what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 46 of 46 RSS Feed

Files Date: 2014-09-02 to 2014-09-03

Mandriva Linux Security Advisory 2014-168
Posted Sep 2, 2014
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2014-168 - An integer overflow in liblzo before 2.07 allows attackers to cause a denial of service or possibly code execution in applications using performing LZO decompression on a compressed payload from the attacker. The libvncserver library is built with a bundled copy of minilzo, which is a part of liblzo containing the vulnerable code. The x11vnc packages is now build against the system libvncserver library to avoid security issues in the bundled copy. The icecream packages is built with a bundled copy of minilzo, which is a part of liblzo containing the vulnerable code.

tags | advisory, denial of service, overflow, code execution
systems | linux, mandriva
advisories | CVE-2014-4607
SHA-256 | 250c81914e24825853b855493501760094ef441b094b49344065f2078e67daa7
Mandriva Linux Security Advisory 2014-167
Posted Sep 2, 2014
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2014-167 - A flaw was found in the way file uses cdf_read_property_info function when checks stream offsets for certain Composite Document Format. An insufficient input validation flaw for p and q minimal and maximal value, leads to a pointer overflow. This issue only affects 32bit systems.

tags | advisory, overflow
systems | linux, mandriva
advisories | CVE-2014-3587
SHA-256 | f8d7e43872aa510920846f8b14c0035f5df720810cc8b007b765fc3a7cbe43fa
Mandriva Linux Security Advisory 2014-166
Posted Sep 2, 2014
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2014-166 - Ben Reser discovered that serf did not correctly handle SSL certificates with NUL bytes in the CommonName or SubjectAltNames fields. A remote attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications.

tags | advisory, remote
systems | linux, mandriva
advisories | CVE-2014-3504
SHA-256 | 12079b09a2f77f4dd2d0d59a4ecbb786e81a328e62175d579ca8fa9038067cf5
Mandriva Linux Security Advisory 2014-165
Posted Sep 2, 2014
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2014-165 - MIT Kerberos 5 allows attackers to cause a denial of service via a buffer over-read or NULL pointer dereference, by injecting invalid tokens into a GSSAPI application session. MIT Kerberos 5 allows attackers to cause a denial of service via a double-free flaw or NULL pointer dereference, while processing invalid SPNEGO tokens. In MIT Kerberos 5, when kadmind is configured to use LDAP for the KDC database, an authenticated remote attacker can cause it to perform an out-of-bounds write.

tags | advisory, remote, denial of service
systems | linux, mandriva
advisories | CVE-2014-4341, CVE-2014-4342, CVE-2014-4344, CVE-2014-4345
SHA-256 | 1e9f84d92cfa944b8c243cde11eefeb215c7381ed94e3f32f26202deebb50962
Mandriva Linux Security Advisory 2014-163
Posted Sep 2, 2014
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2014-163 - The Python Imaging Library is vulnerable to a denial of service attack in the IcnsImagePlugin.

tags | advisory, denial of service, python
systems | linux, mandriva
advisories | CVE-2014-3589
SHA-256 | afb710df14fbec67d1be0b96fe1ae2ec0268ada2547f05c4920452d191433231
Mandriva Linux Security Advisory 2014-164
Posted Sep 2, 2014
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2014-164 - In phpMyAdmin before 4.1.14.3, multiple XSS vulnerabilities exist in browse table, ENUM editor, monitor, query charts and table relations pages. In phpMyAdmin before 4.1.14.3, with a crafted view name it is possible to trigger an XSS when dropping the view in view operation page.

tags | advisory, vulnerability
systems | linux, mandriva
advisories | CVE-2014-5273, CVE-2014-5274
SHA-256 | 9bdc629351863588a9db6815ce09ad1539beadcff17de2e871f58b3c7758f7ec
Mandriva Linux Security Advisory 2014-162
Posted Sep 2, 2014
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2014-162 - Untrusted search path vulnerability in Catfish allows local users to gain privileges via a Trojan horse catfish.py in the current working directory.

tags | advisory, local, trojan
systems | linux, mandriva
advisories | CVE-2014-2093
SHA-256 | b0c314e22c41ff39beee0ffc571c39b44eeff2914e97fe3ab3a560cfb144c1f7
Mandriva Linux Security Advisory 2014-161
Posted Sep 2, 2014
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2014-161 - Bert Huijben discovered that Subversion did not properly handle cached credentials. A malicious server could possibly use this issue to obtain credentials cached for a different server.

tags | advisory
systems | linux, mandriva
advisories | CVE-2014-3528
SHA-256 | 132b3487657859c7a1528569ea114ef3171a3930187f1688038ba92c8cf36fe0
Mandriva Linux Security Advisory 2014-160
Posted Sep 2, 2014
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2014-160 - A heap-based buffer overflow in gpgme before 1.5.1 could allow a specially crafted certificate to cause crashes or potentially cause arbitrary code execution.

tags | advisory, overflow, arbitrary, code execution
systems | linux, mandriva
advisories | CVE-2014-3564
SHA-256 | 3a2632bb92e57a77a1c220ac77855a0de178391c091931127952d4759be91148
Debian Security Advisory 3015-1
Posted Sep 2, 2014
Authored by Debian | Site debian.org

Debian Linux Security Advisory 3015-1 - A heap-based overflow vulnerability was found in the way Lua, a simple, extensible, embeddable programming language, handles varargs functions with many fixed parameters called with few arguments, leading to application crashes or, potentially, arbitrary code execution.

tags | advisory, overflow, arbitrary, code execution
systems | linux, debian
advisories | CVE-2014-5461
SHA-256 | 08d936ff79542fbe391fe2ed9161089263714f74f69a38383de657f660aeebf2
Debian Security Advisory 3016-1
Posted Sep 2, 2014
Authored by Debian | Site debian.org

Debian Linux Security Advisory 3016-1 - A heap-based overflow vulnerability was found in the way Lua, a simple, extensible, embeddable programming language, handles varargs functions with many fixed parameters called with few arguments, leading to application crashes or, potentially, arbitrary code execution.

tags | advisory, overflow, arbitrary, code execution
systems | linux, debian
advisories | CVE-2014-5461
SHA-256 | b7cb2a0b0cf0c1c23b6934bdb7db254c50a5071d9ac48f83383b5b00a704724c
Apple iOS 7.1.2 Merge Apps Service Local Bypass
Posted Sep 2, 2014
Authored by Benjamin Kunz Mejri, Vulnerability Laboratory | Site vulnerability-lab.com

Apple iOS version 7.1.2 suffered from a merge apps service local bypass vulnerability.

tags | exploit, bypass
systems | apple
SHA-256 | bde56b5339d282ecce81034f7886104e9c86ea3b318f49048406a4c281fd013a
JQuery 1.4.2 Cross Site Scripting
Posted Sep 2, 2014
Authored by Mauro Risonho de Paula Assumpcao

JQuery version 1.4.2 suffers from a create object option in runtime client-side cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 17ead7ca89da6c91771cbedd876a663573f5710a9c57d5cbdc92e3677c5d84fe
Gentoo Linux Security Advisory 201408-18
Posted Sep 2, 2014
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201408-18 - Multiple vulnerabilities have been found in NRPE, the worst of which can allow execution of arbitrary code. Versions less than 2.15 are affected.

tags | advisory, arbitrary, vulnerability
systems | linux, gentoo
advisories | CVE-2013-1362, CVE-2014-2913
SHA-256 | 8feca3ff4326a9ccd5256ab771b701482e417dac6ed79c6214bd0541bdfa1b2e
Gentoo Linux Security Advisory 201409-02
Posted Sep 2, 2014
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201409-2 - Multiple vulnerabilities have been found in Net-SNMP which could allow remote attackers to cause Denial of Service. Versions less than 5.7.3_pre3 are affected.

tags | advisory, remote, denial of service, vulnerability
systems | linux, gentoo
advisories | CVE-2012-2141, CVE-2012-6151, CVE-2014-2284, CVE-2014-2285
SHA-256 | 08005ad35e18864fc49dc7b6919608e14ad35acf3207c18c8ffbaed33c442753
Gentoo Linux Security Advisory 201408-17
Posted Sep 2, 2014
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201408-17 - Multiple vulnerabilities have been found in QEMU, worst of which allows local attackers to execute arbitrary code. Versions less than 2.0.0-r1 are affected.

tags | advisory, arbitrary, local, vulnerability
systems | linux, gentoo
advisories | CVE-2013-4544, CVE-2014-0142, CVE-2014-0143, CVE-2014-0144, CVE-2014-0145, CVE-2014-0146, CVE-2014-0147, CVE-2014-0150, CVE-2014-0222, CVE-2014-0223, CVE-2014-2894, CVE-2014-3461
SHA-256 | 9d6ef3512527b948060fb59c7854bf14c239e1401b4d23ee32f8ef1c70a86be4
Gentoo Linux Security Advisory 201409-01
Posted Sep 2, 2014
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201409-1 - Multiple vulnerabilities have been found in Wireshark which could allow remote attackers to cause Denial of Service. Versions less than 1.10.9 are affected.

tags | advisory, remote, denial of service, vulnerability
systems | linux, gentoo
advisories | CVE-2014-5161, CVE-2014-5162, CVE-2014-5163, CVE-2014-5164, CVE-2014-5165
SHA-256 | 5807eebc0a5e06aa104ea296cd91654bd6977fcb7878d0a434584e3bd3da8d17
Debian Security Advisory 2987-2
Posted Sep 2, 2014
Authored by Debian | Site debian.org

Debian Linux Security Advisory 2987-2 - The previous security update for OpenJDK 7, DSA-2987-1, introduced a regression due to an overly strict bytecode verifier. As a result, legitimate bytecode which is produced by some non-Java languages would no longer run.

tags | advisory, java
systems | linux, debian
SHA-256 | c71d680eb23fcd049e23197483d5df7a15cf39f7cb9e47aff2165daccfd850f2
Gentoo Linux Security Advisory 201408-16
Posted Sep 2, 2014
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201408-16 - Multiple vulnerabilities have been found in Chromium, the worst of which can allow remote attackers to execute arbitrary code. Versions less than 37.0.2062.94 are affected.

tags | advisory, remote, arbitrary, vulnerability
systems | linux, gentoo
advisories | CVE-2014-0538, CVE-2014-1700, CVE-2014-1701, CVE-2014-1702, CVE-2014-1703, CVE-2014-1704, CVE-2014-1705, CVE-2014-1713, CVE-2014-1714, CVE-2014-1715, CVE-2014-1716, CVE-2014-1717, CVE-2014-1718, CVE-2014-1719, CVE-2014-1720, CVE-2014-1721, CVE-2014-1722, CVE-2014-1723, CVE-2014-1724, CVE-2014-1725, CVE-2014-1726, CVE-2014-1727, CVE-2014-1728, CVE-2014-1729, CVE-2014-1730, CVE-2014-1731, CVE-2014-1732, CVE-2014-1733
SHA-256 | f982e5d93f95183c0a72615e79486d596bdaa8fc191f532f95a4c5751a9c6d6d
Gentoo Linux Security Advisory 201408-19
Posted Sep 2, 2014
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201408-19 - Multiple vulnerabilities have been found in OpenOffice and LibreOffice, the worst of which may result in execution of arbitrary code.

tags | advisory, arbitrary, vulnerability
systems | linux, gentoo
advisories | CVE-2006-4339, CVE-2009-0200, CVE-2009-0201, CVE-2009-0217, CVE-2009-2949, CVE-2009-2950, CVE-2009-3301, CVE-2009-3302, CVE-2010-0395, CVE-2010-2935, CVE-2010-2936, CVE-2010-3450, CVE-2010-3451, CVE-2010-3452, CVE-2010-3453, CVE-2010-3454, CVE-2010-3689, CVE-2010-4253, CVE-2010-4643, CVE-2011-2713, CVE-2012-0037, CVE-2012-1149, CVE-2012-2149, CVE-2012-2334, CVE-2012-2665, CVE-2014-0247
SHA-256 | 25cba7cb86e5c00a8edba21108a03562ceee1d3bf37cd0e99baa6eabd8e19dc3
Gentoo Linux Security Advisory 201408-15
Posted Sep 2, 2014
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201408-15 - Multiple vulnerabilities have been found in PostgreSQL, the worst of which may allow remote Denial of Service. Versions prior to 9.3.3 are affected.

tags | advisory, remote, denial of service, vulnerability
systems | linux, gentoo
advisories | CVE-2013-0255, CVE-2013-1899, CVE-2013-1900, CVE-2013-1901, CVE-2014-0060, CVE-2014-0061, CVE-2014-0062, CVE-2014-0063, CVE-2014-0064, CVE-2014-0065, CVE-2014-0066, CVE-2014-2669
SHA-256 | bafcfd9d037a64e13d657004fbba9cbe2af1f8cbbe7b4185af4a965e78b19db5
Page 2 of 2
Back12Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    17 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close