|
62208
|
Disclosed: 2010-01-12
Description:
Unknown / Incomplete
Comments: 0, Blogs: 0, References: 1
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
Ipswitch WhatsUp Gold Vulnerability Scan Remote DoS
|
|
62207
|
Disclosed: 2009-11-13
Description:
Unknown / Incomplete
Comments: 0, Blogs: 0, References: 5
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
Fujitsu Multiple Products SSL Server Unspecified File Descriptor Exhaustion DoS
|
|
62206
|
Disclosed: 2009-11-13
Description:
Unknown / Incomplete
Comments: 0, Blogs: 0, References: 5
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
Fujitsu Multiple Products Expired CA SSL Certificate Issue Restriction Bypass
|
|
62205
|
Disclosed: 2009-11-13
Description:
Unknown / Incomplete
Comments: 0, Blogs: 0, References: 5
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
Fujitsu Multiple Products Client SSL Certificate Handling Overflow
|
|
62204
|
Disclosed: 2009-12-23
Description:
Unknown / Incomplete
Comments: 0, Blogs: 0, References: 1
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
Veritas Cluster Server (VCS) Notifier Resource Vulnerability Scan Remote DoS
|
|
62203
|
Disclosed: 2010-01-21
Description:
Unknown / Incomplete
Comments: 0, Blogs: 0, References: 4
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| - Input Manipulation
- Information Disclosure
| | | | | |
|
SAP BusinessObjects BusinessProcessBI/axis2-web/HappyAxis.jsp Information Disclosure
|
|
62202
|
Disclosed: 2010-01-21
Description:
Unknown / Incomplete
Comments: 0, Blogs: 0, References: 4
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| - Input Manipulation
- Information Disclosure
| | | | | |
|
SAP BusinessObjects dswsbobje/axis2-web/HappyAxis.jsp Information Disclosure
|
|
62201
|
Disclosed: 2010-01-21
Description:
Unknown / Incomplete
Comments: 0, Blogs: 0, References: 11
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
SAP BusinessObjects PerformanceManagement/jsp/wait-frameset.jsp dummyParam Parameter XSS
|
|
62200
|
Disclosed: 2010-01-21
Description:
Unknown / Incomplete
Comments: 0, Blogs: 0, References: 11
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
SAP BusinessObjects PerformanceManagement/jsp/viewWebiReportHeader.jsp sEntry Parameter XSS
|
|
62199
|
Disclosed: 2010-01-21
Description:
Unknown / Incomplete
Comments: 0, Blogs: 0, References: 11
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
SAP BusinessObjects PerformanceManagement/jsp/ic_pm/wigoalleftlisttr.jsp flowid Parameter XSS
|
|
|
|
|
|
18293
|
Views: 505
Description:
By default, many of Belkin wireless routers using a default ssid of "belkin54g" are preconfigured with a default password. The "admin" account has a null password which is publicly known and documented. This allows attackers to trivially access the program or system.
Comments: 1, Blogs: 0, References: 5
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| - Authentication Management
| | | | | |
|
Belkin 54G Routers Admin Account Default Null Password
|
|
61697
|
Views: 257
Description:
Internet Explorer contains a flaw that may allow a context-dependent attacker to execute arbitrary code. The issue is triggered when a specially crafted website causes mshtml.dll to access memory that has been freed, allowing code execution.
Comments: 0, Blogs: 34, References: 17
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
- Context Dependent
- Local / Remote
| | | | | | |
|
Microsoft IE mshtml.dll Use-After-Free Arbitrary Code Execution (Aurora)
|
|
382
|
Views: 206
Description:
By default, PostgresSQL installs without a default password for the postgres user account. This username and password combination is publicly known and documented. This allows attackers to trivially access the program or system with administrative priveleges.
Comments: 0, Blogs: 0, References: 19
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
- Remote / Network Access
- Local Access Required
| - Authentication Management
| - Loss of Confidentiality
- Loss of Integrity
- Loss of Availability
| | | | |
|
PostgreSQL Server Default Password
|
|
40621
|
Views: 144
Description:
Simple PHP Blog contains a flaw that allows a remote Cross-Site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps and/or confirmation for sensitive transactions to delete posts. By using a crafted URL (e.g. a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
Comments: 0, Blogs: 0, References: 8
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
Simple PHP Blog (SPHPBlog) add_link.php link_id Parameter CSRF
|
|
877
|
Views: 138
Description:
RFC compliant web servers support the TRACE HTTP method, which contains a flaw that may lead to an unauthorized information disclosure. The TRACE method is used to debug web server connections and allows the client to see what is being received at the other end of the request chain. Enabled by default in all major web servers, a remote attacker may abuse the HTTP TRACE functionality, i.e. cross-site scripting (XSS), which will disclose sensitive configuration information resulting in a loss of confidentiality.
Comments: 0, Blogs: 0, References: 28
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
Multiple Web Server Dangerous HTTP Method TRACE
|
|
3092
|
Views: 135
Description:
A potentially interesting file, directory or CGI was found on the web server. While there is no known vulnerability or exploit associated with this, it may contain sensitive information which can be disclosed to unauthenticated remote users, or aid in more focused attacks.
Comments: 0, Blogs: 0, References: 770
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
Interesting Web Document Found
|
|
60980
|
Views: 130
Description:
Acrobat and Reader contain a flaw that may allow an attacker to execute arbitrary code. The issue is triggered by a use-after-free condition in Doc.media.newPlayer when parsing a specially crafted PDF file.
Comments: 0, Blogs: 9, References: 37
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
- Local / Remote
- Context Dependent
| | | | | - Vendor Verified
- Uncoordinated Disclosure
- Discovered in the Wild
| |
|
Adobe Reader / Acrobat Doc.media.newPlayer Use-After-Free Arbitrary Code Execution
|
|
59968
|
Views: 122
Description:
(Description Provided by CVE) : The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
Comments: 0, Blogs: 1, References: 57
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
Microsoft IIS SSL / TLS Renegotiation Handshakes MiTM Plaintext Data Injection
|
|
16866
|
Views: 121
Description:
A remote overflow exists in Terminator 3: War of the Machines. The application fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted request containing an overly long CD-key hash, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
Comments: 0, Blogs: 0, References: 6
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
Terminator 3: War of the Machines Client CD-key Overflow
|
|
44643
|
Views: 102
Description:
A buffer overflow exists in HD Audio Codec Driver. RTKVHDA.sys and RTKVHDA64.sys fail to validate IOCTL requests resulting in an integer overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
Comments: 0, Blogs: 0, References: 8
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | - Vendor Verified
- Coordinated Disclosure
| |
|
Realtek HD Audio Codec Driver RTKVHDA.sys / RTKVHDA64.sys IOCTL Request Handling Overflow
|
|
|
61697
|
Blogs: 34
Description:
Internet Explorer contains a flaw that may allow a context-dependent attacker to execute arbitrary code. The issue is triggered when a specially crafted website causes mshtml.dll to access memory that has been freed, allowing code execution.
Comments: 0, Blogs: 34, References: 17
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
- Context Dependent
- Local / Remote
| | | | | | |
|
Microsoft IE mshtml.dll Use-After-Free Arbitrary Code Execution (Aurora)
|
|
61651
|
Blogs: 6
Description:
(Description Provided by CVE) : Integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) in Microsoft Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code via compressed data that represents a crafted EOT font, aka "Microtype Express Compressed Fonts Integer Flaw in the LZCOMP Decompressor Vulnerability."
Comments: 0, Blogs: 6, References: 8
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
- Remote / Network Access
- Context Dependent
| | | | | | |
|
Microsoft Windows Embedded OpenType Font Engine LZCOMP Decompressor Font Handling Arbitrary Code Execution
|
|
60980
|
Blogs: 5
Description:
Acrobat and Reader contain a flaw that may allow an attacker to execute arbitrary code. The issue is triggered by a use-after-free condition in Doc.media.newPlayer when parsing a specially crafted PDF file.
Comments: 0, Blogs: 9, References: 37
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
- Local / Remote
- Context Dependent
| | | | | - Vendor Verified
- Uncoordinated Disclosure
- Discovered in the Wild
| |
|
Adobe Reader / Acrobat Doc.media.newPlayer Use-After-Free Arbitrary Code Execution
|
|
61904
|
Blogs: 2
Description:
(Description Provided by CVE) : Multiple integer overflows in Adobe Shockwave Player before 11.5.6.606 allow remote attackers to execute arbitrary code via (1) an unspecified block type in a Shockwave file, leading to a heap-based buffer overflow; and might allow remote attackers to execute arbitrary code via (2) an unspecified 3D block in a Shockwave file, leading to memory corruption; or (3) a crafted 3D model in a Shockwave file, leading to heap memory corruption.
Comments: 0, Blogs: 2, References: 11
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
Adobe Shockwave Player Crafted 3D Model Memory Corruption Overflow
|
|
60521
|
Blogs: 1
Description:
(Description Provided by CVE) : The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
Comments: 0, Blogs: 1, References: 32
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| - Cryptographic
- Input Manipulation
| | | | | |
|
Ingate Firewall/SIParator SSL / TLS Renegotiation Handshakes MiTM Plaintext Data Injection
|
|
60832
|
Blogs: 1
Description:
(Description Provided by CVE) : The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication requests, which allows remote attackers to execute arbitrary code via crafted structures in a malformed request, aka "Internet Authentication Service Memory Corruption Vulnerability."
Comments: 0, Blogs: 2, References: 6
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
Microsoft Windows Internet Authentication Service Protected Extensible Authentication Protocol (PEAP) Message Handling Remote Memory Corruption
|
|
62128
|
Blogs: 1
Description:
(Description Provided by CVE) : Recovery Mode in Apple iPhone OS 1.0 through 3.1.2, and iPhone OS for iPod touch 1.1 through 3.1.2, allows physically proximate attackers to bypass device locking, and read or modify arbitrary data, via a USB control message that triggers memory corruption.
Comments: 0, Blogs: 1, References: 4
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
Apple iPhone OS Recovery Mode USB Control Message Device Locking Bypass
|
Blogs provided by Technorati
|