.:[ packet storm ]:.
                             
never stop questioning
never stop questioning

 Section:  .. / 0801-advisories  /

Page 27 of 27
<< 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 >> Files 650 - 655 of 655
Currently sorted by: File NameSort By: Last Modified, File Size

 ///  File Name: waraxe-2008-SA063.txt
Description:
Kayako SupportSuite version 3.11.01 suffers from an information leakage vulnerability.
Author:Janek Vind aka waraxe
Homepage:http://www.waraxe.us/
File Size:1935
Last Modified:Jan 21 21:44:32 2008
MD5 Checksum:72dd608cff7316f07126bd0e47d01441

 ///  File Name: whitedunboffs.txt
Description:
White Dune versions 0.29beta791 and below suffer from buffer overflow and format string vulnerabilities.
Author:Luigi Auriemma
Homepage:http://aluigi.org/
Related Exploit:whitedunboffs.zip
File Size:3825
Last Modified:Jan 2 17:50:20 2008
MD5 Checksum:1c2c037eb7e377688b681cd3b319c2d5

 ///  File Name: yasslick.txt
Description:
yaSSL versions 1.75 and below suffer from invalid memory access and buffer overflow vulnerabilities.
Author:Luigi Auriemma
Homepage:http://aluigi.org/
Related Exploit:yasslick.zip
File Size:4738
Last Modified:Jan 4 20:22:28 2008
MD5 Checksum:ca567cce4d6d28609d58393922207d08

 ///  File Name: ZDI-08-001.txt
Description:
A vulnerability allows attackers to execute arbitrary code on vulnerable installations of IBM Tivoli Storage Manager Express. Authentication is not required to exploit this vulnerability. The specific flaw resides in the TSM Express Backup Server service, dsmsvc.exe, which listens by default on TCP port 1500. The process trusts a user-supplied length value. By supplying a large number, an attacker can overflow a static heap buffer leading to arbitrary code execution in the context of the SYSTEM user. Tivoli Storage Manager Express version 5.3 is affected.
Author:Tenable Network Security,Sebastian Apelt
Homepage:http://www.zerodayinitiative.com/
File Size:3054
Related CVE(s):CVE-2008-0247
Last Modified:Jan 14 17:38:21 2008
MD5 Checksum:7a0c52554fa38a18476a3e556c03e3d5

 ///  File Name: ZDI-08-002.txt
Description:
A vulnerability allows attackers to execute arbitrary code on vulnerable installations of Citrix Presentation Server. Authentication is not required to exploit this vulnerability. The specific flaw resides in the Independent Management Architecture service, ImaSrv.exe, which listens by default on TCP port 2512 or 2513. The process trusts a user-suppled value as a parameter to a memory allocation. By supplying a specific value, an undersized heap buffer may be allocated. Subsequently, an attacker can then overflow that heap buffer by sending an overly large packet leading to arbitrary code execution in the context of the SYSTEM user.
Author:Eric DETOISIEN
Homepage:http://www.zerodayinitiative.com/
File Size:3437
Last Modified:Jan 18 05:38:14 2008
MD5 Checksum:b633e3e2771697f71e17271da86d5369