SecurityFocus Newsletter #357

Peter Laborge <[email protected]> Tue, 04 Jul 2006 14:01:49 -0600
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #357
----------------------------------------

This issue is Sponsored by: Watchfire

Methodologies & Tools for Web Application Security Assessment
With the rapid rise in the number and types of security threats, web application security assessments should be considered a crucial phase in the development of any web application. What methodology should be followed? What tools can accelerate the assessment process? See for yourself. Download this Whitepaper today!

https://www.watchfire.com/securearea/whitepapers.aspx?id=701500000008VmX

------------------------------------------------------------------
I.    FRONT AND CENTER
        1. MySpace, a place without MyParents
        2. Strider URL Tracer with Typo Patrol
II.   BUGTRAQ SUMMARY
        1. WordPress Paged Parameter SQL Injection Vulnerability
        2. Communigate Pro Server Pop Denial of Service Vulnerability
        3. Vincent Leclercq News Cross-Site Scripting Vulnerabilities
        4. Microsoft Internet Explorer ADODB.Recordset Filter Property Denial of Service Vulnerability
        5. MoniWiki Wiki.PHP Cross-Site Scripting Vulnerability
        6. LibWMF WMF File Handling Integer Overflow Vulnerability
        7. Plume CMS DBInstall.PHP Remote File Include Vulnerability
        8. EZWaiter Cross-site Scripting Vulnerability
        9. HP-UX Mkdir Local Unauthorized Access Vulnerability
        10. HP-UX Passwd Unspecified Local Denial of Service Vulnerability
        11. GnuPG Parse_User_ID Remote Buffer Overflow Vulnerability
        12. DHCDBD Remote Denial of Service Vulnerability
        13. KDE ArtsWrapper Local Privilege Escalation Vulnerability
        14. Asterisk IAX2 Remote Buffer Overflow Vulnerability
        15. wv2 Remote Buffer Overflow Vulnerability
        16. Lincoln D. Stein Crypt::CBC Perl Module Weak Ciphertext Vulnerability
        17. AstroDog Press Some Chess Board.PHP SQL Injection Vulnerability
        18. FineShop Multiple Input Validation Vulnerabilities
        19. Webmin/Usermin Unspecifed Information Disclosure Vulnerability
        20. IAXClient Multiple Truncated IAX Frames Remote Buffer Overflow Vulnerabilities
        21. Apple iTunes AAC File Parsing Integer Overflow Vulnerability
        22. Opera Malicious HTML Processing Denial of Service Vulnerability
        23. Joomla! Multiple Input Validation Vulnerabilities
        24. Retired: Mozilla Firefox OuterHTML Redirection Handling Information Disclosure Vulnerability
        25. Stud.IP Multiple Remote File Include Vulnerabilities
        26. Geeklog Multiple Remote File Include Vulnerabilities
        27. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
        28. Microsoft Excel Unspecified Remote Code Execution Vulnerability
        29. Microsoft Internet Explorer OutlookExpress.AddressBook Denial of Service Vulnerability
        30. Microsoft Internet Explorer HHCtrl ActiveX Control Memory Corruption Vulnerability
        31. PHPFormGenerator Arbitrary File Upload Vulnerability
        32. Geeklog Connector.PHP Arbitrary File Upload Vulnerability
        33. BXCP Index.PHP SQL Injection Vulnerability
        34. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
        35. Microsoft HLINK.DLL Link Memory Corruption Vulnerability
        36. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
        37. Apple Mac OS X LaunchD Local Format String Vulnerability
        38. SturGeoN Upload Arbitrary File Upload Vulnerability
        39. deV!Lz Clanportal ID Parameter SQL Injection Vulnerability
        40. Randshop Header.Inc.PHP Remote File Include Vulnerability
        41. mAds Search Cross-site Scripting Vulnerability
        42. Diesel Joke Site Category.PHP SQL Injection Vulnerability
        43. Toshiba Bluetooth Stack Object Push Service File Upload Directory Traversal Vulnerability
        44. Adobe Reader Multiple Unspecified Security Vulnerabilities
        45. Buddy Zone Multiple HTML Injection Vulnerabilities
        46. Toshiba Bluetooth Stack TOSRFBD.SYS Remote Denial of Service Vulnerability
        47. Opera Document Stylesheet Denial Of Service Vulnerability
        48. Noweb Insecure Temporary File Creation Vulnerability
        49. MyNewsGroups Tree.PHP SQL Injection Vulnerability
        50. SiteBuilder-FX Top.PHP Remote File Include Vulnerability
        51. Microsoft Windows TCP/IP Protocol Driver Remote Buffer Overflow Vulnerability
        52. Linux Kernel Netfilter Conntrack_Proto_SCTP.C Denial of Service Vulnerability
        53. NASCAR Racing UDP Datagram Remote Denial of Service Vulnerability
        54. PHPMyAdmin Table Parameter Cross-site Scripting Vulnerability
        55. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
        56. Multiple Mozilla Products IFRAME JavaScript Execution Vulnerability
        57. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
        58. Efone Config.INC Information Disclosure Vulnerability
        59. Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
        60. Mozilla Thunderbird Multiple Remote Information Disclosure Vulnerabilities
        61. Hobbit Monitor Logfetch Information Disclosure Vulnerability
        62. Mozilla Firefox iframe.contentWindow.focus Deleted Object Reference Vulnerability
        63. PostNuke Multiple Cross-Site Scripting Vulnerabilities
        64. Taskjitsu Multiple HTML Injection Vulnerabilities
        65. Eupla Foros Config.INC Information Disclosure Vulnerability
        66. Kamikaze-QSCM Config.INC Information Disclosure Vulnerability
        67. Randshop Index.PHP Remote File Include Vulnerability
        68. Galleria Remote File Include Vulnerability
        69. Kyberna AG Ky2help Meine Links SQL Injection Vulnerability
        70. F5 Firepass 4100 SSL VPN Multiple Unspecified Cross-Site Scripting Vulnerabilities
        71. PHPWebGallery Comments.PHP Cross-site Scripting Vulnerability
        72. iPlanet/Sun Java Messaging Server Local Information Disclosure Vulnerability
        73. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
        74. University Of Washington IMAP Mailbox Name Buffer Overflow Vulnerability
        75. Mutt BROWSE_GET_NAMESPACE IMAP Namespace Processing Remote Buffer Overflow Vulnerability
        76. OpenOffice XML File Format Buffer Overflow Vulnerability
        77. OpenOffice Arbitrary Macro Execution Vulnerability
        78. OpenOffice Java Applet System Access Vulnerability
        79. KDE KDM Session Type Symbolic Link Vulnerability
        80. Squirrelmail Redirect.PHP Local File Include Vulnerability
        81. Sendmail Malformed MIME Message Denial Of Service Vulnerability
        82. Ethereal Multiple Protocol Dissector Vulnerabilities In Versions Prior To 0.99.0
        83. Kaspersky Internet Security Suite Multiple Local Vulnerabilities
        84. Randshop Multiple SQL Injection Vulnerabilities
        85. Opera SSL Certificate Spoofing Weakness
        86. Opera Web Browser JPEG Image Handling Remote Buffer Overflow Vulnerability
        87. Pearl Product Multiple Remote File Include Vulnerabilities
        88. AutoRank Multiple Cross-Site Scripting Vulnerabilities
        89. Native Solutions The Banner Engine Top.PHP Cross-site Scripting Vulnerability
        90. Glossaire Remote File Include Vulnerability
        91. QTO File Manager Multiple Cross-Site Scripting Vulnerabilities
        92. VirtuaStore Password Parameter SQL Injection Vulnerability
        93. Zone Labs ZoneAlarm Registry Key Local Denial Of Service Vulnerability
        94. Free QBoard QB_Path Remote File Include Vulnerabilities
        95. PHP-Fusion Avatar Image Edit_profile.PHP HTML Injection Vulnerability
        96. Hiki Diff Denial Of Service Vulnerability
        97. ImgSvr Denial Of Service Vulnerability
        98. Invision Power Board Index.PHP Act Parameter SQL Injection Vulnerability
        99. Plume CMS Multiple Remote File Include Vulnerabilities
        100. Quake 3 Engine Client Multiple Stack Buffer Overflow Vulnerabilities
III.  SECURITYFOCUS NEWS
        1. AT&T privacy policy overreaches, lawyers say
        2. USB drives pose insider threat
        3. SCADA industry debates flaw disclosure
        4. Researchers eye machines to analyze malware
IV.   SECURITY JOBS LIST SUMMARY
        1. [SJ-JOB] Information Assurance Analyst, Tinton Falls
        2. [SJ-JOB] Security Engineer, Schaumburg
        3. [SJ-JOB] Sales Engineer, Atlanta
        4. [SJ-JOB] Security Architect, Richmond
        5. [SJ-JOB] Security Product Manager, Poway
        6. [SJ-JOB] Account Manager, Abingdon, Oxfordshire
        7. [SJ-JOB] Sales Representative, San Jose
        8. [SJ-JOB] Application Security Architect, Poway
        9. [SJ-JOB] VP, Information Security, Warren
        10. [SJ-JOB] Auditor, Washington
        11. [SJ-JOB] Security Engineer, Bangalore
        12. [SJ-JOB] Sr. Security Analyst, New York
        13. [SJ-JOB] Sr. Security Analyst, Summit
        14. [SJ-JOB] Security Architect, Summit
        15. [SJ-JOB] Security Auditor, Baltimore
        16. [SJ-JOB] Quality Assurance, Atlanta
        17. [SJ-JOB] Security Consultant, London or Berkshire
        18. [SJ-JOB] Sr. Security Analyst, New York
        19. [SJ-JOB] Security Consultant, Baltimore
        20. [SJ-JOB] Security Auditor, Almere
        21. [SJ-JOB] Jr. Security Analyst, Boston
        22. [SJ-JOB] Management, Statewide
        23. [SJ-JOB] Security Consultant, VA/MD/DC
        24. [SJ-JOB] Auditor, Baltimore
        25. [SJ-JOB] Security Auditor, Richmond
        26. [SJ-JOB] Security Consultant, Richmond
        27. [SJ-JOB] CHECK Team Leader, London
        28. [SJ-JOB] Technical Support Engineer, Lexington
        29. [SJ-JOB] Security Consultant, London
        30. [SJ-JOB] Security Engineer, Tempe
        31. [SJ-JOB] Security Engineer, Dubai
        32. [SJ-JOB] Security Consultant, Milan
        33. [SJ-JOB] Security Engineer, Providence
        34. [SJ-JOB] Security Consultant, Riyadh
        35. [SJ-JOB] Quality Assurance, Ann Arbor
        36. [SJ-JOB] Sales Engineer, San Francisco
        37. [SJ-JOB] Security Auditor, Washington
        38. [SJ-JOB] Security Consultant, Washington
        39. [SJ-JOB] Security Researcher, Marlborough, MA
        40. [SJ-JOB] Sr. Security Engineer, Schaumburg
        41. [SJ-JOB] Security Consultant, New York
        42. [SJ-JOB] Manager, Information Security, Sparks
        43. [SJ-JOB] Senior Software Engineer, Palo Alto
        44. [SJ-JOB] Security Consultant, Chicago
        45. [SJ-JOB] Security Consultant, New York City
        46. [SJ-JOB] Security Consultant, Bentonville
        47. [SJ-JOB] Channel / Business Development, San Francisco
        48. [SJ-JOB] Security Consultant, San Francisco
        49. [SJ-JOB] Security Consultant, Seattle
        50. [SJ-JOB] Incident Handler, Schaumburg
        51. [SJ-JOB] Sr. Security Analyst, New York
        52. [SJ-JOB] Auditor, Columbus
        53. [SJ-JOB] Security Consultant, Columbus
        54. [SJ-JOB] Auditor, Atlanta
        55. [SJ-JOB] Security Auditor, Columbus
        56. [SJ-JOB] Remediation Security Analyst, Dallas
        57. [SJ-JOB] Security Architect, Valley Forge
        58. [SJ-JOB] Auditor, Dallas
        59. [SJ-JOB] Sr. Security Analyst, Wilmington
        60. [SJ-JOB] Sr. Security Analyst, raleigh
        61. [SJ-JOB] Sr. Security Analyst, Dallas
        62. [SJ-JOB] Associate Software Engineer, Columbia
        63. [SJ-JOB] Security Consultant, Dallas
        64. [SJ-JOB] Security Auditor, Dallas
        65. [SJ-JOB] Senior Software Engineer, Columbia
        66. [SJ-JOB] Security Product Manager, Deerfield Beach / Ft. Lauderdale
        67. [SJ-JOB] Sr. Security Analyst, HERNDON
        68. [SJ-JOB] Security Auditor, Philadelphia
        69. [SJ-JOB] Auditor, Chicago
        70. [SJ-JOB] Security Consultant, Philadelphia
        71. [SJ-JOB] Security Consultant, Chicago
        72. [SJ-JOB] Security Auditor, Chicago
        73. [SJ-JOB] Security Auditor, Raleigh
        74. [SJ-JOB] Auditor, Raleigh
        75. [SJ-JOB] Auditor, Richmond
        76. [SJ-JOB] Security Consultant, Raleigh
        77. [SJ-JOB] Auditor, Philadelphia
        78. [SJ-JOB] Director, Information Security, Boston
        79. [SJ-JOB] Software Engineer, Columbia
        80. [SJ-JOB] Sales Representative, New York
        81. [SJ-JOB] Security Engineer, Seattle
        82. [SJ-JOB] Sales Engineer, Sterling
        83. [SJ-JOB] Account Manager, Toronto
        84. [SJ-JOB] Sr. Security Analyst, Boston
        85. [SJ-JOB] Sales Engineer, Washington
        86. [SJ-JOB] Security Consultant, PA
        87. [SJ-JOB] Sr. Security Analyst, Cleveland
        88. [SJ-JOB] Sr. Security Analyst, Santa Clara
V.    INCIDENTS LIST SUMMARY
        1. suspicious firewall rules in WinXP firewall
        2. Pix 515 - need help identifying possible attack - simultaneous traffic and memory spikes...
VI.   VULN-DEV RESEARCH LIST SUMMARY
        1. IM exploitable vulnerabilities .. any pointers?
        2. Re[2]: Is Windows TCP/IP source routing PoC code available?
        3. SyScan'06 Highlight - Is Phone Banking Safe?
VII.  MICROSOFT FOCUS LIST SUMMARY
        1. SecurityFocus Microsoft Newsletter #296
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. MySpace, a place without MyParents
By Scott Granneman
Scott Granneman looks at the mass hysteria surrounding MySpace social security issues, examines a collection of frightening reports, and then discusses the real issue of parenting and parental supervision behind keeping our children safe.
http://www.securityfocus.com/columnists/408

2. Strider URL Tracer with Typo Patrol
By Tony Bradley, CISSP-ISSAP
This article looks at Microsoft's free Strider URL Tracer with Typo-Patrol to help fight typo-squatters and domain parking abuse. The tool can be used to protect children from seeing inappropriate or explicit sites that they should not see, and for companies or trademark owners to scan and investigate sites that may be typo-squatting their domain(s) so that they can be investigated and/or prosecuted.
http://www.securityfocus.com/infocus/1869


II.  BUGTRAQ SUMMARY
--------------------
1. WordPress Paged Parameter SQL Injection Vulnerability
BugTraq ID: 18779
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18779
Summary:
WordPress is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

This issue affects version 2.0.3; other versions may also be vulnerable.

2. Communigate Pro Server Pop Denial of Service Vulnerability
BugTraq ID: 18770
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18770
Summary:
CommuniGate Pro Server is prone to a remote denial-of-service vulnerability. This issue reportedly resides in the application's Pop component.

3. Vincent Leclercq News Cross-Site Scripting Vulnerabilities
BugTraq ID: 18775
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18775
Summary:
Vincent Leclercq News is prone to multiple cross-site scripting vulnerability because it fails to properly sanitize user-supplied input before displaying it to users of the application.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

4. Microsoft Internet Explorer ADODB.Recordset Filter Property Denial of Service Vulnerability
BugTraq ID: 18773
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18773
Summary:
Microsoft Internet Explorer is prone to a denial-of-service condition when processing the 'ADODB.Recordset Filter Property' COM object.

A successful attack may cause the browser to fail due to a null-pointer dereference.

5. MoniWiki Wiki.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 11516
Remote: Yes
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/11516
Summary:
MoniWiki is reported prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied URI input before including it in dynamic web page content.

This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the browser of the victim user. This would occur in the security context of the affected website and may allow the attacker to steal cookie-based authentication credentials or launch other attacks.

6. LibWMF WMF File Handling Integer Overflow Vulnerability
BugTraq ID: 18751
Remote: Yes
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/18751
Summary:
Applications using the libwmf library are prone to an integer-overflow vulnerability.

An attacker could exploit this vulnerability to execute arbitrary code in the context of the vulnerable application that uses the affected library. Failed exploit attempts will likely cause denial-of-service conditions.

7. Plume CMS DBInstall.PHP Remote File Include Vulnerability
BugTraq ID: 18750
Remote: Yes
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/18750
Summary:
Plume CMS is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

This issue affects version 1.1.3; other versions may also be vulnerable.

8. EZWaiter Cross-site Scripting Vulnerability
BugTraq ID: 18746
Remote: Yes
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/18746
Summary:
ezWaiter is prone to a cross-site scripting vulnerability because it fails to sanitize input before displaying it to users of the application.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

9. HP-UX Mkdir Local Unauthorized Access Vulnerability
BugTraq ID: 18748
Remote: No
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/18748
Summary:
HP-UX mkdir is prone to a local unauthorized-access vulnerability.

This may facilitate various attacks, including information disclosure and potential code execution, leading to privilege escalation.

10. HP-UX Passwd Unspecified Local Denial of Service Vulnerability
BugTraq ID: 17280
Remote: No
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/17280
Summary:
HP-UX passwd(1) is prone to an unspecified local denial-of-service vulnerability.

This issue arises because the software fails to handle exceptional conditions in a proper manner.

Due to a lack of details, further information cannot be provided at the moment. This BID will be updated when more information becomes available.

11. GnuPG Parse_User_ID Remote Buffer Overflow Vulnerability
BugTraq ID: 18554
Remote: Yes
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/18554
Summary:
GnuPG is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue may allow remote attackers to execute arbitrary machine code in the context of the affected application, but this has not been confirmed.

GnuPG versions 1.4.3 and 1.9.20 are vulnerable to this issue; previous versions may also be affected.

12. DHCDBD Remote Denial of Service Vulnerability
BugTraq ID: 18459
Remote: Yes
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/18459
Summary:
DHCDBD is prone to a remote denial-of-service vulnerability.

The issue presents itself when the application handles malformed data and accesses out-of-bounds memory.

DHCDBD 1.10 and 1.12 are vulnerable to this issue; other versions may also be affected.

13. KDE ArtsWrapper Local Privilege Escalation Vulnerability
BugTraq ID: 18429
Remote: No
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/18429
Summary:
KDE's artswrapper utility is susceptible to a local privilege-escalation vulnerability because it fails to properly implement privilege-dropping functionality when used in conjunction with Linux 2.6 kernels.

This issue allows local attackers to gain superuser privileges, facilitating the complete compromise of affected computers.

14. Asterisk IAX2 Remote Buffer Overflow Vulnerability
BugTraq ID: 18295
Remote: Yes
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/18295
Summary:
Asterisk is prone to a remote buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.

This vulnerability allows remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely crash the server, denying further service to legitimate users.

15. wv2 Remote Buffer Overflow Vulnerability
BugTraq ID: 18437
Remote: Yes
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/18437
Summary:
The wv2 library is prone to a remote buffer-overflow vulnerability. This issue is due to the library's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library to parse malicious Microsoft Word files.

Version 0.2.2 of the wv2 library is vulnerable to this issue; other versions may also be affected.

16. Lincoln D. Stein Crypt::CBC Perl Module Weak Ciphertext Vulnerability
BugTraq ID: 16802
Remote: Yes
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/16802
Summary:
Crypt::CBC is susceptible to a weak-ciphertext vulnerability. This issue is due to a flaw in its creation of IVs (Initialization Vectors) for ciphers with a blocksize larger than 8.

This issue results in the creation of ciphertext that contains bytes encrypted with a constant null IV. This ciphertext is prone to differential cryptanalysis, aiding attackers in compromising the plaintext of encrypted data.

The level of difficulty attackers may face trying to exploit this flaw is currently unknown, but data encrypted with vulnerable versions of Crypt::CBC should be considered insecure.

Crypt::CBC versions prior to 2.17 are vulnerable to this issue if they use the 'RandomIV' header style.

17. AstroDog Press Some Chess Board.PHP SQL Injection Vulnerability
BugTraq ID: 18745
Remote: Yes
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/18745
Summary:
Some Chess is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

18. FineShop Multiple Input Validation Vulnerabilities
BugTraq ID: 18743
Remote: Yes
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/18743
Summary:
FineShop is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

These issues affect version 3.0; earlier versions may also be vulnerable.

19. Webmin/Usermin Unspecifed Information Disclosure Vulnerability
BugTraq ID: 18744
Remote: Yes
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/18744
Summary:
Webmin and Usermin are prone to an unspecified information-disclosure vulnerability. This issue is due to a failure in the applications to properly sanitize user-supplied input.

An attacker can exploit this issue to retrieve potentially sensitive information.

This issue affects Webmin versions prior to 1.290 and Usermin versions prior to 1.220.

20. IAXClient Multiple Truncated IAX Frames Remote Buffer Overflow Vulnerabilities
BugTraq ID: 18307
Remote: Yes
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/18307
Summary:
The IAXClient library is prone to multiple remote buffer-overflow vulnerabilities because it fails to properly bounds-check user-supplied input before copying it to insufficiently sized memory buffers.

These issues allow remote attackers to execute arbitrary machine code in the context of applications that use the affected library to process IAX network datagrams.

The following packages are known to use a vulnerable version of the library:
- IDE FISK, versions 1.35 and prior
- IaxComm, versions prior to 1.2.0
- KIAX, versions 0.8.5 and prior
- LoudHush, versions 1.3.6 and prior

Other packages may also use the affected library.

21. Apple iTunes AAC File Parsing Integer Overflow Vulnerability
BugTraq ID: 18730
Remote: Yes
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/18730
Summary:
iTunes is prone to an integer-overflow vulnerability.

An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may help the attacker gain unauthorized access or escalate privileges.

22. Opera Malicious HTML Processing Denial of Service Vulnerability
BugTraq ID: 18585
Remote: Yes
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/18585
Summary:
Opera 9 is prone to a denial-of-service condition when parsing certain malicious HTML content. Successful exploitation will cause the browser to fail or hang.

Opera 9 is prone to this issue; the Opera 8.x product line is not affected.

23. Joomla! Multiple Input Validation Vulnerabilities
BugTraq ID: 18742
Remote: Yes
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/18742
Summary:
Joomla! is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

24. Retired: Mozilla Firefox OuterHTML Redirection Handling Information Disclosure Vulnerability
BugTraq ID: 18734
Remote: Yes
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/18734
Summary:
Mozilla Firefox is prone to an information-disclosure vulnerability because it fails to properly enforce cross-domain policies.

This issue may allow attackers to access arbitrary websites in the context of a targeted user's browser session. This may allow attackers to perform actions in web applications with the privileges of exploited users or to gain access to potentially sensitive information. This may aid attackers in further attacks.

Further reports indicate that this issue does not affect Firefox as reported. Therefore this BID is being retired.

25. Stud.IP Multiple Remote File Include Vulnerabilities
BugTraq ID: 18741
Remote: Yes
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/18741
Summary:
Stud.IP is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

A successful exploit of these issues allows the attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.

These issues affect version 1.3.0-2; earlier versions may also be vulnerable.

26. Geeklog Multiple Remote File Include Vulnerabilities
BugTraq ID: 18740
Remote: Yes
Last Updated: 2006-06-30
Relevant URL: http://www.securityfocus.com/bid/18740
Summary:
Geeklog is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

A successful exploit of these issues allows the attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.

27. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15725
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/15725
Summary:
The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.

This issue is reported to present itself in the 'StreamPredictor::StreamPredictor' function residing in the 'xpdf/Stream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.

The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.

The 'kpdf ' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

28. Microsoft Excel Unspecified Remote Code Execution Vulnerability
BugTraq ID: 18422
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18422
Summary:
Microsoft Excel is prone to an unspecified remote code-execution vulnerability. Insufficient details are currently available to elaborate further.

Successfully exploiting this issue allows attackers to execute arbitrary code in the context of targeted users.

Attackers are actively exploiting this vulnerability in targeted attacks and to install malicious software.

Note that MS Office applications include functionality to embed Office files as objects contained in other Microsoft Office files. As an example, Microsoft Word files may contain embedded malicious Microsoft Excel files, making Word documents another possible attack vector.

This BID will be updated as further information becomes available.

29. Microsoft Internet Explorer OutlookExpress.AddressBook Denial of Service Vulnerability
BugTraq ID: 18771
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18771
Summary:
Microsoft Internet Explorer is prone to a denial-of-service condition when processing the 'OutlookExpress.AddressBook' COM object.

A successful attack may cause the browser to fail due to a null-pointer dereference.

30. Microsoft Internet Explorer HHCtrl ActiveX Control Memory Corruption Vulnerability
BugTraq ID: 18769
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18769
Summary:
Microsoft Internet Explorer is prone to a memory-corruption vulnerability. This is related to the handling of the HHCtrl ActiveX control.

Attackers may exploit this issue via a malicious web page to execute arbitrary code in the context of the currently logged-in user. Exploitation attempts may lead to a denial-of-service condition as well. Attackers may also employ HTML email to carry out an attack.

31. PHPFormGenerator Arbitrary File Upload Vulnerability
BugTraq ID: 18768
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18768
Summary:
phpFormGenerator is prone to an arbitrary file-upload vulnerability.

An attacker can exploit this vulnerability to upload malicious script code, which will be executed in the context of the webserver process.

An attacker may compromise the application by uploading and executing malicious PHP scripts.

phpFormGenerator 2.09c is reported vulnerable. Other versions may be affected as well.

32. Geeklog Connector.PHP Arbitrary File Upload Vulnerability
BugTraq ID: 18767
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18767
Summary:
Geeklog CMS is prone to an arbitrary file-upload vulnerability.

An attacker can exploit this vulnerability to upload malicious script code, which will be executed in the context of the webserver process.

An attacker may compromise the application by uploading and executing malicious PHP scripts with arbitrary filename extensions, because the application fails to sanitize multiple file extensions.

33. BXCP Index.PHP SQL Injection Vulnerability
BugTraq ID: 18765
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18765
Summary:
BXCP is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

This issue affects versions 0.3.0.4 and prior.

34. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15727
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/15727
Summary:
The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. This can result in the attacker gaining unauthorized access to the vulnerable computer.

This issue is reported to present itself in the 'CTStream::readBaselineSOF' function residing in the 'xpdf/Stream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.

The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, however, earlier versions may also be affected.

The 'kpdf' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

35. Microsoft HLINK.DLL Link Memory Corruption Vulnerability
BugTraq ID: 18500
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18500
Summary:
Microsoft HLINK.DLL is prone to a memory-corruption vulnerability. This issue is due to the library's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

Successfully exploiting this issue allows attackers to execute arbitrary machine code in the context of applications that use the affected library. This facilitates the remote compromise of affected computers. Failed exploit attempts will likely crash targeted applications.

This issue has been shown to be exploitable through Microsoft Excel files. Other applications using the affected library may also be affected.

Information regarding which specific versions of HLINK.DLL are affected (and which Microsoft Windows operating systems that include the affected library) is currently unavailable. This BID will be updated as further information is disclosed.

36. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15726
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/15726
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.

Reportedly, this issue presents itself in the 'DCTStream::readProgressiveSOF' function residing in the 'xpdf/Stream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely vulnerable as well. Applications using embedded xpdf code may also be vulnerable.

The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.

Th 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

37. Apple Mac OS X LaunchD Local Format String Vulnerability
BugTraq ID: 18724
Remote: No
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18724
Summary:
Apple Mac OS X 'launchd' is prone to a local format-string vulnerability. A local attacker can exploit this issue through a malicious 'plist' file that includes externally supplied format specifiers that will be passed to the vulnerable code.

A successful attack may crash the application or lead to arbitrary code execution.

This issue was initially discussed in BID 18686 (Apple Mac OS X Multiple Security Vulnerabilities).

38. SturGeoN Upload Arbitrary File Upload Vulnerability
BugTraq ID: 18764
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18764
Summary:
SturGeoN Upload is prone to an arbitrary file-upload vulnerability.

An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.

39. deV!Lz Clanportal ID Parameter SQL Injection Vulnerability
BugTraq ID: 18762
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18762
Summary:
deV!Lz Clanportal is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

This issue affects version 1.34; other versions may also be vulnerable.

40. Randshop Header.Inc.PHP Remote File Include Vulnerability
BugTraq ID: 18763
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18763
Summary:
Randshop is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

41. mAds Search Cross-site Scripting Vulnerability
BugTraq ID: 18761
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18761
Summary:
mAds is prone to a cross-site scripting vulnerability because it fails to sanitize input before displaying it to users of the application.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

42. Diesel Joke Site Category.PHP SQL Injection Vulnerability
BugTraq ID: 18760
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18760
Summary:
Diesel Joke Site is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

43. Toshiba Bluetooth Stack Object Push Service File Upload Directory Traversal Vulnerability
BugTraq ID: 16236
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/16236
Summary:
Toshiba Bluetooth Stack is prone to directory traversal attacks during Bluetooth file uploads.  The issue exists in the Object Push Service.

This vulnerability may allow an attacker to upload malicious files to arbitrary locations on affected computers over Bluetooth.  An attacker can take advantage of the issue to execute arbitrary code by uploading executables to a location on the computer where they will later be executed.

44. Adobe Reader Multiple Unspecified Security Vulnerabilities
BugTraq ID: 18445
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18445
Summary:
Adobe Reader is susceptible to multiple unspecified security vulnerabilities.

Due to the 'critical' rating given by the vendor, combined with their 'Severity rating system', at least one of these vulnerabilities may be exploited to execute arbitrary machine code in the context of the affected application. This is stated to occur in the Apple Macintosh version of the software.

Other vulnerabilities for the Microsoft Windows version of the software rate a 'low' on the vendor's scale, meaning that the vulnerabilities have minimal impact or are extremely difficult to exploit.

No further details are currently available. This BID will be updated as more information is disclosed.

Versions of Adobe Reader prior to 7.0.8 are vulnerable to these issues.

45. Buddy Zone Multiple HTML Injection Vulnerabilities
BugTraq ID: 18759
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18759
Summary:
Buddy Zone is prone to multiple HTML-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

This issue affects version 1.0.1; other versions may also be vulnerable.

46. Toshiba Bluetooth Stack TOSRFBD.SYS Remote Denial of Service Vulnerability
BugTraq ID: 18527
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18527
Summary:
Toshiba Bluetooth Stack is prone to a remote denial-of-service vulnerability.

Reports indicate that a successful attack can corrupt memory and restart a vulnerable computer.
Toshiba Bluetooth Stack for Windows versions 4.0.23 and prior are reported to be affected.

47. Opera Document Stylesheet Denial Of Service Vulnerability
BugTraq ID: 18758
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18758
Summary:
Opera is prone to a denial-of-service vulnerability. This issue is due to a failure in the application to properly handle user-supplied input.

An attacker can exploit this issue to crash an affected browser, effectively denying service.

48. Noweb Insecure Temporary File Creation Vulnerability
BugTraq ID: 16610
Remote: No
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/16610
Summary:
Noweb creates temporary files in an insecure manner.

Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.

49. MyNewsGroups Tree.PHP SQL Injection Vulnerability
BugTraq ID: 18757
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18757
Summary:
MyNewsGroups is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

This issue affects version 0.6; other versions may also be vulnerable.

50. SiteBuilder-FX Top.PHP Remote File Include Vulnerability
BugTraq ID: 18756
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18756
Summary:
SiteBuilder-FX is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

51. Microsoft Windows TCP/IP Protocol Driver Remote Buffer Overflow Vulnerability
BugTraq ID: 18374
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18374
Summary:
Microsoft Windows is prone to a remote buffer-overflow vulnerability.

The vulnerability arises in the Microsoft Windows TCP/IP protocol driver when IP Source Routing has been enabled.

A remote attacker may trigger a denial-of-service condition or may execute arbitrary code, leading to a complete compromise.

52. Linux Kernel Netfilter Conntrack_Proto_SCTP.C Denial of Service Vulnerability
BugTraq ID: 18755
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18755
Summary:
The Linux kernel 'netfilter' module is prone to a denial-of-service vulnerability.

Successful exploits of this vulnerability will cause the kernel to crash, effectively denying service to legitimate users.

53. NASCAR Racing UDP Datagram Remote Denial of Service Vulnerability
BugTraq ID: 18778
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18778
Summary:
NASCAR Racing is prone to a denial-of-service vulnerability. This issue is due to the application's failure to properly handle empty UDP datagrams.

The vulnerability allows remote attackers from external networks to block communication between the client and the server.

This issue affects NASCAR Racing 4.1.3.1.6, NASCAR Racing 2002 Season 1.1.0.2, and NASCAR Racing 2003 Sesason 1.2.0.1; other versions may also be vulnerable.

54. PHPMyAdmin Table Parameter Cross-site Scripting Vulnerability
BugTraq ID: 18754
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18754
Summary:
phpMyAdmin is prone to a cross-site scripting vulnerability because it fails to sanitize input before displaying it to users of the application.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

55. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
BugTraq ID: 16143
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/16143
Summary:
KPDF and KWord are prone to multiple buffer and integer overflows. Successful exploitation could result in arbitrary code execution in the context of the user running the vulnerable application.

Specific details of these issues are not currently available. This record will be updated when more information becomes available.

The following are vulnerable:

- kdegraphics package
- KPDF versions 3.4.3 and earlier
- KOffice
- KWord versions 1.4.2 and earlier

56. Multiple Mozilla Products IFRAME JavaScript Execution Vulnerability
BugTraq ID: 16770
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/16770
Summary:
Multiple Mozilla products are prone to a script-execution vulnerability.

The vulnerability presents itself when an attacker supplies a specially crafted email to a user containing malicious script code in an IFRAME and the user tries to reply to the mail. Arbitrary JavaScript can be executed even if the user has disabled JavaScript execution in the client.

The following mozilla products are vulnerable to this issue:
- Mozilla Thunderbird, versions prior to 1.5.0.2, and prior to 1.0.8
- Mozilla SeaMonkey, versions prior to 1.0.1
- Mozilla Suite, versions prior to 1.7.13

57. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 17516
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/17516
Summary:
The Mozilla Foundation has released nine security advisories specifying security vulnerabilities in Mozilla Suite, Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- gain elevated privileges in JavaScript code, potentially allowing remote machine code execution
- gain access to potentially sensitive information
- bypass security checks
- spoof window contents.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as the information embargo on the Mozilla Bugzilla entries is lifted and as further information becomes available. This BID will then be retired.

These issues are fixed in:
- Mozilla Firefox versions 1.0.8 and 1.5.0.2
- Mozilla Thunderbird versions 1.0.8 and 1.5.0.2
- Mozilla Suite version 1.7.13
- Mozilla SeaMonkey version 1.0.1

58. Efone Config.INC Information Disclosure Vulnerability
BugTraq ID: 18811
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18811
Summary:
Efone is prone to an information-disclosure vulnerability. This issue occurs because access controls on configuration files are not properly set.

An attacker can exploit this issue to retrieve potentially sensitive information. This may aid in further attacks.

It should be noted that this vulnerability exists only when the '.inc' file extension is not declared as a PHP suffix.

59. Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
BugTraq ID: 16476
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/16476
Summary:
Multiple Mozilla products are prone to multiple vulnerabilities. These issues include various memory-corruption, code-injection, and access-restriction-bypass vulnerabilities. Other undisclosed issues may have also been addressed in the various updated vendor applications.

Successful exploitation of these issues may permit an attacker to execute arbitrary code in the context of the affected application. This may facilitate a compromise of the affected computer; other attacks are also possible.

60. Mozilla Thunderbird Multiple Remote Information Disclosure Vulnerabilities
BugTraq ID: 16881
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/16881
Summary:
Mozilla Thunderbird is susceptible to multiple remote information-disclosure vulnerabilities. These issues are due to the application's failure to properly enforce the restriction for downloading remote content in email messages.

These issues allow remote attackers to gain access to potentially sensitive information, aiding them in further attacks. Attackers may also exploit these issues to know whether and when users read email messages.

Mozilla Thunderbird version 1.5 is vulnerable to these issues; other versions may also be affected.

61. Hobbit Monitor Logfetch Information Disclosure Vulnerability
BugTraq ID: 18752
Remote: No
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18752
Summary:
Hobbit is prone to an information-disclosure vulnerability. This issue is due to a failure in the application to properly verify access to restricted information.

An attacker can exploit this issue to retrieve potentially sensitive information that may aid in further attacks.

62. Mozilla Firefox iframe.contentWindow.focus Deleted Object Reference Vulnerability
BugTraq ID: 17671
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/17671
Summary:
Mozilla Firefox is prone to a vulnerability when rendering malformed JavaScript content. An attacker could exploit this issue to cause the browser to fail or potentially execute arbitrary code.

Firefox versions 1.5 through to 1.5.0.2 running on Windows and Linux platforms are affected.

63. PostNuke Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 18819
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18819
Summary:
PostNuke is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input before displaying it to users of the application.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

64. Taskjitsu Multiple HTML Injection Vulnerabilities
BugTraq ID: 18818
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18818
Summary:
Taskjitsu  is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

These issues affect version 2.0; other versions may also be vulnerable.

65. Eupla Foros Config.INC Information Disclosure Vulnerability
BugTraq ID: 18817
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18817
Summary:
Foros is prone to an information-disclosure vulnerability. This issue occurs because access controls on configuration files are not properly set.

An attacker can exploit this issue to retrieve potentially sensitive information. This may aid in further attacks.

It should be noted that this vulnerability exists only when the '.inc' file extension is not declared as a PHP suffix.

66. Kamikaze-QSCM Config.INC Information Disclosure Vulnerability
BugTraq ID: 18816
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18816
Summary:
Kamikaze-qscm is prone to an information-disclosure vulnerability. This issue occurs because access controls on configuration files are not properly set.

An attacker can exploit this issue to retrieve potentially sensitive information. This may aid in further attacks.

It should be noted that this vulnerability exists only when the '.inc' file extension is not declared as a PHP suffix.

67. Randshop Index.PHP Remote File Include Vulnerability
BugTraq ID: 18809
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18809
Summary:
Randshop is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

68. Galleria Remote File Include Vulnerability
BugTraq ID: 18808
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18808
Summary:
Galleria is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and gain access to the underlying system.

69. Kyberna AG Ky2help Meine Links SQL Injection Vulnerability
BugTraq ID: 18800
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18800
Summary:
Kyberna AG Ky2help is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

70. F5 Firepass 4100 SSL VPN Multiple Unspecified Cross-Site Scripting Vulnerabilities
BugTraq ID: 18799
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18799
Summary:
F5 Firepass 4100 SSL VPN is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

71. PHPWebGallery Comments.PHP Cross-site Scripting Vulnerability
BugTraq ID: 18798
Remote: Yes
Last Updated: 2006-07-04
Relevant URL: http://www.securityfocus.com/bid/18798
Summary:
PhpWebGallery is prone to a cross-site scripting vulnerability because it fails to sanitize input before displaying it to users of the application.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

72. iPlanet/Sun Java Messaging Server Local Information Disclosure Vulnerability
BugTraq ID: 18749
Remote: No
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18749
Summary:
iPlanet Messaging Server and Sun Java Messaging Server are prone to a local information-disclosure vulnerability. This issue occurs because the application returns part of the configuration file if an error is encountered.

An attacker can exploit this issue to retrieve potentially sensitive information. This may aid in further attacks.

73. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15721
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/15721
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.

Reportedly, this issue presents itself in the 'JPXStream::readCodestream' function residing in the 'xpdf/JPXStream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.

The 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

74. University Of Washington IMAP Mailbox Name Buffer Overflow Vulnerability
BugTraq ID: 15009
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/15009
Summary:
University of Washington IMAP is prone to a buffer-overflow vulnerability. This issue is exposed when the application parses mailbox names.

If successful, an attacker may execute arbitrary code in the context of the server process. Note that to exploit this issue, the attacker must first authenticate to the service.

75. Mutt BROWSE_GET_NAMESPACE IMAP Namespace Processing Remote Buffer Overflow Vulnerability
BugTraq ID: 18642
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18642
Summary:
Mutt is prone to a remote buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue may allow remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely crash the application, denying further service to legitimate users.

Mutt version 1.4.2.1 is reported to be vulnerable. Other versions may be affected as well.

76. OpenOffice XML File Format Buffer Overflow Vulnerability
BugTraq ID: 18739
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18739
Summary:
OpenOffice is prone to a vulnerability that allows attackers to gain unauthorized access to a vulnerable computer.

The vendor has reported that this vulnerability allows malicious XML documents to cause a buffer overflow leading to read/write privileges to local files on a vulnerable computer.

77. OpenOffice Arbitrary Macro Execution Vulnerability
BugTraq ID: 18738
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18738
Summary:
OpenOffice is prone to a vulnerability that allows attackers to gain unauthorized access to a vulnerable computer.

The vendor has reported that this vulnerability allows malicious macros to gain read/write privileges to local files on a vulnerable computer.

78. OpenOffice Java Applet System Access Vulnerability
BugTraq ID: 18737
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18737
Summary:
OpenOffice is prone to a vulnerability that allows attackers to gain unauthorized access to a vulnerable computer.

The vendor has reported that this vulnerability allows malicious Java applets to gain read/write privileges to local files on a vulnerable computer.

79. KDE KDM Session Type Symbolic Link Vulnerability
BugTraq ID: 18431
Remote: No
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18431
Summary:
KDM is prone to a vulnerability that may permit symbolic-link attacks when processing the user's session type.

An attacker with local access could potentially exploit this issue to view files and obtain privileged information.

A successful attack would most likely result in the loss of confidentiality and the theft of privileged information.

80. Squirrelmail Redirect.PHP Local File Include Vulnerability
BugTraq ID: 18231
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18231
Summary:
Squirrelmail is prone to a local file-include vulnerability. This is due to improper sanitization of  user-supplied input.

A successful exploit may allow unauthorized users to view files and to execute local scripts; other attacks are also possible.

81. Sendmail Malformed MIME Message Denial Of Service Vulnerability
BugTraq ID: 18433
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18433
Summary:
Sendmail is prone to a denial-of-service vulnerability. This issue is due to a failure in the application to properly handle malformed multi-part MIME messages.

An attacker can exploit this issue to crash the sendmail process during delivery.

82. Ethereal Multiple Protocol Dissector Vulnerabilities In Versions Prior To 0.99.0
BugTraq ID: 17682
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/17682
Summary:
Several vulnerabilities in Ethereal have been disclosed by the vendor. The reported issues are in various protocol dissectors. These issues include:

- Buffer-overflow vulnerabilities
- Denial-of-service vulnerabilities
- Infinite loop denial-of-service vulnerabilities
- Unspecified denial-of-service vulnerabilities
- Off-by-one overflow vulnerabilities

These issues could allow remote attackers to execute arbitrary machine code in the context of the vulnerable application. Attackers could also crash the affected application.

Various vulnerabilities affect different versions of Ethereal, from 0.8.5 through to 0.10.14.

83. Kaspersky Internet Security Suite Multiple Local Vulnerabilities
BugTraq ID: 18341
Remote: No
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18341
Summary:
Kaspersky Internet Security Suite is prone to multiple local vulnerabilities.

These vulnerabilities allow local attackers to crash affected computers, denying service to legitimate users. Attackers might also be able to gain elevated privileges by executing arbitrary machine code in the context of the kernel, but this has not been confirmed.

84. Randshop Multiple SQL Injection Vulnerabilities
BugTraq ID: 15599
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/15599
Summary:
Randshop is prone to multiple SQL injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

All versions of Randshop are reported to be affected.

85. Opera SSL Certificate Spoofing Weakness
BugTraq ID: 18692
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18692
Summary:
Opera is prone to security-bar spoofing. Attackers may exploit this via a malicious web page to spoof the SSL credentials of a site that the victim may trust. This weakness may be useful in phishing or other attacks that rely on content spoofing.

86. Opera Web Browser JPEG Image Handling Remote Buffer Overflow Vulnerability
BugTraq ID: 18594
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18594
Summary:
The Opera web browser is susceptible to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue allows attackers to execute arbitrary machine code in the context of affected applications, facilitating the remote compromise of affected computers.

Opera versions prior to 9.0 are vulnerable to this issue.

87. Pearl Product Multiple Remote File Include Vulnerabilities
BugTraq ID: 18797
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18797
Summary:
Various Pearl products are prone to multiple remote file-include vulnerabilities because the products fail to properly sanitize user-supplied input.

An attacker may leverage these issues to have an arbitrary remote file containing malicious script code execute in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system. Other attacks are also possible.

88. AutoRank Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 18796
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18796
Summary:
AutoRank is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input before displaying it to users of the application.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.


  AutoRank PHP 3.02, AutoRank PRO 5.01 and prior versions of each of these applications are also affected.

89. Native Solutions The Banner Engine Top.PHP Cross-site Scripting Vulnerability
BugTraq ID: 18793
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18793
Summary:
The Banner Engine is prone to a cross-site scripting vulnerability because it fails to sanitize input before displaying it to users of the application.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

90. Glossaire Remote File Include Vulnerability
BugTraq ID: 18792
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18792
Summary:
Glossaire is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and gain access to the underlying system.

91. QTO File Manager Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 18791
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18791
Summary:
QTO File Manager is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input before displaying it to users of the application.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

92. VirtuaStore Password Parameter SQL Injection Vulnerability
BugTraq ID: 18790
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18790
Summary:
VirtuaStore is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

93. Zone Labs ZoneAlarm Registry Key Local Denial Of Service Vulnerability
BugTraq ID: 18789
Remote: No
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18789
Summary:
ZoneAlarm is prone to a denial-of-service vulnerability. This issue is due to a failure in the application to properly handle exceptional conditions.

A local attacker can exploit this issue to cause an error in the the application and a system crash, effectively denying service.

94. Free QBoard QB_Path Remote File Include Vulnerabilities
BugTraq ID: 18788
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18788
Summary:
The free QBoard script is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and gain access to the underlying system.

95. PHP-Fusion Avatar Image Edit_profile.PHP HTML Injection Vulnerability
BugTraq ID: 18787
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18787
Summary:
PHP-Fusion is prone to an HTML-injection vulnerability. This issue is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

96. Hiki Diff Denial Of Service Vulnerability
BugTraq ID: 18785
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18785
Summary:
Hiki is prone to a denial-of-service vulnerability. This vulnerability exists due to an error in processing  a comparison  between two pages.

An attacker can exploit this vulnerability to cause the application to stop responding due to excessive use of system resources, denying service to legitimate users.

97. ImgSvr Denial Of Service Vulnerability
BugTraq ID: 18784
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18784
Summary:
ImgSvr is prone to a denial of service vulnerability. This issue is due to a failure in the application to properly handle user-supplied input.

An attacker can exploit this issue to crash an affected server, effectively denying service.

98. Invision Power Board Index.PHP Act Parameter SQL Injection Vulnerability
BugTraq ID: 18782
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18782
Summary:
Invision Power Board is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Version 1.3 Final is affected; other versions may also be vulnerable to this issue.

99. Plume CMS Multiple Remote File Include Vulnerabilities
BugTraq ID: 18780
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18780
Summary:
Plume CMS is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

A successful exploit of these issues allows the attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.

100. Quake 3 Engine Client Multiple Stack Buffer Overflow Vulnerabilities
BugTraq ID: 18777
Remote: Yes
Last Updated: 2006-07-03
Relevant URL: http://www.securityfocus.com/bid/18777
Summary:
The Quake 3 Engine client application is susceptible to multiple remote stack buffer-overflow vulnerabilities.

These issues allow remote attackers to execute arbitrary machine code with the privileges of the user running the client application.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. AT&T privacy policy overreaches, lawyers say
By: Robert Lemos
A recent change to AT&T's privacy policy for broadband and video users has been labeled overbroad by legal experts, and likely will leave the courts or Congress to decide whether the company's practices are standard or sinister.
http://www.securityfocus.com/news/11398

2. USB drives pose insider threat
By: Robert Lemos
Workers are more wary of putting giveaway CDs in their company's computers, but USB flash drives are another story.
http://www.securityfocus.com/news/11397

3. SCADA industry debates flaw disclosure
By: Robert Lemos
Vulnerability researchers bring in US-CERT to referee the outing of an infrastructure bug, ruffling feathers as vendors and researchers clash over how disclosure should be handled. Sound familiar?
http://www.securityfocus.com/news/11396

4. Researchers eye machines to analyze malware
By: Robert Lemos
Automated classification of malicious software could make recognition of threats faster and names more consistent, but researchers cannot agree on what such a system should look like.
http://www.securityfocus.com/news/11395

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Information Assurance Analyst, Tinton Falls
http://www.securityfocus.com/archive/77/439054

2. [SJ-JOB] Security Engineer, Schaumburg
http://www.securityfocus.com/archive/77/439055

3. [SJ-JOB] Sales Engineer, Atlanta
http://www.securityfocus.com/archive/77/439056

4. [SJ-JOB] Security Architect, Richmond
http://www.securityfocus.com/archive/77/439053

5. [SJ-JOB] Security Product Manager, Poway
http://www.securityfocus.com/archive/77/439052

6. [SJ-JOB] Account Manager, Abingdon, Oxfordshire
http://www.securityfocus.com/archive/77/439036

7. [SJ-JOB] Sales Representative, San Jose
http://www.securityfocus.com/archive/77/439038

8. [SJ-JOB] Application Security Architect, Poway
http://www.securityfocus.com/archive/77/439039

9. [SJ-JOB] VP, Information Security, Warren
http://www.securityfocus.com/archive/77/439037

10. [SJ-JOB] Auditor, Washington
http://www.securityfocus.com/archive/77/439048

11. [SJ-JOB] Security Engineer, Bangalore
http://www.securityfocus.com/archive/77/439028

12. [SJ-JOB] Sr. Security Analyst, New York
http://www.securityfocus.com/archive/77/439025

13. [SJ-JOB] Sr. Security Analyst, Summit
http://www.securityfocus.com/archive/77/439026

14. [SJ-JOB] Security Architect, Summit
http://www.securityfocus.com/archive/77/439027

15. [SJ-JOB] Security Auditor, Baltimore
http://www.securityfocus.com/archive/77/439020

16. [SJ-JOB] Quality Assurance, Atlanta
http://www.securityfocus.com/archive/77/439021

17. [SJ-JOB] Security Consultant, London or Berkshire
http://www.securityfocus.com/archive/77/439022

18. [SJ-JOB] Sr. Security Analyst, New York
http://www.securityfocus.com/archive/77/439018

19. [SJ-JOB] Security Consultant, Baltimore
http://www.securityfocus.com/archive/77/439019

20. [SJ-JOB] Security Auditor, Almere
http://www.securityfocus.com/archive/77/438980

21. [SJ-JOB] Jr. Security Analyst, Boston
http://www.securityfocus.com/archive/77/438977

22. [SJ-JOB] Management, Statewide
http://www.securityfocus.com/archive/77/438978

23. [SJ-JOB] Security Consultant, VA/MD/DC
http://www.securityfocus.com/archive/77/438979

24. [SJ-JOB] Auditor, Baltimore
http://www.securityfocus.com/archive/77/438981

25. [SJ-JOB] Security Auditor, Richmond
http://www.securityfocus.com/archive/77/438956

26. [SJ-JOB] Security Consultant, Richmond
http://www.securityfocus.com/archive/77/438957

27. [SJ-JOB] CHECK Team Leader, London
http://www.securityfocus.com/archive/77/438958

28. [SJ-JOB] Technical Support Engineer, Lexington
http://www.securityfocus.com/archive/77/438954

29. [SJ-JOB] Security Consultant, London
http://www.securityfocus.com/archive/77/438955

30. [SJ-JOB] Security Engineer, Tempe
http://www.securityfocus.com/archive/77/438933

31. [SJ-JOB] Security Engineer, Dubai
http://www.securityfocus.com/archive/77/438934

32. [SJ-JOB] Security Consultant, Milan
http://www.securityfocus.com/archive/77/438935

33. [SJ-JOB] Security Engineer, Providence
http://www.securityfocus.com/archive/77/438937

34. [SJ-JOB] Security Consultant, Riyadh
http://www.securityfocus.com/archive/77/438932

35. [SJ-JOB] Quality Assurance, Ann Arbor
http://www.securityfocus.com/archive/77/438922

36. [SJ-JOB] Sales Engineer, San Francisco
http://www.securityfocus.com/archive/77/438923

37. [SJ-JOB] Security Auditor, Washington
http://www.securityfocus.com/archive/77/438921

38. [SJ-JOB] Security Consultant, Washington
http://www.securityfocus.com/archive/77/438920

39. [SJ-JOB] Security Researcher, Marlborough, MA
http://www.securityfocus.com/archive/77/438918

40. [SJ-JOB] Sr. Security Engineer, Schaumburg
http://www.securityfocus.com/archive/77/438919

41. [SJ-JOB] Security Consultant, New York
http://www.securityfocus.com/archive/77/438746

42. [SJ-JOB] Manager, Information Security, Sparks
http://www.securityfocus.com/archive/77/438747

43. [SJ-JOB] Senior Software Engineer, Palo Alto
http://www.securityfocus.com/archive/77/438748

44. [SJ-JOB] Security Consultant, Chicago
http://www.securityfocus.com/archive/77/438749

45. [SJ-JOB] Security Consultant, New York City
http://www.securityfocus.com/archive/77/438750

46. [SJ-JOB] Security Consultant, Bentonville
http://www.securityfocus.com/archive/77/438741

47. [SJ-JOB] Channel / Business Development, San Francisco
http://www.securityfocus.com/archive/77/438743

48. [SJ-JOB] Security Consultant, San Francisco
http://www.securityfocus.com/archive/77/438744

49. [SJ-JOB] Security Consultant, Seattle
http://www.securityfocus.com/archive/77/438745

50. [SJ-JOB] Incident Handler, Schaumburg
http://www.securityfocus.com/archive/77/438740

51. [SJ-JOB] Sr. Security Analyst, New York
http://www.securityfocus.com/archive/77/438742

52. [SJ-JOB] Auditor, Columbus
http://www.securityfocus.com/archive/77/438739

53. [SJ-JOB] Security Consultant, Columbus
http://www.securityfocus.com/archive/77/438736

54. [SJ-JOB] Auditor, Atlanta
http://www.securityfocus.com/archive/77/438737

55. [SJ-JOB] Security Auditor, Columbus
http://www.securityfocus.com/archive/77/438738

56. [SJ-JOB] Remediation Security Analyst, Dallas
http://www.securityfocus.com/archive/77/438720

57. [SJ-JOB] Security Architect, Valley Forge
http://www.securityfocus.com/archive/77/438719

58. [SJ-JOB] Auditor, Dallas
http://www.securityfocus.com/archive/77/438650

59. [SJ-JOB] Sr. Security Analyst, Wilmington
http://www.securityfocus.com/archive/77/438651

60. [SJ-JOB] Sr. Security Analyst, raleigh
http://www.securityfocus.com/archive/77/438652

61. [SJ-JOB] Sr. Security Analyst, Dallas
http://www.securityfocus.com/archive/77/438611

62. [SJ-JOB] Associate Software Engineer, Columbia
http://www.securityfocus.com/archive/77/438620

63. [SJ-JOB] Security Consultant, Dallas
http://www.securityfocus.com/archive/77/438622

64. [SJ-JOB] Security Auditor, Dallas
http://www.securityfocus.com/archive/77/438648

65. [SJ-JOB] Senior Software Engineer, Columbia
http://www.securityfocus.com/archive/77/438649

66. [SJ-JOB] Security Product Manager, Deerfield Beach / Ft. Lauderdale
http://www.securityfocus.com/archive/77/438618

67. [SJ-JOB] Sr. Security Analyst, HERNDON
http://www.securityfocus.com/archive/77/438619

68. [SJ-JOB] Security Auditor, Philadelphia
http://www.securityfocus.com/archive/77/438616

69. [SJ-JOB] Auditor, Chicago
http://www.securityfocus.com/archive/77/438664

70. [SJ-JOB] Security Consultant, Philadelphia
http://www.securityfocus.com/archive/77/438615

71. [SJ-JOB] Security Consultant, Chicago
http://www.securityfocus.com/archive/77/438617

72. [SJ-JOB] Security Auditor, Chicago
http://www.securityfocus.com/archive/77/438630

73. [SJ-JOB] Security Auditor, Raleigh
http://www.securityfocus.com/archive/77/438644

74. [SJ-JOB] Auditor, Raleigh
http://www.securityfocus.com/archive/77/438646

75. [SJ-JOB] Auditor, Richmond
http://www.securityfocus.com/archive/77/438647

76. [SJ-JOB] Security Consultant, Raleigh
http://www.securityfocus.com/archive/77/438612

77. [SJ-JOB] Auditor, Philadelphia
http://www.securityfocus.com/archive/77/438613

78. [SJ-JOB] Director, Information Security, Boston
http://www.securityfocus.com/archive/77/438512

79. [SJ-JOB] Software Engineer, Columbia
http://www.securityfocus.com/archive/77/438513

80. [SJ-JOB] Sales Representative, New York
http://www.securityfocus.com/archive/77/438514

81. [SJ-JOB] Security Engineer, Seattle
http://www.securityfocus.com/archive/77/438508

82. [SJ-JOB] Sales Engineer, Sterling
http://www.securityfocus.com/archive/77/438509

83. [SJ-JOB] Account Manager, Toronto
http://www.securityfocus.com/archive/77/438510

84. [SJ-JOB] Sr. Security Analyst, Boston
http://www.securityfocus.com/archive/77/438511

85. [SJ-JOB] Sales Engineer, Washington
http://www.securityfocus.com/archive/77/438505

86. [SJ-JOB] Security Consultant, PA
http://www.securityfocus.com/archive/77/438506

87. [SJ-JOB] Sr. Security Analyst, Cleveland
http://www.securityfocus.com/archive/77/438507

88. [SJ-JOB] Sr. Security Analyst, Santa Clara
http://www.securityfocus.com/archive/77/438504

V.   INCIDENTS LIST SUMMARY
---------------------------
1. suspicious firewall rules in WinXP firewall
http://www.securityfocus.com/archive/75/438910

2. Pix 515 - need help identifying possible attack - simultaneous traffic and memory spikes...
http://www.securityfocus.com/archive/75/438673

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. IM exploitable vulnerabilities .. any pointers?
http://www.securityfocus.com/archive/82/438760

2. Re[2]: Is Windows TCP/IP source routing PoC code available?
http://www.securityfocus.com/archive/82/438675

3. SyScan'06 Highlight - Is Phone Banking Safe?
http://www.securityfocus.com/archive/82/438670

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #296
http://www.securityfocus.com/archive/88/438565

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This issue is Sponsored by: Watchfire

Methodologies & Tools for Web Application Security Assessment
With the rapid rise in the number and types of security threats, web application security assessments should be considered a crucial phase in the development of any web application. What methodology should be followed? What tools can accelerate the assessment process? See for yourself. Download this Whitepaper today!

https://www.watchfire.com/securearea/whitepapers.aspx?id=701500000008VmX