Multiple Vulnerabilities in LibreOffice

2012-11-06 Thread advisory
Advisory ID: HTB23106 Product: LibreOffice Suite Vendor: LibreOffice Vulnerable Version(s): 3.5.5.3 and probably prior Tested Version: 3.5.5.3 Vendor Notification: July 26, 2012 Public Disclosure: October 31, 2012 Vulnerability Type: NULL Pointer Dereference [CWE-476] CVE Reference:

SQL Injection Vulnerability in OrangeHRM

2012-11-06 Thread advisory
Advisory ID: HTB23119 Product: OrangeHRM Vendor: OrangeHRM Inc. Vulnerable Version(s): 2.7.1-rc.1 and probably prior Tested Version: 2.7.1-rc.1 Vendor Notification: October 10, 2012 Public Disclosure: October 31, 2012 Vulnerability Type: SQL Injection [CWE-89] CVE Reference: CVE-2012-5367 CVSSv2

multiple critical vulnerabilities in sophos products

2012-11-06 Thread Tavis Ormandy
List, I've completed the second paper in my series analyzing Sophos Antivirus internals, titled Practical Attacks against Sophos Antivirus. As the name suggests, this paper describes realistic attacks against networks using Sophos products. The paper includes a working pre-authentication remote

Wisecracker 1.0 - A high performance distributed cryptanalysis framework

2012-11-06 Thread Vikas N Kumar
Wisecracker is an open source high performance distributed cryptanalysis framework that leverages GPUs and multiple CPUs. It allows security researchers to write their own cryptanalysis tools that can distribute brute-force cryptanalysis work across multiple systems with multiple multi-core

[security bulletin] HPSBHF02699 SSRT100592 rev.2 - HP ProLiant SL Advanced Power Manager (SL-APM), Remote User Validation Failure

2012-11-06 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20566.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c02950841 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c02950841 Version: 2 HPSBHF02699

Vulnerable, superfluous/outdated/deprecated/superseded 3rd party OCXs and DLLs distributed by and installed with Dataram RamDisk 4.0.0

2012-11-06 Thread Stefan Kanthak
Hi @ll, the recently released RamDisk 4.0.0 from Dataram Inc., http://memory.dataram.com/products-and-services/software/ramdisk (formerly known as Cenatek RamDisk) comes with several vulnerable and some superfluous as well as outdated/deprecated/superseded 3rd party OCXs and DLLs from Microsoft.