| OSVDB ID | Disclosure Date | Title |
|
27559
Description:
A code execution flaw exists in multiple Mozilla browsers. Firefox and SeaMonkey fail to validate values assigned to window.navigator objects. With a specially crafted website, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2006-07-25
|
Mozilla Multiple Products Window Navigator Object Arbitrary Code Execution
|
|
27561
Description:
(Description Provided by CVE) : Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to hijack native DOM methods from objects in another domain and conduct cross-site scripting (XSS) attacks using DOM methods of the top-level object.
|
2006-07-25
|
Mozilla Multiple Products Top-level Object Method Native DOM XSS
|
|
27562
Description:
(Description Provided by CVE) : Race condition in the JavaScript garbage collection in Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code by causing the garbage collector to delete a temporary variable while it is still being used during the creation of a new Function object.
|
2006-07-25
|
Mozilla Multiple Products JavaScript Garbage Collection Race Condition Arbitrary Code Execution
|
|
27563
Description:
(Description Provided by CVE) : Heap-based buffer overflow in Mozilla Thunderbird before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) via a VCard attachment with a malformed base64 field, which copies more data than expected due to an integer underflow.
|
2006-07-25
|
Mozilla Multiple Products vCard Malformed Base64 Field Overflow
|
|
27564
Description:
(Description Provided by CVE) : Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to reference remote files and possibly load chrome: URLs by tricking the user into copying or dragging links.
|
2006-07-25
|
Mozilla Multiple Products Chrome Scheme Remote Script Execution
|
|
27565
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the XPCNativeWrapper(window).Function construct.
|
2006-07-25
|
Mozilla Multiple Products XPCNativeWrapper(window).Function Construct XSS
|
|
27566
Description:
(Description Provided by CVE) : Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows scripts with the UniversalBrowserRead privilege to gain UniversalXPConnect privileges and possibly execute code or obtain sensitive data by reading into a privileged context.
|
2006-07-25
|
Mozilla Multiple Products UniversalXPConnect Privilege Escalation
|
|
27567
Description:
(Description Provided by CVE) : Mozilla Firefox before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote Proxy AutoConfig (PAC) servers to execute code with elevated privileges via a PAC script that sets the FindProxyForURL function to an eval method on a privileged object.
|
2006-07-25
|
Mozilla Multiple Products PAC Script FindProxyForURL Function Privilege Escalation
|
|
27568
Description:
(Description Provided by CVE) : Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code via script that changes the standard Object() constructor to return a reference to a privileged object and calling "named JavaScript functions" that use the constructor.
|
2006-07-25
|
Mozilla Multiple Products Standard Object() Constructor Manipulation Privilege Escalation
|
|
27569
Description:
(Description Provided by CVE) : The Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving garbage collection that causes deletion of a temporary object that is still being used.
|
2006-07-25
|
Mozilla Multiple Products Garbage Collection Temporary Object Handling Arbitrary Code Execution
|
|
27570
Description:
(Description Provided by CVE) : Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving (1) long strings in the toSource method of the Object, Array, and String objects; and (2) unspecified "string function arguments."
|
2006-07-25
|
Mozilla Multiple Products toSource Method Overflow
|
|
27571
Description:
(Description Provided by CVE) : Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving (1) long strings in the toSource method of the Object, Array, and String objects; and (2) unspecified "string function arguments."
|
2006-07-25
|
Mozilla Multiple Products String Function Objects Unspecified Overflow
|
|
27572
Description:
(Description Provided by CVE) : Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Javascript that leads to memory corruption, including (1) nsListControlFrame::FireMenuItemActiveEvent, (2) buffer overflows in the string class in out-of-memory conditions, (3) table row and column groups, (4) "anonymous box selectors outside of UA stylesheets," (5) stale references to "removed nodes," and (6) running the crypto.generateCRMFRequest callback on deleted context.
|
2006-07-25
|
Mozilla Multiple Products nsListControlFrame::FireMenuItemActiveEvent Arbitrary Code Execution
|
|
27573
Description:
(Description Provided by CVE) : Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Javascript that leads to memory corruption, including (1) nsListControlFrame::FireMenuItemActiveEvent, (2) buffer overflows in the string class in out-of-memory conditions, (3) table row and column groups, (4) "anonymous box selectors outside of UA stylesheets," (5) stale references to "removed nodes," and (6) running the crypto.generateCRMFRequest callback on deleted context.
|
2006-07-25
|
Mozilla Multiple Products String Class Out-of-memory Code Execution
|
|
27574
Description:
(Description Provided by CVE) : Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Javascript that leads to memory corruption, including (1) nsListControlFrame::FireMenuItemActiveEvent, (2) buffer overflows in the string class in out-of-memory conditions, (3) table row and column groups, (4) "anonymous box selectors outside of UA stylesheets," (5) stale references to "removed nodes," and (6) running the crypto.generateCRMFRequest callback on deleted context.
|
2006-07-25
|
Mozilla Multiple Products Table Row/Column Group Unspecified Code Execution
|
|
27575
Description:
(Description Provided by CVE) : Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Javascript that leads to memory corruption, including (1) nsListControlFrame::FireMenuItemActiveEvent, (2) buffer overflows in the string class in out-of-memory conditions, (3) table row and column groups, (4) "anonymous box selectors outside of UA stylesheets," (5) stale references to "removed nodes," and (6) running the crypto.generateCRMFRequest callback on deleted context.
|
2006-07-25
|
Mozilla Multiple Products Anonymous Box Selector Unspecified Code Execution
|
|
27576
Description:
(Description Provided by CVE) : Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Javascript that leads to memory corruption, including (1) nsListControlFrame::FireMenuItemActiveEvent, (2) buffer overflows in the string class in out-of-memory conditions, (3) table row and column groups, (4) "anonymous box selectors outside of UA stylesheets," (5) stale references to "removed nodes," and (6) running the crypto.generateCRMFRequest callback on deleted context.
|
2006-07-25
|
Mozilla Multiple Products crypto.generateCRMFRequest Deleted Context Code Execution
|
|
27577
Description:
(Description Provided by CVE) : Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Javascript that leads to memory corruption, including (1) nsListControlFrame::FireMenuItemActiveEvent, (2) buffer overflows in the string class in out-of-memory conditions, (3) table row and column groups, (4) "anonymous box selectors outside of UA stylesheets," (5) stale references to "removed nodes," and (6) running the crypto.generateCRMFRequest callback on deleted context.
|
2006-07-25
|
Mozilla Multiple Products Removed Node Reference Unspecified Code Execution
|
|
27373
Description:
Microsoft Internet Explorer (MSIE) contains a flaw that may allow a local denial of service. The issue is triggered when attempting to iterate a native function causing a NULL dereference, and will result in loss of availability for the browser.
|
2006-07-25
|
Microsoft IE Native Function Iteration NULL Dereference
|
|
27515
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in guestbook.php in TP-Book 1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the name parameter.
|
2006-07-25
|
TP-Book guestbook.php name Parameter XSS
|
|
27485
Description:
Etomite CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'manager/index.php' script not properly sanitizing user-supplied input to the 'username' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-07-25
|
Etomite manager/index.php username Parameter SQL Injection
|
|
29031
Description:
Unknown / Incomplete
|
2006-07-25
|
phpBB Malformed Search Query DoS
|
|
27374
Description:
Opera contains a flaw that may allow a remote denial of service. The issue is triggered when a background property is set to an overly long URL, and will result in loss of availability for the application.
|
2006-07-25
|
Opera CSS Background Property HTTPS Memory Corruption
|
|
84075
Description:
PHP contains a flaw that may allow a denial of service. The issue is triggered when an error occurs in the imagecreatefromgd2part() function during the handling of an object with a negative width. This will result in loss of availability for the program.
|
2006-07-25
|
PHP imagecreatefromgd2part() Function Negative Width Handling DoS
|
|
27480
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in viewposts.cfm in aXentForum II and earlier allows remote attackers to inject arbitrary web script or HTML via the startrow parameter.
|
2006-07-24
|
aXentForum II viewposts.cfm startrow Parameter XSS
|
|
29865
Description:
(Description Provided by CVE) : Format string vulnerability in the flush_output function in ConsoleStreambuf.cpp in Game Network Engine (GNE) 0.70 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute code via format string specifiers in unspecified vectors involving output to the gout console.
|
2006-07-24
|
GNE ConsoleStreambuf.cpp flush_output Function Remote Format String
|
|
27497
Description:
(Description Provided by CVE) : Integer overflow in the loadChunk function in loaders/load_gt2.c in libmikmod in Mikmod Sound System 3.2.2 allows remote attackers to cause a denial of service via a GRAOUMF TRACKER (GT2) module file with a large (0xffffffff) comment length value in an XCOM chunk.
|
2006-07-24
|
MikMod libmikmod GT2 XCOM Chunk Handling Overflow
|
|
29408
Description:
(Description Provided by CVE) : SQL injection vulnerability in upgradev1.php in X7 Chat 2.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the old_prefix parameter.
|
2006-07-24
|
X7 Chat upgradev1.php old_prefix SQL Injection
|
|
27459
Description:
Simpleshout has been reported to contain a flaw that may allow a remote attacker to execute arbitrary commands. The issue is supposedly due to the sboard.php script not properly sanitizing user input supplied to the 'config' variable. However, subsequent evaluation by CVE staff has determined that the variable keeps a static value and presents no opportunity for an attacker to manipulate the input.
|
2006-07-24
|
Simpleshout sboard.php config Parameter Remote File Inclusion
|
|
31036
Description:
MusicBox contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'type' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-07-24
|
MusicBox index.php type Parameter SQL Injection
|
|
58752
Description:
MusicBox contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the cart.php script not properly sanitizing user-supplied input to the 'message1' and 'message' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-07-24
|
MusicBox cart.php Multiple Parameter SQL Injection
|
|
27549
Description:
(Description Provided by CVE) : Opsware Network Automation System (NAS) 6.0 installs /etc/init.d/mysql with insecure permissions, which allows local users to read the root password for the MySQL MAX database or gain privileges by modifying /etc/init.d/mysql.
|
2006-07-24
|
Opsware NAS /etc/init.d/mysqll MySQL root Cleartext Password Local Disclosure
|
|
27496
Description:
(Description Provided by CVE) : Siemens SpeedStream 2624 allows remote attackers to cause a denial of service (device hang) by sending a crafted packet to the web administrative interface.
|
2006-07-24
|
Siemens SpeedStream 2624 HTTP Server Unspecified Crafted Packet DoS
|
|
27523
Description:
(Description Provided by CVE) : TippingPoint IPS running the TippingPoint Operating System (TOS) before 2.2.4.6519 allows remote attackers to "force the device into layer 2 fallback (L2FB)", causing a denial of service (page fault), via a malformed packet.
|
2006-07-24
|
3Com TippingPoint IPS Crafted Packet Layer 2 Mode Inspection Bypass
|
|
27585
Description:
(Description Provided by CVE) : Directory traversal vulnerability in Check Point Firewall-1 R55W before HFA03 allows remote attackers to read arbitrary files via an encoded .. (dot dot) in the URL on TCP port 18264.
|
2006-07-24
|
Check Point VPN/Firewall Traversal Arbitrary File Access
|
|
27514
Description:
(Description Provided by CVE) : The fbgs framebuffer Postscript/PDF viewer in fbi before 2.01 has a typo that prevents a filter from working correctly, which allows user-assisted attackers to bypass the filter and execute malicious Postscript commands.
|
2006-07-24
|
fbida fbgs Arbitrary Postscript Code Execution
|
|
28083
Description:
(Description Provided by CVE) : Unspecified vulnerability in Prince Clan (Princeclan) Chess component (com_pcchess) 0.8 and earlier for Mambo and Joomla! has unspecified impact and attack vectors.
|
2006-07-24
|
PrinceClan Chess for Mambo/Joomla (com_pcchess) include.pcchess.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
44226
Description:
Unknown / Incomplete
|
2006-07-24
|
IBM WebSphere Application Server (WAS) Custom Properties Cleartext Password Disclosure
|
|
29057
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Shalwan MusicBox 2.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter in a request for the top-level URI. NOTE: the id parameter in index.php, and the type and show parameters in a top action, are already covered by CVE-2006-1349; and the term parameter in a search action is already covered by CVE-2006-1806.
|
2006-07-24
|
MusicBox URI id Parameter XSS
|
|
29058
Description:
(Description Provided by CVE) : Shalwan MusicBox 2.3.4 and earlier allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
|
2006-07-24
|
MusicBox phpinfo.php Information Disclosure
|