| OSVDB ID | Disclosure Date | Title |
|
72151
Description:
Magazeen Theme for WordPress contains a bundled version of TimThumb which contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input passed via the PATH_INFO and 'src' parameter upon submission to the timthumb.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-04-30
|
Magazeen Theme for WordPress timthumb.php Multiple Parameter XSS
|
|
72118
Description:
(Description Provided by CVE) : VMware ESXi 4.0 and 4.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (socket exhaustion) via unspecified network traffic.
|
2011-04-30
|
VMware ESX Server / ESXi Unspecified Socket Exhaustion Remote DoS
|
|
72101
Description:
Core Player is prone to an overflow condition. The application fails to properly sanitize user-supplied input resulting in a stack buffer overflow. With a specially crafted file, a context-dependent attacker can potentially cause arbitrary code execution.
|
2011-04-30
|
MJM Core Player s3m File Handling Overflow
|
|
72102
Description:
QuickPlayer is prone to an overflow condition. The application fails to properly sanitize user-supplied input resulting in a stack buffer overflow. With a specially crafted file, a context-dependent attacker can potentially cause arbitrary code execution.
|
2011-04-30
|
MJM QuickPlayer s3m File Handling Overflow
|
|
72144
Description:
aXes Terminal Server contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'login' parameter upon submission to the axests/terminal script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-04-30
|
LANSA aXes Terminal Server axests/terminal login Parameter XSS
|
|
72152
Description:
Magazeen Theme for WordPress contains a bundled version of TimThumb which contains a flaw that may allow a remote denial of service. The issue is triggered when the program improperly handles large remote image data, resulting in a loss of availability.
|
2011-04-30
|
Magazeen Theme for WordPress Remote Image Data Handling DoS
|
|
72153
Description:
Magazeen Theme for WordPress contains a bundled version of TimThumb which contains a flaw that may allow a remote denial of service. The issue is triggered when the program fails to properly process large image dimensions when passed to the image resizing functionality, resulting in a loss of availability.
|
2011-04-30
|
Magazeen Theme for WordPress Image Dimensions Resizing DoS
|
|
72136
Description:
Data Dynamics ActiveBar ActiveBar1 ActiveX contains a flaw related to the SetLayoutData() method. The issue is triggered when a remote attacker uses a specially crafted 'Data' argument to send a virtual function call to an arbitrary memory location. This may allow an attacker to execute arbitrary code.
|
2011-04-29
|
Data Dynamics ActiveBar ActiveBar1 ActiveX SetLayoutData() Method Data Argument Arbitrary Code Execution
|
|
75980
Description:
(Description Provided by CVE) : Integer overflow in the sys_oabi_semtimedop function in arch/arm/kernel/sys_oabi-compat.c in the Linux kernel before 2.6.39 on the ARM platform, when CONFIG_OABI_COMPAT is enabled, allows local users to gain privileges or cause a denial of service (heap memory corruption) by providing a crafted argument and leveraging a race condition.
|
2011-04-29
|
Linux Kernel CONFIG_OABI_COMPAT semtimedop Call Parsing Local Privilege Escalation
|
|
72104
Description:
Interbase XE is prone to an overflow condition. The database service, ibserver.exe, fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a specially crafted 'connect', opcode 0x01, message, a remote attacker can potentially execute arbitrary code.
|
2011-04-29
|
Interbase XE ibserver.exe connect Request Overflow
|
|
74016
Description:
WebKit contains a use-after-free error that is triggered when handling table caption layouts. With a specially crafted web page, a context-dependent attacker can dereference already freed memory and potentially execute arbitrary code.
|
2011-04-29
|
WebKit Table Caption Layout Handling Use-after-free Arbitrary Code Execution
|
|
77362
Description:
(Description Provided by CVE) : GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the current working directory, which allows local users to gain privileges via crafted files such as Python scripts.
|
2011-04-29
|
GNU Debugger (gdb) .debug_gdb_scripts Parsing Remote Code Execution
|
|
72135
Description:
ICONICS WebHMI VersionInfo ActiveX is prone to an overflow condition. The 'SetActiveXGUID()' method, GenVersion.dll, suffers from a boundary error, resulting in a stack-based buffer overflow. With a specially crafted overly long string to the 'Ax_GUID' parameter, a remote attacker can potentially execute arbitrary code.
|
2011-04-28
|
ICONICS WebHMI VersionInfo ActiveX (GenVersion.dll) SetActiveXGUID() Method Ax_GUID Parameter Overflow
|
|
72055
Description:
BackupPC contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'share' parameter upon submission to the index.cgi script before returning it in the RestoreFile.pm script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-04-28
|
BackupPC RestoreFile.pm XSS
|
|
72576
Description:
Unknown / Incomplete
|
2011-04-28
|
FFmpeg libavutil/log.c av_log_default_callback() Function Unspecified Race Condition
|
|
72051
Description:
phpGraphy contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'theme_dir' parameter upon submission to the themes/default/header.inc.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-04-28
|
phpGraphy themes/default/header.inc.php theme_dir Parameter XSS
|
|
72052
Description:
phpGraphy contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the addition of arbitrary administrator users. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2011-04-28
|
phpGraphy Admin User Creation CSRF
|
|
72053
Description:
WP Photo Album Plugin for WordPress contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the wp-content/plugins/wp-photo-album/wppa.php script does not validate the 'id' parameter upon submission to the wp-admin/admin.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-04-28
|
WP Photo Album Plugin for WordPress wp-admin/admin.php id Parameter XSS
|
|
72057
Description:
Daily Maui Photo Widget Plugin for WordPress contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'title' parameter upon submission to the wp-content/plugins/daily-maui-photo-widget/wp-dailymaui-widget-control.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-04-28
|
Daily Maui Photo Widget Plugin for WordPress wp-content/plugins/daily-maui-photo-widget/wp-dailymaui-widget-control.php title Parameter XSS
|
|
72056
Description:
Daily Maui Photo Widget Plugin for WordPress contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'selected_small', 'selected_medium', 'selected_thumb', 'selected_date', and 'selected_full' parameters upon submission to the wp-content/plugins/daily-maui-photo-widget/wp-dailymaui-widget-control.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-04-28
|
Daily Maui Photo Widget Plugin for WordPress wp-content/plugins/daily-maui-photo-widget/wp-dailymaui-widget-control.php Multiple Parameter XSS
|
|
72098
Description:
LDAP Account Manager contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the 'lib/status.inc' script does not validate the 'selfserviceSaveOk' parameter upon submission to the 'templates/login.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-04-28
|
LDAP Account Manager templates/login.php selfserviceSaveOk Parameter XSS
|
|
72157
Description:
libmodplug is prone to an overflow condition. The 'abc_new_macro()' and 'abc_new_umacro()' functions fail to properly sanitize user-supplied input resulting in a stack buffer overflow. With a specially crafted ABC file, a context-dependent attacker can potentially cause arbitrary code execution.
|
2011-04-28
|
libmodplug src/load_abc.cpp Multiple Function ABC File Handling Overflow
|
|
72291
Description:
NetOp is prone to an overflow condition. Remote Control fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted request, a local attacker can potentially cause arbitrary code execution.
|
2011-04-28
|
NetOp Remote Control DWS File Handling Overflow
|
|
72085
Description:
Mozilla Firefox and SeaMonkey contain a user-after-free flaw related to the OBJECT's mChannel that may allow a context-dependent attacker to execute arbitrary code. No further details have been provided.
|
2011-04-28
|
Mozilla Multiple Products OBJECT's mChannel Use-after-free Remote Code Execution
|
|
72091
Description:
Mozilla Firefox for Windows contains a flaw as the WebGLES library is compiled without ASLR protection. This may allow an attacker to more reliably exploit a code execution vulnerability by bypassing ASLR protection on Windows Vista and newer versions, making these effectively as vulnerable as older versions without ASLR protection.
|
2011-04-28
|
Mozilla Firefox for Windows WebGLES Library Missing ASLR Protection Weakness
|
|
72093
Description:
ANGLE WebGLES graphics library contains an off-by-three overflow condition in the 'Program::getActiveUniformMaxLength' function [libGLESv2/Program.cpp]. With a specially crafted web page, a context-dependent attacker can cause a limited buffer overflow, resulting in a denial of service or potentially execution of arbitrary code.
|
2011-04-28
|
ANGLE WebGLES Graphics Library Program::getActiveUniformMaxLength Off-by-three Overflow
|
|
72112
Description:
FrontAccounting contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the creation of arbitrary administrator users. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2011-04-28
|
FrontAccounting (FA) admin/users.php Arbitrary Admin User Creation CSRF
|
|
72865
Description:
(Description Provided by CVE) : Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long (1) InternationalOrder, (2) InternationalSeparator, or (3) LogFileName property value; or (4) a long bstrFileName argument to the OpenScreen method.
|
2011-04-28
|
InduSoft ISSymbol ActiveX (ISSymbol.ocx) Multiple Overflows
|
|
72187
Description:
HP OpenView Storage Data Protector is prone to an overflow condition. The Backup Client Service, OmniInet.exe, fails to properly sanitize user-supplied input when processing EXEC_BAR messages, resulting in a stack-based buffer overflow. With a specially crafted packet sent to TCP port 5555, a remote attacker can potentially execute arbitrary code.
|
2011-04-28
|
HP OpenView Storage Data Protector Backup Client Service OmniInet.exe EXEC_BAR Message Processing Overflow
|
|
73742
Description:
(Description Provided by CVE) : lsassd in Likewise Open /Enterprise 5.3 before build 7845, Open 6.0 before build 8325, and Enterprise 6.0 before build 178, as distributed in VMware ESXi 4.1 and ESX 4.1 and possibly other products, allows remote attackers to cause a denial of service (daemon crash) via an Active Directory login attempt that provides a username containing an invalid byte sequence.
|
2011-04-28
|
Likewise Open / Enterprise lsassd Service Remote DoS
|
|
72074
Description:
Multiple memory corruption flaws exist in Mozilla Firefox, Thunderbird and SeaMonkey. The programs fail to sanitize certain unspecified user-supplied input, resulting in memory corruption. Through unspecified vectors, a context-dependent attacker can execute arbitrary code.
|
2011-04-28
|
Mozilla Multiple Products Multiple Unspecified Memory Corruption (2011-0079)
|
|
72076
Description:
Mozilla Firefox, Thunderbird and SeaMonkey contain an unspecified flaw that may allow a context-dependent attacker to cause a denial of service. No further details have been provided.
|
2011-04-28
|
Mozilla Multiple Products Unspecified Remote DoS (2011-0069)
|
|
72077
Description:
Mozilla Firefox, Thunderbird and SeaMonkey contain an unspecified flaw that may allow a context-dependent attacker to cause a denial of service. No further details have been provided.
|
2011-04-28
|
Mozilla Multiple Products Unspecified Remote DoS (2011-0070)
|
|
72080
Description:
A memory corruption flaw exists in Mozilla Firefox, Thunderbird and SeaMonkey. The programs fail to sanitize certain unspecified user-supplied input, resulting in memory corruption. Through unspecified vectors, a context-dependent attacker can execute arbitrary code.
|
2011-04-28
|
Mozilla Multiple Products Unspecified Memory Corruption (2011-0074)
|
|
72081
Description:
A memory corruption flaw exists in Mozilla Firefox, Thunderbird and SeaMonkey. The programs fail to sanitize certain unspecified user-supplied input, resulting in memory corruption. Through unspecified vectors, a context-dependent attacker can execute arbitrary code.
|
2011-04-28
|
Mozilla Multiple Products Unspecified Memory Corruption (2011-0075)
|
|
72082
Description:
A memory corruption flaw exists in Mozilla Firefox, Thunderbird and SeaMonkey. The programs fail to sanitize certain unspecified user-supplied input, resulting in memory corruption. Through unspecified vectors, a context-dependent attacker can execute arbitrary code.
|
2011-04-28
|
Mozilla Multiple Products Unspecified Memory Corruption (2011-0077)
|
|
72083
Description:
A memory corruption flaw exists in Mozilla Firefox, Thunderbird and SeaMonkey. The programs fail to sanitize certain unspecified user-supplied input, resulting in memory corruption. Through unspecified vectors, a context-dependent attacker can execute arbitrary code.
|
2011-04-28
|
Mozilla Multiple Products Unspecified Memory Corruption (2011-0078)
|
|
72084
Description:
A memory corruption flaw exists in Mozilla Firefox, Thunderbird and SeaMonkey. The programs fail to sanitize certain unspecified user-supplied input, resulting in memory corruption. Through unspecified vectors, a context-dependent attacker can execute arbitrary code.
|
2011-04-28
|
Mozilla Multiple Products Unspecified Memory Corruption (2011-0072)
|
|
72086
Description:
Mozilla Firefox and SeaMonkey contain a user-after-free flaw related to the OBJECT's mObserverList that may allow a context-dependent attacker to execute arbitrary code. No further details have been provided.
|
2011-04-28
|
Mozilla Multiple Products OBJECT's mObserverList Use-after-free Remote Code Execution
|
|
72087
Description:
Mozilla Firefox and SeaMonkey contain a dangling pointer flaw related to 'nsTreeRange' that may allow a context-dependent attacker to execute arbitrary code.
|
2011-04-28
|
Mozilla Multiple Products nsTreeRange Dangling Pointer Remote Code Execution
|