Section: .. / 0507-advisories /
| /// File Name: |
sa15952.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Jinzora, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/15952/ | | File Size: | 2067 | | Last Modified: | Jul 8 08:47:25 2005 |
| MD5 Checksum: | 253fe2d06208b852ce3f2d633e7196ec |
|
| /// File Name: |
nullsessions.txt |
Description:
|
By taking advantage of hardcoded named pipes allowed for NULL sessions and using the property of MSRPC that, by default, all available RPC interfaces in a process can be reached using any opened endpoint, it is possible to anonymously enumerate Windows services and read the Application and System eventlogs of a remote Windows NT 4.0 or Windows 2000 system.
| | Author: | Jean-Baptiste Marchand | | Homepage: | http://www.hsc.fr/ | | File Size: | 6281 | | Related CVE(s): | CAN-2005-2150 | | Last Modified: | Jul 7 16:33:13 2005 |
| MD5 Checksum: | 403325e9110bbcc9a27420a238d7ab07 |
|
| /// File Name: |
phpxmail.txt |
Description:
|
PHPXMAIL versions 0.7 through 1.1 suffer from an authentication bypass flaw that allows anyone to login by supplying an overly long password.
| | Author: | Stefan Lochbihler | | File Size: | 2274 | | Last Modified: | Jul 7 16:14:12 2005 |
| MD5 Checksum: | 4bfdaa4025f170be6d826174a01c3bda |
|
| /// File Name: |
voip-phones.txt |
Description:
|
Due to ignoring the value of Call-ID and even tag and branch while processing NOTIFY messages, VOIP-Hardphones process spoofed status messages like Messages-Waiting.
| | Author: | Tobias Glemser | | Homepage: | http://pentest.tele-consulting.com | | File Size: | 3140 | | Last Modified: | Jul 7 15:52:56 2005 |
| MD5 Checksum: | e725ab7932a1adec8a882fe879c0faee |
|
| /// File Name: |
sa15949.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in zlib, which can be exploited by malicious people to conduct a DoS (Denial of Service) against a vulnerable application, or potentially to execute arbitrary code.
| | Homepage: | http://secunia.com/advisories/15949/ | | File Size: | 2360 | | Last Modified: | Jul 7 15:48:25 2005 |
| MD5 Checksum: | 5e7907b2dbeb40883465df2dbb278dd8 |
|
| /// File Name: |
sa15947.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in MailWatch for MailScanner, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/15947/ | | File Size: | 1945 | | Last Modified: | Jul 7 15:48:25 2005 |
| MD5 Checksum: | 6c7789c75bed51622b26dfd1be8003e5 |
|
| /// File Name: |
sa15944.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in TikiWiki, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/15944/ | | File Size: | 1871 | | Last Modified: | Jul 7 15:48:25 2005 |
| MD5 Checksum: | 6f064c7c97b83fcfa4735252eef8d212 |
|
| /// File Name: |
sa15941.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in phpPgAdmin, which can be exploited by malicious people to disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/15941/ | | File Size: | 2097 | | Last Modified: | Jul 7 15:48:25 2005 |
| MD5 Checksum: | b346379129c2db1f4d85a2b72b84b3ff |
|
| /// File Name: |
glsa-200507-06.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200507-06 - TikiWiki is vulnerable to arbitrary command execution as described in GLSA 200507-01. Versions less than 1.8.5-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2594 | | Related CVE(s): | CAN-2005-1921 | | Last Modified: | Jul 7 10:51:43 2005 |
| MD5 Checksum: | eb96b1ef4bc4f78be8de2e692003feea |
|
| /// File Name: |
jaws052.txt |
Description:
|
Jaws versions 0.5.2 and below are susceptible to the XML_RPC vulnerability.
| | Author: | Stefan Esser | | Homepage: | http://www.hardened-php.net/ | | File Size: | 3737 | | Last Modified: | Jul 7 10:50:44 2005 |
| MD5 Checksum: | d165445ede5d8db236cb4070ea15b7e6 |
|
| /// File Name: |
dsa-738-1.txt |
Description:
|
Debian Security Advisory DSA 738-1 - A vulnerability was discovered in the way that Razor parses certain email headers that could potentially be used to crash the Razor program, causing a denial of service (DOS).
| | Homepage: | http://security.debian.org/ | | File Size: | 4792 | | Related CVE(s): | CAN-2005-2024 | | Last Modified: | Jul 7 10:49:02 2005 |
| MD5 Checksum: | 4b19c8e56ce81b9aa9776ed943ceb2d7 |
|
| /// File Name: |
07.05.05.txt |
Description:
|
iDEFENSE Security Advisory 07.05.05 - Remote exploitation of a buffer overflow in Adobe Acrobat Reader for Unix could allow an attacker to execute arbitrary code. iDEFENSE has confirmed the existence of this vulnerability in Adobe Acrobat Reader version 5.0.9 for Unix and Adobe Acrobat Reader version 5.0.10 for Unix. Adobe Acrobat for Windows is not affected. Adobe Acrobat 7.0 for Unix is not affected.
| | Homepage: | http://www.idefense.com | | File Size: | 4304 | | Related CVE(s): | CAN-2005-1625 | | Last Modified: | Jul 7 10:43:11 2005 |
| MD5 Checksum: | 161cd1396112c87e0a7be61abd3f7db5 |
|
| /// File Name: |
EXPL-A-2005-011.txt |
Description:
|
QuickBlogger version 1.4 and below is susceptible to a cross site scripting attack.
| | Author: | Donnie Werner | | File Size: | 1462 | | Last Modified: | Jul 7 10:37:25 2005 |
| MD5 Checksum: | 18983de17da8e48a7d3b604c10e0c7b6 |
|
| /// File Name: |
glsa-200507-05.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200507-05 - Tavis Ormandy of the Gentoo Linux Security Audit Team discovered a buffer overflow in zlib. A bounds checking operation failed to take invalid data into account, allowing a specifically malformed deflate data stream to overrun a buffer. Versions less than 1.2.2-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3316 | | Related CVE(s): | CAN-2005-2096 | | Last Modified: | Jul 7 10:21:04 2005 |
| MD5 Checksum: | 69d1f1db4f025b262739ec8591d026e7 |
|
| /// File Name: |
glsa-200507-04.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200507-04 - RealPlayer is vulnerable to a heap overflow when opening RealMedia files which make use of RealText. Versions less than 10.0.5 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3253 | | Related CVE(s): | CAN-2005-1766 | | Last Modified: | Jul 7 10:20:19 2005 |
| MD5 Checksum: | e45232a06ea075709e916ddec19cecb5 |
|
| /// File Name: |
ekg.insecure.txt |
Description:
|
ekg versions 2005-06-05 and below suffer from a temporary file creation vulnerability that can lead to arbitrary code execution.
| | Author: | Eric Romang | | File Size: | 4432 | | Related CVE(s): | CAN-2005-1916 | | Last Modified: | Jul 7 10:19:24 2005 |
| MD5 Checksum: | f41ed795beaf615c6450fb97a091ee5a |
|
| /// File Name: |
dsa-734-1.txt |
Description:
|
Debian Security Advisory DSA 734-1 - Two denial of service problems have been discovered in Gaim, a multi-protocol instant messaging client.
| | Homepage: | http://security.debian.org/ | | File Size: | 6709 | | Related CVE(s): | CAN-2005-1269, CAN-2005-1934 | | Last Modified: | Jul 7 10:10:03 2005 |
| MD5 Checksum: | f5a1b2abee269329d097c6ecc8fe5812 |
|
| /// File Name: |
geeklog1311SQL.txt |
Description:
|
Geeklog versions 1.3.11 and below suffer from a SQL injection vulnerability.
| | Author: | Stefan Esser | | File Size: | 5886 | | Last Modified: | Jul 7 10:02:57 2005 |
| MD5 Checksum: | 27a6547a764e1e168f720866f6ec3118 |
|
| /// File Name: |
ldap.txt |
Description:
|
pam_ldap/nss_ldap fail to re-start TLS when following referred connections. This can result in credentials being sent in clear text when pam_ldap/nss_ldap attempt to rebind.
| | Author: | Rob Holland | | File Size: | 1230 | | Last Modified: | Jul 7 09:59:48 2005 |
| MD5 Checksum: | 4127b8c43bc18009fd879033b7076e19 |
|
| /// File Name: |
dsa-725-2.txt |
Description:
|
Debian Security Advisory DSA 725-1 - Jens Steube discovered that ppxp, yet another PPP program, does not release root privileges when opening potentially user supplied log files. This can be tricked into opening a root shell.
| | Homepage: | http://security.debian.org/ | | File Size: | 10270 | | Related CVE(s): | CAN-2005-0392 | | Last Modified: | Jul 7 09:58:30 2005 |
| MD5 Checksum: | ea0f1eb00dab1b2cd70ff988ca8e3be7 |
|
| /// File Name: |
glsa-200507-03.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200507-03 - Ron van Daal discovered that phpBB contains a vulnerability in the highlighting code. Versions less than 2.0.16 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3175 | | Last Modified: | Jul 7 09:52:23 2005 |
| MD5 Checksum: | bd64628e6c5a4dbca65bb5fdc553e6fa |
|
| /// File Name: |
glsa-200507-02.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200507-02 - James Bercegay of the GulfTech Security Research Team discovered that WordPress insufficiently checks data passed to the XML-RPC server. He also discovered that WordPress has several cross-site scripting and full path disclosure vulnerabilities. Versions less than 1.5.1.3 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3485 | | Related CVE(s): | CAN-2005-1921 | | Last Modified: | Jul 7 09:52:01 2005 |
| MD5 Checksum: | 2a518169301d003b69c0a90bcd8387fb |
|
| /// File Name: |
glsa-200507-01.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200507-01 - James Bercegay of GulfTech Security Research discovered that the PEAR XML-RPC and phpxmlrpc libraries fail to sanitize input sent using the POST method. Versions less than 1.3.1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3177 | | Related CVE(s): | CAN-2005-1921 | | Last Modified: | Jul 7 09:47:37 2005 |
| MD5 Checksum: | da3182ae6ea86a4f0c341991a352feda |
|
| /// File Name: |
jBPM20.txt |
Description:
|
JBoss jBPM suffers from a remote command execution flaw that allows a remote attacker to execute commands with the rights of the JBoss process.
| | Author: | Marc Schoenefeld | | Homepage: | http://www.illegalaccess.org/ | | File Size: | 3601 | | Last Modified: | Jul 7 09:45:22 2005 |
| MD5 Checksum: | 8796fa4fd04467b9e6490dad6668214a |
|
| /// File Name: |
cactiSQL086e-bypass.txt |
Description:
|
Cacti versions 0.8.6e and below suffer from a bypass vulnerability.
| | Author: | Stefan Esser | | File Size: | 5705 | | Last Modified: | Jul 7 09:37:16 2005 |
| MD5 Checksum: | 8a450717ab6be045b80d9adc44587e11 |
|
|
|
|
|