Secunia Vulnerabilities Content Listing for the week of December 4 2008
Windows:--
[SA32987] RadAsm ".rap" Processing Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-12-04
Data_Sniper has discovered a vulnerability in RadAsm, which can be exploited by malicious people to compromise a user's system.
Full Advisory: http://secunia.com/advisories/32987/
--
[SA33000] MailingListPro Database Disclosure Security Issue
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-12-04
AlpHaNiX has reported a security issue in MailingListPro, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: http://secunia.com/advisories/33000/
--
[SA32988] Rae Media Contact Management Software "Password" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-12-04
b3hz4d has reported a vulnerability in Rae Media Contact Management Software, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/32988/
--
[SA32941] Active Trade "username" and "password" SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-12-01
R3d D3v!L has reported some vulnerabilities in Active Trade, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/32941/
--
[SA32930] Ocean12 FAQ Manager Pro "ID" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-01
Stack has reported a vulnerability in Ocean12 FAQ Manager Pro, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/32930/
--
[SA32929] Ocean12 Mailing List Manager Gold Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2008-12-03
Pouya_Server has reported some vulnerabilities in Ocean12 Mailing List Manager Gold, which can be exploited by malicious users and people to conduct SQL injection attacks and by malicious people to conduct cross-site scripting attacks and disclose sensitive information.
Full Advisory: http://secunia.com/advisories/32929/
--
[SA32928] ASPReferral "AccountID" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-01
((r3d D3v!L)) has reported a vulnerability in ASPReferral, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/32928/
--
[SA32927] Active eWebquiz "useremail" and "password" SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Security Bypass
Released: 2008-12-01
R3d D3v!L has reported some vulnerabilities in Active eWebquiz, which
can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
http://secunia.com/advisories/32927/
--
[SA32922] Active Votes "AccountID" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-01
R3d D3v!L has reported a vulnerability in Active Votes, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/32922/
--
[SA32921] Active Products "password" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-12-01
R3d-D3v!L has reported some vulnerabilities in multiple Active products, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/32921/
--
[SA32920] Active Bids "ItemID" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-01
Stack has reported a vulnerability in Active Bids, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/32920/
--
[SA32976] Gallery MX "ID" SQL Injection Vulnerability
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-04
R3d D3v!L has reported a vulnerability in Gallery MX, which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/32976/
--
[SA32973] Calendar Mx Professional "ID" SQL Injection Vulnerability
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-04
R3d D3v!L has reported a vulnerability in Calendar Mx Professional, which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory: ttp://secunia.com/advisories/32973/
--
[SA32940] Microsoft Office Communications Server SIP INVITE Denial of Service
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-12-01
A vulnerability has been reported in Microsoft Office Communications Server, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/32940/
UNIX/Linux:--
[SA32963] Ubuntu update for imlib2
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-03
Ubuntu has issued an update for imlib2. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise an application using the library.
Full Advisory: http://secunia.com/advisories/32963/
--
[SA32962] Gentoo update for optipng
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-03
Gentoo has issued an update for optipng. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: http://secunia.com/advisories/32962/
--
[SA32949] Debian update for imlib2
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-01
Debian has issued an update for imlib2. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise an application using the library.
Full Advisory: http://secunia.com/advisories/32949/
--
[SA32979] PowerDNS CH HINFO Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-12-04
A vulnerability has been reported in PowerDNS, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/32979/
--
[SA32975] Gentoo update for mantisbt
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2008-12-03
Gentoo has issued an update for mantisbt. This fixes a security issue and a vulnerability, which can be exploited by malicious users to disclose potentially sensitive information and compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/32975/
--
[SA32974] Gentoo update for libxml2
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-03
Gentoo has issued an update to libxml2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.
Full Advisory: http://secunia.com/advisories/32974/
--
[SA32972] Gentoo update for lighttpd
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, DoS
Released: 2008-12-03
Gentoo has issued an update for lighttpd. This fixes a weakness and two vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, bypass certain security restrictions, and cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/32972/
--
[SA32971] Gentoo update for ipsec-tools
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-12-03
Gentoo has issued an update for ipsec-tools. This fixes some vulnerabilities, which can be exploited by malicious users and malicious people to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/32971/
--
[SA32970] Gentoo update for enscript
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-12-03
Gentoo has issued an update for enscript. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/32970/
--
[SA32948] Slackware update for ruby
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-12-01
Slackware has issued an update for ruby. This fixes a vulnerability, which can be exploited by malicious people to conduct spoofing attacks.
Full Advisory: http://secunia.com/advisories/32948/
--
[SA32946] Ubuntu update for libvorbis
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-02
Ubuntu has issued an update for libvorbis. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise an application using the library.
Full Advisory: http://secunia.com/advisories/32946/
--
[SA32945] Ubuntu update for imagemagick
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-02
Ubuntu has issued an update for imagemagick. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: http://secunia.com/advisories/32945/
--
[SA32944] Debian update for wireshark
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS
Released: 2008-12-01
Debian has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information or cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/32944/
--
[SA32936] Ubuntu update for clamav
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-12-03
Ubuntu has issued an update for clamav. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/32936/
--
[SA32934] WebGUI Executable Attachments Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-12-03
A vulnerability has been reported in WebGUI, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/32934/
--
[SA32926] ClamAV "cli_check_jpeg_exploit()" Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-12-02
A vulnerability has been reported in ClamAV, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/32926/
--
[SA32918] Ubuntu update for kernel
Critical: Moderately critical
Where: From remote
Impact: Privilege escalation, DoS, System access
Released: 2008-11-28
Ubuntu has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions and gain escalated privileges, and by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/32918/
--
[SA32917] Kolab Server ClamAV Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-03
Some vulnerabilities have been reported in Kolab Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/32917/
--
[SA33002] Ubuntu update for awstats
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-04
Ubuntu has issued an update for awstats. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: http://secunia.com/advisories/33002/
--
[SA32966] Fedora update for wordpress
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-03
Fedora has issued an update for wordpress. This fixes a vulnerability, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory: http://secunia.com/advisories/32966/
--
[SA32954] Debian update for phpmyadmin
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-02
Debian has issued an update for phpmyadmin. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: http://secunia.com/advisories/32954/
--
[SA32952] VMware ESX Server update for bzip2
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-12-03
VMware has issued an update for VMware ESX Server. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/32952/
--
[SA32939] Debian update for awstats
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-03
Debian has issued an update for awstats. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
http://secunia.com/advisories/32939/
--
[SA33003] Ubuntu update for net-snmp
Critical: Less critical
Where: From local network
Impact: DoS, System access
Released: 2008-12-04
Ubuntu has issued an update for net-snmp. This fixes some vulnerabilities, which can be exploited by malicious people to spoof authenticated SNMPv3 packets, cause a DoS (Denial of Service), and compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33003/
--
[SA32968] Fedora update for samba
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2008-12-03
Fedora has issued an update for samba. This fixes a vulnerability, which potentially can be exploited by malicious people to disclose sensitive information.
Full Advisory: http://secunia.com/advisories/32968/
--
[SA32951] Slackware update for samba
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2008-12-01
Slackware has issued an update for samba. This fixes a vulnerability, which potentially can be exploited by malicious people to disclose sensitive information.
Full Advisory: http://secunia.com/advisories/32951/
--
[SA32919] Ubuntu update for samba
Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2008-11-28
Ubuntu has issued an update for samba. This fixes a vulnerability, which potentially can be exploited by malicious people to disclose sensitive information.
Full Advisory: http://secunia.com/advisories/32919/
--
[SA32980] Debian update for perl
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-04
Debian has issued an update for perl. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: http://secunia.com/advisories/32980/
--
[SA32977] IBM HMC HTTP TRACE Response Cross-Site Scripting Weakness
Critical: Not critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-04
IBM has acknowledged a weakness in IBM HMC, which potentially can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: http://secunia.com/advisories/32977/
--
[SA32967] Fedora update for lynx
Critical: Not critical
Where: From remote
Impact: System access
Released: 2008-12-03
Fedora has issued an update for lynx. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory: http://secunia.com/advisories/32967/
--
[SA32969] HP-UX Unspecified Local Denial of Service Vulnerability
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-12-03
A vulnerability has been reported in HP-UX, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/32969/
--
[SA32961] Debian update for flamethrower
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-02
Debian has issued an update for flamethrower. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory:
http://secunia.com/advisories/32961/
--
[SA32960] DAHDI "ZT_SPANCONFIG" IOCTL Privilege Escalation Vulnerability
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-02
A vulnerability has been reported in DAHDI, which potentially can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: http://secunia.com/advisories/32960/
--
[SA32959] Debian update for jailer
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-01
Debian has issued an update for jailer. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: http://secunia.com/advisories/32959/
--
[SA32953] SUSE update for kernel
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-03
SUSE has issued an update for the kernel. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: http://secunia.com/advisories/32953/
--
[SA32947] Zaptel "ZT_SPANCONFIG" IOCTL Privilege Escalation Vulnerabilities
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-02
Some vulnerabilities have been reported in Zaptel, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and potentially gain escalated privileges.
Full Advisory: http://secunia.com/advisories/32947/
--
[SA32943] jailer "updatejail" Insecure Temporary Files
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-01
A security issue has been reported in jailer, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Full Advisory: http://secunia.com/advisories/32943/
--
[SA32933] Linux Kernel PARISC "parisc_show_stack()" Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-12-04
A vulnerability has been reported in the Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/32933/
Cross Platform:--
[SA32991] Sun Java JDK / JRE Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure
of sensitive information, DoS, System access
Released: 2008-12-04
Some vulnerabilities have been reported in Sun Java, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, cause a DoS (Denial of service), or compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/32991/
--
[SA32986] Multi SEO phpBB "pfad" File Inclusion Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-12-04
NoGe has discovered a vulnerability in Multi SEO phpBB, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/32986/
--
[SA32942] VLC Media Player Real Demuxer Integer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-01
A vulnerability has been discovered in VLC Media Player, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: http://secunia.com/advisories/32942/
--
[SA32964] PHP ZipArchive::extractTo() Directory Traversal Vulnerability
Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-12-04
Stefan Esser has reported a vulnerability in PHP, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/32964/
--
[SA32958] Check Up System for Thai Healthcare "search" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-04
CWH Underground has reported a vulnerability in Check Up System for Thai Healthcare, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/32958/
--
[SA32950] RakhiSoftware Shopping Cart Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of system information
Released: 2008-12-01
Charalambous Glafkos has reported some vulnerabilities in RakhiSoftware Shopping Cart, which can be exploited by malicious people to disclose system information, or to conduct SQL injection and cross-site scripting attacks.
Full Advisory: http://secunia.com/advisories/32950/
--
[SA32938] Basic PHP CMS "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-01
CWH Underground has discovered a vulnerability in Basic PHP CMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/32938/
--
[SA32932] Bluo CMS "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-01
The_5p3ctrum has reported a vulnerability in Bluo CMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/32932/
--
[SA32931] mvnForum Unspecified Cross-Site Scripting and Request Forgery
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-03
Some vulnerabilities have been reported in mvnForum, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks.
Full Advisory: http://secunia.com/advisories/32931/
--
[SA32925] PHP TV Portal "mid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-01
A vulnerability has been reported in PHP TV Portal, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/32925/
--
[SA32923] Sunbyte e-Flower "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-03
W4RL0CK has reported a vulnerability in Sunbyte e-Flower, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/32923/
--
[SA32924] CMS Made Simple "cms_language" Cookie Local File Inclusion
Critical: Moderately critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-12-01
A vulnerability has been discovered in CMS Made Simple, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory: http://secunia.com/advisories/32924/
--
[SA32996] W3matter RevSense "section" Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-04
Pouya_Server has reported a vulnerability in W3matter RevSense, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: http://secunia.com/advisories/32996/
--
[SA32985] ImpressCMS Session Fixation Vulnerability
Critical: Less critical
Where: From remote
Impact: Hijacking
Released: 2008-12-04
A vulnerability has been reported in ImpressCMS, which can be exploited by malicious people to conduct session fixation attacks.
Full Advisory: http://secunia.com/advisories/32985/
--
[SA32978] Drupal Storm Module SQL Injection Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-04
Jakub Suchy has reported some vulnerabilities in the Storm module for Drupal, which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/32978/
--
[SA32957] IBM Rational ClearCase Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-02
A vulnerability has been reported in IBM Rational ClearCase, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: http://secunia.com/advisories/32957/
--
[SA32937] iNet Orkut Clone "id" SQL Injection and Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-12-03
d3b4g has reported some vulnerabilities in iNet Orkut Clone, which can be exploited by malicious users to conduct SQL injection attacks and malicious people to conduct cross-site scripting attacks.
Full Advisory: http://secunia.com/advisories/32937/
--
[SA32935] Movable Type Unspecified Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-03
A vulnerability has been reported in Movable Type, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: http://secunia.com/advisories/32935/
--
[SA32965] VMware ESX / ESXi Virtual Hardware Memory Corruption Vulnerability
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-12-03
A vulnerability has been reported in VMware ESX / ESXi, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory: http://secunia.com/advisories/32965/
Secunia Updates - December 2008
Moderators: Moderator, Global Moderator
Secunia Updates - December 2008

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Secunia Updates - December 2008
Secunia Vulnerabilities Content Listing for the week of December 26 2008
Windows:--
[SA33257] webcamXP Directory Traversal Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-12-22
nicx0 has discovered a vulnerability in webcamXP, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: http://secunia.com/advisories/33257/
--
[SA33245] Emefa Guestbook Database Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-12-22
Cyber.Zer0 has discovered a security issue in Emefa Guestbook, which cab be exploited by malicious people to disclose sensitive
information.
Full Advisory: http://secunia.com/advisories/33245/
--
[SA33281] Hitachi GroupMax Workflow Development Kit Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-22
A vulnerability has been reported in Groupmax Web Workflow SDK Set for Active Server Pages and Groupmax Workflow Development Kit for Active Server Pages, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: http://secunia.com/advisories/33281/
--
[SA33249] PowerStrip "pstrip.sys" IOCTL Handling Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-22
alex has discovered a vulnerability in PowerStrip, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: http://secunia.com/advisories/33249/
--
[SA33310] PGP Desktop PGPwded.sys Driver Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-12-24
A vulnerability has been discovered in PGP Desktop, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/33310/
UNIX/Linux:--
[SA33323] Gentoo update for imlib2
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-24
Gentoo has issued an update for imlib2. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise an application using the library.
Full Advisory: http://secunia.com/advisories/33323/
--
[SA33315] Gentoo update for vlc
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-24
Gentoo has issued an update for vlc. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: http://secunia.com/advisories/33315/
--
[SA33297] Fedora update for firefox and xulrunner
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, System access
Released: 2008-12-22
Fedora has issued an update for firefox and xulrunner. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, conduct cross-site scripting attacks, or potentially compromise a user's
system.
Full Advisory: http://secunia.com/advisories/33297/
--
[SA33294] SUSE update for flash-player
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-12-22
SUSE has issued an update for flash-player. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: http://secunia.com/advisories/33294/
--
[SA33291] Fedora update for moodle
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-12-22
Fedora has issued an update for moodle. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33291/
--
[SA33285] Fedora update for firefox
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, System access
Released: 2008-12-22
Fedora has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, conduct cross-site scripting attacks, or potentially compromise a user's system.
Full Advisory: http://secunia.com/advisories/33285/
--
[SA33284] Fedora update for seamonkey
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, System access
Released: 2008-12-22
Fedora has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, disclose sensitive information, conduct cross-site scripting attacks, or potentially compromise a user's
system.
Full Advisory: http://secunia.com/advisories/33284/
--
[SA33267] Red Hat update for flash-plugin
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-12-22
Red Hat has issued an update for flash-plugin. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: http://secunia.com/advisories/33267/
--
[SA33241] Ubuntu update for imlib2
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-22
Ubuntu has issued an update for imlib2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise an application using the library.
Full Advisory: http://secunia.com/advisories/33241/
--
[SA33240] BitDefender Antivirus Scanner for Unices PE File Parsing Integer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-12-19
Some vulnerabilities have been reported in BitDefender, which potentially can be exploited by malicious people to compromise a
vulnerable system.
Full Advisory: http://secunia.com/advisories/33240/
--
[SA33238] Red Hat update for java-1.6.0-bea
Critical: Highly critical
Where: From remote
Impact: System access, DoS, Exposure of sensitive information, Exposure of system information, Security Bypass
Released: 2008-12-19
Red Hat has issued an update for java-1.6.0-bea. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, disclose system information or potentially sensitive information, cause a DoS (Denial of Service), or
compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33238/
--
[SA33237] Red Hat update for java-1.5.0-bea
Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-12-19
Red Hat has issued an update for java-1.5.0-bea. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, cause a DoS (Denial of Service), and compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33237/
--
[SA33236] Red Hat update for java-1.4.2-bea
Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-12-19
Red Hat has issued an update for java-1.4.2-bea. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions and compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33236/
--
[SA33317] Gentoo update for clamav
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-24
Gentoo has issued an update for clamav. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33317/
--
[SA33314] Ubuntu update for perl
Critical: Moderately critical
Where: From remote
Impact: Privilege escalation, DoS, System access
Released: 2008-12-24
Ubuntu has issued an update for perl. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated
privileges and by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33314/
--
[SA33290] Fedora update for roundcubemail
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-12-22
Fedora has issued an update for roundcubemail. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/33290/
--
[SA33287] Fedora update for rsyslog
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-12-22
Fedora has issued an update for rsyslog. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security
restrictions.
Full Advisory: http://secunia.com/advisories/33287/
--
[SA33286] Fedora update for phpPgAdmin
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-12-22
Fedora has issued an update for phpPgAdmin. This fixes a vulnerability, which can be exploited by malicious people to disclose sensitive
information.
Full Advisory: http://secunia.com/advisories/33286/
--
[SA33264] Gentoo update for pdns
Critical: Moderately critical
Where: From remote
Impact: Spoofing, DoS
Released: 2008-12-22
Gentoo has issued an update for pdns. This fixes a weakness and a vulnerability, which can be exploited by malicious people to conduct
spoofing attacks or cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/33264/
--
[SA33259] Debian update for courier-authlib
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-22
Debian has issued an update for courier-authlib. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
SQL injection attacks.
Full Advisory: http://secunia.com/advisories/33259/
--
[SA33258] Gentoo phpCollab Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-22
Gentoo has acknowledged some vulnerabilities in phpCollab, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/33258/
--
[SA33243] Ubuntu update for blender
Critical: Moderately critical
Where: From remote
Impact: Privilege escalation, System access
Released: 2008-12-22
Ubuntu has issued an update for blender. This fixes some vulnerabilities, which can be exploited by malicious, local users to
gain escalated privileges and by malicious people to compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33243/
--
[SA33235] Courier Authentication Library Postgres SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-19
A vulnerability has been reported in the Courier Authentication Library, which can be exploited by malicious people to conduct SQL
injection attacks.
Full Advisory: http://secunia.com/advisories/33235/
--
[SA33260] rPath update for cups
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-12-22
rPath has issued an update for cups. This fixes some vulnerabilities, which can potentially be exploited by malicious people to compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33260/
--
[SA33320] Ubuntu update for nagios2
Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-12-24
Ubuntu has issued an update for nagios2. This fixes some vulnerabilities, which can be exploited by malicious users to bypass
certain security restrictions or by malicious people to conduct cross-site request forgery attacks.
Full Advisory: http://secunia.com/advisories/33320/
--
[SA33299] rPath update for dovecot
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-12-23
rPath has issued an update for dovecot. This fixes a security issue, which can be exploited by malicious users to bypass certain security
restrictions.
Full Advisory: http://secunia.com/advisories/33299/
--
[SA33275] UW-imapd c-client Library Off-by-one Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-12-22
A vulnerability has been reported in UW-imapd, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/33275/
--
[SA33261] Debian update for proftpd-dfsg
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-22
Debian has issued an update for proftpd-dfsg. This fixes a vulnerability, which can be exploited by malicious people to conduct
cross-site request forgery attacks.
Full Advisory: http://secunia.com/advisories/33261/
--
[SA33242] Avaya CMS / IR Java JRE Zip Archive Parsing Vulnerability
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-12-22
Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: http://secunia.com/advisories/33242/
--
[SA33239] Debian update for moodle
Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-12-22
Debian has issued an update for moodle. This fixes some vulnerabilities, which can be exploited by malicious users to conduct script insertion attacks, and by malicious people to bypass certain security restrictions or conduct cross-site request forgery and cross-site scripting attacks.
Full Advisory: http://secunia.com/advisories/33239/
--
[SA33234] Ubuntu update for nagios3
Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-12-23
Ubuntu has issued an update for nagios3. This fixes some vulnerabilities, which can be exploited by malicious users to bypass certain security restrictions or by malicious people to conduct cross-site request forgery attacks.
Full Advisory: http://secunia.com/advisories/33234/
--
[SA33288] Fedora update for openvpn
Critical: Less critical
Where: From local network
Impact: System access
Released: 2008-12-22
Fedora has issued an update for openvpn. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33288/
--
[SA33279] Debian update for avahi
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-12-22
Debian has issued an update for avahi. This fixes a security issue and a vulnerability, which can be exploited by malicious, local users and
by malicious people to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/33279/
--
[SA33292] Fedora update for libvirt
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-12-22
Fedora has issued an update for libvirt. This fixes a security issue, which can be exploited by malicious, local users to bypass certain
security restrictions.
Full Advisory: http://secunia.com/advisories/33292/
--
[SA33282] Fedora update for git
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-22
Fedora has issued an update for git. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: http://secunia.com/advisories/33282/
--
[SA33278] PDFjam Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-22
Some security issues have been reported in PDFjam, which can be exploited by malicious, local users to perform certain actions with
escalated privileges.
Full Advisory: http://secunia.com/advisories/33278/
--
[SA33270] GIT "gitweb" Privilege Escalation Security Issue
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-22
A security issue has been reported in GIT, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: http://secunia.com/advisories/33270/
--
[SA33316] Gentoo update for ampache
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-24
Gentoo has issued an update for ampache. This fixes a security issue, which can be exploited by malicious local users to perform certain
actions with escalated privileges.
Full Advisory: http://secunia.com/advisories/33316/
--
[SA33303] KVM VNC "protocol_client_msg()" Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-12-23
A security issue has been reported in KVM, which can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/33303/
Cross Platform:--
[SA33272] Yourplace Security Issue and Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, DoS, System access
Released: 2008-12-23
Some vulnerabilities and a security issue have been discovered in Yourplace, which can be exploited by malicious people to disclose potentially sensitive information, bypass certain security restrictions, cause a DoS (Denial of Service), and compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33272/
--
[SA33247] ReVou Twitter Clone Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-12-22
Some vulnerabilities have been reported in ReVou Twitter Clone, which can be exploited by malicious people to bypass certain security
restrictions and by malicious users to potentially compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33247/
--
[SA33302] TYPO3 WEBERkommunal Facilities Extension SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-23
A vulnerability has been reported in the WEBERkommunal Facilities (wes_facilities) extension for TYPO3, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/33302/
--
[SA33301] TYPO3 Simple File Browser Extension Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-12-23
A vulnerability has been reported in the Simple File Browser (simplefilebrowser) extension for TYPO3, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: http://secunia.com/advisories/33301/
--
[SA33277] KnowledgeTree Cross-Site Scripting and Privilege Escalation
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Privilege escalation
Released: 2008-12-22
Some vulnerabilities have been reported in KnowledgeTree, which can be exploited by malicious users to gain escalated privileges and by malicious people to conduct cross-site scripting attacks.
Full Advisory: http://secunia.com/advisories/33277/
--
[SA33276] Text Lines Rearrange Script "filename" File Disclosure Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-12-23
SirGod has discovered a vulnerability in Text Lines Rearrange Script, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: http://secunia.com/advisories/33276/
--
[SA33274] Wordpress Page Flip Image Gallery Plugin "book_id" File Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-12-23
GoLd_M has discovered a vulnerability in the Page Flip Image Gallery plugin for Wordpress, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: http://secunia.com/advisories/33274/
--
[SA33271] Joomla Volunteer Management System Component "job_id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-23
boom3rang has reported a vulnerability in the Volunteer Management System component for Joomla, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/33271/
--
[SA33269] SolarCMS Forum Component "cat" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-23
athos has discovered a vulnerability in the Forum component for SolarCMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/33269/
--
[SA33266] MySQL Calendar "username" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-12-23
StAkeR has discovered a vulnerability in MySQL Calendar, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/33266/
--
[SA33255] Emetrix Multiple Products "filename" File Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-12-22
Cold z3ro has reported a vulnerability in multiple Emetrix products, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: http://secunia.com/advisories/33255/
--
[SA33254] TYPO3 WEC Discussion Forum Extension Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-12-23
Some vulnerabilities have been reported in the WEC Discussion Forum (wec_discussion) extension for TYPO3, which can be exploited by malicious people to conduct SQL injection and cross-site scripting attacks.
Full Advisory: http://secunia.com/advisories/33254/
--
[SA33253] myPHPscripts Login Session Cross-Site Scripting and Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information
Released: 2008-12-22
Osirys has discovered a security issue and some vulnerabilities in myPHPscripts Login Session, which can be exploited by malicious people to conduct cross-site scripting attacks or disclose sensitive information.
Full Advisory: http://secunia.com/advisories/33253/
--
[SA33252] FreeLyrics "p" File Disclosure Security Issue
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-12-22
Piker has discovered a security issue in FreeLyrics, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: http://secunia.com/advisories/33252/
--
[SA33250] Constructr CMS "show_page" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-22
A vulnerability has been discovered in Constructr CMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/33250/
--
[SA33248] REDPEACH CMS "zv" SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-23
Lidloses_Auge has reported some vulnerabilities in REDPEACH CMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/33248/
--
[SA33246] TYPO3 phpMyAdmin Extension Cross-Site Request Forgery
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-23
A vulnerability has been reported in the phpMyAdmin (phpmyadmin) extension for TYPO3, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
http://secunia.com/advisories/33246/
--
[SA33311] Psi File Transfer Service Packet Parsing Vulnerabilities
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-12-24
sha0 has discovered some vulnerabilities in Psi, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/33311/
--
[SA33289] Fedora update for drupal-views
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-22
Fedora has issued an update for drupal-views. This fixes some vulnerabilities, which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/33289/
--
[SA33262] TYPO3 Vox populi Extension Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-23
A vulnerability has been reported in the Vox populi (mv_vox_populi) extension for TYPO3, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: http://secunia.com/advisories/33262/
--
[SA33256] TYPO3 DR Wiki Extension Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-23
A vulnerability has been reported in the DR Wiki (dr_wiki) extension for TYPO3, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory: http://secunia.com/advisories/33256/
--
[SA33293] QEMU VNC "protocol_client_msg()" Denial of Service
Critical: Not critical
Where: From local network
Impact: DoS
Released: 2008-12-23
A security issue has been reported in QEMU, which can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/33293/
Windows:--
[SA33257] webcamXP Directory Traversal Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-12-22
nicx0 has discovered a vulnerability in webcamXP, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: http://secunia.com/advisories/33257/
--
[SA33245] Emefa Guestbook Database Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-12-22
Cyber.Zer0 has discovered a security issue in Emefa Guestbook, which cab be exploited by malicious people to disclose sensitive
information.
Full Advisory: http://secunia.com/advisories/33245/
--
[SA33281] Hitachi GroupMax Workflow Development Kit Cross-Site Scripting Vulnerability
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-22
A vulnerability has been reported in Groupmax Web Workflow SDK Set for Active Server Pages and Groupmax Workflow Development Kit for Active Server Pages, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: http://secunia.com/advisories/33281/
--
[SA33249] PowerStrip "pstrip.sys" IOCTL Handling Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-22
alex has discovered a vulnerability in PowerStrip, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: http://secunia.com/advisories/33249/
--
[SA33310] PGP Desktop PGPwded.sys Driver Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-12-24
A vulnerability has been discovered in PGP Desktop, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/33310/
UNIX/Linux:--
[SA33323] Gentoo update for imlib2
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-24
Gentoo has issued an update for imlib2. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise an application using the library.
Full Advisory: http://secunia.com/advisories/33323/
--
[SA33315] Gentoo update for vlc
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-24
Gentoo has issued an update for vlc. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: http://secunia.com/advisories/33315/
--
[SA33297] Fedora update for firefox and xulrunner
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, System access
Released: 2008-12-22
Fedora has issued an update for firefox and xulrunner. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, conduct cross-site scripting attacks, or potentially compromise a user's
system.
Full Advisory: http://secunia.com/advisories/33297/
--
[SA33294] SUSE update for flash-player
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-12-22
SUSE has issued an update for flash-player. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: http://secunia.com/advisories/33294/
--
[SA33291] Fedora update for moodle
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-12-22
Fedora has issued an update for moodle. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33291/
--
[SA33285] Fedora update for firefox
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, System access
Released: 2008-12-22
Fedora has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, conduct cross-site scripting attacks, or potentially compromise a user's system.
Full Advisory: http://secunia.com/advisories/33285/
--
[SA33284] Fedora update for seamonkey
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, System access
Released: 2008-12-22
Fedora has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, disclose sensitive information, conduct cross-site scripting attacks, or potentially compromise a user's
system.
Full Advisory: http://secunia.com/advisories/33284/
--
[SA33267] Red Hat update for flash-plugin
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-12-22
Red Hat has issued an update for flash-plugin. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory: http://secunia.com/advisories/33267/
--
[SA33241] Ubuntu update for imlib2
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-22
Ubuntu has issued an update for imlib2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise an application using the library.
Full Advisory: http://secunia.com/advisories/33241/
--
[SA33240] BitDefender Antivirus Scanner for Unices PE File Parsing Integer Overflows
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-12-19
Some vulnerabilities have been reported in BitDefender, which potentially can be exploited by malicious people to compromise a
vulnerable system.
Full Advisory: http://secunia.com/advisories/33240/
--
[SA33238] Red Hat update for java-1.6.0-bea
Critical: Highly critical
Where: From remote
Impact: System access, DoS, Exposure of sensitive information, Exposure of system information, Security Bypass
Released: 2008-12-19
Red Hat has issued an update for java-1.6.0-bea. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, disclose system information or potentially sensitive information, cause a DoS (Denial of Service), or
compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33238/
--
[SA33237] Red Hat update for java-1.5.0-bea
Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-12-19
Red Hat has issued an update for java-1.5.0-bea. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, cause a DoS (Denial of Service), and compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33237/
--
[SA33236] Red Hat update for java-1.4.2-bea
Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-12-19
Red Hat has issued an update for java-1.4.2-bea. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions and compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33236/
--
[SA33317] Gentoo update for clamav
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-24
Gentoo has issued an update for clamav. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33317/
--
[SA33314] Ubuntu update for perl
Critical: Moderately critical
Where: From remote
Impact: Privilege escalation, DoS, System access
Released: 2008-12-24
Ubuntu has issued an update for perl. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated
privileges and by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33314/
--
[SA33290] Fedora update for roundcubemail
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-12-22
Fedora has issued an update for roundcubemail. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/33290/
--
[SA33287] Fedora update for rsyslog
Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-12-22
Fedora has issued an update for rsyslog. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security
restrictions.
Full Advisory: http://secunia.com/advisories/33287/
--
[SA33286] Fedora update for phpPgAdmin
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-12-22
Fedora has issued an update for phpPgAdmin. This fixes a vulnerability, which can be exploited by malicious people to disclose sensitive
information.
Full Advisory: http://secunia.com/advisories/33286/
--
[SA33264] Gentoo update for pdns
Critical: Moderately critical
Where: From remote
Impact: Spoofing, DoS
Released: 2008-12-22
Gentoo has issued an update for pdns. This fixes a weakness and a vulnerability, which can be exploited by malicious people to conduct
spoofing attacks or cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/33264/
--
[SA33259] Debian update for courier-authlib
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-22
Debian has issued an update for courier-authlib. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
SQL injection attacks.
Full Advisory: http://secunia.com/advisories/33259/
--
[SA33258] Gentoo phpCollab Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-22
Gentoo has acknowledged some vulnerabilities in phpCollab, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/33258/
--
[SA33243] Ubuntu update for blender
Critical: Moderately critical
Where: From remote
Impact: Privilege escalation, System access
Released: 2008-12-22
Ubuntu has issued an update for blender. This fixes some vulnerabilities, which can be exploited by malicious, local users to
gain escalated privileges and by malicious people to compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33243/
--
[SA33235] Courier Authentication Library Postgres SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-19
A vulnerability has been reported in the Courier Authentication Library, which can be exploited by malicious people to conduct SQL
injection attacks.
Full Advisory: http://secunia.com/advisories/33235/
--
[SA33260] rPath update for cups
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-12-22
rPath has issued an update for cups. This fixes some vulnerabilities, which can potentially be exploited by malicious people to compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33260/
--
[SA33320] Ubuntu update for nagios2
Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-12-24
Ubuntu has issued an update for nagios2. This fixes some vulnerabilities, which can be exploited by malicious users to bypass
certain security restrictions or by malicious people to conduct cross-site request forgery attacks.
Full Advisory: http://secunia.com/advisories/33320/
--
[SA33299] rPath update for dovecot
Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-12-23
rPath has issued an update for dovecot. This fixes a security issue, which can be exploited by malicious users to bypass certain security
restrictions.
Full Advisory: http://secunia.com/advisories/33299/
--
[SA33275] UW-imapd c-client Library Off-by-one Vulnerability
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-12-22
A vulnerability has been reported in UW-imapd, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/33275/
--
[SA33261] Debian update for proftpd-dfsg
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-22
Debian has issued an update for proftpd-dfsg. This fixes a vulnerability, which can be exploited by malicious people to conduct
cross-site request forgery attacks.
Full Advisory: http://secunia.com/advisories/33261/
--
[SA33242] Avaya CMS / IR Java JRE Zip Archive Parsing Vulnerability
Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-12-22
Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: http://secunia.com/advisories/33242/
--
[SA33239] Debian update for moodle
Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-12-22
Debian has issued an update for moodle. This fixes some vulnerabilities, which can be exploited by malicious users to conduct script insertion attacks, and by malicious people to bypass certain security restrictions or conduct cross-site request forgery and cross-site scripting attacks.
Full Advisory: http://secunia.com/advisories/33239/
--
[SA33234] Ubuntu update for nagios3
Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-12-23
Ubuntu has issued an update for nagios3. This fixes some vulnerabilities, which can be exploited by malicious users to bypass certain security restrictions or by malicious people to conduct cross-site request forgery attacks.
Full Advisory: http://secunia.com/advisories/33234/
--
[SA33288] Fedora update for openvpn
Critical: Less critical
Where: From local network
Impact: System access
Released: 2008-12-22
Fedora has issued an update for openvpn. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33288/
--
[SA33279] Debian update for avahi
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-12-22
Debian has issued an update for avahi. This fixes a security issue and a vulnerability, which can be exploited by malicious, local users and
by malicious people to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/33279/
--
[SA33292] Fedora update for libvirt
Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-12-22
Fedora has issued an update for libvirt. This fixes a security issue, which can be exploited by malicious, local users to bypass certain
security restrictions.
Full Advisory: http://secunia.com/advisories/33292/
--
[SA33282] Fedora update for git
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-22
Fedora has issued an update for git. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: http://secunia.com/advisories/33282/
--
[SA33278] PDFjam Insecure Temporary Files
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-22
Some security issues have been reported in PDFjam, which can be exploited by malicious, local users to perform certain actions with
escalated privileges.
Full Advisory: http://secunia.com/advisories/33278/
--
[SA33270] GIT "gitweb" Privilege Escalation Security Issue
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-22
A security issue has been reported in GIT, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory: http://secunia.com/advisories/33270/
--
[SA33316] Gentoo update for ampache
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-24
Gentoo has issued an update for ampache. This fixes a security issue, which can be exploited by malicious local users to perform certain
actions with escalated privileges.
Full Advisory: http://secunia.com/advisories/33316/
--
[SA33303] KVM VNC "protocol_client_msg()" Denial of Service
Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-12-23
A security issue has been reported in KVM, which can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/33303/
Cross Platform:--
[SA33272] Yourplace Security Issue and Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, DoS, System access
Released: 2008-12-23
Some vulnerabilities and a security issue have been discovered in Yourplace, which can be exploited by malicious people to disclose potentially sensitive information, bypass certain security restrictions, cause a DoS (Denial of Service), and compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33272/
--
[SA33247] ReVou Twitter Clone Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-12-22
Some vulnerabilities have been reported in ReVou Twitter Clone, which can be exploited by malicious people to bypass certain security
restrictions and by malicious users to potentially compromise a vulnerable system.
Full Advisory: http://secunia.com/advisories/33247/
--
[SA33302] TYPO3 WEBERkommunal Facilities Extension SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-23
A vulnerability has been reported in the WEBERkommunal Facilities (wes_facilities) extension for TYPO3, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/33302/
--
[SA33301] TYPO3 Simple File Browser Extension Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-12-23
A vulnerability has been reported in the Simple File Browser (simplefilebrowser) extension for TYPO3, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: http://secunia.com/advisories/33301/
--
[SA33277] KnowledgeTree Cross-Site Scripting and Privilege Escalation
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Privilege escalation
Released: 2008-12-22
Some vulnerabilities have been reported in KnowledgeTree, which can be exploited by malicious users to gain escalated privileges and by malicious people to conduct cross-site scripting attacks.
Full Advisory: http://secunia.com/advisories/33277/
--
[SA33276] Text Lines Rearrange Script "filename" File Disclosure Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-12-23
SirGod has discovered a vulnerability in Text Lines Rearrange Script, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: http://secunia.com/advisories/33276/
--
[SA33274] Wordpress Page Flip Image Gallery Plugin "book_id" File Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-12-23
GoLd_M has discovered a vulnerability in the Page Flip Image Gallery plugin for Wordpress, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: http://secunia.com/advisories/33274/
--
[SA33271] Joomla Volunteer Management System Component "job_id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-23
boom3rang has reported a vulnerability in the Volunteer Management System component for Joomla, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/33271/
--
[SA33269] SolarCMS Forum Component "cat" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-23
athos has discovered a vulnerability in the Forum component for SolarCMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/33269/
--
[SA33266] MySQL Calendar "username" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-12-23
StAkeR has discovered a vulnerability in MySQL Calendar, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/33266/
--
[SA33255] Emetrix Multiple Products "filename" File Disclosure
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-12-22
Cold z3ro has reported a vulnerability in multiple Emetrix products, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: http://secunia.com/advisories/33255/
--
[SA33254] TYPO3 WEC Discussion Forum Extension Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-12-23
Some vulnerabilities have been reported in the WEC Discussion Forum (wec_discussion) extension for TYPO3, which can be exploited by malicious people to conduct SQL injection and cross-site scripting attacks.
Full Advisory: http://secunia.com/advisories/33254/
--
[SA33253] myPHPscripts Login Session Cross-Site Scripting and Information Disclosure
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information
Released: 2008-12-22
Osirys has discovered a security issue and some vulnerabilities in myPHPscripts Login Session, which can be exploited by malicious people to conduct cross-site scripting attacks or disclose sensitive information.
Full Advisory: http://secunia.com/advisories/33253/
--
[SA33252] FreeLyrics "p" File Disclosure Security Issue
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-12-22
Piker has discovered a security issue in FreeLyrics, which can be exploited by malicious people to disclose sensitive information.
Full Advisory: http://secunia.com/advisories/33252/
--
[SA33250] Constructr CMS "show_page" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-22
A vulnerability has been discovered in Constructr CMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/33250/
--
[SA33248] REDPEACH CMS "zv" SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-23
Lidloses_Auge has reported some vulnerabilities in REDPEACH CMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/33248/
--
[SA33246] TYPO3 phpMyAdmin Extension Cross-Site Request Forgery
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-23
A vulnerability has been reported in the phpMyAdmin (phpmyadmin) extension for TYPO3, which can be exploited by malicious people to conduct cross-site request forgery attacks.
Full Advisory:
http://secunia.com/advisories/33246/
--
[SA33311] Psi File Transfer Service Packet Parsing Vulnerabilities
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-12-24
sha0 has discovered some vulnerabilities in Psi, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/33311/
--
[SA33289] Fedora update for drupal-views
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-22
Fedora has issued an update for drupal-views. This fixes some vulnerabilities, which can be exploited by malicious users to conduct SQL injection attacks.
Full Advisory: http://secunia.com/advisories/33289/
--
[SA33262] TYPO3 Vox populi Extension Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-23
A vulnerability has been reported in the Vox populi (mv_vox_populi) extension for TYPO3, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory: http://secunia.com/advisories/33262/
--
[SA33256] TYPO3 DR Wiki Extension Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-23
A vulnerability has been reported in the DR Wiki (dr_wiki) extension for TYPO3, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory: http://secunia.com/advisories/33256/
--
[SA33293] QEMU VNC "protocol_client_msg()" Denial of Service
Critical: Not critical
Where: From local network
Impact: DoS
Released: 2008-12-23
A security issue has been reported in QEMU, which can be exploited by malicious users to cause a DoS (Denial of Service).
Full Advisory: http://secunia.com/advisories/33293/

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
