| OSVDB ID | Disclosure Date | Title |
|
16475
Description:
Unknown / Incomplete
|
2005-01-15
|
WordPress upload.php Unauthorized File Upload
|
|
14569
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in common.inc in Drupal before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via certain inputs.
|
2005-01-15
|
Drupal Unspecified XSS
|
|
13041
Description:
SparkleBlog contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "id" variable upon submission to the journal.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-01-15
|
SparkleBlog journal.php id Parameter XSS
|
|
13042
Description:
SparkleBlog contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a specially crafted URL containing an invalid argument to the id variable is submitted to the journal.php script, which will disclose installation path information resulting in a loss of confidentiality.
|
2005-01-15
|
SparkleBlog journal.php Path Disclosure
|
|
13043
Description:
SparkleBlog contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a specially crafted URL containing an invalid argument to the id variable is submitted to archives.php, which will disclose installation path information resulting in a loss of confidentiality.
|
2005-01-15
|
SparkleBlog archives.php Path Disclosure
|
|
13044
Description:
SparkleBlog contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a specially crafted URL containing an invalid argument to the id variable is sent to the update.php script, which will disclose installation path information resulting in a loss of confidentiality.
|
2005-01-15
|
SparkleBlog update.php Path Disclosure
|
|
45128
Description:
SHA-1 Algorithm contains a flaw in cryptanalysis that may result in hash function collusion. This will allow a remote attacker to more easily bypass protection mechanisms and gain access to password information.
|
2005-01-14
|
SHA-1 Algorithm Hash Function Collision Cryptanalysis Weakness
|
|
12946
Description:
A local overflow exists in Exim. Exim fails to check the length of a string resulting in a buffer overflow in the dns_build_reverse() function. Exim drops SUID privileges before the vulnerable code is reached. With a specially crafted request, an attacker can further escalate privileges or retrieve the mailer uid to access email messages, resulting in a loss of integrity and confidentiality.
|
2005-01-14
|
Exim -bh Command Line Option dns_build_reverse Function Local Overflow
|
|
13057
Description:
A chroot() call is implemented in AtheOS, and its behavior is supposed to be POSIX conformant. Once chroot(<directory>) is issued by a process, <directory> should become the base directory ('/') with no way to go out of the jail. That feature is widely used to protect applications against unwanted directory traversals (ftp, http, etc.) . After a chroot() call on AtheOS, '/' indeed seems to become the base directory. '/path/to/file' is translated to '<directory>/path/to/file' . Unfortunately, relative paths aren't checked against the current chroot jail. Therefore, '../../../../path/to/file' will be translated to a file out of the chroot limits.
|
2005-01-14
|
SCO UnixWare Chroot Unspecified Escape
|
|
12902
Description:
Midnight Commander contains multiple format strings that may allow an attacker to execute arbitrary code. No further details have been provided.
|
2005-01-14
|
Midnight Commander Multiple Unspecified Format Strings
|
|
12903
Description:
Midnight Commander contains multiple overflow flaws that may allow an attacker to execute arbitrary code. No further details have been provided.
|
2005-01-14
|
Midnight Commander Multiple Unspecified Overflows
|
|
12904
Description:
Midnight Commander contains a flaw that may allow a local denial of service. The issue is caused by an infinte loop flaw, and will result in loss of availability.
|
2005-01-14
|
Midnight Commander Unspecified Infinite Loop DoS
|
|
12905
Description:
Midnight Commander contains a flaw that may allow a local denial of service. The issue is due to a corrupted selection header, and will result in loss of availability.
|
2005-01-14
|
Midnight Commander Corrupted Selection Header DoS
|
|
12906
Description:
Midnight Commander contains a flaw related to a non-descript Null Dereference that may allow an attacker to cause a denial of service. No further details have been provided.
|
2005-01-14
|
Midnight Commander Unspecified Null Dereference DoS
|
|
12907
Description:
Midnight Commander contains a flaw related to a non-descript Unallocated Memory that may allow an attacker to cause a denial of service. No further details have been provided.
|
2005-01-14
|
Midnight Commander Unspecified Unallocated Memory Issue
|
|
12908
Description:
Midnight Commander contains a flaw related to a non-descript freed memory issue that may allow an attacker to cause a denial of service. No further details have been provided.
|
2005-01-14
|
Midnight Commander Unspecified Freed Memory DoS
|
|
12909
Description:
Midnight Commander contains a flaw related to the non-existant file descriptor handling that may allow an attacker to cause a denial of service. No further details have been provided.
|
2005-01-14
|
Midnight Commander Nonexistent File Descriptor Handling DoS
|
|
12910
Description:
Midnight Commander contains a flaw related to insecure filename quoting that may allow an attacker to execute arbitrary code. No further details have been provided.
|
2005-01-14
|
Midnight Commander Insecure Filename Quoting Arbitrary Command Execution
|
|
12911
Description:
Midnight Commander contains a flaw that may allow an attacker to cause a denial of service. No further details have been provided.
|
2005-01-14
|
Midnight Commander Unspecified Underflow DoS
|
|
13040
Description:
Windows contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when IE is given the path to a javascript file known to be installed by default, which will disclose installation path information resulting in a loss of confidentiality.
|
2005-01-14
|
Microsoft IE Javascript Load Local File Path Disclosure
|
|
13147
Description:
(Description Provided by CVE) : prefs.php in SquirrelMail before 1.4.4, with register_globals enabled, allows remote attackers to inject local code into the SquirrelMail code via custom preference handlers.
|
2005-01-14
|
SquirrelMail prefs.php Local File Inclusion
|
|
12985
Description:
Unknown / Incomplete
|
2005-01-14
|
Siteman forum.php page Parameter XSS
|
|
12986
Description:
Unknown / Incomplete
|
2005-01-14
|
Siteman news.php page Parameter XSS
|
|
12894
Description:
(Description Provided by CVE) : helvis 1.8h2_1 and earlier allows local users to recover and read the files of other users via the elvrec setuid program.
|
2005-01-13
|
helvis elvrec Recover Arbitrary Files
|
|
12914
Description:
Linux Kernel contains a flaw that may allow a malicious user to execute arbitrary code with root privileges on multi-processor systems. The issue is caused by the page fault handler and is triggered when two threads, which share the same virtual memory space, request a stack expansion simultaneously. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity.
|
2005-01-13
|
Linux Kernel Multiprocessor Page Fault Handler Race Condition
|
|
12882
Description:
The tcltags script distributed with vim uses an insecure method to create temporary files. This could allow an attacker to read or possibly change files without appropriate permissions, resulting in a loss of integrity.
|
2005-01-13
|
Vim tcltags Script Symlink Arbitrary File Overwrite
|
|
12883
Description:
Vim contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered due to the tclflags and vimspell.sh scripts creating temporary files insecurely allowing an attacker to create symlinks and overwrite arbitrary files. This flaw may lead to a loss of Integrity and/or Availability.
|
2005-01-13
|
Vim vimspell.sh Script Symlink Arbitrary File Overwrite
|
|
12897
Description:
(Description Provided by CVE) : Breed patch 1 and earlier allows remote attackers to cause a denial of service (application crash) via an empty UDP packet, which triggers a null dereference.
|
2005-01-13
|
Brat Designs Breed Empty UDP Datagram DoS
|
|
13133
Description:
Windows contains a flaw that may allow a remote denial of service. The issue is triggered when IE processes an iframe tag with a malformed attribute, and will result in loss of availability for the browser.
|
2005-01-13
|
Microsoft IE iframe Tag Malformed file Attribute DoS
|
|
12913
Description:
(Description Provided by CVE) : Format string vulnerability in the log routine for gopher daemon (gopherd) 3.0.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
|
2005-01-13
|
Gopher Server (gopherd) Log Routine Format String
|
|
12917
Description:
(Description Provided by CVE) : The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file.
|
2005-01-13
|
Linux Kernel Elf Binary Overlapping VMA Local Privilege Escalation
|
|
12919
Description:
A remote overflow exists in MaxDB. The 'websql' CGI fails to perform proper bounds checking resulting in a buffer overflow. By supplying an overly long password, a remote attacker can cause arbitrary code execution with SYSTEM privileges resulting in a loss of integrity.
|
2005-01-13
|
MySQL MaxDB WebAgent websql Remote Overflow
|
|
12920
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in f.aspx in forumKIT 1.0 allows remote attackers to inject arbitrary web script or HTML via the members parameter.
|
2005-01-13
|
ForumKIT f.aspx members Parameter XSS
|
|
12925
Description:
ZeroBoard contains a flaw that allows a remote attacker to arbitrary access files outside of the web path. The issue is due to the '_head.php' script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the '_zb_path' variable.
|
2005-01-13
|
ZeroBoard _head.php Traversal Arbitrary File Access
|
|
12926
Description:
ZeroBoard contains a flaw that allows a remote attacker to arbitrary access files outside of the web path. The issue is due to the 'write.php' script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the 'dir' variable.
|
2005-01-13
|
ZeroBoard write.php Traversal Arbitrary File Access
|
|
12927
Description:
ZeroBoard contains a flaw that allows a remote attacker to arbitrary access files outside of the web path. The issue is due to the 'outlogin.php' script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the '_zb_path' variable.
|
2005-01-13
|
ZeroBoard outlogin.php Traversal Arbitrary File Access
|
|
12928
Description:
ZeroBoard contains a flaw that may allow a remote attacker to execute arbritary commands. The issue is due to 'print_category.php' script not properly sanitizing user input supplied to the 'dir' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-01-13
|
ZeroBoard print_category.php dir Parameter Remote File Inclusion
|
|
12929
Description:
ZeroBoard contains a flaw that may allow a remote attacker to execute arbritary commands. The issue is due to 'login.php' script not properly sanitizing user input supplied to the 'dir' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-01-13
|
ZeroBoard login.php dir Parameter Remote File Inclusion
|
|
12930
Description:
ZeroBoard contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'setup.php' script not properly sanitizing user input supplied to the 'dir' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-01-13
|
ZeroBoard setup.php dir Parameter Remote File Inclusion
|
|
12931
Description:
ZeroBoard contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'ask_password.php' script not properly sanitizing user input supplied to the 'dir' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-01-13
|
ZeroBoard ask_password.php dir Parameter Remote File Inclusion
|