| OSVDB ID | Disclosure Date | Title |
|
89876
Description:
By default, Edimax BR-6428n installs with default user credentials (username/password combination). The 'admin' account has a password of '1234', which is publicly known and documented. This allows remote attackers to trivially access the program or system and gain privileged access.
|
2010-09-21
|
Edimax BR-6428n Default Admin Credentials
|
|
68221
Description:
SWiSH Max3 is prone to a flaw in the way it loads dynamic-link libraries (DLL). The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows an attacker to inject custom code that will be run with the privilege of the program or user executing the program. This can be done by tricking a user into opening a SWI file from the local file system or a USB drive in some cases. This attack can be leveraged remotely in some cases by placing the malicious file or library on a network share or extracted archive downloaded from a remote source.
|
2010-09-20
|
SWiSH Max3 Path Subversion Arbitrary DLL Injection Code Execution
|
|
68222
Description:
Fotobook Editor is prone to a flaw in the way it loads dynamic-link libraries (DLL). The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows an attacker to inject custom code that will be run with the privilege of the program or user executing the program. This can be done by tricking a user into opening a DTP file from the local file system or a USB drive in some cases. This attack can be leveraged remotely in some cases by placing the malicious file or library on a network share or extracted archive downloaded from a remote source.
|
2010-09-20
|
Fotobook Editor Path Subversion Arbitrary DLL Injection Code Execution
|
|
68163
Description:
(Description Provided by CVE) : Multiple integer signedness errors in net/rose/af_rose.c in the Linux kernel before 2.6.36-rc5-next-20100923 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a rose_getname function call, related to the rose_bind and rose_connect functions.
|
2010-09-20
|
Linux Kernel net/rose/af_rose.c Multiple Function Signedness Error Local DoS
|
|
68167
Description:
bzip2 contains an integer overflow condition in the decompress functionality. The issue is due to the 'BZ2_decompress()' function in decompress.c not validating user-supplied input when decompressing files. With a specially crafted compressed file, a context-dependent attacker can cause an integer overflow, resulting in a denial of service or potentially execution of arbitrary code.
|
2010-09-20
|
bzip2 decompress.c BZ_decompress Function Overflow
|
|
69658
Description:
OpenSSH contains a flaw related to public parameter validation of the J-PAKE protocol. The issue is triggered when a remote attacker uses crafted values for each round of the protocol to avoid the requirement for the shared sacred and bypass authentication.
|
2010-09-20
|
OpenSSH J-PAKE Public Parameter Validation Shared Secret Authentication Bypass
|
|
70660
Description:
The 'vbd_create' function in Xen allows guest OS users to cause a denial of service when attempting to access a virtual CD-ROM through the blkback driver.
|
2010-09-20
|
Linux Kernel on RHEL Xen vbd_create Function blkback Driver Virtual CD-ROM Device Access Local DoS
|
|
68162
Description:
(Description Provided by CVE) : Stack-based buffer overflow in the HTTP proxy service in Alcatel-Lucent OmniVista 4760 server before R5.1.06.03.c_Patch3 allows remote attackers to execute arbitrary code or cause a denial of service (service crash) via a long request.
|
2010-09-20
|
OmniVista 4760 HTTP Proxy Crafted HTTP Request Remote Overflow
|
|
68161
Description:
(Description Provided by CVE) : The default configuration of the CCAgent option before 9.0.8.4 in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition enables maintenance access, which allows remote attackers to monitor or reconfigure Contact Center operations via vectors involving TSA_maintenance.exe.
|
2010-09-20
|
OmniTouch Contact Center TSA Server Tsa_Maintainance.exe Admin Interface Access Restriction Bypass
|
|
68160
Description:
(Description Provided by CVE) : The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition relies on client-side authorization checking, and unconditionally sends the SuperUser password to the client for use during an authorized session, which allows remote attackers to monitor or reconfigure Contact Center operations via a modified client application.
|
2010-09-20
|
OmniTouch Contact Center Authentication Mechanism Weakness Admin Password Disclosure
|
|
68152
Description:
LightNEasy contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'LightNEasy.php' script not properly sanitizing user-supplied input to the 'handle' parameter and to the 'userhandle' cookie. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-09-20
|
LightNEasy LightNEasy.php Multiple Parameter SQL Injection
|
|
68194
Description:
Primitive CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'cms_write.php' script not properly sanitizing user-supplied input to the 'title' and 'menutitle' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-09-20
|
Primitive CMS cms_write.php Multiple Parameter SQL Injection
|
|
68258
Description:
(Description Provided by CVE) : The (1) init.d/slurm and (2) init.d/slurmdbd scripts in SLURM before 2.1.14 place the . (dot) directory in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
|
2010-09-20
|
SLURM slurm LD_LIBRARY_PATH Path Subversion Local Privilege Escalation
|
|
68259
Description:
(Description Provided by CVE) : The (1) init.d/slurm and (2) init.d/slurmdbd scripts in SLURM before 2.1.14 place the . (dot) directory in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
|
2010-09-20
|
SLURM slurmdbd LD_LIBRARY_PATH Path Subversion Local Privilege Escalation
|
|
68302
Description:
(Description Provided by CVE) : Buffer overflow in the find_stream_bounds function in pdf.c in libclamav in ClamAV before 0.96.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. NOTE: some of these details are obtained from third party information.
|
2010-09-20
|
ClamAV pdf.c find_stream_bounds Function Crafted PDF File Handling Overflow
|
|
72658
Description:
Unknown / Incomplete
|
2010-09-20
|
IB Promotion Advanced Business Web Suite Search Facility qs Parameter XSS
|
|
69286
Description:
Unknown / Incomplete
|
2010-09-20
|
Battle.net Mobile Authenticator MITM Weakness
|
|
68195
Description:
SmarterMail contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the 'FileStorageUpload.ashx' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the 'name' parameter. This directory traversal attack would allow the attacker to access arbitrary files.
|
2010-09-19
|
SmarterMail FileStorageUpload.ashx name Parameter Traversal Arbitrary File Access
|
|
68193
Description:
BoutikOne contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'list.php' script not properly sanitizing user-supplied input to the 'page' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-09-19
|
BoutikOne list.php page Parameter SQL Injection
|
|
68287
Description:
Pluck contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions such as create an arbitrary user. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2010-09-19
|
Pluck Arbitrary User Creation CSRF
|
|
91791
Description:
mingetty contains a flaw that allows an attacker to traverse outside of a restricted path. The issue is due to the chdir() function not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../). This directory traversal attack would allow a local attacker to gain access to arbitrary files.
|
2010-09-19
|
mingetty chdir() Function Traversal Arbitrary File Access
|
|
68402
Description:
(Description Provided by CVE) : The DRDA Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (database server ABEND) by using the client CLI on Linux, UNIX, or Windows for executing a prepared statement with a large number of parameter markers.
|
2010-09-18
|
IBM DB2 UDB DRDA Services Component CLI Prepared Statement Remote DoS
|
|
70607
Description:
PHP contains a flaw that may allow a context-dependent denial of service. The issue is triggered when a use-after-free error in the Zend engine occurs, allowing a context-dependent attacker to use vectors related to the '__set', '__get', '__isset' and '__unset' methods to cause a denial of service, or possibly have other unspecified impact.
|
2010-09-18
|
PHP Zend Engine Multiple Method Object Reference Access Use-after-free DoS
|
|
76216
Description:
Restaurant Guide Component for Joomla! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-09-18
|
Restaurant Guide Component for Joomla! index.php id Parameter SQL Injection
|
|
76241
Description:
Restaurant Guide Component for Joomla! contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input placed after the > character. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-09-18
|
Restaurant Guide Component for Joomla! > Character Parsing XSS
|
|
76254
Description:
Gambio contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'product_reviews_info.php' script not properly sanitizing user-supplied input to the 'products_id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-09-18
|
Gambio product_reviews_info.php products_id Parameter SQL Injection
|
|
68087
Description:
Unknown / Incomplete
|
2010-09-17
|
Nagios XI Multiple Unspecified Script Multiple Parameter XSS
|
|
68097
Description:
Unknown / Incomplete
|
2010-09-17
|
BlueCMS Database Backup Predictable Filename Information Disclosure
|
|
68058
Description:
phpmyfamily contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'reason' parameter upon submission to the 'inc/passwdform.inc.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-09-17
|
phpmyfamily inc/passwdform.inc.php reason Parameter XSS
|
|
68057
Description:
phpmyfamily contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'referer' parameter upon submission to the 'mail.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-09-17
|
phpmyfamily mail.php referer Parameter XSS
|
|
68056
Description:
phpmyfamily contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'person' parameter upon submission to the 'track.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-09-17
|
phpmyfamily track.php person Parameter XSS
|
|
68055
Description:
phpmyfamily contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the multiple unspecified functionalities. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2010-09-17
|
phpmyfamily Multiple Unspecified Admin Function CSRF
|
|
68054
Description:
phpmyfamily contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'my.php' script not properly sanitizing user-supplied input to the 'pwdEmail' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-09-17
|
phpmyfamily my.php pwdEmail Parameter SQL Injection
|
|
68053
Description:
phpmyfamily contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'track.php' script not properly sanitizing user-supplied input to the 'email' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-09-17
|
phpmyfamily track.php email Parameter SQL Injection
|
|
68052
Description:
phpmyfamily contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'passthru.php' script not properly sanitizing user-supplied input to the 'transcript' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-09-17
|
phpmyfamily passthru.php transcript Parameter SQL Injection
|
|
68051
Description:
phpmyfamily contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the 'passthru.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the 'transcript' parameter. This directory traversal attack would allow the attacker to delete arbitrary files on the system.
|
2010-09-17
|
phpmyfamily passthru.php transcript Parameter Traversal Arbitrary File Deletion
|
|
68365
Description:
WebKit contains a typecasting flaw in the 'rendererIsNeeded' function when handling parents that are not SVG elements. With a specially crafted web page, a context-dependent attacker can corrupt memory to cause a denial of service or potentially execute arbitrary code.
|
2010-09-17
|
WebKit rendererIsNeeded SVG Document Handling Bad Cast Memory Corruption
|
|
68096
Description:
(Description Provided by CVE) : Stack-based buffer overflow in WTclient.dll in SCADA Engine BACnet OPC Client before 1.0.25 allows user-assisted remote attackers to execute arbitrary code via a crafted .csv file, related to a status log message.
|
2010-09-17
|
SCADA Engine BACnet OPC Client WTclient.dll Status Log Message Overflow
|
|
68117
Description:
Unknown / Incomplete
|
2010-09-17
|
NitroView ESM Management Interface Unspecified Arbitrary File Access
|
|
68133
Description:
Unknown / Incomplete
|
2010-09-17
|
Syncrify Unspecified Page Direct Request Password Setup Access Restriction Bypass
|