NetBSD

10 February

CVE-2012-0834

Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and ea ...

CVE-2012-0452

Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, ...

CVE-2012-0840

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash v ...

CVE-2012-0831

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive dur ...

CVE-2011-4534

ZenSysSrv.exe in Ing. Punzenberger COPA-DATA zenon 6.51 SP0 allows remote attackers to cause a denia ...

CVE-2011-4533

zenAdminSrv.exe in Ing. Punzenberger COPA-DATA zenon 6.51 SP0 allows remote attackers to cause a den ...

CVE-2011-4039

Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Repor ...

CVE-2011-4038

Cross-site scripting (XSS) vulnerability in Invensys Wonderware HMI Reports 3.42.835.0304 an ...

CVE-2012-1046

Cross-site scripting (XSS) vulnerability in TM1 Web in IBM Cognos TM1 9.5.2 FP1 allows remot ...

08 February

CVE-2011-3972

The shader translator implementation in Google Chrome before 17.0.963.46 allows remote attackers to ...

Óâåäîìëåíèÿ 1 - 25 of 100
First | Prev. | 1 2 3 4 5 6 | Next | Last 

NetBSD Security Advisory 2011-003: Exhausting kernel memory from user controlled value

Kernel memory can be exhausted by a specially crafted program. This may cause a panic.

09 march, 2011

NetBSD Security Advisory 2010-010: Buffer Length Handling Errors in netsmb

Local Kernel Memory Exhaustion DoS Attack.

26 october, 2010

NetBSD Security Advisory 2010-009: Privilege Handling Errors In larn

Unprivileged Local Users Can Gain Access To "games" Group.

26 october, 2010

NetBSD Security Advisory 2010-006: Buffer length checking errors in CODA

The CODA filesystem kernel module was incorrectly checking buffer limits enabling a regular user read access to kernel memory

02 september, 2010

NetBSD-SA2010-003: azalia(4)/hdaudio(4) negative mixer index panic

A signedness issue in the azalia(4) and hdaudio(4) drivers allows a local attacker to cause a kernel panic.

04 february, 2010

NetBSD Security Advisory 2009-012: SHA2 implementation potential buffer overflow

An error initializing a SHA2 context causes vulnerable applications using libcrypto to suffer from a 4- or 8-byte buffer overflow (for SHA256 and SHA512 correspondingly) with fixed content, potentially causing applications to crash.

29 july, 2009

NetBSD Security Advisory 2008-013: IPv6 Neighbor Discovery Protocol

An attacker may be able to forge IPv6 routing entries to intercept network traffic or cause a denial of service attack.

28 october, 2008

NetBSD Security Advisory 2008-012: Denial of service issues in racoon(8)

Currently racoon(8) does not remove orphaned invalid connections initiated by a remote peer. As a result of this a otential denial of service issue can occur.

17 september, 2008

NetBSD Security Advisory 2008-011: ICMPv6 MLD query

A malformed ICMPv6 MLD (RFC 2710) query directed at a NetBSD host can result in a denial of service (system panic).

05 september, 2008

NetBSD Security Advisory 2008-010: Malicious PPPoE discovery packet can overrun a kernel buffer

A bug in range checking allows a malicious packet to make the kernel access memory outside of the allocated buffer and cause a kernel crash.

28 august, 2008

NetBSD-SA2006-023 OpenSSL RSA Signature Forgery

OpenSSL contains a vulnerability in the validation of PKCS #1 v1.5 signatures.

27 november, 2006

NetBSD 3.0.2 and 3.1 available - multiple security fixes

The NetBSD Project is pleased to announce that versions 3.0.2 and 3.1 of the NetBSD operating system are now available in both source and binary form.

20 november, 2006

NetBSD-SA2006-023 OpenSSL RSA Signature Forgery

OpenSSL contains a vulnerability in the validation of PKCS #1 v1.5 signatures.

22 september, 2006

NetBSD-SA2006-022 BIND recursive query and SIG query processing

Two denial of service vulnerabilities have been reported in bind which can cause the name server daemon to crash.

22 september, 2006

NetBSD-SA2006-021 Integer overflows in CID-keyed font parser

There are integer overflows present in the CID-keys font parser as supplied with both XFree86 and X11R7.0.

22 september, 2006

NetBSD-SA2006-020 Integer overflows in PCF font parsers

There are integer overflows present in the PCF font parsers as supplied with both XFree86 and X11R7.0.

22 september, 2006

NetBSD-SA2006-019 Malicious PPP options can overrun a kernel buffer

A problem has been identified in the in-kernel PPP code shared by ISDN PPP interfaces ippp(4) and pppoe(4).

05 september, 2006

NetBSD Security Advisory 2006-019 -- Malicious PPP options can overrun a kernel buffer

A problem has been identified in the in-kernel PPP code shared by ISDN PPP interfaces ippp(4) and pppoe(4).

24 august, 2006

NetBSD Security Advisory 2006-018 sail(6), dm(8) and tetris(6) buffer overflows

The sail, dungeon master arbiter and tetris games all contain buffer overflows.

01 june, 2006

NetBSD Security Advisory 2006-017 Sendmail malformed multipart MIME messages

Sendmail is vulnerable to a denial of service condition in the handling of malformed multipart MIME messages.

30 may, 2006

NetBSD Security Advisory 2006-016 IPv6 socket options can crash the system

Insufficient validation when parsing IPv6 socket options can lead to a system crash.

23 may, 2006

NetBSD Security Advisory 2006-014 An audio subsystem race condition may crash the system

A system crash can occur if a user changes the sample rate of an audio device during playback.

03 may, 2006

Óâåäîìëåíèÿ 1 - 25 of 100
First | Prev. | 1 2 3 4 5 6 | Next | Last

CVE-2012-0834

Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parameter in a query_engine action to cmd.php.

10 february, 2012

CVE-2012-0452

Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, and SeaMonkey 2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trig ...

10 february, 2012

CVE-2012-0840

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CP ...

10 february, 2012

CVE-2012-0831

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to m ...

10 february, 2012

CVE-2011-4534

ZenSysSrv.exe in Ing. Punzenberger COPA-DATA zenon 6.51 SP0 allows remote attackers to cause a denial of service (service crash) or possibly execute arbitrary code via a series of connections and disconnections on TCP port 1101, aka Reference Numb ...

10 february, 2012

CVE-2011-4533

zenAdminSrv.exe in Ing. Punzenberger COPA-DATA zenon 6.51 SP0 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted packet to TCP port 50777, aka Reference Number 25240.

10 february, 2012

CVE-2011-4039

Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assisted remote attackers to execute arbitrary code via a malformed file that triggers a "write access vi ...

10 february, 2012

CVE-2011-4038

Cross-site scripting (XSS) vulnerability in Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows remote attackers to inject arbitrary web script or HTML via uns ...

10 february, 2012

CVE-2012-1046

Cross-site scripting (XSS) vulnerability in TM1 Web in IBM Cognos TM1 9.5.2 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0696.

10 february, 2012

CVE-2011-3972

The shader translator implementation in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

08 february, 2012

MS12-004 midiOutPlayNextPolyEvent Heap Overflow Exploit

Target: Microsoft Windows Media
Impact: Code execution

ActFax Server FTP RETR Remote Buffer Overflow Exploit

Target: ActFax Server 4.27 Build 0223 and previous versions
Impact: Arbitrary commands execution

ActFax Server (LPD/LPR) Remote Buffer Overflow Exploit

Target: ActFax Server 4.27 Build 0223 and previous versions
Impact: Arbitrary commands execution