| OSVDB ID | Disclosure Date | Title |
|
4974
Description:
ImageFolio contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate user input upon submission to the "nph-build.cgi" script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2002-11-22
|
ImageFolio nph-build.cgi XSS
|
|
90033
Description:
Libxml2 contains a flaw in the xmlNewGlobalState function in threads.c that may allow a denial of service. The issue is due to an unspecified initialization error, which may allow a context-dependent attacker to crash the program.
|
2002-11-22
|
Libxml2 threads.c xmlNewGlobalState Function Unspecified Initialization DoS
|
|
15411
Description:
(Description Provided by CVE) : Alcatel OmniSwitch 7700/7800 switches running AOS 5.1.1 contains a back door telnet server that was intended for development but not removed before distribution, which allows remote attackers to gain administrative privileges.
|
2002-11-22
|
Alcatel OmniSwitch AOS Backdoor Telnet Server Remote Access
|
|
4605
Description:
(Description Provided by CVE) : Rational ClearCase 4.1, 2002.05, and possibly other versions allows remote attackers to cause a denial of service (crash) via certain packets to port 371, e.g. via nmap.
|
2002-11-22
|
ClearCase TCP Connect DoS
|
|
59170
Description:
(Description Provided by CVE) : Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET request.
|
2002-11-21
|
Zeroo Web Server URI Traversal Arbitrary File Access
|
|
2969
Description:
Microsoft Virtual Machine (VM) may allow remote attackers to bypass security checks and execute arbitrary code. This flaw is due to the ByteCode Verifier component and the fact it does not check for the presence of certain malicious code when a Java applet is loaded. This can be exploited by placing the macicious code in an HTML document and luring a vulnerable machine to load it via Internet Explorer or a mail reader.
|
2002-11-21
|
Microsoft VM Bytecode Verifier Execute Arbitrary Code
|
|
3280
Description:
vBulletin contains a flaw that allows a remote Cross Site Scripting attack. This flaw exists because the application does not validate URI parameters upon submission to the memberlist.php script. This could allow a user to send a specially crafted request that would execute arbitrary code on the server leading to a loss of integrity.
|
2002-11-21
|
vBulletin memberlist.php XSS
|
|
4725
Description:
(Description Provided by CVE) : Symantec Java! JIT (Just-In-Time) Compiler for Netscape Communicator 4.0 through 4.8 allows remote attackers to execute arbitrary Java commands via an applet that uses a jump call, which is not correctly compiled by the JIT compiler.
|
2002-11-21
|
Symantec Java! JIT (Just-In-Time) Jump Call Arbitrary Command Execution
|
|
13417
Description:
Microsoft Java Virtual Machine allows untrusted Java applets to access COM (Component Object Model) objects. An attack may be able to compromise a vulnerable system by including a malicious Java applet that will execute arbitrary code via COM. Normally only trusted Java applets should be able to access COM objects.
|
2002-11-21
|
Microsoft Virtual Machine COM Object Arbitrary Code Execution
|
|
60353
Description:
(Description Provided by CVE) : Netscape Communicator 4.0 through 4.79 allows remote attackers to bypass JVM security and execute arbitrary Java code via an applet that loads user-supplied Java classes.
|
2002-11-21
|
Netscape Communicator User-supplied Java Class JVM Security Bypass
|
|
4347
Description:
Unknown / Incomplete
|
2002-11-20
|
Java and JVM JIT Safety Rules Bypass
|
|
4348
Description:
Unknown / Incomplete
|
2002-11-20
|
Java and JVM Bytecode Verifier Safety Rules Bypass
|
|
4349
Description:
Unknown / Incomplete
|
2002-11-20
|
Java and JVM Bytecode Verifier File Read/Write
|
|
4350
Description:
Unknown / Incomplete
|
2002-11-20
|
Java and JVM System Classes Code Upload and Exection
|
|
14502
Description:
(Description Provided by CVE) : Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.
|
2002-11-20
|
Microsoft Data Access Components RDS Data Stub Remote Overflow
|
|
7844
Description:
(Description Provided by CVE) : Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading."
|
2002-11-20
|
Microsoft IE Object Tag Temporary File Information Disclosure
|
|
7846
Description:
(Description Provided by CVE) : Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."
|
2002-11-20
|
Microsoft IE PNG Invalid Length Code DoS
|
|
14525
Description:
(Description Provided by CVE) : Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypted password that causes the overflow during decryption in which a DOS codepage string is converted to a little-endian UCS2 unicode string.
|
2002-11-20
|
Samba Encrypted Password String Conversion Decryption Overflow DoS
|
|
20754
Description:
NetBSD contains a flaw that may allow a malicious attacker to corrupt state tables in intermediate firewall devices via the STAT command in ftpd. The issue is triggered when a filename that contains "\n[0-9]" is specified. It is possible that the flaw may result in a loss of integrity and/or availability.
|
2002-11-20
|
NetBSD ftpd STAT Command Firewall State Table Corruption DoS
|
|
35876
Description:
Unknown / Incomplete
|
2002-11-20
|
Immoblier agentadmin.php Multiple SQL Injection
|
|
35877
Description:
Unknown / Incomplete
|
2002-11-20
|
Immoblier phpinfo.php Information Disclosure
|
|
60069
Description:
(Description Provided by CVE) : Cisco PIX Firewall 6.0.3 and earlier, and 6.1.x to 6.1.3, do not delete the duplicate ISAKMP SAs for a user's VPN session, which allows local users to hijack a session via a man-in-the-middle attack.
|
2002-11-20
|
Cisco PIX Firewall User VPN Session Duplicate ISAKMP SA MiTM Weakness
|
|
60070
Description:
(Description Provided by CVE) : Buffer overflow in Cisco PIX Firewall 5.2.x to 5.2.8, 6.0.x to 6.0.3, 6.1.x to 6.1.3, and 6.2.x to 6.2.1 allows remote attackers to cause a denial of service via HTTP traffic authentication using (1) TACACS+ or (2) RADIUS.
|
2002-11-20
|
Cisco PIX Firewall Multiple Method HTTP Authentication Remote DoS
|
|
60223
Description:
(Description Provided by CVE) : syslogd on OpenBSD 2.9 through 3.2 does not change the source IP address of syslog packets when the machine's IP addressed is changed without rebooting, e.g. via ifconfig, which can cause incorrect information to be sent to the syslog server.
|
2002-11-20
|
OpenBSD syslogd Persistent IP Logging Weakness
|
|
60253
Description:
(Description Provided by CVE) : Opera 6.0.3, when using Squid 2.4 for HTTPS proxying, does not properly handle when accepting a non-global certificate authority (CA) certificate from a site and establishing a subsequent HTTPS connection, which allows remote attackers to cause a denial of service (crash).
|
2002-11-20
|
Opera Proxied Connection Non-global Certificate Authority (CA) Handling DoS
|
|
60280
Description:
(Description Provided by CVE) : Allied Telesyn AT-8024 1.3.1 and Rapier 24 switches allow remote authenticated users to cause a denial of service in the management interface via a stream of zero (null) bytes sent via UDP to a running service.
|
2002-11-20
|
Allied Telesyn Multiple Device UDP Null Byte Stream Remote DoS
|
|
4351
Description:
(Description Provided by CVE) : Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name.
|
2002-11-19
|
Netscape Predictable Directory Structure Allows Theft of Prefs File
|
|
14523
Description:
(Description Provided by CVE) : importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315).
|
2002-11-19
|
Sun iPlanet WebServer Admin Server Error Log XSS
|
|
45903
Description:
A buffer overflow exists in Tftpd32. tftpd fails to validate filename arguments resulting in a stack overflow. With a specially crafted request, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2002-11-19
|
Tftpd32 tftpd Filename Argument Handling Remote Overflow
|
|
7101
Description:
(Description Provided by CVE) : openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks and obtain certain configuration and version information.
|
2002-11-19
|
Open WebMail openwebmail.pl Information Disclosure
|
|
9220
Description:
Sun Microsystems Sun ONE/iPlanet Web Server contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the messages in the error log when viewed using the iPlanet Admin Console. This could allow a user to create a specially crafted error message that would execute arbitrary code on the iPlanet server at the privilege level of the administrator, leading to a loss of integrity.
|
2002-11-19
|
Sun ONE/iPlanet Web Server Admin Server Error Log XSS
|
|
14524
Description:
(Description Provided by CVE) : importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315).
|
2002-11-19
|
iPlanet WebServer Admin Server Perl Script open() Function Arbitrary Command Execution
|
|
31840
Description:
(Description Provided by CVE) : The DNS resolver in unspecified versions of Fujitsu UXP/V, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods.
|
2002-11-19
|
Fujitsu UXP/V DNS Resolver Remote Birthday Attack Cache Poisoning
|
|
31843
Description:
(Description Provided by CVE) : The DNS resolver in unspecified versions of Infoblox DNS One, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods.
|
2002-11-19
|
Infoblox DNS One DNS Resolver Remote Birthday Attack Cache Poisoning
|
|
60250
Description:
(Description Provided by CVE) : Certain patches for QNX Neutrino realtime operating system (RTOS) 6.2.0 set insecure permissions for the files (1) /sbin/io-audio by OS Update Patch A, (2) /bin/shutdown, (3) /sbin/fs-pkg, and (4) phshutdown by QNX experimental patches, (5) cpim, (6) vpim, (7) phrelaycfg, and (8) columns, (9) othello, (10) peg, (11) solitaire, and (12) vpoker in the games pack 2.0.3, which allows local users to gain privileges by modifying the files before permissions are changed.
|
2002-11-19
|
QNX RTOS OS Update Patch A /sbin/io-audio Permission Weakness Local Privilege Escalation
|
|
60278
Description:
(Description Provided by CVE) : Photon microGUI in QNX Neutrino realtime operating system (RTOS) 6.1.0 and 6.2.0 allows attackers to read user clipboard information via a direct request to the 1.TEXT file in a directory whose name is a hex-encoded user ID.
|
2002-11-19
|
QNX RTOS Photon microGUI 1.TEXT Clipboard Content Disclosure
|
|
60251
Description:
(Description Provided by CVE) : Certain patches for QNX Neutrino realtime operating system (RTOS) 6.2.0 set insecure permissions for the files (1) /sbin/io-audio by OS Update Patch A, (2) /bin/shutdown, (3) /sbin/fs-pkg, and (4) phshutdown by QNX experimental patches, (5) cpim, (6) vpim, (7) phrelaycfg, and (8) columns, (9) othello, (10) peg, (11) solitaire, and (12) vpoker in the games pack 2.0.3, which allows local users to gain privileges by modifying the files before permissions are changed.
|
2002-11-19
|
QNX RTOS Experimental Patches Multiple File Permission Weakness Local Privilege Escalation
|
|
60252
Description:
(Description Provided by CVE) : Certain patches for QNX Neutrino realtime operating system (RTOS) 6.2.0 set insecure permissions for the files (1) /sbin/io-audio by OS Update Patch A, (2) /bin/shutdown, (3) /sbin/fs-pkg, and (4) phshutdown by QNX experimental patches, (5) cpim, (6) vpim, (7) phrelaycfg, and (8) columns, (9) othello, (10) peg, (11) solitaire, and (12) vpoker in the games pack 2.0.3, which allows local users to gain privileges by modifying the files before permissions are changed.
|
2002-11-19
|
QNX RTOS Game Pack Multiple File Permission Weakness Local Privilege Escalation
|
|
16011
Description:
(Description Provided by CVE) : dhcpcd DHCP client daemon 1.3.22 and earlier allows local users to execute arbitrary code via shell metacharacters that are fed from a dhcpd .info script into a .exe script.
|
2002-11-18
|
dhcpcd DHCP Client Daemon .info File Command Execution
|
|
16408
Description:
Unknown / Incomplete
|
2002-11-18
|
Mozilla CheckLoadURI XUL Script Arbitrary Javascript File Access
|