New User, Welcome!     Login

Vulnerability Database

[scip_Advisory 4143] Shemes Grabbit Malicious NZB Date Denial of Service

VIII. SOURCES

scip AG - Security is our Business (german)
http://www.scip.ch

scip AG - Vulnerability Database (german)
http://www.scip.ch/?vuldb.4143

computec.ch Document Database (german)
http://www.computec.ch


RE: CORE-2007-0817: Remote Command execution, HTML and JavaScript injection vulnerabilities in AOL's Instant Messaging software

security advisory to provide vulnerable users with the details needed to
assess risk and devise their own mitigation mechanisms until official
fixed versions of the clients are made available.
*2007-09-19*: Email sent to AOL indicating that information about the
reported vulnerabilities is now part of Mitre CVE dictionary, the US
National Vulnerability Database [3], the Securityfocus.com vulnerability
Database [4] and the Secunia.com website [5], therefore Core considers
that any security-aware party (either good or bad intended) can now easily
figure out a remote exploitation method. In fact, several messages in
AOL's technical forums seem to indicate that users of AIM clients are
experiencing AIM "bugs" or "problems" related to the issues reported in

MacOS X 10.5/10.6 libc/strtod(3) buffer overflow

- - http://securityreason.com/key/Arciemowicz.Maksymilian.gpg
- - http://securityreason.com/key/sp3x.gpg

http://securityreason.com/
http://securityreason.com/exploit_alert/ - Exploit Database
http://securityreason.com/security_alert/ - Vulnerability Database

-----BEGIN PGP SIGNATURE-----

iEYEARECAAYFAktGcnsACgkQpiCeOKaYa9aRzgCgth+8HlRjOPmeJNGc+wCplmmC
xsAAoNsMatpwiW8k93sTbjMayHfPna1a

[scip_Advisory 4142] Skype Client for Mac Chat Unicode Denial of Service

VIII. SOURCES

scip AG - Security is our Business (german)
http://www.scip.ch/

scip AG - Vulnerability Database (german)
http://www.scip.ch/?vuldb.4142

computec.ch Document Database (german)
http://www.computec.ch


[scip_Advisory 4021] IBM Lotus Notes 8.5 RSS Widget Privilege Escalation

VIII. SOURCES

scip AG - Security Consulting Information Process (german)
http://www.scip.ch/

scip AG - Vulnerability Database (german)
http://www.scip.ch/?vuldb.4021

computec.ch Document Database (german)
http://www.computec.ch/download.php


[scip_Advisory 3807] Dreambox DM500 webserver long URL request denial of service

VIII. SOURCES

scip AG - Security Consulting Information Process (german)
http://www.scip.ch/

scip AG Vulnerability Database (german)
http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=3807

computec.ch document data base (german)
http://www.computec.ch/download.php


CORE-2007-0817: Remote Command execution, HTML and JavaScript injection vulnerabilities in AOL's Instant Messaging software

security advisory to provide vulnerable users with the details needed to
assess risk and devise their own mitigation mechanisms until official
fixed versions of the clients are made available.
*2007-09-19*: Email sent to AOL indicating that information about the
reported vulnerabilities is now part of Mitre CVE dictionary, the US
National Vulnerability Database [3], the Securityfocus.com vulnerability
Database [4] and the Secunia.com website [5], therefore Core considers
that any security-aware party (either good or bad intended) can now easily
figure out a remote exploitation method. In fact, several messages in
AOL's technical forums seem to indicate that users of AIM clients are
experiencing AIM "bugs" or "problems" related to the issues reported in

Sun Solaris 10 libc/*convert (*cvt) buffer overflow

GPG:
- - http://securityreason.com/key/Arciemowicz.Maksymilian.gpg

http://securityreason.com/
http://securityreason.com/exploit_alert/ - Exploit Database
http://securityreason.com/security_alert/ - Vulnerability Database
-----BEGIN PGP SIGNATURE-----

iEYEARECAAYFAkv2dzwACgkQpiCeOKaYa9ZlZgCePDO6yzT92gv8BZWgVIzkRVz7
SHIAn2EeEKyQMPdGXWcEahv0lYzwizzy
=SXST

Sun Solaris 10 filesystem rm(1),find(1),etc, Denial-of-service

GPG:
- - http://securityreason.com/key/Arciemowicz.Maksymilian.gpg

http://securityreason.com/
http://securityreason.com/exploit_alert/ - Exploit Database
http://securityreason.com/security_alert/ - Vulnerability Database

-----BEGIN PGP SIGNATURE-----

iEYEARECAAYFAkv2dbQACgkQpiCeOKaYa9aN0QCgvsk4mNEx7yXRqAX/CHOZl53x
J2YAn1OnO769x8IN2evc3VMt79QTOp+O

Sun Solaris 10 ftpd Cross-site request forgery

GPG:
- - http://securityreason.com/key/Arciemowicz.Maksymilian.gpg

http://securityreason.com/
http://securityreason.com/exploit_alert/ - Exploit Database
http://securityreason.com/security_alert/ - Vulnerability Database
-----BEGIN PGP SIGNATURE-----

iEYEARECAAYFAkv2dacACgkQpiCeOKaYa9ZuwwCfcLbAFFQOpZ4+2j5sSOvNUa97
7HEAoJLTh6ygjroFhJuboBfgRuIhFEoh
=5zDe

[scip_Advisory 4020] Check Point Connectra R62 Login Script Injection Vulnerability

VIII. SOURCES

scip AG - Security Consulting Information Process (german)
http://www.scip.ch/

scip AG Vulnerability Database (german)
http://www.scip.ch/?vuldb.4020

IX. DISCLOSURE TIMELINE

2009/09/04 Identification of the vulnerability, Vendor is being

[scip-Advisory 4063] PasswordManager Pro 6.1 Script Injection Vulnerability

VIII. SOURCES

scip AG - Security Consulting Information Process (german)
http://www.scip.ch/

scip AG Vulnerability Database (german)
http://www.scip.ch/?vuldb.4063


IX. DISCLOSURE TIMELINE


[scip_Advisory 3809] Pro2col StingRay FTS login username cross site scripting

VIII. SOURCES

scip AG - Security Consulting Information Process (german)
http://www.scip.ch/

scip AG Vulnerability Database (german)
http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=3809

computec.ch document data base (german)
http://www.computec.ch/download.php


[scip_Advisory 3808] D-Link DIR-100 long url filter evasion

VIII. SOURCES

scip AG - Security Consulting Information Process (german)
http://www.scip.ch/

scip AG Vulnerability Database (german)
http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=3808

computec.ch document data base (german)
http://www.computec.ch/download.php


Google SoC 2008: Security Projects

Google will begin accepting student applications on Monday, March 24, 
2008! Please help spread the word and encourage all eligible students to 
apply for one of the security related projects!

OSVDB: The Open Source Vulnerability Database:
http://osvdb.org/blog/?p=231

OSSIM: Open Source Security Information Management:
http://www.ossim.net/dokuwiki/doku.php?id=ideas


SYM07-029 Symantec BEWS Multiple DoS in Job Engine

CVE-2007-4347 to the integer overflow DoS issues

These issues are candidates for inclusion in the CVE list (http://cve.mitre.org), which standardizes names for security issues. 

SecurityFocus has assigned Bugtraq ID BID 26028 for the null pointer issue and BID 26029 for the integer overflow issues 
for inclusion in the SecurityFocus vulnerability database. 


Symantec strongly recommends using encrypted email for reporting vulnerability information to secure@symantec.com. 
The Symantec Product Security PGP key can be obtained from http://www.symantec.com/security. 




Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!