12/15/2008

Secunia weekly vulnerability listing

Windows:
[SA33089] Internet Explorer Data Binding Memory Corruption
Vulnerability
[SA33035] Microsoft Internet Explorer Multiple Vulnerabilities
[SA33020] Microsoft Windows GDI Image Parsing Vulnerabilities
[SA33080] CF Shopkart SQL Injection and Database Disclosure
[SA33074] CF_Calendar "calid" SQL Injection Vulnerability
[SA33070] CFMBlog "categorynbr" SQL Injection Vulnerability
[SA33067] PostEcards "cid" SQL Injection and Database Disclosure
[SA33064] CF_Forum "categorynbr" SQL Injection Vulnerability
[SA33063] Microsoft Office SharePoint Server Security Bypass
Vulnerability
[SA33053] Microsoft Windows Explorer Search Handling Vulnerabilities
[SA33044] Poll Pro "Password" SQL Injection Vulnerability
[SA33030] Professional Download Assistant SQL Injections and Database
Disclosure
[SA33029] Ikon AdManager "ikonBAnner_AdManager.mdb" Database
Disclosure
[SA33018] Educate Server "db.mdb" Database Disclosure Security Issue
[SA33012] RankEm "txtusername" and "txtpassword" SQL Injection
Vulnerabilities
[SA33011] NightFall Personal Diary Database Disclosure and Cross-Site
Scripting
[SA33009] Teamworx Server SQL Injection and Database Disclosure
[SA33008] QMail Mailing List Manager Database Disclosure
[SA33004] ASP Auto Dealer "ID" SQL Injection Vulnerability
[SA33060] 3CX Phone System "fName" and "fPassword" Cross-Site
Scripting
[SA33034] Microsoft SQL Server 2000 "sp_replwritetovarbin()" Buffer
Overflow
[SA33017] Orb Networks Orb HTTP Processing Denial of Service

UNIX/Linux:
[SA33058] Microsoft Windows Media Products Two Vulnerabilities
[SA33056] Fedora update for java-1.6.0-openjdk
[SA33054] Fedora update for squirrelmail
[SA33040] TWiki Cross-Site Scripting and Command Injection
Vulnerabilities
[SA33015] Red Hat update for java-1.5.0-sun / java-1.6.0-sun
[SA33120]  Sun Java System Portal Server File Disclosure Vulnerability
[SA33108] Sun Ray Server Software Two Vulnerabilities
[SA33104] HP-UX DCE Unspecified Denial of Service Vulnerability
[SA33094] SUSE update for pdns
[SA33093] SUSE update for squirrelmail
[SA33091] SUSE update for gnutls
[SA33087] SUSE Update for Multiple Packages
[SA33082] Ubuntu update for vinagre
[SA33071] Debian update for squirrelmail
[SA33066] Debian update for lcms
[SA33061] Debian update for streamripper
[SA33052] Red Hat update for tomcat
[SA33050] Sun Solaris OpenSSL PKCS#11 Denial of Service Vulnerability
[SA33046] Fedora update for vinagre
[SA33041] Vinagre "vinagre_utils_show_error()" Format String
Vulnerability
[SA33016] Debian update for clamav
[SA33013] Red Hat update for ruby
[SA33010] SUSE update for kernel
[SA33111] Gentoo update for cups
[SA33085] Avaya Messaging Storage Server CUPS Multiple Vulnerabilities
[SA33116] Gentoo update for Archive-Tar
[SA33115] Gentoo update for opensc
[SA33121] Sun Solaris SSH CBC Mode Plaintext Recovery Vulnerability
[SA33095] Avaya Products Net-snmp GETBULK Denial of Service
[SA33092] SUSE update for samba
[SA33006] Ubuntu update for nfs-utils
[SA33119] Sun Ray Windows Connector Information Disclosure
Vulnerability
[SA33055] Fedora update for dbus
[SA33051] Gentoo update for mgetty
[SA33047] D-Bus Default Configuration Security Bypass
[SA33005] Avaya Products ed "strip_escapes()" Buffer Overflow Security
Issue
[SA33083] rPath update for kernel
[SA33081] Ubuntu update for compiz-fusion-plugins-main
[SA33078] Linux Kernel MIPS Syscall Denial of Service
[SA33077] Compiz Fusion Expo Plugin Security Bypass

Other:
[SA33032] Linksys WVC54GC Information Disclosure and ActiveX Control
Buffer Overflow
[SA33057] Aruba Mobility Controller EAP Frame Denial of Service
[SA33028] HP DECnet-Plus for OpenVMS Security Bypass

Cross Platform:
[SA33043] DesignWorks Professional ".cct" Buffer Overflow
Vulnerability
[SA33007] Tizag Countdown Creator File Upload Vulnerability
[SA33112] Drupal Cross-Site Request Forgery and Script Insertion
[SA33106] Max's Guestbook "name" and "email" Script Insertion
[SA33097] eZ Publish Insufficient User ID Validation Vulnerability
[SA33096] Webmaster Marketplace "u" SQL Injection Vulnerability
[SA33088] Pro Chat Rooms Cross-Site Scripting and Script Insertion
[SA33086] Butterfly Organizer "id" and "mytable" SQL Injection
Vulnerabilities
[SA33084] Atlassian JIRA Dynamic URL Transformation Vulnerability
[SA33073] Peel "rubid" SQL Injection vulnerability
[SA33065] PHP Multiple Newsletters File Inclusion and Cross-Site
Scripting
[SA33048] XOOPS Script Insertion and Local File Inclusion
[SA33039] IPN Pro 3 "settings.php" Security Bypass Vulnerability
[SA33038] DL PayCart "settings.php" Security Bypass Vulnerability
[SA33037] Bonza Cart "ad_settings.php" Security Bypass Vulnerability
[SA33033] w3blabor CMS Multiple Vulnerabilities
[SA33031] phpBB Tag Board Module "id" SQL Injection Vulnerability
[SA33027] phpAddEdit "editform" Local File Inclusion Vulnerability
[SA33024] BPowerHouse Multiple Products "page" and "admin" Local File
Inclusion
[SA33021] Tribiq CMS "cID" SQL Injection Vulnerability
[SA33019] Multiple Membership Script "id" SQL Injection Vulnerability
[SA33014] phpPgAdmin "_language" Local File Inclusion  Vulnerability
[SA33049] BMC PATROL Version Logging Format String Vulnerability
[SA33079] Moodle Unspecified Cross-Site Scripting Vulnerability
[SA33076] phpMyAdmin Cross-Site Request Forgery Vulnerability
[SA33069] PhPepperShop Webshop Multiple Cross-Site Scripting
Vulnerabilities
[SA33023] ImpressCMS "rank_title" Script Insertion Vulnerability
[SA33022] IBM WebSphere Application Server Multiple Vulnerabilities
[SA33062] Google Gears Cross-Site Scripting Weakness
[SA33059] PunBB Cross-Site Scripting and SQL Injection Vulnerabilities
[SA33025] Tor Two Weaknesses

http://www.secunia.com

11:55 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Post a comment