Section: .. / 0607-advisories /
| /// File Name: |
sa21206.txt |
Description:
|
Secunia Security Advisory - Tamriel has discovered a vulnerability in Professional Home Page Tools Login Script, which can be exploited by malicious people to conduct script insertion attacks.
| | Homepage: | http://secunia.com/advisories/21206/ | | File Size: | 2350 | | Last Modified: | Jul 27 01:44:57 2006 |
| MD5 Checksum: | e3ebfc2d62b6f8a42ab06d146bc59634 |
|
| /// File Name: |
sa21210.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for mozilla-thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting and HTTP response smuggling attacks, and potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/21210/ | | File Size: | 13427 | | Last Modified: | Jul 27 01:44:57 2006 |
| MD5 Checksum: | 065c912a81a055ea554cfc6e43ed990d |
|
| /// File Name: |
sa20852.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered a vulnerability in AutoVue SolidModel Professional, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/20852/ | | File Size: | 2459 | | Last Modified: | Jul 26 05:16:24 2006 |
| MD5 Checksum: | 6d5460b1dc41afac536e120eb14beac7 |
|
| /// File Name: |
TSRT-06-04.txt |
Description:
|
A vulnerability exists in the IQnetworks Enterprise Security Analyzer. The specific flaw exists within Topology.exe, which binds by default to TCP port 10628. During the processing of long prefixes to the GUIADDDEVICE, ADDDEVICE, or DELETEDEVICE command, a stack based buffer overflow occurs.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2540 | | Related CVE(s): | CVE-2006-3838 | | Last Modified: | Jul 26 05:16:16 2006 |
| MD5 Checksum: | 135f2de067322b0116c9e9f9ef6e959c |
|
| /// File Name: |
TSRT-06-03.txt |
Description:
|
A vulnerability exists in the IQnetworks Enterprise Security Analyzer. The flaw specifically exists within the Syslog daemon, syslogserver.exe, during the processing of long arguments passed through various commands on TCP port 10617.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2832 | | Related CVE(s): | CVE-2006-3838 | | Last Modified: | Jul 26 05:15:27 2006 |
| MD5 Checksum: | a3eaf0380b3667bfe61509341cf90847 |
|
| /// File Name: |
sa21205.txt |
Description:
|
Secunia Security Advisory - Tamriel has reported a vulnerability in TP-Book, which can be exploited by malicious people to conduct script insertion attacks.
| | Homepage: | http://secunia.com/advisories/21205/ | | File Size: | 2149 | | Last Modified: | Jul 26 05:12:24 2006 |
| MD5 Checksum: | f25fc181b4ddd723477103cf50296fee |
|
| /// File Name: |
sa21178.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for mozilla. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting and HTTP response smuggling attacks, disclose sensitive information, and potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/21178/ | | File Size: | 17296 | | Last Modified: | Jul 26 05:12:12 2006 |
| MD5 Checksum: | df13c7ef99811116b1d51afcd48e5983 |
|
| /// File Name: |
sa21190.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious users to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/21190/ | | File Size: | 1989 | | Last Modified: | Jul 26 05:12:12 2006 |
| MD5 Checksum: | 48fcb58ee09512d775a676a40403d181 |
|
| /// File Name: |
sa21202.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for php. This fixes some vulnerabilities, where one has an unknown impact and others can be exploited to bypass certain security restrictions or cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/21202/ | | File Size: | 2371 | | Last Modified: | Jul 26 05:12:12 2006 |
| MD5 Checksum: | 9df136c938397c4d6dacbb350ff05a92 |
|
| /// File Name: |
ZDI-06-024.txt |
Description:
|
A vulnerability exists in the IQnetworks Enterprise Security Analyzer. The specific flaw exists within EnterpriseSecurityAnalyzer.exe, which binds by default to TCP port 10616. During the processing of long arguments to the LICMGR_ADDLICENSE command a stack based buffer overflow occurs.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3039 | | Related CVE(s): | CVE-2006-3838 | | Last Modified: | Jul 26 05:11:59 2006 |
| MD5 Checksum: | af2e73ee9fc1378045233c98169b7cad |
|
| /// File Name: |
ZDI-06-023.txt |
Description:
|
A vulnerability exists in the IQnetworks Enterprise Security Analyzer. The specific flaw exists within the Syslog daemon, syslogserver.exe, during the processing of long strings transmitted to the listening TCP port. The vulnerability is not exposed over UDP. The default configuration does not expose the open TCP port.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3046 | | Related CVE(s): | CVE-2006-3838 | | Last Modified: | Jul 26 05:11:05 2006 |
| MD5 Checksum: | 9b06a86618e60a889d2bc9323526e33b |
|
| /// File Name: |
MDKSA-2006-131.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-131 - Peter Bieringer discovered a flaw in the perl Net::Server module where the "log" function was not safe against format string exploits in version 0.87 and earlier.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 2582 | | Related CVE(s): | CVE-2005-1127 | | Last Modified: | Jul 26 05:07:54 2006 |
| MD5 Checksum: | af46570e7d44cbc56e0180a4bb04a0ac |
|
| /// File Name: |
tpbook100.txt |
Description:
|
TP-Book versions 1.00 and below suffer from cross site scripting vulnerabilities.
| | Author: | Tamriel | | File Size: | 1212 | | Last Modified: | Jul 26 05:05:19 2006 |
| MD5 Checksum: | 22d05bd682276d939f91e2f255c3faac |
|
| /// File Name: |
prohp.txt |
Description:
|
Professional Home Page suffers from cross site scripting flaws.
| | Author: | Tamriel | | File Size: | 1688 | | Last Modified: | Jul 26 05:04:31 2006 |
| MD5 Checksum: | 314b7d4c466b61a6a02357d678f8e316 |
|
| /// File Name: |
glsa-200607-10.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200607-10 - During an internal audit the Samba team discovered that a flaw in the way Samba stores share connection requests could lead to a Denial of Service. Versions less than 3.0.22-r3 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2586 | | Last Modified: | Jul 26 05:03:08 2006 |
| MD5 Checksum: | a0869a2b9ff2602a94cdba9a3376a32c |
|
| /// File Name: |
secunia-FileCOPA.txt |
Description:
|
Secunia Research has discovered a vulnerability in FileCOPA, which can be exploited by malicious users to compromise a vulnerable system. The vulnerability is caused due to an integer underflow error in the FTP service (filecpnt.exe) when processing directory arguments passed to certain FTP commands (e.g. "CWD", "DELE", "MDTM", and "MKD"). This can be exploited to cause a stack-based buffer overflow by passing a specially crafted, overly long argument to one of the affected FTP commands. Successful exploitation allows execution of arbitrary code. Versions below 1.01 are affected.
| | Author: | Carsten Eiram | | Homepage: | http://secunia.com/ | | File Size: | 4247 | | Related CVE(s): | CVE-2006-3768 | | Last Modified: | Jul 26 05:00:37 2006 |
| MD5 Checksum: | cbcc6166e39d9608e8505eee337a6a75 |
|
| /// File Name: |
glsa-200607-09.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200607-09 - Wireshark dissectors have been found vulnerable to a large number of exploits, including off-by-one errors, buffer overflows, format string overflows and an infinite loop. Versions less than 0.99.2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 4075 | | Last Modified: | Jul 26 04:58:30 2006 |
| MD5 Checksum: | b0e7ffe4211b404b4a952bf9178bf645 |
|
| /// File Name: |
powarc962-en.txt |
Description:
|
A vulnerability has been found in PowerArchiver version 9.62.03 that allows for arbitrary code execution.
| | Author: | Tan Chew Keong | | File Size: | 657 | | Last Modified: | Jul 26 04:58:19 2006 |
| MD5 Checksum: | e9bec764bc19dc25253454e1fdc762cc |
|
| /// File Name: |
agephone1381-en.txt |
Description:
|
A vulnerability has been found in AGEphone versions 1.24 and 1.38.1 that allows for arbitrary code execution.
| | Author: | Tan Chew Keong | | File Size: | 445 | | Last Modified: | Jul 26 04:26:57 2006 |
| MD5 Checksum: | ca11e9865f277afe515c728a5dd621ff |
|
| /// File Name: |
turbozip6-en.txt |
Description:
|
A vulnerability has been found in TurboZIP 6.0 that allows for arbitrary code execution.
| | Author: | Tan Chew Keong | | File Size: | 443 | | Last Modified: | Jul 26 04:26:12 2006 |
| MD5 Checksum: | 82ccc3e162c09fe5b8957e8ce9c53f17 |
|
| /// File Name: |
dynazip5007-en.txt |
Description:
|
Some vulnerabilities have been found in DynaZip DZIP32.DLL/DZIPS32.DLL that allow for arbitrary code execution. DynaZip Max version 5.0.0.7 and DynaZip Max Secure version 6.0.0.4 are affected.
| | Author: | Tan Chew Keong | | File Size: | 648 | | Last Modified: | Jul 26 04:24:30 2006 |
| MD5 Checksum: | 2ccfa941a7d2618004881b66f4ec8454 |
|
| /// File Name: |
04072006_tweed.pdf |
Description:
|
Tumbleweed's Email Firewall has three separate vulnerabilities within its LHA processing routines inside of its EMF Decomposer.
| | Author: | Ryan Smith | | Homepage: | http://www.hustlelabs.com | | File Size: | 117148 | | Last Modified: | Jul 26 04:11:23 2006 |
| MD5 Checksum: | b9120c970b1bbb456be2e586166b59a0 |
|
| /// File Name: |
lmmgt2ho.txt |
Description:
|
libmikmod versions 3.2.2 and below suffer from a heap overflow vulnerability.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org | | Related Exploit: | lmmgt2ho.zip | | File Size: | 2747 | | Last Modified: | Jul 26 04:06:20 2006 |
| MD5 Checksum: | 474a8b93b4e8ef40ccbc5b0c6e162de3 |
|
| /// File Name: |
dsa-1124-1.txt |
Description:
|
Debian Security Advisory 1124-1 - Toth Andras discovered that the fbgs framebuffer postscript/PDF viewer contains a typo, which prevents the intended filter against malicious postscript commands from working correctly. This might lead to the deletion of user data when displaying a postscript file.
| | Homepage: | http://www.debian.org/security | | File Size: | 6676 | | Related CVE(s): | CVE-2006-3119 | | Last Modified: | Jul 26 03:58:51 2006 |
| MD5 Checksum: | 66ff21c247496d1a4f467fee67480976 |
|
| /// File Name: |
dsa-1123-1.txt |
Description:
|
Debian Security Advisory 1123-1 - Luigi Auriemma discovered that DUMB, a tracker music library, performs insufficient sanitising of values parsed from IT music files, which might lead to a buffer overflow and execution of arbitrary code if manipulated files are read.
| | Homepage: | http://www.debian.org/security | | File Size: | 10638 | | Related CVE(s): | CVE-2006-3668 | | Last Modified: | Jul 26 03:58:18 2006 |
| MD5 Checksum: | 9c4e3f208c8bfa1ae909c1864681427c |
|
|
|
|
|