| OSVDB ID | Disclosure Date | Title |
|
36310
Description:
(Description Provided by CVE) : SQL injection vulnerability in show_event.php in the Expanded Calendar (calendar_panel) 2.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the m_month parameter.
|
2007-03-31
|
PHP-Fusion Expanded Calendar Module show_event.php m_month Variable SQL Injection
|
|
41985
Description:
(Description Provided by CVE) : Multiple off-by-one errors in VooDoo cIRCle before 1.1.beta27 allow remote attackers to cause a denial of service (connection loss) or possibly execute arbitrary code via a (1) DNS name response of the exact length as a buffer; or a long (2) channel name, (3) partyline channel name, or unspecified vectors in crafted BOTNET packets.
|
2007-03-31
|
VooDoo cIRCle BOTNET Channel Name Overflow
|
|
41986
Description:
(Description Provided by CVE) : Multiple off-by-one errors in VooDoo cIRCle before 1.1.beta27 allow remote attackers to cause a denial of service (connection loss) or possibly execute arbitrary code via a (1) DNS name response of the exact length as a buffer; or a long (2) channel name, (3) partyline channel name, or unspecified vectors in crafted BOTNET packets.
|
2007-03-31
|
VooDoo cIRCle DNS Response Handling Overflow
|
|
34626
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in lib/timesheet.class.php in Softerra Time-Assistant 6.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_dir or (2) lib_dir parameter.
|
2007-03-30
|
Softerra Time-Assistant lib/timesheet.class.php Multiple Variable Remote File Inclusion
|
|
34988
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in JCcorp URLshrink before 1.3.2 have unspecified attack vectors and impact.
|
2007-03-30
|
URLShrink Multiple Unspecified Issues
|
|
34640
Description:
(Description Provided by CVE) : Stack-based buffer overflow in the dns_decode_reverse_name function in dns_decode.c in dproxy-nexgen allows remote attackers to execute arbitrary code by sending a crafted packet to port 53/udp, a different issue than CVE-2007-1465.
|
2007-03-30
|
dproxy-nexgen dns_decode.c dns_decode_reverse_name Function Remote Overflow
|
|
35445
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in MOD_forum_fields_parse.php in the Forum picture and META tags 1.7 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
|
2007-03-30
|
Forum Picture and META Tags Module for phpBB MOD_forum_fields_parse.php phpbb_root_path Variable Remote File Inclusion
|
|
34679
Description:
(Description Provided by CVE) : The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters.
|
2007-03-30
|
Qt codecs/qutfcodec.cpp UTF-8 Decoder Long Sequence XSS
|
|
33955
Description:
PHP contains a flaw that may allow a context-dependent attacker to gain elevated privileges. The issue is due to an integer signedness error in the printf function family as used on 64 bit machines. When a negative argument number is passed to the php_formatted_print function before a 64 to 32 bit truncation, it may bypass a check for the maximum allowable value causing memory corruption. This may allow an attacker to execute arbitrary code.
|
2007-03-30
|
PHP php_formatted_print Function 64 Bit Casting Memory Corruption
|
|
34767
Description:
PHP contains a flaw that may allow a context-dependent attacker to gain elevated privileges. The issue is due to an integer signedness error in the printf function family as used on 64 bit machines. When a width and precision of -1 is passed to the php_sprintf_appendstring function, it may place an internal buffer at an arbitrary memory location. This may allow an attacker to execute arbitrary code.
|
2007-03-30
|
PHP php_sprintf_appendstring Function 64 Bit Casting Memory Corruption
|
|
37305
Description:
(Description Provided by CVE) : Directory traversal vulnerability in classes/captcha/captcha.jpg.php in Drake CMS allows remote attackers to read arbitrary files or list arbitrary directories, and obtain the installation path, via a .. (dot dot) in the d_private parameter. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS."
|
2007-03-30
|
Drake CMS classes/captcha/captcha.jpg.php d_private Variable Traversal Arbitrary File Access
|
|
37306
Description:
(Description Provided by CVE) : Directory traversal vulnerability in 404.php in Drake CMS allows remote attackers to include and execute arbitrary local arbitrary files via a .. (dot dot) in the d_private parameter. NOTE: some of these details are obtained from third party information. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS."
|
2007-03-30
|
Drake CMS 404.php d_private Variable Traversal Local File Inclusion
|
|
37307
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in admin/classes/ui.dta.php in Drake CMS allows remote attackers to inject arbitrary web script or HTML via the desc[][title] field. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS."
|
2007-03-30
|
Drake CMS admin/classes/ui.dta.php desc[][title] Variable XSS
|
|
34658
Description:
(Description Provided by CVE) : member.php in MyBB (aka MyBulletinBoard), when debug mode is available, allows remote authenticated users to change the password of any account by providing the account's registered e-mail address in a debug request for a do_lostpw action, which prints the change password verification code in the debug output.
|
2007-03-30
|
MyBulletinBoard (MyBB) member.php do_lostpw Action Arbitrary Account Password Modification
|
|
34987
Description:
(Description Provided by CVE) : JCcorp URLshrink 1.3.1 allows remote attackers to execute arbitrary PHP code via the email address field in an HTML link. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2007-03-30
|
URLshrink email address field Arbirtary PHP Code Execution
|
|
34588
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in MailDwarf 3.01 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
2007-03-30
|
MailDwarf Unspecified XSS
|
|
34589
Description:
(Description Provided by CVE) : Unspecified vulnerability in MailDwarf 3.01 and earlier allows remote attackers to send e-mail to addresses different from the configured addresses.
|
2007-03-30
|
MailDwarf Unspecified Arbitrary E-mail Relay
|
|
34590
Description:
(Description Provided by CVE) : Unspecified vulnerability in Hitachi JP1/HiCommand DeviceManager, Global Link Availability Manager, Replication Monitor, Tiered Storage Manager, and Tuning Manager allows local users to obtain authentication information via unspecified vectors.
|
2007-03-30
|
Hitachi JP1/HiCommand Unspecified Authentication Credential Disclosure
|
|
34895
Description:
Unknown / Incomplete
|
2007-03-30
|
URLshrink Free Multiple Unspecified Issues
|
|
34897
Description:
(Description Provided by CVE) : Buffer overflow in the pfs_mountd.rpc RPC daemon in the Portable File System (PFS) in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to execute arbitrary code by sending "a call to procedure 5, followed by a crafted payload to procedure 2."
|
2007-03-30
|
HP-UX Portable File System (PFS) pfs_mountd.rpc Remote Code Execution
|
|
34544
Description:
(Description Provided by CVE) : SQL injection vulnerability in Hitachi Collaboration - Online Community Management 01-00 through 01-30, as used in Groupmax Collaboration Portal, Groupmax Collaboration Web Client, uCosminexus Collaboration Portal, Cosminexus Collaboration Portal, and uCosminexus Content Manager, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
2007-03-30
|
Hitachi Multiple Products Unspecified SQL Injection
|
|
34318
Description:
(Description Provided by CVE) : The LinkSBIcons method in the SuperBuddy ActiveX control (Sb.SuperBuddy.1) in America Online 9.0 Security Edition dereferences an arbitrary function pointer, which allows remote attackers to execute arbitrary code via a modified pointer value.
|
2007-03-30
|
America Online SuperBuddy ActiveX Control (Sb.SuperBuddy.1) LinkSBIcons Method Arbitrary Code Execution
|
|
34126
Description:
(Description Provided by CVE) : The RPC service in mediasvr.exe in CA BrightStor ARCserve Backup 11.5 SP2 build 4237 allows remote attackers to execute arbitrary code via crafted xdr_handle_t data in RPC packets, which is used in calculating an address for a function call, as demonstrated using the 191 (0xbf) RPC request.
|
2007-03-30
|
CA BrightStor ARCserve Backup MEDIASVR.EXE RPC Request
Code Execution
|
|
37365
Description:
(Description Provided by CVE) : Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the table parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, a related issue to CVE-2006-2019.
|
2007-03-30
|
JSBoard login.php table Traversal Local File Inclusion
|
|
37373
Description:
(Description Provided by CVE) : SQL injection vulnerability in viewcat.php in the Repository module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter.
|
2007-03-30
|
Repository Module for XOOPS viewcat.php cid Variable SQL Injection
|
|
34947
Description:
(Description Provided by CVE) : PulseAudio 0.9.5 allows remote attackers to cause a denial of service (daemon crash) via (1) a PA_PSTREAM_DESCRIPTOR_LENGTH value of FRAME_SIZE_MAX_ALLOW sent on TCP port 9875, which triggers a p->export assertion failure in do_read; (2) a PA_PSTREAM_DESCRIPTOR_LENGTH value of 0 sent on TCP port 9875, which triggers a length assertion failure in pa_memblock_new; or (3) an empty packet on UDP port 9875, which triggers a t assertion failure in pa_sdp_parse; and allows remote authenticated users to cause a denial of service (daemon crash) via a crafted packet on TCP port 9875 that (4) triggers a maxlength assertion failure in pa_memblockq_new, (5) triggers a size assertion failure in pa_xmalloc, or (6) plays a certain sound file.
|
2007-03-29
|
PulseAudio Multiple Method Malformed Packet Remote DoS
|
|
34981
Description:
(Description Provided by CVE) : Buffer overflow in the drmgr command in IBM AIX 5.2 and 5.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long path name.
|
2007-03-29
|
IBM AIX drmgr Path Name Local Overflow
|
|
35458
Description:
(Description Provided by CVE) : Directory traversal vulnerability in inc/lang.php in sBLOG 0.7.3 Beta allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conf_lang_default parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by inc/lang.php.
|
2007-03-29
|
sBLOG inc/lang.php conf_lang_default Variable Local File Inclusion
|
|
33629
Description:
A remote overflow exists in Microsoft Internet Explorer. The browser fails to check the buffer on animated cursors and icons resulting in a stack buffer overflow. With a specially crafted request, an attacker can execute arbitrary code resulting in a loss of integrity.
|
2007-03-29
|
Microsoft IE Animated Cursor (.ani) Handling Arbitrary Command Execution
|
|
34535
Description:
(Description Provided by CVE) : Mozilla Firefox 2.0.0.1 through 2.0.0.3 does not canonicalize URLs before checking them against the phishing site blacklist, which allows remote attackers to bypass phishing protection via multiple / (slash) characters in the URL.
|
2007-03-29
|
Mozilla Firefox Crafted URL Phishing Blacklist Bypass
|
|
33954
Description:
PHP contains a flaw that may allow a context-dependent attacker to gain access to sensitive information. The issue is due to the iptcembed function not properly handling user-supplied input. If an attacker can force an interruption that triggers a user space error handler that changes a parameter, they may be able to gain access to arbitrary portions of the system memory.
|
2007-03-29
|
PHP iptcembed() Function Interruption Arbitrary Memory Disclosure
|
|
35211
Description:
(Description Provided by CVE) : The JNILoader ActiveX control (STJNILoader.ocx) 3.1.0.26 in IBM Lotus Notes Sametime before 7.5 allows remote attackers to load arbitrary DLL libraries and execute arbitrary code via arbitrary arguments to the loadLibrary function.
|
2007-03-29
|
IBM Lotus Sametime JNILoader ActiveX control (STJNILoader.ocx) Remote Code Execution
|
|
35207
Description:
(Description Provided by CVE) : Unspecified vulnerability in (1) Deskbar.dll and (2) Toolbar.dll in AOL 9.0 before February 2007 allows remote attackers to cause a denial of service (browser crash) via unknown vectors.
|
2007-03-29
|
AOL Deskbar.dll / Toolbar.dll Unspecified DoS
|
|
36519
Description:
(Description Provided by CVE) : Directory traversal vulnerability in rdw_helpers.py in rdiffWeb before 0.3.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to the /browse URI.
|
2007-03-29
|
rdiffWeb rdw_helpers.py path Variable Traversal Arbitrary File Access
|
|
34464
Description:
(Description Provided by CVE) : SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
2007-03-29
|
FriendFinder Module for XOOPS view.php id Variable SQL Injection
|
|
34936
Description:
(Description Provided by CVE) : SQL injection vulnerability in wall.php in Picture-Engine 1.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.
|
2007-03-29
|
Picture-Engine wall.php cat Variable SQL Injection
|
|
34518
Description:
(Description Provided by CVE) : Minna De Office 1.x and 2.x does not properly restrict user access to certain privileged actions, which allows local users to change the configuration or have other unspecified impact. NOTE: some of these details are obtained from third party information.
|
2007-03-29
|
Minna De Office Privileged Access Unspecified Restriction Bypass
|
|
34543
Description:
(Description Provided by CVE) : CruiseWorks 1.09e and earlier does not properly restrict user access to certain privileged actions, which allows local users to change the configuration or have other unspecified impact. NOTE: some of these details are obtained from third party information.
|
2007-03-29
|
CruiseWorks Privileged Action Access Restrictions Bypass
|
|
36160
Description:
(Description Provided by CVE) : Buffer overflow in the wireless driver 6.0.0.18 for D-Link DWL-G650+ (Rev. A1) on Windows XP allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a beacon frame with a long TIM Information Element.
|
2007-03-29
|
D-Link DWL-G650+ Wireless Driver Beacon TIM Information Element Overflow
|
|
34593
Description:
(Description Provided by CVE) : Heap-based buffer overflow in the kernel in NetBSD 3.0, certain versions of FreeBSD and OpenBSD, and possibly other BSD derived operating systems allows local users to have an unknown impact. NOTE: this information is based upon a vague pre-advisory with no actionable information. Details will be updated after 20070329.
|
2007-03-29
|
Multiple BSD Unspecified Kernel Overflow
|