.com/advisories/31359/[/url]
--
[SA31346] Online Dating "mail_id" SQL Injection Vulnerability
Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-08-04
Corwin has reported a vulnerability in Online Dating, which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31346/\"]http://secunia.com/advisories/31346/[/url]
--
[SA31490] Red Hat Network Proxy Server update for mod_perl
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-08-14
Red Hat has issued an update for the Red Hat Network Proxy Server mod_perl package. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31490/\"]http://secunia.com/advisories/31490/[/url]
--
[SA31436] Gentoo update for openldap
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-08-11
Gentoo has issued an update for openldap. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31436/\"]http://secunia.com/advisories/31436/[/url]
--
[SA31364] Ubuntu update for OpenLDAP
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-08-04
Ubuntu has issued an update for OpenLDAP. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31364/\"]http://secunia.com/advisories/31364/[/url]
--
[SA31351] Gentoo update for net-snmp
Critical: Less critical
Where: From local network
Impact: Spoofing, DoS, System access
Released: 2008-08-06
Gentoo has issued an update for net-snmp. This fixes some vulnerabilities, which can be exploited by malicious people to spoof authenticated SNMPv3 packets or potentially to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31351/\"]http://secunia.com/advisories/31351/[/url]
--
[SA31334] SUSE update for net-snmp
Critical: Less critical
Where: From local network
Impact: Spoofing, DoS, System access
Released: 2008-08-01
SUSE has issued an update for net-snmp. This fixes some vulnerabilities, which can be exploited by malicious people to spoof authenticated SNMPv3 packets and potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31334/\"]http://secunia.com/advisories/31334/[/url]
--
[SA31322] Red Hat update for nfs-utils
Critical: Less critical
Where: From local network
Impact: Security Bypass
Released: 2008-08-01
Red Hat has issued an update for nfs-utils. This fixes a security issue, which can be exploited by malicious people to potentially bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31322/\"]http://secunia.com/advisories/31322/[/url]
--
[SA31500] SUSE update for postfix
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation
Released: 2008-08-14
SUSE has issued an update for postfix. This fixes some security issues, which can be exploited by malicious, local users to disclose potentially sensitive information and perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31500/\"]http://secunia.com/advisories/31500/[/url]
--
[SA31485] Postfix Symlink Handling and Destination Ownership Security Issues
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation
Released: 2008-08-14
Sebastian Krahmer has reported some security issues in Postfix, which can be exploited by malicious, local users to disclose potentially sensitive information and perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31485/\"]http://secunia.com/advisories/31485/[/url]
--
[SA31420] Gentoo update for uudeview and nzbget
Critical: Less critical
Where: Local system
Impact: Manipulation of data
Released: 2008-08-12
Gentoo has issued an update for uudeview and nzbget. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31420/\"]http://secunia.com/advisories/31420/[/url]
--
[SA31418] Amarok "MagnatuneBrowser::listDownloadComplete()" Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-12
A security issue has been reported in Amarok, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31418/\"]http://secunia.com/advisories/31418/[/url]
--
[SA31398] CA Products Ingres Multiple Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-07
Some vulnerabilities have been reported in CA products, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31398/\"]http://secunia.com/advisories/31398/[/url]
--
[SA31356] Sun Solaris namefs Kernel Module Privilege Escalation
Critical: Less critical
Where: Local system
Impact: DoS, System access
Released: 2008-08-04
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31356/\"]http://secunia.com/advisories/31356/[/url]
--
[SA31341] Red Hat update for kernel
Critical: Less critical
Where: Local system
Impact: Security Bypass, Privilege escalation, DoS
Released: 2008-08-05
Red Hat has issued an update for the kernel. This fixes two vulnerabilities and a security issue, which can be exploited by malicious, local users to cause a DoS (Denial of Service), bypass certain security restrictions, or to potentially gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31341/\"]http://secunia.com/advisories/31341/[/url]
--
[SA31318] MaxDB "dbmsrv" Privilege Escalation Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-01
A vulnerability has been reported in MaxDB, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31318/\"]http://secunia.com/advisories/31318/[/url]
--
[SA31317] Gentoo update for vlc
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-01
Gentoo has issued an update for vlc. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31317/\"]http://secunia.com/advisories/31317/[/url]
--
[SA31448] Debian update for pdns
Critical: Not critical
Where: From remote
Impact: Spoofing
Released: 2008-08-12
Debian has issued an update for pdns. This fixes a weakness, which can be exploited by malicious people to conduct spoofing attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31448/\"]http://secunia.com/advisories/31448/[/url]
--
[SA31401] Fedora update for pdns
Critical: Not critical
Where: From remote
Impact: Spoofing
Released: 2008-08-08
Fedora has issued an update for pdns. This fixes a weakness, which can be exploited by malicious people to conduct spoofing attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31401/\"]http://secunia.com/advisories/31401/[/url]
--
[SA31468] VMware VirtualCenter User Account Disclosure
Critical: Not critical
Where: From local network
Impact: Exposure of system information
Released: 2008-08-13
A security issue has been reported in VMware VirtualCenter, which can be exploited by malicious users to disclose certain system information.
Full Advisory: [url=\"http://secunia.com/advisories/31468/\"]http://secunia.com/advisories/31468/[/url]
--
[SA31396] Gentoo update for dhcp
Critical: Not critical
Where: From local network
Impact: DoS
Released: 2008-08-07
Gentoo has issued an update for dhcp. This fixes a weakness, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31396/\"]http://secunia.com/advisories/31396/[/url]
--
[SA31499] Red Hat update for hplip
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-08-14
Red Hat has issued an update for hplip. This fixes a security issue, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31499/\"]http://secunia.com/advisories/31499/[/url]
--
[SA31470] HPLIP hpssd Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-08-14
A security issue has been reported in hplip, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31470/\"]http://secunia.com/advisories/31470/[/url]
--
[SA31366] Linux Kernel Information Disclosure and Denial of Service
Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information, DoS
Released: 2008-08-06
Some vulnerabilities have been reported in the Linux Kernel, which can be exploited by malicious, local users to disclose potentially sensitive information or to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31366/\"]http://secunia.com/advisories/31366/[/url]
--
[SA31348] Sun Solaris "pthread_mutex_reltimedlock_np" Local Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-08-06
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31348/\"]http://secunia.com/advisories/31348/[/url]
[url=\"http://secunia.com\"]Secunia[/url] Vulnerabilities Advisories for the week of August 14th 2008 Part Two - Other & Cross Platform
[b]Other:--[/b]
[SA31482] HP TCP/IP Services for OpenVMS BIND DNS Cache Poisoning
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-08-14
HP has acknowledged a vulnerability in HP OpenVMS TCP/IP Services, which can be exploited by malicious people to poison the DNS cache.
Full Advisory: [url=\"http://secunia.com/advisories/31482/\"]http://secunia.com/advisories/31482/[/url]
--
[SA31451] Yamaha RT Series Routers DNS Cache Poisoning
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-08-12
A vulnerability has been reported in Yamaha RT Series Routers, which can be exploited by malicious people to poison the DNS cache.
Full Advisory: [url=\"http://secunia.com/advisories/31451/\"]http://secunia.com/advisories/31451/[/url]
--
[SA31354] Astaro Security Gateway DNS Cache Poisoning
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-08-05
Astaro has acknowledged a vulnerability in Astaro Security Gateway, which can be exploited by malicious people to poison the DNS cache.
Full Advisory: [url=\"http://secunia.com/advisories/31354/\"]http://secunia.com/advisories/31354/[/url]
--
[SA31435] Alcatel-Lucent OmniSwitch Series Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-08-12
Deral Heiland has reported a vulnerability in various OmniSwitch products, which can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31435/\"]http://secunia.com/advisories/31435/[/url]
--
[SA31391] 8e6 R3000 "Host" URL Filter Bypass Vulnerability
Critical: Less critical
Where: From local network
Impact: Security Bypass
Released: 2008-08-07
nnposter has reported a vulnerability in 8e6 R3000 Internet Filter, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31391/\"]http://secunia.com/advisories/31391/[/url]
--
[SA31329] Xerox Phaser 8400 Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-08-06
crit3rion has reported a vulnerability in Xerox Phaser 8400, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31329/\"]http://secunia.com/advisories/31329/[/url]
[b]Cross Platform:--[/b]
[SA31475] Freeway File Inclusion and Cross-Site Scripting Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2008-08-13
Some vulnerabilities have been reported in Freeway, which can be exploited by malicious people to conduct cross-site scripting attacks and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31475/\"]http://secunia.com/advisories/31475/[/url]
--
[SA31424] pPIM Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data, System access
Released: 2008-08-12
Some vulnerabilities have been discovered in pPIM (Phlatline's Personal Information Manager), which can be exploited by malicious people or users to manipulate data and compromise a vulnerable system, and by malicious people to conduct cross-site scripting attacks and bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31424/\"]http://secunia.com/advisories/31424/[/url]
--
[SA31394] e107 download.php "extract()" Vulnerability
Critical: Highly critical
Where: From remote
Impact: Manipulation of data, System access
Released: 2008-08-08
James Bercegay has discovered a vulnerability in e107, which can be exploited by malicious people to conduct SQL injection attacks and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31394/\"]http://secunia.com/advisories/31394/[/url]
--
[SA31389] LoveCMS Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-08-06
PoMdaPiMp has reported some vulnerabilities in LoveCMS, which can be exploited by malicious people to bypass certain security restrictions and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31389/\"]http://secunia.com/advisories/31389/[/url]
--
[SA31374] Contenido Unspecified File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-08-07
Some vulnerabilities have been reported in Contenido, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31374/\"]http://secunia.com/advisories/31374/[/url]
--
[SA31484] PHP Realty "docID" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-08-13
CraCkEr has reported a vulnerability in PHP Realty, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31484/\"]http://secunia.com/advisories/31484/[/url]
--
[SA31476] Sun Java System Web Proxy Server FTP Subsystem Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-08-13
A vulnerability has been reported in Sun Java System Web Proxy Server, which can be exploited by malicious, local users and malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31476/\"]http://secunia.com/advisories/31476/[/url]
--
[SA31466] Ventrilo Server Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-08-13
Luigi Auriemma and Andre Malm have reported a vulnerability in Ventrilo Server, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31466/\"]http://secunia.com/advisories/31466/[/url]
--
[SA31463] NavBoard Local File Inclusion and Cross-Site Scripting
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-08-14
CraCkEr has discovered some vulnerabilities in NavBoard, which can be exploited by malicious people to conduct cross-site scripting attacks and disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31463/\"]http://secunia.com/advisories/31463/[/url]
--
[SA31462] Drupal Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, System access
Released: 2008-08-14
Some vulnerabilities have been reported in Drupal, which can be exploited by malicious users to conduct script insertion attacks and compromise a vulnerable system, and by malicious people to conduct cross-site scripting and cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/31462/\"]http://secunia.com/advisories/31462/[/url]
--
[SA31456] Gelato "img" File Disclosure Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-08-13
jiko has discovered a vulnerability in Gelato, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31456/\"]http://secunia.com/advisories/31456/[/url]
--
[SA31447] VitalQIP DNS Cache Poisoning Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-08-14
Alcatel-Lucent has acknowledged a vulnerability in VitalQIP, which can be exploited by malicious people to poison the DNS cache.
Full Advisory: [url=\"http://secunia.com/advisories/31447/\"]http://secunia.com/advisories/31447/[/url]
--
[SA31431] Kayako SupportSuite Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-08-12
James Bercegay has reported some vulnerabilities in Kayako SupportSuite, which can be exploited by malicious users to conduct SQL injection attacks, and by malicious people to conduct cross-site scripting and script insertion attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31431/\"]http://secunia.com/advisories/31431/[/url]
--
[SA31430] Ruby Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Spoofing, DoS
Released: 2008-08-11
Some vulnerabilities have been reported in Ruby, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS
(Denial of Service), and conduct spoofing attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31430/\"]http://secunia.com/advisories/31430/[/url]
--
[SA31427] Skulltag NULL Pointer Dereference Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-08-11
Luigi Auriemma has reported a vulnerability in Skulltag, which can be exploited by malicious people to a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31427/\"]http://secunia.com/advisories/31427/[/url]
--
[SA31421] Vacation Rental Script "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-12
CraCkEr has discovered a vulnerability in Vacation Rental Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31421/\"]http://secunia.com/advisories/31421/[/url]
--
[SA31419] Quicksilver Forums "forums[]" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-11
irk4z has discovered a vulnerability in Quicksilver Forums, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31419/\"]http://secunia.com/advisories/31419/[/url]
--
[SA31414] RTH File Disclosure and SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-08-08
Some vulnerabilities have been reported in RTH, which can be exploited by malicious people to conduct SQL injection attacks or to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31414/\"]http://secunia.com/advisories/31414/[/url]
--
[SA31408] OpenImpro "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-08-11
nuclear has discovered a vulnerability in OpenImpro, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31408/\"]http://secunia.com/advisories/31408/[/url]
--
[SA31406] Harmoni "Username" Script Insertion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-11
A vulnerability has been reported in Harmoni, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31406/\"]http://secunia.com/advisories/31406/[/url]
--
[SA31392] WSN Products "TID" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-08-08
otmorozok428 has reported a vulnerability in various WSN products, which can be exploited by malicious users to disclose sensitive information and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31392/\"]http://secunia.com/advisories/31392/[/url]
--
[SA31383] Free Hosting Manager Insecure Cookie Handling Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-08-07
lvlr-Erfan has discovered a vulnerability in Free Hosting Manager, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31383/\"]http://secunia.com/advisories/31383/[/url]
--
[SA31382] PowerGap Shopsystem "ag" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-08
Rohit Bansal has reported a vulnerability in PowerGap Shopsystem, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31382/\"]http://secunia.com/advisories/31382/[/url]
--
[SA31381] Apache Tomcat 6 Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-08-04
Some vulnerabilities have been reported in Apache Tomcat, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, or disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31381/\"]http://secunia.com/advisories/31381/[/url]
--
[SA31379] Apache Tomcat Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-08-04
Some vulnerabilities have been reported in Apache Tomcat, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, or di
Secunia Updates - August 2008
Moderators: Moderator, Global Moderator
Secunia Updates - August 2008

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Secunia Updates - August 2008
[url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of August 21 2008
[b]Windows:--[/b]
[SA31554] Anzio Web Print Object (WePO) ActiveX Component "mainurl" Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-08-21
Core Security Technologies has reported a vulnerability in the Anzio Web Print Object (WePO) ActiveX component, which can be exploited by
malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31554/\"]http://secunia.com/advisories/31554/[/url]
--
[SA31534] MailScan for Mail Servers Web Administration Interface Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information
Released: 2008-08-19
Oliver Karow has reported some vulnerabilities in MailScan for Mail Servers, which can be exploited by malicious people to disclose potentially sensitive information, conduct cross-site scripting attacks, and bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/31534/\"]http://secunia.com/advisories/31534/[/url]
--
[SA31511] EO Video Playlist File "Name" Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-08-18
Muris Kurgas has discovered a vulnerability in EO Video, which can be
exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/31511/\"]http://secunia.com/advisories/31511/[/url]
--
[SA31504] WS_FTP Home / Professional Format String Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-08-19
securfrog has discovered a vulnerability in WS_FTP Home and Professional, which can be exploited by malicious people to potentially
compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31504/\"]http://secunia.com/advisories/31504/[/url]
--
[SA31559] Folder Lock Weak Password Encryption Security Issue
Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-08-21
Charalambous Glafkos and George Nicolaou have discovered a security issue in Folder Lock, which can be exploited by malicious, local users
to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31559/\"]http://secunia.com/advisories/31559/[/url]
[b]
UNIX/Linux:--[/b]
[SA31550] Programs Rating "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-20
Hussin X has reported a vulnerability in Programs Rating, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31550/\"]http://secunia.com/advisories/31550/[/url]
--
[SA31542] Banner Management "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-08-20
S.W.A.T. has reported a vulnerability in Banner Management, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31542/\"]http://secunia.com/advisories/31542/[/url]
--
[SA31535] Avaya CMS Solaris "snoop" Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-08-20
Avaya has acknowledged some vulnerabilities in Avaya CMS, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31535/\"]http://secunia.com/advisories/31535/[/url]
--
[SA31531] Reflection for Secure IT Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass, Exposure of sensitive information, DoS
Released: 2008-08-18
Attachmate has reported some vulnerabilities in Reflection for Secure IT, where some have unknown impacts and others can be exploited by
malicious, local users to disclose sensitive information and bypass certain security restrictions, and by malicious people to cause a DoS
(Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31531/\"]http://secunia.com/advisories/31531/[/url]
--
[SA31526] EchoVNC for Linux "CLogger::WriteFormated()" Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-18
A vulnerability has been reported in EchoVNC for Linux, which potentially can be exploited by malicious people to compromise a user's
system.
Full Advisory: [url=\"http://secunia.com/advisories/31526/\"]http://secunia.com/advisories/31526/[/url]
--
[SA31518] SUSE update for python
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-08-19
SUSE has issued an update for python. This fixes some vulnerabilities, where some have unknown impact and others can potentially be exploited
by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31518/\"]http://secunia.com/advisories/31518/[/url]
--
[SA31538] Sun Java System Portal Server Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-19
A vulnerability has been reported in Sun Java System Portal Server, which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31538/\"]http://secunia.com/advisories/31538/[/url]
--
[SA31524] Avaya Products nss_ldap Race Condition Security Issue
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-18
Avaya has acknowleged a security issue in various Avaya products, which can be exploited by malicious people to manipulate certain data.
Full Advisory: [url=\"http://secunia.com/advisories/31524/\"]http://secunia.com/advisories/31524/[/url]
--
[SA31508] neon "parse_domain()" Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-08-21
A vulnerability has been reported in neon, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31508/\"]http://secunia.com/advisories/31508/[/url]
--
[SA31536] Avaya CMS Solaris namefs Kernel Module Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-08-20
Avaya has acknowledged a vulnerability in Avaya CMS, which can be exploited by malicious, local users to cause a DoS (Denial of Service)
or to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31536/\"]http://secunia.com/advisories/31536/[/url]
--
[SA31530] Debian update for postfix
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-19
Debian has issued an update for postfix. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31530/\"]http://secunia.com/advisories/31530/[/url]
--
[SA31507] Mktemp Insecure Random Name Generator Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-15
A vulnerability has been reported in Mktemp, which can be exploited by malicious, local users to perform certain actions with escalated
privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31507/\"]http://secunia.com/advisories/31507/[/url]
--
[SA31517] Sun Solaris NFSv4 Client Kernel Module Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-08-20
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31517/\"]http://secunia.com/advisories/31517/[/url]
--
[SA31509] Linux Kernel "dccp_setsockopt_change()" Integer Overflow
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-08-18
A vulnerability has been reported in the Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31509/\"]http://secunia.com/advisories/31509/[/url]
--
[SA31501] Avaya CMS Solaris "picld" Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-08-20
Avaya has acknowledged a vulnerability in Avaya CMS, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31501/\"]http://secunia.com/advisories/31501/[/url]
[b]Cross Platform:--[/b]
[SA31549] Opera Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-08-20
Some vulnerabilities have been reported in Opera, which can be exploited by malicious people to conduct spoofing and cross-site scripting attacks, bypass certain security restrictions, disclose potentially sensitive information, or potentially compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31549/\"]http://secunia.com/advisories/31549/[/url]
--
[SA31521] PHP Live Helper Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information, System access
Released: 2008-08-20
James Bercegay has reported some vulnerabilities in PHP Live Helper, which can be exploited by malicious people to conduct SQL injection
attacks and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31521/\"]http://secunia.com/advisories/31521/[/url]
--
[SA31502] xine-lib Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-15
Some vulnerabilities have been reported in xine-lib, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31502/\"]http://secunia.com/advisories/31502/[/url]
--
[SA31547] Short Url & Url Tracker Script "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-20
Hussin X has reported a vulnerability in Short Url & Url Tracker Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31547/\"]http://secunia.com/advisories/31547/[/url]
--
[SA31546] URL Rotator Script "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-20
Hussin X has reported a vulnerability in URL Rotator Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31546/\"]http://secunia.com/advisories/31546/[/url]
--
[SA31544] Active PHP Bookmarks "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-08-20
Hussin X has discovered a vulnerability in Active PHP Bookmarks (APB), which can be exploited by malicious people to conduct SQL injection
attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31544/\"]http://secunia.com/advisories/31544/[/url]
--
[SA31541] Viral Marketing Script "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-20
Hussin X has reported a vulnerability in Viral Marketing Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31541/\"]http://secunia.com/advisories/31541/[/url]
--
[SA31539] SunShop Shopping Cart class.ajax.php SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-21
James Bercegay has reported some vulnerabilities in SunShop Shopping Cart, which can be exploited by malicious people to conduct SQL
injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31539/\"]http://secunia.com/advisories/31539/[/url]
--
[SA31537] SFS Affiliate Directory "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-19
Hussin X has reported a vulnerability in SFS Affiliate Directory, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31537/\"]http://secunia.com/advisories/31537/[/url]
--
[SA31529] Ad-Exchange Script "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-20
Hussin X has reported a vulnerability in Ad-Exchange Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31529/\"]http://secunia.com/advisories/31529/[/url]
--
[SA31522] vbDrupal Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, System access
Released: 2008-08-18
Some vulnerabilities have been reported in vbDrupal, which can be exploited by malicious users to conduct script insertion attacks and
compromise a vulnerable system, and by malicious people to conduct cross-site scripting and cross-site request forgery attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31522/\"]http://secunia.com/advisories/31522/[/url]
--
[SA31520] Papoo "suchanzahl" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-19
Russ McRee has reported a vulnerability in Papoo, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31520/\"]http://secunia.com/advisories/31520/[/url]
--
[SA31516] dotCMS Two File Disclosure Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-08-18
Don has discovered two vulnerabilities in dotCMS, which can be
exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31516/\"]http://secunia.com/advisories/31516/[/url]
--
[SA31515] ZEEJOBSITE "adid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-08-18
Hussin X has reported a vulnerability in ZEEJOBSITE, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31515/\"]http://secunia.com/advisories/31515/[/url]
--
[SA31513] YourFreeWorld Classifieds Script "category" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-20
Hussin X has reported a vulnerability in YourFreeWorld Classifieds Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31513/\"]http://secunia.com/advisories/31513/[/url]
--
[SA31512] VLC Media Player TTA Processing Integer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-18
g_ has discovered a vulnerability in VLC Media Player, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31512/\"]http://secunia.com/advisories/31512/[/url]
--
[SA31510] Forced Matrix Script "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-20
Hussin X has reported a vulnerability in Forced Matrix Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31510/\"]http://secunia.com/advisories/31510/[/url]
--
[SA31506] E-Shop Shopping Cart "cid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-15
Mormoroth has reported a vulnerability in E-Shop Shopping Cart (E-Php Shopping Cart), which can be exploited by malicious people to conduct
SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31506/\"]http://secunia.com/advisories/31506/[/url]
--
[SA31552] vBulletin Private Message Subject Script Insertion
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-21
Federico Muttis has reported a vulnerability in vBulletin, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31552/\"]http://secunia.com/advisories/31552/[/url]
--
[SA31543] NOAH Unspecified Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-19
A vulnerability has been reported in NOAH, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31543/\"]http://secunia.com/advisories/31543/[/url]
--
[SA31532] FlexCMS "PreviousColorsString" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-18
Khashayar Fereidani has discovered a vulnerability in FlexCMS, which
can be exploited by malicious people to conduct cross-site scripting
attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/31532/\"]http://secunia.com/advisories/31532/[/url]
--
[SA31528] Mambo Two Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-18
Khashayar Fereidani has discovered two vulnerabilities in Mambo, which can be exploited by malicious people to conduct cross-site scripting
attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31528/\"]http://secunia.com/advisories/31528/[/url]
--
[SA31527] Vanilla Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-20
Some vulnerabilities have been reported in Vanilla, which can be exploited by malicious users to conduct script insertion attacks, and by malicious people to conduct cross-site scripting and cross-site request forgery attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31527/\"]http://secunia.com/advisories/31527/[/url]
--
[SA31525] Interleave Information Disclosure Security Issues
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-08-19
Some security issues have been reported in Interleave, which can be exploited by malicious users to disclose certain sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31525/\"]http://secunia.com/advisories/31525/[/url]
--
[SA31519] AWStats URL Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-18
Morgan Todd has discovered a vulnerability in AWStats, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31519/\"]http://secunia.com/advisories/31519/[/url]
--
[SA31503] Harmoni Cross-Site Request Forgery and Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2008-08-15
Two vulnerabilities have been reported in Harmoni, which can be exploited by malicious people to bypass certain security restrictions and conduct cross-site request forgery attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31503/\"]http://secunia.com/advisories/31503/[/url]
--
[SA31533] PHPizabi "id" Information Disclosure and Manipulation
Critical: Not critical
Where: From remote
Impact: Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-08-19
Lostmon has discovered a vulnerability in PHPizabi, which can be exploited by malicious users to disclose sensitive information and manipulate data.
Full Advisory: [url=\"http://secunia.com/advisories/31533/\"]http://secunia.com/advisories/31533/[/url]
--
[SA31505] GnuTLS "gnutls_handshake()" Denial of Service
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2008-08-15
A vulnerability has been reported in GnuTLS, which can potentially be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31505/\"]http://secunia.com/advisories/31505/[/url]
[b]Windows:--[/b]
[SA31554] Anzio Web Print Object (WePO) ActiveX Component "mainurl" Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-08-21
Core Security Technologies has reported a vulnerability in the Anzio Web Print Object (WePO) ActiveX component, which can be exploited by
malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31554/\"]http://secunia.com/advisories/31554/[/url]
--
[SA31534] MailScan for Mail Servers Web Administration Interface Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information
Released: 2008-08-19
Oliver Karow has reported some vulnerabilities in MailScan for Mail Servers, which can be exploited by malicious people to disclose potentially sensitive information, conduct cross-site scripting attacks, and bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/31534/\"]http://secunia.com/advisories/31534/[/url]
--
[SA31511] EO Video Playlist File "Name" Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-08-18
Muris Kurgas has discovered a vulnerability in EO Video, which can be
exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/31511/\"]http://secunia.com/advisories/31511/[/url]
--
[SA31504] WS_FTP Home / Professional Format String Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-08-19
securfrog has discovered a vulnerability in WS_FTP Home and Professional, which can be exploited by malicious people to potentially
compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31504/\"]http://secunia.com/advisories/31504/[/url]
--
[SA31559] Folder Lock Weak Password Encryption Security Issue
Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-08-21
Charalambous Glafkos and George Nicolaou have discovered a security issue in Folder Lock, which can be exploited by malicious, local users
to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31559/\"]http://secunia.com/advisories/31559/[/url]
[b]
UNIX/Linux:--[/b]
[SA31550] Programs Rating "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-20
Hussin X has reported a vulnerability in Programs Rating, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31550/\"]http://secunia.com/advisories/31550/[/url]
--
[SA31542] Banner Management "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-08-20
S.W.A.T. has reported a vulnerability in Banner Management, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31542/\"]http://secunia.com/advisories/31542/[/url]
--
[SA31535] Avaya CMS Solaris "snoop" Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-08-20
Avaya has acknowledged some vulnerabilities in Avaya CMS, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31535/\"]http://secunia.com/advisories/31535/[/url]
--
[SA31531] Reflection for Secure IT Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass, Exposure of sensitive information, DoS
Released: 2008-08-18
Attachmate has reported some vulnerabilities in Reflection for Secure IT, where some have unknown impacts and others can be exploited by
malicious, local users to disclose sensitive information and bypass certain security restrictions, and by malicious people to cause a DoS
(Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31531/\"]http://secunia.com/advisories/31531/[/url]
--
[SA31526] EchoVNC for Linux "CLogger::WriteFormated()" Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-18
A vulnerability has been reported in EchoVNC for Linux, which potentially can be exploited by malicious people to compromise a user's
system.
Full Advisory: [url=\"http://secunia.com/advisories/31526/\"]http://secunia.com/advisories/31526/[/url]
--
[SA31518] SUSE update for python
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-08-19
SUSE has issued an update for python. This fixes some vulnerabilities, where some have unknown impact and others can potentially be exploited
by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31518/\"]http://secunia.com/advisories/31518/[/url]
--
[SA31538] Sun Java System Portal Server Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-19
A vulnerability has been reported in Sun Java System Portal Server, which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31538/\"]http://secunia.com/advisories/31538/[/url]
--
[SA31524] Avaya Products nss_ldap Race Condition Security Issue
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-18
Avaya has acknowleged a security issue in various Avaya products, which can be exploited by malicious people to manipulate certain data.
Full Advisory: [url=\"http://secunia.com/advisories/31524/\"]http://secunia.com/advisories/31524/[/url]
--
[SA31508] neon "parse_domain()" Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-08-21
A vulnerability has been reported in neon, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31508/\"]http://secunia.com/advisories/31508/[/url]
--
[SA31536] Avaya CMS Solaris namefs Kernel Module Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-08-20
Avaya has acknowledged a vulnerability in Avaya CMS, which can be exploited by malicious, local users to cause a DoS (Denial of Service)
or to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31536/\"]http://secunia.com/advisories/31536/[/url]
--
[SA31530] Debian update for postfix
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-19
Debian has issued an update for postfix. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31530/\"]http://secunia.com/advisories/31530/[/url]
--
[SA31507] Mktemp Insecure Random Name Generator Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-15
A vulnerability has been reported in Mktemp, which can be exploited by malicious, local users to perform certain actions with escalated
privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31507/\"]http://secunia.com/advisories/31507/[/url]
--
[SA31517] Sun Solaris NFSv4 Client Kernel Module Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-08-20
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31517/\"]http://secunia.com/advisories/31517/[/url]
--
[SA31509] Linux Kernel "dccp_setsockopt_change()" Integer Overflow
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-08-18
A vulnerability has been reported in the Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31509/\"]http://secunia.com/advisories/31509/[/url]
--
[SA31501] Avaya CMS Solaris "picld" Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-08-20
Avaya has acknowledged a vulnerability in Avaya CMS, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31501/\"]http://secunia.com/advisories/31501/[/url]
[b]Cross Platform:--[/b]
[SA31549] Opera Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-08-20
Some vulnerabilities have been reported in Opera, which can be exploited by malicious people to conduct spoofing and cross-site scripting attacks, bypass certain security restrictions, disclose potentially sensitive information, or potentially compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31549/\"]http://secunia.com/advisories/31549/[/url]
--
[SA31521] PHP Live Helper Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information, System access
Released: 2008-08-20
James Bercegay has reported some vulnerabilities in PHP Live Helper, which can be exploited by malicious people to conduct SQL injection
attacks and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31521/\"]http://secunia.com/advisories/31521/[/url]
--
[SA31502] xine-lib Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-15
Some vulnerabilities have been reported in xine-lib, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31502/\"]http://secunia.com/advisories/31502/[/url]
--
[SA31547] Short Url & Url Tracker Script "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-20
Hussin X has reported a vulnerability in Short Url & Url Tracker Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31547/\"]http://secunia.com/advisories/31547/[/url]
--
[SA31546] URL Rotator Script "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-20
Hussin X has reported a vulnerability in URL Rotator Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31546/\"]http://secunia.com/advisories/31546/[/url]
--
[SA31544] Active PHP Bookmarks "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-08-20
Hussin X has discovered a vulnerability in Active PHP Bookmarks (APB), which can be exploited by malicious people to conduct SQL injection
attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31544/\"]http://secunia.com/advisories/31544/[/url]
--
[SA31541] Viral Marketing Script "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-20
Hussin X has reported a vulnerability in Viral Marketing Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31541/\"]http://secunia.com/advisories/31541/[/url]
--
[SA31539] SunShop Shopping Cart class.ajax.php SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-21
James Bercegay has reported some vulnerabilities in SunShop Shopping Cart, which can be exploited by malicious people to conduct SQL
injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31539/\"]http://secunia.com/advisories/31539/[/url]
--
[SA31537] SFS Affiliate Directory "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-19
Hussin X has reported a vulnerability in SFS Affiliate Directory, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31537/\"]http://secunia.com/advisories/31537/[/url]
--
[SA31529] Ad-Exchange Script "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-20
Hussin X has reported a vulnerability in Ad-Exchange Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31529/\"]http://secunia.com/advisories/31529/[/url]
--
[SA31522] vbDrupal Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, System access
Released: 2008-08-18
Some vulnerabilities have been reported in vbDrupal, which can be exploited by malicious users to conduct script insertion attacks and
compromise a vulnerable system, and by malicious people to conduct cross-site scripting and cross-site request forgery attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31522/\"]http://secunia.com/advisories/31522/[/url]
--
[SA31520] Papoo "suchanzahl" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-19
Russ McRee has reported a vulnerability in Papoo, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31520/\"]http://secunia.com/advisories/31520/[/url]
--
[SA31516] dotCMS Two File Disclosure Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-08-18
Don has discovered two vulnerabilities in dotCMS, which can be
exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31516/\"]http://secunia.com/advisories/31516/[/url]
--
[SA31515] ZEEJOBSITE "adid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-08-18
Hussin X has reported a vulnerability in ZEEJOBSITE, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31515/\"]http://secunia.com/advisories/31515/[/url]
--
[SA31513] YourFreeWorld Classifieds Script "category" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-20
Hussin X has reported a vulnerability in YourFreeWorld Classifieds Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31513/\"]http://secunia.com/advisories/31513/[/url]
--
[SA31512] VLC Media Player TTA Processing Integer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-18
g_ has discovered a vulnerability in VLC Media Player, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31512/\"]http://secunia.com/advisories/31512/[/url]
--
[SA31510] Forced Matrix Script "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-20
Hussin X has reported a vulnerability in Forced Matrix Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31510/\"]http://secunia.com/advisories/31510/[/url]
--
[SA31506] E-Shop Shopping Cart "cid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-15
Mormoroth has reported a vulnerability in E-Shop Shopping Cart (E-Php Shopping Cart), which can be exploited by malicious people to conduct
SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31506/\"]http://secunia.com/advisories/31506/[/url]
--
[SA31552] vBulletin Private Message Subject Script Insertion
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-21
Federico Muttis has reported a vulnerability in vBulletin, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31552/\"]http://secunia.com/advisories/31552/[/url]
--
[SA31543] NOAH Unspecified Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-19
A vulnerability has been reported in NOAH, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31543/\"]http://secunia.com/advisories/31543/[/url]
--
[SA31532] FlexCMS "PreviousColorsString" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-18
Khashayar Fereidani has discovered a vulnerability in FlexCMS, which
can be exploited by malicious people to conduct cross-site scripting
attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/31532/\"]http://secunia.com/advisories/31532/[/url]
--
[SA31528] Mambo Two Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-18
Khashayar Fereidani has discovered two vulnerabilities in Mambo, which can be exploited by malicious people to conduct cross-site scripting
attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31528/\"]http://secunia.com/advisories/31528/[/url]
--
[SA31527] Vanilla Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-20
Some vulnerabilities have been reported in Vanilla, which can be exploited by malicious users to conduct script insertion attacks, and by malicious people to conduct cross-site scripting and cross-site request forgery attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31527/\"]http://secunia.com/advisories/31527/[/url]
--
[SA31525] Interleave Information Disclosure Security Issues
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-08-19
Some security issues have been reported in Interleave, which can be exploited by malicious users to disclose certain sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31525/\"]http://secunia.com/advisories/31525/[/url]
--
[SA31519] AWStats URL Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-18
Morgan Todd has discovered a vulnerability in AWStats, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31519/\"]http://secunia.com/advisories/31519/[/url]
--
[SA31503] Harmoni Cross-Site Request Forgery and Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2008-08-15
Two vulnerabilities have been reported in Harmoni, which can be exploited by malicious people to bypass certain security restrictions and conduct cross-site request forgery attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31503/\"]http://secunia.com/advisories/31503/[/url]
--
[SA31533] PHPizabi "id" Information Disclosure and Manipulation
Critical: Not critical
Where: From remote
Impact: Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-08-19
Lostmon has discovered a vulnerability in PHPizabi, which can be exploited by malicious users to disclose sensitive information and manipulate data.
Full Advisory: [url=\"http://secunia.com/advisories/31533/\"]http://secunia.com/advisories/31533/[/url]
--
[SA31505] GnuTLS "gnutls_handshake()" Denial of Service
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2008-08-15
A vulnerability has been reported in GnuTLS, which can potentially be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31505/\"]http://secunia.com/advisories/31505/[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Secunia Updates - August 2008
[url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of August 28 2008
[b]Windows:--[/b]
[b][SA31615] SoftArtisans XFile FileManager ActiveX Control Multiple Buffer Overflows[/b]
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-08-26
Will Dormann has reported some vulnerabilities in SoftArtisans XFile, which can be exploited by malicious people to compromise a user's
system.
Full Advisory: [url=\"http://secunia.com/advisories/31615/\"]http://secunia.com/advisories/31615/[/url]
[b][SA31616] HP Enterprise Discovery Unspecified Privilege Escalation[/b]
Critical: Moderately critical
Where: From remote
Impact: Privilege escalation
Released: 2008-08-27
A vulnerability has been reported in HP Enterprise Discovery, which can be exploited by malicious users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31616/\"]http://secunia.com/advisories/31616/[/url]
[b][SA31607] Pluck blog_include_react.php Local File Inclusion[/b]
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-08-26
Digital Security Research Group have reported two vulnerabilities in Pluck, which can be exploited by malicious people to disclose sensitive
information.
Full Advisory: [url=\"http://secunia.com/advisories/31607/\"]http://secunia.com/advisories/31607/[/url]
[b][SA31631] KM Scanner File Utility Multiple Vulnerabilities[/b]
Critical: Moderately critical
Where: From local network
Impact: DoS, System access, Security Bypass
Released: 2008-08-27
Seth Fogie has reported some vulnerabilities in KM Scanner File Utility, which can be exploited by malicious people to cause a DoS (Denial of Service), bypass certain security restrictions, and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31631/\"]http://secunia.com/advisories/31631/[/url]
[b][SA31618] TIBCO Hawk Multiple Buffer Overflow Vulnerabilities[/b]
Critical: Moderately critical
Where: From local network
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-08-26
Some vulnerabilities have been reported in multiple TIBCO products, which can be exploited by malicious people to disclose sensitive
information, cause a DoS (Denial of Service), or to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31618/\"]http://secunia.com/advisories/31618/[/url]
[b][SA31637] Smart Survey "sid" Cross-Site Scripting Vulnerability[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-27
Bug Researchers Group has reported a vulnerability in Smart Survey, which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31637/\"]http://secunia.com/advisories/31637/[/url]
[b]UNIX/Linux:--[/b]
[SA31620] Ubuntu update for yelp
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-28
Ubuntu has issued an update for yelp. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31620/\"]http://secunia.com/advisories/31620/[/url]
[b][SA31600] SUSE update for Sun Java[/b]
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-08-25
SUSE has issued an update for Sun Java. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose system information or potentially sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31600/\"]http://secunia.com/advisories/31600/[/url]
[b][SA31586] SUSE update for IBM Java[/b]
Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-08-25
SUSE has issued an update for IBM Java. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31586/\"]http://secunia.com/advisories/31586/[/url]
[b][SA31580] SUSE update for IBMJava2-JRE and IBMJava2-SDK[/b]
Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-08-25
SUSE has issued an update for IBMJava2-JRE and IBMJava2-SDK. This fixes some vulnerabilities, which can be exploited by malicious people to
bypass certain security restrictions, cause a DoS (Denial of Service), and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31580/\"]http://secunia.com/advisories/31580/[/url]
[b][SA31576] Astaro update for ClamAV[/b]
Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-08-22
Astaro has issued an update for ClamAV. This fixes some vulnerabilities, which potentially can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), or compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31576/\"]http://secunia.com/advisories/31576/[/url]
[b][SA31567] xine-lib Multiple Vulnerabilities[/b]
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-25
Some vulnerabilities have been reported in xine-lib, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31567/\"]http://secunia.com/advisories/31567/[/url]
[b][SA31646] Red Hat update for openoffice.org[/b]
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-08-28
Red Hat has issued an update for openoffice.org. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31646/\"]http://secunia.com/advisories/31646/[/url]
[b][SA31639] Red Hat update for tomcat[/b]
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-08-28
Red Hat has issued an update for tomcat. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, or disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31639/\"]http://secunia.com/advisories/31639/[/url]
[b][SA31638] Sharity Unspecified Vulnerability[/b]
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-08-27
A vulnerability with an unknown impact has been reported in Sharity.
Full Advisory: [url=\"http://secunia.com/advisories/31638/\"]http://secunia.com/advisories/31638/[/url]
[b][SA31628] Red Hat update for kernel[/b]
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-08-27
Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, disclose potentially sensitive information, cause a DoS (Denial of Service), and potentially gain escalated privileges, and by malicious people to cause a DoS.
Full Advisory: [url=\"http://secunia.com/advisories/31628/\"]http://secunia.com/advisories/31628/[/url]
[b][SA31624] Red Hat update for ipsec-tools
[/b]
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-08-27
Red Hat has issued an update for ipsec-tools. This fixes two vulnerabilities, which can be exploited by malicious users and malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31624/\"]http://secunia.com/advisories/31624/[/url]
[b][SA31623] Debian update for tiff[/b]
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-27
Debian has issued an update for tiff. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service)
or to potentially compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31623/\"]http://secunia.com/advisories/31623/[/url]
[b][SA31604] Avaya Products Perl Regular Expressions Unicode Data Buffer Overflow[/b]
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-25
Avaya has acknowledged a vulnerability in various Avaya products, which can potentially be exploited by malicious people to compromise a
vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31604/\"]http://secunia.com/advisories/31604/[/url]
[b][SA31590] Debian update for libxml2[/b]
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-08-25
Debian has issued an update for libxml2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory: [url=\"http://secunia.com/advisories/31590/\"]http://secunia.com/advisories/31590/[/url]
[b][SA31577] Avaya Communication Manager FreeType Multiple Vulnerabilities[/b]
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-22
Avaya has acknowledged some vulnerabilities in Avaya Communication Manager, which potentially can be exploited by malicious people to
compromise an application using the FreeType library.
Full Advisory: [url=\"http://secunia.com/advisories/31577/\"]http://secunia.com/advisories/31577/[/url]
[b][SA31575] Red Hat Update for Tampered OpenSSH Packages[/b]
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-08-22
Red Hat has issued an update for openssh, which corrects a small number of OpenSSH packages that have been tampered with.
Full Advisory: [url=\"http://secunia.com/advisories/31575/\"]http://secunia.com/advisories/31575/[/url]
[b][SA31566] Red Hat update for libxml2[/b]
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-08-22
Red Hat has issued an update for libxml2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory: [url=\"http://secunia.com/advisories/31566/\"]http://secunia.com/advisories/31566/[/url]
[b][SA31565] Red Hat Directory Server Multiple Vulnerabilities[/b]
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2008-08-28
Some vulnerabilities have been reported in Red Hat Directory Server, which can be exploited by malicious people to conduct cross-site
scripting attacks, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31565/\"]http://secunia.com/advisories/31565/[/url]
[b][SA31651] HP-UX update for Apache[/b]
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-08-28
HP has issued an update for Apache. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial
of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31651/\"]http://secunia.com/advisories/31651/[/url]
[b][SA31633] BitlBee Account Recreation Security Issue[/b]
Critical: Less critical
Where: From remote
Impact: Hijacking, Security Bypass
Released: 2008-08-27
A security issue has been reported in BitlBee, which can be exploited by malicious people to bypass certain security restrictions and hijack
accounts.
Full Advisory: [url=\"http://secunia.com/advisories/31633/\"]http://secunia.com/advisories/31633/[/url]
[b][SA31625] Xoops PopnupBlog Module "index.php" Cross-Site Scripting[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-27
Lostmon has discovered two vulnerabilities in the PopnupBlog module for Xoops, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31625/\"]http://secunia.com/advisories/31625/[/url]
[b][SA31612] Red Hat update for adminutil[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-28
Red Hat has issued an update for adminutil. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31612/\"]http://secunia.com/advisories/31612/[/url]
[b][SA31589] Photo Cart "qtitle" Cross-Site Scripting Vulnerability[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-25
Tyler Trioxide has reported a vulnerability in Photo Cart, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31589/\"]http://secunia.com/advisories/31589/[/url]
[b][SA31627] Red Hat Directory Server Denial of Service Vulnerabilities[/b]
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-08-28
Some vulnerabilities have been reported in Red Hat Directory Server, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory: [url=\"http://secunia.com/advisories/31627/\"]http://secunia.com/advisories/31627/[/url]
[b][SA31597] NetBSD PPPoE Packet Processing Tag Length Vulnerability[/b]
Critical: Less critical
Where: From local network
Impact: DoS, System access
Released: 2008-08-26
A vulnerability has been reported in NetBSD, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially
compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31597/\"]http://secunia.com/advisories/31597/[/url]
[b][SA31568] Avaya Products Net-snmp Multiple Vulnerabilities[/b]
Critical: Less critical
Where: From local network
Impact: Spoofing, DoS, System access
Released: 2008-08-22
Avaya has acknowledged some vulnerabilities in various Avaya products, which can be exploited by malicious people to spoof authenticated
SNMPv3 packets or to potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31568/\"]http://secunia.com/advisories/31568/[/url]
[b][SA31658] Honeyd "test.sh" Insecure Temporary Files[/b]
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-28
A security issue has been reported in Honeyd, which can be exploited by malicious, local users to perform certain actions with escalated
privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31658/\"]http://secunia.com/advisories/31658/[/url]
[b][SA31648] Citadel "migrate_aliases.sh" Insecure Temporary Files[/b]
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-28
A security issue has been discovered in Citadel, which can be exploited by malicious, local users to perform certain actions with escalated
privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31648/\"]http://secunia.com/advisories/31648/[/url]
[b][SA31647] R "javareconf" Insecure Temporary Files[/b]
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-28
A security issue has been reported in R, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31647/\"]http://secunia.com/advisories/31647/[/url]
[b][SA31614] Ubuntu update for kernel[/b]
Critical: Less critical
Where: Local system
Impact: Security Bypass, Privilege escalation, DoS
Released: 2008-08-26
Ubuntu has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, cause a DoS (Denial of Service), and potentially gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31614/\"]http://secunia.com/advisories/31614/[/url]
[b][SA31605] DriveCrypt Plus Pack Password Disclosure Security Issue[/b]
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-08-27
A security issue has been discovered in DriveCrypt Plus Pack, which can be exploited by malicious, local users to disclose sensitive
information.
Full Advisory: [url=\"http://secunia.com/advisories/31605/\"]http://secunia.com/advisories/31605/[/url]
[b]
[SA31581] OpenVMS SMGSHR.EXE Buffer Overflow Vulnerability[/b]
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-26
A vulnerability has been reported in OpenVMS, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31581/\"]http://secunia.com/advisories/31581/[/url]
[b][SA31561] Xen "flask_op" Buffer Overflow Vulnerability[/b]
Critical: Less critical
Where: Local system
Impact: Security Bypass, DoS
Released: 2008-08-22
A vulnerability has been reported in Xen, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or potentially bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31561/\"]http://secunia.com/advisories/31561/[/url]
[b][SA31592] Vim Shell Command Injection Weaknesses[/b]
Critical: Not critical
Where: From remote
Impact: System access
Released: 2008-08-25
Some weaknesses have been reported in Vim, which can be exploited by malicious people to potentially compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31592/\"]http://secunia.com/advisories/31592/[/url]
[b][SA31659] Tiger "genmsgidx" Insecure Temporary Files[/b]
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-28
A security issue has been reported in Tiger, which can be exploited by malicious, local users to perform certain actions with escalated
privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31659/\"]http://secunia.com/advisories/31659/[/url]
[b][SA31657] Ampache "gather-messages.sh" Insecure Temporary Files[/b]
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-28
A security issue has been reported in Ampache, which can be exploited by malicious, local users to perform certain actions with escalated
privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31657/\"]http://secunia.com/advisories/31657/[/url]
[b][SA31622] Sun Solaris NFS RPC Zones Denial of Service[/b]
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-08-27
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31622/\"]http://secunia.com/advisories/31622/[/url]
[b][SA31601] Samba "group_mapping.tdb" Insecure Permissions Security Issue[/b]
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-08-26
A security issue has been reported in Samba, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31601/\"]http://secunia.com/advisories/31601/[/url]
[b][SA31598] Sun Solaris NFS Kernel Module Denial of Service[/b]
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-08-25
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31598/\"]http://secunia.com/advisories/31598/[/url]
[b][SA31579] Linux Kernel "rt6_fill_node()" Denial of Service Vulnerability[/b]
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-08-22
A vulnerability has been reported in the Linux kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31579/\"]http://secunia.com/advisories/31579/[/url]
[b]Other:--[/b]
[b][SA31572] Accellion File Transfer Appliance "forgot_password.html" Cross-Site Scripting[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-26
Eric BEAULIEU has reported a vulnerability in Accellion File Transfer Appliance, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31572/\"]http://secunia.com/advisories/31572/[/url]
[b]Cross Platform:--[/b]
[SA31603] JustSystems Ichitaro Products Unspecified Code Execution Vulnerability
Critical: Extremely critical
Where: From remote
Impact: System access
Released: 2008-08-28
A vulnerability has been reported in JustSystems Ichitaro products, which can be exploited by malicious people to compromise a user's
system.
Full Advisory: [url=\"http://secunia.com/advisories/31603/\"]http://secunia.com/advisories/31603/[/url]
[b][SA31630] AWStats Totals Cross-site Scripting and PHP Code Execution[/b]
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2008-08-27
Emory University has reported some vulnerabilities in AWStats Totals, which can be exploited by malicious people to conduct cross-site
scripting attacks or to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31630/\"]http://secunia.com/advisories/31630/[/url]
[b][SA31641] Quick Poll "id" SQL Injection Vulnerability[/b]
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-28
Hussin X has reported a vulnerability in Quick Poll, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31641/\"]http://secunia.com/advisories/31641/[/url]
[b]
[SA31640] OpenOffice "rtl_allocateMemory()" Truncation Vulnerability[/b]
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-28
A vulnerability has been reported in OpenOffice, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31640/\"]http://secunia.com/advisories/31640/[/url]
[b][SA31635] IBM DB2 CLR Stored Procedures Unspecified Vulnerability[/b]
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-08-27
A vulnerability with an unknown impact has been reported in IBM DB2.
Full Advisory: [url=\"http://secunia.com/advisories/31635/\"]http://secunia.com/advisories/31635/[/url]
[b][SA31626] Million Pixel Ad Script "id_cat" SQL Injection[/b]
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-27
Hussin X has reported a vulnerability in Million Pixel Ad Script (Million Pixel Script), which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31626/\"]http://secunia.com/advisories/31626/[/url]
[b][SA31621] Kolifa.net Download Script "id" SQL Injection Vulnerability[/b]
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-27
Kacak has reported a vulnerability in Kolifa.net Download Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31621/\"]http://secunia.com/advisories/31621/[/url]
[b][SA31610] LibTIFF LZW Decoder Buffer Underflow Vulnerability[/b]
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-26
A vulnerability has been reported in LibTIFF, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially
compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31610/\"]http://secunia.com/advisories/31610/[/url]
[b][SA31602] Ruby REXML Denial of Service Vulnerability
[/b]
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-08-25
A vulnerability has been reported in Ruby, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31602/\"]http://secunia.com/advisories/31602/[/url]
[b][SA31599] CMME Multiple Vulnerabilities[/b]
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-08-28
SirGod has discovered some vulnerabilities and a security issue in CMME (Content Management Made Easy), which can be exploited by malicious
people to conduct cross-site scripting attacks and disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31599/\"]http://secunia.com/advisories/31599/[/url]
[SA31585] Five Star Review Script SQL Injection and Cross-Site Scripting
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2008-08-25
Mr.SQL has reported two vulnerabilities in Five Star Review Script, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31585/\"]http://secunia.com/advisories/31585/[/url]
[b][SA31584] MiaCMS "id" SQL Injection Vulnerabilities[/b]
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-08-26
~!Dok_tOR!~ has discovered some vulnerabilities in MiaCMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31584/\"]http://secunia.com/advisories/31584/[/url]
[b][SA31582] LacoodaST Multiple Vulnerabilities[/b]
Critical: Moderately critical
Where: From remote
Impact: Hijacking, Cross Site Scripting, System access
Released: 2008-08-22
Some vulnerabilities have been reported in LacoodaST, which can be exploited by malicious people to conduct cross-site scripting and,
cross-site request forgery, or session fixation attacks, and malicious users to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31582/\"]http://secunia.com/advisories/31582/[/url]
[b][SA31574] La!cooda WIZ Multiple Vulnerabilities[/b]
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2008-08-22
Some vulnerabilities have been reported in La!cooda WIZ, which can be exploited by malicious people to conduct cross-site scripting and
cross-site request forgery attacks, and malicious users to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31574/\"]http://secunia.com/advisories/31574/[/url]
[b][SA31573] Crafty Syntax Live Help "department" SQL Injection Vulnerabilities[/b]
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-26
James Bercegay has discovered two vulnerabilities in Crafty Syntax Live Help, which can be exploited by malicious people to conduct SQL
injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31573/\"]http://secunia.com/advisories/31573/[/url]
[b][SA31571] Pars4u Videosharing V1 "cat_id" SQL Injection[/b]
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-22
Mr.SQL has reported a vulnerability in Pars4u Videosharing V1, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31571/\"]http://secunia.com/advisories/31571/[/url]
[b][SA31570] Easy Site Local File Inclusion and Directory Listing Vulnerabilities[/b]
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-08-22
SirGod has discovered two vulnerabilities in Easy Site, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31570/\"]http://secunia.com/advisories/31570/[/url]
[b][SA31569] TinyCMS "config[template]" Local File Inclusion Vulnerability[/b]
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-08-22
cOndemned has discovered a vulnerability in TinyCMS, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31569/\"]http://secunia.com/advisories/31569/[/url]
[b][SA31564] Matterdaddy Market "index.php" SQL Injection[/b]
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-25
~!Dok_tOR!~ has discovered two vulnerabilities in Matterdaddy Market, which can be exploited by malicious people to conduct SQL injection
attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31564/\"]http://secunia.com/advisories/31564/[/url]
[b][SA31563] FAR-PHP "c" Local File Inclusion Vulnerability[/b]
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-08-22
Beenu Arora has discovered a vulnerability in FAR-PHP, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31563/\"]http://secunia.com/advisories/31563/[/url]
[b][SA31562] CCMS Gaming "id" SQL Injection Vulnerability[/b]
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-26
~!Dok_tOR!~ has reported a vulnerability in CCMS Gaming, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31562/\"]http://secunia.com/advisories/31562/[/url]
[b][SA31560] webEdition CMS "we_objectID" SQL Injection Vulnerability[/b]
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-27
Lidloses_Auge has reported a vulnerability in webEdition CMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31560/\"]http://secunia.com/advisories/31560/[/url]
[b][SA31643] Mono Sys.Web HTTP Header Injection Vulnerability[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-28
Juraj Skripsky has reported a vulnerability in Mono, which can be exploited by malicious people to conduct HTTP header injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31643/\"]http://secunia.com/advisories/31643/[/url]
[b]
[SA31634] IBM Lotus Quickr Multiple Cross-Site Scripting Vulnerabilities[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-27
Some vulnerabilities have been reported in IBM Lotus Quickr, which can be exploited by malicious people to conduct cross-site scripting
attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31634/\"]http://secunia.com/advisories/31634/[/url]
[b][SA31611] mysql-lists Unspecified Cross-Site Scripting Vulnerability[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-26
A vulnerability has been reported in mysql-lists, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31611/\"]http://secunia.com/advisories/31611/[/url]
[b][SA31609] Civic Website Manager Calendar Control Cross-Site Scripting[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-26
Some vulnerabilities have been reported in Civic Website Manager, which can be exploited by malicious people to conduct cross-site scripting
attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31609/\"]http://secunia.com/advisories/31609/[/url]
[b][SA31608] AN Guestbook Cross-Site Scripting Vulnerabilities[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-26
Some vulnerabilities have been reported in AN Guestbook, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31608/\"]http://secunia.com/advisories/31608/[/url]
[b][SA31606] ezContents Multiple Local File Inclusion Vulnerabilities[/b]
Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-08-26
Digital Security Research Group have discovered some vulnerabilities in
ezContents, which can be exploited by malicious people to disclose
sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31606/\"]http://secunia.com/advisories/31606/[/url]
[b]
[SA31596] GBrowse Cross-Site Scripting Vulnerability[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-25
A vulnerability has been reported in GBrowse, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31596/\"]http://secunia.com/advisories/31596/[/url]
[b][SA31591] ACG-PTP Multiple Script Insertion Vulnerabilities[/b]
Critical: Not critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-25
FatBack Mac has reported some vulnerabilities in ACG-PTP, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31591/\"]http://secunia.com/advisories/31591/[/url]
[b]Windows:--[/b]
[b][SA31615] SoftArtisans XFile FileManager ActiveX Control Multiple Buffer Overflows[/b]
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-08-26
Will Dormann has reported some vulnerabilities in SoftArtisans XFile, which can be exploited by malicious people to compromise a user's
system.
Full Advisory: [url=\"http://secunia.com/advisories/31615/\"]http://secunia.com/advisories/31615/[/url]
[b][SA31616] HP Enterprise Discovery Unspecified Privilege Escalation[/b]
Critical: Moderately critical
Where: From remote
Impact: Privilege escalation
Released: 2008-08-27
A vulnerability has been reported in HP Enterprise Discovery, which can be exploited by malicious users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31616/\"]http://secunia.com/advisories/31616/[/url]
[b][SA31607] Pluck blog_include_react.php Local File Inclusion[/b]
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-08-26
Digital Security Research Group have reported two vulnerabilities in Pluck, which can be exploited by malicious people to disclose sensitive
information.
Full Advisory: [url=\"http://secunia.com/advisories/31607/\"]http://secunia.com/advisories/31607/[/url]
[b][SA31631] KM Scanner File Utility Multiple Vulnerabilities[/b]
Critical: Moderately critical
Where: From local network
Impact: DoS, System access, Security Bypass
Released: 2008-08-27
Seth Fogie has reported some vulnerabilities in KM Scanner File Utility, which can be exploited by malicious people to cause a DoS (Denial of Service), bypass certain security restrictions, and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31631/\"]http://secunia.com/advisories/31631/[/url]
[b][SA31618] TIBCO Hawk Multiple Buffer Overflow Vulnerabilities[/b]
Critical: Moderately critical
Where: From local network
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-08-26
Some vulnerabilities have been reported in multiple TIBCO products, which can be exploited by malicious people to disclose sensitive
information, cause a DoS (Denial of Service), or to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31618/\"]http://secunia.com/advisories/31618/[/url]
[b][SA31637] Smart Survey "sid" Cross-Site Scripting Vulnerability[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-27
Bug Researchers Group has reported a vulnerability in Smart Survey, which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31637/\"]http://secunia.com/advisories/31637/[/url]
[b]UNIX/Linux:--[/b]
[SA31620] Ubuntu update for yelp
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-28
Ubuntu has issued an update for yelp. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31620/\"]http://secunia.com/advisories/31620/[/url]
[b][SA31600] SUSE update for Sun Java[/b]
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-08-25
SUSE has issued an update for Sun Java. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose system information or potentially sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31600/\"]http://secunia.com/advisories/31600/[/url]
[b][SA31586] SUSE update for IBM Java[/b]
Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-08-25
SUSE has issued an update for IBM Java. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31586/\"]http://secunia.com/advisories/31586/[/url]
[b][SA31580] SUSE update for IBMJava2-JRE and IBMJava2-SDK[/b]
Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-08-25
SUSE has issued an update for IBMJava2-JRE and IBMJava2-SDK. This fixes some vulnerabilities, which can be exploited by malicious people to
bypass certain security restrictions, cause a DoS (Denial of Service), and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31580/\"]http://secunia.com/advisories/31580/[/url]
[b][SA31576] Astaro update for ClamAV[/b]
Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-08-22
Astaro has issued an update for ClamAV. This fixes some vulnerabilities, which potentially can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), or compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31576/\"]http://secunia.com/advisories/31576/[/url]
[b][SA31567] xine-lib Multiple Vulnerabilities[/b]
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-25
Some vulnerabilities have been reported in xine-lib, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31567/\"]http://secunia.com/advisories/31567/[/url]
[b][SA31646] Red Hat update for openoffice.org[/b]
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-08-28
Red Hat has issued an update for openoffice.org. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31646/\"]http://secunia.com/advisories/31646/[/url]
[b][SA31639] Red Hat update for tomcat[/b]
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-08-28
Red Hat has issued an update for tomcat. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, or disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31639/\"]http://secunia.com/advisories/31639/[/url]
[b][SA31638] Sharity Unspecified Vulnerability[/b]
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-08-27
A vulnerability with an unknown impact has been reported in Sharity.
Full Advisory: [url=\"http://secunia.com/advisories/31638/\"]http://secunia.com/advisories/31638/[/url]
[b][SA31628] Red Hat update for kernel[/b]
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-08-27
Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, disclose potentially sensitive information, cause a DoS (Denial of Service), and potentially gain escalated privileges, and by malicious people to cause a DoS.
Full Advisory: [url=\"http://secunia.com/advisories/31628/\"]http://secunia.com/advisories/31628/[/url]
[b][SA31624] Red Hat update for ipsec-tools
[/b]
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-08-27
Red Hat has issued an update for ipsec-tools. This fixes two vulnerabilities, which can be exploited by malicious users and malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31624/\"]http://secunia.com/advisories/31624/[/url]
[b][SA31623] Debian update for tiff[/b]
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-27
Debian has issued an update for tiff. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service)
or to potentially compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31623/\"]http://secunia.com/advisories/31623/[/url]
[b][SA31604] Avaya Products Perl Regular Expressions Unicode Data Buffer Overflow[/b]
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-25
Avaya has acknowledged a vulnerability in various Avaya products, which can potentially be exploited by malicious people to compromise a
vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31604/\"]http://secunia.com/advisories/31604/[/url]
[b][SA31590] Debian update for libxml2[/b]
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-08-25
Debian has issued an update for libxml2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory: [url=\"http://secunia.com/advisories/31590/\"]http://secunia.com/advisories/31590/[/url]
[b][SA31577] Avaya Communication Manager FreeType Multiple Vulnerabilities[/b]
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-22
Avaya has acknowledged some vulnerabilities in Avaya Communication Manager, which potentially can be exploited by malicious people to
compromise an application using the FreeType library.
Full Advisory: [url=\"http://secunia.com/advisories/31577/\"]http://secunia.com/advisories/31577/[/url]
[b][SA31575] Red Hat Update for Tampered OpenSSH Packages[/b]
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-08-22
Red Hat has issued an update for openssh, which corrects a small number of OpenSSH packages that have been tampered with.
Full Advisory: [url=\"http://secunia.com/advisories/31575/\"]http://secunia.com/advisories/31575/[/url]
[b][SA31566] Red Hat update for libxml2[/b]
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-08-22
Red Hat has issued an update for libxml2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory: [url=\"http://secunia.com/advisories/31566/\"]http://secunia.com/advisories/31566/[/url]
[b][SA31565] Red Hat Directory Server Multiple Vulnerabilities[/b]
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2008-08-28
Some vulnerabilities have been reported in Red Hat Directory Server, which can be exploited by malicious people to conduct cross-site
scripting attacks, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31565/\"]http://secunia.com/advisories/31565/[/url]
[b][SA31651] HP-UX update for Apache[/b]
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-08-28
HP has issued an update for Apache. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial
of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31651/\"]http://secunia.com/advisories/31651/[/url]
[b][SA31633] BitlBee Account Recreation Security Issue[/b]
Critical: Less critical
Where: From remote
Impact: Hijacking, Security Bypass
Released: 2008-08-27
A security issue has been reported in BitlBee, which can be exploited by malicious people to bypass certain security restrictions and hijack
accounts.
Full Advisory: [url=\"http://secunia.com/advisories/31633/\"]http://secunia.com/advisories/31633/[/url]
[b][SA31625] Xoops PopnupBlog Module "index.php" Cross-Site Scripting[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-27
Lostmon has discovered two vulnerabilities in the PopnupBlog module for Xoops, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31625/\"]http://secunia.com/advisories/31625/[/url]
[b][SA31612] Red Hat update for adminutil[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-28
Red Hat has issued an update for adminutil. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31612/\"]http://secunia.com/advisories/31612/[/url]
[b][SA31589] Photo Cart "qtitle" Cross-Site Scripting Vulnerability[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-25
Tyler Trioxide has reported a vulnerability in Photo Cart, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31589/\"]http://secunia.com/advisories/31589/[/url]
[b][SA31627] Red Hat Directory Server Denial of Service Vulnerabilities[/b]
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-08-28
Some vulnerabilities have been reported in Red Hat Directory Server, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory: [url=\"http://secunia.com/advisories/31627/\"]http://secunia.com/advisories/31627/[/url]
[b][SA31597] NetBSD PPPoE Packet Processing Tag Length Vulnerability[/b]
Critical: Less critical
Where: From local network
Impact: DoS, System access
Released: 2008-08-26
A vulnerability has been reported in NetBSD, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially
compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31597/\"]http://secunia.com/advisories/31597/[/url]
[b][SA31568] Avaya Products Net-snmp Multiple Vulnerabilities[/b]
Critical: Less critical
Where: From local network
Impact: Spoofing, DoS, System access
Released: 2008-08-22
Avaya has acknowledged some vulnerabilities in various Avaya products, which can be exploited by malicious people to spoof authenticated
SNMPv3 packets or to potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31568/\"]http://secunia.com/advisories/31568/[/url]
[b][SA31658] Honeyd "test.sh" Insecure Temporary Files[/b]
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-28
A security issue has been reported in Honeyd, which can be exploited by malicious, local users to perform certain actions with escalated
privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31658/\"]http://secunia.com/advisories/31658/[/url]
[b][SA31648] Citadel "migrate_aliases.sh" Insecure Temporary Files[/b]
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-28
A security issue has been discovered in Citadel, which can be exploited by malicious, local users to perform certain actions with escalated
privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31648/\"]http://secunia.com/advisories/31648/[/url]
[b][SA31647] R "javareconf" Insecure Temporary Files[/b]
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-28
A security issue has been reported in R, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31647/\"]http://secunia.com/advisories/31647/[/url]
[b][SA31614] Ubuntu update for kernel[/b]
Critical: Less critical
Where: Local system
Impact: Security Bypass, Privilege escalation, DoS
Released: 2008-08-26
Ubuntu has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, cause a DoS (Denial of Service), and potentially gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31614/\"]http://secunia.com/advisories/31614/[/url]
[b][SA31605] DriveCrypt Plus Pack Password Disclosure Security Issue[/b]
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-08-27
A security issue has been discovered in DriveCrypt Plus Pack, which can be exploited by malicious, local users to disclose sensitive
information.
Full Advisory: [url=\"http://secunia.com/advisories/31605/\"]http://secunia.com/advisories/31605/[/url]
[b]
[SA31581] OpenVMS SMGSHR.EXE Buffer Overflow Vulnerability[/b]
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-26
A vulnerability has been reported in OpenVMS, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31581/\"]http://secunia.com/advisories/31581/[/url]
[b][SA31561] Xen "flask_op" Buffer Overflow Vulnerability[/b]
Critical: Less critical
Where: Local system
Impact: Security Bypass, DoS
Released: 2008-08-22
A vulnerability has been reported in Xen, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or potentially bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31561/\"]http://secunia.com/advisories/31561/[/url]
[b][SA31592] Vim Shell Command Injection Weaknesses[/b]
Critical: Not critical
Where: From remote
Impact: System access
Released: 2008-08-25
Some weaknesses have been reported in Vim, which can be exploited by malicious people to potentially compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31592/\"]http://secunia.com/advisories/31592/[/url]
[b][SA31659] Tiger "genmsgidx" Insecure Temporary Files[/b]
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-28
A security issue has been reported in Tiger, which can be exploited by malicious, local users to perform certain actions with escalated
privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31659/\"]http://secunia.com/advisories/31659/[/url]
[b][SA31657] Ampache "gather-messages.sh" Insecure Temporary Files[/b]
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-28
A security issue has been reported in Ampache, which can be exploited by malicious, local users to perform certain actions with escalated
privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31657/\"]http://secunia.com/advisories/31657/[/url]
[b][SA31622] Sun Solaris NFS RPC Zones Denial of Service[/b]
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-08-27
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31622/\"]http://secunia.com/advisories/31622/[/url]
[b][SA31601] Samba "group_mapping.tdb" Insecure Permissions Security Issue[/b]
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-08-26
A security issue has been reported in Samba, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31601/\"]http://secunia.com/advisories/31601/[/url]
[b][SA31598] Sun Solaris NFS Kernel Module Denial of Service[/b]
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-08-25
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31598/\"]http://secunia.com/advisories/31598/[/url]
[b][SA31579] Linux Kernel "rt6_fill_node()" Denial of Service Vulnerability[/b]
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-08-22
A vulnerability has been reported in the Linux kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31579/\"]http://secunia.com/advisories/31579/[/url]
[b]Other:--[/b]
[b][SA31572] Accellion File Transfer Appliance "forgot_password.html" Cross-Site Scripting[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-26
Eric BEAULIEU has reported a vulnerability in Accellion File Transfer Appliance, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31572/\"]http://secunia.com/advisories/31572/[/url]
[b]Cross Platform:--[/b]
[SA31603] JustSystems Ichitaro Products Unspecified Code Execution Vulnerability
Critical: Extremely critical
Where: From remote
Impact: System access
Released: 2008-08-28
A vulnerability has been reported in JustSystems Ichitaro products, which can be exploited by malicious people to compromise a user's
system.
Full Advisory: [url=\"http://secunia.com/advisories/31603/\"]http://secunia.com/advisories/31603/[/url]
[b][SA31630] AWStats Totals Cross-site Scripting and PHP Code Execution[/b]
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2008-08-27
Emory University has reported some vulnerabilities in AWStats Totals, which can be exploited by malicious people to conduct cross-site
scripting attacks or to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31630/\"]http://secunia.com/advisories/31630/[/url]
[b][SA31641] Quick Poll "id" SQL Injection Vulnerability[/b]
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-28
Hussin X has reported a vulnerability in Quick Poll, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31641/\"]http://secunia.com/advisories/31641/[/url]
[b]
[SA31640] OpenOffice "rtl_allocateMemory()" Truncation Vulnerability[/b]
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-28
A vulnerability has been reported in OpenOffice, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31640/\"]http://secunia.com/advisories/31640/[/url]
[b][SA31635] IBM DB2 CLR Stored Procedures Unspecified Vulnerability[/b]
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-08-27
A vulnerability with an unknown impact has been reported in IBM DB2.
Full Advisory: [url=\"http://secunia.com/advisories/31635/\"]http://secunia.com/advisories/31635/[/url]
[b][SA31626] Million Pixel Ad Script "id_cat" SQL Injection[/b]
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-27
Hussin X has reported a vulnerability in Million Pixel Ad Script (Million Pixel Script), which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31626/\"]http://secunia.com/advisories/31626/[/url]
[b][SA31621] Kolifa.net Download Script "id" SQL Injection Vulnerability[/b]
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-27
Kacak has reported a vulnerability in Kolifa.net Download Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31621/\"]http://secunia.com/advisories/31621/[/url]
[b][SA31610] LibTIFF LZW Decoder Buffer Underflow Vulnerability[/b]
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-26
A vulnerability has been reported in LibTIFF, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially
compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31610/\"]http://secunia.com/advisories/31610/[/url]
[b][SA31602] Ruby REXML Denial of Service Vulnerability
[/b]
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-08-25
A vulnerability has been reported in Ruby, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31602/\"]http://secunia.com/advisories/31602/[/url]
[b][SA31599] CMME Multiple Vulnerabilities[/b]
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-08-28
SirGod has discovered some vulnerabilities and a security issue in CMME (Content Management Made Easy), which can be exploited by malicious
people to conduct cross-site scripting attacks and disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31599/\"]http://secunia.com/advisories/31599/[/url]
[SA31585] Five Star Review Script SQL Injection and Cross-Site Scripting
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2008-08-25
Mr.SQL has reported two vulnerabilities in Five Star Review Script, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31585/\"]http://secunia.com/advisories/31585/[/url]
[b][SA31584] MiaCMS "id" SQL Injection Vulnerabilities[/b]
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-08-26
~!Dok_tOR!~ has discovered some vulnerabilities in MiaCMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31584/\"]http://secunia.com/advisories/31584/[/url]
[b][SA31582] LacoodaST Multiple Vulnerabilities[/b]
Critical: Moderately critical
Where: From remote
Impact: Hijacking, Cross Site Scripting, System access
Released: 2008-08-22
Some vulnerabilities have been reported in LacoodaST, which can be exploited by malicious people to conduct cross-site scripting and,
cross-site request forgery, or session fixation attacks, and malicious users to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31582/\"]http://secunia.com/advisories/31582/[/url]
[b][SA31574] La!cooda WIZ Multiple Vulnerabilities[/b]
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2008-08-22
Some vulnerabilities have been reported in La!cooda WIZ, which can be exploited by malicious people to conduct cross-site scripting and
cross-site request forgery attacks, and malicious users to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31574/\"]http://secunia.com/advisories/31574/[/url]
[b][SA31573] Crafty Syntax Live Help "department" SQL Injection Vulnerabilities[/b]
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-26
James Bercegay has discovered two vulnerabilities in Crafty Syntax Live Help, which can be exploited by malicious people to conduct SQL
injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31573/\"]http://secunia.com/advisories/31573/[/url]
[b][SA31571] Pars4u Videosharing V1 "cat_id" SQL Injection[/b]
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-22
Mr.SQL has reported a vulnerability in Pars4u Videosharing V1, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31571/\"]http://secunia.com/advisories/31571/[/url]
[b][SA31570] Easy Site Local File Inclusion and Directory Listing Vulnerabilities[/b]
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-08-22
SirGod has discovered two vulnerabilities in Easy Site, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31570/\"]http://secunia.com/advisories/31570/[/url]
[b][SA31569] TinyCMS "config[template]" Local File Inclusion Vulnerability[/b]
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-08-22
cOndemned has discovered a vulnerability in TinyCMS, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31569/\"]http://secunia.com/advisories/31569/[/url]
[b][SA31564] Matterdaddy Market "index.php" SQL Injection[/b]
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-25
~!Dok_tOR!~ has discovered two vulnerabilities in Matterdaddy Market, which can be exploited by malicious people to conduct SQL injection
attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31564/\"]http://secunia.com/advisories/31564/[/url]
[b][SA31563] FAR-PHP "c" Local File Inclusion Vulnerability[/b]
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-08-22
Beenu Arora has discovered a vulnerability in FAR-PHP, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31563/\"]http://secunia.com/advisories/31563/[/url]
[b][SA31562] CCMS Gaming "id" SQL Injection Vulnerability[/b]
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-26
~!Dok_tOR!~ has reported a vulnerability in CCMS Gaming, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31562/\"]http://secunia.com/advisories/31562/[/url]
[b][SA31560] webEdition CMS "we_objectID" SQL Injection Vulnerability[/b]
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-08-27
Lidloses_Auge has reported a vulnerability in webEdition CMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31560/\"]http://secunia.com/advisories/31560/[/url]
[b][SA31643] Mono Sys.Web HTTP Header Injection Vulnerability[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-28
Juraj Skripsky has reported a vulnerability in Mono, which can be exploited by malicious people to conduct HTTP header injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31643/\"]http://secunia.com/advisories/31643/[/url]
[b]
[SA31634] IBM Lotus Quickr Multiple Cross-Site Scripting Vulnerabilities[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-27
Some vulnerabilities have been reported in IBM Lotus Quickr, which can be exploited by malicious people to conduct cross-site scripting
attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31634/\"]http://secunia.com/advisories/31634/[/url]
[b][SA31611] mysql-lists Unspecified Cross-Site Scripting Vulnerability[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-26
A vulnerability has been reported in mysql-lists, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31611/\"]http://secunia.com/advisories/31611/[/url]
[b][SA31609] Civic Website Manager Calendar Control Cross-Site Scripting[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-26
Some vulnerabilities have been reported in Civic Website Manager, which can be exploited by malicious people to conduct cross-site scripting
attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31609/\"]http://secunia.com/advisories/31609/[/url]
[b][SA31608] AN Guestbook Cross-Site Scripting Vulnerabilities[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-26
Some vulnerabilities have been reported in AN Guestbook, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31608/\"]http://secunia.com/advisories/31608/[/url]
[b][SA31606] ezContents Multiple Local File Inclusion Vulnerabilities[/b]
Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-08-26
Digital Security Research Group have discovered some vulnerabilities in
ezContents, which can be exploited by malicious people to disclose
sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31606/\"]http://secunia.com/advisories/31606/[/url]
[b]
[SA31596] GBrowse Cross-Site Scripting Vulnerability[/b]
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-25
A vulnerability has been reported in GBrowse, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31596/\"]http://secunia.com/advisories/31596/[/url]
[b][SA31591] ACG-PTP Multiple Script Insertion Vulnerabilities[/b]
Critical: Not critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-25
FatBack Mac has reported some vulnerabilities in ACG-PTP, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31591/\"]http://secunia.com/advisories/31591/[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
