ZDI-09-099: Hewlett-Packard OpenView Data Protector Backup Client Service Buffer Overflow Vulnerability

2009-12-21 Thread ZDI Disclosures
ZDI-09-099: Hewlett-Packard OpenView Data Protector Backup Client Service Buffer Overflow Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-099 December 17, 2009 -- CVE ID: CVE-2007-2280 -- Affected Vendors: Hewlett-Packard -- Affected Products: Hewlett-Packard OpenView Data

TPTI-09-15: HP OpenView Data Protector Cell Manager Heap Overflow Vulnerability

2009-12-21 Thread dvlabs
TPTI-09-15: HP OpenView Data Protector Cell Manager Heap Overflow Vulnerability http://dvlabs.tippingpoint.com/advisory/TPTI-09-15 December 17, 2009 -- CVE ID: CVE-2007-2281 -- Affected Vendors: Hewlett-Packard -- Affected Products: Hewlett-Packard OpenView -- TippingPoint(TM) IPS Customer

Re: Powered By Dvbbs Version 7.1.0 Sp1 By Pass

2009-12-21 Thread macaco-listo
By : Hasadya Raed Contact : Raed (at) BsdMail (dot) Com [email concealed] Israel -- Script : Dvbbs Version 7.1.0 Sp1 Dork : Powered By Dvbbs Version 7.1.0 Sp1 -- Exploit : http://www.victim.com/Data/Dvbbs7.mdb ..

[ MDVSA-2009:336 ] koffice

2009-12-21 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:336 http://www.mandriva.com/security/

[ISecAuditors Security Advisories] Simple PHP Blog = 0.5.1 Local File Include vulnerability

2009-12-21 Thread ISecAuditors Security Advisories
= INTERNET SECURITY AUDITORS ALERT 2009-005 - Original release date: March 2nd, 2009 - Last revised: December 18th, 2009 - Discovered by: Juan Galiana Lara - Severity: 6.8/10 (CVSS scored) = I. VULNERABILITY

[ISecAuditors Security Advisories] PHP-Calendar = v1.1 'configfile' Remote and Local File Inclusion vulnerability

2009-12-21 Thread ISecAuditors Security Advisories
= INTERNET SECURITY AUDITORS ALERT 2009-011 - Original release date: October 13th, 2009 - Last revised: December 18th, 2009 - Discovered by: Juan Galiana Lara - CVE ID: CVE-2009-3702 - Severity: 8.5/10 (CVSS Base Score)

[USN-875-1] Red Hat Cluster Suite vulnerabilities

2009-12-21 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-875-1 December 18, 2009 redhat-cluster, redhat-cluster-suite vulnerabilities CVE-2008-4192, CVE-2008-4579, CVE-2008-4580, CVE-2008-6552, CVE-2008-6560

SMF (Simple Machine Forum) 1.1.11 XSS - Discovered by : Khashayar Fereidani

2009-12-21 Thread irancrash
|| Script : SMF (Simple Machine Forum) 1.1.11 || Vulnerability Type : Active XSS ( Active Cross Site Scripting ) || Risk : Low || Discovered By Khashayar Fereidani || http://ircrash.com http://bugtraq.ircrash.com || Note : For use this vulnerability you need access to censor words panel .

[USN-873-1] Firefox 3.0 and Xulrunner 1.9 vulnerabilities

2009-12-21 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-873-1 December 18, 2009 firefox-3.0, xulrunner-1.9 vulnerabilities CVE-2009-3979, CVE-2009-3981, CVE-2009-3983, CVE-2009-3984, CVE-2009-3985, CVE-2009-3986

[USN-874-1] Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities

2009-12-21 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-874-1 December 18, 2009 firefox-3.5, xulrunner-1.9.1 vulnerabilities CVE-2009-3388, CVE-2009-3389, CVE-2009-3979, CVE-2009-3980, CVE-2009-3982, CVE-2009-3983, CVE-2009-3984, CVE-2009-3985, CVE-2009-3986

[SECURITY] [DSA-1959-1] New ganeti packages fix arbitrary command execution

2009-12-21 Thread Raphael Geissert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1959-1 secur...@debian.org http://www.debian.org/security/ Raphael Geissert December 19, 2009

[SECURITY] [DSA 1960-1] New acpid packages fix weak file permissions

2009-12-21 Thread Raphael Geissert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1960-1 secur...@debian.org http://www.debian.org/security/ Raphael Geissert December 19, 2009

[ GLSA 200912-02 ] Ruby on Rails: Multiple vulnerabilities

2009-12-21 Thread Alex Legler
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200912-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

phpPollScript - 1.3 Remote File Include

2009-12-21 Thread admin
#phpPollScript = 1.3 Remote File Include Vulnerability #Download Script : http://download.tomex.org/phpPollScriptv13b.zip #Author : ZZxxHackerzzXX #Contact : ad...@ekin0x.com #Location : Turkey

pragmaMx CMS Blind SQL/XPath Injection vulnerability

2009-12-21 Thread hadikiamarsi
### # # CMS Name : pragmaMx ( All Version ) # # Bug Type : Blind SQL/XPath Injection vulnerability # # Found by : Hadi Kiamarsi # # Contact : hadikiamarsi [at] hotmail.com # # Download :

TLS Renegotiation Vulnerability: Proof of Concept Code (Python)

2009-12-21 Thread RedTeam Pentesting GmbH
Information about a vulnerability in the TLS protocol was published in the beginning of November 2009. Attackers can take advantage of that vulnerability to inject arbitrary prefixes into a network connection protected by TLS. This can result in severe vulnerabilities, depending on the application

SQL-Ledger – severa l vulnerabilities

2009-12-21 Thread Alexander Klink
||| Security Advisory AKLINK-SA-2009-001 ||| ||| CVE-2009-3580 (CVE candidate)||| ||| CVE-2009-3581 (CVE candidate)||| ||| CVE-2009-3582 (CVE candidate)||| ||| CVE-2009-3583 (CVE candidate)||| ||| CVE-2009-3584 (CVE