.:[ packet storm ]:.
                         
know your enemy
know your enemy

 Section:  .. / Last 20 Advisory Files /

 ///  File Name:ie8-forcedtweet.txt
Description:
Microsoft Internet Explorer 8 suffers from a vulnerability that allows an arbitrary web site the ability to force a victim to make tweets.
Author:Chris Evans
File Size:1131
Last Modified:Sep 3 19:25:48 2010
MD5 Checksum:51e26942b1d61bf8696ece2a57b00b66

 ///  File Name:moaub03-trendmicro.pdf
Description:
Month Of Abysssec Undisclosed Bugs - Trend Micro Internet Security Pro 2010 suffers from an Active-X extSetOwner remote code execution vulnerability.
Author:Abysssec,Shahin
Homepage:http://www.abysssec.com/
Related Exploit:moaub-trendmicro.txt
File Size:359668
Last Modified:Sep 3 19:17:17 2010
MD5 Checksum:81b892dac8eb292ac0b50174b0d75657

 ///  File Name:moaub03-visinia.pdf
Description:
Month Of Abysssec Undisclosed Bugs - Visinia version 1.3 suffers from cross site request forgery and local file inclusion vulnerabilities.
Author:Abysssec,Shahin
Homepage:http://www.abysssec.com/
Related Exploit:moaub-visinia.txt
File Size:362975
Last Modified:Sep 3 19:15:33 2010
MD5 Checksum:619881b402da33983acd8bed63e7fe1d

 ///  File Name:googlechrome-corruption.txt
Description:
VUPEN Vulnerability Research Team discovered a high risk vulnerability affecting Google Chrome. The vulnerability is caused by a memory corruption error when processing focus events, which could be exploited by remote attackers to potentially execute arbitrary code by tricking a user into visiting a specially crafted web page. Google Chrome versions prior to 6.0.472.53 are affected.
Author:Matthieu Bonetti
Homepage:http://www.vupen.com/
File Size:2371
Last Modified:Sep 3 19:12:55 2010
MD5 Checksum:d7bb1c9543aec34baff17e3f886116fb

 ///  File Name:dsa-2102-1.txt
Description:
Debian Linux Security Advisory 2102-1 - It has been discovered that in barnowl, a curses-based instant-messaging client, the return codes of calls to the ZPending and ZReceiveNotice functions in libzephyr were not checked, allowing attackers to cause a denial of service (crash of the application), and possibly execute arbitrary code.
Author:Debian
Homepage:http://www.debian.org/security
File Size:5479
Related CVE(s):CVE-2010-2725
Last Modified:Sep 3 19:08:51 2010
MD5 Checksum:de4af2887f97b53bbc11ac63308a1a5c

 ///  File Name:HPSBMA02572-SSRT100082.txt
Description:
HP Security Bulletin - A potential security vulnerability has been identified with HP Operations Agent running on Windows. The vulnerabilities could be exploited locally resulting in an elevation of privileges and remotely allowing execution of arbitrary code.
Homepage:http://www.hp.com/
File Size:6011
Related CVE(s):CVE-2010-3004, CVE-2010-3005
Last Modified:Sep 3 19:04:55 2010
MD5 Checksum:3a249f396673948dfc9c54350c90b961

 ///  File Name:MDVSA-2010-170.txt
Description:
Mandriva Linux Security Advisory 2010-170 - GNU Wget 1.12 and earlier uses a server-provided filename instead of the original URL to determine the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a 3xx redirect to a URL with a.wgetrc filename followed by a 3xx redirect to a URL with a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.
Author:Mandriva
Homepage:http://www.mandriva.com/security/
File Size:5600
Related CVE(s):CVE-2010-2252
Last Modified:Sep 2 23:47:14 2010
MD5 Checksum:1d5d76c35a7524b8752e4dfab043cf0f

 ///  File Name:glsa-201009-01.txt
Description:
Gentoo Linux Security Advisory 201009-1 - An integer overflow vulnerability in wxGTK might enable remote attackers to cause the execution of arbitrary code. wxGTK is prone to an integer overflow error in the wxImage::Create() function in src/common/image.cpp, possibly leading to a heap-based buffer overflow. Versions less than 2.8.10.1-r1 are affected.
Author:Gentoo
Homepage:http://security.gentoo.org
File Size:3040
Related CVE(s):CVE-2009-2369
Last Modified:Sep 2 23:46:38 2010
MD5 Checksum:fdf7e822a65781e0b83fcc9be4491798

 ///  File Name:moaub02-apple.pdf
Description:
Month Of Abysssec Undisclosed Bugs - Apple QuickTime player version 7.6.5 FlashPix NumberOfTiles remote code execution exploit.
Author:Abysssec,Shahin
Homepage:http://www.abysssec.com/
Related Exploit:moaub-quicktime.txt
File Size:154759
Related CVE(s):CVE-2010-0519
Last Modified:Sep 2 23:37:47 2010
MD5 Checksum:e1e2b6f4c40321ac93c73434a39dc229

 ///  File Name:USN-982-1.txt
Description:
Ubuntu Security Notice 982-1 - It was discovered that Wget would use filenames provided by the server when following 3xx redirects. If a user or automated system were tricked into downloading a file from a malicious site, a remote attacker could create the file with an arbitrary name (e.g. .wgetrc), and possibly run arbitrary code.
Author:Ubuntu
Homepage:http://security.ubuntu.com/
File Size:11134
Related CVE(s):CVE-2010-2252
Last Modified:Sep 2 23:15:02 2010
MD5 Checksum:772e3ecddbb0e78f9ad1482e49e5c2b0

 ///  File Name:MDVSA-2010-169.txt
Description:
Mandriva Linux Security Advisory 2010-169 - dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not properly suppress a script's URL in certain circumstances involving a redirect and an error message, which allows remote attackers to obtain sensitive information about script parameters via a crafted HTML document, related to the window.onerror handler. Mozilla Firefox permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote HTTP servers to obtain sensitive information via a crafted document. Various other Mozilla related vulnerabilities have been addressed.
Author:Mandriva
Homepage:http://www.mandriva.com/security/
File Size:74322
Related CVE(s):CVE-2010-2754, CVE-2010-0654, CVE-2010-1213, CVE-2010-2753, CVE-2010-1211
Last Modified:Sep 2 23:08:28 2010
MD5 Checksum:0f02f3eda393e2a0d929deb75ea471a5

 ///  File Name:moaub01-cpanel.pdf
Description:
Month Of Abysssec Undisclosed Bugs - Cpanel suffers from a PHP restriction bypass vulnerability. Versions 11.25 and below are affected.
Author:Abysssec,Shahin
Homepage:http://www.abysssec.com/
Related Exploit:moaub-cpanel.txt
File Size:111765
Last Modified:Sep 1 16:33:24 2010
MD5 Checksum:742e27e87f22754fb5fce6e831b68d44

 ///  File Name:moaub01-adobe.pdf
Description:
Month Of Abysssec Undisclosed Bugs - Adobe Acrobat Reader and Flash Player suffer from a "newclass" invalid pointer vulnerability.
Author:Abysssec,Shahin
Homepage:http://www.abysssec.com/
Related Exploit:moaub-adobenewclass.txt
File Size:141640
Related CVE(s):CVE-2010-1297
Last Modified:Sep 1 16:29:42 2010
MD5 Checksum:fdb5c4d67a6da028140181593899cb19

 ///  File Name:MDVSA-2010-168.txt
Description:
Mandriva Linux Security Advisory 2010-168 - Double free vulnerability in the ssl3_get_key_exchange function in the OpenSSL client in OpenSSL 1.0.0a, 0.9.8, 0.9.7, and possibly other versions, when using ECDH, allows context-dependent attackers to cause a denial of service and possibly execute some sources refer to this as a use-after-free issue. The updated packages have been patched to correct this issue.
Author:Mandriva
Homepage:http://www.mandriva.com/security/
File Size:3636
Related CVE(s):CVE-2010-2939
Last Modified:Sep 1 16:28:29 2010
MD5 Checksum:f0c6c2f4720853cfe16f3b61747fe479

 ///  File Name:macosxparental-bypass.txt
Description:
The parental controls built into the Mac OS X Mail client can be easily bypassed by anyone who knows the email address of the child and his/her parent.
Author:Jonathan Kamens
File Size:4344
Last Modified:Sep 1 16:14:38 2010
MD5 Checksum:a9781fd5642b187fa7ed3b0e9f72ac7f

 ///  File Name:VMSA-2010-0013.txt
Description:
VMware Security Advisory - The service console package cpio is updated to version 2.5-6.RHEL3. The service console package tar is updated to version 1.13.25-16.RHEL3. The service console packages for samba are updated to version samba-3.0.9-1.3E.17vmw, samba-client-3.0.9-1.3E.17vmw and samba-common-3.0.9-1.3E.17vmw. The service console package krb5 is updated to version 1.2.7-72. The service console package perl is updated to version 5.8.0-101.EL3.
Homepage:http://www.vmware.com/
File Size:10502
Related CVE(s):CVE-2005-4268, CVE-2010-0624, CVE-2010-0624, CVE-2010-2063, CVE-2010-1321, CVE-2010-1168, CVE-2010-1447
Last Modified:Sep 1 13:39:58 2010
MD5 Checksum:b09485d6be1c4762b45d7696cf3e5929

 ///  File Name:MDVSA-2010-167.txt
Description:
Mandriva Linux Security Advisory 2010-167 - lwp-download in libwww-perl before 5.835 does not reject downloads to filenames that begin with a. character, which allows remote servers to create or overwrite files via a 3xx redirect to a URL with a crafted filename or a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.
Author:Mandriva
Homepage:http://www.mandriva.com/security/
File Size:5605
Related CVE(s):CVE-2010-2253
Last Modified:Sep 1 13:36:21 2010
MD5 Checksum:a51472767c3f02ea5ccf9de1e8f2c8ef

 ///  File Name:dsa-2101-1.txt
Description:
Debian Linux Security Advisory 2101-1 - Several implementation errors in the dissector of the Wireshark network traffic analyzer for the ASN.1 BER protocol and in the SigComp Universal Decompressor Virtual Machine may lead to the execution of arbitrary code.
Author:Debian
Homepage:http://www.debian.org/security
File Size:11187
Related CVE(s):CVE-2010-2994, CVE-2010-2995
Last Modified:Aug 31 19:55:01 2010
MD5 Checksum:9e4517c5c11a2c8679174a546d3783a4

 ///  File Name:apphp-xssxsrf.txt
Description:
ApPHP suffers from cross site request forgery and cross site scripting vulnerabilities.
Author:Edgard Chammas
File Size:827
Last Modified:Aug 31 19:50:07 2010
MD5 Checksum:98d1db1212daa5664ef8d0e3227ebf09

 ///  File Name:HPSBMA02571-SSRT100034.txt
Description:
HP Security Bulletin - A potential security vulnerability has been identified with HP Insight Diagnostics Online Edition running on Linux. The vulnerability could be exploited remotely resulting in cross site scripting (XSS).
Homepage:http://www.hp.com/
File Size:6111
Related CVE(s):CVE-2010-3003
Last Modified:Aug 31 14:49:21 2010
MD5 Checksum:4e1948b4fa0864277f76dc2ab1b3e3e0