New User, Welcome!     Login

Next Page >>

vulnerability management

Nortel Telephony Server Denial of Service

Communication Server 1000
and others.

See associated products on the Nortel advisory.

Vulnerability Management:
-------------------------
June 2007:    Vulnerability found
June 2007:    Nortel Security notified
October 2007: Nortel Advisory available
October 2007: Compass Security Information

Nortel IP Phone forced re-authentication

IP Softphone 2050
and others.

See associated products on the Nortel advisory.

Vulnerability Management:
-------------------------
June 2007:    Vulnerability found
June 2007:    Nortel Security notified
October 2007: Nortel Advisory & Patches available
October 2007: Compass Security Information

Nortel IP Phone Flooding Denial of Service

IP Softphone 2050
and others.

See associated products on the Nortel advisory.

Vulnerability Management:
-------------------------
June 2007:    Vulnerability found
June 2007:    Nortel Security notified
October 2007: Nortel Advisory available
October 2007: Compass Security Information

Nortel IP Phone Surveillance Mode

IP Softphone 2050
and others.

See associated products on the Nortel advisory.

Vulnerability Management:
-------------------------
June 2007:    Vulnerability found
June 2007:    Nortel Security notified
October 2007: Nortel Advisory & Patches available
October 2007: Compass Security Information

Nortel UNIStim IP Softphone Buffer-Overflow

Vulnerable:
-----------
IP Softphone 2050

Vulnerability Management:
-------------------------
June 2007:    Vulnerability found
June 2007:    Nortel Security notified
October 2007: Nortel Advisory available
October 2007: Compass Security Information

Alcatel OmniPCX Enterprise VoIP Vulnerability

Not vulnerable:
---------------
Alcatel OmniPCX Enterprise release 8.0

Vulnerability Management:
-------------------------
June 2007:     Vulnerability found
June 2007:     Alcatel Security notified
November 2007: Alcatel Advisory available
November 2007: Alcatel Security Information

[CSNC] OKI C5510MFP Printer Password Disclosure

Currenty, there is no workaround on the printer itself. A solution would
be to implement ACLs in the network infrastructure level / firewall and
block communication with ports that are not needed for printing.


Vulnerability Management:
-------------------------
09/26/2007: Vendor notified
10/04/2007: Vendor receipt
01/16/2008: According to our contact at OKI, the information will be
used for further development and there will be no patched firmware for

R7-0039: Accellion File Transfer Appliance Multiple Vulnerabilities

-- Credit:
This vulnerability was discovered by HD Moore


-- About Rapid7 Security
Rapid7 provides vulnerability management, compliance and penetration
testing solutions for Web application, network and database security. In
addition to developing the NeXpose Vulnerability Management system,
Rapid7 manages the Metasploit Project and is the primary sponsor of the
W3AF web assessment tool.


CFP: European Conference on Computer Network Defense

Privacy Protection
Security Policies
Peer-to-Peer and Grid Security
Network Monitoring
Web Security
Vulnerability Management and Tracking
Network Forensics
Wireless and Mobile Security
Cryptography
Network Discovery and Mapping
Incident Response and Management

EC2ND 2009 CFP - 5th European Conference on Computer Network Defence

      * Privacy Protection
      * Security Policy
      * Peer-to-Peer and Grid Security
      * Network Monitoring
      * Web Security
      * Vulnerability Management and Tracking
      * Network Forensics
      * Wireless and Mobile Security
      * Cryptography
      * Network Discovery and Mapping
      * Incident Response and Management

EC2ND 2009 CFP - 5th European Conference on Computer Network Defence

      * Privacy Protection
      * Security Policy
      * Peer-to-Peer and Grid Security
      * Network Monitoring
      * Web Security
      * Vulnerability Management and Tracking
      * Network Forensics
      * Wireless and Mobile Security
      * Cryptography
      * Network Discovery and Mapping
      * Incident Response and Management

R7-0038: Check Point Endpoint Security Server Information Disclosure

-- Credit:
This vulnerability was discovered by HD Moore

-- About Rapid7 Security
Rapid7 provides vulnerability management, compliance and penetration
testing solutions for Web application, network and database security. In
addition to developing the NeXpose Vulnerability Management system,
Rapid7 manages the Metasploit Project and is the primary sponsor of the
W3AF web assessment tool.


[R7-0035] VxWorks Authentication Library Weak Password Hashing

-- Credit:
This vulnerability was discovered by HD Moore

-- About Rapid7 Security
Rapid7 provides vulnerability management, compliance and penetration
testing solutions for Web application, network and database security. In
addition to developing the NeXpose Vulnerability Management system,
Rapid7 manages the Metasploit Project and is the primary sponsor of the
W3AF web assessment tool.


[R7-0034] VxWorks WDB Agent Debug Service Exposure

instances, first by Bennett Todd in 2002 and then Shawn Merdinger in
2005. A comprehensive analysis of all affected devices was conducted by
HD Moore in 2010.

-- About Rapid7 Security
Rapid7 provides vulnerability management, compliance and penetration
testing solutions for Web application, network and database security. In
addition to developing the NeXpose Vulnerability Management system,
Rapid7 manages the Metasploit Project and is the primary sponsor of the
W3AF web assessment tool.


R7-0037: SAP BusinessObjects Axis2 Default Admin Password

This vulnerability was reported by Joshua Abraham and Will Vandevanter.

About Rapid7 Security:

Rapid7 provides vulnerability management, compliance and penetration
testing solutions for Web application, network and database security. In
addition to developing the NeXpose Vulnerability Management system,
Rapid7 manages the Metasploit Project and is the primary sponsor of the
W3AF web assessment tool.


R7-0036: FCKEditor.NET File Upload Code Execution

-- Credit:
This vulnerability was discovered by Will Vandevanter of the Rapid7 professional services team during a customer engagement.

-- About Rapid7 Security
Rapid7 provides vulnerability management, compliance and penetration testing solutions for Web application, network and database security. In addition to developing the NeXpose Vulnerability Management system, Rapid7 manages the Metasploit Project and is the primary sponsor of the
W3AF web assessment tool. 

Our vulnerability disclosure policy is available online at:

http://www.rapid7.com/disclosure.jsp

Secunia Research: Autonomy KeyView wosr.dll Data Block Parsing Buffer Overflow

CVE-2010-0135 for the vulnerability.
 
====================================================================== 
9) About Secunia
 
Secunia offers vulnerability management solutions to corporate
customers with verified and reliable vulnerability intelligence
relevant to their specific system configuration:
 
http://secunia.com/advisories/business_solutions/
 

Secunia Research: Autonomy KeyView rtfsr.dll RTF Parsing Signedness Error

CVE-2010-0134 for the vulnerability.

====================================================================== 
9) About Secunia

Secunia offers vulnerability management solutions to corporate
customers with verified and reliable vulnerability intelligence
relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/


Secunia Research: SonicWALL SSL-VPN End-Point ActiveX Control Buffer Overflow

CVE-2010-2583 for the vulnerability.

====================================================================== 
9) About Secunia

Secunia offers vulnerability management solutions to corporate
customers with verified and reliable vulnerability intelligence
relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/


Secunia Research: Autonomy KeyView wkssr.dll Floating Point Conversion Buffer Overflow

CVE-2010-0131 for the vulnerability.

====================================================================== 
9) About Secunia

Secunia offers vulnerability management solutions to corporate
customers with verified and reliable vulnerability intelligence
relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/


Secunia Research: Autonomy KeyView Compound File Parsing Buffer Overflow

CVE-2010-0126 for the vulnerability.

====================================================================== 
9) About Secunia

Secunia offers vulnerability management solutions to corporate
customers with verified and reliable vulnerability intelligence
relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/


Secunia Research: GIGABYTE Dldrv2 ActiveX Control Unsafe Methods

CVE-2010-1517 for the vulnerabilities.

====================================================================== 
9) About Secunia

Secunia offers vulnerability management solutions to corporate
customers with verified and reliable vulnerability intelligence
relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/


Secunia Research: GIGABYTE Dldrv2 ActiveX Control Array Indexing Vulnerability

CVE-2010-1518 for the vulnerability.

====================================================================== 
9) About Secunia

Secunia offers vulnerability management solutions to corporate
customers with verified and reliable vulnerability intelligence
relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/


Secunia Research: McAfee E-Business Server Auth Packet Handling Buffer Overflow

CVE-2007-2957 for the vulnerability.

======================================================================
9) About Secunia

Secunia offers vulnerability management solutions to corporate
customers with verified and reliable vulnerability intelligence
relevant to their specific system configuration:

http://corporate.secunia.com/


Secunia Research: Autonomy Keyview Ichitaro Text Parsing Buffer Overflow

CVE-2011-0338 for the vulnerability.

====================================================================== 
9) About Secunia

Secunia offers vulnerability management solutions to corporate
customers with verified and reliable vulnerability intelligence
relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/


Secunia Research: CUPS IPP Tags Memory Corruption Vulnerability

CVE-2007-4351 for the vulnerability.

====================================================================== 
9) About Secunia

Secunia offers vulnerability management solutions to corporate
customers with verified and reliable vulnerability intelligence
relevant to their specific system configuration:

http://corporate.secunia.com/


Secunia Research: IPSwitch IMail Server IMail Client Buffer Overflow

CVE-2007-4345 for the vulnerability.

====================================================================== 
9) About Secunia

Secunia offers vulnerability management solutions to corporate
customers with verified and reliable vulnerability intelligence
relevant to their specific system configuration:

http://corporate.secunia.com/


Secunia Research: IBM Tivoli Storage Manager Client CAD Service Script Insertion

CVE-2007-4348 for the vulnerability.

====================================================================== 
8) About Secunia

Secunia offers vulnerability management solutions to corporate
customers with verified and reliable vulnerability intelligence
relevant to their specific system configuration:

http://corporate.secunia.com/


Secunia Research: IrfanView Palette File Importing Buffer Overflow Vulnerability

CVE-2007-4343 for the vulnerability.

====================================================================== 
9) About Secunia

Secunia offers vulnerability management solutions to corporate
customers with verified and reliable vulnerability intelligence
relevant to their specific system configuration:

http://corporate.secunia.com/


Secunia Research: Symantec Backup Exec Job Engine Denial of Service

(integer overflows) for the vulnerabilities.

====================================================================== 
9) About Secunia

Secunia offers vulnerability management solutions to corporate
customers with verified and reliable vulnerability intelligence
relevant to their specific system configuration:

http://corporate.secunia.com/


Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!