User login

Defcon News

New Files / Applications

Security Vulnerabilities

December 29, 2007

01:00
Linux Kernel ISDN PPP Remote Denial of Service Vulnerability

August 27, 2007

12:15
PHP versions 5.2.0 and below local buffer overflow exploit for Win32 that makes use of php_iisfunc.dll.
12:15
Alpha Centauri Software SIDVault LDAP server remote root exploit.
12:15
iDefense Security Advisory 08.27.07 - Remote exploitation of multiple buffer overflow vulnerabilities within Motorola Inc.'s Timbuktu allows attackers to crash the service or potentially execute arbitrary code with SYSTEM privileges. iDefense has confirmed the existence of these vulnerabilities within version 8.6.3.1367 of Motorola Inc.'s Timbuktu Pro for Windows. Older versions are suspected to be vulnerable.
12:15
iDefense Security Advisory 08.27.07 - Remote exploitation of a directory traversal vulnerability in Motorola Inc.'s Timbuktu Pro allows attackers to delete or create files with SYSTEM privileges. iDefense confirmed the existence of this vulnerability in version 8.6.3.1367 of Motorola Inc.'s Timbuktu Pro for Windows. Other versions, including those for other operating systems are suspected to be vulnerable.
12:15
Ubuntu Security Notice 503-1 - Various flaws were discovered in the layout and JavaScript engines. By tricking a user into opening a malicious email, an attacker could execute arbitrary code with the user's privileges. Please note that JavaScript is disabled by default for emails, and it is not recommended to enable it. Jesper Johansson discovered that spaces and double-quotes were not correctly handled when launching external programs. In rare configurations, after tricking a user into opening a malicious email, an attacker could execute helpers with arbitrary arguments with the user's privileges.
12:15
Debian Security Advisory 1358-1 - Several remote vulnerabilities have been discovered in Asterisk, a free software PBX and telephony toolkit. These flaws range from denial of service to code execution vulnerabilities.
12:15
Stampit Web suffers from a denial of service vulnerability.
12:15
The SIDVault LDAP server is susceptible to a remote buffer overflow vulnerability.
12:15
12:15
Sunshop v4.0 >> Advertisement ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!" - White Paper Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection! https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=701600000004c29
12:15
[SECURITY] [DSA 1358-1] New asterisk packages fix several vulnerabilities
12:15
InterWorx-CP Multiple HTML Injections Vulnerabilitie

August 25, 2007

18:00
It appears that sybase.com suffers from a cross site scripting vulnerability.
18:00
AutoIndex PHP Script versions 2.2.1 and below suffer from cross site scripting vulnerabilities.
13:15
VMWare Workstation version 6.0 for Windows suffers from a denial of service vulnerability and possible privilege escalation.
13:15
Asterisk Project Security Advisory - Asterisk suffers from a crash vulnerability when passed invalid MIME bodies when using voicemail with IMAP storage.
13:15
BufferZone version 2.5 suffers from denial of service and possible privilege escalation vulnerabilities.
13:15
A remote heap overflow condition in Real Helix's RTSP service could allow for arbitrary code execution. The vulnerable code is triggered with the use of an RTSP command with multiple 'Require' headers. Versions prior to 11.1.4 are affected.
13:15
A remotely exploitable vulnerability has been discovered in the file parsing engine of Sophos AntiVirus versions prior to 2.48.0. The bug exists during the file parsing of UPX packed files.