| OSVDB ID | Disclosure Date | Title |
|
69537
Description:
Enano CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'email' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-11-30
|
Enano CMS index.php email Parameter SQL Injection
|
|
69539
Description:
DynPG CMS contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the 'index.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the 'CHG_DYNPG_SET_LANGUAGE' parameter. This directory traversal attack would allow the attacker to access arbitrary files.
|
2010-11-30
|
DynPG CMS index.php CHG_DYNPG_SET_LANGUAGE Parameter Traversal Arbitrary File Access
|
|
69534
Description:
Winamp is prone to an overflow condition. An integer overflow error in 'in_nsv.dll' when parsing the NSV Table of Contents data can result in a heap-based buffer overflow. With a specially crafted stream or file, a context-dependent attacker can potentially execute arbitrary code.
|
2010-11-30
|
Winamp in_nsv.dll NSV Table of Contents Data Overflow
|
|
69535
Description:
Winamp is prone to an overflow condition. The in_midi plugin functionality fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted file, a context-dependent attacker can potentially execute arbitrary code.
|
2010-11-30
|
Winamp in_midi Plugin MIDI File Format Processing Overflow
|
|
69607
Description:
MIT Kerberos 5 (krb5) contains a flaw related to the Key Distrubiton Center (KDC). The KDC does not properly restrict the use of TGT credentials for armoring TGS requests. The issue is triggered when a remote, authenticated attacker rewrites an inner request (or 'KrbFastReq Forgery Issue']. This may allow the attacker to impersonate a client.
|
2010-11-30
|
MIT Kerberos 5 Key Distribution Center (KDC) TGS Request TGT Credentials Inner Request KrbFastReq Forgery Issue
|
|
69610
Description:
MIT Kerberos 5 (krb5) contains a flaw related to the acceptability of checksums. This may allow a remote attacker to modify user-visible prompt text, modify a reponse to a KDC, or forge a KRB-SAFE message via unkeyed checksums or the use of RC4 keys.
|
2010-11-30
|
MIT Kerberos 5 Checksum Acceptability Weakness KDC / KRB-SAFE Message Forgery Issue
|
|
89049
Description:
Foswiki contains a flaw that may lead to unauthorized disclosure of potentially sensitive information. The issue is triggered when searching private group topics. The program fails to properly check ACLs, which may allow an unprivileged remote attacker to gain access to group topic information.
|
2010-11-30
|
Foswiki Unprivileged Search Private Group Topic Disclosure
|
|
71571
Description:
Some versions of an unspecified package hosted on the savannah.gnu.org FTP site were found to contain a backdoor. The Trojaned code presumably allows a knowledgeable attacker to gain some form of privileged access. Using this backdoor, an attacker could gain elevated privileges to the remote host.
|
2010-11-30
|
savannah.gnu.org Unspecified Project Trojaned Distribution
|
|
69532
Description:
Kerio Control contains a flaw related to the Web Filter component. This is caused by an unspecified error and has an unknown impact. No further details have been provided.
|
2010-11-30
|
Kerio Control Web Filter Unspecified Issue
|
|
69611
Description:
ClamAV contains a flaw that may allow a remote denial of service. The issue is triggered when handling PDF files, and can be exploited to result in loss of availability.
|
2010-11-30
|
ClamAV libclamav pdf.c PDF File Handling DoS (2010-4260)
|
|
69608
Description:
MIT Kerberos 5 (krb5) does not properly reject RC4 key-derivation checksums. The issue is triggered when a remote, authenticated attacker forges an 'AD-SIGNEDPATH' or 'AD-KDC-ISSUED' signature through vulnerabilities in certain certain one-byte stream-cipher operations. This may allow an attacker to gain elevated privileges.
|
2010-11-30
|
MIT Kerberos 5 (krb5) RC4 Key-derivation Checksums One-byte Stream-cipher Operation Signature Forgery Issue
|
|
69609
Description:
[MIT Kerberos 5 (krb5)contains a flaw related to the acceptability of checksums. This may allow a remote attacker to forge GSS tokens via an unkeyed checksum, gain privileges via an unkeyed PAC checksum (the attacker must be authenticated in this case), or have other unspecified impact via a KrbFastArmoredReq checksum based on an RC4 key.
|
2010-11-30
|
MIT Kerberos 5 (krb5) Checksum Acceptability Weakness RC4 Key GSS Token Forgery Issue
|
|
69612
Description:
A memory corruption flaw exists in ClamAV. The 'icon_cb()' function contains an off-by-one error, which can be exploited to result in memory corruption. This may allow a remote attacker to execute arbitrary code.
|
2010-11-30
|
ClamAV libclamav pe_icons.c icon_cb() Function Off-by-one Memory Corruption
|
|
69631
Description:
DynPG CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'in _rights.php' script not properly sanitizing user-supplied input to the 'giveRights_UserId' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-11-30
|
DynPG CMS in _rights.php giveRights_UserId Parameter SQL Injection
|
|
69632
Description:
DynPG CMS contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered due to 'languages.inc.php' allowing remote attackers to obtain sensitive information via a direct request, disclosing the installation path in an error message to a remote attacker.
|
2010-11-30
|
DynPG CMS languages.inc.php Direct Request Path Disclosure
|
|
69652
Description:
FontForge is prone to an overflow condition. The program fails to parse overly long 'CHARSET_REGISTRY' lines properly, resulting in a stack-based buffer overflow. With a specially crafted BDF font file, a remote attacker can potentially execute arbitrary code.
|
2010-11-30
|
FontForge BDF Font File CHARSET_REGISTRY Header Overflow
|
|
69656
Description:
ClamAV contains a flaw that may allow a remote denial of service. The issue is triggered when handling PDF files, and can be exploited to result in loss of availability.
|
2010-11-30
|
ClamAV libclamav pdf.c PDF File Handling DoS (2010-4479)
|
|
70658
Description:
Linux Kernel contains a flaw that may allow a local denial of service. The issue is triggered when the 'pipe_fcntl' function in 'fs/pipe.c' fails to determine whether a file is a named pipe, allowing a local attacker to use a F_SETPIPE_SZ fcntl call to cause a denial of service.
|
2010-11-30
|
Linux Kernel fs/pipe.c pipe_fcntl Function F_SETPIPE_SZ fcntl Call Local DoS
|
|
71533
Description:
WebKit contains a use-after-free error that is triggered when handling CSS stylesheets lacking wrappers in detached subtrees. With a specially crafted web page, a context-dependent attacker can dereference already freed memory and potentially execute arbitrary code.
|
2010-11-30
|
WebKit CSS Stylesheets Lacking Wrappers Detached Subtrees Handling Use-after-free Issue
|
|
71501
Description:
WebKit contains a use-after-free error that is triggered when the title of an AccessibilityImageMapLink is requested, but the map's area element is removed. With a specially crafted web page, a context-dependent attacker can dereference already freed memory and potentially execute arbitrary code.
|
2010-11-30
|
WebKit Accessibility Notification Sending Style Computation Use-after-free Issue
|
|
71572
Description:
Unknown / Incomplete
|
2010-11-30
|
Wernhart Guestbook insert.phtml Multiple Parameter XSS
|
|
74994
Description:
Unknown / Incomplete
|
2010-11-30
|
Canon Original Decision Data (ODD) Digital Signature Spoofing Weakness
|
|
73144
Description:
(Description Provided by CVE) : index.php in Enano CMS 1.1.7pl1, and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2, allows remote attackers to obtain sensitive information via a crafted title parameter, which reveals the installation path in an error message.
|
2010-11-30
|
Enano CMS index.php title Parameter Error Message Path Disclosure
|
|
69569
Description:
BugTracker.NET contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'pcd' parameter upon submission to the edit_bug.aspx script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-11-29
|
BugTracker.NET edit_bug.aspx pcd Parameter XSS
|
|
69576
Description:
BugTracker.NET contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'bug_id' parameter upon submission to the edit_comment.aspx script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-11-29
|
BugTracker.NET edit_comment.aspx bug_id Parameter XSS
|
|
69575
Description:
BugTracker.NET contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'default_name' parameter upon submission to the edit_customfield.aspx script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-11-29
|
BugTracker.NET edit_customfield.aspx default_name Parameter XSS
|
|
69574
Description:
BugTracker.NET contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'id' parameter upon submission to the edit_user_permissions2.aspx script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-11-29
|
BugTracker.NET edit_user_permissions2.aspx id Parameter XSS
|
|
69573
Description:
BugTracker.NET contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the bugs.aspx script not properly sanitizing user-supplied input to the 'qu_id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-11-29
|
BugTracker.NET bugs.aspx qu_id Parameter SQL Injection
|
|
69572
Description:
BugTracker.NET contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the delete_query.aspx script not properly sanitizing user-supplied input to the 'row_id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-11-29
|
BugTracker.NET delete_query.aspx row_id Parameter SQL Injection
|
|
69571
Description:
BugTracker.NET contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the edit_bug.aspx script not properly sanitizing user-supplied input to the 'us_id' and 'new_project' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-11-29
|
BugTracker.NET edit_bug.aspx Multiple Parameter SQL Injection
|
|
69570
Description:
BugTracker.NET contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the massedit.aspx script not properly sanitizing user-supplied input to the 'bug_list' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-11-29
|
BugTracker.NET massedit.aspx bug_list Parameter SQL Injection
|
|
69786
Description:
BizDir contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'f_srch' parameter upon submission to the bizdir.cgi script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-11-29
|
BizDir bizdir.cgi f_srch Parameter XSS
|
|
69503
Description:
McAfee VirusScan Enterprise is prone to a flaw in the way it loads dynamic-link libraries (DLL). The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows an attacker to inject custom code that will be run with the privilege of the program or user executing the program. This can be done by tricking a user into opening a Word Document with an embedded ActiveX control from a remote WebDAV or SMB share in Microsoft Office 2003.
|
2010-11-29
|
McAfee VirusScan Enterprise Path Subversion Arbitrary DLL Injection Code Execution
|
|
69613
Description:
Xen contains a flaw that may allow a local denial of service. The issue is triggered when insufficient restriction checks within the 'fixup_page_fault()' function in 'xen/arch/x86/traps.c' are exploited from a guest system to trigger a 'BUG_ON()', which will result in loss of availability.
|
2010-11-29
|
Xen xen/arch/x86/traps.c fixup_page_fault() Function Local DoS
|
|
69582
Description:
Multiple Cisco products contain a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the remote-access IPSec VPN implementation responds to an Aggressive Mode IKE Phase I message only when the group name is configured on the device, allowing a remote attacker to enumerate valid group names via IKE negotiation attempts.
|
2010-11-29
|
Cisco Multiple Products IPSec VPN Aggressive Mode IKE Phase I Message Response Group Name Remote Enumeration
|
|
69505
Description:
Big Truck Broker contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'news_default.asp' script not properly sanitizing user-supplied input to the 'txtSiteId' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-11-29
|
Big Truck Broker news_default.asp txtSiteId Parameter SQL Injection
|
|
69504
Description:
SiteEngine contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'comments.php' script not properly sanitizing user-supplied input to the 'module' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-11-29
|
SiteEngine comments.php module Parameter SQL Injection
|
|
69506
Description:
MemHT Portal contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'User-Agent' HTTP header upon submission to the index.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-11-29
|
MemHT Portal index.php User-Agent HTTP Header XSS
|
|
69533
Description:
GNU Gnash contains a flaw related to the configure script functionality. The issue is triggered when a local attacker uses symlink attacks to overwrite arbitrary files with privileges of the user running the script.
|
2010-11-29
|
GNU Gnash Configure Script Temporary File Symlink Arbitrary File Overwrite
|
|
69580
Description:
RV Dealer Website contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'search.asp' script not properly sanitizing user-supplied input to the 'selStock' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-11-29
|
RV Dealer Website search.asp selStock Parameter SQL Injection
|