«
Expand/Collapse
90 items tagged "extension"
Related tags:
zip extension [+],
zip [+],
stack buffer [+],
suhosin [+],
integer overflow vulnerability [+],
calendar [+],
memory corruption [+],
buffer overflow vulnerability [+],
tom sawyer software [+],
tom sawyer [+],
openssl [+],
php [+],
transparent [+],
privilege escalation vulnerability [+],
denial of service [+],
x.org [+],
x server [+],
webapps [+],
platform [+],
php versions [+],
phar [+],
parser [+],
overflow vulnerability [+],
openslp [+],
idefense security advisory [+],
idefense [+],
heap [+],
day [+],
cookie [+],
code execution [+],
cisco application [+],
buffer overflow [+],
x webdav [+],
txt [+],
safer use [+],
protocol [+],
pidgin [+],
mac os x [+],
mac os [+],
kernel panic [+],
kernel [+],
joomla [+],
jingle [+],
firefox [+],
factory [+],
cisco security advisory [+],
cisco security [+],
application extension [+],
service vulnerability [+],
yoono [+],
xinput [+],
typo3 [+],
typo [+],
sql injection [+],
sql [+],
shm [+],
security extension [+],
security [+],
render [+],
profiles [+],
privilege [+],
pbx extension [+],
pbx [+],
object initialization [+],
mysqlnd [+],
mydashboard [+],
multiple buffer overflow [+],
mod [+],
mit shm [+],
memory [+],
manager cs [+],
malware [+],
local privilege escalation [+],
local [+],
intl [+],
information disclosure vulnerability [+],
information disclosure [+],
information [+],
gd extension [+],
function [+],
free software updates [+],
free [+],
field [+],
extension manager [+],
elastix [+],
dll [+],
dj classifieds [+],
com [+],
buffer overflow vulnerabilities [+],
buffer [+],
brute force attack [+],
browser extension [+],
browser [+],
attack [+],
advisory [+],
adobe [+],
abc index [+],
abc extension [+],
abc [+],
Software [+],
exif [+],
xmlrpc [+],
vulnerability [+]
-
-
15:48
»
Packet Storm Security Exploits
A possible stack buffer overflow in Suhosin extension's transparent cookie encryption that can only be triggered in an uncommon and weakened Suhosin configuration can lead to arbitrary remote code execution, if the FORTIFY_SOURCE compile option was not used when Suhosin was compiled. Versions 0.9.32.1 and below are affected.
-
15:48
»
Packet Storm Security Recent Files
A possible stack buffer overflow in Suhosin extension's transparent cookie encryption that can only be triggered in an uncommon and weakened Suhosin configuration can lead to arbitrary remote code execution, if the FORTIFY_SOURCE compile option was not used when Suhosin was compiled. Versions 0.9.32.1 and below are affected.
-
15:48
»
Packet Storm Security Misc. Files
A possible stack buffer overflow in Suhosin extension's transparent cookie encryption that can only be triggered in an uncommon and weakened Suhosin configuration can lead to arbitrary remote code execution, if the FORTIFY_SOURCE compile option was not used when Suhosin was compiled. Versions 0.9.32.1 and below are affected.
-
-
18:09
»
SecuriTeam
A memory corruption vulnerability in Tom Sawyer Software's GET Extension Factory could allow an attacker to execute arbitrary code with the privileges of the affected user.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
17:45
»
Packet Storm Security Advisories
iDefense Security Advisory 05.03.11 - Remote exploitation of a memory corruption vulnerability in Tom Sawyer Software's GET Extension Factory could allow an attacker to execute arbitrary code with the privileges of the affected user. The vulnerability exists within the way that Internet Explorer instantiates GET Extension Factory COM objects, which is not intended to be created inside of the browser. The object does not initialize properly, and this leads to a memory corruption vulnerability that an attacker can exploit to execute arbitrary code. iDefense has confirmed Tom Sawyer's Default GET Extension Factory 5.5.2.237, tsgetxu71ex552.dll and tsgetx71ex552.dll to be vulnerable. VMWare VirtualCenter 2.5 Update 6, VirtualCenter 2.5 Update 6a is vulnerable.
-
17:45
»
Packet Storm Security Recent Files
iDefense Security Advisory 05.03.11 - Remote exploitation of a memory corruption vulnerability in Tom Sawyer Software's GET Extension Factory could allow an attacker to execute arbitrary code with the privileges of the affected user. The vulnerability exists within the way that Internet Explorer instantiates GET Extension Factory COM objects, which is not intended to be created inside of the browser. The object does not initialize properly, and this leads to a memory corruption vulnerability that an attacker can exploit to execute arbitrary code. iDefense has confirmed Tom Sawyer's Default GET Extension Factory 5.5.2.237, tsgetxu71ex552.dll and tsgetx71ex552.dll to be vulnerable. VMWare VirtualCenter 2.5 Update 6, VirtualCenter 2.5 Update 6a is vulnerable.
-
17:45
»
Packet Storm Security Misc. Files
iDefense Security Advisory 05.03.11 - Remote exploitation of a memory corruption vulnerability in Tom Sawyer Software's GET Extension Factory could allow an attacker to execute arbitrary code with the privileges of the affected user. The vulnerability exists within the way that Internet Explorer instantiates GET Extension Factory COM objects, which is not intended to be created inside of the browser. The object does not initialize properly, and this leads to a memory corruption vulnerability that an attacker can exploit to execute arbitrary code. iDefense has confirmed Tom Sawyer's Default GET Extension Factory 5.5.2.237, tsgetxu71ex552.dll and tsgetx71ex552.dll to be vulnerable. VMWare VirtualCenter 2.5 Update 6, VirtualCenter 2.5 Update 6a is vulnerable.
-
-
10:58
»
Packet Storm Security Exploits
The PHP phar extension suffers from a heap overflow vulnerability. PHP version 5.3.6 is affected with phar extension version 1.1.1.
-
-
20:34
»
Packet Storm Security Recent Files
The Mac OS X WebDAV kernel extension is vulnerable to a denial of service issue that allows a local unprivileged user to trigger a kernel panic due to a memory overallocation.
-
20:33
»
Packet Storm Security Advisories
The Mac OS X WebDAV kernel extension is vulnerable to a denial of service issue that allows a local unprivileged user to trigger a kernel panic due to a memory overallocation.
-
20:23
»
SecuriTeam
A privilege escalation vulnerability was identified in Cisco Application Extension Platform.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
3:01
»
Packet Storm Security Advisories
Cisco Security Advisory - The Cisco Application Extension Platform contains a privilege escalation vulnerability in the tech support diagnostic shell that may allow an authenticated user to obtain administrative access to a vulnerable Cisco Application Extension Platform module. Cisco has released free software updates that address this vulnerability. There is no workaround for this vulnerability.