| OSVDB ID | Disclosure Date | Title |
|
70473
Description:
HP OpenView Network Node Manager is prone to multiple overflow conditions. The 'nnmRptConfig.exe' module fails to properly sanitize user-supplied input resulting in buffer overflows. With a specially crafted overly long 'data_select1', 'nameParams', 'schdParams', 'nameParams', 'text1' or 'schd_select1' parameter sent via a POST request to one of the CGI functions of NNM, a remote attacker can potentially execute arbitrary code.
|
2011-01-10
|
HP OpenView Network Node Manager (OV NNM) nnmRptConfig.exe Multiple Parameter Remote Overflow
|
|
70622
Description:
HP Business Service Management on Windows contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-01-10
|
HP Business Service Management on Windows Unspecified XSS
|
|
70681
Description:
syslog-ng contains a type casting error when assigning world-writable permissions to a log file. This may be exploited by a local attacker to modify the file contents.
|
2011-01-10
|
syslog-ng Type Casting Log File Permission Weakness Local File Modification
|
|
70724
Description:
Newv SmartClient NewvCommon ActiveX contains a flaw related to the NewvCommon.ocx control. The 'RunCommand()' method may allow a remote attacker to execute arbitrary code.
|
2011-01-10
|
Newv SmartClient NewvCommon ActiveX (NewvCommon.ocx) RunCommand() Method Arbitrary File Execution
|
|
75073
Description:
(Description Provided by CVE) : slapd (aka ns-slapd) in 389 Directory Server before 1.2.8.a2 does not properly manage the c_timelimit field of the connection table element, which allows remote attackers to cause a denial of service (daemon outage) via Simple Paged Results connections, as demonstrated by using multiple processes to replay TCP sessions, a different vulnerability than CVE-2011-0019.
|
2011-01-10
|
389 Directory Server Simple Paged Results Remote DoS
|
|
70366
Description:
KingView is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a heap overflow. With a specially crafted TCP request, a remote attacker can potentially cause arbitrary code execution.
|
2011-01-09
|
WellinTech KingView HistorySvr.exe TCP Request Remote Overflow
|
|
70401
Description:
Captcha Plugin for Joomla! contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the [plugins/system/captcha/playcode.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the 'lng' parameter. This directory traversal attack would allow the attacker to read arbitrary files.
|
2011-01-09
|
Captcha Plugin for Joomla! plugins/system/captcha/playcode.php lng Parameter Traversal Arbitrary File Access
|
|
70433
Description:
Mingle Forum Plugin for WordPress contains a flaw when updating forum posts. This may be exploited by a remote attacker to edit any post by browsing directly to the Edit Post page.
|
2011-01-08
|
Mingle Forum Plugin for WordPress Edit Post Page Direct Request Forum Post Manipulation
|
|
70434
Description:
Mingle Forum Plugin for WordPress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'wp-content/plugins/mingle-forum/feed.php' script not properly sanitizing user-supplied input to the 'topic' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-01-08
|
Mingle Forum Plugin for WordPress wp-content/plugins/mingle-forum/feed.php topic Parameter SQL Injection
|
|
70435
Description:
Mingle Forum Plugin for WordPress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'wpf-post.php id' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-01-08
|
Mingle Forum Plugin for WordPress wpf-post.php id Parameter SQL Injection
|
|
70436
Description:
Mingle Forum Plugin for WordPress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'wpf-class.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-01-08
|
Mingle Forum Plugin for WordPress wpf-class.php id Parameter SQL Injection
|
|
71650
Description:
(Description Provided by CVE) : The ima_lsm_rule_init function in security/integrity/ima/ima_policy.c in the Linux kernel before 2.6.37, when the Linux Security Modules (LSM) framework is disabled, allows local users to bypass Integrity Measurement Architecture (IMA) rules in opportunistic circumstances by leveraging an administrator's addition of an IMA rule for LSM.
|
2011-01-08
|
Linux Kernel ima_match_rules() LSM Rule Mismatch Weakness
|
|
70411
Description:
IRIX contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a signedness error within the 'syssgi()' system call when processing the request value 'SGI_XLV_ATTR_GET' with the request attribute value 'XLV_ATTR_STATS' is exploited, which will disclose kernel memory to a local attacker. This may also be abused to cause a kernel panic denial of service.
|
2011-01-08
|
IRIX syssgi() System Call Signedness Error Local Kernel Memory Disclosure
|
|
70395
Description:
Zwii contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'system/system.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'set[template][value]' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2011-01-08
|
Zwii system/system.php set[template][value] Parameter Traversal Local File Inclusion
|
|
70408
Description:
NetSupport Manager is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a long control hostname sent to TCP port 5405, a remote attacker can potentially execute arbitrary code.
|
2011-01-08
|
NetSupport Manager Client Control Hostname Remote Overflow
|
|
70615
Description:
Ax Developer CMS contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'modules/profile/user.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'aXconf[default_language]' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2011-01-08
|
Ax Developer CMS modules/profile/user.php aXconf[default_language] Parameter Traversal Local File Inclusion
|
|
70617
Description:
HP Data Protector Manager contains a flaw that may allow a remote denial of service. The RDS service (rds.exe) uses _rm32.dll to allocate memory when receiving packets, and upon reception of an overly large packet, malloc cannot allocate the size, which will result in loss of availability for the program.
|
2011-01-08
|
HP Data Protector Manager rds.exe Packet Size Handling Remote DoS
|
|
70619
Description:
VideoSpirit Pro and VideoSpirit Lite are prone to an overflow condition. The programs fail to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted .visprj file with a long 'name' attribute, a context-dependent attacker can potentially execute arbitrary code.
|
2011-01-08
|
VideoSpirit Multiple Products VISPRJ File valitem Element Multiple Attribute Handling Overflow
|
|
72005
Description:
Joostina contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the com_search component does not validate the 'ordering' parameter upon submission to the index.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-01-08
|
Joostina index.php com_search Component ordering Parameter XSS
|
|
75908
Description:
WSN Software contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker sends a direct request to multiple scripts, which discloses the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2011-01-08
|
WSN Software Multiple Script Direct Request Path Disclosure
|
|
76271
Description:
Unknown / Incomplete
|
2011-01-08
|
Vanilla Forums Cookie Information Disclosure
|
|
76272
Description:
Unknown / Incomplete
|
2011-01-08
|
Vanilla Forums Multiple Plugin Access Restriction Bypass
|
|
70419
Description:
Easy File Uploader Module for Joomla! contains a flaw related to the improper validation of uploaded file extensions. This may allow a remote attacker to upload arbitrary PHP files by passing an allowed MIME media type in the HTTP headers. This will allow the execution of arbitrary PHP code.
|
2011-01-07
|
Easy File Uploader Module for Joomla! Arbitrary File Upload
|
|
70420
Description:
CUDA Toolkit Developer Drivers for Linux contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the 'cudaHostAlloc()' and 'cuMemHostAlloc()' API calls return uncleared pinned memory, which may be exploited to disclose potentially sensitive memory to a local attacker.
|
2011-01-07
|
CUDA Toolkit Developer Drivers for Linux Multiple API Call Memory Disclosure
|
|
70665
Description:
A memory corruption flaw exists in Linux Kernel. The 'dvb_ca_ioctl()' function in 'drivers/media/dvb/ttpci/av7110_ca.c' fails to sanitize user-supplied input, resulting in memory corruption. With a specially crafted IOTCL, a local attacker can execute arbitrary code.
|
2011-01-07
|
Linux Kernel drivers/media/dvb/ttpci/av7110_ca.c dvb_ca_ioctl() Function Crafted IOCTL Handling Memory Corruption
|
|
72007
Description:
SAP Management Console contains a flaw that may allow a remote denial of service. The issue is triggered when an error when processing administration commands occurs, allowing a remote attacker to restart the service.
|
2011-01-07
|
SAP Management Console (SAP MC) Unspecified Remote Service Restart DoS
|
|
72008
Description:
SAP Management Console contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an error in some 'sapstartsrv' SOAP server methods occurs, which will disclose sensitive information about log file lists content, profile parameters, and developer traces to a remote attacker.
|
2011-01-07
|
SAP Management Console (SAP MC) sapstartsrv SOAP Server Unauthenticated Remote Information Disclosure
|
|
79401
Description:
Unknown / Incomplete
|
2011-01-07
|
International Game Technology (IGT) Draw Poker Machine Double Up Feature Inflated Payout Weakness
|
|
70331
Description:
AppArmor contains a flaw related to the parser. The issue is triggered when the program is misconfigured, allowing a local attacker to cause the parser to generate policy using an unconfined fallback execute transition. This may allow an attacker to bypass security restrictions.
|
2011-01-07
|
AppArmor Parser Profile Policy Unconfined Fallback Execute Transition Restriction Bypass
|
|
70306
Description:
StageTracker is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a heap overflow. With a specially crafted SetList file entry, a context-dependent attacker can potentially cause execution of arbitrary code.
|
2011-01-07
|
StageTracker SetList File Entry Handling Overflow
|
|
70305
Description:
pimd contains a flaw that may allow a malicious local user to overwrite arbitrary files on the system. The issue is due to the '/var/tmp/pimd.dump' and '/var/tmp/pimd.cache' files creating temporary files insecurely. It is possible for a local attacker to use a symlink attack to cause the program to unexpectedly write to, or overwrite an attacker specified file.
|
2011-01-07
|
pimd Multiple Temporary File Symlink Arbitrary File Overwrite
|
|
70312
Description:
Mono contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an unspecified error within the 'mod_mono' module occurs, which will disclose ASPX script source code to a remote attacker.
|
2011-01-07
|
Mono ASP.NET mod_mono Module ASPX Script Source Disclosure
|
|
70314
Description:
concrete5 contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the addition of scrapbook entries. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2011-01-07
|
concrete5 Scrapbook Entry Addition CSRF
|
|
70656
Description:
VLC Media Player is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a heap-based buffer overflow. With a specially crafted CDG video, a context-dependent attacker can cause a denial of service, or possibly execute arbitrary code.
|
2011-01-07
|
VLC Media Player CDG Decoder cdg.c Crafted Video File Handling Overflow DoS
|
|
73294
Description:
Afaria Data Security Manager contains an unspecified flaw related to login that may allow an attacker to access a locked device. No further details have been provided.
|
2011-01-07
|
Sybase Afaria Data Security Manager on Symbian Unspecified Login Bypass
|
|
72699
Description:
(Description Provided by CVE) : Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0.1 on z/OS allows attackers to read arbitrary files via unknown vectors.
|
2011-01-07
|
IBM WebSphere Application Server (WAS) Admin Console /ibm/console/jvmLogDetail.do runtimeErrFileName Parameter Arbitrary File Access
|
|
82528
Description:
BS.player is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted M3U file, a context-dependent attacker can potentially execute arbitrary code.
|
2011-01-07
|
BS.player M3U File Handling Overflow
|
|
70368
Description:
dpkg contains a flaw that allows a context-dependent attacker to traverse outside of a restricted path. The issue is due to the dpkg-source component not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via patches for source-format packages. This directory traversal attack would allow the attacker to overwrite arbitrary files.
|
2011-01-06
|
dpkg dpkg-source source-format Package Traversal Arbitrary File Overwrite
|
|
70440
Description:
Contao contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the 'X_FORWARDED_FOR' HTTP header before being used when submitting to the 'system/modules/comments/Comments.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-01-06
|
Contao system/modules/comments/Comments.php X_FORWARDED_FOR HTTP Header XSS
|
|
74341
Description:
McAfee VirusScan contains a flaw that may allow a malicious local user to overwrite arbitrary files on the system. The issue is due to the program creating temporary files insecurely. It is possible for a local attacker to use a symlink attack to cause the program to unexpectedly write to, or overwrite an attacker specified file.
|
2011-01-06
|
McAfee VirusScan Command Line Updater Script /tmp Symlink Arbitrary File Ovewrite
|