Contents
Cal Poly Pomona

Latest Windows and Mac Bulletins

Report date: December 08, 2008  Date posted: December 08, 2008

This report combines relevant bulletins from SANS, Secunia and CERT. The wording is original with some "back" links added where needed. The CERT index lists vulnerabilities with and without solutions. Click the link for specific information.

At a very minimum, look at the SANS bulletins as they include the top issues on a weekly basis. Next, review Secunia for a more complete listing with well structured bulletins avaiable as external links. Finally, the CERT section contains very detailed information and many newly discovered vulnerabilities and updates on existing issues.

Tip: highlight any link below to reveal the criticality or priority.

    SANS Bulletin - Vol 7 Num 48

    Secunia Bulletin - 2008-49

    CERT Bulletin - SB08-343

    None relevant

    BULLETIN DETAIL


    Secunia Bulletin

    back  [SA32987] RadAsm ".rap" Processing Buffer Overflow Vulnerability

    Critical:  Highly critical
    Where: From remote
    Impact: System access
    Released: 2008-12-04

    Data_Sniper has discovered a vulnerability in RadAsm, which can be exploited by malicious people to compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/32987/


    back  [SA33000] MailingListPro Database Disclosure Security Issue

    Critical:  Moderately critical
    Where: From remote
    Impact: Exposure of sensitive information
    Released: 2008-12-04

    AlpHaNiX has reported a security issue in MailingListPro, which can be exploited by malicious people to disclose sensitive information.

    Full Advisory:
    http://secunia.com/advisories/33000/


    back  [SA32988] Rae Media Contact Management Software "Password" SQL Injection

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass, Manipulation of data
    Released: 2008-12-04

    b3hz4d has reported a vulnerability in Rae Media Contact Management Software, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32988/


    back  [SA32941] Active Trade "username" and "password" SQL Injection Vulnerabilities

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass, Manipulation of data
    Released: 2008-12-01

    R3d D3v!L has reported some vulnerabilities in Active Trade, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32941/


    back  [SA32930] Ocean12 FAQ Manager Pro "ID" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2008-12-01

    Stack has reported a vulnerability in Ocean12 FAQ Manager Pro, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32930/


    back  [SA32929] Ocean12 Mailing List Manager Gold Multiple Vulnerabilities

    Critical:  Moderately critical
    Where: From remote
    Impact: Cross Site Scripting, Manipulation of data, Exposure of
    sensitive information
    Released: 2008-12-03

    Pouya_Server has reported some vulnerabilities in Ocean12 Mailing List Manager Gold, which can be exploited by malicious users and people to conduct SQL injection attacks and by malicious people to conduct cross-site scripting attacks and disclose sensitive information.

    Full Advisory:
    http://secunia.com/advisories/32929/


    back  [SA32928] ASPReferral "AccountID" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2008-12-01

    ((r3d D3v!L)) has reported a vulnerability in ASPReferral, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32928/


    back  [SA32927] Active eWebquiz "useremail" and "password" SQL Injection Vulnerabilities

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data, Security Bypass
    Released: 2008-12-01

    R3d D3v!L has reported some vulnerabilities in Active eWebquiz, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32927/


    back  [SA32922] Active Votes "AccountID" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2008-12-01

    R3d D3v!L has reported a vulnerability in Active Votes, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32922/


    back  [SA32921] Active Products "password" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass, Manipulation of data
    Released: 2008-12-01

    R3d-D3v!L has reported some vulnerabilities in multiple Active products, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32921/


    back  [SA32920] Active Bids "ItemID" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2008-12-01

    Stack has reported a vulnerability in Active Bids, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32920/


    back  [SA32976] Gallery MX "ID" SQL Injection Vulnerability

    Critical:  Less critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2008-12-04

    R3d D3v!L has reported a vulnerability in Gallery MX, which can be exploited by malicious users to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32976/


    back  [SA32973] Calendar Mx Professional "ID" SQL Injection Vulnerability

    Critical:  Less critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2008-12-04

    R3d D3v!L has reported a vulnerability in Calendar Mx Professional, which can be exploited by malicious users to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32973/


    back  [SA32940] Microsoft Office Communications Server SIP INVITE Denial of Service

    Critical:  Less critical
    Where: From remote
    Impact: DoS
    Released: 2008-12-01

    A vulnerability has been reported in Microsoft Office Communications Server, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/32940/


    back  [SA32963] Ubuntu update for imlib2

    Critical:  Highly critical
    Where: From remote
    Impact: DoS, System access
    Released: 2008-12-03

    Ubuntu has issued an update for imlib2. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise an application using the library.

    Full Advisory:
    http://secunia.com/advisories/32963/


    back  [SA32962] Gentoo update for optipng

    Critical:  Highly critical
    Where: From remote
    Impact: DoS, System access
    Released: 2008-12-03

    Gentoo has issued an update for optipng. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/32962/


    back  [SA32949] Debian update for imlib2

    Critical:  Highly critical
    Where: From remote
    Impact: DoS, System access
    Released: 2008-12-01

    Debian has issued an update for imlib2. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise an application using the library.

    Full Advisory:
    http://secunia.com/advisories/32949/


    back  [SA32979] PowerDNS CH HINFO Denial of Service Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: DoS
    Released: 2008-12-04

    A vulnerability has been reported in PowerDNS, which can be exploited by malicious people to cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/32979/


    back  [SA32975] Gentoo update for mantisbt

    Critical:  Moderately critical
    Where: From remote
    Impact: Exposure of sensitive information, System access
    Released: 2008-12-03

    Gentoo has issued an update for mantisbt. This fixes a security issue and a vulnerability, which can be exploited by malicious users to disclose potentially sensitive information and compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/32975/


    back  [SA32974] Gentoo update for libxml2

    Critical:  Moderately critical
    Where: From remote
    Impact: DoS, System access
    Released: 2008-12-03

    Gentoo has issued an update to libxml2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.

    Full Advisory:
    http://secunia.com/advisories/32974/


    back  [SA32972] Gentoo update for lighttpd

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass, Exposure of sensitive information, DoS
    Released: 2008-12-03

    Gentoo has issued an update for lighttpd. This fixes a weakness and two vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, bypass certain security restrictions, and cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/32972/


    back  [SA32971] Gentoo update for ipsec-tools

    Critical:  Moderately critical
    Where: From remote
    Impact: DoS
    Released: 2008-12-03

    Gentoo has issued an update for ipsec-tools. This fixes some vulnerabilities, which can be exploited by malicious users and malicious people to cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/32971/


    back  [SA32970] Gentoo update for enscript

    Critical:  Moderately critical
    Where: From remote
    Impact: System access
    Released: 2008-12-03

    Gentoo has issued an update for enscript. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/32970/


    back  [SA32948] Slackware update for ruby

    Critical:  Moderately critical
    Where: From remote
    Impact: Spoofing
    Released: 2008-12-01

    Slackware has issued an update for ruby. This fixes a vulnerability, which can be exploited by malicious people to conduct spoofing attacks.

    Full Advisory:
    http://secunia.com/advisories/32948/


    back  [SA32946] Ubuntu update for libvorbis

    Critical:  Moderately critical
    Where: From remote
    Impact: DoS, System access
    Released: 2008-12-02

    Ubuntu has issued an update for libvorbis. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise an application using the library.

    Full Advisory:
    http://secunia.com/advisories/32946/


    back  [SA32945] Ubuntu update for imagemagick

    Critical:  Moderately critical
    Where: From remote
    Impact: DoS, System access
    Released: 2008-12-02

    Ubuntu has issued an update for imagemagick. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/32945/


    back  [SA32944] Debian update for wireshark

    Critical:  Moderately critical
    Where: From remote
    Impact: Exposure of sensitive information, DoS
    Released: 2008-12-01

    Debian has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information or cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/32944/


    back  [SA32936] Ubuntu update for clamav

    Critical:  Moderately critical
    Where: From remote
    Impact: DoS
    Released: 2008-12-03

    Ubuntu has issued an update for clamav. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/32936/


    back  [SA32934] WebGUI Executable Attachments Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: System access
    Released: 2008-12-03

    A vulnerability has been reported in WebGUI, which can be exploited by malicious people to compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/32934/


    back  [SA32926] ClamAV "cli_check_jpeg_exploit()" Denial of Service Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: DoS
    Released: 2008-12-02

    A vulnerability has been reported in ClamAV, which can be exploited by malicious people to cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/32926/


    back  [SA32918] Ubuntu update for kernel

    Critical:  Moderately critical
    Where: From remote
    Impact: Privilege escalation, DoS, System access
    Released: 2008-11-28

    Ubuntu has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions and gain escalated privileges, and by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/32918/


    back  [SA32917] Kolab Server ClamAV Multiple Vulnerabilities

    Critical:  Moderately critical
    Where: From remote
    Impact: DoS, System access
    Released: 2008-12-03

    Some vulnerabilities have been reported in Kolab Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/32917/


    back  [SA33002] Ubuntu update for awstats

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-12-04

    Ubuntu has issued an update for awstats. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks.

    Full Advisory:
    http://secunia.com/advisories/33002/


    back  [SA32966] Fedora update for wordpress

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-12-03

    Fedora has issued an update for wordpress. This fixes a vulnerability, which can be exploited by malicious people to conduct script insertion attacks.

    Full Advisory:
    http://secunia.com/advisories/32966/


    back  [SA32954] Debian update for phpmyadmin

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-12-02

    Debian has issued an update for phpmyadmin. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks.

    Full Advisory:
    http://secunia.com/advisories/32954/


    back  [SA32952] VMware ESX Server update for bzip2

    Critical:  Less critical
    Where: From remote
    Impact: DoS
    Released: 2008-12-03

    VMware has issued an update for VMware ESX Server. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/32952/


    back  [SA32939] Debian update for awstats

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-12-03

    Debian has issued an update for awstats. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks.

    Full Advisory:
    http://secunia.com/advisories/32939/


    back  [SA33003] Ubuntu update for net-snmp

    Critical:  Less critical
    Where: From local network
    Impact: DoS, System access
    Released: 2008-12-04

    Ubuntu has issued an update for net-snmp. This fixes some vulnerabilities, which can be exploited by malicious people to spoof authenticated SNMPv3 packets, cause a DoS (Denial of Service), and compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/33003/


    back  [SA32968] Fedora update for samba

    Critical:  Less critical
    Where: From local network
    Impact: Exposure of sensitive information
    Released: 2008-12-03

    Fedora has issued an update for samba. This fixes a vulnerability, which potentially can be exploited by malicious people to disclose sensitive information.

    Full Advisory:
    http://secunia.com/advisories/32968/


    back  [SA32951] Slackware update for samba

    Critical:  Less critical
    Where: From local network
    Impact: Exposure of sensitive information
    Released: 2008-12-01

    Slackware has issued an update for samba. This fixes a vulnerability, which potentially can be exploited by malicious people to disclose sensitive information.

    Full Advisory:
    http://secunia.com/advisories/32951/


    back  [SA32919] Ubuntu update for samba

    Critical:  Less critical
    Where: From local network
    Impact: Exposure of sensitive information
    Released: 2008-11-28

    Ubuntu has issued an update for samba. This fixes a vulnerability, which potentially can be exploited by malicious people to disclose sensitive information.

    Full Advisory:
    http://secunia.com/advisories/32919/


    back  [SA32980] Debian update for perl

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-12-04

    Debian has issued an update for perl. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/32980/


    back  [SA32977] IBM HMC HTTP TRACE Response Cross-Site Scripting Weakness

    Critical:  Not critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-12-04

    IBM has acknowledged a weakness in IBM HMC, which potentially can be exploited by malicious people to conduct cross-site scripting attacks.

    Full Advisory:
    http://secunia.com/advisories/32977/


    back  [SA32967] Fedora update for lynx

    Critical:  Not critical
    Where: From remote
    Impact: System access
    Released: 2008-12-03

    Fedora has issued an update for lynx. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/32967/


    back  [SA32969] HP-UX Unspecified Local Denial of Service Vulnerability

    Critical:  Not critical
    Where: Local system
    Impact: DoS
    Released: 2008-12-03

    A vulnerability has been reported in HP-UX, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/32969/


    back  [SA32961] Debian update for flamethrower

    Critical:  Not critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-12-02

    Debian has issued an update for flamethrower. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/32961/


    back  [SA32960] DAHDI "ZT_SPANCONFIG" IOCTL Privilege Escalation Vulnerability

    Critical:  Not critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-12-02

    A vulnerability has been reported in DAHDI, which potentially can be exploited by malicious, local users to gain escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/32960/


    back  [SA32959] Debian update for jailer

    Critical:  Not critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-12-01

    Debian has issued an update for jailer. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/32959/


    back  [SA32953] SUSE update for kernel

    Critical:  Not critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-12-03

    SUSE has issued an update for the kernel. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/32953/


    back  [SA32947] Zaptel "ZT_SPANCONFIG" IOCTL Privilege Escalation Vulnerabilities

    Critical:  Not critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-12-02

    Some vulnerabilities have been reported in Zaptel, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and potentially gain escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/32947/


    back  [SA32943] jailer "updatejail" Insecure Temporary Files

    Critical:  Not critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-12-01

    A security issue has been reported in jailer, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/32943/


    back  [SA32933] Linux Kernel PARISC "parisc_show_stack()" Denial of Service

    Critical:  Not critical
    Where: Local system
    Impact: DoS
    Released: 2008-12-04

    A vulnerability has been reported in the Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/32933/


    Other:


    back  [SA32991] Sun Java JDK / JRE Multiple Vulnerabilities

    Critical:  Highly critical
    Where: From remote
    Impact: Security Bypass, Exposure of system information, Exposure
    of sensitive information, DoS, System access
    Released: 2008-12-04

    Some vulnerabilities have been reported in Sun Java, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, cause a DoS (Denial of service), or compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/32991/


    back  [SA32986] Multi SEO phpBB "pfad" File Inclusion Vulnerability

    Critical:  Highly critical
    Where: From remote
    Impact: System access
    Released: 2008-12-04

    NoGe has discovered a vulnerability in Multi SEO phpBB, which can be exploited by malicious people to compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/32986/


    back  [SA32942] VLC Media Player Real Demuxer Integer Overflow Vulnerability

    Critical:  Highly critical
    Where: From remote
    Impact: DoS, System access
    Released: 2008-12-01

    A vulnerability has been discovered in VLC Media Player, which potentially can be exploited by malicious people to compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/32942/


    back  [SA32964] PHP ZipArchive::extractTo() Directory Traversal Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: System access
    Released: 2008-12-04

    Stefan Esser has reported a vulnerability in PHP, which can be exploited by malicious people to compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/32964/


    back  [SA32958] Check Up System for Thai Healthcare "search" SQL Injection

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2008-12-04

    CWH Underground has reported a vulnerability in Check Up System for Thai Healthcare, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32958/


    back  [SA32950] RakhiSoftware Shopping Cart Multiple Vulnerabilities

    Critical:  Moderately critical
    Where: From remote
    Impact: Cross Site Scripting, Manipulation of data, Exposure of
    system information
    Released: 2008-12-01

    Charalambous Glafkos has reported some vulnerabilities in RakhiSoftware Shopping Cart, which can be exploited by malicious people to disclose system information, or to conduct SQL injection and cross-site scripting attacks.

    Full Advisory:
    http://secunia.com/advisories/32950/


    back  [SA32938] Basic PHP CMS "id" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2008-12-01

    CWH Underground has discovered a vulnerability in Basic PHP CMS, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32938/


    back  [SA32932] Bluo CMS "id" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2008-12-01

    The_5p3ctrum has reported a vulnerability in Bluo CMS, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32932/


    back  [SA32931] mvnForum Unspecified Cross-Site Scripting and Request Forgery

    Critical:  Moderately critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-12-03

    Some vulnerabilities have been reported in mvnForum, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks.

    Full Advisory:
    http://secunia.com/advisories/32931/


    back  [SA32925] PHP TV Portal "mid" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2008-12-01

    A vulnerability has been reported in PHP TV Portal, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32925/


    back  [SA32923] Sunbyte e-Flower "id" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2008-12-03

    W4RL0CK has reported a vulnerability in Sunbyte e-Flower, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32923/


    back  [SA32924] CMS Made Simple "cms_language" Cookie Local File Inclusion

    Critical:  Moderately critical
    Where: Local system
    Impact: Exposure of sensitive information
    Released: 2008-12-01

    A vulnerability has been discovered in CMS Made Simple, which can be exploited by malicious people to disclose potentially sensitive information.

    Full Advisory:
    http://secunia.com/advisories/32924/


    back  [SA32996] W3matter RevSense "section" Cross-Site Scripting Vulnerability

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-12-04

    Pouya_Server has reported a vulnerability in W3matter RevSense, which can be exploited by malicious people to conduct cross-site scripting attacks.

    Full Advisory:
    http://secunia.com/advisories/32996/


    back  [SA32985] ImpressCMS Session Fixation Vulnerability

    Critical:  Less critical
    Where: From remote
    Impact: Hijacking
    Released: 2008-12-04

    A vulnerability has been reported in ImpressCMS, which can be exploited by malicious people to conduct session fixation attacks.

    Full Advisory:
    http://secunia.com/advisories/32985/


    back  [SA32978] Drupal Storm Module SQL Injection Vulnerabilities

    Critical:  Less critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2008-12-04

    Jakub Suchy has reported some vulnerabilities in the Storm module for Drupal, which can be exploited by malicious users to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32978/


    back  [SA32957] IBM Rational ClearCase Cross-Site Scripting Vulnerability

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-12-02

    A vulnerability has been reported in IBM Rational ClearCase, which can be exploited by malicious people to conduct cross-site scripting attacks.

    Full Advisory:
    http://secunia.com/advisories/32957/


    back  [SA32937] iNet Orkut Clone "id" SQL Injection and Cross-Site Scripting

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting, Manipulation of data
    Released: 2008-12-03

    d3b4g has reported some vulnerabilities in iNet Orkut Clone, which can be exploited by malicious users to conduct SQL injection attacks and malicious people to conduct cross-site scripting attacks.

    Full Advisory:
    http://secunia.com/advisories/32937/


    back  [SA32935] Movable Type Unspecified Cross-Site Scripting Vulnerability

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-12-03

    A vulnerability has been reported in Movable Type, which can be exploited by malicious people to conduct cross-site scripting attacks.

    Full Advisory:
    http://secunia.com/advisories/32935/


    back  [SA32965] VMware ESX / ESXi Virtual Hardware Memory Corruption Vulnerability

    Critical:  Less critical
    Where: Local system
    Impact: Security Bypass
    Released: 2008-12-03

    A vulnerability has been reported in VMware ESX / ESXi, which can be exploited by malicious, local users to bypass certain security restrictions.

    Full Advisory:
    http://secunia.com/advisories/32965/



CERT Bulletin


back Relevant Products

  • 2000
  • 98
  • BEA
  • Internet
  • Mac
  • Mac OS X
  • Macos
  • Microsoft
  • OS X
  • OSx
  • Opera
  • PuTTY
  • Safari
  • Windows
  • Windows Media
  • XP
  • acrobat
  • adobe
  • anti-virus
  • antivirus
  • apple
  • browser
  • browsers
  • cumulative
  • eudora
  • excel
  • exchange
  • firefox
  • gecko
  • iis
  • internet information server
  • java
  • mozilla
  • netscape
  • novell
  • office
  • osx
  • outlook
  • player
  • powerpoint
  • qualcomm
  • realnetworks
  • realplayer
  • samba
  • symantec
  • thunderbird
  • trend
  • veritas
  • word
  • zone
  • zonealarm