Secunia Security Updates - May 2008
Posted: Fri May 02, 2008 4:55 pm
[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of May 2 2008[/b][/i]
[b]Windows:--[/b]
[SA30037] Akamai Download Manager Code Execution Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-01
A vulnerability has been reported in Akamai Download Manager, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30037/\"]http://secunia.com/advisories/30037/[/url]
--
[SA29990] E-Post Mail Server POP3 Password Disclosure Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-04-28
Tan Chew Keong has reported a vulnerability in E-Post Mail Server, which can be exploited by malicious people to disclose sensitive
information.
Full Advisory:
[url=\"http://secunia.com/advisories/29990/\"]http://secunia.com/advisories/29990/[/url]
--
[SA29979] MegaBBS SQL Injection and Cross-Site Scripting Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-04-28
AmnPardaz Security Research Team have reported some vulnerabilities in MegaBBS, which can be exploited by malicious users to conduct SQL injection attacks and by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29979/\"]http://secunia.com/advisories/29979/[/url]
--
[SA30036] SNMPc "SNMP TRAP" Packet Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-05-01
Wade Alcorn and John Heasman have reported a vulnerability in SNMPc, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30036/\"]http://secunia.com/advisories/30036/[/url]
--
[SA30007] Rising Antivirus "NtOpenProcess()" Hooked Function Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-04-29
Core Security Technologies has reported a vulnerability in Rising Antivirus, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30007/\"]http://secunia.com/advisories/30007/[/url]
--
[SA30006] Comodo Firewall Pro Hooked Functions Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-04-29
Core Security Technologies has reported some vulnerabilities in Comodo Firewall Pro, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30006/\"]http://secunia.com/advisories/30006/[/url]
--
[SA30005] BitDefender Antivirus 2008 "NtOpenProcess()" Hooked Function Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-04-29
Core Security Technologies has reported a vulnerability in BitDefender Antivirus 2008, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30005/\"]http://secunia.com/advisories/30005/[/url]
--
[SA29996] Sophos Anti-Virus "NtCreateKey()" Hooked Function Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-04-29
Core Security Technologies has reported a vulnerability in Sophos Anti-Virus, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29996/\"]http://secunia.com/advisories/29996/[/url]
[b]UNIX/Linux:--[/b]
[SA30033] Fedora update for poppler
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-30
Fedora has issued an update for poppler. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30033/\"]http://secunia.com/advisories/30033/[/url]
--
[SA30029] Red Hat update for thunderbird
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-01
Red Hat has issued an update for thunderbird. This fixes a vulnerability, which can potentially be exploited by malicious people
to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30029/\"]http://secunia.com/advisories/30029/[/url]
--
[SA30021] Fedora update for xine-lib
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-30
Fedora has issued an update for xine-lib. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30021/\"]http://secunia.com/advisories/30021/[/url]
--
[SA30020] GNOME PeerCast "HTTP::getAuthUserPass()" Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-30
Nico Golde has reported a vulnerability in GNOME PeerCast, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30020/\"]http://secunia.com/advisories/30020/[/url]
--
[SA30012] Debian update for iceape
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-29
Debian has issued an update for iceape. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30012/\"]http://secunia.com/advisories/30012/[/url]
--
[SA30003] Red Hat update for java-1.5.0-bea
Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-04-28
Red Hat has issued an update for java-1.5.0-bea. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), or compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30003/\"]http://secunia.com/advisories/30003/[/url]
--
[SA30001] Fedora update for KDE4
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-30
Fedora has issued an update for KDE4. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30001/\"]http://secunia.com/advisories/30001/[/url]
--
[SA29999] Red Hat update for java-1.4.2-bea
Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-04-28
Red Hat has issued an update for java-1.4.2-bea. This fixes a vulnerability, which can be exploited by malicious people to bypass
certain security restrictions and potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29999/\"]http://secunia.com/advisories/29999/[/url]
--
[SA29994] Fedora update for wordpress
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, System access
Released: 2008-04-30
Fedora has issued an update for wordpress. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting attacks, bypass certain security restrictions, and to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29994/\"]http://secunia.com/advisories/29994/[/url]
--
[SA29980] KDE KHTML PNG Processing Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-28
A vulnerability has been reported in KDE, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29980/\"]http://secunia.com/advisories/29980/[/url]
--
[SA30032] Fedora update for squid
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-04-30
Fedora has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30032/\"]http://secunia.com/advisories/30032/[/url]
--
[SA30031] Fedora update for moin
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-04-30
Fedora has issued an update for moin. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks and bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30031/\"]http://secunia.com/advisories/30031/[/url]
--
[SA30030] Fedora update for perl-Imager
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-30
Fedora has issued an update for perl-Imager. This fixes a vulnerability, which potentially can be exploited by malicious people
to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30030/\"]http://secunia.com/advisories/30030/[/url]
--
[SA30025] Fedora update for perl
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-30
Fedora has issued an update for perl. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30025/\"]http://secunia.com/advisories/30025/[/url]
--
[SA30023] Fedora update for lighttpd
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-04-30
Fedora has issued an update for lighttpd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30023/\"]http://secunia.com/advisories/30023/[/url]
--
[SA30011] Imager Image-Based Fill Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-29
A vulnerability has been reported in Imager, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30011/\"]http://secunia.com/advisories/30011/[/url]
--
[SA30009] Slackware update for libpng
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-04-29
Slackware has issued an update for libpng. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose potentially sensitive information, or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30009/\"]http://secunia.com/advisories/30009/[/url]
--
[SA29995] ZoneMinder Unspecified Code Execution Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-04-28
Some vulnerabilities have been reported in ZoneMinder, which potentially can be exploited by malicious users to compromise a
vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29995/\"]http://secunia.com/advisories/29995/[/url]
--
[SA29992] rPath update for libpng
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-04-30
rPath has issued an update for libpng. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose potentially sensitive information, or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/29992/\"]http://secunia.com/advisories/29992/[/url]
--
[SA29984] Fedora update for dbmail
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-04-30
Fedora has issued an update for dbmail. This fixes a vulnerability,
which can be exploited by malicious people to bypass certain security
restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29984/\"]http://secunia.com/advisories/29984/[/url]
--
[SA29976] IBM WebSphere Application Server Java Plugin Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-05-01
A vulnerability has been reported in IBM WebSphere Application Server, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29976/\"]http://secunia.com/advisories/29976/[/url]
--
[SA29986] HP-UX WBEM Services OpenPegasus PAM Module Buffer Overflows
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-04-30
HP has acknowledged some vulnerabilities in HP-UX, which can potentially be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29986/\"]http://secunia.com/advisories/29986/[/url]
--
[SA30027] cPanel Cross-Site Request Forgery Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-01
Some vulnerabilities have been reported in cPanel, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30027/\"]http://secunia.com/advisories/30027/[/url]
--
[SA30013] Debian update for wordpress
Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-05-02
Debian has issued an update for wordpress. This fixes a vulnerability, which can potentially be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30013/\"]http://secunia.com/advisories/30013/[/url]
--
[SA30004] miniBB "whatus" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-29
IRCRASH has discovered a vulnerability in miniBB, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30004/\"]http://secunia.com/advisories/30004/[/url]
--
[SA29988] Sun Solaris Apache Modules Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-28
Sun has acknowledged some vulnerabilities in Solaris, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29988/\"]http://secunia.com/advisories/29988/[/url]
--
[SA30042] Debian update for asterisk
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-05-01
Debian has issued an update for asterisk. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30042/\"]http://secunia.com/advisories/30042/[/url]
--
[SA30010] Fedora update for asterisk
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-04-30
Fedora has issued an update for asterisk. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30010/\"]http://secunia.com/advisories/30010/[/url]
--
[SA30044] Linux Kernel Multiple Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-05-02
Some vulnerabilities have been reported in the Linux kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to potentially gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30044/\"]http://secunia.com/advisories/30044/[/url]
--
[SA30018] Debian update for kernel
Critical: Less critical
Where: Local system
Impact: Security Bypass, Privilege escalation, DoS
Released: 2008-05-02
Debian has issued an update for the kernel. This fixes some vulnerabilities and security issues, which can be exploited by
malicious, local users to bypass certain security restrictions, cause a DoS (Denial of Service), or to potentially gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30018/\"]http://secunia.com/advisories/30018/[/url]
--
[SA29977] Gentoo update for kde
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-04-29
Gentoo has issued an update for kdelibs. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to potentially gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29977/\"]http://secunia.com/advisories/29977/[/url]
--
[SA30014] util-linux-ng "login" Audit Log Injection Weakness
Critical: Not critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-29
A weakness has been reported in util-linux-ng, which can be exploited by malicious people to manipulate certain data.
Full Advisory:
[url=\"http://secunia.com/advisories/30014/\"]http://secunia.com/advisories/30014/[/url]
--
[SA30008] GraphicsMagick Insecure File Extension Processing
Critical: Not critical
Where: From remote
Impact: Security Bypass
Released: 2008-05-02
A security issue has been reported in GraphicsMagick, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30008/\"]http://secunia.com/advisories/30008/[/url]
--
[SA29982] Fedora update for util-linux-ng
Critical: Not critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-30
Fedora has issued an update for util-linux-ng. This fixes a weakness, which can be exploited by malicious people to manipulate certain data.
Full Advisory:
[url=\"http://secunia.com/advisories/29982/\"]http://secunia.com/advisories/29982/[/url]
[b]Other:--[/b]
[SA30054] ALAXALA Networks AX Series BGP UPDATE Message Processing
Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-05-02
A vulnerability has been reported in ALAXALA Networks AX series, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30054/\"]http://secunia.com/advisories/30054/[/url]
--
[SA30038] Nortel Multimedia Communication Server PC Client Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-05-01
A vulnerability has been reported in Nortel Multimedia Communication Server (MCS), which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30038/\"]http://secunia.com/advisories/30038/[/url]
--
[SA30028] Hitachi GR Series BGP UPDATE Message Processing Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-05-02
A vulnerability has been reported in Hitachi GR series routers, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30028/\"]http://secunia.com/advisories/30028/[/url]
--
[SA30026] Motorola Surfboard Cable Modem Web Interface Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-30
Rook Security has reported a vulnerability in Motorola Surfboard Cable Modem, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30026/\"]http://secunia.com/advisories/30026/[/url]
[b]Cross Platform:--[/b]
[SA30022] Harris WapChat Multiple File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-05-02
k1n9k0ng has discovered some vulnerabilities in Harris WapChat, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30022/\"]http://secunia.com/advisories/30022/[/url]
--
[SA29989] PhpGedView Unspecified Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-29
A vulnerability has been reported in PhpGedView, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29989/\"]http://secunia.com/advisories/29989/[/url]
--
[SA29987] Sun StarOffice/StarSuite Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-28
Sun has acknowledged some vulnerabilities in Sun StarOffice and StarSuite, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29987/\"]http://secunia.com/advisories/29987/[/url]
--
[SA29978] Sun Java System Directory Server "bind-dn" Security Bypass
Critical: Highly critical
Where: From remote
Impact: Security Bypass
Released: 2008-04-28
Sun has acknowledged a vulnerability in Sun Java System Directory Server, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29978/\"]http://secunia.com/advisories/29978/[/url]
--
[SA30052] ActualAnalyzer Lite "style" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-05-02
IRCRASH has discovered a vulnerability in ActualAnalyzer, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30052/\"]http://secunia.com/advisories/30052/[/url]
--
[SA30048] PHP Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass, DoS, System access
Released: 2008-05-02
Some vulnerabilities have been reported in PHP, where some have unknown impacts and others can be exploited by malicious users to bypass certain security restrictions, and potentially by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30048/\"]http://secunia.com/advisories/30048/[/url]
--
[SA30046] vlbook Cross-Site Scripting and Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-05-02
IRCRASH has reported two vulnerabilities in vlbook, which can be exploited by malicious people to conduct cross-site scripting attacks or disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30046/\"]http://secunia.com/advisories/30046/[/url]
--
[SA30043] Robocode AWT Event Queue Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-05-02
A security issue has been reported in Robocode, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30043/\"]http://secunia.com/advisories/30043/[/url]
--
[SA30015] Project-Based Calendaring System File Disclosure Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-05-01
GoLd_M has discovered some vulnerabilities in Project-Based Calendaring System, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30015/\"]http://secunia.com/advisories/30015/[/url]
--
[SA29997] miniBB Cross-Site Scripting and SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-04-28
__GiReX__ has reported some vulnerabilities in miniBB, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29997/\"]http://secunia.com/advisories/29997/[/url]
--
[SA29991] Joovili "category" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-29
HaCkeR-EgY has reported a vulnerability in Joovili, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29991/\"]http://secunia.com/advisories/29991/[/url]
--
[SA29985] WebGUI Data Form List View Unspecified Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-05-02
A vulnerability with an unknown impact has been reported in WebGUI.
Full Advisory:
[url=\"http://secunia.com/advisories/29985/\"]http://secunia.com/advisories/29985/[/url]
--
[SA29983] Softbiz Web Host Directory Script "host_id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-30
M.Hasran Addahroni has reported a vulnerability in Softbiz Web Host Directory Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29983/\"]http://secunia.com/advisories/29983/[/url]
--
[SA29981] Jokes Site Script "catagorie" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-29
ProgenTR has reported a vulnerability in Jokes Site Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29981/\"]http://secunia.com/advisories/29981/[/url]
--
[SA30049] Mjguest "level" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-02
IRCRASH has discovered a vulnerability in Mjguest, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30049/\"]http://secunia.com/advisories/30049/[/url]
--
[SA30002] Sugar Community Edition RSS Module Information Disclosure Vulnerability
Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-04-29
Roberto Suggi Liverani has reported a vulnerability in Sugar Community Edition, which can be exploited by malicious users to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30002/\"]http://secunia.com/advisories/30002/[/url]
--
[SA29993] XOOPS Various Bluemoon inc. Modules Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-28
Some vulnerabilities have been reported in various Bluemoon inc. modules for XOOPS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29993/\"]http://secunia.com/advisories/29993/[/url]
[b]Windows:--[/b]
[SA30037] Akamai Download Manager Code Execution Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-05-01
A vulnerability has been reported in Akamai Download Manager, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30037/\"]http://secunia.com/advisories/30037/[/url]
--
[SA29990] E-Post Mail Server POP3 Password Disclosure Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-04-28
Tan Chew Keong has reported a vulnerability in E-Post Mail Server, which can be exploited by malicious people to disclose sensitive
information.
Full Advisory:
[url=\"http://secunia.com/advisories/29990/\"]http://secunia.com/advisories/29990/[/url]
--
[SA29979] MegaBBS SQL Injection and Cross-Site Scripting Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-04-28
AmnPardaz Security Research Team have reported some vulnerabilities in MegaBBS, which can be exploited by malicious users to conduct SQL injection attacks and by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29979/\"]http://secunia.com/advisories/29979/[/url]
--
[SA30036] SNMPc "SNMP TRAP" Packet Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-05-01
Wade Alcorn and John Heasman have reported a vulnerability in SNMPc, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30036/\"]http://secunia.com/advisories/30036/[/url]
--
[SA30007] Rising Antivirus "NtOpenProcess()" Hooked Function Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-04-29
Core Security Technologies has reported a vulnerability in Rising Antivirus, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30007/\"]http://secunia.com/advisories/30007/[/url]
--
[SA30006] Comodo Firewall Pro Hooked Functions Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-04-29
Core Security Technologies has reported some vulnerabilities in Comodo Firewall Pro, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30006/\"]http://secunia.com/advisories/30006/[/url]
--
[SA30005] BitDefender Antivirus 2008 "NtOpenProcess()" Hooked Function Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-04-29
Core Security Technologies has reported a vulnerability in BitDefender Antivirus 2008, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30005/\"]http://secunia.com/advisories/30005/[/url]
--
[SA29996] Sophos Anti-Virus "NtCreateKey()" Hooked Function Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-04-29
Core Security Technologies has reported a vulnerability in Sophos Anti-Virus, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29996/\"]http://secunia.com/advisories/29996/[/url]
[b]UNIX/Linux:--[/b]
[SA30033] Fedora update for poppler
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-30
Fedora has issued an update for poppler. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30033/\"]http://secunia.com/advisories/30033/[/url]
--
[SA30029] Red Hat update for thunderbird
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-05-01
Red Hat has issued an update for thunderbird. This fixes a vulnerability, which can potentially be exploited by malicious people
to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30029/\"]http://secunia.com/advisories/30029/[/url]
--
[SA30021] Fedora update for xine-lib
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-30
Fedora has issued an update for xine-lib. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30021/\"]http://secunia.com/advisories/30021/[/url]
--
[SA30020] GNOME PeerCast "HTTP::getAuthUserPass()" Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-30
Nico Golde has reported a vulnerability in GNOME PeerCast, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30020/\"]http://secunia.com/advisories/30020/[/url]
--
[SA30012] Debian update for iceape
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-29
Debian has issued an update for iceape. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30012/\"]http://secunia.com/advisories/30012/[/url]
--
[SA30003] Red Hat update for java-1.5.0-bea
Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-04-28
Red Hat has issued an update for java-1.5.0-bea. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), or compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30003/\"]http://secunia.com/advisories/30003/[/url]
--
[SA30001] Fedora update for KDE4
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-30
Fedora has issued an update for KDE4. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30001/\"]http://secunia.com/advisories/30001/[/url]
--
[SA29999] Red Hat update for java-1.4.2-bea
Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-04-28
Red Hat has issued an update for java-1.4.2-bea. This fixes a vulnerability, which can be exploited by malicious people to bypass
certain security restrictions and potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29999/\"]http://secunia.com/advisories/29999/[/url]
--
[SA29994] Fedora update for wordpress
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, System access
Released: 2008-04-30
Fedora has issued an update for wordpress. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting attacks, bypass certain security restrictions, and to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29994/\"]http://secunia.com/advisories/29994/[/url]
--
[SA29980] KDE KHTML PNG Processing Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-28
A vulnerability has been reported in KDE, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29980/\"]http://secunia.com/advisories/29980/[/url]
--
[SA30032] Fedora update for squid
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-04-30
Fedora has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30032/\"]http://secunia.com/advisories/30032/[/url]
--
[SA30031] Fedora update for moin
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-04-30
Fedora has issued an update for moin. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks and bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30031/\"]http://secunia.com/advisories/30031/[/url]
--
[SA30030] Fedora update for perl-Imager
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-30
Fedora has issued an update for perl-Imager. This fixes a vulnerability, which potentially can be exploited by malicious people
to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30030/\"]http://secunia.com/advisories/30030/[/url]
--
[SA30025] Fedora update for perl
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-30
Fedora has issued an update for perl. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30025/\"]http://secunia.com/advisories/30025/[/url]
--
[SA30023] Fedora update for lighttpd
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-04-30
Fedora has issued an update for lighttpd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30023/\"]http://secunia.com/advisories/30023/[/url]
--
[SA30011] Imager Image-Based Fill Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-29
A vulnerability has been reported in Imager, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30011/\"]http://secunia.com/advisories/30011/[/url]
--
[SA30009] Slackware update for libpng
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-04-29
Slackware has issued an update for libpng. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose potentially sensitive information, or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30009/\"]http://secunia.com/advisories/30009/[/url]
--
[SA29995] ZoneMinder Unspecified Code Execution Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-04-28
Some vulnerabilities have been reported in ZoneMinder, which potentially can be exploited by malicious users to compromise a
vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29995/\"]http://secunia.com/advisories/29995/[/url]
--
[SA29992] rPath update for libpng
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-04-30
rPath has issued an update for libpng. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose potentially sensitive information, or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/29992/\"]http://secunia.com/advisories/29992/[/url]
--
[SA29984] Fedora update for dbmail
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-04-30
Fedora has issued an update for dbmail. This fixes a vulnerability,
which can be exploited by malicious people to bypass certain security
restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29984/\"]http://secunia.com/advisories/29984/[/url]
--
[SA29976] IBM WebSphere Application Server Java Plugin Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-05-01
A vulnerability has been reported in IBM WebSphere Application Server, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29976/\"]http://secunia.com/advisories/29976/[/url]
--
[SA29986] HP-UX WBEM Services OpenPegasus PAM Module Buffer Overflows
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-04-30
HP has acknowledged some vulnerabilities in HP-UX, which can potentially be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29986/\"]http://secunia.com/advisories/29986/[/url]
--
[SA30027] cPanel Cross-Site Request Forgery Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-01
Some vulnerabilities have been reported in cPanel, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30027/\"]http://secunia.com/advisories/30027/[/url]
--
[SA30013] Debian update for wordpress
Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-05-02
Debian has issued an update for wordpress. This fixes a vulnerability, which can potentially be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30013/\"]http://secunia.com/advisories/30013/[/url]
--
[SA30004] miniBB "whatus" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-29
IRCRASH has discovered a vulnerability in miniBB, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30004/\"]http://secunia.com/advisories/30004/[/url]
--
[SA29988] Sun Solaris Apache Modules Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-28
Sun has acknowledged some vulnerabilities in Solaris, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29988/\"]http://secunia.com/advisories/29988/[/url]
--
[SA30042] Debian update for asterisk
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-05-01
Debian has issued an update for asterisk. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30042/\"]http://secunia.com/advisories/30042/[/url]
--
[SA30010] Fedora update for asterisk
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-04-30
Fedora has issued an update for asterisk. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30010/\"]http://secunia.com/advisories/30010/[/url]
--
[SA30044] Linux Kernel Multiple Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-05-02
Some vulnerabilities have been reported in the Linux kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to potentially gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30044/\"]http://secunia.com/advisories/30044/[/url]
--
[SA30018] Debian update for kernel
Critical: Less critical
Where: Local system
Impact: Security Bypass, Privilege escalation, DoS
Released: 2008-05-02
Debian has issued an update for the kernel. This fixes some vulnerabilities and security issues, which can be exploited by
malicious, local users to bypass certain security restrictions, cause a DoS (Denial of Service), or to potentially gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30018/\"]http://secunia.com/advisories/30018/[/url]
--
[SA29977] Gentoo update for kde
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-04-29
Gentoo has issued an update for kdelibs. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to potentially gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29977/\"]http://secunia.com/advisories/29977/[/url]
--
[SA30014] util-linux-ng "login" Audit Log Injection Weakness
Critical: Not critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-29
A weakness has been reported in util-linux-ng, which can be exploited by malicious people to manipulate certain data.
Full Advisory:
[url=\"http://secunia.com/advisories/30014/\"]http://secunia.com/advisories/30014/[/url]
--
[SA30008] GraphicsMagick Insecure File Extension Processing
Critical: Not critical
Where: From remote
Impact: Security Bypass
Released: 2008-05-02
A security issue has been reported in GraphicsMagick, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30008/\"]http://secunia.com/advisories/30008/[/url]
--
[SA29982] Fedora update for util-linux-ng
Critical: Not critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-30
Fedora has issued an update for util-linux-ng. This fixes a weakness, which can be exploited by malicious people to manipulate certain data.
Full Advisory:
[url=\"http://secunia.com/advisories/29982/\"]http://secunia.com/advisories/29982/[/url]
[b]Other:--[/b]
[SA30054] ALAXALA Networks AX Series BGP UPDATE Message Processing
Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-05-02
A vulnerability has been reported in ALAXALA Networks AX series, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30054/\"]http://secunia.com/advisories/30054/[/url]
--
[SA30038] Nortel Multimedia Communication Server PC Client Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-05-01
A vulnerability has been reported in Nortel Multimedia Communication Server (MCS), which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30038/\"]http://secunia.com/advisories/30038/[/url]
--
[SA30028] Hitachi GR Series BGP UPDATE Message Processing Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-05-02
A vulnerability has been reported in Hitachi GR series routers, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30028/\"]http://secunia.com/advisories/30028/[/url]
--
[SA30026] Motorola Surfboard Cable Modem Web Interface Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-30
Rook Security has reported a vulnerability in Motorola Surfboard Cable Modem, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30026/\"]http://secunia.com/advisories/30026/[/url]
[b]Cross Platform:--[/b]
[SA30022] Harris WapChat Multiple File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-05-02
k1n9k0ng has discovered some vulnerabilities in Harris WapChat, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30022/\"]http://secunia.com/advisories/30022/[/url]
--
[SA29989] PhpGedView Unspecified Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-29
A vulnerability has been reported in PhpGedView, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29989/\"]http://secunia.com/advisories/29989/[/url]
--
[SA29987] Sun StarOffice/StarSuite Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-28
Sun has acknowledged some vulnerabilities in Sun StarOffice and StarSuite, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29987/\"]http://secunia.com/advisories/29987/[/url]
--
[SA29978] Sun Java System Directory Server "bind-dn" Security Bypass
Critical: Highly critical
Where: From remote
Impact: Security Bypass
Released: 2008-04-28
Sun has acknowledged a vulnerability in Sun Java System Directory Server, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29978/\"]http://secunia.com/advisories/29978/[/url]
--
[SA30052] ActualAnalyzer Lite "style" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-05-02
IRCRASH has discovered a vulnerability in ActualAnalyzer, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30052/\"]http://secunia.com/advisories/30052/[/url]
--
[SA30048] PHP Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass, DoS, System access
Released: 2008-05-02
Some vulnerabilities have been reported in PHP, where some have unknown impacts and others can be exploited by malicious users to bypass certain security restrictions, and potentially by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30048/\"]http://secunia.com/advisories/30048/[/url]
--
[SA30046] vlbook Cross-Site Scripting and Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-05-02
IRCRASH has reported two vulnerabilities in vlbook, which can be exploited by malicious people to conduct cross-site scripting attacks or disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30046/\"]http://secunia.com/advisories/30046/[/url]
--
[SA30043] Robocode AWT Event Queue Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-05-02
A security issue has been reported in Robocode, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30043/\"]http://secunia.com/advisories/30043/[/url]
--
[SA30015] Project-Based Calendaring System File Disclosure Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-05-01
GoLd_M has discovered some vulnerabilities in Project-Based Calendaring System, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30015/\"]http://secunia.com/advisories/30015/[/url]
--
[SA29997] miniBB Cross-Site Scripting and SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-04-28
__GiReX__ has reported some vulnerabilities in miniBB, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29997/\"]http://secunia.com/advisories/29997/[/url]
--
[SA29991] Joovili "category" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-29
HaCkeR-EgY has reported a vulnerability in Joovili, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29991/\"]http://secunia.com/advisories/29991/[/url]
--
[SA29985] WebGUI Data Form List View Unspecified Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-05-02
A vulnerability with an unknown impact has been reported in WebGUI.
Full Advisory:
[url=\"http://secunia.com/advisories/29985/\"]http://secunia.com/advisories/29985/[/url]
--
[SA29983] Softbiz Web Host Directory Script "host_id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-30
M.Hasran Addahroni has reported a vulnerability in Softbiz Web Host Directory Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29983/\"]http://secunia.com/advisories/29983/[/url]
--
[SA29981] Jokes Site Script "catagorie" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-29
ProgenTR has reported a vulnerability in Jokes Site Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29981/\"]http://secunia.com/advisories/29981/[/url]
--
[SA30049] Mjguest "level" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-05-02
IRCRASH has discovered a vulnerability in Mjguest, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30049/\"]http://secunia.com/advisories/30049/[/url]
--
[SA30002] Sugar Community Edition RSS Module Information Disclosure Vulnerability
Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-04-29
Roberto Suggi Liverani has reported a vulnerability in Sugar Community Edition, which can be exploited by malicious users to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30002/\"]http://secunia.com/advisories/30002/[/url]
--
[SA29993] XOOPS Various Bluemoon inc. Modules Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-28
Some vulnerabilities have been reported in various Bluemoon inc. modules for XOOPS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29993/\"]http://secunia.com/advisories/29993/[/url]