ertisan
No favorite files added yet
(Jan 28, 2007 - 10:41 AM)
Highly critical flaw in OpenOffice 2.x (2007-01-04)
http://secunia.com/advisories/23612/
Critical: Highly critical
Impact: System access
Where: From remote
Software: OpenOffice.org 2.x
OpenOffice 1.1.x
OpenOffice 1.0.x
John Heasman has reported some vulnerabilities in OpenOffice, which can be exploited by malicious people to compromise a user's system.
Successful exploitation of the vulnerabilities allows execution of arbitrary code and requires that a user is tricked into opening a specially crafted WMF/EMF file or a specially crafted document.
The vulnerabilities are reported in OpenOffice prior to version 2.1.0. Other versions may also be affected.
Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to execute arbitrary code via a crafted (a) WMF or (b) EMF file that triggers heap-based buffer overflows in (1) wmf/winwmf.cxx, during processing of META_ESCAPE records; and wmf/enhwmf.cxx, during processing of (2) EMR_POLYPOLYGON and (3) EMR_POLYPOLYGON16 records.
(Nov 1, 2006 - 8:46 AM)
WinAMP Pro Version $14.95
WMP11 is free
(Nov 1, 2006 - 8:32 AM)
I hate using different programs when you can do it better with 1 unique program. WMP11 is better and lighter than WinAMP. WMP11 Instant Search is fantastic! With WMP11 you can also organize and watch your photos!!!
WinAmp Pro version prize is $14.95, instead WMP11 is free and better
(Nov 1, 2006 - 8:28 AM)
I've tested many times with IE7 under WinXP SP2 and Secunia exploit doesn't work so IE7 is NOT affected by this flaw.
(Oct 31, 2006 - 9:10 AM)
Another new flaw in Firefox 2.0
Mozilla Firefox 2.0 is prone to a DoS within its javascript Range object. In a
special condition, a NULL Pointer Deference occur and Firefox crashes. Code execution is possible but not yet verified.
PoC test here: http://security-protocols.com/poc/ff2_death.html