| OSVDB ID | Disclosure Date | Title |
|
31986
Description:
Unknown / Incomplete
|
2006-11-21
|
Grandora searchmain.asp Multiple Parameter SQL Injection
|
|
31991
Description:
Unknown / Incomplete
|
2006-11-21
|
Grandora searchmain.asp cat Parameter XSS
|
|
31988
Description:
Unknown / Incomplete
|
2006-11-21
|
Grandora searchoption.asp Multiple Parameter SQL Injection
|
|
18731
Description:
(Description Provided by CVE) : Grandstream BudgeTone 101 and 102 running firmware 1.0.6.7 and possibly earlier versions, allows remote attackers to cause a denial of service (device hang or reboot) via a large UDP packet to port 5060.
|
2005-08-12
|
Grandstream Budge Tone Malformed UDP Packet DoS
|
|
34347
Description:
(Description Provided by CVE) : The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a denial of service (device crash) via SIP (1) INVITE, (2) CANCEL, or unspecified other messages with a WWW-Authenticate header containing a crafted Digest domain.
|
2007-03-21
|
Grandstream BudgeTone 200 SIP Messages Malformed WWW-Authenticate Header DoS
|
|
29556
Description:
(Description Provided by CVE) : Grandstream GXP-2000 VoIP Desktop Phone, firmware version 1.1.0.5, allows remote attackers to cause a denial of service (hang or reboot) via a large amount of ASCII data sent to port (1) 5060/UDP, (2) 5062/UDP, (3) 5064/UDP, (4) 5066/UDP, (5) 9876/UDP, or (6) 26789/UDP.
|
2006-10-04
|
Grandstream GXP-2000 UDP Port Ascii Data Saturation DoS
|
|
40186
Description:
(Description Provided by CVE) : The Grandstream HT-488 0.1 allows remote attackers to cause a denial of service (device crash) via a flood of fragmented packets to port 5060.
|
2007-10-24
|
Grandstream HandyTone HT-488 Fragmented Packet Saturation DoS
|
|
40187
Description:
(Description Provided by CVE) : Buffer overflow in the SIP parser on the Grandstream HT-488 0.1 allows remote attackers to cause a denial of service (device crash) via a crafted SIP INVITE message.
|
2007-10-24
|
Grandstream HandyTone HT-488 SIP INVITE Message Handling Remote Overflow
|
|
40185
Description:
(Description Provided by CVE) : The Grandstream SIP Phone GXV-3000 with firmware 1.0.1.7, Loader 1.0.0.6, and Boot 1.0.0.18 allows remote attackers to force silent call completion, eavesdrop on the phone's local environment, and cause a denial of service (blocked call reception) via a certain SIP INVITE message followed by a certain "SIP/2.0 183 Session Progress" message.
|
2007-08-22
|
Grandstream SIP Phone GXV-3000 Crafted SIP INVITE Message Privilege Escalation
|
|
38876
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Fenriru (1) Sleipnir 2.5.17 R2 and earlier and (2) Grani 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search field in a search for additions to the Favorites section.
|
2007-11-13
|
Grani Search Field Favorites Section XSS
|
|
38731
Description:
Unknown / Incomplete
|
2007-11-13
|
Grani Unspecified XSS
|
|
28553
Description:
GrapAgenda contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to index.php not properly sanitizing user input supplied to the 'page' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-05
|
GrapAgenda index.php page Parameter Remote File Inclusion
|
|
44760
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in includes/functions.php in Quate Grape Web Statistics 0.2a allows remote attackers to execute arbitrary PHP code via a URL in the location parameter.
|
2008-04-18
|
Grape Web Statistics includes/functions.php location Parameter Remote File Inclusion
|
|
46257
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in GraphicsMagick before 1.1.14, and 1.2.x before 1.2.3, allow remote attackers to cause a denial of service (crash) via unspecified vectors in (1) XCF and (2) CINEON images.
|
2008-06-05
|
GraphicsMagick CINEON Image Handling Unspecified DoS
|
|
13279
Description:
Unknown / Incomplete
|
2005-01-23
|
GraphicsMagick DIB File Parsing Issue
|
|
46258
Description:
(Description Provided by CVE) : Unspecified vulnerability in GraphicsMagick before 1.2.3 allows remote attackers to cause a denial of service (crash) via unspecified vectors in DPX images. NOTE: some of these details are obtained from third party information.
|
2008-06-05
|
GraphicsMagick DPX Image Handling Unspecified DoS
|
|
46632
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file.
|
2008-06-29
|
GraphicsMagick GetImageCharacteristics() Function File Comment Handling DoS
|
|
44953
Description:
Unknown / Incomplete
|
2008-04-28
|
GraphicsMagick Insecure File Extension Handling Program Invocation
|
|
46633
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file.
|
2008-06-29
|
GraphicsMagick Multiple Decoders Unspecified DoS
|
|
16319
Description:
Unknown / Incomplete
|
2005-05-03
|
GraphicsMagick PNM Image Decoding Overflow
|
|
46256
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in GraphicsMagick before 1.1.14, and 1.2.x before 1.2.3, allow remote attackers to cause a denial of service (crash) via unspecified vectors in (1) XCF and (2) CINEON images.
|
2008-06-05
|
GraphicsMagick XCF Image Handling Unspecified DoS
|
|
16775
Description:
(Description Provided by CVE) : The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of service (infinite loop) via an image with a zero color mask.
|
2005-05-21
|
GraphicsMagick XWD Color Mask Decoding DoS
|
|
51920
Description:
Unknown / Incomplete
|
2009-01-21
|
GraphicsMagick coders/bmp.c ReadBMPImage() Function Crafted BMP File Handling DoS
|
|
51921
Description:
Unknown / Incomplete
|
2009-01-22
|
GraphicsMagick coders/dib.c ReadDIBImage() Function Crafted DIB File Handling DoS
|
|
46254
Description:
(Description Provided by CVE) : Multiple heap-based buffer underflows in the ReadPALMImage function in coders/palm.c in GraphicsMagick before 1.2.3 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted PALM image, a different vulnerability than CVE-2007-0770. NOTE: some of these details are obtained from third party information.
|
2008-06-05
|
GraphicsMagick coders/palm.c ReadPALMImage() Function PALM Image Handling Overflow
|
|
46255
Description:
(Description Provided by CVE) : Heap-based buffer overflow in the DecodeImage function in coders/pict.c in GraphicsMagick before 1.1.14, and 1.2.x before 1.2.3, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted PICT image. NOTE: some of these details are obtained from third party information.
|
2008-06-05
|
GraphicsMagick coders/pict.c DecodeImage() Function PICT Image Handling Overflow
|
|
8687
Description:
GraphicsMagick contains a flaw related to the XorCompositeOp() function in composite.c that may allow an attacker to cause a buffer overflow. No further details have been provided.
|
2004-03-21
|
GraphicsMagick composite.c XorCompositeOp Overflow
|
|
8688
Description:
GraphicsMagick contains a flaw related to the TransformRGBImage() function in image.c that may allow an attacker to cause a integer overflow. No further details have been provided.
|
2003-04-14
|
GraphicsMagick image.c TransformRGBImage Overflow
|
|
49864
Description:
(Description Provided by CVE) : Graphiks MyForum 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the (1) myforum_login and (2) myforum_pass cookies to 1.
|
2008-10-28
|
Graphiks MyForum Multiple Cookie Manipulation Admin Authentication Bypass
|
|
49398
Description:
Graphiks MyForum contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'lecture.php' script not properly sanitizing user-supplied input to the 'id' variable. This may allow an attacker to inject or manipulate SQL queries in the backend database.
|
2008-10-26
|
Graphiks MyForum lecture.php id Parameter SQL Injection
|