Page 1 of 1
Secunia Security Updates - July 2008
Posted: Thu Jul 03, 2008 11:18 pm
by Tami
[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of July 3 2008[/b][/i]
[b]Windows:--[/b]
[SA30937] Opera for Windows Unspecified Code Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-07-03
A vulnerability has been reported in Opera, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30937/\"]http://secunia.com/advisories/30937/[/url]
--
[SA30891] S.T.A.L.K.E.R.: Shadow of Chernobyl Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-30
Luigi Auriemma has reported some vulnerabilities in S.T.A.L.K.E.R.: Shadow of Chernobyl, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30891/\"]http://secunia.com/advisories/30891/[/url]
--
[SA30896] EfesTECH Shop "cat_id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-02
Dr.Kacak has reported a vulnerability in EfesTECH Shop, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30896/\"]http://secunia.com/advisories/30896/[/url]
--
[SA30880] Soldner Secret Wars Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-07-01
Luigi Auriemma has reported a vulnerability in Soldner Secret Wars, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30880/\"]http://secunia.com/advisories/30880/[/url]
--
[SA30874] Philboard Cross-Site Scripting and SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-06-30
Bl@ckbe@rD has reported some vulnerabilities in Philboard, which can be exploited by malicious people to conduct cross-site scripting and SQL
injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30874/\"]http://secunia.com/advisories/30874/[/url]
--
[SA30882] Cybozu Products Cross-Site Request Forgery Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-27
A vulnerability has been reported in Cybozu products, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30882/\"]http://secunia.com/advisories/30882/[/url]
--
[SA30876] Commtouch Enterprise Anti-Spam Gateway "PARAMS" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-06-27
Erez Metula has reported a vulnerability in Commtouch Enterprise Anti-Spam Gateway, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30876/\"]http://secunia.com/advisories/30876/[/url]
--
[SA30871] Cybozu Garoon Session Fixation and Script Insertion
Critical: Less critical
Where: From remote
Impact: Hijacking, Cross Site Scripting
Released: 2008-06-27
Some vulnerabilities have been reported in Cybozu Garoon, which can be exploited by malicious people to conduct session fixation and script
insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30871/\"]http://secunia.com/advisories/30871/[/url]
--
[SA30904] Novell Client NWFS.SYS Unspecified Vulnerability
Critical: Less critical
Where: Local system
Impact: Unknown
Released: 2008-06-30
A vulnerability with an unknown impact has been reported in Novell Client.
Full Advisory:
[url=\"http://secunia.com/advisories/30904/\"]http://secunia.com/advisories/30904/[/url]
[b]UNIX/Linux:--[/b]
[SA30903] Red Hat update for firefox
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, DoS, System access
Released: 2008-07-02
Red Hat has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, to bypass certain security restrictions, or to potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30903/\"]http://secunia.com/advisories/30903/[/url]
--
[SA30898] Ubuntu update for firefox
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, DoS, System access
Released: 2008-07-02
Ubuntu has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, to bypass certain security restrictions, or to potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30898/\"]http://secunia.com/advisories/30898/[/url]
--
[SA30894] Slackware update for ruby
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-06-30
Slackware has issued an update for ruby. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30894/\"]http://secunia.com/advisories/30894/[/url]
--
[SA30878] Red Hat update for seamonkey
Critical: Highly critical
Where: From remote
Impact: System access, DoS, Exposure of sensitive information, Spoofing, Cross Site Scripting, Security Bypass
Released: 2008-07-03
Red Hat has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, disclose sensitive information, or potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30878/\"]http://secunia.com/advisories/30878/[/url]
--
[SA30875] rPath update for ruby
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-06-27
rPath has issued an update for ruby. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive
information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30875/\"]http://secunia.com/advisories/30875/[/url]
--
[SA30867] Ubuntu update for ruby1.8
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-06-27
Ubuntu has issued an update for ruby1.8. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30867/\"]http://secunia.com/advisories/30867/[/url]
--
[SA30932] rPath update for tshark and wireshark
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS
Released: 2008-07-03
rPath has issued an update for tshark and wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to disclose
potentially sensitive information or cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30932/\"]http://secunia.com/advisories/30932/[/url]
--
[SA30929] Red Hat update for rhpki-common
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-07-03
Red Hat has issued an update for rhpki-common. This fixes a security issue, which can be exploited by malicious people to bypass certain
security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30929/\"]http://secunia.com/advisories/30929/[/url]
--
[SA30910] Debian update for sympa
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-07-02
Debian has issued an update for sympa. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30910/\"]http://secunia.com/advisories/30910/[/url]
--
[SA30887] BareNuked CMS "password" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-07-01
CWH Underground has discovered a vulnerability in BareNuked CMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30887/\"]http://secunia.com/advisories/30887/[/url]
--
[SA30868] Ubuntu update for openssl
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-06-27
Ubuntu has issued an update for openssl. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30868/\"]http://secunia.com/advisories/30868/[/url]
--
[SA30864] Gentoo update for motion
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-07-01
Gentoo has issued an update for motion. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30864/\"]http://secunia.com/advisories/30864/[/url]
--
[SA30927] Fedora update for ruby
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-07-03
Fedora has issued an update for ruby. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30927/\"]http://secunia.com/advisories/30927/[/url]
--
[SA30908] Sun Solaris 10 Tomcat Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, DoS
Released: 2008-07-01
Sun has acknowledged some vulnerabilities in Tomcat included in Sun Solaris 10, which can be exploited by malicious people to bypass
certain security restrictions, disclose potentially sensitive information, conduct cross-site scripting attacks, or to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30908/\"]http://secunia.com/advisories/30908/[/url]
--
[SA30899] Sun Solaris 9 Tomcat Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, DoS
Released: 2008-07-01
Sun has acknowledged some vulnerabilities in Tomcat included in Sun Solaris 9, which can be exploited by malicious people to bypass certain
security restrictions, disclose potentially sensitive information, conduct cross-site scripting attacks, or to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30899/\"]http://secunia.com/advisories/30899/[/url]
--
[SA30895] Fedora update for fetchmail
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-06-30
Fedora has issued an update for fetchmail. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30895/\"]http://secunia.com/advisories/30895/[/url]
--
[SA30872] Gentoo update for python
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-07-01
Gentoo has issued an update for python. This fixes some security issues, which can potentially be exploited by malicious people to
disclose sensitive information, cause a DoS (Denial of Service), or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30872/\"]http://secunia.com/advisories/30872/[/url]
--
[SA30920] Fedora update for kernel
Critical: Less critical
Where: From local network
Impact: Privilege escalation, DoS
Released: 2008-07-02
Fedora has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to
gain escalated privileges and by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30920/\"]http://secunia.com/advisories/30920/[/url]
--
[SA30917] Fedora update for openldap
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-07-03
Fedora has issued an update for openldap. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30917/\"]http://secunia.com/advisories/30917/[/url]
--
[SA30914] Fedora update for squid
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-07-03
Fedora has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30914/\"]http://secunia.com/advisories/30914/[/url]
--
[SA30901] rPath update for kernel
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-07-01
rPath has issued an update for the kernel. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30901/\"]http://secunia.com/advisories/30901/[/url]
--
[SA30890] SUSE update for kernel
Critical: Less critical
Where: From local network
Impact: Privilege escalation, DoS
Released: 2008-07-02
SUSE has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service), and by malicious, local users to cause a DoS or to potentially gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30890/\"]http://secunia.com/advisories/30890/[/url]
--
[SA30863] Sun Solaris snmpXdmid Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-06-27
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30863/\"]http://secunia.com/advisories/30863/[/url]
--
[SA30873] CheckInstall Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-06-27
Two security issues have been reported in CheckInstall, which can be exploited by malicious, local users to perform certain actions with
escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30873/\"]http://secunia.com/advisories/30873/[/url]
--
[SA30869] Debian update for dbus
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-06-27
Debian has issued an update for dbus. This fixes a security issue, which can be exploited by malicious, local users to bypass certain
security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30869/\"]http://secunia.com/advisories/30869/[/url]
--
[SA30918] Linux DC++ NULL Pointer Dereference and Incomplete Message Denial of Service
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2008-07-02
Two weaknesses have been reported in Linux DC++, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30918/\"]http://secunia.com/advisories/30918/[/url]
--
[SA30907] Fedora update for linuxdcpp
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2008-07-03
Fedora has issued an update for linuxdccp. This fixes two weaknesses, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30907/\"]http://secunia.com/advisories/30907/[/url]
[b]Other:
Cross Platform:--[/b]
[SA30915] Mozilla Thunderbird Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-02
Some vulnerabilities have been reported in Mozilla Thunderbird, which potentially can be exploited by malicious people to compromise a user's
system.
Full Advisory:
[url=\"http://secunia.com/advisories/30915/\"]http://secunia.com/advisories/30915/[/url]
--
[SA30911] Mozilla Firefox Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of system information, Exposure of sensitive information, DoS, System
access
Released: 2008-07-02
Some vulnerabilities have been reported in Mozilla Firefox, which can be exploited by malicious people to conduct cross-site scripting and
spoofing attacks, bypass certain security restrictions, disclose sensitive information, or potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30911/\"]http://secunia.com/advisories/30911/[/url]
--
[SA30905] TYPO3 WEC Discussion Forum Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2008-07-01
Some vulnerabilities have been reported in the WEC Discussion Forum (wec_discussion) extension for TYPO3, which can be exploited by
malicious people to conduct cross-site scripting attacks or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30905/\"]http://secunia.com/advisories/30905/[/url]
--
[SA30900] HIOX Banner Rotator "hm" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-07-01
Ghost Hacker has discovered a vulnerability in HIOX Banner Rotator (HBR), which can be exploited by malicious people to compromise a
vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30900/\"]http://secunia.com/advisories/30900/[/url]
--
[SA30902] AShop Deluxe "cat" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-07-02
n0c0py has reported a vulnerability in AShop Deluxe, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30902/\"]http://secunia.com/advisories/30902/[/url]
--
[SA30897] plx Ad Trader "adid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-07-02
Hussin X has reported a vulnerability in plx Ad Trader, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30897/\"]http://secunia.com/advisories/30897/[/url]
--
[SA30893] Sun Java System Access Manager XSLT Stylesheet Processing Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-06-30
A vulnerability has been reported in Sun Java Access Manager, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30893/\"]http://secunia.com/advisories/30893/[/url]
--
[SA30892] myBloggie SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-01
Jesper Jurcenoks has reported some vulnerabilities in myBloggie, which can be exploited by malicious users or people to conduct SQL injection
attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30892/\"]http://secunia.com/advisories/30892/[/url]
--
[SA30889] Pivot "t" Directory Traversal Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-07-01
Nine:Situations:Group::bookoo has reported a vulnerability in Pivot, which can be exploited by malicious people to disclose sensitive
information.
Full Advisory:
[url=\"http://secunia.com/advisories/30889/\"]http://secunia.com/advisories/30889/[/url]
--
[SA30886] Wireshark Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS
Released: 2008-07-01
Some vulnerabilities have been reported in Wireshark, which can be exploited by malicious people to disclose potentially sensitive
information or cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30886/\"]http://secunia.com/advisories/30886/[/url]
--
[SA30885] Various TYPO3 Extensions Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data, DoS
Released: 2008-07-01
Multiple vulnerabilities have been reported in various TYPO3 extensions, which can be exploited by malicious users or people to
bypass certain security restrictions, conduct SQL injection attacks or cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30885/\"]http://secunia.com/advisories/30885/[/url]
--
[SA30881] Pidgin MSN File Transfer Filename Processing Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-06-27
Juan Pablo Lopez Yacubian has discovered a vulnerability in Pidgin, which potentially can be exploited by malicious people to compromise a
user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30881/\"]http://secunia.com/advisories/30881/[/url]
--
[SA30877] eTicket "pri" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-27
Omer Singer has reported a vulnerability in eTicket, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30877/\"]http://secunia.com/advisories/30877/[/url]
--
[SA30870] testMaker PHP Code Execution Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-06-27
A vulnerability has been reported in testMaker, which can be exploited by malicious users to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30870/\"]http://secunia.com/advisories/30870/[/url]
--
[SA30866] CAT2 "spaw_root" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-07-02
StAkeR has discovered a vulnerability in CAT2, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30866/\"]http://secunia.com/advisories/30866/[/url]
--
[SA30865] SePortal SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-06-30
Mr.SQL has reported some vulnerabilities in SePortal, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30865/\"]http://secunia.com/advisories/30865/[/url]
--
[SA30862] Riddles Website "riddleid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-27
Cyb3r-1sT has discovered a vulnerability in Riddles Website, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30862/\"]http://secunia.com/advisories/30862/[/url]
--
[SA30861] Tips Website "tipid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-27
Cyb3r-1sT has discovered a vulnerability in Tips Website, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30861/\"]http://secunia.com/advisories/30861/[/url]
--
[SA30860] Jokes Website "jokeid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-27
Cyb3r-1sT has discovered a vulnerability in Jokes Website, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30860/\"]http://secunia.com/advisories/30860/[/url]
--
[SA30859] Drinks Website "drinkid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-06-27
Cyb3r-1sT has discovered a vulnerability in Drinks Website, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30859/\"]http://secunia.com/advisories/30859/[/url]
--
[SA30936] Drupal Outline Designer Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-07-03
A vulnerability has been reported in the Outline Designer module for Drupal, which can be exploited by malicious users to bypass certain
security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30936/\"]http://secunia.com/advisories/30936/[/url]
--
[SA30935] Opera Canvas Functions Information Disclosure
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-07-03
A vulnerability has been reported in Opera, which can be exploited by malicious people to potentially disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30935/\"]http://secunia.com/advisories/30935/[/url]
--
[SA30934] Drupal Tinytax taxonomy block Script Insertion Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-03
Some vulnerabilities have been reported in the Tinytax taxonomy block module for Drupal, which can be exploited by malicious users to conduct
script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30934/\"]http://secunia.com/advisories/30934/[/url]
--
[SA30933] Drupal Taxonomy Autotagger SQL Injection and Script Insertion
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-07-03
Some vulnerabilities have been reported in the Taxonomy Autotagger module for Drupal, which can be exploited by malicious users to conduct
SQL injection and script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30933/\"]http://secunia.com/advisories/30933/[/url]
--
[SA30928] Drupal Organic groups Information Disclosure and Script Insertion
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information
Released: 2008-07-03
Some vulnerabilities have been reported in the Organic groups module for Drupal, which can be exploited by malicious users to disclose
potentially sensitive information or conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30928/\"]http://secunia.com/advisories/30928/[/url]
--
[SA30924] Ruby "rb_ary_fill()" Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-07-02
Vincenzo "snagg" Iozzo has reported a vulnerability in Ruby, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30924/\"]http://secunia.com/advisories/30924/[/url]
--
[SA30923] FreeStyle Wiki Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-03
A vulnerability has been reported in FreeStyle Wiki, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30923/\"]http://secunia.com/advisories/30923/[/url]
--
[SA30919] XchangeBoard "boardID" SQL Injection Vulnerability
Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-07-03
haZl0oh has discovered a vulnerability in XchangeBoard, which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30919/\"]http://secunia.com/advisories/30919/[/url]
--
[SA30912] HP System Management Homepage Unspecified Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-02
A vulnerability has been reported in HP System Management Homepage (SMH), which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30912/\"]http://secunia.com/advisories/30912/[/url]
--
[SA30909] PHP Agenda "page" Local File Inclusion
Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-07-02
StAkeR has discovered a vulnerability in PHP Agenda, which can be exploited by malicious users to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30909/\"]http://secunia.com/advisories/30909/[/url]
--
[SA30906] TYPO3 Send-A-Card Extension Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-01
Some vulnerabilities have been reported in the Send-A-Card (sr_sendcard) extension for TYPO3, which can be exploited by malicious
people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30906/\"]http://secunia.com/advisories/30906/[/url]
--
[SA30884] TYPO3 phpMyAdmin Extension Unspecified Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-01
A vulnerability has been reported in the phpMyAdmin (phpmyadmin) extension for TYPO3, which can be exploited by malicious people to
conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30884/\"]http://secunia.com/advisories/30884/[/url]
--
[SA30879] GraphicsMagick Multiple Denial of Service Vulnerabilities
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-07-01
Some vulnerabilities have been reported in GraphicsMagick, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30879/\"]http://secunia.com/advisories/30879/[/url]
Secunia Security Updates - July 2008
Posted: Thu Jul 17, 2008 5:55 pm
by Josh
[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of July 17 2008[/b][/i]
[b]Windows:--[/b]
[SA30975] Microsoft Word Unspecified Code Execution Vulnerability
Critical: Extremely critical
Where: From remote
Impact: System access
Released: 2008-07-09
A vulnerability has been reported in Microsoft Word, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30975/\"]http://secunia.com/advisories/30975/[/url]
--
[SA31141] BlackBerry Unite! PDF Processing Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-17
A vulnerability has been reported in BlackBerry Unite!, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/31141/\"]http://secunia.com/advisories/31141/[/url]
--
[SA31095] Black Ice Document Imaging SDK "OpenGifFile()" Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-07-16
r0ut3r has discovered a vulnerability in Black Ice Document Imaging SDK, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/31095/\"]http://secunia.com/advisories/31095/[/url]
--
[SA31092] BlackBerry Enterprise Server PDF Processing Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-17
A vulnerability has been reported in BlackBerry Enterprise Server, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/31092/\"]http://secunia.com/advisories/31092/[/url]
--
[SA31087] Oracle Products Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, Privilege escalation, DoS, System access, Unknown
Released: 2008-07-16
Multiple vulnerabilities have been reported for various Oracle products. Some vulnerabilities have unknown impacts while others can be exploited by malicious, local users to gain escalated privileges, by malicious users to cause a DoS (Denial of Service), disclose sensitive information, gain escalated privileges, or compromise a vulnerable system, and by malicious people to bypass certain security restrictions or to cause a DoS.
Full Advisory:
[url=\"http://secunia.com/advisories/31087/\"]http://secunia.com/advisories/31087/[/url]
--
[SA30952] PPMate PPMedia Class ActiveX Control Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-07-16
Parvez Anwar has discovered a vulnerability in PPMate, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30952/\"]http://secunia.com/advisories/30952/[/url]
--
[SA31118] F-Prot Antivirus Multiple Denial of Service Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-07-17
Some vulnerabilities have been reported in F-Prot Antivirus, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/31118/\"]http://secunia.com/advisories/31118/[/url]
--
[SA31114] FreeStyle Wiki CGI::Session "File" Driver "CGISESSID" Directory Traversal
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-07-17
Tan Chew Keong has reported a vulnerability in FreeStyle Wiki, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/31114/\"]http://secunia.com/advisories/31114/[/url]
--
[SA31102] WinRemotePC Packet Handling Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-07-16
Shinnok has discovered a vulnerability in WinRemotePC, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/31102/\"]http://secunia.com/advisories/31102/[/url]
--
[SA31001] Adobe RoboHelp Server Cross-Site Scripting and SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Cross Site Scripting
Released: 2008-07-09
Some vulnerabilities have been reported in Adobe RoboHelp Server, which can be exploited by malicious people to conduct cross-site scripting and
SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/31001/\"]http://secunia.com/advisories/31001/[/url]
--
[SA30997] Download Accelerator Plus Import File Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-07-09
Krystian Kloskowski has discovered a vulnerability in Download Accelerator Plus, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30997/\"]http://secunia.com/advisories/30997/[/url]
--
[SA30987] Dokeos "include" Local File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, Exposure of system information
Released: 2008-07-09
A vulnerability has been reported in Dokeos, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/30987/\"]http://secunia.com/advisories/30987/[/url]
--
[SA30968] Procapita SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-14
pelzi has reported some vulnerabilities in Procapita, which can be exploited by malicious people or users to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30968/\"]http://secunia.com/advisories/30968/[/url]
--
[SA30964] Microsoft Outlook Web Access Script Insertion Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-08
Two vulnerabilities have been reported in Microsoft Outlook Web Access for Exchange Server, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30964/\"]http://secunia.com/advisories/30964/[/url]
--
[SA30953] Microsoft Windows Explorer Saved Search Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-07-08
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30953/\"]http://secunia.com/advisories/30953/[/url]
--
[SA30940] CMailServer POP3 Class ActiveX Control Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-07-07
Nine:Situations:Group::bruiser has discovered a vulnerability in CMailServer, which can be exploited by malicious users to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30940/\"]http://secunia.com/advisories/30940/[/url]
--
[SA31148] HP Select Identity Active Directory Bidirectional LDAP Connector Unauthorized Access
Critical: Moderately critical
Where: From local network
Impact: Security Bypass
Released: 2008-07-17
Some vulnerabilities have been reported in HP Select Identity Active Directory Bidirectional LDAP Connector, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/31148/\"]http://secunia.com/advisories/31148/[/url]
--
[SA31117] CGI::Session "File" Driver "CGISESSID" Directory Traversal
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-07-17
Tan Chew Keong has reported a vulnerability in CGI::Session, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/31117/\"]http://secunia.com/advisories/31117/[/url]
--
[SA30978] Xerox CentreWare Web Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-07-09
Some vulnerabilities have been reported in Xerox CentreWare Web, which can be exploited by malicious users to conduct SQL injection attacks, and by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30978/\"]http://secunia.com/advisories/30978/[/url]
--
[SA30970] Microsoft SQL Server and MSDE Multiple Vulnerabilities
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information, Privilege escalation
Released: 2008-07-08
Four vulnerabilities have been reported in Microsoft SQL Server, which can be exploited by malicious users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/30970/\"]http://secunia.com/advisories/30970/[/url]
[b]UNIX/Linux:--[/b]
[SA31132] Mozilla Firefox 3 on Mac OS X GIF File Handling Code Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-07-17
A vulnerability has been reported in Firefox 3 on Mac OS X, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/31132/\"]http://secunia.com/advisories/31132/[/url]
--
[SA31122] Red Hat update for seamonkey
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-07-16
Red Hat has issued an update for seamonkey. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable
system.
Full Advisory:
[url=\"http://secunia.com/advisories/31122/\"]http://secunia.com/advisories/31122/[/url]
--
[SA31121] Red Hat update for firefox
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, System access
Released: 2008-07-16
Red Hat has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions and disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/31121/\"]http://secunia.com/advisories/31121/[/url]
--
[SA31099] php Help Agent "content" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-07-16
BeyazKurt has discovered a vulnerability in php Help Agent, which can be exploited by malicious people to disclose sensitive information and compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/31099/\"]http://secunia.com/advisories/31099/[/url]
--
[SA31090] Red Hat update for ruby
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-15
Red Hat has issued an update for ruby. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/31090/\"]http://secunia.com/advisories/31090/[/url]
--
[SA31078] Fedora update for java-1.6.0-openjdk
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-07-15
Fedora has issued an update for java-1.6.0-openjdk. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose system information or potentially sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/31078/\"]http://secunia.com/advisories/31078/[/url]
--
[SA31076] SUSE update for MozillaFirefox
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure
of system information, Exposure of sensitive information, DoS, System
access
Released: 2008-07-14
SUSE has issued an update for MozillaFirefox. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, disclose sensitive information, or potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/31076/\"]http://secunia.com/advisories/31076/[/url]
--
[SA31069] Debian update for iceweasel
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-07-14
Debian has issued an update for iceweasel. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, disclose sensitive information, or potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/31069/\"]http://secunia.com/advisories/31069/[/url]
--
[SA31067] Red Hat update for java-1.4.2-ibm
Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-07-15
Red Hat has issued an update for java-1.4.2-ibm. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service), bypass certain security restrictions, or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/31067/\"]http://secunia.com/advisories/31067/[/url]
--
[SA31062] Red Hat update for ruby
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-15
Red Hat has issued an update for ruby. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/31062/\"]http://secunia.com/advisories/31062/[/url]
--
[SA31055] Red Hat update for java-1.5.0-sun
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-07-15
Red Hat has issued an update for java-1.5.0-sun. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose system information or potentially sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/31055/\"]http://secunia.com/advisories/31055/[/url]
--
[SA31051] SUSE update for MozillaFirefox
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-07-11
SUSE has issued an update for MozillaFirefox. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, disclose sensitive information, or potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/31051/\"]http://secunia.com/advisories/31051/[/url]
--
[SA31043] Sun Solaris Thunderbird Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, System access
Released: 2008-07-11
Sun has acknowledged some vulnerabilities in Thunderbird included in Sun Solaris, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, conduct cross-site scripting attacks, or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/31043/\"]http://secunia.com/advisories/31043/[/url]
--
[SA31035] Debian update for poppler
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-10
Debian has issued an update for poppler. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/31035/\"]http://secunia.com/advisories/31035/[/url]
--
[SA31029] Gentoo update for openoffice and openoffice-bin
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-07-10
Gentoo has issued an update for openoffice and openoffice-bin. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/31029/\"]http://secunia.com/advisories/31029/[/url]
--
[SA31023] Slackware update for seamonkey
Critical: Highly critical
Where: From remote
Impact: System access, DoS, Exposure of sensitive information, Exposure of system information, Spoofing, Cross Site Scripting, Security Bypass
Released: 2008-07-10
Slackware has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, disclose sensitive information, or potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/31023/\"]http://secunia.com/advisories/31023/[/url]
--
[SA31021] Slackware update for mozilla-firefox
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-07-10
Slackware has issued an update for mozilla-firefox. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, disclose sensitive information, or potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/31021/\"]http://secunia.com/advisories/31021/[/url]
--
[SA31020] Fedora update for java-1.7.0-icedtea
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-07-10
Fedora has issued an update for java-1.7.0-icedtea. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose system information or potentially sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/31020/\"]http://secunia.com/advisories/31020/[/url]
--
[SA31008] rPath update for firefox
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-07-09
rPath has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, disclose sensitive information, or potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/31008/\"]http://secunia.com/advisories/31008/[/url]
--
[SA31005] Fedora update for seamonkey
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-07-09
Fedora has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, disclose sensitive information, or potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/31005/\"]http://secunia.com/advisories/31005/[/url]
--
[SA31002] Gentoo update for poppler
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-09
Gentoo has issued an update for poppler. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/31002/\"]http://secunia.com/advisories/31002/[/url]
--
[SA30992] Fedora update for WebKit
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-07-09
Fedora has issued an update for WebKit. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30992/\"]http://secunia.com/advisories/30992/[/url]
--
[SA30963] Poppler "pageWidgets" Uninitialized Memory Access
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-08
A vulnerability has been reported in Poppler, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30963/\"]http://secunia.com/advisories/30963/[/url]
--
[SA30949] Fedora update for firefox
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-07-07
Fedora has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, disclose sensitive information, or potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30949/\"]http://secunia.com/advisories/30949/[/url]
--
[SA31143] HP-UX update for bind
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-17
HP has issued an update for bind. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/31143/\"]http://secunia.com/advisories/31143/[/url]
--
[SA31124] Red Hat update for php
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-07-17
Red Hat has issued an update for php. This fixes some vulnerabilities, which can be exploited by malicious users to bypass certain security restrictions, and by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/31124/\"]http://secunia.com/advisories/31124/[/url]
--
[SA31119] Red Hat update for php
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-07-16
Red Hat has issued an update for php. This fixes some vulnerabilities, which can be exploited by malicious users and malicious people to
bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/31119/\"]http://secunia.com/advisories/31119/[/url]
--
[SA31107] Ubuntu update for kernel
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, Privilege escalation, DoS, System access
Released: 2008-07-16
Ubuntu has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), bypass certain security restrictions, disclose potentially sensitive information, and gain escalated privileges, and malicious people to cause a DoS and potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/31107/\"]http://secunia.com/advisories/31107/[/url]
--
[SA31105] Debian update for gaim
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-16
Debian has issued an update for gaim. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/31105/\"]http://secunia.com/advisories/31105/[/url]
--
[SA31104] Debian update for lighttpd
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-07-16
Debian has issued an update for lighttpd. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/31104/\"]http://secunia.com/advisories/31104/[/url]
--
[SA31094] IBM AIX DNS Cache Poisoning
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-16
A vulnerability has been reported in IBM AIX, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/31094/\"]http://secunia.com/advisories/31094/[/url]
--
[SA31085] Fedora update for wireshark
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS
Released: 2008-07-15
Fedora has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information or cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/31085/\"]http://secunia.com/advisories/31085/[/url]
--
[SA31083] Scripteen Free Image Hosting Script Security Bypass and SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-07-14
Some vulnerabilities have been discovered in Scripteen Free Image Hosting Script, which can be exploited by malicious people to bypass certain security restrictions and conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/31083/\"]http://secunia.com/advisories/31083/[/url]
--
[SA31082] Fedora update for php-pecl-apc
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-07-15
Fedora has issued an update for php-pecl-apc. This fixes a vulnerability, which can be exploited by malicious users to bypass certain security restrictions and potentially by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/31082/\"]http://secunia.com/advisories/31082/[/url]
--
[SA31080] Fedora update for newsx
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-15
Fedora has issued an update for newsx. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/31080/\"]http://secunia.com/advisories/31080/[/url]
--
[SA31079] Fedora update for drupal
Critical: Moderately critical
Where: From remote
Impact: Hijacking, Cross Site Scripting, Manipulation of data
Released: 2008-07-15
Fedora has issued an update for drupal. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting, cross-site request forgery, session fixation, SQL injection, and script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/31079/\"]http://secunia.com/advisories/31079/[/url]
--
[SA31072] Gentoo update for bind
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-14
Gentoo has issued an update for bind. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/31072/\"]http://secunia.com/advisories/31072/[/url]
--
[SA31071] Maian Recipe "recipe_cookie" Security Bypass Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-07-15
S.W.A.T. has reported a vulnerability in Maian Recipe, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/31071/\"]http://secunia.com/advisories/31071/[/url]
--
[SA31060] Apple Xcode tools Vulnerability and Security Issue
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2008-07-14
A vulnerability and a security issue have been reported in Xcode tools, which can be exploited by malicious people to disclose sensitive information or to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/31060/\"]http://secunia.com/advisories/31060/[/url]
--
[SA31058] reSIProcate Long Domain Name Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-07-14
A vulnerability has been reported in reSIProcate, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/31058/\"]http://secunia.com/advisories/31058/[/url]
--
[SA31052] SUSE update for bind
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-11
SUSE has issued an update for bind. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/31052/\"]http://secunia.com/advisories/31052/[/url]
--
[SA31037] Sophos Products Zero-byte MIME Attachments Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-07-10
A vulnerability has been reported in some Sophos products, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/31037/\"]http://secunia.com/advisories/31037/[/url]
--
[SA31033] FreeBSD update for bind
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-15
FreeBSD has issued an update for bind. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/31033/\"]http://secunia.com/advisories/31033/[/url]
--
[SA31022] Slackware update for bind
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-10
Slackware has issued an update for bind. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/31022/\"]http://secunia.com/advisories/31022/[/url]
--
[SA31019] Fedora update for bind
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-10
Fedora has issued an update for bind. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/31019/\"]http://secunia.com/advisories/31019/[/url]
--
[SA31016] Red Hat update for pidgin
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-09
Red Hat has issued an update for pidgin. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/31016/\"]http://secunia.com/advisories/31016/[/url]
--
[SA31014] Sun Solaris DNS Cache Poisoning Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-09
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/31014/\"]http://secunia.com/advisories/31014/[/url]
--
[SA31011] Nominum CNS and Vantio DNS Cache Poisoning Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-09
Nominum has acknowledged a vulnerability in Nominum CNS and Vantio, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/31011/\"]http://secunia.com/advisories/31011/[/url]
--
[SA31007] rPath update for vsftpd
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-07-09
rPath has issued an update for vsftpd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/31007/\"]http://secunia.com/advisories/31007/[/url]
--
[SA30998] Ubuntu update for bind
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-09
Ubuntu has issued an update for bind. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/30998/\"]http://secunia.com/advisories/30998/[/url]
--
[SA30994] FFmpeg libavformat "str_read_packet()" Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-09
A vulnerability has been reported in FFmpeg, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30994/\"]http://secunia.com/advisories/30994/[/url]
--
[SA30993] Fedora update for sipp
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-09
Fedora has issued an update for sipp. This fixes two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30993/\"]http://secunia.com/advisories/30993/[/url]
--
[SA30990] Ubuntu update for pcre3
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-15
Ubuntu has issued an update for pcre3. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30990/\"]http://secunia.com/advisories/30990/[/url]
--
[SA30989] Debian bind DNS Cache Poisoning Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-09
Debian has acknowledged a vulnerability in bind, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/30989/\"]http://secunia.com/advisories/30989/[/url]
--
[SA30988] Debian update for bind9
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-09
Debian has issued an update for bind9. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/30988/\"]http://secunia.com/advisories/30988/[/url]
--
[SA30980] Sun Solaris 10 DNS Cache Poisoning Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-09
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/30980/\"]http://secunia.com/advisories/30980/[/url]
--
[SA30977] Red Hat update for bind
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-09
Red Hat has issued an update for bind. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/30977/\"]http://secunia.com/advisories/30977/[/url]
--
[SA30972] Gentoo update for libpcre and glib
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-08
Gentoo has issued an update for libpcre and glib. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30972/\"]http://secunia.com/advisories/30972/[/url]
--
[SA30971] Pidgin MSN SLP Message Integer Overflow Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-09
Some vulnerabilities have been reported in Pidgin, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30971/\"]http://secunia.com/advisories/30971/[/url]
--
[SA30967] SUSE Update for Multiple Packages
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of
data, DoS, System access
Released: 2008-07-07
SUSE has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious people with physical access to bypass certain security restrictions, and malicious people to conduct cross-site scripting and SQL injection attacks, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30967/\"]http://secunia.com/advisories/30967/[/url]
--
[SA30962] SUSE update for kernel
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-07-07
SUSE has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, and gain escalated privileges, and by malicious people to cause a DoS.
Full Advisory:
[url=\"http://secunia.com/advisories/30962/\"]http://secunia.com/advisories/30962/[/url]
--
[SA30961] Debian update for pcre3
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-07
Debian has issued an update for pcre3. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30961/\"]http://secunia.com/advisories/30961/[/url]
[SA30958] Fedora update for pcre
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-07
Fedora has issued an update for pcre. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30958/\"]http://secunia.com/advisories/30958/[/url]
--
[SA30945] Fedora update for glib2
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-04
Fedora has issued an update for glib2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30945/\"]http://secunia.com/advisories/30945/[/url]
--
[SA30944] GNOME Glib PCRE pcre_compile.c Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-04
A vulnerability has been reported in GNOME Glib, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially
compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/30944/\"]http://secunia.com/advisories/30944/[/url]
--
[SA30942] rPath update for wireshark
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS
Released: 2008-07-04
rPath has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information or cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30942/\"]http://secunia.com/advisories/30942/[/url]
--
[SA31057] Red Hat update for bluez-libs and bluez-utils
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-07-15
Red Hat has issued an update for bluez-libs and bluez-utils. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/31057/\"]http://secunia.com/advisories/31057/[/url]
--
[SA30957] BlueZ SDP Processing Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-07-07
A vulnerability has been reported in BlueZ, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/30957/\"]http://secunia.com/advisories/30957/[/url]
--
[SA31142] rPath update for httpd
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-17
rPath has issued an update for httpd. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/31142/\"]http://secunia.com/advisories/31142/[/url]
--
[SA31026] Gentoo update for apache
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2008-07-10
Gentoo has issued an update for apache. This fixes a some vulnerabilities, which can be exploited by malicious people to conduct cross-site request forgery attacks and cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/31026/\"]http://secunia.com/advisories/31026/[/url]
--
[SA31018] Fedora update for moodle
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-07-09
Fedora has issued an update for moodle. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/31018/\"]http://secunia.com/advisories/31018/[/url]
--
[SA31006] rPath update for ruby
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-07-09
rPath has issued an update for ruby. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/31006/\"]http://secunia.com/advisories/31006/[/url]
--
[SA30986] Moodle KSES HTML Filter Bypass Vulnerability
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-07-09
Some vulnerabilities have been reported in Moodle, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30986/\"]http://secunia.com/advisories/30986/[/url]
--
[SA30960] Debian update for wordpress
Critical: Less critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-07-07
Debian has issued an update for wordpress. This fixes a vulnerability, which can be exploited by malicious users to bypass certain security restrictions and to manipulate data.
Full Advisory:
[url=\"http://secunia.com/advisories/30960/\"]http://secunia.com/advisories/30960/[/url]
--
[SA30955] Simple Machines Forum "HTML-Tag" Vulnerability
Critical: Less critical
Where: From remote
Impact: Unknown
Released: 2008-07-17
A vulnerability with an unknown impact has been reported in Simple Machines Forum.
Full Advisory:
[url=\"http://secunia.com/advisories/30955/\"]http://secunia.com/advisories/30955/[/url]
--
[SA30941] Fedora update for jetty
Critical: Less critical
Where: From remote
Impact: Hijacking, Cross Site Scripting
Released: 2008-07-07
Fedora has issued an update for jetty. This fixes some vulnerabilities, which can be exploited by malicious people to conduct HTTP response splitting and cross-site scripting attacks and potentially hijack a user session.
Full Advisory:
[url=\"http://secunia.com/advisories/30941/\"]http://secunia.com/advisories/30941/[/url]
--
[SA30996] Red Hat update for openldap
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-07-10
Red Hat has issued an update for openldap. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30996/\"]http://secunia.com/advisories/30996/[/url]
--
[SA31131] Debian update for afuse
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-07-17
Debian has issued an update for afuse. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/31131/\"]http://secunia.com/advisories/31131/[/url]
--
[SA31109] OpenBSD update for X.Org
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-07-16
OpenBSD has issued an update for X.Org. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/31109/\"]http://secunia.com/advisories/31109/[/url]
--
[SA31103] Op "XAUTHORITY" Buffer Overflow Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-07-16
Nico Golde has reported a vulnerability in Op, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/31103/\"]http://secunia.com/advisories/31103/[/url]
--
[SA31086] Afuse Shell Command Injection Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-07-16
A vulnerability has been reported in Afuse, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/31086/\"]http://secunia.com/advisories/31086/[/url]
--
[SA31066] Debian update for mysql-dfsg-5.0
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-07-14
Debian has issued an update for mysql-dfsg-5.0. This fixes a security issue, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/31066/\"]http://secunia.com/advisories/31066/[/url]
--
[SA31048] Linux Kernel Multiple Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-07-11
Some vulnerabilities have been reported in the Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to potentially gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/31048/\"]http://secunia.com/advisories/31048/[/url]
--
[SA31025] Gentoo update for nx
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-07-10
Gentoo has issued an update for nx. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/31025/\"]http://secunia.com/advisories/31025/[/url]
--
[SA31110] Gentoo update for mercurial
Critical: Not critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-16
Gentoo has issued an update for mercurial. This fixes a security issue, which can be exploited by malicious people to manipulate certain data.
Full Advisory:
[url=\"http://secunia.com/advisories/31110/\"]http://secunia.com/advisories/31110/[/url]
--
[SA31108] Mercurial "applydiff()" Directory Traversal Security Issue
Critical: Not critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-16
A security issue has been reported in Mercurial, which can be exploited by malicious people to manipulate certain data.
Full Advisory:
[url=\"http://secunia.com/advisories/31108/\"]http://secunia.com/advisories/31108/[/url]
[b]Other:--[/b]
[SA31034] Apple TV Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-07-11
Some vulnerabilities have been reported in Apple TV, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/31034/\"]http://secunia.com/advisories/31034/[/url]
--
[SA31153] Blue Coat ProxyRA DNS Cache Poisoning Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-17
Blue Coat has acknowledged a vulnerability in Blue Coat ProxyRA, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/31153/\"]http://secunia.com/advisories/31153/[/url]
--
[SA31152] Blue Coat Director DNS Cache Poisoning Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-17
Blue Coat has acknowledged a vulnerability in Blue Coat Director, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/31152/\"]http://secunia.com/advisories/31152/[/url]
--
[SA31151] Blue Coat ProxySG DNS Cache Poisoning Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-17
Blue Coat has acknowledged a vulnerability in Blue Coat ProxySG, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/31151/\"]http://secunia.com/advisories/31151/[/url]
--
[SA31137] Blue Coat PacketShaper and iShaper DNS Cache Poisoning
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-17
Blue Coat has acknowledged a vulnerability in Blue Coat PacketShaper and iShaper, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/31137/\"]http://secunia.com/advisories/31137/[/url]
--
[SA31093] F5 Products DNS Cache Poisoning Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-16
A vulnerability has been reported in various F5 products, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/31093/\"]http://secunia.com/advisories/31093/[/url]
--
[SA31065] Novell Netware DNS Cache Poisoning Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-14
A vulnerability has been reported in Novell Netware, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/31065/\"]http://secunia.com/advisories/31065/[/url]
--
[SA31031] Nixu Secure Name Server BIND Query Port DNS Cache Poisoning
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-10
A vulnerability has been reported in Nixu Secure Name Server, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/31031/\"]http://secunia.com/advisories/31031/[/url]
--
[SA31030] Infoblox NIOS BIND Query Port DNS Cache Poisoning
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-10
A vulnerability has been reported in Infoblox NIOS, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/31030/\"]http://secunia.com/advisories/31030/[/url]
--
[SA31012] Juniper Networks Products DNS Cache Poisoning Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-09
A vulnerability has been reported in various Juniper Network products, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/31012/\"]http://secunia.com/advisories/31012/[/url]
--
[SA30965] F5 FirePass 1200 SSL VPN SNMP Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-07-09
nnposter has reported a vulnerability in F5 FirePass 1200 SSL VPN, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/30965/\"]http://secunia.com/advisories/30965/[/url]
[b]Cross Platform:--[/b]
[SA31127] PHPizabi "writeLogEntry()" Arbitrary PHP Code Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-07-17
inphex has discovered a vulnerability in PHPizabi, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/31127/\"]http://secunia.com/advisories/31127/[/url]
--
[SA31113] HP Oracle for OpenView Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Unknown, Security Bypass, Exposure of sensitive information, Privilege escalation, DoS, System access
Released: 2008-07-16
HP has acknowledged some vulnerabilities in HP Oracle for Openview (OfO). Some vulnerabilities have unknown impacts while others can be exploited by malicious, local users to gain escalated privileges, by malicious users to cause a DoS (Denial of Service), disclose sensitive information, gain escalated privileges, or compromise a vulnerable system, and by malicious people to bypass certain security restrictions or to cause a DoS.
Full Advisory:
[url=\"http://secunia.com/advisories/31113/\"]http://secunia.com/advisories/31113/[/url]
--
[SA31106] Mozilla Firefox 3 URI Launching and XUL Error Page Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Spoofing, System access
Released: 2008-07-16
Some vulnerabilities have been reported in Firefox 3, which can be exploited by malicious people to bypass certain security restrictions, potentially conduct spoofing attacks, or compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/31106/\"]http://secunia.com/advisories/31106/[/url]
--
[SA31101] Pragyan CMS File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-07-16
N3TR00T3R has reported some vulnerabilities in Pragyan CMS, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/31101/\"]http://secunia.com/advisories/31101/[/url]
--
[SA31074] Apple iPhone / iPod touch Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, DoS, System access
Released: 2008-07-14
Some vulnerabilities have been reported in Apple iPhone and iPod touch, which can be exploited by malicious people to conduct spoofing and
cross-site scripting attacks, cause a DoS (Denial of Service), bypass certain security restrictions, or compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/31074/\"]http://secunia.com/advisories/31074/[/url]
--
[SA31010] Sun Java JDK / JRE Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-07-09
Some vulnerabilities have been reported in Sun Java, which can be exploited by malicious people to bypass certain security restrictions, disclose system information or potentially sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/31010/\"]http://secunia.com/advisories/31010/[/url]
--
[SA30999] Ray "sIncPath" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-07-09
RoMaNcYxHaCkEr has reported a vulnerability in Ray, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30999/\"]http://secunia.com/advisories/30999/[/url]
--
[SA30995] SafeHTML "dir[plugins]" File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-07-09
RoMaNcYxHaCkEr has reported some vulnerabilities in SafeHTML, which can be exploited by malicious people to disclose sensitive information or to
compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30995/\"]http://secunia.com/advisories/30995/[/url]
--
[SA30991] vBulletin Two Script Insertion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-09
Some vulnerabilities have been reported in vBulletin, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/30991/\"]http://secunia.com/advisories/30991/[/url]
--
[SA30981] Dolphin File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-07-09
RoMaNcYxHaCkEr has reported some vulnerabilities in Dolphin, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30981/\"]http://secunia.com/advisories/30981/[/url]
--
[SA30956] Yourplace Authentication Bypass Vulnerability
Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-07-07
A vulnerability has been discovered in Yourplace, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/30956/\"]http://secunia.com/advisories/30956/[/url]
--
[SA30951] 1024 CMS Multiple File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-07-07
Some vulnerabilities have been reported in 1024 CMS, which can be exploited by malicious people to disclose sensitive information or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30951/\"]http://secunia.com/advisories/30951/[/url]
--
[SA30950] Neutrino Atomic Edition Security Bypass Vulnerability
Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-07-08
Ams has reported a vulnerability in Neutrino Atomic Edition, which can be exploited by malicious people to bypass certain security restrictions and compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30950/\"]http://secunia.com/advisories/30950/[/url]
--
[SA30948] webXell Editor File Upload Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-07-08
CWH Underground has discovered a vulnerability in webXell, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30948/\"]http://secunia.com/advisories/30948/[/url]
--
[SA30947] Thelia auth.php Security Bypass Vulnerability
Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-07-07
Black_H has discovered a vulnerability in Thelia, which can be exploited by malicious people to bypass certain security restrictions and compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30947/\"]http://secunia.com/advisories/30947/[/url]
--
[SA30939] ImperialBB Avatar File Upload Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-07-07
PHPLizardo has discovered a vulnerability in ImperialBB, which can be exploited by malicious users to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/30939/\"]http://secunia.com/advisories/30939/[/url]
--
[SA31126] Joomla DT Register Component "eventId" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-07-17
His0k4 has reported a vulnerability in the DT Register component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/31126/\"]http://secunia.com/advisories/31126/[/url]
--
[SA31116] Claroline Unspecified Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-07-17
Some vulnerabilities with an unknown impact have been reported in Claroline.
Full Advisory:
[url=\"http://secunia.com/advisories/31116/\"]http://secunia.com/advisories/31116/[/url]
--
[SA31112] AlstraSoft Affiliate Network Pro "pgm" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-17
Hussin X has reported a vulnerability in AlstraSoft Affiliate Network Pro, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/31112/\"]http://secunia.com/advisories/31112/[/url]
--
[SA31100] Comdev Web Blogger "arcmonth" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-16
M. Hasran Addahroni has discovered a vulnerability in Comdev Web Blogger, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/31100/\"]http://secunia.com/advisories/31100/[/url]
--
[SA31098] Galatolo WebManager SQL Injection and Cross-Site Scripting
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2008-07-16
StAkeR has discovered two vulnerabilities in Galatolo WebManager (GWM), which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/31098/\"]http://secunia.com/advisories/31098/[/url]
Secunia Security Updates - July 2008
Posted: Thu Jul 24, 2008 4:52 pm
by Tami
[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of July 24 2008[/b][/i]
[b]Windows:--[/b]
[SA31187] Pre Survey Poll "catid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-23
DreamTurk has reported a vulnerability in Pre Survey Poll, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31187/\"]http://secunia.com/advisories/31187/[/url]
--
[SA31170] HRS Multi "key" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-22
Mr.SQL has reported a vulnerability in HRS Multi, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31170/\"]http://secunia.com/advisories/31170/[/url]
--
[SA31158] SWAT 4 Denial of Service Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-07-21
Luigi Auriemma has reported some vulnerabilities in SWAT 4, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31158/\"]http://secunia.com/advisories/31158/[/url]
[b]UNIX/Linux:--[/b]
[SA31195] Red Hat update for thunderbird
Critical: Highly critical
Where: From remote
Impact: Spoofing, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-07-24
Red Hat has issued an update for thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to conduct spoofing attacks, disclose sensitive information, or compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31195/\"]http://secunia.com/advisories/31195/[/url]
--
[SA31183] Debian update for xulrunner
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-07-24
Debian has issued an update for xulrunner. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, disclose sensitive information, or potentially compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31183/\"]http://secunia.com/advisories/31183/[/url]
--
[SA31182] Gentoo update for peercast
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-22
Gentoo has issued an update for peercast. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31182/\"]http://secunia.com/advisories/31182/[/url]
--
[SA31181] Debian update for ruby1.8
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-22
Debian has issued an update for ruby1.8. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31181/\"]http://secunia.com/advisories/31181/[/url]
--
[SA31180] Gentoo BitchX Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Privilege escalation, System access
Released: 2008-07-22
Gentoo has acknowledged a security issue and a vulnerability in bitchx, which can be exploited by malicious, local users to perform certain actions with escalated privileges and by malicious people to potentially compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31180/\"]http://secunia.com/advisories/31180/[/url]
--
[SA31176] Debian update for iceweasel
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, System
access
Released: 2008-07-24
Debian has issued an update for iceweasel. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31176/\"]http://secunia.com/advisories/31176/[/url]
--
[SA31167] SUSE Update for Multiple Packages
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, DoS, System access
Released: 2008-07-21
SUSE has issued an update for multiple packages. This fixes some security issues and some vulnerabilities, which can be exploited by malicious people to manipulate certain data, bypass certain security restrictions, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31167/\"]http://secunia.com/advisories/31167/[/url]
--
[SA31157] Fedora update for firefox
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, System access
Released: 2008-07-18
Fedora has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31157/\"]http://secunia.com/advisories/31157/[/url]
--
[SA31154] Fedora update for seamonkey
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-07-18
Fedora has issued an update for seamonkey. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31154/\"]http://secunia.com/advisories/31154/[/url]
--
[SA31212] OpenBSD BIND Query Port DNS Cache Poisoning
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-24
OpenBSD has acknowledged a vulnerability in BIND, which can be exploited by malicious people to poison the DNS cache.
Full Advisory: [url=\"http://secunia.com/advisories/31212/\"]http://secunia.com/advisories/31212/[/url]
--
[SA31209] Slackware update for dnsmasq
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-24
Slackware has issued an update for dnsmasq. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
Full Advisory: [url=\"http://secunia.com/advisories/31209/\"]http://secunia.com/advisories/31209/[/url]
--
[SA31208] IPCop update for perl
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-24
An updated version of IPCop has been released, which fixes some vulnerabilities in perl, which can potentially be exploited by malicious people to cause a Denial of Service or to compromise a vulnerable perl application.
Full Advisory: [url=\"http://secunia.com/advisories/31208/\"]http://secunia.com/advisories/31208/[/url]
--
[SA31206] Debian update for clamav
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-07-24
Debian has issued an update for clamav. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31206/\"]http://secunia.com/advisories/31206/[/url]
--
[SA31204] IPCop update for various packages
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Spoofing, DoS
Released: 2008-07-23
An updated version of IPCop has been released, which fixes some vulnerabilities in bzip2, dnsmasq, and snort, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), and poison the DNS cache.
Full Advisory: [url=\"http://secunia.com/advisories/31204/\"]http://secunia.com/advisories/31204/[/url]
--
[SA31200] Ubuntu update for php
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass, DoS, System access
Released: 2008-07-24
Ubuntu has issued an update for php. This fixes some vulnerabilities, where some have unknown impacts and others can be exploited by malicious users to bypass certain security restrictions, and potentially by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31200/\"]http://secunia.com/advisories/31200/[/url]
--
[SA31199] Ubuntu update for dnsmasq
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-23
Ubuntu has issued an update for dnsmasq. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
Full Advisory: [url=\"http://secunia.com/advisories/31199/\"]http://secunia.com/advisories/31199/[/url]
--
[SA31197] dnsmasq Denial of Service and DNS Cache Poisoning
Critical: Moderately critical
Where: From remote
Impact: Spoofing, DoS
Released: 2008-07-23
Some vulnerabilities have been reported in dnsmasq, which can be exploited by malicious people to cause a DoS (Denial of Service) and poison the DNS cache.
Full Advisory: [url=\"http://secunia.com/advisories/31197/\"]http://secunia.com/advisories/31197/[/url]
--
[SA31171] Fedora update for mantis
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2008-07-23
Fedora has issued an update for mantis. This fixes some vulnerabilities, which can be exploited by malicious users to compromise a vulnerable system and malicious people to conduct cross-site scripting and request forgery attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31171/\"]http://secunia.com/advisories/31171/[/url]
--
[SA31169] rPath update for bind
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-21
rPath has issued an update for bind. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
Full Advisory: [url=\"http://secunia.com/advisories/31169/\"]http://secunia.com/advisories/31169/[/url]
--
[SA31168] Debian update for libgd2
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-22
Debian has issued an update for libgd2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory: [url=\"http://secunia.com/advisories/31168/\"]http://secunia.com/advisories/31168/[/url]
--
[SA31163] Fedora update for python-formencode
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-07-18
Fedora has issued an update for python-formencode. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31163/\"]http://secunia.com/advisories/31163/[/url]
--
[SA31155] Sun Solaris System Management Agent SNMP Daemon Buffer Overflow
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-07-18
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31155/\"]http://secunia.com/advisories/31155/[/url]
--
[SA31202] SUSE update for kernel
Critical: Less critical
Where: From remote
Impact: Privilege escalation, DoS
Released: 2008-07-23
SUSE has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and potentially gain escalated privileges, and malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31202/\"]http://secunia.com/advisories/31202/[/url]
--
[SA31175] Filesys::SmbClientParser Shell Command Injection Vulnerability
Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-07-21
Jesus Olmos Gonzalez has discovered a vulnerability in Filesys::SmbClientParser, which can be exploited by malicious people to compromise an application using the module.
Full Advisory: [url=\"http://secunia.com/advisories/31175/\"]http://secunia.com/advisories/31175/[/url]
--
[SA31194] Fedora update for asterisk
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-07-24
Fedora has issued an update for asterisk. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to conduct DoS attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31194/\"]http://secunia.com/advisories/31194/[/url]
--
[SA31172] Linux Kernel LDT Buffer Size Handling Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-07-24
A vulnerability has been reported in the Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and potentially gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31172/\"]http://secunia.com/advisories/31172/[/url]
--
[SA31159] Vim configure.in Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-07-18
A security issue has been reported in Vim, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31159/\"]http://secunia.com/advisories/31159/[/url]
--
[SA31198] Red Hat update for kernel
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-07-24
Red Hat has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31198/\"]http://secunia.com/advisories/31198/[/url]
--
[SA31184] Gentoo Bacula MySQL Director Password Disclosure Weakness
Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-07-22
Gentoo has acknowledged a weakness in bacula, which can be exploited by malicious, local users to disclose potentially sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31184/\"]http://secunia.com/advisories/31184/[/url]
--
[SA31179] OpenSSH "X11UseLocalhost" X11 Forwarding Security Issue
Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-07-22
A security issue has been reported in OpenSSH, which can be exploited by malicious, local users to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31179/\"]http://secunia.com/advisories/31179/[/url]
[b]Other:--[/b]
[SA31173] Century Systems Routers Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-22
A vulnerability has been reported in various Century Systems routers, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31173/\"]http://secunia.com/advisories/31173/[/url]
[b]
Cross Platform:--[/b]
[SA31203] SocialEngine SQL Injection and Code Execution
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, System access
Released: 2008-07-23
Tim Loshak has reported some vulnerabilities in SocialEngine, which can be exploited by malicious users to compromise a vulnerable system, and by malicious people to conduct SQL injection attacks and bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31203/\"]http://secunia.com/advisories/31203/[/url]
--
[SA31161] YouTube Blog Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-07-23
Some vulnerabilities have been discovered in YouTube Blog, which can be exploited by malicious people to conduct cross-site scripting and SQL
injection attacks, disclose sensitive information, and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31161/\"]http://secunia.com/advisories/31161/[/url]
--
[SA31193] EasyPublish SQL Injection and Cross-Site Scripting
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2008-07-22
Khashayar Fereidani has discovered two vulnerabilities in EasyPublish, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31193/\"]http://secunia.com/advisories/31193/[/url]
--
[SA31192] EasyE-Cards SQL Injection and Cross-Site Scripting
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-07-22
Khashayar Fereidani has discovered some vulnerabilities in EasyE-Cards, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31192/\"]http://secunia.com/advisories/31192/[/url]
--
[SA31190] MyReview Disclosure of Sensitive Information
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-07-22
Julien Thomas has reported a security issue in MyReview, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31190/\"]http://secunia.com/advisories/31190/[/url]
--
[SA31189] EasyDynamicPages SQL Injection and Cross-Site Scripting
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-07-22
Khashayar Fereidani has discovered two vulnerabilities in EasyDynamicPages, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31189/\"]http://secunia.com/advisories/31189/[/url]
--
[SA31185] ZDaemon Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-07-22
Luigi Auriemma has reported a vulnerability in ZDaemon, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31185/\"]http://secunia.com/advisories/31185/[/url]
--
[SA31174] Def-Blog "article" SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-21
CWH Underground has discovered some vulnerabilities in Def-Blog, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31174/\"]http://secunia.com/advisories/31174/[/url]
--
[SA31166] MojoClassifieds "cat_a" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-22
Mr.SQL has reported a vulnerability in MojoClassifieds, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31166/\"]http://secunia.com/advisories/31166/[/url]
--
[SA31165] MojoPersonals "cat" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-22
Mr.SQL has reported a vulnerability in MojoPersonals, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31165/\"]http://secunia.com/advisories/31165/[/url]
--
[SA31164] MojoJobs "cat_a" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-22
Mr.SQL has reported a vulnerability in MojoJobs, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31164/\"]http://secunia.com/advisories/31164/[/url]
--
[SA31162] MojoAuto "cat_a" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-22
Mr.SQL has reported a vulnerability in MojoAuto, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31162/\"]http://secunia.com/advisories/31162/[/url]
--
[SA31156] ShopCartDx "pid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-22
Cr@zy_King has reported a vulnerability in ShopCartDX, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31156/\"]http://secunia.com/advisories/31156/[/url]
--
[SA31211] Drupal Session Fixation Vulnerability
Critical: Less critical
Where: From remote
Impact: Hijacking
Released: 2008-07-24
A vulnerability has been reported in Drupal, which can be exploited by malicious people to conduct session fixation attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31211/\"]http://secunia.com/advisories/31211/[/url]
--
[SA31201] Claroline Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-23
Digital Security Research Group have reported some vulnerabilities in Claroline, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31201/\"]http://secunia.com/advisories/31201/[/url]
--
[SA31196] Moodle Script Insertion and Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-23
ProCheckUp Ltd have reported two vulnerabilities in Moodle, which can be exploited by malicious users to conduct script insertion attacks, and by malicious people to conduct cross-site request forgery attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31196/\"]http://secunia.com/advisories/31196/[/url]
--
[SA31191] EasyBookMarker "rs" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-22
Khashayar Fereidani has discovered a vulnerability in EasyBookMarker, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31191/\"]http://secunia.com/advisories/31191/[/url]
--
[SA31188] Geeklog Forum Plugin Search Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-23
A vulnerability has been reported in the Forum plugin for Geeklog, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31188/\"]http://secunia.com/advisories/31188/[/url]
--
[SA31186] EMC Retrospect Multiple Vulnerabilities
Critical: Less critical
Where: From local network
Impact: Brute force, Exposure of sensitive information, DoS
Released: 2008-07-22
Some vulnerabilities and a security issue has been reported in EMC Retrospect, which can be exploited by malicious people to disclose sensitive information or cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31186/\"]http://secunia.com/advisories/31186/[/url]
--
[SA31178] Asterisk Two Denial of Service Vulnerabilities
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-07-23
Two vulnerabilities have been reported in Asterisk, which can be exploited by malicious people to cause a DoS (Denial of Service) or to conduct DoS attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31178/\"]http://secunia.com/advisories/31178/[/url]
Secunia Security Updates - July 2008
Posted: Thu Jul 31, 2008 4:00 pm
by Tami
[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing For the week of July 31 2008[/b][/i]
[b]Windows:--[/b]
[SA31294] CoolPlayer M3U File Processing Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-07-30
Guido Landi has discovered a vulnerability in CoolPlayer, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31294/\"]http://secunia.com/advisories/31294/[/url]
--
[SA31277] Trend Micro OfficeScan Web-Deployment ObjRemoveCtrl Class Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-07-29
Elazar Broad has discovered some vulnerabilities in Trend Micro OfficeScan, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31277/\"]http://secunia.com/advisories/31277/[/url]
--
[SA31258] BookMine Cross-Site Scripting and SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-07-30
Russ McRee has reported some vulnerabilities in BookMine, which can be exploited by malicious people to conduct cross-site scripting and SQL
injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31258/\"]http://secunia.com/advisories/31258/[/url]
--
[SA31242] ScrewTurn Wiki System Log Script Insertion
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-30
Ferruh Mavituna has reported a vulnerability in ScrewTurn Wiki, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31242/\"]http://secunia.com/advisories/31242/[/url]
--
[SA31239] Pixelpost "language_full" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-07-29
Digital Security Research Group has reported a vulnerability in Pixelpost, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31239/\"]http://secunia.com/advisories/31239/[/url]
--
[SA31228] cwRsync OpenSSL Denial of Service Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-07-28
Two vulnerabilities have been reported in cwRsync, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31228/\"]http://secunia.com/advisories/31228/[/url]
--
[SA31281] Web Wiz Forum Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-28
CSDT has reported some vulnerabilities in Web Wiz Forum, which can be exploited by malicious people to conduct cross-site request forgery and
cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31281/\"]http://secunia.com/advisories/31281/[/url]
--
[SA31272] Web Wiz Rich Text Editor "email" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-29
CSDT has discovered a vulnerability in Web Wiz Rich Text Editor, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31272/\"]http://secunia.com/advisories/31272/[/url]
--
[SA31282] European Performance Systems Probe Builder Arbitrary Process Termination
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-07-29
A vulnerability has been reported in European Performance Systems Probe Builder, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31282/\"]http://secunia.com/advisories/31282/[/url]
--
[SA31278] HP OpenView Internet Service Probe Builder Arbitrary Process Termination
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-07-29
A vulnerability has been reported in HP OpenView Internet Service, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31278/\"]http://secunia.com/advisories/31278/[/url]
[b]UNIX/Linux:--[/b]
[SA31308] rPath update for openssl
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-31
rPath has issued an update for openssl. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31308/\"]http://secunia.com/advisories/31308/[/url]
--
[SA31286] Slackware update for mozillla-thunderbird
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-29
Slackware has issued an update for mozilla-thunderbird. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31286/\"]http://secunia.com/advisories/31286/[/url]
--
[SA31270] Ubuntu update for firefox and xulrunner
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Spoofing, DoS, System access
Released: 2008-07-29
Ubuntu has issued an update for firefox and xulrunner. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, potentially conduct spoofing attacks, or compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31270/\"]http://secunia.com/advisories/31270/[/url]
--
[SA31267] Ubuntu update for poppler
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-29
Ubuntu has issued an update for poppler. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory: [url=\"http://secunia.com/advisories/31267/\"]http://secunia.com/advisories/31267/[/url]
--
[SA31261] rPath update for firefox
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, System access
Released: 2008-07-29
rPath has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, bypass certain security restrictions, and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31261/\"]http://secunia.com/advisories/31261/[/url]
--
[SA31256] Debian update for ruby1.9
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-28
Debian has issued an update for ruby1.9. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/31256/\"]http://secunia.com/advisories/31256/[/url]
--
[SA31253] Debian update for icedove
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2008-07-28
Debian has issued an update for icedove. This fixes some vulnerabilities, which can be exploited by malicious people to conduct spoofing attacks, bypass certain security restrictions, disclose sensitive information, or potentially compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31253/\"]http://secunia.com/advisories/31253/[/url]
--
[SA31246] VMware ESX Server update for Samba and vmnix
Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, Privilege escalation, DoS, System access
Released: 2008-07-29
VMware has issued an update for VMware ESX Server. This fixes some vulnerabilities, which can be exploited by malicious, local users to disclose potentially sensitive information, to cause a DoS (Denial of Service), or to gain escalated privileges, and malicious people to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31246/\"]http://secunia.com/advisories/31246/[/url]
--
[SA31220] Ubuntu update for thunderbird
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-07-25
Ubuntu has issued an update for thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, disclose sensitive information, or potentially compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31220/\"]http://secunia.com/advisories/31220/[/url]
--
[SA31311] Fedora update for pdns-recursor
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-31
Fedora has issued an update for pdns-recursor. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
Full Advisory: [url=\"http://secunia.com/advisories/31311/\"]http://secunia.com/advisories/31311/[/url]
--
[SA31307] Debian update for newsx
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-31
Debian has issued an update for newsx. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31307/\"]http://secunia.com/advisories/31307/[/url]
--
[SA31289] Slackware update for vim
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-07-29
Slackware has issued an update for vim. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31289/\"]http://secunia.com/advisories/31289/[/url]
--
[SA31288] Slackware update for openssl
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-07-29
Slackware has issued an update for openssl. This fixes two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31288/\"]http://secunia.com/advisories/31288/[/url]
--
[SA31280] Affinium Campaign Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of system information, Exposure of sensitive information, DoS
Released: 2008-07-30
Some vulnerabilities have been reported in Affinium Campaign, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, conduct cross-site scripting and script insertion attacks, or cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31280/\"]http://secunia.com/advisories/31280/[/url]
--
[SA31269] Avaya CMS Sun Java JDK / JRE Same Origin Policy Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-07-28
Avaya has acknowledged a vulnerability in Avaya CMS, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31269/\"]http://secunia.com/advisories/31269/[/url]
--
[SA31268] Ubuntu update for ffmpeg
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-29
Ubuntu has issued an update for ffmpeg. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31268/\"]http://secunia.com/advisories/31268/[/url]
--
[SA31257] rPath update for tshark and wireshark
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-07-29
rPath has issued an update for tshark and wireshark. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31257/\"]http://secunia.com/advisories/31257/[/url]
--
[SA31251] reSIProcate Unspecified Memory Consumption Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-07-28
Some vulnerabilities have been reported in reSIProcate, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31251/\"]http://secunia.com/advisories/31251/[/url]
--
[SA31236] NetBSD update for bind
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-28
NetBSD has issued an update for bind. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
Full Advisory: [url=\"http://secunia.com/advisories/31236/\"]http://secunia.com/advisories/31236/[/url]
--
[SA31235] PHP Hosting Directory "adm" Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-07-31
Stack has discovered a vulnerability in PHP Hosting Directory, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31235/\"]http://secunia.com/advisories/31235/[/url]
--
[SA31224] Red Hat update for rdesktop
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-07-25
Red Hat has issued an update for rdesktop. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31224/\"]http://secunia.com/advisories/31224/[/url]
--
[SA31223] Red Hat update for vsftpd
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-07-25
Red Hat has issued an update for vsftpd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31223/\"]http://secunia.com/advisories/31223/[/url]
--
[SA31222] Red Hat update for rdesktop
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-07-25
Red Hat has issued an update for rdesktop. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/31222/\"]http://secunia.com/advisories/31222/[/url]
--
[SA31314] Fedora update for trac
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-31
Fedora has issued an update for trac. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31314/\"]http://secunia.com/advisories/31314/[/url]
--
[SA31301] Sun N1 Service Provisioning System Web Server Plugin Vulnerability
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-07-31
A vulnerability has been reported in Sun N1 Service Provisioning System, which can be exploited by malicious users to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31301/\"]http://secunia.com/advisories/31301/[/url]
--
[SA31287] Slackware update for fetchmail
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-07-29
Slackware has issued an update for fetchmail. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31287/\"]http://secunia.com/advisories/31287/[/url]
--
[SA31284] Condor Authorization Policy Wildcard Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-07-30
A security issue has been reported in Condor, which can be exploited by malicious users to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31284/\"]http://secunia.com/advisories/31284/[/url]
--
[SA31262] rPath update for fetchmail
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-07-29
rPath has issued an update for fetchmail. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31262/\"]http://secunia.com/advisories/31262/[/url]
--
[SA31255] Debian update for python2.5
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-07-28
Debian has issued an update for python2.5. This fixes some security issues, which can potentially be exploited by malicious people to disclose sensitive information, cause a DoS (Denial of Service), or to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31255/\"]http://secunia.com/advisories/31255/[/url]
--
[SA31254] Debian update for python-dns
Critical: Less critical
Where: From remote
Impact: Spoofing
Released: 2008-07-28
Debian has issued an update for python-dns. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
Full Advisory: [url=\"http://secunia.com/advisories/31254/\"]http://secunia.com/advisories/31254/[/url]
--
[SA31227] Red Hat update for nss_ldap
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-25
Red Hat has issued an update for nss_ldap. This fixes a security issue, which can be exploited by malicious people to manipulate certain data.
Full Advisory: [url=\"http://secunia.com/advisories/31227/\"]http://secunia.com/advisories/31227/[/url]
--
[SA31309] HP-UX System Administration Manager Security Issue
Critical: Less critical
Where: From local network
Impact: Security Bypass
Released: 2008-07-31
A security issue has been reported in HP-UX, which can lead to an insecure configuration.
Full Advisory: [url=\"http://secunia.com/advisories/31309/\"]http://secunia.com/advisories/31309/[/url]
--
[SA31226] Red Hat update for mysql
Critical: Less critical
Where: From local network
Impact: Security Bypass, DoS
Released: 2008-07-25
Red Hat has issued an update for mysql. This fixes some vulnerabilities and security issues, which can be exploited by malicious, local users to bypass certain security restrictions and by malicious users to cause a DoS (Denial of Service) or to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31226/\"]http://secunia.com/advisories/31226/[/url]
--
[SA31229] Red Hat update for kernel
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-07-25
Red Hat has issued an update for kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and potentially gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/31229/\"]http://secunia.com/advisories/31229/[/url]
--
[SA31312] Fedora update for phpMyAdmin
Critical: Not critical
Where: From remote
Impact: Cross Site Scripting, Spoofing
Released: 2008-07-31
Fedora has issued an update for phpMyAdmin. This fixes two vulnerabilities, which can be exploited by malicious local users to conduct cross-site scripting attacks, and by malicious people to conduct spoofing attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31312/\"]http://secunia.com/advisories/31312/[/url]
--
[SA31303] Sun Solaris "picld" Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-07-31
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31303/\"]http://secunia.com/advisories/31303/[/url]
--
[SA31225] Red Hat update for coreutils
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-07-25
Red Hat has issued an update for coreutils. This fixes a security issue, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31225/\"]http://secunia.com/advisories/31225/[/url]
[b]Other:--[/b]
[SA31221] Citrix NetScaler DNS Cache Poisoning
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-07-25
Citrix has acknowledged a vulnerability in NetScaler, which can be exploited by malicious people to poison the DNS cache.
Full Advisory: [url=\"http://secunia.com/advisories/31221/\"]http://secunia.com/advisories/31221/[/url]
--
[SA31304] Panasonic Network Cameras Error Page Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-31
A vulnerability has been reported in various Panasonic network cameras, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31304/\"]http://secunia.com/advisories/31304/[/url]
--
[SA31285] Axesstel AXW-D800 Authentication Bypass Vulnerabilities
Critical: Less critical
Where: From local network
Impact: Security Bypass
Released: 2008-07-31
Bboyhacks has reported some vulnerabilities in Axesstel AXW-D800, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/31285/\"]http://secunia.com/advisories/31285/[/url]
[b]Cross Platform:--[/b]
[SA31300] HIOX Random Ad "hm" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-07-31
Ghost Hacker has discovered a vulnerability in HIOX Random Ad, which can be exploited by malicious people to disclose sensitive information and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31300/\"]http://secunia.com/advisories/31300/[/url]
--
[SA31299] HIOX Browser Statistics "hm" File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information, System access
Released: 2008-07-31
Ghost Hacker has discovered two vulnerabilities in HIOX Browser Statistics, which can be exploited by malicious people to disclose sensitive information and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31299/\"]http://secunia.com/advisories/31299/[/url]
--
[SA31265] Unreal Tournament 3 Denial of Service and Memory Corruption
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-07-30
Luigi Auriemma has reported some vulnerabilities in Unreal Tournament, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31265/\"]http://secunia.com/advisories/31265/[/url]
--
[SA31297] nzFotolog "action_file" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-07-31
R3d.W0rm has discovered a vulnerability in nzFotolog, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31297/\"]http://secunia.com/advisories/31297/[/url]
--
[SA31296] ZeeScripts Reviews "ItemID" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-31
Mr.SQL has reported a vulnerability in ZeeScripts Reviews, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31296/\"]http://secunia.com/advisories/31296/[/url]
--
[SA31292] Article Friendly Two SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-31
Mr.SQL has reported two vulnerabilities in Article Friendly, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31292/\"]http://secunia.com/advisories/31292/[/url]
--
[SA31291] PozScripts Classified Ads "cid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-31
Hussin X has reported a vulnerability in PozScripts Classified Ads, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31291/\"]http://secunia.com/advisories/31291/[/url]
--
[SA31290] AVG Anti-Virus UPX Processing Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-07-29
Sergio 'shadown' Alvarez has reported a vulnerability in AVG Anti-Virus, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31290/\"]http://secunia.com/advisories/31290/[/url]
--
[SA31279] @Mail Multiple Information Disclosure Security Issues
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-07-30
Some security issues have been discovered in @Mail, which can be exploited by malicious, local users and malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31279/\"]http://secunia.com/advisories/31279/[/url]
--
[SA31276] TubeGuru Video Sharing Script "UID" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-31
Hussin X has reported a vulnerability in TubeGuru Video Sharing Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31276/\"]http://secunia.com/advisories/31276/[/url]
--
[SA31275] ViArt Shop "category_id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-07-29
James Bercegay has reported a vulnerability in ViArt Shop, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31275/\"]http://secunia.com/advisories/31275/[/url]
--
[SA31266] Unreal Tournament 2004 Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-07-30
Luigi Auriemma has reported a vulnerability in Unreal Tournament 2004, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/31266/\"]http://secunia.com/advisories/31266/[/url]
--
[SA31260] Gregarius "rsargs[]" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-29
James Bercegay has discovered a vulnerability in Gregarius, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31260/\"]http://secunia.com/advisories/31260/[/url]
--
[SA31259] ImpressCMS "modules/admin.php" Unspecified Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-07-31
A vulnerability with an unknown impact has been reported in ImpressCMS.
Full Advisory: [url=\"http://secunia.com/advisories/31259/\"]http://secunia.com/advisories/31259/[/url]
--
[SA31252] fizzMedia "mid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-31
Mr.SQL has reported a vulnerability in fizzMedia, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31252/\"]http://secunia.com/advisories/31252/[/url]
--
[SA31250] fipsCMS light "r" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-28
U238 has reported a vulnerability in fipsCMS light, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31250/\"]http://secunia.com/advisories/31250/[/url]
--
[SA31249] Jamroom Authentication Bypass and Multiple Unspecified Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass
Released: 2008-07-29
Some vulnerabilities have been reported in Jamroom, one of which can be exploited by malicious people to bypass certain security restrictions, while others have unknown impacts.
Full Advisory: [url=\"http://secunia.com/advisories/31249/\"]http://secunia.com/advisories/31249/[/url]
--
[SA31248] IceBB "username" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-28
girex has reported a vulnerability in IceBB, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31248/\"]http://secunia.com/advisories/31248/[/url]
--
[SA31247] Möbius for Mimsy XG SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-31
dun has reported two vulnerabilities in Möbius for Mimsy XG, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31247/\"]http://secunia.com/advisories/31247/[/url]
--
[SA31244] TriO "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-28
dun has reported a vulnerability in TriO, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31244/\"]http://secunia.com/advisories/31244/[/url]
--
[SA31243] CMScout "bit" Local File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-07-28
R3d.W0rm has discovered a vulnerability in CMScout, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31243/\"]http://secunia.com/advisories/31243/[/url]
--
[SA31241] GC Auction Platinum "cate_id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-07-28
Hussin X has reported a vulnerability in GC Auction Platinum, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31241/\"]http://secunia.com/advisories/31241/[/url]
--
[SA31240] SiteAdmin "art" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-07-28
Cr@zy_King has reported a vulnerability in SiteAdmin, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31240/\"]http://secunia.com/advisories/31240/[/url]
--
[SA31238] Youtuber Clone "UID" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-28
Hussin X has reported a vulnerability in Youtuber Clone, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31238/\"]http://secunia.com/advisories/31238/[/url]
--
[SA31234] Camera Life "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-07-28
nuclear has discovered a vulnerability in Camera Life, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31234/\"]http://secunia.com/advisories/31234/[/url]
--
[SA31218] Cerberus CMS "cerberus_user" Cookie Script Insertion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-29
A vulnerability has been reported in Cerberus CMS, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31218/\"]http://secunia.com/advisories/31218/[/url]
--
[SA31283] phpFreeChat nickid Hijacking Vulnerability
Critical: Less critical
Where: From remote
Impact: Hijacking
Released: 2008-07-31
A vulnerability has been reported in phpFreeChat, which can be exploited by malicious users to conduct hijacking attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31283/\"]http://secunia.com/advisories/31283/[/url]
--
[SA31274] ATutor "type" File Inclusion Vulnerability
Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-07-29
R3d.W0rm has discovered a vulnerability in ATutor, which can be exploited by malicious users to disclose sensitive information and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/31274/\"]http://secunia.com/advisories/31274/[/url]
--
[SA31264] Owl Intranet Engine "username" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-29
Fabian Fingerle has discovered a vulnerability in Owl Intranet Engine, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31264/\"]http://secunia.com/advisories/31264/[/url]
--
[SA31233] XRMS CRM Information Disclosure and Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information
Released: 2008-07-28
AzzCoder has discovered two vulnerabilities in XRMS CRM, which can be exploited by malicious people to conduct cross-site scripting attacks and disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31233/\"]http://secunia.com/advisories/31233/[/url]
--
[SA31231] Trac Wiki Engine Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-28
A vulnerability has been reported in Trac, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31231/\"]http://secunia.com/advisories/31231/[/url]
--
[SA31219] PunBB SMTP Command Injection and Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-07-28
Some vulnerabilities have been reported in PunBB, which can be exploited by malicious people to bypass certain security restrictions or conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31219/\"]http://secunia.com/advisories/31219/[/url]
--
[SA31217] Lore Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-07-25
Some vulnerabilities have been reported in Lore, which can be exploited by malicious people to conduct cross-site scripting-attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31217/\"]http://secunia.com/advisories/31217/[/url]
--
[SA31263] phpMyAdmin Cross-Site Scripting and Spoofing
Critical: Not critical
Where: From remote
Impact: Cross Site Scripting, Spoofing
Released: 2008-07-29
Aung Khant has reported two vulnerabilities in phpMyAdmin, which can be exploited by malicious local users to conduct cross-site scripting attacks, and by malicious people to conduct spoofing attacks.
Full Advisory: [url=\"http://secunia.com/advisories/31263/\"]http://secunia.com/advisories/31263/[/url]
--
[SA31232] PhpWebGallery E-Mail Address Information Disclosure
Critical: Not critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-07-30
Pat has reported a vulnerability in PhpWebGallery, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/31232/\"]http://secunia.com/advisories/31232/[/url]