New User, Welcome!     Login

application suite

iDefense Security Advisory 01.10.11: HP Network Node Manager Command Injection Vulnerability

Jan 10, 2011

I. BACKGROUND

HP Network Node Manager Command Injection Vulnerability HP Network Node
Manager (NNM) is an application suite that is used to map out and
manage network topography. NNM runs on a variety of platforms,
including Linux and multiple versions of Windows. For more information,
see the vendor's site found at the following link:
http://www.openview.hp.com/products/nnm/index.html


Bractus SunTrack Multiple XSS

Vendor: Bractus (http://bract.us)
Product: SunTrack (http://bract.us/demo/login.jsp)

Multiple stored XSS vulnerabilities exist in the Bractus SunTrack
courier software suite.

Affected scripts:
newprofile.html (title parameter)
signup/signup.html (firstname, lastname, company parameter)
contact.html (firstname, lastname, address[0].street1 parameter)

iDefense Security Advisory 05.12.09: Microsoft PowerPoint PPT95 Import Multiple Stack Buffer Overflow Vulnerabilities

May 12, 2009

I. BACKGROUND

Microsoft PowerPoint is the presentation application that is included
with Microsoft Corp's Office productivity software suite. More
information is available at the following website.

http://office.microsoft.com/en-us/word/default.aspx

II. DESCRIPTION

iDefense Security Advisory 03.09.10: Microsoft Excel FNGROUPNAME Record Uninitialized Memory Vulnerability

Mar 09, 2010

I. BACKGROUND

Excel is the spreadsheet application included with Microsoft Corp.'s
Office productivity software suite. More information is available at
the following website:

http://office.microsoft.com/excel/

II. DESCRIPTION

iDefense Security Advisory 08.12.08: Microsoft Excel FORMAT Record Invalid Array Index Vulnerability

Aug 12, 2008

I. BACKGROUND

Microsoft Excel is the spreadsheet application that is included with
Microsoft Corp.'s Office productivity software suite. More information
is available at the following website.

http://office.microsoft.com/excel/

II. DESCRIPTION

Secunia Research: Samba "receive_smb_raw()" Buffer Overflow Vulnerability

Where:  From remote

====================================================================== 
3) Vendor's Description of Software 

"Samba is an Open Source/Free Software suite that has, since 1992,
provided file and print services to all manner of SMB/CIFS clients,
including the numerous versions of Microsoft Windows operating systems.
Samba is freely available under the GNU General Public License."

Product Link:

[ GLSA 200708-09 ] Mozilla products: Multiple vulnerabilities

==========

Mozilla Firefox is an open-source web browser from the Mozilla Project,
and Mozilla Thunderbird an email client. The SeaMonkey project is a
community effort to deliver production-quality releases of code derived
from the application formerly known as the 'Mozilla Application Suite'.
XULRunner is a Mozilla runtime package that can be used to bootstrap
XUL+XPCOM applications like Firefox and Thunderbird.

Affected packages
=================

Secunia Research: OpenOffice.org Word Document Table Parsing Buffer Overflow

Where:  Remote

====================================================================== 
3) Vendor's Description of Software 

"OpenOffice.org 3 is the leading open-source office software suite for
word processing, spreadsheets, presentations, graphics, databases and
more.".

Product Link:
http://openoffice.org/

iDefense Security Advisory 03.09.10: Microsoft Excel MDXTUPLE Record Heap Overflow Vulnerability

Mar 09, 2010

I. BACKGROUND

Excel is the spreadsheet application included with Microsoft Corp.'s
Office productivity software suite. More information is available at
the following website:

http://office.microsoft.com/excel/

II. DESCRIPTION

iDefense Security Advisory 10.14.08: Microsoft Host Integration Server 2006 Command Execution Vulnerability

http://labs.idefense.com/intelligence/vulnerabilities/
Oct 14, 2008

I. BACKGROUND

The Host Integration Server is an application suite that is used to
communicate with IBM mainframe servers. One of the components of the
suite is a remote management interface. This interface is implemented
by an RPC server that listens on a dynamic TCP port. The UUID of the
vulnerable RPC service is 'ed6ee250-e0d1-11cf-925a-00aa00c006c1'. For
more information regarding the Host Integration Server, see the

iDefense Security Advisory 08.12.08: Microsoft Excel Chart AxesSet Invalid Array Index Vulnerability

Aug 12, 2008

I. BACKGROUND

Microsoft Excel is the spreadsheet application that is included with
Microsoft Corp.'s Office productivity software suite. More information
is available at the following website.

http://office.microsoft.com/excel/

II. DESCRIPTION

SeaMonkey 1.1.8 Remote Array Overrun (Arbitrary code execution)

Original URL:
http://securityreason.com/achievement_securityalert/71


- --- 0.Description ---
The SeaMonkey project is a community effort to develop the SeaMonkey all-in-one internet application suite (see below). Such a software suite was previously made popular by Netscape and Mozilla, and the SeaMonkey project continues to develop and deliver high-quality updates to this concept. Containing an Internet browser, email & newsgroup client with an included web feed reader, HTML editor, IRC chat and web development tools, SeaMonkey is sure to appeal to advanced users, web developers and corporate users.


- --- 1. SeaMonkey 1.1.18 Remote Array Overrun (Arbitrary code execution) ---
The main problem exist in dtoa implementation. SeaMonkey has the same dtoa as a KDE, Opera and all BSD systems. This issue has been fixed in Firefox 3.5.4 and fix


iDefense Security Advisory 02.06.09: HP Network Node Manager Multiple Information Disclosure Vulnerabilities

http://labs.idefense.com/intelligence/vulnerabilities/
Feb 06, 2009

I. BACKGROUND

HP Network Node Manager (NNM) is an application suite that is used to
map out and manage network topography. NNM runs on a variety of
platforms, including Linux and multiple versions of Windows. For more
information, see the vendor's site found at the following link.

http://www.openview.hp.com/products/nnm/index.html

iDefense Security Advisory 06.11.09: Microsoft Excel SST Record Integer Overflow Vulnerability

Jun 09, 2009

I. BACKGROUND

Excel is the spreadsheet application included with Microsoft Corp.'s
Office productivity software suite. More information is available at
the following website:

http://office.microsoft.com/excel/

II. DESCRIPTION

iDefense Security Advisory 02.06.09: HP Network Node Manager Multiple Command Injection Vulnerabilities

http://labs.idefense.com/intelligence/vulnerabilities/
Feb 06, 2009

I. BACKGROUND

HP Network Node Manager (NNM) is an application suite that is used to
map out and manage network topography. NNM runs on a variety of
platforms, including Linux and multiple versions of Windows. For more
information, see the vendor's site found at the following link.

http://www.openview.hp.com/products/nnm/index.html

iDefense Security Advisory 11.10.09: Microsoft Excel FEATHEADER Record Memory Corruption Vulnerability

Nov 10, 2009

I. BACKGROUND

Excel is the spreadsheet application included with Microsoft Corp.'s
Office productivity software suite. More information is available at
the following website:

http://office.microsoft.com/excel/

II. DESCRIPTION

[ GLSA 200808-03 ] Mozilla products: Multiple vulnerabilities

Mozilla Firefox is an open-source web browser and Mozilla Thunderbird
an open-source email client, both from the Mozilla Project. The
SeaMonkey project is a community effort to deliver production-quality
releases of code derived from the application formerly known as the
'Mozilla Application Suite'. XULRunner is a Mozilla runtime package
that can be used to bootstrap XUL+XPCOM applications like Firefox and
Thunderbird.

Affected packages
=================

iDefense Security Advisory 03.09.10: Microsoft Excel MDXSET Record Heap Overflow Vulnerability

Mar 09, 2010

I. BACKGROUND

Excel is the spreadsheet application included with Microsoft Corp.'s
Office productivity software suite. More information is available at
the following website:

http://office.microsoft.com/excel/

II. DESCRIPTION

Secunia Research: OpenOffice.org Word Document Table Parsing Integer Underflow

Where:  From remote

====================================================================== 
3) Vendor's Description of Software 

"OpenOffice.org 3 is the leading open-source office software suite for
word processing, spreadsheets, presentations, graphics, databases and
more.".

Product Link:
http://openoffice.org/

EEYE: Multiple Vulnerabilities in CA ARCserve for Laptops & Desktops

CA Protection Suites r2

Overview:
eEye Digital Security has discovered multiple vulnerabilities within CA
ARCserve for Laptops & Desktops (L&D), an enterprise-level backup
software suite designed for workstations.  The vulnerabilities can be
utilized by an attacker to execute arbitrary code on a remote system
anonymously over TCP/1900.


Technical Details:

iDefense Security Advisory 03.11.08: Microsoft Excel 2003 Malformed Formula Memory Corruption Vulnerability

Mar 11, 2008

I. BACKGROUND

Microsoft Excel is the spreadsheet application that is included with
Microsoft Corp's Office productivity software suite. More information
is available at the following website.

http://office.microsoft.com/excel/

II. DESCRIPTION

iDefense Security Advisory 03.09.10: Microsoft Excel Sheet Object Type Confusion Vulnerability

Mar 09, 2010

I. BACKGROUND

Excel is the spreadsheet application included with Microsoft Corp.'s
Office productivity software suite. More information is available at
the following website:

http://office.microsoft.com/excel/

II. DESCRIPTION

Secunia Research: Samba "send_mailslot()" Buffer Overflow Vulnerability

Where:  Local network

====================================================================== 
3) Vendor's Description of Software 

"Samba is an Open Source/Free Software suite that has, since 1992,
provided file and print services to all manner of SMB/CIFS clients,
including the numerous versions of Microsoft Windows operating systems.
Samba is freely available under the GNU General Public License."

Product Link:

iDefense Security Advisory 03.11.08: Microsoft Excel DVAL Heap Corruption Vulnerability

Mar 11, 2008

I. BACKGROUND

Microsoft Excel is the spreadsheet application that is included with
Microsoft Corp's Office productivity software suite. More information
is available at the following website.

http://office.microsoft.com/excel/

II. DESCRIPTION

iDefense Security Advisory 12.10.08: Microsoft Excel Malformed Object Memoy Corruption Vulnerability

Dec 09, 2008

I. BACKGROUND

Excel is the spreadsheet application included with Microsoft Corp.'s
Office productivity software suite. More information is available at
the following website:

http://office.microsoft.com/excel/

II. DESCRIPTION

iDefense Security Advisory 06.26.09: HP Network Node Manager rping Stack Buffer Overflow Vulnerability

http://labs.idefense.com/intelligence/vulnerabilities/
Jun 26, 2009

I. BACKGROUND

HP Network Node Manager (NNM) is an application suite that is used to
map out and manage network topography. NNM runs on a variety of
platforms, including Linux and multiple versions of Windows. For more
information, see the vendor's site at the following link.

http://www.openview.hp.com/products/nnm/index.html

VUPEN Security Research - OpenOffice Word Document Processing Heap Overflow Vulnerabilities

I. BACKGROUND
---------------------

OpenOffice.org (OO.o or OOo), commonly known as OpenOffice, is an
open source software application suite available for a number of
different computer operating systems. It is distributed as free
software and written using its own GUI toolkit. It supports the
ISO/IEC standard OpenDocument Format (ODF) for data interchange
as its default file format, as well as Microsoft Office formats
among others. (Wikipedia)

[INFIGO-2008-03-07]: Surgemail 38k4 IMAP server remote stack overflow

==[ Overview

SurgeMail Mail Server Software Suite - combines advanced features, high
performance and ease of use. Works on Windows, UNIX (Linux, Solaris etc.),
Mac OSX, FreeBSD and others. Surgemail integrated email server is an
Antispam Server, Antivirus Server, Webmail Server, Groupware Server, 
Blog Server and much more. 


[ GLSA 200805-18 ] Mozilla products: Multiple vulnerabilities

Mozilla Firefox is an open-source web browser and Mozilla Thunderbird
an open-source email client, both from the Mozilla Project. The
SeaMonkey project is a community effort to deliver production-quality
releases of code derived from the application formerly known as the
'Mozilla Application Suite'. XULRunner is a Mozilla runtime package
that can be used to bootstrap XUL+XPCOM applications like Firefox and
Thunderbird.

Affected packages
=================

Secunia Research: Samba "reply_netbios_packet()" Buffer Overflow Vulnerability

Where:  Local network

====================================================================== 
3) Vendor's Description of Software 

"Samba is an Open Source/Free Software suite that has, since 1992,
provided file and print services to all manner of SMB/CIFS clients,
including the numerous versions of Microsoft Windows operating systems.
Samba is freely available under the GNU General Public License."

Product Link:



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!