Games
| |
3-D, Action, Adventure, Fighting, Flight, Gaming Utilities, Racing, Sports, Strategy/War |
Internet
| |
Anti-Spam Tools, Browser Utilities, Browsers, Chat - IRC, Chat - Video, Dial-up Networking, Download Managers, E-Commerce, E-mail Clients, Email Notification, eBay Utilities, FTP, HTML Editors, HTML Tools, Instant Messaging, Internet Phones, Modem Sharing, Network Information, Online Security, Privacy & Anonymity, Push Media, Real Time Stock, Real Time Weather, Search Utilities, Server Software, Telnet, Time Synch, Usenet Readers, Usenet Utilities, VRML, Web Site Promotion, WebCams, Winsock Utilities |
Media
| |
Animation, Audio Editors, Audio Players, Audio Plug-ins, CD Players, Image Editors, Image Plug-ins, Image Viewers, MP3 Encoders, MP3 Players, MP3 Rippers, MP3 Utilities, Video Editors, Video Players, Video Plug-ins |

|
|
Previous Page
-
Next Page
Jump to Page:
1
.
2
.
3
.
4
.
5
.
6
.
7
.
8
.
9
.
10
.
11
.
12
.
13
.
14
.
15
.
16
.
17
.
18
.
19
.
20

Download It!
|
Microsoft File Access Vulnerability in Personal Web Server Security Patch
|
Status:Free
|
|
Not Rated
|
|
Microsoft has released a patch that eliminates a vulnerability in certain
versions of Personal Web Server running under Windows 95 or Windows 98,
which could allow files on the server to be read by an unauthorized user
who knew the name of the file and requested it via a specific non-standard
URL. Users running web server products on Microsoft Windows NT are not
affected. This vulnerability allows a file request that uses a non-standard URL to
bypass the server's normal file access controls. The file must be
specifically requested by name, so the requester would need to know the
name of the file or correctly guess it. The vulnerability would allow files
on the server to be read, but not changed or deleted, and would not allow
new files to be written to the server. The vulnerability does not usurp any
administrative privileges on the server.
Although some of the affected products are provided as part of Windows 95
and 98, none are turned on by default. Further, none of the affected
products exhibit the vulnerability when run on Windows NT.
|
File Size:
0.000Mb
|
Homepage Link
|
|

Download It!
|
Microsoft IIS "Domain Resolution" and "FTP Download" Vulnerabilities patch
|
Status:Free
|
|
Not Rated
|
|
Microsoft has released a patch that eliminates two security
vulnerabilities in Microsoft Internet Information Server 4.0.
The vulnerabilities allow security restrictions in IIS to be
bypassed under certain conditions, as discussed below. There are two vulnerabilities at issue here:
- IIS 4.0 provides the ability to restrict access to a web
site based on the user's domain. However, if IIS cannot
resolve a user's IP address to a domain, it will grant
the user's first request for a session. It will correctly
deny them thereafter.
- A user who accesses an FTP site via a browser will be able
to download files even if they are marked No Access. This
vulnerability is due to a regression error that was
introduced in hotfixes released after Windows NT 4.0 Service
Pack 5; it does not exist in SP5 or in previous versions.
Neither vulnerability provides a means to usurp control of the server. A
patch is available that eliminates both vulnerabilities.
|
File Size:
0.000Mb
|
Homepage Link
|
|
![]()
Download It!
|
Microsoft IIS "Double Byte Code Page" vulnerability (updated patch)
|
Status:Free
|
|
Not Rated
|
|
Microsoft has released a patch that
eliminates a vulnerability in
Microsoft Internet Information Server that
could allow a web site
visitor to view the source code for selected
files on the server, if the
server's default language is set to Chinese,
Japanese or Korean. When IIS is run on a
machine on which a double-byte character set
code page
is used (i.e., the default language on the
server is set to Chinese,
Japanese, or Korean), and a specific URL
construction is used to request a
file in a virtual directory, normal
server-side processing is bypassed. As
a result, the file is simply delivered as
text to the browser, thereby
allowing the source code to be viewed. Microsoft has identifed and corrected a regression error in the IIS 4.0
version of the previously-released patch for the "Double Byte Code Page"
vulnerability. The corrected patch has been re-released.
|
File Size:
0.000Mb
|
Homepage Link
|
|

Download It!
|
Microsoft IIS "Escape Character Parsing" Vulnerability patch
|
Status:Free
|
|
Not Rated
|
|
RFC 1738 specifies that web servers must allow hexadecimal digits to be
input in URLs by preceding them with the so-called "escape" character, a
percent sign. IIS complies with this specification, but also accepts
characters after the percent sign that are not hexadecimal digits. Some of
these translate to printable ASCII characters, and this could provide an
alternate means of specifying files in URLs.
The vulnerability does not affect IIS; even specifying a file name via this
alternate method does not bypass IIS' access controls. However, third-party
software that runs atop IIS but does not perform canonicalization is
affected by it.
|
File Size:
0.000Mb
|
Homepage Link
|
|

Download It!
|
Microsoft IIS "GET" Vulnerability security fix
|
Status:Free
|
|
Not Rated
|
|
Microsoft has released a patch that fixes a vulnerability in Microsoft
Internet Information Server that could allow denial-of-service attacks
to be mounted against web servers. This vulnerability involves the HTTP GET method, which is used to obtain
information from an IIS web server. Specially-malformed GET requests can
create a denial of service situation that consumes all server resources,
causing a server to "hang." In some cases, the server can be put back into
service by stopping and restarting IIS; in others, the server may need to be
rebooted. This situation cannot happen accidentally. The malformed GET
requests must be deliberately constructed and sent to the server. It is
important to note that this vulnerability does not allow data on the server
to be compromised, nor does it allow any privileges on it to be usurped.
|
File Size:
0.500Mb
|
Homepage Link
|
|
Previous Page
-
Next Page
Jump to Page:
1
.
2
.
3
.
4
.
5
.
6
.
7
.
8
.
9
.
10
.
11
.
12
.
13
.
14
.
15
.
16
.
17
.
18
.
19
.
20
|
|