| OSVDB ID | Disclosure Date | Title |
|
55089
Description:
(Description Provided by CVE) : Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to execute arbitrary code by uploading a file with only an extension in its name, then accessing the file via a direct request to a modified filename under cache/modules/Emails/, as demonstrated using .php as the entire original name.
|
2009-06-13
|
SugarCRM Emails Module File Upload Arbitrary PHP Code Execution
|
|
55088
Description:
FireStats Plugin for Wordpress contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'wp-content/plugins/firestats/firestats-wordpress.php' script not properly sanitizing user input supplied to the 'fs_javascript' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2009-06-13
|
FireStats Plugin for Wordpress wp-content/plugins/firestats/firestats-wordpress.php fs_javascript Parameter Remote File Inclusion
|
|
61781
Description:
Unknown / Incomplete
|
2009-06-13
|
Ikraus Multiple Products Parsing Engine Multiple Method Scanning Bypass
|
|
61783
Description:
Unknown / Incomplete
|
2009-06-13
|
Kaspersky Multiple Products Crafted PDF File Scan Bypass
|
|
55138
Description:
(Description Provided by CVE) : The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors.
|
2009-06-12
|
Mozilla Multiple Products Browser Engine nsEventStateManager::GetContentState / nsNativeTheme::CheckBooleanAttr Memory Corruption
|
|
55148
Description:
(Description Provided by CVE) : Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors involving "double frame construction."
|
2009-06-12
|
Mozilla Multiple Products Double Frame Construction Memory Corruption
|
|
55152
Description:
(Description Provided by CVE) : The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) js_LeaveSharpObject, (2) ParseXMLSource, and (3) a certain assertion in jsinterp.c; and other vectors.
|
2009-06-12
|
Mozilla Multiple Products JavaScript Engine js_LeaveSharpObject Memory Corruption
|
|
55162
Description:
(Description Provided by CVE) : Visual truncation vulnerability in netwerk/dns/src/nsIDNService.cpp in Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 allows remote attackers to spoof the location bar via an IDN with invalid Unicode characters that are displayed as whitespace, as demonstrated by the \u115A through \u115E characters.
|
2009-06-12
|
Mozilla Multiple Products Invalid Unicode Character Title Bar Spoofing
|
|
55161
Description:
(Description Provided by CVE) : Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located after the file:// substring in a URL, which allows user-assisted remote attackers to read arbitrary cookies via a crafted HTML document, as demonstrated by a URL with file://example.com/C:/ at the beginning.
|
2009-06-12
|
Mozilla Multiple Products file: Resource Cross Domain Arbitrary Cookie Access
|
|
55160
Description:
(Description Provided by CVE) : Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
|
2009-06-12
|
Mozilla Multiple Products Proxy Server CONNECT Response Manipulation SSL MiTM Weakness
|
|
55157
Description:
(Description Provided by CVE) : The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's owner document to null in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted event handler, related to an incorrect context for this event handler.
|
2009-06-12
|
Mozilla Multiple Products Garbage-collection Implementation Crafted Event Handler Privilege Escalation
|
|
55163
Description:
(Description Provided by CVE) : Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document, aka a "file-URL-to-file-URL scripting" attack.
|
2009-06-12
|
Mozilla Firefox Location Bar file: URL Principal Assocation Access Restriction Bypass
|
|
55158
Description:
(Description Provided by CVE) : Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page.
|
2009-06-12
|
Mozilla Multiple Products XUL Document Script Loading Content Policy Bypass
|
|
55159
Description:
(Description Provided by CVE) : js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to execute arbitrary web script with the privileges of a chrome object, as demonstrated by the browser sidebar and the FeedWriter.
|
2009-06-12
|
Mozilla Multiple Products xpcwrappedjsclass.cpp JavaScript Chrome Privilege Escalation
|
|
55147
Description:
(Description Provided by CVE) : The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors.
|
2009-06-12
|
Mozilla Multiple Products Browser Engine Multiple Unspecified Memory Corruption
|
|
55146
Description:
(Description Provided by CVE) : The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors.
|
2009-06-12
|
Mozilla Multiple Products Browser Engine xulrunner nsWindow::SetCursor Function Cursor Manipulation Memory Corruption
|
|
55145
Description:
(Description Provided by CVE) : The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors.
|
2009-06-12
|
Mozilla Multiple Products Browser Engine nsHTMLEditor::HideResizers contentEditable Property Manipulation Memory Corruption
|
|
55144
Description:
(Description Provided by CVE) : The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors.
|
2009-06-12
|
Mozilla Multiple Products Browser Engine AtomTableClearEntry Multiple Method Memory Corruption
|
|
55143
Description:
(Description Provided by CVE) : The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors.
|
2009-06-12
|
Mozilla Multiple Products Browser Engine nsListBoxBodyFrame::GetNextItemBox xul:listbox Handling Memory Corruption
|
|
55142
Description:
(Description Provided by CVE) : The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors.
|
2009-06-12
|
Mozilla Multiple Products Browser Engine PL_DHashTableFinish style Tag Handling Memory Corruption
|
|
55141
Description:
(Description Provided by CVE) : The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors.
|
2009-06-12
|
Mozilla Multiple Products Browser Engine IsPercentageAware Function Memory Corruption
|
|
55140
Description:
(Description Provided by CVE) : The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors.
|
2009-06-12
|
Mozilla Multiple Products Browser Engine nsTextFrame::ClearTextRun Accessibility Functionality Memory Corruption
|
|
55139
Description:
(Description Provided by CVE) : The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors.
|
2009-06-12
|
Mozilla Multiple Products Browser Engine UnhookTextRunFromFrames / ClearAllTextRunReferences Memory Corruption
|
|
55153
Description:
(Description Provided by CVE) : The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) js_LeaveSharpObject, (2) ParseXMLSource, and (3) a certain assertion in jsinterp.c; and other vectors.
|
2009-06-12
|
Mozilla Multiple Products JavaScript Engine jsxml.c ParseXMLSource Memory Corruption
|
|
55154
Description:
(Description Provided by CVE) : The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) js_LeaveSharpObject, (2) ParseXMLSource, and (3) a certain assertion in jsinterp.c; and other vectors.
|
2009-06-12
|
Mozilla Multiple Products JavaScript Engine jsinterp.c c.hasOwnProperty Memory Corruption
|
|
55155
Description:
(Description Provided by CVE) : The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) js_LeaveSharpObject, (2) ParseXMLSource, and (3) a certain assertion in jsinterp.c; and other vectors.
|
2009-06-12
|
Mozilla Multiple Products JavaScript Engine Unspecified Memory Corruption
|
|
55383
Description:
transLucid contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate NodeID and action parameters upon submission to the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-06-12
|
transLucid index.php Multiple Parameter XSS
|
|
55384
Description:
transLucid contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the NodeID parameter upon submission to the admin_section functionality of the index.php. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-06-12
|
transLucid index.php admin_section Functionality NodeID Parameter XSS
|
|
55385
Description:
transLucid contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the page name or URL parameters when editing or creating a page. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-06-12
|
transLucid Page Edit Functionality Multiple Parameter XSS
|
|
55034
Description:
(Description Provided by CVE) : git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request containing extra unrecognized arguments.
|
2009-06-12
|
Git git-daemon Crafted Request Handling Infinite Loop DoS
|
|
55081
Description:
TBDEV.NET contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'returnto' parameters upon submission to the 'makepoll.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-06-12
|
TBDEV.NET makepoll.php returnto Parameter XSS
|
|
55084
Description:
Zip Store Chat contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the admin/index.asp script not properly sanitizing user-supplied input to the 'login' and 'senha' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2009-06-12
|
Zip Store Chat admin/index.asp Multiple Parameter SQL Injection
|
|
55085
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.40.4 and 1.40.7 allow remote attackers to inject arbitrary web script or HTML via the (1) menu or (2) sort parameter to pivot/index.php, (3) the value of a check array parameter in a delete action to pivot/index.php, (4) the element name in a check array parameter in a delete action to pivot/index.php, (5) the edituser parameter in an edituser action to pivot/index.php, (6) the edit parameter in a templates action to pivot/index.php, (7) the blog parameter in a blog_edit1 action to pivot/index.php, (8) the cat parameter in a cat_edit action to pivot/index.php, (9) a certain form field in a doaction=1 request to pivot/index.php, (10) the url field in a my_weblog edit_prefs action to pivot/user.php, or (11) the username (aka name) field in a my_weblog reg_user action to pivot/user.php.
|
2009-06-12
|
Pivot pivot/index.php Multiple Parameter XSS
|
|
55082
Description:
TBDEV.NET contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'returnto' parameters upon submission to the 'polls.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-06-12
|
TBDEV.NET polls.php returnto Parameter XSS
|
|
55083
Description:
TBDEV.NET contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'info' parameters upon submission to the 'my.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-06-12
|
TBDEV.NET my.php info Parameter XSS
|
|
55126
Description:
A remote overflow exists in Green Dam. Green Dam fails to properly handle overly long URLS resulting in a stack-based buffer overflow. With a specially crafted URL, an attacker can cause a boundary error allowing for arbitrary code execution resulting in a loss of confidentiality, integrity, and/or availability.
|
2009-06-12
|
Green Dam URL Handling Overflow
|
|
55092
Description:
4images contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'user_homepage' parameters upon submission to the 'member.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-06-12
|
4images member.php user_homepage Parameter XSS
|
|
55086
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.40.4 and 1.40.7 allow remote attackers to inject arbitrary web script or HTML via the (1) menu or (2) sort parameter to pivot/index.php, (3) the value of a check array parameter in a delete action to pivot/index.php, (4) the element name in a check array parameter in a delete action to pivot/index.php, (5) the edituser parameter in an edituser action to pivot/index.php, (6) the edit parameter in a templates action to pivot/index.php, (7) the blog parameter in a blog_edit1 action to pivot/index.php, (8) the cat parameter in a cat_edit action to pivot/index.php, (9) a certain form field in a doaction=1 request to pivot/index.php, (10) the url field in a my_weblog edit_prefs action to pivot/user.php, or (11) the username (aka name) field in a my_weblog reg_user action to pivot/user.php.
|
2009-06-12
|
Pivot Visitor Registration user.php Multiple Function XSS
|
|
55115
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in admin.php in SkyBlueCanvas 1.1 r237 allow remote attackers to inject arbitrary web script or HTML via the (1) mgroup, (2) mgr, (3) objtype, (4) id, and (5) dir parameters.
|
2009-06-12
|
SkyBlueCanvas admin.php Multiple Parameter XSS
|
|
55114
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in index.php in Webmedia Explorer (webmex) 5.09 and 5.10 allow remote attackers to inject arbitrary web script or HTML via event handlers such as onmouseover in the (1) search or (2) tag parameters; (3) arbitrary invalid parameter names that are not properly handled when triggered on a column; (4) bookmark parameter in an edit action; or (5) email parameter in a remember action.
|
2009-06-12
|
Webmedia Explorer index.php Multiple Parameter XSS
|