Page 1 of 1
Secunia Bulletins February 2008
Posted: Fri Feb 01, 2008 6:06 pm
by Tami
[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing For The Week of February 1 2008[/b][/i]
[b]Windows:--[/b]
[SA28733] Aurigma Image Uploader ActiveX Control "Action" Property Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-01
Elazar Broad has discovered a vulnerability in Aurigma Image Uploader, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28733/\"]http://secunia.com/advisories/28733/[/url]
--
[SA28724] SwiftView Viewer ActiveX Control/Plug-in Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-31
Will Dormann has reported some vulnerabilities in SwiftView Viewer, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28724/\"]http://secunia.com/advisories/28724/[/url]
--
[SA28715] MySpace Uploader Control ActiveX Control "Action" Property Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-31
Elazar Broad has discovered a vulnerability in MySpace Uploader Control, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28715/\"]http://secunia.com/advisories/28715/[/url]
--
[SA28710] GFL SDK Radiance RGBE Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-30
Secunia Research has discovered a vulnerability in GFL SDK, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28710/\"]http://secunia.com/advisories/28710/[/url]
--
[SA28688] IrfanView FlashPix Plug-in Memory Corruption Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-29
Marsu has discovered a vulnerability in the FlashPix plug-in for IrfanView, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28688/\"]http://secunia.com/advisories/28688/[/url]
--
[SA28660] Persits Software XUpload "AddFile()" Method Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-29
Some vulnerabilities have been discovered in Persits Software XUpload, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28660/\"]http://secunia.com/advisories/28660/[/url]
--
[SA28649] NamoInstaller ActiveX Control NamoInstall Class "Install()" Insecure Method
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-28
plan-s has discovered a vulnerability in NamoInstaller ActiveX Control, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28649/\"]http://secunia.com/advisories/28649/[/url]
--
[SA28647] Move Networks Upgrade Manager Upgrade Class ActiveX Control Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-25
Elazar Broad has discovered a vulnerability in Move Networks Upgrade Manager, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28647/\"]http://secunia.com/advisories/28647/[/url]
--
[SA28662] CandyPress Store SQL Injection and Cross-Site Scripting
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2008-01-28
Some vulnerabilities have been reported in CandyPress Store, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28662/\"]http://secunia.com/advisories/28662/[/url]
--
[SA28653] ASPired2Protect login.asp SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-29
Aria-Security Team has reported some vulnerabilities in ASPired2Protect, which can be exploited by malicious people to conduct
SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28653/\"]http://secunia.com/advisories/28653/[/url]
--
[SA28651] Pre Dynamic Institution Multiple SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-01-28
Aria-Security Team have reported some vulnerabilities in Pre Dynamic Institution, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28651/\"]http://secunia.com/advisories/28651/[/url]
--
[SA28689] IBM Informix Storage Manager XDR Library Multiple Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-01-29
IBM has acknowledged some vulnerabilities in Informix Storage Manager, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28689/\"]http://secunia.com/advisories/28689/[/url]
--
[SA28663] Proficy HMI/SCADA - CIMPLICITY w32rtr.exe Packet Processing Buffer Overflow
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-01-28
Eyal Udassin has reported a vulnerability in Proficy HMI/SCADA - CIMPLICITY, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28663/\"]http://secunia.com/advisories/28663/[/url]
--
[SA28735] Uniwin eCart Professional "rp" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-01
sascha has reported a vulnerability in Uniwin eCart Professional, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28735/\"]http://secunia.com/advisories/28735/[/url]
--
[SA28695] BitTorrent Web UI HTTP Request "Range" Header Processing Denial of Service
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-01-29
Luigi Auriemma has discovered a vulnerability in BitTorrent, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28695/\"]http://secunia.com/advisories/28695/[/url]
--
[SA28686] uTorrent Web UI HTTP Request "Range" Header Processing Denial of Service
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-01-29
Luigi Auriemma has discovered a vulnerability in uTorrent, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28686/\"]http://secunia.com/advisories/28686/[/url]
--
[SA28675] SoftCart Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-30
Russ McRee has reported some vulnerabilities in SoftCart, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28675/\"]http://secunia.com/advisories/28675/[/url]
--
[SA28678] Proficy Real-Time Information Portal "Add WebSource" File Upload Vulnerability
Critical: Less critical
Where: From local network
Impact: System access
Released: 2008-01-28
Eyal Udassin has reported a vulnerability in Proficy Real-Time Information Portal, which can be exploited by malicious users to
compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28678/\"]http://secunia.com/advisories/28678/[/url]
[b]UNIX/Linux:--[/b]
[SA28725] Gnumeric XLS HLINK Opcode Processing Code Execution
Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-31
A vulnerability has been reported in Gnumeric, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28725/\"]http://secunia.com/advisories/28725/[/url]
--
[SA28719] Gentoo update for peercast
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-31
Gentoo has issued an update for peercast. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28719/\"]http://secunia.com/advisories/28719/[/url]
--
[SA28671] Debian update for yarssr
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-28
Debian has issued an update for yarssr. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28671/\"]http://secunia.com/advisories/28671/[/url]
--
[SA28720] Gentoo update for kazehakase
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-01-31
Gentoo has issued an update for kazehakase. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose potentially sensitive information, and compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28720/\"]http://secunia.com/advisories/28720/[/url]
--
[SA28716] Gentoo update for libxml2
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-31
Gentoo has issued an update for libxml2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28716/\"]http://secunia.com/advisories/28716/[/url]
--
[SA28714] Gentoo update for goffice
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-01-31
Gentoo has issued an update for goffice. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service), disclose potentially sensitive information, and compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28714/\"]http://secunia.com/advisories/28714/[/url]
--
[SA28674] Gentoo update for xine-lib
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-28
Gentoo has issued an update for xine-lib. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28674/\"]http://secunia.com/advisories/28674/[/url]
--
[SA28673] Gentoo update for ngircd
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-28
Gentoo has issued an update for ngircd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28673/\"]http://secunia.com/advisories/28673/[/url]
--
[SA28669] Fedora update for icu
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-28
Fedora has issued an update for icu. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28669/\"]http://secunia.com/advisories/28669/[/url]
--
[SA28666] Fedora update for xine-lib
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-29
Fedora has issued an update for xine-lib. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28666/\"]http://secunia.com/advisories/28666/[/url]
--
[SA28658] SUSE update for php4 and php5
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Privilege escalation, DoS, System access
Released: 2008-01-29
SUSE has issued an update for php4 and php5. This fixes some vulnerabilities, where some have unknown impacts and others can be exploited by malicious, local users to gain escalated privileges, malicious users to bypass certain security restrictions, and by malicious people to cause a DoS (Denial of Service) and potentially execute arbitrary code.
Full Advisory:
[url=\"http://secunia.com/advisories/28658/\"]http://secunia.com/advisories/28658/[/url]
--
[SA28650] Gentoo update for maradns
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-30
Gentoo has issued an update for maradns. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28650/\"]http://secunia.com/advisories/28650/[/url]
--
[SA28728] Gentoo update for xdg-utils
Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-01-31
Gentoo has issued an update for xdg-utils. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28728/\"]http://secunia.com/advisories/28728/[/url]
--
[SA28726] OpenBSD bgplg "cmd" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-31
Alexandr Polyakov and Anton Karpov have reported a vulnerability in OpenBSD bgplg, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28726/\"]http://secunia.com/advisories/28726/[/url]
--
[SA28697] Gentoo update for netkit-ftpd
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-01-30
Gentoo has acknowledged a vulnerability in netkit-ftpd, which can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28697/\"]http://secunia.com/advisories/28697/[/url]
--
[SA28661] AmpJuke "limit" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-30
ShaF**k31 has reported a vulnerability in AmpJuke, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28661/\"]http://secunia.com/advisories/28661/[/url]
--
[SA28648] Avaya Products e2fsprogs Integer Overflow Vulnerabilities
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-25
Avaya has acknowledged some vulnerabilities in multiple Avaya products, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28648/\"]http://secunia.com/advisories/28648/[/url]
--
[SA28645] Mandriva update for ruby
Critical: Less critical
Where: From remote
Impact: Spoofing
Released: 2008-01-31
Mandriva has issued an update for ruby. This fixes some security issues, which can be exploited by malicious people to conduct spoofing attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28645/\"]http://secunia.com/advisories/28645/[/url]
--
[SA28679] Gentoo update for postgresql
Critical: Less critical
Where: From local network
Impact: Privilege escalation, DoS
Released: 2008-01-29
Gentoo has issued an update for postgresql. This fixes some vulnerabilities, which can be exploited by malicious users to gain
escalated privileges or to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28679/\"]http://secunia.com/advisories/28679/[/url]
--
[SA28676] Fedora update for cups
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-01-28
Fedora has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28676/\"]http://secunia.com/advisories/28676/[/url]
--
[SA28738] Ubuntu update for pulseaudio
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-01
Ubuntu has issued an update for pulseaudio. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28738/\"]http://secunia.com/advisories/28738/[/url]
--
[SA28718] rPath update for xorg-x11
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-31
rPath has issued an update for xorg-x11. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28718/\"]http://secunia.com/advisories/28718/[/url]
--
[SA28693] Avaya CMS Solaris X Window System and X Server Multiple Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-29
Avaya has acknowledged some vulnerabilities in Avaya CMS (Call Management System), which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28693/\"]http://secunia.com/advisories/28693/[/url]
--
[SA28665] PatchLink Update Client for Unix Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Manipulation of data, Privilege escalation
Released: 2008-01-30
Larry W. Cashdollar has reported two security issues in the PatchLink Update client for Unix, which can be exploited by malicious, local users to truncate arbitrary files and to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28665/\"]http://secunia.com/advisories/28665/[/url]
--
[SA28664] Fedora update for kernel
Critical: Less critical
Where: Local system
Impact: Security Bypass, Manipulation of data
Released: 2008-01-29
Fedora has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions and corrupt a file system.
Full Advisory:
[url=\"http://secunia.com/advisories/28664/\"]http://secunia.com/advisories/28664/[/url]
--
[SA28672] Gentoo update for blam
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-28
Gentoo has issued an update for blam. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28672/\"]http://secunia.com/advisories/28672/[/url]
--
[SA28654] Linux Kernel minix File System Denial of Service Vulnerability
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-01-28
A vulnerability has been reported in the Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28654/\"]http://secunia.com/advisories/28654/[/url]
[b]Other:--[/b]
[SA28667] IBM Hardware Management Console Pegasus CIM Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-29
A vulnerability has been reported in IBM HMC, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28667/\"]http://secunia.com/advisories/28667/[/url]
--
[SA28690] Yamaha RT Series Routers Cross-Site Request Forgery Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-29
A vulnerability has been reported in Yamaha RT Series Routers, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28690/\"]http://secunia.com/advisories/28690/[/url]
--
[SA28655] F5 BIG-IP Application Security Manager "report_type" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-28
nnposter has reported a vulnerability in F5 BIG-IP Application Security Manager, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28655/\"]http://secunia.com/advisories/28655/[/url]
[b]Cross Platform:--[/b]
[SA28731] Drupal Project Issue Tracking Module File Upload and Script Insertion
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2008-01-31
Some vulnerabilities have been reported in the Project Issue Tracking module for Drupal, which can be exploited by malicious users to conduct script insertion attacks and compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28731/\"]http://secunia.com/advisories/28731/[/url]
--
[SA28704] Connectix Boards "template_path" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-01-30
HouSSaMix has discovered a vulnerability in Connectix Boards, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28704/\"]http://secunia.com/advisories/28704/[/url]
--
[SA28685] Smart Publisher "filedata" PHP Code Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-30
GoLd_M has reported a vulnerability in Smart Publisher, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28685/\"]http://secunia.com/advisories/28685/[/url]
--
[SA28682] Coppermine Photo Gallery Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, System access
Released: 2008-01-30
Some vulnerabilities have been reported in Coppermine Photo Gallery, which can be exploited by malicious people to conduct cross-site scripting attacks or to compromise a vulnerable system and by malicious users to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28682/\"]http://secunia.com/advisories/28682/[/url]
--
[SA28652] Mambo LaiThai Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Unknown, Manipulation of data, System access
Released: 2008-01-29
Some vulnerabilities have been reported in Mambo LaiThai, some with an unknown impact and others, which can be exploited by malicious people to conduct SQL injection attacks or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28652/\"]http://secunia.com/advisories/28652/[/url]
--
[SA28737] Nilson's Blogger Two Local File Inclusion Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-02-01
muuratsalo has discovered two vulnerabilities in Nilson's Blogger, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28737/\"]http://secunia.com/advisories/28737/[/url]
--
[SA28732] Drupal Secure Site Module Security Bypass Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-31
A vulnerability has been reported in the Secure Site module for Drupal, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28732/\"]http://secunia.com/advisories/28732/[/url]
--
[SA28729] Drupal Comment Upload Module File Upload Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-31
A vulnerability has been reported in the Comment Upload Module for Drupal, which can be exploited by malicious users to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28729/\"]http://secunia.com/advisories/28729/[/url]
--
[SA28727] PHP Links "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-31
Houssamix has discovered a vulnerability in PHP Links, which can be
exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28727/\"]http://secunia.com/advisories/28727/[/url]
--
[SA28722] VirtueMart File Disclosure and Cross-Site Request Forgery Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-01-31
Two vulnerabilities have been reported in VirtueMart, which can be exploited by malicious people to conduct cross-site request forgery attacks or to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28722/\"]http://secunia.com/advisories/28722/[/url]
--
[SA28717] Drupal OpenID Module "claimed_id" Authority Spoofing
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-01-31
A vulnerability has been reported in the OpenID module for Drupal, which can be exploited by malicious people to spoof OpenID authorities.
Full Advisory:
[url=\"http://secunia.com/advisories/28717/\"]http://secunia.com/advisories/28717/[/url]
--
[SA28709] phpCMS "file" File Disclosure Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-01-30
Alexandr Polyakov and Stas Svistunovich have discovered a vulnerability in phpCMS, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28709/\"]http://secunia.com/advisories/28709/[/url]
--
[SA28708] WordPress AdServe Plugin "id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-30
enter_the_dragon has discovered a vulnerability in the AdServe plugin for WordPress, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28708/\"]http://secunia.com/advisories/28708/[/url]
--
[SA28702] WordPress WassUp Plugin "to_date" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-31
enter_the_dragon has reported a vulnerability in the WassUp plugin for WordPress, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28702/\"]http://secunia.com/advisories/28702/[/url]
--
[SA28691] Bigware Shop "pollid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-30
D4m14n has discovered a vulnerability in Bigware Shop, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28691/\"]http://secunia.com/advisories/28691/[/url]
--
[SA28683] WordPress WP-Cal Plugin "id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-29
Houssamix has discovered a vulnerability in the WP-Cal plugin for WordPress, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28683/\"]http://secunia.com/advisories/28683/[/url]
--
[SA28681] Simple Forum Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-01-29
tomplixsee has discovered some vulnerabilities in Simple Forum, which can be exploited by malicious people to conduct cross-site scripting attacks or to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28681/\"]http://secunia.com/advisories/28681/[/url]
--
[SA28670] Mambo Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of system information
Released: 2008-01-29
AmnPardaz Security Research Team have discovered some vulnerabilities and a weakness in Mambo, which can be exploited by malicious people to disclose system information, conduct cross-site scripting and cross-site request forgery attacks, and to manipulate data.
Full Advisory:
[url=\"http://secunia.com/advisories/28670/\"]http://secunia.com/advisories/28670/[/url]
--
[SA28656] phpIP Management Two SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of sensitive information
Released: 2008-01-28
Charles Hooper has discovered two vulnerabilities in phpIP Management, which can be exploited by malicious people and users to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28656/\"]http://secunia.com/advisories/28656/[/url]
--
[SA28646] Seagull PHP Framework "files" Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-01-25
fuzion has discovered a vulnerability in Seagull PHP Framework, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28646/\"]http://secunia.com/advisories/28646/[/url]
--
[SA28711] Cisco Wireless Control System Apache Tomcat JK Web Server Connector Buffer Overflow
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-01-31
Cisco has acknowledged a vulnerability in Cisco Wireless Control System (WCS), which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28711/\"]http://secunia.com/advisories/28711/[/url]
--
[SA28746] Sun Java Runtime Environment External XML Entities Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-01
Sun has acknowledged a security issue in Sun Java Runtime Environment (JRE), which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28746/\"]http://secunia.com/advisories/28746/[/url]
--
[SA28742] Liferay Portal Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Spoofing
Released: 2008-02-01
Tomasz Kuczynski has reported some vulnerabilities in Liferay Portal, which can be exploited by malicious people to conduct cross-site request forgery and phishing attacks, and by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28742/\"]http://secunia.com/advisories/28742/[/url]
--
[SA28730] Drupal Userpoints Module Cross-Site Request Forgery Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-31
A vulnerability has been reported in the Userpoints module for Drupal, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28730/\"]http://secunia.com/advisories/28730/[/url]
--
[SA28692] Hal Networks Products Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-30
Some vulnerabilities have been reported in Hal Networks products, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28692/\"]http://secunia.com/advisories/28692/[/url]
--
[SA28687] Tripwire Enterprise Login Page Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-31
Dave Lewis has reported a vulnerability in Tripwire Enterprise, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28687/\"]http://secunia.com/advisories/28687/[/url]
--
[SA28684] webSPELL Cross-Site Scripting and Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-31
NBBN has discovered two vulnerabilities in webSPELL, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28684/\"]http://secunia.com/advisories/28684/[/url]
--
[SA28680] Nucleus CMS URL Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-30
Alexandr Polyakov and Stas Svistunovich have reported a vulnerability in Nucleus CMS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28680/\"]http://secunia.com/advisories/28680/[/url]
Secunia Bulletins February 2008
Posted: Thu Feb 07, 2008 5:13 pm
by Tami
[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of February 7 2008[/b][/i]
[b]Windows:--[/b]
[SA28809] Ourgame GLWorld HanGamePluginCn18 Class ActiveX Control Buffer Overflows
Critical: Extremely critical
Where: From remote
Impact: System access
Released: 2008-02-06
Two vulnerabilities have been discovered in Ourgame GLWorld, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28809/\"]http://secunia.com/advisories/28809/[/url]
--
[SA28757] Yahoo! Music Jukebox ActiveX Control Buffer Overflows
Critical: Extremely critical
Where: From remote
Impact: System access
Released: 2008-02-04
Some vulnerabilities have been discovered in Yahoo! Music Jukebox, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28757/\"]http://secunia.com/advisories/28757/[/url]
--
[SA28797] ACDSee Photo Manager XBM File Processing Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-07
Trend Micro has reported a vulnerability in ACDSee Photo Manager, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28797/\"]http://secunia.com/advisories/28797/[/url]
--
[SA28791] Skype Cross-Zone Scripting Security Enhancement
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-06
An update has been released for Skype, which implements security enhancements to prevent compromise of users' systems.
Full Advisory:
[url=\"http://secunia.com/advisories/28791/\"]http://secunia.com/advisories/28791/[/url]
--
[SA28765] Nero Media Player Playlist Processing Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-05
securfrog has discovered a vulnerability in Nero Media Player, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28765/\"]http://secunia.com/advisories/28765/[/url]
--
[SA28760] Titan FTP Server Command Processing Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-04
securfrog has discovered a vulnerability in Titan FTP Server, which potentially can be exploited by malicious people to compromise a
vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28760/\"]http://secunia.com/advisories/28760/[/url]
--
[SA28822] IPSwitch WS_FTP Server Manager Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-02-07
Luigi Auriemma has discovered a security issue in IPSwitch WS_FTP Server, which can be exploited by malicious people to bypass certain access restrictions and disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28822/\"]http://secunia.com/advisories/28822/[/url]
--
[SA28753] IpSwitch WS_FTP Server with SSH Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-04
securfrog has discovered a vulnerability in IpSwitch WS_FTP Server with SSH, which can be exploited by malicious users to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28753/\"]http://secunia.com/advisories/28753/[/url]
--
[SA28811] SAP SAPSprint Multiple Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-02-07
Some vulnerabilities have been reported in SAPSprint, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28811/\"]http://secunia.com/advisories/28811/[/url]
--
[SA28786] SAP GUI SAPLPD Multiple Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-02-05
Luigi Auriemma has discovered some vulnerabilities in SAP GUI, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28786/\"]http://secunia.com/advisories/28786/[/url]
--
[SA28763] WinCom LPD Total Multiple Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: Security Bypass, DoS, System access
Released: 2008-02-05
Luigi Auriemma has discovered some vulnerabilities in WinCom LPD Total, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28763/\"]http://secunia.com/advisories/28763/[/url]
--
[SA28770] RaidenHTTPD Unspecified Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-05
A vulnerability has been reported in RaidenHTTPD, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28770/\"]http://secunia.com/advisories/28770/[/url]
--
[SA28755] Xlight FTP Server LDAP Blank Password Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-04
A security issue has been reported in Xlight FTP Server, which can be exploited by malicious users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28755/\"]http://secunia.com/advisories/28755/[/url]
--
[SA28761] Ipswitch WS_FTP Server FTP Log Server Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-05
Luigi Auriemma has discovered a vulnerability in Ipswitch WS_FTP Server, which can be exploited by malicious people to cause a DoS
(Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28761/\"]http://secunia.com/advisories/28761/[/url]
--
[SA28832] Symantec Altiris Notification Server Agent Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-07
A vulnerability has been reported in Symantec Altiris Notification Server, which can be exploited by malicious, local users to gain
escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28832/\"]http://secunia.com/advisories/28832/[/url]
--
[SA28792] Novell Client Challenge Response Client Clipboard Disclosure Weakness
Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-02-05
A weakness has been reported in the Challenge Response Client included in Novell Client, which can be exploited by malicious, local users to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28792/\"]http://secunia.com/advisories/28792/[/url]
[b]UNIX/Linux:--[/b]
[SA28821] Gentoo doomsday Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-07
Gentoo has acknowledged some vulnerabilities in doomsday, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28821/\"]http://secunia.com/advisories/28821/[/url]
--
[SA28812] Debian update for poppler
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-06
Debian has issued an update for poppler. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28812/\"]http://secunia.com/advisories/28812/[/url]
--
[SA28805] Apple iPhoto Photocast Format String Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-06
A vulnerability has been reported in Apple iPhoto, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28805/\"]http://secunia.com/advisories/28805/[/url]
--
[SA28801] xine-lib FLAC Processing Memory Corruption Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-05
A vulnerability has been discovered in xine-lib, which can potentially be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28801/\"]http://secunia.com/advisories/28801/[/url]
--
[SA28800] Sun Solaris ImageMagick Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-05
Sun has acknowledged some vulnerabilities in ImageMagick for Sun Solaris, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28800/\"]http://secunia.com/advisories/28800/[/url]
--
[SA28779] MPlayer Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-05
Some vulnerabilities have been reported in MPlayer, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28779/\"]http://secunia.com/advisories/28779/[/url]
--
[SA28777] SUSE update for IBMJava5-JRE and IBMJava5-SDK
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-02-04
SUSE has issued an update for IBMJava5-JRE and IBMJava5-SDK. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, manipulate data, disclose sensitive information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28777/\"]http://secunia.com/advisories/28777/[/url]
--
[SA28830] Gentoo update for sdl-image
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-07
Gentoo has issued an update for sdl-image. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28830/\"]http://secunia.com/advisories/28830/[/url]
--
[SA28819] OpenBSD DNS Server PRNG Transaction ID Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-02-07
Amit Klein has reported a vulnerability in OpenBSD, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/28819/\"]http://secunia.com/advisories/28819/[/url]
--
[SA28816] NetBSD "ipcomp6_input()" Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-06
A vulnerability has been reported in NetBSD, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28816/\"]http://secunia.com/advisories/28816/[/url]
--
[SA28814] Debian update for squid
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-06
Debian has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28814/\"]http://secunia.com/advisories/28814/[/url]
--
[SA28788] KAME Project "ipcomp6_input()" Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-06
A vulnerability has been reported in the KAME Project, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28788/\"]http://secunia.com/advisories/28788/[/url]
--
[SA28783] rPath update for icu
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-07
rPath has issued an update for icu. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28783/\"]http://secunia.com/advisories/28783/[/url]
--
[SA28782] Fedora update for deluge
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-04
Fedora has issued an update for deluge. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28782/\"]http://secunia.com/advisories/28782/[/url]
--
[SA28769] Debian update for python-cherrypy
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-06
Debian has issued an update for python-cherrypy. This fixes a vulnerability, which can be exploited by malicious people to bypass
certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28769/\"]http://secunia.com/advisories/28769/[/url]
--
[SA28752] Fedora update for SDL_image
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-04
Fedora has issued an update for SDL_image. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28752/\"]http://secunia.com/advisories/28752/[/url]
--
[SA28749] Ubuntu update for apache2
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2008-02-05
Ubuntu has issued an update for apache2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28749/\"]http://secunia.com/advisories/28749/[/url]
--
[SA28825] Debian update for net-snmp
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-07
Debian has issued an update for net-snmp. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28825/\"]http://secunia.com/advisories/28825/[/url]
--
[SA28751] Fedora update for kdebase
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-02-04
Fedora has issued an update for kdebase. This fixes a weakness, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28751/\"]http://secunia.com/advisories/28751/[/url]
[b]Other:--[/b]
[SA28750] HP-UX update for Apache
Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-02-04
HP-UX has issued an update for Apache. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, and by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28750/\"]http://secunia.com/advisories/28750/[/url]
--
[SA28762] RouterOS SNMPd "SNMP SET" Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-04
ShadOS has reported a vulnerability in RouterOS, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28762/\"]http://secunia.com/advisories/28762/[/url]
[b]Cross Platform:--[/b]
[SA28833] TinTin++ / WinTin++ Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Manipulation of data, DoS, System access
Released: 2008-02-07
Luigi Auriemma has discovered some vulnerabilities and a weakness in TinTin++ and WinTin++, which can be exploited by malicious people to cause a DoS (Denial of Service), manipulate data, or to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28833/\"]http://secunia.com/advisories/28833/[/url]
--
[SA28810] Documentum Administrator/Webtop "dmclTrace.jsp" Arbitrary File Overwrite
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-06
Pablo Gaston Milano has reported a vulnerability in Documentum Administrator and Documentum Webtop, which can be exploited by
malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28810/\"]http://secunia.com/advisories/28810/[/url]
--
[SA28795] Sun JRE Applet Handling Two Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-06
Two vulnerabilities have been reported in Sun JRE, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28795/\"]http://secunia.com/advisories/28795/[/url]
--
[SA28790] Openads Arbitrary PHP Code Execution Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-05
A vulnerability has been reported in Openads, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28790/\"]http://secunia.com/advisories/28790/[/url]
--
[SA28831] osCommerce Customer Testimonials Addon SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-07
A vulnerability has been discovered in the Customer Testimonials addon for osCommerce, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28831/\"]http://secunia.com/advisories/28831/[/url]
--
[SA28803] Mihalism Multi Host "username" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-07
Moubik has discovered a vulnerability in Mihalism Multi Host, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28803/\"]http://secunia.com/advisories/28803/[/url]
--
[SA28802] Adobe Reader Unspecified Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-02-06
Some vulnerabilities with unknown impacts have been reported in Adobe Reader.
Full Advisory:
[url=\"http://secunia.com/advisories/28802/\"]http://secunia.com/advisories/28802/[/url]
--
[SA28789] WordPress MU File Upload and Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-02-06
Alexander Concha has reported a vulnerability in WordPress MU, which can be exploited by malicious users to bypass certain security
restrictions and to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28789/\"]http://secunia.com/advisories/28789/[/url]
--
[SA28784] Tk GIF Processing Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-06
A vulnerability has been reported in Tk, which can potentially be exploited by malicious people to compromise an application using the
library.
Full Advisory:
[url=\"http://secunia.com/advisories/28784/\"]http://secunia.com/advisories/28784/[/url]
--
[SA28781] Deluge "bdecode_recursive()" Stack Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-04
A vulnerability has been reported in Deluge, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28781/\"]http://secunia.com/advisories/28781/[/url]
--
[SA28780] ITechBids "item_id" SQL Injection and Cross-Site Scripting
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2008-02-05
Two vulnerabilities have been discovered in ITechBids, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28780/\"]http://secunia.com/advisories/28780/[/url]
--
[SA28773] ITechClassifieds "CatID" SQL Injection and Cross-site Scripting
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-02-04
Crackers_Child has discovered two vulnerabilities in ITechClassifieds, which can be exploited by malicious people to conduct cross-site
scripting and SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28773/\"]http://secunia.com/advisories/28773/[/url]
--
[SA28771] IBM DB2 UDB Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass, Privilege escalation, DoS
Released: 2008-02-04
Multiple vulnerabilities have been reported in IBM DB2 UDB, where some have unknown impacts, while others can be exploited by malicious, local users to gain escalated privileges, and by malicious people to bypass certain security restrictions or to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28771/\"]http://secunia.com/advisories/28771/[/url]
--
[SA28767] Wordspew Plugin for Wordpress "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-04
S@BUN has reported a vulnerability in the Wordspew plugin for Wordpress, which can be exploited by malicious people to conduct SQL
injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28767/\"]http://secunia.com/advisories/28767/[/url]
--
[SA28759] WordPress DMSGuestbook Plugin Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-02-05
NBBN has discovered some vulnerabilities in the DMSGuestbook plugin for WordPress, which can be exploited by malicious users to disclose sensitive information or to manipulate data, and by malicious people to conduct cross-site scripting and script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28759/\"]http://secunia.com/advisories/28759/[/url]
--
[SA28756] BlogPHP SQL Injection and Cross-Site Scripting
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2008-02-04
Dr.Crash has discovered two vulnerabilities in BlogPHP, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28756/\"]http://secunia.com/advisories/28756/[/url]
--
[SA28813] HP Storage Essentials SRM Multiple Unspecified Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: Security Bypass, System access
Released: 2008-02-07
Some vulnerabilities have been reported in HP Storage Essentials SRM, which can be exploited by malicious people to bypass certain security restrictions or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28813/\"]http://secunia.com/advisories/28813/[/url]
--
[SA28787] Symantec Backup Exec System Recovery Manager File Upload Vulnerability
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-02-05
A vulnerability has been reported in Symantec Backup Exec System Recovery Manager, which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28787/\"]http://secunia.com/advisories/28787/[/url]
--
[SA28827] Webmin / Usermin "search" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-07
A vulnerability has been discovered in Webmin and Usermin, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28827/\"]http://secunia.com/advisories/28827/[/url]
--
[SA28823] WordPress XML-RPC Post Edit Vulnerability
Critical: Less critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-02-07
A vulnerability has been reported in WordPress, which can be exploited by malicious users to bypass certain security restrictions and to
manipulate data.
Full Advisory:
[url=\"http://secunia.com/advisories/28823/\"]http://secunia.com/advisories/28823/[/url]
--
[SA28794] Mailman Script Insertion Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-05
A vulnerability has been reported in Mailman, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28794/\"]http://secunia.com/advisories/28794/[/url]
--
[SA28793] Textpattern Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-02-05
Some vulnerabilities have been reported in Textpattern, which can be exploited by malicious users to disclose sensitive information or
conduct script insertion attacks, and by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28793/\"]http://secunia.com/advisories/28793/[/url]
--
[SA28785] IBM WebSphere Edge Server Caching Proxy Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-07
A vulnerability has been reported in IBM WebSphere Edge Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28785/\"]http://secunia.com/advisories/28785/[/url]
--
[SA28778] Novell GroupWise WebAccess Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-04
Some vulnerabilities have been reported in Novell GroupWise, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28778/\"]http://secunia.com/advisories/28778/[/url]
--
[SA28775] Youtube Script "lang[please_wait]" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-04
Smasher has reported a vulnerability in Youtube Script, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28775/\"]http://secunia.com/advisories/28775/[/url]
--
[SA28774] Domain Trader "id" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-04
Crackers_Child has reported a vulnerability in Domain Trader, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28774/\"]http://secunia.com/advisories/28774/[/url]
--
[SA28772] WordPress WP-Footnotes Plugin "admin_panel.php" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-04
NBBN has discovered some vulnerabilities in the WP-Footnotes plugin for WordPress, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28772/\"]http://secunia.com/advisories/28772/[/url]
--
[SA28798] HP OpenView Network Node Manager Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-06
A vulnerability has been reported in HP OpenView Network Node Manager, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28798/\"]http://secunia.com/advisories/28798/[/url]
Secunia Bulletins February 2008
Posted: Thu Feb 14, 2008 5:21 pm
by Tami
[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing - Week of February 14th[/b][/i]
[b]Windows:--[/b]
[SA28909] Microsoft Office Object Parsing Memory Corruption Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-12
A vulnerability has been reported in Microsoft Office, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28909/\"]http://secunia.com/advisories/28909/[/url]
--
[SA28906] Microsoft Office Publisher File Parsing Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-12
Some vulnerabilities have been reported in Microsoft Office Publisher, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28906/\"]http://secunia.com/advisories/28906/[/url]
--
[SA28904] Microsoft Works File Converter File Parsing Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-12
Some vulnerabilities have been reported in Microsoft Office and Microsoft Works, which can be exploited by malicious people to
compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28904/\"]http://secunia.com/advisories/28904/[/url]
--
[SA28903] Microsoft Internet Explorer Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-12
Some vulnerabilities have been reported in Internet Explorer, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28903/\"]http://secunia.com/advisories/28903/[/url]
--
[SA28902] Microsoft Windows OLE Automation Memory Corruption
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-12
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28902/\"]http://secunia.com/advisories/28902/[/url]
--
[SA28901] Microsoft Word File Information Block Memory Corruption
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-12
A vulnerability has been reported in Microsoft Word, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28901/\"]http://secunia.com/advisories/28901/[/url]
--
[SA28894] Microsoft WebDAV Mini-Redirector Pathname Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-12
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28894/\"]http://secunia.com/advisories/28894/[/url]
--
[SA28893] Microsoft Internet Information Services Code Execution Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-12
A vulnerability has been reported in Microsoft Internet Information Services (IIS), which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28893/\"]http://secunia.com/advisories/28893/[/url]
--
[SA28855] jetAudio ASX Parsing Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-11
Laurent Gaffie has discovered a vulnerability in jetAudio, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28855/\"]http://secunia.com/advisories/28855/[/url]
--
[SA28854] Sony ImageStation AxRUploadControl ActiveX Control "SetLogging()" Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-11
david130490 has discovered a vulnerability in Sony ImageStation AxRUploadControl Object ActiveX control, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28854/\"]http://secunia.com/advisories/28854/[/url]
--
[SA28863] SafeNet Sentinel Protection Server/Key Server Directory Traversal Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-02-12
Luigi Auriemma has discovered a vulnerability in SafeNet Sentinel Protection Server and Key Server, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28863/\"]http://secunia.com/advisories/28863/[/url]
--
[SA28842] Husrev BlackBoard "forumid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-11
Cr@zy_King has discovered a vulnerability in Husrev BlackBoard, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28842/\"]http://secunia.com/advisories/28842/[/url]
--
[SA28905] RPM Remote Print Manager Service "Receive data file" Buffer Overflow
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-02-12
Luigi Auriemma has discovered a vulnerability in RPM Remote Print Manager, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28905/\"]http://secunia.com/advisories/28905/[/url]
--
[SA28895] Novell Client NWSPOOL.DLL "EnumPrinters()" Buffer Overflow
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-02-12
A vulnerability has been reported in Novell Client, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28895/\"]http://secunia.com/advisories/28895/[/url]
--
[SA28890] Larson Network Print Server Format String and Buffer Overflow Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-02-12
Luigi Auriemma has discovered two vulnerabilities in Larson Network Print Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28890/\"]http://secunia.com/advisories/28890/[/url]
--
[SA28870] cyan soft Products Format String and Denial of Service Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-02-11
Luigi Auriemma has discovered some vulnerabilities in cyan soft products, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28870/\"]http://secunia.com/advisories/28870/[/url]
--
[SA28945] Adobe RoboHelp Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-13
A vulnerability has been reported in RoboHelp, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28945/\"]http://secunia.com/advisories/28945/[/url]
--
[SA28908] Beyond! Job Board "FKeywords" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-12
Ivan Sanchez and Maximiliano Soler have reported a vulnerability in Beyond! Job Board, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28908/\"]http://secunia.com/advisories/28908/[/url]
--
[SA28882] Tendenci CMS search.asp Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-13
Russ McRee has reported some vulnerabilities in Tendenci CMS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28882/\"]http://secunia.com/advisories/28882/[/url]
--
[SA28934] Intermate WinIPDS Directory Traversal and Denial of Service Vulnerabilities
Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information, DoS
Released: 2008-02-13
Luigi Auriemma has reported some vulnerabilities in Intermate WinIPDS, which can be exploited by malicious people to disclose sensitive information or cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28934/\"]http://secunia.com/advisories/28934/[/url]
--
[SA28862] ExtremeZ-IP File and Print Server Multiple Vulnerabilities
Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information, DoS
Released: 2008-02-11
Luigi Auriemma has discovered some vulnerabilities in ExtremeZ-IP File and Print Server, which can be exploited by malicious people to disclose potentially sensitive information or cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28862/\"]http://secunia.com/advisories/28862/[/url]
--
[SA28853] Symantec Ghost Solution Suite Client Command Execution Vulnerability
Critical: Less critical
Where: From local network
Impact: System access
Released: 2008-02-08
A vulnerability has been reported in Symantec Ghost Solution Suite, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28853/\"]http://secunia.com/advisories/28853/[/url]
--
[SA28975] Fortinet FortiClient Privilege Escalation Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-14
Ruben Santamarta has reported a vulnerability in Fortinet FortiClient, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28975/\"]http://secunia.com/advisories/28975/[/url]
--
[SA28849] Microsoft Internet Information Services Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-12
A vulnerability has been reported in Microsoft Internet Information Services (IIS), which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28849/\"]http://secunia.com/advisories/28849/[/url]
[b]UNIX/Linux:--[/b]
[SA28956] Debian update for mplayer
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-13
Debian has issued an update for mplayer. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28956/\"]http://secunia.com/advisories/28956/[/url]
--
[SA28948] Gentoo update for gnumeric
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-13
Gentoo has issued an update for gnumeric. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28948/\"]http://secunia.com/advisories/28948/[/url]
--
[SA28939] Fedora update for firefox, seamonkey, and gtkmozembedmm
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-02-13
Fedora has issued an update for firefox, seamonkey, and gtkmozembedmm. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or potentially to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28939/\"]http://secunia.com/advisories/28939/[/url]
--
[SA28924] Fedora update for firefox, seamonkey, gtkmozembedmm, and
Miro
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-02-13
Fedora has issued an update for firefox, seamonkey, gtkmozembedmm, and Miro. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28924/\"]http://secunia.com/advisories/28924/[/url]
--
[SA28918] Fedora update for xine-lib
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-13
Fedora has issued an update for xine-lib. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28918/\"]http://secunia.com/advisories/28918/[/url]
--
[SA28913] Fedora update for clamav
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-13
Fedora has issued an update for clamav. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28913/\"]http://secunia.com/advisories/28913/[/url]
--
[SA28907] ClamAV Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-12
Some vulnerabilities have been reported in ClamAV, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28907/\"]http://secunia.com/advisories/28907/[/url]
--
[SA28898] Gentoo update for gallery
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, System access
Released: 2008-02-12
Gentoo has issued an update for gallery. This fixes a weakness and some vulnerabilities, where some have unspecified impacts and others can be exploited by malicious users or malicious people to disclose sensitive information, conduct cross-site scripting attacks, bypass certain security restrictions, and potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28898/\"]http://secunia.com/advisories/28898/[/url]
--
[SA28891] Apple Mac OS X Security Update Fixes Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Privilege escalation, DoS, System access
Released: 2008-02-12
Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities and weaknesses.
Full Advisory:
[url=\"http://secunia.com/advisories/28891/\"]http://secunia.com/advisories/28891/[/url]
--
[SA28888] Red Hat update for java-1.5.0-sun
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-12
Red Hat has issued an update for java-1.5.0-sun. This fixes two vulnerabilities, which can be exploited by malicious people to
compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28888/\"]http://secunia.com/advisories/28888/[/url]
--
[SA28879] Debian update for xulrunner
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-02-11
Debian has issued an update for xulrunner. This fixes some weaknesses and vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28879/\"]http://secunia.com/advisories/28879/[/url]
--
[SA28877] rPath update for firefox
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-02-11
rPath has issued an update for firefox. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28877/\"]http://secunia.com/advisories/28877/[/url]
--
[SA28865] Debian update for icedove
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, DoS, System access
Released: 2008-02-11
Debian has issued an update for icedove. This fixes some vulnerabilities, which can be exploited by malicious people to disclose
sensitive information, bypass certain security restrictions, or potentially to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28865/\"]http://secunia.com/advisories/28865/[/url]
--
[SA28864] Debian update for iceweasel
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-02-11
Debian has issued an update for iceweasel. This fixes some weaknesses and vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28864/\"]http://secunia.com/advisories/28864/[/url]
--
[SA28845] Mandriva update for gd
Critical: Highly critical
Where: From remote
Impact: System access, DoS
Released: 2008-02-08
Mandriva has issued an update for gd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28845/\"]http://secunia.com/advisories/28845/[/url]
--
[SA28839] Ubuntu update for firefox
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-02-08
Ubuntu has issued an update for firefox. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious
people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's
system.
Full Advisory:
[url=\"http://secunia.com/advisories/28839/\"]http://secunia.com/advisories/28839/[/url]
--
[SA28979] FreeBSD update for ipsec
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-14
FreeBSD has issued an update for ipsec. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28979/\"]http://secunia.com/advisories/28979/[/url]
--
[SA28960] Fedora update for glib2
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-14
Fedora has released an update for glib2. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28960/\"]http://secunia.com/advisories/28960/[/url]
--
[SA28959] Graphviz GD GIF Handling Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-13
A vulnerability has been reported in Graphviz, which can potentially be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28959/\"]http://secunia.com/advisories/28959/[/url]
--
[SA28954] rPath update for tk
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-13
rPath has issued an update for tk. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28954/\"]http://secunia.com/advisories/28954/[/url]
--
[SA28930] Debian update for nagios-plugins
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-13
Debian has issued an update for nagios-plugins. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28930/\"]http://secunia.com/advisories/28930/[/url]
--
[SA28915] Fedora update for tomcat5
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of sensitive information
Released: 2008-02-13
Fedora has issued an update for tomcat5. This fixes a security issue, which can be exploited by malicious, local users to bypass certain security restrictions, and some vulnerabilities, which can be exploited by malicious people to manipulate certain data or to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28915/\"]http://secunia.com/advisories/28915/[/url]
--
[SA28911] ikiwiki Two Script Insertion Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-12
Two vulnerabilities have been reported in ikiwiki, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28911/\"]http://secunia.com/advisories/28911/[/url]
--
[SA28897] Gentoo update for horde-imp
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data
Released: 2008-02-12
Gentoo has issued an update for horde-imp. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions and manipulate data.
Full Advisory:
[url=\"http://secunia.com/advisories/28897/\"]http://secunia.com/advisories/28897/[/url]
--
[SA28869] rPath update for SDL_image
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-14
rPath has issued an update for SDL_image. This fixes two vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28869/\"]http://secunia.com/advisories/28869/[/url]
--
[SA28867] Debian update for tk8.4
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-11
Debian has issued an update for tk8.4. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28867/\"]http://secunia.com/advisories/28867/[/url]
--
[SA28866] Fedora update for graphviz
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-13
Fedora has issued an update for graphviz. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28866/\"]http://secunia.com/advisories/28866/[/url]
--
[SA28857] Debian update for tk8.3
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-11
Debian has issued an update for tk8.3. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28857/\"]http://secunia.com/advisories/28857/[/url]
--
[SA28850] Mandriva update for SDL_image
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-08
Mandriva has issued an update for SDL_image. This fixes two vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28850/\"]http://secunia.com/advisories/28850/[/url]
--
[SA28848] Mandriva update for tk
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-08
Mandriva has issued an update for tk. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28848/\"]http://secunia.com/advisories/28848/[/url]
--
[SA28838] SUSE Update for Multiple Packages
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Privilege escalation, DoS, System access
Released: 2008-02-08
SUSE has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges and cause a DoS (Denial of Service), by malicious users to manipulate data, gain escalated privileges, and cause a DoS, and by malicious people to manipulate data, bypass certain security restrictions, cause a DoS, and potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28838/\"]http://secunia.com/advisories/28838/[/url]
--
[SA28837] Debian update for sdl-image1.2
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-11
Debian has issued an update for sdl-image1.2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28837/\"]http://secunia.com/advisories/28837/[/url]
--
[SA28971] Ubuntu update for kernel
Critical: Less critical
Where: From remote
Impact: Unknown, Security Bypass, Manipulation of data, Exposure of sensitive information, DoS
Released: 2008-02-14
Ubuntu has issued an update for the kernel. This fixes a security issue and some vulnerabilities, where one has an unknown impact and others can be exploited by malicious, local users to disclose potentially sensitive information, cause a DoS (Denial of Service), bypass certain security restrictions, and corrupt a file system, and by malicious people to cause a DoS.
Full Advisory:
[url=\"http://secunia.com/advisories/28971/\"]http://secunia.com/advisories/28971/[/url]
--
[SA28965] HP-UX update for Apache
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-14
HP-UX has issued an update for Apache. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28965/\"]http://secunia.com/advisories/28965/[/url]
--
[SA28951] OpenCA Cross-Site Request Forgery Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-14
Alexander Klink has reported a vulnerability in OpenCA, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28951/\"]http://secunia.com/advisories/28951/[/url]
--
[SA28920] Fedora update for wordpress
Critical: Less critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-02-13
Fedora has issued an update for wordpress. This fixes a vulnerability, which can be exploited by malicious users to bypass certain security restrictions and to manipulate data.
Full Advisory:
[url=\"http://secunia.com/advisories/28920/\"]http://secunia.com/advisories/28920/[/url]
--
[SA28916] Fedora update for mailman
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-13
Fedora has issued an update for mailman. This fixes a vulnerability, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28916/\"]http://secunia.com/advisories/28916/[/url]
--
[SA28871] Debian update for phpbb2
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, System access
Released: 2008-02-11
Debian has issued an update for phpbb2. This fixes some vulnerabilities, which can be exploited by malicious users to
compromise a vulnerable system and by malicious people to conduct cross-site scripting and cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28871/\"]http://secunia.com/advisories/28871/[/url]
--
[SA28860] rPath update for boost
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-02-14
rPath has issued an update for boost. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28860/\"]http://secunia.com/advisories/28860/[/url]
--
[SA28953] rPath update for openldap
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-13
rPath has issued an update for openldap. This fixes some vulnerabilities, which can be exploited by malicious users to cause a
DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28953/\"]http://secunia.com/advisories/28953/[/url]
--
[SA28926] OpenLDAP modrdn Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-13
A vulnerability has been reported in OpenLDAP, which can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28926/\"]http://secunia.com/advisories/28926/[/url]
--
[SA28914] Fedora update for openldap
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-13
Fedora has issued an update for openldap. This fixes a vulnerability, which can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28914/\"]http://secunia.com/advisories/28914/[/url]
--
[SA28952] Gentoo update for pulseaudio
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-14
Gentoo has issued an update for pulseaudio. This fixes a security issue, which can be exploited by malicious, local users to perform
certain actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28952/\"]http://secunia.com/advisories/28952/[/url]
--
[SA28944] Gentoo update for scponly
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-13
Gentoo has issued an update for scponly. This fixes a security issue, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28944/\"]http://secunia.com/advisories/28944/[/url]
--
[SA28941] Avaya CMS Sun Solaris X Window System and X Server Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-02-14
Avaya has acknowledged some vulnerabilities in Avaya CMS, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28941/\"]http://secunia.com/advisories/28941/[/url]
--
[SA28937] Red Hat update for kernel
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-13
Red Hat has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious, local users to gain
escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28937/\"]http://secunia.com/advisories/28937/[/url]
--
[SA28933] Ubuntu update for kernel
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-13
Ubuntu has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28933/\"]http://secunia.com/advisories/28933/[/url]
--
[SA28931] Sun Solaris 10 Language Input Methods Security Issue
Critical: Less critical
Where: Local system
Impact: Manipulation of data
Released: 2008-02-13
A security issue has been reported in Sun Solaris, which can be exploited by malicious, local users to modify certain files or
directories.
Full Advisory:
[url=\"http://secunia.com/advisories/28931/\"]http://secunia.com/advisories/28931/[/url]
--
[SA28925] rPath update for kernel
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-13
rPath has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28925/\"]http://secunia.com/advisories/28925/[/url]
--
[SA28917] Fedora update for duplicity
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-02-13
Fedora has issued an update for duplicity. This fixes a security issue, which can be exploited by malicious, local users to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28917/\"]http://secunia.com/advisories/28917/[/url]
--
[SA28912] Fedora update for kernel-xen
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-13
Fedora has issued an update for kernel-xen. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28912/\"]http://secunia.com/advisories/28912/[/url]
--
[SA28896] Fedora update for kernel
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-02-12
Fedora has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, and gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28896/\"]http://secunia.com/advisories/28896/[/url]
--
[SA28889] SUSE update for kernel
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation
Released: 2008-02-12
SUSE has issued an update for the kernel. This fixes a security issue an a vulnerability, which can be exploited by malicious, local users to disclose potentially sensitive information or gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28889/\"]http://secunia.com/advisories/28889/[/url]
--
[SA28885] NX Server X11 Multiple Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-02-12
Some vulnerabilities have been reported in NX Server, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28885/\"]http://secunia.com/advisories/28885/[/url]
--
[SA28875] Debian update for linux-2.6
Critical: Less critical
Where: Local system
Impact: Security Bypass, Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-02-12
Debian has issued an update for linux-2.6. This fixes some vulnerabilities, which can be exploited by malicious, local users to
bypass certain security restrictions, cause a DoS (Denial of Service), disclose potentially sensitive information, and gain escalated
privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28875/\"]http://secunia.com/advisories/28875/[/url]
--
[SA28858] Mandriva update for kernel
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-12
Mandriva has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious, local users to gain
escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28858/\"]http://secunia.com/advisories/28858/[/url]
--
[SA28856] Website META Language Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-08
Some security issues have been reported in Website META Language, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28856/\"]http://secunia.com/advisories/28856/[/url]
--
[SA28843] OpenBSD update for X.Org
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-02-08
OpenBSD has issued an update for X.Org.This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28843/\"]http://secunia.com/advisories/28843/[/url]
--
[SA28835] Linux Kernel "vmsplice()" System Call Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-02-11
Some vulnerabilities have been reported in the Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, and gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28835/\"]http://secunia.com/advisories/28835/[/url]
--
[SA28928] FreeBSD "sendfile" Information Disclosure Security Issue
Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-02-14
A security issue has been reported in FreeBSD, which potentially can be exploited by malicious, local users to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28928/\"]http://secunia.com/advisories/28928/[/url]
--
[SA28921] Sun Solaris USB Mouse STREAMS Module Local Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-02-13
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28921/\"]http://secunia.com/advisories/28921/[/url]
[b]Other:--[/b]
[SA28935] Cisco Unified IP Phone Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-14
Some vulnerabilities have been reported in Cisco Unified IP Phone models, which can be exploited by malicious users to compromise a vulnerable device or by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable device.
Full Advisory:
[url=\"http://secunia.com/advisories/28935/\"]http://secunia.com/advisories/28935/[/url]
--
[SA28932] Cisco Unified Communications Manager "key" SQL Injection
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-14
A vulnerability has been reported in Cisco Unified Communications Manager, which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28932/\"]http://secunia.com/advisories/28932/[/url]
[b]Cross Platform:--[/b]
[SA28946] Adobe Flash Media Server Edge Server Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-13
Some vulnerabilities have been reported in Adobe Flash Media Server, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28946/\"]http://secunia.com/advisories/28946/[/url]
--
[SA28886] SAPID CMF "last_module" PHP Code Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-11
GoLd_M has discovered a vulnerability in SAPID CMF, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28886/\"]http://secunia.com/advisories/28886/[/url]
--
[SA28874] Open-Realty "last_module" PHP Code Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-11
Iron has discovered a vulnerability in Open-Realty, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28874/\"]http://secunia.com/advisories/28874/[/url]
--
[SA28859] PacerCMS "last_module" PHP Code Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-11
GoLd_M has discovered a vulnerability in PacerCMS, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28859/\"]http://secunia.com/advisories/28859/[/url]
--
[SA28851] Adobe Reader/Acrobat 7 Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Unknown, System access
Released: 2008-02-08
Some vulnerabilities have been reported in Adobe Reader/Acrobat, some of which have unknown impacts while others can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28851/\"]http://secunia.com/advisories/28851/[/url]
--
[SA28836] PowerNews Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of
sensitive information, System access
Released: 2008-02-11
Some vulnerabilities and a weakness have been discovered in PowerNews, which can be exploited by malicious users to compromise a vulnerable system and by malicious people to conduct cross-site scripting and SQL injection attacks, disclose certain information, and compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28836/\"]http://secunia.com/advisories/28836/[/url]
--
[SA28969] JSPWiki Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-02-14
Moshe BA has discovered some vulnerabilities in JSPWiki, which can be exploited by malicious people to conduct cross-site scripting attacks or to disclose potentially sensitive information, and by malicious users to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28969/\"]http://secunia.com/advisories/28969/[/url]
--
[SA28950] AuraCMS "albums" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-13
DNX has discovered a vulnerability in AuraCMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28950/\"]http://secunia.com/advisories/28950/[/url]
--
[SA28929] iTheora "url" Disclosure of Sensitive Information
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-02-14
A vulnerability has been reported in iTheora, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28929/\"]http://secunia.com/advisories/28929/[/url]
--
[SA28927] artmedic weblog Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-02-13
muuratsalo has discovered some vulnerabilities in artmedic weblog, which can be exploited by malicious people to conduct cross-site scripting attacks or to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28927/\"]http://secunia.com/advisories/28927/[/url]
--
[SA28923] PCRE Character Class Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-14
A vulnerability has been reported in PCRE, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28923/\"]http://secunia.com/advisories/28923/[/url]
--
[SA28892] Ajax Simple Chat Script Insertion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-12
Aria-Security Team has reported a vulnerability in Ajax Simple Chat, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28892/\"]http://secunia.com/advisories/28892/[/url]
--
[SA28887] ITechBids "item_id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-11
SoSo H H has reported a vulnerability in ITechBids, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28887/\"]http://secunia.com/advisories/28887/[/url]
--
[SA28883] Joomla! Rapid Recipe Component Two SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-12
breaker_unit has discovered two vulnerabilities in the Rapid Recipe component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28883/\"]http://secunia.com/advisories/28883/[/url]
--
[SA28878] Apache Tomcat Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-11
Some vulnerabilities have been reported in Apache Tomcat, which can be exploited by malicious people to manipulate certain data or to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28878/\"]http://secunia.com/advisories/28878/[/url]
--
[SA28873] Journalness "last_module" PHP Code Execution
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-02-11
Iron has discovered a vulnerability in Journalness, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28873/\"]http://secunia.com/advisories/28873/[/url]
--
[SA28872] Cacti Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-02-12
Some vulnerabilities have been reported in Cacti, which can be exploited by malicious people to conduct HTTP response splitting,
cross-site scripting, and SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28872/\"]http://secunia.com/advisories/28872/[/url]
--
[SA28861] Joomla! XML-RPC / Blogger API Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-11
A vulnerability has been reported in Joomla!, which can be exploited by malicious people to manipulate certain data.
Full Advisory:
[url=\"http://secunia.com/advisories/28861/\"]http://secunia.com/advisories/28861/[/url]
--
[SA28847] PHParanoid Cross-Site Request Forgery and Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass, Cross Site Scripting
Released: 2008-02-14
Some vulnerabilities have been reported in PHParanoid, which can be exploited by malicious people to conduct cross-site request forgery attacks and to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28847/\"]http://secunia.com/advisories/28847/[/url]
--
[SA28846] IEA Products Management Web Server Memory Corruption Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-11
Luigi Auriemma has discovered a vulnerability in various IEA Products, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28846/\"]http://secunia.com/advisories/28846/[/url]
--
[SA28947] Adobe Connect Enterprise Server Flash Media Server Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-02-13
Some vulnerabilities have been reported in Adobe Connect Enterprise Server, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28947/\"]http://secunia.com/advisories/28947/[/url]
--
[SA28919] F-Secure Products CAB and RAR Archives Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-13
A vulnerability has been reported in various F-Secure products, which can be exploited by malware to bypass the scanning functionality.
Full Advisory:
[url=\"http://secunia.com/advisories/28919/\"]http://secunia.com/advisories/28919/[/url]
--
[SA28900] Simple Machines Forum SMF Shoutbox Mod Script Insertion
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-12
enterth3dragon has discovered a vulnerability in the SMF Shoutbox mod for Simple Machines Forum, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28900/\"]http://secunia.com/advisories/28900/[/url]
--
[SA28899] MercuryBoard "message" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-12
Aria-Security Team have discovered a vulnerability in MercuryBoard, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28899/\"]http://secunia.com/advisories/28899/[/url]
--
[SA28884] Apache Tomcat Cookie Handling Session ID Disclosure
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-02-11
Two vulnerabilities have been reported in Apache Tomcat, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28884/\"]http://secunia.com/advisories/28884/[/url]
--
[SA28881] Loris Hotel Reservation System "hotel_name" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-11
Russ McRee has reported a vulnerability in Loris Hotel Reservation System, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28881/\"]http://secunia.com/advisories/28881/[/url]
--
[SA28876] Drupal Header Image Module Security Bypass Vulnerability
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-14
A vulnerability has been reported in the Header Image module for Drupal, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28876/\"]http://secunia.com/advisories/28876/[/url]
--
[SA28852] Serendipity Freetag Plugin Tag Name Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-11
Alexander Brachmann has reported a vulnerability in the Freetag plugin for Serendipity, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28852/\"]http://secunia.com/advisories/28852/[/url]
--
[SA28844] HP Select Identity Multiple Unspecified Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-02-08
Some vulnerabilities have been reported in HP Select Identity, which can be exploited by malicious users to bypass certain security
restrictions or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28844/\"]http://secunia.com/advisories/28844/[/url]
--
[SA28841] Sift Unity "qt" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-08
Russ McRee has reported a vulnerability in Sift Unity, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28841/\"]http://secunia.com/advisories/28841/[/url]
--
[SA28840] MODx Cross-Site Scripting and Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-08
Alexandr Polyakov and Stas Svistunovich have discovered some vulnerabilities in MODx, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28840/\"]http://secunia.com/advisories/28840/[/url]
Secunia Bulletins February 2008
Posted: Thu Feb 21, 2008 6:12 pm
by Tami
[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of February 21 2008[/b][/i]
[b]Windows:--[/b]
[SA29035] IBM Lotus Notes Java Plug-in Sandbox Security Bypass
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-20
A vulnerability has been reported in IBM Lotus Notes, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29035/\"]http://secunia.com/advisories/29035/[/url]
--
[SA29003] Now SMS/MMS Gateway HTTP/SMPP Handling Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-20
Luigi Auriemma has discovered some vulnerabilities in Now SMS/MMS Gateway, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29003/\"]http://secunia.com/advisories/29003/[/url]
--
[SA29024] SmarterMail Subject Script Insertion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-20
Juan Pablo Lopez Yacubian has discovered a vulnerability in SmarterMail, which can be exploited by malicious people to conduct
script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29024/\"]http://secunia.com/advisories/29024/[/url]
--
[SA29021] Kerio MailServer Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-19
Some vulnerabilities have been reported in Kerio MailServer, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29021/\"]http://secunia.com/advisories/29021/[/url]
--
[SA29007] webcamXP Denial of Service and Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS
Released: 2008-02-19
Luigi Auriemma has discovered a vulnerability in webcamXP, which can be exploited by malicious people to cause a DoS (Denial of Service) or to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29007/\"]http://secunia.com/advisories/29007/[/url]
--
[SA29002] freeSSHd SSH Server Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-18
Luigi Auriemma has discovered a vulnerability in freeSSHd, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29002/\"]http://secunia.com/advisories/29002/[/url]
--
[SA29011] EMC RepliStor Data Decompression Buffer Overflows
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-02-21
Some vulnerabilities have been reported in EMC RepliStor, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29011/\"]http://secunia.com/advisories/29011/[/url]
--
[SA29031] IBM Lotus Notes Java Applet Signature Execution Control List Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-20
A security issue has been reported in IBM Lotus Notes, which can be exploited by malicious people to bypass certain security mechanisms.
Full Advisory:
[url=\"http://secunia.com/advisories/29031/\"]http://secunia.com/advisories/29031/[/url]
--
[SA28984] StatCounteX "admin.asp" Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-02-18
SekoMirza has discovered a security issue in StatCounteX, which can be exploited by malicious people to bypass certain security restrictions and to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28984/\"]http://secunia.com/advisories/28984/[/url]
--
[SA29033] Symantec Veritas Storage Foundation Scheduler Service Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-21
A vulnerability has been reported in Symantec Veritas Storage Foundation, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29033/\"]http://secunia.com/advisories/29033/[/url]
--
[SA29030] Hitachi EUR Print Manager Unspecified Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-20
A vulnerability has been reported in Hitachi EUR Print Manager, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29030/\"]http://secunia.com/advisories/29030/[/url]
--
[SA29005] DESlock+ DLMFDISK.sys/DLMFENC.sys Privilege Escalation Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-02-19
mu-b has reported some vulnerabilities in DESlock+, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29005/\"]http://secunia.com/advisories/29005/[/url]
[b]UNIX/Linux:--[/b]
[SA29026] Kolab Server ClamAV Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-19
Some vulnerabilities have been reported in Kolab Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29026/\"]http://secunia.com/advisories/29026/[/url]
--
[SA29012] SWORD diatheke.pl Shell Command Injection Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-19
A vulnerability has been discovered in SWORD, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29012/\"]http://secunia.com/advisories/29012/[/url]
--
[SA29001] SUSE update for clamav
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-18
SUSE has issued an update for clamav. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29001/\"]http://secunia.com/advisories/29001/[/url]
--
[SA28989] Mandriva update for xine-lib
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-18
Mandriva has issued an update for xine-lib. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28989/\"]http://secunia.com/advisories/28989/[/url]
--
[SA28983] SUSE update for acroread
Critical: Highly critical
Where: From remote
Impact: Unknown, DoS, System access
Released: 2008-02-19
SUSE has issued an update for acroread. This fixes some vulnerabilities, some of which have unknown impacts while others can be
exploited by malicious people to cause a DoS (Denial of Service) or compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/28983/\"]http://secunia.com/advisories/28983/[/url]
--
[SA29017] LightBlog "username" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-02-19
muuratsalo has discovered a vulnerability in LightBlog, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29017/\"]http://secunia.com/advisories/29017/[/url]
--
[SA28996] Fedora update for pcre
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-19
Fedora has issued an update for pcre. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28996/\"]http://secunia.com/advisories/28996/[/url]
--
[SA28993] HP Tru64 UNIX Perl Regular Expressions Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-21
HP has acknowledged a vulnerability in HP Tru64 UNIX, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28993/\"]http://secunia.com/advisories/28993/[/url]
--
[SA28985] GNOME GLib PCRE Character Class Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-18
A vulnerability has been reported in GNOME GLib, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/28985/\"]http://secunia.com/advisories/28985/[/url]
--
[SA28994] CUPS "process_browse_data()" Double Free Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-02-20
A vulnerability has been discovered in CUPS, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/28994/\"]http://secunia.com/advisories/28994/[/url]
--
[SA29004] Lotus Quickr Unspecified Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-18
A vulnerability has been reported in Lotus Quickr, which can be exploited by malicious people to conduct cross-site scripting
attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29004/\"]http://secunia.com/advisories/29004/[/url]
--
[SA28987] Fedora update for moin
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-21
Fedora has issued an update for moin. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28987/\"]http://secunia.com/advisories/28987/[/url]
--
[SA28982] Multiple Horde Products Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-18
A security issue has been reported in multiple Horde products, which can be exploited by malicious users to bypass certain security
restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28982/\"]http://secunia.com/advisories/28982/[/url]
--
[SA29028] Hitachi SEWB3/PLATFORM Unspecified Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-20
A vulnerability has been reported in Hitachi SEWB3/PLATFORM, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29028/\"]http://secunia.com/advisories/29028/[/url]
--
[SA29009] wyrd Insecure Temporary File
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-18
A vulnerability has been discovered in wyrd, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29009/\"]http://secunia.com/advisories/29009/[/url]
--
[SA28995] Linux Kernel Multiple Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-02-19
Some vulnerabilities have been reported in the Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and potentially gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/28995/\"]http://secunia.com/advisories/28995/[/url]
--
[SA28981] Fedora update for scponly
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-18
Fedora has issued an update for scponly. This fixes a security issue, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/28981/\"]http://secunia.com/advisories/28981/[/url]
--
[SA28997] Avaya CMS Solaris X Window System Information Disclosure
Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-02-19
Avaya has acknowledged a vulnerability in Avaya CMS, which can be exploited by malicious, local users to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28997/\"]http://secunia.com/advisories/28997/[/url]
--
[SA28990] Sun Solaris vuidmice STREAMS Modules Local Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-02-18
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/28990/\"]http://secunia.com/advisories/28990/[/url]
[b]Other:[/b]
[b]Cross Platform:--[/b]
[SA29049] Netscape Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-02-21
Netscape has acknowledged some weaknesses, a security issue, and some vulnerabilities in Netscape Navigator, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29049/\"]http://secunia.com/advisories/29049/[/url]
--
[SA29047] Globsy "globsy_edit.php" Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-21
A vulnerability has been discovered an Globsy, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29047/\"]http://secunia.com/advisories/29047/[/url]
--
[SA29042] BEA JRockit Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of system
information, Exposure of sensitive information, System access
Released: 2008-02-20
Some vulnerabilities have been reported in BEA JRockit, which can be exploited by malicious people to bypass certain security restrictions, manipulate data, disclose sensitive/system information, or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29042/\"]http://secunia.com/advisories/29042/[/url]
--
[SA29010] MoinMoin Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2008-02-20
Some vulnerabilities have been reported in MoinMoin, which can be exploited by malicious people to conduct cross-site scripting attacks, to manipulate certain data, or potentially to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29010/\"]http://secunia.com/advisories/29010/[/url]
--
[SA29044] Joomla hwdVideoShare Component "cat_id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-21
S@BUN has discovered a vulnerability in the hwdVideoShare component for Joomla, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29044/\"]http://secunia.com/advisories/29044/[/url]
--
[SA29041] BEA WebLogic Products Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Hijacking, Security Bypass, Cross Site Scripting, Brute force, Exposure of system information, Exposure of sensitive
information
Released: 2008-02-20
Some vulnerabilities, security issues, and a weakness have been reported in various BEA WebLogic products, which can be exploited by malicious users to conduct script insertion attacks, and by malicious people to conduct session fixation, cross-site scripting, or brute force attacks, disclose sensitive information, or to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29041/\"]http://secunia.com/advisories/29041/[/url]
--
[SA29034] Schoolwires Academic Portal browse.asp Cross-Site Scripting and SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-02-20
Russ McRee has reported two vulnerabilities in Schoolwires Academic Portal, which can be exploited by malicious people to conduct
cross-site scripting or SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29034/\"]http://secunia.com/advisories/29034/[/url]
--
[SA29029] Opera Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information
Released: 2008-02-20
Some vulnerabilities have been reported in Opera, which can be exploited by malicious people to conduct cross-site scripting attacks, disclose sensitive information, or to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29029/\"]http://secunia.com/advisories/29029/[/url]
--
[SA29022] IBM DB2 Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, DoS
Released: 2008-02-19
Some vulnerabilities have been reported in IBM DB2, some of which have unknown impacts, while one can potentially be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29022/\"]http://secunia.com/advisories/29022/[/url]
--
[SA29018] iScripts MultiCart "productid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-21
t0pP8uZz and xprog have reported a vulnerability in iScripts MultiCart, which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29018/\"]http://secunia.com/advisories/29018/[/url]
--
[SA29008] Joomla astatsPRO Component "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Cross Site Scripting
Released: 2008-02-21
A vulnerability has been reported in the astatsPRO component for Joomla, which can be exploited by malicious people to conduct
cross-site scripting and SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29008/\"]http://secunia.com/advisories/29008/[/url]
--
[SA29006] XPWeb "Download.php" Arbitrary File Download
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-02-18
GoLd_M has discovered a vulnerability in XPWeb, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29006/\"]http://secunia.com/advisories/29006/[/url]
--
[SA28998] Joomla! jooget Component "id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-18
S@BUN has discovered a vulnerability in the jooget component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28998/\"]http://secunia.com/advisories/28998/[/url]
--
[SA28992] BanPro-DMS "action" Local File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-02-18
muuratsalo has discovered a vulnerability in BanPro-DMS, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28992/\"]http://secunia.com/advisories/28992/[/url]
--
[SA28991] BEA Products Information Disclosure Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-02-20
A vulnerability has been reported in some BEA Plumtree Collaboration and BEA AquaLogic Interaction, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/28991/\"]http://secunia.com/advisories/28991/[/url]
--
[SA28988] WordPress WP Photo Album Plugin "photo" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-20
A vulnerability has been reported in the WP Photo Album (WPPA) plugin for WordPress, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28988/\"]http://secunia.com/advisories/28988/[/url]
--
[SA28986] Joomla! Quran Component "surano" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-18
breaker_unit and Don have discovered a vulnerability in the Quran component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28986/\"]http://secunia.com/advisories/28986/[/url]
--
[SA28980] Joomla! Quiz Component "tid" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-15
S@BUN has discovered a vulnerability in the Quiz component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/28980/\"]http://secunia.com/advisories/28980/[/url]
--
[SA29050] Symantec Veritas Storage Foundation Administrator Service Buffer Overflow
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-02-21
A vulnerability has been reported in Symantec Veritas Storage Foundation, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29050/\"]http://secunia.com/advisories/29050/[/url]
--
[SA29045] Sybase SQL Anywhere MobiLink Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-02-21
Luigi Auriemma has discovered a vulnerability in Sybase MobiLink, which can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29045/\"]http://secunia.com/advisories/29045/[/url]
--
[SA29055] Invision Power Board BBCodes Script Insertion Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-21
A vulnerability has been reported in Invision Power Board, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29055/\"]http://secunia.com/advisories/29055/[/url]
--
[SA29043] PunBB Password Change and Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Brute force
Released: 2008-02-21
A vulnerability and a weakness have been discovered in PunBB, which can be exploited by malicious users to manipulate data and by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29043/\"]http://secunia.com/advisories/29043/[/url]
--
[SA29040] BEA Products "name" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-20
Jan Fry and Adrian Pastor have reported a vulnerability in BEA AquaLogic Interaction and BEA Plumtree Foundation, which can be
exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29040/\"]http://secunia.com/advisories/29040/[/url]
--
[SA29039] Tor World CGI Scripts Multiple Unspecified Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-21
Some vulnerabilities have been reported in various Tor World CGI Scripts, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29039/\"]http://secunia.com/advisories/29039/[/url]
--
[SA29023] Jinzora Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-20
Alexandr Polyakov and Stas Svistunovich have discovered some vulnerabilities in Jinzora, which can be exploited by malicious people to conduct cross-site scripting and script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29023/\"]http://secunia.com/advisories/29023/[/url]
--
[SA29020] WoltLab Burning Board "sortOrder" SQL Injection
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-20
NBBN has reported a vulnerability in WoltLab Burning Board, which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29020/\"]http://secunia.com/advisories/29020/[/url]
--
[SA29019] Lyris ListManager Security Bypass Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-20
Tyler Shields has reported some vulnerabilities in Lyris ListManager, which can be exploited by malicious users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29019/\"]http://secunia.com/advisories/29019/[/url]
--
[SA29016] ProjectPier Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-19
L4teral has reported some vulnerabilities in ProjectPier, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks, and by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29016/\"]http://secunia.com/advisories/29016/[/url]
--
[SA29015] ATutor Script Insertion Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-19
L4teral has discovered some vulnerabilities in ATutor, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29015/\"]http://secunia.com/advisories/29015/[/url]
Secunia Bulletins February 2008
Posted: Fri Feb 29, 2008 6:33 am
by Tami
[url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing For February 28 2008
[b]
Windows:--[/b]
[SA29146] 4XEM VatDecoder VatCtrl Class ActiveX Control "Url" Property Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-27
rgod has discovered a vulnerability in 4XEM VatDecoder, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29146/\"]http://secunia.com/advisories/29146/[/url]
--
[SA29145] RTSP MPEG4 SP Control ActiveX Control "Url" Property Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-27
rgod has discovered a vulnerability in RTSP MPEG4 SP Control, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29145/\"]http://secunia.com/advisories/29145/[/url]
--
[SA29138] ICQ Message Processing Format String Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-28
B0B has discovered a vulnerability in ICQ, which can be exploited by malicious people to compromise another user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29138/\"]http://secunia.com/advisories/29138/[/url]
--
[SA29131] D-Link MPEG4 SHM (Audio) Control ActiveX Control "Url" Property Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-27
rgod has discovered a vulnerability in D-Link MPEG4 SHM (Audio) Control, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29131/\"]http://secunia.com/advisories/29131/[/url]
--
[SA29109] Rising Online Virus Scanner Web Scan ActiveX Control "UpdateEngine()" Insecure Method
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-26
John Smith has discovered a vulnerability in Rising Online Virus Scanner, which can be exploited by malicious people to compromise a
user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29109/\"]http://secunia.com/advisories/29109/[/url]
--
[SA29108] Move Media Player Quantum Streaming IE Player "UploadLogs()" Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-26
Elazar Broad has discovered a vulnerability in Move Media Player, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29108/\"]http://secunia.com/advisories/29108/[/url]
--
[SA29137] NetWin WebMail Format String Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-02-27
Luigi Auriemma has reported a vulnerability in NetWin WebMail, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29137/\"]http://secunia.com/advisories/29137/[/url]
--
[SA29105] SurgeMail Format String and Buffer Overflow Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-26
Luigi Auriemma has discovered some vulnerabilities in SurgeMail, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29105/\"]http://secunia.com/advisories/29105/[/url]
--
[SA29102] Porar Webboard question.asp SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-26
xcorpitx has reported a vulnerability in Porar Webboard, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29102/\"]http://secunia.com/advisories/29102/[/url]
--
[SA29096] SurgeFTP "Content-Length" Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-26
Luigi Auriemma has discovered a vulnerability in SurgeFTP, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29096/\"]http://secunia.com/advisories/29096/[/url]
--
[SA29124] Trend Micro OfficeScan CGI Module and Policy Server Buffer Overflows
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-02-28
Luigi Auriemma has discovered some vulnerabilities in Trend Micro OfficeScan, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29124/\"]http://secunia.com/advisories/29124/[/url]
--
[SA29062] Zilab Chat and Instant Messaging Server Multiple Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-02-22
Luigi Auriemma has discovered some vulnerabilities in Zilab Chat and Instant Messaging (ZIM) Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29062/\"]http://secunia.com/advisories/29062/[/url]
--
[SA29142] AuthentiX Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-28
William Hicks and Chris Castaldo have discovered some vulnerabilities in AuthentiX, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29142/\"]http://secunia.com/advisories/29142/[/url]
--
[SA29151] Trend Micro OfficeScan 8.0 Policy Server Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-28
Luigi Auriemma has discovered a vulnerability in Trend Micro OfficeScan, which can be exploited by malicious people to cause a DoS
(Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29151/\"]http://secunia.com/advisories/29151/[/url]
--
[SA29075] Double-Take for Windows Information Disclosure and Denial of Service
Critical: Less critical
Where: From local network
Impact: Exposure of system information, DoS
Released: 2008-02-25
Luigi Auriemma has reported some vulnerabilities in Double-Take for Windows, which can be exploited by malicious people to disclose system information and cause a DoS (Denial of Service)
Full Advisory:
[url=\"http://secunia.com/advisories/29075/\"]http://secunia.com/advisories/29075/[/url]
--
[SA29117] VMware Products Shared Folders Directory Traversal Vulnerability
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-26
Gerardo Richarte has reported a vulnerability in VMware products, which can be exploited by malicious, local users or malicious applications to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29117/\"]http://secunia.com/advisories/29117/[/url]
[b]UNIX/Linux:--[/b]
[SA29141] Gentoo update for xine-lib
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-27
Gentoo has issued an update in xine-lib. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29141/\"]http://secunia.com/advisories/29141/[/url]
--
[SA29135] Debian update for ghostscript
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-28
Debian has issued an update for ghostscript. This fixes a vulnerability, which can be exploited by malicious people to compromise
a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29135/\"]http://secunia.com/advisories/29135/[/url]
--
[SA29115] Fedora update for sword
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-26
Fedora has issued an update for sword. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29115/\"]http://secunia.com/advisories/29115/[/url]
--
[SA29112] Red Hat update for ghostscript
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-28
Red Hat has issued an update for ghostscript. This fixes a vulnerability, which can be exploited by malicious people to compromise
a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29112/\"]http://secunia.com/advisories/29112/[/url]
--
[SA29104] Debian update for koffice
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-26
Debian has issued an update for koffice. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29104/\"]http://secunia.com/advisories/29104/[/url]
--
[SA29094] GraphicsMagick Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-25
Some vulnerabilities have been reported in GraphicsMagick, which can be exploited by malicious people to conduct DoS (Denial of Service) attacks or compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29094/\"]http://secunia.com/advisories/29094/[/url]
--
[SA29086] Debian update for iceape
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-02-25
Debian has issued an update for iceape. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29086/\"]http://secunia.com/advisories/29086/[/url]
--
[SA29065] Red Hat update for acroread
Critical: Highly critical
Where: From remote
Impact: Unknown, Hijacking, DoS, System access
Released: 2008-02-25
Red Hat has issued an update for acroread. This fixes some vulnerabilities, some of which have unknown impacts, while others can
be exploited by malicious people to conduct cross-site request forgery attacks, cause a DoS (Denial of Service), or compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29065/\"]http://secunia.com/advisories/29065/[/url]
--
[SA29060] Gentoo udpate for clamav
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-22
Gentoo has issued an update for clamav. This fixes some vulnerabilities, which can be exploited to cause a DoS (Denial of
Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29060/\"]http://secunia.com/advisories/29060/[/url]
--
[SA29161] IBM AIX libc "inet_network()" Off-By-One Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-28
IBM has acknowledged a vulnerability in AIX, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29161/\"]http://secunia.com/advisories/29161/[/url]
--
[SA29157] Red Hat update for gd
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-28
Red Hat has issued an update for gd. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29157/\"]http://secunia.com/advisories/29157/[/url]
--
[SA29130] Apple Mac OS X "ipcomp6_input()" Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-27
A vulnerability has been reported in Apple Mac OS X, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29130/\"]http://secunia.com/advisories/29130/[/url]
--
[SA29100] Sun Solaris Firewall Security Bypass and Denial of Service
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS
Released: 2008-02-25
Sun has acknowledged a vulnerability in Solaris, which can be exploited by malicious people to bypass certain security restrictions and cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29100/\"]http://secunia.com/advisories/29100/[/url]
--
[SA29085] Gentoo update for python
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-25
Gentoo has issued an update for python. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29085/\"]http://secunia.com/advisories/29085/[/url]
--
[SA29079] Red Hat update for netpbm
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-28
Red Hat has issued an update for netpbm. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29079/\"]http://secunia.com/advisories/29079/[/url]
--
[SA29078] OpenBSD Two Denial of Service Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-25
Two vulnerabilities have been reported in OpenBSD, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29078/\"]http://secunia.com/advisories/29078/[/url]
--
[SA29074] Solaris 10 Perl Regular Expressions Unicode Data Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-22
Sun has acknowledged a vulnerability in Solaris, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29074/\"]http://secunia.com/advisories/29074/[/url]
--
[SA29070] Red Hat update for tcltk
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-22
Red Hat has issued an update for tcltk. This fixes some vulnerabilities, which can be exploited by malicious users to cause a
DoS (Denial of Service) and potentially by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/29070/\"]http://secunia.com/advisories/29070/[/url]
--
[SA29069] Red Hat update for tk
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-22
Red Hat has issued an update for tk. This fixes some vulnerabilities, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/29069/\"]http://secunia.com/advisories/29069/[/url]
--
[SA29066] lighttpd File Descriptor Array Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-22
A vulnerability has been reported in lighttpd, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29066/\"]http://secunia.com/advisories/29066/[/url]
--
[SA29120] Fedora update for cups
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-02-26
Fedora has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29120/\"]http://secunia.com/advisories/29120/[/url]
--
[SA29127] DNSSEC-Tools libval Validation Algorithm Security Issue
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-26
A security issue has been reported in DNSSEC-Tools, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29127/\"]http://secunia.com/advisories/29127/[/url]
--
[SA29114] Maian Cart "keywords" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-28
Russ McRee has discovered a vulnerability in Maian Cart, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29114/\"]http://secunia.com/advisories/29114/[/url]
--
[SA29095] Fedora update for dnssec-tools
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-26
Fedora has issued an update for dnssec-tools. This fixes a security issue, which can be exploited by malicious people to bypass certain
security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29095/\"]http://secunia.com/advisories/29095/[/url]
--
[SA29083] Mandriva update for nss_ldap
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-25
Mandriva has issued an update for nss_ldap. This fixes a security issue, which can be exploited by malicious people to manipulate certain data.
Full Advisory:
[url=\"http://secunia.com/advisories/29083/\"]http://secunia.com/advisories/29083/[/url]
--
[SA29071] Debian update for turba2
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-25
Debian has issued an update for turba2. This fixes a security issue, which can be exploited by malicious users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29071/\"]http://secunia.com/advisories/29071/[/url]
--
[SA29058] Debian update for kernel
Critical: Less critical
Where: From remote
Impact: Unknown, Security Bypass, Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-02-25
Debian has issued an update for kernel-2.4.27 and kernel-2.6.8. This fixes some weaknesses, security issues, and vulnerabilities, where one has an unknown impact, and others can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, bypass certain security restrictions, and gain escalated privileges, and by malicious people to cause a DoS.
Full Advisory:
[url=\"http://secunia.com/advisories/29058/\"]http://secunia.com/advisories/29058/[/url]
--
[SA29132] Mandriva update for cups
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-28
Mandriva has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29132/\"]http://secunia.com/advisories/29132/[/url]
--
[SA29087] Red Hat update for cups
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-25
Red Hat has issued an update for cups. This fixes two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29087/\"]http://secunia.com/advisories/29087/[/url]
--
[SA29068] Red Hat update for openldap
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-22
Red Hat has issued an update for openldap. This fixes some vulnerabilities, which can be exploited by malicious users to cause a
DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29068/\"]http://secunia.com/advisories/29068/[/url]
--
[SA29067] Red Hat update for cups
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-02-22
Red Hat has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29067/\"]http://secunia.com/advisories/29067/[/url]
--
[SA29160] Red Hat update for dbus
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-28
Red Hat has issued an update for dbus. This fixes a security issue, which can be exploited by malicious, local users to bypass certain
security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29160/\"]http://secunia.com/advisories/29160/[/url]
--
[SA29148] D-Bus "send_interface" Security Policy Bypass
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-28
A security issue has been reported in D-Bus, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29148/\"]http://secunia.com/advisories/29148/[/url]
--
[SA29139] IBM AIX X Server Multiple Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation
Released: 2008-02-28
IBM has acknowledged some vulnerabilities in AIX, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29139/\"]http://secunia.com/advisories/29139/[/url]
--
[SA29113] Fedora update for wyrd
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-26
Fedora has issued an update for wyrd. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29113/\"]http://secunia.com/advisories/29113/[/url]
--
[SA29111] Symark PowerBroker Client Binaries Buffer Overflow Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-27
Michael Ligh and Greg Sinclair have reported some vulnerabilities in Symark PowerBroker, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29111/\"]http://secunia.com/advisories/29111/[/url]
--
[SA29080] SplitVT "xprop" Privilege Escalation Security Issue
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-22
A security issue has been reported in SplitVT, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29080/\"]http://secunia.com/advisories/29080/[/url]
--
[SA29064] Debian update for splitvt
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-22
Debian has issued an update for splitvt. This fixes a security issue, which can be exploited by malicious, local users to gain escalated
privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29064/\"]http://secunia.com/advisories/29064/[/url]
--
[SA29059] Debian update for dspam
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-02-22
Debian has issued an update for dspam. This fixes a security issue, which can be exploited by malicious, local users to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29059/\"]http://secunia.com/advisories/29059/[/url]
--
[SA29136] Fedora update for kvm
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-26
Fedora has issued an update for kvm. This fixes a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29136/\"]http://secunia.com/advisories/29136/[/url]
--
[SA29129] KVM Block Device Backend Security Bypass
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-26
A vulnerability has been reported in KVM, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29129/\"]http://secunia.com/advisories/29129/[/url]
--
[SA29097] Net Activity Viewer Privilege Escalation Security Issue
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-25
A security issue has been reported in Net Activity Viewer, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29097/\"]http://secunia.com/advisories/29097/[/url]
--
[SA29081] Fedora update for qemu
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-26
Fedora has issued an update for qemu. This fixes a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29081/\"]http://secunia.com/advisories/29081/[/url]
[b]Other:--[/b]
[SA29082] Cisco IP Phone 7921 Insecure PEAP Implementation
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2008-02-27
A security issue has been reported in Cisco IP Phone 7921, which potentially can be exploited by malicious people to disclose sensitive
information.
Full Advisory:
[url=\"http://secunia.com/advisories/29082/\"]http://secunia.com/advisories/29082/[/url]
[b]Cross Platform:--[/b]
[SA29153] Miro MP4 Demuxer Arbitrary Memory Overwrite
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-28
A vulnerability has been reported in Miro, which can potentially be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29153/\"]http://secunia.com/advisories/29153/[/url]
--
[SA29140] Symantec Products Symantec Decomposer RAR File Handling Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-27
Two vulnerabilities have been reported in various Symantec products, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29140/\"]http://secunia.com/advisories/29140/[/url]
--
[SA29133] Mozilla Thunderbird MIME Processing Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-27
A vulnerability has been reported in Mozilla Thunderbird, which can be exploited by malicious people to potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29133/\"]http://secunia.com/advisories/29133/[/url]
--
[SA29122] VLC Media Player MP4 Demuxer Arbitrary Memory Overwrite
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-27
A vulnerability has been reported in VLC Media Player, which can potentially be exploited by malicious people to compromise a user's
system.
Full Advisory:
[url=\"http://secunia.com/advisories/29122/\"]http://secunia.com/advisories/29122/[/url]
--
[SA29110] DBHcms "extmanager_install" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-02-26
Iron has discovered a vulnerability in DBHcms, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29110/\"]http://secunia.com/advisories/29110/[/url]
--
[SA29103] Ghostscript "zseticcspace()" Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-28
Chris Evans has reported a vulnerability in Ghostscript, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29103/\"]http://secunia.com/advisories/29103/[/url]
--
[SA29099] WordPress Sniplets Plugin Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-02-27
NBBN has discovered some vulnerabilities in the Sniplets plugin for WordPress, which can be exploited by malicious people to conduct
cross-site scripting attacks, disclose sensitive information, or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29099/\"]http://secunia.com/advisories/29099/[/url]
--
[SA29089] php Download Manager "content" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-25
BeyazKurt has discovered a vulnerability in php Download Manager, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29089/\"]http://secunia.com/advisories/29089/[/url]
--
[SA29088] Interstage Application Server Single Sign-On Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-25
A vulnerability has been reported in Interstage Application Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29088/\"]http://secunia.com/advisories/29088/[/url]
--
[SA29077] Quantum Star "CONFIG[gameroot]" File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-02-25
RoMaNcYxHaCkEr has discovered two vulnerabilities in Quantum Star: Generations, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29077/\"]http://secunia.com/advisories/29077/[/url]
--
[SA29076] phpQLAdmin "_SESSION[path]" File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-02-25
RoMaNcYxHaCkEr has reported two vulnerabilities in phpQLAdmin, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29076/\"]http://secunia.com/advisories/29076/[/url]
--
[SA29156] Wireshark Multiple Denial of Service Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-28
Some vulnerabilities have been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29156/\"]http://secunia.com/advisories/29156/[/url]
--
[SA29123] eazyPortal "session_vars" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-28
Iron has discovered a vulnerability in eazyPortal, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29123/\"]http://secunia.com/advisories/29123/[/url]
--
[SA29107] Xoops XM-Memberstats Module "letter" and "sortby" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-25
Two vulnerabilities have been discovered in the XM-Memberstats module for Xoops, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29107/\"]http://secunia.com/advisories/29107/[/url]
--
[SA29106] Joomla! "mosConfig_absolute_path" File Inclusion
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-02-25
Hendrik-Jan Verheij has discovered a vulnerability in Joomla!, which can be exploited by malicious people to compromise a vulnerable
system.
Full Advisory:
[url=\"http://secunia.com/advisories/29106/\"]http://secunia.com/advisories/29106/[/url]
--
[SA29090] Joomla! Gary's Cookbook Component "id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-25
S@BUN has discovered a vulnerability in the Gary's Cookbook component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29090/\"]http://secunia.com/advisories/29090/[/url]
--
[SA29084] H-Sphere SiteStudio Unspecified Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-02-26
A vulnerability with unknown impact has been reported in H-Sphere SiteStudio.
Full Advisory:
[url=\"http://secunia.com/advisories/29084/\"]http://secunia.com/advisories/29084/[/url]
--
[SA29073] XOOPS Tiny Event Module "id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-22
S@BUN has discovered a vulnerability in the Tiny Event module for XOOPS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29073/\"]http://secunia.com/advisories/29073/[/url]
--
[SA29063] XOOPS Prayer List Module "cid" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-22
S@BUN has discovered a vulnerability in the Prayer List module for XOOPS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29063/\"]http://secunia.com/advisories/29063/[/url]
--
[SA29061] beContent "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-02-22
Cr@zy_King has reported a vulnerability in beContent, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29061/\"]http://secunia.com/advisories/29061/[/url]
--
[SA29150] Interspire Shopping Cart "search_query" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-28
Russ McRee has reported a vulnerability in Interspire Shopping Cart, which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29150/\"]http://secunia.com/advisories/29150/[/url]
--
[SA29128] Serendipity Script Insertion and Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-27
Hanno Boeck has discovered two vulnerabilities in Serendipity, which can be exploited by malicious users to conduct cross-site scripting and script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29128/\"]http://secunia.com/advisories/29128/[/url]
--
[SA29118] Drupal Multiple Script Insertion Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-28
Some vulnerabilities have been reported in Drupal, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29118/\"]http://secunia.com/advisories/29118/[/url]
--
[SA29116] Plume CMS "dir" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-26
Omer Singer has discovered a vulnerability in Plume CMS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29116/\"]http://secunia.com/advisories/29116/[/url]
--
[SA29093] Matt's Whois "domain" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-25
Ivan Sanchez and Maximiliano Soler have reported a vulnerability in Matt's Whois, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29093/\"]http://secunia.com/advisories/29093/[/url]
--
[SA29092] TikiWiki "tiki-edit_article.php" Script Insertion Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-25
A vulnerability has been reported in TikiWiki, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29092/\"]http://secunia.com/advisories/29092/[/url]
--
[SA29072] IBM Lotus Quickr/QuickPlace Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-25
Nir Goldshlager (Avnet) has reported a vulnerability in IBM Lotus Quickr/QuickPlace, which can be exploited by malicious people to
conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29072/\"]http://secunia.com/advisories/29072/[/url]