[USN-970-1] GnuPG2 vulnerability

2010-08-12 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-970-1August 11, 2010 gnupg2 vulnerability CVE-2010-2547 === A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 9.0

ZDI-10-151: Microsoft Office Word 2007 plcffldMom Parsing Remote Code Execution Vulnerability

2010-08-12 Thread ZDI Disclosures
ZDI-10-151: Microsoft Office Word 2007 plcffldMom Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-151 August 11, 2010 -- CVE ID: CVE-2010-1903 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Microsoft -- Affected Products: Microsof

ZDI-10-152: Apple WebKit RTL LineBox Overflow Remote Code Execution Vulnerability

2010-08-12 Thread ZDI Disclosures
ZDI-10-152: Apple WebKit RTL LineBox Overflow Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-152 August 11, 2010 -- CVE ID: CVE-2010-0049 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- Vulnerab

ZDI-10-153: Apple Webkit SVG Floating Text Element Remote Code Execution Vulnerability

2010-08-12 Thread ZDI Disclosures
ZDI-10-153: Apple Webkit SVG Floating Text Element Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-153 August 11, 2010 -- CVE ID: CVE-2010-1787 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- Tip

ZDI-10-154: Apple Webkit Button First-Letter Style Rendering Remote Code Execution Vulnerability

2010-08-12 Thread ZDI Disclosures
ZDI-10-154: Apple Webkit Button First-Letter Style Rendering Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-154 August 11, 2010 -- CVE ID: CVE-2010-1392 -- Affected Vendors: Apple -- Affected Products: Apple WebKit -- TippingPoint(TM) IPS Customer Protec

Secunia Research: Opera "Download" Dialog File Execution Security Issue

2010-08-12 Thread Secunia Research
== Secunia Research 12/08/2010 - Opera "Download" Dialog File Execution Security Issue - == Table of Contents Affected Software...

[ MDVSA-2010:148 ] pidgin

2010-08-12 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:148 http://www.mandriva.com/security/ _

[ MDVSA-2010:149 ] freetype2

2010-08-12 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:149 http://www.mandriva.com/security/ _

[SECURITY] [DSA 2091-1] New squirrelmail packages fix cross-site request forgery

2010-08-12 Thread Luciano Bello
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-2091-1 secur...@debian.org http://www.debian.org/security/Luciano Bello August 12, 2010

SQL Injection vulnerability in CMS WebManager-Pro

2010-08-12 Thread MustLive
Hello Bugtraq! I want to warn you about SQL Injection vulnerability in CMS WebManager-Pro. SQL Injection: http://site/index.php?content_id=-1%20or%20version()=4 Affected software: Vulnerable are CMS WebManager-Pro v.7.4.3 (version from FGS_Studio) and previous versions. Original version of C