Page 1 of 1
Secunia Updates - November 2008
Posted: Fri Nov 07, 2008 6:51 pm
by Tami
[b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of November 6 2008[/b]
[b]Windows:--[/b]
[SA32546] NOS Microsystems getPlus ActiveX Control Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-05
A vulnerability has been reported in the NOS Microsystems getPlus ActiveX control, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32546/\"]http://secunia.com/advisories/32546/[/url]
--
[SA32513] Chilkat Crypt ActiveX Component "WriteFile()" Insecure Method
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-04
shinnai has discovered a vulnerability in Chilkat Crypt ActiveX Component, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32513/\"]http://secunia.com/advisories/32513/[/url]
[b]UNIX/Linux:--[/b]
[SA32538] Gentoo update for opera
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-11-04
Gentoo has issued an update for opera. This fixes some vulnerabilities, which can be exploited by malicious people to disclose system and potentially sensitive information, conduct spoofing and cross-site scripting attacks, bypass certain security restrictions, and potentially compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32538/\"]http://secunia.com/advisories/32538/[/url]
--
[SA32514] Dns2tcp "dns_decode()" Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-03
A vulnerability has been reported in Dns2tcp, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32514/\"]http://secunia.com/advisories/32514/[/url]
--
[SA32493] Mahara Multiple Command Execution Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-05
Some vulnerabilities have been reported in Mahara, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32493/\"]http://secunia.com/advisories/32493/[/url]
--
[SA32489] Fedora update for openoffice.org
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-10-31
Fedora has issued an update for openoffice.org. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32489/\"]http://secunia.com/advisories/32489/[/url]
--
[SA32530] Ubuntu update for enscript
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-04
Ubuntu has issued an update for enscript. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32530/\"]http://secunia.com/advisories/32530/[/url]
--
[SA32521] Fedora update for enscript
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-06
Fedora has issued an update for enscript. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32521/\"]http://secunia.com/advisories/32521/[/url]
--
[SA32518] Fedora update for ktorrent
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-11-06
Fedora has issued an update for ktorrent. This fixes some vulnerabilities, which can be exploited by malicious users to compromise a vulnerable system and malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32518/\"]http://secunia.com/advisories/32518/[/url]
--
[SA32512] Fedora update for uw-imap
Critical: Moderately critical
Where: From remote
Impact: Privilege escalation, System access
Released: 2008-11-06
Fedora has issued an update for uw-imap. This fixes some vulnerabilities, which can be exploited by malicious, local users to potentially gain escalated privileges, and by malicious people to potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32512/\"]http://secunia.com/advisories/32512/[/url]
--
[SA32509] Ubuntu update for kernel
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-05
Ubuntu has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32509/\"]http://secunia.com/advisories/32509/[/url]
--
[SA32496] Gentoo update for libspf2
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-10-31
Gentoo has issued an update for libspf2. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise an application using the library.
Full Advisory: [url=\"http://secunia.com/advisories/32496/\"]http://secunia.com/advisories/32496/[/url]
--
[SA32488] VMware ESX Server update for libxml2
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-10-31
VMware has issued an update for VMware ESX Server. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/32488/\"]http://secunia.com/advisories/32488/[/url]
--
[SA32483] UW-imapd "tmail" and "dmail" Buffer Overflow Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Privilege escalation, System access
Released: 2008-11-03
Two vulnerabilities have been reported in UW-imapd, which can be exploited by malicious, local users to potentially gain escalated privileges, and by malicious people to potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32483/\"]http://secunia.com/advisories/32483/[/url]
--
[SA32545] HP-UX Xserver Multiple Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: Privilege escalation, DoS, System access
Released: 2008-11-04
HP has acknowledged some vulnerabilities in HP-UX, which can be exploited by malicious, local users to disclose potentially sensitive information or gain escalated privileges, and by malicious people to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32545/\"]http://secunia.com/advisories/32545/[/url]
--
[SA32553] PTK Command Execution Vulnerability
Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-11-06
A vulnerability has been reported in PTK, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32553/\"]http://secunia.com/advisories/32553/[/url]
--
[SA32543] Nagios Cross-Site Request Forgery Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-05
A vulnerability has been reported in Nagios, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32543/\"]http://secunia.com/advisories/32543/[/url]
--
[SA32482] Fedora update for phpMyAdmin
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-10-31
Fedora has issued an update for phpMyAdmin. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32482/\"]http://secunia.com/advisories/32482/[/url]
--
[SA32560] Net-snmp GETBULK Integer Overflow Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-11-03
A vulnerability has been reported in Net-snmp, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/32560/\"]http://secunia.com/advisories/32560/[/url]
--
[SA32539] Red Hat update for net-snmp
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-11-04
Red Hat has issued an update for net-snmp. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/32539/\"]http://secunia.com/advisories/32539/[/url]
--
[SA32531] Fedora update for net-snmp
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-11-06
Fedora has issued an update for net-snmp. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/32531/\"]http://secunia.com/advisories/32531/[/url]
--
[SA32578] Debian update for mysql-dfsg-5.0
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-11-06
Debian has issued an update for mysql-dfsg-5.0. This fixes a security issue, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32578/\"]http://secunia.com/advisories/32578/[/url]
--
[SA32554] Novell Access Manger Identity Server X509 Session Improper Termination
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-11-05
A security issue has been reported in Novell Access Manager Identity Server, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32554/\"]http://secunia.com/advisories/32554/[/url]
--
[SA32544] HP System Management Homepage Unspecified Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-04
A vulnerability has been reported in HP System Management Homepage (SMH), which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32544/\"]http://secunia.com/advisories/32544/[/url]
--
[SA32485] Red hat update for kernel
Critical: Less critical
Where: Local system
Impact: DoS, Privilege escalation, Exposure of sensitive information
Released: 2008-11-04
Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), to disclose potentially sensitive information, or to potentially gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32485/\"]http://secunia.com/advisories/32485/[/url]
--
[SA32566] Ubuntu update for system-tools-backends
Critical: Not critical
Where: From remote
Impact: Brute force
Released: 2008-11-06
Ubuntu has issued an update for system-tools-backend. This fixes a weakness, which can be exploited by malicious people to conduct brute force attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32566/\"]http://secunia.com/advisories/32566/[/url]
--
[SA32510] Linux Kernel "hfsplus_find_cat()" and "hfsplus_block_allocate()" Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-11-04
Some vulnerabilities have been reported in the Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/32510/\"]http://secunia.com/advisories/32510/[/url]
--
[SA32487] CrossFire Map Pack combine.pl Insecure Temporary Files
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-10-31
A security issue has been reported in CrossFire, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32487/\"]http://secunia.com/advisories/32487/[/url]
[b]Other:--[/b]
[SA32498] SonicWALL Products Content Filtering Service Cross-Site Scripting
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-10-31
A vulnerability has been reported in various SonicWALL products, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32498/\"]http://secunia.com/advisories/32498/[/url]
--
[SA32573] Cisco IOS / CatOS VLAN Trunking Protocol Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-11-06
A vulnerability has been reported in Cisco IOS/CatOS, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/32573/\"]http://secunia.com/advisories/32573/[/url]
[b]Cross Platform:--
[/b]
[SA32569] VLC Media Player CUE and RealText Processing Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-06
Two vulnerabilities have been reported in VLC Media Player, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32569/\"]http://secunia.com/advisories/32569/[/url]
--
[SA32551] Joomla Dada Mail Manager Component "mosConfig_absolute_path" File Inclusion
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-06
NoGe has discovered a vulnerability in the Dada Mail Manager component for Joomla, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32551/\"]http://secunia.com/advisories/32551/[/url]
--
[SA32533] Joomla VirtueMart Google Base Component "mosConfig_absolute_path" File Inclusion
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-05
NoGe has discovered a vulnerability in the VirtueMart Google Base component for Joomla, which can be exploited by malicious people to compromise a vulnerable system
Full Advisory: [url=\"http://secunia.com/advisories/32533/\"]http://secunia.com/advisories/32533/[/url]
--
[SA32520] Joomla Flash Tree Gallery Component "mosConfig_live_site" File Inclusion
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-03
NoGe has reported a vulnerability in the Flash Tree Gallery component for Joomla!, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32520/\"]http://secunia.com/advisories/32520/[/url]
--
[SA32516] Simple Machines Forum Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information, System access
Released: 2008-11-05
Some vulnerabilities have been discovered in Simple Machines Forum, which can be exploited by malicious people to conduct cross-site request forgery attacks and by malicious users to disclose potentially sensitive information and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32516/\"]http://secunia.com/advisories/32516/[/url]
--
[SA32515] Way Of The Warrior "plancia" File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2008-11-05
Some vulnerabilities have been discovered in Way Of The Warrior (WOTW), which can be exploited by malicious people to disclose sensitive information or compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32515/\"]http://secunia.com/advisories/32515/[/url]
--
[SA32579] Five Dollar Scripts Drinks Script "recid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-06
Ex Tacy has reported a vulnerability in Five Dollar Scripts Drinks script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32579/\"]http://secunia.com/advisories/32579/[/url]
--
[SA32564] PHPX "news_id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-06
StAkeR has discovered a vulnerability in PHPX, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32564/\"]http://secunia.com/advisories/32564/[/url]
--
[SA32563] Pre Podcast Portal "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-06
G4N0K has reported a vulnerability in Pre Podcast Portal, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32563/\"]http://secunia.com/advisories/32563/[/url]
--
[SA32559] GeSHi Unspecified Code Execution Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-03
A vulnerability has been reported in GeSHI, which can potentially be exploited by malicious people to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32559/\"]http://secunia.com/advisories/32559/[/url]
--
[SA32558] SFS Multiple Products "cat_id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-03
A vulnerability has been reported in multiple SFS products, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32558/\"]http://secunia.com/advisories/32558/[/url]
--
[SA32557] PreProjects Products Cookie Security Bypass Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-06
G4N0K has reported a vulnerability in multiple PreProjects products, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32557/\"]http://secunia.com/advisories/32557/[/url]
--
[SA32556] nicLOR Sito Includefile "page_file" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-11-05
StAkeR has discovered a vulnerability in nicLOR Sito Includefile, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/32556/\"]http://secunia.com/advisories/32556/[/url]
--
[SA32552] SFS EZ BIZ PRO "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-03
d3b4g has reported a vulnerability in SFS EZ BIZ PRO, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32552/\"]http://secunia.com/advisories/32552/[/url]
--
[SA32550] SFS EZ Webring "cat" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-03
d3b4g has reported a vulnerability in SFS EZ Webring, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32550/\"]http://secunia.com/advisories/32550/[/url]
--
[SA32548] Tribiq CMS "template_path" Cross-Site Scripting and Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-11-03
Some vulnerabilities have been discovered in Tribiq CMS, which can be exploited by malicious people to conduct cross-site scripting attacks or to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/32548/\"]http://secunia.com/advisories/32548/[/url]
--
[SA32547] PHP Auto Listings "itemno" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-06
G4N0K has reported a vulnerability in PHP Auto Listings, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32547/\"]http://secunia.com/advisories/32547/[/url]
--
[SA32542] Logz CMS "art" SQL Injection and Cross-Site Scripting
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-11-03
Some vulnerabilities have been discovered in Logz CMS, which can be
exploited by malicious people to conduct cross-site scripting and SQL
injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/32542/\"]http://secunia.com/advisories/32542/[/url]
--
[SA32540] U-Mail "edit.php" Arbitrary File Creation Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-11-05
Shennan Wang has reported a vulnerability in U-Mail, which can be exploited by malicious users to bypass certain security restrictions and potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32540/\"]http://secunia.com/advisories/32540/[/url]
--
[SA32536] SFS EZ Hotscripts-like Site Multiple SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-03
Some vulnerabilities have been reported in SFS EZ Hotscripts-like Site, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32536/\"]http://secunia.com/advisories/32536/[/url]
--
[SA32532] SFS EZ Hot ot Not "phid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-03
d3b4g has reported a vulnerability in SFS EZ Hot ot Not, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32532/\"]http://secunia.com/advisories/32532/[/url]
--
[SA32528] SFS EZ Auction "cat" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, Manipulation of data
Released: 2008-11-03
Mountassif Moad has reported a vulnerability in SFS EZ Auction, which can be exploited by malicious people to conduct SQL Injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32528/\"]http://secunia.com/advisories/32528/[/url]
--
[SA32527] SFS EZ Career "topic" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-03
Mountassif Moad has reported a vulnerability in SFS EZ Career, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32527/\"]http://secunia.com/advisories/32527/[/url]
--
[SA32526] SFS EZ Top Sites "ts" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-03
Mountassif Moad has reported a vulnerability in SFS EZ Top Sites, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32526/\"]http://secunia.com/advisories/32526/[/url]
--
[SA32525] SFS EZ e-store "where" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-03
ZoRLu has reported a vulnerability in SFS EZ e-store, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32525/\"]http://secunia.com/advisories/32525/[/url]
--
[SA32524] SFS EZ Pub Site "cat" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-03
Hakxer has reported a vulnerability in SFS EZ Pub Site, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32524/\"]http://secunia.com/advisories/32524/[/url]
--
[SA32523] Joomla Pro Desk Component "include_file" Local File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-11-05
d3v1l has reported a vulnerability in the Pro Desk component for Joomla, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/32523/\"]http://secunia.com/advisories/32523/[/url]
--
[SA32522] SFS EZ Gaming Cheats "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-03
ZoRLu has reported a vulnerability in SFS EZ Gaming Cheats, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32522/\"]http://secunia.com/advisories/32522/[/url]
--
[SA32519] Article Publisher Pro SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-11-03
Some vulnerabilities have been reported in Article Publisher Pro, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32519/\"]http://secunia.com/advisories/32519/[/url]
--
[SA32517] Acc Scripts Products "username_cookie" Cookie Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-04
Hakxer has reported a vulnerability in multiple Acc Scripts products, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32517/\"]http://secunia.com/advisories/32517/[/url]
--
[SA32507] Acc PHP eMail "NEWSLETTERLOGIN" Cookie Security Bypass Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-04
Hakxer has reported a vulnerability in Acc PHP eMail, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32507/\"]http://secunia.com/advisories/32507/[/url]
--
[SA32504] YourFreeWorld Products "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-03
Hussin X has reported a vulnerability in various YourFreeWorld products, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32504/\"]http://secunia.com/advisories/32504/[/url]
--
[SA32503] ToursManager "cityid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-05
G4N0K has reported a vulnerability in ToursManager, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32503/\"]http://secunia.com/advisories/32503/[/url]
--
[SA32502] Simple Document Management System "login" and "pass" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-05
Yuri has discovered a vulnerability in Simple Document Management System (SDMS), which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32502/\"]http://secunia.com/advisories/32502/[/url]
--
[SA32500] PHP-Nuke BookCatalog Module "catid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-10-31
Ehsan_Hp200 has reported a vulnerability in the BookCatalog module for PHP-Nuke, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32500/\"]http://secunia.com/advisories/32500/[/url]
--
[SA32497] Apache Struts Security Bypass and Directory Traversal
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information
Released: 2008-11-04
Some vulnerabilities have been reported in Apache Struts, which can be exploited by malicious people to bypass certain security restrictions or to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/32497/\"]http://secunia.com/advisories/32497/[/url]
--
[SA32495] XWork "ParameterInterceptor" Security Bypass Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-04
A vulnerability has been reported in XWork, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32495/\"]http://secunia.com/advisories/32495/[/url]
--
[SA32492] YourFreeWorld Shopping Cart Script "c" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-03
Hussin X has reported a vulnerability in YourFreeWorld Shopping Cart Script with Affiliate Program, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32492/\"]http://secunia.com/advisories/32492/[/url]
--
[SA32491] Joovili Multiple Cookie Security Bypass Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-03
ZoRLu has reported a vulnerability in Joovili, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32491/\"]http://secunia.com/advisories/32491/[/url]
--
[SA32484] NetRisk Cross-Site Scripting and SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-11-03
StAkeR has discovered some vulnerabilities in NetRisk, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32484/\"]http://secunia.com/advisories/32484/[/url]
--
[SA32572] Drupal Content Construction Kit Script Insertion Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-06
Some vulnerabilities have been reported in the Drupal Content Construction Kit (CCK), which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32572/\"]http://secunia.com/advisories/32572/[/url]
--
[SA32555] DHCart "order.php" Two Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-05
Lostmon has reported two vulnerabilities in DHCart, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32555/\"]http://secunia.com/advisories/32555/[/url]
--
[SA32549] firmCHANNEL Digital Signage "action" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-05
Brad Antoniewicz has reported a vulnerability in firmCHANNEL Digital Signage, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32549/\"]http://secunia.com/advisories/32549/[/url]
--
[SA32511] RateMe Cross-Site Scripting and Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-03
Russ McRee has reported some vulnerabilities in RateMe, which can be exploited by malicious people to conduct cross-site request forgery and cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32511/\"]http://secunia.com/advisories/32511/[/url]
--
[SA32506] SignMe "hash" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-03
Russ McRee has discovered a vulnerability in SignMe, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32506/\"]http://secunia.com/advisories/32506/[/url]
--
[SA32505] MyGallery "mghash" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-03
Russ McRee has discovered a vulnerability in MyGallery, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32505/\"]http://secunia.com/advisories/32505/[/url]
--
[SA32567] Adobe ColdFusion Sandbox Security Bypass Vulnerability
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-11-06
A vulnerability has been reported in Adobe ColdFusion, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32567/\"]http://secunia.com/advisories/32567/[/url]
Secunia Updates - November 2008
Posted: Thu Nov 13, 2008 6:16 pm
by Tami
[b][url=\"http://secunia.com\"]Secunia[/url] Vulnerabilities Content Listing for the week of November 13 2008[/b]
[b]Windows:--[/b]
[SA32698] ooVoo URI Handler Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-12
bruiser has discovered a vulnerability in ooVoo, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32698/\"]http://secunia.com/advisories/32698/[/url]
--
[SA32682] SAP GUI MDrmSap ActiveX Control Code Execution Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-11
A vulnerability has been reported in SAPgui, which can be exploited by
malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/32682/\"]http://secunia.com/advisories/32682/[/url]
--
[SA32597] hMAilServer PHPWebAdmin File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2008-11-07
Nine:Situations:Group::strawdog has discovered some vulnerabilities in hMailServer PHPWebAdmin, which can be exploited by malicious people to
disclose potentially sensitive information and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32597/\"]http://secunia.com/advisories/32597/[/url]
--
[SA32675] Dizi Film Portal "film" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-11
Kaan KAMIS has discovered a vulnerability in Dizi Film Portal, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32675/\"]http://secunia.com/advisories/32675/[/url]
--
[SA32590] Arab Portal "file" File Disclosure Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-11-10
IRCRASH has reported a vulnerability in Arab Portal, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/32590/\"]http://secunia.com/advisories/32590/[/url]
--
[SA32633] Microsoft Windows SMB Authentication Credential Replay Vulnerability
Critical: Moderately critical
Where: From local network
Impact: Security Bypass, Spoofing
Released: 2008-11-11
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to bypass certain security features.
Full Advisory: [url=\"http://secunia.com/advisories/32633/\"]http://secunia.com/advisories/32633/[/url]
--
[SA32618] Trend Micro ServerProtect Multiple Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-11-12
Some vulnerabilities have been reported in Trend Micro ServerProtect, which potentially can be exploited by malicious people to compromise a
vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32618/\"]http://secunia.com/advisories/32618/[/url]
--
[SA32683] IBM Metrica Products Cross-Site Scripting and Script Insertion
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-13
Francesco Bianchino has reported a vulnerability in Metrica products, which can be exploited by malicious users to conduct script insertion attacks and by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32683/\"]http://secunia.com/advisories/32683/[/url]
--
[SA32592] Orb Networks Orb Directory Traversal Vulnerability
Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-11-10
A vulnerability has been reported in Orb, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/32592/\"]http://secunia.com/advisories/32592/[/url]
--
[SA32669] Anti-Trojan Elite Atepmon.sys IOCTL Handling Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-11-10
alex has discovered a vulnerability in Anti-Trojan Elite, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or potentially gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32669/\"]http://secunia.com/advisories/32669/[/url]
--
[SA32634] Anti-Keylogger Elite "AKEProtect.sys" IOCTL Handling Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-11-10
alex has discovered some vulnerabilities in Anti-Keylogger Elite, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to potentially gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32634/\"]http://secunia.com/advisories/32634/[/url]
[b]UNIX/Linux:--[/b]
[SA32714] Mozilla SeaMonkey Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-13
Some vulnerabilities have been reported in Mozilla SeaMonkey, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32714/\"]http://secunia.com/advisories/32714/[/url]
--
[SA32713] Mozilla Firefox 3 Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-13
Some vulnerabilities have been reported in Mozilla Firefox, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32713/\"]http://secunia.com/advisories/32713/[/url]
--
[SA32708] Fedora update for optipng
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-13
Fedora has issued an update for optipng. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32708/\"]http://secunia.com/advisories/32708/[/url]
--
[SA32700] Red Hat update for acroread
Critical: Highly critical
Where: From remote
Impact: Privilege escalation, System access
Released: 2008-11-13
Red Hat has issued an update for acroread. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges or by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32700/\"]http://secunia.com/advisories/32700/[/url]
--
[SA32695] Red Hat update for firefox
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-13
Red Hat has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32695/\"]http://secunia.com/advisories/32695/[/url]
--
[SA32694] Red Hat update for seamonkey
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-13
Red Hat has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32694/\"]http://secunia.com/advisories/32694/[/url]
--
[SA32688] Apple iLife / Aperture Image Processing Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-12
Apple has acknowledged some vulnerabilities in Apple iLife and Aperture, which can potentially be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32688/\"]http://secunia.com/advisories/32688/[/url]
--
[SA32629] SUSE update for yelp
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-07
SUSE has issued an update for yelp. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32629/\"]http://secunia.com/advisories/32629/[/url]
--
[SA32702] Red Hat update for flash-plugin
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2008-11-13
Red Hat has issued an update for flash-plugin. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, manipulate certain data, conduct cross-site scripting attacks, or disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/32702/\"]http://secunia.com/advisories/32702/[/url]
--
[SA32687] Red Hat update for gnutls
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Spoofing
Released: 2008-11-12
Red Hat has issued an update for gnutls. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32687/\"]http://secunia.com/advisories/32687/[/url]
--
[SA32681] Fedora update for gnutls
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Spoofing
Released: 2008-11-12
Fedora has issued an update for gnutls. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32681/\"]http://secunia.com/advisories/32681/[/url]
--
[SA32678] Debian update for libcdaudio
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-13
Debian has issued an update for libcdaudio. This fixes a vulnerability, which can be exploited by malicious people to compromise an application
using the library.
Full Advisory: [url=\"http://secunia.com/advisories/32678/\"]http://secunia.com/advisories/32678/[/url]
--
[SA32677] Ubuntu update for dovecot
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-11-10
Ubuntu has issued an update for dovecot. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/32677/\"]http://secunia.com/advisories/32677/[/url]
--
[SA32661] Gentoo update for faad2
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-10
Gentoo has issued an update for faad2. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32661/\"]http://secunia.com/advisories/32661/[/url]
--
[SA32656] Gentoo update for graphviz
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-10
Gentoo has issued an update for graphviz. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32656/\"]http://secunia.com/advisories/32656/[/url]
--
[SA32625] Sun Solaris IP Filter DNS Cache Poisoning
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-11-12
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious people to poison the DNS cache.
Full Advisory: [url=\"http://secunia.com/advisories/32625/\"]http://secunia.com/advisories/32625/[/url]
--
[SA32619] GnuTLS X.509 Certificate Chain Validation Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Spoofing
Released: 2008-11-10
A vulnerability has been reported in GnuTLS, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32619/\"]http://secunia.com/advisories/32619/[/url]
--
[SA32614] Fedora update for ipsec-tools
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-11-07
Fedora has issued an update for ipsec-tools. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/32614/\"]http://secunia.com/advisories/32614/[/url]
--
[SA32608] Ubuntu update for tk
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-07
Ubuntu has issued an update for tk. This fixes a vulnerability, which can be exploited by malicious people to compromise an application using the library.
Full Advisory: [url=\"http://secunia.com/advisories/32608/\"]http://secunia.com/advisories/32608/[/url]
--
[SA32607] Ubuntu update for netpbm
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-07
Ubuntu has issued an update for netpbm. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise a
vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32607/\"]http://secunia.com/advisories/32607/[/url]
--
[SA32606] Sun Java System Identity Manager Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-11-12
Some vulnerabilities have been reported in Sun Java System Identity Manager, which can be exploited by malicious people to conduct cross-site scripting attacks and to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32606/\"]http://secunia.com/advisories/32606/[/url]
--
[SA32668] Sun Solaris DHCP Request Handling Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-11-10
Some vulnerabilities have been reported in Sun Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32668/\"]http://secunia.com/advisories/32668/[/url]
--
[SA32685] Red Hat update for httpd
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2008-11-12
Red Hat has issued an update for httpd. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks or potentially cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/32685/\"]http://secunia.com/advisories/32685/[/url]
--
[SA32662] Gentoo update for gallery
Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, Cross Site Scripting
Released: 2008-11-10
Gentoo has issued an update for gallery. This fixes some vulnerabilities, which can be exploited by malicious users to conduct script insertion attacks and disclose potentially sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/32662/\"]http://secunia.com/advisories/32662/[/url]
--
[SA32630] op5 Monitor Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-11
A vulnerability has been reported in op5 Monitor, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32630/\"]http://secunia.com/advisories/32630/[/url]
--
[SA32620] Fedora update for php-Smarty
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-07
Fedora has issued an update for php-Smarty. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security
restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32620/\"]http://secunia.com/advisories/32620/[/url]
--
[SA32615] Fedora update for drupal-cck
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-07
Fedora has issued an update for drupal-cck. This fixes some vulnerabilities, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32615/\"]http://secunia.com/advisories/32615/[/url]
--
[SA32610] Nagios "cmd.cgi" Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-07
Andreas Ericsson has discovered a vulnerability in Nagios, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/32610/\"]http://secunia.com/advisories/32610/[/url]
--
[SA32599] TestLink Multiple Script Insertion Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-07
Some vulnerabilities have been reported in TestLink, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32599/\"]http://secunia.com/advisories/32599/[/url]
--
[SA32711] rPath update for net-snmp
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-11-13
rPath has issued an update for net-snmp. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/32711/\"]http://secunia.com/advisories/32711/[/url]
--
[SA32664] Debian update for net-snmp
Critical: Less critical
Where: From local network
Impact: Spoofing, DoS, System access
Released: 2008-11-10
Debian has issued an update for net-snmp. This fixes some vulnerabilities, which can be exploited by malicious people to spoof authenticated SNMPv3 packets, cause a DoS (Denial of Service), and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32664/\"]http://secunia.com/advisories/32664/[/url]
--
[SA32709] rPath update for kernel
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-13
rPath has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32709/\"]http://secunia.com/advisories/32709/[/url]
--
[SA32701] Fedora update for blender
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-12
Fedora has issued an update for blender. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32701/\"]http://secunia.com/advisories/32701/[/url]
--
[SA32679] smcFanControl "main()" Privilege Escalation Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-12
KaiJern Lau has reported a vulnerability in smcFanControl, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32679/\"]http://secunia.com/advisories/32679/[/url]
--
[SA32674] Sun Logical Domains Authentication Bypass Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-13
A vulnerability has been reported in Sun Logical Domains (LDoms), which can be exploited by malicious, local users to bypass certain security
restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32674/\"]http://secunia.com/advisories/32674/[/url]
--
[SA32627] CDRW-Taper "amlabel-cdrw" Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-07
A security issue has been reported in CDRW-Taper, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32627/\"]http://secunia.com/advisories/32627/[/url]
--
[SA32621] HP Tru64 UNIX AdvFS "showfile" Privilege Escalation Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-07
A vulnerability has been reported in HP Tru64 UNIX, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32621/\"]http://secunia.com/advisories/32621/[/url]
--
[SA32616] Fedora update for cman, gfs2-utils, and rgmanager
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-07
Fedora has issued an update for cman, gfs2-utils, and rgmanager. This fixes some security issues, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32616/\"]http://secunia.com/advisories/32616/[/url]
--
[SA32605] Apertium Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-11
Some security issues have been reported in Apertium, which can be
exploited by malicious, local users to perform certain actions with
escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/32605/\"]http://secunia.com/advisories/32605/[/url]
--
[SA32602] Cluster Project Unspecified Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-07
Some security issues have been reported in Cluster Project, which can be exploited by malicious, local users to perform certain actions with
escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32602/\"]http://secunia.com/advisories/32602/[/url]
--
[SA32598] Scilab Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-10
Some security issues have been reported in Scilab, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32598/\"]http://secunia.com/advisories/32598/[/url]
--
[SA32589] DigitalDJ fest.pl Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-07
A security issue has been reported in DigitalDJ, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32589/\"]http://secunia.com/advisories/32589/[/url]
--
[SA32588] Rancid "getipacctg" Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-07
A security issue has been reported in Rancid, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32588/\"]http://secunia.com/advisories/32588/[/url]
--
[SA32587] lmbench Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-07
Some security issue have been reported in lmbench, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32587/\"]http://secunia.com/advisories/32587/[/url]
--
[SA32707] Fedora update for libpng10
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2008-11-13
Fedora has issued an update for libpng10. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/32707/\"]http://secunia.com/advisories/32707/[/url]
--
[SA32710] rPath update for initscripts
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-13
rPath has issued an update for initscripts. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/32710/\"]http://secunia.com/advisories/32710/[/url]
--
[SA32691] Ubuntu update for gnome-screensaver
Critical: Not critical
Where: Local system
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-11-12
Ubuntu has issued an update for gnome-screensaver. This fixes a weakness and a security issue, which can be exploited by malicious people with physical access to disclose potentially sensitive information or bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32691/\"]http://secunia.com/advisories/32691/[/url]
--
[SA32671] WIMS "account.sh" Insecure Temporary Files
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-11
A security issue has been reported in WIMS, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32671/\"]http://secunia.com/advisories/32671/[/url]
--
[SA32667] Sun Solstice X.25 Local Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-11-10
A vulnerability has been reported in Solstice X.25, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/32667/\"]http://secunia.com/advisories/32667/[/url]
--
[SA32655] Linux Kernel Denial of Service Vulnerabilities
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-11-11
Some vulnerabilities have been reported in the Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/32655/\"]http://secunia.com/advisories/32655/[/url]
[b]
Other:--[/b]
[SA32631] 2Wire Routers Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-11-12
hkm has reported a vulnerability in various 2Wire Routers, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/32631/\"]http://secunia.com/advisories/32631/[/url]
--
[SA32635] Siemens SpeedStream 5200 "Host" Header Authentication Bypass
Critical: Less critical
Where: From local network
Impact: Security Bypass
Released: 2008-11-12
hkm has reported a vulnerability in Siemens SpeedStream 5200, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32635/\"]http://secunia.com/advisories/32635/[/url]
--
[SA32623] Sweex RO002 Router Undocumented Account Security Issue
Critical: Less critical
Where: From local network
Impact: Security Bypass
Released: 2008-11-11
Rob Stout has reported a security issue in the Sweex RO002 Router, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32623/\"]http://secunia.com/advisories/32623/[/url]
[b]
Cross Platform:--[/b]
[SA32715] Mozilla Thunderbird Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access, Exposure of sensitive information, Exposure of system information, Security Bypass
Released: 2008-11-13
Some vulnerabilities have been reported in Mozilla Thunderbird, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32715/\"]http://secunia.com/advisories/32715/[/url]
--
[SA32693] Mozilla Firefox 2 Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-13
Some vulnerabilities have been reported in Mozilla Firefox, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32693/\"]http://secunia.com/advisories/32693/[/url]
--
[SA32666] AlstraSoft SendIt Pro File Upload Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-13
ZoRLu has reported a vulnerability in AlstraSoft SendIt Pro, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32666/\"]http://secunia.com/advisories/32666/[/url]
--
[SA32651] OptiPNG BMP Reader Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-11
A vulnerability has been reported in OptiPNG, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32651/\"]http://secunia.com/advisories/32651/[/url]
--
[SA32643] Sanusart Simple PHP Guestbook Script PHP Code Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-11
GoLd_M has reported a vulnerability in Sanusart Simple PHP Guestbook Script, which can be exploited by malicious people to compromise a
vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32643/\"]http://secunia.com/advisories/32643/[/url]
--
[SA32628] Enthusiast "path" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-10
AmnPardaz Security Research Team has discovered a vulnerability in Enthusiast, which can be exploited by malicious people to compromise a
vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32628/\"]http://secunia.com/advisories/32628/[/url]
--
[SA32626] PHPStore Multiple Products File Upload Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-12
ZoRLu has reported a vulnerability in multiple PHPStore products, which can be exploited by malicious users to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32626/\"]http://secunia.com/advisories/32626/[/url]
--
[SA32712] HP Service Manager Unspecified Security Bypass Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-13
A vulnerability has been reported in HP Service Manager, which can be exploited by malicious users to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32712/\"]http://secunia.com/advisories/32712/[/url]
--
[SA32703] ActiveCampaign TrioLive "department_id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-11-12
Russ McRee has reported a vulnerability in ActiveCampaign TrioLive, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32703/\"]http://secunia.com/advisories/32703/[/url]
--
[SA32673] MyioSoft Products "rsargs" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-10
ZoRLu has discovered a vulnerability in multiple MyioSoft products, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32673/\"]http://secunia.com/advisories/32673/[/url]
--
[SA32665] AlstraSoft Article Manager Pro "username" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-11-13
ZoRLu has reported a vulnerability in AlstraSoft Article Manager Pro, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32665/\"]http://secunia.com/advisories/32665/[/url]
--
[SA32663] ClamAV "get_unicode_name()" Off-By-One Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-10
Moritz Jodeit has reported a vulnerability in ClamAV, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32663/\"]http://secunia.com/advisories/32663/[/url]
--
[SA32660] AlstraSoft Web Host Directory "pwd" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-13
ZoRLu has reported a vulnerability in AlstraSoft Web Host Directory, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32660/\"]http://secunia.com/advisories/32660/[/url]
--
[SA32653] WOW Raid Manager "auth_phpbb3.php" Authentication Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-11
A vulnerability has been reported in WOW Raid Manager, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32653/\"]http://secunia.com/advisories/32653/[/url]
--
[SA32652] Trac Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Spoofing, DoS
Released: 2008-11-10
Some vulnerabilities have been reported in Trac, which can be exploited by malicious people to cause a DoS (Denial of Service) or to conduct phishing attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32652/\"]http://secunia.com/advisories/32652/[/url]
--
[SA32647] PozScripts Business Directory Script "cid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-12
Hussin X has reported a vulnerability in PozScripts Business Directory Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32647/\"]http://secunia.com/advisories/32647/[/url]
--
[SA32646] Mole Group Rental Script "username" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-10
Cyber-Zone has reported a vulnerability in Mole Group Rental Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32646/\"]http://secunia.com/advisories/32646/[/url]
[SA32645] OTManager CMS "Tipo" File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-13
colt7r has discovered a vulnerability in OTManager CMS, which can be exploited by malicious users to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32645/\"]http://secunia.com/advisories/32645/[/url]
[SA32644] TurnkeyForms Web Hosting Directory Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-11-13
G4N0K has reported some vulnerabilities in TurnkeyForms Web Hosting Directory, which can be exploited by malicious people to bypass certain
security restrictions and disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/32644/\"]http://secunia.com/advisories/32644/[/url]
[SA32641] E-topbiz Online Store 1 "user" and "cat_id" SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-10
Some vulnerabilities have been reported in E-topbiz Online Store 1, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32641/\"]http://secunia.com/advisories/32641/[/url]
[SA32640] Mini Web Calendar Cross-Site Scripting and Local File Disclosure
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-11-10
ahmadbady has discovered two vulnerabilities in Mini Web Calendar, which can be exploited by malicious people to conduct cross-site scripting attacks or to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/32640/\"]http://secunia.com/advisories/32640/[/url]
[SA32639] E-topbiz Number Links 1 "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-10
Hussin X has reported a vulnerability in E-topbiz Number Links 1, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32639/\"]http://secunia.com/advisories/32639/[/url]
[SA32638] TYPO3 eluna_pagecomments Extension Cross-Site Scripting and SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-11-10
Some vulnerabilities have been reported in the eluna_pagecomments extension for TYPO3, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32638/\"]http://secunia.com/advisories/32638/[/url]
[SA32637] Domain Seller Pro "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-10
TR-ShaRk has reported a vulnerability in Domain Seller Pro, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32637/\"]http://secunia.com/advisories/32637/[/url]
[SA32636] MyioSoft EasyBookMarker "Parent" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-10
G4N0K has discovered a vulnerability in MyioSoft EasyBookMarker, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32636/\"]http://secunia.com/advisories/32636/[/url]
[SA32632] MemHT Portal "title" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-12
Ams has discovered a vulnerability in MemHT Portal, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32632/\"]http://secunia.com/advisories/32632/[/url]
[SA32622] Joomla! Script Insertion Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-11
Some vulnerabilities have been reported in Joomla!, which can be exploited by malicious users and potentially malicious people to conduct script insertion attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32622/\"]http://secunia.com/advisories/32622/[/url]
[SA32617] Zeeways Shaadi Clone Authentication Bypass Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-11
G4N0K has reported a vulnerability in Zeeways Shaadi Clone, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32617/\"]http://secunia.com/advisories/32617/[/url]
[SA32613] Mole Group Pizza Online Ordering Script "manufacturers_id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-07
Cyb3r-1sT has reported a vulnerability in Mole Group Pizza Online Ordering Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32613/\"]http://secunia.com/advisories/32613/[/url]
[SA32603] V3 Chat Products "admin" Cookie Security Bypass Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-10
Cyber-Zone has reported a vulnerability in multiple V3 Chat products, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32603/\"]http://secunia.com/advisories/32603/[/url]
[SA32601] Zeeways PhotoVideoTube Authentication Bypass Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-11
Mountassif Moad has reported a vulnerability in Zeeways PhotoVideoTube, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32601/\"]http://secunia.com/advisories/32601/[/url]
[SA32600] AJSquare Free Polling Script Authentication Bypass Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-12
G4N0K has discovered a vulnerability in AJ Square Free Polling Script, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32600/\"]http://secunia.com/advisories/32600/[/url]
[SA32596] DevelopItEasy Events Calendar Multiple SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-07
Cyb3r-1sT has reported some vulnerabilities in DevelopItEasy Events Calendar, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32596/\"]http://secunia.com/advisories/32596/[/url]
[SA32595] DevelopItEasy News And Article System Multiple SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-07
Cyb3r-1sT has reported some vulnerabilities in DevelopItEasy News And Article System, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32595/\"]http://secunia.com/advisories/32595/[/url]
[SA32594] DevelopItEasy Membership System Multiple SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-07
Cyb3r-1sT has reported some vulnerabilities in DevelopItEasy Membership System, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32594/\"]http://secunia.com/advisories/32594/[/url]
[SA32593] DevelopItEasy Photo Gallery Multiple SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-07
Cyb3r-1sT has reported some vulnerabilities in DevelopItEasy Photo Gallery, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32593/\"]http://secunia.com/advisories/32593/[/url]
[SA32591] TurnkeyForms Local Classifieds SQL Injection and Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of sensitive information
Released: 2008-11-07
A vulnerability and a security issue have been reported in TurnkeyForms Local Classifieds, which can be exploited by malicious people to conduct SQL injection attacks and bypass certain security restrictions
Full Advisory: [url=\"http://secunia.com/advisories/32591/\"]http://secunia.com/advisories/32591/[/url]
[SA32586] PHP Classifieds "admin_username" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-07
ZoRLu has reported a vulnerability in PHP Classifieds, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32586/\"]http://secunia.com/advisories/32586/[/url]
[SA32689] TYPO3 "file" Backend Module Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-13
A vulnerability has been reported in TYPO3, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32689/\"]http://secunia.com/advisories/32689/[/url]
[SA32670] Sun Java System Messaging Server Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-13
A vulnerability has been reported in Sun Java System Messaging Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32670/\"]http://secunia.com/advisories/32670/[/url]
[SA32657] buymyscripts.net Lyrics Script "k" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-12
A vulnerability has been reported in buymyscripts.net Lyrics Script, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32657/\"]http://secunia.com/advisories/32657/[/url]
[SA32654] TYPO3 phpMyAdmin Extension "db" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-10
A vulnerability has been reported in the phpMyAdmin extension for TYPO3, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32654/\"]http://secunia.com/advisories/32654/[/url]
[SA32650] buymyscripts.net Clickbank Portal "keyword" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-12
A vulnerability has been reported in buymyscripts.net Clickbank Portal, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32650/\"]http://secunia.com/advisories/32650/[/url]
[SA32649] buymyscripts.net Recipe Website Script "keyword" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-12
A vulnerability has been reported in buymyscripts.net Recipe Website Script, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32649/\"]http://secunia.com/advisories/32649/[/url]
[SA32642] Fresh Email Script "Email" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-13
Don has reported a vulnerability in Fresh Email Script, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32642/\"]http://secunia.com/advisories/32642/[/url]
[SA32680] Blender Insecure Python Module Search Path Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-12
A vulnerability has been reported in Blender, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32680/\"]http://secunia.com/advisories/32680/[/url]
[SA32624] VMware ESX / ESXi Privilege Escalation and Directory Traversal Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-07
Some vulnerabilities have been reported in VMware ESX and ESXi, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32624/\"]http://secunia.com/advisories/32624/[/url]
[SA32612] VMware Products Privilege Escalation Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-07
A vulnerability has been reported in various VMware products, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32612/\"]http://secunia.com/advisories/32612/[/url]
[SA32686] MoinMoin Full Path Disclosure Weakness
Critical: Not critical
Where: From remote
Impact: Exposure of system information
Released: 2008-11-10
Xia Shing Zee has discovered a weakness in MoinMoin, which can be exploited by malicious people to disclose system information.
Full Advisory: [url=\"http://secunia.com/advisories/32686/\"]http://secunia.com/advisories/32686/[/url]
Secunia Updates - November 2008
Posted: Sat Nov 22, 2008 5:35 am
by Tami
[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing For The Week of November 20 2008[/b][/i]
[b]Windows:--[/b]
[SA32772] Adobe AIR Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-18
Some vulnerabilities have been reported in Adobe AIR, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32772/\"]http://secunia.com/advisories/32772/[/url]
--
[SA32743] GungHo LoadPrgAx ActiveX Control Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-17
A vulnerability has been reported in the GungHo LoadPrgAx ActiveX control, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32743/\"]http://secunia.com/advisories/32743/[/url]
--
[SA32729] Exodus Improper "im://" URI Handling Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-18
strawdog has discovered a vulnerability in Exodus, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32729/\"]http://secunia.com/advisories/32729/[/url]
--
[SA32725] VeryDOC PDF Viewer ActiveX Control "OpenPDF()" Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-17
r0ut3r has discovered a vulnerability in the VeryDOC PDF Viewer ActiveX control, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32725/\"]http://secunia.com/advisories/32725/[/url]
--
[SA32785] Pre ASP Job Board "Username" and "Password" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-11-20
R3d-D3v!L has reported some vulnerabilities in Pre ASP Job Board, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32785/\"]http://secunia.com/advisories/32785/[/url]
--
[SA32750] Openasp "idpage" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-18
athos has discovered a vulnerability in Openasp, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32750/\"]http://secunia.com/advisories/32750/[/url]
--
[SA32810] Symantec Backup Exec for Windows Servers Multiple Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: Security Bypass, DoS, System access
Released: 2008-11-20
Some vulnerabilities have been reported in Symantec Backup Exec for Windows Servers, which can be exploited by malicious people to bypass certain security restrictions and by malicious users to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32810/\"]http://secunia.com/advisories/32810/[/url]
--
[SA32771] Flash Media Server Video Stream Capture Security Issue
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-18
A security issue has been reported in Flash Media Server, which can be exploited by malicious people to capture content.
Full Advisory: [url=\"http://secunia.com/advisories/32771/\"]http://secunia.com/advisories/32771/[/url]
--
[SA32738] Chilkat Socket ActiveX Component "SaveLastError()" Insecure Method
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-18
Zigma has discovered a vulnerability in Chilkat Socket ActiveX Component, which can be exploited by malicious people to overwrite arbitrary files.
Full Advisory: [url=\"http://secunia.com/advisories/32738/\"]http://secunia.com/advisories/32738/[/url]
[b]
UNIX/Linux:--[/b]
[SA32798] Red Hat update for thunderbird
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-20
Red Hat has issued an update for thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32798/\"]http://secunia.com/advisories/32798/[/url]
--
[SA32796] imlib2 XPM Processing Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-20
A vulnerability has been discovered in imlib2, which can be exploited by malicious people to potentially compromise an application using the library.
Full Advisory: [url=\"http://secunia.com/advisories/32796/\"]http://secunia.com/advisories/32796/[/url]
--
[SA32778] Ubuntu update for firefox, firefox-3.0, and xulrunner-1.9
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-19
Ubuntu has issued an update for firefox, firefox-3.0, and xulrunner-1.9. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32778/\"]http://secunia.com/advisories/32778/[/url]
--
[SA32766] Red Hat update for libxml2
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-18
Red Hat has issued an update for libxml2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.
Full Advisory: [url=\"http://secunia.com/advisories/32766/\"]http://secunia.com/advisories/32766/[/url]
--
[SA32764] Ubuntu update for libxml2
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-19
Ubuntu has issued an update for libxml2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.
Full Advisory: [url=\"http://secunia.com/advisories/32764/\"]http://secunia.com/advisories/32764/[/url]
--
[SA32762] Debian update for libxml2
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-18
Debian has issued an update for libxml2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.
Full Advisory: [url=\"http://secunia.com/advisories/32762/\"]http://secunia.com/advisories/32762/[/url]
--
[SA32749] Slackware update for mozilla-firefox
Critical: Highly critical
Where: From remote
Impact: System access, Exposure of sensitive information, Exposure of system information, Security Bypass
Released: 2008-11-17
Slackware has issued an update for mozilla-firefox. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32749/\"]http://secunia.com/advisories/32749/[/url]
--
[SA32748] Slackware update for seamonkey
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-17
Slackware has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32748/\"]http://secunia.com/advisories/32748/[/url]
--
[SA32721] Fedora update for firefox and xulrunner
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-14
Fedora has issued an update for firefox and xulrunner. This fixes some vulnerabilities, which can be exploited by malicious people to disclose
sensitive information, bypass certain security restrictions, or compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32721/\"]http://secunia.com/advisories/32721/[/url]
--
[SA32811] Slackware update for libxml2
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-20
Slackware has issued an update for libxml2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.
Full Advisory: [url=\"http://secunia.com/advisories/32811/\"]http://secunia.com/advisories/32811/[/url]
--
[SA32807] rPath update for libxml2
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-20
rPath has issued an update for libxml2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.
Full Advisory: [url=\"http://secunia.com/advisories/32807/\"]http://secunia.com/advisories/32807/[/url]
--
[SA32802] Fedora update for libxml2
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-20
Fedora has issued an update for libxml2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.
Full Advisory: [url=\"http://secunia.com/advisories/32802/\"]http://secunia.com/advisories/32802/[/url]
--
[SA32793] Debian update for python2.4
Critical: Moderately critical
Where: From remote
Impact: Unknown, DoS, System access
Released: 2008-11-20
Debian has issued an update for python2.4. This fixes some vulnerabilities, where some have unknown impact and others can potentially be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32793/\"]http://secunia.com/advisories/32793/[/url]
--
[SA32773] Libxml2 Two Integer Overflow Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-18
Two vulnerabilities have been reported in Libxml2, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.
Full Advisory: [url=\"http://secunia.com/advisories/32773/\"]http://secunia.com/advisories/32773/[/url]
--
[SA32765] Ubuntu update for clamav
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-18
Ubuntu has issued an update for clamav. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32765/\"]http://secunia.com/advisories/32765/[/url]
--
[SA32759] SUSE Update for Multiple Packages
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-11-17
SUSE has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, disclose potentially sensitive information, or potentially gain escalated privileges, by malicious users to cause a DoS (Denial of Service), and by malicious people to bypass certain security restrictions, disclose potentially sensitive information, cause a DoS, or potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32759/\"]http://secunia.com/advisories/32759/[/url]
--
[SA32753] rPath update for enscript
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-18
rPath has issued an update for enscript. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32753/\"]http://secunia.com/advisories/32753/[/url]
--
[SA32746] Gentoo update for php
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass, Exposure of sensitive information, DoS, System access
Released: 2008-11-17
Gentoo has issued an update for php. This fixes some vulnerabilities, where some have unknown impacts and others can be exploited by malicious users to bypass certain security restrictions, and potentially by malicious people to disclose potentially sensitive information, cause a DoS (Denial of Service), or to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32746/\"]http://secunia.com/advisories/32746/[/url]
--
[SA32720] Astaro update for libspf2
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-14
Astaro has issued an update for libspf2. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise an application using the library.
Full Advisory: [url=\"http://secunia.com/advisories/32720/\"]http://secunia.com/advisories/32720/[/url]
--
[SA32805] Fedora update for roundup
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-20
Fedora has issued an update for roundup. This fixes a security issue, which can be exploited by malicious users to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32805/\"]http://secunia.com/advisories/32805/[/url]
--
[SA32803] Fedora update for grip
Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-11-20
Fedora has issued an update for grip. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32803/\"]http://secunia.com/advisories/32803/[/url]
--
[SA32800] HP OpenView Network Node Manager Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-20
HP has acknowledged some vulnerabilities in OpenView Network Node Manager, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32800/\"]http://secunia.com/advisories/32800/[/url]
--
[SA32768] Dovecot ManageSieve Directory Traversal Security Issue
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-18
A security issue has been reported in Dovecot ManageSieve, which can be exploited by malicious users to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32768/\"]http://secunia.com/advisories/32768/[/url]
--
[SA32761] No-IP Linux Dynamic Update Client Buffer Overflow Vulnerability
Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-11-19
xenomuta has reported a vulnerability in No-IP Linux Dynamic Update Client (DUC), which potentially can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32761/\"]http://secunia.com/advisories/32761/[/url]
--
[SA32719] Linux Kernel "hfs_cat_find_brec()" Buffer Overflow Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-14
A vulnerability has been reported in the Linux Kernel, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32719/\"]http://secunia.com/advisories/32719/[/url]
--
[SA32769] Ubuntu update for mysql-dfsg-5.0
Critical: Less critical
Where: From local network
Impact: Security Bypass, DoS
Released: 2008-11-18
Ubuntu has issued an update for mysql-dfsg-5.0. This fixes a security issue and a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions and malicious users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/32769/\"]http://secunia.com/advisories/32769/[/url]
--
[SA32760] OpenSSH CBC Mode Plaintext Recovery Vulnerability
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2008-11-17
A vulnerability has been reported in OpenSSH, which potentially can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/32760/\"]http://secunia.com/advisories/32760/[/url]
--
[SA32820] SystemImager "si_mkbootserver" Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-20
A security issue has been reported in SystemImager, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32820/\"]http://secunia.com/advisories/32820/[/url]
--
[SA32780] pam_mount "passwdehd" Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-20
A security issue has been reported in pam_mount, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32780/\"]http://secunia.com/advisories/32780/[/url]
--
[SA32774] Citrix XenServer Ext2/Ext3 Processing Security Bypass Vulnerability
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-11-19
A vulnerability has been reported in Citrix XenServer, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32774/\"]http://secunia.com/advisories/32774/[/url]
--
[SA32730] MailScanner "trend-autoupdate" Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-20
A security issue has been reported in MailScanner, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32730/\"]http://secunia.com/advisories/32730/[/url]
--
[SA32804] Fedora update for cobbler
Critical: Not critical
Where: From remote
Impact: Privilege escalation
Released: 2008-11-20
Fedora has issued an update for cobbler. This fixes a vulnerability, which can be exploited by malicious users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32804/\"]http://secunia.com/advisories/32804/[/url]
--
[SA32737] Cobbler Web Interface Privilege Escalation Vulnerability
Critical: Not critical
Where: From remote
Impact: Privilege escalation
Released: 2008-11-17
A vulnerability has been reported in Cobbler, which can be exploited by malicious users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32737/\"]http://secunia.com/advisories/32737/[/url]
--
[SA32818] P3nfs Insecure Temporary Files
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-20
A security issue has been reported in P3nfs, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32818/\"]http://secunia.com/advisories/32818/[/url]
--
[SA32799] Red Hat update for kernel
Critical: Not critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-11-20
Red Hat has issued an update for the kernel. This fixes a security issue and some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32799/\"]http://secunia.com/advisories/32799/[/url]
--
[SA32792] Ubuntu update for hplip
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-11-20
Ubuntu has issued an update for hplip. This fixes a security issue, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/32792/\"]http://secunia.com/advisories/32792/[/url]
[b]
Other:--[/b]
[SA32716] Netgear WGR614 Web Interface Request Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-11-18
sr. has reported a vulnerability in Netgear WGR614v9, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/32716/\"]http://secunia.com/advisories/32716/[/url]
[b]
Cross Platform:--[/b]
[SA32745] Free Directory Script "API_HOME_DIR" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-19
Ghost Hacker has discovered a vulnerability in Free Directory Script, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32745/\"]http://secunia.com/advisories/32745/[/url]
--
[SA32734] phpFan "includepath" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-18
Ahmadbady has reported a vulnerability in phpFan, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32734/\"]http://secunia.com/advisories/32734/[/url]
--
[SA32783] W3matter Multiple Products "f[password]" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-11-20
Some vulnerabilities have been reported in multiple W3matter products, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32783/\"]http://secunia.com/advisories/32783/[/url]
--
[SA32751] mxCamArchive Information Disclosure and PHP Code Execution
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2008-11-18
Ahmadbady has discovered some vulnerabilities in mxCamArchive, which can be exploited by malicious people to disclose sensitive information and malicious users to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32751/\"]http://secunia.com/advisories/32751/[/url]
--
[SA32747] E-topbiz AdManager "group" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-18
Hussin X has reported a vulnerability in E-topbiz AdManager, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32747/\"]http://secunia.com/advisories/32747/[/url]
--
[SA32744] ScriptsEz FREEze Greetings "pwd.txt" Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-11-18
cOndemned has discovered a security issue in ScriptsEz FREEze Greetings, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/32744/\"]http://secunia.com/advisories/32744/[/url]
--
[SA32741] PHPStore Wholesales "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-17
Hussin X has reported a vulnerability in PHPStore Wholesales, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32741/\"]http://secunia.com/advisories/32741/[/url]
--
[SA32736] Pluck "g_pcltar_lib_dir" Local File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-11-18
Digital Security Research Group have reported a vulnerability in Pluck, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/32736/\"]http://secunia.com/advisories/32736/[/url]
--
[SA32733] Jadu Galaxies "categoryID" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-18
ZoRLu has reported a vulnerability in Jadu Galaxies, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32733/\"]http://secunia.com/advisories/32733/[/url]
--
[SA32732] TurnkeyForms Text Link Sales SQL Injection and Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-11-17
Some vulnerabilities have been reported in TurnkeyForms Text Link Sales, which can be exploited by malicious people to bypass certain security restrictions and by malicious users to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32732/\"]http://secunia.com/advisories/32732/[/url]
--
[SA32727] Simple Customer "email" and "password" SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-18
d3b4g has discovered some vulnerabilities in Simple Customer, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32727/\"]http://secunia.com/advisories/32727/[/url]
--
[SA32726] SaturnCMS Multiple SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-11-18
Hussin X has reported some vulnerabilities in SaturnCMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32726/\"]http://secunia.com/advisories/32726/[/url]
--
[SA32724] Ultrastats "serverid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-18
eek has discovered a vulnerability in Ultrastats, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32724/\"]http://secunia.com/advisories/32724/[/url]
--
[SA32718] VideoScript "admin/cp.php" Security Bypass Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-18
G4N0K has reported a vulnerability in VideoScript, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32718/\"]http://secunia.com/advisories/32718/[/url]
--
[SA32717] PHPStore Yahoo Answers "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-17
Snakespc has reported a vulnerability in PHPStore Yahoo Answers, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32717/\"]http://secunia.com/advisories/32717/[/url]
--
[SA32815] refbase "headerMsg" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-20
A vulnerability has been reported in refbase, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32815/\"]http://secunia.com/advisories/32815/[/url]
--
[SA32788] MyTopix "send" SQL Injection Vulnerability
Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-20
cOndemned has discovered a vulnerability in MyTopix, which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32788/\"]http://secunia.com/advisories/32788/[/url]
--
[SA32779] KimsON Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-19
md.r00t has reported a vulnerability in KimsON, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32779/\"]http://secunia.com/advisories/32779/[/url]
--
[SA32757] BoutikOne CMS "search_query" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-17
d3v1l has reported a vulnerability in BoutikOne CMS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32757/\"]http://secunia.com/advisories/32757/[/url]
--
[SA32739] Streber Unspecified Cross-Site Request Forgery Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-18
Some vulnerabilities have been reported in Streber, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32739/\"]http://secunia.com/advisories/32739/[/url]
--
[SA32740] SSH Tectia Products CBC Mode Plaintext Recovery Vulnerability
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2008-11-17
A vulnerability has been reported in multiple SSH Tectia products, which potentially can be exploited by malicious people to disclose sensitive nformation.
Full Advisory: [url=\"http://secunia.com/advisories/32740/\"]http://secunia.com/advisories/32740/[/url]
--
[SA32775] vBulletin SQL Injection Vulnerabilities
Critical: Not critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-18
Janek Vind has reported some vulnerabilities in vBulletin, which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32775/\"]http://secunia.com/advisories/32775/[/url]
--
[SA32752] Opera "file://" URI Handling Buffer Overflow Vulnerability
Critical: Not critical
Where: From remote
Impact: System access
Released: 2008-11-18
send9 has discovered a vulnerability in Opera, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32752/\"]http://secunia.com/advisories/32752/[/url]
--
[SA32735] vBulletin Calender SQL Injection Vulnerability
Critical: Not critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-18
Janek Vind has reported some vulnerabilities in vBulletin, which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32735/\"]http://secunia.com/advisories/32735/[/url]
Secunia Updates - November 2008
Posted: Thu Nov 27, 2008 5:13 pm
by Tami
[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of November 27 2008[/b][/i]
[b]
Windows:--[/b]
[SA32881] K-Lite Codec Pack ffdshow URL Processing Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-26
A vulnerability has been reported in K-Lite Codec Pack, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32881/\"]http://secunia.com/advisories/32881/[/url]
--
[SA32850] Nero ShowTime M3U Processing Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-27
Gjoko 'LiquidWorm' Krstic has reported a vulnerability in Nero ShowTime, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32850/\"]http://secunia.com/advisories/32850/[/url]
--
[SA32846] ffdshow URL Processing Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-24
A vulnerability has been reported in ffdshow, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32846/\"]http://secunia.com/advisories/32846/[/url]
--
[SA32829] FlexCell Grid ActiveX Control "HttpDownloadFile()" Arbitrary File Overwrite
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-24
Alfons Luja has discovered a vulnerability in the FlexCell Grid ActiveX control, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32829/\"]http://secunia.com/advisories/32829/[/url]
--
[SA32823] Quicksilver Forums "lang" File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, Exposure of system information
Released: 2008-11-25
__GiReX__ has reported a vulnerability in Quicksilver Forums, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/32823/\"]http://secunia.com/advisories/32823/[/url]
--
[SA32852] iPhone Configuration Web Utility for Windows Directory Traversal
Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-11-24
A vulnerability has been discovered in iPhone Configuration Web Utility for Windows, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/32852/\"]http://secunia.com/advisories/32852/[/url]
[b]UNIX/Linux:--[/b]
[SA32878] Ubuntu update for thunderbird
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-26
Ubuntu has issued an update for mozilla-thunderbird and thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32878/\"]http://secunia.com/advisories/32878/[/url]
--
[SA32876] SUSE Update for Mozilla Products
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-26
SUSE has issued an update for MozillaFirefox, MozillaThunderbird, and seamonkey. This fixes some vulnerabilities, which can be exploited by
malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32876/\"]http://secunia.com/advisories/32876/[/url]
--
[SA32872] SUSE Update for Multiple Packages
Critical: Highly critical
Where: From remote
Impact: Privilege escalation, DoS, System access
Released: 2008-11-25
SUSE has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges or by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32872/\"]http://secunia.com/advisories/32872/[/url]
--
[SA32860] Ubuntu update for webkit
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-25
Ubuntu has issued an update for webkit. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32860/\"]http://secunia.com/advisories/32860/[/url]
--
[SA32856] Ubuntu update for openoffice.org
Critical: Highly critical
Where: From remote
Impact: Privilege escalation, System access
Released: 2008-11-25
Ubuntu has issued an update for openoffice.org and openoffice.org-amd64. This fixes some vulnerabilities and a security issue, which potentially can be exploited by malicious people to compromise a user's system, and by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32856/\"]http://secunia.com/advisories/32856/[/url]
--
[SA32853] Debian update for iceweasel
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-25
Debian has issued an update for iceweasel. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32853/\"]http://secunia.com/advisories/32853/[/url]
--
[SA32845] Debian update for xulrunner
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-11-24
Debian has issued an update for xulrunner. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, to disclose sensitive information, or to potentially compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32845/\"]http://secunia.com/advisories/32845/[/url]
--
[SA32843] Fedora update for imlib2
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-26
Fedora has issued an update for imlib2. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise an application using the library.
Full Advisory: [url=\"http://secunia.com/advisories/32843/\"]http://secunia.com/advisories/32843/[/url]
--
[SA32835] Slackware update for mozilla-thunderbird
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-24
Slackware has issued an update for mozilla-thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32835/\"]http://secunia.com/advisories/32835/[/url]
--
[SA32884] HP Secure Web Server/Internet Express for Tru64 UNIX PHP Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-26
HP has acknowledged a vulnerability in Secure Web Server for Tru64 UNIX and Internet Express for Tru64 UNIX, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32884/\"]http://secunia.com/advisories/32884/[/url]
--
[SA32879] Ubuntu update for GnuTLS
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Spoofing
Released: 2008-11-26
Ubuntu has issued an update for gnutls12, gnutls13, and gnutls26. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32879/\"]http://secunia.com/advisories/32879/[/url]
--
[SA32864] Red Hat update for vim
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-25
Red Hat has issued an update for vim. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32864/\"]http://secunia.com/advisories/32864/[/url]
--
[SA32863] Red Hat update for vim
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-25
Red Hat has issued an update for vim. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32863/\"]http://secunia.com/advisories/32863/[/url]
--
[SA32861] Ubuntu update for gaim
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-25
Ubuntu has issued an update for gaim. This fixes some vulnerabilities, which can be exploited by malicious people to potentially compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32861/\"]http://secunia.com/advisories/32861/[/url]
--
[SA32859] Ubuntu update for pidgin
Critical: Moderately critical
Where: From remote
Impact: Spoofing, DoS, System access
Released: 2008-11-25
Ubuntu has issued an update for pidgin. This fixes some vulnerabilities, which can be exploited by malicious people to conduct spoofing attacks and potentially compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32859/\"]http://secunia.com/advisories/32859/[/url]
--
[SA32858] Red Hat update for vim
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-25
Red Hat has issued an update for vim. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32858/\"]http://secunia.com/advisories/32858/[/url]
--
[SA32854] Debian update for enscript
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-25
Debian has issued an update for enscript. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32854/\"]http://secunia.com/advisories/32854/[/url]
--
[SA32839] rPath update for vim, vim-minimal, and gvim
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-25
rPath has issued an update for vim, vim-minimal, and gvim. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32839/\"]http://secunia.com/advisories/32839/[/url]
--
[SA32834] SUSE update for phpMyAdmin and lighttpd
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, Manipulation of data, Exposure of system information, Exposure of sensitive information, DoS
Released: 2008-11-25
SUSE has issued an update for phpMyAdmin and lighttpd. This fixes some vulnerabilities, which can be exploited by malicious, local users to conduct cross-site scripting attacks, and by malicious users to disclose system and potentially sensitive information, and by malicious people to conduct spoofing attacks, conduct SQL injection attacks, disclose system and potentially sensitive information, and cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/32834/\"]http://secunia.com/advisories/32834/[/url]
--
[SA32871] FreeBSD "arc4random()" Insufficient Entropy Sources Security Issue
Critical: Less critical
Where: From remote
Impact: Brute force
Released: 2008-11-25
FreeBSD has acknowledged a security issue, which can be exploited by malicious people to conduct brute force attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32871/\"]http://secunia.com/advisories/32871/[/url]
--
[SA32838] rPath update for httpd
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2008-11-24
rPath has issued an update for httpd. This fixes some vulnerabilities, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32838/\"]http://secunia.com/advisories/32838/[/url]
--
[SA32862] Red Hat update for tog-pegasus
Critical: Less critical
Where: From local network
Impact: Security Bypass, Brute force
Released: 2008-11-25
Red Hat has issued an update for tog-pegasus. This fixes a security issues and a weakness, which can be exploited by people to conduct brute force attacks and malicious users to bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32862/\"]http://secunia.com/advisories/32862/[/url]
--
[SA32916] IBM AIX Multiple Privilege Escalation Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-27
Some vulnerabilities have been reported in IBM AIX, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32916/\"]http://secunia.com/advisories/32916/[/url]
--
[SA32855] Debian update for hf
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-24
Debian has issued an update for hf. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32855/\"]http://secunia.com/advisories/32855/[/url]
--
[SA32832] SUSE update for yast2-backup
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-25
SUSE has issued an update for yast2-backup. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32832/\"]http://secunia.com/advisories/32832/[/url]
--
[SA32831] hf "hfkernel" Privilege Escalation Security Issue
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-24
Steve Kemp has reported a security issue in hf, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32831/\"]http://secunia.com/advisories/32831/[/url]
--
[SA32875] Fedora update for geda-gnetlist
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-25
Fedora has issued an update for geda-gnetlist. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32875/\"]http://secunia.com/advisories/32875/[/url]
--
[SA32851] VirtualBox "AcquireDaemonLock()" Insecure Temporary Files
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-25
A security issue has been reported in VirtualBox, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: [url=\"http://secunia.com/advisories/32851/\"]http://secunia.com/advisories/32851/[/url]
[b]Other:--[/b]
[SA32827] Siemens C450IP / C475IP Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-11-27
A vulnerability has been reported in Siemens C450IP / C475IP, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/32827/\"]http://secunia.com/advisories/32827/[/url]
--
[SA32836] I-O DATA HDL-F Series Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-26
A vulnerability has been reported in I-O DATA HDL-F series, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32836/\"]http://secunia.com/advisories/32836/[/url]
[b]Cross Platform:--[/b]
[SA32848] Amaya Two Buffer Overflow Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-25
r0ut3r has discovered two vulnerabilities in Amaya, which can be exploited by malicious people to compromise a user's system.
Full Advisory: [url=\"http://secunia.com/advisories/32848/\"]http://secunia.com/advisories/32848/[/url]
--
[SA32825] LoveCMS Download Manager Module File Upload Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-26
cOndemned has discovered a vulnerability in the Download Manager module for LoveCMS, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32825/\"]http://secunia.com/advisories/32825/[/url]
--
[SA32824] MODx CMS "reflect_base" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-24
RoMaNcYxHaCkEr has discovered a vulnerability in MODx CMS, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: [url=\"http://secunia.com/advisories/32824/\"]http://secunia.com/advisories/32824/[/url]
--
[SA32887] Star Articles "subcatid" and "artid" SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-27
b3hz4d has reported some vulnerabilities in Star Articles, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32887/\"]http://secunia.com/advisories/32887/[/url]
--
[SA32874] WebStudio eHotel "pageid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-26
Hussin X has reported a vulnerability in WebStudio eHotel, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32874/\"]http://secunia.com/advisories/32874/[/url]
--
[SA32873] WebStudio eCatalogue "pageid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-26
Hussin X has reported a vulnerability in WebStudio eCatalogue, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32873/\"]http://secunia.com/advisories/32873/[/url]
--
[SA32868] FAQ Manager SQL Injection and File Inclusion Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-11-26
Some vulnerabilities have been discovered in FAQ Manager, which can be exploited by malicious people to disclose sensitive information and conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32868/\"]http://secunia.com/advisories/32868/[/url]
--
[SA32866] Clean CMS "id" Cross-Site Scripting and SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-11-26
ZoRLu has discovered a vulnerability in Clean CMS, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32866/\"]http://secunia.com/advisories/32866/[/url]
--
[SA32865] fuzzylime (cms) "p" File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-11-26
Alfons Luja has discovered a vulnerability in Fuzzylime CMS, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/32865/\"]http://secunia.com/advisories/32865/[/url]
--
[SA32844] Cars Portal "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-26
Snakespc has reported a vulnerability in Cars Portal, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32844/\"]http://secunia.com/advisories/32844/[/url]
--
[SA32841] PG Multiple Products "login_lg" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-11-24
ZoRLu has reported a vulnerability in multiple PG products, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32841/\"]http://secunia.com/advisories/32841/[/url]
--
[SA32840] Wireshark SMTP Processing Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-11-24
A vulnerability has been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: [url=\"http://secunia.com/advisories/32840/\"]http://secunia.com/advisories/32840/[/url]
--
[SA32837] PG Job Site Pro "poll_view_id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-24
ZoRLu has reported a vulnerability in PG Job Site Pro, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32837/\"]http://secunia.com/advisories/32837/[/url]
--
[SA32830] xt:Commerce SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-21
A vulnerability has been reported in xt:Commerce, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32830/\"]http://secunia.com/advisories/32830/[/url]
--
[SA32826] Red Hat update for java-1.4.2-ibm
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information
Released: 2008-11-25
Red Hat has issued an update for java-1.4.2-ibm. This fixes some vulnerabilities, which can be exploited by malicious people to disclose system and potentially sensitive information and bypass certain security restrictions.
Full Advisory: [url=\"http://secunia.com/advisories/32826/\"]http://secunia.com/advisories/32826/[/url]
--
[SA32822] Easyedit CMS Multiple SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-21
d3v1l has reported some vulnerabilities in Easyedit CMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32822/\"]http://secunia.com/advisories/32822/[/url]
--
[SA32905] Drupal Comment Mail Module Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-27
A vulnerability has been reported in the Comment Mail module for Drupal, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32905/\"]http://secunia.com/advisories/32905/[/url]
--
[SA32904] Drupal User Karma Module Cross-Site Scripting and SQL Injection
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-11-27
Some vulnerabilities have been reported in the User Karma module for Drupal, which can be exploited by malicious users to conduct SQL injection attacks and by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32904/\"]http://secunia.com/advisories/32904/[/url]
--
[SA32898] Post Affiliate Pro "umprof_status" SQL Injection Vulnerability
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-27
XaDoS has reported a vulnerability in Post Affiliate Pro, which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32898/\"]http://secunia.com/advisories/32898/[/url]
--
[SA32882] WordPress "Host" Header RSS Feed Script Insertion Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-26
Jeremias Reith has reported a vulnerability in WordPress, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32882/\"]http://secunia.com/advisories/32882/[/url]
--
[SA32880] MyBB "Referer" Header "my_post_key" Token Disclosure
Critical: Less critical
Where: From remote
Impact: Hijacking, Cross Site Scripting, Exposure of sensitive information
Released: 2008-11-26
NBBN has discovered some vulnerabilities in MyBB, which can be exploited can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/32880/\"]http://secunia.com/advisories/32880/[/url]
--
[SA32867] COMS "q" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-25
Pouya_Server has reported a vulnerability in COMS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32867/\"]http://secunia.com/advisories/32867/[/url]
--
[SA32828] Softbiz Classifieds Script "msg" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-21
Vahid Ezraeil has reported a vulnerability in Softbiz Classifieds Script, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: [url=\"http://secunia.com/advisories/32828/\"]http://secunia.com/advisories/32828/[/url]
--
[SA32833] Attachmate Products SSH CBC Mode Plaintext Recovery Vulnerability
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2008-11-24
A vulnerability has been reported in various Attachmate products, which potentially can be exploited by malicious people to disclose sensitive information.
Full Advisory: [url=\"http://secunia.com/advisories/32833/\"]http://secunia.com/advisories/32833/[/url]