Section: .. / Last 20 Files /
| /// File Name: | Botan-1.9.4.tgz | Description:
| Botan is a C++ library of cryptographic algorithms, including AES, DES, SHA-1, RSA, DSA, Diffie-Hellman, and many others. It also supports X.509 certificates and CRLs, and PKCS #10 certificate requests, and has a high level filter/pipe message processing system. The library is easily portable to most systems and compilers, and includes a substantial tutorial and API reference. | | Homepage: | http://botan.randombit.net/ | | Changes: | This version adds a SSLv3/TLSv1.0 implementation, the GOST 34.10-2001 signature scheme, and the XSalsa20 stream cipher. New countermeasures against fault attacks on signature schemes are included. New SIMD optimizations for the IDEA and Noekeon block ciphers are available, and CBC and XTS modes can now make use of cipher implementations that use SIMD. A SQLite-like amalgamation option is now available, making botan very easy to distribute in applications. The dependency on TR1 for ECC has been removed, making ECDSA/ECDH available on Windows and with older compilers. | | File Size: | 3415352 | | Last Modified: | Mar 10 11:10:20 2010 | | MD5 Checksum: | 8ff9f7929b05295e9701adf1c8859a32 |
|
| /// File Name: | gnupg-2.0.15.tar.bz2 | Description:
| GnuPG (the GNU Privacy Guard or GPG) is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440. As such, it is meant to be compatible with PGP from NAI, Inc. Because it does not use any patented algorithms, it can be used without any restrictions. | | Homepage: | http://www.gnupg.org | | Changes: | A regression in 2.0.14 which prevented unprotection of new or changed gpg-agent passphrases was fixed. A new command "--passwd" was added. libassuan 2.0 is now used. | | File Size: | 3976879 | | Last Modified: | Mar 10 11:08:27 2010 | | MD5 Checksum: | c1286e85b66349879dc4b760dd83e2f1 |
|
| /// File Name: | fwbuilder-4.0.0.tar.gz | Description:
| Firewall Builder consists of a GUI and set of policy compilers for various firewall platforms. It helps users maintain a database of objects and allows policy editing using simple drag-and-drop operations. The GUI and policy compilers are completely independent, which provides for a consistent abstract model and the same GUI for different firewall platforms. It currently supports iptables, ipfilter, ipfw, OpenBSD pf, Cisco PIX and FWSM, and Cisco routers access lists. | | Homepage: | http://www.fwbuilder.org | | Changes: | This is a major upgrade. It comes with support for high availability firewall configurations, including heartbeat, vrrpd, keepalived, and conntrackd on Linux, CARP and pfsync on OpenBSD, and PIX failover configuration. It can generate configuration scripts to manage IP addresses, VLAN, bridge, and bonding interfaces on the firewall. Drop-in support for OpenWRT firewall script is now available, as well as experimental integration with IPCOP firewall appliances. The has supports undo and redo of unlimited depth and was generally streamlined and improved. | | File Size: | 5275041 | | Last Modified: | Mar 10 11:03:43 2010 | | MD5 Checksum: | 211788146729375d450756f104441068 |
|
| /// File Name: | anantasoft-xsrf.txt | Description:
| Anantasoft Gazelle CMS suffers from a cross site request forgery vulnerability. | | Author: | Pratul Agrawal | | File Size: | 2808 | | Last Modified: | Mar 10 10:59:29 2010 | | MD5 Checksum: | dad820e563724bc7b8c491876c9048fa |
|
| /// File Name: | secunia-etsdisclose.txt | Description:
| Secunia Research has discovered security issue in Employee Timeclock Software, which can be exploited by malicious, local users to disclose sensitive information. The security issue is caused due to the application passing the database password via the command line to the "mysqldump" utility, which potentially can be exploited to disclose the password via the process list. Version 0.99 is affected. | | Homepage: | http://secunia.com/ | | File Size: | 4385 | | Related CVE(s): | CVE-2010-0124 | | Last Modified: | Mar 10 10:57:24 2010 | | MD5 Checksum: | 5c55f50ca9c91dbe8978a3bb60746a6c |
|
| /// File Name: | secunia-etssql.txt | Description:
| Secunia Research has discovered some vulnerabilities in Employee Timeclock Software, which can be exploited by malicious people to conduct SQL injection attacks. Input passed to the "username" and "password" parameters in auth.php and login_action.php is not properly sanitized before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Version 0.99 is affected. | | Homepage: | http://secunia.com/ | | File Size: | 4407 | | Related CVE(s): | CVE-2010-0122 | | Last Modified: | Mar 10 10:55:45 2010 | | MD5 Checksum: | 97deca06ff6efb5d59e274ff9355eacb |
|
| /// File Name: | notepadpoc.zip | Description:
| The MS HTML Help control activex is prone to a remote CHM help file hijack vulnerability when applications invoke help. Multiple built-in applications are vulnerable to this. The impact of the vulnerability is the loading of the incorrect CHM help file when it resides in the same directory the application invoking help starts in. This proof of concept exploit leverages Notepad to demonstrate the vulnerability. | | Author: | Eduardo Prado | | File Size: | 28918 | | Last Modified: | Mar 10 10:51:10 2010 | | MD5 Checksum: | 3f0edb83fb8c525b3c7a93556ab16cc7 |
|
| /// File Name: | tarcpio-overflow.txt | Description:
| GNU Tar and GNU Cpio suffer from a heap-based buffer overflow vulnerability. Tar versions prior to 1.23 and Cpio versions prior to 2.11 are affected. | | Author: | Jakob Lell | | File Size: | 5110 | | Related CVE(s): | CVE-2010-0624 | | Last Modified: | Mar 10 10:48:29 2010 | | MD5 Checksum: | f12725e9c18845e64dcff526a6f7d29f |
|
| /// File Name: | ispcp-rfi.txt | Description:
| ispCP Omega versions 1.0.4 and below suffer from a remote file inclusion vulnerability. | | Author: | cr4wl3r | | File Size: | 2068 | | Last Modified: | Mar 10 10:47:10 2010 | | MD5 Checksum: | 1ecfa63512e948355cf15fd528e4c374 |
|
| /// File Name: | secunia-etsb.txt | Description:
| Secunia Research has discovered security issue in Employee Timeclock Software, which can be exploited by malicious people to disclose sensitive information. The database backup functionality stores the database backup with a semi-predictable file name inside the web root. This can be exploited to download the backup by guessing the file name. Version 0.99 is affected. | | Homepage: | http://secunia.com/ | | File Size: | 4397 | | Related CVE(s): | CVE-2010-0123 | | Last Modified: | Mar 10 10:44:55 2010 | | MD5 Checksum: | 691c19edbe543e11cd7b2a8326ea3cd9 |
|
| /// File Name: | softbizjobsrecruitment-sql.txt | Description:
| Softbiz Jobs and Recruitment script suffers from a remote SQL injection vulnerability. | | Author: | Easy Laster | | File Size: | 1605 | | Last Modified: | Mar 10 10:42:00 2010 | | MD5 Checksum: | a2b901cd5a4520daee9be76aab46b150 |
|
| /// File Name: | campsite-xsrf.txt | Description:
| Campsite version 3.3.5 suffers from a cross site request forgery vulnerability. | | Author: | Pratul Agrawal | | File Size: | 1620 | | Last Modified: | Mar 10 10:22:41 2010 | | MD5 Checksum: | 02c5f2f26afd7f5d5c3d519bb791a6fe |
|
| /// File Name: | 03.09.10-4.txt | Description:
| iDefense Security Advisory 03.09.10 - Remote exploitation of a heap overflow vulnerability in Microsoft Corp.'s Excel could allow an attacker to execute arbitrary code with the privileges of the current user. This vulnerability occurs when parsing an MDXTUPLE record inside of the Excel Workbook globals stream. This record is used to store metadata for external data connections in the workbook. The vulnerability occurs when a MDXTUPLE record is broken up into several records. This could allow an attacker to trigger a heap based buffer overflow by controlling both the allocation size of a heap buffer and the number of bytes copied into this buffer. iDefense has confirmed the existence of this vulnerability in Excel versions 2007 SP0, SP1, and SP2. Previous versions do not appear to be affected as they do not support parsing the record that triggers the vulnerability. A full list of vulnerable Microsoft products can be found in Microsoft Security Bulletin MS10-017. | | Author: | Sean Larsson,iDefense Labs | | Homepage: | http://www.idefense.com/ | | File Size: | 3817 | | Related CVE(s): | CVE-2010-0260 | | Last Modified: | Mar 10 10:20:50 2010 | | MD5 Checksum: | 361cae51b434d20705f58c6f7cde7793 |
|
| /// File Name: | 03.09.10-3.txt | Description:
| iDefense Security Advisory 03.09.10 - Remote exploitation of a heap overflow vulnerability in Microsoft Corp.'s Excel could allow an attacker to execute arbitrary code with the privileges of the current user. This vulnerability occurs when parsing an MDXSET record inside of the Excel Workbook globals stream. This record is used to store metadata for external data connections in the workbook. The vulnerability occurs when a MDXSET record is broken up into several records. This could allow an attacker to trigger a heap based buffer overflow by controlling both the allocation size of a heap buffer and the number of bytes copied into this buffer. iDefense has confirmed the existence of this vulnerability in Excel versions 2007 SP0, SP1, and SP2. Previous versions do not appear to be affected as they do not support parsing the record that triggers the vulnerability. A full list of vulnerable Microsoft products can be found in Microsoft Security Bulletin MS10-017. | | Author: | Sean Larsson,iDefense Labs | | Homepage: | http://www.idefense.com/ | | File Size: | 3813 | | Related CVE(s): | CVE-2010-0261 | | Last Modified: | Mar 10 10:19:19 2010 | | MD5 Checksum: | fcd3d4df59f6a8656e954ecae6950e45 |
|
| /// File Name: | 03.09.10-2.txt | Description:
| iDefense Security Advisory 03.09.10 - Remote exploitation of an uninitialized memory vulnerability in Microsoft Corp.'s Excel could allow an attacker to execute arbitrary code with the privileges of the current user. The vulnerability occurs due to Excel using a local function variable without properly initializing it. This error occurs when parsing several related records inside of an Excel worksheet. When Excel parses certain records in a particular order, a stack variable may not be initialized properly. If an attacker can control the area of memory used for this variable, then it is possible to execute arbitrary code on the targeted host. iDefense has confirmed the existence of this vulnerability in Excel versions 2003 SP3, 2007 SP0, SP1, and SP3 . Previous versions do not appear to be affected. A full list of vulnerable Microsoft products can be found in Microsoft Security Bulletin MS10-017. | | Author: | Sean Larsson,iDefense Labs | | Homepage: | http://www.idefense.com/ | | File Size: | 3939 | | Related CVE(s): | CVE-2010-0262 | | Last Modified: | Mar 10 10:17:18 2010 | | MD5 Checksum: | 4c6d869c98aaa46c8b7d0dec92b565e3 |
|
| /// File Name: | 60cyclecms-xss.txt | Description:
| 60cycleCMS suffers from a cross site scripting vulnerability. | | Author: | Pratul Agrawal | | File Size: | 3606 | | Last Modified: | Mar 10 10:15:49 2010 | | MD5 Checksum: | 47b9959eebc266e101924d1fd6e37482 |
|
| /// File Name: | 03.09.10-1.txt | Description:
| iDefense Security Advisory 03.09.10 - Remote exploitation of a type confusion vulnerability in Microsoft Corp.'s Excel could allow an attacker to execute arbitrary code with the privileges of the current user. This vulnerability is a type confusion vulnerability that occurs when parsing several related Excel record types. In this case, the type confusion is due to multiple records containing fields that identify the type of an object shared between them. By controlling memory outside of the bounds of the allocated heap chunk, an attacker can control a C++ object pointer used in a virtual function call. This can result in an area of memory being treated as a different type of object than it actually is, resulting in access outside of the bounds of the allocated object. iDefense has confirmed the existence of this vulnerability in all currently supported versions of Excel (2007 SP1/SP2, 2003 SP3, XP SP3), and also the currently unsupported Excel 2000 SP3. A full list of vulnerable Microsoft products can be found in Microsoft Security Bulletin MS10-017. | | Author: | Sean Larsson,iDefense Labs | | Homepage: | http://www.idefense.com/ | | File Size: | 4148 | | Related CVE(s): | CVE-2010-0258 | | Last Modified: | Mar 10 10:09:49 2010 | | MD5 Checksum: | bc5319861ff9ff807a6e7bfce8180ecb |
|
| /// File Name: | friendlytr69-sql.txt | Description:
| Friendly-Tech FriendlyTR69 CPE remote management version 2.8.9 suffers from a remote SQL injection vulnerability. | | Author: | Yaniv Miron | | File Size: | 1792 | | Last Modified: | Mar 10 10:08:22 2010 | | MD5 Checksum: | e9c939b6efcdae9fd324a8ff61d3f247 |
|
| /// File Name: | hydra-sqlxss.txt | Description:
| Hydra CMS suffers from cross site scripting and remote SQL injection vulnerabilities. | | Author: | MustLive | | File Size: | 1083 | | Last Modified: | Mar 10 10:07:08 2010 | | MD5 Checksum: | 1e7bf05f74db4c8d6bb5c916597f23bf |
|
|
|
|
|