Mandriva

15 May

CVE-2012-2612

The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatch ...

CVE-2012-2611

The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200. ...

CVE-2012-2514

The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Disp ...

CVE-2012-2513

The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher ...

CVE-2012-2512

The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Disp ...

CVE-2012-2511

The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispat ...

14 May

CVE-2012-2333

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1 ...

CVE-2012-2277

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5. ...

CVE-2012-2276

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5. ...

CVE-2012-1804

Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds r ...

Óâåäîìëåíèÿ 547 - 561 of 831
First | Prev. | 32 33 34 35 36 37 38 39 40 41 42 | Next | Last 

[ MDKSA-2006:148 ] - Updated xorg-x11 packages fix vulnerabilities

An integer overflow flaw was discovered in how xorg-x11/XFree86 handles PCF files.

24 august, 2006

[ MDKSA-2006:147 ] - Updated squirrelmail packages fix vulnerabilities

Cross-site scripting (XSS) vulnerability in search.php in SquirrelMail 1.5.1 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary HTML via the mailbox parameter (CVE-2006-3174).

22 august, 2006

[ MDKSA-2006:144 ] - Updated php packages fix vulnerability

A vulnerability was discovered in the sscanf function that could allow attackers in certain circumstances to execute arbitrary code via argument swapping which incremented an index past the end of an array and triggered a buffer over-read.

21 august, 2006

[ MDKSA-2006:145 ] - Updated Firefox packages fix multiple vulnerabilities

A number of security vulnerabilities have been discovered and corrected in the latest Mozilla Firefox program.

21 august, 2006

[ MDKSA-2006:146 ] - Updated Thunderbird packages fix multiple vulnerabilities

A number of security vulnerabilities have been discovered and corrected in the latest Mozilla Thunderbird program.

21 august, 2006

[ MDKSA-2006:143-1 ] - Updated Firefox packages fix multiple vulnerabilities

A number of security vulnerabilities have been discovered and corrected in the latest Mozilla Firefox program.

17 august, 2006

[ MDKSA-2006:143 ] - Updated Firefox packages fix multiple vulnerabilities

A number of security vulnerabilities have been discovered and corrected in the latest Mozilla Firefox program.

16 august, 2006

[ MDKSA-2006:141 ] - Updated gnupg packages fix vulnerability

An integer overflow vulnerability was discovered in gnupg where an attacker could create a carefully-crafted message packet with a large length that could cause gnupg to crash or possibly overwrite memory when opened.

14 august, 2006

[ MDKSA-2006:142 ] - Updated heartbeat packages fix vulnerability

Two vulnerabilities in heartbeat prior to 2.0.6 was discovered by Yan Rong Ge.

14 august, 2006

[ MDKSA-2006:139 ] - Updated krb5 packages fix local privilege escalation vulnerability

A flaw was discovered in some bundled Kerberos-aware packages that would fail to check the results of the setuid() call.

09 august, 2006

[ MDKSA-2006:140 ] - Updated ncompress packages fix vulnerability

Tavis Ormandy, of the Google Security Team, discovered that ncompress, when uncompressing data, performed no bounds checking, which could allow a specially crafted datastream to underflow a .bss buffer with attacker controlled data.

09 august, 2006

[ MDKSA-2006:138 ] - Updated clamav packages fix vulnerability

Damian Put discovered a boundary error in the UPX extraction module in ClamAV which is used to unpack PE Windows executables.

08 august, 2006

[ MDKSA-2006:136 ] - Updated kdegraphics packages fix multiple libtiff vulnerabilities

Tavis Ormandy, Google Security Team, discovered several vulnerabilites the libtiff image processing library.

01 august, 2006

[ MDKSA-2006:137 ] - Updated libtiff packages fix multiple vulnerabilities

Several buffer overflows have been discovered, including a stack buffer overflow via TIFFFetchShortPair()

01 august, 2006

[ MDKSA-2006:135 ] - Updated freeciv packages fix DoS vulnerabilities

Buffer overflow in Freeciv 2.1.0-beta1 and earlier, and SVN 15 Jul 2006 and earlier, allows remote attackers to cause a denial of service (crash)

31 july, 2006

Óâåäîìëåíèÿ 547 - 561 of 831
First | Prev. | -12 -11 -10 -9 -8 -7 -6 -5 -4 -3 -2 -1 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 | Next | Last

CVE-2012-2612

The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2611

The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2, when a certain Developer Trace configuration is enabled, allows remote attackers to execu ...

15 may, 2012

CVE-2012-2514

The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2513

The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2512

The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2511

The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2333

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecif ...

14 may, 2012

CVE-2012-2277

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (pvcontrol.exe process hang) via \n (line feed) characters in the Id fields of ...

14 may, 2012

CVE-2012-2276

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via input data that (1) lacks FIPS ...

14 may, 2012

CVE-2012-1804

Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted HTTP request.

14 may, 2012

Firefox 8/9 AttributeChildRemoved() Use-After-Free Exploit

Target: Mozilla Firefox 8.x, 9.x
Impact: Code execution

MS12-027 MSCOMCTL ActiveX Buffer Overflow Exploit (meta)

Target: MSCOMCTL ActiveX
Impact: Code execution

Microsoft Windows RDP PoC (CVE-2012-0002)

Target: Microsoft Windows XP, 2003, Vista, 7, 2008
Impact: Code execution