New Security Vulnerabilities 27th March 2007
The following new security tests were added to Telspace' database:
TOTAL THREATS IN THE DATABASE 14245
NEW THREATS RISK FACTOR SUMMARY
(*****) Urgent Risk 4
(**** ) Critical Risk 36
(*** ) High Risk 1
(** ) Medium Risk 4
(* ) Low Risk 0
NEW THREATS FAMILY SUMMARY
Solaris Local Checks 20
Fedora Local Checks 7
Mandrake Local Checks 4
FreeBSD Local Checks 4
Windows 3
Web Services 2
Remote Shell Access 1
Centos Local Checks 1
Red Hat Local Checks 1
Denial of Service 1
Cross-Site Scripting 1
(*****) Urgent Risk - Web Services
Webapp.org WebAPP < 0.9.9.6 Multiple Vulnerabilities
(*****) Urgent Risk - Windows
Microsoft Hotfix KB828741 (network check)
(*****) Urgent Risk - Remote Shell Access
BrightStor ARCserve Multiple Vulnerabilities (QO86255)
(*****) Urgent Risk - Web Services
mod_jk Long URL Stack Overflow Vulnerability
(**** ) Critical Risk - Solaris Local Checks
Solaris 10 (i386) : 123591-03
(**** ) Critical Risk - Solaris Local Checks
Solaris 8 (i386) : 119044-03
(**** ) Critical Risk - Fedora Local Checks
Fedora Core 5 2007-336: kernel
(**** ) Critical Risk - Solaris Local Checks
Solaris 9 (sparc) : 122300-03
(**** ) Critical Risk - Denial of Service
Squid < 2.6.STABLE12
(**** ) Critical Risk - Solaris Local Checks
Solaris 8 (sparc) : 119044-03
(**** ) Critical Risk - Solaris Local Checks
Solaris 8 (i386) : 125359-01
(**** ) Critical Risk - Mandrake Local Checks
MDKSA-2007:064: openoffice.org
(**** ) Critical Risk - Centos Local Checks
CentOS : RHSA-2007-0066
(**** ) Critical Risk - Solaris Local Checks
Solaris 10 (i386) : 125101-03
(**** ) Critical Risk - Fedora Local Checks
Fedora Core 6 2007-315: gnupg
(**** ) Critical Risk - Solaris Local Checks
Solaris 10 (i386) : 119044-03
(**** ) Critical Risk - Solaris Local Checks
Solaris 9 (sparc) : 119044-03
(**** ) Critical Risk - Solaris Local Checks
Solaris 9 (i386) : 119044-03
(**** ) Critical Risk - Fedora Local Checks
Fedora Core 5 2007-316: gnupg
(**** ) Critical Risk - Fedora Local Checks
Fedora Core 6 2007-335: kernel
(**** ) Critical Risk - Red Hat Local Checks
RHSA-2007-0066: wireshark
(**** ) Critical Risk - Solaris Local Checks
Solaris 9 (i386) : 125359-01
(**** ) Critical Risk - Solaris Local Checks
Solaris 10 (i386) : 125359-01
(**** ) Critical Risk - Fedora Local Checks
Fedora Core 6 2007-347: tcpdump
(**** ) Critical Risk - Solaris Local Checks
Solaris 10 (sparc) : 124939-03
(**** ) Critical Risk - Fedora Local Checks
Fedora Core 5 2007-348: tcpdump
(**** ) Critical Risk - Windows
EPolicy Orchestrator SiteManager ActiveX Control Buffer Overflow
Vulnerabilities
(**** ) Critical Risk - Solaris Local Checks
Solaris 8 (sparc) : 125358-01
(**** ) Critical Risk - Fedora Local Checks
Fedora Core 5 2007-1219: cups
(**** ) Critical Risk - Solaris Local Checks
Solaris 9 (i386) : 122301-03
(**** ) Critical Risk - Solaris Local Checks
Solaris 10 (sparc) : 125358-01
(**** ) Critical Risk - Solaris Local Checks
Solaris 10 (sparc) : 123590-03
(**** ) Critical Risk - Mandrake Local Checks
MDKSA-2007:061: mplayer
(**** ) Critical Risk - Solaris Local Checks
Solaris 10 (sparc) : 119044-03
(**** ) Critical Risk - Windows
Trend Micro UPX File Parsing Denial of Service Vulnerability
(**** ) Critical Risk - Solaris Local Checks
Solaris 10 (i386) : 124939-03
(**** ) Critical Risk - Solaris Local Checks
Solaris 9 (sparc) : 125358-01
(**** ) Critical Risk - Mandrake Local Checks
MDKSA-2007:063: libwpd
(**** ) Critical Risk - Solaris Local Checks
Solaris 9 (i386) : 124833-01
(**** ) Critical Risk - Mandrake Local Checks
MDKSA-2007:062: xine-lib
(*** ) High Risk - Cross-Site Scripting
Horde new_lang Parameter Cross-Site Scripting Vulnerability
(** ) Medium Risk - FreeBSD Local Checks
FreeBSD : samba -- potential Denial of Service bug in smbd (929)
(** ) Medium Risk - FreeBSD Local Checks
FreeBSD : sql-ledger -- security bypass vulnerability (931)
(** ) Medium Risk - FreeBSD Local Checks
FreeBSD : cacti -- remote injection exploit (930)
(** ) Medium Risk - FreeBSD Local Checks
FreeBSD : samba -- format string bug in afsacl.so VFS plugin (928) |