Skip Navigation

  • Home
  • Contact us
  • FAQ
  • Glossary
  • Public key
  • Sitemap
  • Cymraeg
  • What's new
CPNI - Centre for the Protection of National Infastructure

Advanced search

  • About CPNI
  • The threats
  • Security planning
  • Methods of attack
  • Protecting your assets
  • Products and services
    • CSIRTUK advisories
      • Advisories archive
    • General protective security publications
    • InfoSec briefings
    • InfoSec technical notes
    • InfoSec vulnerability disclosures
    • Good practice guidelines
    • Viewpoints
    • Information exchanges
  • Research
Home > Products and services > CSIRTUK advisories > Advisories archive > August 2007

August 2007

August 2007

- 3370 - Yahoo Messenger YVerInfo.dll ActiveX Multiple Remote Buffer Overflow Vulnerabilities

Remote exploitation of multiple buffer overflow vulnerabilities in Yahoo Inc.'s Yahoo! Messenger 8.1 allows attackers to execute arbitrary code with the privileges of the currently logged in user.

- 3366 - Cisco Security Advisory: XSS and SQL Injection in Cisco CallManager/Unified Communications Manager Logon Page

Cisco CallManager and Unified Communications Manager are vulnerable to cross-site Scripting (XSS) and SQL Injection attacks in the lang variable of the admin and user logon pages.

- 3365 - SUN Weekly Summary Week of 19-Aug-2007 - 25-Aug-2007

The Sun(SM) Alert Weekly Summary Report, a newsletter that provides a weekly listing of newly released and updated Sun Alert Notifications

- 3364 - Cisco Security Response: VTY Authentication Bypass Vulnerability

This is the Cisco PSIRT response to the NileSOFT Security Advisory entitled "Bypass Authentication Vulnerability on Cisco Catalyst 3750 12.2(25)", posted on 2007 August 29th at 0900 UTC (GMT).

- 3363 - Firmware version 7.2.1 for AirPort Extreme 802.11n* base stations

A design issue exists in the IPv6 protocol's handling of type 0 routing headers.

- 3359 - Trend Micro ServerProtect Multiple Vulnerabilities

Description of two Trend ServerProtect vulnerabilities by iDefense. 
Note that reports have been received from various sources indicating that there is some scanning for vulnerable systems.

- 3358 - HP Security advisory - Storage Management Appliance (SMA)

Various potential security vulnerabilities have been identified in Microsoft software that is running on the Storage Management Appliance (SMA). Some of these vulnerabilities may be pertinent to the SMA, please check the table in the Resolution section of this Security Bulletin.

- 3357 - ZoneAlarm vulnerabilties

Details of two iDefense Security advisories concerning vulnerabilities in Zone Labs products

- 3356 - SUN Weekly Summary

The Sun(SM) Alert Weekly Summary Report, a newsletter that provides a weekly listing of newly released and updated Sun Alert Notifications

- 3355 - Cisco Security Response: Multiple SIP Vulnerabilities in the Cisco 7960 IP Phones

Cisco PSIRT response to an issue discovered and reported to Cisco by Radu State, Humberto J. Abdelnur and Olivier Festor regarding two Session Initiation Protocol (SIP) vulnerabilities in the Cisco 7940/7960 IP Phones.

- 3354 - HP Openview Security Advisories

Description of a number of vulnerabilities in HP Openview

- 3353 - iDefense Advisories concerning vulnerabilities in IBM DB2 Universal Database

Description of several vulnerabilities in IBM DB2 Universal Database

- 3352 - Cisco Security Advisories

Description of a number of CISCO security advisories

- 3350 - A Good Practice Guide on Pre-employment Screening

New document released by CPNI discussing  preemployment screening.

- 3349 - WebSphere MQ Security Updates Available

Description of vulnerabilities in WebSphere MQ for which IBM have produced security fixes.

- 3346 - Microsoft Security Bulletin Summary for August 2007

This bulletin summary lists Microsoft security bulletins released for August 2007.
  • Accessibility |
  • Terms and conditions |
  • Privacy statement |
  • Data protection act |
  • Freedom of information |