| OSVDB ID | Disclosure Date | Title |
|
7881
Description:
(Description Provided by CVE) : The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read and modify the contents of the Clipboard via an applet that accesses the (1) ClipBoardGetText and (2) ClipBoardSetText methods of the INativeServices class.
|
2002-11-08
|
Microsoft Java Implementation INativeServices Clipboard Content Disclosure
|
|
7882
Description:
(Description Provided by CVE) : The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read arbitrary local files and network shares via an applet tag with a codebase set to a "file://%00" (null character) URL.
|
2002-11-08
|
Microsoft Java Applet Codebase Tag Arbitrary File Read
|
|
7883
Description:
(Description Provided by CVE) : The Microsoft Java implementation, as used in Internet Explorer, provides a public load0() method for the CabCracker class (com.ms.vm.loader.CabCracker), which allows remote attackers to bypass the security checks that are performed by the load() method.
|
2002-11-08
|
Microsoft Java Implementation CabCracker Class Security Bypass
|
|
7884
Description:
(Description Provided by CVE) : The Microsoft Java implementation, as used in Internet Explorer, can provide HTML object references to applets via Javascript, which allows remote attackers to cause a denial of service (crash due to illegal memory accesses) and possibly conduct other unauthorized activities via an applet that uses those references to access proprietary Microsoft methods.
|
2002-11-08
|
Microsoft Java Virtual Machine Passed HTML Object DoS
|
|
7885
Description:
(Description Provided by CVE) : The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private constructors) by providing the class name in the code parameter, aka "Incomplete Java Object Instantiation Vulnerability."
|
2002-11-08
|
Microsoft Java Implementation Applet Tag DoS
|
|
7886
Description:
(Description Provided by CVE) : The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended StandardSecurityManager restrictions by modifying the (1) deniedDefinitionPackages or (2) deniedAccessPackages settings, causing a denial of service by adding Java applets to the list of applets that are prevented from running.
|
2002-11-08
|
Microsoft Java Virtual Machine StandardSecurityManager Restriction Bypass
|
|
7896
Description:
(Description Provided by CVE) : The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to steal cookies and execute script in a different security context via a URL that contains a colon in the domain portion, which is not properly parsed and loads an applet from a malicious site within the security context of the site that is being visited by the user.
|
2002-11-08
|
Microsoft IE Java Implementation Malformed Domain Portion Arbitrary Script Execution
|
|
9902
Description:
PostNuke News Module contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "topic" variable upon submission to the index.php script of the News module. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2002-11-08
|
PostNuke News Module index.php topic Parameter XSS
|
|
13412
Description:
(Description Provided by CVE) : Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java applet that accesses the user.dir system property, aka "User.dir Exposure Vulnerability."
|
2002-11-08
|
Microsoft Virtual Machine user.dir Property Information Disclosure
|
|
13418
Description:
(Description Provided by CVE) : Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error.
|
2002-11-08
|
Microsoft Virtual Machine Applet Tag Malformed CODEBASE Arbitrary File Access
|
|
14439
Description:
(Description Provided by CVE) : Buffer overflow in the DNS SRV code for nss_ldap before nss_ldap-198 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
|
2002-11-08
|
nss_ldap DNS SRV Code Remote Overflow
|
|
14514
Description:
(Description Provided by CVE) : Peter Sandvik's Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via an HTTP request with a sequence of multiple / (slash) characters such as http://www.example.com///file/.
|
2002-11-08
|
Simple Web Server (SWS) Multiple Slash Arbitrary Restricted File Access
|
|
19947
Description:
Zeus Admin Server contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the section variable upon submission to the index.fcgi script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2002-11-08
|
Zeus Technologies Admin Server index.fcgi section Parameter XSS
|
|
24537
Description:
(Description Provided by CVE) : Unspecified "security vulnerability" in Baby FTP Server versions before November 7, 2002 has unknown impact and attack vectors.
|
2002-11-07
|
Baby FTP Server Format String DoS
|
|
6948
Description:
(Description Provided by CVE) : Pine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email message with a From header that contains a large number of quotation marks (").
|
2002-11-07
|
Pine Malformed From: Header DoS
|
|
8356
Description:
(Description Provided by CVE) : Buffer overflow in Window Maker (wmaker) 0.80.0 and earlier may allow remote attackers to execute arbitrary code via a certain image file that is not properly handled when Window Maker uses width and height information to allocate a buffer.
|
2002-11-07
|
Window Maker Image File Overflow
|
|
9227
Description:
(Description Provided by CVE) : An incomplete fix for a cross-site scripting (XSS) vulnerability in SquirrelMail 1.2.8 calls the strip_tags function on the PHP_SELF value but does not save the result back to that variable, leaving it open to cross-site scripting attacks.
|
2002-11-07
|
SquirrelMail strip_tags Function PHP_SELF Value XSS
|
|
59185
Description:
Perception LiteServe contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate encoded hostnames and query string parameters upon submission to the dir script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2002-11-07
|
Perception LiteServe Host: Header DNS Wildcard XSS
|
|
59186
Description:
LiteServe contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate URL encoding in general and the 'dir' script allows for the injection of parametrized values. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2002-11-07
|
Perception LiteServe Indexed Folder dir Request XSS
|
|
60115
Description:
(Description Provided by CVE) : Lotus Domino 5.0.9a and earlier, even when configured with the 'DominoNoBanner=1' option, allows remote attackers to obtain potential sensitive information such as the version via a request for a non-existent .nsf database, which leaks the version in the HTTP banner.
|
2002-11-07
|
IBM Lotus Domino DominoNoBanner Functionality Non-existent .nsf Database Request Remote Information Disclosure
|
|
60116
Description:
(Description Provided by CVE) : ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attackers to obtain the passwords via an HTTP request to a .user file.
|
2002-11-07
|
CuteCast Forum .user File Request Cleartext Password Remote Disclosure
|
|
62108
Description:
Unknown / Incomplete
|
2002-11-07
|
Yahoo! Messenger Shared File Access User Status Enumeration
|
|
4792
Description:
(Description Provided by CVE) : The Mail::Mailer Perl module in the perl-MailTools package 1.47 and earlier uses mailx as the default mailer, which allows remote attackers to execute arbitrary commands by inserting them into the mail body, which is then processed by mailx.
|
2002-11-06
|
perl-MailTools Command Execution
|
|
3322
Description:
Apache with mod_php contains a flaw that may allow a malicious user to take control of the HTTP server. The issue is triggered when an attacker is able to execute external programs. It is possible that the flaw may allow hijacking of the HTTP server resulting in a loss of confidentiality, integrity, and/or availability.
|
2002-11-06
|
mod_php for Apache HTTP Server Process Hijack
|
|
4232
Description:
Apache Cocoon contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the user name variable in the /samples/protected/login module is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2002-11-06
|
Apache Cocoon DatabaseAuthenticatorAction SQL Injection
|
|
9589
Description:
(Description Provided by CVE) : The Linux kernel 2.4.20 and earlier, and 2.5.x, when running on x86 systems, allows local users to cause a denial of service (hang) via the emulation mode, which does not properly clear TF and NT EFLAGs.
|
2002-11-06
|
Linux Kernel Emulation Mode TF/NT EFLAGs Local DoS
|
|
11870
Description:
(Description Provided by CVE) : Maped in LuxMan 0.41 uses the user-provided search path to find and execute the gzip program, which allows local users to modify /dev/mem and gain privileges via a modified PATH environment variable that points to a Trojan horse gzip program.
|
2002-11-06
|
LuxMan Maped PATH Subversion Privilege Escalation
|
|
60005
Description:
(Description Provided by CVE) : The timer implementation in QNX RTOS 6.1.0 allows local users to cause a denial of service (hang) and possibly execute arbitrary code by creating multiple timers with a 1-ms tick.
|
2002-11-06
|
QNX RTOS Timer Implementation Local DoS
|
|
60111
Description:
(Description Provided by CVE) : Macromedia JRun 3.0, 3.1, and 4.0 allow remote attackers to view the source code of .JSP files via Unicode encoded character values in a URL.
|
2002-11-06
|
Macromedia JRun Unicode Encoded URL .jsp Source Disclosure
|
|
60112
Description:
(Description Provided by CVE) : Unknown "file disclosure" vulnerability in Macromedia JRun 3.0, 3.1, and 4.0, related to a log file or jrun.ini, with unknown impact.
|
2002-11-06
|
Macromedia JRun Unspecified File Disclosure
|
|
60113
Description:
(Description Provided by CVE) : OpenBSD before 3.2 allows local users to cause a denial of service (kernel crash) via a call to getrlimit(2) with invalid arguments, possibly due to an integer signedness error.
|
2002-11-06
|
OpenBSD getrlimit(2) System Call Local DoS
|
|
60105
Description:
(Description Provided by CVE) : Serv-U FTP server 3.0, 3.1 and 4.0.0.4 does not accept new connections while validating user folder access rights, which allows remote attackers to cause a denial of service (no new connections) via a series of MKD commands.
|
2002-11-06
|
Serv-U FTP Server MKD Command Remote DoS
|
|
2183
Description:
Safe.pm contains a flaw that could allow a local or remote attacker execute code outside of Safe.pm's restricted environment called a compartment. If the compartment has been accessed at least once, an attacker could change the the mask of the compartment to access code outside of the compartment.
|
2002-11-05
|
Perl Safe.pm Access Bypass
|
|
6066
Description:
Conectiva linuxconf contains a flaw that may allow a remote attacker to send e-mail without authenticating (ie: "spam"). The problem is that linuxconf utility generates the sendmail configuration file (sendmail.cf) with options that configures sendmail to run as an open mail relay.
|
2002-11-05
|
Linuxconf mailconf Improper Sendmail Relay Configuration
|
|
4452
Description:
SnortCenter contains a flaw that may allow a local user to gain access to sensitive configuration information. The issue is due to a flaw in the program's creation of temporary files done with world readable/writeable permissions. A local user can read these files to gain information such as configuration optoins, usernames and passwords.
|
2002-11-05
|
SnortCenter Temporary File Local Information Disclosure
|
|
4586
Description:
SnortCenter contains a flaw that may allow a local attacker to overwrite arbitrary files. The issue is due to the program creating temporary files with predictable names. If an attacker creates a symlink anticipating the file creation, they may be able to overwrite arbitrary files.
|
2002-11-05
|
SnortCenter Temporary File Arbitrary Overwrite
|
|
7997
Description:
A local overflow exists in IBM AIX. The nslookup utility fails to validate input resulting in a buffer overflow. With a specially crafted request, an attacker can cause the execution of arbitrary code, but not with escalated privileges. Impact is low risk.
|
2002-11-05
|
IBM AIX nslookup Local Overflow
|
|
11366
Description:
(Description Provided by CVE) : Unknown vulnerability in Cluster Interconnect for HP TruCluster Server 5.0A, 5.1, and 5.1A may allow local and remote attackers to cause a denial of service.
|
2002-11-05
|
HP TruCluster Server Cluster Interconnect Unspecified DoS
|
|
11863
Description:
(Description Provided by CVE) : cnd.c in mgetty 1.1.28 and earlier does not properly filter non-printable characters and quotes, which may allow remote attackers to execute arbitrary commands via shell metacharacters in (1) caller ID or (2) caller name strings.
|
2002-11-05
|
mgetty Non-printable Character String Arbitrary Command Execution
|
|
14552
Description:
(Description Provided by CVE) : Unknown vulnerability in autofs on AIX 4.3.0, when using executable maps, allows attackers to execute arbitrary commands as root, possibly related to "string handling around how the executable map is called."
|
2002-11-05
|
IBM AIX autofs Unspecified Executable Maps Privilege Escalation
|