buffer overflow
Windows Me HyperTerminal Buffer Overflow Vulnerability May 24, 2001
Windows Me HyperTerminal Buffer Overflow Vulnerability May 24, 2001 is a patch used for deleting a security vulnerability in the HyperTerminal application which ships with some Microsoft operating systems more>> <<less
Microsoft Windows 2000 Patch: Hyperterminal Buffer Overflow Update
Microsoft Windows 2000 Patch: Hyperterminal Buffer Overflow Update has come as a useful program which can tackle the HyperTerminal Buffer Overflow security vulnerability in Windows 2000. more>>
Microsoft Windows 2000 Patch: Hyperterminal Buffer Overflow Update has come as a useful program which can tackle the "HyperTerminal Buffer Overflow" security vulnerability in Windows 2000. If you receive and open an HTML e-mail message that contains a particularly malformed Web address (URL), the URL can be used to exploit this vulnerability and run arbitrary code on your computer.
Note Although HyperTerminal ships as part of several Microsoft products, it was developed by Hilgraeve, Inc.
Windows Phone Book Service Buffer Overflow Vulnerability Patch 1.0
Windows Phone Book Service Buffer Overflow Vulnerability Patch is developed to be a helpful program to remove a security vulnerability in an optional service more>>
Windows Phone Book Service Buffer Overflow Vulnerability Patch 1.0 is developed to be a helpful program to remove a security vulnerability in an optional service that ships with Windows 2000 Servers. The vulnerability could allow a malicious user to execute hostile code on a remote server that is running the service.
Microsoft Windows NT 4.0 Patch: Phone Book Service Buffer Overflow Update
Microsoft Windows NT 4.0 Patch: Phone Book Service Buffer Overflow Update brings you an update designed for solving the Phone Book Service Buffer Overflow security vulnerability in Windows NT® 4.0. more>> <<less
Windows 2000 HyperTerminal Buffer Overflow Vulnerability Patch May 25, 2001
Windows 2000 HyperTerminal Buffer Overflow Vulnerability Patch is an update to resolve the HyperTerminal Buffer Overflow security vulnerability in Windows 2000 more>>
Windows 2000 HyperTerminal Buffer Overflow Vulnerability Patch May 25, 2001 is an update to resolve the 'HyperTerminal Buffer Overflow' security vulnerability in Windows 2000. If you receive and open an HTML e-mail message that contains a particularly malformed Web address (URL), the URL can be used to exploit this vulnerability and run arbitrary code on your computer.
Microsoft Windows NT 4.0 Patch: Hyperterminal Buffer Overflow Vulnerability Update
Microsoft Windows NT 4.0 Patch: Hyperterminal Buffer Overflow Vulnerability Update is written to be an essential update to deal with two HyperTerminal Buffer Overflow security vulnerabilities in computers running Windows NT® 4.0 more>> <<less
Microsoft Windows ME Security Patch: HyperTerminal Buffer Overflow Vulnerability 10-18-00
The HyperTerminal application is a utility that installs, by default, on all versions of Windows 98, 98SE, Windows ME, Windows NT, and Windows 2000. The product contains an unchecked buffer in a secti more>>
Microsoft Windows 2000 Security Patch: HyperTerminal Buffer Overflow Vulnerability 10-18-00
The HyperTerminal application is a utility that installs, by default, on all versions of Windows 98, 98SE, Windows ME, Windows NT, and Windows 2000. The product contains an unchecked buffer in a secti more>>
Microsoft Windows 98/98SE Security Patch: HyperTerminal Buffer Overflow Vulnerability 10-18-00
The HyperTerminal application is a utility that installs, by default, on all versions of Windows 98, 98SE, Windows ME, Windows NT, and Windows 2000. The product contains an unchecked buffer in a secti more>>
Tab Overflow Scrollbar 1.7
Adds a horizontal scrollbar below the tab bar when Firefox 2 is in tab overflow mode for easier tab navigation more>>
Tab Overflow Scrollbar will also give a vertical scrollbar to the alltabs dropdown menu, when its required.
ASF Buffer Fix 1.0.0
ASF Buffer Fix - change values and fix ASF Buffer problems more>>
ASF Buffer Fix is a simple tool designed to change a few values in the file headers to fix this problem. This is done in-place (without writing a new copy of the file) and is very quick.
System requirements:
- NET Framework 2.0
Buffer Synth 2 1.03
Buffer Synth 2 is like a cross between a wave-table synthesizer and GRM Tools Freeze plugin more>>
Tomasz asked me to do a sequel to Buffer Synth and I got a bit carried away and created a bit of a monster. Please read the manual, theres a couple of things the plugin can do that you wont be able to work out from just playing with the gui. (Its almost obvious that Tomasz did the gui for this one as well)
Note: If youre running a Matrox G550 graphics card, be sure to make sure Use Bus Mastering is turned on, otherwise the plugins gui will be unbearably slow.
Buffer Overrun in MDAC Function Could Allow Code E 1.0
Microsoft Data Access Components (MDAC) is a collection of components that provides the underlying functionality for a number of database operations, such as connecting to remote databases and more>> Microsoft Data Access Components (MDAC) is a collection of components that provides the underlying functionality for a number of database operations, such as connecting to remote databases and returning data to a client. When a client system on a network tries to see a list of computers that are running SQL Server and that reside on the network, it sends a broadcast request to all the devices that are on the network. Because of a vulnerability in a specific MDAC component, an attacker could respond to this request with a specially-crafted packet that could cause a buffer overflow.
An attacker who successfully exploited this vulnerability could gain the same level of privileges over the system as the program that initiated the broadcast request. The actions an attacker could carry out would be dependent on the permissions under which the program using MDAC ran. If the program ran with limited privileges, an attacker would be limited accordingly; however, if the program ran under the local system context, the attacker would have the same level of permissions.
Since the original version of MDAC on your system may have changed from updates available on the Microsoft Web site, we recommend using the following tool to determine the version of MDAC you have on your system: Microsoft Knowledge Base article 301202 "HOW TO: Check for MDAC Version" discusses this tool and explains how to use it. Also, Microsoft Knowledge Base article 231943 discusses the release history of the different versions of MDAC.
Mitigating factors:
- For an attack to be successful an attacker would have to simulate a SQL server that is on the same IP subnet as the target system.
- When a client system on a network tries to see a list of computers that are running SQL Server and that reside on the network, it sends a broadcast request to all the devices that are on the network. A target system must initiate such a broadcast request to be vulnerable to an attack. An attacker would have no way of launching this first step but would have to wait for anyone to enumerate computers that are running SQL Server on the same subnet. Also, a system is not vulnerable by having these SQL management tools installed.
- Code executed on the client system would only run under the privileges of the client program that made the broadcast request.
Firefox 1.0.7
Mozilla Firefox is a fast, full-featured Web browser more>> Firefox 1.0.7 is a security and stability release. We strongly recommend that all users upgrade to this latest version.
This version includes several security and stability fixes, including a fix for a reported buffer overflow vulnerability and a fix for a Linux shell command vulnerability.
Specific changes in Firefox 1.0.7
Fix for a potential buffer overflow vulnerability when loading a hostname with all soft-hyphens
Fix to prevent URLs passed from external programs from being parsed by the shell (Linux only)
Fix to prevent a crash when loading a Proxy Auto-Config (PAC) script that uses an "eval" statement
Fix to restore InstallTrigger.getVersion() for Extension authors<<less
Buffer Overrun in MDAC Function Could Allow Code Execution (832483) 1.0
Buffer Overrun in MDAC Function Could Allow Code Execution (832483) is an advanced program which satisfies you with a collection of components that provides the underlying functionality for a number of database operations, such as connecting to remote databases and returning data to a client. more>>
Buffer Overrun in MDAC Function Could Allow Code Execution (832483) 1.0 is an advanced program which satisfies you with a collection of components that provides the underlying functionality for a number of database operations, such as connecting to remote databases and returning data to a client.
When a client system on a network tries to see a list of computers that are running SQL Server and that reside on the network, it sends a broadcast request to all the devices that are on the network. Because of a vulnerability in a specific MDAC component, an attacker could respond to this request with a specially-crafted packet that could cause a buffer overflow.
An attacker who successfully exploited this vulnerability could gain the same level of privileges over the system as the program that initiated the broadcast request. The actions an attacker could carry out would be dependent on the permissions under which the program using MDAC ran. If the program ran with limited privileges, an attacker would be limited accordingly; however, if the program ran under the local system context, the attacker would have the same level of permissions.
Since the original version of MDAC on your system may have changed from updates available on the Microsoft Web site, recommend using the following tool to determine the version of MDAC you have on your system: Microsoft Knowledge Base article 301202 "HOW TO: Check for MDAC Version" discusses this tool and explains how to use it. Also, Microsoft Knowledge Base article 231943 discusses the release history of the different versions of MDAC.
Mitigating factors:
- For an attack to be successful an attacker would have to simulate a SQL server that is on the same IP subnet as the target system.
- When a client system on a network tries to see a list of computers that are running SQL Server and that reside on the network, it sends a broadcast request to all the devices that are on the network. A target system must initiate such a broadcast request to be vulnerable to an attack. An attacker would have no way of launching this first step but would have to wait for anyone to enumerate computers that are running SQL Server on the same subnet. Also, a system is not vulnerable by having these SQL management tools installed.
- Code executed on the client system would only run under the privileges of the client program that made the broadcast request.