Thinking OPEN

Contributor Archive

E-courirer Cms [Medium]

By Security Team • Nov 6th, 2009 • Category: Security Notifications

Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbitrary web script or HTML via the UserGUID parameter to (1) Wizard_tracking.asp, (2) wizard_oe2.asp, (3) your-register.asp, (4) main-whyregister.asp, and (5) your.asp in home/, and other unspecified vectors…

CVE Identifier: CVE-2009-3905
Vulnerability Type(s):
Severity: Medium



E-courirer Cms [Medium]

By Security Team • Nov 6th, 2009 • Category: Security Notifications

Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbitrary web script or HTML via the UserGUID parameter to home/index.asp and other unspecified vectors….

CVE Identifier: CVE-2009-3901
Vulnerability Type(s):
Severity: Medium



Blender 2.49b and prior [High]

By Security Team • Nov 6th, 2009 • Category: Security Notifications

Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoad action of a ScriptLink SDNA….

CVE Identifier: CVE-2009-3850
Vulnerability Type(s):
Severity: High



Vulndisco Pack 8.12 and prior [High]

By Security Team • Nov 5th, 2009 • Category: Security Notifications

Buffer overflow in Sun Java System Web Server 7.0 Update 6 has unspecified impact and remote attack vectors, as demonstrated by the vd_sjws module in VulnDisco Pack Professional 8.12…

CVE Identifier: CVE-2009-3878
Vulnerability Type(s):
Severity: High



Jdk 1.6.0 and prior [Medium]

By Security Team • Nov 5th, 2009 • Category: Security Notifications

Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP headers, which are not properly parsed by the ASN.1 DER input stream parser, aka Bug Id 6864911….

CVE Identifier: CVE-2009-3877
Vulnerability Type(s):
Severity: Medium



Jdk 1.6.0 and prior [Medium]

By Security Team • Nov 5th, 2009 • Category: Security Notifications

Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted DER encoded data, which is not properly decoded by the ASN.1 DER input stream parser, aka Bug Id 6864911….

CVE Identifier: CVE-2009-3876
Vulnerability Type(s):
Severity: Medium



Jdk 1.6.0 and prior [Medium]

By Security Team • Nov 5th, 2009 • Category: Security Notifications

The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors related to “timing attack vulnerabilities,” aka Bug Id 6863503….

CVE Identifier: CVE-2009-3875
Vulnerability Type(s):
Severity: Medium



Jdk 1.6.0 and prior [High]

By Security Team • Nov 5th, 2009 • Category: Security Notifications

Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via large subsample dimensions in a JPEG file that triggers a heap-based buffer overflow, aka Bug Id 6874643….

CVE Identifier: CVE-2009-3874
Vulnerability Type(s):
Severity: High



Jdk 1.6.0 and prior [Low]

By Security Team • Nov 5th, 2009 • Category: Security Notifications

The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a “quantization problem,” aka Bug Id 6862968….

CVE Identifier: CVE-2009-3873
Vulnerability Type(s):
Severity: Low



Jdk 1.6.0 and prior [Unknown Severity]

By Security Team • Nov 5th, 2009 • Category: Security Notifications

Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862969….

CVE Identifier: CVE-2009-3872
Vulnerability Type(s):
Severity: Unknown Severity