exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 39 of 39 RSS Feed

Files Date: 2010-03-11 to 2010-03-12

Secunia Security Advisory 38880
Posted Mar 11, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Ubuntu has issued an update for dpkg. This fixes a vulnerability, which can be exploited by malicious people to manipulate certain data or compromise a vulnerable system.

tags | advisory
systems | linux, ubuntu
SHA-256 | d34b8ed0a03f15c88a195d0c2d414e43f73625ed5fb7de211c498929d9dd4a3b
Secunia Security Advisory 38901
Posted Mar 11, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Debian has issued an update for kvm. This fixes some vulnerabilities, which can be exploited by malicious, local users in a KVM guest to cause a DoS (Denial of Service) and potentially gain escalated privileges.

tags | advisory, denial of service, local, vulnerability
systems | linux, debian
SHA-256 | b9c8a0da863de74248ab8b8d126d18bd56a13c2ed5c5ae08e37df776afe77258
Secunia Security Advisory 38913
Posted Mar 11, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in the TinyMCE module for Drupal, which can be exploited by malicious users to conduct script insertion attacks.

tags | advisory
SHA-256 | 62614889fe7fcf257f4d81ab0f59a77be64114b2764240bf996e7b5a5cb37d5f
Mandriva Linux Security Advisory 2010-060
Posted Mar 11, 2010
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2010-060 - The htcpHandleTstRequest function in htcp.c in Squid 2.x and 3.0 through 3.0.STABLE23 allows remote attackers to cause a denial of service (crash) via crafted packets to the HTCP port, which triggers a NULL pointer dereference. Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers. The updated packages have been patched to correct this issue.

tags | advisory, remote, denial of service
systems | linux, mandriva
advisories | CVE-2010-0639
SHA-256 | 661f12b4d05d295d68360ef3b6e85e913a7eab12a3a6263ea69415c8e41882b3
Cookie Monster 1.6
Posted Mar 11, 2010
Authored by Tom Neaves | Site tomneaves.com

Cookie Monster is a cookie analysis tool written in Python. Cookie Monster will grab cookies from a host and assign each character a number. This number can be used to perform mathematical calculations on the differences in order to find a pattern and see if cookie prediction is possible.

tags | web, python
SHA-256 | 2ea212371ff52f7cdc5a9a96dc54b6d8e61438beb08855caa82fdf7b84a5f569
SUPERAntiSpyware / Super Ad Blocker Privilege Escalation
Posted Mar 11, 2010
Authored by Luka Milkovic

SUPERAntiSpyware and Super Ad Blocker have almost identical device drivers in order to set up hooks and perform other duties from kernel space. These device drivers suffer from lack of validation of parameters passed from user mode. Additionally, some of the functions accessible from user mode are inherently insecure and lead to easy privilege escalation. All vulnerabilities are applicable to both applications. Proof of concept code included with full advisory.

tags | exploit, kernel, vulnerability, proof of concept
SHA-256 | 93da6437bcb9637e120be7066882ac3cc94fb1b077eadc44cf86ee641dfae3c6
Joomla About SQL Injection
Posted Mar 11, 2010
Authored by Snakespc

The Joomla About component suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 9ef1e1ad7f752d0f8c3d5d96a17b46d69f06f3ede569d82b714da5e900020741
Ubuntu Security Notice 908-1
Posted Mar 11, 2010
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 908-1 - It was discovered that mod_proxy_ajp did not properly handle errors when a client doesn't send a request body. A remote attacker could exploit this with a crafted request and cause a denial of service. This issue affected Ubuntu 8.04 LTS, 8.10, 9.04 and 9.10. It was discovered that Apache did not properly handle headers in subrequests under certain conditions. A remote attacker could exploit this with a crafted request and possibly obtain sensitive information from previous requests.

tags | advisory, remote, denial of service
systems | linux, ubuntu
advisories | CVE-2010-0408, CVE-2010-0434
SHA-256 | 80d32823dfe961f4baf74b024c759d7fbcb6e2c7ef4911f5901600a679ada31f
Mandriva Linux Security Advisory 2010-059
Posted Mar 11, 2010
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2010-059 - Unspecified vulnerability in Guest Additions in Sun xVM VirtualBox 1.6.x and 2.0.x before 2.0.12, 2.1.x, and 2.2.x, and Sun VirtualBox before 3.0.10, allows guest OS users to cause a denial of service (memory consumption) on the guest OS via unknown vectors. Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers. The updated packages have been patched to correct this issue.

tags | advisory, denial of service
systems | linux, mandriva
advisories | CVE-2009-3940
SHA-256 | d1f0ae42f56c3585d6cea7fb2cee597d287eb71ad35bb226d41784daea2574b9
Debian Linux Security Advisory 2010-1
Posted Mar 11, 2010
Authored by Debian | Site debian.org

Debian Linux Security Advisory 2010-1 - Several local vulnerabilities have been discovered in kvm, a full virtualization system.

tags | advisory, local, vulnerability
systems | linux, debian
advisories | CVE-2010-0298, CVE-2010-0306, CVE-2010-0309, CVE-2010-0419
SHA-256 | 26bf9b70f55c01cac135f5a868a8ec35a51a7b037e9a95f028c0f10c4079e475
XnView DICOM Parsing Integer Overflow
Posted Mar 11, 2010
Authored by Stefan Cornelius | Site secunia.com

Secunia Research has discovered a vulnerability in XnView, which can be exploited by malicious people to potentially compromise a user's system. The vulnerability is caused due to an integer overflow when processing DICOM images with certain dimensions. This can be exploited to cause a heap-based buffer overflow by e.g. tricking a user into opening a specially crafted DICOM file. Version 1.97 is affected.

tags | advisory, overflow
advisories | CVE-2009-4001
SHA-256 | efa3ea2064ba6d18a4e149ff97e318e1885159d38d9d0c2bc5986a2d69036f67
Microsoft Office Excel Record Processing Code Execution
Posted Mar 11, 2010
Authored by Nicolas Joly | Site vupen.com

VUPEN Vulnerability Research Team discovered a critical vulnerability affecting Microsoft Office Excel. The flaw is caused by a memory corruption error when processing malformed "EntExU2" records in an Excel document, which could be exploited by attackers to execute arbitrary code.

tags | advisory, arbitrary
advisories | CVE-2010-0257
SHA-256 | 13f9968930b3332dbfde62e94caad311f358ab18e12e54fe2ff3b65655a29182
Microsoft Internet Explorer iepeers.dll Use After Free
Posted Mar 11, 2010
Authored by Trancer | Site metasploit.com

This Metasploit module exploits a use-after-free vulnerability within iepeers.dll of Microsoft Internet Explorer versions 6 and 7. NOTE: Internet Explorer 8 and Internet Explorer 5 are not affected.

tags | exploit
advisories | CVE-2010-0806
SHA-256 | ca6ec897859207169db7407f8bb4734a3760e5319a030b811baaa720b7efddaa
PHPCityPortal SQL Injection / Remote File Inclusion
Posted Mar 11, 2010
Authored by R3d-D3v!L

PHPCityPortal suffers from remote file inclusion and SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, code execution, sql injection, file inclusion
SHA-256 | 82026a7c3f499732c4377fb5cf0c832e25b3fd2cb5e4f608892d6f3e1d36d307
Page 2 of 2
Back12Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    48 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    60 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close