Section: .. / 0601-advisories /
| /// File Name: |
sa18647.txt |
Description:
|
Unavailable.
| | File Size: | 1957 | | Last Modified: | Jan 31 04:54:09 2006 |
| MD5 Checksum: | 148698c90fbf675bd4e3b20cc42b4fe4 |
|
| /// File Name: |
sa18648.txt |
Description:
|
Unavailable.
| | File Size: | 1836 | | Last Modified: | Jan 31 04:54:09 2006 |
| MD5 Checksum: | 4e7a901ddd2796ce018c08a00d758690 |
|
| /// File Name: |
sa18649.txt |
Description:
|
Unavailable.
| | File Size: | 1968 | | Last Modified: | Jan 31 04:54:09 2006 |
| MD5 Checksum: | afcc766bddfbcc395e2d02dd1d4ffb22 |
|
| /// File Name: |
sa18650.txt |
Description:
|
Unavailable.
| | File Size: | 1884 | | Last Modified: | Jan 31 04:54:09 2006 |
| MD5 Checksum: | c9823b175cab24d3510c3b27f88b1158 |
|
| /// File Name: |
SenaoSI-7800H.txt |
Description:
|
An undocumented open port, UDP/17185, VxWorks WDB remote debugging (wdbrpc) is left in from development. This open port may allow an attacker unauthenticated access to the phone's OS, yield sensitive information, create opportunities for DoS, etc.
| | Author: | Shawn Merdinger | | File Size: | 1206 | | Last Modified: | Jan 22 22:46:33 2006 |
| MD5 Checksum: | ef73181990373bb697dbdc05b50f365d |
|
| /// File Name: |
snmptradFormat.txt |
Description:
|
There is a format string vulnerability in the snmptrapd server from the cmu-snmp package. Versions cmu-snmp-linux-3.7 and cmu-snmp-linux-3.6 have been verified as susceptible.
| | Author: | Seregorn | | Homepage: | http://www.digitalarmaments.com/ | | File Size: | 2340 | | Last Modified: | Jan 22 01:01:00 2006 |
| MD5 Checksum: | c367e33e8de15c35eaebd77b946d4613 |
|
| /// File Name: |
SSRT051058.txt |
Description:
|
HP Security Bulletin - A potential security vulnerability has been identified with HP-UX running Secure Shell. The vulnerability could be remotely exploited to allow a remote unauthorized user to create a Denial of Service (DoS).
| | Author: | HP | | Homepage: | http://www.hp.com | | File Size: | 6238 | | Related CVE(s): | CVE-2005-2096, CAN-2005-2798 | | Last Modified: | Jan 11 07:09:23 2006 |
| MD5 Checksum: | 120478549624859a69f0a24def709246 |
|
| /// File Name: |
SSRT061099.txt |
Description:
|
HPSBUX02091 SSRT061099 rev.1 - A potential security vulnerability has been identified with HP-UX systems where the vulnerability may be exploited to allow a local user to increase privilege.
| | Author: | HP | | Homepage: | http://www.hp.com | | File Size: | 5942 | | Last Modified: | Jan 27 08:21:17 2006 |
| MD5 Checksum: | bb2141ac05392e55292a8666c825d51a |
|
| /// File Name: |
SSRT061104.txt |
Description:
|
HPSBMA02094 SSRT061104 rev.1 - Oracle(R) has issued a Critical Patch Update which contains solutions for a number of potential security vulnerabilities. These vulnerabilities may be exploited locally or remotely to compromise the confidentiality, availability or integrity of Oracle for OpenView (OfO).
| | Author: | HP | | Homepage: | http://www.hp.com | | File Size: | 8077 | | Last Modified: | Jan 27 08:21:56 2006 |
| MD5 Checksum: | a8ffb84c39d8b740ceec3bff7ae3f417 |
|
| /// File Name: |
superXSS.txt |
Description:
|
Superonline.com is susceptible to a cross site scripting attack.
| | Author: | nukedx | | Homepage: | http://www.nukedx.com | | File Size: | 2154 | | Last Modified: | Jan 15 03:04:14 2006 |
| MD5 Checksum: | 23a61183007e7e291dc3981a50cff2b9 |
|
| /// File Name: |
SUSA-SA-2006-002.txt |
Description:
|
SUSE Security Announcement - iDEFENSE reported a security problem with the Novell Remote Manager. By passing a huge or negative size via a HTTP request header to httpstkd it was possible to corrupt heap memory and so potentially execute code.
| | Homepage: | http://www.suse.com | | File Size: | 11665 | | Related CVE(s): | CVE-2005-3655 | | Last Modified: | Jan 15 18:05:25 2006 |
| MD5 Checksum: | 52287cb8c3781e32c8a4c1ca74588e11 |
|
| /// File Name: |
SUSE-SA-2006-003.txt |
Description:
|
SUSE Security Announcement - Maksim Orlovich discovered a bug in the JavaScript interpreter used by Konqueror. UTF-8 encoded URLs could lead to a buffer overflow that causes the browser to crash or execute arbitrary code. Attackers could trick users into visiting specially crafted web sites that exploit this bug (CVE-2006-0019).
| | Author: | Ludwig Nussel | | Homepage: | http://www.suse.com | | File Size: | 16441 | | Last Modified: | Jan 26 06:06:08 2006 |
| MD5 Checksum: | d4aa6a76a958cfcb774a256f84cd94a1 |
|
| /// File Name: |
SUSE-SA-2006-004.txt |
Description:
|
Stefan Esser discovered a bug in in the register_globals emulation of phpMyAdmin that allowes to overwrite variables. An attacker could exploit the bug to ultimately execute code (CVE-2005-4079). Additionally several cross-site-scripting bugs were discovered (CVE-2005-3787, CVE-2005-3665).
| | Author: | Ludwig Nussel | | Homepage: | http://www.suse.com | | File Size: | 14534 | | Last Modified: | Jan 27 09:02:28 2006 |
| MD5 Checksum: | 5540d4c1518e4fd77b1b8597f5b4585c |
|
| /// File Name: |
TA06-005A.txt |
Description:
|
Technical Cyber Security Alert TA06-005A - Microsoft Security Bulletin MS06-001 contains an update to fix a vulnerability in the way Microsoft Windows handles images in the Windows Metafile (WMF) format. A remote, unauthenticated attacker may be able to execute arbitrary code if the user is persuaded to view a specially crafted Windows Metafile.
| | Homepage: | http://www.us-cert.gov | | File Size: | 2974 | | Last Modified: | Jan 8 06:24:03 2006 |
| MD5 Checksum: | d633db50e3ad33d50480c1e03eb0f8d8 |
|
| /// File Name: |
TA06-010A.txt |
Description:
|
Technical Cyber Security Alert TA06-010A - Microsoft has released updates that address critical vulnerabilities in Windows, Outlook, and Exchange. Exploitation of these vulnerabilities could allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial of service on a vulnerable system.
| | Homepage: | http://www.us-cert.gov | | File Size: | 4287 | | Related CVE(s): | CVE-2006-0002, CVE-2006-0010 | | Last Modified: | Jan 11 07:17:43 2006 |
| MD5 Checksum: | a93b658e9fa476065cda39f686810137 |
|
| /// File Name: |
TA06-018A.txt |
Description:
|
Technical Cyber Security Alert TA06-018A - Various Oracle products and components are affected by multiple vulnerabilities. The impacts of these vulnerabilities include remote execution of arbitrary code, information disclosure, and denial of service.
| | Author: | CERT | | Homepage: | http://www.us-cert.gov/cas/techalerts/TA06-018A.html | | File Size: | 6845 | | Last Modified: | Jan 25 08:57:21 2006 |
| MD5 Checksum: | af6b4e92f1561a7cc62f129e33bd63de |
|
| /// File Name: |
thinksecureWEP.txt |
Description:
|
ThinkSECURE has discovered that certain well-known wireless chipsets, using vulnerable drivers under the Windows XP operating system and when configured to use WEP with Open Authentication, can be tricked by a 802.11-based wireless client adapter operating in master mode ("the attacker") to discard the WEP settings and negotiate a post-association connection with the attacker in the clear.
| | Author: | Christopher Low, Julian Ho | | Homepage: | http://www.securitystartshere.net/page-vulns-wccd.htm | | File Size: | 5885 | | Last Modified: | Jan 22 00:45:39 2006 |
| MD5 Checksum: | fd92f7c3e6caf7f856af5dc2c398774b |
|
| /// File Name: |
USN-233-1.txt |
Description:
|
Ubuntu Security Notice USN-233-1 - Steve Fosdick discovered a remote Denial of Service vulnerability in fetchmail. When using fetchmail in 'multidrop' mode, a malicious email server could cause a crash by sending an email without any headers.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 5324 | | Related CVE(s): | CVE-2005-4348 | | Last Modified: | Jan 3 03:50:14 2006 |
| MD5 Checksum: | 1ff5310dd89df8c9acf0b8ec68b7b692 |
|
| /// File Name: |
USN-234-1.txt |
Description:
|
Ubuntu Security Notice USN-234-1 - Richard Harms discovered that cpio did not sufficiently validate file properties when creating archives. Files with e. g. a very large size caused a buffer overflow.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 4314 | | Related CVE(s): | CVE-2005-4268 | | Last Modified: | Jan 3 03:50:58 2006 |
| MD5 Checksum: | aaadcc9c33136e60bc692736218c04e4 |
|
|
|
|
|