Page 1 of 1

Secunia Updates - December 2008

Posted: Fri Dec 05, 2008 1:19 am
by Tami
Secunia Vulnerabilities Content Listing for the week of December 4 2008

Windows:--

[SA32987] RadAsm ".rap" Processing Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-12-04

Data_Sniper has discovered a vulnerability in RadAsm, which can be exploited by malicious people to compromise a user's system.

Full Advisory: http://secunia.com/advisories/32987/

--

[SA33000] MailingListPro Database Disclosure Security Issue

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-12-04

AlpHaNiX has reported a security issue in MailingListPro, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: http://secunia.com/advisories/33000/

--

[SA32988] Rae Media Contact Management Software "Password" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-12-04

b3hz4d has reported a vulnerability in Rae Media Contact Management Software, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/32988/

--

[SA32941] Active Trade "username" and "password" SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-12-01

R3d D3v!L has reported some vulnerabilities in Active Trade, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/32941/

--

[SA32930] Ocean12 FAQ Manager Pro "ID" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-01

Stack has reported a vulnerability in Ocean12 FAQ Manager Pro, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/32930/

--

[SA32929] Ocean12 Mailing List Manager Gold Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2008-12-03

Pouya_Server has reported some vulnerabilities in Ocean12 Mailing List Manager Gold, which can be exploited by malicious users and people to conduct SQL injection attacks and by malicious people to conduct cross-site scripting attacks and disclose sensitive information.

Full Advisory: http://secunia.com/advisories/32929/

--

[SA32928] ASPReferral "AccountID" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-01

((r3d D3v!L)) has reported a vulnerability in ASPReferral, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/32928/

--

[SA32927] Active eWebquiz "useremail" and "password" SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Security Bypass
Released: 2008-12-01

R3d D3v!L has reported some vulnerabilities in Active eWebquiz, which
can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/32927/

--

[SA32922] Active Votes "AccountID" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-01

R3d D3v!L has reported a vulnerability in Active Votes, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/32922/

--

[SA32921] Active Products "password" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-12-01

R3d-D3v!L has reported some vulnerabilities in multiple Active products, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/32921/

--

[SA32920] Active Bids "ItemID" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-01

Stack has reported a vulnerability in Active Bids, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/32920/

--

[SA32976] Gallery MX "ID" SQL Injection Vulnerability

Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-04

R3d D3v!L has reported a vulnerability in Gallery MX, which can be exploited by malicious users to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/32976/

--

[SA32973] Calendar Mx Professional "ID" SQL Injection Vulnerability

Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-04

R3d D3v!L has reported a vulnerability in Calendar Mx Professional, which can be exploited by malicious users to conduct SQL injection attacks.

Full Advisory: ttp://secunia.com/advisories/32973/

--

[SA32940] Microsoft Office Communications Server SIP INVITE Denial of Service

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-12-01

A vulnerability has been reported in Microsoft Office Communications Server, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: http://secunia.com/advisories/32940/


UNIX/Linux:--

[SA32963] Ubuntu update for imlib2

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-03

Ubuntu has issued an update for imlib2. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise an application using the library.

Full Advisory: http://secunia.com/advisories/32963/

--

[SA32962] Gentoo update for optipng

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-03

Gentoo has issued an update for optipng. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: http://secunia.com/advisories/32962/

--

[SA32949] Debian update for imlib2

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-01

Debian has issued an update for imlib2. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise an application using the library.

Full Advisory: http://secunia.com/advisories/32949/

--

[SA32979] PowerDNS CH HINFO Denial of Service Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-12-04

A vulnerability has been reported in PowerDNS, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: http://secunia.com/advisories/32979/

--

[SA32975] Gentoo update for mantisbt

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2008-12-03

Gentoo has issued an update for mantisbt. This fixes a security issue and a vulnerability, which can be exploited by malicious users to disclose potentially sensitive information and compromise a vulnerable system.

Full Advisory: http://secunia.com/advisories/32975/

--

[SA32974] Gentoo update for libxml2

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-03

Gentoo has issued an update to libxml2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.

Full Advisory: http://secunia.com/advisories/32974/

--

[SA32972] Gentoo update for lighttpd

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, DoS
Released: 2008-12-03

Gentoo has issued an update for lighttpd. This fixes a weakness and two vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, bypass certain security restrictions, and cause a DoS (Denial of Service).

Full Advisory: http://secunia.com/advisories/32972/

--

[SA32971] Gentoo update for ipsec-tools

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-12-03

Gentoo has issued an update for ipsec-tools. This fixes some vulnerabilities, which can be exploited by malicious users and malicious people to cause a DoS (Denial of Service).

Full Advisory: http://secunia.com/advisories/32971/

--

[SA32970] Gentoo update for enscript

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-12-03

Gentoo has issued an update for enscript. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: http://secunia.com/advisories/32970/

--

[SA32948] Slackware update for ruby

Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-12-01

Slackware has issued an update for ruby. This fixes a vulnerability, which can be exploited by malicious people to conduct spoofing attacks.

Full Advisory: http://secunia.com/advisories/32948/

--

[SA32946] Ubuntu update for libvorbis

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-02

Ubuntu has issued an update for libvorbis. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise an application using the library.

Full Advisory: http://secunia.com/advisories/32946/

--

[SA32945] Ubuntu update for imagemagick

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-02

Ubuntu has issued an update for imagemagick. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: http://secunia.com/advisories/32945/

--

[SA32944] Debian update for wireshark

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS
Released: 2008-12-01

Debian has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information or cause a DoS (Denial of Service).

Full Advisory: http://secunia.com/advisories/32944/

--

[SA32936] Ubuntu update for clamav

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-12-03

Ubuntu has issued an update for clamav. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: http://secunia.com/advisories/32936/

--

[SA32934] WebGUI Executable Attachments Vulnerability

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-12-03

A vulnerability has been reported in WebGUI, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: http://secunia.com/advisories/32934/

--

[SA32926] ClamAV "cli_check_jpeg_exploit()" Denial of Service Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-12-02

A vulnerability has been reported in ClamAV, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: http://secunia.com/advisories/32926/

--

[SA32918] Ubuntu update for kernel

Critical: Moderately critical
Where: From remote
Impact: Privilege escalation, DoS, System access
Released: 2008-11-28

Ubuntu has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions and gain escalated privileges, and by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.

Full Advisory: http://secunia.com/advisories/32918/

--

[SA32917] Kolab Server ClamAV Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-03

Some vulnerabilities have been reported in Kolab Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory: http://secunia.com/advisories/32917/

--

[SA33002] Ubuntu update for awstats

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-04

Ubuntu has issued an update for awstats. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: http://secunia.com/advisories/33002/

--

[SA32966] Fedora update for wordpress

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-03

Fedora has issued an update for wordpress. This fixes a vulnerability, which can be exploited by malicious people to conduct script insertion attacks.

Full Advisory: http://secunia.com/advisories/32966/

--

[SA32954] Debian update for phpmyadmin

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-02

Debian has issued an update for phpmyadmin. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: http://secunia.com/advisories/32954/

--

[SA32952] VMware ESX Server update for bzip2

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-12-03

VMware has issued an update for VMware ESX Server. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: http://secunia.com/advisories/32952/

--

[SA32939] Debian update for awstats

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-03

Debian has issued an update for awstats. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
http://secunia.com/advisories/32939/

--

[SA33003] Ubuntu update for net-snmp

Critical: Less critical
Where: From local network
Impact: DoS, System access
Released: 2008-12-04

Ubuntu has issued an update for net-snmp. This fixes some vulnerabilities, which can be exploited by malicious people to spoof authenticated SNMPv3 packets, cause a DoS (Denial of Service), and compromise a vulnerable system.

Full Advisory: http://secunia.com/advisories/33003/

--

[SA32968] Fedora update for samba

Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2008-12-03

Fedora has issued an update for samba. This fixes a vulnerability, which potentially can be exploited by malicious people to disclose sensitive information.

Full Advisory: http://secunia.com/advisories/32968/

--

[SA32951] Slackware update for samba

Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2008-12-01

Slackware has issued an update for samba. This fixes a vulnerability, which potentially can be exploited by malicious people to disclose sensitive information.

Full Advisory: http://secunia.com/advisories/32951/

--

[SA32919] Ubuntu update for samba

Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2008-11-28

Ubuntu has issued an update for samba. This fixes a vulnerability, which potentially can be exploited by malicious people to disclose sensitive information.

Full Advisory: http://secunia.com/advisories/32919/

--

[SA32980] Debian update for perl

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-04

Debian has issued an update for perl. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: http://secunia.com/advisories/32980/

--

[SA32977] IBM HMC HTTP TRACE Response Cross-Site Scripting Weakness

Critical: Not critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-04

IBM has acknowledged a weakness in IBM HMC, which potentially can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: http://secunia.com/advisories/32977/

--

[SA32967] Fedora update for lynx

Critical: Not critical
Where: From remote
Impact: System access
Released: 2008-12-03

Fedora has issued an update for lynx. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory: http://secunia.com/advisories/32967/

--

[SA32969] HP-UX Unspecified Local Denial of Service Vulnerability

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-12-03

A vulnerability has been reported in HP-UX, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

Full Advisory: http://secunia.com/advisories/32969/

--

[SA32961] Debian update for flamethrower

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-02

Debian has issued an update for flamethrower. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory:
http://secunia.com/advisories/32961/

--

[SA32960] DAHDI "ZT_SPANCONFIG" IOCTL Privilege Escalation Vulnerability

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-02

A vulnerability has been reported in DAHDI, which potentially can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: http://secunia.com/advisories/32960/

--

[SA32959] Debian update for jailer

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-01

Debian has issued an update for jailer. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: http://secunia.com/advisories/32959/

--

[SA32953] SUSE update for kernel

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-03

SUSE has issued an update for the kernel. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: http://secunia.com/advisories/32953/

--

[SA32947] Zaptel "ZT_SPANCONFIG" IOCTL Privilege Escalation Vulnerabilities

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-02

Some vulnerabilities have been reported in Zaptel, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and potentially gain escalated privileges.

Full Advisory: http://secunia.com/advisories/32947/

--

[SA32943] jailer "updatejail" Insecure Temporary Files

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-01

A security issue has been reported in jailer, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: http://secunia.com/advisories/32943/

--

[SA32933] Linux Kernel PARISC "parisc_show_stack()" Denial of Service

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-12-04

A vulnerability has been reported in the Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

Full Advisory: http://secunia.com/advisories/32933/


Cross Platform:--

[SA32991] Sun Java JDK / JRE Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure
of sensitive information, DoS, System access
Released: 2008-12-04

Some vulnerabilities have been reported in Sun Java, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, cause a DoS (Denial of service), or compromise a vulnerable system.

Full Advisory: http://secunia.com/advisories/32991/

--

[SA32986] Multi SEO phpBB "pfad" File Inclusion Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-12-04

NoGe has discovered a vulnerability in Multi SEO phpBB, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: http://secunia.com/advisories/32986/

--

[SA32942] VLC Media Player Real Demuxer Integer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-01

A vulnerability has been discovered in VLC Media Player, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: http://secunia.com/advisories/32942/

--

[SA32964] PHP ZipArchive::extractTo() Directory Traversal Vulnerability

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-12-04

Stefan Esser has reported a vulnerability in PHP, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: http://secunia.com/advisories/32964/

--

[SA32958] Check Up System for Thai Healthcare "search" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-04

CWH Underground has reported a vulnerability in Check Up System for Thai Healthcare, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/32958/

--

[SA32950] RakhiSoftware Shopping Cart Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of system information
Released: 2008-12-01

Charalambous Glafkos has reported some vulnerabilities in RakhiSoftware Shopping Cart, which can be exploited by malicious people to disclose system information, or to conduct SQL injection and cross-site scripting attacks.

Full Advisory: http://secunia.com/advisories/32950/

--

[SA32938] Basic PHP CMS "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-01

CWH Underground has discovered a vulnerability in Basic PHP CMS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/32938/

--

[SA32932] Bluo CMS "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-01

The_5p3ctrum has reported a vulnerability in Bluo CMS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/32932/

--

[SA32931] mvnForum Unspecified Cross-Site Scripting and Request Forgery

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-03

Some vulnerabilities have been reported in mvnForum, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks.

Full Advisory: http://secunia.com/advisories/32931/

--

[SA32925] PHP TV Portal "mid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-01

A vulnerability has been reported in PHP TV Portal, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/32925/

--

[SA32923] Sunbyte e-Flower "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-03

W4RL0CK has reported a vulnerability in Sunbyte e-Flower, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/32923/

--

[SA32924] CMS Made Simple "cms_language" Cookie Local File Inclusion

Critical: Moderately critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-12-01

A vulnerability has been discovered in CMS Made Simple, which can be exploited by malicious people to disclose potentially sensitive information.

Full Advisory: http://secunia.com/advisories/32924/

--

[SA32996] W3matter RevSense "section" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-04

Pouya_Server has reported a vulnerability in W3matter RevSense, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: http://secunia.com/advisories/32996/

--

[SA32985] ImpressCMS Session Fixation Vulnerability

Critical: Less critical
Where: From remote
Impact: Hijacking
Released: 2008-12-04

A vulnerability has been reported in ImpressCMS, which can be exploited by malicious people to conduct session fixation attacks.

Full Advisory: http://secunia.com/advisories/32985/

--

[SA32978] Drupal Storm Module SQL Injection Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-04

Jakub Suchy has reported some vulnerabilities in the Storm module for Drupal, which can be exploited by malicious users to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/32978/

--

[SA32957] IBM Rational ClearCase Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-02

A vulnerability has been reported in IBM Rational ClearCase, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: http://secunia.com/advisories/32957/

--

[SA32937] iNet Orkut Clone "id" SQL Injection and Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-12-03

d3b4g has reported some vulnerabilities in iNet Orkut Clone, which can be exploited by malicious users to conduct SQL injection attacks and malicious people to conduct cross-site scripting attacks.

Full Advisory: http://secunia.com/advisories/32937/

--

[SA32935] Movable Type Unspecified Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-03

A vulnerability has been reported in Movable Type, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: http://secunia.com/advisories/32935/

--

[SA32965] VMware ESX / ESXi Virtual Hardware Memory Corruption Vulnerability

Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-12-03

A vulnerability has been reported in VMware ESX / ESXi, which can be exploited by malicious, local users to bypass certain security restrictions.

Full Advisory: http://secunia.com/advisories/32965/

Secunia Updates - December 2008

Posted: Fri Dec 26, 2008 7:36 pm
by Tami
Secunia Vulnerabilities Content Listing for the week of December 26 2008

Windows:--

[SA33257] webcamXP Directory Traversal Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-12-22

nicx0 has discovered a vulnerability in webcamXP, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: http://secunia.com/advisories/33257/

--

[SA33245] Emefa Guestbook Database Disclosure

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-12-22

Cyber.Zer0 has discovered a security issue in Emefa Guestbook, which cab be exploited by malicious people to disclose sensitive
information.

Full Advisory: http://secunia.com/advisories/33245/

--

[SA33281] Hitachi GroupMax Workflow Development Kit Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-22

A vulnerability has been reported in Groupmax Web Workflow SDK Set for Active Server Pages and Groupmax Workflow Development Kit for Active Server Pages, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: http://secunia.com/advisories/33281/

--

[SA33249] PowerStrip "pstrip.sys" IOCTL Handling Privilege Escalation

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-22

alex has discovered a vulnerability in PowerStrip, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: http://secunia.com/advisories/33249/

--

[SA33310] PGP Desktop PGPwded.sys Driver Denial of Service

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-12-24

A vulnerability has been discovered in PGP Desktop, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: http://secunia.com/advisories/33310/


UNIX/Linux:--

[SA33323] Gentoo update for imlib2

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-24

Gentoo has issued an update for imlib2. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise an application using the library.

Full Advisory: http://secunia.com/advisories/33323/

--

[SA33315] Gentoo update for vlc

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-24

Gentoo has issued an update for vlc. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: http://secunia.com/advisories/33315/

--

[SA33297] Fedora update for firefox and xulrunner

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, System access
Released: 2008-12-22

Fedora has issued an update for firefox and xulrunner. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, conduct cross-site scripting attacks, or potentially compromise a user's
system.

Full Advisory: http://secunia.com/advisories/33297/

--

[SA33294] SUSE update for flash-player

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-12-22

SUSE has issued an update for flash-player. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: http://secunia.com/advisories/33294/

--

[SA33291] Fedora update for moodle

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-12-22

Fedora has issued an update for moodle. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: http://secunia.com/advisories/33291/

--

[SA33285] Fedora update for firefox

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, System access
Released: 2008-12-22

Fedora has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, conduct cross-site scripting attacks, or potentially compromise a user's system.

Full Advisory: http://secunia.com/advisories/33285/

--

[SA33284] Fedora update for seamonkey

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, System access
Released: 2008-12-22

Fedora has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, disclose sensitive information, conduct cross-site scripting attacks, or potentially compromise a user's
system.

Full Advisory: http://secunia.com/advisories/33284/

--

[SA33267] Red Hat update for flash-plugin

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-12-22

Red Hat has issued an update for flash-plugin. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: http://secunia.com/advisories/33267/

--

[SA33241] Ubuntu update for imlib2

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-22

Ubuntu has issued an update for imlib2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise an application using the library.

Full Advisory: http://secunia.com/advisories/33241/

--

[SA33240] BitDefender Antivirus Scanner for Unices PE File Parsing Integer Overflows

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-12-19

Some vulnerabilities have been reported in BitDefender, which potentially can be exploited by malicious people to compromise a
vulnerable system.

Full Advisory: http://secunia.com/advisories/33240/

--

[SA33238] Red Hat update for java-1.6.0-bea

Critical: Highly critical
Where: From remote
Impact: System access, DoS, Exposure of sensitive information, Exposure of system information, Security Bypass
Released: 2008-12-19

Red Hat has issued an update for java-1.6.0-bea. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, disclose system information or potentially sensitive information, cause a DoS (Denial of Service), or
compromise a vulnerable system.

Full Advisory: http://secunia.com/advisories/33238/

--

[SA33237] Red Hat update for java-1.5.0-bea

Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-12-19

Red Hat has issued an update for java-1.5.0-bea. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, cause a DoS (Denial of Service), and compromise a vulnerable system.

Full Advisory: http://secunia.com/advisories/33237/

--

[SA33236] Red Hat update for java-1.4.2-bea

Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-12-19

Red Hat has issued an update for java-1.4.2-bea. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions and compromise a vulnerable system.

Full Advisory: http://secunia.com/advisories/33236/

--

[SA33317] Gentoo update for clamav

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-12-24

Gentoo has issued an update for clamav. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory: http://secunia.com/advisories/33317/

--

[SA33314] Ubuntu update for perl

Critical: Moderately critical
Where: From remote
Impact: Privilege escalation, DoS, System access
Released: 2008-12-24

Ubuntu has issued an update for perl. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated
privileges and by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.

Full Advisory: http://secunia.com/advisories/33314/

--

[SA33290] Fedora update for roundcubemail

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-12-22

Fedora has issued an update for roundcubemail. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: http://secunia.com/advisories/33290/

--

[SA33287] Fedora update for rsyslog

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-12-22

Fedora has issued an update for rsyslog. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security
restrictions.

Full Advisory: http://secunia.com/advisories/33287/

--

[SA33286] Fedora update for phpPgAdmin

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-12-22

Fedora has issued an update for phpPgAdmin. This fixes a vulnerability, which can be exploited by malicious people to disclose sensitive
information.

Full Advisory: http://secunia.com/advisories/33286/

--

[SA33264] Gentoo update for pdns

Critical: Moderately critical
Where: From remote
Impact: Spoofing, DoS
Released: 2008-12-22

Gentoo has issued an update for pdns. This fixes a weakness and a vulnerability, which can be exploited by malicious people to conduct
spoofing attacks or cause a DoS (Denial of Service).

Full Advisory: http://secunia.com/advisories/33264/

--

[SA33259] Debian update for courier-authlib

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-22

Debian has issued an update for courier-authlib. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
SQL injection attacks.

Full Advisory: http://secunia.com/advisories/33259/

--

[SA33258] Gentoo phpCollab Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-22

Gentoo has acknowledged some vulnerabilities in phpCollab, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/33258/

--

[SA33243] Ubuntu update for blender

Critical: Moderately critical
Where: From remote
Impact: Privilege escalation, System access
Released: 2008-12-22

Ubuntu has issued an update for blender. This fixes some vulnerabilities, which can be exploited by malicious, local users to
gain escalated privileges and by malicious people to compromise a vulnerable system.

Full Advisory: http://secunia.com/advisories/33243/

--

[SA33235] Courier Authentication Library Postgres SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-19

A vulnerability has been reported in the Courier Authentication Library, which can be exploited by malicious people to conduct SQL
injection attacks.

Full Advisory: http://secunia.com/advisories/33235/

--

[SA33260] rPath update for cups

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-12-22

rPath has issued an update for cups. This fixes some vulnerabilities, which can potentially be exploited by malicious people to compromise a vulnerable system.

Full Advisory: http://secunia.com/advisories/33260/

--

[SA33320] Ubuntu update for nagios2

Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-12-24

Ubuntu has issued an update for nagios2. This fixes some vulnerabilities, which can be exploited by malicious users to bypass
certain security restrictions or by malicious people to conduct cross-site request forgery attacks.

Full Advisory: http://secunia.com/advisories/33320/

--

[SA33299] rPath update for dovecot

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-12-23

rPath has issued an update for dovecot. This fixes a security issue, which can be exploited by malicious users to bypass certain security
restrictions.

Full Advisory: http://secunia.com/advisories/33299/

--

[SA33275] UW-imapd c-client Library Off-by-one Vulnerability

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-12-22

A vulnerability has been reported in UW-imapd, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: http://secunia.com/advisories/33275/

--

[SA33261] Debian update for proftpd-dfsg

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-22

Debian has issued an update for proftpd-dfsg. This fixes a vulnerability, which can be exploited by malicious people to conduct
cross-site request forgery attacks.

Full Advisory: http://secunia.com/advisories/33261/

--

[SA33242] Avaya CMS / IR Java JRE Zip Archive Parsing Vulnerability

Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-12-22

Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: http://secunia.com/advisories/33242/

--

[SA33239] Debian update for moodle

Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-12-22

Debian has issued an update for moodle. This fixes some vulnerabilities, which can be exploited by malicious users to conduct script insertion attacks, and by malicious people to bypass certain security restrictions or conduct cross-site request forgery and cross-site scripting attacks.

Full Advisory: http://secunia.com/advisories/33239/

--

[SA33234] Ubuntu update for nagios3

Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-12-23

Ubuntu has issued an update for nagios3. This fixes some vulnerabilities, which can be exploited by malicious users to bypass certain security restrictions or by malicious people to conduct cross-site request forgery attacks.

Full Advisory: http://secunia.com/advisories/33234/

--

[SA33288] Fedora update for openvpn

Critical: Less critical
Where: From local network
Impact: System access
Released: 2008-12-22

Fedora has issued an update for openvpn. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: http://secunia.com/advisories/33288/

--

[SA33279] Debian update for avahi

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-12-22

Debian has issued an update for avahi. This fixes a security issue and a vulnerability, which can be exploited by malicious, local users and
by malicious people to cause a DoS (Denial of Service).

Full Advisory: http://secunia.com/advisories/33279/

--

[SA33292] Fedora update for libvirt

Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-12-22

Fedora has issued an update for libvirt. This fixes a security issue, which can be exploited by malicious, local users to bypass certain
security restrictions.

Full Advisory: http://secunia.com/advisories/33292/

--

[SA33282] Fedora update for git

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-22

Fedora has issued an update for git. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: http://secunia.com/advisories/33282/

--

[SA33278] PDFjam Insecure Temporary Files

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-22

Some security issues have been reported in PDFjam, which can be exploited by malicious, local users to perform certain actions with
escalated privileges.

Full Advisory: http://secunia.com/advisories/33278/

--

[SA33270] GIT "gitweb" Privilege Escalation Security Issue

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-22

A security issue has been reported in GIT, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: http://secunia.com/advisories/33270/

--

[SA33316] Gentoo update for ampache

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-12-24

Gentoo has issued an update for ampache. This fixes a security issue, which can be exploited by malicious local users to perform certain
actions with escalated privileges.

Full Advisory: http://secunia.com/advisories/33316/

--

[SA33303] KVM VNC "protocol_client_msg()" Denial of Service

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-12-23

A security issue has been reported in KVM, which can be exploited by malicious users to cause a DoS (Denial of Service).

Full Advisory: http://secunia.com/advisories/33303/


Cross Platform:--

[SA33272] Yourplace Security Issue and Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, DoS, System access
Released: 2008-12-23

Some vulnerabilities and a security issue have been discovered in Yourplace, which can be exploited by malicious people to disclose potentially sensitive information, bypass certain security restrictions, cause a DoS (Denial of Service), and compromise a vulnerable system.

Full Advisory: http://secunia.com/advisories/33272/

--

[SA33247] ReVou Twitter Clone Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-12-22

Some vulnerabilities have been reported in ReVou Twitter Clone, which can be exploited by malicious people to bypass certain security
restrictions and by malicious users to potentially compromise a vulnerable system.

Full Advisory: http://secunia.com/advisories/33247/

--

[SA33302] TYPO3 WEBERkommunal Facilities Extension SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-23

A vulnerability has been reported in the WEBERkommunal Facilities (wes_facilities) extension for TYPO3, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/33302/

--

[SA33301] TYPO3 Simple File Browser Extension Information Disclosure

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-12-23

A vulnerability has been reported in the Simple File Browser (simplefilebrowser) extension for TYPO3, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: http://secunia.com/advisories/33301/

--

[SA33277] KnowledgeTree Cross-Site Scripting and Privilege Escalation

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Privilege escalation
Released: 2008-12-22

Some vulnerabilities have been reported in KnowledgeTree, which can be exploited by malicious users to gain escalated privileges and by malicious people to conduct cross-site scripting attacks.

Full Advisory: http://secunia.com/advisories/33277/

--

[SA33276] Text Lines Rearrange Script "filename" File Disclosure Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-12-23

SirGod has discovered a vulnerability in Text Lines Rearrange Script, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: http://secunia.com/advisories/33276/

--

[SA33274] Wordpress Page Flip Image Gallery Plugin "book_id" File Disclosure

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-12-23

GoLd_M has discovered a vulnerability in the Page Flip Image Gallery plugin for Wordpress, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: http://secunia.com/advisories/33274/

--

[SA33271] Joomla Volunteer Management System Component "job_id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-23

boom3rang has reported a vulnerability in the Volunteer Management System component for Joomla, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/33271/

--

[SA33269] SolarCMS Forum Component "cat" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-23

athos has discovered a vulnerability in the Forum component for SolarCMS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/33269/

--

[SA33266] MySQL Calendar "username" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-12-23

StAkeR has discovered a vulnerability in MySQL Calendar, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/33266/

--

[SA33255] Emetrix Multiple Products "filename" File Disclosure

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-12-22

Cold z3ro has reported a vulnerability in multiple Emetrix products, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: http://secunia.com/advisories/33255/

--

[SA33254] TYPO3 WEC Discussion Forum Extension Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-12-23

Some vulnerabilities have been reported in the WEC Discussion Forum (wec_discussion) extension for TYPO3, which can be exploited by malicious people to conduct SQL injection and cross-site scripting attacks.

Full Advisory: http://secunia.com/advisories/33254/

--

[SA33253] myPHPscripts Login Session Cross-Site Scripting and Information Disclosure

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information
Released: 2008-12-22

Osirys has discovered a security issue and some vulnerabilities in myPHPscripts Login Session, which can be exploited by malicious people to conduct cross-site scripting attacks or disclose sensitive information.

Full Advisory: http://secunia.com/advisories/33253/

--

[SA33252] FreeLyrics "p" File Disclosure Security Issue

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-12-22

Piker has discovered a security issue in FreeLyrics, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: http://secunia.com/advisories/33252/

--

[SA33250] Constructr CMS "show_page" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-22

A vulnerability has been discovered in Constructr CMS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/33250/

--

[SA33248] REDPEACH CMS "zv" SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-23

Lidloses_Auge has reported some vulnerabilities in REDPEACH CMS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/33248/

--

[SA33246] TYPO3 phpMyAdmin Extension Cross-Site Request Forgery

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-23

A vulnerability has been reported in the phpMyAdmin (phpmyadmin) extension for TYPO3, which can be exploited by malicious people to conduct cross-site request forgery attacks.

Full Advisory:
http://secunia.com/advisories/33246/

--

[SA33311] Psi File Transfer Service Packet Parsing Vulnerabilities

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-12-24

sha0 has discovered some vulnerabilities in Psi, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: http://secunia.com/advisories/33311/

--

[SA33289] Fedora update for drupal-views

Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-12-22

Fedora has issued an update for drupal-views. This fixes some vulnerabilities, which can be exploited by malicious users to conduct SQL injection attacks.

Full Advisory: http://secunia.com/advisories/33289/

--

[SA33262] TYPO3 Vox populi Extension Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-23

A vulnerability has been reported in the Vox populi (mv_vox_populi) extension for TYPO3, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: http://secunia.com/advisories/33262/

--

[SA33256] TYPO3 DR Wiki Extension Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-12-23

A vulnerability has been reported in the DR Wiki (dr_wiki) extension for TYPO3, which can be exploited by malicious people to conduct
cross-site scripting attacks.

Full Advisory: http://secunia.com/advisories/33256/

--

[SA33293] QEMU VNC "protocol_client_msg()" Denial of Service

Critical: Not critical
Where: From local network
Impact: DoS
Released: 2008-12-23

A security issue has been reported in QEMU, which can be exploited by malicious users to cause a DoS (Denial of Service).

Full Advisory: http://secunia.com/advisories/33293/