.:[ packet storm ]:.
                               
preserving full disclosure
preserving full disclosure

 Section:  .. / advisories / iss  /

Page 4 of 4
<< 1 2 3 4 >> Files 75 - 85 of 85
Currently sorted by: File NameSort By: Last Modified, File Size

 ///  File Name: iss.99-12-12.snoop
Description:
ISS has discovered a remotely exploitable buffer overflow condition in the Solaris Snoop application. Snoop is a network sniffing tool that ships with all Solaris 2.x operating systems. This overflow allows a knowledgeable attacker to seize control of the Snoop application. Solaris 2.4, 2.5, 2.5.1, 2.6, and 2.7 were found to be vulnerable. Patches available here.
File Size:5006
Last Modified:Dec 14 01:30:54 1999
MD5 Checksum:fa51995314eee09ba2549218fdb3ebd3

 ///  File Name: iss.bind4-8.txt
Description:
ISS Security Advisory - Bind 8 v8.3.3-REL and below and Bind 4 v4.9.10-REL and below contain a flaw in the formation of DNS responses containing SIG resource records (RR) that allows remote code execution. Two denial of service vulnerabilities exist as well. A workaround is available by turning off recursive DNS functionality.
Homepage:http://xforce.iss.net
File Size:7694
Related CVE(s):CAN-2002-1219, CAN-2002-1220, CAN-2002-1221
Last Modified:Nov 13 12:48:50 2002
MD5 Checksum:17867314448a7d78bc9b1ebb770928cd

 ///  File Name: iss.exchange.txt
Description:
ISS Security Advisory - Microsoft Exchange Server v5.5 contains a remotely exploitable buffer overflow. This flaw allows attackers to either crash Exchange and block all inbound and outbound email delivery or allow an attacker to gain complete control of the server.
Homepage:http://www.iss.net
File Size:3101
Last Modified:Jul 25 07:53:51 2002
MD5 Checksum:ae145c1d4f7894ecbafc5ad974e6533a

 ///  File Name: iss.iss.txt
Description:
ISS Security Advisory - A vulnerability found in the manner used by Internet Scanner to parse certain types of non-standard HTTP responses can result in a remotely exploitable buffer overflow condition. This affects Internet Scanner version 6.2.1 for Windows (NT/2000) and has been corrected with X-Press Update 6.17.
Homepage:http://xforce.iss.net
File Size:2916
Last Modified:Sep 18 23:34:33 2002
MD5 Checksum:59a67df3aadbf955c0bd2e782c368f5d

 ///  File Name: iss.polycom.txt
Description:
ISS Security Advisory - Polycom ViewStation videoconferencing products contain several remote vulnerabilities which allow attackers to gather information about the device, retrieve files, crash the device, and monitor videoconferences. Polycom ViewStation 7.2 and earlier and Polycom ViewStation FX/VS 4000 version 4.1.5 and below are affected.
Author:Jeff Horne
Homepage:http://xforce.iss.net
File Size:5793
Related CVE(s):CAN-2002-0626, CAN-2002-0627, CAN-2002-0628, CAN-2002-0629, CAN-2002-0630
Last Modified:Sep 5 09:07:21 2002
MD5 Checksum:4aa04177e96055df305f827067346d7c

 ///  File Name: iss.slammer.worm.txt
Description:
ISS Security Advisory - The "Microsoft SQL Slammer Worm" is spreading via unpatched SQL servers. Once a vulnerable computer is compromised, the worm will infect that target, randomly select a new target, and resend the exploit and propagation code to that host sending a large amount of network traffic in the process which crashes some network equipment.
Homepage:http://xforce.iss.net
File Size:6188
Related CVE(s):CAN-2002-0649
Last Modified:Jan 25 19:10:08 2003
MD5 Checksum:6ddebac702eda1acef91bb54c7773882

 ///  File Name: iss.smb-dos.txt
Description:
ISS Security Advisory - Windows NT, 2000, and XP can be crashed remotely by sending a malformed packet to port 139, triggering a heap overflow. Exploit available. All affected versions of the Windows operating system are configured with the vulnerable service enabled by default. Includes snort rule. MS security bulletin for this bug is MS02-045.
Homepage:http://www.iss.net/security_center
File Size:5124
Related CVE(s):CAN-2002-0724
Last Modified:Aug 30 20:50:36 2002
MD5 Checksum:c1a41e51ef34733065164f72ef91735d

 ///  File Name: iss.snort-rpc.txt
Description:
ISS Security Advisory - Snort v1.8 through 1.9.0 contains a remote root vulnerability in the processing of fragmented RPC traffic. Since fragment sizes are not properly checked against the remaining buffer space, remote attackers can execute arbitrary code as root by sending a packet to any IP in network space a snort sensor is listening to. Successful exploitation does not generate log entries, and non-executable stacks do not offer protection.
Homepage:http://xforce.iss.net
File Size:2912
Last Modified:Mar 11 00:26:56 2003
MD5 Checksum:9586718047fb1b5adb1e3adb78451830

 ///  File Name: iss.summary.6.6
Description:
ISS Security Alert Summary for May 10, 2001 - Volume 6 Number 6. 120 new vulnerabilities were reported this month. This document has links to more information and full advisories on each. Includes: thebat-masked-file-type, php-nuke-url-redirect, orinoco-rg1000-wep-key, navision-server-dos, ustorekeeper-retrieve-files, resin-view-javabean, bpftp-obtain-credentials, ntpd-remote-bo, cisco-css-elevate-privileges, bea-tuxedo-remote-access, ultimatebb-bypass-authentication, bintec-x4000-nmap-dos, firebox-kernel-dos, cisco-pix-tacacs-dos, ipfilter-access-ports, veritas-netbackup-nc-dos, nai-pgp-split-keys, solaris-kcms-command-bo, talkback-cgi-read-files, ftp-glob-implementation, pine-tmp-file-symlink, ftp-glob-expansion, netscape-javascript-access-data, strip-weak-passwords, solaris-xsun-home-bo, compaq-activex-dos, alcatel-expert-account, alcatel-tftp-lan-access, alcatel-tftp-wan-access, oracle-appserver-ndwfn4-bo, alcatel-blank-password, solaris-dtsession-bo, solaris-kcssunwiosolf-bo, lightwave-consoleserver-brute-force, nph-maillist-execute-code, ghost-configuration-server-dos, lotus-domino-device-dos, lotus-domino-header-dos, lotus-domino-url-dos, lotus-domino-corba-dos, ghost-database-engine-dos, cfingerd-remote-format-string, lotus-domino-unicode-dos, mkpasswd-weak-passwords, solaris-ipcs-bo, interscan-viruswall-isadmin-bo, hylafax-hfaxd-format-string, cisco-vpn-ip-dos, ibm-websphere-reveals-path, qpc-ftpd-bo, qpc-ftpd-directory-traversal, qpc-popd-bo, ncm-content-database-access, netscape-smartdownload-sdph20-bo, sco-openserver-accept-bo, sco-openserver-cancel-bo, sco-openserver-disable-bo, sco-openserver-enable-bo, sco-openserver-lp-bo, sco-openserver-lpfilter-bo, sco-openserver-lpstat-bo, sco-openserver-reject-bo, sco-openserver-rmail-bo, sco-openserver-tput-bo, ibm-websphere-macro-dos, sco-openserver-lpmove-bo, reliant-unix-ppd-symlink, exuberant-ctags-symlink, processit-cgi-view-info, isa-web-proxy-dos, ie-clsid-execute-files, cisco-catalyst-8021x-dos, bubblemon-elevate-privileges, dcforum-az-directory-traversal, dcforum-az-file-upload, dcforum-az-expr, linux-netfilter-iptables, xitami-server-dos, samba-tmpfile-symlink, goahead-aux-dos, analogx-simpleserver-aux-dos, viking-hex-directory-traversal, solaris-ftp-shadow-recovery, thebat-pop3-dos, eudora-plain-text-attachment, vmware-mount-symlink, kfm-tmpfile-symlink, cyberscheduler-timezone-bo, ms-dacipp-webdav-access, oracle-tnslsnr80-dos, innfeed-c-bo, iplanet-calendar-plaintext-password, nedit-print-symlink, checkbo-tcp-bo, hp-pcltotiff-insecure-permissions, netopia-timbuktu-gain-access, cisco-cbos-gain-information, ie-xml-stylesheets-scripting, gftp-format-string, bordermanager-vpn-syn-dos, saft-sendfiled-execute-code, mercury-mta-bo, qnx-fat-file-read, viking-dot-directory-traversal, netcruiser-server-path-disclosure, perl-webserver-directory-traversal, small-http-aux-dos, ipswitch-imail-smtp-bo, kerberos-inject-base64-encode, irix-netprint-shared-library, webxq-dot-directory-traversal, raidenftpd-dot-directory-traversal, perlcal-calmake-directory-traversal, icq-webfront-dos, alex-ftp-directory-traversal, webweaver-ftp-path-disclosure, webweaver-web-directory-traversal, winamp-aip-bo, bearshare-dot-download-files, and iis-isapi-bo.
Homepage:http://xforce.iss.net
File Size:49686
Last Modified:May 16 03:07:09 2001
MD5 Checksum:358149138360bf4d1ae5e25e561405cc

 ///  Directory: / summary /
Description:
Unavailable.
Total Files:51
Last Modified:Sep 14 08:52:34 2004