| OSVDB ID | Disclosure Date | Title |
|
37732
Description:
(Description Provided by CVE) : Sergey Lyubka Simple HTTPD (shttpd) 1.38 allows remote attackers to obtain sensitive information (script source code) via a URL with a trailing encoded space (%20).
|
2007-06-23
|
Simple HTTPD (shttpd) Encoded Space (%20) Script Source Disclosure
|
|
36331
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the opsubmenu parameter.
|
2007-06-23
|
KeyFocus (KF) Web Server index.wkf opsubmenu Parameter XSS
|
|
39010
Description:
(Description Provided by CVE) : LiteWEB 2.7 allows remote attackers to cause a denial of service (hang) via a large number of requests for nonexistent pages.
|
2007-06-23
|
LiteWEB Nonexistent Page Saturation Request Remote DoS
|
|
39014
Description:
(Description Provided by CVE) : ** DISPUTED ** Microsoft Windows XP SP2 allows local users, who have sessions created by another user's RunAs (run as) command, to kill arbitrary processes of this other user, as demonstrated by the taskkill program. NOTE: the researcher claims a vendor dispute in which the vendor states that "RunAs and UAC are convenience features, not security boundaries. If you need a security guarantee, please log out and log back in with a different account."
|
2007-06-23
|
Microsoft Windows RunAs Command Local Arbitrary Process DoS
|
|
45364
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in download.php in the Adam van Dongen Forum (com_forum) component (aka phpBB component) 1.2.4RC3 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
|
2007-06-22
|
com_forum (phpBB Component) for Mambo download.php phpbb_root_path Parameter Remote File Inclusion
|
|
37729
Description:
(Description Provided by CVE) : ageet AGEphone before 1.6.2, running on Windows Mobile 5 on the HTC HyTN Pocket PC device, allows remote attackers to (1) cause a denial of service (call disruption and device hang) via a SIP message with a malformed header and (2) cause a denial of service (call disruption, false ring indication, and device outage) via a SIP message with a malformed SDP delimiter.
|
2007-06-22
|
AGEphone Malformed SIP Message Handling Remote DoS
|
|
37730
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in ageet AGEphone before 1.6.3 allow remote attackers to have an unknown impact via malformed SIP packets.
|
2007-06-22
|
AGEphone Malformed SIP Message Handling Multiple Unspecified Issues
|
|
45379
Description:
(Description Provided by CVE) : Memory leak in the token OCR functionality in ekg before 1:1.7~rc2-1etch1 on Debian GNU/Linux Etch allows remote attackers to cause a denial of service.
|
2007-06-22
|
ekg on Debian Linux Token OCR Functionality Remote Memory Exhaustion DoS
|
|
45378
Description:
(Description Provided by CVE) : ekg before 1:1.7~rc2-1etch1 on Debian GNU/Linux Etch allows remote attackers to cause a denial of service (NULL pointer dereference) via a vector related to the token OCR functionality.
|
2007-06-22
|
ekg on Debian Linux Token OCR Functionality NULL Dereference Remote DoS
|
|
45377
Description:
(Description Provided by CVE) : Memory leak in the image message functionality in ekg before 1:1.7~rc2-1etch1 on Debian GNU/Linux Etch allows remote attackers to cause a denial of service.
|
2007-06-22
|
ekg on Debian Linux Image Message Functionality Remote Memory Exhaustion DoS
|
|
36450
Description:
Mac OS X contains a flaw related to the WebKit that may allow a remote attacker to execute arbitrary code via a specially crafted web page. No further details have been provided.
|
2007-06-22
|
Apple Mac OS X / iPhone WebKit Frame Sets Unspecified Memory Corruption
|
|
36452
Description:
(Description Provided by CVE) : Race condition in Apple Safari 3 Beta before 3.0.2 on Mac OS X, Windows XP, Windows Vista, and iPhone before 1.0.1, allows remote attackers to bypass the JavaScript security model and modify pages outside of the security domain and conduct cross-site scripting (XSS) attacks via vectors related to page updating and HTTP redirects.
|
2007-06-22
|
Apple Safari / iPhone HTTP Redirect Unspecified JavaScript Security Model
|
|
37805
Description:
(Description Provided by CVE) : Buffer overflow in bbs100 before 3.2 allows remote attackers to cause a denial of service (crash) by attempting to login as the Guest user when another Guest user is already logged in, possibly related to the state_login_prompt function in state_login.c.
|
2007-06-22
|
bbs100 Concurrent Guest Login Overflow DoS
|
|
37806
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in bbs100 before 3.2 allow remote attackers to cause a denial of service (crash) via unspecified vectors, possibly involving certain v*printf and shift_StringIO functions. NOTE: some details were obtained from third party information.
|
2007-06-22
|
bbs100 src/StringIO.c shift_StringIO() Function DoS
|
|
37807
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in bbs100 before 3.2 allow remote attackers to cause a denial of service (crash) via unspecified vectors, possibly involving certain v*printf and shift_StringIO functions. NOTE: some details were obtained from third party information.
|
2007-06-22
|
bbs100 on Debian PPC v*printf() DoS
|
|
41635
Description:
(Description Provided by CVE) : SlackRoll before 8 accepts gpg exit codes other than 0 and 1 as evidence of a valid signature, which allows remote Slackware mirror sites or man-in-the-middle attackers to cause a denial of service (data inconsistency) or possibly install Trojan horse packages via malformed gpg signatures.
|
2007-06-22
|
Slackroll Malformed gpg Signature Exit Code Weakness
|
|
37750
Description:
access2asp contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'od' and 'search' variables upon submission to the suppliersList.asp script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-06-22
|
access2asp suppliersList.asp Multiple Parameter XSS
|
|
37751
Description:
access2asp contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'od' and 'search' variables upon submission to the contactsList.asp script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-06-22
|
access2asp contactsList.asp Multiple Parameter XSS
|
|
37614
Description:
(Description Provided by CVE) : Xythos Enterprise Document Manager (XEDM), Digital Locker (XDL), and possibly WebFile Server before 6.0.46.1 allow remote authenticated users to associate arbitrary Content-Type HTTP headers with documents, which might facilitate malware distribution.
|
2007-06-22
|
Xythos Multiple Products Content-Type HTTP Header Document Association Weakness
|
|
37615
Description:
(Description Provided by CVE) : Multiple cross-site request forgery (CSRF) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to execute commands as arbitrary users via (1) a saved Workflow name or (2) the Content-Type HTTP header. NOTE: item 2 also affects the same version numbers of Xythos Digital Locker (XDL). One or both vectors might also affect Xythos WebFile Server.
|
2007-06-22
|
Xythos Multiple Products Saved Workflow Name CSRF
|
|
37616
Description:
(Description Provided by CVE) : Multiple cross-site request forgery (CSRF) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to execute commands as arbitrary users via (1) a saved Workflow name or (2) the Content-Type HTTP header. NOTE: item 2 also affects the same version numbers of Xythos Digital Locker (XDL). One or both vectors might also affect Xythos WebFile Server.
|
2007-06-22
|
Xythos Multiple Products Content-Type HTTP Header CSRF
|
|
37621
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to inject arbitrary web script or HTML via (1) a saved Workflow name; (2) a Workflow name, related to deletion of a Workflow template; (3) the Content-Type HTTP header; or (4) the name of an uploaded file. NOTE: items 3 and 4 also affect the same version numbers of Xythos Digital Locker (XDL). Some or all vectors might also affect Xythos WebFile Server.
|
2007-06-22
|
Xythos Multiple Products Saved Workflow Name XSS
|
|
37622
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to inject arbitrary web script or HTML via (1) a saved Workflow name; (2) a Workflow name, related to deletion of a Workflow template; (3) the Content-Type HTTP header; or (4) the name of an uploaded file. NOTE: items 3 and 4 also affect the same version numbers of Xythos Digital Locker (XDL). Some or all vectors might also affect Xythos WebFile Server.
|
2007-06-22
|
Xythos Multiple Products Workflow Template XSS
|
|
37623
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to inject arbitrary web script or HTML via (1) a saved Workflow name; (2) a Workflow name, related to deletion of a Workflow template; (3) the Content-Type HTTP header; or (4) the name of an uploaded file. NOTE: items 3 and 4 also affect the same version numbers of Xythos Digital Locker (XDL). Some or all vectors might also affect Xythos WebFile Server.
|
2007-06-22
|
Xythos Multiple Products Content-Type HTTP Header XSS
|
|
37624
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to inject arbitrary web script or HTML via (1) a saved Workflow name; (2) a Workflow name, related to deletion of a Workflow template; (3) the Content-Type HTTP header; or (4) the name of an uploaded file. NOTE: items 3 and 4 also affect the same version numbers of Xythos Digital Locker (XDL). Some or all vectors might also affect Xythos WebFile Server.
|
2007-06-22
|
Xythos Multiple Products Uploaded File XSS
|
|
37507
Description:
(Description Provided by CVE) : The Avahi daemon in Avahi before 0.6.20 allows attackers to cause a denial of service (exit) via empty TXT data over D-Bus, which triggers an assert error.
|
2007-06-22
|
Avahi D-Bus Empty TXT Data Remote DoS
|
|
35860
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Simple CGI Wrapper (scgiwrap) in cPanel before 10.9.1, and 11.x before 11.4.19-R14378, allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2007-06-22
|
cPanel Simple CGI Wrapper URI XSS
|
|
35861
Description:
(Description Provided by CVE) : Simple CGI Wrapper (scgiwrap) in cPanel before 10.9.1, and 11.x before 11.4.19-R14378, allows remote attackers to obtain sensitive information via a direct request, which reveals the path in an error message. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2007-06-22
|
cPanel Simple CGI Wrapper Direct Request Path Disclosure
|
|
36281
Description:
Sun Board contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'include.php' script not properly sanitizing user input supplied to the 'sunPath' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-06-22
|
Sun Board include.php sunPath Parameter Remote File Inclusion
|
|
36282
Description:
Sun Board contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'skin/board/default/doctype.php' script not properly sanitizing user input supplied to the 'dir' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-06-22
|
Sun Board skin/board/default/doctype.php dir Parameter Remote File Inclusion
|
|
36325
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in SerWeb 0.9.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _SERWEB[serwebdir] parameter to (1) html/load_apu.php or (2) html/mail_prepend.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2007-06-22
|
SERWeb html/load_apu.php _SERWEB[serwebdir] Parameter Remote File Inclusion
|
|
36326
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in SerWeb 0.9.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _SERWEB[serwebdir] parameter to (1) html/load_apu.php or (2) html/mail_prepend.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2007-06-22
|
SERWeb html/mail_prepend.php _SERWEB[serwebdir] Parameter Remote File Inclusion
|
|
36368
Description:
Powl contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'plugins/widgets/htmledit/htmledit.php' script not properly sanitizing user input supplied to the '_POWL[installPath]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-06-22
|
Powl plugins/widgets/htmledit/htmledit.php _POWL[installPath] Parameter Remote File Inclusion
|
|
36721
Description:
(Description Provided by CVE) : Buffer overflow in Warzone 2100 Resurrection before 2.0.7 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long filename when setting background music.
|
2007-06-22
|
Warzone 2100 Resurrection Background Music File Handling Overflow
|
|
38222
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in index.php in phpRaider 1.0.0 rc8 allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) type parameter.
|
2007-06-22
|
phpRaider index.php Multiple Parameter SQL Injection
|
|
38226
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in bosDataGrid 2.50 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) GridSearch, (2) gsearch, or (3) ParentID parameter to an unspecified component.
|
2007-06-22
|
bosDataGrid Unspecified Component Multiple Parameter XSS
|
|
38227
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via the (1) artid parameter to mod.php in a viewarticle action (publisher mod) and the (2) bid parameter to banners.php in a click action. NOTE: the mod.php viewdisk and viewlink vectors are already covered by CVE-2006-6873.
|
2007-06-22
|
eNdonesia mod.php viewarticle Action artid Parameter SQL Injection
|
|
38228
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via the (1) artid parameter to mod.php in a viewarticle action (publisher mod) and the (2) bid parameter to banners.php in a click action. NOTE: the mod.php viewdisk and viewlink vectors are already covered by CVE-2006-6873.
|
2007-06-22
|
eNdonesia banners.php click Action bid Parameter SQL Injection
|
|
41644
Description:
(Description Provided by CVE) : The web container in IBM WebSphere Application Server (WAS) before 6.0.2.21, and 6.1.x before 6.1.0.9, sends response data intended for a different request in certain circumstances after a closed connection error, which might allow remote attackers to obtain sensitive information.
|
2007-06-22
|
IBM WebSphere Application Server (WAS) Web Container Cross-Request Information Disclosure
|
|
42189
Description:
(Description Provided by CVE) : Integer overflow in the __status_Update function in stats.c VideoLAN VLC Media Player before 0.8.6c allows remote attackers to cause a denial of service (crash) via a WAV file with a large sample rate.
|
2007-06-21
|
VLC Media Player stats.c __status_Update() Function WAV File Handling Overflow
|