Category Archives: Badware


Badware and virus programs in general

CVE-2008-2089 (Solaris)

Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (panic) via a crafted SCTP packet.

Posted in Badware | Leave a comment

CVE-2008-2092 (SPA-2102 Phone Adapter)

Linksys SPA-2102 Phone Adapter 3.3.6 allows remote attackers to cause a denial of service (crash) via a long ping packet (“ping of death”). NOTE: the severity of this issue has been disputed since there are limited attack scenarios.

Posted in Badware | Leave a comment

CVE-2008-2089 (Solaris)

Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (panic) via a crafted SCTP packet.

Posted in Badware | Leave a comment

CVE-2008-2089 (Solaris)

Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (panic) via a crafted SCTP packet.

Posted in Badware | Leave a comment

CVE-2008-2091 (kubelance)

Directory traversal vulnerability in ipn.php in KubeLabs Kubelance 1.6.4 allows remote attackers to include and execute arbitrary local files via the i parameter.

Posted in Badware | Leave a comment

CVE-2008-2091 (kubelance)

Directory traversal vulnerability in ipn.php in KubeLabs Kubelance 1.6.4 allows remote attackers to include and execute arbitrary local files via the i parameter.

Posted in Badware | Leave a comment

CVE-2008-2089 (Solaris)

Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (panic) via a crafted SCTP packet.

Posted in Badware | Leave a comment

CVE-2008-2005 (InTouch, SuiteLink)

The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, allows remote attackers to cause a denial of service (NULL pointer dereference and service shutdown) and possibly execute arbitrary code via a large length value in a Registration packet to TCP port 5413, which causes a memory allocation failure.

Posted in Badware | Leave a comment

CVE-2008-2087 (Web Hosting Directory Script)

SQL injection vulnerability in search_result.php in Softbiz Web Host Directory Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the host_id parameter, a different vector than CVE-2005-3817.

Posted in Badware | Leave a comment

CVE-2008-2092 (SPA-2102 Phone Adapter)

Linksys SPA-2102 Phone Adapter 3.3.6 allows remote attackers to cause a denial of service (crash) via a long ping packet (“ping of death”). NOTE: the severity of this issue has been disputed since there are limited attack scenarios.

Posted in Badware | Leave a comment