FreeBSD

15 May

CVE-2012-2612

The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatch ...

CVE-2012-2611

The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200. ...

CVE-2012-2514

The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Disp ...

CVE-2012-2513

The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher ...

CVE-2012-2512

The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Disp ...

CVE-2012-2511

The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispat ...

14 May

CVE-2012-2333

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1 ...

CVE-2012-2277

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5. ...

CVE-2012-2276

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5. ...

CVE-2012-1804

Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds r ...

Óâåäîìëåíèÿ 292 - 306 of 426
First | Prev. | 15 16 17 18 19 20 21 22 23 24 25 | Next | Last 

FreeBSD-SA-96:20.stack-overflow: unauthorized access via buffer overruns

The programs in question store user-supplied information in internal buffers.

02 september, 2001

FreeBSD-SA-96:21.talkd: unauthorized access via buffer overrun in talkd

To quote AUSCERT: talk is a communication program which copies text from one users terminal to that of another, possibly remote, user.

02 september, 2001

FreeBSD-SA-97:02.lpd: Buffer overflow in lpd

The lpd program runs as root.

02 september, 2001

FreeBSD-SA-97:03.sysinstall: sysinstall bug

One of the port installation options in sysinstall is to install an anonymous ftp setup on the system.

02 september, 2001

FreeBSD-SA-97:04.procfs: security compromise via procfs

A problem exists in the procfs kernel code that allows processes to write memory of other processes where it should have been prohibited.

02 september, 2001

FreeBSD-SA-97:05.open: security compromise via open()

A problem exists in the open() syscall that allows processes to obtain a valid file descriptor without having read or write permissions on the file being opened.

02 september, 2001

FreeBSD-SA-97:06.f00f: Pentium processors have flaw allowing unpriviledged crashes

A specific sequence of instructions, starting with the byte codes F0 0F (hex) cause Pentium processors to lock up.

02 september, 2001

FreeBSD-SA-98:01.land: LAND attack can cause harm to running FreeBSD systems

A problem exists in most FreeBSD derived stacks that allows a malicious user to send a packet that causes the sytsem to lock up, thus producing a denial of service attack.

02 september, 2001

FreeBSD-SA-98:02.mmap: security compromise via mmap

Due to a 4.4BSD VM system problem, it is possible to memory-map a read-only descriptor to a character device in read-write mode.

02 september, 2001

FreeBSD-SA-98:03.ttcp: Problems with TTCP

An accelerated open is initiated by a client by sending a new TCP option, called CC, to the server.

02 september, 2001

FreeBSD-SA-98:04.mmap: security compromise via mmap

It is possible for a process to open an append-only file according to the limitations of the flags, and then mmap the file shared with write permission even when the file is marked as append-only or immutable.

02 september, 2001

FreeBSD-SA-98:05.nfs: system crash with NFS

When creating hard links on file systems, the kernel checks that both the original file and the link to it are located on the same file system.

02 september, 2001

FreeBSD-SA-98:06.icmp: smurf attack

A solution at the intermediate network being abused to generate the ICMP echo replies is to either block ICMP echo requests directed to a broadcast address or to configure the hosts on that network not to respond to such an ICMP request.

02 september, 2001

FreeBSD-SA-98:07.rst: TCP RST denial of sevice

A denail of service attack can be launched against FreeBSD systems running without one of the patches supplied later in this message.

02 september, 2001

FreeBSD-SA-98:08.fragment: IP fragmentation denial of service

There is a bug in the IP fragment reassembly code that might lead to a kernel panic.

02 september, 2001

Óâåäîìëåíèÿ 292 - 306 of 426
First | Prev. | -2 -1 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 | Next | Last

CVE-2012-2612

The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2611

The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2, when a certain Developer Trace configuration is enabled, allows remote attackers to execu ...

15 may, 2012

CVE-2012-2514

The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2513

The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2512

The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2511

The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2333

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecif ...

14 may, 2012

CVE-2012-2277

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (pvcontrol.exe process hang) via \n (line feed) characters in the Id fields of ...

14 may, 2012

CVE-2012-2276

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via input data that (1) lacks FIPS ...

14 may, 2012

CVE-2012-1804

Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted HTTP request.

14 may, 2012

Firefox 8/9 AttributeChildRemoved() Use-After-Free Exploit

Target: Mozilla Firefox 8.x, 9.x
Impact: Code execution

MS12-027 MSCOMCTL ActiveX Buffer Overflow Exploit (meta)

Target: MSCOMCTL ActiveX
Impact: Code execution

Microsoft Windows RDP PoC (CVE-2012-0002)

Target: Microsoft Windows XP, 2003, Vista, 7, 2008
Impact: Code execution