Monthly Archive: July 2005
14/07/2005
by
Fred
· Published 14/07/2005
The get_parameter_from_freqency_source function in beep2 1.0, 1.1 and 1.2, when installed setuid root, allows local users to read arbitrary files via unknown attack vectors. Date published : 2005-07-14 http://www.securityfocus.com/bid/3859 http://www.kip.iis.toyama-u.ac.jp/~shingo/beep/package/src/beep2-1.2a.tar.gz
14/07/2005
by
Fred
· Published 14/07/2005
Format string vulnerability in Kaffe OpenVM 1.0.6 and earlier allows local users to execute arbitrary code, when a java.lang.NoClassDefFoundError is thrown, via format specifiers in the forName attribute. Date published : 2005-07-14 http://www.securityfocus.com/bid/4249 http://cert.uni-stuttgart.de/archive/vuln-dev/2002/03/msg00050.html
14/07/2005
by
Fred
· Published 14/07/2005
Cross-site scripting (XSS) vulnerability in WoltLab Burning Board (wbboard) 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the message parameter. Date published : 2005-07-14 http://www.securityfocus.com/bid/4512 http://archives.neohapsis.com/archives/bugtraq/2002-04/0163.html
14/07/2005
by
Fred
· Published 14/07/2005
Netgear RP114 Cable/DSL Web Safe Router Firmware 3.26 uses a default administrator password and accepts admin logins on the external interface, which allows remote attackers to gain privileges if the password is not changed....
14/07/2005
by
Fred
· Published 14/07/2005
PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote attackers to execute arbitrary PHP code via the include_file parameter. Date published : 2005-07-14 http://www.securityfocus.com/bid/5037 http://archives.neohapsis.com/archives/bugtraq/2002-06/0188.html
14/07/2005
by
Fred
· Published 14/07/2005
sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentation fault. Date published : 2005-07-14 http://www.securityfocus.com/bid/3995 http://online.securityfocus.com/archive/1/253183
14/07/2005
by
Fred
· Published 14/07/2005
sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcpd. Date published : 2005-07-14 http://www.securityfocus.com/bid/3994 http://online.securityfocus.com/archive/1/253183
14/07/2005
by
Fred
· Published 14/07/2005
User-mode Linux (UML) 2.4.17-8 does not restrict access to kernel address space, which allows local users to execute arbitrary code. Date published : 2005-07-14 http://www.securityfocus.com/bid/3973 http://archives.neohapsis.com/archives/bugtraq/2002-01/0338.html
14/07/2005
by
Fred
· Published 14/07/2005
PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and possibly execute code via the caselist parameter. Date published : 2005-07-14 http://www.securityfocus.com/bid/4381 http://archives.neohapsis.com/archives/bugtraq/2002-03/0345.html
14/07/2005
by
Fred
· Published 14/07/2005
Lotus Domino 5.0.8 web server returns different error messages when a valid or invalid user is provided in HTTP requests, which allows remote attackers to determine valid user names and makes it easier to...
14/07/2005
by
Fred
· Published 14/07/2005
Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain. Date published...
14/07/2005
by
Fred
· Published 14/07/2005
Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request. Date published : 2005-07-14 http://www.securityfocus.com/bid/3796 http://www.securityfocus.com/advisories/3761
14/07/2005
by
Fred
· Published 14/07/2005
Cross-site scripting (XSS) vulnerability in the fom CGI program (fom.cgi) in Faq-O-Matic 2.711 and 2.712 allows remote attackers to inject arbitrary web script or HTML via the file parameter. Date published : 2005-07-14 http://www.securityfocus.com/bid/4565... ;
14/07/2005
by
Fred
· Published 14/07/2005
Cross-site scripting (XSS) vulnerability in htsearch.cgi in htdig () 3.1.5, 3.1.6, and 3.2 allows remote attackers to inject arbitrary web script or HTML via the words parameter. Date published : 2005-07-14 http://www.securityfocus.com/bid/5091 http://archives.neohapsis.com/archives/bugtraq/2002-06/0321.html