Search   Feed   Browse   Add
Feed items 1 - 10 of 781 for June 2008

Edgeos - New Vulnerabilities

Edgeos - Private-Labeled Vulnerability Assessment Services

RHSA-2008-0504: xorg - (Found June 29, 2008 )

Critical Risk -- Updated xorg-x11-server packages that fix several security issues are now available for Red Hat Enterprise Linux 5. This update has been rated as having important security impact by the Red Hat Security Response Team. X.Org is an open source implementation of the X Window System. It provides basic low-level functionality that full-fledged graphical user interfaces are designed upon. An input validation flaw was discovered in X.org's Security and Record extensions. A...
http://www.edgeos.com/threats/33153

SuSE Security Update: tkimg: fix for vulnerabilities while parsing GIF images. (tkimg-5328) - (Found June 29, 2008 )

Critical Risk -- This update fixes two vulnerabilities while parsing GIFimages. (CVE-2008-0553, CVE-2006-4484)
http://www.edgeos.com/threats/33123

USN615-1 : Evolution vulnerabilities - (Found June 29, 2008 )

Critical Risk -- Alin Rad Pop of Secunia Research discovered that Evolution did notproperly validate timezone data when processing iCalendar attachments.If a user disabled the ITip Formatter plugin and viewed a craftediCalendar attachment, an attacker could cause a denial of service orpossibly execute code with user privileges. Note that the ITipFormatter plugin is enabled by default in Ubuntu. (CVE-2008-1108)Alin Rad Pop of Secunia Research discovered that Evolution did notproperly validate...
http://www.edgeos.com/threats/33124

Akamai Red Swoosh < 3333 Cross-Site Request Forgery Vulnerability - (Found June 29, 2008 )

High Risk -- The remote host is running Akamai Red Swoosh client, which handlessoftware distribution via the Swoosh network. The version of Red Swoosh installed on the remote host includes a webserver that listens on the loopback interface for management commandsand that fails to properly sanitize the HTTP Referer header. Bytricking a user on the affected host into visiting a specially-craftedweb page, an attacker can leverage this issue to cause files fromarbitrary URLs to be downloaded and...
http://www.edgeos.com/threats/33126

IBM WebSphere Application Server < 6.1.0.17 Unspecified Vulnerability - (Found June 29, 2008 )

Critical Risk -- IBM WebSphere Application Server 6.1 before Fix Pack 17 appears to berunning on the remote host. There reportedly is an attribute in aSOAP security header in such versions that may cause a securityexplosure in Web Services applications (PK61315).
http://www.edgeos.com/threats/33127

DB2 < 9 Fix Pack 5 - (Found June 29, 2008 )

Urgent Risk -- According to its version, the installation of DB2 on the remote hostis affected by one or more of the following issues : - There is an unspecified security vulnerability related to a 'DB2FMP' process (IZ20352). - There is an unspecified security vulnerability in a CLR-stored procedure deployment from IBM Database Add-Ins for Visual Studio (JR28432). - The password used to connect to the database can be seen in plaintext in a memory dump (JR27422). - There is a...
http://www.edgeos.com/threats/33128

OpenOffice < 2.4.1 rtl_allocateMemory Integer Overflow Vulnerability - (Found June 29, 2008 )

Critical Risk -- The version of OpenOffice installed on the remote host reportedlycontains an integer overflow vulnerability in 'rtl_allocateMemory()',a custom memory allocation function used by the application. If anattacker can trick a user on the affected system, he can leverage thisissue to execute arbitrary code subject to his privileges.
http://www.edgeos.com/threats/33129

QuickTime < 7.5 (Windows) - (Found June 29, 2008 )

Critical Risk -- The version of QuickTime installed on the remote Windows host is olderthan 7.5. Such versions contain several vulnerabilities : - There are two heap buffer overflows in QuickTime's handling of PICT image files that could result in a program crash or arbitrary code execution (CVE-2008-1581 and CVE-2008-1583). - There is a memory corruption issue in QuickTime's handling of AAC-encoded media content that could result in a program crash or arbitrary code...
http://www.edgeos.com/threats/33130

QuickTime < 7.5 (Mac OS X) - (Found June 29, 2008 )

Critical Risk -- The version of QuickTime installed on the remote Mac OS X host isolder than 7.5. Such versions contain several vulnerabilities : - There is a heap buffer overflow in QuickTime's handling of PICT image files that could result in a program crash or arbitrary code execution (CVE-2008-1583). - There is a memory corruption issue in QuickTime's handling of AAC-encoded media content that could result in a program crash or arbitrary code execution (CVE-2008-1582). .
http://www.edgeos.com/threats/33131

SuSE Security Update: tkimg: fix for vulnerabilities while parsing GIF images. (tkimg-5320) - (Found June 29, 2008 )

Critical Risk -- This update fixes two vulnerabilities while parsing GIFimages. (CVE-2008-0553, CVE-2006-4484)
http://www.edgeos.com/threats/33122
Available Archives
- June (781 items)
Sponsored Links
© 2008 FeedCapsule.com  |  Contact