FreeBSD

15 May

CVE-2012-2612

The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatch ...

CVE-2012-2611

The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200. ...

CVE-2012-2514

The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Disp ...

CVE-2012-2513

The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher ...

CVE-2012-2512

The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Disp ...

CVE-2012-2511

The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispat ...

14 May

CVE-2012-2333

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1 ...

CVE-2012-2277

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5. ...

CVE-2012-2276

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5. ...

CVE-2012-1804

Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds r ...

Óâåäîìëåíèÿ 142 - 156 of 426
First | Prev. | 5 6 7 8 9 10 11 12 13 14 15 | Next | Last 

FreeBSD-SA-00:31.canna: Canna port contains remote vulnerability [REVISED]

The Canna server contains an overflowable buffer which may be exploited by a remote user to execute arbitrary code on the local system as user 'bin'.

12 may, 2004

FreeBSD-SA-00:61.tcpdump: tcpdump contains remote vulnerabilities [REISSUED]

Several overflowable buffers were discovered in the version of tcpdump included in FreeBSD, during internal source code auditing.

12 may, 2004

FreeBSD-SA-00:62.top: top allows reading of kernel memory [REISSUED]

A "format string vulnerability" was discovered in the top(1) utility which allows unprivileged local users to cause the top process to execute arbitrary code.

12 may, 2004

FreeBSD-SA-00:68.ncurses: ncurses allows local privilege escalation [REVISED]

There exists an overflowable buffer in the libncurses library in the processing of cursor movement capabilities.

12 may, 2004

FreeBSD-SA-00:69.telnetd: telnetd allows remote system resource consumption [REVISED]

The telnet protocol allows for UNIX environment variables to be passed from the client to the user login session on the server.

12 may, 2004

FreeBSD-SA-00:77.procfs: Several vulnerabilities in procfs [REVISED]

There were several problems discovered in the procfs code: 1) Unprivileged local users can gain superuser privileges due to insufficient access control checks on the /proc//mem and /proc//ctl files, which gives access to a process address space and perform various control operations on the process respectively.

12 may, 2004

FreeBSD-SA-00:78.bitchx: bitchx/ko-bitchx allows remote code execution [REVISED]

The bitchx port, versions prior to 1.0c17_1, and ko-bitchx port, versions prior to 1.0c16_3, contains a remote vulnerability.

12 may, 2004

FreeBSD-SA-01:09.crontab: crontab allows users to read certain files [REVISED]

crontab(8) was discovered to contain a vulnerability that may allow local users to read any file on the system that conform to a valid crontab(5) file syntax.

12 may, 2004

FreeBSD-SA-01:11.inetd: inetd ident server allows remote users to partially

During internal auditing, the internal ident server in inetd was found to incorrectly set group privileges according to the user.

12 may, 2004

FreeBSD-SA-01:12.periodic: periodic uses insecure temporary files [REVISED]

A vulnerability was inadvertently introduced into periodic that caused temporary files with insecure file names to be used in the system's temporary directory.

12 may, 2004

FreeBSD-SA-01:32.ipfilter: IPFilter may incorrectly pass packets [REVISED]

When matching a packet fragment, insufficient checks were performed to ensure the fragment is valid.

12 may, 2004

FreeBSD-SA-01:33.ftpd-glob: globbing vulnerability in ftpd [REVISED]

The glob() function contains potential buffer overflows that may be exploitable through the FTP daemon.

12 may, 2004

FreeBSD-SA-01:40.fts: fts(3) routines contain race condition [REVISED]

The fts routines are vulnerable to a race condition when ascending a file hierarchy, which allows an attacker who has control over part of the hierarchy into which fts is descending to cause the application to ascend beyond the starting point of the file traversal, and enter other parts of the filesystem.

12 may, 2004

FreeBSD-SA-01:42.signal: signal handling during exec may allow local root

A flaw exists in FreeBSD signal handler clearing that would allow for some signal handlers to remain in effect after the exec.

12 may, 2004

FreeBSD-SA-01:49.telnetd: telnetd contains remote buffer overflow

An overflowable buffer was found in the version of telnetd included with FreeBSD.

12 may, 2004

Óâåäîìëåíèÿ 142 - 156 of 426
First | Prev. | -12 -11 -10 -9 -8 -7 -6 -5 -4 -3 -2 -1 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 | Next | Last

CVE-2012-2612

The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2611

The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2, when a certain Developer Trace configuration is enabled, allows remote attackers to execu ...

15 may, 2012

CVE-2012-2514

The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2513

The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2512

The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2511

The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2333

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecif ...

14 may, 2012

CVE-2012-2277

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (pvcontrol.exe process hang) via \n (line feed) characters in the Id fields of ...

14 may, 2012

CVE-2012-2276

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via input data that (1) lacks FIPS ...

14 may, 2012

CVE-2012-1804

Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted HTTP request.

14 may, 2012

Firefox 8/9 AttributeChildRemoved() Use-After-Free Exploit

Target: Mozilla Firefox 8.x, 9.x
Impact: Code execution

MS12-027 MSCOMCTL ActiveX Buffer Overflow Exploit (meta)

Target: MSCOMCTL ActiveX
Impact: Code execution

Microsoft Windows RDP PoC (CVE-2012-0002)

Target: Microsoft Windows XP, 2003, Vista, 7, 2008
Impact: Code execution