Multiple Vendor NOS Microsystems getPlus Downloader Stack Buffer Overflow Vulnerability
9 Nov. 2008
Summary
The getPlus Download Manager is "a software management tool. It is used to download, install, and update other software through the browser. The getPlus Download Manager consists of an ActiveX control that is used to prompt users to install other vendor's software. Adobe uses this control for web based installations of Adobe Reader. If a client installed Adobe Reader through the Adobe website, they will have the control on their system". Remote exploitation of a stack based buffer overflow vulnerability in NOS Microsystems Ltd.'s getPlus Download Manager, potentially used by multiple vendors, could allow an attacker to execute arbitrary code with the privileges of the current user.
Credit:
The information has been provided by iDefense Labs Security Advisories.
The original article can be found at: http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=754
http://www.securiteam.com/windowsntfocus/6U0082KN5Y.html
Orb Media Server Directory Traversal
9 Nov. 2008
Summary
Orb Networks' Orb media server is vulnerable to directory traversal attacks. Users can leverage specially crafted GET requests to read arbitrary files.
Credit:
The information has been provided by Steven James and r at b13$.
http://www.securiteam.com/windowsntfocus/6T0072KN5W.html

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic