New User, Welcome!     Login

Next Page >>

Reported By

Survey: "MIME/Content-Type-Sniffing" Issues in Image Uploads in Forum Scripts

Advisory: “Cross-Site Scripting” in Avatar uploads in fluxBB

Application: fluxBB
Vulnerable Versions: 1.3-legacy and older 1.3 versions.
Reported By: Jacques Copeau

Note
***********
This advisory is part of a survey about vulnerable file uploads in forum
software. The survey will be published after all vendors have fixed their

CA ARCserve Backup Discovery Service Denial of Service Vulnerability

CA Advisory Date: 2008-06-17


Reported By: Luigi Auriemma


Impact: A remote attacker can cause a denial of service.



[CAID 35673, 35674, 35675, 35676, 35677]: CA ARCserve Backup for Laptops and Desktops Multiple Server Vulnerabilities

CA Vuln ID (CAID): 35673, 35674, 35675, 35676, 35677

CA Advisory Date: 2007-09-20

Reported By: Sean Larsson (VeriSign iDefense Labs)
             anonymous researcher working with the iDefense VCP
             eEye Digital Security


Impact: A remote attacker can execute arbitrary code or cause a 

CA20090126-01: CA Anti-Virus Engine Detection Evasion Multiple Vulnerabilities [Updated]

CA Advisory Date: 2009-01-26
CA Advisory Updated: May 12, 2009


Reported By:
Thierry Zoller and Sergio Alvarez of n.runs AG


Impact: A remote attacker can evade detection.


CA Multiple Products DSM ListCtrl ActiveX Control Buffer Overflow Vulnerability

CVE: CVE-2008-1472

CA Advisory Date: 2008-03-28

Reported By: Exploit code posted at milw0rm.com

Impact: A remote attacker can cause a denial of service or execute 
arbitrary code.

Summary: CA products that implement the DSM ListCtrl ActiveX 

CA Secure Content Manager HTTP Gateway Service FTP Request Vulnerabilities

CA Advisory Date: 2008-06-03


Reported By: Sebastian Apelt working with ZDI/TippingPoint
             Cody Pierce, TippingPoint DVLabs


Impact: A remote attacker can cause a denial of service or execute 
arbitrary code.

CA20090615-01: CA ARCserve Backup Message Engine Denial of Service Vulnerabilities

CA Advisory Date: 2009-06-15


Reported By: iViZ Security Research Team


Impact: A remote attacker can cause a denial of service.



[CAID 35754]: CA Host-Based Intrusion Prevention System (CA HIPS) Server Vulnerability

CA Vuln ID (CAID): 35754

CA Advisory Date: 2007-10-18

Reported By: David Maciejak

Impact: A remote attacker can take unauthorized administrative 
action.

Summary: CA Host-Based Intrusion Prevention System (CA HIPS) 

CA Service Desk Multiple Cross-Site Scripting Vulnerabilities

CA Advisory Date: 2008-09-24


Reported By:
Open Security Foundation


Impact: A remote attacker can conduct cross-site scripting attacks.


CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1)

CA Advisory Date: 2009-01-23


Reported By: n/a


Impact: Refer to the CVE identifiers for details.



[CAID 35690, 35691, 35692]: CA BrightStor Hierarchical Storage Manager CsAgent Multiple Vulnerabilities

CA Vuln ID (CAID): 35690, 35691, 35692

CA Advisory Date: 2007-09-26

Reported By: Sean Larsson, iDefense Labs
             anonymous researcher working with the iDefense VCP
             Aaron Portnoy of DV Labs (dvlabs.tippingpoint.com)

Impact: A remote attacker can execute arbitrary code or cause a 
denial of service condition.

[CAID 35724, 35725, 35726]: CA BrightStor ARCserve Backup Multiple Vulnerabilities

CA Vuln ID (CAID): 35724, 35725, 35726

CA Advisory Date: 2007-10-10

Reported By: 
Anonymous researcher working with the iDefense VCP (CVE-2007-5325)
Dyon Balding of Secunia Research (CVE-2007-5326)
Cocoruder of Fortinet Security Research Team (CVE-2007-5327)
Tenable Network Security (CVE-2007-5328)
Pedram Amini of DV Labs (dvlabs.tippingpoint.com) (CVE-2007-5329)

CA DSM gui_cm_ctrls ActiveX Control Vulnerability

CA Advisory Date: 2008-04-15


Reported By: Greg Linares of eEye Digital Security


Impact: A remote attacker can execute arbitrary code or cause a 
denial of service condition.


CA ARCserve Backup Multiple Vulnerabilities

CA Advisory Date: 2008-10-09


Reported By:
Haifei Li of Fortinet's FortiGuard Global Security Research Team
Vulnerability Research Team of Assurent Secure Technologies, a 
   TELUS Company
Greg Linares of eEye Digital Security


CA20090107-01: CA Service Metric Analysis and CA Service Level Management smmsnmpd Arbitrary Command Execution Vulnerability

CA Advisory Date: 2009-01-07


Reported By:
Michel Arboi of Tenable Network Security


Impact: A remote attacker can execute arbitrary commands.


CA20090429-01: CA ARCserve Backup Apache HTTP Server Multiple Vulnerabilities

CA Advisory Date: 2009-04-29


Reported By:
Apache Software Foundation
David Endler of iDefense
Ulf Harnhammar for SITIC, Swedish IT Incident Centre



CA ARCserve Backup caloggerd and xdr Functions Vulnerabilities

CA Advisory Date: 2008-05-19


Reported By: An anonymous researcher working with the iDefense VCP
             Damian Put working with ZDI/TippingPoint


Impact: A remote attacker can cause a denial of service or execute 
arbitrary code.

CA ARCserve Backup for Laptops and Desktops Server and CA Desktop Management Suite Multiple Vulnerabilities

Title: CA ARCserve Backup for Laptops and Desktops Server and CA 
Desktop Management Suite Multiple Vulnerabilities

CA Advisory Date: 2008-04-03

Reported By: Dyon Balding of Secunia Research

Impact: A remote attacker can execute arbitrary code or cause a 
denial of service condition.

Summary: CA ARCserve Backup for Laptops and Desktops Server 

CA20090126-01: CA Anti-Virus Engine Detection Evasion Multiple Vulnerabilities

CA Advisory Date: 2009-01-26


Reported By:
Thierry Zoller and Sergio Alvarez of n.runs AG


Impact: A remote attacker can evade detection.


CA ARCserve Backup for Laptops and Desktops Server LGServer Service Vulnerability

CA Advisory Date: 2008-07-31


Reported By: Vulnerability Research Team of Assurent Secure 
Technologies, a TELUS Company


Impact: A remote attacker can execute arbitrary code or cause a 
denial of service condition. 

[CAID 35724, 35725, 35726]: CA BrightStor ARCserve Backup Multiple Vulnerabilities

CA Vuln ID (CAID): 35724, 35725, 35726

CA Advisory Date: 2007-10-10
CA Advisory Updated: 2007-12-05

Reported By: 
Anonymous researcher working with the iDefense VCP (CVE-2007-5325)
Dyon Balding of Secunia Research (CVE-2007-5326)
Cocoruder of Fortinet Security Research Team (CVE-2007-5327)
Tenable Network Security (CVE-2007-5328)
Pedram Amini of DV Labs (dvlabs.tippingpoint.com) (CVE-2007-5329)

[CAID 35970]: CA Products That Embed Ingres Authentication Vulnerability

CA Vuln ID (CAID): 35970

CA Advisory Date: 2007-12-19

Reported By: Ingres Corporation

Impact: Attacker can gain elevated privileges.

Summary: A potential vulnerability exists in the Ingres software 
that is embedded in various CA products. This vulnerability exists 

CA Alert Notification Server Multiple Vulnerabilities

Title: CA Alert Notification Server Multiple Vulnerabilities

CA Advisory Date: 2008-04-03

Reported By: An anonymous researcher working with the iDefense VCP

Impact: A remote authenticated attacker can execute arbitrary code 
or cause a denial of service condition.

Summary: CA Alert Notification Server service contains multiple 

CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities

CA Advisory Date: 2009-01-23


Reported By: n/a


Impact: A remote attacker can execute arbitrary commands.



CA Products That Embed Ingres Multiple Vulnerabilities

CA Advisory Date: 2008-08-01


Reported By: iDefense Labs


Impact: A remote attacker can execute arbitrary code, gain 
privileges, or cause a denial of service condition. 


CA Host-Based Intrusion Prevention System SDK kmxfw.sys Multiple Vulnerabilities

CA Advisory Date: 2008-08-11


Reported By:
CVE-2008-2926 - Tobias Klein
CVE-2008-3174 - Elazar Broad


Impact: A remote attacker can cause a denial of service or 

CA ARCserve Backup LDBserver Vulnerability

CA Advisory Date: 2008-12-10


Reported By:
Dyon Balding of Secunia Research


Impact: A remote attacker can cause a denial of service or execute 
arbitrary code.

CA20090615-01: CA ARCserve Backup Message Engine Denial of Service Vulnerabilities (Updated)

CA Advisory Date: 2009-06-15


Reported By: iViZ Security Research Team


Impact: A remote attacker can cause a denial of service.



AST-2008-006 - 3-way handshake in IAX2 incomplete

   |--------------------+---------------------------------------------------|
   |   Exploits Known   | Yes                                               |
   |--------------------+---------------------------------------------------|
   |    Reported On     | April 18, 2008                                    |
   |--------------------+---------------------------------------------------|
   |    Reported By     | Joel R. Voss aka. Javantea < jvoss AT altsci DOT  |
   |                    | com >                                             |
   |--------------------+---------------------------------------------------|
   |     Posted On      | April 22, 2008                                    |
   |--------------------+---------------------------------------------------|
   |  Last Updated On   | April 22, 2008                                    |

AST-2008-004: Format String Vulnerability in Logger and Manager

   |--------------------+---------------------------------------------------|
   |   Exploits Known   | No                                                |
   |--------------------+---------------------------------------------------|
   |    Reported On     | March 13, 2008                                    |
   |--------------------+---------------------------------------------------|
   |    Reported By     | Steve Davies (bugs.digium.com user stevedavies)   |
   |                    |                                                   |
   |                    | Brandon Kruse (bugs.digium.com user bkruse)       |
   |--------------------+---------------------------------------------------|
   |     Posted On      | March 18, 2008                                    |
   |--------------------+---------------------------------------------------|

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!