OpenPKG

10 February

CVE-2012-0834

Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and ea ...

CVE-2012-0452

Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, ...

CVE-2012-0840

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash v ...

CVE-2012-0831

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive dur ...

CVE-2011-4534

ZenSysSrv.exe in Ing. Punzenberger COPA-DATA zenon 6.51 SP0 allows remote attackers to cause a denia ...

CVE-2011-4533

zenAdminSrv.exe in Ing. Punzenberger COPA-DATA zenon 6.51 SP0 allows remote attackers to cause a den ...

CVE-2011-4039

Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Repor ...

CVE-2011-4038

Cross-site scripting (XSS) vulnerability in Invensys Wonderware HMI Reports 3.42.835.0304 an ...

CVE-2012-1046

Cross-site scripting (XSS) vulnerability in TM1 Web in IBM Cognos TM1 9.5.2 FP1 allows remot ...

08 February

CVE-2011-3972

The shader translator implementation in Google Chrome before 17.0.963.46 allows remote attackers to ...

Óâåäîìëåíèÿ 1 - 23 of 188
First | Prev. | 1 2 3 4 5 6 7 8 9 10 11 | Next | Last 

[ OpenPKG-SA-2007.023 ] OpenPKG Security Advisory (perl)

Will Drewry and Tavis Ormandy of the Google Security Team have discovered a UTF-8 related heap overflow in the regular expression compiler of the Perl [0] programming language, probably allowing attackers to execute arbitrary code by compiling specially crafted regular expressions.

08 november, 2007

[ OpenPKG-SA-2007.022 ] OpenPKG Security Advisory (bind)

As confirmed [0] by the vendor, two vulnerabilities exist in the DNS server BIND [1]: 1.

25 july, 2007

[ OpenPKG-SA-2007.021 ] OpenPKG Security Advisory (wordpress)

A vendor-confirmed [0] SQL-injection vulnerability in version 2.2 of the CMS WordPress [1] was exploited [2].

08 june, 2007

[ OpenPKG-SA-2007.020 ] OpenPKG Security Advisory (php Security fixes)

According to a vendor release announcement [0] multiple security Enhancements and Fixes were fixed in version 5.2.3 of the programming language PHP [1].

01 june, 2007

[ OpenPKG-SA-2007.019 ] OpenPKG Security Advisory (php)

Steffan Esser published "the Month of PHP Bugs" [0] and revealed multiple vulnerabilities regarding the programming language PHP [1].

25 may, 2007

[ OpenPKG-SA-2007.018 ] OpenPKG Security Advisory (freetype)

A vulnerability caused by an integer signedness error was found [0] by Victor Stinner in the font rendering library Freetype [1], versions up to and including 2.3.4.

24 may, 2007

[ OpenPKG-SA-2007.017 ] OpenPKG Security Advisory (ratbox)

A Denial of Service (DoS) vulnerability exists in the Ratbox IRC Daemon [0], versions up to and including 2.2.5.

18 may, 2007

[ OpenPKG-SA-2007.016 ] OpenPKG Security Advisory (libgd)

Multiple security issues exist in the fast graphics generation library libgd (aka GD) [0], versions up to and including 2.0.33.

18 may, 2007

[ OpenPKG-SA-2007.015 ] OpenPKG Security Advisory (Quagga)

A Denial of Service (DoS) vulnerability exists in the routing daemon Quagga [0], versions up to and including 0.99.6.

18 may, 2007

[ OpenPKG-SA-2007.014 ] OpenPKG Security Advisory (bind)

As confirmed by the vendor [0], a vulnerability exists in the DNS server BIND [1], version 9.4 up to 9.4.1.

18 may, 2007

[ OpenPKG-SA-2007.013 ] OpenPKG Security Advisory (png)

As confirmed by the vendor, a Denial of Service (DoS) vulnerability exists in the PNG [0] image format library libpng [1].

18 may, 2007

[ OpenPKG-SA-2007.012 ] OpenPKG Security Advisory (Samba)

Multiple vulnerabilities were found in the CIFS/SMB server implementation Samba [0]: 1.

17 may, 2007

[ OpenPKG-SA-2007.011 ] OpenPKG Security Advisory (Apache/mod_perl)

A vulnerability has been reported [0] in mod_perl [1], which potentially can be exploited by malicious people to cause a DoS (Denial of Service).

29 march, 2007

[ OpenPKG-SA-2007.010 ] OpenPKG Security Advisory (php)

According to a vendor release announcement [0], multiple vulnerabilities exist in the programming language PHP [1], version up to and including 5.2.0.

23 february, 2007

[ OpenPKG-SA-2007.009 ] OpenPKG Security Advisory (twiki)

According to a vendor security advisory [0], a vulnerability exists in the SessionPlugin extension of the Wiki engine TWiki [1], version up to and including 4.1.0.

11 february, 2007

[ OpenPKG-SA-2007.007 ] OpenPKG Security Advisory (bind)

As confirmed by vendor security advisories [0][1], two security issues exist in the DNS server BIND [2], versions up to 9.3.4.

28 january, 2007

[ OpenPKG-SA-2007.006 ] OpenPKG Security Advisory (MIT Kerberos)

According to vendor security advisories [0][1], two security issues exist in the Kerberos network authentication system implementation MIT Kerberos [2].

22 january, 2007

[ OpenPKG-SA-2007.005 ] OpenPKG Security Advisory (WordPress)

According to a security advisory from Stefan Esser [0], a vulnerability exists in the Weblog publishing system WordPress [1], versions up to and including 2.0.5.

22 january, 2007

[ OpenPKG-SA-2007.004 ] OpenPKG Security Advisory (Fetchmail)

According to vendor release notes [0] and security advisories [1][2], two security issues exist in the POP3/IMAP batch client Fetchmail [3], version up to and including 6.3.5.

22 january, 2007

[ OpenPKG-SA-2007.003 ] OpenPKG Security Advisory (Drupal)

According to upstream vendor security advisories [0][1], two vulnerabilities exist in the content management system Drupal [2], version up to and including 4.7.4.

22 january, 2007

[ OpenPKG-SA-2007.002 ] OpenPKG Security Advisory (bzip2)

Together with two portability and stability issues, two older security issues were fixed in the compression tool BZip2 [0], versions up to and including 1.0.3.

22 january, 2007

[ OpenPKG-SA-2007.001 ] OpenPKG Security Advisory (Cacti)

Three vulnerabilities have been identified and exploited [0] in the network monitoring and graphing frontend Cacti [1], versions up to and including 0.8.6i.

22 january, 2007

Óâåäîìëåíèÿ 1 - 23 of 188
First | Prev. | 1 2 3 4 5 6 7 8 9 10 11 12 | Next | Last

CVE-2012-0834

Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parameter in a query_engine action to cmd.php.

10 february, 2012

CVE-2012-0452

Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, and SeaMonkey 2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trig ...

10 february, 2012

CVE-2012-0840

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CP ...

10 february, 2012

CVE-2012-0831

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to m ...

10 february, 2012

CVE-2011-4534

ZenSysSrv.exe in Ing. Punzenberger COPA-DATA zenon 6.51 SP0 allows remote attackers to cause a denial of service (service crash) or possibly execute arbitrary code via a series of connections and disconnections on TCP port 1101, aka Reference Numb ...

10 february, 2012

CVE-2011-4533

zenAdminSrv.exe in Ing. Punzenberger COPA-DATA zenon 6.51 SP0 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted packet to TCP port 50777, aka Reference Number 25240.

10 february, 2012

CVE-2011-4039

Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assisted remote attackers to execute arbitrary code via a malformed file that triggers a "write access vi ...

10 february, 2012

CVE-2011-4038

Cross-site scripting (XSS) vulnerability in Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows remote attackers to inject arbitrary web script or HTML via uns ...

10 february, 2012

CVE-2012-1046

Cross-site scripting (XSS) vulnerability in TM1 Web in IBM Cognos TM1 9.5.2 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0696.

10 february, 2012

CVE-2011-3972

The shader translator implementation in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

08 february, 2012

MS12-004 midiOutPlayNextPolyEvent Heap Overflow Exploit

Target: Microsoft Windows Media
Impact: Code execution

ActFax Server FTP RETR Remote Buffer Overflow Exploit

Target: ActFax Server 4.27 Build 0223 and previous versions
Impact: Arbitrary commands execution

ActFax Server (LPD/LPR) Remote Buffer Overflow Exploit

Target: ActFax Server 4.27 Build 0223 and previous versions
Impact: Arbitrary commands execution