Secunia 2007 Bulletins
Moderators: Moderator, Global Moderator
Secunia 2007 Bulletins
September 20 2007
A week after Microsoft released its security patches for August, several vulnerabilities have been reported in various Microsoft
products, which can be exploited by malicious people to compromise vulnerable systems.
The first, a vulnerability in Microsoft Windows, is caused by a boundary error in the "FindFile()" function of the CFileFind class in
the mfc42.dll and mfc42u.dll files. Passing an overly long argument to the affected function exploits the vulnerability, and causes a heap-based buffer overflow.
Two Hewlett-Packard products are known to contain vectors that may allow exploitation of this vulnerability: HP All-in-One Series Web Release software/driver installer version 2.1.0, and HP Photo & Imaging Gallery version 1.1.
The vulnerability is confirmed on a fully-patched Windows XP SP2 including mfc42.dll version 6.2.4131.0 and mfc42u.dll version
6.2.8071.0, and remains unpatched. For more information, refer to: http://secunia.com/advisories/26800/
Several other vulnerabilities were reported in two Microsoft Visual Studio ActiveX controls. The PDWizard.ocx ActiveX control contains the insecure methods "StartProcess()" and "SyncShell()", which can be exploited to execute arbitrary commands on the system. Other insecure methods have also been reported, such as "SaveAs()", "CABDefaultURL()", "CABFileName()", and "CABRunFile()".
The "Load()" and "SaveAs()" methods of the VBTOVSI.DLL ActiveX control can also be exploited to, for example, load a local file and save it in an arbitrary location or overwrite an arbitrary file.
The vulnerabilities are reported in version 6.0, and remain unpatched.
--
Some vulnerabilities have been reported in OpenOffice, which potentially can be exploited by malicious people to compromise a
user's system. By tricking a user into, for example, opening a specially crafted document that requires processing of TIFF images,
integer overflows can occur, which when exploited trigger heap-based buffer overflows. Successful exploitation may allow the execution of arbitrary code.
The vulnerabilities are reported in versions prior to 2.3. Users of OpenOffice versions prior to 2.3 are urged to upgrade to the fixed version. Users of the OpenOffice 1.1.x and 1.0.x branches should note that these versions are not patched, and should instead upgrade to version 2.3. For more information, refer to: http://secunia.com/advisories/26816/
--
A vulnerability in the popular virtual world Second Life was reported this week, which could potentially give a malicious person access to a legitimate player's user account.
The problem is that SecondLife registers the "secondlife://" URI handler and allows invoking SecondLife with arbitrary command line arguments. By using certain parameters, such as "-autologin" and "-loginuri", it is possible to gain knowledge of, for example, a user's username and password hash by specifying a malicious server.
Successful exploitation requires that the legitimate user is, for example, tricked into visiting a malicious website. The vulnerability, which is reported in version 1.x, remains unpatched. Users are urged not to browse untrusted sites. For more information, refer to: http://secunia.com/advisories/26845/
--
VIRUS ALERTS:
During the past week Secunia collected 167 virus descriptions from the Antivirus vendors. However, none were deemed MEDIUM risk or higher according to the Secunia assessment scale.
Vulnerabilities Content Listing
Windows:--
[SA26835] RemoteDocs R-Viewer RDZ Code Execution and Information Disclosure
Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2007-09-18
Adam Baldwin has reported a vulnerability and a security issue in RemoteDocs R-Viewer, which potentially can be exploited by malicious, local users to disclose sensitive information and by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26835/
--
[SA26830] PhotoChannel Networks Photo Upload Plugin ActiveX Control Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-17
Will Dormann has reported some vulnerabilities in PhotoChannel Networks Photo Upload Plugin ActiveX Control, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26830/
--
[SA26820] WinSCP Protocol Handler Command Line Switch Injection
Critical: Highly critical
Where: From remote
Impact: Manipulation of data, System access
Released: 2007-09-14
Kender.Security has discovered a vulnerability in WinSCP, which can be exploited by malicious people to manipulate certain files on a user's system and potentially to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26820/
--
[SA26878] Mercury Mail Transport System IMAPD SEARCH Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-09-20
void has discovered a vulnerability in Mercury Mail Transport System, which can be exploited by malicious users to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26878/
--
[SA26815] jetCast Server HTTP Request Processing Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-09-14
vCore has discovered a vulnerability in jetCast Server, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26815/
--
[SA26889] WebBatch Information Disclosure and Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information
Released: 2007-09-20
Doz has reported a vulnerability and a security issue in WebBatch, which can be exploited by malicious people to disclose system
information or conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/26889/
--
[SA26845] Second Life URI Handler Registration Vulnerability
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-09-18
pdp has reported a vulnerability in Second Life, which can be exploited by malicious people to disclose certain sensitive information.
Full Advisory:
http://secunia.com/advisories/26845/
--
[SA26836] MW6 Technologies QRCode ActiveX Control Two Insecure Methods
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2007-09-18
shinnai has discovered two vulnerabilities in MW6 Technologies QRCode ActiveX control, which can be exploited by malicious people to overwrite arbitrary files.
Full Advisory:
http://secunia.com/advisories/26836/
--
[SA26832] WinImage Directory Traversal Vulnerability
Critical: Less critical
Where: From remote
Impact: System access
Released: 2007-09-18
j00ru has discovered a vulnerability in WinImage, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26832/
UNIX/Linux:--
[SA26909] VMware ESX Server Multiple Security Updates
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Privilege escalation, DoS, System access
Released: 2007-09-20
VMware has issued an update for VMware ESX Server. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, perform certain actions with escalated privileges, or to cause a DoS (Denial of Service), by malicious users to bypass certain security restrictions, and by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26909/
--
[SA26861] rPath update for openoffice.org
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-19
rPath has issued an update for openoffice.org. This fixes a vulnerability, which potentially can be exploited by malicious people
to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26861/
--
[SA26855] Fedora update for openoffice.org
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-19
Fedora has issued an update for openoffice.org. This fixes a vulnerability, which potentially can be exploited by malicious people
to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26855/
--
[SA26844] Red Hat update for openoffice.org
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-18
Red Hat has issued an update for openoffice.org. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26844/
--
[SA26828] Gentoo update for realplayer
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-17
Gentoo has issued an update for realplayer. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26828/
--
[SA26824] rPath update for lighttpd
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-17
rPath has issued an update for lighttpd. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26824/
--
[SA26822] Trustix Update for Multiple Packages
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, DoS, System access
Released: 2007-09-18
Trustix has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or bypass certain security restrictions, and by malicious people to cause a DoS, conduct
cross-site scripting attacks, or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26822/
--
[SA26817] Debian update for openoffice.org
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-18
Debian has issued an update for openoffice.org. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26817/
--
[SA26896] Red Hat update for nfs-utils-lib
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-09-20
Red Hat has issued an update for nfs-utils-lib. This fixes a vulnerability, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26896/
--
[SA26882] Fedora update for qt
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-09-19
Fedora has issued an update for qt. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/26882/
--
[SA26880] Gentoo update for phpwiki
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2007-09-19
Gentoo has issued an update for phpwiki. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/26880/
--
[SA26868] Ubuntu update for qt
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-09-19
Ubuntu has issued an update for qt. This fixes a vulnerability, which can potentially be exploited by malicious people to cause a DoS (Denial of Service) or to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/26868/
--
[SA26865] Red Hat update for libvorbis
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-09-20
Red Hat has issued an update for libvorbis. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/26865/
--
[SA26862] Gentoo update for poppler
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-09-20
Gentoo has issued an update for poppler. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/26862/
--
[SA26860] rPath update for kdebase
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-09-19
rPath has issued an update for kdebase. This fixes a vulnerability, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/26860/
--
[SA26858] Sun Solaris BIND 8 Predictable DNS Query IDs Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2007-09-19
Sun has acknowledged a vulnerability in BIND 8 for Sun Solaris, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
http://secunia.com/advisories/26858/
--
[SA26857] SGI Advanced Linux Environment Multiple Updates
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-09-20
SGI has issued multiple updates for SGI Advanced Linux Environment. These fix some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26857/
--
[SA26856] Fedora update for gd
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-09-19
Fedora has issued an update for gd. This fixes some vulnerabilities, which can potentially be exploited to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26856/
--
[SA26852] Avaya Products Qt QTextEdit Error Message Handling Format String Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-09-17
Avaya has acknowledged a vulnerability in various Avaya products, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26852/
--
[SA26847] Avaya Products BIND Predictable DNS Query IDs Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2007-09-17
Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
http://secunia.com/advisories/26847/
--
[SA26838] rPath Update for Multiple php Packages
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass
Released: 2007-09-18
rPath has issued an update for multiple php packages. This fixes some vulnerabilities, where some have unknown impacts and others can be exploited by malicious, local users and malicious users to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/26838/
--
[SA26827] Gentoo flac123 Comment Parsing Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-09-17
Gentoo has acknowledged a vulnerability in flac123, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26827/
--
[SA26826] Gentoo update for eggdrop
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-09-17
Gentoo has issued an update for eggdrop. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26826/
--
[SA26821] PHP Webquest "id_actividad" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-09-17
D4real_TeaM has discovered a vulnerability in PHP Webquest, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/26821/
--
[SA26814] Gentoo update for streamripper
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-09-14
Gentoo has issued an update for streamripper. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26814/
--
[SA26813] Gentoo update for kvirc
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-09-14
Gentoo has issues an update for kvirc. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26813/
--
[SA26811] Qt QUtf8Decoder Off-By-One Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-09-14
A vulnerability has been reported in Qt, which can potentially be exploited by malicious people to cause a DoS (Denial of Service) or to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/26811/
--
[SA26823] rPath update for xorg-x11
Critical: Moderately critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-17
rPath has issued an update for xorg-x11. This fixes a vulnerability, which can potentially be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/26823/
--
[SA26901] Ubuntu update for t1lib
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-09-20
Ubuntu has issued an update for t1lib. This fixes a vulnerability, which can be exploited by malicious users to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26901/
--
[SA26872] Fedora update for cacti
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-09-19
Fedora has issued an update for cacti. This fixes some vulnerabilities, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26872/
--
[SA26870] Fedora update for mediawiki
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-09-19
Fedora has issued an update for mediawiki. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/26870/
--
[SA26863] Fedora update for quagga
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-09-19
Fedora has issued an update for quagga. This fixes some vulnerabilities, which potentially can be exploited by malicious users
to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26863/
--
[SA26842] Fedora update for httpd
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information, DoS
Released: 2007-09-19
Fedora has issued an update for httpd. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/26842/
--
[SA26831] AXIS 207W Network Camera Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2007-09-17
Seth Fogie has reported some vulnerabilities in the AXIS 207W Network Camera, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks, or by malicious users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26831/
--
[SA26829] Ubuntu update for quagga
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-09-17
Ubuntu has issued an update for quagga. This fixes some vulnerabilities, which can be exploited by malicious users to cause a
DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26829/
--
[SA26825] inotify-tools "inotifytools_snprintf()" Buffer Overflow Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-09-19
A vulnerability has been reported in inotify-tools, which can potentially be exploited by malicious users to compromise an
application using the library.
Full Advisory:
http://secunia.com/advisories/26825/
--
[SA26897] Red Hat update for xorg-x11
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-20
Red Hat has issued an update for xorg-x11. This fixes a vulnerability, which potentially can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/26897/
--
[SA26873] HP-UX logins(1M) Command Security Issue
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2007-09-20
A security issue has been reported in HP-UX, which may result in password problems not being detected.
Full Advisory:
http://secunia.com/advisories/26873/
--
[SA26866] SKK Tools skkdic-expr.c Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-19
A security issue has been reported in SKK Tools. This can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/26866/
--
[SA26859] Ubuntu update for xorg-server
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-19
Ubuntu has issued an update for xorg-server. This fixes a vulnerability, which potentially can be exploited by malicious, local
users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/26859/
--
[SA26834] rPath update for samba and samba-swat
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-17
rPath has issued an update for samba and samba-swat. This fixes a security issue, which can be exploited by malicious, local users gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/26834/
--
[SA26818] Gentoo update for id3lib
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-17
Gentoo has issued an update for id3lib. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/26818/
--
[SA26900] rPath update for gdm
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-09-20
rPath has issued an update for gdm. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26900/
--
[SA26894] KDE KDM Login Password Check Security Bypass
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2007-09-20
KDE has acknowledged a security issue in KDM, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/26894/
--
[SA26879] Gentoo update for gdm
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-09-19
Gentoo has issued an update for gdm. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26879/
--
[SA26810] Gentoo update for po4a
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-14
Gentoo has issued an update for po4a. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/26810/
Other:--
[SA26853] OmniPCX Enterprise Unified Maintenance Tool Shell Command Injection
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-17
A vulnerability has been reported in the OmniPCX Enterprise Unified Maintenance Tool, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26853/
--
[SA26869] AirDefense Airsensor M520 HTTPS Request Handling Denial of Service Vulnerabilities
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-09-19
Alex Hernandez has reported some vulnerabilities in AirDefense Airsensor M520, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26869/
Cross Platform:--
[SA26849] Joomla Joomla!12Pictures Component "mosConfig_live_site" File Inclusion
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-19
Morgan has reported a vulnerability in the Joomla!12Pictures component for Joomla, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26849/
--
[SA26840] Shop-Script FREE Security Bypass and PHP Code Execution
Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2007-09-18
Raz0r has discovered some vulnerabilities in Shop-Script FREE, which can be exploited by malicious people to bypass certain security restrictions and compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26840/
--
[SA26839] OpenOffice TIFF Parsing Integer Overflow Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-18
Some vulnerabilities have been reported in OpenOffice, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26839/
--
[SA26819] Alien Arena 2007 Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-09-14
Luigi Auriemma has reported some vulnerabilities in Alien Arena 2007, which can be exploited by malicious people to conduct DoS (Denial of Service) attacks or to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26819/
--
[SA26816] OpenOffice 2 TIFF Parsing Integer Overflow Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-18
Some vulnerabilities have been reported in OpenOffice, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26816/
--
[SA26812] phpFFL "PHPFFL_FILE_ROOT" File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information, System access
Released: 2007-09-17
Some vulnerabilities have been discovered in phpFFL (Fantasy Football League Manager), which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26812/
--
[SA26809] Joomla joomlaradio Component "mosConfig_live_site" File Inclusion
Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2007-09-14
Morgan has discovered a vulnerability in the joomlaradio component for Joomla, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26809/
--
[SA26908] PhpWebGallery "author" Script Insertion
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-09-20
nights_shadow has discovered a vulnerability in PhpWebGallery, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/26908/
--
[SA26902] OneCMS "abc" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-09-20
str0ke has reported a vulnerability in OneCMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/26902/
--
[SA26877] Merak Mail Server Email Body Script Insertion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-09-19
MWR InfoSecurity has reported a vulnerability in Merak Mail Server, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/26877/
--
[SA26875] phpBB Styles Demo Module SQL Injection and Cross-Site Scripting
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2007-09-19
nexen has discovered two vulnerabilities in the Styles Demo module for phpBB, which can be exploited by malicious people to conduct cross-site scripting attacks and SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/26875/
--
[SA26851] Chupix "fichier" Directory Traversal Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-09-17
GoLd_M has discovered a vulnerability in Chupix, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/26851/
--
[SA26890] VMWare Products Multiple Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: Privilege escalation, DoS, System access
Released: 2007-09-20
Multiple vulnerabilities have been reported in various VMware products, which can be exploited by malicious, local users to gain escalated privileges or cause a DoS (Denial of Service) or by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26890/
--
[SA26883] IBM Tivoli Storage Manager Client Information Disclosure and Buffer Overflow
Critical: Moderately critical
Where: From local network
Impact: Exposure of sensitive information, System access
Released: 2007-09-20
Two vulnerabilities have been reported in IBM Tivoli Storage Manager (TSM) Client, which can be exploited by malicious people to disclose sensitive information or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26883/
--
[SA26886] Phormer Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-09-20
nights.shadow has discovered some vulnerabilities in Phormer, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/26886/
--
[SA26881] Firefox "-chrome" Parameter Security Issue
Critical: Less critical
Where: From remote
Impact: System access
Released: 2007-09-19
Mozilla has acknowledged a security issue in Firefox, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26881/
--
[SA26854] b1gMail "chapter" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-09-18
malibu.r has reported a vulnerability in b1gMail, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/26854/
--
[SA26848] Bugzilla "createemailregexp" Security Bypass Vulnerability
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-09-19
A vulnerability has been reported in Bugzilla, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/26848/
--
[SA26843] Coppermine Photo Gallery Cross-Site Scripting and Local File Inclusion
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2007-09-18
L4teral has discovered two vulnerabilities in Coppermine Photo Gallery, which can be exploited by malicious people to conduct cross-site scripting attacks and by malicious users to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/26843/
--
[SA26841] TinyWebGallery Multiple URL Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-09-17
VIRANGAR UNDER GR0UND TEAM has discovered some vulnerabilities in TinyWebGallery, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/26841/
--
[SA26837] Python imageop "tovideo()" Integer Overflow Security Issue
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-09-19
Slythers Bro has discovered a security issue in the imageop module for Python, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26837/
--
[SA26833] osCMax URL Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-09-17
VIRANGAR UNDER GR0UND TEAM has discovered a vulnerability in osCMax, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/26833/
--
[SA26876] Dibbler Multiple Denial of Service Vulnerabilities
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-09-20
Mu Security research team has reported some vulnerabilities in Dibbler, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26876/
A week after Microsoft released its security patches for August, several vulnerabilities have been reported in various Microsoft
products, which can be exploited by malicious people to compromise vulnerable systems.
The first, a vulnerability in Microsoft Windows, is caused by a boundary error in the "FindFile()" function of the CFileFind class in
the mfc42.dll and mfc42u.dll files. Passing an overly long argument to the affected function exploits the vulnerability, and causes a heap-based buffer overflow.
Two Hewlett-Packard products are known to contain vectors that may allow exploitation of this vulnerability: HP All-in-One Series Web Release software/driver installer version 2.1.0, and HP Photo & Imaging Gallery version 1.1.
The vulnerability is confirmed on a fully-patched Windows XP SP2 including mfc42.dll version 6.2.4131.0 and mfc42u.dll version
6.2.8071.0, and remains unpatched. For more information, refer to: http://secunia.com/advisories/26800/
Several other vulnerabilities were reported in two Microsoft Visual Studio ActiveX controls. The PDWizard.ocx ActiveX control contains the insecure methods "StartProcess()" and "SyncShell()", which can be exploited to execute arbitrary commands on the system. Other insecure methods have also been reported, such as "SaveAs()", "CABDefaultURL()", "CABFileName()", and "CABRunFile()".
The "Load()" and "SaveAs()" methods of the VBTOVSI.DLL ActiveX control can also be exploited to, for example, load a local file and save it in an arbitrary location or overwrite an arbitrary file.
The vulnerabilities are reported in version 6.0, and remain unpatched.
--
Some vulnerabilities have been reported in OpenOffice, which potentially can be exploited by malicious people to compromise a
user's system. By tricking a user into, for example, opening a specially crafted document that requires processing of TIFF images,
integer overflows can occur, which when exploited trigger heap-based buffer overflows. Successful exploitation may allow the execution of arbitrary code.
The vulnerabilities are reported in versions prior to 2.3. Users of OpenOffice versions prior to 2.3 are urged to upgrade to the fixed version. Users of the OpenOffice 1.1.x and 1.0.x branches should note that these versions are not patched, and should instead upgrade to version 2.3. For more information, refer to: http://secunia.com/advisories/26816/
--
A vulnerability in the popular virtual world Second Life was reported this week, which could potentially give a malicious person access to a legitimate player's user account.
The problem is that SecondLife registers the "secondlife://" URI handler and allows invoking SecondLife with arbitrary command line arguments. By using certain parameters, such as "-autologin" and "-loginuri", it is possible to gain knowledge of, for example, a user's username and password hash by specifying a malicious server.
Successful exploitation requires that the legitimate user is, for example, tricked into visiting a malicious website. The vulnerability, which is reported in version 1.x, remains unpatched. Users are urged not to browse untrusted sites. For more information, refer to: http://secunia.com/advisories/26845/
--
VIRUS ALERTS:
During the past week Secunia collected 167 virus descriptions from the Antivirus vendors. However, none were deemed MEDIUM risk or higher according to the Secunia assessment scale.
Vulnerabilities Content Listing
Windows:--
[SA26835] RemoteDocs R-Viewer RDZ Code Execution and Information Disclosure
Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2007-09-18
Adam Baldwin has reported a vulnerability and a security issue in RemoteDocs R-Viewer, which potentially can be exploited by malicious, local users to disclose sensitive information and by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26835/
--
[SA26830] PhotoChannel Networks Photo Upload Plugin ActiveX Control Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-17
Will Dormann has reported some vulnerabilities in PhotoChannel Networks Photo Upload Plugin ActiveX Control, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26830/
--
[SA26820] WinSCP Protocol Handler Command Line Switch Injection
Critical: Highly critical
Where: From remote
Impact: Manipulation of data, System access
Released: 2007-09-14
Kender.Security has discovered a vulnerability in WinSCP, which can be exploited by malicious people to manipulate certain files on a user's system and potentially to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26820/
--
[SA26878] Mercury Mail Transport System IMAPD SEARCH Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-09-20
void has discovered a vulnerability in Mercury Mail Transport System, which can be exploited by malicious users to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26878/
--
[SA26815] jetCast Server HTTP Request Processing Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-09-14
vCore has discovered a vulnerability in jetCast Server, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26815/
--
[SA26889] WebBatch Information Disclosure and Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information
Released: 2007-09-20
Doz has reported a vulnerability and a security issue in WebBatch, which can be exploited by malicious people to disclose system
information or conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/26889/
--
[SA26845] Second Life URI Handler Registration Vulnerability
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-09-18
pdp has reported a vulnerability in Second Life, which can be exploited by malicious people to disclose certain sensitive information.
Full Advisory:
http://secunia.com/advisories/26845/
--
[SA26836] MW6 Technologies QRCode ActiveX Control Two Insecure Methods
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2007-09-18
shinnai has discovered two vulnerabilities in MW6 Technologies QRCode ActiveX control, which can be exploited by malicious people to overwrite arbitrary files.
Full Advisory:
http://secunia.com/advisories/26836/
--
[SA26832] WinImage Directory Traversal Vulnerability
Critical: Less critical
Where: From remote
Impact: System access
Released: 2007-09-18
j00ru has discovered a vulnerability in WinImage, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26832/
UNIX/Linux:--
[SA26909] VMware ESX Server Multiple Security Updates
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Privilege escalation, DoS, System access
Released: 2007-09-20
VMware has issued an update for VMware ESX Server. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, perform certain actions with escalated privileges, or to cause a DoS (Denial of Service), by malicious users to bypass certain security restrictions, and by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26909/
--
[SA26861] rPath update for openoffice.org
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-19
rPath has issued an update for openoffice.org. This fixes a vulnerability, which potentially can be exploited by malicious people
to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26861/
--
[SA26855] Fedora update for openoffice.org
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-19
Fedora has issued an update for openoffice.org. This fixes a vulnerability, which potentially can be exploited by malicious people
to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26855/
--
[SA26844] Red Hat update for openoffice.org
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-18
Red Hat has issued an update for openoffice.org. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26844/
--
[SA26828] Gentoo update for realplayer
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-17
Gentoo has issued an update for realplayer. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26828/
--
[SA26824] rPath update for lighttpd
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-17
rPath has issued an update for lighttpd. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26824/
--
[SA26822] Trustix Update for Multiple Packages
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, DoS, System access
Released: 2007-09-18
Trustix has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or bypass certain security restrictions, and by malicious people to cause a DoS, conduct
cross-site scripting attacks, or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26822/
--
[SA26817] Debian update for openoffice.org
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-18
Debian has issued an update for openoffice.org. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26817/
--
[SA26896] Red Hat update for nfs-utils-lib
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-09-20
Red Hat has issued an update for nfs-utils-lib. This fixes a vulnerability, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26896/
--
[SA26882] Fedora update for qt
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-09-19
Fedora has issued an update for qt. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/26882/
--
[SA26880] Gentoo update for phpwiki
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2007-09-19
Gentoo has issued an update for phpwiki. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/26880/
--
[SA26868] Ubuntu update for qt
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-09-19
Ubuntu has issued an update for qt. This fixes a vulnerability, which can potentially be exploited by malicious people to cause a DoS (Denial of Service) or to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/26868/
--
[SA26865] Red Hat update for libvorbis
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-09-20
Red Hat has issued an update for libvorbis. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/26865/
--
[SA26862] Gentoo update for poppler
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-09-20
Gentoo has issued an update for poppler. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/26862/
--
[SA26860] rPath update for kdebase
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-09-19
rPath has issued an update for kdebase. This fixes a vulnerability, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/26860/
--
[SA26858] Sun Solaris BIND 8 Predictable DNS Query IDs Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2007-09-19
Sun has acknowledged a vulnerability in BIND 8 for Sun Solaris, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
http://secunia.com/advisories/26858/
--
[SA26857] SGI Advanced Linux Environment Multiple Updates
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-09-20
SGI has issued multiple updates for SGI Advanced Linux Environment. These fix some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26857/
--
[SA26856] Fedora update for gd
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-09-19
Fedora has issued an update for gd. This fixes some vulnerabilities, which can potentially be exploited to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26856/
--
[SA26852] Avaya Products Qt QTextEdit Error Message Handling Format String Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-09-17
Avaya has acknowledged a vulnerability in various Avaya products, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26852/
--
[SA26847] Avaya Products BIND Predictable DNS Query IDs Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2007-09-17
Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
http://secunia.com/advisories/26847/
--
[SA26838] rPath Update for Multiple php Packages
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass
Released: 2007-09-18
rPath has issued an update for multiple php packages. This fixes some vulnerabilities, where some have unknown impacts and others can be exploited by malicious, local users and malicious users to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/26838/
--
[SA26827] Gentoo flac123 Comment Parsing Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-09-17
Gentoo has acknowledged a vulnerability in flac123, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26827/
--
[SA26826] Gentoo update for eggdrop
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-09-17
Gentoo has issued an update for eggdrop. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26826/
--
[SA26821] PHP Webquest "id_actividad" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-09-17
D4real_TeaM has discovered a vulnerability in PHP Webquest, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/26821/
--
[SA26814] Gentoo update for streamripper
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-09-14
Gentoo has issued an update for streamripper. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26814/
--
[SA26813] Gentoo update for kvirc
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-09-14
Gentoo has issues an update for kvirc. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26813/
--
[SA26811] Qt QUtf8Decoder Off-By-One Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-09-14
A vulnerability has been reported in Qt, which can potentially be exploited by malicious people to cause a DoS (Denial of Service) or to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/26811/
--
[SA26823] rPath update for xorg-x11
Critical: Moderately critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-17
rPath has issued an update for xorg-x11. This fixes a vulnerability, which can potentially be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/26823/
--
[SA26901] Ubuntu update for t1lib
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-09-20
Ubuntu has issued an update for t1lib. This fixes a vulnerability, which can be exploited by malicious users to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26901/
--
[SA26872] Fedora update for cacti
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-09-19
Fedora has issued an update for cacti. This fixes some vulnerabilities, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26872/
--
[SA26870] Fedora update for mediawiki
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-09-19
Fedora has issued an update for mediawiki. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/26870/
--
[SA26863] Fedora update for quagga
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-09-19
Fedora has issued an update for quagga. This fixes some vulnerabilities, which potentially can be exploited by malicious users
to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26863/
--
[SA26842] Fedora update for httpd
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information, DoS
Released: 2007-09-19
Fedora has issued an update for httpd. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/26842/
--
[SA26831] AXIS 207W Network Camera Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2007-09-17
Seth Fogie has reported some vulnerabilities in the AXIS 207W Network Camera, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks, or by malicious users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26831/
--
[SA26829] Ubuntu update for quagga
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-09-17
Ubuntu has issued an update for quagga. This fixes some vulnerabilities, which can be exploited by malicious users to cause a
DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26829/
--
[SA26825] inotify-tools "inotifytools_snprintf()" Buffer Overflow Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-09-19
A vulnerability has been reported in inotify-tools, which can potentially be exploited by malicious users to compromise an
application using the library.
Full Advisory:
http://secunia.com/advisories/26825/
--
[SA26897] Red Hat update for xorg-x11
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-20
Red Hat has issued an update for xorg-x11. This fixes a vulnerability, which potentially can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/26897/
--
[SA26873] HP-UX logins(1M) Command Security Issue
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2007-09-20
A security issue has been reported in HP-UX, which may result in password problems not being detected.
Full Advisory:
http://secunia.com/advisories/26873/
--
[SA26866] SKK Tools skkdic-expr.c Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-19
A security issue has been reported in SKK Tools. This can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/26866/
--
[SA26859] Ubuntu update for xorg-server
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-19
Ubuntu has issued an update for xorg-server. This fixes a vulnerability, which potentially can be exploited by malicious, local
users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/26859/
--
[SA26834] rPath update for samba and samba-swat
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-17
rPath has issued an update for samba and samba-swat. This fixes a security issue, which can be exploited by malicious, local users gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/26834/
--
[SA26818] Gentoo update for id3lib
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-17
Gentoo has issued an update for id3lib. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/26818/
--
[SA26900] rPath update for gdm
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-09-20
rPath has issued an update for gdm. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26900/
--
[SA26894] KDE KDM Login Password Check Security Bypass
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2007-09-20
KDE has acknowledged a security issue in KDM, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/26894/
--
[SA26879] Gentoo update for gdm
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-09-19
Gentoo has issued an update for gdm. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26879/
--
[SA26810] Gentoo update for po4a
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-14
Gentoo has issued an update for po4a. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/26810/
Other:--
[SA26853] OmniPCX Enterprise Unified Maintenance Tool Shell Command Injection
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-17
A vulnerability has been reported in the OmniPCX Enterprise Unified Maintenance Tool, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26853/
--
[SA26869] AirDefense Airsensor M520 HTTPS Request Handling Denial of Service Vulnerabilities
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-09-19
Alex Hernandez has reported some vulnerabilities in AirDefense Airsensor M520, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26869/
Cross Platform:--
[SA26849] Joomla Joomla!12Pictures Component "mosConfig_live_site" File Inclusion
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-19
Morgan has reported a vulnerability in the Joomla!12Pictures component for Joomla, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26849/
--
[SA26840] Shop-Script FREE Security Bypass and PHP Code Execution
Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2007-09-18
Raz0r has discovered some vulnerabilities in Shop-Script FREE, which can be exploited by malicious people to bypass certain security restrictions and compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26840/
--
[SA26839] OpenOffice TIFF Parsing Integer Overflow Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-18
Some vulnerabilities have been reported in OpenOffice, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26839/
--
[SA26819] Alien Arena 2007 Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-09-14
Luigi Auriemma has reported some vulnerabilities in Alien Arena 2007, which can be exploited by malicious people to conduct DoS (Denial of Service) attacks or to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26819/
--
[SA26816] OpenOffice 2 TIFF Parsing Integer Overflow Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-18
Some vulnerabilities have been reported in OpenOffice, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26816/
--
[SA26812] phpFFL "PHPFFL_FILE_ROOT" File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information, System access
Released: 2007-09-17
Some vulnerabilities have been discovered in phpFFL (Fantasy Football League Manager), which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26812/
--
[SA26809] Joomla joomlaradio Component "mosConfig_live_site" File Inclusion
Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2007-09-14
Morgan has discovered a vulnerability in the joomlaradio component for Joomla, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26809/
--
[SA26908] PhpWebGallery "author" Script Insertion
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-09-20
nights_shadow has discovered a vulnerability in PhpWebGallery, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/26908/
--
[SA26902] OneCMS "abc" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-09-20
str0ke has reported a vulnerability in OneCMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/26902/
--
[SA26877] Merak Mail Server Email Body Script Insertion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-09-19
MWR InfoSecurity has reported a vulnerability in Merak Mail Server, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/26877/
--
[SA26875] phpBB Styles Demo Module SQL Injection and Cross-Site Scripting
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2007-09-19
nexen has discovered two vulnerabilities in the Styles Demo module for phpBB, which can be exploited by malicious people to conduct cross-site scripting attacks and SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/26875/
--
[SA26851] Chupix "fichier" Directory Traversal Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-09-17
GoLd_M has discovered a vulnerability in Chupix, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/26851/
--
[SA26890] VMWare Products Multiple Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: Privilege escalation, DoS, System access
Released: 2007-09-20
Multiple vulnerabilities have been reported in various VMware products, which can be exploited by malicious, local users to gain escalated privileges or cause a DoS (Denial of Service) or by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26890/
--
[SA26883] IBM Tivoli Storage Manager Client Information Disclosure and Buffer Overflow
Critical: Moderately critical
Where: From local network
Impact: Exposure of sensitive information, System access
Released: 2007-09-20
Two vulnerabilities have been reported in IBM Tivoli Storage Manager (TSM) Client, which can be exploited by malicious people to disclose sensitive information or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26883/
--
[SA26886] Phormer Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-09-20
nights.shadow has discovered some vulnerabilities in Phormer, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/26886/
--
[SA26881] Firefox "-chrome" Parameter Security Issue
Critical: Less critical
Where: From remote
Impact: System access
Released: 2007-09-19
Mozilla has acknowledged a security issue in Firefox, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/26881/
--
[SA26854] b1gMail "chapter" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-09-18
malibu.r has reported a vulnerability in b1gMail, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/26854/
--
[SA26848] Bugzilla "createemailregexp" Security Bypass Vulnerability
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-09-19
A vulnerability has been reported in Bugzilla, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/26848/
--
[SA26843] Coppermine Photo Gallery Cross-Site Scripting and Local File Inclusion
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2007-09-18
L4teral has discovered two vulnerabilities in Coppermine Photo Gallery, which can be exploited by malicious people to conduct cross-site scripting attacks and by malicious users to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/26843/
--
[SA26841] TinyWebGallery Multiple URL Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-09-17
VIRANGAR UNDER GR0UND TEAM has discovered some vulnerabilities in TinyWebGallery, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/26841/
--
[SA26837] Python imageop "tovideo()" Integer Overflow Security Issue
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-09-19
Slythers Bro has discovered a security issue in the imageop module for Python, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/26837/
--
[SA26833] osCMax URL Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-09-17
VIRANGAR UNDER GR0UND TEAM has discovered a vulnerability in osCMax, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/26833/
--
[SA26876] Dibbler Multiple Denial of Service Vulnerabilities
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-09-20
Mu Security research team has reported some vulnerabilities in Dibbler, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/26876/

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Secunia 2007 Bulletins
October 10 2007
Microsoft acknowledged a vulnerability in the way it handles URIs. The issue, which was first reported as a Firefox vulnerability in
July, was eventually determined by Secunia Research to be a Windows problem.
The vulnerability is caused by an input validation error within the handling of URIs with registered URI handlers (e.g. "mailto", "news", "nntp", "snews", "telnet", and "http"). This can be exploited to execute arbitrary commands when a user of certain applications visits a malicious website or clicks on a link with a specially crafted URI containing a "%" character and ending with a certain extension (e.g. ".bat" or ".cmd").
The following have been identified as being possible attack vectors on Windows XP SP2 and Windows 2003 SP2 systems in which Internet Explorer 7 is installed:
* Firefox version 2.0.0.5 and Netscape Navigator version 9.0b2 (when opening a link or visiting a malicious website)
* mIRC version 6.3 (when opening a link)
* Adobe Reader/Acrobat version 8.1 and prior (when opening PDF files)
* Outlook Express 6 (e.g. when following specially crafted links in VCards)
* Outlook 2000 (e.g. when following specially crafted links in VCards)
Microsoft has released a security advisory for users to refer to while they further investigate the problem. For more information, refer to: http://secunia.com/advisories/26201/
--
A vulnerability has been reported in OpenBSD, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
DHCP requests within dhcpd in the "cons_options()" function in options.c are improperly handled, which can be exploited to cause a
stack-based buffer overflow by sending a specially crafted DHCP request specifying a maximum message size between DHCP_FIXED_LEN and DHCP_FIXED_LEN + 3.
Successful exploitation may allow the execution of arbitrary code. Users are urged to apply patches released by the OpenBSD team. Patches are available for OpenBSD 4.0, 4.1, and 4.2. For more information, refer to:
http://secunia.com/advisories/27160/
--
Two vulnerabilities previously discovered in Adobe Photoshop last April were confirmed by Secunia Research to also be present in Adobe GoLive and Adobe Illustrator.
The vulnerabilities, which are caused by input validation errors in the PNG.8BI and BMP.8BI format plugins, can be exploited to cause
heap-based buffer overflows. In GoLive, this moderately critical vulnerability is exploitable by, for example, dragging a specially
crafted PNG or BMP file into the HTML layout interface. In Illustrator, this is exploitable, for example, by simply opening a specially crafted PNG or BMP file, which is why Secunia rates the vulnerability in Illustrator as highly critical. Exploiting these vulnerabilities allows an attacker to execute arbitrary code.
Adobe has released fixes for the vulnerability in Adobe Illustrator. Fixes for the vulnerability in Adobe GoLive are also available for
Windows users; Macintosh users are advised to perform the vendor-recommended workarounds in the meantime. For more information, refer to:
http://secunia.com/advisories/26846/
http://secunia.com/advisories/26864/
A vulnerability in Adobe Pagemaker was also disclosed this week. The highly critical vulnerability, which is caused by a boundary error in MAIPM6.DLL when handling font names in PageMaker (.PMD) files, can be exploited to cause a stack-based buffer overflow by, for example, opening a specially-crafted .PMD file containing an overly long font name.
Successful exploitation allows execution of arbitrary code. The vendor has also released updates for the affected software. All Adobe
Pagemaker 7.0.1 and 7.0.2 users are urged to apply the updates as soon as possible.
Windows:--
[SA27151] Microsoft Word Unspecified Memory Corruption Vulnerability
Critical: Extremely critical
Where: From remote
Impact: System access
Released: 2007-10-09
A vulnerability has been reported in Microsoft Word, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27151/
--
[SA27187] Kaspersky Online Scanner ActiveX Control Format String Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-11
A vulnerability has been reported in Kaspersky Online Scanner, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27187/
--
[SA27158] Adobe Pagemaker Long Font Name Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-10
Tan Chew Keong has reported a vulnerability in Adobe Pagemaker, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27158/
--
[SA27143] Electronic Arts SnoopyCtrl ActiveX Control Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-09
Will Dormann has reported some vulnerabilities in Electronic Arts SnoopyCtrl ActiveX control, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27143/
--
[SA27112] Microsoft Windows NNTP Response Handling Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-09
VeriSign iDefense Labs has reported a vulnerability in Microsoft Windows, which can be exploited by malicious people to compromise a
user's system.
Full Advisory:
http://secunia.com/advisories/27112/
--
[SA27092] Microsoft Windows Kodak Image Viewer Code Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-09
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27092/
--
[SA27192] CA BrightStor ARCServe Backup Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2007-10-11
Multiple vulnerabilities have been reported in CA BrightStor ARCserve Backup, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27192/
--
[SA27157] World in Conflict VOIP Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-10
Luigi Auriemma has reported a vulnerability in World in Conflict, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
http://secunia.com/advisories/27157/
--
[SA27075] Hitachi Cosminexus JSSE SSL/TLS Handshake Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-05
A vulnerability has been reported in Hitachi Cosminexus, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27075/
--
[SA27166] EMC RepliStor Server Service Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-10-11
Aaron Portnoy has reported a vulnerability in EMC RepliStor, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27166/
--
[SA27148] Microsoft Windows SharePoint Services / Office SharePoint Server Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-09
A vulnerability has been reported in Microsoft SharePoint Services and Office SharePoint Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27148/
--
[SA27133] Internet Explorer Unspecified Address Bar Spoofing Vulnerability
Critical: Less critical
Where: From remote
Impact: Spoofing
Released: 2007-10-09
A vulnerability has been reported in Internet Explorer, which can be exploited by a malicious website to spoof the address bar.
Full Advisory:
http://secunia.com/advisories/27133/
--
[SA27120] DB Manager "id" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-08
r0t has reported a vulnerability in DB Manager, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27120/
--
[SA27115] dbList "dblisttest.asp" Multiple Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-08
r0t has reported some vulnerabilities in dbList, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27115/
--
[SA27095] Pegasus Imaging ImagXpress Two ActiveX Controls Insecure Methods
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-08
shinnai has discovered two vulnerabilities in Pegasus Imaging ImagXpress, which can be exploited by malicious people to overwrite or
delete arbitrary files.
Full Advisory:
http://secunia.com/advisories/27095/
--
[SA27080] Helm Web Hosting Control Panel Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-05
r0t has reported some vulnerabilities in Helm Web Hosting Control Panel, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27080/
--
[SA27153] Microsoft Windows 2000 RPC Authentication Information Disclosure
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2007-10-09
A vulnerability has been reported in Microsoft Windows 2000, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27153/
--
[SA27134] Microsoft Windows RPC Authentication Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-10-09
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27134/
--
[SA27082] NetSupport Products Unspecified Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-10-05
A vulnerability has been reported in NetSupport products, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27082/
--
[SA27094] VBA32 Antivirus Insecure Default Directory Permissions
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-05
A security issue has been discovered in VBA32 Antivirus, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27094/
--
[SA27144] Microsoft Expression Media Password Disclosure Weakness
Critical: Not critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-10-10
A weakness has been reported in Microsoft Expression Media, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27144/
--
[SA27136] Interstage Application Server Full Path Disclosure Weakness
Critical: Not critical
Where: From remote
Impact: Exposure of system information
Released: 2007-10-09
A weakness has been reported in Interstage Application Server, which can be exploited by malicious people to disclose system information.
Full Advisory:
http://secunia.com/advisories/27136/
UNIX/Linux:--
[SA27190] TikiWiki tiki-graph_formula.php Function Injection
Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-11
ShAnKaR has reported a vulnerability in TikiWiki, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27190/
--
[SA27164] LightBlog Security Bypass and File Upload Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, System access
Released: 2007-10-10
BlackHawk has discovered two vulnerabilities in LightBlog, which can be exploited by malicious people to bypass certain security restrictions and to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27164/
--
[SA27139] LiveAlbum "livealbum_dir" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information, System access
Released: 2007-10-09
S.W.A.T. has discovered a vulnerability in LiveAlbum, which can be exploited by malicious people to disclose sensitive information or to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27139/
--
[SA27117] AlsaPlayer Vorbis Input Plug-in OGG Processing Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-08
Some vulnerabilities have been reported in AlsaPlayer, which potentially can be exploited by malicious people to compromise a user's
system.
Full Advisory:
http://secunia.com/advisories/27117/
--
[SA27097] Gentoo update for openssl
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-08
Gentoo has issued an update for openssl. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27097/
--
[SA27087] Fedora update for openoffice.org
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-05
Fedora has issued an update for openoffice.org. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27087/
--
[SA27081] Gentoo update for librpcsecgss
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-05
Gentoo has issued an update for librpcsecgss. This fixes a vulnerability, which can be exploited by malicious people to compromise
an application using the library.
Full Advisory:
http://secunia.com/advisories/27081/
--
[SA27078] Mandriva update for openssl
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-05
Mandriva has issued an update for openssl. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27078/
--
[SA27077] Ubuntu update for openoffice.org
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-05
Ubuntu has issued an update for openoffice.org. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27077/
--
[SA27185] cpDynaLinks "category" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-10-11
s0cratex has discovered a vulnerability in cpDynaLinks, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27185/
--
[SA27184] Asterisk IMAP Storage Voicemail Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-11
A vulnerability has been reported in Asterisk, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27184/
--
[SA27167] Gentoo update for NX
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-10
Gentoo has released an update for NX. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27167/
--
[SA27162] NX Server PCF Integer Overflow Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-10
Some vulnerabilities have been reported in NX Server, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27162/
--
[SA27156] Gentoo updates for koffice, kword, kdegraphics, and kpdf
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-10-10
Gentoo has issued updates for koffice, kword, kdegraphics, and kpdf. These fix a vulnerability, which potentially can be exploited by
malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27156/
--
[SA27146] Avaya Products nfs-utils-lib Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-09
Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27146/
--
[SA27131] PHP Homepage M "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-10-09
[PHCN] Mahjong has discovered a vulnerability in PHP Homepage M, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27131/
--
[SA27129] OpenH323 opal Session Initiation Protocol Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-08
A vulnerability has been reported in OpenH323 opal, which can potentially be exploited by malicious people to compromise an
application using the library.
Full Advisory:
http://secunia.com/advisories/27129/
--
[SA27128] Ekiga opal Session Initiation Protocol Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-08
A vulnerability has been reported in Ekiga, which can potentially be exploited by malicious people to compromise an vulnerable system.
Full Advisory:
http://secunia.com/advisories/27128/
--
[SA27124] Nagios Plugins Long Location Header Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-10-08
Nobuhiro Ban has reported a vulnerability in Nagios Plugins, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27124/
--
[SA27118] Red Hat update for opal
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-08
Red Hat has issued an update for opal. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27118/
--
[SA27113] Verlihub Control Panel "page" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information
Released: 2007-10-09
Methodman has reported a vulnerability in Verlihub Control Panel, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27113/
--
[SA27110] Fedora update for php
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass
Released: 2007-10-08
Fedora has issued an update for php. This fixes some vulnerabilities, where some have unknown impacts and others can be exploited by malicious users to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27110/
--
[SA27102] Gentoo update for php
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass, Exposure of sensitive
information, Privilege escalation, DoS, System access
Released: 2007-10-08
Gentoo has issued an update for php. This fixes some security issues and vulnerabilities, where some have unknown impacts and others can be exploited by malicious, local users to bypass certain security restrictions, by malicious users to bypass certain security
restrictions, gain escalated privileges, and cause a DoS (Denial of Service), and by malicious people to expose potentially sensitive
information, cause a DoS, and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27102/
--
[SA27100] Gentoo update for libsndfile
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-10-08
Gentoo has issued an update for libsndfile. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27100/
--
[SA27099] Gentoo update for libvorbis
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-08
Gentoo has issued an update for libvorbis. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) and potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27099/
--
[SA27086] Gentoo update for tk
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-08
Gentoo has issued an update for tk. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an
application using the library.
Full Advisory:
http://secunia.com/advisories/27086/
--
[SA27071] Ubuntu update for libsndfile
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-10-05
Ubuntu has issued an update for libsndfile. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27071/
--
[SA27176] Sun Solaris X Font Server Multiple Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-10-11
Sun has acknowledged some vulnerabilities in Sun Solaris, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27176/
--
[SA27160] OpenBSD dhcpd Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-10-10
A vulnerability has been reported in OpenBSD, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27160/
--
[SA27150] Red Hat update for pwlib
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-09
Red Hat has issued an update for pwlib. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27150/
--
[SA27119] Minki "page" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-08
r0t has discovered a vulnerability in Minki, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27119/
--
[SA27108] Red Hat update for kdelibs
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Spoofing
Released: 2007-10-08
Red Hat has issued an update for kdelibs. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting and spoofing attacks.
Full Advisory:
http://secunia.com/advisories/27108/
--
[SA27106] Red Hat update for kdebase
Critical: Less critical
Where: From remote
Impact: Security Bypass, Spoofing
Released: 2007-10-08
Red Hat has issued an update for kdebase. This fixes a security issue and some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions and by malicious people to conduct spoofing attacks.
Full Advisory:
http://secunia.com/advisories/27106/
--
[SA27096] Fedora update for kdebase
Critical: Less critical
Where: From remote
Impact: Security Bypass, Spoofing
Released: 2007-10-09
Fedora has issued an update for kdebase. This fixes a security issue and some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions and by malicious people to conduct spoofing attacks.
Full Advisory:
http://secunia.com/advisories/27096/
--
[SA27090] Fedora update for kdelibs
Critical: Less critical
Where: From remote
Impact: Spoofing
Released: 2007-10-09
Fedora has issued an update for kdelibs. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
spoofing attacks.
Full Advisory:
http://secunia.com/advisories/27090/
--
[SA27155] Ubuntu update for mysql
Critical: Less critical
Where: From local network
Impact: Security Bypass, Privilege escalation, DoS
Released: 2007-10-11
Ubuntu has issued an update for mysql. This fixes some vulnerabilities and security issues, which can be exploited by malicious users to gain escalated privileges, bypass certain security restrictions and cause a DoS (Denial of Service) or malicious people to cause a DoS.
Full Advisory:
http://secunia.com/advisories/27155/
--
[SA27132] Fedora update for elinks
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2007-10-09
Fedora has issued an update for elinks. This fixes a weakness, which can be exploited by malicious people to disclose sensitive
information.
Full Advisory:
http://secunia.com/advisories/27132/
--
[SA27125] rPath update for elinks
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2007-10-08
rPath has issued an update for elinks. This fixes a weakness, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27125/
--
[SA27168] Debian update for xfs
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-10
Debian has issued an update for xfs. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated
privileges.
Full Advisory:
http://secunia.com/advisories/27168/
--
[SA27161] Ubuntu update for xen
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-10
Ubuntu has issued an update for xen. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated
privileges.
Full Advisory:
http://secunia.com/advisories/27161/
--
[SA27147] Avaya Products X.org X11 Composite Pixmap Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-09
Avaya has acknowledged a vulnerability in various Avaya products, which potentially can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27147/
--
[SA27141] rPath update for xen
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-09
rPath has issued an update for xen. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated
privileges.
Full Advisory:
http://secunia.com/advisories/27141/
--
[SA27111] ldapscripts Command Line User Credentials Disclosure
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2007-10-09
A security issue has been reported in ldapscripts, which can be exploited by malicious, local users to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27111/
--
[SA27103] Fedora update for xen
Critical: Less critical
Where: Local system
Impact: Security Bypass, Privilege escalation
Released: 2007-10-09
Fedora has issued an update for xen. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain
security restrictions or gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27103/
--
[SA27085] Debian update for xen-utils
Critical: Less critical
Where: Local system
Impact: Security Bypass, Privilege escalation
Released: 2007-10-08
Debian has issued an update for xen-utils. This fixes some vulnerabilities, which can be exploited by malicious, local users to
bypass certain security restrictions or gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27085/
--
[SA27079] Ubuntu update for debian-goodies
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-05
Ubuntu has issued an update for debian-goodies. This fixes a vulnerability, which can be exploited by malicious, local users to
perform actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27079/
--
[SA27076] guilt Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-05
Some vulnerabilities have been reported in guilt, which can be exploited by malicious, local users to perform certain actions with
escalated privileges.
Full Advisory:
http://secunia.com/advisories/27076/
--
[SA27072] Fedora update for xen
Critical: Less critical
Where: Local system
Impact: Security Bypass, Privilege escalation
Released: 2007-10-05
Fedora has issued an update for xen. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain
security restrictions and gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27072/
--
[SA27088] Fedora update for pidgin
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2007-10-05
Fedora has issued an update for pidgin. This fixes a weakness, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
http://secunia.com/advisories/27088/
--
[SA27101] Fedora update for kernel
Critical: Not critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2007-10-09
Fedora has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious, local users to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27101/
--
[SA27188] Fedora update for util-linux
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-11
Fedora has issued an update for util-linux. This fixes a vulnerability, which potentially can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27188/
--
[SA27154] Sun Solaris Virtual File System (VFS) Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-10-10
Sun has acknowledged a vulnerability in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).
Full Advisory:
http://secunia.com/advisories/27154/
--
[SA27152] Sun Solaris Trusted Extensions "labeld" Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-10-10
Sun has acknowledged two vulnerabilities in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).
Full Advisory:
http://secunia.com/advisories/27152/
--
[SA27135] Sun Solaris vuidmice Streams Modules Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-10-09
A security issue has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).
Full Advisory:
http://secunia.com/advisories/27135/
--
[SA27104] rPath update for util-linux
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-09
rPath has issued an update for util-linux. This fixes a vulnerability, which potentially can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27104/
--
[SA27098] Gentoo update for qgit
Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation
Released: 2007-10-08
Gentoo has issued an update for qgit. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated
privileges.
Full Advisory:
http://secunia.com/advisories/27098/
--
[SA27089] Fedora update for kdebase
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2007-10-05
Fedora has issued an update for kdebase. This fixes a security issue, which can be exploited by malicious, local users to bypass certain
security restrictions.
Full Advisory:
http://secunia.com/advisories/27089/
Other:--
[SA27084] OpenVMS Denial of Service Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-05
Some vulnerabilities have been reported in OpenVMS, which can be exploited by malicious, local users and by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27084/
--
[SA27169] Cisco IOS Line Printer Daemon Buffer Overflow Vulnerability
Critical: Not critical
Where: From local network
Impact: DoS, System access
Released: 2007-10-11
Andy Davis has reported a vulnerability in Cisco IOS, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27169/
--
[SA27175] Sun Solaris 10 BSM Network Auditing Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-10-11
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).
Full Advisory:
http://secunia.com/advisories/27175/
Cross Platform:--
[SA27174] Knowledgeroot Knowledgebase FCKEditor PHP File Upload Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-11
A vulnerability has been reported in Knowledgeroot Knowledgebase, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27174/
--
[SA27172] NuSEO.PHP "nuseo_dir" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information, System access
Released: 2007-10-11
BiNgZa has discovered a vulnerability in NuSEO.PHP, which can be exploited by malicious people to disclose sensitive information or to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27172/
--
[SA27140] xKiosk WEB "PEARPATH" Remote File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-09
BorN To K!LL has reported a vulnerability in xKiosk WEB, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27140/
--
[SA27123] FCKEditor PHP File Upload Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-11
Janek Vind has reported a vulnerability in FCKEditor, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27123/
--
[SA27199] ViArt Shop iDEAL Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information
Released: 2007-10-11
A vulnerability has been reported in ViArt Shop, which can be exploited by malicious people to gain knowledge of sensitive and system
information.
Full Advisory:
http://secunia.com/advisories/27199/
--
[SA27159] LedgerSMB Multiple SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-10-10
Some vulnerabilities have been reported in LedgerSMB, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27159/
--
[SA27142] TYPOlight webCMS "preview.php" Arbitrary File Download
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information
Released: 2007-10-09
Stephan Munz has reported a vulnerability in TYPOlight webCMS, which can be exploited by malicious people to disclose sensitive
information.
Full Advisory:
http://secunia.com/advisories/27142/
--
[SA27138] Softbiz Jobs and Recruitment Script "cid" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-10-09
IRCRASH has reported a vulnerability in Softbiz Jobs and Recruitment Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27138/
--
[SA27137] Wesnoth UTF-8 Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-10
A vulnerability has been reported in Wesnoth, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27137/
--
[SA27114] SkaDate "view_mode" Directory Traversal Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information
Released: 2007-10-08
SnIpEr_SA has reported a vulnerability in SkaDate, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27114/
--
[SA27109] TorrentTrader Cross-Site Scripting and Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information,
Exposure of sensitive information
Released: 2007-10-09
HACKERS PAL has discovered some vulnerabilities in TorrentTrader, which can be exploited by malicious people to conduct cross-site scripting attacks or to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27109/
--
[SA27107] DropTeam Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2007-10-08
Luigi Auriemma has reported some vulnerabilities in DropTeam, which can be exploited by malicious people to disclose sensitive information or to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27107/
--
[SA27091] wzdftpd "do_login_loop()" Off-By-One Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-08
k1tk4t has discovered a vulnerability in wzdftpd, which can be exploited by malicious people to cause a DoS (Denial of Service) or
potentially to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27091/
--
[SA27083] The Dawn of Time HTTP Authentication Format String Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-08
Luigi Auriemma has reported a vulnerability in The Dawn of Time, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27083/
--
[SA27194] Interspire ActiveKB NX "page" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-11
durito has reported a vulnerability in ActiveKB NX, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27194/
--
[SA27173] phpMyAdmin "setup.php" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-11
Omer Singer has reported a vulnerability in phpMyAdmin, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27173/
--
[SA27163] DNews dnewsweb Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-10
Doz has discovered two vulnerabilities in DNews, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27163/
--
[SA27130] libpng ICC Profile Chunk Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-08
A vulnerability has been reported in libpng, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27130/
--
[SA27127] PWLib "PString::vsprintf()" Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-09
A vulnerability has been discovered in PWLib, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27127/
--
[SA27093] libpng Multiple Denial of Service Vulnerabilities
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-08
Some vulnerabilities have been reported in libpng, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27093/
--
[SA27073] MailBee WebMail Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-09
Ivan Javier Sanchez has reported some vulnerabilities in MailBee WebMail, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27073/
--
[SA27074] Hitachi Cosminexus Agent Unspecified Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-10-05
A vulnerability has been reported in Hitachi Cosminexus Agent, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
http://secunia.com/advisories/27074/
--
[SA27145] util-linux Privilege Escalation Vulnerability
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-09
A vulnerability has been reported in util-linux, which potentially can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27145/
--
[SA27121] WebSphere Application Server for z/OS HTTP Server Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-10-09
IBM has acknowledged a vulnerability in WebSphere Application Server for z/OS, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27121/
Microsoft acknowledged a vulnerability in the way it handles URIs. The issue, which was first reported as a Firefox vulnerability in
July, was eventually determined by Secunia Research to be a Windows problem.
The vulnerability is caused by an input validation error within the handling of URIs with registered URI handlers (e.g. "mailto", "news", "nntp", "snews", "telnet", and "http"). This can be exploited to execute arbitrary commands when a user of certain applications visits a malicious website or clicks on a link with a specially crafted URI containing a "%" character and ending with a certain extension (e.g. ".bat" or ".cmd").
The following have been identified as being possible attack vectors on Windows XP SP2 and Windows 2003 SP2 systems in which Internet Explorer 7 is installed:
* Firefox version 2.0.0.5 and Netscape Navigator version 9.0b2 (when opening a link or visiting a malicious website)
* mIRC version 6.3 (when opening a link)
* Adobe Reader/Acrobat version 8.1 and prior (when opening PDF files)
* Outlook Express 6 (e.g. when following specially crafted links in VCards)
* Outlook 2000 (e.g. when following specially crafted links in VCards)
Microsoft has released a security advisory for users to refer to while they further investigate the problem. For more information, refer to: http://secunia.com/advisories/26201/
--
A vulnerability has been reported in OpenBSD, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
DHCP requests within dhcpd in the "cons_options()" function in options.c are improperly handled, which can be exploited to cause a
stack-based buffer overflow by sending a specially crafted DHCP request specifying a maximum message size between DHCP_FIXED_LEN and DHCP_FIXED_LEN + 3.
Successful exploitation may allow the execution of arbitrary code. Users are urged to apply patches released by the OpenBSD team. Patches are available for OpenBSD 4.0, 4.1, and 4.2. For more information, refer to:
http://secunia.com/advisories/27160/
--
Two vulnerabilities previously discovered in Adobe Photoshop last April were confirmed by Secunia Research to also be present in Adobe GoLive and Adobe Illustrator.
The vulnerabilities, which are caused by input validation errors in the PNG.8BI and BMP.8BI format plugins, can be exploited to cause
heap-based buffer overflows. In GoLive, this moderately critical vulnerability is exploitable by, for example, dragging a specially
crafted PNG or BMP file into the HTML layout interface. In Illustrator, this is exploitable, for example, by simply opening a specially crafted PNG or BMP file, which is why Secunia rates the vulnerability in Illustrator as highly critical. Exploiting these vulnerabilities allows an attacker to execute arbitrary code.
Adobe has released fixes for the vulnerability in Adobe Illustrator. Fixes for the vulnerability in Adobe GoLive are also available for
Windows users; Macintosh users are advised to perform the vendor-recommended workarounds in the meantime. For more information, refer to:
http://secunia.com/advisories/26846/
http://secunia.com/advisories/26864/
A vulnerability in Adobe Pagemaker was also disclosed this week. The highly critical vulnerability, which is caused by a boundary error in MAIPM6.DLL when handling font names in PageMaker (.PMD) files, can be exploited to cause a stack-based buffer overflow by, for example, opening a specially-crafted .PMD file containing an overly long font name.
Successful exploitation allows execution of arbitrary code. The vendor has also released updates for the affected software. All Adobe
Pagemaker 7.0.1 and 7.0.2 users are urged to apply the updates as soon as possible.
Windows:--
[SA27151] Microsoft Word Unspecified Memory Corruption Vulnerability
Critical: Extremely critical
Where: From remote
Impact: System access
Released: 2007-10-09
A vulnerability has been reported in Microsoft Word, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27151/
--
[SA27187] Kaspersky Online Scanner ActiveX Control Format String Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-11
A vulnerability has been reported in Kaspersky Online Scanner, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27187/
--
[SA27158] Adobe Pagemaker Long Font Name Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-10
Tan Chew Keong has reported a vulnerability in Adobe Pagemaker, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27158/
--
[SA27143] Electronic Arts SnoopyCtrl ActiveX Control Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-09
Will Dormann has reported some vulnerabilities in Electronic Arts SnoopyCtrl ActiveX control, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27143/
--
[SA27112] Microsoft Windows NNTP Response Handling Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-09
VeriSign iDefense Labs has reported a vulnerability in Microsoft Windows, which can be exploited by malicious people to compromise a
user's system.
Full Advisory:
http://secunia.com/advisories/27112/
--
[SA27092] Microsoft Windows Kodak Image Viewer Code Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-09
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27092/
--
[SA27192] CA BrightStor ARCServe Backup Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2007-10-11
Multiple vulnerabilities have been reported in CA BrightStor ARCserve Backup, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27192/
--
[SA27157] World in Conflict VOIP Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-10
Luigi Auriemma has reported a vulnerability in World in Conflict, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
http://secunia.com/advisories/27157/
--
[SA27075] Hitachi Cosminexus JSSE SSL/TLS Handshake Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-05
A vulnerability has been reported in Hitachi Cosminexus, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27075/
--
[SA27166] EMC RepliStor Server Service Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-10-11
Aaron Portnoy has reported a vulnerability in EMC RepliStor, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27166/
--
[SA27148] Microsoft Windows SharePoint Services / Office SharePoint Server Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-09
A vulnerability has been reported in Microsoft SharePoint Services and Office SharePoint Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27148/
--
[SA27133] Internet Explorer Unspecified Address Bar Spoofing Vulnerability
Critical: Less critical
Where: From remote
Impact: Spoofing
Released: 2007-10-09
A vulnerability has been reported in Internet Explorer, which can be exploited by a malicious website to spoof the address bar.
Full Advisory:
http://secunia.com/advisories/27133/
--
[SA27120] DB Manager "id" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-08
r0t has reported a vulnerability in DB Manager, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27120/
--
[SA27115] dbList "dblisttest.asp" Multiple Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-08
r0t has reported some vulnerabilities in dbList, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27115/
--
[SA27095] Pegasus Imaging ImagXpress Two ActiveX Controls Insecure Methods
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-08
shinnai has discovered two vulnerabilities in Pegasus Imaging ImagXpress, which can be exploited by malicious people to overwrite or
delete arbitrary files.
Full Advisory:
http://secunia.com/advisories/27095/
--
[SA27080] Helm Web Hosting Control Panel Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-05
r0t has reported some vulnerabilities in Helm Web Hosting Control Panel, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27080/
--
[SA27153] Microsoft Windows 2000 RPC Authentication Information Disclosure
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2007-10-09
A vulnerability has been reported in Microsoft Windows 2000, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27153/
--
[SA27134] Microsoft Windows RPC Authentication Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-10-09
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27134/
--
[SA27082] NetSupport Products Unspecified Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-10-05
A vulnerability has been reported in NetSupport products, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27082/
--
[SA27094] VBA32 Antivirus Insecure Default Directory Permissions
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-05
A security issue has been discovered in VBA32 Antivirus, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27094/
--
[SA27144] Microsoft Expression Media Password Disclosure Weakness
Critical: Not critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-10-10
A weakness has been reported in Microsoft Expression Media, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27144/
--
[SA27136] Interstage Application Server Full Path Disclosure Weakness
Critical: Not critical
Where: From remote
Impact: Exposure of system information
Released: 2007-10-09
A weakness has been reported in Interstage Application Server, which can be exploited by malicious people to disclose system information.
Full Advisory:
http://secunia.com/advisories/27136/
UNIX/Linux:--
[SA27190] TikiWiki tiki-graph_formula.php Function Injection
Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-11
ShAnKaR has reported a vulnerability in TikiWiki, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27190/
--
[SA27164] LightBlog Security Bypass and File Upload Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, System access
Released: 2007-10-10
BlackHawk has discovered two vulnerabilities in LightBlog, which can be exploited by malicious people to bypass certain security restrictions and to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27164/
--
[SA27139] LiveAlbum "livealbum_dir" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information, System access
Released: 2007-10-09
S.W.A.T. has discovered a vulnerability in LiveAlbum, which can be exploited by malicious people to disclose sensitive information or to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27139/
--
[SA27117] AlsaPlayer Vorbis Input Plug-in OGG Processing Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-08
Some vulnerabilities have been reported in AlsaPlayer, which potentially can be exploited by malicious people to compromise a user's
system.
Full Advisory:
http://secunia.com/advisories/27117/
--
[SA27097] Gentoo update for openssl
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-08
Gentoo has issued an update for openssl. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27097/
--
[SA27087] Fedora update for openoffice.org
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-05
Fedora has issued an update for openoffice.org. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27087/
--
[SA27081] Gentoo update for librpcsecgss
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-05
Gentoo has issued an update for librpcsecgss. This fixes a vulnerability, which can be exploited by malicious people to compromise
an application using the library.
Full Advisory:
http://secunia.com/advisories/27081/
--
[SA27078] Mandriva update for openssl
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-05
Mandriva has issued an update for openssl. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27078/
--
[SA27077] Ubuntu update for openoffice.org
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-05
Ubuntu has issued an update for openoffice.org. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27077/
--
[SA27185] cpDynaLinks "category" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-10-11
s0cratex has discovered a vulnerability in cpDynaLinks, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27185/
--
[SA27184] Asterisk IMAP Storage Voicemail Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-11
A vulnerability has been reported in Asterisk, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27184/
--
[SA27167] Gentoo update for NX
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-10
Gentoo has released an update for NX. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27167/
--
[SA27162] NX Server PCF Integer Overflow Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-10
Some vulnerabilities have been reported in NX Server, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27162/
--
[SA27156] Gentoo updates for koffice, kword, kdegraphics, and kpdf
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-10-10
Gentoo has issued updates for koffice, kword, kdegraphics, and kpdf. These fix a vulnerability, which potentially can be exploited by
malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27156/
--
[SA27146] Avaya Products nfs-utils-lib Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-09
Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27146/
--
[SA27131] PHP Homepage M "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-10-09
[PHCN] Mahjong has discovered a vulnerability in PHP Homepage M, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27131/
--
[SA27129] OpenH323 opal Session Initiation Protocol Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-08
A vulnerability has been reported in OpenH323 opal, which can potentially be exploited by malicious people to compromise an
application using the library.
Full Advisory:
http://secunia.com/advisories/27129/
--
[SA27128] Ekiga opal Session Initiation Protocol Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-08
A vulnerability has been reported in Ekiga, which can potentially be exploited by malicious people to compromise an vulnerable system.
Full Advisory:
http://secunia.com/advisories/27128/
--
[SA27124] Nagios Plugins Long Location Header Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-10-08
Nobuhiro Ban has reported a vulnerability in Nagios Plugins, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27124/
--
[SA27118] Red Hat update for opal
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-08
Red Hat has issued an update for opal. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27118/
--
[SA27113] Verlihub Control Panel "page" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information
Released: 2007-10-09
Methodman has reported a vulnerability in Verlihub Control Panel, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27113/
--
[SA27110] Fedora update for php
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass
Released: 2007-10-08
Fedora has issued an update for php. This fixes some vulnerabilities, where some have unknown impacts and others can be exploited by malicious users to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27110/
--
[SA27102] Gentoo update for php
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass, Exposure of sensitive
information, Privilege escalation, DoS, System access
Released: 2007-10-08
Gentoo has issued an update for php. This fixes some security issues and vulnerabilities, where some have unknown impacts and others can be exploited by malicious, local users to bypass certain security restrictions, by malicious users to bypass certain security
restrictions, gain escalated privileges, and cause a DoS (Denial of Service), and by malicious people to expose potentially sensitive
information, cause a DoS, and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27102/
--
[SA27100] Gentoo update for libsndfile
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-10-08
Gentoo has issued an update for libsndfile. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27100/
--
[SA27099] Gentoo update for libvorbis
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-08
Gentoo has issued an update for libvorbis. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) and potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27099/
--
[SA27086] Gentoo update for tk
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-08
Gentoo has issued an update for tk. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an
application using the library.
Full Advisory:
http://secunia.com/advisories/27086/
--
[SA27071] Ubuntu update for libsndfile
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-10-05
Ubuntu has issued an update for libsndfile. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27071/
--
[SA27176] Sun Solaris X Font Server Multiple Vulnerabilities
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-10-11
Sun has acknowledged some vulnerabilities in Sun Solaris, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27176/
--
[SA27160] OpenBSD dhcpd Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-10-10
A vulnerability has been reported in OpenBSD, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27160/
--
[SA27150] Red Hat update for pwlib
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-09
Red Hat has issued an update for pwlib. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27150/
--
[SA27119] Minki "page" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-08
r0t has discovered a vulnerability in Minki, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27119/
--
[SA27108] Red Hat update for kdelibs
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Spoofing
Released: 2007-10-08
Red Hat has issued an update for kdelibs. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting and spoofing attacks.
Full Advisory:
http://secunia.com/advisories/27108/
--
[SA27106] Red Hat update for kdebase
Critical: Less critical
Where: From remote
Impact: Security Bypass, Spoofing
Released: 2007-10-08
Red Hat has issued an update for kdebase. This fixes a security issue and some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions and by malicious people to conduct spoofing attacks.
Full Advisory:
http://secunia.com/advisories/27106/
--
[SA27096] Fedora update for kdebase
Critical: Less critical
Where: From remote
Impact: Security Bypass, Spoofing
Released: 2007-10-09
Fedora has issued an update for kdebase. This fixes a security issue and some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions and by malicious people to conduct spoofing attacks.
Full Advisory:
http://secunia.com/advisories/27096/
--
[SA27090] Fedora update for kdelibs
Critical: Less critical
Where: From remote
Impact: Spoofing
Released: 2007-10-09
Fedora has issued an update for kdelibs. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
spoofing attacks.
Full Advisory:
http://secunia.com/advisories/27090/
--
[SA27155] Ubuntu update for mysql
Critical: Less critical
Where: From local network
Impact: Security Bypass, Privilege escalation, DoS
Released: 2007-10-11
Ubuntu has issued an update for mysql. This fixes some vulnerabilities and security issues, which can be exploited by malicious users to gain escalated privileges, bypass certain security restrictions and cause a DoS (Denial of Service) or malicious people to cause a DoS.
Full Advisory:
http://secunia.com/advisories/27155/
--
[SA27132] Fedora update for elinks
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2007-10-09
Fedora has issued an update for elinks. This fixes a weakness, which can be exploited by malicious people to disclose sensitive
information.
Full Advisory:
http://secunia.com/advisories/27132/
--
[SA27125] rPath update for elinks
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2007-10-08
rPath has issued an update for elinks. This fixes a weakness, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27125/
--
[SA27168] Debian update for xfs
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-10
Debian has issued an update for xfs. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated
privileges.
Full Advisory:
http://secunia.com/advisories/27168/
--
[SA27161] Ubuntu update for xen
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-10
Ubuntu has issued an update for xen. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated
privileges.
Full Advisory:
http://secunia.com/advisories/27161/
--
[SA27147] Avaya Products X.org X11 Composite Pixmap Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-09
Avaya has acknowledged a vulnerability in various Avaya products, which potentially can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27147/
--
[SA27141] rPath update for xen
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-09
rPath has issued an update for xen. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated
privileges.
Full Advisory:
http://secunia.com/advisories/27141/
--
[SA27111] ldapscripts Command Line User Credentials Disclosure
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2007-10-09
A security issue has been reported in ldapscripts, which can be exploited by malicious, local users to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27111/
--
[SA27103] Fedora update for xen
Critical: Less critical
Where: Local system
Impact: Security Bypass, Privilege escalation
Released: 2007-10-09
Fedora has issued an update for xen. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain
security restrictions or gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27103/
--
[SA27085] Debian update for xen-utils
Critical: Less critical
Where: Local system
Impact: Security Bypass, Privilege escalation
Released: 2007-10-08
Debian has issued an update for xen-utils. This fixes some vulnerabilities, which can be exploited by malicious, local users to
bypass certain security restrictions or gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27085/
--
[SA27079] Ubuntu update for debian-goodies
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-05
Ubuntu has issued an update for debian-goodies. This fixes a vulnerability, which can be exploited by malicious, local users to
perform actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27079/
--
[SA27076] guilt Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-05
Some vulnerabilities have been reported in guilt, which can be exploited by malicious, local users to perform certain actions with
escalated privileges.
Full Advisory:
http://secunia.com/advisories/27076/
--
[SA27072] Fedora update for xen
Critical: Less critical
Where: Local system
Impact: Security Bypass, Privilege escalation
Released: 2007-10-05
Fedora has issued an update for xen. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain
security restrictions and gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27072/
--
[SA27088] Fedora update for pidgin
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2007-10-05
Fedora has issued an update for pidgin. This fixes a weakness, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
http://secunia.com/advisories/27088/
--
[SA27101] Fedora update for kernel
Critical: Not critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2007-10-09
Fedora has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious, local users to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27101/
--
[SA27188] Fedora update for util-linux
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-11
Fedora has issued an update for util-linux. This fixes a vulnerability, which potentially can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27188/
--
[SA27154] Sun Solaris Virtual File System (VFS) Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-10-10
Sun has acknowledged a vulnerability in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).
Full Advisory:
http://secunia.com/advisories/27154/
--
[SA27152] Sun Solaris Trusted Extensions "labeld" Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-10-10
Sun has acknowledged two vulnerabilities in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).
Full Advisory:
http://secunia.com/advisories/27152/
--
[SA27135] Sun Solaris vuidmice Streams Modules Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-10-09
A security issue has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).
Full Advisory:
http://secunia.com/advisories/27135/
--
[SA27104] rPath update for util-linux
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-09
rPath has issued an update for util-linux. This fixes a vulnerability, which potentially can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27104/
--
[SA27098] Gentoo update for qgit
Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation
Released: 2007-10-08
Gentoo has issued an update for qgit. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated
privileges.
Full Advisory:
http://secunia.com/advisories/27098/
--
[SA27089] Fedora update for kdebase
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2007-10-05
Fedora has issued an update for kdebase. This fixes a security issue, which can be exploited by malicious, local users to bypass certain
security restrictions.
Full Advisory:
http://secunia.com/advisories/27089/
Other:--
[SA27084] OpenVMS Denial of Service Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-05
Some vulnerabilities have been reported in OpenVMS, which can be exploited by malicious, local users and by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27084/
--
[SA27169] Cisco IOS Line Printer Daemon Buffer Overflow Vulnerability
Critical: Not critical
Where: From local network
Impact: DoS, System access
Released: 2007-10-11
Andy Davis has reported a vulnerability in Cisco IOS, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27169/
--
[SA27175] Sun Solaris 10 BSM Network Auditing Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-10-11
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).
Full Advisory:
http://secunia.com/advisories/27175/
Cross Platform:--
[SA27174] Knowledgeroot Knowledgebase FCKEditor PHP File Upload Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-11
A vulnerability has been reported in Knowledgeroot Knowledgebase, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27174/
--
[SA27172] NuSEO.PHP "nuseo_dir" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information, System access
Released: 2007-10-11
BiNgZa has discovered a vulnerability in NuSEO.PHP, which can be exploited by malicious people to disclose sensitive information or to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27172/
--
[SA27140] xKiosk WEB "PEARPATH" Remote File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-09
BorN To K!LL has reported a vulnerability in xKiosk WEB, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27140/
--
[SA27123] FCKEditor PHP File Upload Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-11
Janek Vind has reported a vulnerability in FCKEditor, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27123/
--
[SA27199] ViArt Shop iDEAL Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information
Released: 2007-10-11
A vulnerability has been reported in ViArt Shop, which can be exploited by malicious people to gain knowledge of sensitive and system
information.
Full Advisory:
http://secunia.com/advisories/27199/
--
[SA27159] LedgerSMB Multiple SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-10-10
Some vulnerabilities have been reported in LedgerSMB, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27159/
--
[SA27142] TYPOlight webCMS "preview.php" Arbitrary File Download
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information
Released: 2007-10-09
Stephan Munz has reported a vulnerability in TYPOlight webCMS, which can be exploited by malicious people to disclose sensitive
information.
Full Advisory:
http://secunia.com/advisories/27142/
--
[SA27138] Softbiz Jobs and Recruitment Script "cid" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-10-09
IRCRASH has reported a vulnerability in Softbiz Jobs and Recruitment Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27138/
--
[SA27137] Wesnoth UTF-8 Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-10
A vulnerability has been reported in Wesnoth, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27137/
--
[SA27114] SkaDate "view_mode" Directory Traversal Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information
Released: 2007-10-08
SnIpEr_SA has reported a vulnerability in SkaDate, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27114/
--
[SA27109] TorrentTrader Cross-Site Scripting and Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information,
Exposure of sensitive information
Released: 2007-10-09
HACKERS PAL has discovered some vulnerabilities in TorrentTrader, which can be exploited by malicious people to conduct cross-site scripting attacks or to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27109/
--
[SA27107] DropTeam Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2007-10-08
Luigi Auriemma has reported some vulnerabilities in DropTeam, which can be exploited by malicious people to disclose sensitive information or to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27107/
--
[SA27091] wzdftpd "do_login_loop()" Off-By-One Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-08
k1tk4t has discovered a vulnerability in wzdftpd, which can be exploited by malicious people to cause a DoS (Denial of Service) or
potentially to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27091/
--
[SA27083] The Dawn of Time HTTP Authentication Format String Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-08
Luigi Auriemma has reported a vulnerability in The Dawn of Time, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27083/
--
[SA27194] Interspire ActiveKB NX "page" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-11
durito has reported a vulnerability in ActiveKB NX, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27194/
--
[SA27173] phpMyAdmin "setup.php" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-11
Omer Singer has reported a vulnerability in phpMyAdmin, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27173/
--
[SA27163] DNews dnewsweb Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-10
Doz has discovered two vulnerabilities in DNews, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27163/
--
[SA27130] libpng ICC Profile Chunk Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-08
A vulnerability has been reported in libpng, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27130/
--
[SA27127] PWLib "PString::vsprintf()" Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-09
A vulnerability has been discovered in PWLib, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27127/
--
[SA27093] libpng Multiple Denial of Service Vulnerabilities
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-08
Some vulnerabilities have been reported in libpng, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27093/
--
[SA27073] MailBee WebMail Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-09
Ivan Javier Sanchez has reported some vulnerabilities in MailBee WebMail, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27073/
--
[SA27074] Hitachi Cosminexus Agent Unspecified Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-10-05
A vulnerability has been reported in Hitachi Cosminexus Agent, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
http://secunia.com/advisories/27074/
--
[SA27145] util-linux Privilege Escalation Vulnerability
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-09
A vulnerability has been reported in util-linux, which potentially can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27145/
--
[SA27121] WebSphere Application Server for z/OS HTTP Server Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-10-09
IBM has acknowledged a vulnerability in WebSphere Application Server for z/OS, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27121/
Last edited by Tami on Thu Oct 11, 2007 3:32 pm, edited 1 time in total.

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Secunia 2007 Bulletins
Weekly Secunia Update for October 18 2007
Windows:--
[SA27242] Live for Speed Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-15
Luigi Auriemma has reported a vulnerability in Live for Speed, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27242/
--
[SA27223] Winamp FLAC Media File Processing Integer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-12
Some vulnerabilities have been reported in Winamp, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27223/
--
[SA27287] Miranda Multiple Buffer Overflow Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-18
Some vulnerabilities have been reported in Miranda, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27287/
--
[SA27268] Okul Otomasyon Portal "id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-17
dumenci has reported a vulnerability in Okul Otomasyon Portal, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27268/
--
[SA27214] Cisco Products Unspecified Unauthorized Access Vulnerability
Critical: Less critical
Where: From local network
Impact: Security Bypass, Manipulation of data, Exposure of
sensitive information
Released: 2007-10-18
A vulnerability has been reported in Cisco products, which can be exploited by malicious users to bypass certain security restrictions, disclose certain sensitive information, and manipulate certain data.
Full Advisory:
http://secunia.com/advisories/27214/
UNIX/Linux:--
[SA27261] SUSE update for Sun Java
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of system
information, Exposure of sensitive information, System access
Released: 2007-10-18
SUSE has issued an update for Sun Java. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, manipulate data, disclose sensitive/system information, or potentially compromise a vulnerable
system.
Full Advisory:
http://secunia.com/advisories/27261/
--
[SA27229] SUSE Update for Multiple Packages
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Spoofing, Privilege escalation, DoS,
System access
Released: 2007-10-15
SUSE has issued updates for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions or gain escalated privileges, and by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27229/
--
[SA27220] eXtremail Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-16
mu-b has reported multiple vulnerabilities in eXtremail, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27220/
--
[SA27217] Fedora update for openssl
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-16
Fedora has issued an update for openssl. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27217/
--
[SA27216] Sun Solaris update for mozilla
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-12
Sun Solaris has issued an update for mozilla. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27216/
--
[SA27206] Red Hat update for java
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of system
information, Exposure of sensitive information, System access
Released: 2007-10-12
Red Hat has issued an update for java. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, manipulate data, disclose sensitive and system information, or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27206/
--
[SA27205] Red Hat update for openssl
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-12
Red Hat has issued an update for openssl. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27205/
--
[SA27203] Red Hat update for java-1.5.0-bea
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, DoS, System access
Released: 2007-10-16
Red Hat has issued an update for java-1.5.0-bea. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting attacks, cause a DoS (Denial of Service), or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27203/
--
[SA27281] Avaya Products CUPS "StreamPredictor" Multiple
Vulnerabilities
Critical: Highly critical
Where: From local network
Impact: System access
Released: 2007-10-17
Avaya has acknowledged some vulnerabilities in various Avaya products, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27281/
--
[SA27296] Cisco Unified Communications Manager Two Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-18
Two vulnerabilities have been reported in Cisco Unified Communications Manager (CUCM), which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27296/
--
[SA27278] Asterisk-Addons "cdr_addon_mysql" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-17
A vulnerability has been reported in Asterisk-Addons, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27278/
--
[SA27254] Gentoo update for denyhosts
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-15
Gentoo has issued an update for denyhosts. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27254/
--
[SA27241] Debian update for wesnoth
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-15
Debian has issued an update for wesnoth. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27241/
--
[SA27237] Avaya Products Cyrus SASL DIGEST-MD5 Pre-Authentication
Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-17
Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27237/
--
[SA27227] SUSE update for kernel
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, Privilege escalation,
DoS
Released: 2007-10-15
SUSE has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to
disclose potential sensitive information, gain escalated privileges, and cause a DoS (Denial of Service) and by malicious people to cause a DoS.
Full Advisory:
http://secunia.com/advisories/27227/
--
[SA27222] Sun Solaris libtiff Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-12
Sun has acknowledged some vulnerabilities in Sun Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27222/
--
[SA27218] Fedora update for wesnoth
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-12
Fedora has issued an update for wesnoth. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27218/
--
[SA27212] Mandriva update for kernel
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Privilege escalation, DoS
Released: 2007-10-16
Mandriva has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, cause a DoS (Denial of Service), or gain escalated privileges, and by malicious people to cause a DoS.
Full Advisory:
http://secunia.com/advisories/27212/
--
[SA27207] Ubuntu update for tk
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-12
Ubuntu has issued an update for tk. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27207/
--
[SA27275] Avaya Products Qt Overlong UTF-8 Sequence Cross-Site
Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-17
Avaya has acknowledged a vulnerability in various Avaya products, which potentially can be exploited to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27275/
--
[SA27272] Gentoo update for balsa
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-17
Gentoo has issued an update for balsa. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27272/
--
[SA27267] HP Tru64 Internet Express update for Apache Tomcat
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information
Released: 2007-10-17
HP has issued an update for Apache Tomcat. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information or conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27267/
--
[SA27262] DCC SOCKS Denial Of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-16
A vulnerability has been reported in DCC, which can potentially be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27262/
--
[SA27253] Gentoo update for ampache
Critical: Less critical
Where: From remote
Impact: Hijacking, Manipulation of data
Released: 2007-10-15
Gentoo has issued an update for ampache. This fixes some vulnerabilities, which can be exploited by malicious users to conduct SQL injection attacks and by malicious people to conduct session fixation attacks.
Full Advisory:
http://secunia.com/advisories/27253/
--
[SA27239] Gentoo update for t1lib
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-15
Gentoo has issued an update for t1lib. This fixes a vulnerability, which can be exploited by malicious users to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27239/
--
[SA27209] HP-UX update for Apache
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-12
HP has issued an update for Apache. This fixes some vulnerabilities, which can be exploited by malicious, local users and malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27209/
--
[SA27204] OpenSER Authentication Header Hijacking Security Issue
Critical: Less critical
Where: From local network
Impact: Hijacking
Released: 2007-10-15
A security issue has been reported in OpenSER, which can be exploited by malicious people to hijack user sessions.
Full Advisory:
http://secunia.com/advisories/27204/
--
[SA27247] Gentoo update for skktools
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-15
Gentoo has issued an update for skktools. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27247/
--
[SA27244] Tramp Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-15
Stefan Monnier has reported a vulnerability in Tramp, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27244/
--
[SA27240] Gentoo update for xfs
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-15
Gentoo has issued an update for xfs. This fixes some vulnerabilities, which can be exploited by malicious, local users to perform certain actions with escalated privileges or gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27240/
--
[SA27232] Fedora update for hplip
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-15
Fedora has issued an update for hplip. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27232/
--
[SA27228] SUSE update for XOrg
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-15
SUSE has issued an update for XOrg. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27228/
--
[SA27221] Ubuntu update for hplip
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-15
Ubuntu has issued an update for hplip. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27221/
--
[SA27202] HPLIP hpssd Command Injection Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-12
Kees Cook has reported a vulnerability in HPLIB, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27202/
--
[SA27235] Fedora update for openssh
Critical: Not critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-16
Fedora has issued an update for openssh. This fixes a vulnerability, which can be exploited by malicious people to inject certain data.
Full Advisory:
http://secunia.com/advisories/27235/
--
[SA27265] HP-UX update for OpenSSL
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-10-17
HP has issued an update for OpenSSL. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27265/
--
[SA27224] Red Hat update for hplib
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-12
Red Hat has issued an update for hplib. This fixes a vulnerability, which potentially can be exploited by malicious, local users to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27224/
--
[SA27215] rPath initscripts Incorrect /var/log/btmp Permissions
Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2007-10-12
rPath has acknowledged a security issue in initscripts, which potentially can be exploited by malicious, local users to disclose
sensitive information.
Full Advisory:
http://secunia.com/advisories/27215/
Other:--
[SA27213] Apple iPod touch / iPhone TIFF Image Processing Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-12
A vulnerability has been reported in Apple iPod touch and Apple iPhone, which potentially can be exploited by malicious people to compromise a vulnerable device.
Full Advisory:
http://secunia.com/advisories/27213/
--
[SA27236] Cisco FWSM HTTPS/MGCP Packet Processing Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-18
Cisco has acknowledged some vulnerabilities in Cisco Firewall Services Module (FWSM), which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27236/
--
[SA27252] Nortel IP Softphone 2050 Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-10-18
A vulnerability has been reported in Nortel IP Softphone 2050, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27252/
--
[SA27274] Sun Solaris bzip2 Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Privilege escalation, DoS
Released: 2007-10-17
Sun has acknowledged a vulnerability in Sun Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27274/
--
[SA27238] Netgear SSL312 "err" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-18
SkyOut has reported a vulnerability in Netgear SSL312, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27238/
--
[SA27282] Nortel CS1000 Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-10-18
A vulnerability has been reported in Nortel CS1000, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27282/
--
[SA27234] Nortel Products Multiple Vulnerabilities
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information, DoS
Released: 2007-10-18
Some vulnerabilities have been reported in various Nortel products, which can be exploited by malicious people to cause a DoS (Denial of Service) and to eavesdrop with affected devices.
Full Advisory:
http://secunia.com/advisories/27234/
--
[SA27231] Cisco CallManager Authentication Header Hijacking Security
Issue
Critical: Less critical
Where: From local network
Impact: Hijacking
Released: 2007-10-18
A security issue has been reported in Cisco CallManager, which can be exploited by malicious people to hijack user sessions.
Full Advisory:
http://secunia.com/advisories/27231/
--
[SA27201] Sun StorageTek 3510 FC Array FTP Denial of Service
Critical: Not critical
Where: From local network
Impact: DoS
Released: 2007-10-16
Sun has acknowledged a vulnerability in Sun StorageTek 3510 FC Array, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27201/
Cross Platform:--
[SA27288] LimeSurvey "rootdir" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-18
S.W.A.T. has discovered a vulnerability in LimeSurvey, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27288/
--
[SA27277] Opera Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, System access, Unknown
Released: 2007-10-17
Some vulnerabilities have been reported in Opera, where one vulnerability has an unknown impact and others can be exploited by malicious people to conduct cross-site scripting attacks and to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27277/
--
[SA27208] PicoFlat CMS "pagina" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information, System access
Released: 2007-10-12
0in has reported a vulnerability in PicoFlat CMS, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27208/
--
[SA27269] artmedic CMS "page" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information
Released: 2007-10-17
iNs has discovered a vulnerability in artmedic CMS, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27269/
--
[SA27259] 1024 CMS Cross-Site Request Forgery Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Hijacking
Released: 2007-10-17
nights shadow has discovered a vulnerability in 1024 CMS, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
http://secunia.com/advisories/27259/
--
[SA27258] Softbiz Recipes Portal Script "sbcat_id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-15
IRCRASH has reported a vulnerability in Softbiz Recipes Portal Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27258/
--
[SA27257] PHP File Sharing System "cam" Directory Traversal
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-10-16
Jonas Thambert has discovered a vulnerability in PHP File Sharing System, which can be exploited by malicious people to conduct directory traversal attacks.
Full Advisory:
http://secunia.com/advisories/27257/
--
[SA27255] doop "page" Local File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information
Released: 2007-10-16
vladii has discovered a vulnerability in doop, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27255/
--
[SA27251] Oracle Products Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Manipulation of data, Exposure of sensitive
information, DoS
Released: 2007-10-17
Multiple vulnerabilities have been reported for various Oracle products. Some have unknown impacts, others can be exploited to disclose sensitive information, conduct SQL injection attacks, or to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27251/
--
[SA27250] VirtueMart Unspecified PHP Code Execution
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-10-16
A vulnerability has been reported in VirtueMart, which can be exploited by malicious users to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27250/
--
[SA27249] IBM WebSphere Application Server Unspecified Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2007-10-15
A vulnerability with an unknown impact has been reported in IBM WebSphere Application Server.
Full Advisory:
http://secunia.com/advisories/27249/
--
[SA27230] RunCms newbb_plus Unspecified Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2007-10-17
A vulnerability with an unknown impact has been reported in RunCms.
Full Advisory:
http://secunia.com/advisories/27230/
--
[SA27219] KwsPHP "newsletter" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-12
S4mi has discovered a vulnerability in KwsPHP, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27219/
--
[SA27211] HP Select Identity Unspecified Unauthorized Access Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2007-10-12
A vulnerability has been reported in HP Select Identity, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27211/
--
[SA27210] FLAC Media File Processing Integer Overflow Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-10-12
Some vulnerabilities have been reported in FLAC, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27210/
--
[SA27293] vbDrupal Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, System access
Released: 2007-10-18
Some vulnerabilities have been reported in vbDrupal, which can be exploited by malicious users to conduct HTTP response splitting attacks, and by malicious people to conduct cross-site scripting and cross-site request forgery attacks, bypass certain security restrictions, and compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27293/
--
[SA27292] Drupal Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2007-10-18
Some vulnerabilities have been reported in Drupal, which can be exploited by malicious people to conduct cross-site scripting attacks and bypass certain security restrictions, and by malicious users to conduct HTTP response splitting attacks.
Full Advisory:
http://secunia.com/advisories/27292/
--
[SA27290] Drupal Code Execution and Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2007-10-18
Some vulnerabilities have been reported in Drupal, which can be exploited by malicious people to conduct cross-site request forgery attacks and to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27290/
--
[SA27289] Drupal Web Links Module Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-18
Brandon Bergren has reported a vulnerability in the Web Links module for Drupal, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27289/
--
[SA27264] Simple PHP Blog Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-18
Demential has discovered a vulnerability in Simple PHP Blog, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
http://secunia.com/advisories/27264/
--
[SA27263] mnoGoSearch Default Template "t" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-18
A vulnerability has been reported in mnoGoSearch, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27263/
--
[SA27246] phpMyAdmin "server_status.php" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-18
Omer Singer has discovered a vulnerability in phpMyAdmin, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27246/
--
[SA27245] WebMod "auth.w" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-16
Nemessis has reported a vulnerability in WebMod, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27245/
--
[SA27225] InnovaPortal Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-18
Jose Luis Góngora Fernández has reported some vulnerabilities in InnovaPortal, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27225/
Windows:--
[SA27242] Live for Speed Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-15
Luigi Auriemma has reported a vulnerability in Live for Speed, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27242/
--
[SA27223] Winamp FLAC Media File Processing Integer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-12
Some vulnerabilities have been reported in Winamp, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27223/
--
[SA27287] Miranda Multiple Buffer Overflow Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-18
Some vulnerabilities have been reported in Miranda, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27287/
--
[SA27268] Okul Otomasyon Portal "id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-17
dumenci has reported a vulnerability in Okul Otomasyon Portal, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27268/
--
[SA27214] Cisco Products Unspecified Unauthorized Access Vulnerability
Critical: Less critical
Where: From local network
Impact: Security Bypass, Manipulation of data, Exposure of
sensitive information
Released: 2007-10-18
A vulnerability has been reported in Cisco products, which can be exploited by malicious users to bypass certain security restrictions, disclose certain sensitive information, and manipulate certain data.
Full Advisory:
http://secunia.com/advisories/27214/
UNIX/Linux:--
[SA27261] SUSE update for Sun Java
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of system
information, Exposure of sensitive information, System access
Released: 2007-10-18
SUSE has issued an update for Sun Java. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, manipulate data, disclose sensitive/system information, or potentially compromise a vulnerable
system.
Full Advisory:
http://secunia.com/advisories/27261/
--
[SA27229] SUSE Update for Multiple Packages
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Spoofing, Privilege escalation, DoS,
System access
Released: 2007-10-15
SUSE has issued updates for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions or gain escalated privileges, and by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27229/
--
[SA27220] eXtremail Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-16
mu-b has reported multiple vulnerabilities in eXtremail, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27220/
--
[SA27217] Fedora update for openssl
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-16
Fedora has issued an update for openssl. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27217/
--
[SA27216] Sun Solaris update for mozilla
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-12
Sun Solaris has issued an update for mozilla. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27216/
--
[SA27206] Red Hat update for java
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of system
information, Exposure of sensitive information, System access
Released: 2007-10-12
Red Hat has issued an update for java. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, manipulate data, disclose sensitive and system information, or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27206/
--
[SA27205] Red Hat update for openssl
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-12
Red Hat has issued an update for openssl. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27205/
--
[SA27203] Red Hat update for java-1.5.0-bea
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, DoS, System access
Released: 2007-10-16
Red Hat has issued an update for java-1.5.0-bea. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting attacks, cause a DoS (Denial of Service), or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27203/
--
[SA27281] Avaya Products CUPS "StreamPredictor" Multiple
Vulnerabilities
Critical: Highly critical
Where: From local network
Impact: System access
Released: 2007-10-17
Avaya has acknowledged some vulnerabilities in various Avaya products, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27281/
--
[SA27296] Cisco Unified Communications Manager Two Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-18
Two vulnerabilities have been reported in Cisco Unified Communications Manager (CUCM), which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27296/
--
[SA27278] Asterisk-Addons "cdr_addon_mysql" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-17
A vulnerability has been reported in Asterisk-Addons, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27278/
--
[SA27254] Gentoo update for denyhosts
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-15
Gentoo has issued an update for denyhosts. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27254/
--
[SA27241] Debian update for wesnoth
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-15
Debian has issued an update for wesnoth. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27241/
--
[SA27237] Avaya Products Cyrus SASL DIGEST-MD5 Pre-Authentication
Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-17
Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27237/
--
[SA27227] SUSE update for kernel
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, Privilege escalation,
DoS
Released: 2007-10-15
SUSE has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to
disclose potential sensitive information, gain escalated privileges, and cause a DoS (Denial of Service) and by malicious people to cause a DoS.
Full Advisory:
http://secunia.com/advisories/27227/
--
[SA27222] Sun Solaris libtiff Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-12
Sun has acknowledged some vulnerabilities in Sun Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27222/
--
[SA27218] Fedora update for wesnoth
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-12
Fedora has issued an update for wesnoth. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27218/
--
[SA27212] Mandriva update for kernel
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Privilege escalation, DoS
Released: 2007-10-16
Mandriva has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, cause a DoS (Denial of Service), or gain escalated privileges, and by malicious people to cause a DoS.
Full Advisory:
http://secunia.com/advisories/27212/
--
[SA27207] Ubuntu update for tk
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-12
Ubuntu has issued an update for tk. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27207/
--
[SA27275] Avaya Products Qt Overlong UTF-8 Sequence Cross-Site
Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-17
Avaya has acknowledged a vulnerability in various Avaya products, which potentially can be exploited to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27275/
--
[SA27272] Gentoo update for balsa
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-17
Gentoo has issued an update for balsa. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27272/
--
[SA27267] HP Tru64 Internet Express update for Apache Tomcat
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information
Released: 2007-10-17
HP has issued an update for Apache Tomcat. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information or conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27267/
--
[SA27262] DCC SOCKS Denial Of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-16
A vulnerability has been reported in DCC, which can potentially be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27262/
--
[SA27253] Gentoo update for ampache
Critical: Less critical
Where: From remote
Impact: Hijacking, Manipulation of data
Released: 2007-10-15
Gentoo has issued an update for ampache. This fixes some vulnerabilities, which can be exploited by malicious users to conduct SQL injection attacks and by malicious people to conduct session fixation attacks.
Full Advisory:
http://secunia.com/advisories/27253/
--
[SA27239] Gentoo update for t1lib
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-15
Gentoo has issued an update for t1lib. This fixes a vulnerability, which can be exploited by malicious users to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27239/
--
[SA27209] HP-UX update for Apache
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-12
HP has issued an update for Apache. This fixes some vulnerabilities, which can be exploited by malicious, local users and malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27209/
--
[SA27204] OpenSER Authentication Header Hijacking Security Issue
Critical: Less critical
Where: From local network
Impact: Hijacking
Released: 2007-10-15
A security issue has been reported in OpenSER, which can be exploited by malicious people to hijack user sessions.
Full Advisory:
http://secunia.com/advisories/27204/
--
[SA27247] Gentoo update for skktools
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-15
Gentoo has issued an update for skktools. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27247/
--
[SA27244] Tramp Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-15
Stefan Monnier has reported a vulnerability in Tramp, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27244/
--
[SA27240] Gentoo update for xfs
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-15
Gentoo has issued an update for xfs. This fixes some vulnerabilities, which can be exploited by malicious, local users to perform certain actions with escalated privileges or gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27240/
--
[SA27232] Fedora update for hplip
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-15
Fedora has issued an update for hplip. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27232/
--
[SA27228] SUSE update for XOrg
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-15
SUSE has issued an update for XOrg. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27228/
--
[SA27221] Ubuntu update for hplip
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-15
Ubuntu has issued an update for hplip. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27221/
--
[SA27202] HPLIP hpssd Command Injection Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-12
Kees Cook has reported a vulnerability in HPLIB, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27202/
--
[SA27235] Fedora update for openssh
Critical: Not critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-16
Fedora has issued an update for openssh. This fixes a vulnerability, which can be exploited by malicious people to inject certain data.
Full Advisory:
http://secunia.com/advisories/27235/
--
[SA27265] HP-UX update for OpenSSL
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-10-17
HP has issued an update for OpenSSL. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27265/
--
[SA27224] Red Hat update for hplib
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-12
Red Hat has issued an update for hplib. This fixes a vulnerability, which potentially can be exploited by malicious, local users to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27224/
--
[SA27215] rPath initscripts Incorrect /var/log/btmp Permissions
Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2007-10-12
rPath has acknowledged a security issue in initscripts, which potentially can be exploited by malicious, local users to disclose
sensitive information.
Full Advisory:
http://secunia.com/advisories/27215/
Other:--
[SA27213] Apple iPod touch / iPhone TIFF Image Processing Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-12
A vulnerability has been reported in Apple iPod touch and Apple iPhone, which potentially can be exploited by malicious people to compromise a vulnerable device.
Full Advisory:
http://secunia.com/advisories/27213/
--
[SA27236] Cisco FWSM HTTPS/MGCP Packet Processing Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-18
Cisco has acknowledged some vulnerabilities in Cisco Firewall Services Module (FWSM), which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27236/
--
[SA27252] Nortel IP Softphone 2050 Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-10-18
A vulnerability has been reported in Nortel IP Softphone 2050, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27252/
--
[SA27274] Sun Solaris bzip2 Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Privilege escalation, DoS
Released: 2007-10-17
Sun has acknowledged a vulnerability in Sun Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27274/
--
[SA27238] Netgear SSL312 "err" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-18
SkyOut has reported a vulnerability in Netgear SSL312, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27238/
--
[SA27282] Nortel CS1000 Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-10-18
A vulnerability has been reported in Nortel CS1000, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27282/
--
[SA27234] Nortel Products Multiple Vulnerabilities
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information, DoS
Released: 2007-10-18
Some vulnerabilities have been reported in various Nortel products, which can be exploited by malicious people to cause a DoS (Denial of Service) and to eavesdrop with affected devices.
Full Advisory:
http://secunia.com/advisories/27234/
--
[SA27231] Cisco CallManager Authentication Header Hijacking Security
Issue
Critical: Less critical
Where: From local network
Impact: Hijacking
Released: 2007-10-18
A security issue has been reported in Cisco CallManager, which can be exploited by malicious people to hijack user sessions.
Full Advisory:
http://secunia.com/advisories/27231/
--
[SA27201] Sun StorageTek 3510 FC Array FTP Denial of Service
Critical: Not critical
Where: From local network
Impact: DoS
Released: 2007-10-16
Sun has acknowledged a vulnerability in Sun StorageTek 3510 FC Array, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27201/
Cross Platform:--
[SA27288] LimeSurvey "rootdir" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-18
S.W.A.T. has discovered a vulnerability in LimeSurvey, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27288/
--
[SA27277] Opera Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, System access, Unknown
Released: 2007-10-17
Some vulnerabilities have been reported in Opera, where one vulnerability has an unknown impact and others can be exploited by malicious people to conduct cross-site scripting attacks and to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27277/
--
[SA27208] PicoFlat CMS "pagina" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information, System access
Released: 2007-10-12
0in has reported a vulnerability in PicoFlat CMS, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27208/
--
[SA27269] artmedic CMS "page" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information
Released: 2007-10-17
iNs has discovered a vulnerability in artmedic CMS, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27269/
--
[SA27259] 1024 CMS Cross-Site Request Forgery Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Hijacking
Released: 2007-10-17
nights shadow has discovered a vulnerability in 1024 CMS, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
http://secunia.com/advisories/27259/
--
[SA27258] Softbiz Recipes Portal Script "sbcat_id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-15
IRCRASH has reported a vulnerability in Softbiz Recipes Portal Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27258/
--
[SA27257] PHP File Sharing System "cam" Directory Traversal
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-10-16
Jonas Thambert has discovered a vulnerability in PHP File Sharing System, which can be exploited by malicious people to conduct directory traversal attacks.
Full Advisory:
http://secunia.com/advisories/27257/
--
[SA27255] doop "page" Local File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information
Released: 2007-10-16
vladii has discovered a vulnerability in doop, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27255/
--
[SA27251] Oracle Products Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Manipulation of data, Exposure of sensitive
information, DoS
Released: 2007-10-17
Multiple vulnerabilities have been reported for various Oracle products. Some have unknown impacts, others can be exploited to disclose sensitive information, conduct SQL injection attacks, or to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27251/
--
[SA27250] VirtueMart Unspecified PHP Code Execution
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-10-16
A vulnerability has been reported in VirtueMart, which can be exploited by malicious users to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27250/
--
[SA27249] IBM WebSphere Application Server Unspecified Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2007-10-15
A vulnerability with an unknown impact has been reported in IBM WebSphere Application Server.
Full Advisory:
http://secunia.com/advisories/27249/
--
[SA27230] RunCms newbb_plus Unspecified Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2007-10-17
A vulnerability with an unknown impact has been reported in RunCms.
Full Advisory:
http://secunia.com/advisories/27230/
--
[SA27219] KwsPHP "newsletter" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-12
S4mi has discovered a vulnerability in KwsPHP, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27219/
--
[SA27211] HP Select Identity Unspecified Unauthorized Access Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2007-10-12
A vulnerability has been reported in HP Select Identity, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27211/
--
[SA27210] FLAC Media File Processing Integer Overflow Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-10-12
Some vulnerabilities have been reported in FLAC, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27210/
--
[SA27293] vbDrupal Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, System access
Released: 2007-10-18
Some vulnerabilities have been reported in vbDrupal, which can be exploited by malicious users to conduct HTTP response splitting attacks, and by malicious people to conduct cross-site scripting and cross-site request forgery attacks, bypass certain security restrictions, and compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27293/
--
[SA27292] Drupal Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2007-10-18
Some vulnerabilities have been reported in Drupal, which can be exploited by malicious people to conduct cross-site scripting attacks and bypass certain security restrictions, and by malicious users to conduct HTTP response splitting attacks.
Full Advisory:
http://secunia.com/advisories/27292/
--
[SA27290] Drupal Code Execution and Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2007-10-18
Some vulnerabilities have been reported in Drupal, which can be exploited by malicious people to conduct cross-site request forgery attacks and to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27290/
--
[SA27289] Drupal Web Links Module Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-18
Brandon Bergren has reported a vulnerability in the Web Links module for Drupal, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27289/
--
[SA27264] Simple PHP Blog Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-18
Demential has discovered a vulnerability in Simple PHP Blog, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
http://secunia.com/advisories/27264/
--
[SA27263] mnoGoSearch Default Template "t" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-18
A vulnerability has been reported in mnoGoSearch, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27263/
--
[SA27246] phpMyAdmin "server_status.php" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-18
Omer Singer has discovered a vulnerability in phpMyAdmin, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27246/
--
[SA27245] WebMod "auth.w" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-16
Nemessis has reported a vulnerability in WebMod, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27245/
--
[SA27225] InnovaPortal Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-18
Jose Luis Góngora Fernández has reported some vulnerabilities in InnovaPortal, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27225/

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Secunia 2007 Bulletins
Vulnerabilities Content Listing for the week of October 25 2007
Windows:--
[SA27317] IBM Lotus Notes WordPerfect File Viewer Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-23
Tan Chew Keong has reported a vulnerability in IBM Lotus Notes, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27317/
--
[SA27304] Verity Keyview SDK Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-23
Multiple vulnerabilities have been reported in Verity Keyview SDK, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27304/
--
[SA27396] Aleris Web Publishing Server "mode" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-25
Joseph.Giron13 has reported a vulnerability in Aleris Web Publishing Server, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27396/
--
[SA27349] Mono System.Web StaticFileHandler.cs Source Code Disclosure Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-10-22
A vulnerability has been reported in Mono, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27349/
--
[SA27321] IBM Lotus Domino Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2007-10-23
Multiple vulnerabilities have been reported in IBM Lotus Domino, which can be exploited by malicious, local users to gain knowledge of sensitive information and by malicious users to bypass certain security restrictions or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27321/
--
[SA27301] CA Host-Based Intrusion Prevention System Server Script
Insertion
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-19
A vulnerability has been reported in CA Host-Based Intrusion Prevention System (CA HIPS), which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/27301/
--
[SA27368] CREApark GOLD KÖY PORTALI "aranan" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-24
GeFORC3 has reported a vulnerability in CREApark GOLD KÖY PORTALI, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27368/
--
[SA27365] WebIf "cmd" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-23
SkyOut has reported a vulnerability in WebIf, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27365/
--
[SA27339] CandyPress Store "msg" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-24
Snoop Security has reported a vulnerability in CandyPress Store, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27339/
--
[SA27337] ASP Site Search SearchSimon Lite "QUERY" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-22
Aria-Security has reported a vulnerability in ASP Site Search SearchSimon Lite, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27337/
--
[SA27342] IBM Lotus Notes Insecure Default Directory Permissions
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-24
A security issue has been discovered in IBM Lotus Notes, which can be exploited by malicious, local users to manipulate arbitrary files.
Full Advisory:
http://secunia.com/advisories/27342/
--
[SA27312] SpeedFan Speedfan.sys Privilege Escalation and Denial of
Service
Critical: Less critical
Where: Local system
Impact: Security Bypass, Privilege escalation, DoS
Released: 2007-10-19
Ruben Santamarta has reported some vulnerabilities and a weakness in SpeedFan, which can be exploited by malicious, local users to bypass certain security restrictions, cause a DoS (Denial of Service) or gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27312/
UNIX/Linux:--
[SA27393] JustSystems Ichitaro Document Processing Multiple Buffer
Overflows
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-25
Hiroshi Ukai has reported some vulnerabilities in Ichitaro, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27393/
--
[SA27387] Fedora update for firefox
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-24
Fedora has issued an update for firefox. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27387/
--
[SA27383] Ubuntu update for mozilla-thunderbird
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-24
Ubuntu has issued an update for mozilla-thunderbird. This fixes a weakness and some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, manipulate certain data, expose sensitive information, or compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27383/
--
[SA27370] Gentoo update for openoffice
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-23
Gentoo has issued an update for openoffice. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27370/
--
[SA27364] Gentoo update for imagemagick
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-25
Gentoo has issued an update for imagemagick. This fixes some vulnerabilities, which can be exploited by malicious people to conduct DoS (Denial of Service) attacks or compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27364/
--
[SA27363] Ubuntu update for OpenSSL
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-23
Ubuntu has issued an update for OpenSSL. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27363/
--
[SA27358] Fedora update for blam
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-25
Fedora has issued an update for blam. This package has been rebuilt against a new version of the firefox package. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27358/
--
[SA27356] Fedora update for seamonkey
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-24
Fedora has issued an update for seamonkey. This fixes some vulnerabilities and a weakness, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27356/
--
[SA27345] Jeebles Directory Information Disclosure and PHP Code Execution
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-10-23
Some vulnerabilities have been discovered in Jeebles Directory, which can be exploited by malicious people to disclose sensitive information and by malicious users to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27345/
--
[SA27344] Gentoo update for tikiwiki
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-22
Gentoo has issued an update for tikiwiki. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27344/
--
[SA27336] Debian update for xulrunner
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-22
Debian has issued an update for xulrunner. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27336/
--
[SA27335] Ubuntu update for firefox
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-23
Ubuntu has issued an update for firefox. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27335/
--
[SA27330] Red Hat update for openssl
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-22
Red Hat has issued an update for openssl. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27330/
--
[SA27327] Red Hat update for seamonkey
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, Manipulation of data, Exposure of sensitive information, System access
Released: 2007-10-22
Red Hat has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks, disclose sensitive information, conduct phishing attacks, manipulate certain data and compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27327/
--
[SA27326] Debian update for icedove
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-10-22
Debian has issued an update for icedove. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27326/
--
[SA27325] Red Hat update for thunderbird
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-22
Red Hat has issued an update for thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks, disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27325/
--
[SA27309] rPath update for ImageMagick
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-19
rPath has issued an update for ImageMagick. This fixes some vulnerabilities, which can be exploited by malicious people to conduct DoS (Denial of Service) attacks or compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27309/
--
[SA27308] Gentoo pdfkit and imagekits "StreamPredictor" Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-19
Gentoo has acknowledged some vulnerabilities in pdfkit and imagekits, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27308/
--
[SA27298] SUSE update for Mozilla Firefox
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-22
SUSE has issued an update for Mozilla Firefox. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27298/
--
[SA27377] rPath update for php, php-mysql and php-pgsql
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass, DoS, System access
Released: 2007-10-25
rPath has issued an update for php, php-mysql and php-pgsql. This fixes some vulnerabilities, where some have unknown impacts and others can be exploited by malicious users to bypass certain security restrictions or by malicious people to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27377/
--
[SA27366] Gentoo MLDonkey Empty "p2p" Password Security Issue
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-10-25
A security issue has been reported in Gentoo, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27366/
--
[SA27362] Ubuntu update for nagios-plugins
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-10-23
Ubuntu has issued an update for nagios-plugins. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27362/
--
[SA27357] DeleGate Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-23
Some vulnerabilities have been reported in DeleGate, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27357/
--
[SA27355] Red Hat update for flac
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-10-23
Red Hat has issued an update for flac. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27355/
--
[SA27351] Red Hat update for php
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Privilege escalation
Released: 2007-10-24
Red Hat has issued an update for php. This fixes a weakness and some vulnerabilities, which can be exploited by malicious users to bypass certain security restrictions and gain escalated privileges, and by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27351/
--
[SA27322] Red Hat update for kernel
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS
Released: 2007-10-22
Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions and to cause a DoS (Denial of Service), and by malicious people to cause a DoS.
Full Advisory:
http://secunia.com/advisories/27322/
--
[SA27305] InstaGuide Weather Free "PageName" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-10-23
BorN To K!LL has discovered a vulnerability in InstaGuide Weather Free, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27305/
--
[SA27302] LiteSpeed Web Server Script Source Code Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-10-23
Tr3mbl3r has reported a vulnerability in LiteSpeed Web Server, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27302/
--
[SA27350] Ubuntu update for dhcp
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-10-23
Ubuntu has issued an update for dhcp. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27350/
--
[SA27338] Red Hat update for dhcp
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-10-24
Red Hat has issued an update for dhcp. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27338/
--
[SA27391] Red Hat update for libpng
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-24
Red Hat has issued an update for libpng. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27391/
--
[SA27369] Fedora update for libpng and libpng10
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-24
Fedora has issued an update for libpng and libpng10. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27369/
--
[SA27352] Fedora update for drupal
Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, System access
Released: 2007-10-24
Fedora has issued an update for drupal. This fixes some vulnerabilities, which can be exploited by malicious users to conduct HTTP response splitting attacks, and by malicious people to conduct cross-site request forgery and cross-site scripting attacks, bypass certain security restrictions, and to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27352/
--
[SA27334] Debian update for reprepro
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-10-24
Debian has issued an update for reprepro. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27334/
--
[SA27319] Ubuntu update for ghostscript and gs-gpl
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-23
Ubuntu has issued an update for ghostscript and gs-gpl. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27319/
--
[SA27318] Gentoo update for star
Critical: Less critical
Where: From remote
Impact: System access
Released: 2007-10-23
Gentoo has issued an update for star. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27318/
--
[SA27316] Nagios Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-22
A vulnerability has been reported in Nagios, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27316/
--
[SA27314] Gentoo update for sleuthkit
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-19
Gentoo has issued an update for sleuthkit. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27314/
--
[SA27307] The Sleuth Kit "file" Integer Underflow Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-19
A vulnerability has been reported in The Sleuth Kit, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27307/
--
[SA27303] Debian update for zoph
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-19
Debian has issued an update for zoph. This fixes a vulnerability, which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27303/
--
[SA27297] Debian update for t1lib
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-19
Debian has issued an update for t1lib. This fixes a vulnerability, which can be exploited by malicious users to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27297/
--
[SA27397] Gentoo update for hplip
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-25
Gentoo has issued an update for hplip. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27397/
--
[SA27389] Xen "xenbaked" Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Manipulation of data
Released: 2007-10-24
Steve Kemp has reported a security issue in Xen, which can be exploited by malicious, local users to truncate arbitrary files.
Full Advisory:
http://secunia.com/advisories/27389/
--
[SA27343] Gentoo update for tramp
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-22
Gentoo has issued an update for tramp. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27343/
--
[SA27332] Mandriva update for hplip
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-23
Mandriva has issued an update for hplip. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27332/
--
[SA27374] Debian update for xfce4-terminal
Critical: Not critical
Where: From remote
Impact: Security Bypass
Released: 2007-10-24
Debian has issued an update for xfce4-terminal. This fixes a security issue, which can be exploited by malicious people to inject shell commands.
Full Advisory:
http://secunia.com/advisories/27374/
--
[SA27331] rPath update for cpio and tar
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2007-10-24
rPath has issued an update for cpio and tar. This fixes a vulnerability, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27331/
--
[SA27386] Avaya CMS / IR Sun Solaris RPC Services Library Denial of Service
Critical: Not critical
Where: From local network
Impact: DoS
Released: 2007-10-25
Avaya has acknowledged a vulnerability in Avaya CMS and IR, which can be exploited by malicious, local users and malicious users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27386/
--
[SA27392] Fedora update for xscreensaver, tempest, and rss-glx
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2007-10-24
Fedora has issued updates for xscreensaver, tempest, and rss-glx. These fix a security issue, which can be exploited by malicious people with physical access to a system to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27392/
--
[SA27381] Ubuntu update for gnome-screensaver
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2007-10-24
Ubuntu has issued an update for gnome-screensaver. This fixes a security issue, which can be exploited by malicious people with physical access to a system to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27381/
--
[SA27354] Ubuntu update for util-linux
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-23
Ubuntu has issued an update for util-linux. This fixes a vulnerability, which potentially can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27354/
--
[SA27306] Sun Solaris Kernel Statistics Retrieval Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-10-19
Sun has acknowledged some vulnerabilities in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27306/
Other:--
[SA27333] Warpzilla Enhanced Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-22
Some vulnerabilities and a weakness have been reported in Warpzilla Enhanced, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27333/
--
[SA27328] Sun Solaris Mozilla Layout Engine Unspecified Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-23
Sun has acknowledged some vulnerabilities in Sun Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27328/
--
[SA27329] Cisco Products EAP Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-10-22
A vulnerability has been reported in various Cisco products, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27329/
Cross Platform:--
[SA27385] php basic basicFramework "root" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-10-24
Alucar has reported a vulnerability in php basic basicFramework, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27385/
--
[SA27360] Netscape Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-23
Netscape has acknowledged some vulnerabilities and a weakness in Netscape Navigator, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27360/
--
[SA27347] PHP Project Management File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-10-23
Some vulnerabilities have been reported in PHP Project Management, which can be exploited by malicious people to disclose sensitive information and compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27347/
--
[SA27320] Sun JRE Applet Handling Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-23
A vulnerability has been reported in Sun JRE, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27320/
--
[SA27315] Mozilla SeaMonkey Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-19
Some vulnerabilities and a weakness have been reported in Mozilla SeaMonkey, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27315/
--
[SA27313] Mozilla Thunderbird Memory Corruption Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-19
Some vulnerabilities have been reported in Mozilla Thunderbird, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27313/
--
[SA27311] Mozilla Firefox Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-19
Some vulnerabilities and a weakness have been reported in Mozilla Firefox, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27311/
--
[SA27359] Simple PHP Blog Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of system information, Exposure of sensitive information, System access
Released: 2007-10-24
DarkFig has reported some vulnerabilities in Simple PHP Blog, which can be exploited by malicious people to bypass certain security restrictions and conduct script insertion and cross-site request forgery attacks, and by malicious users to disclose sensitive information and compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27359/
--
[SA27348] Vanilla SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-22
InATeam has reported some vulnerabilities in Vanilla, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27348/
--
[SA27346] Simple Machines Forum SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-22
Michael Brooks has reported some vulnerabilities in Simple Machines Forum, which can be exploited by malicious users and malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27346/
--
[SA27323] MultiXTpm Application Server "DebugPrint()" Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-10-23
A vulnerability has been reported in MultiXTpm Application Server, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27323/
--
[SA27398] Apache Tomcat WebDAV Arbitrary File Content Disclosure
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-10-25
eliteb0y has reported a vulnerability in Apache Tomcat, which can be exploited by malicious users to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27398/
--
[SA27390] SWAMP "username" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-25
morin.josh has reported a vulnerability in SWAMP, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27390/
--
[SA27341] HP OpenView Products httpd.tkd Unspecified Unauthorized Data Access
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-10-25
A vulnerability has been reported in HP OpenView Configuration Management (CM) Infrastructure (Radia) and Client Configuration Manager (CCM), which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27341/
--
[SA27324] SocketMail "lost_id" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-23
Ivan Sanchez and Maximiliano Soler have reported a vulnerability in SocketMail, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27324/
--
[SA27310] WWWISIS IAH Module "exprSearch" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-19
A vulnerability has been discovered in the IAH (Interface for Access of Health Information) module for WWWISIS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27310/
--
[SA27353] 3proxy FTP Proxy Module "OPEN" Command Double-Free
Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-10-24
Venustech AD-LAB has reported a vulnerability in 3proxy, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27353/
--
[SA27372] Pidgin HTML Processing Denial of Service
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2007-10-25
A weakness has been reported in Pidgin, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27372/
Windows:--
[SA27317] IBM Lotus Notes WordPerfect File Viewer Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-23
Tan Chew Keong has reported a vulnerability in IBM Lotus Notes, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27317/
--
[SA27304] Verity Keyview SDK Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-23
Multiple vulnerabilities have been reported in Verity Keyview SDK, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27304/
--
[SA27396] Aleris Web Publishing Server "mode" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-25
Joseph.Giron13 has reported a vulnerability in Aleris Web Publishing Server, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27396/
--
[SA27349] Mono System.Web StaticFileHandler.cs Source Code Disclosure Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-10-22
A vulnerability has been reported in Mono, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27349/
--
[SA27321] IBM Lotus Domino Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2007-10-23
Multiple vulnerabilities have been reported in IBM Lotus Domino, which can be exploited by malicious, local users to gain knowledge of sensitive information and by malicious users to bypass certain security restrictions or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27321/
--
[SA27301] CA Host-Based Intrusion Prevention System Server Script
Insertion
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-19
A vulnerability has been reported in CA Host-Based Intrusion Prevention System (CA HIPS), which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/27301/
--
[SA27368] CREApark GOLD KÖY PORTALI "aranan" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-24
GeFORC3 has reported a vulnerability in CREApark GOLD KÖY PORTALI, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27368/
--
[SA27365] WebIf "cmd" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-23
SkyOut has reported a vulnerability in WebIf, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27365/
--
[SA27339] CandyPress Store "msg" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-24
Snoop Security has reported a vulnerability in CandyPress Store, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27339/
--
[SA27337] ASP Site Search SearchSimon Lite "QUERY" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-22
Aria-Security has reported a vulnerability in ASP Site Search SearchSimon Lite, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27337/
--
[SA27342] IBM Lotus Notes Insecure Default Directory Permissions
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-24
A security issue has been discovered in IBM Lotus Notes, which can be exploited by malicious, local users to manipulate arbitrary files.
Full Advisory:
http://secunia.com/advisories/27342/
--
[SA27312] SpeedFan Speedfan.sys Privilege Escalation and Denial of
Service
Critical: Less critical
Where: Local system
Impact: Security Bypass, Privilege escalation, DoS
Released: 2007-10-19
Ruben Santamarta has reported some vulnerabilities and a weakness in SpeedFan, which can be exploited by malicious, local users to bypass certain security restrictions, cause a DoS (Denial of Service) or gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27312/
UNIX/Linux:--
[SA27393] JustSystems Ichitaro Document Processing Multiple Buffer
Overflows
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-25
Hiroshi Ukai has reported some vulnerabilities in Ichitaro, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27393/
--
[SA27387] Fedora update for firefox
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-24
Fedora has issued an update for firefox. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27387/
--
[SA27383] Ubuntu update for mozilla-thunderbird
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-24
Ubuntu has issued an update for mozilla-thunderbird. This fixes a weakness and some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, manipulate certain data, expose sensitive information, or compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27383/
--
[SA27370] Gentoo update for openoffice
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-23
Gentoo has issued an update for openoffice. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27370/
--
[SA27364] Gentoo update for imagemagick
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-25
Gentoo has issued an update for imagemagick. This fixes some vulnerabilities, which can be exploited by malicious people to conduct DoS (Denial of Service) attacks or compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27364/
--
[SA27363] Ubuntu update for OpenSSL
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-23
Ubuntu has issued an update for OpenSSL. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27363/
--
[SA27358] Fedora update for blam
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-25
Fedora has issued an update for blam. This package has been rebuilt against a new version of the firefox package. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27358/
--
[SA27356] Fedora update for seamonkey
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-24
Fedora has issued an update for seamonkey. This fixes some vulnerabilities and a weakness, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27356/
--
[SA27345] Jeebles Directory Information Disclosure and PHP Code Execution
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-10-23
Some vulnerabilities have been discovered in Jeebles Directory, which can be exploited by malicious people to disclose sensitive information and by malicious users to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27345/
--
[SA27344] Gentoo update for tikiwiki
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-22
Gentoo has issued an update for tikiwiki. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27344/
--
[SA27336] Debian update for xulrunner
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-22
Debian has issued an update for xulrunner. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27336/
--
[SA27335] Ubuntu update for firefox
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-23
Ubuntu has issued an update for firefox. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27335/
--
[SA27330] Red Hat update for openssl
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-22
Red Hat has issued an update for openssl. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27330/
--
[SA27327] Red Hat update for seamonkey
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, Manipulation of data, Exposure of sensitive information, System access
Released: 2007-10-22
Red Hat has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks, disclose sensitive information, conduct phishing attacks, manipulate certain data and compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27327/
--
[SA27326] Debian update for icedove
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-10-22
Debian has issued an update for icedove. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27326/
--
[SA27325] Red Hat update for thunderbird
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-22
Red Hat has issued an update for thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks, disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27325/
--
[SA27309] rPath update for ImageMagick
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-19
rPath has issued an update for ImageMagick. This fixes some vulnerabilities, which can be exploited by malicious people to conduct DoS (Denial of Service) attacks or compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27309/
--
[SA27308] Gentoo pdfkit and imagekits "StreamPredictor" Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-19
Gentoo has acknowledged some vulnerabilities in pdfkit and imagekits, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27308/
--
[SA27298] SUSE update for Mozilla Firefox
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-22
SUSE has issued an update for Mozilla Firefox. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27298/
--
[SA27377] rPath update for php, php-mysql and php-pgsql
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass, DoS, System access
Released: 2007-10-25
rPath has issued an update for php, php-mysql and php-pgsql. This fixes some vulnerabilities, where some have unknown impacts and others can be exploited by malicious users to bypass certain security restrictions or by malicious people to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27377/
--
[SA27366] Gentoo MLDonkey Empty "p2p" Password Security Issue
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-10-25
A security issue has been reported in Gentoo, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27366/
--
[SA27362] Ubuntu update for nagios-plugins
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-10-23
Ubuntu has issued an update for nagios-plugins. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27362/
--
[SA27357] DeleGate Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-23
Some vulnerabilities have been reported in DeleGate, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27357/
--
[SA27355] Red Hat update for flac
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-10-23
Red Hat has issued an update for flac. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27355/
--
[SA27351] Red Hat update for php
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Privilege escalation
Released: 2007-10-24
Red Hat has issued an update for php. This fixes a weakness and some vulnerabilities, which can be exploited by malicious users to bypass certain security restrictions and gain escalated privileges, and by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27351/
--
[SA27322] Red Hat update for kernel
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS
Released: 2007-10-22
Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions and to cause a DoS (Denial of Service), and by malicious people to cause a DoS.
Full Advisory:
http://secunia.com/advisories/27322/
--
[SA27305] InstaGuide Weather Free "PageName" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-10-23
BorN To K!LL has discovered a vulnerability in InstaGuide Weather Free, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27305/
--
[SA27302] LiteSpeed Web Server Script Source Code Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-10-23
Tr3mbl3r has reported a vulnerability in LiteSpeed Web Server, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27302/
--
[SA27350] Ubuntu update for dhcp
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-10-23
Ubuntu has issued an update for dhcp. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27350/
--
[SA27338] Red Hat update for dhcp
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-10-24
Red Hat has issued an update for dhcp. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27338/
--
[SA27391] Red Hat update for libpng
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-24
Red Hat has issued an update for libpng. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27391/
--
[SA27369] Fedora update for libpng and libpng10
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-24
Fedora has issued an update for libpng and libpng10. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27369/
--
[SA27352] Fedora update for drupal
Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, System access
Released: 2007-10-24
Fedora has issued an update for drupal. This fixes some vulnerabilities, which can be exploited by malicious users to conduct HTTP response splitting attacks, and by malicious people to conduct cross-site request forgery and cross-site scripting attacks, bypass certain security restrictions, and to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27352/
--
[SA27334] Debian update for reprepro
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-10-24
Debian has issued an update for reprepro. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27334/
--
[SA27319] Ubuntu update for ghostscript and gs-gpl
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-23
Ubuntu has issued an update for ghostscript and gs-gpl. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27319/
--
[SA27318] Gentoo update for star
Critical: Less critical
Where: From remote
Impact: System access
Released: 2007-10-23
Gentoo has issued an update for star. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27318/
--
[SA27316] Nagios Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-22
A vulnerability has been reported in Nagios, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27316/
--
[SA27314] Gentoo update for sleuthkit
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-19
Gentoo has issued an update for sleuthkit. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27314/
--
[SA27307] The Sleuth Kit "file" Integer Underflow Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-19
A vulnerability has been reported in The Sleuth Kit, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27307/
--
[SA27303] Debian update for zoph
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-19
Debian has issued an update for zoph. This fixes a vulnerability, which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27303/
--
[SA27297] Debian update for t1lib
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-19
Debian has issued an update for t1lib. This fixes a vulnerability, which can be exploited by malicious users to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27297/
--
[SA27397] Gentoo update for hplip
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-25
Gentoo has issued an update for hplip. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27397/
--
[SA27389] Xen "xenbaked" Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Manipulation of data
Released: 2007-10-24
Steve Kemp has reported a security issue in Xen, which can be exploited by malicious, local users to truncate arbitrary files.
Full Advisory:
http://secunia.com/advisories/27389/
--
[SA27343] Gentoo update for tramp
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-22
Gentoo has issued an update for tramp. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27343/
--
[SA27332] Mandriva update for hplip
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-23
Mandriva has issued an update for hplip. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27332/
--
[SA27374] Debian update for xfce4-terminal
Critical: Not critical
Where: From remote
Impact: Security Bypass
Released: 2007-10-24
Debian has issued an update for xfce4-terminal. This fixes a security issue, which can be exploited by malicious people to inject shell commands.
Full Advisory:
http://secunia.com/advisories/27374/
--
[SA27331] rPath update for cpio and tar
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2007-10-24
rPath has issued an update for cpio and tar. This fixes a vulnerability, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27331/
--
[SA27386] Avaya CMS / IR Sun Solaris RPC Services Library Denial of Service
Critical: Not critical
Where: From local network
Impact: DoS
Released: 2007-10-25
Avaya has acknowledged a vulnerability in Avaya CMS and IR, which can be exploited by malicious, local users and malicious users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27386/
--
[SA27392] Fedora update for xscreensaver, tempest, and rss-glx
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2007-10-24
Fedora has issued updates for xscreensaver, tempest, and rss-glx. These fix a security issue, which can be exploited by malicious people with physical access to a system to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27392/
--
[SA27381] Ubuntu update for gnome-screensaver
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2007-10-24
Ubuntu has issued an update for gnome-screensaver. This fixes a security issue, which can be exploited by malicious people with physical access to a system to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27381/
--
[SA27354] Ubuntu update for util-linux
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-23
Ubuntu has issued an update for util-linux. This fixes a vulnerability, which potentially can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27354/
--
[SA27306] Sun Solaris Kernel Statistics Retrieval Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-10-19
Sun has acknowledged some vulnerabilities in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27306/
Other:--
[SA27333] Warpzilla Enhanced Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-22
Some vulnerabilities and a weakness have been reported in Warpzilla Enhanced, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27333/
--
[SA27328] Sun Solaris Mozilla Layout Engine Unspecified Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-23
Sun has acknowledged some vulnerabilities in Sun Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27328/
--
[SA27329] Cisco Products EAP Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-10-22
A vulnerability has been reported in various Cisco products, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27329/
Cross Platform:--
[SA27385] php basic basicFramework "root" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-10-24
Alucar has reported a vulnerability in php basic basicFramework, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27385/
--
[SA27360] Netscape Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-23
Netscape has acknowledged some vulnerabilities and a weakness in Netscape Navigator, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27360/
--
[SA27347] PHP Project Management File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-10-23
Some vulnerabilities have been reported in PHP Project Management, which can be exploited by malicious people to disclose sensitive information and compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27347/
--
[SA27320] Sun JRE Applet Handling Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-23
A vulnerability has been reported in Sun JRE, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27320/
--
[SA27315] Mozilla SeaMonkey Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-19
Some vulnerabilities and a weakness have been reported in Mozilla SeaMonkey, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27315/
--
[SA27313] Mozilla Thunderbird Memory Corruption Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-19
Some vulnerabilities have been reported in Mozilla Thunderbird, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27313/
--
[SA27311] Mozilla Firefox Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-19
Some vulnerabilities and a weakness have been reported in Mozilla Firefox, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27311/
--
[SA27359] Simple PHP Blog Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of system information, Exposure of sensitive information, System access
Released: 2007-10-24
DarkFig has reported some vulnerabilities in Simple PHP Blog, which can be exploited by malicious people to bypass certain security restrictions and conduct script insertion and cross-site request forgery attacks, and by malicious users to disclose sensitive information and compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27359/
--
[SA27348] Vanilla SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-22
InATeam has reported some vulnerabilities in Vanilla, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27348/
--
[SA27346] Simple Machines Forum SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-22
Michael Brooks has reported some vulnerabilities in Simple Machines Forum, which can be exploited by malicious users and malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27346/
--
[SA27323] MultiXTpm Application Server "DebugPrint()" Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-10-23
A vulnerability has been reported in MultiXTpm Application Server, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27323/
--
[SA27398] Apache Tomcat WebDAV Arbitrary File Content Disclosure
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-10-25
eliteb0y has reported a vulnerability in Apache Tomcat, which can be exploited by malicious users to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27398/
--
[SA27390] SWAMP "username" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-25
morin.josh has reported a vulnerability in SWAMP, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27390/
--
[SA27341] HP OpenView Products httpd.tkd Unspecified Unauthorized Data Access
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-10-25
A vulnerability has been reported in HP OpenView Configuration Management (CM) Infrastructure (Radia) and Client Configuration Manager (CCM), which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27341/
--
[SA27324] SocketMail "lost_id" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-23
Ivan Sanchez and Maximiliano Soler have reported a vulnerability in SocketMail, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27324/
--
[SA27310] WWWISIS IAH Module "exprSearch" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-19
A vulnerability has been discovered in the IAH (Interface for Access of Health Information) module for WWWISIS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27310/
--
[SA27353] 3proxy FTP Proxy Module "OPEN" Command Double-Free
Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-10-24
Venustech AD-LAB has reported a vulnerability in 3proxy, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27353/
--
[SA27372] Pidgin HTML Processing Denial of Service
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2007-10-25
A weakness has been reported in Pidgin, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27372/

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Secunia 2007 Bulletins
Vulnerabilities Listing for November 1 2007
Windows:--
[SA27475] Macrovision Products Update Service ActiveX Control Insecure Methods
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-01
Some vulnerabilities have been reported in Macrovision products, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27475/
--
[SA27468] Novell BorderManager Client Trust Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-01
A vulnerability has been reported in Novell BorderManager, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27468/
--
[SA27429] Symantec Mail Security for Exchange File Parsing Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-29
Multiple vulnerabilities have been discovered in Symantec Mail Security for Exchange, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27429/
--
[SA27418] GOM Player GOM Manager ActiveX Control Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-29
rgod has discovered a vulnerability in GOM Player, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27418/
--
[SA27417] World in Conflict Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-29
Luigi Auriemma has reported a vulnerability in World in Conflict, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27417/
--
[SA27412] Symantec Altiris Deployment Solution Directory Traversal and Privilege Escalation
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information, Privilege escalation
Released: 2007-10-31
Two vulnerabilities have been reported in Symantec Altiris Deployment Solution, which can be exploited by malicious people to disclose potentially sensitive information and by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27412/
UNIX/Linux:--
[SA27458] Perdition IMAP Server Format String Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-31
Bernhard Mueller has reported a vulnerability in Perdition, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27458/
--
[SA27454] yarssr GUI.pm URL Handling Command Injection Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-31
Duncan Gilmore has discovered a vulnerability in yarssr, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27454/
--
[SA27439] SUSE Update for Multiple Packages
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-01
SUSE has issued updates for multiple packages. These fix some vulnerabilities, which can be exploited by malicious users and
malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27439/
--
[SA27434] Gentoo update for openssl
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-31
Gentoo has issued an update for openssl. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27434/
--
[SA27431] Gentoo update for opera
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2007-10-31
Gentoo has issued an update for opera. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks and to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27431/
--
[SA27427] Sun Solaris Mozilla JavaScript Engine Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-29
Sun has acknowledged some vulnerabilities in Mozilla 1.7 for Sun Solaris, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27427/
--
[SA27425] Debian update for iceweasel
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-29
Debian has issued an update for iceweasel. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27425/
--
[SA27423] Sun Mozilla Layout Engine Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-31
Sun has acknowledged some vulnerabilities in Mozilla 1.7 for Sun Solaris, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27423/
--
[SA27414] SUSE update for MozillaFirefox, mozilla, and seamonkey
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-26
SUSE has issued an update for MozillaFirefox, mozilla, and seamonkey. This fixes a weakness and some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, bypass certain security restrictions, manipulate certain data, and compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27414/
--
[SA27403] rPath update for firefox and thunderbird
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-29
rPath has issued an update for firefox and thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, conduct phishing attacks, manipulate certain data, and compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27403/
--
[SA27470] ISPworker Two Directory Traversal Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-11-01
GoLd_M has discovered two vulnerabilities in ISPworker, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27470/
--
[SA27465] IBM AIX BIND 8 Predictable DNS Query IDs Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2007-10-31
IBM has acknowledged a vulnerability in AIX, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
http://secunia.com/advisories/27465/
--
[SA27459] Avaya CMS / IR BIND Predictable DNS Query IDs Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2007-10-31
Avaya has acknowledged a vulnerability in Avaya CMS and IR, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
http://secunia.com/advisories/27459/
--
[SA27441] Apple Xcode Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Privilege escalation, DoS, System access
Released: 2007-10-31
Apple has acknowledged some vulnerabilities in Apple Xcode, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27441/
--
[SA27409] HP Oracle for OpenView Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Manipulation of data, Exposure of sensitive information, DoS
Released: 2007-10-26
HP has acknowledged some vulnerabilities in HP OfO (Oracle for Openview). Some of these vulnerabilities have unknown impacts, others can be exploited to disclose sensitive information, conduct SQL injection attacks, or to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27409/
--
[SA27445] SUSE update for cups
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-11-01
SUSE has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27445/
--
[SA27419] Nagios Plugins "check_snmp" Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-10-26
fabiodds has reported a vulnerability in Nagios Plugins, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27419/
--
[SA27410] Red Hat update for cups
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-10-31
Red Hat has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27410/
--
[SA27461] AirKiosk URL Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-31
Skien has reported a vulnerability in AirKiosk, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27461/
--
[SA27460] Fedora update for python
Critical: Less critical
Where: From remote
Impact: System access, DoS
Released: 2007-10-30
Fedora has issued an update for python. This fixes a security issue, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27460/
--
[SA27453] Fedora update for tar
Critical: Less critical
Where: From remote
Impact: System access
Released: 2007-10-30
Fedora has issued an update for tar. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27453/
--
[SA27444] Saxon "config[news_url]" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-30
Jesper Jurcenoks has reported a vulnerability in Saxon (Simple Accessible XHTML Online News), which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27444/
--
[SA27442] NuFW "samp_send()" Buffer Overflow Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-30
A vulnerability has been reported in NuFW, which can potentially be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27442/
--
[SA27432] Fedora update for ruby
Critical: Less critical
Where: From remote
Impact: Spoofing
Released: 2007-10-30
Fedora has issued an update for ruby. This fixes a security issue, which can be exploited by malicious people to conduct spoofing attacks.
Full Advisory:
http://secunia.com/advisories/27432/
--
[SA27428] Sun Solaris 10 SCTP INIT Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-29
Sun has acknowledged a vulnerability in Solaris, which can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27428/
--
[SA27424] OpenLDAP Denial of Service Vulnerabilities
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-29
Some vulnerabilities have been reported in OpenLDAP, which can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27424/
--
[SA27405] Ubuntu update for libpng
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-26
Ubuntu has issued an update for libpng. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27405/
--
[SA27474] rPath update for cups
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-11-01
rPath has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27474/
--
[SA27436] Red Hat update for kernel
Critical: Less critical
Where: From local network
Impact: Security Bypass, Exposure of sensitive information, DoS
Released: 2007-11-01
Red Hat has issued an update for the kernel. This fixes a weakness, some security issues and vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, and malicious users and malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27436/
--
[SA27438] Liferea "feedlist.opml" Backup Insecure File Permissions
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2007-10-30
A security issue has been reported in Liferea, which can be exploited by malicious, local users to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27438/
--
[SA27437] IBM AIX Multiple Privilege Escalation Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-31
Multiple vulnerabilities have been reported in IBM AIX, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27437/
--
[SA27408] Debian update for xen-utils
Critical: Less critical
Where: Local system
Impact: Manipulation of data
Released: 2007-10-26
Debian has issued an update for xen-utils. This fixes a security issue, which can be exploited by malicious, local users to truncate arbitrary files.
Full Advisory:
http://secunia.com/advisories/27408/
--
[SA27420] vobcopy "/tmp/vobcopy.bla" Insecure Temporary File
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-29
Joey Hess has reported a security issue in vobcopy, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27420/
Other:--
[SA27433] Nortel Business Communications Manager BIND 8 Predictable DNS Query IDs
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2007-10-29
Nortel has acknowledged a vulnerability in Business Communications Manager, which potentially can be exploited by malicious people to poison the DNS cache.
Full Advisory:
http://secunia.com/advisories/27433/
--
[SA27416] Sun Fire X2100/X2200 Embedded Lights Out Manager Command Execution
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-10-30
A vulnerability has been reported in Sun Fire X2100 M2 and X2200 M2, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27416/
--
[SA27452] Blue Coat ProxySG SGOS Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-01
A vulnerability has been reported in the Blue Coat ProxySG SGOS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27452/
--
[SA27451] Hitachi Products Information Disclosure Vulnerability
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-10-31
A vulnerability has been reported in multiple Hitachi products, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27451/
Cross Platform:--
[SA27413] Sige "SYS_PATH" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-10-29
GoLd_M has discovered a vulnerability in Sige, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27413/
--
[SA27448] IBM WebSphere "uddigui/navigateTree.do" Cross-Site Scripting and Request Forgery
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-31
IBM has acknowledged some vulnerabilities in IBM WebSphere, which can be exploited by malicious people to conduct cross-site scripting and request forgery attacks.
Full Advisory:
http://secunia.com/advisories/27448/
--
[SA27443] JobSite Professional "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-10-29
ZynbER has reported a vulnerability in JobSite Professional, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27443/
--
[SA27430] PHP-AGTC membership system adduser.php Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2007-10-30
0x90 has reported a vulnerability in PHP-AGTC membership system, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27430/
--
[SA27422] Micro Login System userpwd.txt Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-10-29
0x90 has discovered a security issue in Micro Login System, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27422/
--
[SA27411] AMX Mod X "geoip_code2()" and "geoip_code3()" Off-By-One Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-26
Simon Logic has reported some vulnerabilities in AMX Mod X, which can potentially be exploited by malicious people to cause a DoS (Denial of Service) or compromise an application using the plugin.
Full Advisory:
http://secunia.com/advisories/27411/
--
[SA27406] Multi-Forums Multiple SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-26
KiNgOfThEwOrLd has reported some vulnerabilities in the Multi-Forums module for phpBB, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27406/
--
[SA27482] Apache Geronimo SQLLoginModule Non-existing User Authentication Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-11-01
A security issue has been reported in Apache Geronimo, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27482/
--
[SA27481] Apache Geronimo WebDAV Arbitrary File Content Disclosure
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-11-01
A vulnerability has been acknowledged in Apache Geronimo, which can be exploited by malicious users to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27481/
--
[SA27478] IBM WebSphere Application Server Community Edition SQLLoginModule Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-11-01
IBM has acknowledged a security issue in WebSphere Application Server Community Edition, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27478/
--
[SA27464] IBM WebSphere Application Server Community Edition MEJB Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-10-31
IBM has acknowledged a vulnerability in WebSphere Application Server Community Edition, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27464/
--
[SA27457] ILIAS Mail and Forum Message URL Script Insertion
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-31
L4teral has discovered some vulnerabilities in ILIAS, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/27457/
--
[SA27449] Omnistar Live "category_id" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-30
Doz has reported a vulnerability in Omnistar Live, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27449/
--
[SA27446] WebSphere Application Server Community Edition WebDAV Content Disclosure
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-11-01
IBM has acknowledged a vulnerability in WebSphere Application Server Community Edition, which can be exploited by malicious users to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27446/
--
[SA27435] Django "i18n" Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-29
A vulnerability has been reported in Django, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27435/
--
[SA27415] OneOrZero Helpdesk "description" Script Insertion
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-26
Joseph.Giron13 has discovered a vulnerability in OneOrZero Helpdesk, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/27415/
--
[SA27407] WordPress "posts_columns" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-29
Janek Vind has discovered a vulnerability in WordPress, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27407/
--
[SA27404] rNote Two Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-26
RoMaNcYxHaCkEr has discovered two vulnerabilities in rNote, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27404/
Windows:--
[SA27475] Macrovision Products Update Service ActiveX Control Insecure Methods
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-01
Some vulnerabilities have been reported in Macrovision products, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27475/
--
[SA27468] Novell BorderManager Client Trust Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-01
A vulnerability has been reported in Novell BorderManager, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27468/
--
[SA27429] Symantec Mail Security for Exchange File Parsing Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-29
Multiple vulnerabilities have been discovered in Symantec Mail Security for Exchange, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27429/
--
[SA27418] GOM Player GOM Manager ActiveX Control Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-29
rgod has discovered a vulnerability in GOM Player, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27418/
--
[SA27417] World in Conflict Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-10-29
Luigi Auriemma has reported a vulnerability in World in Conflict, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27417/
--
[SA27412] Symantec Altiris Deployment Solution Directory Traversal and Privilege Escalation
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information, Privilege escalation
Released: 2007-10-31
Two vulnerabilities have been reported in Symantec Altiris Deployment Solution, which can be exploited by malicious people to disclose potentially sensitive information and by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27412/
UNIX/Linux:--
[SA27458] Perdition IMAP Server Format String Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-31
Bernhard Mueller has reported a vulnerability in Perdition, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27458/
--
[SA27454] yarssr GUI.pm URL Handling Command Injection Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-10-31
Duncan Gilmore has discovered a vulnerability in yarssr, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27454/
--
[SA27439] SUSE Update for Multiple Packages
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-01
SUSE has issued updates for multiple packages. These fix some vulnerabilities, which can be exploited by malicious users and
malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27439/
--
[SA27434] Gentoo update for openssl
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-31
Gentoo has issued an update for openssl. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27434/
--
[SA27431] Gentoo update for opera
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2007-10-31
Gentoo has issued an update for opera. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks and to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27431/
--
[SA27427] Sun Solaris Mozilla JavaScript Engine Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-29
Sun has acknowledged some vulnerabilities in Mozilla 1.7 for Sun Solaris, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27427/
--
[SA27425] Debian update for iceweasel
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-29
Debian has issued an update for iceweasel. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27425/
--
[SA27423] Sun Mozilla Layout Engine Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-31
Sun has acknowledged some vulnerabilities in Mozilla 1.7 for Sun Solaris, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27423/
--
[SA27414] SUSE update for MozillaFirefox, mozilla, and seamonkey
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-26
SUSE has issued an update for MozillaFirefox, mozilla, and seamonkey. This fixes a weakness and some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, bypass certain security restrictions, manipulate certain data, and compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27414/
--
[SA27403] rPath update for firefox and thunderbird
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-10-29
rPath has issued an update for firefox and thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, conduct phishing attacks, manipulate certain data, and compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27403/
--
[SA27470] ISPworker Two Directory Traversal Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-11-01
GoLd_M has discovered two vulnerabilities in ISPworker, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27470/
--
[SA27465] IBM AIX BIND 8 Predictable DNS Query IDs Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2007-10-31
IBM has acknowledged a vulnerability in AIX, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
http://secunia.com/advisories/27465/
--
[SA27459] Avaya CMS / IR BIND Predictable DNS Query IDs Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2007-10-31
Avaya has acknowledged a vulnerability in Avaya CMS and IR, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
http://secunia.com/advisories/27459/
--
[SA27441] Apple Xcode Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Privilege escalation, DoS, System access
Released: 2007-10-31
Apple has acknowledged some vulnerabilities in Apple Xcode, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27441/
--
[SA27409] HP Oracle for OpenView Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Manipulation of data, Exposure of sensitive information, DoS
Released: 2007-10-26
HP has acknowledged some vulnerabilities in HP OfO (Oracle for Openview). Some of these vulnerabilities have unknown impacts, others can be exploited to disclose sensitive information, conduct SQL injection attacks, or to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27409/
--
[SA27445] SUSE update for cups
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-11-01
SUSE has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27445/
--
[SA27419] Nagios Plugins "check_snmp" Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-10-26
fabiodds has reported a vulnerability in Nagios Plugins, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27419/
--
[SA27410] Red Hat update for cups
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-10-31
Red Hat has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27410/
--
[SA27461] AirKiosk URL Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-31
Skien has reported a vulnerability in AirKiosk, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27461/
--
[SA27460] Fedora update for python
Critical: Less critical
Where: From remote
Impact: System access, DoS
Released: 2007-10-30
Fedora has issued an update for python. This fixes a security issue, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27460/
--
[SA27453] Fedora update for tar
Critical: Less critical
Where: From remote
Impact: System access
Released: 2007-10-30
Fedora has issued an update for tar. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27453/
--
[SA27444] Saxon "config[news_url]" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-30
Jesper Jurcenoks has reported a vulnerability in Saxon (Simple Accessible XHTML Online News), which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27444/
--
[SA27442] NuFW "samp_send()" Buffer Overflow Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-30
A vulnerability has been reported in NuFW, which can potentially be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27442/
--
[SA27432] Fedora update for ruby
Critical: Less critical
Where: From remote
Impact: Spoofing
Released: 2007-10-30
Fedora has issued an update for ruby. This fixes a security issue, which can be exploited by malicious people to conduct spoofing attacks.
Full Advisory:
http://secunia.com/advisories/27432/
--
[SA27428] Sun Solaris 10 SCTP INIT Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-29
Sun has acknowledged a vulnerability in Solaris, which can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27428/
--
[SA27424] OpenLDAP Denial of Service Vulnerabilities
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-29
Some vulnerabilities have been reported in OpenLDAP, which can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27424/
--
[SA27405] Ubuntu update for libpng
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-26
Ubuntu has issued an update for libpng. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27405/
--
[SA27474] rPath update for cups
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-11-01
rPath has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27474/
--
[SA27436] Red Hat update for kernel
Critical: Less critical
Where: From local network
Impact: Security Bypass, Exposure of sensitive information, DoS
Released: 2007-11-01
Red Hat has issued an update for the kernel. This fixes a weakness, some security issues and vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, and malicious users and malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27436/
--
[SA27438] Liferea "feedlist.opml" Backup Insecure File Permissions
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2007-10-30
A security issue has been reported in Liferea, which can be exploited by malicious, local users to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27438/
--
[SA27437] IBM AIX Multiple Privilege Escalation Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-31
Multiple vulnerabilities have been reported in IBM AIX, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27437/
--
[SA27408] Debian update for xen-utils
Critical: Less critical
Where: Local system
Impact: Manipulation of data
Released: 2007-10-26
Debian has issued an update for xen-utils. This fixes a security issue, which can be exploited by malicious, local users to truncate arbitrary files.
Full Advisory:
http://secunia.com/advisories/27408/
--
[SA27420] vobcopy "/tmp/vobcopy.bla" Insecure Temporary File
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-10-29
Joey Hess has reported a security issue in vobcopy, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27420/
Other:--
[SA27433] Nortel Business Communications Manager BIND 8 Predictable DNS Query IDs
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2007-10-29
Nortel has acknowledged a vulnerability in Business Communications Manager, which potentially can be exploited by malicious people to poison the DNS cache.
Full Advisory:
http://secunia.com/advisories/27433/
--
[SA27416] Sun Fire X2100/X2200 Embedded Lights Out Manager Command Execution
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-10-30
A vulnerability has been reported in Sun Fire X2100 M2 and X2200 M2, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27416/
--
[SA27452] Blue Coat ProxySG SGOS Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-01
A vulnerability has been reported in the Blue Coat ProxySG SGOS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27452/
--
[SA27451] Hitachi Products Information Disclosure Vulnerability
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-10-31
A vulnerability has been reported in multiple Hitachi products, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27451/
Cross Platform:--
[SA27413] Sige "SYS_PATH" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-10-29
GoLd_M has discovered a vulnerability in Sige, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27413/
--
[SA27448] IBM WebSphere "uddigui/navigateTree.do" Cross-Site Scripting and Request Forgery
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-31
IBM has acknowledged some vulnerabilities in IBM WebSphere, which can be exploited by malicious people to conduct cross-site scripting and request forgery attacks.
Full Advisory:
http://secunia.com/advisories/27448/
--
[SA27443] JobSite Professional "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-10-29
ZynbER has reported a vulnerability in JobSite Professional, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27443/
--
[SA27430] PHP-AGTC membership system adduser.php Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2007-10-30
0x90 has reported a vulnerability in PHP-AGTC membership system, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27430/
--
[SA27422] Micro Login System userpwd.txt Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-10-29
0x90 has discovered a security issue in Micro Login System, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27422/
--
[SA27411] AMX Mod X "geoip_code2()" and "geoip_code3()" Off-By-One Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-10-26
Simon Logic has reported some vulnerabilities in AMX Mod X, which can potentially be exploited by malicious people to cause a DoS (Denial of Service) or compromise an application using the plugin.
Full Advisory:
http://secunia.com/advisories/27411/
--
[SA27406] Multi-Forums Multiple SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-10-26
KiNgOfThEwOrLd has reported some vulnerabilities in the Multi-Forums module for phpBB, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27406/
--
[SA27482] Apache Geronimo SQLLoginModule Non-existing User Authentication Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-11-01
A security issue has been reported in Apache Geronimo, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27482/
--
[SA27481] Apache Geronimo WebDAV Arbitrary File Content Disclosure
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-11-01
A vulnerability has been acknowledged in Apache Geronimo, which can be exploited by malicious users to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27481/
--
[SA27478] IBM WebSphere Application Server Community Edition SQLLoginModule Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-11-01
IBM has acknowledged a security issue in WebSphere Application Server Community Edition, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27478/
--
[SA27464] IBM WebSphere Application Server Community Edition MEJB Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-10-31
IBM has acknowledged a vulnerability in WebSphere Application Server Community Edition, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27464/
--
[SA27457] ILIAS Mail and Forum Message URL Script Insertion
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-31
L4teral has discovered some vulnerabilities in ILIAS, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/27457/
--
[SA27449] Omnistar Live "category_id" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-30
Doz has reported a vulnerability in Omnistar Live, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27449/
--
[SA27446] WebSphere Application Server Community Edition WebDAV Content Disclosure
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-11-01
IBM has acknowledged a vulnerability in WebSphere Application Server Community Edition, which can be exploited by malicious users to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27446/
--
[SA27435] Django "i18n" Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-10-29
A vulnerability has been reported in Django, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27435/
--
[SA27415] OneOrZero Helpdesk "description" Script Insertion
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-26
Joseph.Giron13 has discovered a vulnerability in OneOrZero Helpdesk, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/27415/
--
[SA27407] WordPress "posts_columns" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-29
Janek Vind has discovered a vulnerability in WordPress, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27407/
--
[SA27404] rNote Two Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-10-26
RoMaNcYxHaCkEr has discovered two vulnerabilities in rNote, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27404/

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Secunia 2007 Bulletins
Secunia Vulnerabilities Content Listing for November 8 2008
Windows:--
[SA27561] SSReader Pdg2 Control ActiveX Control Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-07
A vulnerability has been discovered in SSReader, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27561/
--
[SA27500] Ourgame GLWorld GlobalLink Chat Control Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-02
Some vulnerabilities have been discovered in Ourgame GLWorld, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27500/
--
[SA27569] Cerberus FTP Server Web Interface Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-08
A vulnerability has been reported in Cerberus FTP Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27569/
--
[SA27552] Microsoft Sysinternals DebugView Dbgv.sys Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-07
A vulnerability has been reported in Microsoft Sysinternals DebugView, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27552/
UNIX/Linux:--
[SA27580] Red Hat update for tcpdump
Critical: Highly critical
Where: From remote
Impact: System access, DoS
Released: 2007-11-08
Red Hat has issued an update for tcpdump. This fixes some vulnerabilities, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27580/
--
[SA27578] KDE and KOffice "Stream.cc" Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-08
Some vulnerabilities have been reported in KDE and KOffice, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27578/
--
[SA27575] Red Hat update for gpdf
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-08
Red Hat has issued an update for gpdf. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27575/
--
[SA27574] Red Hat update for xpdf
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-08
Red Hat has issued an update for xpdf. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27574/
--
[SA27573] Red Hat update for poppler
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-08
Red Hat has issued an update for poppler. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27573/
--
[SA27556] Cypress Malicious Code Execution Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2007-11-07
Chris has reported a vulnerability in the Cypress script for BitchX, which can be exploited by malicious people to disclose potentially sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27556/
--
[SA27553] Poppler "Stream.cc" Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-08
Some vulnerabilities have been reported in Poppler, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27553/
--
[SA27520] Debian update for perdition
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-06
Debian has issued an update for perdition. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27520/
--
[SA27513] Fedora update for firefox
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-11-06
Fedora has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27513/
--
[SA27510] Fedora update for thunderbird
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-11-06
Fedora has issued an update for thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27510/
--
[SA27592] Red Hat update for wireshark
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-11-08
Red Hat has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27592/
--
[SA27579] Red Hat update for tetex
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-08
Red Hat has issued an update for tetex. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27579/
--
[SA27577] Red Hat update for cups
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-08
Red Hat has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27577/
--
[SA27554] rPath update for pcre
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2007-11-07
rPath has issued an update for pcre. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose sensitive information, or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27554/
--
[SA27551] MyWebFTP pass.php Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-11-07
Aria-Security Team have discovered a security issue in MyWebFTP, which can be exploited by malicious people to gain knowledge of sensitive information.
Full Advisory:
http://secunia.com/advisories/27551/
--
[SA27548] Red Hat update for perl
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-06
Red Hat has issued an update for perl. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27548/
--
[SA27547] Red Hat update for pcre
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-06
Red Hat has issued an update for pcre. This fixes some vulnerabilities, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27547/
--
[SA27545] Avaya Products PHP Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass, DoS
Released: 2007-11-06
Avaya has acknowledged some vulnerabilities in multiple Avaya products,
where some have unknown impacts and others can be exploited by malicious
users to bypass certain security restrictions or by malicious people to
cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27545/
--
[SA27543] PCRE Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2007-11-06
Some vulnerabilities have been reported in PCRE, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose sensitive information, or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27543/
--
[SA27538] Debian update for pcre3
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2007-11-06
Debian has issued an update for pcre3. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose sensitive information, or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27538/
--
[SA27531] Mandriva update for perl
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-06
Mandriva has issued an update for perl. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27531/
--
[SA27524] Mandriva update for opal
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-05
Mandriva has issued an update for opal. This fixes a vulnerability, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27524/
--
[SA27507] Fedora update for flac
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-02
Fedora has issued an update for flac. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27507/
--
[SA27503] Gentoo update for sitebar
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information, System access
Released: 2007-11-07
Gentoo has issued an update for sitebar. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks, or by malicious users to disclose potentially sensitive information and compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27503/
--
[SA27502] Gentoo update for gallery
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-02
Gentoo has issued an update for gallery. This fixes some vulnerabilities, which can be exploited by malicious users to
manipulate data.
Full Advisory:
http://secunia.com/advisories/27502/
--
[SA27501] Gentoo update for gftp
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-02
Gentoo has issued an update for gftp. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27501/
--
[SA27540] Ubuntu update for cups
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-06
Ubuntu has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27540/
--
[SA27499] Mandriva update for cups
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-02
Mandriva has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27499/
--
[SA27496] Fedora update for nagios-plugins
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-11-02
Fedora has issued an update for nagios-plugins. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27496/
--
[SA27494] Fedora update for cups
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-02
Fedora has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27494/
--
[SA27593] Red Hat update for httpd
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-08
Red Hat has issued an update for httpd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27593/
--
[SA27590] Red Hat update for pam
Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-11-08
Red Hat has issued an update for pam. This fixes a vulnerability and a security issue, which can be exploited by malicious, local users to disclose sensitive information and by malicious users to inject certain data.
Full Advisory:
http://secunia.com/advisories/27590/
--
[SA27588] Red Hat update for openssh
Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of system information
Released: 2007-11-08
Red Hat has issued an update for openssh. This fixes a vulnerability and a weakness, which can be exploited by malicious people to disclose certain system information and to inject certain data.
Full Advisory:
http://secunia.com/advisories/27588/
--
[SA27583] Gentoo update for mono
Critical: Less critical
Where: From remote
Impact: Unknown
Released: 2007-11-08
Gentoo has issued an update for mono. This fixes a vulnerability with an unknown impact.
Full Advisory:
http://secunia.com/advisories/27583/
--
[SA27563] Gentoo update for apache
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2007-11-08
Gentoo has issued an update for apache. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service) and by malicious people to conduct cross-site scripting attacks and cause a DoS.
Full Advisory:
http://secunia.com/advisories/27563/
--
[SA27562] Gentoo update for python
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-08
Gentoo has issued an update for python. This fixes a security issue, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27562/
--
[SA27555] Linux Kernel "ieee80211_rx()" Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-08
A vulnerability has been reported in the Linux Kernel, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27555/
--
[SA27544] Avaya Products Star Directory Traversal Vulnerability
Critical: Less critical
Where: From remote
Impact: System access
Released: 2007-11-06
Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27544/
--
[SA27541] Gentoo update for madwifi
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-08
Gentoo has issued an update for madwifi. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27541/
--
[SA27532] SkaLinks Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-06
Vincy has discovered a vulnerability in SkaLinks, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
http://secunia.com/advisories/27532/
--
[SA27529] Gentoo update for libpng
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-08
Gentoo has issued an update for libpng. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27529/
--
[SA27518] Mandriva update for pwlib
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-05
Mandriva has issued an update for pwlib. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27518/
--
[SA27516] Fedora update for proftpd
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-11-06
Fedora has issued an update for proftpd. This fixes a security issue, which potentially can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27516/
--
[SA27515] rPath update for perl
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-07
rPath has issued an update for perl. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27515/
--
[SA27506] Fedora update for phpmyadmin
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-02
Fedora has issued an update for phpmyadmin. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27506/
--
[SA27505] Avaya Messaging Products Web Interface Denial of Service
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-02
A vulnerability has been reported in multiple Avaya Messaging Products, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27505/
--
[SA27492] Fedora update for libpng
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-06
Fedora has issued an update for libpng. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27492/
--
[SA27484] NetCommons Unspecified Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-05
A vulnerability has been reported in NetCommons, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27484/
--
[SA27558] Net-snmp GETBULK Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-11-08
A vulnerability has been reported in Net-snmp, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27558/
--
[SA27591] Red Hat update for coolkey
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-08
Red Hat has issued an update for coolkey. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27591/
--
[SA27586] GForge Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Manipulation of data
Released: 2007-11-08
Steve Kemp has reported a security issue in GForge, which can be exploited by malicious, local users to truncate arbitrary files.
Full Advisory:
http://secunia.com/advisories/27586/
--
[SA27560] Mandriva update for xfs
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-07
Mandriva has issued an update for xfs. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27560/
--
[SA27549] Debian update for gforge
Critical: Less critical
Where: Local system
Impact: Manipulation of data
Released: 2007-11-08
Debian has issued an update for gforge. This fixes a security issue, which can be exploited by malicious, local users to truncate arbitrary files.
Full Advisory:
http://secunia.com/advisories/27549/
--
[SA27528] Avaya Products Linux Kernel Multiple Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, DoS
Released: 2007-11-06
Avaya has acknowledged some vulnerabilities in various Avaya products, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27528/
--
[SA27512] Sun SRS Net Connect Software "srsexec" Format String Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-05
A vulnerability has been reported in SRS Net Connect Software, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27512/
--
[SA27511] Debian update for mono
Critical: Less critical
Where: Local system
Impact: Unknown
Released: 2007-11-06
Debian has issued an update for mono. This fixes a vulnerability, which has unknown impacts.
Full Advisory:
http://secunia.com/advisories/27511/
--
[SA27497] Fedora update for xen
Critical: Less critical
Where: Local system
Impact: Manipulation of data
Released: 2007-11-02
Fedora has issued an update for xen. This fixes a security issue, which can be exploited by malicious, local users to truncate arbitrary files.
Full Advisory:
http://secunia.com/advisories/27497/
--
[SA27491] Fedora update for liferea
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2007-11-02
Fedora has issued an update for liferea. This fixes a security issue, which can be exploited by malicious, local users to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27491/
--
[SA27486] Mandriva update for xen
Critical: Less critical
Where: Local system
Impact: Security Bypass, Manipulation of data, Privilege escalation
Released: 2007-11-02
Mandriva has issued an update for xen. This fixes some vulnerabilities, which can be exploited by malicious, local users to truncate arbitrary files, bypass certain security restrictions, or gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27486/
--
[SA27557] Red Hat Update for rhpki-util, rhpki-common, and rhpki-ca
Critical: Not critical
Where: From remote
Impact: Security Bypass
Released: 2007-11-08
Red Hat has issued an update for rhpki-util, rhpki-common, and rhpki-ca. This fixes a security issue, which can result in bypassing certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27557/
--
[SA27514] Fedora update for tar
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2007-11-06
Fedora has issued an update for tar. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27514/
--
[SA27495] Fedora update for pidgin
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2007-11-02
Fedora has issued an update for pidgin. This fixes a weakness, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27495/
--
[SA27489] Mandriva update for netpbm
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2007-11-06
Mandriva has issued an update for netpbm. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27489/
--
[SA27589] Red Hat update for mcstrans
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-11-08
Red Hat has issued an update for mcstrans. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial if Service).
Full Advisory:
http://secunia.com/advisories/27589/
--
[SA27536] Avaya CMS / IR Sun Solaris Kernel Statistics Retrieval Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-11-05
Avaya has acknowledged some vulnerabilities in Avaya CMS and IR, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27536/
--
[SA27519] Sun Solaris SVM Denial of Service Weakness
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-11-08
A weakness has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27519/
--
[SA27488] Symantec AntiVirus for Macintosh Privilege Escalation Weakness
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-02
A weakness has been reported in Symantec AntiVirus for Macintosh and Norton AntiVirus for Macintosh, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27488/
--
[SA27483] iSCSI Enterprise Target "/etc/ietd.conf" Information Disclosure Weakness
Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2007-11-02
A weakness has been discovered in iSCSI Enterprise Target, which can be exploited by malicious, local users to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27483/
Other:--
[SA27498] Symantec Mail Security Appliance File Parsing Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-02
Multiple vulnerabilities have been reported in Symantec Mail Security Appliance, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27498/
Cross Platform:--
[SA27533] JBC Explorer Security Bypass and PHP Code Execution
Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2007-11-06
DarkFig has discovered a vulnerability in JBC Explorer, which can be exploited by malicious people to bypass certain security restrictions and compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27533/
--
[SA27530] Plone "statusmessages" and "linkintegrity" Modules Code Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-06
Two vulnerabilities have been reported in Plone, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27530/
--
[SA27527] SyndeoCMS "cmsdir" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-05
Mdx has reported a vulnerability in SyndeoCMS, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27527/
--
[SA27523] Apple QuickTime Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, System access
Released: 2007-11-06
Some vulnerabilities have been reported in Apple QuickTime, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, and compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27523/
--
[SA27582] PCRE Regex Parsing Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-08
Chris Evans has reported some vulnerabilities in PCRE, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27582/
--
[SA27546] Perl Regular Expressions Unicode Data Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-06
Tavis Ormandy and Will Drewry have reported a vulnerability in Perl, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27546/
--
[SA27517] E-Vendejo "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-05
R00T[ATI] has reported a vulnerability in E-Vendejo, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27517/
--
[SA27508] GNU Emacs Local Variable Processing Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-05
Drake Wilson has reported a vulnerability in GNU Emacs, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27508/
--
[SA27504] PicoFlat CMS Administration Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2007-11-07
Some vulnerabilities have been reported in PicoFlat CMS, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27504/
--
[SA27542] IBM Informix Dynamic Server Unspecified Directory Traversal and Denial of Service
Critical: Moderately critical
Where: From local network
Impact: Unknown, DoS
Released: 2007-11-07
Some vulnerabilities have been reported in IBM Informix Dynamic Server, one of which has an unknown impact and another can be exploited to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27542/
--
[SA27526] Oracle Database PITRIG_DROPMETADATA Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-08
A vulnerability has been reported in Oracle Database, which can be exploited by malicious users to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27526/
--
[SA27525] OpenBase SQL Command Injection and Buffer Overflow
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-11-06
Some vulnerabilities have been reported in Openbase SQL, which can be exploited by malicious users to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27525/
--
[SA27539] Perl Archive::Tar Directory Traversal Vulnerability
Critical: Less critical
Where: From remote
Impact: System access
Released: 2007-11-06
A vulnerability has been reported in the Archive::Tar Perl module, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27539/
--
[SA27535] C++ Sockets Library HTTPSocket Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-07
A vulnerability has been reported in C++ Sockets Library, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27535/
--
[SA27534] Coppermine Photo Gallery "data" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-06
Nicolas Le Gland has reported a vulnerability in Coppermine Photo Gallery, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27534/
--
[SA27509] IBM Lotus Domino Web Server Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Unknown
Released: 2007-11-02
IBM has acknowledged a vulnerability in IBM Lotus Domino Web Server, which can be exploited by malicious users to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27509/
--
[SA27493] Mono Mono.Math.BigInteger Vulnerability
Critical: Less critical
Where: From remote
Impact: Unknown
Released: 2007-11-06
A vulnerability with an unknown impact has been reported in Mono.
Full Advisory:
http://secunia.com/advisories/27493/
--
[SA27490] Helios Calendar "username" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-05
Ivan Sanchez and Maximiliano Soler have reported a vulnerability in Helios Calendar, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27490/
--
[SA27487] SF-Shoutbox "nick" and "shout" Script Insertion Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-05
SkyOut has reported some vulnerabilities in SF-Shoutbox, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/27487/
--
[SA27485] sBlog Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-02
0x90 has discovered a vulnerability in sBlog, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
http://secunia.com/advisories/27485/
Windows:--
[SA27561] SSReader Pdg2 Control ActiveX Control Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-07
A vulnerability has been discovered in SSReader, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27561/
--
[SA27500] Ourgame GLWorld GlobalLink Chat Control Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-02
Some vulnerabilities have been discovered in Ourgame GLWorld, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27500/
--
[SA27569] Cerberus FTP Server Web Interface Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-08
A vulnerability has been reported in Cerberus FTP Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27569/
--
[SA27552] Microsoft Sysinternals DebugView Dbgv.sys Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-07
A vulnerability has been reported in Microsoft Sysinternals DebugView, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27552/
UNIX/Linux:--
[SA27580] Red Hat update for tcpdump
Critical: Highly critical
Where: From remote
Impact: System access, DoS
Released: 2007-11-08
Red Hat has issued an update for tcpdump. This fixes some vulnerabilities, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27580/
--
[SA27578] KDE and KOffice "Stream.cc" Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-08
Some vulnerabilities have been reported in KDE and KOffice, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27578/
--
[SA27575] Red Hat update for gpdf
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-08
Red Hat has issued an update for gpdf. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27575/
--
[SA27574] Red Hat update for xpdf
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-08
Red Hat has issued an update for xpdf. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27574/
--
[SA27573] Red Hat update for poppler
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-08
Red Hat has issued an update for poppler. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27573/
--
[SA27556] Cypress Malicious Code Execution Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2007-11-07
Chris has reported a vulnerability in the Cypress script for BitchX, which can be exploited by malicious people to disclose potentially sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27556/
--
[SA27553] Poppler "Stream.cc" Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-08
Some vulnerabilities have been reported in Poppler, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27553/
--
[SA27520] Debian update for perdition
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-06
Debian has issued an update for perdition. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27520/
--
[SA27513] Fedora update for firefox
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-11-06
Fedora has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27513/
--
[SA27510] Fedora update for thunderbird
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-11-06
Fedora has issued an update for thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27510/
--
[SA27592] Red Hat update for wireshark
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-11-08
Red Hat has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27592/
--
[SA27579] Red Hat update for tetex
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-08
Red Hat has issued an update for tetex. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27579/
--
[SA27577] Red Hat update for cups
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-08
Red Hat has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27577/
--
[SA27554] rPath update for pcre
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2007-11-07
rPath has issued an update for pcre. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose sensitive information, or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27554/
--
[SA27551] MyWebFTP pass.php Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-11-07
Aria-Security Team have discovered a security issue in MyWebFTP, which can be exploited by malicious people to gain knowledge of sensitive information.
Full Advisory:
http://secunia.com/advisories/27551/
--
[SA27548] Red Hat update for perl
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-06
Red Hat has issued an update for perl. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27548/
--
[SA27547] Red Hat update for pcre
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-06
Red Hat has issued an update for pcre. This fixes some vulnerabilities, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27547/
--
[SA27545] Avaya Products PHP Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass, DoS
Released: 2007-11-06
Avaya has acknowledged some vulnerabilities in multiple Avaya products,
where some have unknown impacts and others can be exploited by malicious
users to bypass certain security restrictions or by malicious people to
cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27545/
--
[SA27543] PCRE Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2007-11-06
Some vulnerabilities have been reported in PCRE, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose sensitive information, or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27543/
--
[SA27538] Debian update for pcre3
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2007-11-06
Debian has issued an update for pcre3. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose sensitive information, or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27538/
--
[SA27531] Mandriva update for perl
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-06
Mandriva has issued an update for perl. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27531/
--
[SA27524] Mandriva update for opal
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-05
Mandriva has issued an update for opal. This fixes a vulnerability, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27524/
--
[SA27507] Fedora update for flac
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-02
Fedora has issued an update for flac. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27507/
--
[SA27503] Gentoo update for sitebar
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information, System access
Released: 2007-11-07
Gentoo has issued an update for sitebar. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks, or by malicious users to disclose potentially sensitive information and compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27503/
--
[SA27502] Gentoo update for gallery
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-02
Gentoo has issued an update for gallery. This fixes some vulnerabilities, which can be exploited by malicious users to
manipulate data.
Full Advisory:
http://secunia.com/advisories/27502/
--
[SA27501] Gentoo update for gftp
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-02
Gentoo has issued an update for gftp. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27501/
--
[SA27540] Ubuntu update for cups
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-06
Ubuntu has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27540/
--
[SA27499] Mandriva update for cups
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-02
Mandriva has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27499/
--
[SA27496] Fedora update for nagios-plugins
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-11-02
Fedora has issued an update for nagios-plugins. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27496/
--
[SA27494] Fedora update for cups
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-02
Fedora has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27494/
--
[SA27593] Red Hat update for httpd
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-08
Red Hat has issued an update for httpd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27593/
--
[SA27590] Red Hat update for pam
Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-11-08
Red Hat has issued an update for pam. This fixes a vulnerability and a security issue, which can be exploited by malicious, local users to disclose sensitive information and by malicious users to inject certain data.
Full Advisory:
http://secunia.com/advisories/27590/
--
[SA27588] Red Hat update for openssh
Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of system information
Released: 2007-11-08
Red Hat has issued an update for openssh. This fixes a vulnerability and a weakness, which can be exploited by malicious people to disclose certain system information and to inject certain data.
Full Advisory:
http://secunia.com/advisories/27588/
--
[SA27583] Gentoo update for mono
Critical: Less critical
Where: From remote
Impact: Unknown
Released: 2007-11-08
Gentoo has issued an update for mono. This fixes a vulnerability with an unknown impact.
Full Advisory:
http://secunia.com/advisories/27583/
--
[SA27563] Gentoo update for apache
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2007-11-08
Gentoo has issued an update for apache. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service) and by malicious people to conduct cross-site scripting attacks and cause a DoS.
Full Advisory:
http://secunia.com/advisories/27563/
--
[SA27562] Gentoo update for python
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-08
Gentoo has issued an update for python. This fixes a security issue, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27562/
--
[SA27555] Linux Kernel "ieee80211_rx()" Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-08
A vulnerability has been reported in the Linux Kernel, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27555/
--
[SA27544] Avaya Products Star Directory Traversal Vulnerability
Critical: Less critical
Where: From remote
Impact: System access
Released: 2007-11-06
Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27544/
--
[SA27541] Gentoo update for madwifi
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-08
Gentoo has issued an update for madwifi. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27541/
--
[SA27532] SkaLinks Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-06
Vincy has discovered a vulnerability in SkaLinks, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
http://secunia.com/advisories/27532/
--
[SA27529] Gentoo update for libpng
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-08
Gentoo has issued an update for libpng. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27529/
--
[SA27518] Mandriva update for pwlib
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-05
Mandriva has issued an update for pwlib. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27518/
--
[SA27516] Fedora update for proftpd
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-11-06
Fedora has issued an update for proftpd. This fixes a security issue, which potentially can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27516/
--
[SA27515] rPath update for perl
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-07
rPath has issued an update for perl. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27515/
--
[SA27506] Fedora update for phpmyadmin
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-02
Fedora has issued an update for phpmyadmin. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27506/
--
[SA27505] Avaya Messaging Products Web Interface Denial of Service
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-02
A vulnerability has been reported in multiple Avaya Messaging Products, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27505/
--
[SA27492] Fedora update for libpng
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-06
Fedora has issued an update for libpng. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27492/
--
[SA27484] NetCommons Unspecified Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-05
A vulnerability has been reported in NetCommons, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27484/
--
[SA27558] Net-snmp GETBULK Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-11-08
A vulnerability has been reported in Net-snmp, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27558/
--
[SA27591] Red Hat update for coolkey
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-08
Red Hat has issued an update for coolkey. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27591/
--
[SA27586] GForge Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Manipulation of data
Released: 2007-11-08
Steve Kemp has reported a security issue in GForge, which can be exploited by malicious, local users to truncate arbitrary files.
Full Advisory:
http://secunia.com/advisories/27586/
--
[SA27560] Mandriva update for xfs
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-07
Mandriva has issued an update for xfs. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27560/
--
[SA27549] Debian update for gforge
Critical: Less critical
Where: Local system
Impact: Manipulation of data
Released: 2007-11-08
Debian has issued an update for gforge. This fixes a security issue, which can be exploited by malicious, local users to truncate arbitrary files.
Full Advisory:
http://secunia.com/advisories/27549/
--
[SA27528] Avaya Products Linux Kernel Multiple Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, DoS
Released: 2007-11-06
Avaya has acknowledged some vulnerabilities in various Avaya products, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27528/
--
[SA27512] Sun SRS Net Connect Software "srsexec" Format String Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-05
A vulnerability has been reported in SRS Net Connect Software, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27512/
--
[SA27511] Debian update for mono
Critical: Less critical
Where: Local system
Impact: Unknown
Released: 2007-11-06
Debian has issued an update for mono. This fixes a vulnerability, which has unknown impacts.
Full Advisory:
http://secunia.com/advisories/27511/
--
[SA27497] Fedora update for xen
Critical: Less critical
Where: Local system
Impact: Manipulation of data
Released: 2007-11-02
Fedora has issued an update for xen. This fixes a security issue, which can be exploited by malicious, local users to truncate arbitrary files.
Full Advisory:
http://secunia.com/advisories/27497/
--
[SA27491] Fedora update for liferea
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2007-11-02
Fedora has issued an update for liferea. This fixes a security issue, which can be exploited by malicious, local users to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27491/
--
[SA27486] Mandriva update for xen
Critical: Less critical
Where: Local system
Impact: Security Bypass, Manipulation of data, Privilege escalation
Released: 2007-11-02
Mandriva has issued an update for xen. This fixes some vulnerabilities, which can be exploited by malicious, local users to truncate arbitrary files, bypass certain security restrictions, or gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27486/
--
[SA27557] Red Hat Update for rhpki-util, rhpki-common, and rhpki-ca
Critical: Not critical
Where: From remote
Impact: Security Bypass
Released: 2007-11-08
Red Hat has issued an update for rhpki-util, rhpki-common, and rhpki-ca. This fixes a security issue, which can result in bypassing certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27557/
--
[SA27514] Fedora update for tar
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2007-11-06
Fedora has issued an update for tar. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27514/
--
[SA27495] Fedora update for pidgin
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2007-11-02
Fedora has issued an update for pidgin. This fixes a weakness, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27495/
--
[SA27489] Mandriva update for netpbm
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2007-11-06
Mandriva has issued an update for netpbm. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27489/
--
[SA27589] Red Hat update for mcstrans
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-11-08
Red Hat has issued an update for mcstrans. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial if Service).
Full Advisory:
http://secunia.com/advisories/27589/
--
[SA27536] Avaya CMS / IR Sun Solaris Kernel Statistics Retrieval Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-11-05
Avaya has acknowledged some vulnerabilities in Avaya CMS and IR, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27536/
--
[SA27519] Sun Solaris SVM Denial of Service Weakness
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-11-08
A weakness has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27519/
--
[SA27488] Symantec AntiVirus for Macintosh Privilege Escalation Weakness
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-02
A weakness has been reported in Symantec AntiVirus for Macintosh and Norton AntiVirus for Macintosh, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27488/
--
[SA27483] iSCSI Enterprise Target "/etc/ietd.conf" Information Disclosure Weakness
Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2007-11-02
A weakness has been discovered in iSCSI Enterprise Target, which can be exploited by malicious, local users to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27483/
Other:--
[SA27498] Symantec Mail Security Appliance File Parsing Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-02
Multiple vulnerabilities have been reported in Symantec Mail Security Appliance, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27498/
Cross Platform:--
[SA27533] JBC Explorer Security Bypass and PHP Code Execution
Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2007-11-06
DarkFig has discovered a vulnerability in JBC Explorer, which can be exploited by malicious people to bypass certain security restrictions and compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27533/
--
[SA27530] Plone "statusmessages" and "linkintegrity" Modules Code Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-06
Two vulnerabilities have been reported in Plone, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27530/
--
[SA27527] SyndeoCMS "cmsdir" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-05
Mdx has reported a vulnerability in SyndeoCMS, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27527/
--
[SA27523] Apple QuickTime Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, System access
Released: 2007-11-06
Some vulnerabilities have been reported in Apple QuickTime, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, and compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27523/
--
[SA27582] PCRE Regex Parsing Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-08
Chris Evans has reported some vulnerabilities in PCRE, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27582/
--
[SA27546] Perl Regular Expressions Unicode Data Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-06
Tavis Ormandy and Will Drewry have reported a vulnerability in Perl, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27546/
--
[SA27517] E-Vendejo "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-05
R00T[ATI] has reported a vulnerability in E-Vendejo, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27517/
--
[SA27508] GNU Emacs Local Variable Processing Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-05
Drake Wilson has reported a vulnerability in GNU Emacs, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27508/
--
[SA27504] PicoFlat CMS Administration Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2007-11-07
Some vulnerabilities have been reported in PicoFlat CMS, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27504/
--
[SA27542] IBM Informix Dynamic Server Unspecified Directory Traversal and Denial of Service
Critical: Moderately critical
Where: From local network
Impact: Unknown, DoS
Released: 2007-11-07
Some vulnerabilities have been reported in IBM Informix Dynamic Server, one of which has an unknown impact and another can be exploited to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27542/
--
[SA27526] Oracle Database PITRIG_DROPMETADATA Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-08
A vulnerability has been reported in Oracle Database, which can be exploited by malicious users to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27526/
--
[SA27525] OpenBase SQL Command Injection and Buffer Overflow
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-11-06
Some vulnerabilities have been reported in Openbase SQL, which can be exploited by malicious users to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27525/
--
[SA27539] Perl Archive::Tar Directory Traversal Vulnerability
Critical: Less critical
Where: From remote
Impact: System access
Released: 2007-11-06
A vulnerability has been reported in the Archive::Tar Perl module, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27539/
--
[SA27535] C++ Sockets Library HTTPSocket Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-07
A vulnerability has been reported in C++ Sockets Library, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27535/
--
[SA27534] Coppermine Photo Gallery "data" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-06
Nicolas Le Gland has reported a vulnerability in Coppermine Photo Gallery, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27534/
--
[SA27509] IBM Lotus Domino Web Server Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Unknown
Released: 2007-11-02
IBM has acknowledged a vulnerability in IBM Lotus Domino Web Server, which can be exploited by malicious users to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27509/
--
[SA27493] Mono Mono.Math.BigInteger Vulnerability
Critical: Less critical
Where: From remote
Impact: Unknown
Released: 2007-11-06
A vulnerability with an unknown impact has been reported in Mono.
Full Advisory:
http://secunia.com/advisories/27493/
--
[SA27490] Helios Calendar "username" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-05
Ivan Sanchez and Maximiliano Soler have reported a vulnerability in Helios Calendar, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27490/
--
[SA27487] SF-Shoutbox "nick" and "shout" Script Insertion Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-05
SkyOut has reported some vulnerabilities in SF-Shoutbox, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/27487/
--
[SA27485] sBlog Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-02
0x90 has discovered a vulnerability in sBlog, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
http://secunia.com/advisories/27485/

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Secunia 2007 Bulletins
Vulnerabilities Content Listing for the week of November 15 2007
Windows:--
[SA27622] AOL Radio AmpX ActiveX Control Multiple Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-12
Some vulnerabilities have been reported in AOL Radio, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27622/
--
[SA27660] DocuSafe "artnr" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-15
Aria-Security Team have reported a vulnerability in DocuSafe, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27660/
--
[SA27602] BROCHURE SERVICE "ID" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-09
Aria-Security Team have reported a vulnerability in BROCHURE SERVICE, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27602/
--
[SA27678] Novell Client NWFILTER.SYS Privilege Escalation Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-13
A vulnerability has been reported in Novell Client, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27678/
--
[SA27676] WinPcap NPF.SYS "bpf_filter_init" Array Indexing Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-13
A vulnerability has been reported in WinPcap, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27676/
--
[SA27675] Grani Script Execution Security Issue
Critical: Not critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-13
A security issue has been reported in Grani, which can be exploited by malicious people to execute arbitrary script code.
Full Advisory:
http://secunia.com/advisories/27675/
--
[SA27655] Sleipnir Script Execution Security Issue
Critical: Not critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-13
A security issue has been reported in Sleipnir, which can be exploited by malicious people to execute arbitrary script code.
Full Advisory:
http://secunia.com/advisories/27655/
--
[SA27633] Citrix Presentation Server Published Application Execution Weakness
Critical: Not critical
Where: From remote
Impact: System access
Released: 2007-11-15
A weakness has been reported in Citrix Presentation Server, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27633/
UNIX/Linux:--
[SA27665] Gentoo update for firefox, seamonkey, and xulrunner
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-11-13
Gentoo has issued an update for firefox, seamonkey, and xulrunner. This fixes some vulnerabilities and a weakness, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27665/
--
[SA27656] Red Hat update for kdegraphics
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-13
Red Hat has issued an update for kdegraphics. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27656/
--
[SA27643] Apple Mac OS X Security Update Fixes Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, Privilege escalation, DoS, System access
Released: 2007-11-15
Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities.
Full Advisory:
http://secunia.com/advisories/27643/
--
[SA27642] SUSE update for xpdf
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-12
SUSE has issued an update for xpdf. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27642/
--
[SA27641] SUSE update for poppler
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-12
SUSE has issued an update for poppler. This fixes some vulnerabilities, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27641/
--
[SA27640] SUSE update for koffice
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-12
SUSE has issued an update for koffice. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27640/
--
[SA27637] Slackware update for koffice, kdegraphics, and xpdf
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-12
Slackware has issued updates for koffice, kdegraphics, and xpdf. These fix some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27637/
--
[SA27636] SUSE update for kdegraphics3-pdf
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-14
SUSE has issued an update for kdegraphics-pdf. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27636/
--
[SA27634] SUSE Updates for Multiple Packages
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-15
SUSE has issued updates for xpdf, kdegraphics3-pdf, koffice, libextractor, poppler, gpdf, cups, pdf, and pdftohtml. These fix some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27634/
--
[SA27632] Ubuntu update for poppler
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-14
Ubuntu has issued an update for poppler. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27632/
--
[SA27631] Fedora update for link-grammar
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-15
Fedora has issued an update for link-grammar. This fixes a vulnerability, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27631/
--
[SA27624] Fedora Update for Multiple KDE Packages
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-13
Fedora has issued an update for multiple KDE packages. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27624/
--
[SA27619] Fedora update for xpdf
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-12
Fedora has issued an update for xpdf. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27619/
--
[SA27618] Fedora update for koffice
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-12
Fedora has issued an update for koffice. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27618/
--
[SA27603] Sun Solaris Mozilla 1.7 Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-09
Sun has acknowledged multiple vulnerabilities in Mozilla 1.7 for Sun Solaris, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27603/
--
[SA27646] Gentoo update for pioneers
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-11-15
Gentoo has issued an update for pioneers. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27646/
--
[SA27645] SUSE update for cups
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-14
SUSE has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27645/
--
[SA27628] Ubuntu update for flac
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-14
Ubuntu has issued an update for flac. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27628/
--
[SA27627] Ubuntu update for emacs
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-14
Ubuntu has issued an update for emacs. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27627/
--
[SA27625] Gentoo update for flac
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-13
Gentoo has issued an update for flac. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27625/
--
[SA27615] Fedora update for cups
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-12
Fedora has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27615/
--
[SA27613] Fedora update for perl
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-13
Fedora has issued an update for perl. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27613/
--
[SA27610] Red Hat update for pcre
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-12
Red Hat has issued an update for pcre. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27610/
--
[SA27609] Gentoo update for nagios-plugins
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-09
Gentoo has issued an update for nagios-plugins. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27609/
--
[SA27601] Mandriva update for flac
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-09
Mandriva has issued an update for flac. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27601/
--
[SA27599] Red Hat update for tetex
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-09
Red Hat has issued an update for tetex. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27599/
--
[SA27598] Mandriva update for pcre
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-09
Mandriva has issued an update for pcre. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27598/
--
[SA27604] Gentoo update for cups
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-13
Gentoo has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27604/
--
[SA27673] Red Hat update for ruby
Critical: Less critical
Where: From remote
Impact: Spoofing
Released: 2007-11-13
Red Hat has issued an update for ruby. This fixes some security issues, which can be exploited by malicious people to conduct spoofing attacks.
Full Advisory:
http://secunia.com/advisories/27673/
--
[SA27670] nss_ldap Race Condition Security Issue
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-15
A security issue has been reported in nss_ldap, which can be exploited by malicious people to manipulate certain data.
Full Advisory:
http://secunia.com/advisories/27670/
--
[SA27662] Avaya Products libpng Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-13
Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27662/
--
[SA27657] Gentoo update for rails
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information
Released: 2007-11-15
Gentoo has issued an update for rails. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information and conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27657/
--
[SA27639] Mandriva update for mono
Critical: Less critical
Where: From remote
Impact: Unknown
Released: 2007-11-15
Mandriva has issued an update for mono. This fixes a vulnerability with an unknown impact.
Full Advisory:
http://secunia.com/advisories/27639/
--
[SA27629] Mandriva update for libpng
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-14
Mandriva has issued an update for libpng. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27629/
--
[SA27626] Fedora Update for PEAR MDB2 Packages
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-11-15
Fedora has issued an update for php-pear-MDB2, php-pear-MDB2-Driver-mysqli, and php-pear-MDB2-Driver-mysql. This fixes a security issue, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27626/
--
[SA27616] Fedora update for inotify-tools
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-12
Fedora has issued an update for inotify-tools. This fixes a vulnerability, which potentially can be exploited by malicious users to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27616/
--
[SA27614] SUSE update for kernel
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-12
SUSE has issued an update for the kernel. This fixes two vulnerabilities, which can be exploited by malicious, local users and by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27614/
--
[SA27612] Fedora update for mono
Critical: Less critical
Where: From remote
Impact: Unknown
Released: 2007-11-12
Fedora has issued an update for mono. This fixes a vulnerability with an unknown impact.
Full Advisory:
http://secunia.com/advisories/27612/
--
[SA27597] Fedora update for django
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-12
Fedora has issued an update for django. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27597/
--
[SA27596] Red Hat update for openldap
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-09
Red Hat has issued an update for openldap. This fixes a vulnerability, which can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27596/
--
[SA27595] Debian update for phpmyadmin
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-09
Debian has issued an update for phpmyadmin. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27595/
--
[SA27666] Linux Kernel CIFS "SendReceive()" Buffer Overflow
Critical: Less critical
Where: From local network
Impact: DoS, System access
Released: 2007-11-14
A vulnerability has been reported in the Linux Kernel, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27666/
--
[SA27611] Red Hat Conga "ricci" Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-11-12
A vulnerability has been reported in Red Hat Conga, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27611/
--
[SA27607] Gentoo update for 3proxy
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-11-09
Gentoo has issued an update for 3proxy. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27607/
--
[SA27654] Avaya CMS / IR Sun Solaris FIFO File System Unauthorized Data Access
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2007-11-13
Avaya has acknowledged a vulnerability in Avaya CMS and IR, which can be exploited by malicious, local users to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27654/
--
[SA27681] Gentoo update for cpio
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2007-11-15
Gentoo has issued an update for cpio. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27681/
--
[SA27684] Sun Solaris unzip File Permission Change Vulnerability
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-15
Sun has acknowledged a vulnerability in Sun Solaris, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27684/
--
[SA27653] Fedora update for hugin
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-12
Fedora has issued an update for hugin. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27653/
--
[SA27623] Hugin "hugin_debug_optim_results.txt" Insecure Temporary File
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-12
A security issue has been discovered in Hugin, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27623/
--
[SA27621] Fedora update for tomboy
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-12
Fedora has issued an update for tomboy. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27621/
--
[SA27608] Gentoo update for tomboy
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-09
Gentoo has issued an update for tomboy. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27608/
Other:--
[SA27651] BT Home Hub/Thomson SpeedTouch 7G Multiple Vulnerabilities and Security Issue
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2007-11-12
Adrian Pastor has reported some vulnerabilities and a security issue in BT Home Hub/Thomson SpeedTouch 7G routers, which can be exploited by malicious people to conduct cross-site scripting, cross-site request forgery, and script insertion attacks, and to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27651/
--
[SA27635] HP OpenView Operations Java JRE/JDK JSSE DoS and Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS
Released: 2007-11-15
HP has acknowledged a vulnerability and a security issue in HP OpenView Operations, which can be exploited by malicious people to bypass certain security restrictions or to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27635/
--
[SA27652] Thomson Speedtouch 780 Cross-Site Request Forgery and Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-12
Adrian Pastor has reported some vulnerabilities in Thomson SpeedTouch 780, which can be exploited by malicious people to conduct cross-site request forgery and cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27652/
--
[SA27647] F5 Firepass 4100 SSL VPN "backurl" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-13
Jan Fry and Adrian Pastor have reported a vulnerability in F5 Firepass 4100 SSL VPN, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27647/
--
[SA27606] HP-UX Aries PA-RISC Emulator Unauthorized Access Vulnerability
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2007-11-09
A vulnerability has been reported in HP-UX, which can potentially be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27606/
Cross Platform:--
[SA27667] IBM DB2 Multiple Vulnerabilities and Security Issue
Critical: Moderately critical
Where: From remote
Impact: Unknown, Privilege escalation
Released: 2007-11-15
Some vulnerabilities and a security issue have been reported in IBM DB2, some of which have unknown impacts, and the other can be exploited by malicious, local users to gain escalated privileges or perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27667/
--
[SA27650] LI-Guestbook "country" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-12
security-news.ws has discovered a vulnerability in LI-Guestbook, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27650/
--
[SA27648] PHP Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass
Released: 2007-11-12
Some vulnerabilities and weaknesses have been reported in PHP, where some have unknown impacts and others can be exploited to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27648/
--
[SA27644] Adobe ColdFusion Session Hijacking Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Hijacking
Released: 2007-11-14
A vulnerability has been reported in Adobe ColdFusion, which potentially can be exploited by malicious people to hijack user sessions.
Full Advisory:
http://secunia.com/advisories/27644/
--
[SA27638] ExoPHPDesk register.php Script Insertion Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-15
Joseph.Giron13 has discovered two vulnerabilities in ExoPHPDesk, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/27638/
--
[SA27600] TestLink Unspecified Authorisation Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2007-11-14
A vulnerability has been reported in TestLink, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27600/
--
[SA27677] X7 Chat "room" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-13
ShAy6oOoN has discovered a vulnerability in X7 Chat, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27677/
--
[SA27674] IBM WebSphere Application Server WebContainer "Expect" Header Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-15
A vulnerability has been reported in IBM WebSphere Application Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27674/
--
[SA27671] AutoIndex PHP Script index.php URL Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-13
L4teral has discovered a vulnerability in AutoIndex PHP Script, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27671/
--
[SA27668] eggblog rss.php URL Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-13
Mesut Timur has discovered a vulnerability in eggblog, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27668/
--
[SA27630] phpMyAdmin Database Name SQL Injection and Script Insertion
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2007-11-12
Two vulnerabilities have been reported in phpMyAdmin, which can be exploited by malicious users to conduct script insertion and SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27630/
--
[SA27605] Mozilla Firefox "jar:" Protocol Handling Cross-Site Scripting Security Issue
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-09
A security issue has been reported in Mozilla Firefox, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27605/
Windows:--
[SA27622] AOL Radio AmpX ActiveX Control Multiple Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-12
Some vulnerabilities have been reported in AOL Radio, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27622/
--
[SA27660] DocuSafe "artnr" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-15
Aria-Security Team have reported a vulnerability in DocuSafe, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27660/
--
[SA27602] BROCHURE SERVICE "ID" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-09
Aria-Security Team have reported a vulnerability in BROCHURE SERVICE, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27602/
--
[SA27678] Novell Client NWFILTER.SYS Privilege Escalation Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-13
A vulnerability has been reported in Novell Client, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27678/
--
[SA27676] WinPcap NPF.SYS "bpf_filter_init" Array Indexing Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-13
A vulnerability has been reported in WinPcap, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27676/
--
[SA27675] Grani Script Execution Security Issue
Critical: Not critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-13
A security issue has been reported in Grani, which can be exploited by malicious people to execute arbitrary script code.
Full Advisory:
http://secunia.com/advisories/27675/
--
[SA27655] Sleipnir Script Execution Security Issue
Critical: Not critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-13
A security issue has been reported in Sleipnir, which can be exploited by malicious people to execute arbitrary script code.
Full Advisory:
http://secunia.com/advisories/27655/
--
[SA27633] Citrix Presentation Server Published Application Execution Weakness
Critical: Not critical
Where: From remote
Impact: System access
Released: 2007-11-15
A weakness has been reported in Citrix Presentation Server, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27633/
UNIX/Linux:--
[SA27665] Gentoo update for firefox, seamonkey, and xulrunner
Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-11-13
Gentoo has issued an update for firefox, seamonkey, and xulrunner. This fixes some vulnerabilities and a weakness, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27665/
--
[SA27656] Red Hat update for kdegraphics
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-13
Red Hat has issued an update for kdegraphics. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27656/
--
[SA27643] Apple Mac OS X Security Update Fixes Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, Privilege escalation, DoS, System access
Released: 2007-11-15
Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities.
Full Advisory:
http://secunia.com/advisories/27643/
--
[SA27642] SUSE update for xpdf
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-12
SUSE has issued an update for xpdf. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27642/
--
[SA27641] SUSE update for poppler
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-12
SUSE has issued an update for poppler. This fixes some vulnerabilities, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27641/
--
[SA27640] SUSE update for koffice
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-12
SUSE has issued an update for koffice. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27640/
--
[SA27637] Slackware update for koffice, kdegraphics, and xpdf
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-12
Slackware has issued updates for koffice, kdegraphics, and xpdf. These fix some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27637/
--
[SA27636] SUSE update for kdegraphics3-pdf
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-14
SUSE has issued an update for kdegraphics-pdf. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27636/
--
[SA27634] SUSE Updates for Multiple Packages
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-15
SUSE has issued updates for xpdf, kdegraphics3-pdf, koffice, libextractor, poppler, gpdf, cups, pdf, and pdftohtml. These fix some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27634/
--
[SA27632] Ubuntu update for poppler
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-14
Ubuntu has issued an update for poppler. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27632/
--
[SA27631] Fedora update for link-grammar
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-15
Fedora has issued an update for link-grammar. This fixes a vulnerability, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27631/
--
[SA27624] Fedora Update for Multiple KDE Packages
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-13
Fedora has issued an update for multiple KDE packages. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27624/
--
[SA27619] Fedora update for xpdf
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-12
Fedora has issued an update for xpdf. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27619/
--
[SA27618] Fedora update for koffice
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-12
Fedora has issued an update for koffice. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27618/
--
[SA27603] Sun Solaris Mozilla 1.7 Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-09
Sun has acknowledged multiple vulnerabilities in Mozilla 1.7 for Sun Solaris, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27603/
--
[SA27646] Gentoo update for pioneers
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-11-15
Gentoo has issued an update for pioneers. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27646/
--
[SA27645] SUSE update for cups
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-14
SUSE has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27645/
--
[SA27628] Ubuntu update for flac
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-14
Ubuntu has issued an update for flac. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27628/
--
[SA27627] Ubuntu update for emacs
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-14
Ubuntu has issued an update for emacs. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27627/
--
[SA27625] Gentoo update for flac
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-13
Gentoo has issued an update for flac. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27625/
--
[SA27615] Fedora update for cups
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-12
Fedora has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27615/
--
[SA27613] Fedora update for perl
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-13
Fedora has issued an update for perl. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27613/
--
[SA27610] Red Hat update for pcre
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-12
Red Hat has issued an update for pcre. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27610/
--
[SA27609] Gentoo update for nagios-plugins
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-09
Gentoo has issued an update for nagios-plugins. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27609/
--
[SA27601] Mandriva update for flac
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-09
Mandriva has issued an update for flac. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27601/
--
[SA27599] Red Hat update for tetex
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-09
Red Hat has issued an update for tetex. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27599/
--
[SA27598] Mandriva update for pcre
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-09
Mandriva has issued an update for pcre. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27598/
--
[SA27604] Gentoo update for cups
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-13
Gentoo has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27604/
--
[SA27673] Red Hat update for ruby
Critical: Less critical
Where: From remote
Impact: Spoofing
Released: 2007-11-13
Red Hat has issued an update for ruby. This fixes some security issues, which can be exploited by malicious people to conduct spoofing attacks.
Full Advisory:
http://secunia.com/advisories/27673/
--
[SA27670] nss_ldap Race Condition Security Issue
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-15
A security issue has been reported in nss_ldap, which can be exploited by malicious people to manipulate certain data.
Full Advisory:
http://secunia.com/advisories/27670/
--
[SA27662] Avaya Products libpng Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-13
Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27662/
--
[SA27657] Gentoo update for rails
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information
Released: 2007-11-15
Gentoo has issued an update for rails. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information and conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27657/
--
[SA27639] Mandriva update for mono
Critical: Less critical
Where: From remote
Impact: Unknown
Released: 2007-11-15
Mandriva has issued an update for mono. This fixes a vulnerability with an unknown impact.
Full Advisory:
http://secunia.com/advisories/27639/
--
[SA27629] Mandriva update for libpng
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-14
Mandriva has issued an update for libpng. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27629/
--
[SA27626] Fedora Update for PEAR MDB2 Packages
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-11-15
Fedora has issued an update for php-pear-MDB2, php-pear-MDB2-Driver-mysqli, and php-pear-MDB2-Driver-mysql. This fixes a security issue, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27626/
--
[SA27616] Fedora update for inotify-tools
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-12
Fedora has issued an update for inotify-tools. This fixes a vulnerability, which potentially can be exploited by malicious users to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27616/
--
[SA27614] SUSE update for kernel
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-12
SUSE has issued an update for the kernel. This fixes two vulnerabilities, which can be exploited by malicious, local users and by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27614/
--
[SA27612] Fedora update for mono
Critical: Less critical
Where: From remote
Impact: Unknown
Released: 2007-11-12
Fedora has issued an update for mono. This fixes a vulnerability with an unknown impact.
Full Advisory:
http://secunia.com/advisories/27612/
--
[SA27597] Fedora update for django
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-12
Fedora has issued an update for django. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27597/
--
[SA27596] Red Hat update for openldap
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-09
Red Hat has issued an update for openldap. This fixes a vulnerability, which can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27596/
--
[SA27595] Debian update for phpmyadmin
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-09
Debian has issued an update for phpmyadmin. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27595/
--
[SA27666] Linux Kernel CIFS "SendReceive()" Buffer Overflow
Critical: Less critical
Where: From local network
Impact: DoS, System access
Released: 2007-11-14
A vulnerability has been reported in the Linux Kernel, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27666/
--
[SA27611] Red Hat Conga "ricci" Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-11-12
A vulnerability has been reported in Red Hat Conga, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27611/
--
[SA27607] Gentoo update for 3proxy
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-11-09
Gentoo has issued an update for 3proxy. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27607/
--
[SA27654] Avaya CMS / IR Sun Solaris FIFO File System Unauthorized Data Access
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2007-11-13
Avaya has acknowledged a vulnerability in Avaya CMS and IR, which can be exploited by malicious, local users to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27654/
--
[SA27681] Gentoo update for cpio
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2007-11-15
Gentoo has issued an update for cpio. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27681/
--
[SA27684] Sun Solaris unzip File Permission Change Vulnerability
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-15
Sun has acknowledged a vulnerability in Sun Solaris, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27684/
--
[SA27653] Fedora update for hugin
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-12
Fedora has issued an update for hugin. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27653/
--
[SA27623] Hugin "hugin_debug_optim_results.txt" Insecure Temporary File
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-12
A security issue has been discovered in Hugin, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27623/
--
[SA27621] Fedora update for tomboy
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-12
Fedora has issued an update for tomboy. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27621/
--
[SA27608] Gentoo update for tomboy
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-09
Gentoo has issued an update for tomboy. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27608/
Other:--
[SA27651] BT Home Hub/Thomson SpeedTouch 7G Multiple Vulnerabilities and Security Issue
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2007-11-12
Adrian Pastor has reported some vulnerabilities and a security issue in BT Home Hub/Thomson SpeedTouch 7G routers, which can be exploited by malicious people to conduct cross-site scripting, cross-site request forgery, and script insertion attacks, and to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27651/
--
[SA27635] HP OpenView Operations Java JRE/JDK JSSE DoS and Security Bypass
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS
Released: 2007-11-15
HP has acknowledged a vulnerability and a security issue in HP OpenView Operations, which can be exploited by malicious people to bypass certain security restrictions or to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27635/
--
[SA27652] Thomson Speedtouch 780 Cross-Site Request Forgery and Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-12
Adrian Pastor has reported some vulnerabilities in Thomson SpeedTouch 780, which can be exploited by malicious people to conduct cross-site request forgery and cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27652/
--
[SA27647] F5 Firepass 4100 SSL VPN "backurl" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-13
Jan Fry and Adrian Pastor have reported a vulnerability in F5 Firepass 4100 SSL VPN, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27647/
--
[SA27606] HP-UX Aries PA-RISC Emulator Unauthorized Access Vulnerability
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2007-11-09
A vulnerability has been reported in HP-UX, which can potentially be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27606/
Cross Platform:--
[SA27667] IBM DB2 Multiple Vulnerabilities and Security Issue
Critical: Moderately critical
Where: From remote
Impact: Unknown, Privilege escalation
Released: 2007-11-15
Some vulnerabilities and a security issue have been reported in IBM DB2, some of which have unknown impacts, and the other can be exploited by malicious, local users to gain escalated privileges or perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27667/
--
[SA27650] LI-Guestbook "country" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-12
security-news.ws has discovered a vulnerability in LI-Guestbook, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27650/
--
[SA27648] PHP Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass
Released: 2007-11-12
Some vulnerabilities and weaknesses have been reported in PHP, where some have unknown impacts and others can be exploited to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27648/
--
[SA27644] Adobe ColdFusion Session Hijacking Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Hijacking
Released: 2007-11-14
A vulnerability has been reported in Adobe ColdFusion, which potentially can be exploited by malicious people to hijack user sessions.
Full Advisory:
http://secunia.com/advisories/27644/
--
[SA27638] ExoPHPDesk register.php Script Insertion Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-15
Joseph.Giron13 has discovered two vulnerabilities in ExoPHPDesk, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/27638/
--
[SA27600] TestLink Unspecified Authorisation Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2007-11-14
A vulnerability has been reported in TestLink, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27600/
--
[SA27677] X7 Chat "room" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-13
ShAy6oOoN has discovered a vulnerability in X7 Chat, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27677/
--
[SA27674] IBM WebSphere Application Server WebContainer "Expect" Header Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-15
A vulnerability has been reported in IBM WebSphere Application Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27674/
--
[SA27671] AutoIndex PHP Script index.php URL Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-13
L4teral has discovered a vulnerability in AutoIndex PHP Script, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27671/
--
[SA27668] eggblog rss.php URL Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-13
Mesut Timur has discovered a vulnerability in eggblog, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27668/
--
[SA27630] phpMyAdmin Database Name SQL Injection and Script Insertion
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2007-11-12
Two vulnerabilities have been reported in phpMyAdmin, which can be exploited by malicious users to conduct script insertion and SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27630/
--
[SA27605] Mozilla Firefox "jar:" Protocol Handling Cross-Site Scripting Security Issue
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-09
A security issue has been reported in Mozilla Firefox, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27605/

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Secunia 2007 Bulletins
Vulnerabilities Content Listing For The Week of November 23 2007
Windows:--
[SA27717] BitDefender Online Scanner ActiveX Control Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-21
Greg Linares has reported a vulnerability in BitDefender Online Scanner, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27717/
--
[SA27779] VU Case Manager "default.asp" SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-22
Aria-Security.Net has reported some vulnerabilities in VU Case Manager, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27779/
--
[SA27774] GWExtranet Information Disclosure and Script Insertion Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2007-11-22
Joseph.giron13 has reported some vulnerabilities in GWExtranet, which can be exploited by malicious people to disclose sensitive information, and by malicious users to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/27774/
--
[SA27758] VU Mass Mailer "redir.asp" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-22
Aria-Security.Net has reported a vulnerability in VU Mass Mailer, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27758/
--
[SA27734] Lhaplus LZH Archive Processing Unspecified Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-22
A vulnerability has been reported in Lhaplus, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27734/
--
[SA27700] Click&BaneX Two SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2007-11-20
Aria-Security Team have reported two vulnerabilities in Click&BaneX, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27700/
--
[SA27736] Ability Mail Server Unspecified IMAP4 Command Processing Denial of Service
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-21
A vulnerability has been reported in Ability Mail Server, which potentially can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27736/
--
[SA27751] Invensys Wonderware InTouch Insecure NetDDE Share Permissions Security Issue
Critical: Less critical
Where: From local network
Impact: System access
Released: 2007-11-21
A security issue has been reported in Invensys Wonderware InTouch, which potentially can be exploited by malicious users to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27751/
UNIX/Linux:--
[SA27785] Apple Mail Command Execution Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-22
A vulnerability has been reported in Apple Mail, which can be exploitedby malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27785/
--
[SA27772] Debian update for kdegraphics
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-22
Debian has issued an update for kdegraphics. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27772/
--
[SA27744] Slackware update for mozilla-thunderbird
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-21
Slackware has issued an update for mozilla-thunderbird. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27744/
--
[SA27716] SUSE update for java-1_5_0-ibm
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2007-11-19
SUSE has issued an update for java-1_5_0-ibm. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, manipulate data, disclose sensitive/system information, cause a DoS (Denial of Service), or
potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27716/
--
[SA27706] Gentoo update for vmware
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Privilege escalation, DoS, System access
Released: 2007-11-19
Gentoo has issued an update for vmware. This fixes some vulnerabilities, which can be exploited by malicious, local users to
bypass certain security restrictions, perform certain actions with escalated privileges, or to cause a DoS (Denial of Service), by
malicious users to bypass certain security restrictions, and by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27706/
--
[SA27705] Gentoo update for poppler, koffice, kword, kdegraphics, and kpdf
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-19
Gentoo has issued an update for poppler, koffice, kword, kdegraphics, and kpdf. These fix some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27705/
--
[SA27704] Gentoo update for mozilla-thunderbird
Critical: Highly critical
Where: From remote
Impact: System access, DoS
Released: 2007-11-19
Gentoo has issued an update for mozilla-thunderbird. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27704/
--
[SA27702] Gentoo update for link-grammar
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-19
Gentoo has issued an update for link-grammar. This fixes a vulnerability, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27702/
--
[SA27693] HP-UX update for JRE/JDK
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of system information, Exposure of sensitive information, System access
Released: 2007-11-16
HP has issued an update for JRE/JDK. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, manipulate data, disclose sensitive/system information, or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27693/
--
[SA27780] rPath update for flac
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-22
rPath has issued an update for flac. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27780/
--
[SA27761] IRC Services Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-11-21
A vulnerability has been reported in IRC Services, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27761/
--
[SA27754] I Hear U Multiple Denial of Service Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-11-21
Luigi Auriemma has reported some vulnerabilities in I Hear U, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27754/
--
[SA27745] Fedora update for cacti
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-22
Fedora has issued an update for cacti. This fixes a vulnerability, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27745/
--
[SA27743] Mandriva update for tetex
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-11-21
Mandriva has issued an update for tetex. This fixes some vulnerabilities, which can be exploited by malicious, local users to
disclose and manipulate sensitive information, and by malicious people to potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27743/
--
[SA27741] Gentoo update for pcre
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2007-11-21
Gentoo has issued an update for pcre. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose sensitive information, or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27741/
--
[SA27728] Fedora update for emacs
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-19
Fedora has issued an update for emacs. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27728/
--
[SA27724] Mandriva update for cups
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-20
Mandriva has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) and potentially to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27724/
--
[SA27721] Mandriva update for pdftohtml
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-19
Mandriva has issued an update for pdftohtml. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27721/
--
[SA27718] Fedora update for tetex
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-11-21
Fedora has issued an update for tetex. This fixes some vulnerabilities, which can be exploited by malicious, local users to disclose and manipulate sensitive information and by malicious people to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27718/
--
[SA27703] rPath update for kernel
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-11-22
rPath has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users and
by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27703/
--
[SA27692] ngIRCd "JOIN" Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-11-19
A vulnerability has been reported in ngIRCd, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27692/
--
[SA27742] Gentoo update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-21
Gentoo has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27742/
--
[SA27731] Slackware update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-19
Slackware has issued an update for samba. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27731/
--
[SA27720] Mandriva update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-19
Mandriva has issued an update for samba. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27720/
--
[SA27712] Debian update for cupsys
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-19
Debian has issued an update for cupsys. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27712/
--
[SA27701] rPath update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-19
rPath has issued an update for samba. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27701/
--
[SA27694] Ubuntu update for vmware
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-11-16
Ubuntu has issued an update for vmware. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27694/
--
[SA27691] Red Hat update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-16
Red Hat has issued an update for samba. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27691/
--
[SA27715] Gentoo update for bochs
Critical: Moderately critical
Where: Local system
Impact: System access, DoS
Released: 2007-11-19
Gentoo has issued an update for bochs. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27715/
--
[SA27753] Fedora update for phpmyadmin
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2007-11-22
Fedora has issued an update for phpmyadmin. This fixes some vulnerabilities, which can be exploited by malicious users to conduct script insertion and SQL injection attacks and by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27753/
--
[SA27746] Slackware update for libpng
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-21
Slackware has issued an update for libpng. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27746/
--
[SA27732] SUSE update for apache2
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2007-11-20
SUSE has issued an update for apache2. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), and by malicious people to conduct cross-site scripting attacks or to cause a DoS.
Full Advisory:
http://secunia.com/advisories/27732/
--
[SA27727] Fedora update for tomcat5
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information
Released: 2007-11-19
Fedora has issued an update for tomcat5. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting attacks or to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27727/
--
[SA27695] Apple Mac OS X Application Firewall Weaknesses and Security Issue
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-11-16
Some weaknesses and a security issue have been reported in Apple Mac OS X, which can lead to exposure of certain services.
Full Advisory:
http://secunia.com/advisories/27695/
--
[SA27747] Avaya Products Kernel Multiple Vulnerabilities
Critical: Less critical
Where: From local network
Impact: Security Bypass, Exposure of sensitive information, DoS
Released: 2007-11-21
Avaya has acknowledged some vulnerabilities, security issues, and a weakness in various Avaya products, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and disclose potentially sensitive information, and by malicious users and malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27747/
--
[SA27740] Gentoo update for net-snmp
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-11-21
Gentoo has issued an update for net-snmp. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27740/
--
[SA27733] Fedora update for net-snmp
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-11-21
Fedora has issued an update for net-snmp. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27733/
--
[SA27690] nss-mdns Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-11-22
A vulnerability has been reported in nss-mdns, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27690/
--
[SA27689] Red Hat update for net-snmp
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-11-16
Red Hat has issued an update for net-snmp. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27689/
--
[SA27739] Gentoo update for feynmf
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-21
Gentoo has issued an update for feynmf. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27739/
--
[SA27737] feynmf Insecure Temporary File Creation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-21
A vulnerability has been reported in feynmf, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27737/
--
[SA27710] OmniPCX Enterprise Communications Server IP Touch Phone Audio Unavailability Weakness
Critical: Not critical
Where: From local network
Impact: DoS
Released: 2007-11-20
A weakness has been reported in OmniPCX Enterprise Communications Server, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27710/
--
[SA27771] Liferea Insecure LD_LIBRARY_PATH Privilege Escalation
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-22
A security issue has been reported in Liferea, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27771/
Other:--
[SA27696] HP-UX update for BIND 8
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2007-11-21
HP-UX has issued an update for BIND 8. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
http://secunia.com/advisories/27696/
--
[SA27738] Linksys WAG54GS Cross-Site Scripting and Cross-Site Request Forgery Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-21
Adrian Pastor has reported some vulnerabilities in Linksys WAG54GS, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks.
Full Advisory:
http://secunia.com/advisories/27738/
Cross Platform:--
[SA27767] TalkBack Multiple File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-11-22
NoGe has discovered some vulnerabilities in TalkBack, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27767/
--
[SA27723] datecomm "pg" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-11-19
VerY-SecReT has reported a vulnerability in datecomm, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27723/
--
[SA27722] meBiblio "action" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-11-19
ShAy6oOoN has discovered a vulnerability in meBiblio, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27722/
--
[SA27708] Sciurus Hosting Panel Security Bypass and PHP Code Execution
Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2007-11-19
Liz0ziM has discovered two vulnerabilities in Sciurus Hosting Panel, which can be exploited by malicious people to bypass certain security restrictions and to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27708/
--
[SA27698] phpBBViet "phpbb_root_path" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-11-19
xoron has discovered a vulnerability in phpBBViet, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27698/
--
[SA27777] Wireshark Multiple Denial of Service Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-11-22
Some vulnerabilities have been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27777/
--
[SA27765] DevMass Shopping Cart "kfm_base_path" File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-11-22
S.W.A.T. has reported a vulnerability in DevMass Shopping Cart, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27765/
--
[SA27762] IBM WebSphere Application Server Two Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, DoS
Released: 2007-11-22
Some vulnerabilities have been reported in IBM WebSphere Application Server, one of which has an unknown impact, while the other can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27762/
--
[SA27735] JP1/File Transmission Server/FTP Authentication Bypass and DoS
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS
Released: 2007-11-22
Two vulnerabilities have been reported in JP1/File Transmission Server/FTP, which can be exploited by malicious users to cause a DoS (Denial of Service) and by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27735/
--
[SA27730] ProfileCMS "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-22
M.Hasran Addahroni has reported a vulnerability in ProfileCMS, which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27730/
--
[SA27729] Rigs Of Rods Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-11-20
Luigi Auriemma has reported a vulnerability in Rigs of Rods, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27729/
--
[SA27719] Cacti Unspecified SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-19
A vulnerability has been reported in Cacti, which potentially can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27719/
--
[SA27713] JiRo's Banner System "Email"/"Password" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-19
Some vulnerabilities have been reported in JiRo's Banner System, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27713/
--
[SA27711] LIVE555 Media Server "parseRTSPRequestString()" Denial of
Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-11-19
Luigi Auriemma has reported a vulnerability in LIVE555 Media Server, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27711/
--
[SA27709] IceBB "X-Forwarded-For" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-19
Gu1ll4um3r0m41n has discovered a vulnerability in IceBB, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27709/
--
[SA27750] FileMaker Pro/Server Instant Web Publishing Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-21
A vulnerability has been reported in FileMaker Pro/Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27750/
--
[SA27749] Feed2JS Feed URL Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-21
A vulnerability has been reported in Feed2JS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27749/
--
[SA27748] phpMyAdmin "convcharset" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-21
Tim Brown has discovered a vulnerability in phpMyAdmin, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27748/
--
[SA27752] IBM Director CIM Server Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-11-21
A vulnerability has been reported in IBM Director, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27752/
--
[SA27714] WordPress Cookies Security Bypass Weakness
Critical: Not critical
Where: From remote
Impact: Security Bypass
Released: 2007-11-21
Steven J. Murdoch has discovered a weakness in WordPress, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27714/
Windows:--
[SA27717] BitDefender Online Scanner ActiveX Control Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-21
Greg Linares has reported a vulnerability in BitDefender Online Scanner, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27717/
--
[SA27779] VU Case Manager "default.asp" SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-22
Aria-Security.Net has reported some vulnerabilities in VU Case Manager, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27779/
--
[SA27774] GWExtranet Information Disclosure and Script Insertion Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2007-11-22
Joseph.giron13 has reported some vulnerabilities in GWExtranet, which can be exploited by malicious people to disclose sensitive information, and by malicious users to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/27774/
--
[SA27758] VU Mass Mailer "redir.asp" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-22
Aria-Security.Net has reported a vulnerability in VU Mass Mailer, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27758/
--
[SA27734] Lhaplus LZH Archive Processing Unspecified Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-22
A vulnerability has been reported in Lhaplus, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27734/
--
[SA27700] Click&BaneX Two SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2007-11-20
Aria-Security Team have reported two vulnerabilities in Click&BaneX, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27700/
--
[SA27736] Ability Mail Server Unspecified IMAP4 Command Processing Denial of Service
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-21
A vulnerability has been reported in Ability Mail Server, which potentially can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27736/
--
[SA27751] Invensys Wonderware InTouch Insecure NetDDE Share Permissions Security Issue
Critical: Less critical
Where: From local network
Impact: System access
Released: 2007-11-21
A security issue has been reported in Invensys Wonderware InTouch, which potentially can be exploited by malicious users to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27751/
UNIX/Linux:--
[SA27785] Apple Mail Command Execution Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-22
A vulnerability has been reported in Apple Mail, which can be exploitedby malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27785/
--
[SA27772] Debian update for kdegraphics
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-22
Debian has issued an update for kdegraphics. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27772/
--
[SA27744] Slackware update for mozilla-thunderbird
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-21
Slackware has issued an update for mozilla-thunderbird. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27744/
--
[SA27716] SUSE update for java-1_5_0-ibm
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2007-11-19
SUSE has issued an update for java-1_5_0-ibm. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, manipulate data, disclose sensitive/system information, cause a DoS (Denial of Service), or
potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27716/
--
[SA27706] Gentoo update for vmware
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Privilege escalation, DoS, System access
Released: 2007-11-19
Gentoo has issued an update for vmware. This fixes some vulnerabilities, which can be exploited by malicious, local users to
bypass certain security restrictions, perform certain actions with escalated privileges, or to cause a DoS (Denial of Service), by
malicious users to bypass certain security restrictions, and by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27706/
--
[SA27705] Gentoo update for poppler, koffice, kword, kdegraphics, and kpdf
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-19
Gentoo has issued an update for poppler, koffice, kword, kdegraphics, and kpdf. These fix some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27705/
--
[SA27704] Gentoo update for mozilla-thunderbird
Critical: Highly critical
Where: From remote
Impact: System access, DoS
Released: 2007-11-19
Gentoo has issued an update for mozilla-thunderbird. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27704/
--
[SA27702] Gentoo update for link-grammar
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-19
Gentoo has issued an update for link-grammar. This fixes a vulnerability, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27702/
--
[SA27693] HP-UX update for JRE/JDK
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of system information, Exposure of sensitive information, System access
Released: 2007-11-16
HP has issued an update for JRE/JDK. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, manipulate data, disclose sensitive/system information, or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27693/
--
[SA27780] rPath update for flac
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-22
rPath has issued an update for flac. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27780/
--
[SA27761] IRC Services Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-11-21
A vulnerability has been reported in IRC Services, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27761/
--
[SA27754] I Hear U Multiple Denial of Service Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-11-21
Luigi Auriemma has reported some vulnerabilities in I Hear U, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27754/
--
[SA27745] Fedora update for cacti
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-22
Fedora has issued an update for cacti. This fixes a vulnerability, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27745/
--
[SA27743] Mandriva update for tetex
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-11-21
Mandriva has issued an update for tetex. This fixes some vulnerabilities, which can be exploited by malicious, local users to
disclose and manipulate sensitive information, and by malicious people to potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27743/
--
[SA27741] Gentoo update for pcre
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2007-11-21
Gentoo has issued an update for pcre. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose sensitive information, or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27741/
--
[SA27728] Fedora update for emacs
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-19
Fedora has issued an update for emacs. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27728/
--
[SA27724] Mandriva update for cups
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-20
Mandriva has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) and potentially to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27724/
--
[SA27721] Mandriva update for pdftohtml
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-19
Mandriva has issued an update for pdftohtml. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27721/
--
[SA27718] Fedora update for tetex
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-11-21
Fedora has issued an update for tetex. This fixes some vulnerabilities, which can be exploited by malicious, local users to disclose and manipulate sensitive information and by malicious people to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27718/
--
[SA27703] rPath update for kernel
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-11-22
rPath has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users and
by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27703/
--
[SA27692] ngIRCd "JOIN" Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-11-19
A vulnerability has been reported in ngIRCd, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27692/
--
[SA27742] Gentoo update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-21
Gentoo has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27742/
--
[SA27731] Slackware update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-19
Slackware has issued an update for samba. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27731/
--
[SA27720] Mandriva update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-19
Mandriva has issued an update for samba. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27720/
--
[SA27712] Debian update for cupsys
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-19
Debian has issued an update for cupsys. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27712/
--
[SA27701] rPath update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-19
rPath has issued an update for samba. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27701/
--
[SA27694] Ubuntu update for vmware
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-11-16
Ubuntu has issued an update for vmware. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27694/
--
[SA27691] Red Hat update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-11-16
Red Hat has issued an update for samba. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27691/
--
[SA27715] Gentoo update for bochs
Critical: Moderately critical
Where: Local system
Impact: System access, DoS
Released: 2007-11-19
Gentoo has issued an update for bochs. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27715/
--
[SA27753] Fedora update for phpmyadmin
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2007-11-22
Fedora has issued an update for phpmyadmin. This fixes some vulnerabilities, which can be exploited by malicious users to conduct script insertion and SQL injection attacks and by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27753/
--
[SA27746] Slackware update for libpng
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-11-21
Slackware has issued an update for libpng. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27746/
--
[SA27732] SUSE update for apache2
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2007-11-20
SUSE has issued an update for apache2. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), and by malicious people to conduct cross-site scripting attacks or to cause a DoS.
Full Advisory:
http://secunia.com/advisories/27732/
--
[SA27727] Fedora update for tomcat5
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information
Released: 2007-11-19
Fedora has issued an update for tomcat5. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting attacks or to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27727/
--
[SA27695] Apple Mac OS X Application Firewall Weaknesses and Security Issue
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-11-16
Some weaknesses and a security issue have been reported in Apple Mac OS X, which can lead to exposure of certain services.
Full Advisory:
http://secunia.com/advisories/27695/
--
[SA27747] Avaya Products Kernel Multiple Vulnerabilities
Critical: Less critical
Where: From local network
Impact: Security Bypass, Exposure of sensitive information, DoS
Released: 2007-11-21
Avaya has acknowledged some vulnerabilities, security issues, and a weakness in various Avaya products, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and disclose potentially sensitive information, and by malicious users and malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27747/
--
[SA27740] Gentoo update for net-snmp
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-11-21
Gentoo has issued an update for net-snmp. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27740/
--
[SA27733] Fedora update for net-snmp
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-11-21
Fedora has issued an update for net-snmp. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27733/
--
[SA27690] nss-mdns Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-11-22
A vulnerability has been reported in nss-mdns, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27690/
--
[SA27689] Red Hat update for net-snmp
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-11-16
Red Hat has issued an update for net-snmp. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27689/
--
[SA27739] Gentoo update for feynmf
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-21
Gentoo has issued an update for feynmf. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27739/
--
[SA27737] feynmf Insecure Temporary File Creation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-21
A vulnerability has been reported in feynmf, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27737/
--
[SA27710] OmniPCX Enterprise Communications Server IP Touch Phone Audio Unavailability Weakness
Critical: Not critical
Where: From local network
Impact: DoS
Released: 2007-11-20
A weakness has been reported in OmniPCX Enterprise Communications Server, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27710/
--
[SA27771] Liferea Insecure LD_LIBRARY_PATH Privilege Escalation
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-22
A security issue has been reported in Liferea, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27771/
Other:--
[SA27696] HP-UX update for BIND 8
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2007-11-21
HP-UX has issued an update for BIND 8. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
http://secunia.com/advisories/27696/
--
[SA27738] Linksys WAG54GS Cross-Site Scripting and Cross-Site Request Forgery Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-21
Adrian Pastor has reported some vulnerabilities in Linksys WAG54GS, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks.
Full Advisory:
http://secunia.com/advisories/27738/
Cross Platform:--
[SA27767] TalkBack Multiple File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-11-22
NoGe has discovered some vulnerabilities in TalkBack, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27767/
--
[SA27723] datecomm "pg" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-11-19
VerY-SecReT has reported a vulnerability in datecomm, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27723/
--
[SA27722] meBiblio "action" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-11-19
ShAy6oOoN has discovered a vulnerability in meBiblio, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27722/
--
[SA27708] Sciurus Hosting Panel Security Bypass and PHP Code Execution
Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2007-11-19
Liz0ziM has discovered two vulnerabilities in Sciurus Hosting Panel, which can be exploited by malicious people to bypass certain security restrictions and to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27708/
--
[SA27698] phpBBViet "phpbb_root_path" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-11-19
xoron has discovered a vulnerability in phpBBViet, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27698/
--
[SA27777] Wireshark Multiple Denial of Service Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-11-22
Some vulnerabilities have been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27777/
--
[SA27765] DevMass Shopping Cart "kfm_base_path" File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-11-22
S.W.A.T. has reported a vulnerability in DevMass Shopping Cart, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27765/
--
[SA27762] IBM WebSphere Application Server Two Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, DoS
Released: 2007-11-22
Some vulnerabilities have been reported in IBM WebSphere Application Server, one of which has an unknown impact, while the other can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27762/
--
[SA27735] JP1/File Transmission Server/FTP Authentication Bypass and DoS
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS
Released: 2007-11-22
Two vulnerabilities have been reported in JP1/File Transmission Server/FTP, which can be exploited by malicious users to cause a DoS (Denial of Service) and by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27735/
--
[SA27730] ProfileCMS "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-22
M.Hasran Addahroni has reported a vulnerability in ProfileCMS, which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27730/
--
[SA27729] Rigs Of Rods Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-11-20
Luigi Auriemma has reported a vulnerability in Rigs of Rods, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27729/
--
[SA27719] Cacti Unspecified SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-19
A vulnerability has been reported in Cacti, which potentially can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27719/
--
[SA27713] JiRo's Banner System "Email"/"Password" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-19
Some vulnerabilities have been reported in JiRo's Banner System, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27713/
--
[SA27711] LIVE555 Media Server "parseRTSPRequestString()" Denial of
Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-11-19
Luigi Auriemma has reported a vulnerability in LIVE555 Media Server, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27711/
--
[SA27709] IceBB "X-Forwarded-For" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-19
Gu1ll4um3r0m41n has discovered a vulnerability in IceBB, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27709/
--
[SA27750] FileMaker Pro/Server Instant Web Publishing Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-21
A vulnerability has been reported in FileMaker Pro/Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27750/
--
[SA27749] Feed2JS Feed URL Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-21
A vulnerability has been reported in Feed2JS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27749/
--
[SA27748] phpMyAdmin "convcharset" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-21
Tim Brown has discovered a vulnerability in phpMyAdmin, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27748/
--
[SA27752] IBM Director CIM Server Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-11-21
A vulnerability has been reported in IBM Director, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27752/
--
[SA27714] WordPress Cookies Security Bypass Weakness
Critical: Not critical
Where: From remote
Impact: Security Bypass
Released: 2007-11-21
Steven J. Murdoch has discovered a weakness in WordPress, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27714/

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Secunia 2007 Bulletins
Vulnerabilities Content Listing for the week of November 29 2007
Windows:--
[SA27849] Autonomy Keyview SDK Lotus 1-2-3 File Viewer Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-29
Some vulnerabilities have been reported in Autonomy Keyview SDK, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27849/
--
[SA27836] IBM Lotus Notes 5 / 6 Lotus 1-2-3 File Viewer Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-27
Some vulnerabilities have been reported in IBM Lotus Notes, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27836/
--
[SA27835] IBM Lotus Notes Lotus 1-2-3 File Viewer Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-27
Some vulnerabilities have been reported in IBM Lotus Notes, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27835/
--
[SA27822] DWD Realty Two SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2007-11-27
Aria-Security Team have reported two vulnerabilities in DWD Realty, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27822/
--
[SA27813] NetAuctionHelp Classified Ads Two SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-27
Aria-Security Team have reported two vulnerabilities in NetAuctionHelp Classified Ads, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27813/
--
[SA27812] Dora Emlak Script Multiple SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-26
GeFORC3 has reported some vulnerabilities in Dora Emlak Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27812/
--
[SA27811] SafeNet Sentinel Protection Server/Key Server Directory Traversal Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-11-27
A vulnerability has been reported in SafeNet Sentinel Protection Server and Key Server, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27811/
--
[SA27803] E-Lite POS Login SQL Injection Vulnerability and User Enumeration
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of system information
Released: 2007-11-26
A vulnerability and a weakness have been reported in E-Lite POS, which can be exploited by malicious people to enumerate valid user accounts or conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27803/
--
[SA27798] My-Time Two SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2007-11-26
Aria-Security Team have reported two vulnerabilities in My-Time (Timesheet), which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27798/
UNIX/Linux:--
[SA27856] rPath update for cups, poppler, and tetex
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-29
rPath has issued an update for cups, poppler, and tetex. This fixes some vulnerabilities, which can be exploited by malicious people to
cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27856/
--
[SA27855] Fedora update for firefox
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-11-29
Fedora has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting and cross-site request forgery attacks or potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27855/
--
[SA27845] Slackware update for firefox
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-11-28
Slackware has issued an update for firefox. This fixes a security issue and some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks or potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27845/
--
[SA27804] Red Hat update for java-1.5.0-ibm
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of system information, Exposure of sensitive information, System access
Released: 2007-11-28
Red Hat has issued an update for java-1.5.0-ibm. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, manipulate data, disclose sensitive/system information, or potentially compromise a vulnerable
system.
Full Advisory:
http://secunia.com/advisories/27804/
--
[SA27797] Red Hat update for firefox
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-11-27
Red Hat has issued an update for firefox. This fixes a security issue and some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks and potentially to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27797/
--
[SA27796] Ubuntu update for firefox
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-11-27
Ubuntu has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting and cross-site request forgery attacks and potentially to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27796/
--
[SA27817] Debian update for wireshark
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-11-27
Debian has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27817/
--
[SA27806] Debian update for tk8.3
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-28
Debian has issued an update for tk8.3. This fixes a vulnerability, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27806/
--
[SA27801] Debian update for tk8.4
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-28
Debian has issued an update for tk8.4. This fixes a vulnerability, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27801/
--
[SA27857] Mandriva update for cpio
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-29
Mandriva has issued an update for cpio. This fixes two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27857/
--
[SA27818] Debian update for ruby1.9
Critical: Less critical
Where: From remote
Impact: Spoofing
Released: 2007-11-26
Debian has issued an update for ruby1.9. This fixes some security issues, which can be exploited by malicious people to conduct spoofing attacks.
Full Advisory:
http://secunia.com/advisories/27818/
--
[SA27830] Samhain Random Number Generator Weakness
Critical: Less critical
Where: From local network
Impact: Brute force, Exposure of sensitive information
Released: 2007-11-27
A weakness has been reported in Samhain, which can be exploited by malicious people to disclose potentially sensitive information and to perform brute force attacks.
Full Advisory:
http://secunia.com/advisories/27830/
--
[SA27823] Debian update for mysql-dfsg, mysql-dfsg-5.0, and mysql-dfsg-4.1
Critical: Less critical
Where: From local network
Impact: Security Bypass, Privilege escalation, DoS
Released: 2007-11-27
Debian has issued an update for mysql-dfsg, mysql-dfsg-5.0, and mysql-dfsg-4.1. This fixes some security issues and vulnerabilities,
which can be exploited by malicious users to bypass certain security restrictions, gain escalated privileges, or cause a DoS (Denial of
Service), and by malicious people to cause a DoS.
Full Advisory:
http://secunia.com/advisories/27823/
--
[SA27860] IBM Lotus Notes Client for Linux Insecure File Permissions
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-29
Some security issues have been reported in Lotus Notes for Linux, which can be exploited by malicious, local users to gain escalated
privileges.
Full Advisory:
http://secunia.com/advisories/27860/
--
[SA27847] Fedora scanbuttond Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-28
Michal Jaegermann has reported a security issue in Fedora, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27847/
--
[SA27841] Audacity Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Manipulation of data, DoS
Released: 2007-11-28
Viktor Griph has reported a security issue in Audacity, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to delete arbitrary files and directories.
Full Advisory:
http://secunia.com/advisories/27841/
--
[SA27858] Ubuntu update for pidgin
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2007-11-29
Ubuntu has issued an update for pidgin. This fixes a weakness, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
http://secunia.com/advisories/27858/
--
[SA27799] Fedora update for blam
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-27
Fedora has issued an update for blam. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27799/
Other:--
[SA27870] Avaya Products OpenSSL Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2007-11-29
Avaya has acknowledged a vulnerability and a weakness in various Avaya products, which can be exploited by malicious, local users to disclose sensitive information and by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27870/
--
[SA27869] Avaya Products PCRE Regex Parsing Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-29
Avaya has acknowledged some vulnerabilities in various Avaya products, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27869/
--
[SA27862] Avaya Products PCRE Character Class Processing Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-29
Avaya has acknowledged a vulnerability in various Avaya products, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27862/
--
[SA27832] Sun Solaris libTIFF Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-29
Sun has acknowledged some vulnerabilities in Sun Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27832/
--
[SA27829] Cisco Unified IP Phone Extension Mobility Weakness
Critical: Not critical
Where: From local network
Impact: Security Bypass
Released: 2007-11-29
Joffrey Czarney has reported a weakness in Cisco Unified IP Phones, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27829/
--
[SA27831] Sun Solaris Remote Procedure Call Module Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-11-29
Sun has acknowledged a vulnerability in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).
Full Advisory:
http://secunia.com/advisories/27831/
Cross Platform:--
[SA27854] Charray's CMS "ccms_library_path" File Inclusion
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-11-29
MhZ91 has discovered two vulnerabilities in Charray's CMS, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27854/
--
[SA27852] PHP_CON "webappcfg[APPPATH]" File Inclusion
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-11-29
GoLd_M has reported a vulnerability in PHP_CON, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27852/
--
[SA27800] Netscape Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-11-28
Netscape has acknowledged some vulnerabilities in Netscape Navigator, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks or potentially to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27800/
--
[SA27866] TuMusika Evolution Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-11-29
Some vulnerabilities have been discovered in TuMusika Evolution, which can be exploited by malicious people to disclose sensitive
information.
Full Advisory:
http://secunia.com/advisories/27866/
--
[SA27848] GNUMP3d Authentication Bypass Security Issue
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2007-11-28
James has reported a security issue in GNUMP3d, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27848/
--
[SA27843] wpQuiz Two SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-28
Kacper has discovered two vulnerabilities in wpQuiz, which can be exploited by malicious people and malicious users to conduct SQL
injection attacks.
Full Advisory:
http://secunia.com/advisories/27843/
--
[SA27825] Ruby-GNOME2 "Gtk::MessageDialog.new()" Format String Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-28
Chris Rohlf has reported a vulnerability in Ruby-GNOME2, which can potentially be exploited by malicious people to compromise an
application using the library.
Full Advisory:
http://secunia.com/advisories/27825/
--
[SA27820] Project Alumni Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2007-11-26
tomplixsee has discovered some vulnerabilities in Project Alumni, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks and to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27820/
--
[SA27816] SeaMonkey Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-11-27
Some vulnerabilities have been reported in Mozilla SeaMonkey, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks and potentially to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27816/
--
[SA27815] Amber Script "id" Local File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-11-26
Crackers_Child has reported a vulnerability in Amber Script, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27815/
--
[SA27810] PHP-Nuke NSN Script Depository Module Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-11-27
KiNgOfThEwOrLd has discovered a vulnerability in the NSN Script Depository module for PHP-Nuke, which can be exploited by malicious
people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27810/
--
[SA27808] Softbiz Freelancers Cross-Site Scripting and SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2007-11-29
IRCRASH (Dr.Crash) has reported some vulnerabilities in Softbiz Freelancers Script, which can be exploited by malicious people to
conduct cross-site scripting and SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27808/
--
[SA27837] @Mail "func" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-29
A vulnerability has been reported in @Mail, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27837/
--
[SA27834] Basic Analysis and Security Engine "base_qry_main.php" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-27
Two vulnerabilities have been reported in Base Analysis and Security Engine, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27834/
--
[SA27828] PHPDevShell Privilege Escalation Vulnerability
Critical: Less critical
Where: From remote
Impact: Privilege escalation
Released: 2007-11-28
A vulnerability has been reported in PHPDevShell, which can be exploited by malicious users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27828/
--
[SA27826] FMDeluxe "id" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-27
Jose Luis Góngora Fernández has discovered a vulnerability in FMDeluxe, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27826/
--
[SA27821] Liferay Portal "emailAddress" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-28
Joshua Morin has reported a vulnerability in Liferay Portal, which can be exploited by malicious people to conduct cross-site scripting
attacks.
Full Advisory:
http://secunia.com/advisories/27821/
--
[SA27814] vBTube "search" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-28
Crackers_Child has reported a vulnerability in vBTube, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27814/
--
[SA27809] PHPSlideshow "directory" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-26
Jose Luis Góngora Fernández has discovered a vulnerability in PHPSlideshow, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27809/
--
[SA27807] JAF CMS Two Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-26
lammat has discovered two vulnerabilities in JAF CMS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27807/
--
[SA27833] ManageEngine EventLog Analyzer Insecure MySQL Installation
Critical: Less critical
Where: From local network
Impact: Security Bypass
Released: 2007-11-28
A security issue has been reported in ManageEngine EventLog Analyzer, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27833/
--
[SA27840] BEA AquaLogic Interaction Plumtree Portal Information Disclosure
Critical: Not critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-11-28
Adrian Pastor and Jan Fry have reported some weaknesses in BEA AquaLogic Interaction, which can be exploited by malicious people to
disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27840/
Windows:--
[SA27849] Autonomy Keyview SDK Lotus 1-2-3 File Viewer Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-29
Some vulnerabilities have been reported in Autonomy Keyview SDK, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27849/
--
[SA27836] IBM Lotus Notes 5 / 6 Lotus 1-2-3 File Viewer Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-27
Some vulnerabilities have been reported in IBM Lotus Notes, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27836/
--
[SA27835] IBM Lotus Notes Lotus 1-2-3 File Viewer Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-11-27
Some vulnerabilities have been reported in IBM Lotus Notes, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27835/
--
[SA27822] DWD Realty Two SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2007-11-27
Aria-Security Team have reported two vulnerabilities in DWD Realty, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27822/
--
[SA27813] NetAuctionHelp Classified Ads Two SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-27
Aria-Security Team have reported two vulnerabilities in NetAuctionHelp Classified Ads, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27813/
--
[SA27812] Dora Emlak Script Multiple SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-26
GeFORC3 has reported some vulnerabilities in Dora Emlak Script, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27812/
--
[SA27811] SafeNet Sentinel Protection Server/Key Server Directory Traversal Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-11-27
A vulnerability has been reported in SafeNet Sentinel Protection Server and Key Server, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27811/
--
[SA27803] E-Lite POS Login SQL Injection Vulnerability and User Enumeration
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of system information
Released: 2007-11-26
A vulnerability and a weakness have been reported in E-Lite POS, which can be exploited by malicious people to enumerate valid user accounts or conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27803/
--
[SA27798] My-Time Two SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2007-11-26
Aria-Security Team have reported two vulnerabilities in My-Time (Timesheet), which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27798/
UNIX/Linux:--
[SA27856] rPath update for cups, poppler, and tetex
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-29
rPath has issued an update for cups, poppler, and tetex. This fixes some vulnerabilities, which can be exploited by malicious people to
cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27856/
--
[SA27855] Fedora update for firefox
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-11-29
Fedora has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting and cross-site request forgery attacks or potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27855/
--
[SA27845] Slackware update for firefox
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-11-28
Slackware has issued an update for firefox. This fixes a security issue and some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks or potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27845/
--
[SA27804] Red Hat update for java-1.5.0-ibm
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of system information, Exposure of sensitive information, System access
Released: 2007-11-28
Red Hat has issued an update for java-1.5.0-ibm. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, manipulate data, disclose sensitive/system information, or potentially compromise a vulnerable
system.
Full Advisory:
http://secunia.com/advisories/27804/
--
[SA27797] Red Hat update for firefox
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-11-27
Red Hat has issued an update for firefox. This fixes a security issue and some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks and potentially to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27797/
--
[SA27796] Ubuntu update for firefox
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-11-27
Ubuntu has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting and cross-site request forgery attacks and potentially to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27796/
--
[SA27817] Debian update for wireshark
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-11-27
Debian has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27817/
--
[SA27806] Debian update for tk8.3
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-28
Debian has issued an update for tk8.3. This fixes a vulnerability, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27806/
--
[SA27801] Debian update for tk8.4
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-28
Debian has issued an update for tk8.4. This fixes a vulnerability, which can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27801/
--
[SA27857] Mandriva update for cpio
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-29
Mandriva has issued an update for cpio. This fixes two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27857/
--
[SA27818] Debian update for ruby1.9
Critical: Less critical
Where: From remote
Impact: Spoofing
Released: 2007-11-26
Debian has issued an update for ruby1.9. This fixes some security issues, which can be exploited by malicious people to conduct spoofing attacks.
Full Advisory:
http://secunia.com/advisories/27818/
--
[SA27830] Samhain Random Number Generator Weakness
Critical: Less critical
Where: From local network
Impact: Brute force, Exposure of sensitive information
Released: 2007-11-27
A weakness has been reported in Samhain, which can be exploited by malicious people to disclose potentially sensitive information and to perform brute force attacks.
Full Advisory:
http://secunia.com/advisories/27830/
--
[SA27823] Debian update for mysql-dfsg, mysql-dfsg-5.0, and mysql-dfsg-4.1
Critical: Less critical
Where: From local network
Impact: Security Bypass, Privilege escalation, DoS
Released: 2007-11-27
Debian has issued an update for mysql-dfsg, mysql-dfsg-5.0, and mysql-dfsg-4.1. This fixes some security issues and vulnerabilities,
which can be exploited by malicious users to bypass certain security restrictions, gain escalated privileges, or cause a DoS (Denial of
Service), and by malicious people to cause a DoS.
Full Advisory:
http://secunia.com/advisories/27823/
--
[SA27860] IBM Lotus Notes Client for Linux Insecure File Permissions
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-29
Some security issues have been reported in Lotus Notes for Linux, which can be exploited by malicious, local users to gain escalated
privileges.
Full Advisory:
http://secunia.com/advisories/27860/
--
[SA27847] Fedora scanbuttond Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-28
Michal Jaegermann has reported a security issue in Fedora, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27847/
--
[SA27841] Audacity Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Manipulation of data, DoS
Released: 2007-11-28
Viktor Griph has reported a security issue in Audacity, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to delete arbitrary files and directories.
Full Advisory:
http://secunia.com/advisories/27841/
--
[SA27858] Ubuntu update for pidgin
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2007-11-29
Ubuntu has issued an update for pidgin. This fixes a weakness, which can be exploited by malicious people to cause a DoS (Denial of
Service).
Full Advisory:
http://secunia.com/advisories/27858/
--
[SA27799] Fedora update for blam
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-11-27
Fedora has issued an update for blam. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27799/
Other:--
[SA27870] Avaya Products OpenSSL Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2007-11-29
Avaya has acknowledged a vulnerability and a weakness in various Avaya products, which can be exploited by malicious, local users to disclose sensitive information and by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27870/
--
[SA27869] Avaya Products PCRE Regex Parsing Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-29
Avaya has acknowledged some vulnerabilities in various Avaya products, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27869/
--
[SA27862] Avaya Products PCRE Character Class Processing Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-29
Avaya has acknowledged a vulnerability in various Avaya products, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27862/
--
[SA27832] Sun Solaris libTIFF Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-29
Sun has acknowledged some vulnerabilities in Sun Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27832/
--
[SA27829] Cisco Unified IP Phone Extension Mobility Weakness
Critical: Not critical
Where: From local network
Impact: Security Bypass
Released: 2007-11-29
Joffrey Czarney has reported a weakness in Cisco Unified IP Phones, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27829/
--
[SA27831] Sun Solaris Remote Procedure Call Module Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-11-29
Sun has acknowledged a vulnerability in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).
Full Advisory:
http://secunia.com/advisories/27831/
Cross Platform:--
[SA27854] Charray's CMS "ccms_library_path" File Inclusion
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-11-29
MhZ91 has discovered two vulnerabilities in Charray's CMS, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27854/
--
[SA27852] PHP_CON "webappcfg[APPPATH]" File Inclusion
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-11-29
GoLd_M has reported a vulnerability in PHP_CON, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27852/
--
[SA27800] Netscape Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-11-28
Netscape has acknowledged some vulnerabilities in Netscape Navigator, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks or potentially to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27800/
--
[SA27866] TuMusika Evolution Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-11-29
Some vulnerabilities have been discovered in TuMusika Evolution, which can be exploited by malicious people to disclose sensitive
information.
Full Advisory:
http://secunia.com/advisories/27866/
--
[SA27848] GNUMP3d Authentication Bypass Security Issue
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2007-11-28
James has reported a security issue in GNUMP3d, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27848/
--
[SA27843] wpQuiz Two SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-28
Kacper has discovered two vulnerabilities in wpQuiz, which can be exploited by malicious people and malicious users to conduct SQL
injection attacks.
Full Advisory:
http://secunia.com/advisories/27843/
--
[SA27825] Ruby-GNOME2 "Gtk::MessageDialog.new()" Format String Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-11-28
Chris Rohlf has reported a vulnerability in Ruby-GNOME2, which can potentially be exploited by malicious people to compromise an
application using the library.
Full Advisory:
http://secunia.com/advisories/27825/
--
[SA27820] Project Alumni Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2007-11-26
tomplixsee has discovered some vulnerabilities in Project Alumni, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks and to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27820/
--
[SA27816] SeaMonkey Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-11-27
Some vulnerabilities have been reported in Mozilla SeaMonkey, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks and potentially to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27816/
--
[SA27815] Amber Script "id" Local File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-11-26
Crackers_Child has reported a vulnerability in Amber Script, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27815/
--
[SA27810] PHP-Nuke NSN Script Depository Module Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-11-27
KiNgOfThEwOrLd has discovered a vulnerability in the NSN Script Depository module for PHP-Nuke, which can be exploited by malicious
people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27810/
--
[SA27808] Softbiz Freelancers Cross-Site Scripting and SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2007-11-29
IRCRASH (Dr.Crash) has reported some vulnerabilities in Softbiz Freelancers Script, which can be exploited by malicious people to
conduct cross-site scripting and SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27808/
--
[SA27837] @Mail "func" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-29
A vulnerability has been reported in @Mail, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27837/
--
[SA27834] Basic Analysis and Security Engine "base_qry_main.php" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-27
Two vulnerabilities have been reported in Base Analysis and Security Engine, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27834/
--
[SA27828] PHPDevShell Privilege Escalation Vulnerability
Critical: Less critical
Where: From remote
Impact: Privilege escalation
Released: 2007-11-28
A vulnerability has been reported in PHPDevShell, which can be exploited by malicious users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27828/
--
[SA27826] FMDeluxe "id" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-27
Jose Luis Góngora Fernández has discovered a vulnerability in FMDeluxe, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27826/
--
[SA27821] Liferay Portal "emailAddress" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-28
Joshua Morin has reported a vulnerability in Liferay Portal, which can be exploited by malicious people to conduct cross-site scripting
attacks.
Full Advisory:
http://secunia.com/advisories/27821/
--
[SA27814] vBTube "search" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-28
Crackers_Child has reported a vulnerability in vBTube, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27814/
--
[SA27809] PHPSlideshow "directory" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-26
Jose Luis Góngora Fernández has discovered a vulnerability in PHPSlideshow, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27809/
--
[SA27807] JAF CMS Two Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-26
lammat has discovered two vulnerabilities in JAF CMS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27807/
--
[SA27833] ManageEngine EventLog Analyzer Insecure MySQL Installation
Critical: Less critical
Where: From local network
Impact: Security Bypass
Released: 2007-11-28
A security issue has been reported in ManageEngine EventLog Analyzer, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27833/
--
[SA27840] BEA AquaLogic Interaction Plumtree Portal Information Disclosure
Critical: Not critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-11-28
Adrian Pastor and Jan Fry have reported some weaknesses in BEA AquaLogic Interaction, which can be exploited by malicious people to
disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27840/

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Secunia 2007 Bulletins
Secunia Vulnerabilities Content Listing For The Week of December 6 2007
Windows:--
[SA27963] Novell BorderManager Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2007-12-06
Some vulnerabilities have been reported in Novell BorderManager, which can be exploited by malicious people to bypass certain security restrictions or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27963/
--
[SA27929] avast! Home/Professional TAR File Processing Heap Corruption
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-05
A vulnerability has been reported in avast! Home/Professional, which can be exploited by malicious people to compromise a vulnerable
system.
Full Advisory:
http://secunia.com/advisories/27929/
--
[SA27930] HTTP File Server File Upload Directory Traversal Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-06
Luigi Auriemma has reported a vulnerability in HTTP File Server, which can be exploited by malicious users to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27930/
--
[SA27923] Absolute News Manager .NET Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2007-12-05
Some vulnerabilities have been reported in Absolute News Manager .NET, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks, or to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27923/
--
[SA27911] Snitz Forums 2000 "BuildTime" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-04
Soroush Dalili has discovered a vulnerability in Snitz Forums, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27911/
--
[SA27947] Cisco Security Agent Unspecified System Driver Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-12-06
A vulnerability has been reported in Cisco Security Agent for Windows, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27947/
--
[SA27917] SonicWALL Global VPN Client Configuration File Format String Vulnerability
Critical: Less critical
Where: From remote
Impact: System access
Released: 2007-12-05
A vulnerability has been discovered in SonicWALL GLobal VPN Client, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27917/
--
[SA27901] Microsoft Web Proxy Auto-Discovery Feature Security Issue
Critical: Less critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information
Released: 2007-12-04
A security issue has been reported in Microsoft's Web Proxy Auto-Discovery (WPAD) feature, which can be exploited by malicious
people to conduct man-in-the-middle (MITM) attacks.
Full Advisory:
http://secunia.com/advisories/27901/
--
[SA27935] Citrix EdgeSight Configuration File Information Disclosure Weakness
Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2007-12-05
A weakness has been reported in Citrix EdgeSight, which can be exploited by malicious, local users to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27935/
UNIX/Linux:--
[SA27944] SUSE update for MozillaFirefox
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-12-06
SUSE has issued an update for MozillaFirefox. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site request forgery and cross-site scripting attacks or potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27944/
--
[SA27933] Mandriva update for openssl
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-05
Mandriva has issued an update for openssl. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27933/
--
[SA27931] Debian update for openoffice.org and hsqldb
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-06
Debian has issued an update for openoffice.org and hsqldb. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27931/
--
[SA27916] Red Hat update for openoffice.org2
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-06
Red Hat has issued an update for openoffice.org2. This fixes a vulnerability, which potentially can be exploited by malicious people
to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27916/
--
[SA27914] Red Hat update for openoffice.org and hsqldb
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-06
Red Hat has issued an update for openoffice.org and hsqldb. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27914/
--
[SA27875] FTP Admin Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of system information, Exposure of sensitive information, System access
Released: 2007-11-30
Omni has discovered some vulnerabilities in FTP Admin, which can be exploited by malicious users to compromise a vulnerable system, and by malicious people to conduct cross-site scripting attacks and bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27875/
--
[SA27965] SUSE Update for Multiple Packages
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, DoS, System access
Released: 2007-12-06
SUSE has issued an update for multiple packages. This fixes a security issue and some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, conduct cross-site scripting attacks, cause a DoS (Denial of Service), and
potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27965/
--
[SA27950] Gentoo update for cacti
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-06
Gentoo has issued an update for cacti. This fixes a vulnerability, which potentially can be exploited by malicious people to conduct SQL
injection attacks.
Full Advisory:
http://secunia.com/advisories/27950/
--
[SA27943] Debian update for wesnoth
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-12-06
Debian has issued an update for wesnoth. This fixes a vulnerability, which can be exploited by malicious people to disclose potentially
sensitive information.
Full Advisory:
http://secunia.com/advisories/27943/
--
[SA27936] Ubuntu update for perl
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-05
Ubuntu has issued an update for perl. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27936/
--
[SA27920] Fedora update for wesnoth
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, DoS, System access
Released: 2007-12-04
Fedora has issued an update for wesnoth. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service), disclose potentially sensitive information, or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27920/
--
[SA27919] Fedora update for kernel
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-04
Fedora has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users and
by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27919/
--
[SA27910] Squid Cache Update Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-04
A vulnerability has been reported in Squid, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27910/
--
[SA27896] Slackware update for rsync
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2007-12-03
Slackware has issued an update for rsync. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27896/
--
[SA27891] Debian update for cacti
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-03
Debian has issued an update for cacti. This fixes a vulnerability, which can be exploited by malicious people to conduct SQL injection
attacks.
Full Advisory:
http://secunia.com/advisories/27891/
--
[SA27888] SUSE update for kernel
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-04
SUSE has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service) and by malicious people to cause a DoS and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27888/
--
[SA27887] Ubuntu update for cairo
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-04
Ubuntu has issued an update for cairo. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27887/
--
[SA27880] Cairo PNG Image Processing Integer Overflow
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-30
A vulnerability has been reported in Cairo, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27880/
--
[SA27927] SUSE update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-06
SUSE has issued an update for samba. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27927/
--
[SA27937] Ubuntu update for mono
Critical: Less critical
Where: From remote
Impact: System access, DoS
Released: 2007-12-05
Ubuntu has issued an update for mono. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27937/
--
[SA27912] SUSE update for kernel
Critical: Less critical
Where: From remote
Impact: Unknown, Security Bypass, Privilege escalation, DoS, System access
Released: 2007-12-04
SUSE has issued an update for the kernel. This fixes a weakness, a security issue, and some vulnerabilities, where one has unknown impacts and others can be exploited by malicious, local users to bypass certain security restrictions, cause a DoS (Denial of Service), and gain escalated privileges, or by malicious people to cause a DoS or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27912/
--
[SA27892] Debian update for asterisk
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-03
Debian has issued an update for asterisk. This fixes a vulnerability, which can be exploited by malicious users to conduct SQL injection
attacks.
Full Advisory:
http://secunia.com/advisories/27892/
--
[SA27890] Red Hat update for htdig
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-04
Red Hat has issued an update for htdig. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory:
http://secunia.com/advisories/27890/
--
[SA27882] Mandriva update for apache
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-12-04
Mandriva has issued an update for apache. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27882/
--
[SA27879] FreeBSD sys_dev_random Random Data Replay Vulnerability
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2007-11-30
A vulnerability has been reported in FreeBSD, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27879/
--
[SA27915] Xen "mov_to_rr" Security Bypass Vulnerability
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2007-12-05
A vulnerability has been reported in Xen, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27915/
--
[SA27913] Red Hat update for kernel
Critical: Less critical
Where: Local system
Impact: Security Bypass, DoS
Released: 2007-12-04
Red Hat has issued an update for the kernel. This fixes some security issues and vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27913/
--
[SA27899] Zsh difflog.pl Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-03
A security issue has been reported in Zsh, which can be exploited by malicious, local users to perform certain actions with escalated
privileges.
Full Advisory:
http://secunia.com/advisories/27899/
--
[SA27897] Claws Mail sylprint.pl Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-03
A security issue has been reported in Claws Mail, which can be exploited by malicious, local users to perform certain actions with
escalated privileges.
Full Advisory:
http://secunia.com/advisories/27897/
--
[SA27948] Debian update for zabbix
Critical: Not critical
Where: From local network
Impact: Privilege escalation
Released: 2007-12-06
Debian has issued an update for zabbix. This fixes a weakness, which can be exploited by malicious users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27948/
--
[SA27903] Zabbix "UserParameter" Privilege Escalation Weakness
Critical: Not critical
Where: From local network
Impact: Privilege escalation
Released: 2007-12-03
A weakness has been reported in Zabbix, which can be exploited by malicious users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27903/
--
[SA27952] Gentoo update for hugin
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-06
Gentoo has issued an update for hugin. This fixes a security issue, which can be exploited by malicious, local users to perform certain
actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27952/
--
[SA27939] OpenVMS for Integrity Servers Denial of Service Vulnerabilities
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-12-05
Some vulnerabilities have been reported in OpenVMS for Integrity Servers, which can be exploited by malicious, local users to cause a
DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27939/
--
[SA27921] Avaya Products Xterm Security Bypass Security Issue
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2007-12-05
Avaya has acknowledged a security issue in various Avaya products, which potentially can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27921/
--
[SA27908] Linux Kernel "do_coredump()" Information Disclosure
Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2007-12-05
A security issue has been reported in the Linux Kernel, which can be exploited by malicious, local users to disclose potentially sensitive
information.
Full Advisory:
http://secunia.com/advisories/27908/
--
[SA27886] Mandriva update for vixie-cron
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-12-04
Mandriva has issued an update for vixie-cron. This fixes a vulnerability, which can be exploited by malicious, local users to
cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27886/
--
[SA27884] Mac OS X Local Denial of Service Vulnerability
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-12-05
A vulnerability has been discovered in Mac OS X, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27884/
--
[SA27877] Solaris 10 Linux Branded Zones Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-12-03
A vulnerability has been reported in Solaris 10, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27877/
Other:--
[SA27904] F5 FirePass 4100 SSL VPN Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-03
Some vulnerabilities have been reported in F5 FirePass 4100 SSL VPN, which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory:
http://secunia.com/advisories/27904/
--
[SA27898] Cisco IP Phone 7940 SIP INVITE Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-12-06
The Madynes research team has reported a vulnerability in Cisco IP Phone 7940, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27898/
--
[SA27926] Sun SPARC Enterprise XCP Firmware Denial Of Service Vulnerabilities
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-12-05
Some vulnerabilities have been reported in the XSCF Control Package (XCP) firmware for Sun SPARC Enterprise M4000/M5000/M8000/M9000, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27926/
--
[SA27945] Nokia N95 SIP Message Processing Denial of Service Weakness
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2007-12-06
Humberto J. Abdelnur, Radu State, and Olivier Festor have reported a weakness in Nokia N95, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27945/
Cross Platform:--
[SA27928] OpenOffice Database Document Processing Unspecified Code Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-05
A vulnerability has been reported in OpenOffice, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27928/
--
[SA27895] tellmatic "tm_includepath" File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-03
ShAy6oOoN has discovered some vulnerabilities in tellmatic, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27895/
--
[SA27878] VLC Media Player ActiveX Plugin and FLAC Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-03
Some vulnerabilities have been reported in VLC Media Player, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27878/
--
[SA27876] p.mapper "_SESSION[PM_INCPHP]" File Inclusion
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-12-03
ShAy6oOoN has reported a vulnerability in p.mapper, which can be exploited by malicious people to disclose sensitive information or to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27876/
--
[SA27951] vbDrupal "taxonomy_select_nodes()" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-06
A vulnerability has been reported in vbDrupal, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27951/
--
[SA27949] SineCms SQL Injection and Script Insertion
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2007-12-06
KiNgOfThEwOrLd has discovered some vulnerabilities in SineCms, which can be exploited by malicious people to conduct script insertion and SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27949/
--
[SA27932] Drupal "taxonomy_select_nodes()" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-06
A vulnerability has been reported in Drupal, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27932/
--
[SA27924] HP Select Identity Unspecified Unauthorised Access Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2007-12-05
A vulnerability has been reported in HP Select Identity, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27924/
--
[SA27909] Beehive Forum SQL Injection and Unspecified Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Manipulation of data, Exposure of sensitive information
Released: 2007-12-04
Some vulnerabilities have been reported in Beehive Forum, some with unknown impact and one which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27909/
--
[SA27905] Typespeed Division By Zero Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-03
A vulnerability has been reported in Typespeed, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27905/
--
[SA27881] Seditio "pag_sub[]" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-11-30
InATeam have discovered a vulnerability in Seditio, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27881/
--
[SA27873] Asterisk Postgres Realtime Engine SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-30
A vulnerability has been reported in Asterisk, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27873/
--
[SA27953] Drupal Shoutbox Module Script Insertion Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-06
Some vulnerabilities have been reported in the Shoutbox module for Drupal, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/27953/
--
[SA27941] IBM Lotus Sametime Meeting WebRunMenuFrame Page Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-06
A vulnerability has been reported in IBM Lotus Sametime, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27941/
--
[SA27925] Jetty Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Hijacking
Released: 2007-12-05
Some vulnerabilities have been reported in Jetty, which can be exploited by malicious people to conduct HTTP response splitting and
cross-site scripting attacks and potentially hijack a user session.
Full Advisory:
http://secunia.com/advisories/27925/
--
[SA27918] Fusion News Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-06
A vulnerability has been reported in Fusion News, which can be exploited by malicious users to conduct cross-site request forgery
attacks.
Full Advisory:
http://secunia.com/advisories/27918/
--
[SA27906] Apache HTTP Method Request Entity Too Large Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-03
Adrian Pastor and Amir Azam have discovered a vulnerability in Apache, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27906/
--
[SA27902] CiscoWorks Common Services Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-06
Dave Lewis has reported a vulnerability in CiscoWorks Common Services, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27902/
--
[SA27900] IBM Tivoli Netcool Security Manager Unspecified Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-03
A vulnerability has been reported in IBM Tivoli Netcool Security Manager, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27900/
--
[SA27889] e2fsprogs libext2fs Integer Overflow Vulnerabilities
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-06
Some vulnerabilities have been reported in the libext2fs library of e2fsprogs, which potentially can be exploited by malicious people to
compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27889/
--
[SA27883] Hitachi JP1/Cm2/Network Node Manager Unspecified Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-30
A vulnerability has been reported in Hitachi JP1/Cm2/Network Node Manager, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27883/
--
[SA27874] CRM-CTT "CheckCustomerAccess()" Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-12-03
A security issue has been reported in CRM-CTT, which can be exploited by malicious users to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27874/
--
[SA27907] Firefox Charset Inheritance Cross-Site Scripting Security Issue
Critical: Not critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-04
Paul Szabo has discovered a security issue in Firefox, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27907/
Windows:--
[SA27963] Novell BorderManager Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2007-12-06
Some vulnerabilities have been reported in Novell BorderManager, which can be exploited by malicious people to bypass certain security restrictions or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27963/
--
[SA27929] avast! Home/Professional TAR File Processing Heap Corruption
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-05
A vulnerability has been reported in avast! Home/Professional, which can be exploited by malicious people to compromise a vulnerable
system.
Full Advisory:
http://secunia.com/advisories/27929/
--
[SA27930] HTTP File Server File Upload Directory Traversal Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-06
Luigi Auriemma has reported a vulnerability in HTTP File Server, which can be exploited by malicious users to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27930/
--
[SA27923] Absolute News Manager .NET Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2007-12-05
Some vulnerabilities have been reported in Absolute News Manager .NET, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks, or to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27923/
--
[SA27911] Snitz Forums 2000 "BuildTime" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-04
Soroush Dalili has discovered a vulnerability in Snitz Forums, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27911/
--
[SA27947] Cisco Security Agent Unspecified System Driver Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-12-06
A vulnerability has been reported in Cisco Security Agent for Windows, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27947/
--
[SA27917] SonicWALL Global VPN Client Configuration File Format String Vulnerability
Critical: Less critical
Where: From remote
Impact: System access
Released: 2007-12-05
A vulnerability has been discovered in SonicWALL GLobal VPN Client, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27917/
--
[SA27901] Microsoft Web Proxy Auto-Discovery Feature Security Issue
Critical: Less critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information
Released: 2007-12-04
A security issue has been reported in Microsoft's Web Proxy Auto-Discovery (WPAD) feature, which can be exploited by malicious
people to conduct man-in-the-middle (MITM) attacks.
Full Advisory:
http://secunia.com/advisories/27901/
--
[SA27935] Citrix EdgeSight Configuration File Information Disclosure Weakness
Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2007-12-05
A weakness has been reported in Citrix EdgeSight, which can be exploited by malicious, local users to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/27935/
UNIX/Linux:--
[SA27944] SUSE update for MozillaFirefox
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-12-06
SUSE has issued an update for MozillaFirefox. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site request forgery and cross-site scripting attacks or potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27944/
--
[SA27933] Mandriva update for openssl
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-05
Mandriva has issued an update for openssl. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27933/
--
[SA27931] Debian update for openoffice.org and hsqldb
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-06
Debian has issued an update for openoffice.org and hsqldb. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27931/
--
[SA27916] Red Hat update for openoffice.org2
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-06
Red Hat has issued an update for openoffice.org2. This fixes a vulnerability, which potentially can be exploited by malicious people
to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27916/
--
[SA27914] Red Hat update for openoffice.org and hsqldb
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-06
Red Hat has issued an update for openoffice.org and hsqldb. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27914/
--
[SA27875] FTP Admin Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of system information, Exposure of sensitive information, System access
Released: 2007-11-30
Omni has discovered some vulnerabilities in FTP Admin, which can be exploited by malicious users to compromise a vulnerable system, and by malicious people to conduct cross-site scripting attacks and bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27875/
--
[SA27965] SUSE Update for Multiple Packages
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, DoS, System access
Released: 2007-12-06
SUSE has issued an update for multiple packages. This fixes a security issue and some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, conduct cross-site scripting attacks, cause a DoS (Denial of Service), and
potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27965/
--
[SA27950] Gentoo update for cacti
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-06
Gentoo has issued an update for cacti. This fixes a vulnerability, which potentially can be exploited by malicious people to conduct SQL
injection attacks.
Full Advisory:
http://secunia.com/advisories/27950/
--
[SA27943] Debian update for wesnoth
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-12-06
Debian has issued an update for wesnoth. This fixes a vulnerability, which can be exploited by malicious people to disclose potentially
sensitive information.
Full Advisory:
http://secunia.com/advisories/27943/
--
[SA27936] Ubuntu update for perl
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-05
Ubuntu has issued an update for perl. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27936/
--
[SA27920] Fedora update for wesnoth
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, DoS, System access
Released: 2007-12-04
Fedora has issued an update for wesnoth. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service), disclose potentially sensitive information, or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27920/
--
[SA27919] Fedora update for kernel
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-04
Fedora has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users and
by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27919/
--
[SA27910] Squid Cache Update Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-04
A vulnerability has been reported in Squid, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27910/
--
[SA27896] Slackware update for rsync
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2007-12-03
Slackware has issued an update for rsync. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27896/
--
[SA27891] Debian update for cacti
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-03
Debian has issued an update for cacti. This fixes a vulnerability, which can be exploited by malicious people to conduct SQL injection
attacks.
Full Advisory:
http://secunia.com/advisories/27891/
--
[SA27888] SUSE update for kernel
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-04
SUSE has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service) and by malicious people to cause a DoS and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27888/
--
[SA27887] Ubuntu update for cairo
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-04
Ubuntu has issued an update for cairo. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27887/
--
[SA27880] Cairo PNG Image Processing Integer Overflow
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-11-30
A vulnerability has been reported in Cairo, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27880/
--
[SA27927] SUSE update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-06
SUSE has issued an update for samba. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27927/
--
[SA27937] Ubuntu update for mono
Critical: Less critical
Where: From remote
Impact: System access, DoS
Released: 2007-12-05
Ubuntu has issued an update for mono. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27937/
--
[SA27912] SUSE update for kernel
Critical: Less critical
Where: From remote
Impact: Unknown, Security Bypass, Privilege escalation, DoS, System access
Released: 2007-12-04
SUSE has issued an update for the kernel. This fixes a weakness, a security issue, and some vulnerabilities, where one has unknown impacts and others can be exploited by malicious, local users to bypass certain security restrictions, cause a DoS (Denial of Service), and gain escalated privileges, or by malicious people to cause a DoS or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27912/
--
[SA27892] Debian update for asterisk
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-03
Debian has issued an update for asterisk. This fixes a vulnerability, which can be exploited by malicious users to conduct SQL injection
attacks.
Full Advisory:
http://secunia.com/advisories/27892/
--
[SA27890] Red Hat update for htdig
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-04
Red Hat has issued an update for htdig. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory:
http://secunia.com/advisories/27890/
--
[SA27882] Mandriva update for apache
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-12-04
Mandriva has issued an update for apache. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27882/
--
[SA27879] FreeBSD sys_dev_random Random Data Replay Vulnerability
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2007-11-30
A vulnerability has been reported in FreeBSD, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27879/
--
[SA27915] Xen "mov_to_rr" Security Bypass Vulnerability
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2007-12-05
A vulnerability has been reported in Xen, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27915/
--
[SA27913] Red Hat update for kernel
Critical: Less critical
Where: Local system
Impact: Security Bypass, DoS
Released: 2007-12-04
Red Hat has issued an update for the kernel. This fixes some security issues and vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27913/
--
[SA27899] Zsh difflog.pl Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-03
A security issue has been reported in Zsh, which can be exploited by malicious, local users to perform certain actions with escalated
privileges.
Full Advisory:
http://secunia.com/advisories/27899/
--
[SA27897] Claws Mail sylprint.pl Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-03
A security issue has been reported in Claws Mail, which can be exploited by malicious, local users to perform certain actions with
escalated privileges.
Full Advisory:
http://secunia.com/advisories/27897/
--
[SA27948] Debian update for zabbix
Critical: Not critical
Where: From local network
Impact: Privilege escalation
Released: 2007-12-06
Debian has issued an update for zabbix. This fixes a weakness, which can be exploited by malicious users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27948/
--
[SA27903] Zabbix "UserParameter" Privilege Escalation Weakness
Critical: Not critical
Where: From local network
Impact: Privilege escalation
Released: 2007-12-03
A weakness has been reported in Zabbix, which can be exploited by malicious users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27903/
--
[SA27952] Gentoo update for hugin
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-06
Gentoo has issued an update for hugin. This fixes a security issue, which can be exploited by malicious, local users to perform certain
actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27952/
--
[SA27939] OpenVMS for Integrity Servers Denial of Service Vulnerabilities
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-12-05
Some vulnerabilities have been reported in OpenVMS for Integrity Servers, which can be exploited by malicious, local users to cause a
DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27939/
--
[SA27921] Avaya Products Xterm Security Bypass Security Issue
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2007-12-05
Avaya has acknowledged a security issue in various Avaya products, which potentially can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27921/
--
[SA27908] Linux Kernel "do_coredump()" Information Disclosure
Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2007-12-05
A security issue has been reported in the Linux Kernel, which can be exploited by malicious, local users to disclose potentially sensitive
information.
Full Advisory:
http://secunia.com/advisories/27908/
--
[SA27886] Mandriva update for vixie-cron
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-12-04
Mandriva has issued an update for vixie-cron. This fixes a vulnerability, which can be exploited by malicious, local users to
cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27886/
--
[SA27884] Mac OS X Local Denial of Service Vulnerability
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-12-05
A vulnerability has been discovered in Mac OS X, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27884/
--
[SA27877] Solaris 10 Linux Branded Zones Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-12-03
A vulnerability has been reported in Solaris 10, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27877/
Other:--
[SA27904] F5 FirePass 4100 SSL VPN Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-03
Some vulnerabilities have been reported in F5 FirePass 4100 SSL VPN, which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory:
http://secunia.com/advisories/27904/
--
[SA27898] Cisco IP Phone 7940 SIP INVITE Denial of Service Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-12-06
The Madynes research team has reported a vulnerability in Cisco IP Phone 7940, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27898/
--
[SA27926] Sun SPARC Enterprise XCP Firmware Denial Of Service Vulnerabilities
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-12-05
Some vulnerabilities have been reported in the XSCF Control Package (XCP) firmware for Sun SPARC Enterprise M4000/M5000/M8000/M9000, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27926/
--
[SA27945] Nokia N95 SIP Message Processing Denial of Service Weakness
Critical: Not critical
Where: From remote
Impact: DoS
Released: 2007-12-06
Humberto J. Abdelnur, Radu State, and Olivier Festor have reported a weakness in Nokia N95, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27945/
Cross Platform:--
[SA27928] OpenOffice Database Document Processing Unspecified Code Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-05
A vulnerability has been reported in OpenOffice, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27928/
--
[SA27895] tellmatic "tm_includepath" File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-03
ShAy6oOoN has discovered some vulnerabilities in tellmatic, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27895/
--
[SA27878] VLC Media Player ActiveX Plugin and FLAC Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-03
Some vulnerabilities have been reported in VLC Media Player, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27878/
--
[SA27876] p.mapper "_SESSION[PM_INCPHP]" File Inclusion
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-12-03
ShAy6oOoN has reported a vulnerability in p.mapper, which can be exploited by malicious people to disclose sensitive information or to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27876/
--
[SA27951] vbDrupal "taxonomy_select_nodes()" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-06
A vulnerability has been reported in vbDrupal, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27951/
--
[SA27949] SineCms SQL Injection and Script Insertion
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2007-12-06
KiNgOfThEwOrLd has discovered some vulnerabilities in SineCms, which can be exploited by malicious people to conduct script insertion and SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27949/
--
[SA27932] Drupal "taxonomy_select_nodes()" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-06
A vulnerability has been reported in Drupal, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27932/
--
[SA27924] HP Select Identity Unspecified Unauthorised Access Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2007-12-05
A vulnerability has been reported in HP Select Identity, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27924/
--
[SA27909] Beehive Forum SQL Injection and Unspecified Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Manipulation of data, Exposure of sensitive information
Released: 2007-12-04
Some vulnerabilities have been reported in Beehive Forum, some with unknown impact and one which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27909/
--
[SA27905] Typespeed Division By Zero Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-03
A vulnerability has been reported in Typespeed, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27905/
--
[SA27881] Seditio "pag_sub[]" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-11-30
InATeam have discovered a vulnerability in Seditio, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27881/
--
[SA27873] Asterisk Postgres Realtime Engine SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-11-30
A vulnerability has been reported in Asterisk, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27873/
--
[SA27953] Drupal Shoutbox Module Script Insertion Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-06
Some vulnerabilities have been reported in the Shoutbox module for Drupal, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/27953/
--
[SA27941] IBM Lotus Sametime Meeting WebRunMenuFrame Page Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-06
A vulnerability has been reported in IBM Lotus Sametime, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27941/
--
[SA27925] Jetty Multiple Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Hijacking
Released: 2007-12-05
Some vulnerabilities have been reported in Jetty, which can be exploited by malicious people to conduct HTTP response splitting and
cross-site scripting attacks and potentially hijack a user session.
Full Advisory:
http://secunia.com/advisories/27925/
--
[SA27918] Fusion News Cross-Site Request Forgery
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-06
A vulnerability has been reported in Fusion News, which can be exploited by malicious users to conduct cross-site request forgery
attacks.
Full Advisory:
http://secunia.com/advisories/27918/
--
[SA27906] Apache HTTP Method Request Entity Too Large Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-03
Adrian Pastor and Amir Azam have discovered a vulnerability in Apache, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27906/
--
[SA27902] CiscoWorks Common Services Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-06
Dave Lewis has reported a vulnerability in CiscoWorks Common Services, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27902/
--
[SA27900] IBM Tivoli Netcool Security Manager Unspecified Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-03
A vulnerability has been reported in IBM Tivoli Netcool Security Manager, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27900/
--
[SA27889] e2fsprogs libext2fs Integer Overflow Vulnerabilities
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-06
Some vulnerabilities have been reported in the libext2fs library of e2fsprogs, which potentially can be exploited by malicious people to
compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27889/
--
[SA27883] Hitachi JP1/Cm2/Network Node Manager Unspecified Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-11-30
A vulnerability has been reported in Hitachi JP1/Cm2/Network Node Manager, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27883/
--
[SA27874] CRM-CTT "CheckCustomerAccess()" Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-12-03
A security issue has been reported in CRM-CTT, which can be exploited by malicious users to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/27874/
--
[SA27907] Firefox Charset Inheritance Cross-Site Scripting Security Issue
Critical: Not critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-04
Paul Szabo has discovered a security issue in Firefox, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27907/
Last edited by Tami on Thu Dec 06, 2007 6:21 pm, edited 1 time in total.

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Secunia 2007 Bulletins
Secunia Vulnerabilities Content Listing For The Week of December 13 2007
Windows:--
[SA28036] Internet Explorer Multiple Code Execution Vulnerabilities
Critical: Extremely critical
Where: From remote
Impact: System access
Released: 2007-12-11
Some vulnerabilities have been reported in Internet Explorer, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28036/
--
[SA27992] JustSystems Ichitaro Document Processing Buffer Overflow
Critical: Extremely critical
Where: From remote
Impact: System access
Released: 2007-12-13
A vulnerability has been reported in JustSystems Ichitaro, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27992/
--
[SA28055] HP Info Center HPInfo Class ActiveX Control Insecure Methods
Critical: Highly critical
Where: From remote
Impact: Manipulation of data, Exposure of system information, System access
Released: 2007-12-12
porkythepig has reported some vulnerabilities in HP Info Center, which can be exploited by malicious people to gain knowledge of certain system information, manipulate registry data, and to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28055/
--
[SA28034] Windows Media Format Runtime ASF Parsing Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-11
IBM X-Force has reported four vulnerabilities in Windows Media Format Runtime / Windows Media Services, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28034/
--
[SA28031] BadBlue Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, System access
Released: 2007-12-11
Luigi Auriemma has reported some vulnerabilities in BadBlue, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, and compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28031/
--
[SA28010] Microsoft DirectX SAMI/WAV/AVI File Parsing Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-11
Two vulnerabilities have been reported in Microsoft DirectX, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28010/
--
[SA27998] 3ivx MPEG-4 MP4 File Processing Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-10
SYS 49152 has discovered some vulnerabilities in 3ivx MPEG-4, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27998/
--
[SA28038] Trend Micro Products UUE File Parsing Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-12
Sowhat has reported a vulnerability in some Trend Micro products, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28038/
--
[SA28032] BarracudaDrive Web Server Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of system information, Exposure of sensitive information, DoS
Released: 2007-12-11
Luigi Auriemma has reported some vulnerabilities in BarracudaDrive Web Server, which can be exploited by malicious users to manipulate certain data and cause a DoS (Denial of Service), and by malicious people to conduct script insertion attacks and disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28032/
--
[SA28007] Easy File Sharing Web Server Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2007-12-10
Luigi Auriemma has reported some vulnerabilities in Easy File Sharing Web Server, which can be exploited by malicious people to disclose sensitive information and by malicious users to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28007/
--
[SA27976] PenPal Three SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-07
Aria-Security Team have reported some vulnerabilities in PenPal, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27976/
--
[SA28051] Microsoft Windows Message Queuing Buffer Overflow
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-11
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28051/
--
[SA27997] Microsoft Windows Vista SMBv2 Signing Vulnerability
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-11
A vulnerability has been reported in Microsoft Windows Vista, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27997/
--
[SA28019] Websense "username" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-11
Dave Lewis has reported a vulnerability in Websense Enterprise and Websense Web Security Suite, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28019/
--
[SA28015] Windows Vista Kernel Legacy Reply Path Validation Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-11
A vulnerability has been reported in Microsoft Windows Vista, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/28015/
--
[SA28011] Microsoft Windows Message Queuing Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-11
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/28011/
--
[SA28072] Kerio WinRoute Firewall Proxy Server Unspecified Security Bypass
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2007-12-13
A weakness has been reported in Kerio WinRoute Firewall, which potentially can be exploited by malicious, local users to bypass
certain security restrictions.
Full Advisory:
http://secunia.com/advisories/28072/
UNIX/Linux:--
[SA28068] Sun Solaris update for Adobe Flash Player
Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2007-12-12
Sun has issued an update for Adobe Flash Player. This fixes some vulnerabilities, which can be exploited by malicious people to gain
knowledge of sensitive information or compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28068/
--
[SA28056] Red Hat update for java-1.4.2-bea
Critical: Highly critical
Where: From remote
Impact: System access, DoS
Released: 2007-12-12
Red Hat has issued an update for java-1.4.2-bea. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28056/
--
[SA28043] Fedora update for poppler
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-11
Fedora has issued an update for poppler. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28043/
--
[SA28039] SUSE update for OpenOffice_org
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-11
SUSE has issued an update for OpenOffice_org. This fixes a vulnerability, which can be exploited by malicious people to compromise
a user's system.
Full Advisory:
http://secunia.com/advisories/28039/
--
[SA28001] Debian update for iceweasel
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-12-10
Debian has issued an update for iceweasel. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site request forgery and cross-site scripting attacks or potentially to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28001/
--
[SA27979] Fedora update for seamonkey
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-12-10
Fedora has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting and cross-site request forgery attacks and potentially to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27979/
--
[SA27972] Fedora update for openoffice.org
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-10
Fedora has issued an update for openoffice.org. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27972/
--
[SA28060] Debian update for ruby-gnome2
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-12
Debian has issued an update for ruby-gnome2. This fixes a vulnerability, which potentially can be exploited by malicious people
to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28060/
--
[SA28050] Red Hat update for python
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2007-12-11
Red Hat has issued an update for python. This fixes a security issue and a vulnerability, which can be exploited by malicious people to disclose potentially sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28050/
--
[SA28044] IBM AIX Multiple Unspecified Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2007-12-12
Multiple vulnerabilities have been reported in IBM AIX, which have unknown impacts.
Full Advisory:
http://secunia.com/advisories/28044/
--
[SA28041] Avaya Products PCRE Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2007-12-13
Avaya has acknowledged some vulnerabilities in various Avaya products, which can be exploited by malicious people to disclose sensitive information, cause a DoS (Denial of Service), or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28041/
--
[SA28033] Debian update for kernel
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-11
Debian has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users and
by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28033/
--
[SA28027] Red Hat update for python
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2007-12-11
Red Hat has issued an update for python. This fixes some security issues and a vulnerability, which can be exploited by malicious people to disclose potentially sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28027/
--
[SA28022] Gentoo update for ruby-gtk2
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-10
Gentoo has issued an update for ruby-gtk2. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28022/
--
[SA28021] Gentoo update for emul-linux-x86-qtlibs
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-10
Gentoo has issued an update for emul-linux-x86-qtlibs. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28021/
--
[SA28008] Debian update for sitebar
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information, System access
Released: 2007-12-10
Debian has issued an update for sitebar. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting attacks, and by malicious users to disclose potentially sensitive information and compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28008/
--
[SA28002] wwwstats "link" Script Insertion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-10
Jesus Olmos Gonzalez has reported a vulnerability in wwwstats, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/28002/
--
[SA27996] Debian update for qt-x11-free
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-10
Debian has issued an update for qt-x11-free. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27996/
--
[SA27989] Fedora update for eggdrop
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-11
Fedora has issued an update for eggdrop. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27989/
--
[SA27985] Gentoo update for cairo
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-10
Gentoo has issued an update for cairo. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27985/
--
[SA27984] Gentoo update for emacs
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-10
Gentoo has issued an update for emacs. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27984/
--
[SA27975] Fedora update for ruby-gnome
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-10
Fedora has issued an update for ruby-gnome. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27975/
--
[SA27973] Fedora update for drupal
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-10
Fedora has issued an update for drupal. This fixes a vulnerability, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27973/
--
[SA28067] Mandriva update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-12
Mandriva has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28067/
--
[SA28029] Gentoo update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-11
Gentoo has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28029/
--
[SA28028] rPath update for samba and samba-swat
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-11
rPath has issued an update for samba and samba-swat. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28028/
--
[SA28003] SUSE update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-12
SUSE has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28003/
--
[SA27999] Debian update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-11
Debian has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27999/
--
[SA27993] Slackware update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-11
Slackware has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27993/
--
[SA27982] Gentoo update for firebird
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-10
Gentoo has issued an update for firebird. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27982/
--
[SA27977] Fedora update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-11
Fedora has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27977/
--
[SA28062] Debian update for htdig
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-12
Debian has issued an update for htdig. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory:
http://secunia.com/advisories/28062/
--
[SA28061] Debian update for libnss-ldap
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-12
Debian has issued an update for nss-ldap. This fixes a security issue, which can be exploited by malicious persons to manipulate certain data.
Full Advisory:
http://secunia.com/advisories/28061/
--
[SA28042] Mandriva update for e2fsprogs
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-11
Mandriva has issued an update for e2fsprogs. This fixes a vulnerability, which potentially can be exploited by malicious people
to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28042/
--
[SA28030] rPath update for e2fsprogs
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-12
rPath has issued an update for e2fsprogs. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28030/
--
[SA28000] Ubuntu update for e2fsprogs
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-10
Ubuntu has issued an update for e2fsprogs. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28000/
--
[SA27987] Debian update for e2fsprogs
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-10
Debian has issued an update for e2fsprogs. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27987/
--
[SA27983] Gentoo update for PEAR-MDB2
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-12-10
Gentoo has issued an update for PEAR-MDB2. This fixes a security issue, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27983/
--
[SA27980] Fedora update for nagios
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-10
Fedora has issued an update for nagios. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory:
http://secunia.com/advisories/27980/
--
[SA27971] Avaya Products Apache mod_proxy "date" Denial of Service
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-12-07
Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27971/
--
[SA27967] Ubuntu update for tetex-bin and texlive-bin
Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-12-07
Ubuntu has issued an update for tetex-bin and texlive-bin. This fixes some vulnerabilities, which can be exploited by malicious, local users to disclose and manipulate sensitive information and by malicious people to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27967/
--
[SA28040] Mandriva update for MySQL
Critical: Less critical
Where: From local network
Impact: Security Bypass, Manipulation of data, DoS
Released: 2007-12-11
Mandriva has issued an update for MySQL. This fixes some vulnerabilities, which can be exploited by malicious, local users to
manipulate certain data and by malicious users to bypass certain security restrictions or cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28040/
--
[SA28052] Red Hat autofs "/net" Privilege Escalation Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-12
A vulnerability has been reported in Red Hat Enterprise Linux, which can be exploited by malicious, local users to gain escalated
privileges.
Full Advisory:
http://secunia.com/advisories/28052/
--
[SA28023] Gentoo update for lookup
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-10
Gentoo has issued an update for lookup. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/28023/
--
[SA28004] Fedora update for xorg-x11-xfs
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-11
Fedora has issued an update for xorg-x11-xfs. This fixes some vulnerabilities, which can be exploited by malicious, local users to
gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/28004/
--
[SA27978] Fedora update for zabbix
Critical: Not critical
Where: From local network
Impact: Privilege escalation
Released: 2007-12-10
Fedora has issued an update for zabbix. This fixes a weakness, which can be exploited by malicious users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27978/
--
[SA28070] Linux Kernel "mmap_min_addr" Security Bypass
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2007-12-12
A security issue has been reported in the Linux Kernel, which can be exploited by malicious, local users to bypass certain security
restrictions.
Full Advisory:
http://secunia.com/advisories/28070/
--
[SA28057] Avaya CMS / IR Solaris Remote Procedure Call Module Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-12-12
Avaya has acknowledged a vulnerability in Avaya CMS / IR, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28057/
--
[SA28048] Mac OS X "cs_validate_page()" Local Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-12-13
mu-b has reported a vulnerability in Mac OS X, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28048/
Other:--
[SA27970] IBM HMC Version 3 Privilege Escalation Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-07
Some vulnerabilities have been reported in IBM HMC, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27970/
Cross Platform:--
[SA28066] ViArt CMS/HelpDesk/Shop "root_folder_path" File Inclusion
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-12-12
RoMaNcYxHaCkEr has discovered a vulnerability in various ViArt products, which can be exploited by malicious people to disclose
sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28066/
--
[SA28058] CityWriter "path" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-13
RoMaNcYxHaCkEr has discovered a vulnerability in CityWriter, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28058/
--
[SA28054] Fastpublish CMS designconfig.php File Inclusion
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-12-13
RoMaNcYxHaCkEr has discovered a vulnerability in Fastpublish CMS, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28054/
--
[SA28047] Falcon Series One Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2007-12-11
MhZ91 has reported some vulnerabilities in Falcon Series One, which can be exploited by malicious people to conduct script insertion and cross-site request forgery attacks and to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28047/
--
[SA28018] Sun StarOffice/StarSuite Database Document Processing Arbitrary Java Method Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-10
Sun has acknowledged a vulnerability in Sun StarOffice and StarSuite, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28018/
--
[SA27974] Novell NetMail AntiVirus Agent Integer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-07
A vulnerability has been reported in Novell NetMail, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27974/
--
[SA28080] Robocode Arbitrary Java Code Execution Security Issue
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2007-12-13
A security issue has been reported in Robocode, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/28080/
--
[SA28075] MMS Gallery PHP "id" File Inclusion Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-12-13
GoLd_M has reported some vulnerabilities in MMS Gallery PHP, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28075/
--
[SA28071] xml2owl "file" Information Disclosure Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-12-13
GoLd_M has discovered a vulnerability in xml2owl, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28071/
--
[SA28053] Mcms Easy Web Make "template" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-12-12
MhZ91 has discovered a vulnerability in Mcms Easy Web Make, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28053/
--
[SA28045] Falt4 CMS Cross-Site Scripting and SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2007-12-11
Mesut Timur has reported some vulnerabilities in Falt4 CMS, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28045/
--
[SA28035] Cybozu Office Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2007-12-11
Some vulnerabilities have been reported in Cybozu Office, which can be exploited by malicious people to conduct cross-site scripting attacks, HTTP header injection attacks, or cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28035/
--
[SA28014] aurora framework "pack_var()" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-12
A vulnerability has been reported in aurora framework, which can be exploited by malicious people to conduct SQL injection attacks against applications using the framework.
Full Advisory:
http://secunia.com/advisories/28014/
--
[SA28013] PolDoc Document Management System "filename" Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-12-10
GoLd_M has discovered a vulnerability in PolDoc Document Management System (PDDMS), which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28013/
--
[SA27990] DWdirectory "search" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-10
t0pP8uZz & xprog have reported a vulnerability in DWdirectory, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27990/
--
[SA27988] Ace Image Hosting Script "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-10
t0pP8uZz & xprog have reported a vulnerability in Ace Image Hosting Script, which can be exploited by malicious people to conduct SQL injections attacks.
Full Advisory:
http://secunia.com/advisories/27988/
--
[SA27986] Content Injector "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-12-10
S.W.A.T. has discovered a vulnerability in Content Injector, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27986/
--
[SA28082] Hitachi Web Server Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-13
Hitachi has acknowledged some vulnerabilities in the Hitachi Web Server, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28082/
--
[SA28081] Apache mod_imap Module Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-13
A vulnerability has been reported in the mod_imap module for Apache, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28081/
--
[SA28078] BEA WebLogic Mobility Server Image Converter Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-12-13
A vulnerability has been reported in the BEA WebLogic Mobility Server, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/28078/
--
[SA28077] JBoss Seam "order" EJBQL Injection Vulnerability
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-13
A vulnerability has been reported in JBoss Seam, which potentially can be exploited by malicious people to conduct SQL injection attacks against applications using the framework.
Full Advisory:
http://secunia.com/advisories/28077/
--
[SA28073] Apache mod_imap Module Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-12
A vulnerability has been reported in the mod_imap module for Apache, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28073/
--
[SA28069] Rainboard Unspecified Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-12
A vulnerability has been reported in Rainboard, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28069/
--
[SA28063] MySQL Security Issue and Two Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Manipulation of data, Privilege escalation, DoS
Released: 2007-12-12
A security issue and two vulnerabilities have been reported in MySQL, which can be exploited by malicious users to gain escalated privileges, manipulate certain data, or to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28063/
--
[SA28049] Cybozu Products Cross-Site Scripting and HTTP Header
Injection
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-11
Some vulnerabilities have been reported in Cybozu products, which can be exploited by malicious people to conduct cross-site scripting and HTTP header injection attacks.
Full Advisory:
http://secunia.com/advisories/28049/
--
[SA28046] Apache mod_imagemap Module Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-12
A vulnerability has been reported in the mod_imagemap module for Apache, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28046/
--
[SA28024] bitweaver Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-10
DoZ has discovered some vulnerabilities in bitweaver, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28024/
--
[SA28012] Serendipity Remote RSS Sidebar Plugin Script Insertion
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-10
A vulnerability has been reported in Serendipity, which can be exploited by malicious people to conduct script-insertion attacks.
Full Advisory:
http://secunia.com/advisories/28012/
--
[SA28006] WebSPELL Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-11
Brainhead has discovered some vulnerabilities in WebSPELL, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28006/
--
[SA28005] WordPress GBK/Big5 Character Set "s" SQL Injection
Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-12-11
Abel Cheung has discovered a vulnerability in WordPress, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28005/
--
[SA27966] OpenNewsletter "type" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-07
Manuel Fernandez has discovered a vulnerability in OpenNewsletter, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27966/
--
[SA28026] Websense User-Agent Filtering Bypass Security Issue
Critical: Less critical
Where: From local network
Impact: Security Bypass
Released: 2007-12-13
mrhinkydink has reported a security issue in Websense, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/28026/
--
[SA27981] MySQL System Table Information Overwrite Vulnerability
Critical: Less critical
Where: Local system
Impact: Manipulation of data
Released: 2007-12-10
A vulnerability has been reported in MySQL, which can be exploited by malicious, local users to manipulate certain data.
Full Advisory:
http://secunia.com/advisories/27981/
Windows:--
[SA28036] Internet Explorer Multiple Code Execution Vulnerabilities
Critical: Extremely critical
Where: From remote
Impact: System access
Released: 2007-12-11
Some vulnerabilities have been reported in Internet Explorer, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28036/
--
[SA27992] JustSystems Ichitaro Document Processing Buffer Overflow
Critical: Extremely critical
Where: From remote
Impact: System access
Released: 2007-12-13
A vulnerability has been reported in JustSystems Ichitaro, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27992/
--
[SA28055] HP Info Center HPInfo Class ActiveX Control Insecure Methods
Critical: Highly critical
Where: From remote
Impact: Manipulation of data, Exposure of system information, System access
Released: 2007-12-12
porkythepig has reported some vulnerabilities in HP Info Center, which can be exploited by malicious people to gain knowledge of certain system information, manipulate registry data, and to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28055/
--
[SA28034] Windows Media Format Runtime ASF Parsing Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-11
IBM X-Force has reported four vulnerabilities in Windows Media Format Runtime / Windows Media Services, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28034/
--
[SA28031] BadBlue Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, System access
Released: 2007-12-11
Luigi Auriemma has reported some vulnerabilities in BadBlue, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, and compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28031/
--
[SA28010] Microsoft DirectX SAMI/WAV/AVI File Parsing Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-11
Two vulnerabilities have been reported in Microsoft DirectX, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28010/
--
[SA27998] 3ivx MPEG-4 MP4 File Processing Buffer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-10
SYS 49152 has discovered some vulnerabilities in 3ivx MPEG-4, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27998/
--
[SA28038] Trend Micro Products UUE File Parsing Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-12
Sowhat has reported a vulnerability in some Trend Micro products, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28038/
--
[SA28032] BarracudaDrive Web Server Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of system information, Exposure of sensitive information, DoS
Released: 2007-12-11
Luigi Auriemma has reported some vulnerabilities in BarracudaDrive Web Server, which can be exploited by malicious users to manipulate certain data and cause a DoS (Denial of Service), and by malicious people to conduct script insertion attacks and disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28032/
--
[SA28007] Easy File Sharing Web Server Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2007-12-10
Luigi Auriemma has reported some vulnerabilities in Easy File Sharing Web Server, which can be exploited by malicious people to disclose sensitive information and by malicious users to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28007/
--
[SA27976] PenPal Three SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-07
Aria-Security Team have reported some vulnerabilities in PenPal, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27976/
--
[SA28051] Microsoft Windows Message Queuing Buffer Overflow
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-11
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28051/
--
[SA27997] Microsoft Windows Vista SMBv2 Signing Vulnerability
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-11
A vulnerability has been reported in Microsoft Windows Vista, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27997/
--
[SA28019] Websense "username" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-11
Dave Lewis has reported a vulnerability in Websense Enterprise and Websense Web Security Suite, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28019/
--
[SA28015] Windows Vista Kernel Legacy Reply Path Validation Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-11
A vulnerability has been reported in Microsoft Windows Vista, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/28015/
--
[SA28011] Microsoft Windows Message Queuing Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-11
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/28011/
--
[SA28072] Kerio WinRoute Firewall Proxy Server Unspecified Security Bypass
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2007-12-13
A weakness has been reported in Kerio WinRoute Firewall, which potentially can be exploited by malicious, local users to bypass
certain security restrictions.
Full Advisory:
http://secunia.com/advisories/28072/
UNIX/Linux:--
[SA28068] Sun Solaris update for Adobe Flash Player
Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2007-12-12
Sun has issued an update for Adobe Flash Player. This fixes some vulnerabilities, which can be exploited by malicious people to gain
knowledge of sensitive information or compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28068/
--
[SA28056] Red Hat update for java-1.4.2-bea
Critical: Highly critical
Where: From remote
Impact: System access, DoS
Released: 2007-12-12
Red Hat has issued an update for java-1.4.2-bea. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28056/
--
[SA28043] Fedora update for poppler
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-11
Fedora has issued an update for poppler. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28043/
--
[SA28039] SUSE update for OpenOffice_org
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-11
SUSE has issued an update for OpenOffice_org. This fixes a vulnerability, which can be exploited by malicious people to compromise
a user's system.
Full Advisory:
http://secunia.com/advisories/28039/
--
[SA28001] Debian update for iceweasel
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-12-10
Debian has issued an update for iceweasel. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site request forgery and cross-site scripting attacks or potentially to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28001/
--
[SA27979] Fedora update for seamonkey
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2007-12-10
Fedora has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting and cross-site request forgery attacks and potentially to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27979/
--
[SA27972] Fedora update for openoffice.org
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-10
Fedora has issued an update for openoffice.org. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27972/
--
[SA28060] Debian update for ruby-gnome2
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-12
Debian has issued an update for ruby-gnome2. This fixes a vulnerability, which potentially can be exploited by malicious people
to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28060/
--
[SA28050] Red Hat update for python
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2007-12-11
Red Hat has issued an update for python. This fixes a security issue and a vulnerability, which can be exploited by malicious people to disclose potentially sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28050/
--
[SA28044] IBM AIX Multiple Unspecified Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2007-12-12
Multiple vulnerabilities have been reported in IBM AIX, which have unknown impacts.
Full Advisory:
http://secunia.com/advisories/28044/
--
[SA28041] Avaya Products PCRE Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2007-12-13
Avaya has acknowledged some vulnerabilities in various Avaya products, which can be exploited by malicious people to disclose sensitive information, cause a DoS (Denial of Service), or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28041/
--
[SA28033] Debian update for kernel
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-11
Debian has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users and
by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28033/
--
[SA28027] Red Hat update for python
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2007-12-11
Red Hat has issued an update for python. This fixes some security issues and a vulnerability, which can be exploited by malicious people to disclose potentially sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28027/
--
[SA28022] Gentoo update for ruby-gtk2
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-10
Gentoo has issued an update for ruby-gtk2. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28022/
--
[SA28021] Gentoo update for emul-linux-x86-qtlibs
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-10
Gentoo has issued an update for emul-linux-x86-qtlibs. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28021/
--
[SA28008] Debian update for sitebar
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information, System access
Released: 2007-12-10
Debian has issued an update for sitebar. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting attacks, and by malicious users to disclose potentially sensitive information and compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28008/
--
[SA28002] wwwstats "link" Script Insertion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-10
Jesus Olmos Gonzalez has reported a vulnerability in wwwstats, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/28002/
--
[SA27996] Debian update for qt-x11-free
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-10
Debian has issued an update for qt-x11-free. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27996/
--
[SA27989] Fedora update for eggdrop
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-11
Fedora has issued an update for eggdrop. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27989/
--
[SA27985] Gentoo update for cairo
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-10
Gentoo has issued an update for cairo. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27985/
--
[SA27984] Gentoo update for emacs
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-10
Gentoo has issued an update for emacs. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/27984/
--
[SA27975] Fedora update for ruby-gnome
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-10
Fedora has issued an update for ruby-gnome. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27975/
--
[SA27973] Fedora update for drupal
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-10
Fedora has issued an update for drupal. This fixes a vulnerability, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27973/
--
[SA28067] Mandriva update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-12
Mandriva has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28067/
--
[SA28029] Gentoo update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-11
Gentoo has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28029/
--
[SA28028] rPath update for samba and samba-swat
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-11
rPath has issued an update for samba and samba-swat. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28028/
--
[SA28003] SUSE update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-12
SUSE has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28003/
--
[SA27999] Debian update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-11
Debian has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27999/
--
[SA27993] Slackware update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-11
Slackware has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27993/
--
[SA27982] Gentoo update for firebird
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-10
Gentoo has issued an update for firebird. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27982/
--
[SA27977] Fedora update for samba
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-11
Fedora has issued an update for samba. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27977/
--
[SA28062] Debian update for htdig
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-12
Debian has issued an update for htdig. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory:
http://secunia.com/advisories/28062/
--
[SA28061] Debian update for libnss-ldap
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-12
Debian has issued an update for nss-ldap. This fixes a security issue, which can be exploited by malicious persons to manipulate certain data.
Full Advisory:
http://secunia.com/advisories/28061/
--
[SA28042] Mandriva update for e2fsprogs
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-11
Mandriva has issued an update for e2fsprogs. This fixes a vulnerability, which potentially can be exploited by malicious people
to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28042/
--
[SA28030] rPath update for e2fsprogs
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-12
rPath has issued an update for e2fsprogs. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28030/
--
[SA28000] Ubuntu update for e2fsprogs
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-10
Ubuntu has issued an update for e2fsprogs. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28000/
--
[SA27987] Debian update for e2fsprogs
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-10
Debian has issued an update for e2fsprogs. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/27987/
--
[SA27983] Gentoo update for PEAR-MDB2
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-12-10
Gentoo has issued an update for PEAR-MDB2. This fixes a security issue, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/27983/
--
[SA27980] Fedora update for nagios
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-10
Fedora has issued an update for nagios. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site
scripting attacks.
Full Advisory:
http://secunia.com/advisories/27980/
--
[SA27971] Avaya Products Apache mod_proxy "date" Denial of Service
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-12-07
Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/27971/
--
[SA27967] Ubuntu update for tetex-bin and texlive-bin
Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-12-07
Ubuntu has issued an update for tetex-bin and texlive-bin. This fixes some vulnerabilities, which can be exploited by malicious, local users to disclose and manipulate sensitive information and by malicious people to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27967/
--
[SA28040] Mandriva update for MySQL
Critical: Less critical
Where: From local network
Impact: Security Bypass, Manipulation of data, DoS
Released: 2007-12-11
Mandriva has issued an update for MySQL. This fixes some vulnerabilities, which can be exploited by malicious, local users to
manipulate certain data and by malicious users to bypass certain security restrictions or cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28040/
--
[SA28052] Red Hat autofs "/net" Privilege Escalation Vulnerability
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-12
A vulnerability has been reported in Red Hat Enterprise Linux, which can be exploited by malicious, local users to gain escalated
privileges.
Full Advisory:
http://secunia.com/advisories/28052/
--
[SA28023] Gentoo update for lookup
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-10
Gentoo has issued an update for lookup. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/28023/
--
[SA28004] Fedora update for xorg-x11-xfs
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-11
Fedora has issued an update for xorg-x11-xfs. This fixes some vulnerabilities, which can be exploited by malicious, local users to
gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/28004/
--
[SA27978] Fedora update for zabbix
Critical: Not critical
Where: From local network
Impact: Privilege escalation
Released: 2007-12-10
Fedora has issued an update for zabbix. This fixes a weakness, which can be exploited by malicious users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/27978/
--
[SA28070] Linux Kernel "mmap_min_addr" Security Bypass
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2007-12-12
A security issue has been reported in the Linux Kernel, which can be exploited by malicious, local users to bypass certain security
restrictions.
Full Advisory:
http://secunia.com/advisories/28070/
--
[SA28057] Avaya CMS / IR Solaris Remote Procedure Call Module Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-12-12
Avaya has acknowledged a vulnerability in Avaya CMS / IR, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28057/
--
[SA28048] Mac OS X "cs_validate_page()" Local Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-12-13
mu-b has reported a vulnerability in Mac OS X, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28048/
Other:--
[SA27970] IBM HMC Version 3 Privilege Escalation Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-07
Some vulnerabilities have been reported in IBM HMC, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/27970/
Cross Platform:--
[SA28066] ViArt CMS/HelpDesk/Shop "root_folder_path" File Inclusion
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-12-12
RoMaNcYxHaCkEr has discovered a vulnerability in various ViArt products, which can be exploited by malicious people to disclose
sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28066/
--
[SA28058] CityWriter "path" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-13
RoMaNcYxHaCkEr has discovered a vulnerability in CityWriter, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28058/
--
[SA28054] Fastpublish CMS designconfig.php File Inclusion
Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2007-12-13
RoMaNcYxHaCkEr has discovered a vulnerability in Fastpublish CMS, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28054/
--
[SA28047] Falcon Series One Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2007-12-11
MhZ91 has reported some vulnerabilities in Falcon Series One, which can be exploited by malicious people to conduct script insertion and cross-site request forgery attacks and to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28047/
--
[SA28018] Sun StarOffice/StarSuite Database Document Processing Arbitrary Java Method Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-10
Sun has acknowledged a vulnerability in Sun StarOffice and StarSuite, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28018/
--
[SA27974] Novell NetMail AntiVirus Agent Integer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-07
A vulnerability has been reported in Novell NetMail, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/27974/
--
[SA28080] Robocode Arbitrary Java Code Execution Security Issue
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2007-12-13
A security issue has been reported in Robocode, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/28080/
--
[SA28075] MMS Gallery PHP "id" File Inclusion Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-12-13
GoLd_M has reported some vulnerabilities in MMS Gallery PHP, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28075/
--
[SA28071] xml2owl "file" Information Disclosure Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-12-13
GoLd_M has discovered a vulnerability in xml2owl, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28071/
--
[SA28053] Mcms Easy Web Make "template" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-12-12
MhZ91 has discovered a vulnerability in Mcms Easy Web Make, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28053/
--
[SA28045] Falt4 CMS Cross-Site Scripting and SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2007-12-11
Mesut Timur has reported some vulnerabilities in Falt4 CMS, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28045/
--
[SA28035] Cybozu Office Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2007-12-11
Some vulnerabilities have been reported in Cybozu Office, which can be exploited by malicious people to conduct cross-site scripting attacks, HTTP header injection attacks, or cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28035/
--
[SA28014] aurora framework "pack_var()" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-12
A vulnerability has been reported in aurora framework, which can be exploited by malicious people to conduct SQL injection attacks against applications using the framework.
Full Advisory:
http://secunia.com/advisories/28014/
--
[SA28013] PolDoc Document Management System "filename" Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-12-10
GoLd_M has discovered a vulnerability in PolDoc Document Management System (PDDMS), which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28013/
--
[SA27990] DWdirectory "search" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-10
t0pP8uZz & xprog have reported a vulnerability in DWdirectory, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27990/
--
[SA27988] Ace Image Hosting Script "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-10
t0pP8uZz & xprog have reported a vulnerability in Ace Image Hosting Script, which can be exploited by malicious people to conduct SQL injections attacks.
Full Advisory:
http://secunia.com/advisories/27988/
--
[SA27986] Content Injector "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-12-10
S.W.A.T. has discovered a vulnerability in Content Injector, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/27986/
--
[SA28082] Hitachi Web Server Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-13
Hitachi has acknowledged some vulnerabilities in the Hitachi Web Server, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28082/
--
[SA28081] Apache mod_imap Module Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-13
A vulnerability has been reported in the mod_imap module for Apache, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28081/
--
[SA28078] BEA WebLogic Mobility Server Image Converter Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-12-13
A vulnerability has been reported in the BEA WebLogic Mobility Server, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/28078/
--
[SA28077] JBoss Seam "order" EJBQL Injection Vulnerability
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-13
A vulnerability has been reported in JBoss Seam, which potentially can be exploited by malicious people to conduct SQL injection attacks against applications using the framework.
Full Advisory:
http://secunia.com/advisories/28077/
--
[SA28073] Apache mod_imap Module Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-12
A vulnerability has been reported in the mod_imap module for Apache, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28073/
--
[SA28069] Rainboard Unspecified Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-12
A vulnerability has been reported in Rainboard, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28069/
--
[SA28063] MySQL Security Issue and Two Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Manipulation of data, Privilege escalation, DoS
Released: 2007-12-12
A security issue and two vulnerabilities have been reported in MySQL, which can be exploited by malicious users to gain escalated privileges, manipulate certain data, or to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28063/
--
[SA28049] Cybozu Products Cross-Site Scripting and HTTP Header
Injection
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-11
Some vulnerabilities have been reported in Cybozu products, which can be exploited by malicious people to conduct cross-site scripting and HTTP header injection attacks.
Full Advisory:
http://secunia.com/advisories/28049/
--
[SA28046] Apache mod_imagemap Module Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-12
A vulnerability has been reported in the mod_imagemap module for Apache, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28046/
--
[SA28024] bitweaver Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-10
DoZ has discovered some vulnerabilities in bitweaver, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28024/
--
[SA28012] Serendipity Remote RSS Sidebar Plugin Script Insertion
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-10
A vulnerability has been reported in Serendipity, which can be exploited by malicious people to conduct script-insertion attacks.
Full Advisory:
http://secunia.com/advisories/28012/
--
[SA28006] WebSPELL Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-11
Brainhead has discovered some vulnerabilities in WebSPELL, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28006/
--
[SA28005] WordPress GBK/Big5 Character Set "s" SQL Injection
Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-12-11
Abel Cheung has discovered a vulnerability in WordPress, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28005/
--
[SA27966] OpenNewsletter "type" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-07
Manuel Fernandez has discovered a vulnerability in OpenNewsletter, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/27966/
--
[SA28026] Websense User-Agent Filtering Bypass Security Issue
Critical: Less critical
Where: From local network
Impact: Security Bypass
Released: 2007-12-13
mrhinkydink has reported a security issue in Websense, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/28026/
--
[SA27981] MySQL System Table Information Overwrite Vulnerability
Critical: Less critical
Where: Local system
Impact: Manipulation of data
Released: 2007-12-10
A vulnerability has been reported in MySQL, which can be exploited by malicious, local users to manipulate certain data.
Full Advisory:
http://secunia.com/advisories/27981/

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Secunia 2007 Bulletins
Secunia Vulnerabilities Content Listing for the week of December 20 2007
Windows:--
[SA28144] Rosoft Media Player File Processing Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-19
Juan Pablo Lopez Yacubian has discovered a vulnerability in Rosoft Media Player, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28144/
--
[SA28134] iMesh IMWebControl Class ActiveX Control Code Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-18
rgod has discovered a vulnerability in iMesh, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28134/
--
[SA28120] PeerCast "handshakeHTTP()" Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-18
Luigi Auriemma has reported a vulnerability in PeerCast, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28120/
--
[SA28160] WFTPD Explorer LIST Reply Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-19
r4x has reported a vulnerability in WFTPD Explorer, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28160/
--
[SA28143] RaidenHTTPD "ulang" Local File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-12-18
rgod has discovered a vulnerability in RaidenHTTPD, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28143/
--
[SA28111] phPay Local File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-12-17
Michael Brooks has discovered a vulnerability in phPay, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28111/
--
[SA28131] St. Bernard Open File Manager Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-18
A vulnerability has been reported in St. Bernard Open File Manager, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28131/
--
[SA28177] HP Software Update ContentCollection Class ActiveX Control Insecure Method
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-20
porkythepig has reported a vulnerability in HP Software Update, which can be exploited by malicious people to overwrite arbitrary files on a user's system.
Full Advisory:
http://secunia.com/advisories/28177/
--
[SA28150] Citrix Web Interface Unspecified Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-19
A vulnerability has been reported in Citrix Web Interface, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28150/
--
[SA28142] SurgeMail Webmail "Host" Header Processing Denial of Service
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-12-18
rgod has discovered a vulnerability in SurgeMail, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28142/
UNIX/Linux:--
[SA28157] Red Hat update for flash-plugin
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information, Privilege escalation, DoS, System access
Released: 2007-12-19
Red Hat has issued an update for flash-plugin. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to conduct cross-site scripting and HTTP request splitting attacks, disclose sensitive information, cause a Denial of Service (DoS), or to potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28157/
--
[SA28136] Apple Mac OS X Security Update Fixes Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Hijacking, Security Bypass, Cross Site Scripting, Exposure of system information, Exposure of sensitive information, Privilege escalation, DoS, System access
Released: 2007-12-18
Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities.
Full Advisory:
http://secunia.com/advisories/28136/
--
[SA28135] Sun Solaris Firefox / Thunderbird Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2007-12-19
Sun has acknowledged some vulnerabilities in Sun Solaris, which can be exploited by malicious people to conduct spoofing and cross-site scripting attacks, to disclose sensitive information, and potentially to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28135/
--
[SA28115] Mac OS X Java Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Privilege escalation, DoS, System access
Released: 2007-12-17
Some vulnerabilities have been reported and acknowledged in Mac OS X, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting attacks, to cause a DoS (Denial of Service), or to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28115/
--
[SA28112] Centreon "fileOreonConf" File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-18
Michael Brooks has reported some vulnerabilities in Centreon, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28112/
--
[SA28084] HP-UX update for OpenSSL
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-14
HP has issued an update for OpenSSL. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28084/
--
[SA28170] Ubuntu update for kernel
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-20
Ubuntu has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users and by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28170/
--
[SA28167] IBM AIX Perl Regular Expressions Unicode Data Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-19
IBM has acknowledged a vulnerability in AIX, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28167/
--
[SA28147] Ubuntu update for libgd2
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-19
Ubuntu has issued an update for libgd2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28147/
--
[SA28132] Exiv2 EXIF Parsing Integer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-18
A vulnerability has been reported in Exiv2, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28132/
--
[SA28114] Sun Solaris Gimp Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-18
Sun has acknowledged some vulnerabilities in Gimp, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28114/
--
[SA28113] Gentoo update for cups
Critical: Moderately critical
Where: From remote
Impact: Privilege escalation, DoS, System access
Released: 2007-12-19
Gentoo has issued an update for cups. This fixes a security issue and some vulnerabilities, which can be exploited by malicious, local users to perform certain actions with escalated privileges and by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28113/
--
[SA28109] Red Hat update for squid
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-19
Red Hat has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28109/
--
[SA28103] Debian update for centericq
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-17
Debian has issued an update for centericq. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28103/
--
[SA28101] Debian update for link-grammar
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-18
Debian has issued an update for link-grammar. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28101/
--
[SA28091] Fedora update for squid
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-17
Fedora has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28091/
--
[SA28090] Gentoo update for ircservices
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-14
Gentoo has issued an update for ircservices. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28090/
--
[SA28086] Debian update for mydns
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-17
Debian has issued an update for mydns. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28086/
--
[SA28151] Sun Management Center Default Account Security Issue
Critical: Moderately critical
Where: From local network
Impact: Security Bypass
Released: 2007-12-19
A security issue has been reported in Sun Management Center, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/28151/
--
[SA28129] CUPS SNMP Backend "asn1_get_string()" Signedness Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-12-18
A vulnerability has been reported in CUPS, which can be exploited by
malicious people to cause a DoS (Denial of Service) or potentially
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28129/
--
[SA28089] Avaya Products Samba "send_mailslot()" Buffer Overflow
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-14
Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28089/
--
[SA28087] HP-UX DCE swagentd Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-12-14
A vulnerability has been reported in HP-UX, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28087/
--
[SA28162] Red Hat update for kernel
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-12-20
Red Hat has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28162/
--
[SA28107] rPath update for tetex
Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-12-18
rPath has issued an update for tetex. This fixes some vulnerabilities, which can be exploited by malicious, local users to disclose and manipulate sensitive information and by malicious people to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28107/
--
[SA28148] Sun Ray Device Manager Daemon Data Manipulation and DoS
Critical: Less critical
Where: From local network
Impact: Manipulation of data, DoS
Released: 2007-12-19
Some vulnerabilities have been reported in Sun Ray Server Software, which can be exploited by malicious, local users or malicious people to manipulate certain data or cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28148/
--
[SA28108] Slackware update for mysql
Critical: Less critical
Where: From local network
Impact: Security Bypass, Manipulation of data, DoS
Released: 2007-12-17
Slackware has issued an update for mysql. This fixes a security issue and some vulnerabilities, which can be exploited by malicious, local users to manipulate certain data and by malicious users to bypass certain security restrictions and cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28108/
--
[SA28099] Red Hat update for mysql
Critical: Less critical
Where: From local network
Impact: Manipulation of data, DoS
Released: 2007-12-19
Red Hat has issued an update for mysql. This fixes some vulnerabilities, which can be exploited by malicious, local users to manipulate certain data and by malicious users to cause a DoS (Denial
of Service).
Full Advisory:
http://secunia.com/advisories/28099/
--
[SA28139] Alternate pdftops Filter for CUPS Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-18
A security issue has been reported in the Alternate pdftops Filter for CUPS, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/28139/
--
[SA28123] scponly Command Passthrough Security Bypass
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2007-12-17
A security issue has been reported in scponly, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/28123/
--
[SA28105] Linux Kernel "hrtimer_start()" Integer Overflow Vulnerability
Critical: Less critical
Where: Local system
Impact: Unknown
Released: 2007-12-17
A vulnerability with an unknown impact has been reported in the Linux Kernel.
Full Advisory:
http://secunia.com/advisories/28105/
--
[SA28097] Fedora update for autofs
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-17
Fedora has issued an update for autofs. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/28097/
--
[SA28094] Gentoo Portage "etc-update" Information Disclosure
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2007-12-14
Gentoo has acknowledged a security issue in Portage, which can be exploited by malicious, local users to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/28094/
--
[SA28088] rPath update for kernel
Critical: Less critical
Where: Local system
Impact: Unknown
Released: 2007-12-19
rPath has issued an update for the kernel. This fixes a vulnerability with an unknown impact.
Full Advisory:
http://secunia.com/advisories/28088/
--
[SA28181] rPath update for kdebase
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-12-20
rPath has issued an update for kdebase. This fixes a weakness, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28181/
--
[SA28104] KDE KDM Local Denial of Service Weakness
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-12-20
A weakness has been reported in KDE, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28104/
Other:--
[SA28175] Cisco Firewall Services Module Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-20
A vulnerability has been reported in the Cisco Firewall Services Module (FWSM), which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28175/
--
[SA28100] Juniper JUNOS BGP UPDATE Message Processing Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-17
A vulnerability has been reported in Juniper JUNOS, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28100/
--
[SA28096] Sun Solaris 10 NFS "netgroups" Security Bypass Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2007-12-14
Sun has acknowledged a vulnerability in Solaris, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/28096/
--
[SA28093] NeoOffice Unspecified OpenOffice.org Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2007-12-14
A vulnerability with an unknown impact has been reported in NeoOffice.
Full Advisory:
http://secunia.com/advisories/28093/
Cross Platform:--
[SA28169] Opera Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, System access
Released: 2007-12-19
Some vulnerabilities have been reported in Opera, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, and compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28169/
--
[SA28161] Adobe Flash Player Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Unknown, Security Bypass, Cross Site Scripting, Manipulation of data, Exposure of sensitive information, Privilege escalation, DoS, System access
Released: 2007-12-19
Some vulnerabilities have been reported in Adobe Flash Player, where one vulnerability has an unknown impact and others can be exploited by malicious, local users to gain escalated privileges and by malicious people to bypass certain security restrictions, conduct cross-site scripting and HTTP request splitting attacks, disclose sensitive information, cause a Denial of Service (DoS), or to potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28161/
--
[SA28117] ClamAV "cli_scanpe()" MEW Handling Integer Overflow
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-19
A vulnerability has been reported in ClamAV, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28117/
--
[SA28095] SquirrelMail Package Compromise
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-14
A package compromise has been reported in SquirrelMail, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28095/
--
[SA28092] Apple QuickTime Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-14
Some vulnerabilities have been reported in Apple QuickTime, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28092/
--
[SA28155] phpMyRealty Two SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-12-19
Koller has reported two vulnerabilities in phpMyRealty (PMR), which can be exploited by malicious people and malicious users to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28155/
--
[SA28154] Dokeos "My productions" Multiple Extensions File Upload Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-19
A vulnerability has been discovered in Dokeos, which can be exploited by malicious users to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28154/
--
[SA28138] PunBB Automatic Image Upload with Thumbnails Module File Upload
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2007-12-18
Peter Österberg has discovered a vulnerability in the Automatic Image Upload with Thumbnails module for PunBB, which can be exploited by malicious users to conduct cross-site scripting attacks and to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28138/
--
[SA28137] LineShout Two Script Insertion Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-18
David Sopas has reported two vulnerabilities in LineShout, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/28137/
--
[SA28126] FreeWebshop.org Admin Credentials Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information
Released: 2007-12-17
k1tk4t has discovered a vulnerability in FreeWebshop.org, which can be exploited by malicious people to bypass certain security restrictions and to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28126/
--
[SA28124] Hammer of Thyrion "HuffDecode()" Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-17
A vulnerability has been reported in Hammer of Thyrion, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28124/
--
[SA28119] PHP Real Estate Classifieds "id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-12-18
t0pP8uZz & xprog have reported a vulnerability in PHP Real Estate Classifieds, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28119/
--
[SA28110] exiftags Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-17
Some vulnerabilities have been reported in exiftags, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28110/
--
[SA28098] CourseMill Learning Management System "user" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-14
sasquatch has reported a vulnerability in CourseMill Learning Management System, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28098/
--
[SA28164] GF-3XPLORER Cross-Site Scripting and Information Disclosure
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-19
MhZ91 has discovered a vulnerability and a security issue in GF-3XPLORER, which can be exploited by malicious people to conduct cross-site scripting attacks or to disclose system information.
Full Advisory:
http://secunia.com/advisories/28164/
--
[SA28149] Asterisk Registration Database Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-12-19
A security issue has been reported in Asterisk, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/28149/
--
[SA28133] Mambo Two Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-19
Beenu Arora has discovered two vulnerabilities in Mambo, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28133/
--
[SA28130] WordPress Draft Information Disclosure
Critical: Less critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information
Released: 2007-12-19
Michael Brooks has discovered a vulnerability in WordPress, which can be exploited by malicious people to bypass certain security restrictions and to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28130/
--
[SA28122] Google Web Toolkit Benchmark Reporting System Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-18
A vulnerability has been reported in Google Web Toolkit, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28122/
--
[SA28116] Ganglia Web Interface Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-17
Some vulnerabilities have been reported in Ganglia, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28116/
--
[SA28106] Flyspray Two Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-17
Two vulnerabilities have been reported in Flyspray, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28106/
--
[SA28118] syslog-ng Timestamps Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-12-18
A vulnerability has been reported in syslog-ng, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28118/
Windows:--
[SA28144] Rosoft Media Player File Processing Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-19
Juan Pablo Lopez Yacubian has discovered a vulnerability in Rosoft Media Player, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28144/
--
[SA28134] iMesh IMWebControl Class ActiveX Control Code Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-18
rgod has discovered a vulnerability in iMesh, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28134/
--
[SA28120] PeerCast "handshakeHTTP()" Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-18
Luigi Auriemma has reported a vulnerability in PeerCast, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28120/
--
[SA28160] WFTPD Explorer LIST Reply Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-19
r4x has reported a vulnerability in WFTPD Explorer, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28160/
--
[SA28143] RaidenHTTPD "ulang" Local File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-12-18
rgod has discovered a vulnerability in RaidenHTTPD, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28143/
--
[SA28111] phPay Local File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-12-17
Michael Brooks has discovered a vulnerability in phPay, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28111/
--
[SA28131] St. Bernard Open File Manager Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-18
A vulnerability has been reported in St. Bernard Open File Manager, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28131/
--
[SA28177] HP Software Update ContentCollection Class ActiveX Control Insecure Method
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-20
porkythepig has reported a vulnerability in HP Software Update, which can be exploited by malicious people to overwrite arbitrary files on a user's system.
Full Advisory:
http://secunia.com/advisories/28177/
--
[SA28150] Citrix Web Interface Unspecified Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-19
A vulnerability has been reported in Citrix Web Interface, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28150/
--
[SA28142] SurgeMail Webmail "Host" Header Processing Denial of Service
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-12-18
rgod has discovered a vulnerability in SurgeMail, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28142/
UNIX/Linux:--
[SA28157] Red Hat update for flash-plugin
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information, Privilege escalation, DoS, System access
Released: 2007-12-19
Red Hat has issued an update for flash-plugin. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to conduct cross-site scripting and HTTP request splitting attacks, disclose sensitive information, cause a Denial of Service (DoS), or to potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28157/
--
[SA28136] Apple Mac OS X Security Update Fixes Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Hijacking, Security Bypass, Cross Site Scripting, Exposure of system information, Exposure of sensitive information, Privilege escalation, DoS, System access
Released: 2007-12-18
Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities.
Full Advisory:
http://secunia.com/advisories/28136/
--
[SA28135] Sun Solaris Firefox / Thunderbird Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, Exposure of sensitive information, DoS, System access
Released: 2007-12-19
Sun has acknowledged some vulnerabilities in Sun Solaris, which can be exploited by malicious people to conduct spoofing and cross-site scripting attacks, to disclose sensitive information, and potentially to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28135/
--
[SA28115] Mac OS X Java Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Privilege escalation, DoS, System access
Released: 2007-12-17
Some vulnerabilities have been reported and acknowledged in Mac OS X, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting attacks, to cause a DoS (Denial of Service), or to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28115/
--
[SA28112] Centreon "fileOreonConf" File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-18
Michael Brooks has reported some vulnerabilities in Centreon, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28112/
--
[SA28084] HP-UX update for OpenSSL
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-14
HP has issued an update for OpenSSL. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28084/
--
[SA28170] Ubuntu update for kernel
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-20
Ubuntu has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users and by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28170/
--
[SA28167] IBM AIX Perl Regular Expressions Unicode Data Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-19
IBM has acknowledged a vulnerability in AIX, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28167/
--
[SA28147] Ubuntu update for libgd2
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-19
Ubuntu has issued an update for libgd2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28147/
--
[SA28132] Exiv2 EXIF Parsing Integer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-18
A vulnerability has been reported in Exiv2, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28132/
--
[SA28114] Sun Solaris Gimp Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-18
Sun has acknowledged some vulnerabilities in Gimp, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28114/
--
[SA28113] Gentoo update for cups
Critical: Moderately critical
Where: From remote
Impact: Privilege escalation, DoS, System access
Released: 2007-12-19
Gentoo has issued an update for cups. This fixes a security issue and some vulnerabilities, which can be exploited by malicious, local users to perform certain actions with escalated privileges and by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28113/
--
[SA28109] Red Hat update for squid
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-19
Red Hat has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28109/
--
[SA28103] Debian update for centericq
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-17
Debian has issued an update for centericq. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28103/
--
[SA28101] Debian update for link-grammar
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-18
Debian has issued an update for link-grammar. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28101/
--
[SA28091] Fedora update for squid
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-17
Fedora has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28091/
--
[SA28090] Gentoo update for ircservices
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-14
Gentoo has issued an update for ircservices. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28090/
--
[SA28086] Debian update for mydns
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-17
Debian has issued an update for mydns. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28086/
--
[SA28151] Sun Management Center Default Account Security Issue
Critical: Moderately critical
Where: From local network
Impact: Security Bypass
Released: 2007-12-19
A security issue has been reported in Sun Management Center, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/28151/
--
[SA28129] CUPS SNMP Backend "asn1_get_string()" Signedness Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-12-18
A vulnerability has been reported in CUPS, which can be exploited by
malicious people to cause a DoS (Denial of Service) or potentially
compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28129/
--
[SA28089] Avaya Products Samba "send_mailslot()" Buffer Overflow
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2007-12-14
Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28089/
--
[SA28087] HP-UX DCE swagentd Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2007-12-14
A vulnerability has been reported in HP-UX, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28087/
--
[SA28162] Red Hat update for kernel
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-12-20
Red Hat has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28162/
--
[SA28107] rPath update for tetex
Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2007-12-18
rPath has issued an update for tetex. This fixes some vulnerabilities, which can be exploited by malicious, local users to disclose and manipulate sensitive information and by malicious people to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28107/
--
[SA28148] Sun Ray Device Manager Daemon Data Manipulation and DoS
Critical: Less critical
Where: From local network
Impact: Manipulation of data, DoS
Released: 2007-12-19
Some vulnerabilities have been reported in Sun Ray Server Software, which can be exploited by malicious, local users or malicious people to manipulate certain data or cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28148/
--
[SA28108] Slackware update for mysql
Critical: Less critical
Where: From local network
Impact: Security Bypass, Manipulation of data, DoS
Released: 2007-12-17
Slackware has issued an update for mysql. This fixes a security issue and some vulnerabilities, which can be exploited by malicious, local users to manipulate certain data and by malicious users to bypass certain security restrictions and cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28108/
--
[SA28099] Red Hat update for mysql
Critical: Less critical
Where: From local network
Impact: Manipulation of data, DoS
Released: 2007-12-19
Red Hat has issued an update for mysql. This fixes some vulnerabilities, which can be exploited by malicious, local users to manipulate certain data and by malicious users to cause a DoS (Denial
of Service).
Full Advisory:
http://secunia.com/advisories/28099/
--
[SA28139] Alternate pdftops Filter for CUPS Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-18
A security issue has been reported in the Alternate pdftops Filter for CUPS, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/28139/
--
[SA28123] scponly Command Passthrough Security Bypass
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2007-12-17
A security issue has been reported in scponly, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/28123/
--
[SA28105] Linux Kernel "hrtimer_start()" Integer Overflow Vulnerability
Critical: Less critical
Where: Local system
Impact: Unknown
Released: 2007-12-17
A vulnerability with an unknown impact has been reported in the Linux Kernel.
Full Advisory:
http://secunia.com/advisories/28105/
--
[SA28097] Fedora update for autofs
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-12-17
Fedora has issued an update for autofs. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
http://secunia.com/advisories/28097/
--
[SA28094] Gentoo Portage "etc-update" Information Disclosure
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2007-12-14
Gentoo has acknowledged a security issue in Portage, which can be exploited by malicious, local users to disclose potentially sensitive information.
Full Advisory:
http://secunia.com/advisories/28094/
--
[SA28088] rPath update for kernel
Critical: Less critical
Where: Local system
Impact: Unknown
Released: 2007-12-19
rPath has issued an update for the kernel. This fixes a vulnerability with an unknown impact.
Full Advisory:
http://secunia.com/advisories/28088/
--
[SA28181] rPath update for kdebase
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-12-20
rPath has issued an update for kdebase. This fixes a weakness, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28181/
--
[SA28104] KDE KDM Local Denial of Service Weakness
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-12-20
A weakness has been reported in KDE, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28104/
Other:--
[SA28175] Cisco Firewall Services Module Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-20
A vulnerability has been reported in the Cisco Firewall Services Module (FWSM), which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28175/
--
[SA28100] Juniper JUNOS BGP UPDATE Message Processing Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-17
A vulnerability has been reported in Juniper JUNOS, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28100/
--
[SA28096] Sun Solaris 10 NFS "netgroups" Security Bypass Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2007-12-14
Sun has acknowledged a vulnerability in Solaris, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/28096/
--
[SA28093] NeoOffice Unspecified OpenOffice.org Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2007-12-14
A vulnerability with an unknown impact has been reported in NeoOffice.
Full Advisory:
http://secunia.com/advisories/28093/
Cross Platform:--
[SA28169] Opera Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, System access
Released: 2007-12-19
Some vulnerabilities have been reported in Opera, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, and compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28169/
--
[SA28161] Adobe Flash Player Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Unknown, Security Bypass, Cross Site Scripting, Manipulation of data, Exposure of sensitive information, Privilege escalation, DoS, System access
Released: 2007-12-19
Some vulnerabilities have been reported in Adobe Flash Player, where one vulnerability has an unknown impact and others can be exploited by malicious, local users to gain escalated privileges and by malicious people to bypass certain security restrictions, conduct cross-site scripting and HTTP request splitting attacks, disclose sensitive information, cause a Denial of Service (DoS), or to potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28161/
--
[SA28117] ClamAV "cli_scanpe()" MEW Handling Integer Overflow
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-19
A vulnerability has been reported in ClamAV, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28117/
--
[SA28095] SquirrelMail Package Compromise
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-14
A package compromise has been reported in SquirrelMail, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28095/
--
[SA28092] Apple QuickTime Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-14
Some vulnerabilities have been reported in Apple QuickTime, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28092/
--
[SA28155] phpMyRealty Two SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-12-19
Koller has reported two vulnerabilities in phpMyRealty (PMR), which can be exploited by malicious people and malicious users to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28155/
--
[SA28154] Dokeos "My productions" Multiple Extensions File Upload Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-19
A vulnerability has been discovered in Dokeos, which can be exploited by malicious users to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28154/
--
[SA28138] PunBB Automatic Image Upload with Thumbnails Module File Upload
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2007-12-18
Peter Österberg has discovered a vulnerability in the Automatic Image Upload with Thumbnails module for PunBB, which can be exploited by malicious users to conduct cross-site scripting attacks and to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28138/
--
[SA28137] LineShout Two Script Insertion Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-18
David Sopas has reported two vulnerabilities in LineShout, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory:
http://secunia.com/advisories/28137/
--
[SA28126] FreeWebshop.org Admin Credentials Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information
Released: 2007-12-17
k1tk4t has discovered a vulnerability in FreeWebshop.org, which can be exploited by malicious people to bypass certain security restrictions and to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28126/
--
[SA28124] Hammer of Thyrion "HuffDecode()" Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-17
A vulnerability has been reported in Hammer of Thyrion, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28124/
--
[SA28119] PHP Real Estate Classifieds "id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2007-12-18
t0pP8uZz & xprog have reported a vulnerability in PHP Real Estate Classifieds, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28119/
--
[SA28110] exiftags Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-17
Some vulnerabilities have been reported in exiftags, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28110/
--
[SA28098] CourseMill Learning Management System "user" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-14
sasquatch has reported a vulnerability in CourseMill Learning Management System, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28098/
--
[SA28164] GF-3XPLORER Cross-Site Scripting and Information Disclosure
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-19
MhZ91 has discovered a vulnerability and a security issue in GF-3XPLORER, which can be exploited by malicious people to conduct cross-site scripting attacks or to disclose system information.
Full Advisory:
http://secunia.com/advisories/28164/
--
[SA28149] Asterisk Registration Database Security Bypass
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-12-19
A security issue has been reported in Asterisk, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/28149/
--
[SA28133] Mambo Two Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-19
Beenu Arora has discovered two vulnerabilities in Mambo, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28133/
--
[SA28130] WordPress Draft Information Disclosure
Critical: Less critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information
Released: 2007-12-19
Michael Brooks has discovered a vulnerability in WordPress, which can be exploited by malicious people to bypass certain security restrictions and to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28130/
--
[SA28122] Google Web Toolkit Benchmark Reporting System Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-18
A vulnerability has been reported in Google Web Toolkit, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28122/
--
[SA28116] Ganglia Web Interface Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-17
Some vulnerabilities have been reported in Ganglia, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28116/
--
[SA28106] Flyspray Two Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-17
Two vulnerabilities have been reported in Flyspray, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28106/
--
[SA28118] syslog-ng Timestamps Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-12-18
A vulnerability has been reported in syslog-ng, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28118/

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Secunia 2007 Bulletins
Secunia Vulnerabilities Content Listing For The Week of December 27 2007
Windows:--
[SA28236] Total Player M3U Playlist Parsing Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-26
David G.M. has discovered a vulnerability in Total Player, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28236/
--
[SA28218] Mercury LoadRunner XUpload ActiveX Control Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-26
A vulnerability has been discovered in HP Mercury LoadRunner, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28218/
--
[SA28215] WinAce UUE File Decompression Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-25
A vulnerability has been reported in WinAce, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28215/
--
[SA28214] Zoom Player Error Message Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-25
Luigi Auriemma has discovered a vulnerability in Zoom Player, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28214/
--
[SA28205] Groove Virtual Office XUpload ActiveX Control Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-26
A vulnerability has been discovered in Groove Virtual Office, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28205/
--
[SA28234] Ada Image Server Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2007-12-25
Some vulnerabilities have been discovered in Ada Image Server, which can be exploited by malicious people to conduct cross-site scripting attacks or gain knowledge of sensitive information.
Full Advisory:
http://secunia.com/advisories/28234/
--
[SA28208] WinUAE Floppy Disk Image File Loading Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-24
Luigi Auriemma has discovered a vulnerability in WinUAE, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28208/
--
[SA28206] Web Sihirbazi "default.asp" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-26
bypas has reported two vulnerabilities in Web Sihirbazi, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28206/
--
[SA28193] Aeries Browser Interface "EmailAddress" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-21
Aria-Security Team have reported a vulnerability in Aeries Browser Interface (ABI), which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28193/
--
[SA28252] IPortalX Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-27
Doz has reported some vulnerabilities in IPortalX, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28252/
UNIX/Linux:--
[SA28246] Fedora update for gallery2
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, System access
Released: 2007-12-26
Fedora has issued an update for gallery2. This fixes some vulnerabilities and a weakness, where some have unspecified impacts and others can be exploited by malicious users or malicious people to disclose sensitive information, conduct cross-site scripting attacks, bypass certain security restrictions, and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28246/
--
[SA28213] SUSE update for flash-player
Critical: Highly critical
Where: From remote
Impact: Unknown, Security Bypass, Cross Site Scripting, Manipulation of data, Exposure of sensitive information, Privilege escalation, DoS, System access
Released: 2007-12-24
SUSE has issued an update for flash-player. This fixes some vulnerabilities, where one vulnerability has an unknown impact and others can be exploited by malicious, local users to gain escalated privileges and by malicious people to bypass certain security restrictions, conduct cross-site scripting and HTTP request splitting attacks, disclose sensitive information, cause a Denial of Service (DoS), or to potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28213/
--
[SA28201] PMOS Help Desk PHP Code Execution and Security Bypass
Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2007-12-26
EgiX has discovered a vulnerability in PMOS Help Desk, which can be exploited by malicious people to bypass certain security restrictions and to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28201/
--
[SA28238] Bitflu StorageFarabDb Security Bypass Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2007-12-27
A vulnerability has been reported in Bitflu, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/28238/
--
[SA28207] Fedora update for wireshark
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-24
Fedora has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28207/
--
[SA28198] Moodle MRBS Module "id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-24
root at hanicker.it has reported a vulnerability in the MRBS Module for Moodle, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28198/
--
[SA28197] Fedora update for wireshark
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-21
Fedora has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28197/
--
[SA28195] Fedora update for libexif
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-21
Fedora has issued an update for libexif. This fixes two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28195/
--
[SA28200] Debian update for cupsys
Critical: Moderately critical
Where: From local network
Impact: Privilege escalation, DoS, System access
Released: 2007-12-27
Debian has issued an update for cupsys. This fixes a security issue and a vulnerability, which can be exploited by malicious, local users to perform certain actions with escalated privileges, and by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28200/
--
[SA28241] GreaseKit / Creammonkey GM API Vulnerability
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-12-26
A vulnerability was reported in GreaseKit / Creammonkey, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/28241/
--
[SA28224] Sun Solaris Apache Cross-Site Scripting and Denial of Service
Critical: Not critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2007-12-24
Sun has acknowledged some vulnerabilities in Apache for Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28224/
--
[SA28212] Sun Solaris Apache Cross-Site Scripting and Denial of Service
Critical: Not critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2007-12-24
Sun has acknowledged some vulnerabilities in Apache for Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28212/
Other:--
[SA28191] HP-UX rpc.yppasswdd Unspecified Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-12-21
A vulnerability has been reported in HP-UX, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28191/
--
[SA28192] HP Tru64 UNIX FFM Unspecified Denial of Service Vulnerability
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-12-21
A vulnerability has been reported in HP Tru64 UNIX, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28192/
Cross Platform:--
[SA28251] Mambo Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Unknown, Cross Site Scripting, System access
Released: 2007-12-27
Some vulnerabilities have been reported in Mambo, one with an unknown impact and others, which can be exploited by malicious people to conduct cross-site scripting attacks or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28251/
--
[SA28245] NmnNewsletter "output" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-26
CraCkEr has discovered a vulnerability in NmnNewsletter, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28245/
--
[SA28240] Shadowed Portal File Inclusion and PHP Code Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-26
The:Paradox has discovered two vulnerabilities in Shadowed Portal, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28240/
--
[SA28233] VLC Media Player Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-25
Some vulnerabilities have been discovered in VLC Media Player, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28233/
--
[SA28230] phpAutoVideo Two File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2007-12-25
MhZ91 has reported two vulnerabilities in phpAutoVideo, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28230/
--
[SA28250] XZero Community Classifieds "subcatid" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-27
Kw3rLn has reported a vulnerability in XZero Community Classifieds, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28250/
--
[SA28242] mBlog "page" Local File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-12-25
irk4z has discovered a vulnerability in mBlog, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28242/
--
[SA28232] MailMachinePRO "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, Manipulation of data
Released: 2007-12-26
MhZ91 has reported a vulnerability in MailMachinePRO, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28232/
--
[SA28225] TikiWiki Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Cross Site Scripting
Released: 2007-12-24
Some vulnerabilities have been reported in TikiWiki, where some have unknown impacts and others can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28225/
--
[SA28217] TCPreen FD_SET Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-25
A vulnerability has been reported in TCPreen, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28217/
--
[SA28202] CuteNews "search.php" Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-12-24
Janek Vind has reported some vulnerabilities in CuteNews, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28202/
--
[SA28188] Woltlab Burning Board Lite "search.php" SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-21
nbbn has discovered some vulnerabilities in Wotlab Burning Board Lite, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28188/
--
[SA28239] PDFlib "pdc_fsearch_fopen()" Buffer Overflow Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-25
poplix has discovered a vulnerability in PDFlib, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28239/
--
[SA28235] SimpleForum "searchkey" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-25
Jose Luis Góngora Fernández has reported a vulnerability in SimpleForum Pro, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28235/
--
[SA28216] Sun Java System Web Server / Web Proxy Server Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-24
Some vulnerabilities have been reported in Sun Java System Web Server /
Web Proxy Server, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28216/
--
[SA28196] IBM HTTP Server Two Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-21
IBM has acknowledged two vulnerabilities in IBM HTTP Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28196/
--
[SA28190] Limbo "com_option" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-26
Omer Singer has discovered a vulnerability in Limbo, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28190/
--
[SA28237] Novell Identity Manager asampsp Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-12-26
A vulnerability has been reported in Novell Identity Manager, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28237/
Windows:--
[SA28236] Total Player M3U Playlist Parsing Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-26
David G.M. has discovered a vulnerability in Total Player, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28236/
--
[SA28218] Mercury LoadRunner XUpload ActiveX Control Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-26
A vulnerability has been discovered in HP Mercury LoadRunner, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28218/
--
[SA28215] WinAce UUE File Decompression Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-25
A vulnerability has been reported in WinAce, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28215/
--
[SA28214] Zoom Player Error Message Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-25
Luigi Auriemma has discovered a vulnerability in Zoom Player, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28214/
--
[SA28205] Groove Virtual Office XUpload ActiveX Control Buffer Overflow
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-26
A vulnerability has been discovered in Groove Virtual Office, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28205/
--
[SA28234] Ada Image Server Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2007-12-25
Some vulnerabilities have been discovered in Ada Image Server, which can be exploited by malicious people to conduct cross-site scripting attacks or gain knowledge of sensitive information.
Full Advisory:
http://secunia.com/advisories/28234/
--
[SA28208] WinUAE Floppy Disk Image File Loading Buffer Overflow
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-12-24
Luigi Auriemma has discovered a vulnerability in WinUAE, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28208/
--
[SA28206] Web Sihirbazi "default.asp" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-26
bypas has reported two vulnerabilities in Web Sihirbazi, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28206/
--
[SA28193] Aeries Browser Interface "EmailAddress" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-21
Aria-Security Team have reported a vulnerability in Aeries Browser Interface (ABI), which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28193/
--
[SA28252] IPortalX Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-27
Doz has reported some vulnerabilities in IPortalX, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28252/
UNIX/Linux:--
[SA28246] Fedora update for gallery2
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, System access
Released: 2007-12-26
Fedora has issued an update for gallery2. This fixes some vulnerabilities and a weakness, where some have unspecified impacts and others can be exploited by malicious users or malicious people to disclose sensitive information, conduct cross-site scripting attacks, bypass certain security restrictions, and potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28246/
--
[SA28213] SUSE update for flash-player
Critical: Highly critical
Where: From remote
Impact: Unknown, Security Bypass, Cross Site Scripting, Manipulation of data, Exposure of sensitive information, Privilege escalation, DoS, System access
Released: 2007-12-24
SUSE has issued an update for flash-player. This fixes some vulnerabilities, where one vulnerability has an unknown impact and others can be exploited by malicious, local users to gain escalated privileges and by malicious people to bypass certain security restrictions, conduct cross-site scripting and HTTP request splitting attacks, disclose sensitive information, cause a Denial of Service (DoS), or to potentially compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28213/
--
[SA28201] PMOS Help Desk PHP Code Execution and Security Bypass
Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2007-12-26
EgiX has discovered a vulnerability in PMOS Help Desk, which can be exploited by malicious people to bypass certain security restrictions and to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28201/
--
[SA28238] Bitflu StorageFarabDb Security Bypass Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2007-12-27
A vulnerability has been reported in Bitflu, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/28238/
--
[SA28207] Fedora update for wireshark
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-24
Fedora has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28207/
--
[SA28198] Moodle MRBS Module "id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-24
root at hanicker.it has reported a vulnerability in the MRBS Module for Moodle, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28198/
--
[SA28197] Fedora update for wireshark
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-21
Fedora has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28197/
--
[SA28195] Fedora update for libexif
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-21
Fedora has issued an update for libexif. This fixes two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28195/
--
[SA28200] Debian update for cupsys
Critical: Moderately critical
Where: From local network
Impact: Privilege escalation, DoS, System access
Released: 2007-12-27
Debian has issued an update for cupsys. This fixes a security issue and a vulnerability, which can be exploited by malicious, local users to perform certain actions with escalated privileges, and by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28200/
--
[SA28241] GreaseKit / Creammonkey GM API Vulnerability
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2007-12-26
A vulnerability was reported in GreaseKit / Creammonkey, which can be exploited by malicious people to bypass certain security restrictions.
Full Advisory:
http://secunia.com/advisories/28241/
--
[SA28224] Sun Solaris Apache Cross-Site Scripting and Denial of Service
Critical: Not critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2007-12-24
Sun has acknowledged some vulnerabilities in Apache for Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28224/
--
[SA28212] Sun Solaris Apache Cross-Site Scripting and Denial of Service
Critical: Not critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2007-12-24
Sun has acknowledged some vulnerabilities in Apache for Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28212/
Other:--
[SA28191] HP-UX rpc.yppasswdd Unspecified Denial of Service Vulnerability
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-12-21
A vulnerability has been reported in HP-UX, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28191/
--
[SA28192] HP Tru64 UNIX FFM Unspecified Denial of Service Vulnerability
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-12-21
A vulnerability has been reported in HP Tru64 UNIX, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28192/
Cross Platform:--
[SA28251] Mambo Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Unknown, Cross Site Scripting, System access
Released: 2007-12-27
Some vulnerabilities have been reported in Mambo, one with an unknown impact and others, which can be exploited by malicious people to conduct cross-site scripting attacks or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28251/
--
[SA28245] NmnNewsletter "output" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-26
CraCkEr has discovered a vulnerability in NmnNewsletter, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28245/
--
[SA28240] Shadowed Portal File Inclusion and PHP Code Execution
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-26
The:Paradox has discovered two vulnerabilities in Shadowed Portal, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28240/
--
[SA28233] VLC Media Player Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-12-25
Some vulnerabilities have been discovered in VLC Media Player, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
http://secunia.com/advisories/28233/
--
[SA28230] phpAutoVideo Two File Inclusion Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2007-12-25
MhZ91 has reported two vulnerabilities in phpAutoVideo, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Full Advisory:
http://secunia.com/advisories/28230/
--
[SA28250] XZero Community Classifieds "subcatid" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-27
Kw3rLn has reported a vulnerability in XZero Community Classifieds, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28250/
--
[SA28242] mBlog "page" Local File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2007-12-25
irk4z has discovered a vulnerability in mBlog, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28242/
--
[SA28232] MailMachinePRO "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, Manipulation of data
Released: 2007-12-26
MhZ91 has reported a vulnerability in MailMachinePRO, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28232/
--
[SA28225] TikiWiki Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Unknown, Cross Site Scripting
Released: 2007-12-24
Some vulnerabilities have been reported in TikiWiki, where some have unknown impacts and others can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28225/
--
[SA28217] TCPreen FD_SET Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-25
A vulnerability has been reported in TCPreen, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28217/
--
[SA28202] CuteNews "search.php" Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2007-12-24
Janek Vind has reported some vulnerabilities in CuteNews, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
http://secunia.com/advisories/28202/
--
[SA28188] Woltlab Burning Board Lite "search.php" SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-12-21
nbbn has discovered some vulnerabilities in Wotlab Burning Board Lite, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/28188/
--
[SA28239] PDFlib "pdc_fsearch_fopen()" Buffer Overflow Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2007-12-25
poplix has discovered a vulnerability in PDFlib, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Full Advisory:
http://secunia.com/advisories/28239/
--
[SA28235] SimpleForum "searchkey" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-25
Jose Luis Góngora Fernández has reported a vulnerability in SimpleForum Pro, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28235/
--
[SA28216] Sun Java System Web Server / Web Proxy Server Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-24
Some vulnerabilities have been reported in Sun Java System Web Server /
Web Proxy Server, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28216/
--
[SA28196] IBM HTTP Server Two Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-21
IBM has acknowledged two vulnerabilities in IBM HTTP Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28196/
--
[SA28190] Limbo "com_option" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-12-26
Omer Singer has discovered a vulnerability in Limbo, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/28190/
--
[SA28237] Novell Identity Manager asampsp Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2007-12-26
A vulnerability has been reported in Novell Identity Manager, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
http://secunia.com/advisories/28237/
Last edited by Tami on Fri Dec 28, 2007 5:11 am, edited 1 time in total.

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
