Section: .. / 0608-advisories /
| /// File Name: |
vnc412.txt |
Description:
|
RealVNC 4.1.2 appears susceptible to a denial of service condition due to an integer overflow.
| | Author: | Niall FitzGibbon | | File Size: | 1933 | | Last Modified: | Aug 27 16:46:02 2006 |
| MD5 Checksum: | 94909118dd3cbaa534653e4798a01ab0 |
|
| /// File Name: |
xoopsSQL.txt |
Description:
|
Xoops version 2.0.14 suffers from a SQL injection flaw.
| | Author: | Omid | | Homepage: | http://www.hackers.ir | | File Size: | 932 | | Last Modified: | Aug 28 01:14:00 2006 |
| MD5 Checksum: | 63f0b661c10e70db8989d68ac68f5f8e |
|
| /// File Name: |
XSec-06-02.txt |
Description:
|
A vulnerability has been found in Internet Explorer 6.0. When Internet Explorer tries to instantiate the IMSKDIC.DLL (Microsoft IME) COM object as an ActiveX control, it may corrupt system memory in such a way that an attacker may cause a denial of service and/or execute arbitrary code.
| | Author: | nop | | Homepage: | http://www.xsec.org/ | | File Size: | 1272 | | Last Modified: | Aug 27 01:59:48 2006 |
| MD5 Checksum: | 1bab1fcfb3b939144ed6596c3d47df2f |
|
| /// File Name: |
XSec-06-03.txt |
Description:
|
A vulnerability has been found in Internet Explorer 6.0. When Internet Explorer tries to instantiate the CHTSKDIC.DLL (Microsoft IME) COM object as an ActiveX control, it may corrupt system memory in such a way that an attacker may cause a denial of service and/or execute arbitrary code.
| | Author: | nop | | Homepage: | http://www.xsec.org/ | | File Size: | 1231 | | Last Modified: | Aug 27 02:01:15 2006 |
| MD5 Checksum: | 05bdcc8835a9059880ccc28ba3d3cf6e |
|
| /// File Name: |
XSec-06-04.txt |
Description:
|
A vulnerability has been found in Internet Explorer 6.0. When Internet Explorer tries to instantiate the msoe.dll (OutLook) COM object as an ActiveX control, it may corrupt system memory in such a way that an attacker may cause a denial of service and/or execute arbitrary code.
| | Author: | nop | | Homepage: | http://www.xsec.org/ | | File Size: | 1257 | | Last Modified: | Aug 27 02:02:10 2006 |
| MD5 Checksum: | 236056c5090e05a6af3d7adee638e683 |
|
| /// File Name: |
XSec-06-06.txt |
Description:
|
A vulnerability has been found in Internet Explorer 6.0 on Microsoft Windows 2003. When Internet Explorer tries to instantiate the tsuserex.dll (Terminal Services) COM object as an ActiveX control, it may corrupt system memory in such a way that an attacker may cause a denial of service and/or execute arbitrary code.
| | Author: | nop | | Homepage: | http://www.xsec.org/ | | File Size: | 1316 | | Last Modified: | Aug 27 14:41:16 2006 |
| MD5 Checksum: | 7784e51aae64059801302e2adbb43d2f |
|
| /// File Name: |
XSec-06-07.txt |
Description:
|
Multiple vulnerability has been found in Visual Studio 6.0. When Internet Explorer tries to instantiate the TCPROPS.DLL, FP30WEC.DLL,mdt2db.dll,mdt2qd.dll,VI30AUT.DLL (Visual Studio 6.0) COM object as an ActiveX control, it may corrupt system memory in such a way that an attacker may cause a denial of service and/or execute arbitrary code.
| | Author: | nop | | Homepage: | http://www.xsec.org/ | | File Size: | 2306 | | Last Modified: | Aug 27 14:42:29 2006 |
| MD5 Checksum: | 6d0e9aa7e366eee6c9543f7a340fb8a4 |
|
| /// File Name: |
XSec-06-08.txt |
Description:
|
Multiple vulnerabilities have been found in Windows 2000. When Internet Explorer tries to instantiate the ciodm.dll, MyInfo.dll, msdxm.ocx, Creator.dll(Media player 9) COM object as an ActiveX control, it may corrupt system memory in such a way that an attacker may cause a denial of service and/or execute arbitrary code.
| | Author: | nop | | Homepage: | http://www.xsec.org/ | | File Size: | 2477 | | Last Modified: | Aug 27 17:24:08 2006 |
| MD5 Checksum: | a4dd37c78c7e9ffe5cbde57c9b165eab |
|
| /// File Name: |
XSec-06-09.txt |
Description:
|
Internet Explorer crashes due to a mishandling of multiple COM objects.
| | Author: | nop | | Homepage: | http://www.xsec.org/ | | File Size: | 2531 | | Last Modified: | Aug 27 17:45:08 2006 |
| MD5 Checksum: | 0a854871f468d9faa71962233472b6c9 |
|
| /// File Name: |
XSec-06-10.txt |
Description:
|
An invalid memory write in Internet Explorer may lead to a denial of service condition or execution of arbitrary code.
| | Author: | nop | | Homepage: | http://www.xsec.org/ | | File Size: | 1288 | | Last Modified: | Aug 28 23:03:33 2006 |
| MD5 Checksum: | d4f58ef069ccf8ef892bedfc0d937e92 |
|
| /// File Name: |
yahooxss.txt |
Description:
|
Yahoo Research suffers from a cross site scripting vulnerability.
| | Author: | Simo64 | | File Size: | 5456 | | Last Modified: | Aug 27 15:09:27 2006 |
| MD5 Checksum: | 962914272bec57f54fe553aa0ab4420c |
|
| /// File Name: |
ZDI-06-026.txt |
Description:
|
A vulnerability in Microsoft Internet Explorer allows arbitrary code execution. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists due to improper garbage collection when multiple "imports" are used on a "styleSheets" collection. Crafting a long chain of CSS imports in an HTML document results in a memory corruption eventually leading to code execution.
| | Author: | Sam Thomas | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2635 | | Related CVE(s): | CVE-2006-3451 | | Last Modified: | Aug 18 01:57:43 2006 |
| MD5 Checksum: | 3bbef368a489c3994360b8254ca78877 |
|
| /// File Name: |
ZDI-06-027.txt |
Description:
|
A vulnerability in Microsoft Internet Explorer allows arbitrary code execution. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific vulnerability exists due to improper handling of CSS class values. Accessing a specially crafted CSS element via document.getElementByID causes a memory corruption eventually leading to code execution.
| | Author: | Sam Thomas | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2595 | | Related CVE(s): | CVE-2006-3450 | | Last Modified: | Aug 18 01:59:36 2006 |
| MD5 Checksum: | 60d51fbccc544e1027e68c4f283ca29a |
|
| /// File Name: |
zend_hash_del_key_or_index_vulnerab..> |
Description:
|
Write up discussing the Zend_Hash_Del_Key_Or_Index vulnerability inherent in PHP that has finally been fixed in the latest releases. Upgrading to 4.4.3 or 5.1.4 is suggested.
| | Author: | Stefan Esser | | Homepage: | http://www.hardened-php.net/ | | File Size: | 26958 | | Last Modified: | Aug 18 00:54:40 2006 |
| MD5 Checksum: | c83c217e2b38f09a901fa6e4b83bc31a |
|
|
|
|
|