SecurityFocus Newsletter #362

Peter Laborge <[email protected]> Tue, 08 Aug 2006 15:26:55 -0600
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #362
----------------------------------------

This issue is Sponsored by: SPI Dynamics

ALERT: Ajax Security Dangers- How Hackers are attacking Ajax Web Apps
While Ajax can greatly improve the usability of a Web application, it can also create several opportunities for possible attack if the application is not designed with security in mind. Download this SPI Dynamics white paper.

https://download.spidynamics.com/1/ad/AJAX.asp?Campaign_ID=70160000000CZBn

------------------------------------------------------------------
I.    FRONT AND CENTER
        1. Dynamic linking in Linux and Windows, part one
        2. E-mail privacy in the workplace
II.   BUGTRAQ SUMMARY
        1. Netious CMS Authorization Bypass Vulnerability
        2. Festalon HES Files Remote Heap Buffer Overflow Vulnerability
        3. MySQL Server Date_Format Denial Of Service Vulnerability
        4. YABB Unauthorized Access Vulnerability
        5. MyBloggie Trackback.PHP Multiple SQL Injection Vulnerabilities
        6. Mozilla Multiple Products Remote Vulnerabilities
        7. PHPCodeCabinet Core.PHP Remote File Include Vulnerability
        8. VBulletin Multiple Cross-Site Scripting Vulnerabilities
        9. Tinyportal Guestbook Multiple HTML Injection Vulnerabilities
        10. LibTiff EstimateStripByteCounts() Denial of Service Vulnerability
        11. LibTIFF TiffFetchShortPair Remote Buffer Overflow Vulnerability
        12. Libtiff Library Anonymous Field Merging Denial of Service Vulnerability
        13. LibTiff Sanity Checks Multiple Denial of Service Vulnerabilities
        14. LibTIFF TiffScanLineSize Remote Buffer Overflow Vulnerability
        15. LibTIFF PixarLog Decoder Remote Heap Buffer Overflow Vulnerability
        16. Libtiff Next RLE Decoder Remote Heap Buffer Overflow Vulnerability
        17. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
        18. Microsoft Windows GDI32.DLL WMF Remote Denial of Service Vulnerability
        19. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
        20. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
        21. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
        22. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
        23. DConnect Daemon DC Chat Denial of Service Vulnerability
        24. EasyCafe Security Restriction Bypass Vulnerability
        25. DConnect Daemon Listen Thread UDP Remote Buffer Overflow Vulnerability
        26. Microsoft Internet Explorer IFrame Refresh Denial of Service Vulnerability
        27. FreeRADIUS Multiple RLM_SQLCounter Buffer Overflow Vulnerabilities
        28. FreeRadius RLM_SQLCounter SQL Injection Vulnerability
        29. CA eTrust Antivirus WebScan Malicious Update Code Execution Vulnerability
        30. O2PHP Oxygen Post.PHP SQL Injection Vulnerability
        31. Microsoft Powerpoint Remote Code Execution Vulnerability
        32. Computer Associates Virus Definition Downgrade Vulnerability
        33. Microsoft Windows MHTML URI Buffer Overflow Vulnerability
        34.  MySQL MERGE Priviledge Revoke Bypass Vulnerability
        35. McAfee SecurityCenter Subscription Manager ActiveX Buffer Overflow Vulnerability
        36. CA eTrust Antivirus WebScan Remote Buffer Overflow Vulnerability
        37. Linux Kernel NFS and EXT3 Combination Remote Denial of Service Vulnerability
        38. Microsoft Winsock Gethostbyname Buffer Overflow Vulnerability
        39. Sun Ray UTXConfig Local Arbitrary File Overwrite Vulnerability
        40. Microsoft Powerpoint Remote Code Execution Vulnerability
        41. Microsoft Windows DNS Client Buffer Overrun Vulnerability
        42. Microsoft Internet Explorer FTP URI Arbitrary FTP Server Command Execution Vulnerability
        43. GnuPG Parse_Comment Remote Buffer Overflow Vulnerability
        44. PHPPrintAnalyzer Index.php Remote File Include Vulnerability
        45. Visual Events Calendar Calendar.PHP Remote File Include Vulnerability
        46. Microsoft Windows HTML Help HHCtrl ActiveX Control Memory Corruption Vulnerability
        47. Microsoft HLINK.DLL Link Memory Corruption Vulnerability
        48. YenerTurK Haber Default.ASP SQL Injection Vulnerability
        49. Microsoft Internet Explorer OuterHTML Redirection Handling Information Disclosure Vulnerability
        50. Microsoft Internet Explorer Frameset Memory Corruption Vulnerability
        51. Linksys WRT54GS POST Request Configuration Change Authentication Bypass Vulnerability
        52. MySQL User-Defined Function Buffer Overflow Vulnerability
        53. PHP Multiple Unspecified Vulnerabilities
        54. Blur6ex Title HTML Injection Vulnerability
        55. FTD Search Box HTML Injection Vulnerability
        56. TWiki Configure Script TYPEOF Parameter Remote Command Execution Vulnerability
        57. Simple CMS Auth.PHP Remote Authentication Bypass Vulnerability
        58. XChat Remote Denial of Service Vulnerability
        59. Barracuda Networks Spam Firewall Multiple Vulnerabilities
        60. Clam Anti-Virus ClamAV UPX Compressed PE File Heap Buffer Overflow Vulnerability
        61. eIQnetworks Enterprise Security Analyzer License Manager Remote Buffer Overflow Vulnerability
        62. DeluxeBB Newpost.PHP Cross-Site Scripting Vulnerability
        63. FlatNuke Index.php Remote File Include Vulnerability
        64. Intel PRO/Wireless Network Connection Drivers Remote Code Execution Vulnerabilities
        65. LibVNCServer Remote Authentication Bypass Vulnerability
        66. VWar Multiple Remote File Include Vulnerabilities
        67. Torbstoff News News.PHP Remote File Include Vulnerability
        68. LHAZ LHA Long Multiple Buffer Overflow Vulnerabilities
        69. XPDF Loca Table Verification Remote Denial of Service Vulnerability
        70. The Address Book Reloaded Unspecified Multiple SQL Injection Vulnerabilities
        71. CHM Lib Extract_chmlib Directory Traversal Vulnerability
        72. Multiple SAPID Products Multiple Remote File Include Vulnerabilities
        73. PHPCC Base_Dir Parameter Remote File Include Vulnerability
        74. TurnkeyWebTools PHP Simple Shop Multiple Remote File Include Vulnerabilities
        75. NewSolved ABS_Path Parameter Remote File Include Vulnerability
        76. The Address Book Login Page Multiple SQL Injection Vulnerabilities
        77. XennoBB Profile.PHP Multiple SQL Injection Vulnerabilities
        78. CakePHP Error.PHP Multiple Cross-Site Scripting Vulnerabilities
        79. JD Wiki For Joomla Main.PHP Remote File Include Vulnerability
        80. Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
        81. Samba Internal Data Structures Denial of Service Vulnerability
        82. phNNTP File_newsportal Remote File Include Vulnerability
        83. Netious CMS Username Parameter SQL Injection Vulnerability
        84. Microsoft Management Console Zone Bypass Vulnerability
        85. PHP SSCANF() Safe_Mode Restriction-Bypass Vulnerability
        86. Microsoft Visual Basic for Applications Document Check Buffer Overflow Vulnerability
        87. Simplog Archive.PHP Cross-Site Scripting Vulnerability
        88. Microsoft Windows Server Service Remote Buffer Overflow Vulnerability
        89. Microsoft Hyperlink Object Library Function Remote Buffer Overflow Vulnerability
        90. Microsoft Internet Explorer Source Element Cross-Domain Information Disclosure Vulnerability
        91. Microsoft Windows 2000 Kernel Local Privilege Escalation Vulnerability
        92. Microsoft Windows Unhandled Exception Remote Code Execution Vulnerability
        93. Microsoft Windows User Profile Privilege Escalation Vulnerability
        94. Microsoft Internet Explorer COM Object Instantiation Code Execution Vulnerability
        95. Microsoft Internet Explorer Window Location Cross-Domain Information Disclosure Vulnerability
        96. Microsoft Internet Explorer Chained Cascading Style Sheets Remote Code Execution Vulnerability
        97. Microsoft Internet Explorer HTML Layout and Positioning Remote Code Execution Vulnerability
        98. DConnect Daemon Multiple Format String Vulnerabilities
        99. Webmin/Usermin Unspecifed Information Disclosure Vulnerability
        100. Pike Unspecified SQL Injection Vulnerability
III.  SECURITYFOCUS NEWS
        1. Researchers warn over Web worms
        2. Attackers pass on OS, aim for drivers and apps
        3. ActiveX security faces storm before calm
        4. SCADA system makers pushed toward security
IV.   SECURITY JOBS LIST SUMMARY
        1. [SJ-JOB] Jr. Security Analyst, Nottingham
        2. [SJ-JOB] Account Manager, Elgin
        3. [SJ-JOB] Sr. Security Analyst, Raleigh
        4. [SJ-JOB] Information Assurance Engineer, Washington
        5. [SJ-JOB] Certification & Accreditation Engineer, McLean
        6. [SJ-JOB] Manager, Information Security, Washington
        7. [SJ-JOB] Security Researcher, Raleigh
        8. [SJ-JOB] Sales Engineer, New York
        9. [SJ-JOB] Security Engineer, New York
        10. [SJ-JOB] Manager, Information Security, Western Kansas
        11. [SJ-JOB] Security Engineer, Westlake Village / Los Angeles area
        12. [SJ-JOB] Security Engineer, Dublin
        13. [SJ-JOB] Account Manager, San Diego
        14. [SJ-JOB] Auditor, Boston
        15. [SJ-JOB] Security Engineer, Warren
        16. [SJ-JOB] Security Engineer, Palm Beach Gardens
        17. [SJ-JOB] Auditor, Charlotte
        18. [SJ-JOB] Security Engineer, Dallas
        19. [SJ-JOB] Jr. Security Analyst, Arlington
        20. [SJ-JOB] Sr. Security Analyst, Brisbane
        21. [SJ-JOB] Technical Support Engineer, San Francisco
        22. [SJ-JOB] Sr. Security Analyst, Atlanta
        23. [SJ-JOB] Security Consultant, Vienna
        24. [SJ-JOB] Application Security Engineer, WASHINGTON
        25. [SJ-JOB] Technical Marketing Engineer, San Francisco
        26. [SJ-JOB] CHECK Team Leader, south east UK
        27. [SJ-JOB] MOD CLAS Consultant, south east uk
        28. [SJ-JOB] Penetration Engineer, london,south east , uk wide
        29. [SJ-JOB] Developer, south east uk
        30. [SJ-JOB] Manager, Information Security, Hyderabad
        31. [SJ-JOB] Certification & Accreditation Engineer, SAN DIEGO
        32. [SJ-JOB] Security Engineer, Austin
        33. [SJ-JOB] Security Engineer, San Antonio
        34. [SJ-JOB] Security Architect, San Antonio
        35. [SJ-JOB] Sr. Product Manager, San Diego
        36. [SJ-JOB] Security Researcher, San Diego
        37. [SJ-JOB] Jr. Security Analyst, San Diego
        38. [SJ-JOB] Jr. Security Analyst, Redwood Shores
        39. [SJ-JOB] Security Consultant, london and home counties
        40. [SJ-JOB] Security Researcher, San Diego
        41. [SJ-JOB] Sr. Security Analyst, Calgary
        42. [SJ-JOB] Sales Engineer, Reston
        43. [SJ-JOB] Security Consultant, london and home counties
        44. [SJ-JOB] Penetration Engineer, london
        45. [SJ-JOB] Certification & Accreditation Engineer, Washington DC
        46. [SJ-JOB] Security Engineer, Washington, DC
        47. [SJ-JOB] Manager, Information Security, Geneva
        48. [SJ-JOB] Security Consultant, Manhattan
        49. [SJ-JOB] Account Manager, Phoenix
        50. [SJ-JOB] Account Manager, San Jose
        51. [SJ-JOB] Software Engineer, Sunnyvale
        52. [SJ-JOB] Security Architect, Oklahoma City
        53. [SJ-JOB] Security Engineer, East Bay
        54. [SJ-JOB] Sr. Security Analyst, London
        55. [SJ-JOB] Application Security Engineer, Atlanta
        56. [SJ-JOB] Account Manager, Minneapolis
V.    INCIDENTS LIST SUMMARY
        1. Active Exploitation of a Vulnerability in Microsoft Windows
VI.   VULN-DEV RESEARCH LIST SUMMARY
        1. Announcement: Feed Injection in Web 2.0: Hacking RSS and Atom Feed Implementations [Whitepaper]
        2. Automatic MIME type detection in Internet Explorer 6.x allowed
        3. Simple CMS
        4. EEYE: research.eeye.com
        5. "Moving" Stack: my poor return address!
VII.  MICROSOFT FOCUS LIST SUMMARY
        1. Help needed
        2. Account Control: Running Windows Vista with Least Privilege
        3. free backgammon
        4. SecurityFocus Microsoft Newsletter #302
        5. username change best practices...
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Dynamic linking in Linux and Windows, part one
By Reji Thomas, and Bhasker Reddy
This article discusses shared libraries in both Windows and Linux, and offers a walk through various data structures to explain how dynamic linking is done in these operating systems. The paper will be useful for developers interested in the security implications and the relative speed of dynamic linking, and assumes some prior knowledge of static and shared libraries.
http://www.securityfocus.com/infocus/1872

2. E-mail privacy in the workplace
By Mark Rasch
Even with a well-heeled corporate privacy policy stating that all employee communications may be monitored in the workplace, the legality of e-mail monitoring is not as clear cut as one might think.
http://www.securityfocus.com/columnists/412


II.  BUGTRAQ SUMMARY
--------------------
1. Netious CMS Authorization Bypass Vulnerability
BugTraq ID: 19421
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19421
Summary:
Netious CMS is prone to an authorization bypass vulnerability because it fails to properly authenticate administrative users.

A successful exploit will allow the attacker to gain administrative access and to manipulate sensitive information. Other attacks are also possible.

2. Festalon HES Files Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 19402
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19402
Summary:
A buffer-overflow vulnerability occurs in the Festalon application because the software fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue may allow attackers to execute arbitrary machine code in the context of the affected application, which may facilitate the remote compromise of affected computers.

Festalon versions 0.5.0 through 0.5.5 are vulnerable to this issue.

3. MySQL Server Date_Format Denial Of Service Vulnerability
BugTraq ID: 19032
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19032
Summary:
MySQL is prone to a remote denial-of-service vulnerability because the database server fails to properly handle unexpected input.

This issue allows remote attackers to crash affected database servers, denying service to legitimate users. Attackers must be able to execute arbitrary SQL statements on affected servers, which requires valid credentials to connect to affected servers.

Attackers may exploit this issue in conjunction with latent SQL-injection vulnerabilities in other applications.

Versions of MySQL prior to 4.1.18, 5.0.19, and 5.1.6 are vulnerable to this issue.

4. YABB Unauthorized Access Vulnerability
BugTraq ID: 19366
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19366
Summary:
YABB is prone to an unauthorized-access vulnerability because it fails to properly secure sensitive information.

A successful exploit will allow the attacker to gain administrative access and to manipulate sensitive information. Other attacks are also possible.

5. MyBloggie Trackback.PHP Multiple SQL Injection Vulnerabilities
BugTraq ID: 19362
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19362
Summary:
MyBloggie is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.

These vulnerabilities could permit remote attackers to pass malicious input to database queries, resulting in the modification of query logic or other attacks.

A successful attack could allow an attacker to compromise the software, access or modify data, or exploit vulnerabilities in the underlying database implementation.

This issue affects version 2.1.4 and earlier; other versions may also be affected.

6. Mozilla Multiple Products Remote Vulnerabilities
BugTraq ID: 19181
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19181
Summary:
The Mozilla Foundation has released thirteen security advisories specifying vulnerabilities in Mozilla Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- run arbitrary script code with elevated privileges
- gain access to potentially sensitive information
- carry out cross-domain scripting attacks.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as more information becomes available.

These issues are fixed in:

- Mozilla Firefox version 1.5.0.5
- Mozilla Thunderbird version 1.5.0.5
- Mozilla SeaMonkey version 1.0.3

7. PHPCodeCabinet Core.PHP Remote File Include Vulnerability
BugTraq ID: 19359
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19359
Summary:
PHPCodeCabinet is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.

PHPCodeCabinet 0.5 and eariler are vulnerable to this issue.

8. VBulletin Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 19358
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19358
Summary:
vBulletin is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Version 3.0.14 is vulnerable to these issues; prior versions may also be affected.

9. Tinyportal Guestbook Multiple HTML Injection Vulnerabilities
BugTraq ID: 19357
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19357
Summary:
Tinyportal is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker could exploit this vulnerability to inject hostile HTML and script code into the browser session of other users of the application.

10. LibTiff EstimateStripByteCounts() Denial of Service Vulnerability
BugTraq ID: 19284
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19284
Summary:
LibTIFF is affected by a denial-of-service vulnerability.

An attacker can exploit this vulnerability to cause a denial of service in applications using the affected library.

11. LibTIFF TiffFetchShortPair Remote Buffer Overflow Vulnerability
BugTraq ID: 19283
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19283
Summary:
LibTIFF is prone to a buffer-overflow vulnerability because the library fails to do proper boundary checks before copying user-supplied data into a finite-sized buffer.

This issue allows remote attackers to execute arbitrary machine code in the context of appications using the affected library. Failed exploit attempts will likely crash the application, denying service to legitimate users.

12. Libtiff Library Anonymous Field Merging Denial of Service Vulnerability
BugTraq ID: 19287
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19287
Summary:
The 'libtiff' library is prone to a denial-of-service vulnerability.

An attacker can exploit this issue by submitting malformed image files.

When the libtiff library routines process a malicious TIFF file, this could result in abnormal behavior, cause the application to become unresponsive, or possibly allow malicious code to execute.

13. LibTiff Sanity Checks Multiple Denial of Service Vulnerabilities
BugTraq ID: 19286
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19286
Summary:
LibTIFF is affected by multiple denial-of-service vulnerabilities.

An attacker can exploit these vulnerabilities to cause a denial of service in applications using the affected library.

14. LibTIFF TiffScanLineSize Remote Buffer Overflow Vulnerability
BugTraq ID: 19288
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19288
Summary:
LibTIFF is prone to a buffer-overflow vulnerability because the library fails to do proper boundary checks before copying user-supplied data into a finite-sized buffer.

This issue allows remote attackers to execute arbitrary machine code in the context of applications using the affected library. Failed exploit attempts will likely crash the application, denying service to legitimate users.

15. LibTIFF PixarLog Decoder Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 19290
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19290
Summary:
The PixarLog Decoder for libTIFF is prone to a remote heap buffer-overflow vulnerability.

This issue may allow attackers to execute arbitrary machine code within the context of the vulnerable application or to cause a denial-of-service.

16. Libtiff Next RLE Decoder Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 19282
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19282
Summary:
The Next RLE Decoder for libTIFF is prone to a remote heap buffer-overflow vulnerability.

This issue occurs because the application fails to check boundary conditions on certain RLE decoding operations.

This issue may allow attackers to execute arbitrary machine code within the context of the vulnerable application or to cause a denial of service.

17. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
BugTraq ID: 16143
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/16143
Summary:
KPDF and KWord are prone to multiple buffer and integer overflows. Successful exploitation could result in arbitrary code execution in the context of the user running the vulnerable application.

Specific details of these issues are not currently available. This record will be updated when more information becomes available.

The following are vulnerable:

- kdegraphics package
- KPDF versions 3.4.3 and earlier
- KOffice
- KWord versions 1.4.2 and earlier

18. Microsoft Windows GDI32.DLL WMF Remote Denial of Service Vulnerability
BugTraq ID: 19365
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19365
Summary:
Microsoft Windows is reportedly prone to a remote denial-of-service vulnerability. This issue occurs because the application fails to handle Malicious WMF file.

This issue may cause Windows Explorer to crash, denying service to legitimate users.

19. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15721
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/15721
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.

Reportedly, this issue presents itself in the 'JPXStream::readCodestream' function residing in the 'xpdf/JPXStream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.

The 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

20. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15725
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/15725
Summary:
The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.

This issue is reported to present itself in the 'StreamPredictor::StreamPredictor' function residing in the 'xpdf/Stream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.

The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.

The 'kpdf ' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

21. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15727
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/15727
Summary:
The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. This can result in the attacker gaining unauthorized access to the vulnerable computer.

This issue is reported to present itself in the 'CTStream::readBaselineSOF' function residing in the 'xpdf/Stream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.

The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, however, earlier versions may also be affected.

The 'kpdf' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

22. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15726
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/15726
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.

Reportedly, this issue presents itself in the 'DCTStream::readProgressiveSOF' function residing in the 'xpdf/Stream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely vulnerable as well. Applications using embedded xpdf code may also be vulnerable.

The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.

Th 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

23. DConnect Daemon DC Chat Denial of Service Vulnerability
BugTraq ID: 19370
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19370
Summary:
DConnect Daemon is prone to a denial-of-service vulnerability.

This issue occurs because the application fails to handle null-pointer exceptions properly.

An attacker can exploit this issue to crash the server, causing a denial-of-service.

Version 0.7.0, CVS July 30th 2006 and prior versions are vulnerable to this issue.

24. EasyCafe Security Restriction Bypass Vulnerability
BugTraq ID: 19401
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19401
Summary:
EasyCafe is prone to a security restriction bypass vulnerability

This issue occurs becaue the application fails to prevent an attacker from gaining unauthorized access to a clients computer.

  An attacker can exploit this issue to gain unauthorized access to the clients computer. Other attacks are also possible.

Version 2.1.7 to 2.2.14 are vulnerable to this issue; other versions may also be affected.

25. DConnect Daemon Listen Thread UDP Remote Buffer Overflow Vulnerability
BugTraq ID: 19369
Remote: Yes
Last Updated: 2006-08-06
Relevant URL: http://www.securityfocus.com/bid/19369
Summary:
DConnect Daemon is prone to a buffer-overflow vulnerability because the library fails to do proper boundary checks before copying user-supplied data into a finite-sized buffer.

This issue allows remote attackers to execute arbitrary code within the context of the application or cause the application to crash causing a denial of service.

Version 0.7.0, CVS July 30th 2006 and prior versions are vulnerable to this issue.

26. Microsoft Internet Explorer IFrame Refresh Denial of Service Vulnerability
BugTraq ID: 19364
Remote: Yes
Last Updated: 2006-08-06
Relevant URL: http://www.securityfocus.com/bid/19364
Summary:
Microsoft Internet Explorer is prone to a denial-of-service vulnerability when handling malicious HTML files.

Successfully exploiting this issue allows attackers to consume excessive CPU resources in the affected browser and eventually cause Internet Explorer to crash, causing a denial-of-service.

27. FreeRADIUS Multiple RLM_SQLCounter Buffer Overflow Vulnerabilities
BugTraq ID: 17293
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/17293
Summary:
FreeRADIUS is prone to multiple buffer-overflow vulnerabilities. These issues are due to a failure in the application to do proper bounds checking on user-supplied data.

Reportedly, these issues may result in a denial-of-service condition only. Attackers cannot exploit these issues to gain unauthorized remote access.

28. FreeRadius RLM_SQLCounter SQL Injection Vulnerability
BugTraq ID: 17294
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/17294
Summary:
FreeRADIUS is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

29. CA eTrust Antivirus WebScan Malicious Update Code Execution Vulnerability
BugTraq ID: 19403
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19403
Summary:
CA eTrust Antivirus WebScan is prone to a remote code-execution vulnerability because it fails to properly validate parameters supplied to the WebScan ActiveX control.

An attacker could exploit this vulnerability to cause WebScan to install malicious application files from an attacker-specified source. This could result in the execution of arbitrary code.

This issue affects version 1.1.0.1047 and earlier; other versions may also be affected.

30. O2PHP Oxygen Post.PHP SQL Injection Vulnerability
BugTraq ID: 17324
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/17324
Summary:
Oxygen is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Oxygen versions 1.1.3 and prior are reported to be affected.

31. Microsoft Powerpoint Remote Code Execution Vulnerability
BugTraq ID: 18957
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/18957
Summary:
Microsoft PowerPoint is prone to a remote code-execution vulnerability.

Successfully exploiting this issue allows attackers to execute arbitrary code in the context of targeted users.

A malicious code named 'Trojan.PPDropper.B' is actively exploiting this vulnerability.

32. Computer Associates Virus Definition Downgrade Vulnerability
BugTraq ID: 19399
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19399
Summary:
A flaw in the Computer Associates WebScan product reportedly could cause the application's virus definitions to be downgraded to a previous version.

This presents a security risk because the virus definitions in question may be out of date and may not effectively detect newer variants of malicious code.

33. Microsoft Windows MHTML URI Buffer Overflow Vulnerability
BugTraq ID: 18198
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/18198
Summary:
Microsoft Windows is susceptible to a remote buffer-overflow vulnerability in 'INETCOMM.DLL'. The library fails to properly bounds-check user-supplied input data before copying it into an insufficiently sized memory buffer.

Remote attackers may exploit this issue to execute arbitrary machine code in the context of affected users. Failed exploit attempts likely result in application crashes, denying service to legitimate users.

34.  MySQL MERGE Priviledge Revoke Bypass Vulnerability
BugTraq ID: 19279
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19279
Summary:
MySQL is prone to a vulnerability that allows users with revoked privileges to a particular table to access these tables without permission.

This issue allows attackers to gain access to data when access privileges have been revoked. The specific impact of this issue depends on the data that the attacker may retrieve.

35. McAfee SecurityCenter Subscription Manager ActiveX Buffer Overflow Vulnerability
BugTraq ID: 19265
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19265
Summary:
McAfee SecurityCenter is prone to a stack-based buffer-overflow vulnerability.  This vulnerability requires a certain amount of user-interaction for an attack to occur, such as visiting a malicious website. A successful exploit would let a remote attacker execute code with the privileges of the currently logged in user.

This issue is reported to affect versions 4.3 through 6.0.22. Please see the affected packages section for a list of McAfee consumer products that ship with vulnerable versions of the McAfee SecurityCenter.

36. CA eTrust Antivirus WebScan Remote Buffer Overflow Vulnerability
BugTraq ID: 19351
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19351
Summary:
CA eTrust Antivirus WebScan is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

Due to improper validation of user-supplied input, a remote attacker may cause a buffer-overflow condition and may also execute arbitrary code in the context of the user running the affected application.

This issue affects version 1.1.0.1047 and earlier; other versions may also be affected.

37. Linux Kernel NFS and EXT3 Combination Remote Denial of Service Vulnerability
BugTraq ID: 19396
Remote: No
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19396
Summary:
The Linux kernel is susceptible to a remote denial-of-service vulnerability because the EXT3 filesystem code fails to properly handle unexpected conditions.

Remote attackers may trigger this issue by sending crafted UDP datagrams to affected computers that are configured as NFS servers, causing filesystem errors. Depending on the mount-time options of affected filesystems, this may result in remounting filesystems as read-only or cause a kernel panic.

Linux kernel versions 2.6.14.4, 2.6.17.6, and 2.6.17.7 are vulnerable to this issue; other versions in the 2.6 series are also likely affected.

38. Microsoft Winsock Gethostbyname Buffer Overflow Vulnerability
BugTraq ID: 19319
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19319
Summary:
The Microsoft Winsock API is prone to a buffer-overflow vulnerability.

This issue can occur when the API is invoked via a malicious file or web page that is sufficient to trigger the vulnerability.  If the exploit is successful, attacker-supplied code will execute, completely comprising the affected computer.

39. Sun Ray UTXConfig Local Arbitrary File Overwrite Vulnerability
BugTraq ID: 19394
Remote: No
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19394
Summary:
The utxconfig utility is prone to a vulnerability that may allow local attackers to create or overwrite arbitrary files.

This issue is due to a failure in the application to properly sanitize user-supplied input.

A local attacker can exploit this issue to create or overwrite arbitrary files with superuser privileges.

40. Microsoft Powerpoint Remote Code Execution Vulnerability
BugTraq ID: 19341
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19341
Summary:
Microsoft PowerPoint is prone to a remote code-execution vulnerability.

This issue results when the application handles malformed record data within a presentation file.

A successful exploit of this issue will let attackers execute arbitrary code in the context of targeted user

41. Microsoft Windows DNS Client Buffer Overrun Vulnerability
BugTraq ID: 19404
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19404
Summary:
Microsoft Windows is prone to a remotely exploitable buffer overrun condition in the DNS client.

This issue is exposed when a client handles a malicious response from a DNS server. This may be leveraged to execute arbitrary code and facilitate a complete compromise of the affected computer.

42. Microsoft Internet Explorer FTP URI Arbitrary FTP Server Command Execution Vulnerability
BugTraq ID: 11826
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/11826
Summary:
Microsoft Internet Explorer is reported prone to an arbitrary FTP server command execution vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI input prior to utilizing it to execute FTP commands on remote servers.

This vulnerability allows attackers to embed arbitrary FTP server commands in malicious URIs. Upon following this malicious URI, the victim users Web browser will reportedly connect to the attacker-specified FTP server, and the malicious commands will be sent to the server. This may allow malicious files to be downloaded to the victims computer without their knowledge. Other attacks are also likely possible.

Note: It has been reported that this issue can be leveraged to send email to arbitrary addresses without user interaction.

43. GnuPG Parse_Comment Remote Buffer Overflow Vulnerability
BugTraq ID: 19110
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19110
Summary:
GnuPG is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue may allow remote attackers to execute arbitrary machine code in the context of the affected application, but this has not been confirmed.

GnuPG version 1.4.4 is vulnerable to this issue; previous versions may also be affected.

44. PHPPrintAnalyzer Index.php Remote File Include Vulnerability
BugTraq ID: 19397
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19397
Summary:
phpPrintAnalyzer is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.

Version 1.1 is vulnerable to this issue; other versions may also be affected.

45. Visual Events Calendar Calendar.PHP Remote File Include Vulnerability
BugTraq ID: 19395
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19395
Summary:
Visual Events Calendar is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.

Version 1.1 is vulnerable to this issue; other versions may also be affected.

46. Microsoft Windows HTML Help HHCtrl ActiveX Control Memory Corruption Vulnerability
BugTraq ID: 18769
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/18769
Summary:
Microsoft Windows HTML Help is prone to a memory-corruption vulnerability. This is related to the handling of the HHCtrl ActiveX control.

Attackers may exploit this issue via a malicious web page to execute arbitrary code in the context of the currently logged-in user. Exploitation attempts may lead to a denial-of-service condition as well. Attackers may also employ HTML email to carry out an attack.

47. Microsoft HLINK.DLL Link Memory Corruption Vulnerability
BugTraq ID: 18500
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/18500
Summary:
Microsoft HLINK.DLL is prone to a memory-corruption vulnerability. This issue is due to the library's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

Successfully exploiting this issue allows attackers to execute arbitrary machine code in the context of applications that use the affected library. This facilitates the remote compromise of affected computers. Failed exploit attempts will likely crash targeted applications.

This issue has been shown to be exploitable through Microsoft Office files. Other applications using the affected library may also be affected.

48. YenerTurK Haber Default.ASP SQL Injection Vulnerability
BugTraq ID: 19393
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19393
Summary:
YenerTurK Haber is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.

A successful attack could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

49. Microsoft Internet Explorer OuterHTML Redirection Handling Information Disclosure Vulnerability
BugTraq ID: 18682
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/18682
Summary:
Microsoft Internet Explorer is prone to an information-disclosure vulnerability because it fails to properly enforce cross-domain policies.

This issue may allow attackers to access arbitrary websites in the context of a targeted user's browser session. This may allow attackers to perform actions in web applications with the privileges of exploited users or to gain access to potentially sensitive information. This may aid attackers in further attacks.

50. Microsoft Internet Explorer Frameset Memory Corruption Vulnerability
BugTraq ID: 18277
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/18277
Summary:
Microsoft Internet Explorer is affected by a memory-corruption vulnerability. This issue arises because the application fails to handle exceptional conditions in a proper manner.

An attacker may exploit this issue by enticing a user to visit a malicious site and then to click anywhere on the page. This results in a denial-of-service condition in the application.

The vendor reports this issue may also be exploited to execute arbitrary code in the context of the victim user.

51. Linksys WRT54GS POST Request Configuration Change Authentication Bypass Vulnerability
BugTraq ID: 19347
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19347
Summary:
Linksys WRT54GS is prone to an authentication-bypass vulnerability. Reportedly, the device permits changes in its configuration settings without requring authentication.

Linksys WRT54GS is prone to an authentication-bypass vulnerability. The problem presents itself when a victim user visits a specially crafted web page on an attacker-controlled site. An attacker can exploit this vulnerability to bypass authentication and modify the configuration settings of the device.

This issue is reported to affect firmware version 1.00.9; other firmware versions may also be affected.

52. MySQL User-Defined Function Buffer Overflow Vulnerability
BugTraq ID: 14509
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/14509
Summary:
MySQL is prone to a buffer-overflow vulnerability. The application fails to perform sufficient boundary checks on data supplied as an argument in a user-defined function.

A database user with sufficient access to create a user-defined function can exploit this issue. Attackers may also be able to exploit this issue through latent SQL-injection vulnerabilities in third-party applications that use the database as a backend.

Successful exploitation will result in the execution of arbitrary code in the context of the database server process.

53. PHP Multiple Unspecified Vulnerabilities
BugTraq ID: 17843
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/17843
Summary:
PHP is vulnerable to multiple unspecified vulnerabilities ranging from buffer-overflow to cross-site scripting issues.

The precise nature of these vulnerabilities is currently not known; this BID will be updated as more information becomes available.

Some of the issues discussed may be related to other BIDs regarding PHP vulnerabilities.

54. Blur6ex Title HTML Injection Vulnerability
BugTraq ID: 19392
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19392
Summary:
Blur6ex is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

Version 0.3 is vulnerable to this issue; other versions may also be affected.

55. FTD Search Box HTML Injection Vulnerability
BugTraq ID: 19391
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19391
Summary:
FTD is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

This issue affects version 3.7.3 and earlier; other versions may also be affected.

56. TWiki Configure Script TYPEOF Parameter Remote Command Execution Vulnerability
BugTraq ID: 19188
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19188
Summary:
TWiki is prone to a remote command-execution vulnerability.

Attackers can exploit this issue to execute arbitrary system commands with the privileges of the webserver process.

57. Simple CMS Auth.PHP Remote Authentication Bypass Vulnerability
BugTraq ID: 19386
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19386
Summary:
Simple CMS is prone to an authentication-bypass vulnerability because of a flaw in the authentication process of the affected package.

Exploiting this issue may allow attackers to gain unauthenticated, remote access to administrative sections of the application.

58. XChat Remote Denial of Service Vulnerability
BugTraq ID: 19398
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19398
Summary:
XChat is prone to a remote denial-of-service vulnerability because it fails to properly handle unexpected data from malicious IRC users.

This issue allows remote attackers to crash affected IRC clients, denying service to legitimate users. To exploit this issue, attackers send malformed data to unsuspecting users.

XChat version 2.6.7 for Windows is vulnerable to this issue; other versions and platforms may also be affected.

59. Barracuda Networks Spam Firewall Multiple Vulnerabilities
BugTraq ID: 19276
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19276
Summary:
Spam Firewall is prone to multiple vulnerabilities, including a directory-traversal issue, access-validation issue, and a remote command-execution issue.

A remote attacker can exploit these issues to gain access to potentially sensitive information and execute commands in the context of the affected application.

Versions 3.3.01.001 to 3.3.03.055 are vulnerable to these issues.

60. Clam Anti-Virus ClamAV UPX Compressed PE File Heap Buffer Overflow Vulnerability
BugTraq ID: 19381
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19381
Summary:
ClamAV is prone to a heap buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.

This issue occurs when the application attempts to handle compressed UPX files.

Exploiting this issue could allow attacker-supplied machine code to be executed in the context of the affected application. The issue would occur when the malformed file is scanned manually or automatically in deployments such as email gateways.

ClamAV versions 0.88.2 and 0.88.3 are vulnerable to this issue; prior versions may also be affected.

61. eIQnetworks Enterprise Security Analyzer License Manager Remote Buffer Overflow Vulnerability
BugTraq ID: 19163
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19163
Summary:
eIQnetworks Enterprise Security Analyzer License Manager is prone to a remote buffer-overflow vulnerability.

This issue can facilitate a remote compromise due to arbitrary code execution.

Enterprise Security Analyzer versions prior to 2.5.0 are vulnerable.

62. DeluxeBB Newpost.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 19390
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19390
Summary:
DeluxeBB is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

This issue affects version 1.08; other versions may also be vulnerable.

63. FlatNuke Index.php Remote File Include Vulnerability
BugTraq ID: 18966
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/18966
Summary:
FlatNuke is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.

Version 2.5.7 is vulnerable to this issue; prior versions may also be affected.

64. Intel PRO/Wireless Network Connection Drivers Remote Code Execution Vulnerabilities
BugTraq ID: 19298
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19298
Summary:
Intel PRO/Wireless Network Connection drivers are prone to multiple remote code-execution vulnerabilities.

An attacker within range of a vulnerable Wi-Fi station can trigger these issues to corrupt memory to execute code with kernel-level privileges.

A successful attack can result in a complete compromise of the affected computer.

Intel PRO/Wireless 2200BG and 2915ABG versions prior to 10.5 with driver version 9.0.4.16 for Windows are vulnerable.

65. LibVNCServer Remote Authentication Bypass Vulnerability
BugTraq ID: 18977
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/18977
Summary:
LibVNCServer is prone to an authentication-bypass vulnerability. This issue is due to a flaw in the authentication process of the affected package.

Exploiting this issue may allow attackers to gain unauthenticated, remote access to the VNC servers.

All versions of LibVNCServer are considered vulnerable to this issue.

Reports indicate that this issue is similar to the issue described in BID 17978 (RealVNC Remote Authentication Bypass Vulnerability). Note that since LibVNCServer and RealVNC do not share code, this issue is being assigned a separate BID.

66. VWar Multiple Remote File Include Vulnerabilities
BugTraq ID: 19387
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19387
Summary:
VWar is prone to multiple remote file-include vulnerabilities because the application fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

These issues affect version 1.5; other versions may also be vulnerable.

67. Torbstoff News News.PHP Remote File Include Vulnerability
BugTraq ID: 19385
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19385
Summary:
Torbstoff News is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.

This issue affects version 4 and earlier.

68. LHAZ LHA Long Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 19377
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19377
Summary:
Lhaz is prone to multiple buffer-overflow vulnerabilities because the application fails to check overly long filenames before copying them to a finite-sized buffer.

An attacker can exploit these issues to execute arbitrary code within the context of the affected application.

Version 1.31 is vulnerable to these issues; other versions may also be affected.

69. XPDF Loca Table Verification Remote Denial of Service Vulnerability
BugTraq ID: 14529
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/14529
Summary:
The 'xpdf' utility is prone to a remote denial-of-service vulnerability.

The vulnerability presents itself when the application tries to verify the validity of a malformed 'loca' table in PDF files.

This issue can result in disk consumption and can ultimately lead to a denial-of-service condition.

The 'kpdf', 'gpdf', and 'CUPS' utilities are vulnerable to this issue as well.

70. The Address Book Reloaded Unspecified Multiple SQL Injection Vulnerabilities
BugTraq ID: 19380
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19380
Summary:
The Address Book Reloaded is prone to multiple SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query.

A successful attack could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

These issues may be related to BID #19378 (The Address Book Login Page Multiple SQL Injection Vulnerabilities).

71. CHM Lib Extract_chmlib Directory Traversal Vulnerability
BugTraq ID: 18511
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/18511
Summary:
CHM Lib is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to place malicious files and to overwrite files in arbitrary locations on the vulnerable system, in the context of the user running the application. Successful exploits may aid in further attacks.

72. Multiple SAPID Products Multiple Remote File Include Vulnerabilities
BugTraq ID: 19383
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19383
Summary:
Multiple SAPID applications are prone to multiple remote file-include vulnerabilities.

An attacker can exploit these issues to execute arbitrary malicious PHP code in the context of the webserver process. These may facilitate a compromise of the application and the underlying system; other attacks are also possible.

73. PHPCC Base_Dir Parameter Remote File Include Vulnerability
BugTraq ID: 19376
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19376
Summary:
phpCC is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.

This issue affects version Beta 4.2; other versions may also be vulnerable.

74. TurnkeyWebTools PHP Simple Shop Multiple Remote File Include Vulnerabilities
BugTraq ID: 19382
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19382
Summary:
PHP Simple Shop is prone to multiple remote file-include vulnerabilities.

An attacker can exploit these issues to execute arbitrary malicious PHP code in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

Version 2.0 is vulnerable; other versions may also be affected.

75. NewSolved ABS_Path Parameter Remote File Include Vulnerability
BugTraq ID: 19379
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19379
Summary:
NEWSolved is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.

This issue affects version 1.9.2; earlier versions may also be vulnerable.

76. The Address Book Login Page Multiple SQL Injection Vulnerabilities
BugTraq ID: 19378
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19378
Summary:
The Address Book is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.

These vulnerabilities could permit remote attackers to pass malicious input to database queries, resulting in the modification of query logic or other attacks.

A successful attack could allow an attacker to compromise the software, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Version 1.04e is vulnerable to these issues; earlier versions may also be affected.

77. XennoBB Profile.PHP Multiple SQL Injection Vulnerabilities
BugTraq ID: 19374
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19374
Summary:
XennoBB is prone to multiple SQL injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query.

A successful attack could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

These issues affect version 2.1.0; earlier versions may also be vulnerable.

78. CakePHP Error.PHP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 19372
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19372
Summary:
CakePHP is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

79. JD Wiki For Joomla Main.PHP Remote File Include Vulnerability
BugTraq ID: 19373
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19373
Summary:
JD-Wiki is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.

JD-Wiki 1.0.2 and earlier are vulnerable to this issue; other versions may also be affected.

80. Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
BugTraq ID: 19204
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19204
Summary:
Apache mod_rewrite is prone to an off-by-one buffer-overflow condition.

The vulnerability arising in the mod_rewrite module's ldap scheme handling allows for potential memory corruption when an attacker exploits certain rewrite rules.

An attacker may exploit this issue to trigger a denial-of-service condition. Reportedly, arbitrary code execution may be possible as well.

81. Samba Internal Data Structures Denial of Service Vulnerability
BugTraq ID: 18927
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/18927
Summary:
The smbd daemon is prone to a denial-of-service vulnerability.

An attacker can exploit this issue to consume excessive memory resources, ultimately crashing the affected application.

This issue affects Samba versions 3.0.1 through 3.0.22 inclusive.

82. phNNTP File_newsportal Remote File Include Vulnerability
BugTraq ID: 19423
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19423
Summary:
phNNTP is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

83. Netious CMS Username Parameter SQL Injection Vulnerability
BugTraq ID: 19419
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19419
Summary:
Netious CMS is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.

A successful attack could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

This issue affects version 0.4; earlier versions may also be vulnerable.

84. Microsoft Management Console Zone Bypass Vulnerability
BugTraq ID: 19417
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19417
Summary:
Microsoft Management Console (MMC) is prone to a cross-zone scripting vulnerability. The cause of this vulnerability is that the operating system does not properly restrict access to MMC components, allowing the MMC files to be referenced from the Internet Zone in some cases.

This vulnerability could let an attacker execute arbitrary code, completely compromising the computer.

85. PHP SSCANF() Safe_Mode Restriction-Bypass Vulnerability
BugTraq ID: 19415
Remote: No
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19415
Summary:
PHP is prone to a 'safe_mode' restriction-bypass vulnerability. Successful exploits could allow an attacker to write files in unauthorized locations and potentially execute code.

This vulnerability would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code, with the 'safe_mode' restriction assumed to isolate the users from each other.

This issue is reported to affect PHP versions 4.4.3 and 5.1.4; other versions may also be vulnerable.

86. Microsoft Visual Basic for Applications Document Check Buffer Overflow Vulnerability
BugTraq ID: 19414
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19414
Summary:
A vulnerability has been discovered in Microsoft Visual Basic for Applications. The vulnerability occurs due to insufficient bounds checking when checking the properties of malicious documents. As a result, a malformed document may be capable of triggering a buffer-overflow within the affected application, effectively allowing for the execution of arbitrary code.

Microsoft Office, Access, Visio, Word, and Works are also reportedly attack vectors, since they employ VBA when handling certain document types. Email is another potential attack vector for this vulnerability, however opening an email would not trigger the issue. Replying or forwarding the message could potentially trigger it.

Microsoft has reported that this issue is being exploited in the wild.

87. Simplog Archive.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 19411
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19411
Summary:
Simplog is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Simplog version 0.9.3.1 is vulnerable to this issue; other versions may also be affected.

88. Microsoft Windows Server Service Remote Buffer Overflow Vulnerability
BugTraq ID: 19409
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19409
Summary:
Microsoft Windows Server Service is prone to a remote buffer-overflow vulnerability.

This vulnerability arises when the service processes a malicious message in RPC communications.

A successful attack may result in arbitrary code execution with SYSTEM privileges leading to a full compromise. Attack attempts may result in denial-of-service conditions as well.

Microsoft has reported that this issue is being exploited in the wild.

89. Microsoft Hyperlink Object Library Function Remote Buffer Overflow Vulnerability
BugTraq ID: 19405
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19405
Summary:
Microsoft's Hyperlink Object Library is prone to a buffer-overflow vulnerability. This issue is due to the library's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

Successfully exploiting this issue allows attackers to execute arbitrary machine code in the context of applications that use the affected library. This facilitates the remote compromise of affected computers. Failed exploit attempts will likely crash targeted applications.

This issue is different than the one described in BID 18500 (Microsoft HLINK.DLL Link Memory Corruption Vulnerability).

90. Microsoft Internet Explorer Source Element Cross-Domain Information Disclosure Vulnerability
BugTraq ID: 19400
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19400
Summary:
Microsoft Internet Explorer is prone to an information-disclosure vulnerability because it fails to properly enforce cross-domain policies.

This issue may allow attackers to access arbitrary websites in the context of a targeted user's browser session. This may allow attackers to perform actions in web applications with the privileges of exploited users or to gain access to potentially sensitive information. This may aid attackers in further attacks.

91. Microsoft Windows 2000 Kernel Local Privilege Escalation Vulnerability
BugTraq ID: 19388
Remote: No
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19388
Summary:
A local privilege-escalation vulnerability exists in Microsoft Windows 2000.

This vulnerability affects the Windows kernel and may be exploited by local attackers to completely compromise an affected computer.

92. Microsoft Windows Unhandled Exception Remote Code Execution Vulnerability
BugTraq ID: 19384
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19384
Summary:
Microsoft Windows is prone to a remote code-execution vulnerability.  This vulnerability is caused by an error in how chained exceptions are unloaded by the operating system.

This vulnerability could be exploited by a malicious web page.  A successful exploit would completely compromise the affected computer.

Specific details about this vulnerability are not available at this time.  This BID will be updated if more information becomes available.

93. Microsoft Windows User Profile Privilege Escalation Vulnerability
BugTraq ID: 19375
Remote: No
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19375
Summary:
Microsoft Windows is prone to a local privilege-escalation vulnerability.  The vulnerability is caused by an insecure search path for the WinLogon facility.  If exploited, this could let an attacker run an arbitrary DLL with elevated privileges.

This issue is reported to affect Windows 2000 in the default configuration.  Other Windows operating systems are not affected unless the configuration settings related to this vulnerability are changed from the default.

94. Microsoft Internet Explorer COM Object Instantiation Code Execution Vulnerability
BugTraq ID: 19340
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19340
Summary:
Microsoft Internet Explorer is prone to a memory-corruption vulnerability that is related to the instantiation of COM objects. This issue results from a design error.

The vulnerability arises because of the way Internet Explorer tries to instantiate certain COM objects as ActiveX controls, resulting in arbitrary code execution. The affected objects are not intended to be instantiated through Internet Explorer.

95. Microsoft Internet Explorer Window Location Cross-Domain Information Disclosure Vulnerability
BugTraq ID: 19339
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19339
Summary:
Microsoft Internet Explorer is prone to a cross-domain information-disclosure vulnerability.

This vulnerability may let a malicious website access properties of a site in an arbitrary external domain. Attackers could exploit this issue to gain access to sensitive information that is associated with the external domain.

96. Microsoft Internet Explorer Chained Cascading Style Sheets Remote Code Execution Vulnerability
BugTraq ID: 19316
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19316
Summary:
Microsoft Internet Explorer is prone to remote code-execution vulnerability.

This issue is related to how the browser handles chained CSS (Cascading Style Sheets).  An attacker could exploit this issue to execute arbitrary code in the context of the user visiting a malicious web page.

This issue affects Internet Explorer on Windows 2000, Windows XP excluding XP SP2, and Windows Server 2003.

97. Microsoft Internet Explorer HTML Layout and Positioning Remote Code Execution Vulnerability
BugTraq ID: 19312
Remote: Yes
Last Updated: 2006-08-08
Relevant URL: http://www.securityfocus.com/bid/19312
Summary:
Microsoft Internet Explorer is prone to remote code-execution vulnerability.

This vulnerability is related to how the browser renders HTML with certain layout and positioning combinations.  An attacker could exploit this issue to execute arbitrary code in the context of the user visiting a malicious web page.

This issue affects Internet Explorer on Windows 2000, Windows XP, and Windows Server 2003.

98. DConnect Daemon Multiple Format String Vulnerabilities
BugTraq ID: 19371
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19371
Summary:
DConnect Daemon is prone to multiple remote format-string because the application fails to sanitize user-supplied input before passing it to a formatted-output function.

An attacker can exploit these issues to execute arbitrary code within the context of the server.

Version 0.7.0, CVS July 30, 2006 and prior versions are vulnerable to this issue.

99. Webmin/Usermin Unspecifed Information Disclosure Vulnerability
BugTraq ID: 18744
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/18744
Summary:
Webmin and Usermin are prone to an unspecified information-disclosure vulnerability. This issue is due to a failure in the applications to properly sanitize user-supplied input.

An attacker can exploit this issue to retrieve potentially sensitive information.

This issue affects Webmin versions prior to 1.290 and Usermin versions prior to 1.220.

Unconfirmed reports suggest that this issue is the same as the one discussed in BID 18613 (Webmin Remote Directory Traversal Vulnerability). However, the fixes associated with that issue did not completely solve the vulnerability.

100. Pike Unspecified SQL Injection Vulnerability
BugTraq ID: 19367
Remote: Yes
Last Updated: 2006-08-07
Relevant URL: http://www.securityfocus.com/bid/19367
Summary:
Pike is prone to an unspecified SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.

A successful attack could allow an attacker to compromise the application, access or modify data, gain administrative access to the application, or exploit vulnerabilities in the underlying database implementation.

Versions prior to 7.6.86 are vulnerable to this issue.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Researchers warn over Web worms
By: Robert Lemos
Exploiting a lack of security checks in browsers and Web servers, Web worms and viruses are likely to become a major threat to surfers.
http://www.securityfocus.com/news/11405

2. Attackers pass on OS, aim for drivers and apps
By: Robert Lemos
The low hanging fruit for vulnerability researchers is no longer found in the operating system, but among common applications and device drivers, say flaw finders.
http://www.securityfocus.com/news/11404

3. ActiveX security faces storm before calm
By: Robert Lemos
A security researcher informs Microsoft of more than 100 flaws in ActiveX controls included with a default installation of Windows XP. Another reason to install Internet Explorer 7?
http://www.securityfocus.com/news/11403

4. SCADA system makers pushed toward security
By: Robert Lemos
Companies that make distributed, real-time control systems--a key part of many nations' critical infrastructure--may be forced by their customers to provide better security.
http://www.securityfocus.com/news/11402

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Jr. Security Analyst, Nottingham
http://www.securityfocus.com/archive/77/442540

2. [SJ-JOB] Account Manager, Elgin
http://www.securityfocus.com/archive/77/442568

3. [SJ-JOB] Sr. Security Analyst, Raleigh
http://www.securityfocus.com/archive/77/442536

4. [SJ-JOB] Information Assurance Engineer, Washington
http://www.securityfocus.com/archive/77/442537

5. [SJ-JOB] Certification & Accreditation Engineer, McLean
http://www.securityfocus.com/archive/77/442539

6. [SJ-JOB] Manager, Information Security, Washington
http://www.securityfocus.com/archive/77/442538

7. [SJ-JOB] Security Researcher, Raleigh
http://www.securityfocus.com/archive/77/442469

8. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/442475

9. [SJ-JOB] Security Engineer, New York
http://www.securityfocus.com/archive/77/442493

10. [SJ-JOB] Manager, Information Security, Western Kansas
http://www.securityfocus.com/archive/77/442463

11. [SJ-JOB] Security Engineer, Westlake Village / Los Angeles area
http://www.securityfocus.com/archive/77/442466

12. [SJ-JOB] Security Engineer, Dublin
http://www.securityfocus.com/archive/77/442470

13. [SJ-JOB] Account Manager, San Diego
http://www.securityfocus.com/archive/77/442473

14. [SJ-JOB] Auditor, Boston
http://www.securityfocus.com/archive/77/442474

15. [SJ-JOB] Security Engineer, Warren
http://www.securityfocus.com/archive/77/442458

16. [SJ-JOB] Security Engineer, Palm Beach Gardens
http://www.securityfocus.com/archive/77/442457

17. [SJ-JOB] Auditor, Charlotte
http://www.securityfocus.com/archive/77/442462

18. [SJ-JOB] Security Engineer, Dallas
http://www.securityfocus.com/archive/77/442200

19. [SJ-JOB] Jr. Security Analyst, Arlington
http://www.securityfocus.com/archive/77/442208

20. [SJ-JOB] Sr. Security Analyst, Brisbane
http://www.securityfocus.com/archive/77/442211

21. [SJ-JOB] Technical Support Engineer, San Francisco
http://www.securityfocus.com/archive/77/442196

22. [SJ-JOB] Sr. Security Analyst, Atlanta
http://www.securityfocus.com/archive/77/442197

23. [SJ-JOB] Security Consultant, Vienna
http://www.securityfocus.com/archive/77/442198

24. [SJ-JOB] Application Security Engineer, WASHINGTON
http://www.securityfocus.com/archive/77/442199

25. [SJ-JOB] Technical Marketing Engineer, San Francisco
http://www.securityfocus.com/archive/77/442207

26. [SJ-JOB] CHECK Team Leader, south east UK
http://www.securityfocus.com/archive/77/442111

27. [SJ-JOB] MOD CLAS Consultant, south east uk
http://www.securityfocus.com/archive/77/442096

28. [SJ-JOB] Penetration Engineer, london,south east , uk wide
http://www.securityfocus.com/archive/77/442097

29. [SJ-JOB] Developer, south east uk
http://www.securityfocus.com/archive/77/442108

30. [SJ-JOB] Manager, Information Security, Hyderabad
http://www.securityfocus.com/archive/77/442109

31. [SJ-JOB] Certification & Accreditation Engineer, SAN DIEGO
http://www.securityfocus.com/archive/77/442110

32. [SJ-JOB] Security Engineer, Austin
http://www.securityfocus.com/archive/77/442093

33. [SJ-JOB] Security Engineer, San Antonio
http://www.securityfocus.com/archive/77/442094

34. [SJ-JOB] Security Architect, San Antonio
http://www.securityfocus.com/archive/77/442095

35. [SJ-JOB] Sr. Product Manager, San Diego
http://www.securityfocus.com/archive/77/442053

36. [SJ-JOB] Security Researcher, San Diego
http://www.securityfocus.com/archive/77/442057

37. [SJ-JOB] Jr. Security Analyst, San Diego
http://www.securityfocus.com/archive/77/442063

38. [SJ-JOB] Jr. Security Analyst, Redwood Shores
http://www.securityfocus.com/archive/77/442064

39. [SJ-JOB] Security Consultant, london and home counties
http://www.securityfocus.com/archive/77/442044

40. [SJ-JOB] Security Researcher, San Diego
http://www.securityfocus.com/archive/77/442056

41. [SJ-JOB] Sr. Security Analyst, Calgary
http://www.securityfocus.com/archive/77/442061

42. [SJ-JOB] Sales Engineer, Reston
http://www.securityfocus.com/archive/77/442062

43. [SJ-JOB] Security Consultant, london and home counties
http://www.securityfocus.com/archive/77/442065

44. [SJ-JOB] Penetration Engineer, london
http://www.securityfocus.com/archive/77/442055

45. [SJ-JOB] Certification & Accreditation Engineer, Washington DC
http://www.securityfocus.com/archive/77/442059

46. [SJ-JOB] Security Engineer, Washington, DC
http://www.securityfocus.com/archive/77/442030

47. [SJ-JOB] Manager, Information Security, Geneva
http://www.securityfocus.com/archive/77/441967

48. [SJ-JOB] Security Consultant, Manhattan
http://www.securityfocus.com/archive/77/441989

49. [SJ-JOB] Account Manager, Phoenix
http://www.securityfocus.com/archive/77/442014

50. [SJ-JOB] Account Manager, San Jose
http://www.securityfocus.com/archive/77/442016

51. [SJ-JOB] Software Engineer, Sunnyvale
http://www.securityfocus.com/archive/77/442031

52. [SJ-JOB] Security Architect, Oklahoma City
http://www.securityfocus.com/archive/77/441965

53. [SJ-JOB] Security Engineer, East Bay
http://www.securityfocus.com/archive/77/441966

54. [SJ-JOB] Sr. Security Analyst, London
http://www.securityfocus.com/archive/77/441968

55. [SJ-JOB] Application Security Engineer, Atlanta
http://www.securityfocus.com/archive/77/442022

56. [SJ-JOB] Account Manager, Minneapolis
http://www.securityfocus.com/archive/77/441964

V.   INCIDENTS LIST SUMMARY
---------------------------
1. Active Exploitation of a Vulnerability in Microsoft Windows
http://www.securityfocus.com/archive/75/442535

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Announcement: Feed Injection in Web 2.0: Hacking RSS and Atom Feed Implementations [Whitepaper]
http://www.securityfocus.com/archive/82/442490

2. Automatic MIME type detection in Internet Explorer 6.x allowed
http://www.securityfocus.com/archive/82/442092

3. Simple CMS
http://www.securityfocus.com/archive/82/442015

4. EEYE: research.eeye.com
http://www.securityfocus.com/archive/82/441984

5. "Moving" Stack: my poor return address!
http://www.securityfocus.com/archive/82/441860

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Help needed
http://www.securityfocus.com/archive/88/442340

2. Account Control: Running Windows Vista with Least Privilege
http://www.securityfocus.com/archive/88/442279

3. free backgammon
http://www.securityfocus.com/archive/88/442167

4. SecurityFocus Microsoft Newsletter #302
http://www.securityfocus.com/archive/88/442049

5. username change best practices...
http://www.securityfocus.com/archive/88/441749

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This issue is Sponsored by: SPI Dynamics

ALERT: Ajax Security Dangers- How Hackers are attacking Ajax Web Apps
While Ajax can greatly improve the usability of a Web application, it can also create several opportunities for possible attack if the application is not designed with security in mind. Download this SPI Dynamics white paper.

https://download.spidynamics.com/1/ad/AJAX.asp?Campaign_ID=70160000000CZBn