New User, Welcome!     Login

Next Page >>

denial of service

Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances

=======

Cisco ASA 5500 Series Adaptive Security Appliances are affected by the
following vulnerabilities:

  * TCP Connection Exhaustion Denial of Service Vulnerability
  * Session Initiation Protocol (SIP) Inspection Denial of Service
    Vulnerabilities
  * Skinny Client Control Protocol (SCCP) Inspection Denial of
    Service Vulnerability
  * WebVPN Datagram Transport Layer Security (DTLS) Denial of Service

Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances

=======

Cisco ASA 5500 Series Adaptive Security Appliances are affected by
multiple vulnerabilities as follows:

  * Three SunRPC Inspection Denial of Service Vulnerabilities
  * Three Transport Layer Security (TLS) Denial of Service
    Vulnerabilities
  * Session Initiation Protocol (SIP) Inspection Denial of Service
    Vulnerability
  * Crafted Internet Key Exchange (IKE) Message Denial of Service

Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module

Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst
6500 Series ASA Services Module are affected by multiple
vulnerabilities as follows:

  * MSN Instant Messenger (IM) Inspection Denial of Service
    vulnerability
  * TACACS+ Authentication Bypass vulnerability
  * Four SunRPC Inspection Denial of Service vulnerabilities
  * Internet Locator Service (ILS) Inspection Denial of Service
    vulnerability

Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module

Cisco ASA 5500 Series Adaptive Security Appliances (ASA) and Cisco
Catalyst 6500 Series ASA Services Module (ASASM) are affected by the
following vulnerabilities:

  * Cisco ASA UDP Inspection Engine Denial of Service Vulnerability
  * Cisco ASA Threat Detection Denial of Service Vulnerability
  * Cisco ASA Syslog Message 305006 Denial of Service Vulnerability
  * Protocol-Independent Multicast Denial of Service Vulnerability

These vulnerabilities are independent of each other; a release that is

Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances

advisory outlines the details of these vulnerabilities:

  * VPN Authentication Bypass when Account Override Feature is Used
    vulnerability

  * Crafted HTTP packet denial of service (DoS) vulnerability

  * Crafted TCP Packet DoS vulnerability

  * Crafted H.323 packet DoS vulnerability


Cisco Security Advisory: Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine

Summary
=======

The Cisco ACE Application Control Engine Module and Cisco ACE 4710
Application Control Engine contain the following DoS vulnerabilities:

  * Real-Time Streaming Protocol (RTSP) inspection DoS vulnerability
  * HTTP, RTSP, and Session Initiation Protocol (SIP) inspection DoS
    vulnerability
  * Secure Socket Layer (SSL) DoS vulnerability

Cisco Security Advisory: Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch

  * Unauthenticated Java Servlet Access
  * Unauthenticated Arbitrary File Upload
  * Cisco Discovery Protocol Remote Code Execution
  * Unauthorized Servlet Access
  * Java RMI Denial of Service
  * Real-Time Transport Control Protocol Denial of Service
  * XML-Remote Procedure Call (RPC) Denial of Service

Duplicate Issue Identification in Other Cisco TelePresence Advisories


Re: DoS vulnerability in Google Chrome

The only thing I could do was to logout and then log back in. Task Manager
was unable to help me even though it was set to "Always On Top". If the Task
Manager was opened first then I might have had a chance but if it weren't
then 4 out of 5 times the best option would be to logout and then re-login.

I believe this is a kind of functionality bug versus denial of service bug
in FireFox which unfortunately is not related to the Chrome Bug.

This was tested at my work since I don't have Google chrome installed on my
linux installation at home. However I believe this can be used / triggered
against any other application installed that FireFox knows exists on the

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Firewall Services Module

The Cisco Firewall Services Module (FWSM) for the Cisco Catalyst 6500
Series switches and Cisco 7600 Series routers is affected by the
following vulnerabilities:

  * Syslog Message Memory Corruption Denial of Service Vulnerability
  * Authentication Proxy Denial of Service Vulnerability
  * TACACS+ Authentication Bypass Vulnerability
  * Sun Remote Procedure Call (SunRPC) Inspection Denial of Service
    Vulnerabilities
  * Internet Locator Server (ILS) Inspection Denial of Service

Re: DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers

>> contacts?
>>
>> MustLive wrote:
>>> Hello Susan!
>>>
>>>> Granted I can denial of service a browser just by loading up a horrible
>>>> add in or just using a browser
>>>
>>> DoS of the browser is already bad thing. And there are many risks for
>>> users
>>> from DoS holes in browsers, which I wrote about in 2008 in my articles

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Wireless LAN Controllers

=======

The Cisco Wireless LAN Controller (WLC) product family is affected by
the following vulnerabilities:

  * Cisco Wireless LAN Controllers HTTP Denial of Service Vulnerability
  * Cisco Wireless LAN Controllers IPv6 Denial of Service Vulnerability
  * Cisco Wireless LAN Controllers WebAuth Denial of Service Vulnerability
  * Cisco Wireless LAN Controllers Unauthorized Access Vulnerability



Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances

Cisco ASA 5500 Series Adaptive Security Appliances are affected by the
following vulnerabilities:

  * Transparent Firewall Packet Buffer Exhaustion Vulnerability
  * Skinny Client Control Protocol (SCCP) Inspection Denial of
    Service Vulnerability
  * Routing Information Protocol (RIP) Denial of Service
    Vulnerability
  * Unauthorized File System Access Vulnerability

These vulnerabilities are independent; a release that is affected by

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Wireless LAN Controllers

Multiple vulnerabilities exist in the Cisco Wireless LAN Controller
(WLC) platforms. This security advisory outlines the details of the
following vulnerabilities:

  * Malformed HTTP or HTTPS authentication response denial of service
    vulnerability
  * SSH connections denial of service vulnerability
  * Crafted HTTP or HTTPS request denial of service vulnerability
  * Crafted HTTP or HTTPS request unauthorized configuration
    modification vulnerability

Cisco Security Advisory: Cisco IOS Software Network Address Translation Vulnerabilities

Summary
=======

The Cisco IOS  Software Network Address Translation functionality
contains three denial of service (DoS) vulnerabilities. The first
vulnerability is in the translation of Session Initiation Protocol
(SIP) packets, the second vulnerability in the translation of H.323
packets and the third vulnerability is in the translation of H.225.0
call signaling for H.323 packets.


Re: DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers

> contacts?
>
> MustLive wrote:
>> Hello Susan!
>>
>>> Granted I can denial of service a browser just by loading up a horrible
>>> add in or just using a browser
>>
>> DoS of the browser is already bad thing. And there are many risks for
>> users
>> from DoS holes in browsers, which I wrote about in 2008 in my articles

[oCERT-2009-014] Android denial-of-service issues

#2009-014 Android denial-of-service issues

Description:

Android, an open source mobile phone platform, is affected by two bugs
that lead to denial-of-service (DoS) conditions.

Two separate DoS issues have been independently reported to oCERT.


Re[3]: DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers

for all readers of the list.

First of all, readers of both Bugtraq and Full-disclosure must understand,
that if you had no questions to my first advisory (from this series of
advisories (I posted three already) of vulnerabilities in browsers,
which belong to group of DoS via protocol handlers), then there must be no
questions for next advisories. Otherwise it'll be double standards (not
moaning on 1st advisory and moaning on 2nd and 3rd ones) and as I already
wrote to the lists, double standards are bad and better to not use them.

Second, I repeat one more time :-), that there can be also made attack

[SECURITY] [DSA 1503-2] New Linux kernel 2.4.27 packages fix several issues

                 CVE-2007-1592 CVE-2007-2172 CVE-2007-2525 CVE-2007-3848
                 CVE-2007-4308 CVE-2007-4311 CVE-2007-5093 CVE-2007-6063
                 CVE-2007-6151 CVE-2007-6206 CVE-2007-6694 CVE-2008-0007
                 
Several local and remote vulnerabilities have been discovered in the Linux
kernel that may lead to a denial of service or the execution of arbitrary
code. 

The package versions referenced in the initial DSA-1503 advisory
introduced a regression that can cause hangs on systems that make use of
the ext2 filesystem. The regression has been resolved in the package

[SECURITY] [DSA 1503-1] New Linux kernel 2.4.27 packages fix several issues

                 CVE-2007-1592 CVE-2007-2172 CVE-2007-2525 CVE-2007-3848
                 CVE-2007-4308 CVE-2007-4311 CVE-2007-5093 CVE-2007-6063
                 CVE-2007-6151 CVE-2007-6206 CVE-2007-6694 CVE-2008-0007
                 
Several local and remote vulnerabilities have been discovered in the Linux
kernel that may lead to a denial of service or the execution of arbitrary
code. The Common Vulnerabilities and Exposures project identifies the
following problems:

CVE-2004-2731


Cisco Security Advisory: Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Cisco Security Advisory: Cisco Unified IP Phone Overflow and Denial
                         of Service Vulnerabilities

Revision 1.0

For Public Release 2008 February 13 1600 UTC (GMT)


[ MDVSA-2010:198 ] kernel

 members, which might allow local users to obtain sensitive information
 from kernel memory via unspecified vectors. (CVE-2009-3228)
 
 The do_pages_move function in mm/migrate.c in the Linux kernel before
 2.6.33-rc7 does not validate node values, which allows local users
 to read arbitrary kernel memory locations, cause a denial of service
 (OOPS), and possibly have unspecified other impact by specifying a
 node that is not part of the kernel node set. (CVE-2010-0415)
 
 The ATI Rage 128 (aka r128) driver in the Linux kernel before
 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE)

[ MDVSA-2010:188 ] kernel

 members, which might allow local users to obtain sensitive information
 from kernel memory via unspecified vectors. (CVE-2009-3228)
 
 The do_pages_move function in mm/migrate.c in the Linux kernel before
 2.6.33-rc7 does not validate node values, which allows local users
 to read arbitrary kernel memory locations, cause a denial of service
 (OOPS), and possibly have unspecified other impact by specifying a
 node that is not part of the kernel node set. (CVE-2010-0415)
 
 The ATI Rage 128 (aka r128) driver in the Linux kernel before
 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE)

[SECURITY] [DSA 2264-1] linux-2.6 security update

http://www.debian.org/security/                              dann frazier
June 18, 2011                          http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : linux-2.6
Vulnerability  : privilege escalation/denial of service/information leak
Problem type   : local/remote
Debian-specific: no
CVE Id(s)      : CVE-2010-2524 CVE-2010-3875 CVE-2010-4075 CVE-2010-4655 
                 CVE-2011-0695 CVE-2011-0710 CVE-2011-0711 CVE-2011-0726
                 CVE-2011-1010 CVE-2011-1012 CVE-2011-1017 CVE-2011-1078 

Re: DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers

Hello Susan!

> Granted I can denial of service a browser just by loading up a horrible
> add in or just using a browser

DoS of the browser is already bad thing. And there are many risks for users
from DoS holes in browsers, which I wrote about in 2008 in my articles
Dangers of DoS attacks on browsers and Dangers of resources consumption DoS
attacks. But mostly browser developers ignore to fix these issues.


Re: DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers

to contacts?

MustLive wrote:
> Hello Susan!
>
>> Granted I can denial of service a browser just by loading up a horrible
>> add in or just using a browser
>
> DoS of the browser is already bad thing. And there are many risks for 
> users
> from DoS holes in browsers, which I wrote about in 2008 in my articles

Cisco Security Advisory: Multiple Vulnerabilities in Cisco TelePresence Recording Server

  * XML-Remote Procedure Call (RPC) Arbitrary File Overwrite

  * Cisco Discovery Protocol Remote Code Execution

  * Ad Hoc Recording Denial of Service

  * Java Remote method Invocation (RMI) Denial of Service

  * Unauthenticated XML-RPC Interface


[USN-1017-1] MySQL vulnerabilities

Details follow:

It was discovered that MySQL incorrectly handled certain requests with the
UPGRADE DATA DIRECTORY NAME command. An authenticated user could exploit
this to make MySQL crash, causing a denial of service. This issue only
affected Ubuntu 9.10 and 10.04 LTS. (CVE-2010-2008)

It was discovered that MySQL incorrectly handled joins involving a table
with a unique SET column. An authenticated user could exploit this to make
MySQL crash, causing a denial of service. This issue only affected Ubuntu

[SECURITY] [DSA 1504-1] New Linux kernel 2.6.8 packages fix several issues

                 CVE-2007-3739 CVE-2007-3740 CVE-2007-3848 CVE-2007-4133
                 CVE-2007-4308 CVE-2007-4573 CVE-2007-5093 CVE-2007-6063
                 CVE-2007-6151 CVE-2007-6206 CVE-2007-6694 CVE-2008-0007

Several local and remote vulnerabilities have been discovered in the Linux
kernel that may lead to a denial of service or the execution of arbitrary
code. The Common Vulnerabilities and Exposures project identifies the
following problems:

CVE-2006-5823


Cisco Security Advisory: Multiple Vulnerabilities in Cisco Wireless LAN Controllers

=======

The Cisco Wireless LAN Controller (WLC) product family is affected by
these vulnerabilities:

  * Two denial of service (DoS) vulnerabilities
  * Three privilege escalation vulnerabilities
  * Two access control list (ACL) bypass vulnerabilities

Note: These vulnerabilities are independent of one another. A device
may be affected by one vulnerability and not affected by another.

[ MDVSA-2011:029 ] kernel

 Problem Description:

 A vulnerability was discovered and corrected in the Linux 2.6 kernel:
 The X.25 implementation does not properly parse facilities, which
 allows remote attackers to cause a denial of service (heap memory
 corruption and panic) or possibly have
 unspecified other impact via malformed data, a different vulnerability
 than CVE-2010-4164. (CVE-2010-3873)
 
 The bcm_connect function Broadcast Manager in the Controller Area

Next Page>>

Copyright © 1995-2013 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!