| OSVDB ID | Disclosure Date | Title |
|
58114
Description:
Gazelle CMS contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'lookup' parameters upon submission to the 'search.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-08-12
|
Gazelle CMS search.php lookup Parameter XSS
|
|
58116
Description:
Gazelle CMS contains a flaw that may allow a malicious user to reset user passwords. The issue is triggered when submitting a password reset to the renew.php script which does not validate the 'user' parameter. It is possible that the flaw may allow password resets resulting in a loss of integrity.
|
2009-08-12
|
Gazelle CMS renew.php user Parameter Password Reset Weakness
|
|
58117
Description:
Gazelle CMS contains a flaw that allows a remote attacker to overwrite files outside of the web path. The issue is due to the admin/settemplate.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'customizetemplate' variable(s).
|
2009-08-12
|
Gazelle CMS admin/settemplate.php customizetemplate Parameter Traversal Arbitrary File Overwrite
|
|
57002
Description:
(Description Provided by CVE) : Format string vulnerability in the CNS_AddTxt function in logs.dll in 2K Games Vietcong 2 1.10 and earlier might allow remote attackers to execute arbitrary code via format string specifiers in the nickname.
|
2009-08-12
|
Vietcong 2 Console Message logs.dll CNS_AddTxt() Function Format String
|
|
57001
Description:
(Description Provided by CVE) : Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.19 and earlier, and NaSMail before 1.7, allow remote attackers to hijack the authentication of unspecified victims via features such as send message and change preferences, related to (1) functions/mailbox_display.php, (2) src/addrbook_search_html.php, (3) src/addressbook.php, (4) src/compose.php, (5) src/folders.php, (6) src/folders_create.php, (7) src/folders_delete.php, (8) src/folders_rename_do.php, (9) src/folders_rename_getname.php, (10) src/folders_subscribe.php, (11) src/move_messages.php, (12) src/options.php, (13) src/options_highlight.php, (14) src/options_identities.php, (15) src/options_order.php, (16) src/search.php, and (17) src/vcard.php.
|
2009-08-12
|
SquirrelMail Multiple Form Pages CSRF
|
|
57026
Description:
Elicio contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'campaignpage.cfm' script not properly sanitizing user-supplied input to the 'c_campaignid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-08-12
|
Elicio campaignpage.cfm c_campaignid Parameter SQL Injection
|
|
57007
Description:
Plume CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'manager/index.php' script not properly sanitizing user-supplied input to the 'm' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-08-12
|
Plume CMS manager/index.php m Parameter SQL Injection
|
|
57008
Description:
Plume CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'manager/tools.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-08-12
|
Plume CMS manager/tools.php id Parameter SQL Injection
|
|
57134
Description:
(Description Provided by CVE) : Cross-site request forgery (CSRF) vulnerability in HP Insight Control Suite For Linux (aka ICE-LX) before 2.11 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
|
2009-08-12
|
HP Insight Control Suite For Linux Unspecified CSRF
|
|
57397
Description:
Buildbot contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate unspecified variables upon submission to the status/web/waterfall.py script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-08-12
|
Buildbot status/web/waterfall.py Unspecified Parameter XSS
|
|
62293
Description:
Unknown / Incomplete
|
2009-08-12
|
Palm Pre WebOS Application Usage Remote Information Disclosure
|
|
62400
Description:
Unknown / Incomplete
|
2009-08-12
|
Microsoft Wordpad Malformed RTF File Parsing Memory Exhaustion DoS
|
|
58203
Description:
(Description Provided by CVE) : OXID eShop 4.x before 4.1.4-21266, 3.x, and 2.x allows remote attackers to obtain sensitive information (session details and order history of other users) via a crafted cookie.
|
2009-08-11
|
OXID eShop Crafted Cookie Arbitrary User Session / Order History Information Disclosure
|
|
56911
Description:
(Description Provided by CVE) : Heap-based buffer overflow in Microsoft Remote Desktop Connection (formerly Terminal Services Client) running RDP 5.0 through 6.1 on Windows, and Remote Desktop Connection Client for Mac 2.0, allows remote attackers to execute arbitrary code via unspecified parameters, aka "Remote Desktop Connection Heap Overflow Vulnerability."
|
2009-08-11
|
Microsoft Remote Desktop Server (RDS) mstscax.dll Packet Parsing Remote Overflow
|
|
56912
Description:
(Description Provided by CVE) : Heap-based buffer overflow in the Microsoft Terminal Services Client ActiveX control running RDP 6.1 on Windows XP SP2, Vista SP1 or SP2, or Server 2008 Gold or SP2; or 5.2 or 6.1 on Windows XP SP3; allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods, aka "Remote Desktop Connection ActiveX Control Heap Overflow Vulnerability."
|
2009-08-11
|
Microsoft Windows Terminal Services Client ActiveX Unspecified Overflow
|
|
56910
Description:
(Description Provided by CVE) : The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors related to erroneous free operations after reading a variant from a stream and deleting this variant, aka "ATL Object Type Mismatch Vulnerability."
|
2009-08-11
|
Microsoft Visual Studio Active Template Library (ATL) Header Mismatch Remote Code Execution
|
|
56908
Description:
(Description Provided by CVE) : Unspecified vulnerability in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed header in a crafted AVI file, aka "Malformed AVI Header Vulnerability."
|
2009-08-11
|
Microsoft Windows Malformed AVI Header Parsing Arbitrary Code Execution
|
|
56909
Description:
(Description Provided by CVE) : Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows allows remote attackers to execute arbitrary code on a Windows 2000 SP4 system via a crafted AVI file, or cause a denial of service on a Windows XP SP2 or SP3, Server 2003 SP2, Vista Gold, SP1, or SP2, or Server 2008 Gold or SP2 system via a crafted AVI file, aka "AVI Integer Overflow Vulnerability."
|
2009-08-11
|
Microsoft Windows AVI Media File Parsing Unspecified Overflow
|
|
56905
Description:
.NET Framework contains a flaw that may allow a remote denial of service. The issue is triggered by the way ASP.NET scheduling is managed , and will result in loss of availability for the IIS service.
|
2009-08-11
|
Microsoft .NET Framework Request Scheduling Crafted HTTP Request Remote DoS
|
|
56904
Description:
(Description Provided by CVE) : The Telnet service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote Telnet servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, aka "Telnet Credential Reflection Vulnerability," a related issue to CVE-2000-0834.
|
2009-08-11
|
Microsoft Windows Telnet NTLM Credential Reflection Remote Access
|
|
56902
Description:
(Description Provided by CVE) : Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC message to a Windows XP SP2 or SP3 or Server 2003 SP2 system, or cause a denial of service via a crafted RPC message to a Vista Gold, SP1, or SP2 or Server 2008 Gold or SP2 system, aka "Workstation Service Memory Corruption Vulnerability."
|
2009-08-11
|
Microsoft Windows Workstation Service NetrGetJoinInformation Function Local Memory Corruption Arbitrary Code Execution
|
|
56901
Description:
(Description Provided by CVE) : The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain privileges via a crafted request, aka "MSMQ Null Pointer Vulnerability."
|
2009-08-11
|
Microsoft Windows Message Queuing Service (MSMQ) mqac.sys IOCTL Request Parsing Local Privilege Escalation
|
|
57030
Description:
Unknown / Incomplete
|
2009-08-11
|
GEM 2 Engine Incomplete Packet Type NULL Dereference Remote DoS
|
|
57031
Description:
Unknown / Incomplete
|
2009-08-11
|
GEM 2 Engine Malformed Packet Handling Remote DoS
|
|
57032
Description:
Unknown / Incomplete
|
2009-08-11
|
GEM 2 Engine Crafted Packet Remote Memory Corruption
|
|
58099
Description:
Fedora Puppet contains a flaw that may allow a malicious user to access restricted files. The issue is triggered when permissions are not set correctly for the /var/log/puppet directory occurs. It is possible that the flaw may allow access to restricted files resulting in a loss of confidentiality and integrity.
|
2009-08-11
|
Puppet /var/log/puppet Permission Weakness Restricted File Access
|
|
57025
Description:
(Description Provided by CVE) : XScreenSaver in Sun Solaris 10, when the accessibility feature is enabled, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276 and CVE-2009-2711.
|
2009-08-11
|
Solaris XScreenSaver (xscreensaver(1)) with Assistive Technology Support Screen Lock Bypass
|
|
56899
Description:
(Description Provided by CVE) : Heap-based buffer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted WINS replication packet that triggers an incorrect buffer-length calculation, aka "WINS Heap Overflow Vulnerability."
|
2009-08-11
|
Microsoft Windows Internet Name Service (WINS) Push Request Handling Remote Overflow
|
|
56900
Description:
(Description Provided by CVE) : Integer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 allows remote WINS replication partners to execute arbitrary code via crafted data structures in a packet, aka "WINS Integer Overflow Vulnerability."
|
2009-08-11
|
Microsoft Windows Internet Name Service (WINS) Network Packet Handling Remote Integer Overflow
|
|
56985
Description:
Libxml2 contains a flaw in the XML attribute handling that may allow a remote denial of service. The issue is due to multiple use-after-free errors when handling 'Notation' and 'Enumeration' attribute types. With a specially crafted XML file, a context-dependent attacker can cause the service to crash.
|
2009-08-11
|
Libxml2 XML File Multiple Attribute Type Handling DoS
|
|
56916
Description:
Office Web Components is prone to an overflow condition. The ActiveX control fails to properly sanitize user-supplied input via the HTMLURL parameter resulting in a buffer overflow. With a specially crafted website, a context-dependent attacker can potentially cause arbitrary code execution.
|
2009-08-11
|
Microsoft Office Web Components HTMLURL Parameter ActiveX Spreadsheet Object Handling Overflow
|
|
56914
Description:
(Description Provided by CVE) : The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 does not properly allocate memory, which allows remote attackers to execute arbitrary code via unspecified vectors that trigger "system state" corruption, aka "Office Web Components Memory Allocation Vulnerability."
|
2009-08-11
|
Microsoft Office Web Components OWC10 ActiveX Loading/Unloading Memory Allocation Arbitrary Code Execution
|
|
56915
Description:
A heap based buffer overflow exists in Microsoft Office Web Components. With a specially crafted web page, an attacker can cause code execution resulting in a loss of confidentiality and/or availability.
|
2009-08-11
|
Microsoft Office Web Components OWC10.Spreadsheet ActiveX BorderAround() Method Heap Corruption Arbitrary Code Execution
|
|
56986
Description:
(Description Provided by CVE) : WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.
|
2009-08-11
|
Apple Safari WebKit ENVED Ekenebt pluginspage Attribute Arbitrary file: URL Information Disclosure
|
|
56987
Description:
(Description Provided by CVE) : Incomplete blacklist vulnerability in WebKit in Apple Safari before 4.0.3, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to spoof domain names in URLs, and possibly conduct phishing attacks, via unspecified homoglyphs.
|
2009-08-11
|
Apple Safari WebKit Unspecified Homoglyph URL Domain Name Spoofing
|
|
56989
Description:
(Description Provided by CVE) : Unspecified vulnerability in Apple Safari 4 before 4.0.3 allows remote web servers to place an arbitrary web site in the Top Sites view, and possibly conduct phishing attacks, via unknown vectors.
|
2009-08-11
|
Apple Safari window.blur Function Top Sites Feature Arbitrary Site Manipulation
|
|
56988
Description:
(Description Provided by CVE) : Buffer overflow in WebKit in Apple Safari before 4.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted floating-point numbers.
|
2009-08-11
|
Apple Safari WebKit Crafted Floating-point Numbers Remote Overflow
|
|
56997
Description:
ViewVC contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'view' parameter upon submission to the 'viewvc.py' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-08-11
|
ViewVC viewvc.py view Parameter XSS
|
|
57000
Description:
SAP NetWeaver Application Server UDDI Client contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'TModel Key' parameter upon submission to the '/uddiclient/process' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-08-11
|
SAP NetWeaver Application Server UDDI Client /uddiclient/process TModel Key Parameter XSS
|
|
57013
Description:
IDoBlog Component for Joomla! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'userid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-08-11
|
IDoBlog Component for Joomla! index.php userid Parameter SQL Injection
|