FreeBSD

15 May

CVE-2012-2612

The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatch ...

CVE-2012-2611

The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200. ...

CVE-2012-2514

The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Disp ...

CVE-2012-2513

The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher ...

CVE-2012-2512

The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Disp ...

CVE-2012-2511

The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispat ...

14 May

CVE-2012-2333

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1 ...

CVE-2012-2277

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5. ...

CVE-2012-2276

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5. ...

CVE-2012-1804

Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds r ...

Óâåäîìëåíèÿ 412 - 426 of 426
First | Prev. | 18 19 20 21 22 23 24 25 26 27 28 | Next | Last 

FreeBSD-SA-01:38.sudo: sudo contains local buffer overflow

The sudo port, versions prior to sudo-1.6.3.7, contains a local command-line buffer overflow allowing a local user to potentially gain increased privileges on the local system.

01 september, 2001

FreeBSD-SA-01:39.tcp-isn: TCP initial sequence number generation contains

It has long been known that an attacker who can guess the initial sequence number which a system will use for the next incoming TCP connection can spoof a TCP connection handshake coming from a machine to which he does not have access, and then send arbitrary data into the resulting TCP connection which will be accepted by the server as coming from the spoofed machine.

01 september, 2001

FreeBSD-SA-01:41.hanterm: hanterm ports allow local root compromise

The hanterm binary is installed with setuid root permissions, but contains insecure code which allows unprivileged local users to obtain root access on the local system.

01 september, 2001

FreeBSD-SA-01:43.fetchmail: fetchmail contains potentially exploitable buffer

The fetchmail port, versions prior to fetchmail-5.8.6, contains a potentially exploitable buffer overflow when rewriting headers longer than 512 bytes.

01 september, 2001

FreeBSD-SA-01:44.gnupg: gnupg contains format string vulnerability

The gnupg port, versions prior to gnupg-1.0.6, contains a format string vulnerability.

01 september, 2001

FreeBSD-SA-01:45.samba: samba

The samba ports, versions prior to samba-2.0.10, samba-devel-2.2.0a, and ja-samba-2.0.9.j1.0_1, fail to properly validate NetBIOS names.

01 september, 2001

FreeBSD-SA-01:46.w3m: w3m contains remotely exploitable buffer overflow

The w3m port, versions prior to w3m-0.2.1_1, contains a buffer overflow in the parsing of MIME headers.

01 september, 2001

FreeBSD-SA-01:47.xinetd: xinetd contains multiple vulnerabilities

The xinetd port, versions prior to xinetd-2.3.0, contains a potentially exploitable buffer overflow in the logging routines.

01 september, 2001

FreeBSD-SA-01:50.windowmaker: windowmaker contains possibly exploitable buffer overflow

The windowmaker ports, versions prior to windowmaker-0.65.0_2 and windowmaker-i18n-0.65.0_1, contain a potentially exploitable buffer overflow when displaying a very long window title in the window list menu.

01 september, 2001

FreeBSD-SA-01:52.fragment: Denial of service using fragmented IPv4 packets

Remote users may be able to prevent a FreeBSD system from communicating with other systems on the network by transmitting large numbers of fragmented IPv4 datagrams.

01 september, 2001

FreeBSD-SA-01:53.ipfw: ipfw `me' on P2P interfaces matches remote address

A flaw in the implementation of the ipfw `me' rules when used in conjunction with point-to-point interfaces results in filter rules which match the remote IP address of the point-to-point interface in addition to the intended local IP address.

01 september, 2001

FreeBSD-SA-01:54.ports-telnetd: telnetd contains remote buffer overflow

This advisory is closely related to the previously released FreeBSD-SA-01:49.telnetd.v1.1 advisory.

01 september, 2001

FreeBSD-SA-01:55.procfs: procfs vulnerability leaks set[ug]id process memory

Prior to the migration of system monitoring utilities (such as ps(8)) to use the sysctl(8) management interface, these utilities formerly used procfs and direct kernel memory access to extract process information, and they ran with the setgid kmem privilege to allow direct kernel memory access.

01 september, 2001

FreeBSD-SA-01:56.tcp_wrappers: tcp_wrappers PARANOID hostname checking does not work

The addition of a flawed check for a numeric result during reverse DNS lookup causes tcp_wrappers to skip some of its sanity checking of DNS results.

01 september, 2001

FreeBSD-SA-01:58.lpd: lpd contains remote root vulnerability

Users on the local machine or on remote systems which are allowed to access the local line printer daemon may be able to cause a buffer overflow.

01 september, 2001

Óâåäîìëåíèÿ 412 - 426 of 426
First | Prev. | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 | Next | Last

CVE-2012-2612

The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2611

The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2, when a certain Developer Trace configuration is enabled, allows remote attackers to execu ...

15 may, 2012

CVE-2012-2514

The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2513

The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2512

The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2511

The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2333

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecif ...

14 may, 2012

CVE-2012-2277

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (pvcontrol.exe process hang) via \n (line feed) characters in the Id fields of ...

14 may, 2012

CVE-2012-2276

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via input data that (1) lacks FIPS ...

14 may, 2012

CVE-2012-1804

Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted HTTP request.

14 may, 2012

Firefox 8/9 AttributeChildRemoved() Use-After-Free Exploit

Target: Mozilla Firefox 8.x, 9.x
Impact: Code execution

MS12-027 MSCOMCTL ActiveX Buffer Overflow Exploit (meta)

Target: MSCOMCTL ActiveX
Impact: Code execution

Microsoft Windows RDP PoC (CVE-2012-0002)

Target: Microsoft Windows XP, 2003, Vista, 7, 2008
Impact: Code execution