| OSVDB ID | Disclosure Date | Title |
|
44123
Description:
Unknown / Incomplete
|
2002-08-30
|
Nortel iSD-SSL ASA 310 3DES Encryption Request Remote Proxy DoS
|
|
14440
Description:
(Description Provided by CVE) : Preboot eXecution Environment (PXE) server allows remote attackers to cause a denial of service (crash) via certain DHCP packets from Voice-Over-IP (VOIP) phones.
|
2002-08-30
|
Intel Preboot eXecution Environment (PXE) Server VOIP Phone Malformed DHCP Packet DoS
|
|
3288
Description:
Abyss Web Server contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker uses a specially crafted GET request, which will disclose file information outside the server directory resulting in a loss of confidentiality.
|
2002-08-30
|
Abyss Web Server Multiple slash Arbitrary Directory Listing
|
|
8645
Description:
CVSTrac contains a flaw related to ticket titles containing a semi-colon (';') that may allow an attacker to execute arbitrary commands on the system. No further details have been provided.
|
2002-08-30
|
CVSTrac Ticket Title Arbitrary Command Execution
|
|
10107
Description:
FactoSystem contains a flaw that may allow a remote attacker to inject arbitrary SQL queries. The issue is due to the 'authornumber' parameter in the 'author.asp' script not being properly sanitized and may allow a remote attacker to inject or manipulate SQL queries.
|
2002-08-30
|
FactoSystem CMS author.asp authornumber Parameter SQL Injection
|
|
10108
Description:
FactoSystem contains a flaw that may allow a remote attacker to inject arbitrary SQL queries. The issue is due to the 'discussblurbid' parameter in the 'discuss.asp' script not being properly sanitized and may allow a remote attacker to inject or manipulate SQL queries.
|
2002-08-30
|
FactoSystem CMS discuss.asp discussblurbid Parameter SQL Injection
|
|
10109
Description:
FactoSystem contains a flaw that may allow a remote attacker to inject arbitrary SQL queries. The issue is due to the 'name' parameter in the 'holdcomment.asp' script not being properly sanitized and may allow a remote attacker to inject or manipulate SQL queries.
|
2002-08-30
|
FactoSystem CMS holdcomment.asp name Parameter SQL Injection
|
|
10110
Description:
FactoSystem contains a flaw that may allow a remote attacker to inject arbitrary SQL queries. The issue is due to the 'email' parameter in the 'holdcomment.asp' script not being properly sanitized and may allow a remote attacker to inject or manipulate SQL queries.
|
2002-08-30
|
FactoSystem CMS holdcomment.asp email Parameter SQL Injection
|
|
59764
Description:
(Description Provided by CVE) : Buffer overflow in gdam123 0.933 and 0.942 allows local users to execute arbitrary code via a long filename parameter.
|
2002-08-30
|
gdam123 Filename Parameter Handling Local Overflow
|
|
16404
Description:
Unknown / Incomplete
|
2002-08-29
|
Mozilla XML File Arbitrary XSLT Stylesheet Access
|
|
60119
Description:
(Description Provided by CVE) : The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicious package comes from a trusted source.
|
2002-08-29
|
Red Hat Package Manager (RPM) checksig Function Signature Validation Weakness
|
|
5124
Description:
A Local overflow exists in Microsoft Terminal Services Advanced Client. The ActiveX Control fails to check for long server names resulting in a buffer overflow. With a specially crafted request, an attacker can cause code execution in the context of the user who has the Advanced Client on their system resulting in a loss of confidentiality and integrity.
|
2002-08-28
|
Microsoft TSAC ActiveX Long Server Name Overflow
|
|
43208
Description:
Unknown / Incomplete
|
2002-08-28
|
Jetty Trailing Slash Suffix Matching Weakness
|
|
8445
Description:
(Description Provided by CVE) : Directory traversal vulnerability in SWServer 2.2 and earlier allows remote attackers to read arbitrary files via a URL containing .. sequences with "/" or "\" characters.
|
2002-08-28
|
SWServer Traversal Arbitrary File Read
|
|
864
Description:
(Description Provided by CVE) : Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system via HTML.
|
2002-08-28
|
Microsoft Windows Certificate Enrollment ActiveX Arbitrary Certificate Deletion
|
|
6067
Description:
linuxconf contains a flaw that may allow a malicious user to gain root privileges. The issue is triggered when passing 964 or more bytes of data to the LINUXCONF_LANG environmental variable overflowing a buffer. It is possible that the flaw may allow arbitrary command execution resulting in a loss of confidentiality and integrity.
|
2002-08-28
|
Linuxconf LINUXCONF_LANG Variable Overflow
|
|
8644
Description:
CVSTrac contains a flaw related to invalid tickets that may allow an attacker to cause the application to crash. No further details have been provided.
|
2002-08-28
|
CVSTrac Invalid Ticket DoS
|
|
9638
Description:
Multiple buffer overflows exists in HP-UX. The LP subsystem is vulnerable to several unspecified overflows. With a specially crafted request, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2002-08-28
|
HP-UX lp Subsystem Multiple Overflow DoS
|
|
11829
Description:
(Description Provided by CVE) : Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and possibly execute arbitrary code, possibly as a result of an integer overflow.
|
2002-08-28
|
PostgreSQL path_encode() Function Overflow
|
|
11830
Description:
(Description Provided by CVE) : Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and possibly execute arbitrary code, possibly as a result of an integer overflow.
|
2002-08-28
|
PostgreSQL path_add() Function Overflow
|
|
11831
Description:
(Description Provided by CVE) : Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and possibly execute arbitrary code, possibly as a result of an integer overflow.
|
2002-08-28
|
PostgreSQL circle_poly() Function Overflow
|
|
14496
Description:
(Description Provided by CVE) : os._execvpe from os.py in Python 2.2.1 and earlier creates temporary files with predictable names, which could allow local users to execute arbitrary code via a symlink attack.
|
2002-08-28
|
Python os.py Predictable Temp File Symlink Privilege Escalation
|
|
59833
Description:
ZMailer is prone to a remote buffer overflow condition, when using IPv6. The issue is triggerd by sending an overly long HELO command. With a specially crafted request, a remote attacker can gain access to the server or crash the server.
|
2002-08-28
|
ZMailer IPv6 HELO Command Handling Remote Overflow
|
|
60117
Description:
(Description Provided by CVE) : The default aide.conf file in Advanced Intrusion Detection Environment (AIDE) before 0.7_1 on FreeBSD before 2002-08-28 does not properly check subdirectories, which could allow local users to bypass detection.
|
2002-08-28
|
Advanced Intrusion Detection Environment (AIDE) on FreeBSD Subdirectory Detection Bypass
|
|
60118
Description:
(Description Provided by CVE) : The Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the printer name.
|
2002-08-28
|
Webmin Printer Administration Module Printer Name Shell Metacharacter Arbitrary Command Execution
|
|
60126
Description:
(Description Provided by CVE) : isakmpd/message.c in isakmpd in FreeBSD before isakmpd-20020403_1, and in OpenBSD 3.1, allows remote attackers to cause a denial of service (crash) by sending Internet Key Exchange (IKE) payloads out of sequence.
|
2002-08-28
|
Multiple BSD isakmpd isakmpd/message.c Crafted IKE Payload Sequence Remote DoS
|
|
60228
Description:
(Description Provided by CVE) : The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary files and execute arbitrary commands via remote_foreign_require and remote_foreign_call requests.
|
2002-08-28
|
Webmin RPC Module remote_foreign_* Request Remote File Manipulation
|
|
60231
Description:
(Description Provided by CVE) : VJE.VJE-RUN in HP-UX 11.00 adds bin to /etc/PATH, which could allow local users to gain privileges.
|
2002-08-28
|
HP-UX VJE.VJE-RUN /etc/PATH Ownership Weakness Local Privilege Escalation
|
|
23655
Description:
(Description Provided by CVE) : Signed integer overflow in the bttv_read function in the bttv driver (bttv-driver.c) in Linux kernel before 2.4.20 has unknown impact and attack vectors.
|
2002-08-27
|
Linux Kernel bttv-driver.c bttv_read Function Overflow
|
|
57277
Description:
Unknown / Incomplete
|
2002-08-27
|
Radiator AuthBy SQL / LDAP* %Eval Character Syntax Unspecified Issue
|
|
5033
Description:
Gaim contains a flaw that may allow a malicious user to induce a Gaim client to process shell metacharacters. The issue is triggered when the 'Manual' browser command fails to validate user suplied input. It is possible that the flaw may allow remote command execution on the client system, resulting in a loss of integrity.
|
2002-08-27
|
Gaim Manual Browser URL Handler Arbitrary Code Execution
|
|
5044
Description:
SCO OpenUnix and UnixWare contain a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when SCO Xserver (Xsco) fails to properly drop privileges when invoking external commands. This flaw may lead to a loss of integrity.
|
2002-08-27
|
OpenUNIX Xsco xkbcomp Unspecified Privilege Escalation
|
|
8643
Description:
CVSTrac contains a flaw related to the chdir() function that may allow an attacker to escape the chroot jail. No further details have been provided.
|
2002-08-27
|
CVSTrac chdir() chroot Jail Escape
|
|
59481
Description:
(Description Provided by CVE) : The installer in Yahoo! Messenger 4.0, 5.0 and 5.5 does not verify package signatures which could allow remote attackers to install trojan programs via DNS spoofing.
|
2002-08-27
|
Yahoo! Messenger Installer Digital Signature Verification Weakness
|
|
23656
Description:
(Description Provided by CVE) : Unspecified vulnerability in the pcilynx ieee1394 firewire driver (pcilynx.c) in Linux kernel before 2.4.20 has unknown impact and attack vectors, related to "wrap handling."
|
2002-08-26
|
Linux Kernel pcilynx ieee1394 Firewire Driver Wrap Handling Unspecified Issue
|
|
16403
Description:
Unknown / Incomplete
|
2002-08-26
|
Mozilla Malformed .jar File Overflow
|
|
4627
Description:
Unknown / Incomplete
|
2002-08-26
|
Microsoft IE Text Control Overflow
|
|
10733
Description:
(Description Provided by CVE) : Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."
|
2002-08-26
|
Microsoft Word/Excel Shared Document INCLUDETEXT Field Arbitrary File Read
|
|
10734
Description:
(Description Provided by CVE) : Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."
|
2002-08-26
|
Microsoft Word/Excel Shared Document INCLUDEPICTURE Field Arbitrary File Read
|
|
59761
Description:
(Description Provided by CVE) : Belkin F5D6130 Wireless Network Access Point running firmware AP14G8 allows remote attackers to cause a denial of service (connection loss) by sending several SNMP GetNextRequest requests.
|
2002-08-26
|
Belkin F5D6130 Wireless Network Access Point SNMP GetNextRequest Request Remote DoS
|