ignorance isn't always an option
Showing 1 - 25 of 67,866 RSS Feed

Files

Mandriva Linux Security Advisory 2012-013
Posted Feb 4, 2012
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2012-013 - Security issues were identified and fixed in mozilla firefox and thunderbird. Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vectors related to incorrect AttributeChildRemoved notifications that affect access to removed nsDOMAttribute child nodes. Mozilla Firefox before 3.6.26 and 4.x through 6.0, Thunderbird before 3.1.18 and 5.0 through 6.0, and SeaMonkey before 2.4 do not properly enforce the IPv6 literal address syntax, which allows remote attackers to obtain sensitive information by making XMLHttpRequest calls through a proxy and reading the error messages. Various other issues were also addressed.

tags | advisory, remote, arbitrary
systems | linux, mandriva
advisories | CVE-2011-3659, CVE-2011-3670, CVE-2012-0442, CVE-2012-0443, CVE-2012-0444, CVE-2012-0445, CVE-2012-0446, CVE-2012-0447, CVE-2012-0449, CVE-2012-0450
MD5 | 8440ddc6266c7f42154730c51559597b
Ubuntu Security Notice USN-1355-1
Posted Feb 4, 2012
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 1355-1 - It was discovered that if a user chose to export their Firefox Sync key the "Firefox Recovery Key.html" file is saved with incorrect permissions, making the file contents potentially readable by other users. Nicolas Gregoire and Aki Helin discovered that when processing a malformed embedded XSLT stylesheet, Firefox can crash due to memory corruption. If the user were tricked into opening a specially crafted page, an attacker could exploit this to cause a denial of service via application crash, or potentially execute code with the privileges of the user invoking Firefox. Various other issues were also addressed.

tags | advisory, denial of service
systems | linux, ubuntu
advisories | CVE-2012-0450, CVE-2012-0449, CVE-2012-0444, CVE-2012-0447, CVE-2012-0446, CVE-2011-3659, CVE-2012-0445, CVE-2012-0443, CVE-2011-3659, CVE-2012-0442, CVE-2012-0443, CVE-2012-0444, CVE-2012-0445, CVE-2012-0446, CVE-2012-0447, CVE-2012-0449, CVE-2012-0450
MD5 | 21014e7685b2de0234ac75fd2b4a5509
Ubuntu Security Notice USN-1355-2
Posted Feb 4, 2012
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 1355-2 - USN-1355-1 fixed vulnerabilities in Firefox. This update provides an updated Mozvoikko package for use with the latest Firefox. It was discovered that if a user chose to export their Firefox Sync key the "Firefox Recovery Key.html" file is saved with incorrect permissions, making the file contents potentially readable by other users. Nicolas Gregoire and Aki Helin discovered that when processing a malformed embedded XSLT stylesheet, Firefox can crash due to memory corruption. If the user were tricked into opening a specially crafted page, an attacker could exploit this to cause a denial of service via application crash, or potentially execute code with the privileges of the user invoking Firefox. Various other issues were also addressed.

tags | advisory, denial of service, vulnerability
systems | linux, ubuntu
advisories | CVE-2012-0450, CVE-2012-0449, CVE-2012-0444, CVE-2012-0447, CVE-2012-0446, CVE-2011-3659, CVE-2012-0445, CVE-2012-0443
MD5 | 8791de077f5bd63d5d9c170bf7739905
Ubuntu Security Notice USN-1355-3
Posted Feb 4, 2012
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 1355-3 - USN-1355-1 fixed vulnerabilities in Firefox. This update provides updated ubufox and webfav packages for use with the latest Firefox. It was discovered that if a user chose to export their Firefox Sync key the "Firefox Recovery Key.html" file is saved with incorrect permissions, making the file contents potentially readable by other users. Nicolas Gregoire and Aki Helin discovered that when processing a malformed embedded XSLT stylesheet, Firefox can crash due to memory corruption. If the user were tricked into opening a specially crafted page, an attacker could exploit this to cause a denial of service via application crash, or potentially execute code with the privileges of the user invoking Firefox. Various other issues were also addressed.

tags | advisory, denial of service, vulnerability
systems | linux, ubuntu
advisories | CVE-2012-0450, CVE-2012-0449, CVE-2012-0444, CVE-2012-0447, CVE-2012-0446, CVE-2011-3659, CVE-2012-0445, CVE-2012-0443
MD5 | 89b0a01e7c3a96dcdd52016aac1b682d
Conduit Wibiya Login Toolbar Cross Site Scripting
Posted Feb 4, 2012
Authored by r007k17-w

Conduit Wibiya Login Toolbar suffers from a cross site scripting vulnerability.

tags | exploit, xss
MD5 | 829118b7d499d7679e3e051f6a58a91b
Conduit Wibiya Password Recovery Toolbar Cross Site Scripting
Posted Feb 4, 2012
Authored by r007k17-w

Conduit Wibiya Password Recovery Toolbar suffers from a cross site scripting vulnerability.

tags | exploit, xss
MD5 | 08fb2a09c22520dcd558560108ec7578
Conduit Image Search Engine Cross Site Scripting
Posted Feb 4, 2012
Authored by r007k17-w

Conduit Image Search Engine suffers from a cross site scripting vulnerability.

tags | exploit, xss
MD5 | 771f2feeb18384483f1f7bed70e69293
EMC Documentum xPlore Information Disclosure
Posted Feb 4, 2012
Site emc.com

EMC Documentum xPlore contains an information disclosure vulnerability that may allow unauthorized users, under certain circumstances, to see certain information on protected objects in an xPlore search result. They will not, however, be allowed to view the objects themselves, or any associated content. Versions 1.0, 1.1 and 1.2 are affected.

tags | advisory, info disclosure
advisories | CVE-2012-0396
MD5 | 47766ee4538f434cc83fdd7864e8341f
Simkom Cross Site Scripting
Posted Feb 4, 2012
Authored by Am!r | Site irist.ir

Simkom suffers from a cross site scripting vulnerability.

tags | exploit, xss
MD5 | 47a7d97ba8b92d125ba12845dbd500b4
Douglass Media SQL Injection
Posted Feb 4, 2012
Authored by Am!r | Site irist.ir

Douglass Media suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 43ce577af5ef8e3acfeaffcf663025b6
Anfibia Remote Command Execution
Posted Feb 4, 2012
Authored by BHG Security Center

Anfibia suffers from a remote command execution vulnerability.

tags | exploit, remote
MD5 | 8ee734f210e0fc429ebfe6f8e39e2a73
Raw CMS Cross Site Scripting
Posted Feb 4, 2012
Authored by Am!r | Site irist.ir

Raw CMS suffers from a cross site scripting vulnerability.

tags | exploit, xss
MD5 | f6950e8a6b392a2a6748831b7a518a66
PHP-Fusion 7.02.04 SQL Injection
Posted Feb 3, 2012
Authored by Am!r | Site irist.ir

PHP-Fusion version 7.02.04 suffers from a remote SQL injection vulnerability in weblinks.php.

tags | exploit, remote, php, sql injection
MD5 | c7b7077619c230bbd6d7ca48f9c40db8
Port Tester 0.1
Posted Feb 3, 2012
Authored by localh0t

This is a simple little port scanning script written in python.

tags | tool, scanner, python
systems | unix
MD5 | b8fc2783fbb4849e4ceac338b595bcb3
RFC6528 - Defending Against Sequence Number Attacks
Posted Feb 3, 2012
Authored by Fernando Gont

This document specifies an algorithm for the generation of TCP Initial Sequence Numbers (ISNs), such that the chances of an off-path attacker guessing the sequence numbers in use by a target connection are reduced. This document revises (and formally obsoletes) RFC 1948, and takes the ISN generation algorithm originally proposed in that document to Standards Track, formally updating RFC 793.

tags | paper, tcp
MD5 | 4bd9d141dba29f999534d68fbcf120f5
Torrent-Stats Denial Of Service
Posted Feb 3, 2012
Authored by otr

Torrent-Stats suffers from a denial of service vulnerability in httpd.c.

tags | exploit, denial of service
MD5 | 93cb8010ef7a0d4b878fb544b07e1f0f
PHP 5.4 Buffer Overflow
Posted Feb 3, 2012
Authored by cataphract

PHP 5.4SVN-2012-02-03 htmlspecialchars/entities buffer overflow proof of concept exploit.

tags | exploit, overflow, php, proof of concept
MD5 | 0ec258ee89e3cba85e56bae3a3aa7458
BSides Detroit 12 Call For Papers
Posted Feb 3, 2012
Site bit.ly

BSides Detroit 12 has announced its Call For Presenters. It will take place June 1st through the 2nd in Detroit, Michigan.

tags | paper, conference
MD5 | 29b6fbd2de729bd2ac17fede3c0a54d2
HP Security Bulletin HPSBGN02740 SSRT100741
Posted Feb 3, 2012
Authored by HP | Site hp.com

HP Security Bulletin HPSBGN02740 SSRT100741 - A potential security vulnerability has been identified with HP Operations Manager, Operations Agent, Performance Agent, Service Health Reporter, Service Health Optimizer, and Performance Manager. The vulnerability can be remotely exploited to execute arbitrary code. Revision 1 of this advisory.

tags | advisory, arbitrary
advisories | CVE-2010-3864
MD5 | 1ee59b68380765139a6c58c7999ac86a
NASA Subdomains Shell Upload / SQL Injection
Posted Feb 3, 2012
Authored by K0242 | Site vulnerability-lab.com

Various NASA subdomains suffer from shell upload and remote SQL injection vulnerabilities.

tags | exploit, remote, shell, vulnerability, sql injection
MD5 | 7502584f2b686b00d2b9d51841b62a1a
Debian Security Advisory 2403-1
Posted Feb 3, 2012
Authored by Debian | Site debian.org

Debian Linux Security Advisory 2403-1 - Stefan Esser discovered that the implementation of the max_input_vars configuration variable in a recent PHP security update was flawed such that it allows remote attackers to crash PHP or potentially execute code.

tags | advisory, remote, php
systems | linux, debian
advisories | CVE-2012-0830
MD5 | c4d8e3fd768c60e10ba1bfdc3db5bf69
Dradis Information Sharing Tool 2.9.0
Posted Feb 3, 2012
Authored by etd | Site dradis.nomejortu.com

dradis is a tool for sharing information during security testing. While plenty of tools exist to help in the different stages of the test, not so many exist to share interesting information captured. When a team of testers is working on the same set of targets, having a common repository of information is essential to avoid duplication of efforts.

Changes: This release added a Retina Network Security Scanner upload plugin and a Zed Attack Proxy upload plugin. The Nessus, Nikto, and Nmap upload plugins are now orders of magnitude faster. A VulnDB import plugin was added to support VulnDB HQ integration. The First Time User's Wizard was updated. Rails was upgraded to version 3.2.
tags | tool, web
systems | unix
MD5 | e8fe9b4cd524c1549a109ff5e66d828a
NetSarang Xlpd Printer Daemon 4 Denial Of Service
Posted Feb 3, 2012
Authored by Prabhu S Angadi | Site secpod.com

The NetSarang Xlpd printer daemon version 4 suffers from a remote denial of service vulnerability. Proof of concept exploit included.

tags | exploit, remote, denial of service, proof of concept
systems | linux
MD5 | 1f73370101126577cb2918b7b219cb82
Achievo 1.4.3 Cross Site Scripting / SQL Injection
Posted Feb 3, 2012
Authored by Chokri B.A | Site vulnerability-lab.com

Achievo version 1.4.3 suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
MD5 | d67bdb28b04d0c4b2ddc8702d445635a
Foswiki Cross Site Scripting
Posted Feb 3, 2012
Authored by Sony

Foswiki suffers from a cross site scripting vulnerability.

tags | exploit, xss
MD5 | 0017fdc6742e13d301b74a7867e5d187
Page 1 of 2,715
Back12345Next

File Archive:

February 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Feb 1st
    36 Files
  • 2
    Feb 2nd
    46 Files
  • 3
    Feb 3rd
    45 Files
  • 4
    Feb 4th
    12 Files
  • 5
    Feb 5th
    0 Files
  • 6
    Feb 6th
    0 Files
  • 7
    Feb 7th
    0 Files
  • 8
    Feb 8th
    0 Files
  • 9
    Feb 9th
    0 Files
  • 10
    Feb 10th
    0 Files
  • 11
    Feb 11th
    0 Files
  • 12
    Feb 12th
    0 Files
  • 13
    Feb 13th
    0 Files
  • 14
    Feb 14th
    0 Files
  • 15
    Feb 15th
    0 Files
  • 16
    Feb 16th
    0 Files
  • 17
    Feb 17th
    0 Files
  • 18
    Feb 18th
    0 Files
  • 19
    Feb 19th
    0 Files
  • 20
    Feb 20th
    0 Files
  • 21
    Feb 21st
    0 Files
  • 22
    Feb 22nd
    0 Files
  • 23
    Feb 23rd
    0 Files
  • 24
    Feb 24th
    0 Files
  • 25
    Feb 25th
    0 Files
  • 26
    Feb 26th
    0 Files
  • 27
    Feb 27th
    0 Files
  • 28
    Feb 28th
    0 Files
  • 29
    Feb 29th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2011 Packet Storm. All rights reserved.

close