exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 45 of 45 RSS Feed

Files Date: 2009-03-25 to 2009-03-26

OpenSSL Security Advisory 20090325
Posted Mar 25, 2009
Site openssl.org

OpenSSL Security Advisory 20090325 - The function ASN1_STRING_print_ex() when used to print a BMPString or UniversalString will crash with an invalid memory access if the encoded length of the string is illegal. Other issues were also addressed.

tags | advisory
advisories | CVE-2009-0590, CVE-2009-0591, CVE-2009-0789
SHA-256 | 1740e31a83c7080938d1549888d5d57117009bb5f4125b9b6e9a693b6f8595f8
Zero Day Initiative Advisory 09-014
Posted Mar 25, 2009
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 09-014 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Acrobat and Adobe Reader. User interaction is required in that a user must visit a malicious web site or open a malicious file. The specific flaw exists when processing malicious JavaScript contained in a PDF document. When supplying a specially crafted argument to the getIcon() method of a Collab object, proper bounds checking is not performed resulting in a stack overflow. If successfully exploited full control of the affected machine running under the credentials of the currently logged in user can be achieved.

tags | advisory, remote, web, overflow, arbitrary, javascript
advisories | CVE-2009-0927
SHA-256 | 3966eb32a4b46860d3fd3a7759decd3530e5798e73e8cc0daf08deac574462a2
Gentoo Linux Security Advisory 200903-38
Posted Mar 25, 2009
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200903-38 - Multiple vulnerabilities have been found in Squid which allow for remote Denial of Service attacks. The arrayShrink function in lib/Array.c can cause an array to shrink to 0 entries, which triggers an assert error. Versions less than 2.7.6 are affected.

tags | advisory, remote, denial of service, vulnerability
systems | linux, gentoo
advisories | CVE-2007-6239, CVE-2008-1612, CVE-2009-0478
SHA-256 | 8e7a23103f5c174d2c66e43c603c3eae5f718455c874e000d29ca014a51a857e
Debian Linux Security Advisory 1753-1
Posted Mar 25, 2009
Authored by Debian | Site debian.org

Debian Security Advisory 1753-1 - As indicated in the Etch release notes, security support for the Iceweasel version in the oldstable distribution (Etch) needed to be stopped before the end of the regular security maintenance life cycle.

tags | advisory
systems | linux, debian
SHA-256 | d3a13db03821e337345d639636f4a2a62e4a990f1f47f22194a866d7c0e0a38b
iDEFENSE Security Advisory 2009-03-24.1
Posted Mar 25, 2009
Authored by iDefense Labs, Sean Larsson | Site idefense.com

iDefense Security Advisory 03.24.09 - Remote exploitation of a heap based buffer overflow vulnerability in Adobe Systems Inc.'s Reader and Acrobat could allow an attacker to execute arbitrary code with the privileges of the current user. The vulnerability occurs when parsing a JBIG2-encoded stream inside of a PDF file. JBIG2 is an image encoding format that is primarily used for encoding monochrome images such as faxes. Acrobat Reader and Acrobat Professional versions 7.1.0, 8.1.3, 9.0.0 and prior versions are vulnerable.

tags | advisory, remote, overflow, arbitrary
advisories | CVE-2009-0928
SHA-256 | e7cfd89da7bd450aec69dbd1d239966531bfa5c6db9726eb7db2cf3f804a3158
Microsoft GdiPlus EMF Integer Overflow
Posted Mar 25, 2009
Authored by redsand | Site blacksecurity.org

Microsoft GdiPlus EMF GpFont.SetData integer overflow proof of concept exploit.

tags | exploit, overflow, proof of concept
SHA-256 | d3b60e5e3688b9d65c839ace2644f485e97a63bf12c1bf04703945cfb3135987
Adobe Acrobat Reader JBIG2 Exploit
Posted Mar 25, 2009
Authored by redsand, xort | Site blacksecurity.org

Adobe Acrobat Reader JBIG2 universal exploit that binds a shell to port 5500.

tags | exploit, shell
advisories | CVE-2009-0658
SHA-256 | 4784e82356d5a32b115f9862328d5e50edd27d6058ed9a90431d49bae5b67386
SurfMyTV Script 1.0 SQL Injection
Posted Mar 25, 2009
Authored by X0r

SurfMyTV Script version 1.0 suffers from a remote SQL injection vulnerability in view.php.

tags | exploit, remote, php, sql injection
SHA-256 | 9b70f344a0d336d6e0bd3376f4ef29f936db487fbfdd4ce86f7edd2c5c311d14
HP Security Bulletin HPSBUX02409 SSRT080171
Posted Mar 25, 2009
Authored by Hewlett Packard | Site hp.com

HP Security Bulletin - A potential security vulnerability has been identified with HP-UX running VRTSvxfs and VRTSodm. The vulnerability could be exploited locally to cause an escalation of privilege. VRTSvxfs and VRTSodm are bundled with Storage Management Suite (SMS) and Storage Management for Oracle (SMO).

tags | advisory
systems | hpux
advisories | CVE-2009-0207
SHA-256 | 5a7b28ccf2b96511d36e3c9d98c5c418293f1048f04632e2e6308a2fb54b82ca
HP Security Bulletin HPSBMA02416 SSRT090008
Posted Mar 25, 2009
Authored by Hewlett Packard | Site hp.com

HP Security Bulletin - Potential vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM). The vulnerabilities could be exploited remotely to execute arbitrary code.

tags | advisory, arbitrary, vulnerability
advisories | CVE-2009-0920, CVE-2009-0921
SHA-256 | f976338d1ba974c66688ca0437322c3fccf76d7ef9d8681481050ba3e79ebd0b
Jinzora Media Jukebox 2.8 Local File Inclusion
Posted Mar 25, 2009
Authored by dun

Jinzora Media Jukebox versions 2.8 and below suffer from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
SHA-256 | d6583277eafcf9feaca16cd6cb51c8c0624c53f0621e381b4eb2ce1e04b25c5e
Monkey-Spider Client Honeypot
Posted Mar 25, 2009
Authored by Ali Ikinci | Site monkeyspider.sourceforge.net

The Monkey-Spider is a crawler based low-interaction client honeypot. It is not only restricted to this use but it is developed as such. The Monkey-Spider crawls web sites to expose their threats to web clients.

tags | tool, web, scanner
systems | unix
SHA-256 | e7e0910bc07c73526187d4c9303ef970e6a820fa1ccafc2efd1aa343e9fc2678
PHPizabi 0.848b Privilege Escalation
Posted Mar 25, 2009
Authored by Nine:Situations:Group | Site retrogod.altervista.org

PHPizabi version 0.848b C1 HFP1 proc.inc.php remote privilege escalation exploit that uses SQL injection.

tags | exploit, remote, php, sql injection
SHA-256 | f19fa58eccb848bc5470bef28dbbf0086ee2285a4e51e3d5c796b1c703fb0ef2
Femitter FTP Server 1.x Traversal / File Manipulation
Posted Mar 25, 2009
Authored by Jonathan Salwan | Site shell-storm.org

Femitter Server FTP version 1.x suffers from directory traversal, file creation, and file deletion vulnerabilities.

tags | exploit, vulnerability, file inclusion
SHA-256 | 074c39eb6217075f81ecd9c0a80de5ad0e6abf7294dd595771abc7bcf17454f2
Harvard SQL Injection
Posted Mar 25, 2009
Authored by CraCkEr

microfluidics.hms.harvard.edu suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | a9cde86211a21cb497455f1514ed0eeb6c961d2486399c76a17bec70390878ec
Comparison Engine Power 1.0 SQL Injection
Posted Mar 25, 2009
Authored by SirGod | Site insecurity.ro

Comparison Engine Power version 1.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | a2ec42239def76fe2daa7c5556b283453ae1d5142d882a3e969475dee7a605ff
Idea Cellular SQL Injection
Posted Mar 25, 2009
Authored by Aseem Jakhar | Site null.co.in

Idea Cellular suffered from a SQL injection vulnerability.

tags | advisory, sql injection
SHA-256 | 58db50ea20a4e0d8945ec934cad0bb3336aad9c5172ea8e6a05907837d051921
IncrediMail 5.86 Cross Site Scripting
Posted Mar 25, 2009
Authored by Bui Quang Minh | Site minhbq.blogspot.com

IncrediMail version 5.86 cross site scripting exploit.

tags | exploit, xss
SHA-256 | 7799d46351965c059220f0119b62b46e65d23589e8c3b252ce527493742cf828
Secunia Security Advisory 34462
Posted Mar 25, 2009
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Slackware has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service), conduct spoofing attacks, or to potentially compromise a user's system.

tags | advisory, denial of service, spoof, vulnerability
systems | linux, slackware
SHA-256 | 5abf5537582fa72b9b1764557be336e895994190beeb14f92f585b24a5ba891e
Secunia Security Advisory 34467
Posted Mar 25, 2009
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Gentoo has issued an update for Squid. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).

tags | advisory, denial of service, vulnerability
systems | linux, gentoo
SHA-256 | 9b161bced60b47f67fcab9b45fd49348be4faac5d875a3bb087de9b6813fa713
Page 2 of 2
Back12Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close