New Security Vulnerabilities 27th March 2007

The following new security tests were added to Telspace' database:

TOTAL THREATS IN THE DATABASE   14245

 

NEW THREATS RISK FACTOR SUMMARY
   (*****)  Urgent Risk          4
   (**** )  Critical Risk        36
   (***  )  High Risk            1
   (**   )  Medium Risk          4
   (*    )  Low Risk             0

 

NEW THREATS FAMILY SUMMARY
   Solaris Local Checks           20
   Fedora Local Checks            7
   Mandrake Local Checks          4
   FreeBSD Local Checks           4
   Windows                        3
   Web Services                   2
   Remote Shell Access            1
   Centos Local Checks            1
   Red Hat Local Checks           1
   Denial of Service              1
   Cross-Site Scripting           1

 

(*****)  Urgent Risk  -  Web Services
Webapp.org WebAPP < 0.9.9.6 Multiple Vulnerabilities

(*****)  Urgent Risk  -  Windows
Microsoft Hotfix KB828741 (network check)

(*****)  Urgent Risk  -  Remote Shell Access
BrightStor ARCserve Multiple Vulnerabilities (QO86255)

(*****)  Urgent Risk  -  Web Services
mod_jk Long URL Stack Overflow Vulnerability

(**** )  Critical Risk  -  Solaris Local Checks
Solaris 10 (i386) : 123591-03

(**** )  Critical Risk  -  Solaris Local Checks
Solaris 8 (i386) : 119044-03

(**** )  Critical Risk  -  Fedora Local Checks
Fedora Core 5 2007-336: kernel

(**** )  Critical Risk  -  Solaris Local Checks
Solaris 9 (sparc) : 122300-03

(**** )  Critical Risk  -  Denial of Service
Squid < 2.6.STABLE12

(**** )  Critical Risk  -  Solaris Local Checks
Solaris 8 (sparc) : 119044-03

(**** )  Critical Risk  -  Solaris Local Checks
Solaris 8 (i386) : 125359-01

(**** )  Critical Risk  -  Mandrake Local Checks
MDKSA-2007:064: openoffice.org

(**** )  Critical Risk  -  Centos Local Checks
CentOS : RHSA-2007-0066

(**** )  Critical Risk  -  Solaris Local Checks
Solaris 10 (i386) : 125101-03

(**** )  Critical Risk  -  Fedora Local Checks
Fedora Core 6 2007-315: gnupg

(**** )  Critical Risk  -  Solaris Local Checks
Solaris 10 (i386) : 119044-03

(**** )  Critical Risk  -  Solaris Local Checks
Solaris 9 (sparc) : 119044-03

(**** )  Critical Risk  -  Solaris Local Checks
Solaris 9 (i386) : 119044-03

(**** )  Critical Risk  -  Fedora Local Checks
Fedora Core 5 2007-316: gnupg

(**** )  Critical Risk  -  Fedora Local Checks
Fedora Core 6 2007-335: kernel

(**** )  Critical Risk  -  Red Hat Local Checks
RHSA-2007-0066: wireshark

(**** )  Critical Risk  -  Solaris Local Checks
Solaris 9 (i386) : 125359-01

(**** )  Critical Risk  -  Solaris Local Checks
Solaris 10 (i386) : 125359-01

(**** )  Critical Risk  -  Fedora Local Checks
Fedora Core 6 2007-347: tcpdump

(**** )  Critical Risk  -  Solaris Local Checks
Solaris 10 (sparc) : 124939-03

(**** )  Critical Risk  -  Fedora Local Checks
Fedora Core 5 2007-348: tcpdump

(**** )  Critical Risk  -  Windows
EPolicy Orchestrator SiteManager ActiveX Control Buffer Overflow
Vulnerabilities

(**** )  Critical Risk  -  Solaris Local Checks
Solaris 8 (sparc) : 125358-01

(**** )  Critical Risk  -  Fedora Local Checks
Fedora Core 5 2007-1219: cups

(**** )  Critical Risk  -  Solaris Local Checks
Solaris 9 (i386) : 122301-03

(**** )  Critical Risk  -  Solaris Local Checks
Solaris 10 (sparc) : 125358-01

(**** )  Critical Risk  -  Solaris Local Checks
Solaris 10 (sparc) : 123590-03

(**** )  Critical Risk  -  Mandrake Local Checks
MDKSA-2007:061: mplayer

(**** )  Critical Risk  -  Solaris Local Checks
Solaris 10 (sparc) : 119044-03

(**** )  Critical Risk  -  Windows
Trend Micro UPX File Parsing Denial of Service Vulnerability

(**** )  Critical Risk  -  Solaris Local Checks
Solaris 10 (i386) : 124939-03

(**** )  Critical Risk  -  Solaris Local Checks
Solaris 9 (sparc) : 125358-01

(**** )  Critical Risk  -  Mandrake Local Checks
MDKSA-2007:063: libwpd

(**** )  Critical Risk  -  Solaris Local Checks
Solaris 9 (i386) : 124833-01

(**** )  Critical Risk  -  Mandrake Local Checks
MDKSA-2007:062: xine-lib

(***  )  High Risk  -  Cross-Site Scripting
Horde new_lang Parameter Cross-Site Scripting Vulnerability

(**   )  Medium Risk  -  FreeBSD Local Checks
FreeBSD : samba -- potential Denial of Service bug in smbd (929)

(**   )  Medium Risk  -  FreeBSD Local Checks
FreeBSD : sql-ledger -- security bypass vulnerability (931)

(**   )  Medium Risk  -  FreeBSD Local Checks
FreeBSD : cacti -- remote injection exploit (930)

(**   )  Medium Risk  -  FreeBSD Local Checks
FreeBSD : samba -- format string bug in afsacl.so VFS plugin (928)



Copyright © 2010 Telspace. All Rights Reserved