SecuriTeam Vulnerabilities

Syndicate content SecuriTeam.com
Beyond Security will help you expose your security holes and will show you what the bad guys already know about your hosts and network. Use our Automated Scanning service to perform a full security audit of your site, and find the latest security news and tools on Beyond Security's SecuriTeam web site.
Updated: 9 weeks 21 hours ago

Vulnerability in Server Service Allows Code Execution (MS08-067, PoC)

Fri, 2008-10-24 11:15
The following exploit code will simulate the MS08-067 vulnerability and cause the Server service to fail on vulnerable Windows systems.

-

Make your website safer. Use external penetration testing service. First report ready in one hour!

EMC NetWorker Denial of Service Vulnerability

Thu, 2008-10-23 09:17
A resource exhaustion vulnerability exists throughout multiple EMC products through an exploited RPC interface.

-

Make your website safer. Use external penetration testing service. First report ready in one hour!

Multiple Vulnerabilities in Cisco PIX and Cisco ASA

Thu, 2008-10-23 09:11
Multiple vulnerabilities exist in the Cisco ASA 5500 Series Adaptive Security Appliances and Cisco PIX Security Appliances. This security advisory outlines details of these vulnerabilities: * ...

-

Make your website safer. Use external penetration testing service. First report ready in one hour!

Veritas Storage Foundation Arbitrary File Read Vulnerability

Thu, 2008-10-23 09:02
Veritas Storage Foundation 5.0 from Symantec provides "a complete solution for heterogeneous online storage management. Based on the industry-leading Veritas Volume Manager and Veritas File System,...

-

Make your website safer. Use external penetration testing service. First report ready in one hour!

HP OpenView Products Shared Trace Service Denial of Service

Thu, 2008-10-23 08:57
Secunia Research has discovered a vulnerability in various HP products, which can be exploited by malicious people to cause a DoS (Denial of Service).

-

Make your website safer. Use external penetration testing service. First report ready in one hour!

Achieving Persistent HTML Injection via SNMP on Embedded Devices

Thu, 2008-10-23 08:49
A new approach to introducing HTML and/or JavaScript vulnerabilities into devices has been found, this new approach utilizes SNMP write capabilities to inject the malicious content into the device,...

-

Make your website safer. Use external penetration testing service. First report ready in one hour!

Vulnerability in Server Service Allows Code Execution (MS08-067)

Wed, 2008-10-22 16:20
This security update resolves a privately reported vulnerability in the Server service. The vulnerability could allow remote code execution if an affected system received a specially crafted RPC re...

-

Make your website safer. Use external penetration testing service. First report ready in one hour!

Opera Stored Cross Site Scripting Vulnerability

Wed, 2008-10-22 10:50
Opera browser is vulnerable to stored Cross Site Scripting. A malicious attacker is able to inject arbitrary browser content through the websites visited with the Opera browser. The code injection ...

-

Make your website safer. Use external penetration testing service. First report ready in one hour!

iaxscan - IAX/2 Host Scanner

Mon, 2008-10-20 01:50

-

Make your website safer. Use external penetration testing service. First report ready in one hour!

GearSoftware Powered Products Local Privilege Escalation (IopfCompleteRequest)

Mon, 2008-10-20 01:01
"GEAR Software has set the standard for professional DVD & CD recording software for more than twenty years. GEAR develops solutions for professional premastering, DVD editing and authoring, and is...

-

Make your website safer. Use external penetration testing service. First report ready in one hour!

Graphviz Buffer Overflow Code Execution

Mon, 2008-10-20 00:51
Graphviz is "an open-source multi-platform graph visualization software. It takes a description of graphs in a simple text format (DOT language), and makes diagrams out of it in several useful form...

-

Make your website safer. Use external penetration testing service. First report ready in one hour!

Novell eDirectory Multiple Vulnerabilities (dhost.exe)

Mon, 2008-10-20 00:48
Multiple vulnerabilities have been discovered in Novell's eDirectory's dhost.exe service, these vulnerabilities would allow an attacker to overflow internal buffers used by the product which can be...

-

Make your website safer. Use external penetration testing service. First report ready in one hour!

Marvell Driver Malformed Association Request Vulnerability

Mon, 2008-10-20 00:35
The wireless drivers in some Wi-Fi access points (such as the MARVELL-based Linksys WAP4400N) do not correctly parse some malformed 802.11 frames.

-

Make your website safer. Use external penetration testing service. First report ready in one hour!

Sun Solstice AdminSuite sadmind adm_build_path() Buffer Overflow Vulnerability

Mon, 2008-10-20 00:34
There exists a vulnerability within a function of the Sun Solstice AdminSuite sadmind, which when properly exploited can lead to remote compromise of the vulnerable system. This vulnerability was c...

-

Make your website safer. Use external penetration testing service. First report ready in one hour!

Telecom Italia Alice Pirelli Routers Backdoor Activates Telnet/FTP/TFTP

Mon, 2008-10-20 00:31
An embedded backdoor allows activation of the telnet/FTP/TFTP/web extended admin interface service with Admin privileges, from internal network LAN on Alice ADSL CPE Modem/Router, manufactered by P...

-

Make your website safer. Use external penetration testing service. First report ready in one hour!

Microsoft Windows AFD.sys Privilege Escalation (Kartoffel Plugin, Exploit, MS08-066)

Thu, 2008-10-16 09:29
Kartoffel is a extensible command-line tool developed with the aim of helping developers to test the security and the reliability of a driver. The following exploit code will use Kartoffel to explo...

-

Make your website safer. Use external penetration testing service. First report ready in one hour!

Token Kidnapping Windows 2003 (Exploit)

Mon, 2008-10-13 06:00
A vulnerability in the way Windows 2003 handles security tokens allow local attackers that are able to execute code to gain elevated privileges by kidnapping an existing token and using it for thei...

-

Make your website safer. Use external penetration testing service. First report ready in one hour!

GuildFTPd CWD and LIST Heap Corruption PoC/DoS (Exploit)

Mon, 2008-10-13 04:39
A vulnerability in GuildFTPd allows remote attackers to cause the server to overflow its allocated heap causing the corruption of the registers during the release of the memory allocated in the hea...

-

Make your website safer. Use external penetration testing service. First report ready in one hour!

NoticeWare E-mail Sever (POP3) Pre-Auth DoS

Sun, 2008-10-12 09:46
NoticeWare E-mail Server has been found to be vulnerable to attack which consists of sending it an overflowing password with a valid username.

-

Make your website safer. Use external penetration testing service. First report ready in one hour!

Apache Tomcat Information Disclosure (RemoteFilterValve)

Sun, 2008-10-12 08:31
Tomcat can, in very rare circumstances, permit a user from a non-permitted IP address to gain access to a context protected with a valve that extends RemoteFilterValve.

-

Make your website safer. Use external penetration testing service. First report ready in one hour!