Current e-BulletinThe CCIP e-Bulletin provides a snapshot of security related news.
Read More
Latest Information Note VoIP. This report outlines characteristics and history of VoIP.
Read More
New Zealand Goverment

June 2008

The following table includes the Vulnerability Alerts for the month.

Note: These links reference external sites. CCIP can not accept responsibility for outdated links or such links contents.
Reference Description Date
Ubuntu
Update for ruby1.8
30/06/08
rPath
Update for ruby
30/06/08
Ubuntu
Update for openssl
30/06/08
Orca
Interactive Forum Script "gConf[dir][layouts]" File Inclusion
30/06/08
eTicket
"pri" SQL Injection Vulnerability
30/06/08
Pidgin
MSN File Transfer Filename Processing Vulnerability
30/06/08
Avaya
Communication Manager Input Validation Vulnerabilities
30/06/08
Cisco
Wide Area Application Services CUPS IPP Tags Memory Corruption
30/06/08
Joomla
NBill Component "cid" SQL Injection
30/06/08
Nortel
Media Processing Server OpenSSL Multiple Vulnerabilities
30/06/08
Sun
Solaris Adobe Reader Multiple Vulnerabilities
27/06/08
Internet
Explorer 6 Window "location" Handling Vulnerability
27/06/08
Fedora
Update for ruby
27/06/08
Viral
DX 1 "bannerid" SQL Injection Vulnerability
27/06/08
WebGUI
Collaboration RSS Feed Information Disclosure
26/06/08
mask
PHP File Manager Cookie Security Bypass
26/06/08
Link
ADS 1 "linkid" SQL Injection Vulnerability
26/06/08
Gentoo
Update for ibm-jdk-bin and ibm-jre-bin
26/06/08
Secunia
IBM AFP Viewer Plug-In "SRC" Property Buffer Overflow
26/06/08
Gentoo
Update for libvorbis
26/06/08
Gentoo
Update for freetype
26/06/08
Gentoo
Update for openssl
26/06/08
Dagger
Default.php File Inclusion Vulnerabilities
26/06/08
Adobe
Reader/Acrobat JavaScript Method Handling Vulnerability
26/06/08
HP-UX
HP CIFS Server Multiple Vulnerabilities
26/06/08
Red Hat
update for IBMJava2-JRE and IBMJava2-SDK
25/06/08
Academic
Web Tools SQL Injection and Cross-Site Scripting
25/06/08
Secunia
Benja CMS Cross-Site Scripting and Security Bypass Vulnerabilities
25/06/08
RSS-aggregator
"path" File Inclusion Vulnerability
25/06/08
SUSE
Update for kernel
25/06/08
HTML
Purifier CSS Cross-Site Scripting and Script Insertion
25/06/08
Red Hat
update for freetype
25/06/08
Fedora
Update for php
25/06/08
Joomla
EXP Shop Component "catid" SQL Injection
25/06/08
Fedora
Update for php
25/06/08
Fedora
Update for clamav
25/06/08
Fedora
Update for xemacs-packages-extra
25/06/08
AJ
HYIP "id" SQL Injection Vulnerability
25/06/08
Apple
Safari for Windows Multiple Vulnerabilities
23/06/08
Debian
Update for libtk-img
23/06/08
XnView
Sun TAAC "format" Buffer Overflow Vulnerability
23/06/08
vBulletin
MCP Cross-Site Scripting Vulnerability
23/06/08
RedHat
update for freetype
23/06/08
Mozilla
Firefox Unspecified Code Execution Vulnerability
23/06/08
Cisco
Intrusion Prevention System Jumbo Frames Denial of Service
23/06/08
Drupal
TrailScout Module Cross-Site Scripting and SQL InjectionVulnerabilities
23/06/08
Sun
Solaris FreeType Multiple Vulnerabilities
23/06/08
Various
TYPO3 Extensions Cross-Site Scripting and SQL InjectionVulnerabilities
20/06/08
Fedora
Update for freetype
20/06/08
BASIC-CMS
"page_id" SQL Injection Vulnerability
20/06/08
Open
Azimyt CMS "lang" Local File Inclusion
19/06/08
Exero
CMS "theme" Local File Inclusion Vulnerabilities
19/06/08
Ubuntu
Update for samba
19/06/08
SUSE
Update for Multiple Packages
18/06/08
Debian
Update for imlib2
18/06/08
Gentoo
Update for evolution
18/06/08
Gentoo
Update for cbrpager
18/06/08
Skulltag
Packet Parsing Denial of Service
18/06/08
Crysis
HTTP/XML-RPC Server Denial of Service
18/06/08
ClamAV
Petite Processing Denial of Service Vulnerability
18/06/08
VMware
ESX Server update for Tomcat and Java JRE
18/06/08
Sun
Java System Calendar Server Denial of Service
18/06/08
Avaya
CMS Solaris "inet_network()" Off-By-One Vulnerability
18/06/08
SUSE
Update for evolution
18/06/08
Novell
IPrint Client Unspecified Vulnerability
18/06/08
Gentoo
Update for rdesktop
18/06/08
Red Hat
update for openoffice.org
18/06/08
Red Hat
update for openoffice.org
18/06/08
Fedora
Update for roundcubemail
18/06/08
Pre
ADS Portal SQL Injection Vulnerabilities
18/06/08
Webmatic
Unspecified SQL Injection and Cross-Site Scripting
17/06/08
devalcms
"currentfile" Local File Inclusion
17/06/08
Debian
Update for mt-daapd
16/06/08
Debian
Update for typo3
16/06/08
Fedora
Update for kernel
16/06/08
Red Hat
update for perl
16/06/08
Drupal
Aggregation Module Multiple Vulnerabilities
16/06/08
Citect
Products ODBC Server Component Buffer Overflow
16/06/08
Fedora
Update for openoffice.org
16/06/08
rPath
Update for kernel
16/06/08
Drupal
Magic Tabs Module Arbitrary PHP Code Execution
16/06/08
Sun
StarOffice/StarSuite "rtl_allocateMemory()" Integer Overflow
16/06/08
Sun
Java Access Manager Unspecified Security Bypass
13/06/08
Logitech
Desktop Messenger BackWeb ActiveX Control Unspecified Buffer Overflows
13/06/08
Cisco
Products SNMPv3 Two Vulnerabilities
13/06/08
FreeType
Multiple Vulnerabilities
13/06/08
Sun
Solaris Firefox Multiple Vulnerabilities
13/06/08
BackWeb
Lite Install Runner ActiveX Control Unspecified BufferOverflows
13/06/08
HP-UX
Update for Apache and Tomcat with PHP
13/06/08
TYPO3
File Upload and Cross-Site Scripting Vulnerabilities
13/06/08
Todd Woolums
ASP News Management Information Disclosure and SQLInjection
13/06/08
Apple
QuickTime Multiple Vulnerabilities
11/06/08
Fujitsu
Interstage Management Console Arbitrary File Access
11/06/08
Courier
Authentication Library SQL Injection Vulnerability
11/06/08
OpenOffice
"rtl_allocateMemory()" Integer Overflow Vulnerability
11/06/08
Real-Estate-Website
Cross-Site Scripting and SQL Injection
11/06/08
Pilot
Cart "article" SQL Injection Vulnerability
11/06/08
Realm
CMS Multiple Vulnerabilities
11/06/08
Debian
Update for linux-2.6
11/06/08
Joomla
JoomlaDate Component "user" SQL Injection
11/06/08
Internet Explorer
Unspecified Memory Corruption Vulnerability
11/06/08
Microsoft
Windows Bluetooth SDP Packet Processing Vulnerability
11/06/08
Motion
"read_client()" Off-By-One Vulnerability
11/06/08
Linux
Kernel ASN.1 BER Decoding Vulnerability
11/06/08
Ubuntu
Update for evolution
11/06/08
VLC
Media Player GnuTLS and Libxml2 Vulnerabilities
11/06/08
Novell
GroupWise Messenger Client Buffer Overflow Vulnerabilities
11/06/08
Joomla
YvComment Component "ArticleID" SQL Injection
11/06/08
DB2
Multiple Vulnerabilities
11/06/08
BrowserCRM
"bcrm_pub_root" File Inclusion Vulnerabilities
10/06/08
Joomla
Rapid Recipe Component "recipe_id" SQL Injection
10/06/08
Joomla
GameQ Component "category_id" SQL Injection
10/06/08
SUSE
Update for Multiple Packages
10/06/08
Gentoo
Update for imlib2
10/06/08
Black Ice Barcode
SDK Multiple Vulnerabilities
09/06/08
Fedora
Update for evolution
09/06/08
1Book
"guestbook.php" PHP Code Execution
09/06/08
Secunia
E107 eChat Plugin "nick" SQL Injection
09/06/08
Akamai
Red Swoosh Client Cross-Site Request Forgery
09/06/08
VMware ESX Server
Multiple Security Updates
09/06/08
Cisco
ASA and PIX Security Appliances Multiple Vulnerabilities
09/06/08
Skype
File URI Code Execution Vulnerability
09/06/08
Joomla
JotLoader Component "cid" SQL Injection
09/06/08
RedHat
update for cups
09/06/08
NASA
BigView PPM File Processing Buffer Overflow
09/06/08
Akamai Download Manager
Arbitrary File Download Vulnerability
09/06/08
Asterisk Addons "ooh323"
Denial of Service Vulnerability
09/06/08
Sun
Solaris "inet_network()" Off-By-One Vulnerability
06/06/08
PHP
Address Book Cross-Site Scripting and SQL Injection
06/06/08
Joomla
Simple Shop Galore Component "catid" SQL Injection
06/06/08
SUSE
Update for samba
06/06/08
HP
Instant Support HPISDataManager.dll ActiveX Control Multiple Vulnerabilities
06/06/08
Secunia
Ease Jukebox NCTSoft ActiveX Controls Buffer Overflow Vulnerabilities
06/06/08
Secunia
Ease MP3 Recorder NCTAudioFile2 ActiveX Control Buffer Overflow
06/06/08
Secunia
Saga CD Ripper NCTAudioGrabber2 ActiveX Control Buffer Overflows
06/06/08
Evolution
ICalendar Two Buffer Overflow Vulnerabilities
06/06/08
Joomla
IDoBlog Component "userid" SQL Injection
06/06/08
Gentoo
Update for libxslt
06/06/08
Asterisk
"pedantic" SIP Processing Denial of Service
06/06/08
Icona
SpA DownloaderActiveX ActiveX Control Module Code Execution Vulnerability
06/06/08
CA
Secure Content Manager Multiple Vulnerabilities
06/06/08
CMS
Easyway "mid" SQL Injection Vulnerability
06/06/08
Secunia
Code-it Software Products NCTAudioGrabber2 ActiveX Control Buffer Overflows
06/06/08
Secunia
MightSOFT Products NCTSoft ActiveX Controls Buffer Overflow Vulnerabilities
06/06/08
Joomla
JooBlog Component "CategoryID" SQL Injection
06/06/08
Sun
Java System Active Server Pages Multiple Vulnerabilities
06/06/08
IBM
WebSphere Application Server Web Services UnspecifiedVulnerability
06/06/08
Magic
Rm AVI Mpeg to MP3 Converter & Editor NCTSoft ActiveX ControlsBuffer Overflows
06/06/08
Sleipnir
Script Execution Vulnerability
06/06/08
Red Hat
update for evolution and evolution28
05/06/08
Joomla
JoomRadio Component "id" SQL Injection
05/06/08
Red Hat
update for evolution
05/06/08
Secunia
ALO Software Products NCTAudioFile2 ActiveX Control Buffer Overflow
05/06/08
Fedora
Update for libpng
05/06/08
rPath
Update for samba
05/06/08
rPath
Update for evolution
05/06/08
Secunia
Cool Record Edit NCTAudioFile2 ActiveX Control Buffer Overflow
05/06/08
Sun
Solaris update for Adobe Flash Player
05/06/08
Secunia
ColorfulSoft Products NCTAudioFile2 ActiveX Control Buffer Overflow
05/06/08
Secunia
OtomiGenX "userAccount" SQL Injection Vulnerability
05/06/08
Secunia
Goodvdsoft.com Products NCTAudioFile2 ActiveX Control Buffer Overflow
05/06/08
Secunia
Akram Software Products NCTAudioFile2 ActiveX Control Buffer Overflow
05/06/08
HP
StorageWorks Storage Mirroring Software Unspecified Code Execution
05/06/08
Fedora
Update for imlib2
05/06/08
MDaemon
WorldClient Multiple Vulnerabilities
04/06/08
Debian
Update for libvorbis
04/06/08
Apple
Safari on Windows Code Execution Vulnerability
04/06/08
CMSimple
File Upload and Local File Inclusion
04/06/08
Debian
Update for samba
04/06/08
Fedora
Update for samba
04/06/08
Fedora
Update for openssl
04/06/08
Secunia
LokiCMS admin.php Authentication Bypass Vulnerability
04/06/08
Secunia
TorrentTrader "info_hash" SQL Injection Vulnerability
04/06/08
Linux
Kernel Denial of Service Vulnerabilities
04/06/08
Joomla
PrayerCenter Component "id" SQL Injection Vulnerability
04/06/08
Solaris
Samba Multiple Vulnerabilities
04/06/08
Alt-N
SecurityGateway "username" Buffer Overflow Vulnerability
03/06/08
Joomla
MyContent Component "id" SQL Injection
03/06/08
Avaya
CMS Solaris Print Service Unspecified Vulnerabilities
03/06/08
Secunia
My Phone Files Media Studio NCTAudioInformation2.dll ActiveX Control Buffer Overflow
03/06/08
Secunia
4U WMA MP3 Converter NCTAudioInformation2.dll ActiveX Control Buffer Overflow
03/06/08
Gentoo
Update for samba
03/06/08
Gentoo
Update for mplayer
03/06/08
Secunia
Powerful Audio Tool NCTAudioInformation2.dll ActiveX Control Buffer Overflow
03/06/08
Secunia
Vista MP3 Recorder NCTAudioFile2 ActiveX Control Buffer Overflow
03/06/08
Secunia
DVBBS login.asp SQL Injection Vulnerability
03/06/08
Secunia
Total Audio Recorder and Editor NCTAudioInformation2.dll ActiveX Control Buffer Overflow
03/06/08
Secunia
Digital Smart Software Products NCTAudioFile2 ActiveX Control BufferOverflow
03/06/08
CMS
From Scratch Information Disclosure and File Upload
03/06/08
Secunia
Total Audio Capture NCTAudioInformation2.dll ActiveX Control Buffer Overflow
03/06/08
Secunia
Color7 Technology Products NCTAudioFile2 ActiveX Control Buffer Overflow
03/06/08
Secunia
HiFi Software Products NCTAudioFile2 ActiveX Control Buffer Overflow
03/06/08
Secunia
Gold Wave Editor NCTAudioFile2 ActiveX Control Buffer Overflow
03/06/08
Secunia
RockN Audio NCTAudioFile2 ActiveX Control Buffer Overflow
03/06/08
rPath
Update for evolution
03/06/08
Fedora
Update for kvm
03/06/08
Fedora
Update for libpng10
03/06/08
CiscoWorks
Common Services Unspecified Code Execution Vulnerability
03/06/08
Debian
Update for libxslt
03/06/08
Fedora
Update for cbrpager
03/06/08
Symantec
Backup Exec System Recovery Manager Directory Traversal
03/06/08
Slackware
Update for samba
03/06/08
Secunia
Alive MP3 WAV Converter NCTAudioInformation2.dll ActiveX Control Buffer Overflow
03/06/08

About this Site & Accessibility | Legal, Privacy & Copyright Information | Sitemap | newzealand.govt.nz

Accessibility Page: 0 | Homepage: 1 | Sitemap: 2 | About CCIP: 4 | Vulnerabilities: 5 | Incidents: 6 | Newsroom: 7 | gcsb.govt.nz: 8 | Contact CCIP: 9 | Skip Link: [ | newzealand.govt.nz: /