| OSVDB ID | Disclosure Date | Title |
|
63646
Description:
(Description Provided by CVE) : Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.
|
2010-01-08
|
J Programming Language libc dtoa Implementation Floating Point Parsing Memory Corruption
|
|
4927
Description:
J Walk contains a flaw that allows a remote attacker to view files outside of the web path. The issue is due to the supplied web server not properly sanitizing user input, specifically traversal style attacks (../../) in the URL, when encoded in part as an escaped Unicode string.
|
2003-03-20
|
J Walk Application Server Encoded Traversal Arbitrary File Disclosure
|
|
39060
Description:
J! Reactions for Joomla! contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'langset.php' script not properly sanitizing user input supplied to the 'comPath' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-08-03
|
J! Reactions for Joomla! (com_jreactions) langset.php comPath Parameter Remote File Inclusion
|
|
73699
Description:
J!Research Component (com_jresearch) for Joomla! contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input related to descriptions before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-12-18
|
J!Research Component (com_jresearch) for Joomla! Descriptions Unspecified XSS
|
|
63147
Description:
J!Research Component for Joomla! contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'index.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) and URL-encoded NULL bytes, supplied to the 'controller' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-03-24
|
J!Research Component (com_jresearch) for Joomla! index.php controller Parameter Directory Traversal Local File Inclusion
|
|
63576
Description:
J!WHMCS Integrator Component for Joomla! contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'index.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../)and URL-encoded NULL bytes, supplied to the 'controller' parameter (when "option" is set to "com_jwhmcs"). This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-04-07
|
J!WHMCS Integrator Component for Joomla! index.php controller Parameter Traversal Local File Inclusion
|
|
36993
Description:
(Description Provided by CVE) : execInBackground.php in J-OWAMP Web Interface 2.1b and earlier allows remote attackers to execute arbitrary commands via shell metacharacters to the (1) exe and (2) args parameters, which are used in an exec function call. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2006-12-08
|
J-OWAMP execInBackground.php Multiple Variable Arbitrary Command Execution
|
|
31855
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in JOWAMP_ShowPage.php in J-OWAMP Web Interface 2.1 allows remote authenticated users to execute arbitrary PHP code via a URL in the link parameter.
|
2006-12-07
|
J-OWAMP Web Interface JOWAMP_ShowPage.php link Parameter Remote File Inclusion
|
|
13794
Description:
(Description Provided by CVE) : The installation of J-Pilot creates the .jpilot directory with the user's umask, which could allow local attackers to read other users' PalmOS backup information if their umasks are not securely set.
|
2000-12-14
|
J-Pilot .jpilot Directory umask Permission Information Disclosure
|
|
33117
Description:
(Description Provided by CVE) : Directory traversal vulnerability in jwpn-photos.php in J-Web Pics Navigator 2.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter.
|
2007-02-21
|
J-Web Pics Navigator jwpn-photos.php dir Parameter Traversal Arbitrary File Access
|
|
33118
Description:
(Description Provided by CVE) : Directory traversal vulnerability in pn-menu.php in J-Web Pics Navigator 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter.
|
2007-02-21
|
J-Web Pics Navigator pn-menu.php dir Parameter Traversal Arbitrary File Access
|
|
28584
Description:
Unknown / Incomplete
|
2006-09-05
|
J. River Media Center Tivo Server server_tivo.dll Remote DoS
|
|
46543
Description:
(Description Provided by CVE) : Unspecified vulnerability in includes/classes/page.php in j00lean-CMS 1.03 has unknown impact and attack vectors.
|
2008-06-23
|
j00lean-CMS includes/classes/page.php Unspecified Security Issue
|
|
3072
Description:
Sun J2EE Reference Implementation on Windows contains a flaw that may allow a malicious user to execute arbitrary files on the host. The issue is triggered when specially crafted SQL statements are issued. It is possible that the flaw may allow DoS or information disclosure, resulting in a loss of confidentiality, integrity, and/or availability.
|
2003-12-16
|
J2EE SDK PointBase Database SQL Flaw
|
|
43211
Description:
Unknown / Incomplete
|
2004-07-02
|
J2EE Unspecified Session Leak
|
|
63802
Description:
JA Comment Component for Joomla! contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'index.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'view' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-04-14
|
JA Comment Component for Joomla! index.php view Parameter Directory Traversal Local File Inclusion
|
|
63724
Description:
JA JobBoard Component for Joomla! contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'index.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the "controller" and "view" parameters (when "option" is set to "com_jajobboard"). This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-04-11
|
JA JobBoard Component for Joomla! index.php Multiple Parameter Traversal Local File Inclusion
|
|
62970
Description:
JA News Component for Joomla! contains a flaw that may allow a remote attacker to disclose potentially sensitive information. The issue is due to the 'index.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) and URL-encoded NULL bytes, supplied to the 'controller' parameter (when "option" is set to "com_janews") . This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-03-16
|
JA News Component for Joomla! index.php controller Parameter Traversal Local File Inclusion
|
|
51310
Description:
JA Showcase Component for Joomla! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the catid parameter when when the option parameter is equal to com_jashowcase and the view parameter is equal to jashowcase. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-01-11
|
JA Showcase Component for Joomla! index.php catid Parameter SQL Injection
|
|
62827
Description:
JA Showcase Component for Joomla! contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the 'index.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the 'controller' parameter (when "option" is set to "com_jashowcase"). This directory traversal attack would allow the attacker to include arbitrary files from local resources.
|
2010-01-10
|
JA Showcase Component for Joomla! index.php controller Parameter Traversal Arbitrary File Access
|
|
81180
Description:
JA T3 Framework Component for Joomla! contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the index.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the 'file' parameter. This directory traversal attack would allow the attacker to view arbitrary files.
|
2012-04-15
|
JA T3 Framework Component for Joomla! index.php file Parameter Traversal Arbitrary File Access
|
|
63599
Description:
JA Voice Component for Joomla! contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'index.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) and URL-encoded NULL bytes, supplied to the 'view' parameter (when "option" is set to "com_javoice"). This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-04-09
|
JA Voice Component for Joomla! index.php view Parameter Traversal Local File Inclusion
|
|
13807
Description:
A local overflow exists in ja-elvis .The ja-elvis contain an exploitable buffer overflow in the elvrec utility.Because elvrec is setuid root,With a specially crafted request unprivileged local users may gain root privileges on the local system ,resulting in a loss of confidentiality, integrity, and availability.
|
2001-02-07
|
ja-elvis elvrec Utility Local Overflow
|
|
81282
Description:
JA-Programacao CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the lerNoticia.php script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-04-20
|
JA-Programacao CMS lerNoticia.php id Parameter SQL Injection
|
|
81283
Description:
JA-Programacao CMS contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'id' parameter upon submission to the lerNoticia.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-04-20
|
JA-Programacao CMS lerNoticia.php id Parameter XSS
|
|
81284
Description:
JA-Programacao CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the produtos/ script not properly sanitizing user-supplied input to the 'divisao' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-04-20
|
JA-Programacao CMS produtos/ divisao Parameter SQL Injection
|
|
81285
Description:
JA-Programacao CMS contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'divisao' parameter upon submission to the produtos/ script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-04-20
|
JA-Programacao CMS produtos/ divisao Parameter XSS
|
|
81286
Description:
JA-Programacao CMS contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'txtProcurar' parameter upon submission to the txtProcurar.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-04-20
|
JA-Programacao CMS txtProcurar.php txtProcurar Parameter XSS
|
|
6990
Description:
(Description Provided by CVE) : Buffer overflow in ja-xklock 2.7.1 and earlier allows local users to gain root privileges.
|
2001-02-07
|
ja-xklock Overflow
|
|
31761
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in pbguestbook.php in JAB Guest Book allows remote attackers to inject arbitrary web script or HTML via the author parameter.
|
2006-12-04
|
JAB Guest Book pbguestbook.php author Variable Arbitrary PHP Command Execution
|