| OSVDB ID | Disclosure Date | Title |
|
47823
Description:
(Description Provided by CVE) : javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
|
2008-08-24
|
R javareconf Temporary File Symlink Arbitrary File Overwrite
|
|
54835
Description:
(Description Provided by CVE) : R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for admin.mdb.
|
2009-06-01
|
R2 Newsletter Stats admin.mdb Direct Request Database Disclosure
|
|
36015
Description:
(Description Provided by CVE) : Directory traversal vulnerability in galeria.php in R2K Gallery 1.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang2 parameter.
|
2007-05-11
|
R2K Gallery galeria.php lang2 Parameter Traversal Arbitrary File Access
|
|
91663
Description:
Ra1NX PHP IRC Bot contains a flaw that is triggered during the handling of the public call feature in private messages. This may allow a remote attacker to bypass the authentication system and potentially execute arbitrary commands.
|
2013-03-25
|
Ra1NX PHP IRC Bot Private Message Public Call Feature Remote Command Execution
|
|
64895
Description:
Unknown / Incomplete
|
2010-01-31
|
RaakCms browse.asp dir Parameter Traversal Arbitrary Directory Listing
|
|
64896
Description:
Unknown / Incomplete
|
2010-01-31
|
RaakCms browseFile.asp dir Parameter Traversal Arbitrary Directory Listing
|
|
64894
Description:
Unknown / Incomplete
|
2010-01-31
|
RaakCms pic.aspx Arbitrary File Upload
|
|
79093
Description:
RabidHamster R2 is prone to an overflow condition. The 'file' command fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a specially crafted request containing an overly long file parameter, a remote attacker can potentially cause arbitrary code execution.
|
2012-02-10
|
RabidHamster R2 Extreme File Command Parsing Remote Overflow
|
|
79094
Description:
RabidHamster R2 contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the telnet service not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the 'file' command. This directory traversal attack would allow the attacker to access arbitrary files.
|
2012-02-10
|
RabidHamster R2 Extreme Telnet Server File Command Traversal Arbitrary File Access
|
|
79095
Description:
RabidHamster R2 contains a flaw related to the telnet service. The issue is due to the service providing only a limited range of PINs. This may allow an attacker to more easily conduct brute-force attacks and to gain access to the service.
|
2012-02-11
|
RabidHamster R2 Extreme Telnet Server PIN Authentication Brute Force Weakness
|
|
79008
Description:
RabidHamster R4 is prone to an overflow condition. The application fails to perform proper bounds checking resulting in a heap-based buffer overflow. With an overly long web request, a remote attacker can potentially cause arbitrary code execution.
|
2012-02-09
|
RabidHamster R4 Boundary Error Web Request Parsing Remote Overflow
|
|
79006
Description:
RabidHamster R4 contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the left_console.html page not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the 'cmd' parameter. This directory traversal attack would allow the attacker to access arbitrary files.
|
2012-02-09
|
RabidHamster R4 left_console.html cmd Parameter loadfile() Function Traversal Arbitrary File Access
|
|
79007
Description:
RabidHamster R4 is prone to an overflow condition. The application fails to perform proper bounds checking when creating log entries resulting in a stack-based buffer overflow. With an overly long web request, a remote attacker can potentially cause arbitrary code execution.
|
2012-02-10
|
RabidHamster R4 Log Entry Creation Web Request Parsing Remote Overflow
|
|
79009
Description:
RabidHamster R4 is prone to an overflow condition. The application fails to perform proper bounds checking when processing the miniscreenshot script function resulting in a stack-based buffer overflow. With a specially crafted web request containing an overly long parameter, a remote attacker can potentially cause arbitrary code execution.
|
2012-02-10
|
RabidHamster R4 miniscreenshot Script Function Web Request Parsing Remote Overflow
|
|
18067
Description:
(Description Provided by CVE) : Format string vulnerability in Race Driver 1.20 and earlier allows remote attackers to cause a denial of service (application crash) via format string specifiers in a (1) nickname or (2) chat message.
|
2005-07-19
|
Race Driver Chat String Format String
|
|
18068
Description:
(Description Provided by CVE) : Buffer overflow in Race Driver 1.20 and earlier allows remote attackers to cause a denial of service (application crash) via a long (1) nickname or (2) chat message.
|
2005-07-19
|
Race Driver Chat String Remote Overflow
|
|
7094
Description:
Unknown / Incomplete
|
2004-06-16
|
Race Driver Malformed Packet Match Termination
|
|
7095
Description:
Unknown / Incomplete
|
2004-06-16
|
Race Driver Message Spoofing
|
|
7093
Description:
Unknown / Incomplete
|
2004-06-16
|
Race Driver Packet Length 0 DoS
|
|
25914
Description:
Unknown / Incomplete
|
2006-05-20
|
RaceEventManagement nennung.php pid Parameter SQL Injection
|
|
25913
Description:
Unknown / Incomplete
|
2006-05-20
|
RaceEventManagement nennung.php pid Parameter XSS
|
|
39601
Description:
A remote overflow exists in Racer v0.5.3beta5. The game fails to verify buffer lengths resulting in a stack overflow. With a specially crafted request, a remote attacker can execute arbitrary code resulting in a loss of integrity.
|
2007-08-13
|
Racer Client/Server UDP Packet Handling Remote Overflow
|
|
78121
Description:
Rack contains a flaw that may allow a remote denial of service. The issue is triggered when an attacker sends multiple crafted parameters which trigger hash collisions, and will result in loss of availability for the program via CPU consumption.
|
2011-12-28
|
Rack Hash Collision Form Parameter Parsing Remote DoS
|
|
89320
Description:
Rack contains a flaw that may allow a remote denial of service. The issue is triggered when parsing an overly long string. With a specially crafted string, a remote attacker can cause a consumption of memory. This will result in a loss of availability for the webserver.
|
2013-01-07
|
Rack Long String Parsing Memory Consumption Remote DoS
|
|
89327
Description:
Rack contains a flaw in the Rack::Auth::AbstractRequest class that may allow a remote denial of service. The issue is triggered when an unspecified error occurs, which will result in a loss of availability for the webserver.
|
2013-01-13
|
Rack Rack::Auth::AbstractRequest Class Unspecified Remote DoS
|
|
89938
Description:
Rack contains a flaw as the Rack::File function creates temporary files insecurely. It is possible for a local attacker to use a symlink attack to traverse to an arbitrary file and disclose its contents. No further details are available.
|
2013-02-07
|
Rack Rack::File Function Symlink Traversal Arbitrary File Disclosure
|
|
89939
Description:
Rack contains a flaw that is due to an error in the Rack::Session::Cookie function. Users of the Marshal session cookie encoding (the default), are subject to a timing attack that may lead an attacker to execute arbitrary code. This attack is more practical against 'cloud' users as intra-cloud latencies are sufficiently low to make the attack viable.
|
2013-02-07
|
Rack Rack::Session::Cookie Function Timing Attack Remote Code Execution
|
|
89317
Description:
Rack contains a flaw in the Regular Expressions Engine that may allow a remote denial of service. The issue is triggered when parsing context-disposition headers. With a specially crafted header, a remote attacker can cause an infinite loop, which will result in a loss of availability for the webserver.
|
2012-05-04
|
Rack Regular Expressions Engine Content-Disposition Header Parsing Infinite Loop Remote DoS
|
|
83077
Description:
Rack::Cache (rack-cache) contains a flaw related to the rubygem caching sensitive HTTP headers. This will result in a weakness that may make it easier for an attacker to gain access to a user's session via a specially crafted header.
|
2012-06-06
|
Rack::Cache (rack-cache) Rubygem Sensitive HTTP Header Caching Weakness
|
|
87179
Description:
Rackspace Application for iOS contains a flaw related to domain name validation during certificate validation. The issue is due to the server hostname not being verified to match a domain name in the Subject's Common Name (CN) or SubjectAltName field of the X.509 certificate. This may allow a man-in-the-middle attacker to spoof SSL servers via an arbitrary certificate that appears valid. Such an attack would allow for the interception of sensitive traffic, and potentially allow for the injection of content into the SSL stream.
|
2012-08-16
|
Rackspace Application for iOS X.509 Certificate Domain Name Matching MiTM Weakness
|