| OSVDB ID | Disclosure Date | Title |
|
41347
Description:
(Description Provided by CVE) : Xen 3.1.1 allows virtual guest system users to cause a denial of service (hypervisor crash) by using a debug register (DR7) to set certain breakpoints.
|
2007-10-31
|
Xen DR7 Debug Register Unprivileged Local DoS
|
|
42004
Description:
(Description Provided by CVE) : The format string protection mechanism in IMAPD for Perdition Mail Retrieval Proxy 1.17 and earlier allows remote attackers to execute arbitrary code via an IMAP tag with a null byte followed by a format string specifier, which is not counted by the mechanism.
|
2007-10-31
|
Perdition Mail Retrieval Proxy IMAPD IMAP Tag Remote Format String Arbitrary Code Execution
|
|
42011
Description:
(Description Provided by CVE) : GUI.pm in yarssr 0.2.2, when Gnome default URL handling is disabled, allows remote attackers to execute arbitrary commands via shell metacharacters in a link element in a feed.
|
2007-10-31
|
yarssr GUI.pm Gnome URL Handling Feed Link Element Arbitrary Command Injection
|
|
56408
Description:
(Description Provided by CVE) : Vidalia bundle before 0.1.2.18, when running on Windows and Mac OS X, installs Privoxy with a configuration file (config.txt or config) that contains insecure (1) enable-remote-toggle and (2) enable-edit-actions settings, which allows remote attackers to bypass intended access restrictions and modify configuration.
|
2007-10-31
|
Vidalia Bundles Insecure Privoxy Configuration Installation
|
|
38328
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Services/Utilities/classes/class.ilUtil.php in ILIAS 3.8.3 and earlier allows remote attackers to inject arbitrary web script or HTML via attributes inside a domain-name string in the (1) mailing or (2) forum component, as demonstrated using the style and onmouseover HTML attributes.
|
2007-10-31
|
ILIAS class.ilUtil.php Mail and Forum Message URL XSS
|
|
38358
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in download.php in ISPworker 1.21 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ticketid and (2) filename parameters.
|
2007-10-31
|
ISPworker download.php Multiple Parameter Traversal Arbitrary File Access
|
|
38414
Description:
ModuleBuilder contains a flaw that allows a remote attacker to read files outside of the web path. The issue is due to the DownloadModule.php not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'file' variable.
|
2007-10-31
|
SugarCRM Module Builder Module DownloadModule.php file Variable Traversal Arbitrary File Download
|
|
39018
Description:
(Description Provided by CVE) : ** DISPUTED ** Directory traversal vulnerability in PageTraiteDownload.php in phpMyConferences 8.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter. NOTE: this issue is disputed for 8.0.2 by a reliable third party, who notes that the PHP code is syntactically incorrect and cannot be executed.
|
2007-10-31
|
phpMyConferences PageTraiteDownload.php dir Parameter Traversal Arbitrary File Access
|
|
39061
Description:
(Description Provided by CVE) : SQL injection vulnerability in Amazing Flash AFCommerce allows remote attackers to execute arbitrary SQL commands via the firstname parameter to an unspecified component, a different issue than CVE-2006-3794. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2007-10-31
|
AFCommerce Unspecified Component firstname Parameter SQL Injection
|
|
39068
Description:
(Description Provided by CVE) : Directory traversal vulnerability in modules/Builder/DownloadModule.php in ModuleBuilder 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
|
2007-10-31
|
ModuleBuilder DownloadModule.php file Parameter Traversal Arbitrary File Access
|
|
40580
Description:
(Description Provided by CVE) : Integer overflow in McAfee E-Business Server before 8.5.3 for Solaris, and before 8.1.2 for Linux, HP-UX, and AIX, allows remote attackers to execute arbitrary code via a large length value in an authentication packet, which results in a heap-based buffer overflow.
|
2007-10-31
|
McAfee E-Business Server Authentication Packet Handling Remote Code Execution
|
|
40402
Description:
(Description Provided by CVE) : Stack-based buffer overflow in the sendrmt function in bellmail in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via a long parameter to the m command.
|
2007-10-30
|
IBM AIX bellmail sendrmt Function m Command Local Overflow
|
|
40403
Description:
(Description Provided by CVE) : Integer underflow in the dns_name_fromtext function in (1) libdns_nonsecure.a and (2) libdns_secure.a in IBM AIX 5.2 allows local users to gain privileges via a crafted "-y" (TSIG key) command line argument to dig.
|
2007-10-30
|
IBM AIX libdns_secure.a / libdns_nonsecure.a dns_name_fromtext Function Local Underflow
|
|
40404
Description:
(Description Provided by CVE) : Buffer overflow in crontab in IBM AIX 5.2 allows local users to gain privileges via long command line arguments.
|
2007-10-30
|
IBM AIX crontab Command Line Argument Local Overflow
|
|
40405
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges via a long argument to the (1) "-p" option to lqueryvg or (2) the "-V" option to lquerypv.
|
2007-10-30
|
IBM AIX lqueryvg -p Argument Local Overflow
|
|
40406
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges via a long argument to the (1) "-p" option to lqueryvg or (2) the "-V" option to lquerypv.
|
2007-10-30
|
IBM AIX lquerypv -V Argument Local Overflow
|
|
40407
Description:
(Description Provided by CVE) : Stack-based buffer overflow in the domacro function in ftp in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long parameter to a macro, as demonstrated by executing a macro via the '$' command.
|
2007-10-30
|
IBM AIX ftp domacro Function Macro Argument Local Privilege Escalation
|
|
48693
Description:
Unknown / Incomplete
|
2007-10-30
|
Joshua Multiple Unspecified Overflows
|
|
39389
Description:
(Description Provided by CVE) : Buffer overflow in IMail Client 9.22, as shipped with IPSwitch IMail Server 2006.22, allows remote attackers to execute arbitrary code via a long boundary parameter in a multipart MIME e-mail message.
|
2007-10-30
|
Ipswitch IMail Client Multipart MIME E-mail Message Handling Overflow
|
|
41620
Description:
(Description Provided by CVE) : IBM Tivoli Continuous Data Protection for Files (CDP) 3.1.0 uses weak permissions (unrestricted write) for the Central Admin Global download directory, which allows local users to place arbitrary files into a location used for updating CDP clients.
|
2007-10-30
|
IBM Tivoli Continuous Data Protection for Files (CDP) Central Admin Global Directory Permission Weakness
|
|
89721
Description:
Libxml2 contains a flaw in the xmlFree() function of xmlmemory.c that may allow a denial of service. The issue is triggered when handling NULL values. With a specially crafted value, a context-dependent attacker can cause the program to crash.
|
2007-10-30
|
Libxml2 xmlmemory.c xmlFree() Function Null Value Handling DoS
|
|
55763
Description:
Unknown / Incomplete
|
2007-10-30
|
Sun StorEdge / StorageTek NAS Long File Name Handling Backup Job Local DoS
|
|
45295
Description:
(Description Provided by CVE) : The reDirect function in lib/controllers/RepViewController.php in OrangeHRM before 2.2.2 does not verify the privileges of a user, which allows remote attackers to obtain access to data via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2007-10-30
|
OrangeHRM lib/controllers/RepViewController.php reDirect Function Unspecified Data Access
|
|
57117
Description:
Unknown / Incomplete
|
2007-10-30
|
Mozilla Firefox onblur() / onfocusout() Functions Nested Loop DoS
|
|
57118
Description:
Unknown / Incomplete
|
2007-10-30
|
Microsoft IE onblur() / onfocusout() Functions Nested Loop DoS
|
|
38300
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Omnistar Live allow remote attackers to inject arbitrary web script or HTML via (1) the category_id parameter to users/kb.php, and possibly (3) the Email Box field in profile.php.
|
2007-10-30
|
Omnistar Live kb.php category_id Parameter XSS
|
|
38305
Description:
Unknown / Incomplete
|
2007-10-30
|
AirKiosk I7/81015lfa URL XSS
|
|
38347
Description:
A code execution flaw exists in Update Service ActiveX control. isusweb.dll fails to validate data passed to several methods resulting download of arbitrary code. With a specially crafted website, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2007-10-30
|
Macrovision Update Service ActiveX (isusweb.dll) Unspecified Arbitrary Code Execution
|
|
38394
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in IBM Tivoli Service Desk 6.2 allows remote authenticated users to inject arbitrary web script or HTML via the Description parameter in a Maximo change action.
|
2007-10-30
|
IBM Tivoli Service Desk Maximo change Action Description Field XSS
|
|
40647
Description:
phpFaber URLInn contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'urlinn_includes/config.php' script not properly sanitizing user input supplied to the 'dir_ws' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-10-30
|
phpFaber URLInn urlinn_includes/config.php dir_ws Parameter Remote File Inclusion
|
|
41943
Description:
(Description Provided by CVE) : SQL injection vulnerability in bb_func_search.php in miniBB 2.1 allows remote attackers to execute arbitrary SQL commands via the table parameter to index.php.
|
2007-10-30
|
miniBB index.php table Parameter SQL Injection
|
|
50716
Description:
Unknown / Incomplete
|
2007-10-30
|
GNU less LESSOPEN Environment Variable Format String
|
|
45297
Description:
(Description Provided by CVE) : Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving creation of a profile.
|
2007-10-29
|
ProfileCMS Profile Creation Unrestricted File Upload Arbitrary PHP Code Execution
|
|
45330
Description:
(Description Provided by CVE) : SAXON 5.4, with display_errors enabled, allows remote attackers to obtain sensitive information via (1) a direct request for news.php, (2) an invalid use of a newsid array parameter to admin/edit-item.php, and possibly unspecified vectors related to additional scripts in (3) admin/, (4) rss/, and (5) the root directory of the installation, which reveal the path in various error messages.
|
2007-10-29
|
SAXON news.php Direct Request Path Disclosure
|
|
45331
Description:
(Description Provided by CVE) : SAXON 5.4, with display_errors enabled, allows remote attackers to obtain sensitive information via (1) a direct request for news.php, (2) an invalid use of a newsid array parameter to admin/edit-item.php, and possibly unspecified vectors related to additional scripts in (3) admin/, (4) rss/, and (5) the root directory of the installation, which reveal the path in various error messages.
|
2007-10-29
|
SAXON admin/edit-item.php Direct Request Path Disclosure
|
|
45332
Description:
(Description Provided by CVE) : SAXON 5.4, with display_errors enabled, allows remote attackers to obtain sensitive information via (1) a direct request for news.php, (2) an invalid use of a newsid array parameter to admin/edit-item.php, and possibly unspecified vectors related to additional scripts in (3) admin/, (4) rss/, and (5) the root directory of the installation, which reveal the path in various error messages.
|
2007-10-29
|
SAXON admin/ Directory Unspecified Scripts Path Disclosure
|
|
45333
Description:
(Description Provided by CVE) : SAXON 5.4, with display_errors enabled, allows remote attackers to obtain sensitive information via (1) a direct request for news.php, (2) an invalid use of a newsid array parameter to admin/edit-item.php, and possibly unspecified vectors related to additional scripts in (3) admin/, (4) rss/, and (5) the root directory of the installation, which reveal the path in various error messages.
|
2007-10-29
|
SAXON rss/ Directory Unspecified Scripts Path Disclosure
|
|
45334
Description:
(Description Provided by CVE) : SAXON 5.4, with display_errors enabled, allows remote attackers to obtain sensitive information via (1) a direct request for news.php, (2) an invalid use of a newsid array parameter to admin/edit-item.php, and possibly unspecified vectors related to additional scripts in (3) admin/, (4) rss/, and (5) the root directory of the installation, which reveal the path in various error messages.
|
2007-10-29
|
SAXON / Directory Unspecified Scripts Path Disclosure
|
|
45285
Description:
(Description Provided by CVE) : ** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via a request to admin/auth/user/1/password/. NOTE: this issue has been disputed by Debian, since product documentation includes a recommendation for a CSRF protection module that is included with the product. However, CVE considers this an issue because the default configuration does not use this module.
|
2007-10-29
|
Django Admin Panel admin/auth/user/1/password/ CSRF
|
|
41998
Description:
(Description Provided by CVE) : Stack-based buffer overflow in Sony SonicStage CONNECT Player (CP) 4.3 allows remote attackers to execute arbitrary code via a long file name in an M3U file.
|
2007-10-29
|
Sony SonicStage CONNECT Player (CP) M3U Filename Handling Overflow
|