The FTP client included with Solaris contains a flaw that allows a malicious FTP server to execute arbitrary commands on the client computer. No further details have been provided.. Read more.
A remote overflow exists in WS_FTP. The WS_FTP fails to sanitize input to
DELE, MDTM, MLST, MKD, RMD, RNFR, RNTO, SIZE, STAT, XMKD, XRMD resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary commands to be execute resulting in a loss of confidentiality.. Read more.
iG Shop contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the 'cats', 'l_price' and 'u_price' variables in the 'page.php' module are not verified properly and will allow an attacker to inject or manipulate SQL queries.. Read more.
Microsoft IIS contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when attempting to access an area protected via basic http authentication without providing realm information. This may disclose the internal IP address or network name in the response header resulting in a loss of confidentiality.. Read more.
A local overflow exists in AIX ping. The AIX ping fails to check command line arguments length resulting in a buffer overflow. With a specially crafted request, an attacker can execute arbitrary commands resulting in a loss of integrity.. Read more.
phpBB contains a flaw that allows a remote cross site scripting attack. The flaw exists because the application does not validate user input upon submission to the username handling routines. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.. Read more.
A remote overflow exists in xloadimage. The 'facesLoad()' function fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted request, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.. Read more.
xli contains a flaw related to the validation of image properties that may allow a remote attacker to execute arbitrary code. No further details have been provided.. Read more.
xli contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is triggered due to the handling of compressed images. With a specially crafted filename containing shell meta characters, a remote attacker could execute arbitrary commands resulting in a loss of integrity.. Read more.
A remote overflow exists in xli. The 'facesLoad()' function fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted request, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.. Read more.
Raptor Firewall is an enterprise level firewall originally developed by Axent Technologies and is maintained and distributed by Symantec. Symantec Enterprise Firewall is .... Read more.
Computer Associates BrightStor ARCserve/Enterprise Backup products provide backup and restore protection for Windows, NetWare, Linux and UNIX servers as well as Windows, .... Read more.
Computer Associates BrightStor ARCserve/Enterprise Backup products provide backup and restore protection for Windows, NetWare, Linux and UNIX servers as well as Windows, .... Read more.
Midnight Commander is a popular file management tool for Unix systems. Among other features, Midnight Commander is provided with a code layer to access the file system; t.... Read more.
A number of TCP/IP stacks are vulnerable to a "loopback" condition initiated by sending a TCP packet with the "SYN" flag set and the source address and port spoofed to eq.... Read more.
Sylpheed is a GTK+ based mail client for Unix, and Unix-like operating systems. It is reported that Sylpheed is susceptible to a buffer overflow vulnerability. This issu.... Read more.
Sender: Dejan Levaja [dejan at levaja dot com]. Read more.
Sender: Some one [someone at cannabismail dot com]. Read more.
Sender: [pageexec at freemail dot hu]. Read more.
Sender: Mandrakelinux Security Team [security at linux-mandrake dot com]. Read more.