Searching upgrades software vulnerabilities


The "ICQ Features on Demand" functionality for


The "ICQ Features on Demand" functionality for Mirabilis ICQ Pro 2003a does not properly verify the authenticity of software upgrades, which allows remote attackers to install arbitrary software via a spoofing attack.


Multiple symlink vulnerabilities in portupgrade


Multiple symlink vulnerabilities in portupgrade before Sunday, December 26, 2004_2 in FreeBSD allow local users to (1) overwrite arbitrary files and possibly replace packages to execute arbitrary code via pkg_fetch, (2) overwrite arbitrary files via temporary files when portupgrade upgrades a port or package, or (3) create arbitrary zero-byte files via the pkgdb.fixme temporary file.


The agent remote upgrade interface in Symantec


The agent remote upgrade interface in Symantec Enterprise Security Manager (ESM) before Thursday, April 05, 2007 does not verify the authenticity of upgrades, which allows remote attackers to execute arbitrary code via software that implements the agent upgrade protocol.


Software vulnerabilities results 1 to 4 of 4     
Page: 1