| OSVDB ID | Disclosure Date | Title |
|
2470
Description:
Unknown / Incomplete
|
2003-08-25
|
phpGACL debug Request Database Password Disclosure
|
|
2471
Description:
akpop3d contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the username variable in the authentication module is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2003-08-25
|
akpop3d username SQL Injection
|
|
2469
Description:
Unknown / Incomplete
|
2003-08-25
|
widz apmon Arbitrary Command Execution
|
|
17378
Description:
Unknown / Incomplete
|
2003-08-25
|
Yaws Web Server Unspecified XSS
|
|
2463
Description:
Unknown / Incomplete
|
2003-08-25
|
Netbula Anyboard Crafted Request System Information Disclosure
|
|
2464
Description:
GBrowse contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the gbrowse script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the "help" variable.
|
2003-08-25
|
GMOD GBrowse gbrowse Arbitrary File Access
|
|
2465
Description:
Unknown / Incomplete
|
2003-08-25
|
DWebPro http.ini Cleartext Authentication Credential Disclosure
|
|
8360
Description:
SNMPc contains a flaw that may lead to an unauthorized password exposure. It is possible to gain access to encrypted passwords when a client attempts to authenticate with the server. The passwords are encrypted with a simple substitution cipher. The encrypted passwords are easily compromised, which may lead to a loss of integrity.
|
2003-08-25
|
SNMPc Client Side Password Disclosure
|
|
66672
Description:
Unknown / Incomplete
|
2003-08-25
|
PHP Unspecified safe_mode Bypass
|
|
7691
Description:
(Description Provided by CVE) : ssh on HP Tru64 UNIX 5.1B and 5.1A does not properly handle RSA signatures when digital certificates and RSA keys are used, which could allow local and remote attackers to gain privileges.
|
2003-08-25
|
HP Tru64 UNIX ssh RSA Key Mishandling Privilege Escalation
|
|
11667
Description:
PHP contains an issue that may allow an attacker to gain elevated privileges. The issue is due to the base64_encode function not properly sanitizing user-supplied input. By passing crafted data to the function, an attacker can trigger an integer overflow and possibly execute arbitrary code.
|
2003-08-25
|
PHP base64_encode Function Unspecified Overflow
|
|
11668
Description:
PHP contains an issue that may allow an attacker to gain elevated privileges. The issue is due to unspecified functions in the GD library not properly sanitizing user-supplied input. By passing crafted data to the library, an attacker can trigger an integer overflow and possibly execute arbitrary code.
|
2003-08-25
|
PHP GD Library Unspecified Overflow
|
|
11670
Description:
PHP contains a flaw that may allow an attacker to gain elevated privileges. The issue is due to the ibase_blob_get() function not properly sanitizing user-supplied input. By passing an overly long string to the function, an attacker can trigger a buffer overflow and execute arbitrary code.
|
2003-08-25
|
PHP ibase_blob_get() Function Overflow
|
|
11671
Description:
PHP contains a flaw that may allow an attacker to gain elevated privileges. The issue is due to the zendlex functionality not properly sanitizing user-supplied input. By passing an overly long string, an attacker can trigger a buffer overflow and execute arbitrary code.
|
2003-08-25
|
PHP zendlex Unspecified Overflow
|
|
16043
Description:
Unknown / Incomplete
|
2003-08-24
|
Mozilla HTML Link Property Chrome Privilege Escalation
|
|
6416
Description:
Blubster contains a flaw that may allow a remote denial of service. The issue is triggered when a packet flood is directed to UDP port 701, and will result in loss of availability for the service.
|
2003-08-24
|
Blubster UDP Port 701 Flood DoS
|
|
8070
Description:
(Description Provided by CVE) : nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array, which is used for authentication.
|
2003-08-24
|
newsPHP nphpd.php Authentication Bypass
|
|
2965
Description:
Microsoft Internet Explorer contains a flaw that may cause a script to be executed in the "My Computer" zone. If a web browser loads a page with malicious content that abuses the method IE uses to retrieve files from the cache, the content is loaded and run under higher priveleges. This method may also be used to run executable files already present on the system, or view file content.
|
2003-08-23
|
Microsoft IE Cache Script Execution in My Zone
|
|
3353
Description:
Invision Power Board contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "adsess" variable upon submission to the admin.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2003-08-23
|
Invision Power Board admin.php adsess Parameter XSS
|
|
3362
Description:
Invision Power Board allows a remote attacker to inject arbitrary HTML code which may allow altering page content, display and more. The issue is due to unchecked IBF formatting tags in user posted content. Such modified content would allow the attacker to execute the code on subsequent viewer's machines.
|
2003-08-23
|
Invision Power Board IBF Tag Injection
|
|
7633
Description:
(Description Provided by CVE) : Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.
|
2003-08-23
|
SCO Unix Docview Arbitrary File Access
|
|
44697
Description:
(Description Provided by CVE) : Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces via certain SecuRemote requests to TCP ports 256 or 264, which leaks the IP addresses in a reply packet.
|
2003-08-22
|
Check Point FireWall-1 SecuRemote TCP Port 256 Malformed Input Internal IP Address Disclosure
|
|
44698
Description:
(Description Provided by CVE) : Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces via certain SecuRemote requests to TCP ports 256 or 264, which leaks the IP addresses in a reply packet.
|
2003-08-22
|
Check Point FireWall-1 SecuRemote TCP Port 264 Traffic Internal IP Address Disclosure
|
|
2461
Description:
(Description Provided by CVE) : GDM before 2.4.1.6, when using the "examine session errors" feature, allows local users to read arbitrary files via a symlink attack on the ~/.xsession-errors file.
|
2003-08-22
|
GNOME Display Manager (gdm) .xsession-errors Symlink Arbitrary File Read
|
|
2146
Description:
BitKeeper versions 3.0.1 and below contain a flaw that may allow a remote attacker to execute arbitrary code on the system. A remote attacker can supply specially-crafted files containing malicious code inside a patch. This then would be executed on the victim's system when the victim loads the patch and could lead to system compromise.
|
2003-08-22
|
BitKeeper Unspecified Code Injection
|
|
2462
Description:
Unknown / Incomplete
|
2003-08-22
|
Piolet TCP Port 701 Traffic Saturation DoS
|
|
6313
Description:
(Description Provided by CVE) : The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a short authorization key name.
|
2003-08-22
|
GNOME Display Manager (gdm) XDMCP Short Authorization Key DoS
|
|
6314
Description:
(Description Provided by CVE) : The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CVE-2003-0549.
|
2003-08-22
|
GNOME Display Manager (gdm) XDMCP Host Name Expiration DoS
|
|
2468
Description:
KisMAC contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when an attacker changes the value of the $DRIVER_KEXT variable in the viha_driver.sh script allowing the creation of a setuid executable owned by the attacker's uid. This flaw may lead to a loss of integrity.
|
2003-08-22
|
KisMAC viha_driver.sh Arbitrary File Ownership Modification
|
|
11772
Description:
(Description Provided by CVE) : Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 allows remote attackers to execute arbitrary code.
|
2003-08-22
|
RealNetworks Helix Universal Server View Source Plug-in RTSP Parser Overflow
|
|
11792
Description:
(Description Provided by CVE) : Buffer overflow in the whois client, which is not setuid but is sometimes called from within CGI programs, may allow remote attackers to execute arbitrary code via a long command line option.
|
2003-08-22
|
whois Client Command Line Overflow
|
|
11846
Description:
KisMAC contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when an attacker changes the value of the $DRIVER_KEXT variable in the 'macjack_load.sh' script allowing the creation of a setuid executable owned by the attacker's uid. This flaw may lead to a loss of integrity.
|
2003-08-22
|
KisMAC macjack_load.sh Arbitrary File Ownership Modification
|
|
11847
Description:
KisMAC contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when an attacker changes the value of the $DRIVER_KEXT variable in the 'airojack_load.sh' script allowing the creation of a setuid executable owned by the attacker's uid. This flaw may lead to a loss of integrity.
|
2003-08-22
|
KisMAC airojack_load.sh Arbitrary File Ownership Modification
|
|
11848
Description:
KisMAC contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when an attacker changes the value of the $DRIVER_KEXT variable in the 'viha_driver.sh' script allowing arbitrary kernel modules to be loaded into memory. This flaw may lead to a loss of integrity.
|
2003-08-22
|
KisMAC viha_driver.sh Arbitrary Kernel Module Loading
|
|
11849
Description:
KisMAC contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when an attacker changes the value of the $DRIVER_KEXT variable in the 'macjack_load.sh' script allowing arbitrary kernel modules to be loaded into memory. This flaw may lead to a loss of integrity.
|
2003-08-22
|
KisMAC macjack_load.sh Arbitrary Kernel Module Loading
|
|
11850
Description:
KisMAC contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when an attacker changes the value of the $DRIVER_KEXT variable in the 'airojack_load.sh' script allowing arbitrary kernel modules to be loaded into memory. This flaw may lead to a loss of integrity.
|
2003-08-22
|
KisMAC airojack_load.sh Arbitrary Kernel Module Loading
|
|
11851
Description:
KisMAC contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when an attacker changes the value of the $DRIVER_KEXT variable in the 'exchangeKernel.sh' script allowing the kernel to be overwritten with an arbitrary kernel. This flaw may lead to a loss of integrity.
|
2003-08-22
|
KisMAC exchangeKernel.sh Kernel Overwrite
|
|
11852
Description:
KisMAC contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when an attacker changes the value of the $DRIVER_KEXT variable in the 'setuid_enable.sh' script allowing the creation of a setuid executable owned by the attacker's uid. This flaw may lead to a loss of integrity.
|
2003-08-22
|
KisMAC setuid_enable.sh Arbitrary File Ownership Modification
|
|
11853
Description:
KisMAC contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when an attacker changes the value of the $DRIVER_KEXT variable in the 'setuid_disable.sh' script allowing the creation of a setuid executable owned by the attacker's uid. This flaw may lead to a loss of integrity.
|
2003-08-22
|
KisMAC setuid_disable.sh Arbitrary File Ownership Modification
|
|
11854
Description:
KisMAC contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when an attacker changes the value of the $DRIVER_KEXT variable in the 'viha_prep.sh' script allowing an arbitrary binary to be executed as root. This flaw may lead to a loss of integrity.
|
2003-08-22
|
KisMAC viha_prep.sh Arbitrary Program Execution
|