| OSVDB ID | Disclosure Date | Title |
|
13514
Description:
(Description Provided by CVE) : Zyxel P310, P314, P324 and Netgear RT311, RT314 running the latest firmware, allows remote attackers on the WAN to obtain the IP address of the LAN side interface by pinging a valid LAN IP address, which generates an ARP reply from the WAN address side that maps the LAN IP address to the WAN's MAC address.
|
2005-01-31
|
Multiple Router Private IP Space Disclosure
|
|
13515
Description:
Unknown / Incomplete
|
2005-01-31
|
RealPlayer RealMedia .rm Security Bypass
|
|
13366
Description:
Unknown / Incomplete
|
2005-01-31
|
PHP Live! GET/POST Unspecified Variable Passing Issue
|
|
13446
Description:
(Description Provided by CVE) : D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user's per-user session bus via that socket.
|
2005-01-31
|
D-Bus Local Session Bus Hijack
|
|
13354
Description:
(Description Provided by CVE) : PostgreSQL (pgsql) 7.4.x, 7.2.x, and other versions allows local users to load arbitrary shared libraries and execute code via the LOAD extension.
|
2005-01-31
|
PostgreSQL LOAD Arbitrary Command Execution
|
|
13355
Description:
(Description Provided by CVE) : PostgreSQL 8.0.0 and earlier allows local users to bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command.
|
2005-01-31
|
PostgreSQL Aggregate Function EXECUTE Restriction Bypass
|
|
13356
Description:
(Description Provided by CVE) : The intagg contrib module for PostgreSQL 8.0.0 and earlier allows attackers to cause a denial of service (crash) via crafted arrays.
|
2005-01-31
|
PostgreSQL intagg Unspecified Security Issue
|
|
13357
Description:
Unknown / Incomplete
|
2005-01-31
|
PostgreSQL plpgsql Cursor Declaration Overflow
|
|
13300
Description:
A remote overflow exists in ngIRCd. ngIRCd contains an integer overflow in the Lists_MakeMask() function. With a specially crafted request, an attacker can cause a DoS and arbitrary code execution resulting in a loss of availability and integrity.
|
2005-01-31
|
ngIRCd Lists_MakeMask() Remote Overflow DoS
|
|
13299
Description:
HP VirtualVault contains a flaw that may allow a remote denial of service. The issue is triggered when an unspecified error in the TGA (Trusted Gateway Agent) daemon occurs, and will result in loss of availability for the service.
|
2005-01-31
|
HP VirtualVault TGA Daemon Unspecified DoS
|
|
13345
Description:
(Description Provided by CVE) : The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.
|
2005-01-31
|
Squid Oversized Reply Header Handling Security Issue
|
|
13344
Description:
Unknown / Incomplete
|
2005-01-31
|
Eternal Lines Web Server Connection Saturation DoS
|
|
13342
Description:
ClamAV contains a flaw that may allow a remote denial of service. The issue is due to an error in the handling of file information in corrupted ZIP files, and will result in loss of availability for the service.
|
2005-01-31
|
Clam AntiVirus ZIP Scanning DoS
|
|
13343
Description:
ClamAV contains a flaw that may allow a remote denial of service. The issue is triggered when sending a base64 encoded image file in a URL an attacker could evade virus scanning. By sending a specially-crafted ZIP file an attacker could cause a Denial of Service by crashing the clamd daemon. occurs, and will result in loss of availability for the clamd service.
|
2005-01-31
|
Clam AntiVirus BMP File Scan Bypass
|
|
13939
Description:
(Description Provided by CVE) : The Software Development Kit (SDK) and Run Time Environment (RTE) 1.4.1 and 1.4.2 for Tru64 UNIX allows remote attackers to cause a denial of service (Java Virtual Machine hang) via object deserialization.
|
2005-01-31
|
HP Tru64 UNIX Sun SDK and RTE JVM DoS
|
|
13329
Description:
fprobe contains a flaw that may allow a remote denial of service. The issue is triggered when specially crafted data containing many hash collisions occurs and is due to vulnerable xor8, xor16, and crc16 hash implementations. This will result in loss of availability for the platform by causing a large amount of CPU usage.
|
2005-01-30
|
fprobe Weak Hash Functions DoS
|
|
13317
Description:
(Description Provided by CVE) : Xpand Rally 1.0.0.0 allows remote attackers or remote malicious game servers to cause a denial of service (application crash) via a packet with large values that are not properly handled in certain malloc or memcpy operations.
|
2005-01-30
|
Xpand Rally Broadcast Remote DoS
|
|
13297
Description:
(Description Provided by CVE) : nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges.
|
2005-01-30
|
ncpfs nwclient.c Based Utilities Arbitrary Privileged File Access
|
|
13298
Description:
(Description Provided by CVE) : Buffer overflow in ncplogin in ncpfs before 2.2.6 allows remote malicious NetWare servers to execute arbitrary code on the NetWare client.
|
2005-01-30
|
ncpfs ncplogin Unspecified Overflow
|
|
13280
Description:
Unknown / Incomplete
|
2005-01-30
|
JShop Server product.php Multiple Parameter XSS
|
|
13320
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Infinite Mobile Delivery Webmail 2.6 allows remote attackers to inject arbitrary web script or HTML via the URL.
|
2005-01-29
|
Captaris Infinite Mobile Delivery Webmail XSS
|
|
13321
Description:
(Description Provided by CVE) : Infinite Mobile Delivery Webmail 2.6 allows remote attackers to gain sensitive information via an HTTP request that contains invalid characters for a Windows foldername, which reveals the path in an error message.
|
2005-01-29
|
Captaris Infinite Mobile Delivery Webmail Path Disclosure
|
|
15061
Description:
(Description Provided by CVE) : MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 and Mail Server 7.6.4r with Icewarp Mail Server 5.3.2 uses weak encryption in the (1) users.cfg, (2) settings.cfg, (3) users.dat or (4) user.dat files, which allows local users to extract the passwords.
|
2005-01-28
|
IceWarp WebMail Multiple File Weak User Info Encryption
|
|
13228
Description:
CitrusDB contains a flaw related to the credit card data import/export functions that may allow an attacker to gain access to that data. No further details have been provided.
|
2005-01-28
|
CitrusDB Credit Card Import/Export Data Disclosure
|
|
13459
Description:
(Description Provided by CVE) : ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
|
2005-01-28
|
Newsgrab Downloaded File Symlink Arbitrary File Overwrite
|
|
60678
Description:
Unknown / Incomplete
|
2005-01-28
|
Apache Roller Comment Email Notification Manipulation DoS
|
|
13873
Description:
Unknown / Incomplete
|
2005-01-28
|
AWStats Default Database Save Permission Weakness
|
|
13322
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in useredit_account.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the user parameter.
|
2005-01-28
|
Alt-N WebAdmin useredit_account.wdm user Parameter XSS
|
|
13323
Description:
(Description Provided by CVE) : useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users' account information via a modified user parameter.
|
2005-01-28
|
Alt-N WebAdmin useredit_account.wdm Arbitrary Account Modification
|
|
13324
Description:
(Description Provided by CVE) : Direct remote injection vulnerability in modalfram.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to load external webpages that appear to come from the WebAdmin server, which allows remote attackers to inject arbitrary HTML or web script to facilitate cross-site scripting (XSS) and phishing attacks.
|
2005-01-28
|
Alt-N WebAdmin modalframe.wdm Arbitrary HTML Injection
|
|
13234
Description:
WebWasher Classic contains a flaw that may allow a malicious user to remotely connect to tcp ports listening on 127.0.0.1 of the WebWasher system. WebWasher Classic supports two server modes: 1) client mode, local mode (bound to 127.0.0.1); 2) server mode - network proxy (bound to 0.0.0.0). The issue is triggered when WebWasher server is running in server mode. It is possible that the flaw may allow an attacker to bypass security controls protecting the WebWasher system resulting in a loss of integrity.
|
2005-01-28
|
WebWasher Classic Server Mode Arbitrary Proxy CONNECT Request
|
|
13318
Description:
Unknown / Incomplete
|
2005-01-28
|
SmarterMail Attachment Upload XSS
|
|
13368
Description:
IceWarp Web Mail contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "username" variable upon submission to the login.html script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-01-28
|
IceWarp WebMail login.html username Parameter XSS
|
|
13369
Description:
IceWarp Web Mail contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "accountid" variable upon submission to the accountsettings_add.html script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-01-28
|
IceWarp WebMail accountsettings_add.html accountid Parameter XSS
|
|
13370
Description:
IceWarp Web Mail contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "Title" variable upon submission to the calendar_addnote.html script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-01-28
|
IceWarp WebMail calendar_addnote.html Title Parameter XSS
|
|
13371
Description:
IceWarp Web Mail contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "Note" variables upon submission to the calendar_addtask.html script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-01-28
|
IceWarp WebMail calendar_addtask.html Note Parameter XSS
|
|
13372
Description:
IceWarp Web Mail contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate multiple variables upon submission to the calendar_addevent.html script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-01-28
|
IceWarp WebMail calendar_addevent.html Multiple Parameter XSS
|
|
13373
Description:
IceWarp Web Mail contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when improper parameters are provided to the calendar_d.html script, which will disclose the physical web path resulting in a loss of confidentiality.
|
2005-01-28
|
IceWarp WebMail calendar_d.html id Variable Path Disclosure
|
|
13374
Description:
IceWarp Web Mail contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when improper parameters are provided to the calendar_m.html script, which will disclose the physical web path resulting in a loss of confidentiality.
|
2005-01-28
|
IceWarp WebMail calendar_m.html id Variable Path Disclosure
|
|
13375
Description:
IceWarp Web Mail contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when improper parameters are provided to the calendar_w.html script, which will disclose the physical web path resulting in a loss of confidentiality.
|
2005-01-28
|
IceWarp WebMail calendar_w.html id Variable Path Disclosure
|