| OSVDB ID | Disclosure Date | Title |
|
25290
Description:
(Description Provided by CVE) : Buffer overflow in BL4 SMTP Server 0.1.4 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long argument to the (1) EHLO, (2) MAIL FROM, and (3) RCPT TO commands.
|
2006-04-27
|
BL4 SMTP Server Multiple Command Remote Overflow
|
|
25086
Description:
NetBSD contains a flaw that may allow a local denial of service. The issue is triggered when a malicious user changes the sample rate of an audio device during playback, and will result in loss of availability for the platform.
|
2006-04-27
|
NetBSD audio_write() Filter List Modification Local DoS
|
|
22351
Description:
(Description Provided by CVE) : Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking an object or pressing keys that are actually applied to a "Yes" approval for executing the control.
|
2006-04-26
|
Microsoft IE Modal Security Dialog Race Condition
|
|
55724
Description:
Unknown / Incomplete
|
2006-04-26
|
Dillo Web Browser HTTP Content-Type Unspecified Input Weakness
|
|
25162
Description:
Unknown / Incomplete
|
2006-04-26
|
Sun Java System Directory Server LDAP Request DoS
|
|
25000
Description:
Océ contains a flaw that may allow a remote denial of service. The issue is triggered due to an error in the built-in webserver when handling an overly long user-supplied URL, and will result in loss of availability for the platform.
|
2006-04-26
|
Océ 3121/3122 Printer Web Server Overflow DoS
|
|
24990
Description:
A remote overflow exists in Squeez and SpeedCommander. Squeez and SpeedCommander fails to handle an ACE archive that contains a file with an overly long filename resulting in a stack-based buffer overflow. With a specially crafted request, an attacker can execute arbitrary code resulting in a loss of integrity.
|
2006-04-26
|
SpeedProject Multiple Products ACE Archive Handling Overflow
|
|
24987
Description:
Instant Photo Gallery contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the portfolio_photo_popup.php script not properly sanitizing user-supplied input to the 'id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-04-26
|
Instant Photo Gallery portfolio_photo_popup.php id Parameter SQL Injection
|
|
24974
Description:
A local overflow exists in abcMIDI. The product fails to limit the bytes read by sscanf in drawtune.c and yapstree.c resulting in a buffer overflow. With a specially crafted .ABC file, an attacker can cause the program to crash or possibly execute arbitrary code resulting in a loss of integrity or availability for the program.
|
2006-04-26
|
abcMIDI ABC Music File Handling Overflow
|
|
25138
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in HTM_PASSWD in DirectAdmin Hosting Management allows remote attackers to inject arbitrary web script or HTML via the domain parameter.
|
2006-04-26
|
DirectAdmin HTM_PASSWD domain Parameter XSS
|
|
25264
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Devsyn Open Bulletin Board (OpenBB) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via (1) the FID parameter in board.php and (2) the TID parameter in read.php. NOTE: the SQL injection issues are already covered by CVE-2005-1612 (read.php) and CVE-2005-2566 (board.php).
|
2006-04-26
|
OpenBB read.php TID Parameter XSS
|
|
25266
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in FarsiNews 2.5.3 Pro and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameters in (a) index.php, and the (3) mod parameter in (b) admin.php.
|
2006-04-26
|
FarsiNews index.php month Parameter XSS
|
|
25267
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in FarsiNews 2.5.3 Pro and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameters in (a) index.php, and the (3) mod parameter in (b) admin.php.
|
2006-04-26
|
FarsiNews admin.php mod Parameter XSS
|
|
25268
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in misc.php in MySmartBB 1.1.x allow remote attackers to inject arbitrary web script or HTML via the (1) id and (2) username parameters.
|
2006-04-26
|
MySmartBB misc.ph Multiple Parameter XSS
|
|
25269
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in misc.php in MySmartBB 1.1.x allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) username parameters.
|
2006-04-26
|
MySmartBB misc.php Multiple Parameter SQL Injection
|
|
25072
Description:
Unknown / Incomplete
|
2006-04-26
|
Midgard Unspecified Critical Issue
|
|
24969
Description:
Groupmax contains a flaw that may allow a remote denial of service. The issue is triggered when opening an SMTP message with an attachment with a filename which is an MS-DOS device name, and will result in loss of availability for the service.
|
2006-04-26
|
Hitachi Groupmax Mail Client Attachment Filename Handling DoS
|
|
40107
Description:
(Description Provided by CVE) : The recursor in PowerDNS before 3.0.1 allows remote attackers to cause a denial of service (application crash) via malformed EDNS0 packets.
|
2006-04-26
|
PowerDNS Malformed EDNS0 Packet Remote DoS
|
|
25084
Description:
Nessus NASL contains a flaw that may allow a remote denial of service. The issue is triggered when a rouge plugin is loaded by the Nessus server which contains a malicious 'split' function call, and will result in loss of availability for the platform.
|
2006-04-25
|
Nessus NASL Processing split Function Remote Overflow DoS
|
|
24942
Description:
3Com Baseline Switch 2848-SFP contains a flaw that may allow a remote denial of service. The issue is triggered when the switch receives a DHCP packet that exceeds 342 bytes in length, and will result in loss of availability for the platform.
|
2006-04-25
|
3Com Baseline Switch 2848-SFP Crafted DHCP Packet Remote DoS
|
|
24993
Description:
(Description Provided by CVE) : Phex before 2.8.6 allows remote attackers to cause a denial of service (application hang) by initiating multiple chat requests to a single user and then logging off.
|
2006-04-25
|
Phex Chat Frame Issue
|
|
24938
Description:
Beagle contains a flaw that may allow a malicious user to pass argbitrary arguments to helper applications. The issue is triggered when Beagle, during its indexing process, launches helper applications. It is possible that the flaw may allow arbitrary code exection, resulting in a loss of integrity.
|
2006-04-25
|
Beagle External Helper Commandline Argument Injection
|
|
24940
Description:
(Description Provided by CVE) : Multiple buffer overflows in abc2ps before 1.3.3 allow user-assisted attackers to execute arbitrary code via crafted ABC music files.
|
2006-04-25
|
abc2ps ABC Music File Processing Overflow
|
|
24994
Description:
DevBB contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'member' variables upon submission to the member.php script. This could allow a user to create a specially crafted URL that would execute arbitrary HTML and script code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-25
|
DevBB member.php member Parameter XSS
|
|
24934
Description:
ampleShop contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the Customeraddresses_RecordAction.cfm script not properly sanitizing user-supplied input to the 'RecordID' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-04-25
|
ampleShop Customeraddresses_RecordAction.cfm RecordID Parameter SQL Injection
|
|
24935
Description:
ampleShop contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the youraccount.cfm script not properly sanitizing user-supplied input to the 'RecordID' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-04-25
|
ampleShop youraccount.cfm RecordID Parameter SQL Injection
|
|
24936
Description:
ampleShop contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the category.cfm script not properly sanitizing user-supplied input to the 'cat' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-04-25
|
ampleShop category.cfm cat Parameter SQL Injection
|
|
24937
Description:
ampleShop contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the detail.cfm script not properly sanitizing user-supplied input to the 'solus' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-04-25
|
ampleShop detail.cfm solus Parameter SQL Injection
|
|
24939
Description:
(Description Provided by CVE) : PhpWebGallery before 1.6.0RC1 allows remote attackers to obtain arbitrary pictures via a request to picture.php without specifying the cat parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
|
2006-04-25
|
PHPWebGallery picture.php cat Variable Arbitrary Picture Disclosure
|
|
57059
Description:
(Description Provided by CVE) : Unspecified vulnerability in Juniper Networks JUNOSe E-series routers before 7-1-1 has unknown impact and remote attack vectors related to the DNS "client code," as demonstrated by the OUSPG PROTOS DNS test suite.
|
2006-04-25
|
Juniper Multiple Products DNS Client Code Unspecified Remote DoS
|
|
24976
Description:
QuickEStore contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the prodpage.cfm script not properly sanitizing user-supplied input to the 'CategoryID' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database. Additionally, by providing a malformed file argument to the script it will disclose the full installation path. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-04-25
|
QuickEStore prodpage.cfm CategoryID Parameter SQL Injection
|
|
24977
Description:
QuickEStore contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.cfm script not properly sanitizing user-supplied input to the 'SubCatID' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database. Additionally, by providing a malformed file argument to the script it will disclose the full installation path. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-04-25
|
QuickEStore index.cfm SubCatID Parameter SQL Injection
|
|
24978
Description:
QuickEStore contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the proddetail.cfm script not properly sanitizing user-supplied input to the 'ItemID' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database. Additionally, by providing a malformed file argument to the script it will disclose the full installation path. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-04-25
|
QuickEStore proddetail.cfm ItemID Parameter SQL Injection
|
|
24979
Description:
QuickEStore contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the checkout.cfm script not properly sanitizing user-supplied input to the 'OrderID' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database. Additionally, by providing a malformed file argument to the script it will disclose the full installation path. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-04-25
|
QuickEStore checkout.cfm OrderID Parameter SQL Injection
|
|
24980
Description:
QuickEStore contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the shipping.cfm script not properly sanitizing user-supplied input to the 'OrderID' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database. Additionally, by providing a malformed file argument to the script it will disclose the full installation path. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-04-25
|
QuickEStore shipping.cfm OrderID Parameter SQL Injection
|
|
24975
Description:
phpWebFTP contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'port' variable upon submission to the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-25
|
phpWebFTP index.php port Parameter XSS
|
|
25005
Description:
Invision Power Board contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not properly validate the 'lastdate' variable in a "preg_replace()" call in the search.php script. This could allow a user to inject and execute arbitrary PHP code via the "e" pattern modifier, leading to a loss of integrity.
|
2006-04-25
|
Invision Power Board search.php lastdate Variable Arbitrary PHP Code Execution
|
|
25006
Description:
(Description Provided by CVE) : SQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary SQL commands via the ck parameter, which can inject at most 32 characters.
|
2006-04-25
|
Invision Power Board lib/func_taskmanager.php ck Parameter SQL Injection
|
|
25007
Description:
Unknown / Incomplete
|
2006-04-25
|
Invision Power Board JPG Crafted GIF Header XSS
|
|
25008
Description:
Invision Power Board contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to action_admin/paysubscriptions.php not properly sanitizing user input supplied to the 'name' variable. This may allow an attacker to include a file from the local host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-04-25
|
Invision Power Board action_admin/paysubscriptions.php name Variable Traversal Arbitrary PHP File Inclusion
|