| OSVDB ID | Disclosure Date | Title |
|
32356
Description:
(Description Provided by CVE) : Buffer overflow in Astonsoft DeepBurner Pro and Free 1.8.0 and earlier allows user-assisted remote attackers to execute arbitrary code via a long file name tag in a dbr file.
|
2006-12-19
|
DeepBurner DBR File Name Tag Parsing Overflow
|
|
32363
Description:
phpProfiles contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the /include/account.inc.php script not properly sanitizing user input supplied to the 'incpath' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-12-19
|
phpProfiles /include/account.inc.php incpath Parameter Remote File Inclusion
|
|
32364
Description:
phpProfiles contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the /include/admin_newcomm.inc.php script not properly sanitizing user input supplied to the 'incpath' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-12-19
|
phpProfiles /include/admin_newcomm.inc.php incpath Parameter Remote File Inclusion
|
|
32365
Description:
phpProfiles contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the /include/body.inc.php script not properly sanitizing user input supplied to the 'incpath' and 'menu' variables. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-12-19
|
phpProfiles /include/body.inc.php Multiple Parameter Remote File Inclusion
|
|
32366
Description:
phpProfiles contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the /include/body_admin.inc.php script not properly sanitizing user input supplied to the 'incpath' and 'menu' variables. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-12-19
|
phpProfiles /include/body_admin.inc.php Multiple Parameter Remote File Inclusion
|
|
32367
Description:
phpProfiles contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the /include/comm_post.inc.php script not properly sanitizing user input supplied to the 'incpath' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-12-19
|
phpProfiles /include/comm_post.inc.php incpath Parameter Remote File Inclusion
|
|
32368
Description:
phpProfiles contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the /include/commrecc.inc.php script not properly sanitizing user input supplied to the 'incpath' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-12-19
|
phpProfiles /include/commrecc.inc.php incpath Parameter Remote File Inclusion
|
|
32369
Description:
phpProfiles contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the /include/do_reg.inc.php script not properly sanitizing user input supplied to the 'incpath' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-12-19
|
phpProfiles /include/do_reg.inc.php incpath Parameter Remote File Inclusion
|
|
32370
Description:
phpProfiles contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the /include/friends.inc.php script not properly sanitizing user input supplied to the 'incpath' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-12-19
|
phpProfiles /include/friends.inc.php incpath Parameter Remote File Inclusion
|
|
32371
Description:
phpProfiles contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the /include/header.inc.php script not properly sanitizing user input supplied to the 'incpath' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-12-19
|
phpProfiles /include/header.inc.php incpath Parameter Remote File Inclusion
|
|
32372
Description:
phpProfiles contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the /include/header_admin.inc.php script not properly sanitizing user input supplied to the 'incpath' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-12-19
|
phpProfiles /include/header_admin.inc.php incpath Parameter Remote File Inclusion
|
|
32373
Description:
phpProfiles contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the /include/index.inc.php script not properly sanitizing user input supplied to the 'incpath' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-12-19
|
phpProfiles /include/index.inc.php incpath Parameter Remote File Inclusion
|
|
32374
Description:
phpProfiles contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the /include/menu_u.inc.php script not properly sanitizing user input supplied to the 'incpath' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-12-19
|
phpProfiles /include/menu_u.inc.php incpath Parameter Remote File Inclusion
|
|
32375
Description:
phpProfiles contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the /include/menu_v.inc.php script not properly sanitizing user input supplied to the 'incpath' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-12-19
|
phpProfiles /include/menu_v.inc.php incpath Parameter Remote File Inclusion
|
|
32376
Description:
phpProfiles contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the /include/notify.inc.php script not properly sanitizing user input supplied to the 'incpath' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-12-19
|
phpProfiles /include/notify.inc.php incpath Parameter Remote File Inclusion
|
|
32393
Description:
(Description Provided by CVE) : Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 5 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_10 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allows attackers to use untrusted applets to "access data in other applets," aka "The first issue."
|
2006-12-19
|
Sun Java JRE Untrusted Applet Privilege Escalation (Issue 1)
|
|
32353
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in export_handler.php in WebCalendar 1.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the format parameter.
|
2006-12-19
|
WebCalendar export_handler.php format Parameter XSS
|
|
32360
Description:
(Description Provided by CVE) : Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code via multiple vectors that use the extract function, as demonstrated by the (1) f, (2) newmessage, (3) newusername, (4) adminuser, and (5) permission parameters.
|
2006-12-19
|
PHP-Update blog.php Admin Authentication Bypass
|
|
32361
Description:
(Description Provided by CVE) : Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code via multiple vectors that use the extract function, as demonstrated by the (1) f, (2) newmessage, (3) newusername, (4) adminuser, and (5) permission parameters.
|
2006-12-19
|
PHP-Update blog.php Arbitrary File Manipulation Code Execution
|
|
37125
Description:
(Description Provided by CVE) : Unspecified versions of the Linux kernel allow local users to cause a denial of service (unrecoverable zombie process) via a program with certain instructions that prevent init from properly reaping a child whose parent has died.
|
2006-12-19
|
Linux Kernel Init Prevention Process Handling Local DoS
|
|
32357
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, and Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, allow attackers to develop Java applets or applications that are able to gain privileges, related to serialization in JRE.
|
2006-12-19
|
Sun Java JRE Serialization Multiple Unspecified Issues
|
|
32358
Description:
(Description Provided by CVE) : Multiple buffer overflows in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allow attackers to develop Java applets that read, write, or execute local files, possibly related to (1) integer overflows in the Java_sun_awt_image_ImagingLib_convolveBI, awt_parseRaster, and awt_parseColorModel functions; (2) a stack overflow in the Java_sun_awt_image_ImagingLib_lookupByteRaster function; and (3) improper handling of certain negative values in the Java_sun_font_SunLayoutEngine_nativeLayout function. NOTE: some of these details are obtained from third party information.
|
2006-12-19
|
Sun Java JRE Java_sun_awt_image_ImagingLib_convolveBI Function Overflow
|
|
32931
Description:
(Description Provided by CVE) : Multiple buffer overflows in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allow attackers to develop Java applets that read, write, or execute local files, possibly related to (1) integer overflows in the Java_sun_awt_image_ImagingLib_convolveBI, awt_parseRaster, and awt_parseColorModel functions; (2) a stack overflow in the Java_sun_awt_image_ImagingLib_lookupByteRaster function; and (3) improper handling of certain negative values in the Java_sun_font_SunLayoutEngine_nativeLayout function. NOTE: some of these details are obtained from third party information.
|
2006-12-19
|
Sun Java JRE awt_parseRaster Function Overflow
|
|
32932
Description:
(Description Provided by CVE) : Multiple buffer overflows in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allow attackers to develop Java applets that read, write, or execute local files, possibly related to (1) integer overflows in the Java_sun_awt_image_ImagingLib_convolveBI, awt_parseRaster, and awt_parseColorModel functions; (2) a stack overflow in the Java_sun_awt_image_ImagingLib_lookupByteRaster function; and (3) improper handling of certain negative values in the Java_sun_font_SunLayoutEngine_nativeLayout function. NOTE: some of these details are obtained from third party information.
|
2006-12-19
|
Sun Java JRE awt_parseColorModel Function Overflow
|
|
32933
Description:
(Description Provided by CVE) : Multiple buffer overflows in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allow attackers to develop Java applets that read, write, or execute local files, possibly related to (1) integer overflows in the Java_sun_awt_image_ImagingLib_convolveBI, awt_parseRaster, and awt_parseColorModel functions; (2) a stack overflow in the Java_sun_awt_image_ImagingLib_lookupByteRaster function; and (3) improper handling of certain negative values in the Java_sun_font_SunLayoutEngine_nativeLayout function. NOTE: some of these details are obtained from third party information.
|
2006-12-19
|
Sun Java JRE Java_sun_awt_image_ImagingLib_lookupByteRaster Function Overflow
|
|
32934
Description:
(Description Provided by CVE) : Multiple buffer overflows in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allow attackers to develop Java applets that read, write, or execute local files, possibly related to (1) integer overflows in the Java_sun_awt_image_ImagingLib_convolveBI, awt_parseRaster, and awt_parseColorModel functions; (2) a stack overflow in the Java_sun_awt_image_ImagingLib_lookupByteRaster function; and (3) improper handling of certain negative values in the Java_sun_font_SunLayoutEngine_nativeLayout function. NOTE: some of these details are obtained from third party information.
|
2006-12-19
|
Sun Java JRE Java_sun_font_SunLayoutEngine_nativeLayout Function Overflow
|
|
32380
Description:
Mac OS X contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when Quicktime for Java is used in conjunction with Quartz Composer to grab local screen images, which will disclose window contents information resulting in a loss of confidentiality.
|
2006-12-19
|
Apple Mac OS X Quicktime/Quartz Composer Information Disclosure
|
|
32390
Description:
(Description Provided by CVE) : Cross-site request forgery (CSRF) vulnerability in urlobox in MKPortal allows remote attackers to delete arbitrary messages as an administrator via a delete operation in an img BBcode tag.
|
2006-12-19
|
MKPortal Shoutbox Message img BBCode CSRF
|
|
32076
Description:
(Description Provided by CVE) : SQL injection vulnerability in down.asp in Burak Yylmaz Download Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
2006-12-19
|
Burak Yilmaz Download Portal down.asp id Parameter SQL Injection
|
|
32346
Description:
(Description Provided by CVE) : Race condition in W29N51.SYS in the Intel 2200BG wireless driver 9.0.3.9 allows remote attackers to cause memory corruption and execute arbitrary code via a series of crafted beacon frames. NOTE: some details are obtained solely from third party information.
|
2006-12-19
|
Intel 2200BG W29N51.SYS Driver Beacon Frame Race Condition Memory Corruption
|
|
32077
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to inject arbitrary web script or HTML via the e parameter.
|
2006-12-19
|
Support Cards 1 (osTicket) /support/view.php e Parameter XSS
|
|
32379
Description:
(Description Provided by CVE) : Multiple buffer overflows in FTP Print Server 2.4 and 2.4.5 in HP LaserJet 5000 Series printers with firmware R.25.15 or R.25.47, and HP LaserJet 5100 Series printers with firmware V.29.12, allow remote attackers to cause a denial of service (device crash) via a long string in the (1) LIST or (2) NLST command.
|
2006-12-19
|
HP FTP Print Server LIST DoS
|
|
32362
Description:
(Description Provided by CVE) : WinFtp Server 2.0.2 allows remote attackers to cause a denial of service (crash) via long (1) PASV, (2) LIST, (3) USER, (4) PORT, and possibly other commands.
|
2006-12-19
|
WinFtp Server Multiple Command Overflow DoS
|
|
32383
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in statistic.php in cwmCounter 5.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
|
2006-12-19
|
cwmCounter statistic.php path Parameter Remote File Inclusion
|
|
38216
Description:
(Description Provided by CVE) : ** DISPUTED ** Absolute path traversal vulnerability in Oracle Database Server, when utl_file_dir is set to a wildcard value or "CREATE ANY DIRECTORY to PUBLIC" privileges exist, allows remote authenticated users to read and modify arbitrary files via full filepaths to utl_file functions such as (1) utl_file.put_line and (2) utl_file.get_line, a related issue to CVE-2005-0701. NOTE: this issue is disputed by third parties who state that this is due to an insecure configuration instead of an inherent vulnerability.
|
2006-12-19
|
Oracle Database Server utl_file Functions Traversal Arbitrary File Manipulation
|
|
37389
Description:
(Description Provided by CVE) : Directory traversal vulnerability in index.php in cwmExplorer 1.0 allows remote attackers to read arbitrary files and source code, and obtain sensitive information via directory traversal sequences in the show_file parameter.
|
2006-12-19
|
cwmExplorer index.php show_file Parameter Traversal Arbitrary File Access
|
|
35200
Description:
(Description Provided by CVE) : The nodeType function in KDE libkhtml 4.2.0 and earlier, as used by Konquerer, KMail, and other programs, allows remote attackers to cause a denial of service (crash) via malformed HTML tags, possibly involving a COL SPAN tag embedded in a RANGE tag.
|
2006-12-19
|
KDE libkhtml nodeType Function Malformed HTML Tag Remote DoS
|
|
34830
Description:
(Description Provided by CVE) : The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a denial of service (Internet Explorer 7 hang) via crafted HTML.
|
2006-12-19
|
Microsoft Outlook Recipient ActiveX (ole32.dll) Crafted HTML DoS
|
|
35709
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in buycd.php in Paristemi 0.8.3 allows remote attackers to execute arbitrary PHP code via a URL in the HTTP_DOCUMENT_ROOT parameter, a different vector than CVE-2006-6689.
|
2006-12-19
|
Paristemi buycd.php HTTP_DOCUMENT_ROOT Parameter Remote File Inclusion
|
|
30854
Description:
(Description Provided by CVE) : Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion BPM r10 through r10.2, eTrust Security Command Center r1 and r8, and Unicenter, does not properly handle when multiple Portal servers are started at the same time and share the same data store, which might cause a Portal user to inherit the session and credentials of a user who is on another Portal server.
|
2006-12-19
|
CA CleverPath Portal Unspecified Session Inheritence
|