<?xml version="1.0" encoding="ISO-8859-1"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><!-- generator="FeedCreator 1.7.2" --><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="0.91">
    <channel>
        <title>SecuMania.org - vulnerabilitie</title>
        <description><![CDATA[SecuMania.org - Latest vulnerabilities]]></description>
        <link>http://www.secumania.org</link>
        <lastBuildDate>Mon, 06 Jul 2009 09:48:25 +0000</lastBuildDate>
        <generator>FeedCreator 1.7.2</generator>
        <image>
            <url>http://www.secumania.org/templates/modular_plazza/images/logo.gif</url>
            <title>SecuMania Security Portal</title>
            <link>http://www.secumania.org</link>
            <description><![CDATA[SecuMania Security Portal]]></description>
        </image>
        <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/Secumania/Vulnerabilities" type="application/rss+xml" /><feedburner:browserFriendly></feedburner:browserFriendly><item>
            <title>Gnome Evolution iCalendar Multiple Buffer Overflow Vulnerabilities</title>
            <link>http://www.secumania.org/security/vulnerabilities/gnome-evolution-icalendar-multiple-buffer-overflow-vulnerabilities-2008060448294/</link>
            <description><![CDATA[
	Gnome Evolution is prone to multiple buffer-overflow vulnerabilities because it fails to adequately bounds-check user-supplied input before copying it to insufficiently sized buffers. The issues arise when the application handles the iCalendar attachments.Successfully exploiting these issues will allow an attacker to execute arbitrary code in the context of the application. Failed exploit attempts will likely crash the application.Gnome Evolution 2.21.1 is vulnerable to these issues; other versions may also be affected.
]]></description>
            <author>SecuMania.org</author>
            <pubDate>Wed, 04 Jun 2008 05:00:00 +0000</pubDate>
        </item>
        <item>
            <title>Computer Associates eTrust Secure Content Manager Multiple Vulnerabilities</title>
            <link>http://www.secumania.org/security/vulnerabilities/computer-associates-etrust-secure-content-manager-multiple-vulnerabilities-2008060448295/</link>
            <description><![CDATA[
	Computer Associates eTrust Secure Content Manages is prone to multiple vulnerabilities due to unspecified boundary condition errors.Successfully exploiting these issues will allow an attacker to execute arbitrary code in the context of the application or cause denial-of-service conditions.These issues affect Computer Associates eTrust Secure Content Manager 8.0.
]]></description>
            <author>SecuMania.org</author>
            <pubDate>Wed, 04 Jun 2008 05:00:00 +0000</pubDate>
        </item>
        <item>
            <title>HP Instant Support 'HPISDataManager.dll' 'GetFileTime' ActiveX Control Buffer Overflow Vulnerability</title>
            <link>http://www.secumania.org/security/vulnerabilities/hp-instant-support-%27hpisdatamanager.dll%27-%27getfiletime%27-activex-control-buffer-overflow-vulnerability-2008060448297/</link>
            <description><![CDATA[
	HP Instant Support 'HPISDataManager.dll' ActiveX control is prone to a remote buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.HP Instant Support 1.0.0.22 and earlier versions are affected.This issue was originally described in BID 29526 (HP Instant Support 'HPISDataManager.dll' ActiveX Control Unspecified Code Execution Vulnerabilities). Due to the availability of new information, this issue is being assigned a new individual BID.
]]></description>
            <author>SecuMania.org</author>
            <pubDate>Wed, 04 Jun 2008 05:00:00 +0000</pubDate>
        </item>
        <item>
            <title>HP Instant Support 'HPISDataManager.dll' 'MoveFile' ActiveX Control Buffer Overflow Vulnerability</title>
            <link>http://www.secumania.org/security/vulnerabilities/hp-instant-support-%27hpisdatamanager.dll%27-%27movefile%27-activex-control-buffer-overflow-vulnerability-2008060448298/</link>
            <description><![CDATA[
	HP Instant Support 'HPISDataManager.dll' ActiveX control is prone to a remote buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.HP Instant Support 1.0.0.22 and earlier versions are affected.This issue was originally described in BID 29526 (HP Instant Support 'HPISDataManager.dll' ActiveX Control Unspecified Code Execution Vulnerabilities). Due to the availability of new information, this issue is being assigned a new individual BID.
]]></description>
            <author>SecuMania.org</author>
            <pubDate>Wed, 04 Jun 2008 05:00:00 +0000</pubDate>
        </item>
        <item>
            <title>HP Instant Support 'HPISDataManager.dll' 'RegistryString' Buffer Overflow Vulnerability</title>
            <link>http://www.secumania.org/security/vulnerabilities/hp-instant-support-%27hpisdatamanager.dll%27-%27registrystring%27-buffer-overflow-vulnerability-2008060448300/</link>
            <description><![CDATA[
	HP Instant Support 'HPISDataManager.dll' ActiveX control is prone to a remote buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.HP Instant Support 1.0.0.22 and earlier versions are affected.This issue was originally described in BID 29526 (HP Instant Support 'HPISDataManager.dll' ActiveX Control Unspecified Code Execution Vulnerabilities). Due to the availability of new information, this issue is being assigned a new individual BID.
]]></description>
            <author>SecuMania.org</author>
            <pubDate>Wed, 04 Jun 2008 05:00:00 +0000</pubDate>
        </item>
        <item>
            <title>LimeSurvey Prior to 1.71 Multiple Remote Vulnerabilities</title>
            <link>http://www.secumania.org/security/vulnerabilities/limesurvey-prior-to-1.71-multiple-remote-vulnerabilities-2008060348286/</link>
            <description><![CDATA[
	LimeSurvey is prone to multiple remote vulnerabilities, including: - An input-validation vulnerability- Multiple unspecified vulnerabilities An attacker can exploit the input-validation issue to modify quota settings. Very little information is known about the unspecified issues. We will update this BID as soon as more information becomes available. LimeSurvey versions prior to 1.71 are vulnerable.
]]></description>
            <author>SecuMania.org</author>
            <pubDate>Tue, 03 Jun 2008 05:00:00 +0000</pubDate>
        </item>
        <item>
            <title>QuickerSite Multiple Vulnerabilities</title>
            <link>http://www.secumania.org/security/vulnerabilities/quickersite-multiple-vulnerabilities-2008060348292/</link>
            <description><![CDATA[
	QuickerSite is prone to multiple vulnerabilities, including an SQL-injection issue, an authentication-bypass issue, multiple cross-site scripting issues and a file upload vulnerability.Successful exploit may allow attackers to:- access or modify data- exploit latent vulnerabilities in the underlying database- obtain sensitive information- gain unauthorized access to the affected application- upload arbitrary files and execute arbitrary server-side script code- execute arbitrary script code in the browser of an unsuspecting user in the context of the affected siteThis will compromise the application and may help in further attacks.The issues affects QuickerSite 1.8.5; other versions may also be vulnerable.
]]></description>
            <author>SecuMania.org</author>
            <pubDate>Tue, 03 Jun 2008 05:00:00 +0000</pubDate>
        </item>
        <item>
            <title>RETIRED: HP Instant Support 'HPISDataManager.dll' ActiveX Control Unspecified Code Execution</title>
            <link>http://www.secumania.org/security/vulnerabilities/retired%3a-hp-instant-support-%27hpisdatamanager.dll%27-activex-control-unspecified-code-execution-2008060348293/</link>
            <description><![CDATA[
	HP Instant Support 'HPISDataManager.dll' ActiveX control is prone to multiple unspecified vulnerabilities that allow remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.HP Instant Support 1.0.0.22 and earlier versions are affected.NOTE: This BID is being retired; the following individual records have been created to better document the issues:29529 HP Instant Support 'HPISDataManager.dll' 'ExtractCab' ActiveX Control Buffer Overflow Vulnerability29530 HP Instant Support ActiveX Control in 'HPISDataManager.dll' Arbitrary File Download Vulnerability29531 HP Instant Support 'HPISDataManager.dll' 'GetFileTime' ActiveX Control Buffer Overflow Vulnerability 29532 HP Instant Support 'HPISDataManager.dll' 'MoveFile' ActiveX Control Buffer Overflow Vulnerability 29533 HP Instant Support 'HPISDataManager.dll' 'StartApp' ActiveX Control Insecure Method Vulnerability29534 HP Instant Support 'HPISDataManager.dll' 'RegistryString' Buffer Overflow Vulnerability 29535 HP Instant Support 'HPISDataManager.dll' ActiveX Control Arbitrary File Creation Vulnerability29536 HP Instant Support 'HPISDataManager.dll' ActiveX Control Arbitrary File Delete Vulnerability
]]></description>
            <author>SecuMania.org</author>
            <pubDate>Tue, 03 Jun 2008 05:00:00 +0000</pubDate>
        </item>
        <item>
            <title>HP Instant Support ActiveX Control in 'HPISDataManager.dll' Arbitrary File Download Vulnerability</title>
            <link>http://www.secumania.org/security/vulnerabilities/hp-instant-support-activex-control-in-%27hpisdatamanager.dll%27-arbitrary-file-download-vulnerability-2008060348296/</link>
            <description><![CDATA[
	HP Instant Support ActiveX control in 'HPISDataManager.dll' is prone to an arbitrary file-download vulnerability. An attacker may exploit this issue by enticing victims into visiting a maliciously crafted webpage. Successful exploits will allow remote attackers to download files from arbitrary locations to the affected computer.  The attacker can also specify arbitrary download locations on the target system.
]]></description>
            <author>SecuMania.org</author>
            <pubDate>Tue, 03 Jun 2008 05:00:00 +0000</pubDate>
        </item>
        <item>
            <title>HP Instant Support 'HPISDataManager.dll' 'StartApp' ActiveX Control Insecure Method Vulnerability</title>
            <link>http://www.secumania.org/security/vulnerabilities/hp-instant-support-%27hpisdatamanager.dll%27-%27startapp%27-activex-control-insecure-method-vulnerability-2008060348299/</link>
            <description><![CDATA[
	HP Instant Support 'HPISDataManager.dll' ActiveX control is prone to an insecure-method vulnerability.Successfully exploiting this issue allows remote attackers to launch arbitrary applications with the privileges of the application running the ActiveX control (typically Internet Explorer).Note that if the attacker could place a malicious executable on the system, they would be able to launch it using this vulnerability.HP Instant Support 1.0.0.22 and earlier versions are affected.This issue was originally described in BID 29526 (HP Instant Support 'HPISDataManager.dll' ActiveX Control Unspecified Code Execution Vulnerabilities). Due to the availability of new information, this issue is being assigned a new individual BID.
]]></description>
            <author>SecuMania.org</author>
            <pubDate>Tue, 03 Jun 2008 05:00:00 +0000</pubDate>
        </item>
    </channel>
</rss>
