vulnerabilities

News

Vuln: Scalable Vector Graphics (SVG) Arbitrary Code Execution Vulnerability
Scalable Vector Graphics (SVG) Arbitrary Code Execution Vulnerability
securityfocus.com | 21-May-2012 02:00

Bugtraq: H2HC Brazil 9th Edition - Call for Papers
H2HC Brazil 9th Edition - Call for Papers
securityfocus.com | 19-May-2012 00:10

Bugtraq: SEC Consult SA-20120518 :: Memory overwrite vulnerability in libwpd (OpenOffice.org) - CVE-2012-2149
SEC Consult SA-20120518 :: Memory overwrite vulnerability in libwpd (OpenOffice.org) - CVE-2012-2149
securityfocus.com | 18-May-2012 23:55

Bugtraq: Re: [oss-security] CVE Request: Planeshift buffer overflow
Re: [oss-security] CVE Request: Planeshift buffer overflow
securityfocus.com | 18-May-2012 23:40

Bugtraq: Re: [oss-security] CVE Request: Planeshift buffer overflow
Re: [oss-security] CVE Request: Planeshift buffer overflow
securityfocus.com | 18-May-2012 23:25

Vuln: Hewlett-Packard Virtual SAN Appliance 'hydra.exe' Remote Buffer Overflow Vulnerability
Hewlett-Packard Virtual SAN Appliance 'hydra.exe' Remote Buffer Overflow Vulnerability
securityfocus.com | 18-May-2012 02:00

CVE-2012-2337
sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.
nvd.nist.gov | 18-May-2012 02:00

CVE-2012-2406
RealNetworks RealPlayer before 15.0.4.53, and RealPlayer SP 1.0 through 1.1.5, does not properly parse ASMRuleBook data in RealMedia files, which allows remote attackers to execute arbitrary code via a crafted file.
nvd.nist.gov | 18-May-2012 02:00

CVE-2012-2411
Buffer overflow in RealNetworks RealPlayer before 15.0.4.53, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted RealJukebox Media file.
nvd.nist.gov | 18-May-2012 02:00

CVE-2012-1589
Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted parameters in a destination URL.
nvd.nist.gov | 18-May-2012 02:00

CVE-2012-2010
The ACMELOGIN implementation in HP OpenVMS 8.3 and 8.4 on the Alpha platform, and 8.3, 8.3-1H1, and 8.4 on the Itanium platform, when the SYS$ACM system service is enabled, allows local users to gain privileges via unspecified vectors.
nvd.nist.gov | 18-May-2012 02:00

Vuln: Linux Kernel KVM 'kvm_apic_accept_pic_intr()' Function Local Denial of Service Vulnerability
Linux Kernel KVM 'kvm_apic_accept_pic_intr()' Function Local Denial of Service Vulnerability
securityfocus.com | 18-May-2012 02:00

Vuln: pidgin-otr 'log_message_cb()' Function Format String Vulnerability
pidgin-otr 'log_message_cb()' Function Format String Vulnerability
securityfocus.com | 18-May-2012 02:00

Vuln: HP OpenVMS Integrity Server Unspecified Local Privilege Escalation Vulnerability
HP OpenVMS Integrity Server Unspecified Local Privilege Escalation Vulnerability
securityfocus.com | 18-May-2012 02:00

CVE-2012-2120
latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
nvd.nist.gov | 18-May-2012 02:00

CVE-2012-2341
Cross-site request forgery (CSRF) vulnerability in the Take Control module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to hijack the authentication of unspecified users for Ajax requests that manipulate files.
nvd.nist.gov | 18-May-2012 02:00

CVE-2012-2322
Integer overflow in the dhcpv6_get_option function in gdhcp/client.c in ConnMan before 0.85 allows remote attackers to cause a denial of service (infinite loop and crash) via an invalid length value in a DHCP packet.
nvd.nist.gov | 18-May-2012 02:00

CVE-2012-2321
The loopback plug-in in ConnMan before 0.85 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) host name or (2) domain name in a DHCP reply.
nvd.nist.gov | 18-May-2012 02:00

CVE-2012-2320
ConnMan before 0.85 does not ensure that netlink messages originate from the kernel, which allows remote attackers to bypass intended access restrictions and cause a denial of service via a crafted netlink message.
nvd.nist.gov | 18-May-2012 02:00

CVE-2012-2118
Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibly execute arbitrary code via format string specifiers in an input device name.
nvd.nist.gov | 18-May-2012 02:00

CVE-2012-2093
src/common/latex.py in Gajim 0.15 allows local users to overwrite arbitrary files via a symlink attack on a temporary latex file, related to the get_tmpfile_name function.
nvd.nist.gov | 18-May-2012 02:00

Bugtraq: [security bulletin] HPSBUX02782 SSRT100844 rev.1 - HP-UX Running OpenSSL, Remote Denial of
[security bulletin] HPSBUX02782 SSRT100844 rev.1 - HP-UX Running OpenSSL, Remote Denial of
securityfocus.com | 18-May-2012 00:09

Bugtraq: [security bulletin] HPSBUX02777 SSRT100854 rev.1 - HP-UX Running Java JRE and JDK, Remote Denial
[security bulletin] HPSBUX02777 SSRT100854 rev.1 - HP-UX Running Java JRE and JDK, Remote Denial
securityfocus.com | 17-May-2012 23:54

Bugtraq: [ MDVSA-2012:078 ] imagemagick
[ MDVSA-2012:078 ] imagemagick
securityfocus.com | 17-May-2012 23:39

Bugtraq: [ MDVSA-2012:077 ] imagemagick
[ MDVSA-2012:077 ] imagemagick
securityfocus.com | 17-May-2012 23:24

CVE-2012-1179 (linux_kernel)
The Linux kernel before 3.3.1, when KVM is used, allows guest OS users to cause a denial of service (host OS crash) by leveraging administrative access to the guest OS, related to the pmd_none_or_clear_bad function and page faults for huge pages.
nvd.nist.gov | 17-May-2012 02:00

CVE-2012-1601 (linux_kernel)
The KVM implementation in the Linux kernel before 3.3.6 allows host OS users to cause a denial of service (NULL pointer dereference and host OS crash) by making a KVM_CREATE_IRQCHIP ioctl call after a virtual CPU already exists.
nvd.nist.gov | 17-May-2012 02:00

CVE-2012-2121 (linux_kernel)
The KVM implementation in the Linux kernel before 3.3.4 does not properly manage the relationships between memory slots and the iommu, which allows guest OS users to cause a denial of service (host OS crash) by leveraging administrative access to the guest OS to conduct hotunplug and hotplug operations on devices.
nvd.nist.gov | 17-May-2012 02:00

CVE-2012-2123 (linux_kernel)
The cap_bprm_set_creds function in security/commoncap.c in the Linux kernel before 3.3.3 does not properly handle the use of file system capabilities (aka fcaps) for implementing a privileged executable file, which allows local users to bypass intended personality restrictions via a crafted application, as demonstrated by an attack that uses a parent process to disable ASLR.
nvd.nist.gov | 17-May-2012 02:00

CVE-2012-2319 (linux_kernel)
Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3.3.5 allow local users to gain privileges via a crafted HFS plus filesystem, a related issue to CVE-2009-4020.
nvd.nist.gov | 17-May-2012 02:00

CVE-2012-1146 (linux_kernel)
The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are attached to the same eventfd, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by registering memory threshold events.
nvd.nist.gov | 17-May-2012 02:00

Vuln: RETIRED: EMC Documentum Information Rights Management (IRM) Server Denial of Service Vulnerabilities
RETIRED: EMC Documentum Information Rights Management (IRM) Server Denial of Service Vulnerabilities
securityfocus.com | 17-May-2012 02:00

Vuln: EMC Documentum Information Rights Management (IRM) Server Multiple Denial of Service Vulnerabilities
EMC Documentum Information Rights Management (IRM) Server Multiple Denial of Service Vulnerabilities
securityfocus.com | 17-May-2012 02:00

CVE-2012-1097 (linux_kernel)
The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a (1) PTRACE_GETREGSET or (2) PTRACE_SETREGSET ptrace call.
nvd.nist.gov | 17-May-2012 02:00

CVE-2012-1090 (linux_kernel)
The cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10 allows local users to cause a denial of service (OOPS) via attempted access to a special file, as demonstrated by a FIFO.
nvd.nist.gov | 17-May-2012 02:00

CVE-2012-0879 (linux_kernel)
The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple processes that share an I/O context.
nvd.nist.gov | 17-May-2012 02:00

CVE-2011-4594 (linux_kernel)
The __sys_sendmsg function in net/socket.c in the Linux kernel before 3.1 allows local users to cause a denial of service (system crash) via crafted use of the sendmmsg system call, leading to an incorrect pointer dereference.
nvd.nist.gov | 17-May-2012 02:00

CVE-2011-3637 (linux_kernel)
The m_stop function in fs/proc/task_mmu.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (OOPS) via vectors that trigger an m_start error.
nvd.nist.gov | 17-May-2012 02:00

CVE-2011-4097 (linux_kernel)
Integer overflow in the oom_badness function in mm/oom_kill.c in the Linux kernel before 3.1.8 on 64-bit platforms allows local users to cause a denial of service (memory consumption or process termination) by using a certain large amount of memory.
nvd.nist.gov | 17-May-2012 02:00

CVE-2011-4112 (linux_kernel)
The net subsystem in the Linux kernel before 3.1 does not properly restrict use of the IFF_TX_SKB_SHARING flag, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability to access /proc/net/pktgen/pgctrl, and then using the pktgen package in conjunction with a bridge device for a VLAN interface.
nvd.nist.gov | 17-May-2012 02:00

CVE-2011-4131 (linux_kernel)
The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words.
nvd.nist.gov | 17-May-2012 02:00

CVE-2011-4326 (linux_kernel)
The udp6_ufo_fragment function in net/ipv6/udp.c in the Linux kernel before 2.6.39, when a certain UDP Fragmentation Offload (UFO) configuration is enabled, allows remote attackers to cause a denial of service (system crash) by sending fragmented IPv6 UDP packets to a bridge device.
nvd.nist.gov | 17-May-2012 02:00

CVE-2011-4611 (linux_kernel)
Integer overflow in the perf_event_interrupt function in arch/powerpc/kernel/perf_event.c in the Linux kernel before 2.6.39 on powerpc platforms allows local users to cause a denial of service (unhandled performance monitor exception) via vectors that trigger certain outcomes of performance events.
nvd.nist.gov | 17-May-2012 02:00

CVE-2011-4621 (linux_kernel)
The Linux kernel before 2.6.37 does not properly implement a certain clock-update optimization, which allows local users to cause a denial of service (system hang) via an application that executes code in a loop.
nvd.nist.gov | 17-May-2012 02:00

CVE-2012-0038 (linux_kernel)
Integer overflow in the xfs_acl_from_disk function in fs/xfs/xfs_acl.c in the Linux kernel before 3.1.9 allows local users to cause a denial of service (panic) via a filesystem with a malformed ACL, leading to a heap-based buffer overflow.
nvd.nist.gov | 17-May-2012 02:00

CVE-2012-0044 (linux_kernel)
Integer overflow in the drm_mode_dirtyfb_ioctl function in drivers/gpu/drm/drm_crtc.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.1.5 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted ioctl call.
nvd.nist.gov | 17-May-2012 02:00

RSS and Atom feeds and forum posts belong to their respective owners.