Page 1 of 1

Secunia Bulletins February 2008

Posted: Fri Feb 01, 2008 6:06 pm
by Tami
[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing For The Week of February 1 2008[/b][/i]

[b]Windows:--[/b]

[SA28733] Aurigma Image Uploader ActiveX Control "Action" Property Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-01

Elazar Broad has discovered a vulnerability in Aurigma Image Uploader, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28733/\"]http://secunia.com/advisories/28733/[/url]

--

[SA28724] SwiftView Viewer ActiveX Control/Plug-in Buffer Overflows

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-31

Will Dormann has reported some vulnerabilities in SwiftView Viewer, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28724/\"]http://secunia.com/advisories/28724/[/url]

--

[SA28715] MySpace Uploader Control ActiveX Control "Action" Property Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-31

Elazar Broad has discovered a vulnerability in MySpace Uploader Control, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28715/\"]http://secunia.com/advisories/28715/[/url]

--

[SA28710] GFL SDK Radiance RGBE Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-30

Secunia Research has discovered a vulnerability in GFL SDK, which can be exploited by malicious people to compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/28710/\"]http://secunia.com/advisories/28710/[/url]

--

[SA28688] IrfanView FlashPix Plug-in Memory Corruption Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-29

Marsu has discovered a vulnerability in the FlashPix plug-in for IrfanView, which potentially can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28688/\"]http://secunia.com/advisories/28688/[/url]

--

[SA28660] Persits Software XUpload "AddFile()" Method Buffer Overflows

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-29

Some vulnerabilities have been discovered in Persits Software XUpload, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28660/\"]http://secunia.com/advisories/28660/[/url]

--

[SA28649] NamoInstaller ActiveX Control NamoInstall Class "Install()" Insecure Method

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-28

plan-s has discovered a vulnerability in NamoInstaller ActiveX Control, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28649/\"]http://secunia.com/advisories/28649/[/url]

--

[SA28647] Move Networks Upgrade Manager Upgrade Class ActiveX Control Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-25

Elazar Broad has discovered a vulnerability in Move Networks Upgrade Manager, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28647/\"]http://secunia.com/advisories/28647/[/url]

--

[SA28662] CandyPress Store SQL Injection and Cross-Site Scripting

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2008-01-28

Some vulnerabilities have been reported in CandyPress Store, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28662/\"]http://secunia.com/advisories/28662/[/url]

--

[SA28653] ASPired2Protect login.asp SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-29

Aria-Security Team has reported some vulnerabilities in ASPired2Protect, which can be exploited by malicious people to conduct
SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28653/\"]http://secunia.com/advisories/28653/[/url]

--

[SA28651] Pre Dynamic Institution Multiple SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-01-28

Aria-Security Team have reported some vulnerabilities in Pre Dynamic Institution, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28651/\"]http://secunia.com/advisories/28651/[/url]

--

[SA28689] IBM Informix Storage Manager XDR Library Multiple Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-01-29

IBM has acknowledged some vulnerabilities in Informix Storage Manager, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28689/\"]http://secunia.com/advisories/28689/[/url]

--

[SA28663] Proficy HMI/SCADA - CIMPLICITY w32rtr.exe Packet Processing Buffer Overflow

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-01-28

Eyal Udassin has reported a vulnerability in Proficy HMI/SCADA - CIMPLICITY, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28663/\"]http://secunia.com/advisories/28663/[/url]

--

[SA28735] Uniwin eCart Professional "rp" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-01

sascha has reported a vulnerability in Uniwin eCart Professional, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28735/\"]http://secunia.com/advisories/28735/[/url]

--

[SA28695] BitTorrent Web UI HTTP Request "Range" Header Processing Denial of Service

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-01-29

Luigi Auriemma has discovered a vulnerability in BitTorrent, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28695/\"]http://secunia.com/advisories/28695/[/url]

--

[SA28686] uTorrent Web UI HTTP Request "Range" Header Processing Denial of Service

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-01-29

Luigi Auriemma has discovered a vulnerability in uTorrent, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28686/\"]http://secunia.com/advisories/28686/[/url]

--

[SA28675] SoftCart Multiple Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-30

Russ McRee has reported some vulnerabilities in SoftCart, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28675/\"]http://secunia.com/advisories/28675/[/url]

--

[SA28678] Proficy Real-Time Information Portal "Add WebSource" File Upload Vulnerability

Critical: Less critical
Where: From local network
Impact: System access
Released: 2008-01-28

Eyal Udassin has reported a vulnerability in Proficy Real-Time Information Portal, which can be exploited by malicious users to
compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28678/\"]http://secunia.com/advisories/28678/[/url]


[b]UNIX/Linux:--[/b]

[SA28725] Gnumeric XLS HLINK Opcode Processing Code Execution
Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-31

A vulnerability has been reported in Gnumeric, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28725/\"]http://secunia.com/advisories/28725/[/url]

--

[SA28719] Gentoo update for peercast

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-31

Gentoo has issued an update for peercast. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28719/\"]http://secunia.com/advisories/28719/[/url]

--

[SA28671] Debian update for yarssr

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-28

Debian has issued an update for yarssr. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28671/\"]http://secunia.com/advisories/28671/[/url]

--

[SA28720] Gentoo update for kazehakase

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-01-31

Gentoo has issued an update for kazehakase. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose potentially sensitive information, and compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28720/\"]http://secunia.com/advisories/28720/[/url]

--

[SA28716] Gentoo update for libxml2

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-31

Gentoo has issued an update for libxml2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28716/\"]http://secunia.com/advisories/28716/[/url]

--

[SA28714] Gentoo update for goffice

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-01-31

Gentoo has issued an update for goffice. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service), disclose potentially sensitive information, and compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28714/\"]http://secunia.com/advisories/28714/[/url]

--

[SA28674] Gentoo update for xine-lib

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-28

Gentoo has issued an update for xine-lib. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28674/\"]http://secunia.com/advisories/28674/[/url]

--

[SA28673] Gentoo update for ngircd

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-28

Gentoo has issued an update for ngircd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28673/\"]http://secunia.com/advisories/28673/[/url]

--

[SA28669] Fedora update for icu

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-28

Fedora has issued an update for icu. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/28669/\"]http://secunia.com/advisories/28669/[/url]

--

[SA28666] Fedora update for xine-lib

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-29

Fedora has issued an update for xine-lib. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28666/\"]http://secunia.com/advisories/28666/[/url]

--

[SA28658] SUSE update for php4 and php5

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Privilege escalation, DoS, System access
Released: 2008-01-29

SUSE has issued an update for php4 and php5. This fixes some vulnerabilities, where some have unknown impacts and others can be exploited by malicious, local users to gain escalated privileges, malicious users to bypass certain security restrictions, and by malicious people to cause a DoS (Denial of Service) and potentially execute arbitrary code.

Full Advisory:
[url=\"http://secunia.com/advisories/28658/\"]http://secunia.com/advisories/28658/[/url]

--

[SA28650] Gentoo update for maradns

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-30

Gentoo has issued an update for maradns. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28650/\"]http://secunia.com/advisories/28650/[/url]

--

[SA28728] Gentoo update for xdg-utils

Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-01-31

Gentoo has issued an update for xdg-utils. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28728/\"]http://secunia.com/advisories/28728/[/url]

--

[SA28726] OpenBSD bgplg "cmd" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-31

Alexandr Polyakov and Anton Karpov have reported a vulnerability in OpenBSD bgplg, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28726/\"]http://secunia.com/advisories/28726/[/url]

--

[SA28697] Gentoo update for netkit-ftpd

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-01-30

Gentoo has acknowledged a vulnerability in netkit-ftpd, which can be exploited by malicious users to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28697/\"]http://secunia.com/advisories/28697/[/url]

--

[SA28661] AmpJuke "limit" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-30

ShaF**k31 has reported a vulnerability in AmpJuke, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28661/\"]http://secunia.com/advisories/28661/[/url]

--

[SA28648] Avaya Products e2fsprogs Integer Overflow Vulnerabilities

Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-25

Avaya has acknowledged some vulnerabilities in multiple Avaya products, which potentially can be exploited by malicious people to compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/28648/\"]http://secunia.com/advisories/28648/[/url]

--

[SA28645] Mandriva update for ruby

Critical: Less critical
Where: From remote
Impact: Spoofing
Released: 2008-01-31

Mandriva has issued an update for ruby. This fixes some security issues, which can be exploited by malicious people to conduct spoofing attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28645/\"]http://secunia.com/advisories/28645/[/url]

--

[SA28679] Gentoo update for postgresql

Critical: Less critical
Where: From local network
Impact: Privilege escalation, DoS
Released: 2008-01-29

Gentoo has issued an update for postgresql. This fixes some vulnerabilities, which can be exploited by malicious users to gain
escalated privileges or to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28679/\"]http://secunia.com/advisories/28679/[/url]

--

[SA28676] Fedora update for cups

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-01-28

Fedora has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28676/\"]http://secunia.com/advisories/28676/[/url]

--

[SA28738] Ubuntu update for pulseaudio

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-01

Ubuntu has issued an update for pulseaudio. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28738/\"]http://secunia.com/advisories/28738/[/url]

--

[SA28718] rPath update for xorg-x11

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-31

rPath has issued an update for xorg-x11. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28718/\"]http://secunia.com/advisories/28718/[/url]

--

[SA28693] Avaya CMS Solaris X Window System and X Server Multiple Vulnerabilities

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-29

Avaya has acknowledged some vulnerabilities in Avaya CMS (Call Management System), which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28693/\"]http://secunia.com/advisories/28693/[/url]

--

[SA28665] PatchLink Update Client for Unix Insecure Temporary Files

Critical: Less critical
Where: Local system
Impact: Manipulation of data, Privilege escalation
Released: 2008-01-30

Larry W. Cashdollar has reported two security issues in the PatchLink Update client for Unix, which can be exploited by malicious, local users to truncate arbitrary files and to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28665/\"]http://secunia.com/advisories/28665/[/url]

--

[SA28664] Fedora update for kernel

Critical: Less critical
Where: Local system
Impact: Security Bypass, Manipulation of data
Released: 2008-01-29

Fedora has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions and corrupt a file system.

Full Advisory:
[url=\"http://secunia.com/advisories/28664/\"]http://secunia.com/advisories/28664/[/url]

--

[SA28672] Gentoo update for blam

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-28

Gentoo has issued an update for blam. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28672/\"]http://secunia.com/advisories/28672/[/url]

--

[SA28654] Linux Kernel minix File System Denial of Service Vulnerability

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-01-28

A vulnerability has been reported in the Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28654/\"]http://secunia.com/advisories/28654/[/url]


[b]Other:--[/b]

[SA28667] IBM Hardware Management Console Pegasus CIM Denial of Service

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-29

A vulnerability has been reported in IBM HMC, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28667/\"]http://secunia.com/advisories/28667/[/url]

--

[SA28690] Yamaha RT Series Routers Cross-Site Request Forgery Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-29

A vulnerability has been reported in Yamaha RT Series Routers, which can be exploited by malicious people to conduct cross-site request forgery attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28690/\"]http://secunia.com/advisories/28690/[/url]

--

[SA28655] F5 BIG-IP Application Security Manager "report_type" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-28

nnposter has reported a vulnerability in F5 BIG-IP Application Security Manager, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28655/\"]http://secunia.com/advisories/28655/[/url]


[b]Cross Platform:--[/b]

[SA28731] Drupal Project Issue Tracking Module File Upload and Script Insertion

Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2008-01-31

Some vulnerabilities have been reported in the Project Issue Tracking module for Drupal, which can be exploited by malicious users to conduct script insertion attacks and compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28731/\"]http://secunia.com/advisories/28731/[/url]

--

[SA28704] Connectix Boards "template_path" File Inclusion Vulnerability

Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-01-30

HouSSaMix has discovered a vulnerability in Connectix Boards, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28704/\"]http://secunia.com/advisories/28704/[/url]

--

[SA28685] Smart Publisher "filedata" PHP Code Execution

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-30

GoLd_M has reported a vulnerability in Smart Publisher, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28685/\"]http://secunia.com/advisories/28685/[/url]

--

[SA28682] Coppermine Photo Gallery Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, System access
Released: 2008-01-30

Some vulnerabilities have been reported in Coppermine Photo Gallery, which can be exploited by malicious people to conduct cross-site scripting attacks or to compromise a vulnerable system and by malicious users to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28682/\"]http://secunia.com/advisories/28682/[/url]

--

[SA28652] Mambo LaiThai Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Unknown, Manipulation of data, System access
Released: 2008-01-29

Some vulnerabilities have been reported in Mambo LaiThai, some with an unknown impact and others, which can be exploited by malicious people to conduct SQL injection attacks or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28652/\"]http://secunia.com/advisories/28652/[/url]

--

[SA28737] Nilson's Blogger Two Local File Inclusion Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-02-01

muuratsalo has discovered two vulnerabilities in Nilson's Blogger, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/28737/\"]http://secunia.com/advisories/28737/[/url]

--

[SA28732] Drupal Secure Site Module Security Bypass Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-31

A vulnerability has been reported in the Secure Site module for Drupal, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/28732/\"]http://secunia.com/advisories/28732/[/url]

--

[SA28729] Drupal Comment Upload Module File Upload Vulnerability

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-31

A vulnerability has been reported in the Comment Upload Module for Drupal, which can be exploited by malicious users to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28729/\"]http://secunia.com/advisories/28729/[/url]

--

[SA28727] PHP Links "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-31

Houssamix has discovered a vulnerability in PHP Links, which can be
exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28727/\"]http://secunia.com/advisories/28727/[/url]

--

[SA28722] VirtueMart File Disclosure and Cross-Site Request Forgery Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-01-31

Two vulnerabilities have been reported in VirtueMart, which can be exploited by malicious people to conduct cross-site request forgery attacks or to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/28722/\"]http://secunia.com/advisories/28722/[/url]

--

[SA28717] Drupal OpenID Module "claimed_id" Authority Spoofing

Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-01-31

A vulnerability has been reported in the OpenID module for Drupal, which can be exploited by malicious people to spoof OpenID authorities.

Full Advisory:
[url=\"http://secunia.com/advisories/28717/\"]http://secunia.com/advisories/28717/[/url]

--

[SA28709] phpCMS "file" File Disclosure Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-01-30

Alexandr Polyakov and Stas Svistunovich have discovered a vulnerability in phpCMS, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/28709/\"]http://secunia.com/advisories/28709/[/url]

--

[SA28708] WordPress AdServe Plugin "id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-30

enter_the_dragon has discovered a vulnerability in the AdServe plugin for WordPress, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28708/\"]http://secunia.com/advisories/28708/[/url]

--

[SA28702] WordPress WassUp Plugin "to_date" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-31

enter_the_dragon has reported a vulnerability in the WassUp plugin for WordPress, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28702/\"]http://secunia.com/advisories/28702/[/url]

--

[SA28691] Bigware Shop "pollid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-30

D4m14n has discovered a vulnerability in Bigware Shop, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28691/\"]http://secunia.com/advisories/28691/[/url]

--

[SA28683] WordPress WP-Cal Plugin "id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-29

Houssamix has discovered a vulnerability in the WP-Cal plugin for WordPress, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28683/\"]http://secunia.com/advisories/28683/[/url]

--

[SA28681] Simple Forum Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-01-29

tomplixsee has discovered some vulnerabilities in Simple Forum, which can be exploited by malicious people to conduct cross-site scripting attacks or to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/28681/\"]http://secunia.com/advisories/28681/[/url]

--

[SA28670] Mambo Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of system information
Released: 2008-01-29

AmnPardaz Security Research Team have discovered some vulnerabilities and a weakness in Mambo, which can be exploited by malicious people to disclose system information, conduct cross-site scripting and cross-site request forgery attacks, and to manipulate data.

Full Advisory:
[url=\"http://secunia.com/advisories/28670/\"]http://secunia.com/advisories/28670/[/url]

--

[SA28656] phpIP Management Two SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of sensitive information
Released: 2008-01-28

Charles Hooper has discovered two vulnerabilities in phpIP Management, which can be exploited by malicious people and users to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28656/\"]http://secunia.com/advisories/28656/[/url]

--

[SA28646] Seagull PHP Framework "files" Information Disclosure

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-01-25

fuzion has discovered a vulnerability in Seagull PHP Framework, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/28646/\"]http://secunia.com/advisories/28646/[/url]

--

[SA28711] Cisco Wireless Control System Apache Tomcat JK Web Server Connector Buffer Overflow

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-01-31

Cisco has acknowledged a vulnerability in Cisco Wireless Control System (WCS), which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28711/\"]http://secunia.com/advisories/28711/[/url]

--

[SA28746] Sun Java Runtime Environment External XML Entities Security Bypass

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-01

Sun has acknowledged a security issue in Sun Java Runtime Environment (JRE), which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/28746/\"]http://secunia.com/advisories/28746/[/url]

--

[SA28742] Liferay Portal Multiple Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Spoofing
Released: 2008-02-01

Tomasz Kuczynski has reported some vulnerabilities in Liferay Portal, which can be exploited by malicious people to conduct cross-site request forgery and phishing attacks, and by malicious users to conduct script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28742/\"]http://secunia.com/advisories/28742/[/url]

--

[SA28730] Drupal Userpoints Module Cross-Site Request Forgery Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-31

A vulnerability has been reported in the Userpoints module for Drupal, which can be exploited by malicious people to conduct cross-site request forgery attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28730/\"]http://secunia.com/advisories/28730/[/url]

--

[SA28692] Hal Networks Products Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-30

Some vulnerabilities have been reported in Hal Networks products, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28692/\"]http://secunia.com/advisories/28692/[/url]

--

[SA28687] Tripwire Enterprise Login Page Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-31

Dave Lewis has reported a vulnerability in Tripwire Enterprise, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28687/\"]http://secunia.com/advisories/28687/[/url]

--

[SA28684] webSPELL Cross-Site Scripting and Request Forgery

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-31

NBBN has discovered two vulnerabilities in webSPELL, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28684/\"]http://secunia.com/advisories/28684/[/url]

--

[SA28680] Nucleus CMS URL Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-30

Alexandr Polyakov and Stas Svistunovich have reported a vulnerability in Nucleus CMS, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28680/\"]http://secunia.com/advisories/28680/[/url]

Secunia Bulletins February 2008

Posted: Thu Feb 07, 2008 5:13 pm
by Tami
[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of February 7 2008[/b][/i]

[b]Windows:--[/b]

[SA28809] Ourgame GLWorld HanGamePluginCn18 Class ActiveX Control Buffer Overflows

Critical: Extremely critical
Where: From remote
Impact: System access
Released: 2008-02-06

Two vulnerabilities have been discovered in Ourgame GLWorld, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28809/\"]http://secunia.com/advisories/28809/[/url]

--

[SA28757] Yahoo! Music Jukebox ActiveX Control Buffer Overflows

Critical: Extremely critical
Where: From remote
Impact: System access
Released: 2008-02-04

Some vulnerabilities have been discovered in Yahoo! Music Jukebox, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28757/\"]http://secunia.com/advisories/28757/[/url]

--

[SA28797] ACDSee Photo Manager XBM File Processing Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-07

Trend Micro has reported a vulnerability in ACDSee Photo Manager, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28797/\"]http://secunia.com/advisories/28797/[/url]

--

[SA28791] Skype Cross-Zone Scripting Security Enhancement

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-06

An update has been released for Skype, which implements security enhancements to prevent compromise of users' systems.

Full Advisory:
[url=\"http://secunia.com/advisories/28791/\"]http://secunia.com/advisories/28791/[/url]

--

[SA28765] Nero Media Player Playlist Processing Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-05

securfrog has discovered a vulnerability in Nero Media Player, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28765/\"]http://secunia.com/advisories/28765/[/url]

--

[SA28760] Titan FTP Server Command Processing Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-04

securfrog has discovered a vulnerability in Titan FTP Server, which potentially can be exploited by malicious people to compromise a
vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28760/\"]http://secunia.com/advisories/28760/[/url]

--

[SA28822] IPSwitch WS_FTP Server Manager Security Bypass

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-02-07

Luigi Auriemma has discovered a security issue in IPSwitch WS_FTP Server, which can be exploited by malicious people to bypass certain access restrictions and disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/28822/\"]http://secunia.com/advisories/28822/[/url]

--

[SA28753] IpSwitch WS_FTP Server with SSH Buffer Overflow Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-04

securfrog has discovered a vulnerability in IpSwitch WS_FTP Server with SSH, which can be exploited by malicious users to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28753/\"]http://secunia.com/advisories/28753/[/url]

--

[SA28811] SAP SAPSprint Multiple Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-02-07

Some vulnerabilities have been reported in SAPSprint, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28811/\"]http://secunia.com/advisories/28811/[/url]

--

[SA28786] SAP GUI SAPLPD Multiple Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-02-05

Luigi Auriemma has discovered some vulnerabilities in SAP GUI, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28786/\"]http://secunia.com/advisories/28786/[/url]

--

[SA28763] WinCom LPD Total Multiple Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: Security Bypass, DoS, System access
Released: 2008-02-05

Luigi Auriemma has discovered some vulnerabilities in WinCom LPD Total, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28763/\"]http://secunia.com/advisories/28763/[/url]

--

[SA28770] RaidenHTTPD Unspecified Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-05

A vulnerability has been reported in RaidenHTTPD, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28770/\"]http://secunia.com/advisories/28770/[/url]

--

[SA28755] Xlight FTP Server LDAP Blank Password Security Bypass

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-04

A security issue has been reported in Xlight FTP Server, which can be exploited by malicious users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/28755/\"]http://secunia.com/advisories/28755/[/url]

--

[SA28761] Ipswitch WS_FTP Server FTP Log Server Denial of Service

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-05

Luigi Auriemma has discovered a vulnerability in Ipswitch WS_FTP Server, which can be exploited by malicious people to cause a DoS
(Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28761/\"]http://secunia.com/advisories/28761/[/url]

--

[SA28832] Symantec Altiris Notification Server Agent Privilege Escalation

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-07

A vulnerability has been reported in Symantec Altiris Notification Server, which can be exploited by malicious, local users to gain
escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28832/\"]http://secunia.com/advisories/28832/[/url]

--

[SA28792] Novell Client Challenge Response Client Clipboard Disclosure Weakness

Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-02-05

A weakness has been reported in the Challenge Response Client included in Novell Client, which can be exploited by malicious, local users to disclose potentially sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/28792/\"]http://secunia.com/advisories/28792/[/url]


[b]UNIX/Linux:--[/b]

[SA28821] Gentoo doomsday Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-07

Gentoo has acknowledged some vulnerabilities in doomsday, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28821/\"]http://secunia.com/advisories/28821/[/url]

--

[SA28812] Debian update for poppler

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-06

Debian has issued an update for poppler. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/28812/\"]http://secunia.com/advisories/28812/[/url]

--

[SA28805] Apple iPhoto Photocast Format String Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-06

A vulnerability has been reported in Apple iPhoto, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28805/\"]http://secunia.com/advisories/28805/[/url]

--

[SA28801] xine-lib FLAC Processing Memory Corruption Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-05

A vulnerability has been discovered in xine-lib, which can potentially be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28801/\"]http://secunia.com/advisories/28801/[/url]

--

[SA28800] Sun Solaris ImageMagick Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-05

Sun has acknowledged some vulnerabilities in ImageMagick for Sun Solaris, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28800/\"]http://secunia.com/advisories/28800/[/url]

--

[SA28779] MPlayer Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-05

Some vulnerabilities have been reported in MPlayer, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28779/\"]http://secunia.com/advisories/28779/[/url]

--

[SA28777] SUSE update for IBMJava5-JRE and IBMJava5-SDK

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-02-04

SUSE has issued an update for IBMJava5-JRE and IBMJava5-SDK. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, manipulate data, disclose sensitive information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28777/\"]http://secunia.com/advisories/28777/[/url]

--

[SA28830] Gentoo update for sdl-image

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-07

Gentoo has issued an update for sdl-image. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/28830/\"]http://secunia.com/advisories/28830/[/url]

--

[SA28819] OpenBSD DNS Server PRNG Transaction ID Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-02-07

Amit Klein has reported a vulnerability in OpenBSD, which can be exploited by malicious people to poison the DNS cache.

Full Advisory:
[url=\"http://secunia.com/advisories/28819/\"]http://secunia.com/advisories/28819/[/url]

--

[SA28816] NetBSD "ipcomp6_input()" Denial of Service

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-06

A vulnerability has been reported in NetBSD, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28816/\"]http://secunia.com/advisories/28816/[/url]

--

[SA28814] Debian update for squid

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-06

Debian has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28814/\"]http://secunia.com/advisories/28814/[/url]

--

[SA28788] KAME Project "ipcomp6_input()" Denial of Service

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-06

A vulnerability has been reported in the KAME Project, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28788/\"]http://secunia.com/advisories/28788/[/url]

--

[SA28783] rPath update for icu

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-07

rPath has issued an update for icu. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/28783/\"]http://secunia.com/advisories/28783/[/url]

--

[SA28782] Fedora update for deluge

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-04

Fedora has issued an update for deluge. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28782/\"]http://secunia.com/advisories/28782/[/url]

--

[SA28769] Debian update for python-cherrypy

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-06

Debian has issued an update for python-cherrypy. This fixes a vulnerability, which can be exploited by malicious people to bypass
certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/28769/\"]http://secunia.com/advisories/28769/[/url]

--

[SA28752] Fedora update for SDL_image

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-04

Fedora has issued an update for SDL_image. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/28752/\"]http://secunia.com/advisories/28752/[/url]

--

[SA28749] Ubuntu update for apache2

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2008-02-05

Ubuntu has issued an update for apache2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28749/\"]http://secunia.com/advisories/28749/[/url]

--

[SA28825] Debian update for net-snmp

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-07

Debian has issued an update for net-snmp. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28825/\"]http://secunia.com/advisories/28825/[/url]

--

[SA28751] Fedora update for kdebase

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-02-04

Fedora has issued an update for kdebase. This fixes a weakness, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28751/\"]http://secunia.com/advisories/28751/[/url]


[b]Other:--[/b]

[SA28750] HP-UX update for Apache

Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-02-04

HP-UX has issued an update for Apache. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, and by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28750/\"]http://secunia.com/advisories/28750/[/url]

--

[SA28762] RouterOS SNMPd "SNMP SET" Denial of Service Vulnerability

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-04

ShadOS has reported a vulnerability in RouterOS, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28762/\"]http://secunia.com/advisories/28762/[/url]


[b]Cross Platform:--[/b]

[SA28833] TinTin++ / WinTin++ Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Manipulation of data, DoS, System access
Released: 2008-02-07

Luigi Auriemma has discovered some vulnerabilities and a weakness in TinTin++ and WinTin++, which can be exploited by malicious people to cause a DoS (Denial of Service), manipulate data, or to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28833/\"]http://secunia.com/advisories/28833/[/url]

--

[SA28810] Documentum Administrator/Webtop "dmclTrace.jsp" Arbitrary File Overwrite

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-06

Pablo Gaston Milano has reported a vulnerability in Documentum Administrator and Documentum Webtop, which can be exploited by
malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28810/\"]http://secunia.com/advisories/28810/[/url]

--

[SA28795] Sun JRE Applet Handling Two Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-06

Two vulnerabilities have been reported in Sun JRE, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28795/\"]http://secunia.com/advisories/28795/[/url]

--

[SA28790] Openads Arbitrary PHP Code Execution Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-05

A vulnerability has been reported in Openads, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28790/\"]http://secunia.com/advisories/28790/[/url]

--

[SA28831] osCommerce Customer Testimonials Addon SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-07

A vulnerability has been discovered in the Customer Testimonials addon for osCommerce, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28831/\"]http://secunia.com/advisories/28831/[/url]

--

[SA28803] Mihalism Multi Host "username" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-07

Moubik has discovered a vulnerability in Mihalism Multi Host, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28803/\"]http://secunia.com/advisories/28803/[/url]

--

[SA28802] Adobe Reader Unspecified Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-02-06

Some vulnerabilities with unknown impacts have been reported in Adobe Reader.

Full Advisory:
[url=\"http://secunia.com/advisories/28802/\"]http://secunia.com/advisories/28802/[/url]

--

[SA28789] WordPress MU File Upload and Security Bypass

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-02-06

Alexander Concha has reported a vulnerability in WordPress MU, which can be exploited by malicious users to bypass certain security
restrictions and to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28789/\"]http://secunia.com/advisories/28789/[/url]

--

[SA28784] Tk GIF Processing Buffer Overflow Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-06

A vulnerability has been reported in Tk, which can potentially be exploited by malicious people to compromise an application using the
library.

Full Advisory:
[url=\"http://secunia.com/advisories/28784/\"]http://secunia.com/advisories/28784/[/url]

--

[SA28781] Deluge "bdecode_recursive()" Stack Overflow Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-04

A vulnerability has been reported in Deluge, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28781/\"]http://secunia.com/advisories/28781/[/url]

--

[SA28780] ITechBids "item_id" SQL Injection and Cross-Site Scripting

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2008-02-05

Two vulnerabilities have been discovered in ITechBids, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28780/\"]http://secunia.com/advisories/28780/[/url]

--

[SA28773] ITechClassifieds "CatID" SQL Injection and Cross-site Scripting

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-02-04

Crackers_Child has discovered two vulnerabilities in ITechClassifieds, which can be exploited by malicious people to conduct cross-site
scripting and SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28773/\"]http://secunia.com/advisories/28773/[/url]

--

[SA28771] IBM DB2 UDB Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass, Privilege escalation, DoS
Released: 2008-02-04

Multiple vulnerabilities have been reported in IBM DB2 UDB, where some have unknown impacts, while others can be exploited by malicious, local users to gain escalated privileges, and by malicious people to bypass certain security restrictions or to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28771/\"]http://secunia.com/advisories/28771/[/url]

--

[SA28767] Wordspew Plugin for Wordpress "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-04

S@BUN has reported a vulnerability in the Wordspew plugin for Wordpress, which can be exploited by malicious people to conduct SQL
injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28767/\"]http://secunia.com/advisories/28767/[/url]

--

[SA28759] WordPress DMSGuestbook Plugin Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-02-05

NBBN has discovered some vulnerabilities in the DMSGuestbook plugin for WordPress, which can be exploited by malicious users to disclose sensitive information or to manipulate data, and by malicious people to conduct cross-site scripting and script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28759/\"]http://secunia.com/advisories/28759/[/url]

--

[SA28756] BlogPHP SQL Injection and Cross-Site Scripting

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2008-02-04

Dr.Crash has discovered two vulnerabilities in BlogPHP, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28756/\"]http://secunia.com/advisories/28756/[/url]

--

[SA28813] HP Storage Essentials SRM Multiple Unspecified Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: Security Bypass, System access
Released: 2008-02-07

Some vulnerabilities have been reported in HP Storage Essentials SRM, which can be exploited by malicious people to bypass certain security restrictions or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28813/\"]http://secunia.com/advisories/28813/[/url]

--

[SA28787] Symantec Backup Exec System Recovery Manager File Upload Vulnerability

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-02-05

A vulnerability has been reported in Symantec Backup Exec System Recovery Manager, which can be exploited by malicious people to
compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28787/\"]http://secunia.com/advisories/28787/[/url]

--

[SA28827] Webmin / Usermin "search" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-07

A vulnerability has been discovered in Webmin and Usermin, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28827/\"]http://secunia.com/advisories/28827/[/url]

--

[SA28823] WordPress XML-RPC Post Edit Vulnerability

Critical: Less critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-02-07

A vulnerability has been reported in WordPress, which can be exploited by malicious users to bypass certain security restrictions and to
manipulate data.

Full Advisory:
[url=\"http://secunia.com/advisories/28823/\"]http://secunia.com/advisories/28823/[/url]

--

[SA28794] Mailman Script Insertion Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-05

A vulnerability has been reported in Mailman, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28794/\"]http://secunia.com/advisories/28794/[/url]

--

[SA28793] Textpattern Multiple Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-02-05

Some vulnerabilities have been reported in Textpattern, which can be exploited by malicious users to disclose sensitive information or
conduct script insertion attacks, and by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28793/\"]http://secunia.com/advisories/28793/[/url]

--

[SA28785] IBM WebSphere Edge Server Caching Proxy Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-07

A vulnerability has been reported in IBM WebSphere Edge Server, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28785/\"]http://secunia.com/advisories/28785/[/url]

--

[SA28778] Novell GroupWise WebAccess Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-04

Some vulnerabilities have been reported in Novell GroupWise, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28778/\"]http://secunia.com/advisories/28778/[/url]

--

[SA28775] Youtube Script "lang[please_wait]" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-04

Smasher has reported a vulnerability in Youtube Script, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28775/\"]http://secunia.com/advisories/28775/[/url]

--

[SA28774] Domain Trader "id" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-04

Crackers_Child has reported a vulnerability in Domain Trader, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28774/\"]http://secunia.com/advisories/28774/[/url]

--

[SA28772] WordPress WP-Footnotes Plugin "admin_panel.php" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-04

NBBN has discovered some vulnerabilities in the WP-Footnotes plugin for WordPress, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28772/\"]http://secunia.com/advisories/28772/[/url]

--

[SA28798] HP OpenView Network Node Manager Denial of Service

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-06

A vulnerability has been reported in HP OpenView Network Node Manager, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28798/\"]http://secunia.com/advisories/28798/[/url]

Secunia Bulletins February 2008

Posted: Thu Feb 14, 2008 5:21 pm
by Tami
[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing - Week of February 14th[/b][/i]

[b]Windows:--[/b]

[SA28909] Microsoft Office Object Parsing Memory Corruption Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-12

A vulnerability has been reported in Microsoft Office, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28909/\"]http://secunia.com/advisories/28909/[/url]

--

[SA28906] Microsoft Office Publisher File Parsing Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-12

Some vulnerabilities have been reported in Microsoft Office Publisher, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28906/\"]http://secunia.com/advisories/28906/[/url]

--

[SA28904] Microsoft Works File Converter File Parsing Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-12

Some vulnerabilities have been reported in Microsoft Office and Microsoft Works, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28904/\"]http://secunia.com/advisories/28904/[/url]

--

[SA28903] Microsoft Internet Explorer Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-12

Some vulnerabilities have been reported in Internet Explorer, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28903/\"]http://secunia.com/advisories/28903/[/url]

--

[SA28902] Microsoft Windows OLE Automation Memory Corruption

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-12

A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28902/\"]http://secunia.com/advisories/28902/[/url]

--

[SA28901] Microsoft Word File Information Block Memory Corruption

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-12

A vulnerability has been reported in Microsoft Word, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28901/\"]http://secunia.com/advisories/28901/[/url]

--

[SA28894] Microsoft WebDAV Mini-Redirector Pathname Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-12

A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28894/\"]http://secunia.com/advisories/28894/[/url]

--

[SA28893] Microsoft Internet Information Services Code Execution Vulnerability

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-12

A vulnerability has been reported in Microsoft Internet Information Services (IIS), which can be exploited by malicious people to
compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28893/\"]http://secunia.com/advisories/28893/[/url]

--

[SA28855] jetAudio ASX Parsing Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-11

Laurent Gaffie has discovered a vulnerability in jetAudio, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28855/\"]http://secunia.com/advisories/28855/[/url]

--

[SA28854] Sony ImageStation AxRUploadControl ActiveX Control "SetLogging()" Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-11

david130490 has discovered a vulnerability in Sony ImageStation AxRUploadControl Object ActiveX control, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28854/\"]http://secunia.com/advisories/28854/[/url]

--

[SA28863] SafeNet Sentinel Protection Server/Key Server Directory Traversal Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-02-12

Luigi Auriemma has discovered a vulnerability in SafeNet Sentinel Protection Server and Key Server, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/28863/\"]http://secunia.com/advisories/28863/[/url]

--

[SA28842] Husrev BlackBoard "forumid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-11

Cr@zy_King has discovered a vulnerability in Husrev BlackBoard, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28842/\"]http://secunia.com/advisories/28842/[/url]

--

[SA28905] RPM Remote Print Manager Service "Receive data file" Buffer Overflow

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-02-12

Luigi Auriemma has discovered a vulnerability in RPM Remote Print Manager, which potentially can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28905/\"]http://secunia.com/advisories/28905/[/url]

--

[SA28895] Novell Client NWSPOOL.DLL "EnumPrinters()" Buffer Overflow

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-02-12

A vulnerability has been reported in Novell Client, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28895/\"]http://secunia.com/advisories/28895/[/url]

--

[SA28890] Larson Network Print Server Format String and Buffer Overflow Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-02-12

Luigi Auriemma has discovered two vulnerabilities in Larson Network Print Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28890/\"]http://secunia.com/advisories/28890/[/url]

--

[SA28870] cyan soft Products Format String and Denial of Service Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-02-11

Luigi Auriemma has discovered some vulnerabilities in cyan soft products, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28870/\"]http://secunia.com/advisories/28870/[/url]

--

[SA28945] Adobe RoboHelp Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-13

A vulnerability has been reported in RoboHelp, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28945/\"]http://secunia.com/advisories/28945/[/url]

--

[SA28908] Beyond! Job Board "FKeywords" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-12

Ivan Sanchez and Maximiliano Soler have reported a vulnerability in Beyond! Job Board, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28908/\"]http://secunia.com/advisories/28908/[/url]

--

[SA28882] Tendenci CMS search.asp Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-13

Russ McRee has reported some vulnerabilities in Tendenci CMS, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28882/\"]http://secunia.com/advisories/28882/[/url]

--

[SA28934] Intermate WinIPDS Directory Traversal and Denial of Service Vulnerabilities

Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information, DoS
Released: 2008-02-13

Luigi Auriemma has reported some vulnerabilities in Intermate WinIPDS, which can be exploited by malicious people to disclose sensitive information or cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28934/\"]http://secunia.com/advisories/28934/[/url]

--

[SA28862] ExtremeZ-IP File and Print Server Multiple Vulnerabilities

Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information, DoS
Released: 2008-02-11

Luigi Auriemma has discovered some vulnerabilities in ExtremeZ-IP File and Print Server, which can be exploited by malicious people to disclose potentially sensitive information or cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28862/\"]http://secunia.com/advisories/28862/[/url]

--

[SA28853] Symantec Ghost Solution Suite Client Command Execution Vulnerability

Critical: Less critical
Where: From local network
Impact: System access
Released: 2008-02-08

A vulnerability has been reported in Symantec Ghost Solution Suite, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28853/\"]http://secunia.com/advisories/28853/[/url]

--

[SA28975] Fortinet FortiClient Privilege Escalation Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-14

Ruben Santamarta has reported a vulnerability in Fortinet FortiClient, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28975/\"]http://secunia.com/advisories/28975/[/url]

--

[SA28849] Microsoft Internet Information Services Privilege Escalation

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-12

A vulnerability has been reported in Microsoft Internet Information Services (IIS), which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28849/\"]http://secunia.com/advisories/28849/[/url]


[b]UNIX/Linux:--[/b]

[SA28956] Debian update for mplayer

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-13

Debian has issued an update for mplayer. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28956/\"]http://secunia.com/advisories/28956/[/url]

--

[SA28948] Gentoo update for gnumeric

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-13

Gentoo has issued an update for gnumeric. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28948/\"]http://secunia.com/advisories/28948/[/url]

--

[SA28939] Fedora update for firefox, seamonkey, and gtkmozembedmm

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-02-13

Fedora has issued an update for firefox, seamonkey, and gtkmozembedmm. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or potentially to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28939/\"]http://secunia.com/advisories/28939/[/url]

--

[SA28924] Fedora update for firefox, seamonkey, gtkmozembedmm, and
Miro

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-02-13

Fedora has issued an update for firefox, seamonkey, gtkmozembedmm, and Miro. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28924/\"]http://secunia.com/advisories/28924/[/url]

--

[SA28918] Fedora update for xine-lib

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-13

Fedora has issued an update for xine-lib. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28918/\"]http://secunia.com/advisories/28918/[/url]

--

[SA28913] Fedora update for clamav

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-13

Fedora has issued an update for clamav. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28913/\"]http://secunia.com/advisories/28913/[/url]

--

[SA28907] ClamAV Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-12

Some vulnerabilities have been reported in ClamAV, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28907/\"]http://secunia.com/advisories/28907/[/url]

--

[SA28898] Gentoo update for gallery

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, System access
Released: 2008-02-12

Gentoo has issued an update for gallery. This fixes a weakness and some vulnerabilities, where some have unspecified impacts and others can be exploited by malicious users or malicious people to disclose sensitive information, conduct cross-site scripting attacks, bypass certain security restrictions, and potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28898/\"]http://secunia.com/advisories/28898/[/url]

--

[SA28891] Apple Mac OS X Security Update Fixes Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Privilege escalation, DoS, System access
Released: 2008-02-12

Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities and weaknesses.

Full Advisory:
[url=\"http://secunia.com/advisories/28891/\"]http://secunia.com/advisories/28891/[/url]

--

[SA28888] Red Hat update for java-1.5.0-sun

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-12

Red Hat has issued an update for java-1.5.0-sun. This fixes two vulnerabilities, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28888/\"]http://secunia.com/advisories/28888/[/url]

--

[SA28879] Debian update for xulrunner

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-02-11

Debian has issued an update for xulrunner. This fixes some weaknesses and vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28879/\"]http://secunia.com/advisories/28879/[/url]

--

[SA28877] rPath update for firefox

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-02-11

rPath has issued an update for firefox. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28877/\"]http://secunia.com/advisories/28877/[/url]

--

[SA28865] Debian update for icedove

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, DoS, System access
Released: 2008-02-11

Debian has issued an update for icedove. This fixes some vulnerabilities, which can be exploited by malicious people to disclose
sensitive information, bypass certain security restrictions, or potentially to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28865/\"]http://secunia.com/advisories/28865/[/url]

--

[SA28864] Debian update for iceweasel

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-02-11

Debian has issued an update for iceweasel. This fixes some weaknesses and vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28864/\"]http://secunia.com/advisories/28864/[/url]

--

[SA28845] Mandriva update for gd

Critical: Highly critical
Where: From remote
Impact: System access, DoS
Released: 2008-02-08

Mandriva has issued an update for gd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/28845/\"]http://secunia.com/advisories/28845/[/url]

--

[SA28839] Ubuntu update for firefox

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-02-08

Ubuntu has issued an update for firefox. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious
people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's
system.

Full Advisory:
[url=\"http://secunia.com/advisories/28839/\"]http://secunia.com/advisories/28839/[/url]

--

[SA28979] FreeBSD update for ipsec

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-14

FreeBSD has issued an update for ipsec. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28979/\"]http://secunia.com/advisories/28979/[/url]

--

[SA28960] Fedora update for glib2

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-14

Fedora has released an update for glib2. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28960/\"]http://secunia.com/advisories/28960/[/url]

--

[SA28959] Graphviz GD GIF Handling Buffer Overflow Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-13

A vulnerability has been reported in Graphviz, which can potentially be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28959/\"]http://secunia.com/advisories/28959/[/url]

--

[SA28954] rPath update for tk

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-13

rPath has issued an update for tk. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/28954/\"]http://secunia.com/advisories/28954/[/url]

--

[SA28930] Debian update for nagios-plugins

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-13

Debian has issued an update for nagios-plugins. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28930/\"]http://secunia.com/advisories/28930/[/url]

--

[SA28915] Fedora update for tomcat5

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of sensitive information
Released: 2008-02-13

Fedora has issued an update for tomcat5. This fixes a security issue, which can be exploited by malicious, local users to bypass certain security restrictions, and some vulnerabilities, which can be exploited by malicious people to manipulate certain data or to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/28915/\"]http://secunia.com/advisories/28915/[/url]

--

[SA28911] ikiwiki Two Script Insertion Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-12

Two vulnerabilities have been reported in ikiwiki, which can be exploited by malicious people to conduct script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28911/\"]http://secunia.com/advisories/28911/[/url]

--

[SA28897] Gentoo update for horde-imp

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data
Released: 2008-02-12

Gentoo has issued an update for horde-imp. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions and manipulate data.

Full Advisory:
[url=\"http://secunia.com/advisories/28897/\"]http://secunia.com/advisories/28897/[/url]

--

[SA28869] rPath update for SDL_image

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-14

rPath has issued an update for SDL_image. This fixes two vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/28869/\"]http://secunia.com/advisories/28869/[/url]

--

[SA28867] Debian update for tk8.4

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-11

Debian has issued an update for tk8.4. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/28867/\"]http://secunia.com/advisories/28867/[/url]

--

[SA28866] Fedora update for graphviz

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-13

Fedora has issued an update for graphviz. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28866/\"]http://secunia.com/advisories/28866/[/url]

--

[SA28857] Debian update for tk8.3

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-11

Debian has issued an update for tk8.3. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/28857/\"]http://secunia.com/advisories/28857/[/url]

--

[SA28850] Mandriva update for SDL_image

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-08

Mandriva has issued an update for SDL_image. This fixes two vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/28850/\"]http://secunia.com/advisories/28850/[/url]

--

[SA28848] Mandriva update for tk

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-08

Mandriva has issued an update for tk. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/28848/\"]http://secunia.com/advisories/28848/[/url]

--

[SA28838] SUSE Update for Multiple Packages

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Privilege escalation, DoS, System access
Released: 2008-02-08

SUSE has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges and cause a DoS (Denial of Service), by malicious users to manipulate data, gain escalated privileges, and cause a DoS, and by malicious people to manipulate data, bypass certain security restrictions, cause a DoS, and potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28838/\"]http://secunia.com/advisories/28838/[/url]

--

[SA28837] Debian update for sdl-image1.2

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-11

Debian has issued an update for sdl-image1.2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/28837/\"]http://secunia.com/advisories/28837/[/url]

--

[SA28971] Ubuntu update for kernel

Critical: Less critical
Where: From remote
Impact: Unknown, Security Bypass, Manipulation of data, Exposure of sensitive information, DoS
Released: 2008-02-14

Ubuntu has issued an update for the kernel. This fixes a security issue and some vulnerabilities, where one has an unknown impact and others can be exploited by malicious, local users to disclose potentially sensitive information, cause a DoS (Denial of Service), bypass certain security restrictions, and corrupt a file system, and by malicious people to cause a DoS.

Full Advisory:
[url=\"http://secunia.com/advisories/28971/\"]http://secunia.com/advisories/28971/[/url]

--

[SA28965] HP-UX update for Apache

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-14

HP-UX has issued an update for Apache. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site
scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28965/\"]http://secunia.com/advisories/28965/[/url]

--

[SA28951] OpenCA Cross-Site Request Forgery Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-14

Alexander Klink has reported a vulnerability in OpenCA, which can be exploited by malicious people to conduct cross-site request forgery attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28951/\"]http://secunia.com/advisories/28951/[/url]

--

[SA28920] Fedora update for wordpress

Critical: Less critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-02-13

Fedora has issued an update for wordpress. This fixes a vulnerability, which can be exploited by malicious users to bypass certain security restrictions and to manipulate data.

Full Advisory:
[url=\"http://secunia.com/advisories/28920/\"]http://secunia.com/advisories/28920/[/url]

--

[SA28916] Fedora update for mailman

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-13

Fedora has issued an update for mailman. This fixes a vulnerability, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28916/\"]http://secunia.com/advisories/28916/[/url]

--

[SA28871] Debian update for phpbb2

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, System access
Released: 2008-02-11

Debian has issued an update for phpbb2. This fixes some vulnerabilities, which can be exploited by malicious users to
compromise a vulnerable system and by malicious people to conduct cross-site scripting and cross-site request forgery attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28871/\"]http://secunia.com/advisories/28871/[/url]

--

[SA28860] rPath update for boost

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-02-14

rPath has issued an update for boost. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28860/\"]http://secunia.com/advisories/28860/[/url]

--

[SA28953] rPath update for openldap

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-13

rPath has issued an update for openldap. This fixes some vulnerabilities, which can be exploited by malicious users to cause a
DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28953/\"]http://secunia.com/advisories/28953/[/url]

--

[SA28926] OpenLDAP modrdn Denial of Service Vulnerability

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-13

A vulnerability has been reported in OpenLDAP, which can be exploited by malicious users to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28926/\"]http://secunia.com/advisories/28926/[/url]

--

[SA28914] Fedora update for openldap

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-13

Fedora has issued an update for openldap. This fixes a vulnerability, which can be exploited by malicious users to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28914/\"]http://secunia.com/advisories/28914/[/url]

--

[SA28952] Gentoo update for pulseaudio

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-14

Gentoo has issued an update for pulseaudio. This fixes a security issue, which can be exploited by malicious, local users to perform
certain actions with escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28952/\"]http://secunia.com/advisories/28952/[/url]

--

[SA28944] Gentoo update for scponly

Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-13

Gentoo has issued an update for scponly. This fixes a security issue, which can be exploited by malicious, local users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/28944/\"]http://secunia.com/advisories/28944/[/url]

--

[SA28941] Avaya CMS Sun Solaris X Window System and X Server Vulnerabilities

Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-02-14

Avaya has acknowledged some vulnerabilities in Avaya CMS, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28941/\"]http://secunia.com/advisories/28941/[/url]

--

[SA28937] Red Hat update for kernel

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-13

Red Hat has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious, local users to gain
escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28937/\"]http://secunia.com/advisories/28937/[/url]

--

[SA28933] Ubuntu update for kernel

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-13

Ubuntu has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28933/\"]http://secunia.com/advisories/28933/[/url]

--

[SA28931] Sun Solaris 10 Language Input Methods Security Issue

Critical: Less critical
Where: Local system
Impact: Manipulation of data
Released: 2008-02-13

A security issue has been reported in Sun Solaris, which can be exploited by malicious, local users to modify certain files or
directories.

Full Advisory:
[url=\"http://secunia.com/advisories/28931/\"]http://secunia.com/advisories/28931/[/url]

--

[SA28925] rPath update for kernel

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-13

rPath has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28925/\"]http://secunia.com/advisories/28925/[/url]

--

[SA28917] Fedora update for duplicity

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-02-13

Fedora has issued an update for duplicity. This fixes a security issue, which can be exploited by malicious, local users to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/28917/\"]http://secunia.com/advisories/28917/[/url]

--

[SA28912] Fedora update for kernel-xen

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-13

Fedora has issued an update for kernel-xen. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28912/\"]http://secunia.com/advisories/28912/[/url]

--

[SA28896] Fedora update for kernel

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-02-12

Fedora has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, and gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28896/\"]http://secunia.com/advisories/28896/[/url]

--

[SA28889] SUSE update for kernel

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation
Released: 2008-02-12

SUSE has issued an update for the kernel. This fixes a security issue an a vulnerability, which can be exploited by malicious, local users to disclose potentially sensitive information or gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28889/\"]http://secunia.com/advisories/28889/[/url]

--

[SA28885] NX Server X11 Multiple Vulnerabilities

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-02-12

Some vulnerabilities have been reported in NX Server, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28885/\"]http://secunia.com/advisories/28885/[/url]

--

[SA28875] Debian update for linux-2.6

Critical: Less critical
Where: Local system
Impact: Security Bypass, Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-02-12

Debian has issued an update for linux-2.6. This fixes some vulnerabilities, which can be exploited by malicious, local users to
bypass certain security restrictions, cause a DoS (Denial of Service), disclose potentially sensitive information, and gain escalated
privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28875/\"]http://secunia.com/advisories/28875/[/url]

--

[SA28858] Mandriva update for kernel

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-12

Mandriva has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious, local users to gain
escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28858/\"]http://secunia.com/advisories/28858/[/url]

--

[SA28856] Website META Language Insecure Temporary Files

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-08

Some security issues have been reported in Website META Language, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28856/\"]http://secunia.com/advisories/28856/[/url]

--

[SA28843] OpenBSD update for X.Org

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-02-08

OpenBSD has issued an update for X.Org.This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28843/\"]http://secunia.com/advisories/28843/[/url]

--

[SA28835] Linux Kernel "vmsplice()" System Call Vulnerabilities

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-02-11

Some vulnerabilities have been reported in the Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, and gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28835/\"]http://secunia.com/advisories/28835/[/url]

--

[SA28928] FreeBSD "sendfile" Information Disclosure Security Issue

Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-02-14

A security issue has been reported in FreeBSD, which potentially can be exploited by malicious, local users to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/28928/\"]http://secunia.com/advisories/28928/[/url]

--

[SA28921] Sun Solaris USB Mouse STREAMS Module Local Denial of Service

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-02-13

A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28921/\"]http://secunia.com/advisories/28921/[/url]


[b]Other:--[/b]

[SA28935] Cisco Unified IP Phone Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-14

Some vulnerabilities have been reported in Cisco Unified IP Phone models, which can be exploited by malicious users to compromise a vulnerable device or by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable device.

Full Advisory:
[url=\"http://secunia.com/advisories/28935/\"]http://secunia.com/advisories/28935/[/url]

--

[SA28932] Cisco Unified Communications Manager "key" SQL Injection

Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-14

A vulnerability has been reported in Cisco Unified Communications Manager, which can be exploited by malicious users to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28932/\"]http://secunia.com/advisories/28932/[/url]


[b]Cross Platform:--[/b]

[SA28946] Adobe Flash Media Server Edge Server Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-13

Some vulnerabilities have been reported in Adobe Flash Media Server, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28946/\"]http://secunia.com/advisories/28946/[/url]

--

[SA28886] SAPID CMF "last_module" PHP Code Execution

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-11

GoLd_M has discovered a vulnerability in SAPID CMF, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28886/\"]http://secunia.com/advisories/28886/[/url]

--

[SA28874] Open-Realty "last_module" PHP Code Execution

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-11

Iron has discovered a vulnerability in Open-Realty, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28874/\"]http://secunia.com/advisories/28874/[/url]

--

[SA28859] PacerCMS "last_module" PHP Code Execution

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-11

GoLd_M has discovered a vulnerability in PacerCMS, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28859/\"]http://secunia.com/advisories/28859/[/url]

--

[SA28851] Adobe Reader/Acrobat 7 Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Unknown, System access
Released: 2008-02-08

Some vulnerabilities have been reported in Adobe Reader/Acrobat, some of which have unknown impacts while others can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28851/\"]http://secunia.com/advisories/28851/[/url]

--

[SA28836] PowerNews Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of
sensitive information, System access
Released: 2008-02-11

Some vulnerabilities and a weakness have been discovered in PowerNews, which can be exploited by malicious users to compromise a vulnerable system and by malicious people to conduct cross-site scripting and SQL injection attacks, disclose certain information, and compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28836/\"]http://secunia.com/advisories/28836/[/url]

--

[SA28969] JSPWiki Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-02-14

Moshe BA has discovered some vulnerabilities in JSPWiki, which can be exploited by malicious people to conduct cross-site scripting attacks or to disclose potentially sensitive information, and by malicious users to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28969/\"]http://secunia.com/advisories/28969/[/url]

--

[SA28950] AuraCMS "albums" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-13

DNX has discovered a vulnerability in AuraCMS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28950/\"]http://secunia.com/advisories/28950/[/url]

--

[SA28929] iTheora "url" Disclosure of Sensitive Information

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-02-14

A vulnerability has been reported in iTheora, which can be exploited by malicious people to disclose potentially sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/28929/\"]http://secunia.com/advisories/28929/[/url]

--

[SA28927] artmedic weblog Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-02-13

muuratsalo has discovered some vulnerabilities in artmedic weblog, which can be exploited by malicious people to conduct cross-site scripting attacks or to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/28927/\"]http://secunia.com/advisories/28927/[/url]

--

[SA28923] PCRE Character Class Buffer Overflow

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-14

A vulnerability has been reported in PCRE, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/28923/\"]http://secunia.com/advisories/28923/[/url]

--

[SA28892] Ajax Simple Chat Script Insertion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-12

Aria-Security Team has reported a vulnerability in Ajax Simple Chat, which can be exploited by malicious people to conduct script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28892/\"]http://secunia.com/advisories/28892/[/url]

--

[SA28887] ITechBids "item_id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-11

SoSo H H has reported a vulnerability in ITechBids, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28887/\"]http://secunia.com/advisories/28887/[/url]

--

[SA28883] Joomla! Rapid Recipe Component Two SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-12

breaker_unit has discovered two vulnerabilities in the Rapid Recipe component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28883/\"]http://secunia.com/advisories/28883/[/url]

--

[SA28878] Apache Tomcat Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-11

Some vulnerabilities have been reported in Apache Tomcat, which can be exploited by malicious people to manipulate certain data or to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/28878/\"]http://secunia.com/advisories/28878/[/url]

--

[SA28873] Journalness "last_module" PHP Code Execution

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-02-11

Iron has discovered a vulnerability in Journalness, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28873/\"]http://secunia.com/advisories/28873/[/url]

--

[SA28872] Cacti Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-02-12

Some vulnerabilities have been reported in Cacti, which can be exploited by malicious people to conduct HTTP response splitting,
cross-site scripting, and SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28872/\"]http://secunia.com/advisories/28872/[/url]

--

[SA28861] Joomla! XML-RPC / Blogger API Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-11

A vulnerability has been reported in Joomla!, which can be exploited by malicious people to manipulate certain data.

Full Advisory:
[url=\"http://secunia.com/advisories/28861/\"]http://secunia.com/advisories/28861/[/url]

--

[SA28847] PHParanoid Cross-Site Request Forgery and Security Bypass

Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass, Cross Site Scripting
Released: 2008-02-14

Some vulnerabilities have been reported in PHParanoid, which can be exploited by malicious people to conduct cross-site request forgery attacks and to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/28847/\"]http://secunia.com/advisories/28847/[/url]

--

[SA28846] IEA Products Management Web Server Memory Corruption Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-11

Luigi Auriemma has discovered a vulnerability in various IEA Products, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28846/\"]http://secunia.com/advisories/28846/[/url]

--

[SA28947] Adobe Connect Enterprise Server Flash Media Server Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-02-13

Some vulnerabilities have been reported in Adobe Connect Enterprise Server, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28947/\"]http://secunia.com/advisories/28947/[/url]

--

[SA28919] F-Secure Products CAB and RAR Archives Security Bypass

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-13

A vulnerability has been reported in various F-Secure products, which can be exploited by malware to bypass the scanning functionality.

Full Advisory:
[url=\"http://secunia.com/advisories/28919/\"]http://secunia.com/advisories/28919/[/url]

--

[SA28900] Simple Machines Forum SMF Shoutbox Mod Script Insertion

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-12

enterth3dragon has discovered a vulnerability in the SMF Shoutbox mod for Simple Machines Forum, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28900/\"]http://secunia.com/advisories/28900/[/url]

--

[SA28899] MercuryBoard "message" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-12

Aria-Security Team have discovered a vulnerability in MercuryBoard, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28899/\"]http://secunia.com/advisories/28899/[/url]

--

[SA28884] Apache Tomcat Cookie Handling Session ID Disclosure

Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-02-11

Two vulnerabilities have been reported in Apache Tomcat, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/28884/\"]http://secunia.com/advisories/28884/[/url]

--

[SA28881] Loris Hotel Reservation System "hotel_name" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-11

Russ McRee has reported a vulnerability in Loris Hotel Reservation System, which can be exploited by malicious people to conduct
cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28881/\"]http://secunia.com/advisories/28881/[/url]

--

[SA28876] Drupal Header Image Module Security Bypass Vulnerability

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-14

A vulnerability has been reported in the Header Image module for Drupal, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/28876/\"]http://secunia.com/advisories/28876/[/url]

--

[SA28852] Serendipity Freetag Plugin Tag Name Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-11

Alexander Brachmann has reported a vulnerability in the Freetag plugin for Serendipity, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28852/\"]http://secunia.com/advisories/28852/[/url]

--

[SA28844] HP Select Identity Multiple Unspecified Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-02-08

Some vulnerabilities have been reported in HP Select Identity, which can be exploited by malicious users to bypass certain security
restrictions or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28844/\"]http://secunia.com/advisories/28844/[/url]

--

[SA28841] Sift Unity "qt" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-08

Russ McRee has reported a vulnerability in Sift Unity, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28841/\"]http://secunia.com/advisories/28841/[/url]

--

[SA28840] MODx Cross-Site Scripting and Cross-Site Request Forgery

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-08

Alexandr Polyakov and Stas Svistunovich have discovered some vulnerabilities in MODx, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28840/\"]http://secunia.com/advisories/28840/[/url]

Secunia Bulletins February 2008

Posted: Thu Feb 21, 2008 6:12 pm
by Tami
[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of February 21 2008[/b][/i]

[b]Windows:--[/b]

[SA29035] IBM Lotus Notes Java Plug-in Sandbox Security Bypass

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-20

A vulnerability has been reported in IBM Lotus Notes, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29035/\"]http://secunia.com/advisories/29035/[/url]

--

[SA29003] Now SMS/MMS Gateway HTTP/SMPP Handling Buffer Overflows

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-20

Luigi Auriemma has discovered some vulnerabilities in Now SMS/MMS Gateway, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29003/\"]http://secunia.com/advisories/29003/[/url]

--

[SA29024] SmarterMail Subject Script Insertion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-20

Juan Pablo Lopez Yacubian has discovered a vulnerability in SmarterMail, which can be exploited by malicious people to conduct
script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29024/\"]http://secunia.com/advisories/29024/[/url]

--

[SA29021] Kerio MailServer Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-19

Some vulnerabilities have been reported in Kerio MailServer, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29021/\"]http://secunia.com/advisories/29021/[/url]

--

[SA29007] webcamXP Denial of Service and Information Disclosure

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS
Released: 2008-02-19

Luigi Auriemma has discovered a vulnerability in webcamXP, which can be exploited by malicious people to cause a DoS (Denial of Service) or to disclose potentially sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29007/\"]http://secunia.com/advisories/29007/[/url]

--

[SA29002] freeSSHd SSH Server Denial of Service Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-18

Luigi Auriemma has discovered a vulnerability in freeSSHd, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29002/\"]http://secunia.com/advisories/29002/[/url]

--

[SA29011] EMC RepliStor Data Decompression Buffer Overflows

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-02-21

Some vulnerabilities have been reported in EMC RepliStor, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29011/\"]http://secunia.com/advisories/29011/[/url]

--

[SA29031] IBM Lotus Notes Java Applet Signature Execution Control List Security Bypass

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-20

A security issue has been reported in IBM Lotus Notes, which can be exploited by malicious people to bypass certain security mechanisms.

Full Advisory:
[url=\"http://secunia.com/advisories/29031/\"]http://secunia.com/advisories/29031/[/url]

--

[SA28984] StatCounteX "admin.asp" Security Bypass

Critical: Less critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-02-18

SekoMirza has discovered a security issue in StatCounteX, which can be exploited by malicious people to bypass certain security restrictions and to disclose potentially sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/28984/\"]http://secunia.com/advisories/28984/[/url]

--

[SA29033] Symantec Veritas Storage Foundation Scheduler Service Denial of Service

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-21

A vulnerability has been reported in Symantec Veritas Storage Foundation, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29033/\"]http://secunia.com/advisories/29033/[/url]

--

[SA29030] Hitachi EUR Print Manager Unspecified Denial of Service Vulnerability

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-20

A vulnerability has been reported in Hitachi EUR Print Manager, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29030/\"]http://secunia.com/advisories/29030/[/url]

--

[SA29005] DESlock+ DLMFDISK.sys/DLMFENC.sys Privilege Escalation Vulnerabilities

Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-02-19

mu-b has reported some vulnerabilities in DESlock+, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29005/\"]http://secunia.com/advisories/29005/[/url]


[b]UNIX/Linux:--[/b]

[SA29026] Kolab Server ClamAV Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-19

Some vulnerabilities have been reported in Kolab Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29026/\"]http://secunia.com/advisories/29026/[/url]

--

[SA29012] SWORD diatheke.pl Shell Command Injection Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-19

A vulnerability has been discovered in SWORD, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29012/\"]http://secunia.com/advisories/29012/[/url]

--

[SA29001] SUSE update for clamav

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-18

SUSE has issued an update for clamav. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29001/\"]http://secunia.com/advisories/29001/[/url]

--

[SA28989] Mandriva update for xine-lib

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-18

Mandriva has issued an update for xine-lib. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28989/\"]http://secunia.com/advisories/28989/[/url]

--

[SA28983] SUSE update for acroread

Critical: Highly critical
Where: From remote
Impact: Unknown, DoS, System access
Released: 2008-02-19

SUSE has issued an update for acroread. This fixes some vulnerabilities, some of which have unknown impacts while others can be
exploited by malicious people to cause a DoS (Denial of Service) or compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/28983/\"]http://secunia.com/advisories/28983/[/url]

--

[SA29017] LightBlog "username" Local File Inclusion

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-02-19

muuratsalo has discovered a vulnerability in LightBlog, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29017/\"]http://secunia.com/advisories/29017/[/url]

--

[SA28996] Fedora update for pcre

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-19

Fedora has issued an update for pcre. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/28996/\"]http://secunia.com/advisories/28996/[/url]

--

[SA28993] HP Tru64 UNIX Perl Regular Expressions Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-21

HP has acknowledged a vulnerability in HP Tru64 UNIX, which potentially can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28993/\"]http://secunia.com/advisories/28993/[/url]

--

[SA28985] GNOME GLib PCRE Character Class Buffer Overflow

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-18

A vulnerability has been reported in GNOME GLib, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/28985/\"]http://secunia.com/advisories/28985/[/url]

--

[SA28994] CUPS "process_browse_data()" Double Free Vulnerability

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-02-20

A vulnerability has been discovered in CUPS, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/28994/\"]http://secunia.com/advisories/28994/[/url]

--

[SA29004] Lotus Quickr Unspecified Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-18

A vulnerability has been reported in Lotus Quickr, which can be exploited by malicious people to conduct cross-site scripting
attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29004/\"]http://secunia.com/advisories/29004/[/url]

--

[SA28987] Fedora update for moin

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-21

Fedora has issued an update for moin. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28987/\"]http://secunia.com/advisories/28987/[/url]

--

[SA28982] Multiple Horde Products Security Bypass

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-18

A security issue has been reported in multiple Horde products, which can be exploited by malicious users to bypass certain security
restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/28982/\"]http://secunia.com/advisories/28982/[/url]

--

[SA29028] Hitachi SEWB3/PLATFORM Unspecified Denial of Service

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-20

A vulnerability has been reported in Hitachi SEWB3/PLATFORM, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29028/\"]http://secunia.com/advisories/29028/[/url]

--

[SA29009] wyrd Insecure Temporary File

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-18

A vulnerability has been discovered in wyrd, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29009/\"]http://secunia.com/advisories/29009/[/url]

--

[SA28995] Linux Kernel Multiple Vulnerabilities

Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-02-19

Some vulnerabilities have been reported in the Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and potentially gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/28995/\"]http://secunia.com/advisories/28995/[/url]

--

[SA28981] Fedora update for scponly

Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-18

Fedora has issued an update for scponly. This fixes a security issue, which can be exploited by malicious, local users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/28981/\"]http://secunia.com/advisories/28981/[/url]

--

[SA28997] Avaya CMS Solaris X Window System Information Disclosure

Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-02-19

Avaya has acknowledged a vulnerability in Avaya CMS, which can be exploited by malicious, local users to disclose potentially sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/28997/\"]http://secunia.com/advisories/28997/[/url]

--

[SA28990] Sun Solaris vuidmice STREAMS Modules Local Denial of Service

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-02-18

A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).

Full Advisory:
[url=\"http://secunia.com/advisories/28990/\"]http://secunia.com/advisories/28990/[/url]


[b]Other:[/b]


[b]Cross Platform:--[/b]

[SA29049] Netscape Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-02-21

Netscape has acknowledged some weaknesses, a security issue, and some vulnerabilities in Netscape Navigator, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29049/\"]http://secunia.com/advisories/29049/[/url]

--

[SA29047] Globsy "globsy_edit.php" Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-21

A vulnerability has been discovered an Globsy, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29047/\"]http://secunia.com/advisories/29047/[/url]

--

[SA29042] BEA JRockit Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of system
information, Exposure of sensitive information, System access
Released: 2008-02-20

Some vulnerabilities have been reported in BEA JRockit, which can be exploited by malicious people to bypass certain security restrictions, manipulate data, disclose sensitive/system information, or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29042/\"]http://secunia.com/advisories/29042/[/url]

--

[SA29010] MoinMoin Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2008-02-20

Some vulnerabilities have been reported in MoinMoin, which can be exploited by malicious people to conduct cross-site scripting attacks, to manipulate certain data, or potentially to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29010/\"]http://secunia.com/advisories/29010/[/url]

--

[SA29044] Joomla hwdVideoShare Component "cat_id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-21

S@BUN has discovered a vulnerability in the hwdVideoShare component for Joomla, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29044/\"]http://secunia.com/advisories/29044/[/url]

--

[SA29041] BEA WebLogic Products Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Hijacking, Security Bypass, Cross Site Scripting, Brute force, Exposure of system information, Exposure of sensitive
information
Released: 2008-02-20

Some vulnerabilities, security issues, and a weakness have been reported in various BEA WebLogic products, which can be exploited by malicious users to conduct script insertion attacks, and by malicious people to conduct session fixation, cross-site scripting, or brute force attacks, disclose sensitive information, or to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29041/\"]http://secunia.com/advisories/29041/[/url]

--

[SA29034] Schoolwires Academic Portal browse.asp Cross-Site Scripting and SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-02-20

Russ McRee has reported two vulnerabilities in Schoolwires Academic Portal, which can be exploited by malicious people to conduct
cross-site scripting or SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29034/\"]http://secunia.com/advisories/29034/[/url]

--

[SA29029] Opera Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information
Released: 2008-02-20

Some vulnerabilities have been reported in Opera, which can be exploited by malicious people to conduct cross-site scripting attacks, disclose sensitive information, or to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29029/\"]http://secunia.com/advisories/29029/[/url]

--

[SA29022] IBM DB2 Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Unknown, DoS
Released: 2008-02-19

Some vulnerabilities have been reported in IBM DB2, some of which have unknown impacts, while one can potentially be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29022/\"]http://secunia.com/advisories/29022/[/url]

--

[SA29018] iScripts MultiCart "productid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-21

t0pP8uZz and xprog have reported a vulnerability in iScripts MultiCart, which can be exploited by malicious users to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29018/\"]http://secunia.com/advisories/29018/[/url]

--

[SA29008] Joomla astatsPRO Component "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Cross Site Scripting
Released: 2008-02-21

A vulnerability has been reported in the astatsPRO component for Joomla, which can be exploited by malicious people to conduct
cross-site scripting and SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29008/\"]http://secunia.com/advisories/29008/[/url]

--

[SA29006] XPWeb "Download.php" Arbitrary File Download

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-02-18

GoLd_M has discovered a vulnerability in XPWeb, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29006/\"]http://secunia.com/advisories/29006/[/url]

--

[SA28998] Joomla! jooget Component "id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-18

S@BUN has discovered a vulnerability in the jooget component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28998/\"]http://secunia.com/advisories/28998/[/url]

--

[SA28992] BanPro-DMS "action" Local File Inclusion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-02-18

muuratsalo has discovered a vulnerability in BanPro-DMS, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/28992/\"]http://secunia.com/advisories/28992/[/url]

--

[SA28991] BEA Products Information Disclosure Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-02-20

A vulnerability has been reported in some BEA Plumtree Collaboration and BEA AquaLogic Interaction, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/28991/\"]http://secunia.com/advisories/28991/[/url]

--

[SA28988] WordPress WP Photo Album Plugin "photo" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-20

A vulnerability has been reported in the WP Photo Album (WPPA) plugin for WordPress, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28988/\"]http://secunia.com/advisories/28988/[/url]

--

[SA28986] Joomla! Quran Component "surano" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-18

breaker_unit and Don have discovered a vulnerability in the Quran component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28986/\"]http://secunia.com/advisories/28986/[/url]

--

[SA28980] Joomla! Quiz Component "tid" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-15

S@BUN has discovered a vulnerability in the Quiz component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/28980/\"]http://secunia.com/advisories/28980/[/url]

--

[SA29050] Symantec Veritas Storage Foundation Administrator Service Buffer Overflow

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-02-21

A vulnerability has been reported in Symantec Veritas Storage Foundation, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29050/\"]http://secunia.com/advisories/29050/[/url]

--

[SA29045] Sybase SQL Anywhere MobiLink Buffer Overflow Vulnerability

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-02-21

Luigi Auriemma has discovered a vulnerability in Sybase MobiLink, which can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29045/\"]http://secunia.com/advisories/29045/[/url]

--

[SA29055] Invision Power Board BBCodes Script Insertion Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-21

A vulnerability has been reported in Invision Power Board, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29055/\"]http://secunia.com/advisories/29055/[/url]

--

[SA29043] PunBB Password Change and Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Brute force
Released: 2008-02-21

A vulnerability and a weakness have been discovered in PunBB, which can be exploited by malicious users to manipulate data and by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29043/\"]http://secunia.com/advisories/29043/[/url]

--

[SA29040] BEA Products "name" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-20

Jan Fry and Adrian Pastor have reported a vulnerability in BEA AquaLogic Interaction and BEA Plumtree Foundation, which can be
exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29040/\"]http://secunia.com/advisories/29040/[/url]

--

[SA29039] Tor World CGI Scripts Multiple Unspecified Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-21

Some vulnerabilities have been reported in various Tor World CGI Scripts, which can be exploited by malicious people to conduct
cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29039/\"]http://secunia.com/advisories/29039/[/url]

--

[SA29023] Jinzora Multiple Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-20

Alexandr Polyakov and Stas Svistunovich have discovered some vulnerabilities in Jinzora, which can be exploited by malicious people to conduct cross-site scripting and script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29023/\"]http://secunia.com/advisories/29023/[/url]

--

[SA29020] WoltLab Burning Board "sortOrder" SQL Injection

Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-20

NBBN has reported a vulnerability in WoltLab Burning Board, which can be exploited by malicious users to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29020/\"]http://secunia.com/advisories/29020/[/url]

--

[SA29019] Lyris ListManager Security Bypass Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-20

Tyler Shields has reported some vulnerabilities in Lyris ListManager, which can be exploited by malicious users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29019/\"]http://secunia.com/advisories/29019/[/url]

--

[SA29016] ProjectPier Multiple Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-19

L4teral has reported some vulnerabilities in ProjectPier, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks, and by malicious users to conduct script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29016/\"]http://secunia.com/advisories/29016/[/url]

--

[SA29015] ATutor Script Insertion Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-19

L4teral has discovered some vulnerabilities in ATutor, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29015/\"]http://secunia.com/advisories/29015/[/url]

Secunia Bulletins February 2008

Posted: Fri Feb 29, 2008 6:33 am
by Tami
[url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing For February 28 2008

[b]
Windows:--[/b]

[SA29146] 4XEM VatDecoder VatCtrl Class ActiveX Control "Url" Property Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-27

rgod has discovered a vulnerability in 4XEM VatDecoder, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29146/\"]http://secunia.com/advisories/29146/[/url]

--

[SA29145] RTSP MPEG4 SP Control ActiveX Control "Url" Property Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-27

rgod has discovered a vulnerability in RTSP MPEG4 SP Control, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29145/\"]http://secunia.com/advisories/29145/[/url]

--

[SA29138] ICQ Message Processing Format String Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-28

B0B has discovered a vulnerability in ICQ, which can be exploited by malicious people to compromise another user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29138/\"]http://secunia.com/advisories/29138/[/url]

--

[SA29131] D-Link MPEG4 SHM (Audio) Control ActiveX Control "Url" Property Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-27

rgod has discovered a vulnerability in D-Link MPEG4 SHM (Audio) Control, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29131/\"]http://secunia.com/advisories/29131/[/url]

--

[SA29109] Rising Online Virus Scanner Web Scan ActiveX Control "UpdateEngine()" Insecure Method

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-26

John Smith has discovered a vulnerability in Rising Online Virus Scanner, which can be exploited by malicious people to compromise a
user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29109/\"]http://secunia.com/advisories/29109/[/url]

--

[SA29108] Move Media Player Quantum Streaming IE Player "UploadLogs()" Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-26

Elazar Broad has discovered a vulnerability in Move Media Player, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29108/\"]http://secunia.com/advisories/29108/[/url]

--

[SA29137] NetWin WebMail Format String Vulnerability

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-02-27

Luigi Auriemma has reported a vulnerability in NetWin WebMail, which potentially can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29137/\"]http://secunia.com/advisories/29137/[/url]

--

[SA29105] SurgeMail Format String and Buffer Overflow Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-26

Luigi Auriemma has discovered some vulnerabilities in SurgeMail, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29105/\"]http://secunia.com/advisories/29105/[/url]

--

[SA29102] Porar Webboard question.asp SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-26

xcorpitx has reported a vulnerability in Porar Webboard, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29102/\"]http://secunia.com/advisories/29102/[/url]

--

[SA29096] SurgeFTP "Content-Length" Denial of Service Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-26

Luigi Auriemma has discovered a vulnerability in SurgeFTP, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29096/\"]http://secunia.com/advisories/29096/[/url]

--

[SA29124] Trend Micro OfficeScan CGI Module and Policy Server Buffer Overflows

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-02-28

Luigi Auriemma has discovered some vulnerabilities in Trend Micro OfficeScan, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29124/\"]http://secunia.com/advisories/29124/[/url]

--

[SA29062] Zilab Chat and Instant Messaging Server Multiple Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-02-22

Luigi Auriemma has discovered some vulnerabilities in Zilab Chat and Instant Messaging (ZIM) Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29062/\"]http://secunia.com/advisories/29062/[/url]

--

[SA29142] AuthentiX Multiple Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-28

William Hicks and Chris Castaldo have discovered some vulnerabilities in AuthentiX, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29142/\"]http://secunia.com/advisories/29142/[/url]

--

[SA29151] Trend Micro OfficeScan 8.0 Policy Server Denial of Service

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-28

Luigi Auriemma has discovered a vulnerability in Trend Micro OfficeScan, which can be exploited by malicious people to cause a DoS
(Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29151/\"]http://secunia.com/advisories/29151/[/url]

--

[SA29075] Double-Take for Windows Information Disclosure and Denial of Service

Critical: Less critical
Where: From local network
Impact: Exposure of system information, DoS
Released: 2008-02-25

Luigi Auriemma has reported some vulnerabilities in Double-Take for Windows, which can be exploited by malicious people to disclose system information and cause a DoS (Denial of Service)

Full Advisory:
[url=\"http://secunia.com/advisories/29075/\"]http://secunia.com/advisories/29075/[/url]

--

[SA29117] VMware Products Shared Folders Directory Traversal Vulnerability

Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-26

Gerardo Richarte has reported a vulnerability in VMware products, which can be exploited by malicious, local users or malicious applications to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29117/\"]http://secunia.com/advisories/29117/[/url]


[b]UNIX/Linux:--[/b]

[SA29141] Gentoo update for xine-lib

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-27

Gentoo has issued an update in xine-lib. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29141/\"]http://secunia.com/advisories/29141/[/url]

--

[SA29135] Debian update for ghostscript

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-28

Debian has issued an update for ghostscript. This fixes a vulnerability, which can be exploited by malicious people to compromise
a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29135/\"]http://secunia.com/advisories/29135/[/url]

--

[SA29115] Fedora update for sword

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-26

Fedora has issued an update for sword. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29115/\"]http://secunia.com/advisories/29115/[/url]

--

[SA29112] Red Hat update for ghostscript

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-28

Red Hat has issued an update for ghostscript. This fixes a vulnerability, which can be exploited by malicious people to compromise
a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29112/\"]http://secunia.com/advisories/29112/[/url]

--

[SA29104] Debian update for koffice

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-26

Debian has issued an update for koffice. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29104/\"]http://secunia.com/advisories/29104/[/url]

--

[SA29094] GraphicsMagick Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-25

Some vulnerabilities have been reported in GraphicsMagick, which can be exploited by malicious people to conduct DoS (Denial of Service) attacks or compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29094/\"]http://secunia.com/advisories/29094/[/url]

--

[SA29086] Debian update for iceape

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-02-25

Debian has issued an update for iceape. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29086/\"]http://secunia.com/advisories/29086/[/url]

--

[SA29065] Red Hat update for acroread

Critical: Highly critical
Where: From remote
Impact: Unknown, Hijacking, DoS, System access
Released: 2008-02-25

Red Hat has issued an update for acroread. This fixes some vulnerabilities, some of which have unknown impacts, while others can
be exploited by malicious people to conduct cross-site request forgery attacks, cause a DoS (Denial of Service), or compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29065/\"]http://secunia.com/advisories/29065/[/url]

--

[SA29060] Gentoo udpate for clamav

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-22

Gentoo has issued an update for clamav. This fixes some vulnerabilities, which can be exploited to cause a DoS (Denial of
Service) or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29060/\"]http://secunia.com/advisories/29060/[/url]

--

[SA29161] IBM AIX libc "inet_network()" Off-By-One Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-28

IBM has acknowledged a vulnerability in AIX, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29161/\"]http://secunia.com/advisories/29161/[/url]

--

[SA29157] Red Hat update for gd

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-28

Red Hat has issued an update for gd. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29157/\"]http://secunia.com/advisories/29157/[/url]

--

[SA29130] Apple Mac OS X "ipcomp6_input()" Denial of Service

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-27

A vulnerability has been reported in Apple Mac OS X, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29130/\"]http://secunia.com/advisories/29130/[/url]

--

[SA29100] Sun Solaris Firewall Security Bypass and Denial of Service

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS
Released: 2008-02-25

Sun has acknowledged a vulnerability in Solaris, which can be exploited by malicious people to bypass certain security restrictions and cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29100/\"]http://secunia.com/advisories/29100/[/url]

--

[SA29085] Gentoo update for python

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-25

Gentoo has issued an update for python. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29085/\"]http://secunia.com/advisories/29085/[/url]

--

[SA29079] Red Hat update for netpbm

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-28

Red Hat has issued an update for netpbm. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29079/\"]http://secunia.com/advisories/29079/[/url]

--

[SA29078] OpenBSD Two Denial of Service Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-25

Two vulnerabilities have been reported in OpenBSD, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29078/\"]http://secunia.com/advisories/29078/[/url]

--

[SA29074] Solaris 10 Perl Regular Expressions Unicode Data Buffer Overflow

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-22

Sun has acknowledged a vulnerability in Solaris, which potentially can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29074/\"]http://secunia.com/advisories/29074/[/url]

--

[SA29070] Red Hat update for tcltk

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-22

Red Hat has issued an update for tcltk. This fixes some vulnerabilities, which can be exploited by malicious users to cause a
DoS (Denial of Service) and potentially by malicious people to compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/29070/\"]http://secunia.com/advisories/29070/[/url]

--

[SA29069] Red Hat update for tk

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-22

Red Hat has issued an update for tk. This fixes some vulnerabilities, which can be exploited by malicious people to compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/29069/\"]http://secunia.com/advisories/29069/[/url]

--

[SA29066] lighttpd File Descriptor Array Denial of Service Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-22

A vulnerability has been reported in lighttpd, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29066/\"]http://secunia.com/advisories/29066/[/url]

--

[SA29120] Fedora update for cups

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-02-26

Fedora has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29120/\"]http://secunia.com/advisories/29120/[/url]

--

[SA29127] DNSSEC-Tools libval Validation Algorithm Security Issue

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-26

A security issue has been reported in DNSSEC-Tools, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29127/\"]http://secunia.com/advisories/29127/[/url]

--

[SA29114] Maian Cart "keywords" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-28

Russ McRee has discovered a vulnerability in Maian Cart, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29114/\"]http://secunia.com/advisories/29114/[/url]

--

[SA29095] Fedora update for dnssec-tools

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-26

Fedora has issued an update for dnssec-tools. This fixes a security issue, which can be exploited by malicious people to bypass certain
security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29095/\"]http://secunia.com/advisories/29095/[/url]

--

[SA29083] Mandriva update for nss_ldap

Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-25

Mandriva has issued an update for nss_ldap. This fixes a security issue, which can be exploited by malicious people to manipulate certain data.

Full Advisory:
[url=\"http://secunia.com/advisories/29083/\"]http://secunia.com/advisories/29083/[/url]

--

[SA29071] Debian update for turba2

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-25

Debian has issued an update for turba2. This fixes a security issue, which can be exploited by malicious users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29071/\"]http://secunia.com/advisories/29071/[/url]

--

[SA29058] Debian update for kernel

Critical: Less critical
Where: From remote
Impact: Unknown, Security Bypass, Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-02-25

Debian has issued an update for kernel-2.4.27 and kernel-2.6.8. This fixes some weaknesses, security issues, and vulnerabilities, where one has an unknown impact, and others can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, bypass certain security restrictions, and gain escalated privileges, and by malicious people to cause a DoS.

Full Advisory:
[url=\"http://secunia.com/advisories/29058/\"]http://secunia.com/advisories/29058/[/url]

--

[SA29132] Mandriva update for cups

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-28

Mandriva has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29132/\"]http://secunia.com/advisories/29132/[/url]

--

[SA29087] Red Hat update for cups

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-25

Red Hat has issued an update for cups. This fixes two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29087/\"]http://secunia.com/advisories/29087/[/url]

--

[SA29068] Red Hat update for openldap

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-22

Red Hat has issued an update for openldap. This fixes some vulnerabilities, which can be exploited by malicious users to cause a
DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29068/\"]http://secunia.com/advisories/29068/[/url]

--

[SA29067] Red Hat update for cups

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-22

Red Hat has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29067/\"]http://secunia.com/advisories/29067/[/url]

--

[SA29160] Red Hat update for dbus

Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-28

Red Hat has issued an update for dbus. This fixes a security issue, which can be exploited by malicious, local users to bypass certain
security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29160/\"]http://secunia.com/advisories/29160/[/url]

--

[SA29148] D-Bus "send_interface" Security Policy Bypass

Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-28

A security issue has been reported in D-Bus, which can be exploited by malicious, local users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29148/\"]http://secunia.com/advisories/29148/[/url]

--

[SA29139] IBM AIX X Server Multiple Vulnerabilities

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation
Released: 2008-02-28

IBM has acknowledged some vulnerabilities in AIX, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29139/\"]http://secunia.com/advisories/29139/[/url]

--

[SA29113] Fedora update for wyrd

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-26

Fedora has issued an update for wyrd. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29113/\"]http://secunia.com/advisories/29113/[/url]

--

[SA29111] Symark PowerBroker Client Binaries Buffer Overflow Vulnerabilities

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-27

Michael Ligh and Greg Sinclair have reported some vulnerabilities in Symark PowerBroker, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29111/\"]http://secunia.com/advisories/29111/[/url]

--

[SA29080] SplitVT "xprop" Privilege Escalation Security Issue

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-22

A security issue has been reported in SplitVT, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29080/\"]http://secunia.com/advisories/29080/[/url]

--

[SA29064] Debian update for splitvt

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-22

Debian has issued an update for splitvt. This fixes a security issue, which can be exploited by malicious, local users to gain escalated
privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29064/\"]http://secunia.com/advisories/29064/[/url]

--

[SA29059] Debian update for dspam

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-02-22

Debian has issued an update for dspam. This fixes a security issue, which can be exploited by malicious, local users to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29059/\"]http://secunia.com/advisories/29059/[/url]

--

[SA29136] Fedora update for kvm

Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-26

Fedora has issued an update for kvm. This fixes a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29136/\"]http://secunia.com/advisories/29136/[/url]

--

[SA29129] KVM Block Device Backend Security Bypass

Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-26

A vulnerability has been reported in KVM, which can be exploited by malicious, local users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29129/\"]http://secunia.com/advisories/29129/[/url]

--

[SA29097] Net Activity Viewer Privilege Escalation Security Issue

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-25

A security issue has been reported in Net Activity Viewer, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29097/\"]http://secunia.com/advisories/29097/[/url]

--

[SA29081] Fedora update for qemu

Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-26

Fedora has issued an update for qemu. This fixes a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29081/\"]http://secunia.com/advisories/29081/[/url]


[b]Other:--[/b]

[SA29082] Cisco IP Phone 7921 Insecure PEAP Implementation

Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2008-02-27

A security issue has been reported in Cisco IP Phone 7921, which potentially can be exploited by malicious people to disclose sensitive
information.

Full Advisory:
[url=\"http://secunia.com/advisories/29082/\"]http://secunia.com/advisories/29082/[/url]


[b]Cross Platform:--[/b]

[SA29153] Miro MP4 Demuxer Arbitrary Memory Overwrite

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-28

A vulnerability has been reported in Miro, which can potentially be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29153/\"]http://secunia.com/advisories/29153/[/url]

--

[SA29140] Symantec Products Symantec Decomposer RAR File Handling Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-27

Two vulnerabilities have been reported in various Symantec products, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29140/\"]http://secunia.com/advisories/29140/[/url]

--

[SA29133] Mozilla Thunderbird MIME Processing Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-27

A vulnerability has been reported in Mozilla Thunderbird, which can be exploited by malicious people to potentially compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29133/\"]http://secunia.com/advisories/29133/[/url]

--

[SA29122] VLC Media Player MP4 Demuxer Arbitrary Memory Overwrite

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-27

A vulnerability has been reported in VLC Media Player, which can potentially be exploited by malicious people to compromise a user's
system.

Full Advisory:
[url=\"http://secunia.com/advisories/29122/\"]http://secunia.com/advisories/29122/[/url]

--

[SA29110] DBHcms "extmanager_install" File Inclusion Vulnerability

Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-02-26

Iron has discovered a vulnerability in DBHcms, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29110/\"]http://secunia.com/advisories/29110/[/url]

--

[SA29103] Ghostscript "zseticcspace()" Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-28

Chris Evans has reported a vulnerability in Ghostscript, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29103/\"]http://secunia.com/advisories/29103/[/url]

--

[SA29099] WordPress Sniplets Plugin Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-02-27

NBBN has discovered some vulnerabilities in the Sniplets plugin for WordPress, which can be exploited by malicious people to conduct
cross-site scripting attacks, disclose sensitive information, or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29099/\"]http://secunia.com/advisories/29099/[/url]

--

[SA29089] php Download Manager "content" File Inclusion Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-25

BeyazKurt has discovered a vulnerability in php Download Manager, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29089/\"]http://secunia.com/advisories/29089/[/url]

--

[SA29088] Interstage Application Server Single Sign-On Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-25

A vulnerability has been reported in Interstage Application Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29088/\"]http://secunia.com/advisories/29088/[/url]

--

[SA29077] Quantum Star "CONFIG[gameroot]" File Inclusion Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-02-25

RoMaNcYxHaCkEr has discovered two vulnerabilities in Quantum Star: Generations, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29077/\"]http://secunia.com/advisories/29077/[/url]

--

[SA29076] phpQLAdmin "_SESSION[path]" File Inclusion Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-02-25

RoMaNcYxHaCkEr has reported two vulnerabilities in phpQLAdmin, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29076/\"]http://secunia.com/advisories/29076/[/url]

--

[SA29156] Wireshark Multiple Denial of Service Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-28

Some vulnerabilities have been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29156/\"]http://secunia.com/advisories/29156/[/url]

--

[SA29123] eazyPortal "session_vars" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-28

Iron has discovered a vulnerability in eazyPortal, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29123/\"]http://secunia.com/advisories/29123/[/url]

--

[SA29107] Xoops XM-Memberstats Module "letter" and "sortby" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-25

Two vulnerabilities have been discovered in the XM-Memberstats module for Xoops, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29107/\"]http://secunia.com/advisories/29107/[/url]

--

[SA29106] Joomla! "mosConfig_absolute_path" File Inclusion

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-02-25

Hendrik-Jan Verheij has discovered a vulnerability in Joomla!, which can be exploited by malicious people to compromise a vulnerable
system.

Full Advisory:
[url=\"http://secunia.com/advisories/29106/\"]http://secunia.com/advisories/29106/[/url]

--

[SA29090] Joomla! Gary's Cookbook Component "id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-25

S@BUN has discovered a vulnerability in the Gary's Cookbook component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29090/\"]http://secunia.com/advisories/29090/[/url]

--

[SA29084] H-Sphere SiteStudio Unspecified Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-02-26

A vulnerability with unknown impact has been reported in H-Sphere SiteStudio.

Full Advisory:
[url=\"http://secunia.com/advisories/29084/\"]http://secunia.com/advisories/29084/[/url]

--

[SA29073] XOOPS Tiny Event Module "id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-22

S@BUN has discovered a vulnerability in the Tiny Event module for XOOPS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29073/\"]http://secunia.com/advisories/29073/[/url]

--

[SA29063] XOOPS Prayer List Module "cid" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-22

S@BUN has discovered a vulnerability in the Prayer List module for XOOPS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29063/\"]http://secunia.com/advisories/29063/[/url]

--

[SA29061] beContent "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-22

Cr@zy_King has reported a vulnerability in beContent, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29061/\"]http://secunia.com/advisories/29061/[/url]

--

[SA29150] Interspire Shopping Cart "search_query" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-28

Russ McRee has reported a vulnerability in Interspire Shopping Cart, which can be exploited by malicious people to conduct cross-site
scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29150/\"]http://secunia.com/advisories/29150/[/url]

--

[SA29128] Serendipity Script Insertion and Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-27

Hanno Boeck has discovered two vulnerabilities in Serendipity, which can be exploited by malicious users to conduct cross-site scripting and script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29128/\"]http://secunia.com/advisories/29128/[/url]

--

[SA29118] Drupal Multiple Script Insertion Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-28

Some vulnerabilities have been reported in Drupal, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29118/\"]http://secunia.com/advisories/29118/[/url]

--

[SA29116] Plume CMS "dir" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-26

Omer Singer has discovered a vulnerability in Plume CMS, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29116/\"]http://secunia.com/advisories/29116/[/url]

--

[SA29093] Matt's Whois "domain" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-25

Ivan Sanchez and Maximiliano Soler have reported a vulnerability in Matt's Whois, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29093/\"]http://secunia.com/advisories/29093/[/url]

--

[SA29092] TikiWiki "tiki-edit_article.php" Script Insertion Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-25

A vulnerability has been reported in TikiWiki, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29092/\"]http://secunia.com/advisories/29092/[/url]

--

[SA29072] IBM Lotus Quickr/QuickPlace Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-25

Nir Goldshlager (Avnet) has reported a vulnerability in IBM Lotus Quickr/QuickPlace, which can be exploited by malicious people to
conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29072/\"]http://secunia.com/advisories/29072/[/url]