Secunia Bulletins March 2008
Posted: Fri Mar 07, 2008 5:52 pm
[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing For March 7 2008[/b][/i]
[b]Windows:--[/b]
[SA29233] Programmer's Notepad ctags Processing Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-06
A vulnerability has been discovered in Programmer's Notepad, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29233/\"]http://secunia.com/advisories/29233/[/url]
--
[SA29195] Learn2 STRunner ActiveX Control Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-03
Will Dormann has reported some vulnerabilities in Learn2 STRunner ActiveX control, which can be exploited by malicious people to
compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29195/\"]http://secunia.com/advisories/29195/[/url]
--
[SA29230] Versant Object Database Command Execution Vulnerability
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-03-05
Luigi Auriemma has discovered a vulnerability in Versant Object Database, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29230/\"]http://secunia.com/advisories/29230/[/url]
--
[SA29213] Borland VisiBroker Smart Agent Packet Handling
Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-04
Luigi Auriemma has reported some vulnerabilities in Borland VisiBroker, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29213/\"]http://secunia.com/advisories/29213/[/url]
--
[SA29208] Borland StarTeam StarTeamMPX and StarTeam Server Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-03
Luigi Auriemma has reported some vulnerabilities in Borland StarTeam, which can be exploited by malicious users or malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29208/\"]http://secunia.com/advisories/29208/[/url]
--
[SA29207] PacketTrap pt360 TFTP Server Two Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-03-05
Two vulnerabilities have been reported in the PacketTrap pt360, which can be exploited by malicious people to cause a DoS (Denial of
Service), disclose sensitive information, or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29207/\"]http://secunia.com/advisories/29207/[/url]
--
[SA29246] eScan Corporate Edition eScan Management Console FTP Server Arbitrary File Download
Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-06
Luigi Auriemma has discovered a vulnerability in eScan Corporate Edition, which can be exploited by malicious people to disclose
sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29246/\"]http://secunia.com/advisories/29246/[/url]
--
[SA29231] Perforce Server Denial of Service Vulnerabilities
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-03-06
Luigi Auriemma has discovered some vulnerabilities in Perforce Server, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29231/\"]http://secunia.com/advisories/29231/[/url]
[b]UNIX/Linux:--[/b]
[SA29258] Gentoo update for evolution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-06
Gentoo has issued an update for evolution. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29258/\"]http://secunia.com/advisories/29258/[/url]
--
[SA29244] Debian update for evolution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-06
Debian has issued an update for evolution. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29244/\"]http://secunia.com/advisories/29244/[/url]
--
[SA29214] Red Hat update for java-1.5.0-bea
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, System access
Released: 2008-03-05
Red Hat has issued an update for java-1.5.0-bea. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, manipulate data, or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29214/\"]http://secunia.com/advisories/29214/[/url]
--
[SA29211] Slackware update for mozilla-thunderbird
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, DoS, System access
Released: 2008-03-03
Slackware has issued an update for mozilla-thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29211/\"]http://secunia.com/advisories/29211/[/url]
--
[SA29210] Ubuntu update for evolution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-06
Ubuntu has issued an update for evolution. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29210/\"]http://secunia.com/advisories/29210/[/url]
--
[SA29205] Gentoo update for acroread
Critical: Highly critical
Where: From remote
Impact: Unknown, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-03-03
Full Advisory:
[url=\"http://secunia.com/advisories/29205/\"]http://secunia.com/advisories/29205/[/url]
--
[SA29196] Slackware update for ghostscript
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-03
Slackware has issued an update for ghostscript. This fixes a vulnerability, which can be exploited by malicious people to compromise
a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29196/\"]http://secunia.com/advisories/29196/[/url]
--
[SA29182] Gentoo update for win32codecs
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-05
Gentoo has issued an update for win32codecs. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29182/\"]http://secunia.com/advisories/29182/[/url]
--
[SA29181] Gentoo update for sword
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-04
Gentoo has issued an update for sword. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29181/\"]http://secunia.com/advisories/29181/[/url]
--
[SA29169] Mandriva update for ghostscript
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-29
Mandriva has issued an update for ghostscript. This fixes a vulnerability, which can be exploited by malicious people to compromise
a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29169/\"]http://secunia.com/advisories/29169/[/url]
--
[SA29167] Fedora update for thunderbird
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, DoS, System access
Released: 2008-02-29
Fedora has issued an update for thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to disclose
sensitive information, bypass certain security restrictions, or potentially to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29167/\"]http://secunia.com/advisories/29167/[/url]
--
[SA29164] rPath update for thunderbird
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, DoS, System access
Released: 2008-03-03
rPath has issued an update for thunderbird. This fixes a security issue and some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and request forgery attacks, disclose potentially sensitive information, bypass certain security restrictions and compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29164/\"]http://secunia.com/advisories/29164/[/url]
--
[SA29163] Red Hat update for evolution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-05
Red Hat has issued an update for evolution. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29163/\"]http://secunia.com/advisories/29163/[/url]
--
[SA29248] Mandriva update for tcl
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-06
Mandriva has issued an update for tcl. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29248/\"]http://secunia.com/advisories/29248/[/url]
--
[SA29223] Mandriva update for wireshark
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-04
Mandriva has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29223/\"]http://secunia.com/advisories/29223/[/url]
--
[SA29209] Gentoo update for lighttpd
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, DoS
Released: 2008-03-06
Gentoo has issued an update for lighttpd. This fixes a security issue and a vulnerability, which can be exploited by malicious people to
disclose potentially sensitive information or cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29209/\"]http://secunia.com/advisories/29209/[/url]
--
[SA29194] Debian update for libicu
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-04
Debian has issued an update for libicu. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/29194/\"]http://secunia.com/advisories/29194/[/url]
--
[SA29188] rPath update for wireshark
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-03
rPath has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29188/\"]http://secunia.com/advisories/29188/[/url]
--
[SA29186] Fedora update for horde
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data
Released: 2008-02-29
Fedora has issued an update for horde. This fixes a security issue and a vulnerability, which can be exploited by malicious people to bypass certain security restrictions and manipulate data.
Full Advisory:
[url=\"http://secunia.com/advisories/29186/\"]http://secunia.com/advisories/29186/[/url]
--
[SA29185] Fedora update for imp
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data
Released: 2008-02-29
Fedora has issued an update for imp. This fixes a security issue and a vulnerability, which can be exploited by malicious users to bypass certain security restrictions, and by malicious people to bypass certain security restrictions and manipulate data.
Full Advisory:
[url=\"http://secunia.com/advisories/29185/\"]http://secunia.com/advisories/29185/[/url]
--
[SA29184] Fedora update for turba
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data
Released: 2008-02-29
Fedora has issued an update for turba. This fixes a security issue and a vulnerability, which can be exploited by malicious users to bypass certain security restrictions and by malicious people to bypass certain security restrictions and manipulate data.
Full Advisory:
[url=\"http://secunia.com/advisories/29184/\"]http://secunia.com/advisories/29184/[/url]
--
[SA29180] NetBSD FAST_IPSEC "ipsec4_get_ulp()" Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-29
A security issue has been reported in NetBSD, which can potentially be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29180/\"]http://secunia.com/advisories/29180/[/url]
--
[SA29178] SUSE update for opera
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information
Released: 2008-02-29
SUSE has issued an update for opera. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site
scripting attacks, disclose sensitive information, or to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29178/\"]http://secunia.com/advisories/29178/[/url]
--
[SA29175] rPath update for pcre
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-29
rPath has issued an update for pcre. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/29175/\"]http://secunia.com/advisories/29175/[/url]
--
[SA29166] rPath update for lighttpd
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-29
rPath has issued an update for lighttpd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29166/\"]http://secunia.com/advisories/29166/[/url]
--
[SA29251] SUSE update for cups
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-06
SUSE has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29251/\"]http://secunia.com/advisories/29251/[/url]
--
[SA29219] Linux Kiss Server "log_message()" Format String Vulnerability
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-03-05
vashnukad has discovered a vulnerability in Linux Kiss Server, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29219/\"]http://secunia.com/advisories/29219/[/url]
--
[SA29203] Gentoo update for firebird
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-03
Gentoo has issued an update for firebird. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29203/\"]http://secunia.com/advisories/29203/[/url]
--
[SA29257] Mandriva update for joomla
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-06
Mandriva has issued an update for joomla. This fixes some vulnerabilities, which can be exploited by malicious users to conduct
script insertion attacks and by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29257/\"]http://secunia.com/advisories/29257/[/url]
--
[SA29235] lighttpd mod_cgi Information Disclosure Security Issue
Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-05
A security issue has been reported in lighttpd, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29235/\"]http://secunia.com/advisories/29235/[/url]
--
[SA29224] VMware ESX Server update for e2fsprogs
Critical: Less critical
Where: From remote
Impact: System access, DoS
Released: 2008-03-04
VMware has issued an update for VMware ESX Server. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/29224/\"]http://secunia.com/advisories/29224/[/url]
--
[SA29202] Fedora update for viewvc
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-03
Fedora has issued an update for viewvc. This fixes some security issues, which can be exploited by malicious people to bypass certain
security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29202/\"]http://secunia.com/advisories/29202/[/url]
--
[SA29198] Gentoo update for mantisbt
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-04
Gentoo has issued an update for mantisbt. This fixes a vulnerability, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29198/\"]http://secunia.com/advisories/29198/[/url]
--
[SA29179] NetBSD file "file_printf()" Integer Underflow Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-29
A vulnerability has been reported in NetBSD, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29179/\"]http://secunia.com/advisories/29179/[/url]
--
[SA29176] ViewVC Multiple Security Issues
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-29
Some security issues have been reported in ViewVC, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29176/\"]http://secunia.com/advisories/29176/[/url]
--
[SA29168] Gentoo update for paramiko
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-03-04
Gentoo has issued an update for paramiko. This fixes a weakness, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29168/\"]http://secunia.com/advisories/29168/[/url]
--
[SA29256] Ubuntu update for openldap
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-03-06
Ubuntu has issued an update for openldap. This fixes some vulnerabilities, which can be exploited by malicious users to cause a
DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29256/\"]http://secunia.com/advisories/29256/[/url]
--
[SA29225] Mandriva update for openldap
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-03-06
Mandriva has issued an update for openldap. This fixes some vulnerabilities, which can be exploited by malicious users to cause a
DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29225/\"]http://secunia.com/advisories/29225/[/url]
--
[SA29189] rPath update for cups
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-03-03
rPath has issued an update for cups. This fixes two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29189/\"]http://secunia.com/advisories/29189/[/url]
--
[SA29240] user-ppp "command_Expand_Interpret()" Buffer Overflow Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-06
sipher has reported a vulnerability in user-ppp, which potentially can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29240/\"]http://secunia.com/advisories/29240/[/url]
--
[SA29238] FreeBSD ppp Buffer Overflow Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-06
A vulnerability has been reported in FreeBSD, which potentially can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29238/\"]http://secunia.com/advisories/29238/[/url]
--
[SA29236] Red Hat update for kernel
Critical: Less critical
Where: Local system
Impact: Unknown, Security Bypass, DoS
Released: 2008-03-06
Red Hat has issued an update for the kernel. This fixes a security issue and some vulnerabilities, where one has an unknown impact and others can be exploited by malicious, local users to bypass certain security restrictions or cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29236/\"]http://secunia.com/advisories/29236/[/url]
--
[SA29234] OpenBSD ppp Buffer Overflow Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-06
A vulnerability has been reported in OpenBSD, which potentially can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29234/\"]http://secunia.com/advisories/29234/[/url]
--
[SA29229] Adobe Reader for Linux Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-04
A security issue has been reported in Adobe Reader, which can be exploited by malicious, local users to perform certain actions with
escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29229/\"]http://secunia.com/advisories/29229/[/url]
--
[SA29206] Gentoo update for audacity
Critical: Less critical
Where: Local system
Impact: Manipulation of data, DoS
Released: 2008-03-03
Gentoo has issued an update for audacity. This fixes a security issue, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to delete arbitrary files and directories.
Full Advisory:
[url=\"http://secunia.com/advisories/29206/\"]http://secunia.com/advisories/29206/[/url]
--
[SA29190] Gentoo update for splitvt
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-04
Gentoo has issued an update for splitvt. This fixes a security issue, which can be exploited by malicious, local users to gain escalated
privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29190/\"]http://secunia.com/advisories/29190/[/url]
--
[SA29187] rPath update for am-utils
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-29
rPath has issued an update for am-utils. This fixes a security issue, which can be exploited by malicious, local users to perform certain
actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29187/\"]http://secunia.com/advisories/29187/[/url]
--
[SA29173] Fedora update for dbus
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-29
Fedora has issued an update for dbus. This fixes a security issue, which can be exploited by malicious, local users to bypass certain
security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29173/\"]http://secunia.com/advisories/29173/[/url]
--
[SA29171] Mandriva update for dbus
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-29
Mandriva has issued an update for dbus. This fixes a security issue, which can be exploited by malicious, local users to bypass certain
security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29171/\"]http://secunia.com/advisories/29171/[/url]
--
[SA29259] Gentoo update for vobcopy
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-06
Gentoo has issued an update for vobcopy. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29259/\"]http://secunia.com/advisories/29259/[/url]
--
[SA29253] Sun Solaris 10 ipsecah Denial of Service Vulnerability
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-03-06
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29253/\"]http://secunia.com/advisories/29253/[/url]
--
[SA29217] Sun Solaris 8 Directory Functions Local Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-03-03
A vulnerability has been reported in Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29217/\"]http://secunia.com/advisories/29217/[/url]
--
[SA29172] Fedora update for xen
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-29
Fedora has issued an update for xen. This fixes a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29172/\"]http://secunia.com/advisories/29172/[/url]
[b]Other:--[/b]
[SA29199] Livebox TP Router ADI Convergence Galaxy FTP Server Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-04
0in has reported a vulnerability in Livebox TP routers, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29199/\"]http://secunia.com/advisories/29199/[/url]
--
[SA29243] Check Point VPN-1 UTM Edge Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-06
Henri Lindberg has reported a vulnerability in Check Point VPN-1 UTM Edge, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29243/\"]http://secunia.com/advisories/29243/[/url]
--
[SA29165] Juniper Networks Secure Access 2000 "delivery_mode" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-04
A vulnerability has been reported in Juniper Networks Secure Access 2000, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29165/\"]http://secunia.com/advisories/29165/[/url]
[b]Cross Platform:--[/b]
[SA29254] Dokeos Code Execution and Cross-Site Scripting
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2008-03-06
Some vulnerabilities have been reported in Dokeos, which can be exploited by malicious people to conduct cross-site scripting attacks
or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29254/\"]http://secunia.com/advisories/29254/[/url]
--
[SA29239] Sun Java JDK / JRE Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, DoS, System access
Released: 2008-03-05
Some vulnerabilities have been reported in Sun Java, which can be exploited by malicious people to cause a DoS (Denial of Service), to bypass certain security restrictions, or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29239/\"]http://secunia.com/advisories/29239/[/url]
--
[SA29232] Ruby WEBrick Information Disclosure Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-06
Some vulnerabilities have been reported in Ruby, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29232/\"]http://secunia.com/advisories/29232/[/url]
--
[SA29218] KC Wiki "page" Information Disclosure and Manipulation
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-03-04
Two vulnerabilities have been discovered in KC Wiki, which can be exploited by malicious people to disclose sensitive information or to manipulate data.
Full Advisory:
[url=\"http://secunia.com/advisories/29218/\"]http://secunia.com/advisories/29218/[/url]
--
[SA29216] MediaWiki JSON Callback Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-03-03
A vulnerability has been reported in MediaWiki, which can potentially be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29216/\"]http://secunia.com/advisories/29216/[/url]
--
[SA29212] Dynamic Photo Gallery "albumID" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-03
Aria-Security Team has reported a vulnerability in Dynamic Photo Gallery, which can be exploited by malicious people to conduct SQL
injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29212/\"]http://secunia.com/advisories/29212/[/url]
--
[SA29193] netOffice Dwins Authentication Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-03
dB has reported a security issue in netOffice Dwins, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29193/\"]http://secunia.com/advisories/29193/[/url]
--
[SA29183] dream4 Koobi Forum Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-29
A vulnerability has been reported in Koobi, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29183/\"]http://secunia.com/advisories/29183/[/url]
--
[SA29174] SILC Toolkit "silc_fingerprint()" Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-03-05
A vulnerability has been reported in SILC (Secure Internet Live Conferencing) Toolkit, which potentially can be exploited by malicious
people to compromise an application using the toolkit.
Full Advisory:
[url=\"http://secunia.com/advisories/29174/\"]http://secunia.com/advisories/29174/[/url]
--
[SA29162] Urulu "connectionId" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-29
Daniel Roethlisberger has reported a vulnerability in Urulu, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29162/\"]http://secunia.com/advisories/29162/[/url]
--
[SA29255] BosDates Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-06
Russ McRee has reported some vulnerabilities in BosDates, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29255/\"]http://secunia.com/advisories/29255/[/url]
--
[SA29252] Sun Java System Access Manager Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-06
A vulnerability has been reported in Sun Java System Access Manager, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29252/\"]http://secunia.com/advisories/29252/[/url]
--
[SA29241] Smarty "regex_replace" Modifier Template Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-05
A vulnerability has been reported in Smarty, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29241/\"]http://secunia.com/advisories/29241/[/url]
--
[SA29222] Xitex WebContent M1 Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-06
Russ McRee has reported a vulnerability in Xitex WebContent M1, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29222/\"]http://secunia.com/advisories/29222/[/url]
--
[SA29221] Eye-Fi Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, DoS
Released: 2008-03-04
Seth Fogie has reported some vulnerabilities in Eye-Fi, which can be exploited by malicious people to conduct spoofing and cross-site
request forgery attacks, or to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29221/\"]http://secunia.com/advisories/29221/[/url]
--
[SA29220] TorrentTrader Classic "msg" Script Insertion Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-04
Dominus has discovered a vulnerability in TorrentTrader Classic, which can be exploited by malicious users to conduct script insertion
attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29220/\"]http://secunia.com/advisories/29220/[/url]
--
[SA29215] Flyspray Cross-Site Scripting and User Enumeration
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information
Released: 2008-03-03
A vulnerability and a weakness have been reported in Flyspray, which can be exploited by malicious people to conduct cross-site scripting attacks or identify valid user accounts.
Full Advisory:
[url=\"http://secunia.com/advisories/29215/\"]http://secunia.com/advisories/29215/[/url]
--
[SA29201] Crafty Syntax Live Help Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-03
Some vulnerabilities have been reported in Crafty Syntax Live Help, which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29201/\"]http://secunia.com/advisories/29201/[/url]
--
[SA29200] phpMyAdmin "$_REQUEST" SQL Injection Vulnerability
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-03
A vulnerability has been reported in phpMyAdmin, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29200/\"]http://secunia.com/advisories/29200/[/url]
--
[SA29192] h2desk Support System Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-03
joseph.giron13 has reported a security issue in h2desk Support System, which can be exploited by malicious users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29192/\"]http://secunia.com/advisories/29192/[/url]
--
[SA29191] Ariadne PINP Annotate Command Execution Vulnerability
Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-03-04
A vulnerability has been reported in Ariadne, which potentially can be exploited by malicious users to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29191/\"]http://secunia.com/advisories/29191/[/url]
--
[SA29177] XRMS CRM "msg" Cross Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-29
vijayv has reported a vulnerability in XRMS CRM, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29177/\"]http://secunia.com/advisories/29177/[/url]
--
[SA29250] Fujitsu Interstage Smart Repository Denial of Service Vulnerabilities
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-03-06
Some vulnerabilities have been reported in various Fujitsu products, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29250/\"]http://secunia.com/advisories/29250/[/url]
--
[SA29170] IBM WebSphere MQ Queue Manager Security Bypass
Critical: Less critical
Where: From local network
Impact: Security Bypass
Released: 2008-02-29
A security issue has been reported in IBM WebSphere MQ, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29170/\"]http://secunia.com/advisories/29170/[/url]
[b]Windows:--[/b]
[SA29233] Programmer's Notepad ctags Processing Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-06
A vulnerability has been discovered in Programmer's Notepad, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29233/\"]http://secunia.com/advisories/29233/[/url]
--
[SA29195] Learn2 STRunner ActiveX Control Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-03
Will Dormann has reported some vulnerabilities in Learn2 STRunner ActiveX control, which can be exploited by malicious people to
compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29195/\"]http://secunia.com/advisories/29195/[/url]
--
[SA29230] Versant Object Database Command Execution Vulnerability
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-03-05
Luigi Auriemma has discovered a vulnerability in Versant Object Database, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29230/\"]http://secunia.com/advisories/29230/[/url]
--
[SA29213] Borland VisiBroker Smart Agent Packet Handling
Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-04
Luigi Auriemma has reported some vulnerabilities in Borland VisiBroker, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29213/\"]http://secunia.com/advisories/29213/[/url]
--
[SA29208] Borland StarTeam StarTeamMPX and StarTeam Server Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-03
Luigi Auriemma has reported some vulnerabilities in Borland StarTeam, which can be exploited by malicious users or malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29208/\"]http://secunia.com/advisories/29208/[/url]
--
[SA29207] PacketTrap pt360 TFTP Server Two Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-03-05
Two vulnerabilities have been reported in the PacketTrap pt360, which can be exploited by malicious people to cause a DoS (Denial of
Service), disclose sensitive information, or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29207/\"]http://secunia.com/advisories/29207/[/url]
--
[SA29246] eScan Corporate Edition eScan Management Console FTP Server Arbitrary File Download
Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-06
Luigi Auriemma has discovered a vulnerability in eScan Corporate Edition, which can be exploited by malicious people to disclose
sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29246/\"]http://secunia.com/advisories/29246/[/url]
--
[SA29231] Perforce Server Denial of Service Vulnerabilities
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-03-06
Luigi Auriemma has discovered some vulnerabilities in Perforce Server, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29231/\"]http://secunia.com/advisories/29231/[/url]
[b]UNIX/Linux:--[/b]
[SA29258] Gentoo update for evolution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-06
Gentoo has issued an update for evolution. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29258/\"]http://secunia.com/advisories/29258/[/url]
--
[SA29244] Debian update for evolution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-06
Debian has issued an update for evolution. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29244/\"]http://secunia.com/advisories/29244/[/url]
--
[SA29214] Red Hat update for java-1.5.0-bea
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, System access
Released: 2008-03-05
Red Hat has issued an update for java-1.5.0-bea. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, manipulate data, or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29214/\"]http://secunia.com/advisories/29214/[/url]
--
[SA29211] Slackware update for mozilla-thunderbird
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, DoS, System access
Released: 2008-03-03
Slackware has issued an update for mozilla-thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29211/\"]http://secunia.com/advisories/29211/[/url]
--
[SA29210] Ubuntu update for evolution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-06
Ubuntu has issued an update for evolution. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29210/\"]http://secunia.com/advisories/29210/[/url]
--
[SA29205] Gentoo update for acroread
Critical: Highly critical
Where: From remote
Impact: Unknown, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-03-03
Full Advisory:
[url=\"http://secunia.com/advisories/29205/\"]http://secunia.com/advisories/29205/[/url]
--
[SA29196] Slackware update for ghostscript
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-03
Slackware has issued an update for ghostscript. This fixes a vulnerability, which can be exploited by malicious people to compromise
a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29196/\"]http://secunia.com/advisories/29196/[/url]
--
[SA29182] Gentoo update for win32codecs
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-05
Gentoo has issued an update for win32codecs. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29182/\"]http://secunia.com/advisories/29182/[/url]
--
[SA29181] Gentoo update for sword
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-04
Gentoo has issued an update for sword. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29181/\"]http://secunia.com/advisories/29181/[/url]
--
[SA29169] Mandriva update for ghostscript
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-29
Mandriva has issued an update for ghostscript. This fixes a vulnerability, which can be exploited by malicious people to compromise
a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29169/\"]http://secunia.com/advisories/29169/[/url]
--
[SA29167] Fedora update for thunderbird
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, DoS, System access
Released: 2008-02-29
Fedora has issued an update for thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to disclose
sensitive information, bypass certain security restrictions, or potentially to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29167/\"]http://secunia.com/advisories/29167/[/url]
--
[SA29164] rPath update for thunderbird
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, DoS, System access
Released: 2008-03-03
rPath has issued an update for thunderbird. This fixes a security issue and some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and request forgery attacks, disclose potentially sensitive information, bypass certain security restrictions and compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29164/\"]http://secunia.com/advisories/29164/[/url]
--
[SA29163] Red Hat update for evolution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-05
Red Hat has issued an update for evolution. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29163/\"]http://secunia.com/advisories/29163/[/url]
--
[SA29248] Mandriva update for tcl
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-06
Mandriva has issued an update for tcl. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29248/\"]http://secunia.com/advisories/29248/[/url]
--
[SA29223] Mandriva update for wireshark
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-04
Mandriva has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29223/\"]http://secunia.com/advisories/29223/[/url]
--
[SA29209] Gentoo update for lighttpd
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, DoS
Released: 2008-03-06
Gentoo has issued an update for lighttpd. This fixes a security issue and a vulnerability, which can be exploited by malicious people to
disclose potentially sensitive information or cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29209/\"]http://secunia.com/advisories/29209/[/url]
--
[SA29194] Debian update for libicu
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-04
Debian has issued an update for libicu. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/29194/\"]http://secunia.com/advisories/29194/[/url]
--
[SA29188] rPath update for wireshark
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-03
rPath has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29188/\"]http://secunia.com/advisories/29188/[/url]
--
[SA29186] Fedora update for horde
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data
Released: 2008-02-29
Fedora has issued an update for horde. This fixes a security issue and a vulnerability, which can be exploited by malicious people to bypass certain security restrictions and manipulate data.
Full Advisory:
[url=\"http://secunia.com/advisories/29186/\"]http://secunia.com/advisories/29186/[/url]
--
[SA29185] Fedora update for imp
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data
Released: 2008-02-29
Fedora has issued an update for imp. This fixes a security issue and a vulnerability, which can be exploited by malicious users to bypass certain security restrictions, and by malicious people to bypass certain security restrictions and manipulate data.
Full Advisory:
[url=\"http://secunia.com/advisories/29185/\"]http://secunia.com/advisories/29185/[/url]
--
[SA29184] Fedora update for turba
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data
Released: 2008-02-29
Fedora has issued an update for turba. This fixes a security issue and a vulnerability, which can be exploited by malicious users to bypass certain security restrictions and by malicious people to bypass certain security restrictions and manipulate data.
Full Advisory:
[url=\"http://secunia.com/advisories/29184/\"]http://secunia.com/advisories/29184/[/url]
--
[SA29180] NetBSD FAST_IPSEC "ipsec4_get_ulp()" Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-29
A security issue has been reported in NetBSD, which can potentially be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29180/\"]http://secunia.com/advisories/29180/[/url]
--
[SA29178] SUSE update for opera
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information
Released: 2008-02-29
SUSE has issued an update for opera. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site
scripting attacks, disclose sensitive information, or to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29178/\"]http://secunia.com/advisories/29178/[/url]
--
[SA29175] rPath update for pcre
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-29
rPath has issued an update for pcre. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/29175/\"]http://secunia.com/advisories/29175/[/url]
--
[SA29166] rPath update for lighttpd
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-29
rPath has issued an update for lighttpd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29166/\"]http://secunia.com/advisories/29166/[/url]
--
[SA29251] SUSE update for cups
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-06
SUSE has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29251/\"]http://secunia.com/advisories/29251/[/url]
--
[SA29219] Linux Kiss Server "log_message()" Format String Vulnerability
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-03-05
vashnukad has discovered a vulnerability in Linux Kiss Server, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29219/\"]http://secunia.com/advisories/29219/[/url]
--
[SA29203] Gentoo update for firebird
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-03
Gentoo has issued an update for firebird. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29203/\"]http://secunia.com/advisories/29203/[/url]
--
[SA29257] Mandriva update for joomla
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-06
Mandriva has issued an update for joomla. This fixes some vulnerabilities, which can be exploited by malicious users to conduct
script insertion attacks and by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29257/\"]http://secunia.com/advisories/29257/[/url]
--
[SA29235] lighttpd mod_cgi Information Disclosure Security Issue
Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-05
A security issue has been reported in lighttpd, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29235/\"]http://secunia.com/advisories/29235/[/url]
--
[SA29224] VMware ESX Server update for e2fsprogs
Critical: Less critical
Where: From remote
Impact: System access, DoS
Released: 2008-03-04
VMware has issued an update for VMware ESX Server. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
[url=\"http://secunia.com/advisories/29224/\"]http://secunia.com/advisories/29224/[/url]
--
[SA29202] Fedora update for viewvc
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-03
Fedora has issued an update for viewvc. This fixes some security issues, which can be exploited by malicious people to bypass certain
security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29202/\"]http://secunia.com/advisories/29202/[/url]
--
[SA29198] Gentoo update for mantisbt
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-04
Gentoo has issued an update for mantisbt. This fixes a vulnerability, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29198/\"]http://secunia.com/advisories/29198/[/url]
--
[SA29179] NetBSD file "file_printf()" Integer Underflow Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-29
A vulnerability has been reported in NetBSD, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29179/\"]http://secunia.com/advisories/29179/[/url]
--
[SA29176] ViewVC Multiple Security Issues
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-29
Some security issues have been reported in ViewVC, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29176/\"]http://secunia.com/advisories/29176/[/url]
--
[SA29168] Gentoo update for paramiko
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-03-04
Gentoo has issued an update for paramiko. This fixes a weakness, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29168/\"]http://secunia.com/advisories/29168/[/url]
--
[SA29256] Ubuntu update for openldap
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-03-06
Ubuntu has issued an update for openldap. This fixes some vulnerabilities, which can be exploited by malicious users to cause a
DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29256/\"]http://secunia.com/advisories/29256/[/url]
--
[SA29225] Mandriva update for openldap
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-03-06
Mandriva has issued an update for openldap. This fixes some vulnerabilities, which can be exploited by malicious users to cause a
DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29225/\"]http://secunia.com/advisories/29225/[/url]
--
[SA29189] rPath update for cups
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-03-03
rPath has issued an update for cups. This fixes two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29189/\"]http://secunia.com/advisories/29189/[/url]
--
[SA29240] user-ppp "command_Expand_Interpret()" Buffer Overflow Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-06
sipher has reported a vulnerability in user-ppp, which potentially can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29240/\"]http://secunia.com/advisories/29240/[/url]
--
[SA29238] FreeBSD ppp Buffer Overflow Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-06
A vulnerability has been reported in FreeBSD, which potentially can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29238/\"]http://secunia.com/advisories/29238/[/url]
--
[SA29236] Red Hat update for kernel
Critical: Less critical
Where: Local system
Impact: Unknown, Security Bypass, DoS
Released: 2008-03-06
Red Hat has issued an update for the kernel. This fixes a security issue and some vulnerabilities, where one has an unknown impact and others can be exploited by malicious, local users to bypass certain security restrictions or cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29236/\"]http://secunia.com/advisories/29236/[/url]
--
[SA29234] OpenBSD ppp Buffer Overflow Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-06
A vulnerability has been reported in OpenBSD, which potentially can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29234/\"]http://secunia.com/advisories/29234/[/url]
--
[SA29229] Adobe Reader for Linux Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-04
A security issue has been reported in Adobe Reader, which can be exploited by malicious, local users to perform certain actions with
escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29229/\"]http://secunia.com/advisories/29229/[/url]
--
[SA29206] Gentoo update for audacity
Critical: Less critical
Where: Local system
Impact: Manipulation of data, DoS
Released: 2008-03-03
Gentoo has issued an update for audacity. This fixes a security issue, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to delete arbitrary files and directories.
Full Advisory:
[url=\"http://secunia.com/advisories/29206/\"]http://secunia.com/advisories/29206/[/url]
--
[SA29190] Gentoo update for splitvt
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-04
Gentoo has issued an update for splitvt. This fixes a security issue, which can be exploited by malicious, local users to gain escalated
privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29190/\"]http://secunia.com/advisories/29190/[/url]
--
[SA29187] rPath update for am-utils
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-29
rPath has issued an update for am-utils. This fixes a security issue, which can be exploited by malicious, local users to perform certain
actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29187/\"]http://secunia.com/advisories/29187/[/url]
--
[SA29173] Fedora update for dbus
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-29
Fedora has issued an update for dbus. This fixes a security issue, which can be exploited by malicious, local users to bypass certain
security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29173/\"]http://secunia.com/advisories/29173/[/url]
--
[SA29171] Mandriva update for dbus
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-29
Mandriva has issued an update for dbus. This fixes a security issue, which can be exploited by malicious, local users to bypass certain
security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29171/\"]http://secunia.com/advisories/29171/[/url]
--
[SA29259] Gentoo update for vobcopy
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-06
Gentoo has issued an update for vobcopy. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29259/\"]http://secunia.com/advisories/29259/[/url]
--
[SA29253] Sun Solaris 10 ipsecah Denial of Service Vulnerability
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-03-06
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29253/\"]http://secunia.com/advisories/29253/[/url]
--
[SA29217] Sun Solaris 8 Directory Functions Local Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-03-03
A vulnerability has been reported in Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29217/\"]http://secunia.com/advisories/29217/[/url]
--
[SA29172] Fedora update for xen
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-29
Fedora has issued an update for xen. This fixes a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29172/\"]http://secunia.com/advisories/29172/[/url]
[b]Other:--[/b]
[SA29199] Livebox TP Router ADI Convergence Galaxy FTP Server Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-04
0in has reported a vulnerability in Livebox TP routers, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29199/\"]http://secunia.com/advisories/29199/[/url]
--
[SA29243] Check Point VPN-1 UTM Edge Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-06
Henri Lindberg has reported a vulnerability in Check Point VPN-1 UTM Edge, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29243/\"]http://secunia.com/advisories/29243/[/url]
--
[SA29165] Juniper Networks Secure Access 2000 "delivery_mode" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-04
A vulnerability has been reported in Juniper Networks Secure Access 2000, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29165/\"]http://secunia.com/advisories/29165/[/url]
[b]Cross Platform:--[/b]
[SA29254] Dokeos Code Execution and Cross-Site Scripting
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2008-03-06
Some vulnerabilities have been reported in Dokeos, which can be exploited by malicious people to conduct cross-site scripting attacks
or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29254/\"]http://secunia.com/advisories/29254/[/url]
--
[SA29239] Sun Java JDK / JRE Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, DoS, System access
Released: 2008-03-05
Some vulnerabilities have been reported in Sun Java, which can be exploited by malicious people to cause a DoS (Denial of Service), to bypass certain security restrictions, or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29239/\"]http://secunia.com/advisories/29239/[/url]
--
[SA29232] Ruby WEBrick Information Disclosure Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-06
Some vulnerabilities have been reported in Ruby, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29232/\"]http://secunia.com/advisories/29232/[/url]
--
[SA29218] KC Wiki "page" Information Disclosure and Manipulation
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-03-04
Two vulnerabilities have been discovered in KC Wiki, which can be exploited by malicious people to disclose sensitive information or to manipulate data.
Full Advisory:
[url=\"http://secunia.com/advisories/29218/\"]http://secunia.com/advisories/29218/[/url]
--
[SA29216] MediaWiki JSON Callback Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-03-03
A vulnerability has been reported in MediaWiki, which can potentially be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29216/\"]http://secunia.com/advisories/29216/[/url]
--
[SA29212] Dynamic Photo Gallery "albumID" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-03
Aria-Security Team has reported a vulnerability in Dynamic Photo Gallery, which can be exploited by malicious people to conduct SQL
injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29212/\"]http://secunia.com/advisories/29212/[/url]
--
[SA29193] netOffice Dwins Authentication Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-03
dB has reported a security issue in netOffice Dwins, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29193/\"]http://secunia.com/advisories/29193/[/url]
--
[SA29183] dream4 Koobi Forum Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-29
A vulnerability has been reported in Koobi, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29183/\"]http://secunia.com/advisories/29183/[/url]
--
[SA29174] SILC Toolkit "silc_fingerprint()" Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-03-05
A vulnerability has been reported in SILC (Secure Internet Live Conferencing) Toolkit, which potentially can be exploited by malicious
people to compromise an application using the toolkit.
Full Advisory:
[url=\"http://secunia.com/advisories/29174/\"]http://secunia.com/advisories/29174/[/url]
--
[SA29162] Urulu "connectionId" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-29
Daniel Roethlisberger has reported a vulnerability in Urulu, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29162/\"]http://secunia.com/advisories/29162/[/url]
--
[SA29255] BosDates Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-06
Russ McRee has reported some vulnerabilities in BosDates, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29255/\"]http://secunia.com/advisories/29255/[/url]
--
[SA29252] Sun Java System Access Manager Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-06
A vulnerability has been reported in Sun Java System Access Manager, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29252/\"]http://secunia.com/advisories/29252/[/url]
--
[SA29241] Smarty "regex_replace" Modifier Template Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-05
A vulnerability has been reported in Smarty, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29241/\"]http://secunia.com/advisories/29241/[/url]
--
[SA29222] Xitex WebContent M1 Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-06
Russ McRee has reported a vulnerability in Xitex WebContent M1, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29222/\"]http://secunia.com/advisories/29222/[/url]
--
[SA29221] Eye-Fi Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, DoS
Released: 2008-03-04
Seth Fogie has reported some vulnerabilities in Eye-Fi, which can be exploited by malicious people to conduct spoofing and cross-site
request forgery attacks, or to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29221/\"]http://secunia.com/advisories/29221/[/url]
--
[SA29220] TorrentTrader Classic "msg" Script Insertion Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-04
Dominus has discovered a vulnerability in TorrentTrader Classic, which can be exploited by malicious users to conduct script insertion
attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29220/\"]http://secunia.com/advisories/29220/[/url]
--
[SA29215] Flyspray Cross-Site Scripting and User Enumeration
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information
Released: 2008-03-03
A vulnerability and a weakness have been reported in Flyspray, which can be exploited by malicious people to conduct cross-site scripting attacks or identify valid user accounts.
Full Advisory:
[url=\"http://secunia.com/advisories/29215/\"]http://secunia.com/advisories/29215/[/url]
--
[SA29201] Crafty Syntax Live Help Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-03
Some vulnerabilities have been reported in Crafty Syntax Live Help, which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29201/\"]http://secunia.com/advisories/29201/[/url]
--
[SA29200] phpMyAdmin "$_REQUEST" SQL Injection Vulnerability
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-03
A vulnerability has been reported in phpMyAdmin, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29200/\"]http://secunia.com/advisories/29200/[/url]
--
[SA29192] h2desk Support System Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-03
joseph.giron13 has reported a security issue in h2desk Support System, which can be exploited by malicious users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29192/\"]http://secunia.com/advisories/29192/[/url]
--
[SA29191] Ariadne PINP Annotate Command Execution Vulnerability
Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-03-04
A vulnerability has been reported in Ariadne, which potentially can be exploited by malicious users to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29191/\"]http://secunia.com/advisories/29191/[/url]
--
[SA29177] XRMS CRM "msg" Cross Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-29
vijayv has reported a vulnerability in XRMS CRM, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29177/\"]http://secunia.com/advisories/29177/[/url]
--
[SA29250] Fujitsu Interstage Smart Repository Denial of Service Vulnerabilities
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-03-06
Some vulnerabilities have been reported in various Fujitsu products, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29250/\"]http://secunia.com/advisories/29250/[/url]
--
[SA29170] IBM WebSphere MQ Queue Manager Security Bypass
Critical: Less critical
Where: From local network
Impact: Security Bypass
Released: 2008-02-29
A security issue has been reported in IBM WebSphere MQ, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29170/\"]http://secunia.com/advisories/29170/[/url]