IOActive security consultants discovered and disclosed the following vulnerabilities.
Buffer Overflow in Mono BigInteger Montgomery Reduction Method
CVE-2007-5197, VU#146292
- Date Discovered 07.25.07
- Date Reported 08.24.07
- Date Disclosed 09.20.07
Synopsis
An exploitable buffer overflow vulnerability in the Montgomery reduction method within the Mono Frameworks BigInteger Class (Mono.Math.BigInteger).
IOActive technical details (PDF)
|
Multiple Total Remote Compromise Vulnerabilities in Mercury SiteScope Monitoring Software
CVE-2007-6257, VU#245025
- Date Discovered 10.05.06
- Date Disclosed 09.20.07
Synopsis
Critical vulnerabilities within the Mercury SiteScope server monitoring software, some of which allow for complete remote compromise of the entire monitored network as well as arbitrary code execution on all servers managed by the SiteScope software.
IOActive technical details (PDF)
|
Multiple Buffer Overflows in legacy mod_jk2 apache module 2.0.3-DEV and earlier
CVE-2007-6257, VU#245025
- Date Discovered 05.01.07
- Date Reported 06.27.07
- Date Disclosed 09.20.07
Synopsis
A buffer overflow in the Host Header field of the legacy version of the mod_jk2 apache module (jakata-tomcat-connectors) which allows for remote code execution in the context of the apache process.
IOActive technical details (PDF)
|
Numerous WebEOC Vulnerabilities
VU#956762, VU#170394, VU#138538, VU#372797, VU#491770, VU#258834, and VU#388282
Dates First Published July 2005
Synopsis
- • WebEOC is vulnerable to a denial-of-service condition via uploading large files (VU#956762). Technical details
- • WebEOC account lock-out policy may allow a denial-of-service (VU#170394). Technical details
- • WebEOC is vulnerable to cross-site scripting attacks (VU#138538). Technical details
- • WebEOC contains multiple SQL injection vulnerabilities (VU#372797). Technical details
- • WebEOC implements weak algorithms to encrypt sensitive information (VU#491770). Technical details
- • WebEOC privileges are based on client-side authorization (VU#258834). Technical details
- • WebEOC uses a global shared key (VU#388282). Technical details
|
|