Archive for the ‘vulnerabilities’ Category

Vuln: RhinoSoft Serv-U Web Client HTTP Request Remote Buffer Overflow Vulnerability

|
Comments Off
RhinoSoft Serv-U Web Client HTTP Request Remote Buffer Overflow Vulnerability

Vuln: Acidcat ASP CMS Multiple Cross Site Scripting Vulnerabilities

|
Comments Off
Acidcat ASP CMS Multiple Cross Site Scripting Vulnerabilities

Vuln: LuraWave JP2 Browser Plug-In ‘npjp2.dll’ Buffer Overflow Vulnerability

|
Comments Off
LuraWave JP2 Browser Plug-In 'npjp2.dll' Buffer Overflow Vulnerability

Vuln: Mozilla Firefox/SeaMonkey/Thunderbird XSLT Stylesheets Denial of Service Vulnerability

|
Comments Off
Mozilla Firefox/SeaMonkey/Thunderbird XSLT Stylesheets Denial of Service Vulnerability

MS11-098 – Important : Vulnerability in Windows Kernel Could Allow Elevation of Privilege (2633171) – Version: 1.1

|
Comments Off
Severity Rating: Important
Revision Note: V1.1 (February 1, 2012): Added a link to Microsoft Knowledge Base Article 2633171 under Known Issues in the Executive Summary.
Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application designed to exploit the vulnerability. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.

MS11-100 – Critical : Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (2638420) – Version: 1.3

|
Comments Off
Severity Rating: Critical
Revision Note: V1.3 (February 1, 2012): Corrected registry keys and installation switches in the deployment tables for Windows Server 2003 and Windows Server 2008, and installation switches in the deployment table for Windows Vista. This is an informational change only. There were no changes to the security update files or detection logic.
Summary: This security update resolves one publicly disclosed vulnerability and three privately reported vulnerabilities in Microsoft .NET Framework. The most severe of these vulnerabilities could allow elevation of privilege if an unauthenticated attacker sends a specially crafted web request to the target site. An attacker who successfully exploited this vulnerability could take any action in the context of an existing account on the ASP.NET site, including executing arbitrary commands. In order to exploit this vulnerability, an attacker must be able to register an account on the ASP.NET site, and must know an existing user name.

Vuln: PHP ‘exif_process_IFD_TAG()’ Remote Integer Overflow Vulnerability

|
Comments Off
PHP 'exif_process_IFD_TAG()' Remote Integer Overflow Vulnerability

Vuln: Adobe Flash Player CVE-2011-2140 Remote Memory Corruption Vulnerability

|
Comments Off
Adobe Flash Player CVE-2011-2140 Remote Memory Corruption Vulnerability

Vuln: Samba SWAT Cross Site Request Forgery Vulnerability

|
Comments Off
Samba SWAT Cross Site Request Forgery Vulnerability

Vuln: PHP Versions Prior to 5.3.7 Multiple Security Vulnerabilities

|
Comments Off
PHP Versions Prior to 5.3.7 Multiple Security Vulnerabilities