Logo for Rosiello Security.
0bfed6f5caae43af3e38e2ad5f5837e643c5bcfeee1d3d1070ce7bbe8ae7d868
Secure Network Operations, Inc. Advisory SRT2003-05-08-1137: A problem appears to be created by a series of strcat(), sprintf(), and strcpy() functions in ListProc <= 8.2.09 enabling an attacker to gain root privileges through a buffer overflow.
6f50fd0f97d230ad3274da01950442528af3f72db94c34f4def4b44e8d943785
This utility removes LKM rootkits that normally are undetectable via the help of vmalloc which manages the memory for a kernel module. Tested against Adore, Knark, Sinapse, Heroin, and others.
1a65bc5b515606ae0a738c74395b3b5abac289826e46616fd86d68bcd4dc0908
Kerio Personal Firewall <= 2.1.4 and Tiny Personal Firewall <= 2.0.15 remote exploit that makes use of a buffer overflow condition discovered in the PFEngine used for both products.
e09529ee95b595d74fd8ddc93ccb3d46340c18332d5c962f794898dac30815bb
Microsoft's Hotmail and Passport .NET accounts are vulnerable to having their password reset by a remote attacker due to lack of input validation for a secondary email address.
da7c4583da30ce3f7f9b4d3258dccc122a3632f5231b1b2da644115ac2f10a3d
The Intuity Audix voicemail system by default is maintained over port 23 (telnet) in a restricted command interface. If an attacker has a known account/password, they can circumvent this interface and get an unrestricted shell using rexec.
4fcde277b065ccb6ef5420098a7767fb530e514f5b5d5d99c34c266efcaab54a
Happymall E-Commerce software versions 4.3 and 4.4 are vulnerable to remote command execution due to a lack of input validation in the normal_html.cgi script.
eab0754ef30dce301af456ecddca51b467284212d77cc05906c7a6f626e4b8b0
Windows Media Player versions 7 and 8 are vulnerable to a directory traversal attack when skin files are downloaded from Internet. The vulnerability allows malicious users to upload an arbitrary file to an arbitrary location when a victim user views a web page.
6830f8477260f63dd614d39ad9542f854621edd6549ee5f678a0dddd09b987a6